Bug#974543: Acknowledgement (segmentation fault on launch)

2020-11-12 Thread Mika Hanhijärvi




I am able to work around this problem on Debian Buster by adding the line:


imports.gi.versions.GtkSource = "3.0";


to the beginning of the file:


/usr/share/sushi/js/viewers/text.js



Bug#974543: Acknowledgement (segmentation fault on launch)

2020-11-11 Thread Mika Hanhijärvi

I am able to work around this problem on Debian Buster by adding the line:

|imports.gi.versions.GtkSource = "3.0";|


to the beginning of the file:

|
|

|/usr/share/sushi/js/viewers/text.js|

|
|



Bug#974543: segmentation fault on launch

2020-11-11 Thread Mika Hanhijärvi
Package: gnome-sushi
Version: 3.30.0-2
Severity: grave

Hello

Sushi does not seem to work on Debian Buster. If I select e.g. some mp3 file in
Nautilus filemanager and press the space bar then nothing happens. The same
happens if I select file of some other type. I also get this error in the
/var/log/syslog

Nov 12 06:16:13 miksuh-laptop kernel: [10482.886638] sushi-start[11917]:
segfault at 0 ip 7ff7a1aaf64f sp 7ffe20adb3c0 error 6 in
libgjs.so.0.0.0[7ff7a1a75000+67000]
Nov 12 06:16:13 miksuh-laptop kernel: [10482.886648] Code: 00 e8 a5 7c fc ff 4c
8b 04 24 48 8d 0d 5d 41 03 00 48 8b 7c 24 18 89 c6 31 d2 31 c0 e8 4a 9e fc ff
48 8b 7b 18 e8 11 8e fc ff <41> c7 07 01 00 00 00 e9 82 00 00 00 0f 1f 44 00 00
48 8b bb 78 01

When I try to launch sushi from the command line it segfaults with the followin
error:

Gjs-Message: 06:06:08.541: JS WARNING: [/usr/share/sushi/js/viewers/text.js
26]: Requiring Gdk but it has 2 versions available; use imports.gi.versions to
pick one
Gjs-Message: 06:06:08.563: JS WARNING: [/usr/share/sushi/js/viewers/text.js
30]: Requiring GtkSource but it has 2 versions available; use
imports.gi.versions to pick one

(sushi-start:11595): Gjs-WARNING **: 06:06:08.564: JS ERROR: Error: Requiring
Sushi, version none: Requiring namespace 'GtkSource' version '3.0', but '4' is
already loaded
@/usr/share/sushi/js/viewers/text.js:33:7

Segmentation fault


This seems to be the same bug as reported upstream here:

https://gitlab.gnome.org/GNOME/sushi/-/issues/12






-- System Information:
Debian Release: 10.6
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.8.0-0.bpo.2-amd64 (SMP w/4 CPU cores)
Kernel taint flags: TAINT_CRAP
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8), 
LANGUAGE=fi_FI.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages gnome-sushi depends on:
ii  gir1.2-clutter-1.0  1.26.2+dfsg-10
ii  gir1.2-clutter-gst-3.0  3.0.26-2
ii  gir1.2-evince-3.0   3.30.2-3+deb10u1
ii  gir1.2-gdkpixbuf-2.02.38.1+dfsg-1
ii  gir1.2-glib-2.0 1.58.3-2
ii  gir1.2-gst-plugins-base-1.0 1.14.4-2
ii  gir1.2-gstreamer-1.01.14.4-1
ii  gir1.2-gtk-3.0  3.24.5-1
ii  gir1.2-gtkclutter-1.0   1.8.4-4
ii  gir1.2-gtksource-3.03.24.9-2
ii  gir1.2-pango-1.01.42.4-8~deb10u1
ii  gir1.2-webkit2-4.0  2.28.4-1~deb10u1
ii  gstreamer1.0-plugins-good   1.14.4-1
ii  libc6   2.28-10
ii  libcairo2   1.16.0-4
ii  libclutter-1.0-01.26.2+dfsg-10
ii  libclutter-gst-3.0-03.0.26-2
ii  libclutter-gtk-1.0-01.8.4-4
ii  libevdocument3-43.30.2-3+deb10u1
ii  libevview3-33.30.2-3+deb10u1
ii  libfreetype62.9.1-3+deb10u2
ii  libgdk-pixbuf2.0-0  2.38.1+dfsg-1
ii  libgirepository-1.0-1   1.58.3-2
ii  libgjs0g1.54.3-1
ii  libglib2.0-02.58.3-2+deb10u2
ii  libgstreamer-plugins-base1.0-0  1.14.4-2
ii  libgstreamer1.0-0   1.14.4-1
ii  libgtk-3-0  3.24.5-1
ii  libgtksourceview-3.0-1  3.24.9-2
ii  libharfbuzz0b   2.3.1-1
ii  libmusicbrainz5-2   5.1.0+git20150707-9
ii  libpango-1.0-0  1.42.4-8~deb10u1
ii  libpangocairo-1.0-0 1.42.4-8~deb10u1
ii  libx11-62:1.6.7-1+deb10u1
ii  nautilus3.30.5-2

gnome-sushi recommends no packages.

Versions of packages gnome-sushi suggests:
ii  gstreamer1.0-libav  1.15.0.1+git20180723+db823502-2

-- no debconf information



Bug#966135: mpv: Unusable when playing from CIFS share

2020-07-23 Thread Mika Tiainen
Package: mpv
Version: 0.32.0-2
Severity: normal
Tags: fixed-upstream

Hi,

Current MPV release has issue that causes very slow read speed from CIFS
mounted share, video freezes every few seconds when cache runs out. This is
already fixed upstream:

https://github.com/mpv-player/mpv/commit/20eead18130fd460d8e9eff50ce14afd3646faab

Can the fix be pulled to Debian, while waiting for a new upstream release?


-- System Information:
Debian Release: bullseye/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.7.0-1-amd64 (SMP w/4 CPU threads)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_GB:en
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages mpv depends on:
ii  libarchive13   3.4.3-1+b1
ii  libasound2 1.2.2-2.3
ii  libass91:0.14.0-2
ii  libavcodec-extra58 [libavcodec58]  7:4.3-3+b1
ii  libavdevice58  7:4.3-3+b1
ii  libavfilter7   7:4.3-3+b1
ii  libavformat58  7:4.3-3+b1
ii  libavutil567:4.3-3+b1
ii  libbluray2 1:1.2.0-3
ii  libc6  2.31-2
ii  libcaca0   0.99.beta19-2.1
ii  libcdio-cdda2  10.2+2.0.0-1+b1
ii  libcdio-paranoia2  10.2+2.0.0-1+b1
ii  libcdio18  2.0.0-2
ii  libdrm22.4.102-1
ii  libdvdnav4 6.1.0-1+b1
ii  libegl11.3.1-1
ii  libgbm120.1.2-1
ii  libgl1 1.3.1-1
ii  libjack-jackd2-0 [libjack-0.125]   1.9.14~dfsg-0.1
ii  libjpeg62-turbo1:2.0.5-1
ii  liblcms2-2 2.9-4+b1
ii  liblua5.2-05.2.4-1.1+b3
ii  libpulse0  13.0-5
ii  librubberband2 1.8.2-1
ii  libsdl2-2.0-0  2.0.12+dfsg1-1
ii  libsmbclient   2:4.12.5+dfsg-3
ii  libsndio7.01.5.0-3
ii  libswresample3 7:4.3-3+b1
ii  libswscale57:4.3-3+b1
ii  libuchardet0   0.0.7-1
ii  libva-drm2 2.8.0-1
ii  libva-wayland2 2.8.0-1
ii  libva-x11-22.8.0-1
ii  libva2 2.8.0-1
ii  libvdpau1  1.4-2
ii  libwayland-client0 1.18.0-1
ii  libwayland-cursor0 1.18.0-1
ii  libwayland-egl11.18.0-1
ii  libx11-6   2:1.6.9-2+b1
ii  libxext6   2:1.3.3-1+b2
ii  libxinerama1   2:1.1.4-2
ii  libxkbcommon0  0.10.0-1
ii  libxrandr2 2:1.5.1-1
ii  libxss11:1.2.3-1
ii  libxv1 2:1.0.11-1
ii  zlib1g 1:1.2.11.dfsg-2

Versions of packages mpv recommends:
ii  xdg-utils   1.1.3-2
ii  youtube-dl  2020.06.16.1-1

mpv suggests no packages.

-- no debconf information



Bug#960380: python3-xarray: Import fails if python3-sparse is also installed

2020-05-12 Thread Mika Pflüger
Package: python3-xarray
Version: 0.15.1-2
Severity: normal

Hi,

if python3-xarray and python3-sparse are both installed, importing xarray fails 
with
an AttributeError, because xarray uses an unqualified "import sparse" trying to
import an internal package. The internal package is shadowed by python3-sparse,
which does not have the same API as xarray's internal package.

The full backtrace in ipython3 is:

22:09:205:~> ipython3
Python 3.8.3rc1 (default, Apr 30 2020, 07:33:30) 
Type 'copyright', 'credits' or 'license' for more information
IPython 7.14.0 -- An enhanced Interactive Python. Type '?' for help.

In [1]: import xarray as xr 
   
---
AttributeErrorTraceback (most recent call last)
 in 
> 1 import xarray as xr

/usr/lib/python3/dist-packages/xarray/__init__.py in 
  1 import pkg_resources
  2 
> 3 from . import testing, tutorial, ufuncs
  4 from .backends.api import (
  5 load_dataarray,

/usr/lib/python3/dist-packages/xarray/testing.py in 
  5 import pandas as pd
  6 
> 7 from xarray.core import duck_array_ops, formatting
  8 from xarray.core.dataarray import DataArray
  9 from xarray.core.dataset import Dataset

/usr/lib/python3/dist-packages/xarray/core/duck_array_ops.py in 
 12 import pandas as pd
 13 
---> 14 from . import dask_array_compat, dask_array_ops, dtypes, npcompat, 
nputils
 15 from .nputils import nanfirst, nanlast
 16 from .pycompat import dask_array_type

/usr/lib/python3/dist-packages/xarray/core/dask_array_compat.py in 
  5 import numpy as np
  6 
> 7 from .pycompat import dask_array_type
  8 
  9 try:

/usr/lib/python3/dist-packages/xarray/core/pycompat.py in 
 15 import sparse
 16 
---> 17 sparse_array_type = (sparse.SparseArray,)
 18 except ImportError:  # pragma: no cover
 19 sparse_array_type = ()

AttributeError: module 'sparse' has no attribute 'SparseArray'


Cheers,

Mika


-- System Information:
Debian Release: bullseye/sid
  APT prefers testing
  APT policy: (650, 'testing'), (450, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.6.0-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8), 
LANGUAGE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages python3-xarray depends on:
ii  python33.8.2-3
ii  python3-numpy  1:1.17.4-5
ii  python3-pandas 0.25.3+dfsg2-2
ii  python3-pkg-resources  46.1.3-1

Versions of packages python3-xarray recommends:
ii  python3-bottleneck  1.2.1+ds1-2+b2
ii  python3-dask2.11.0+dfsg-1
ii  python3-h5netcdf0.8.0-1
ii  python3-netcdf4 1.5.3-1+b5
ii  python3-zarr2.4.0+ds-1

Versions of packages python3-xarray suggests:
pn  python-xarray-doc   
pn  python3-cartopy 
ii  python3-matplotlib  3.2.1-1+b1
pn  python3-pydap   
pn  python3-rasterio
ii  python3-scipy   1.4.1-2
ii  python3-seaborn 0.10.1-1
ii  python3-toolz   0.9.0-1.1

-- no debconf information



Bug#946249: More information on extension breakage

2019-12-06 Thread Mika Boström
Hiya,

One of the affected extensions was LastPass, and in one of their support
forum threads there is a potentially valuable piece of information.

"""
My Firefox was complied with gcc, I compiled it using Clang and that
fixed the problems for me. Lastpass now works again.
"""

The thread in question here:
https://forums.lastpass.com/viewtopic.php?f=12=356405

and the particular post is this one:
https://forums.lastpass.com/viewtopic.php?f=12=356405=10#p1187835

The Mozilla bug references a GCC bug, but admittedly one with different
manifestation.



Bug#913978: (no subject)

2019-09-07 Thread Mika Hanhijärvi
Hi


Has there been any progress in fixing this bug?Atleast I have not heard
about any progress at all. Looks like Gnome developers do not care about
accessibility at all...



Bug#931585: gnome: Executed applications dock lost

2019-07-17 Thread Mika Hanhijärvi
Hi


Are you talking about the legacy status icon panel? It sounds like you
are talking about it. If so then please note that status icon panel was
removed from Gnome, it is not part of the Gnome anymore. So this it not
a bug. Gnome developers decided to remove the legacy status icon panel
from Gnome.  



Bug#931490: should not be removed from Buster (important for visually impaired users))

2019-07-06 Thread Mika Hanhijärvi
Package: revelation
Version: 0.4.14-3
Severity: grave
Tags: ipv6

Hello

I am sorry that I report this so close to Buster release but I just noticeed
that in the Debian Buster release notes it is said that Revelation is removed
from the Buster. Release notes suggests that passwords can be exported from
Revelation and then imported to keepass2 password manager. Unfortunately that
is not an option if you are blind or other visually impaired user like I am.
Keepass2 password manager is not accessible with the Orca screen reader. So it
is not accessible if you are visually impaired. I am still using Debian
Stretch, but this problem most likeyly applies to Buster too. I have tried
every graphical password manager I can find in Debian Stretch and Revelation
isthe only graphical password managerwhich is accessible with the Orca screen
reader. None of the other graphical password managers are accessible with the
Orca screen reader. So Revelation is really the only accessible graphical
password manager for the visually impaired users.

So now if Revelation password manager is is not in Buster then suddenly
visually impaired users have no way to store their passwords and no way to
access passwords already stored in Revelation.

This is not ok, it is not ok to remove Revelation from Debian when there is no
other accessible password manger and no way to use keepass2 because it is not
accessible with Orca screen reader.

Please include Revelation in Buster.



-- System Information:
Debian Release: 9.9
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-9-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages revelation depends on:
ii  gconf2 3.2.6-4+b1
ii  gnome-extra-icons  1.1-3
ii  gnome-icon-theme   3.12.0-2
ii  python 2.7.13-2
ii  python-cracklib2.9.2-5
ii  python-crypto  2.6.1-7
ii  python-dbus1.2.4-1+b1
ii  python-gnome2  2.28.1+dfsg-1.2
ii  python-gobject 3.22.0-2
ii  python-gtk22.24.0-5.1
ii  shared-mime-info   1.8-1+deb9u1

revelation recommends no packages.

revelation suggests no packages.

-- no debconf information



Bug#913978: (no subject)

2019-06-23 Thread Mika Hanhijärvi
Hi


This bug should still be fixed in Buster. If that is not possible then
it would be good if the old style gnome-control-center in Debian
Stretch's Gnome 3.22 could be ported to Buster. It really should be
available as an alternative as a e.g package
gnome-control-center-legacy. The old style gnome-control-center works
just fine with Orca in Stretch.


I really do not understand what are the Gnome developers thinking. They
really should not make changes like this without testing that the new
users interface is accessible with the Orca screen reader. Theyreally
should not release anything before testing it first.


The least that should be done is to provide the old style
gnome-control-center as an alternative.


If nothing else really can be done then those keystorkes should atleast
be documented. That is a really bad work around but ofcourse better than
nothing.


When fixed gnome-control-center will be available it really should be
backported to Buster.


I know this is not Debian's fault so do not understand me wrong.


I hope that you all will have a fun and warm summer :-)



Bug#923203: (no subject)

2019-06-22 Thread Mika Hanhijärvi
Please note that there are many visually impaired users who must use the
Orca screen reader which speaks the content on screen. If pulseaudio
would not start automatically then for the blind user like me it would
be impossible to use the computer.



Bug#721763: brltty grabs tty from CP2102/CP2109 device disconnecting default

2019-03-31 Thread Mika Hanhijärvi

Hello


This bug seems to still exist in Debian 9.8 "Stretch". I actually do not 
own any hardware using the cp210X kernel module, I am just forwarding 
this information here.



Output from lsusb command:


Bus 006 Device 002: ID 10c4:ea60 Cygnal Integrated Products, Inc. CP210x
UART Bridge / myAVR mySmartUSB light
Bus 006 Device 001: ID 1d6b:0001 Linux Foundation 1.1 root hub

Output from logs:

 Mar 31 07:23:57 debian kernel: [ 6221.612063] usb 6-2: new full-speed
USB device number 2 using uhci_hcd
Mar 31 07:23:57 debian kernel: [ 6221.791082] usb 6-2: New USB device
found, idVendor=10c4, idProduct=ea60
Mar 31 07:23:57 debian kernel: [ 6221.791086] usb 6-2: New USB device
strings: Mfr=1, Product=2, SerialNumber=3
Mar 31 07:23:57 debian kernel: [ 6221.791088] usb 6-2: Product: CP2102
USB to UART Bridge Controller
Mar 31 07:23:57 debian kernel: [ 6221.791090] usb 6-2: Manufacturer:
Silicon Labs
Mar 31 07:23:57 debian kernel: [ 6221.791092] usb 6-2: SerialNumber: 0001
Mar 31 07:23:57 debian mtp-probe: checking bus 6, device 2:
"/sys/devices/pci:00/:00:1d.0/usb6/6-2"
Mar 31 07:23:57 debian mtp-probe: bus: 6, device: 2 was not an MTP device
Mar 31 07:23:57 debian kernel: [ 6221.869563] usbcore: registered new
interface driver usbserial
Mar 31 07:23:57 debian kernel: [ 6221.869586] usbcore: registered new
interface driver usbserial_generic
Mar 31 07:23:57 debian kernel: [ 6221.869607] usbserial: USB Serial
support registered for generic
Mar 31 07:23:57 debian kernel: [ 6221.892149] usbcore: registered new
interface driver cp210x
Mar 31 07:23:57 debian kernel: [ 6221.892173] usbserial: USB Serial
support registered for cp210x
Mar 31 07:23:57 debian kernel: [ 6221.892225] cp210x 6-2:1.0: cp210x
converter detected
Mar 31 07:23:57 debian kernel: [ 6221.898200] usb 6-2: cp210x converter
now attached to ttyUSB0
Mar 31 07:24:01 debian brltty[430]: USB configuration set error 16:
Laite tai resurssi varattu.
Mar 31 07:24:01 debian brltty[430]: brltty: USB configuration set error
16: Laite tai resurssi varattu.
Mar 31 07:24:01 debian kernel: [ 6225.530058] usb 6-2: usbfs: interface
0 claimed by cp210x while 'brltty' sets config #1
Mar 31 07:24:01 debian brltty[430]: brltty: USB interface in use: 0 (cp210x)
Mar 31 07:24:01 debian brltty[430]: USB interface in use: 0 (cp210x)
Mar 31 07:24:01 debian kernel: [ 6225.532412] cp210x ttyUSB0: cp210x
converter now disconnected from ttyUSB0
Mar 31 07:24:01 debian kernel: [ 6225.532431] cp210x 6-2:1.0: device
disconnected
Mar 31 07:24:01 debian brltty[430]: Ignored Byte: 00
Mar 31 07:24:01 debian brltty[430]: brltty: Ignored Byte: 00
AFAIK the version of brltty in use is 5.4-7 which is the current brltty in 
Debian Stretch. Any idea if brltty 5.6 or later fixes this problem?

Thanks in advance.

Regards
Mika



Bug#913978: is not accessible with Orca screenreader

2019-01-18 Thread Mika Hanhijärvi

Hi


Thanks a lot. When this bug is fixed I hope it will be fixed also in 
Gnome 3.30, not just in Gnome 3.32 so that Debian Buster will also have 
the fix. It looks like Debian 10 "Buster" will be released with Gnome 
3.30, I ofcourse may be wrong. I am usin Debian stable releases on 
desktop and laptop so I will upgrade all my computers to Debian Buster 
when it is released sometime in the next summer. And after that the next 
time I will upgrade is when Debian 11 will be released sometime in 2021...



On 1/1/19 1:05 AM, Jeremy Bicha wrote:

Control: forwarded -1
https://gitlab.gnome.org/GNOME/gnome-control-center/issues/327

On Sat, Nov 17, 2018 at 4:03 PM Mika Hanhijärvi  wrote:

This is wery severe unacceptable problem. This bug makes Gnome 3.30 unusable
for the visually impaired users because you can not access or change the
desktop settings.

Thank you for taking the time to report this bug.

I agree that the GNOME Settings app has many accessible problems for
navigating with only a keyboard and screen reader.

I opened a bug now for the most critical issue. When that's fixed, you
should be able to navigate most of the Settings app, although there
are some elements that are not read and the context may be unclear.

Thanks,
Jeremy Bicha




Bug#913978: is not accessible with Orca screenreader

2018-11-17 Thread Mika Hanhijärvi
Package: gnome-control-center
Version: 1:3.30.2-1
Severity: grave
Tags: a11y


Hello

I installed Debian Buster on virtual machine awhile ago. I wanted to try Buster
on virtual machine before upgrading my computers which are currently running
Debian Stretch. I am blind so I have to use screen reader which speaks the
content on screen. As a blind user I also can not use mouse so I use computer
from keyboard only without using mouse.

Gnome 3.30 desktop's new style settings window in Debian Buster is currently
completely unusable with the Orca screen reader. It is completely impossible to
access Gnome desktop settings using Orca screen reader. I can open the settings
window but the content of the window is completely inaccessible.

This is wery severe unacceptable problem. This bug makes Gnome 3.30 unusable
for the visually impaired users because you can not access or change the
desktop settings.

Here is how to reproduce this problem:

1) Make sure Orca screen reader is installed and running
2) Open Gnome desktop settings window
3) Try to navigate settings from keyboard using the arrow, tab etc keys.

Expected result should be that Orca should speak the content on screen and you
should be able to navigate and change settings from keyboard without any need
to use mouse. But it does not work as expected and settings window is not
accessiblwhich makes the settings window
completely unusable.



-- System Information:
Debian Release: buster/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 4.18.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages gnome-control-center depends on:
ii  accountsservice0.6.45-1
ii  apg2.2.3.dfsg.1-5
ii  colord 1.4.3-3+b1
ii  desktop-file-utils 0.23-4
ii  gnome-control-center-data  1:3.30.2-1
ii  gnome-desktop3-data3.30.2-1
ii  gnome-settings-daemon  3.30.1.2-1
ii  gsettings-desktop-schemas  3.28.1-1
ii  libaccountsservice00.6.45-1
ii  libatk1.0-02.30.0-1
ii  libc6  2.27-8
ii  libcairo-gobject2  1.16.0-1
ii  libcairo2  1.16.0-1
ii  libcanberra-gtk3-0 0.30-6
ii  libcanberra0   0.30-6
ii  libcheese-gtk253.30.0-1
ii  libcheese8 3.30.0-1
ii  libclutter-1.0-0   1.26.2+dfsg-7
ii  libclutter-gtk-1.0-0   1.8.4-3
ii  libcolord-gtk1 0.1.26-2
ii  libcolord2 1.4.3-3+b1
ii  libcups2   2.2.8-5
ii  libfontconfig1 2.13.1-2
ii  libgdk-pixbuf2.0-0 2.38.0+dfsg-6
ii  libglib2.0-0   2.58.1-2
ii  libgnome-bluetooth13   3.28.2-2
ii  libgnome-desktop-3-17  3.30.2-1
ii  libgoa-1.0-0b  3.30.0-1
ii  libgoa-backend-1.0-1   3.30.0-1
ii  libgrilo-0.3-0 0.3.6-1
ii  libgtk-3-0 3.24.1-2
ii  libgtop-2.0-11 2.38.0-2
ii  libgudev-1.0-0 232-2
ii  libibus-1.0-5  1.5.19-1
ii  libkrb5-3  1.16.1-1
ii  libmm-glib01.8.2-1
ii  libnm0 1.14.4-3
ii  libnma01.8.18-2
ii  libpango-1.0-0 1.42.4-3
ii  libpangocairo-1.0-01.42.4-3
ii  libpolkit-gobject-1-0  0.105-21
ii  libpulse-mainloop-glib012.2-2
ii  libpulse0  12.2-2
ii  libpwquality1  1.4.0-2
ii  libsecret-1-0  0.18.6-3
ii  libsmbclient   2:4.9.1+dfsg-2
ii  libsoup2.4-1   2.64.1-3
ii  libupower-glib30.99.9-1
ii  libwacom2  0.31-1
ii  libwayland-server0 1.16.0-1
ii  libx11-6   2:1.6.7-1
ii  libxi6 2:1.7.9-1
ii  libxml22.9.4+dfsg1-7+b2

Versions of packages gnome-control-center recommends:
ii  cracklib-runtime  2.9.2-5.2+b1
ii  cups-pk-helper0.2.6-1+b1
ii  gkbd-capplet  3.26.0-3
ii  gnome-online-accounts 3.30.0-1
ii  gnome-user-docs   3.30.1-1
ii  gnome-user-share  3.28.0-1
ii  iso-codes 4.1-1
ii  libcanberra-pulse 0.30-6
ii  libnss-myhostname 239-11
ii  mousetweaks   3.12.0-4
ii  network-manager-gnome 1.8.18-2
ii  policykit-1   0.105-21
ii  pulseaudio-module-bluetooth   12.2-2
ii  realmd0.16.3-2
ii  rygel 0.36.2-1
ii  rygel-tracker 0.36.2-1
ii  system-config-printer-common  1.5.11-3

Versions of packages gnome-control-center suggests:
ii  gnome-software   3.30.1-1
ii  gstreamer1.0-pulseaudio  1.14.4-1
pn  libcanberra-gtk-module   
ii  libcanberra-gtk3-module 

Bug#891818: libxmltooling7: 1.6.0-4+deb9u1 security update amd64 build missing

2018-02-28 Thread Mika Tiainen
Package: libxmltooling7
Version: 1.6.0-4+deb9u1
Severity: important
Tags: security

Hi,

There are no amd64 packages for 1.6.0-4+deb9u1 at
http://security.debian.org/pool/updates/main/x/xmltooling/ only arch all
xmltooling-schemas_1.6.0-4+deb9u1_all.deb

-- System Information:
Debian Release: 9.3
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-6-amd64 (SMP w/4 CPU cores)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_GB:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libxmltooling7 depends on:
ii  libc6  2.24-11+deb9u1
ii  libcurl3   7.52.1-5+deb9u4
ii  libgcc11:6.3.0-18+deb9u1
ii  liblog4shib1v5 1.0.9-3
ii  libssl1.0.21.0.2l-2+deb9u2
ii  libstdc++6 6.3.0-18+deb9u1
ii  libxerces-c3.1 3.1.4+debian-2
ii  libxml-security-c17v5  1.7.3-4

libxmltooling7 recommends no packages.

libxmltooling7 suggests no packages.

-- no debconf information



Bug#864670: closed by Samuel Thibault <sthiba...@debian.org> (Bug#864670: fixed in brltty 5.5-2)

2017-10-13 Thread Mika Hanhijärvi
Thank you wery much :-) It would be great if tis new version would be
available for the Stretch too in the backports repository.



Bug#864670: closed by Samuel Thibault <sthiba...@debian.org> (Bug#864670: fixed in brltty 5.5-2)

2017-10-12 Thread Mika Hanhijärvi
Thank you wery much :-) It would be great if tis new version would be
available for the Stretch too in the backports repository.



Bug#864987: firefox-esr: does not work with ALSA but blind many users use ALSA

2017-06-18 Thread Mika Hanhijärvi
Package: firefox-esr
Version: 52.2.0esr-1~deb9u1
Severity: important

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
 ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***
It seems that the Firefox 452 does not work with ALSA anymore. The problem i
with that is that lots of blind and other visually impaired users use ALSA
instead of Pulseaudio. Currently if you want to use both Orca screen reader on
desktop and espeakup on console then it is best to use ALSA instead of
Pulseaudio because Pulseaudio causes problems if you want to use both Orca and
espeakup. Firefox is currrently the only modern web browser on Linux which
works with Orca. Now that Mozilla has dropped support for the ALSA there is not
a single browser which is really usable if you are blind and especially if you
use ALSA instead of Pulseaudio.

I know this is not Debians fault, this is fully Mozillas fault.

I hope that Debian would make the Firefox-estr 45 available easily atleast for
now. Firefox esr 45.9  Worked just fine. I am blind myself and I was thinking
of switching from pulseaudio to alsa because I would like to use both Orca and
espeakup. But now when there is firefox esr 52 in Debian Stretch I am not sure
what should I do. I will probably downgrade Firefox esr to 45.9 using the
Debian snapshots repository. I know how to use snapshots but there is lots of
blind users who do not even know snapshots repository exists.

I know that using old browser may causesevere security risks, but obviously
there is not much option...

Firefo esr also 52.20 currently in Debian Stretch also does not really work as
well with Orca screen reader as Firefox ESR 45.9 did. That is another reason
why I am going to downgrade the browser. I will make another bug report about
that.

This bug report really should be forwarded to Mox
zilla too so that they know what they are doing to blind users...



-- Package-specific info:

-- Extensions information
Name: Adblock Plus
Location: /usr/share/xul-ext/adblock-plus
Package: xul-ext-adblock-plus
Status: enabled

Name: Application Update Service Helper
Location: ${PROFILE_EXTENSIONS}/aushel...@mozilla.org.xpi
Status: enabled

Name: Default theme
Location: 
/usr/lib/firefox-esr/browser/extensions/{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Package: firefox-esr
Status: enabled

Name: Multi-process staged rollout
Location: ${PROFILE_EXTENSIONS}/e10sroll...@mozilla.org.xpi
Status: enabled

Name: Pocket
Location: ${PROFILE_EXTENSIONS}/fire...@getpocket.com.xpi
Status: enabled

Name: Web Compat
Location: ${PROFILE_EXTENSIONS}/webcom...@mozilla.org.xpi
Status: enabled

-- Plugins information
Name: GNOME Shell Integration
Location: /usr/lib/mozilla/plugins/libgnome-shell-browser-plugin.so
Package: gnome-shell
Status: enabled

Name: IcedTea-Web Plugin (using IcedTea-Web 1.6.2 (1.6.2-3.1))
Location: /usr/lib/jvm/java-8-openjdk-amd64/jre/lib/amd64/IcedTeaPlugin.so
Package: icedtea-8-plugin:amd64
Status: enabled

Name: iTunes Application Detector
Location: /usr/lib/mozilla/plugins/librhythmbox-itms-detection-plugin.so
Package: rhythmbox-plugins
Status: enabled


-- Addons package information
ii  firefox-esr52.2.0esr-1~ amd64Mozilla Firefox web browser - Ext
ii  gnome-shell3.22.3-3 amd64graphical shell for the GNOME des
ii  icedtea-8-plug 1.6.2-3.1amd64web browser plugin based on OpenJ
ii  rhythmbox-plug 3.4.1-2+b1   amd64plugins for rhythmbox music playe
ii  xul-ext-adbloc 2.7.3+dfsg-1 all  advertisement blocking extension 

-- System Information:
Debian Release: 9.0
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8), 
LANGUAGE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages firefox-esr depends on:
ii  debianutils   4.8.1.1
ii  fontconfig2.11.0-6.7+b1
ii  libasound21.1.3-5
ii  libatk1.0-0   2.22.0-1
ii  libc6 2.24-11
ii  libcairo-gobject2 1.14.8-1
ii  libcairo2 1.14.8-1
ii  libdbus-1-3   1.10.18-1
ii  libdbus-glib-1-2  0.108-2
ii  libevent-2.0-52.0.21-stable-3
ii  libffi6   3.2.1-6
ii  libfontconfig12.11.0-6.7+b1
ii  libfreetype6  2.6.3-3.2
ii  libgcc1   1:6.3.0-18
ii  libgdk-pixbuf2.0-02.36.5-2
ii  libglib2.0-0  2.50.3-2
ii  libgtk-3-03.22.11-1
ii  libgtk2.0-0   2.24.31-2
ii  libhunspell-1.4-0 1.4.1-2+b2
ii  libjsoncpp1   1.7.4-3
ii  libpango-1.0-0 

Bug#864837: screenreader stops speaking

2017-06-15 Thread Mika Hanhijärvi
Package: gnome-orca
Version: 3.22.2-3
Severity: grave

Hi

I am sorry that I repport this so close to release of Stretch.

I am not really sure to which package I should report this bug. I am not sure
if this bug is in Orca, Pulseaudio, speech-dispatcher or someething else. I
think it might be problem with Pulseaudio, or maybe not. Really do not know.

Note that I tryed to send this bug report earlier but my laptop did run out of
battery when reportbug was sending the bug report so bug report probably was
not sent. I first tryed to send itthe bug report to pulseaudio, but I am now
thinking that maybe I should reportit o Orca so that Debian accessibility guys
get notified about this. I am really sorry if thiscauses mess and a duplicate
bug report to two packages.

I am blind so I have to use computer using the screen reader. So it is
important for me that screen reader works relealibly.

I have espeakup and Orca installed. I would like to use espeakup on console and
Orca on desktop. I also would like to be able to switch between text mode
console and graphical nome desktop without logging out from the desktop.
Currently that does not work. I have two laptops and both have this problem.
Note that I have not made clean Stretch installation, Ihave upgraded my systems
to Stretch.


For some reason if espeakup sppeaks something when the computer is booting then
screen reader does not speak anytging on GDM login screen. If that happens then
screen reader also does not speak at all on desktop. This makes it impossible
for me to login to desktop or use the deshtop. I have noticed that if I go to
text console then eseakup speaks just fin.

If espeakup does not speak anytging then screen reader speaks on GDM login
screen. If I go to text console then espeakup does not speak at all. If I login
to desktop then Orca screen reader speaks just fine. If I login to desktop then
this also happens: If I switch from desktop to GDM login screen thusing the
ctrl + alt + f1 then screen reader does not speak on GDM login screen at all.
If I then return to desktop then Orca screen reader on desktop speaks again
just fine. If I switch form desktop to text console using e.g ctrl + alt + f3
then espeakup does not speak at all on console. If I then switch back to
desktothen Orca speaks again on desktop just fine.


If I logout from desktop to gdm login screen then screen reader speaks on gdm
login screen.

So it seems that the sc reader works just on one of the following views:
console, gdm or desktop. It is not possible to switch between those. That is
not good.



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-orca depends on:
ii  gir1.2-glib-2.01.50.0-1+b1
ii  gir1.2-gtk-3.0 3.22.11-1
ii  gir1.2-pango-1.0   1.40.5-1
ii  gir1.2-wnck-3.03.20.1-3
ii  gsettings-desktop-schemas  3.22.0-1
ii  python33.5.3-1
ii  python3-brlapi 5.4-7
ii  python3-cairo  1.10.0+dfsg-5+b1
ii  python3-gi 3.22.0-2
ii  python3-louis  3.0.0-3
ii  python3-pyatspi2.20.3+dfsg-1
ii  python3-speechd0.8.6-4
ii  speech-dispatcher  0.8.6-4

Versions of packages gnome-orca recommends:
ii  libgail-common  2.24.31-2
ii  xbrlapi 5.4-7

gnome-orca suggests no packages.

-- no debconf information



Bug#864829: screen reader stops speaking

2017-06-15 Thread Mika Hanhijärvi
Package: pulseaudio
Version: 10.0-1
Severity: grave

Hi

I am sorry that I repport this so close to release of Stretch.

I am not really sure to which package I should report this bug. I am not 100%
sure if this g is in Pulseaudio, speech-eispatcher or someething else. I think
it might be a problem with Pulseaudio.

I am blind so I have to use computer using the screen reader. So it is
important for me that screen reader works relealibly.

I am using the Gnome desktop.
I have espeakup and Orca installed. I would like to use espeakup on console and
Orca on desktop. I also would like to be able to switch between text mode
console and graphical nome desktop without logging out from the desktop.
Currently that does not work. I have two laptops and both have this problem.
Note that I have not made clean Stretch installation, Ihave upgraded my systems
to Stretch.


For some reason if espeakup sppeaks something when the computer is booting then
screen reader does not speak anytging on GDM login screen. If that happens then
screen reader also does not speak at all on desktop. This makes it impossible
for me to login to desktop or use the deshtop. I have noticed that if I go to
text console then eseakup speaks just fin.

If espeakup does not speak anytging then screen reader speaks on GDM login
screen. If I go to text console then espeakup does not speak at all. If I login
to desktop then Orca screen reader speaks just fine. If I login to desktop then
this also happens: If I switch from desktop to GDM login screen thusing the
ctrl + alt + f1 then screen reader does not speak on GDM login screen at all.
If I then return to desktop then Orca screen reader on desktop speaks again
just fine. If I switch form desktop to text console using e.g ctrl + alt + f3
then espeakup does not speak at all on console. If I then switch back to
desktothen Orca speaks again on desktop just fine.


If I logout from desktop to gdm login screen then screen reader speaks on gdm
login screen.

So it seems that the sc reader works just on one of the following views:
console, gdm or desktop. It is not possible to switch between those. That is
not good.

I dreally hope this will be fixed vecause this bug makes it impossible to
switch between desktop, gdm and console if you can not see and have to rely on
screen reader.



-- Package-specific info:
File '/etc/default/pulseaudio' does not exist


-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages pulseaudio depends on:
ii  adduser  3.115
ii  libasound2   1.1.3-5
ii  libasound2-plugins   1.1.1-1
ii  libc62.24-11
ii  libcap2  1:2.25-1
ii  libdbus-1-3  1.10.18-1
ii  libgcc1  1:6.3.0-18
ii  libice6  2:1.0.9-2
ii  libltdl7 2.4.6-2
ii  liborc-0.4-0 1:0.4.26-2
ii  libpulse010.0-1
ii  libsm6   2:1.2.2-1+b3
ii  libsndfile1  1.0.27-3
ii  libsoxr0 0.1.2-2
ii  libspeexdsp1 1.2~rc1.2-1+b2
ii  libstdc++6   6.3.0-18
ii  libsystemd0  232-25
ii  libtdb1  1.3.11-2
ii  libudev1 232-25
ii  libwebrtc-audio-processing1  0.3-1
ii  libx11-6 2:1.6.4-3
ii  libx11-xcb1  2:1.6.4-3
ii  libxcb1  1.12-1
ii  libxtst6 2:1.2.3-1
ii  lsb-base 9.20161125
ii  pulseaudio-utils 10.0-1

Versions of packages pulseaudio recommends:
ii  rtkit  0.11-4+b1

Versions of packages pulseaudio suggests:
ii  paman0.9.4-1+b3
ii  paprefs  0.9.10-2+b1
ii  pavucontrol  3.0-3.1
ii  pavumeter0.9.3-4+b3
ii  udev 232-25

-- no debconf information
# This file is part of PulseAudio.
#
# PulseAudio is free software; you can redistribute it and/or modify
# it under the terms of the GNU Lesser General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# PulseAudio is distributed in the hope that it will be useful, but
# WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
# General Public License for more details.
#
# You should have received a copy of the GNU Lesser General Public License
# along with PulseAudio; if not, see .

## Configuration file for PulseAudio clients. See pulse-client.conf(5) for
## more information. Default values are commented out.  Use 

Bug#864670: has broken Finnish braille table

2017-06-12 Thread Mika Hanhijärvi
Package: brltty
Version: 5.4-7
Severity: grave

I did get a new braille display awhile ago. I have been testing it and I have
noticed that braille table for the Finnish  language is broken. Reading text
works but It is impossible to write text in Finnish using the integrated
braille keyboard in the braille display. Writing text in Finnish language is
not possible because writing scandinavian letters (which are wery commonly used
in Finnish language) does not work. The following scandinavian letters are used
in Finnish language. Small letters: ä, ö, å. Capital letters: Ä, Ö, Å.

It seems that the braille table for the Finnish language has many lines which
define some weird control characters. Those lines conflict with lines defining
scandinavian letters . If I remove those conflicting control character lines
then both reading and writing text in Finnish works correctly.

I am a blind user from Finland so it is wery important for me that writing text
in Finnish works. My native language is Finnish so I am really using braille in
Finnish.

The braille table for the Finnish language is in the file:
/etc/brltty/Text/fi.ttb

First of all these lines define scandinavian letters used in the Finnish
language. These lines are correct and SHOULD NOT be changed:

char \xC4   (  345 7 )  # C4 ⡜ Ä [LATIN CAPITAL LETTER A WITH DIAERESIS]
char \xC5   (167 )  # C5 ⡡ Å [LATIN CAPITAL LETTER A WITH RING ABOVE]
char \xD6   ( 2 4 67 )  # D6 ⡪ Ö [LATIN CAPITAL LETTER O WITH DIAERESIS]
char \xE4   (  345   )  # E4 ⠜ ä [LATIN SMALL LETTER A WITH DIAERESIS]
char \xE5   (16  )  # E5 ⠡ å [LATIN SMALL LETTER A WITH RING ABOVE]
char \xF6   ( 2 4 6  )  # F6 ⠪ ö [LATIN SMALL LETTER O WITH DIAERESIS]


The problem described in this bug report is caused by the following lines.

This line is defined incorrectly and conflicts with the small letter "ä" ("ä"
in Finnish braille is dots: 3, 4, 5) :

char \x84   (  345   )  # 84 ⠜   []


- This line conflicts with the small letter "Å" ("å" in Finnish braille is
dots: 1, 6) :

char \x86   (16  )  # 86 ⠡   [START OF SELECTED AREA]


- This line conflicts with the capital letter "Ä" ("Ä" in Finnish braille is
dots: 3, 4, 5, 7) :

char \x8E   (  345 7 )  # 8E ⡜   [SINGLE SHIFT TWO]


- This line conflicts with the capital letter "Å" ("Å" in Finnish braille is
dots: 1,6,7) :

char \x8F   (167 )  # 8F ⡡   [SINGLE SHIFT THREE]


- This line conflicts with the small letter "ö" ("ö" in Finnish braille is
dots: 2, 4, 6) :

char \x94   ( 2 4 6  )  # 94 ⠪   [CANCEL CHARACTER]


- This line conflicts with the capital letter "Ö" ("Ö" in Finnish braille is
dots: 2, 4, 6, 7) :

char \x99   ( 2 4 67 )  # 99 ⡪   []


I really do not know for what and how those control characters are used, all I
know is that if those control character lines are not commented out then
writing text in the Finnish language is not possible. Those control character
lines should be commented out, removed or changed so that those do not conflict
with any other line.

I have compared the Finnish braille table with Swedish braille table because
Swedish is the second official language in finland. It seems that the Swedish
braille table does not define those control characters.

The braille table for the Swedish language is in the file:
/etc/brltty/Text/sv-1996.ttb

How to reproduce this bug:

1) select the Finnish language in the file:
/etc/brltty.conf

Uncomment this line:

text-table  fi  # Finnish

2) Restart brltty
3) connect Braille display which has integrated Braille keyboard
4) start e.g text editor
5) Try to write these scandinavian letters using the integrated Braille
keyboard in the Braille display:

- small letter ä )braille dots: 3, 4, 5)
- small letter ö (braille dots: 2, 4, 6)
- small letter å (braille dots: 1, 6)
- capital letter Ä (braille dots: 3, 4, 5, 7)
- capital letter Ö (braille dots: 2, 4, 6, 7)
- capital letter Å (braille dots: 1, 6, 7)



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages brltty depends on:
ii  init-system-helpers1.48
ii  libasound2 1.1.3-5
ii  libbluetooth3  5.43-2
ii  libbrlapi0.6   5.4-7
ii  libc6  2.24-11
ii  libglib2.0-0   2.50.3-2
ii  libgpm21.20.4-6.2+b1
ii  libicu57   57.1-6
ii  libncursesw5   6.0+20161126-1
ii  libpolkit-gobject-1-0  0.105-18
ii  libsystemd0232-25
ii  libtinfo5  6.0+20161126-1
ii  lsb-base   9.20161125
ii  policykit-10.105-18

Versions of packages brltty recommends:
ii  python  2.7.13-2

Versions of packages brltty 

Bug#859262: closed by Paul Gevers <elb...@debian.org> (Bug#859262: fixed in gnome-orca 3.22.2-3)

2017-05-23 Thread Mika Hanhijärvi
Unfortunately this did not fix the problem. The problem still exists. I 
still have noticed this only when using Synaptic.



One interesting thing is that if it happens when I do this:



/) Go to eg virtual desktop 2 on Gnome/

2) start Synaptic on that virtual desktop

3) click Reload button

4) Go to e.g virtual desktop 1 and do something else like browse the web 
using firefox or something else



5) Let Synaptic to finish reloading the repository information,

6) Go back to virtual desktop 2 where Synaptic is running and where it's 
window is open



Orca stops speaking when you do the step 6. That happened again some 
minutes ago and that has happened many times. Synaptic was running and 
reloading on one virtual desktop and I was browsing facebook on another 
virtual desktop. Everything worked just fine until I did goback to that 
virtual desktop where Synaptic was running. When I did that Orca 
immediately stopped to speak. When I closed the Synaptic using alt + f4 
then Orca started to speak again.



And by the way I do not remember if this problem existed in Debian 
Jessie. Both of my laptops are quite new. I first installed Debian 
Jessien on those laptops, but I upgraded to Stretch soon after that. My 
desktop computer is still running Debian 7.0 "Wheezy". I did not really 
use Debian 8.0 "Jessie" much on those laptops so you can say that I 
jumped from Wheezy to Stretch. This problem does not exist in Wheezy and 
I really can not say if it existed in Jessie, but it does still exist in 
Stretch. I do not know if this problem exists in new Stretch 
installations. I am going to make a clean Stretch install when I buy the 
new SSD disk, but I can not do that right now.











On 05/03/2017 09:51 PM, Debian Bug Tracking System wrote:

This is an automatic notification regarding your Bug report
which was filed against the gnome-orca package:

#859262: gnome-orca: Gets stuck if target app is busy

It has been closed by Paul Gevers .

Their explanation is attached below along with your original report.
If this explanation is unsatisfactory and you have not received a
better one in a separate message then please contact Paul Gevers 
 by
replying to this email.






Bug#862008: crashes, segmentation fault

2017-05-07 Thread Mika Hanhijärvi

Ok, thanks for the info :-)


_ Mika




On 05/07/2017 05:49 PM, Joanmarie Diggs wrote:

I am looking at the line of code which caused the crash and it is the
same line of code as in the bug I reported. So you might have been doing
something different, but it appears to be the same bug which needs to be
fixed in AT-SPI2.

--joanie

On 05/07/2017 09:14 AM, Mika Hanhijärvi wrote:


If it is the same bug then I have to say I did not close any application
when Orca crashed. I also did not do anythything particularly fast. I am
not 100% sure what I Was doing but If I remember correctly I just
switched between virtual Gnome desktops which did have some application
windows open.




On 05/07/2017 03:45 PM, Joanmarie Diggs wrote:

That is this AT-SPI2 bug:
https://bugzilla.gnome.org/show_bug.cgi?id=767074

--joanie

On 05/07/2017 08:00 AM, Mika Hanhijärvi wrote:

Package: gnome-orca
Version: 3.22.2-3
Severity: grave

Orca seems to sometime crash suddenly without any warning. This is
not good
because blind users like me have to rely on screen reader working
reliably.
This, or similar, problem also existed before the latest update to
Orca in
Debian Stretch, so I do not know if this has anything to do with the
latest
Orca update.

There are these lines in the /var/log/syslog

May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Fatal
Python error:
Segmentation fault
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Stack
(most recent
call first):
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/Accessibility.py", line 184
in 
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 256 in
_queuePrintln
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 329 in
_dequeue
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/registry.py", line 155 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 561 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 712 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 269 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 272 in 




-- System Information:
Debian Release: 9.0
APT prefers testing
APT policy: (500, 'testing')
Architecture: amd64
   (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-orca depends on:
ii  gir1.2-glib-2.01.50.0-1+b1
ii  gir1.2-gtk-3.0 3.22.11-1
ii  gir1.2-pango-1.0   1.40.5-1
ii  gir1.2-wnck-3.03.20.1-3
ii  gsettings-desktop-schemas  3.22.0-1
ii  python3-brlapi 5.4-7
ii  python3-cairo  1.10.0+dfsg-5+b1
ii  python3-gi 3.22.0-2
ii  python3-louis  3.0.0-3
ii  python3-pyatspi2.20.3+dfsg-1
ii  python3-speechd0.8.6-4
pn  python3:any
ii  speech-dispatcher  0.8.6-4

Versions of packages gnome-orca recommends:
ii  libgail-common  2.24.31-2
ii  xbrlapi 5.4-7

gnome-orca suggests no packages.

-- no debconf information








Bug#862008: crashes, segmentation fault

2017-05-07 Thread Mika Hanhijärvi
When I read the discussion in Gnome bug page I see that some people have 
regular Orca crashes which happen often e.g when they close some 
application. Luckily I have not noticed problem like that. Orca crashes 
do not happen often or regularly on my computer, just sometimes. I also 
have not had Orca crashes when I have closed applications. I think those 
crashes have happened mostly when I have switched between apps running 
on different Gnome virtual desktops. I run just one application on each 
virtual desktop.






On 05/07/2017 03:45 PM, Joanmarie Diggs wrote:

That is this AT-SPI2 bug: https://bugzilla.gnome.org/show_bug.cgi?id=767074

--joanie

On 05/07/2017 08:00 AM, Mika Hanhijärvi wrote:

Package: gnome-orca
Version: 3.22.2-3
Severity: grave

Orca seems to sometime crash suddenly without any warning. This is not good
because blind users like me have to rely on screen reader working reliably.
This, or similar, problem also existed before the latest update to Orca in
Debian Stretch, so I do not know if this has anything to do with the latest
Orca update.

There are these lines in the /var/log/syslog

May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Fatal Python error:
Segmentation fault
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Stack (most recent
call first):
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/Accessibility.py", line 184 in 
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 256 in
_queuePrintln
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 329 in _dequeue
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/registry.py", line 155 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 561 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 712 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 269 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 272 in 




-- System Information:
Debian Release: 9.0
   APT prefers testing
   APT policy: (500, 'testing')
Architecture: amd64
  (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-orca depends on:
ii  gir1.2-glib-2.01.50.0-1+b1
ii  gir1.2-gtk-3.0 3.22.11-1
ii  gir1.2-pango-1.0   1.40.5-1
ii  gir1.2-wnck-3.03.20.1-3
ii  gsettings-desktop-schemas  3.22.0-1
ii  python3-brlapi 5.4-7
ii  python3-cairo  1.10.0+dfsg-5+b1
ii  python3-gi 3.22.0-2
ii  python3-louis  3.0.0-3
ii  python3-pyatspi2.20.3+dfsg-1
ii  python3-speechd0.8.6-4
pn  python3:any
ii  speech-dispatcher  0.8.6-4

Versions of packages gnome-orca recommends:
ii  libgail-common  2.24.31-2
ii  xbrlapi 5.4-7

gnome-orca suggests no packages.

-- no debconf information






Bug#862008: crashes, segmentation fault

2017-05-07 Thread Mika Hanhijärvi



If it is the same bug then I have to say I did not close any application 
when Orca crashed. I also did not do anythything particularly fast. I am 
not 100% sure what I Was doing but If I remember correctly I just 
switched between virtual Gnome desktops which did have some application 
windows open.





On 05/07/2017 03:45 PM, Joanmarie Diggs wrote:

That is this AT-SPI2 bug: https://bugzilla.gnome.org/show_bug.cgi?id=767074

--joanie

On 05/07/2017 08:00 AM, Mika Hanhijärvi wrote:

Package: gnome-orca
Version: 3.22.2-3
Severity: grave

Orca seems to sometime crash suddenly without any warning. This is not good
because blind users like me have to rely on screen reader working reliably.
This, or similar, problem also existed before the latest update to Orca in
Debian Stretch, so I do not know if this has anything to do with the latest
Orca update.

There are these lines in the /var/log/syslog

May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Fatal Python error:
Segmentation fault
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Stack (most recent
call first):
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/Accessibility.py", line 184 in 
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 256 in
_queuePrintln
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 329 in _dequeue
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/registry.py", line 155 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 561 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 712 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 269 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 272 in 




-- System Information:
Debian Release: 9.0
   APT prefers testing
   APT policy: (500, 'testing')
Architecture: amd64
  (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-orca depends on:
ii  gir1.2-glib-2.01.50.0-1+b1
ii  gir1.2-gtk-3.0 3.22.11-1
ii  gir1.2-pango-1.0   1.40.5-1
ii  gir1.2-wnck-3.03.20.1-3
ii  gsettings-desktop-schemas  3.22.0-1
ii  python3-brlapi 5.4-7
ii  python3-cairo  1.10.0+dfsg-5+b1
ii  python3-gi 3.22.0-2
ii  python3-louis  3.0.0-3
ii  python3-pyatspi2.20.3+dfsg-1
ii  python3-speechd0.8.6-4
pn  python3:any
ii  speech-dispatcher  0.8.6-4

Versions of packages gnome-orca recommends:
ii  libgail-common  2.24.31-2
ii  xbrlapi 5.4-7

gnome-orca suggests no packages.

-- no debconf information






Bug#862008: crashes, segmentation fault

2017-05-07 Thread Mika Hanhijärvi
Package: gnome-orca
Version: 3.22.2-3
Severity: grave

Orca seems to sometime crash suddenly without any warning. This is not good
because blind users like me have to rely on screen reader working reliably.
This, or similar, problem also existed before the latest update to Orca in
Debian Stretch, so I do not know if this has anything to do with the latest
Orca update.

There are these lines in the /var/log/syslog

May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Fatal Python error:
Segmentation fault
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]: Stack (most recent
call first):
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/Accessibility.py", line 184 in 
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 256 in
_queuePrintln
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/event_manager.py", line 329 in _dequeue
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/pyatspi/registry.py", line 155 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 561 in start
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/lib/python3/dist-packages/orca/orca.py", line 712 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 269 in main
May  7 11:21:12 miksuhlaptop2 orca-autostart.desktop[3579]:   File
"/usr/bin/orca", line 272 in 




-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64
 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnome-orca depends on:
ii  gir1.2-glib-2.01.50.0-1+b1
ii  gir1.2-gtk-3.0 3.22.11-1
ii  gir1.2-pango-1.0   1.40.5-1
ii  gir1.2-wnck-3.03.20.1-3
ii  gsettings-desktop-schemas  3.22.0-1
ii  python3-brlapi 5.4-7
ii  python3-cairo  1.10.0+dfsg-5+b1
ii  python3-gi 3.22.0-2
ii  python3-louis  3.0.0-3
ii  python3-pyatspi2.20.3+dfsg-1
ii  python3-speechd0.8.6-4
pn  python3:any
ii  speech-dispatcher  0.8.6-4

Versions of packages gnome-orca recommends:
ii  libgail-common  2.24.31-2
ii  xbrlapi 5.4-7

gnome-orca suggests no packages.

-- no debconf information



Bug#859262: Re: freezes Orca screen reader

2017-04-29 Thread Mika Hanhijärvi

Hello




On 04/29/2017 09:42 PM, Paul Gevers wrote:

Hi Mika, Tim,

On 29-04-17 17:51, Joanmarie Diggs wrote:

And to prepare for fixes of the package in Debian (which is 3.22.2 and
will be extremely hard convince the release managers to update in this
stage due to the freeze), which fixes would we need to backport to fix
the issues identified so far?

commit ea02cc2d268348c22ffe8c23099f6b023d4c90a7
commit 382c5408afc7dd25f9b477a5e30c50ba917155c0
commit d51f87a7f000d099da98247dc7ca337b2b5483be
commit edbfafbd89409bfb1e4a4e3a9339c0b2de7435d6

I prepared and build¹ a Debian gnome-orca package with the above
mentioned upstream commits that should prevent Orca from freezing (or
appearing to do so). It would be great if you could install the deb²
(checksum below³) and report if it resolves your issues with Synaptic
(as my Orca installation isn't set-upped properly, I don't hear anything).

Paul

¹
http://debomatic-amd64.debian.net/distribution#testing/gnome-orca/3.22.2-3~debo1
²
http://debomatic-amd64.debian.net/debomatic/testing/pool/gnome-orca_3.22.2-3~debo1/gnome-orca_3.22.2-3~debo1_all.deb
³
paul@testavoira ~ $ sha256sum gnome-orca_3.22.2-3~debo1_all.deb
6d9c8bca6b211ac1570792dd66fde8a46cdf59a038b87a0d9bf16a43822e1887
gnome-orca_3.22.2-3~debo1_all.deb





Ok. I will try it now, thanks.



Bug#861387: fails to open applet menu

2017-04-29 Thread Mika Hanhijärvi




Hello
On 04/29/2017 06:35 PM, Scott Leggett wrote:

tags 861387 + moreinfo unreproducible
severity 861387 important
--

Hello Mika,

On 2017-04-28.13:17, Mika Hanhijärvi wrote:

Package: pasystray
Version: 0.6.0-1
Severity: grave

Hello

pasystray applet is visible in the Gnome's legacy icon tray but when I click
the  icon then applet menu does not open. This makes pasystray unusable,
atleast on Gnome, I do not know if the problem happens on other desktops too.


Thanks for the bug report.

I have tried to reproduce your issue by downloading the latest live-cd
of Strech with Gnome, and installing pasystray. As you can see in the
attached screenshot, the menu does work for me (both right-click and
left-click).

Could you provide any more information about your Gnome configuration
that is different from the default?

You could also try running `pasystray -d` in a terminal to print debug
information that may help figure out what's going on.

In the meantime, I have downgraded the severity of the bug as I cannot
reproduce it on a default Gnome desktop.





I can not see the screenshot because I am blind. If the pasystray menu 
opens then atleast it does not work with Orca screen reader. Note that I 
use the computer using keyboard whithout using mouse. Blind users like 
me can not use mouse. So  when I say that  i click the pasystray icon, I 
mean that I select the icon using left and right arrow keys from 
keyboard and then I click the icon using enter or space from keyboard.


When I click the pasystray icon Orca screen reader says something like 
"shshshsh" or something like that, but  the pasystray menu can not be 
accessed from keyboard. The menu may be accessible using mouse, but as I 
said I am blind and I can not use mouse.


I am using the Gnome desktop installed by Debian. This problem happens 
on both of my laptops running Debian Stretch. Both laptops have been 
upgraded from Jessie to Stretch  The only package that I have installed 
from outside of debian is Skype.


I have still the padevchooser installed, because pasystray does not 
work. I do not know if that could  cause problems. I would like to 
uninstall padevchooser because it is not in Debian anymore, but if If I 
uninstall it and pasystray does anot work then I have no Pulseaudio 
applet at all...


Here is how to reproduce this bug:

1) install Orca screen reader
2) activate Orca
3) go to Gnome desktop legacy icon tray by pressing  ctrl-alt-tab from 
keyboard
4) select the pasystray applet by using left and right arrow keys from 
keyboard

5( click the  pasystray by pressing enter or space from keyboard



Bug#861387: fails to open applet menu

2017-04-28 Thread Mika Hanhijärvi
Package: pasystray
Version: 0.6.0-1
Severity: grave

Hello

pasystray applet is visible in the Gnome's legacy icon tray but when I click
the  icon then applet menu does not open. This makes pasystray unusable,
atleast on Gnome, I do not know if the problem happens on other desktops too.



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64
 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages pasystray depends on:
ii  gnome-icon-theme 3.12.0-2
ii  libatk1.0-0  2.22.0-1
ii  libavahi-client3 0.6.32-2
ii  libavahi-common3 0.6.32-2
ii  libavahi-glib1   0.6.32-2
ii  libc62.24-10
ii  libcairo-gobject21.14.8-1
ii  libcairo21.14.8-1
ii  libgdk-pixbuf2.0-0   2.36.5-2
ii  libglib2.0-0 2.50.3-2
ii  libgtk-3-0   3.22.11-1
ii  libnotify4   0.7.7-2
ii  libpango-1.0-0   1.40.4-1
ii  libpangocairo-1.0-0  1.40.4-1
ii  libpulse-mainloop-glib0  10.0-1
ii  libpulse010.0-1
ii  libx11-6 2:1.6.4-3

pasystray recommends no packages.

Versions of packages pasystray suggests:
ii  paman   0.9.4-1+b3
ii  paprefs 0.9.10-2+b1
ii  pavucontrol 3.0-3+b3
ii  pavumeter   0.9.3-4+b3
ii  pulseaudio-module-zeroconf  10.0-1

-- no debconf information



Bug#859926: speechd-up: fails to install

2017-04-09 Thread Mika Hanhijärvi

Hello


On 04/09/2017 10:10 PM, Samuel Thibault wrote:

Control: retitle -1 speechd-up: fails to install

Hello,

Mika Hanhijärvi, on dim. 09 avril 2017 13:42:36 +0300, wrote:

When I try to install speechd-up package I get this error:

E: speechd-up: subprocess installed post-installation script returned error
exit status 1

Do you happen to have the espeakup package installed too?  They can't
work at the same time.

Otherwise, could somebody from debian-accessibility check whether
speechd-up works with the current speech-dispatcher?

Samuel




No. I do not have espeakup installed.

I removed espeakup because I wanted to try if speechd-up would solve 
atleast part of the one problem I have (maybe offtopic here). For some 
reason if espeakup speaks something when computer is booting then screen 
reader does not speak on Gdm login screen and on desktop. But espeak 
speaks on console.  So I have to reboot sometimes severaltimes. If  
espeakup does not say anything when computer boots, then screen reader 
speaks on gdm, but not on console. If I then login to desktop then  Orca 
speaks on desktop, but  if I go back to gdm screen whitout logging out 
from desktop first then screen reader does not speak on gdm screen. 
espeakup also does not speak on console. If I logout from desktop then 
screen reader starts to speak on gdm screen again, but espeak still does 
not speak on console. So I can not switch between desktop, gdm login 
screen and console, I am blind so I need to use screen reader.


I have no idea to which package I would need to file the bug, because I 
do not know if the problem is in espeakup, pulseaudio, 
speech-dispatcher, Orca or espeak / espeak-ng   ...


So I wanted to try if speechd-up would solve atleast part of the problem.

- Mika



Bug#859949: has a dependency problem

2017-04-09 Thread Mika Hanhijärvi
Package: python3-espeak
Version: 0.5-1+b4
Severity: grave

Packages python-espeak and python3-espeak can not be installed because of the
dependency problem if espeak speech synthesizer is replaced with espeak-ng by
installing the package libespeak-ng-libespeak1 which replaces the package
libespeak1

This bug makes it impossible to install e.g package ibus-braille when espeak is
replaced with espeak-ng.



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages python3-espeak depends on:
ii  libc6 2.24-9
ii  libespeak-ng-libespeak1 [libespeak1]  1.49.0+dfsg-8
ii  libgcc1   1:6.3.0-11
ii  libstdc++66.3.0-11
ii  python3   3.5.3-1

python3-espeak recommends no packages.

python3-espeak suggests no packages.



Bug#859926: fails to install

2017-04-09 Thread Mika Hanhijärvi
Package: speechd-up
Version: 0.5~20110719-6+b1
Severity: grave

When I try to install speechd-up package I get this error:

E: speechd-up: subprocess installed post-installation script returned error
exit status 1

Synaptic marks the package as installed. If I try to reinstall the package I
get this error:

E: Internal Error, No file name for speechd-up:amd64





-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages speechd-up depends on:
ii  libc6  2.24-9
ii  libdotconf01.3-0.2
ii  libspeechd20.8.6-4
ii  speech-dispatcher  0.8.6-4

speechd-up recommends no packages.

speechd-up suggests no packages.

-- no debconf information



Bug#859262: freezes Orca screen reader

2017-04-01 Thread Mika Hanhijärvi
Package: synaptic
Version: 0.84.2
Severity: grave

Synaptic often freezes the Orca screen reader so that Orca speaks nothing until
Synaptic is closed. The same happens on both of my laptops running Debian
Stretch.

I am blind so I have to use computer using Orca screen reader. It happens wery
often that when I e.g click the Reload button in Synaptic, or select Reload
from the Synaptic menu, then Orca screen reader stops speaking. Synapticdoes
not freeze the whole desktop, just Orca.  This problem seems to happen
randomly, sometimes it happens sometimes it does not. When Synaptic has
finished reloading the package database information Orca may start speaking
again, but often it does not. If it does not then I have to close the Synaptic
by pressing alt + F4 after which Orca starts to speak again.

It also happens sometimes that if I have reloaded repository package database
information and click Mark all updades after that then Orca stops speaking. On
my second laptop it currently happens almost every time that Orca stops
speaking when I click the Mark all updates or select it from the menu. Tkhat
also seems to happen randomly, sometimes it happens sometimes not.

I have not noticed any problems like that when I have used other applications,
this happns only when I am using Synaptic.

As I said I have two laptops running Debian Stretch and both have the same
problems. Both laptops have been upgraded from Jessie to Stretch. The first
laptop was almost clean Jessie installation before it was upgraded to Stretch,
it still has wery little apps installed.

I am using Gnome desktop. I am blind so it is difficult for me to try to figure
out what is wrong. I I have used both espeak and espeak-ng speech synthetisers
with Orca screen reader, the same problem exists notmatter which of those is in
use.



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages synaptic depends on:
ii  hicolor-icon-theme   0.15-1
ii  libapt-inst2.0   1.4~rc2
ii  libapt-pkg5.01.4~rc2
ii  libatk1.0-0  2.22.0-1
ii  libc62.24-9
ii  libcairo-gobject21.14.8-1
ii  libcairo21.14.8-1
ii  libept1.5.0  1.1+nmu3+b1
ii  libgcc1  1:6.3.0-11
ii  libgdk-pixbuf2.0-0   2.36.5-2
ii  libglib2.0-0 2.50.3-2
ii  libgnutls30  3.5.8-3
ii  libgtk-3-0   3.22.9-4
ii  libpango-1.0-0   1.40.4-1
ii  libpangocairo-1.0-0  1.40.4-1
ii  libpcre2-8-0 10.22-3
ii  libstdc++6   6.3.0-11
ii  libvte-2.91-00.46.1-1
ii  libx11-6 2:1.6.4-3
ii  libxapian30  1.4.3-1
ii  policykit-1  0.105-17
ii  zlib1g   1:1.2.8.dfsg-5

Versions of packages synaptic recommends:
ii  libgtk2-perl   2:1.2499-1
ii  rarian-compat  0.8.1-6+b1
ii  xdg-utils  1.1.1-1

Versions of packages synaptic suggests:
ii  apt-xapian-index 0.49
pn  deborphan
pn  dwww 
ii  menu 2.1.47+b1
ii  software-properties-gtk  0.96.20.2-1
ii  tasksel  3.39

-- no debconf information



Bug#858645: opening and saving remote documents fails

2017-03-24 Thread Mika Hanhijärvi
Package: libreoffice-writer
Version: 1:5.2.5-2
Severity: normal

If I try to save document to remote  Google Drive using Libreoffice then I get
the  General input / output error. The same happens if I try to open remote
document.

 when I added my Google Drive account it didn't gave any error. I entered my
email ID in username and my password in password in Google Drive. I don't have
2 factor authentication.

I am blind so it is difficult for me to try to figure out what is wrong.

I am using the current LibreOffice in Debian Stretch



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages libreoffice-writer depends on:
ii  dpkg   1.18.23
ii  libabw-0.1-1   0.1.1-4
ii  libc6  2.24-9
ii  libe-book-0.1-10.1.2-4
ii  libetonyek-0.1-1   0.1.6-5
ii  libgcc11:6.3.0-10
ii  libicu57   57.1-5
ii  libmwaw-0.3-3  0.3.9-1
ii  libodfgen-0.1-10.1.6-2
ii  libreoffice-base-core  1:5.2.5-2
ii  libreoffice-core   1:5.2.5-2
ii  librevenge-0.0-0   0.0.4-6
ii  libstdc++6 6.3.0-10
ii  libwpd-0.10-10 0.10.1-5
ii  libwpg-0.3-3   0.3.1-3
ii  libwps-0.4-4   0.4.5-1
ii  libxml22.9.4+dfsg1-2.2
ii  uno-libs3  5.2.5-2
ii  ure5.2.5-2
ii  zlib1g 1:1.2.8.dfsg-5

Versions of packages libreoffice-writer recommends:
ii  libreoffice-math  1:5.2.5-2

Versions of packages libreoffice-writer suggests:
ii  default-jre [java5-runtime]2:1.8-58
ii  fonts-crosextra-caladea20130214-1
ii  fonts-crosextra-carlito20130920-1
ii  libreoffice-base   1:5.2.5-2
pn  libreoffice-gcj
ii  libreoffice-java-common1:5.2.5-2
ii  openjdk-8-jre [java5-runtime]  8u121-b13-4

Versions of packages libreoffice-core depends on:
ii  fontconfig2.11.0-6.7+b1
ii  fonts-opensymbol  2:102.7+LibO5.2.5-2
ii  libboost-date-time1.62.0  1.62.0+dfsg-4
ii  libc6 2.24-9
ii  libcairo2 1.14.8-1
ii  libclucene-contribs1v52.3.3.4+dfsg-1
ii  libclucene-core1v52.3.3.4+dfsg-1
ii  libcmis-0.5-5v5   0.5.1+git20160603-3+b1
ii  libcups2  2.2.1-8
ii  libcurl3-gnutls   7.52.1-3
ii  libdbus-1-3   1.10.16-1
ii  libdbus-glib-1-2  0.108-2
ii  libdconf1 0.26.0-2+b1
ii  libeot0   0.01-4+b1
ii  libexpat1 2.2.0-2
ii  libexttextcat-2.0-0   3.4.4-2+b1
ii  libfontconfig12.11.0-6.7+b1
ii  libfreetype6  2.6.3-3+b2
ii  libgcc1   1:6.3.0-10
ii  libgl1-mesa-glx [libgl1]  13.0.5-1
ii  libglew2.02.0.0-3+b1
ii  libglib2.0-0  2.50.3-1
ii  libgltf-0.0-0v5   0.0.2-5
ii  libglu1-mesa [libglu1]9.0.0-2.1
ii  libgraphite2-31.3.9-4
ii  libharfbuzz-icu0  1.4.2-1
ii  libharfbuzz0b 1.4.2-1
ii  libhunspell-1.4-0 1.4.1-2+b2
ii  libhyphen02.8.8-5
ii  libice6   2:1.0.9-2
ii  libicu57  57.1-5
ii  libjpeg62-turbo   1:1.5.1-2
ii  liblangtag1   0.6.2-1
ii  liblcms2-22.8-4
ii  libldap-2.4-2 2.4.44+dfsg-3
ii  libmythes-1.2-0   2:1.2.4-3
ii  libneon27-gnutls  0.30.2-2
ii  libnspr4  2:4.12-6
ii  libnss3   2:3.26.2-1
ii  libodfgen-0.1-1   0.1.6-2
ii  libpcre3  2:8.39-2.1
ii  libpng16-16   1.6.28-1
ii  librdf0   1.0.17-1.1
ii  libreoffice-common1:5.2.5-2
ii  librevenge-0.0-0  0.0.4-6
ii  libsm62:1.2.2-1+b3
ii  libstdc++66.3.0-10
ii  libx11-6  2:1.6.4-3
ii  libxext6  2:1.3.3-1+b2
ii  libxinerama1  2:1.1.3-1+b3
ii  libxml2   2.9.4+dfsg1-2.2
ii  libxrandr22:1.5.1-1
ii  libxrender1   1:0.9.10-1
ii  libxslt1.11.1.29-2
ii  uno-libs3 5.2.5-2
ii  ure   5.2.5-2
ii  zlib1g1:1.2.8.dfsg-5

Versions of packages libreoffice-core recommends:
ii  libpaper-utils  1.1.24+nmu5

-- no debconf information



Bug#858634: listviews are not accessible with Orca screen reader

2017-03-24 Thread Mika Hanhijärvi
Package: banshee
Version: 2.6.2-6.1
Severity: important

Hi

Banshe's artist, album, genre and song listviews are not accessible with Orca
screen reader.

I am blind so I have to use computer using screen reader which speaks the
content on screen. If I go e.g to the artist list and try to select one of the
artists using keyboard up and down arrow keys then Orca screen reader speaks
nothing. Same hapeens if I try to select album, genre or song.

This bug makes Banshee unusable for the users who are visually impaired and
have to use computer using screen reader..



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages banshee depends on:
ii  gnome-icon-theme  3.12.0-2
ii  gstreamer1.0-alsa [gstreamer1.0-audiosink]1.10.4-1
ii  gstreamer1.0-plugins-bad [gstreamer1.0-audiosink  1.10.4-1
ii  gstreamer1.0-plugins-base 1.10.4-1
ii  gstreamer1.0-plugins-good [gstreamer1.0-audiosin  1.10.4-1
ii  gstreamer1.0-pulseaudio [gstreamer1.0-audiosink]  1.10.4-1
ii  libc6 2.24-9
ii  libcairo2 1.14.8-1
ii  libdbus-glib-1-2  0.108-2
ii  libdbus-glib2.0-cil   0.6.0-1
ii  libdbus2.0-cil0.8.1-2
ii  libgconf2.0-cil   2.24.2-4
ii  libgdata2.1-cil   2.2.0.0-2
ii  libgdk-pixbuf2.0-02.36.5-2
ii  libgkeyfile1.0-cil0.1-5
ii  libglib2.0-0  2.50.3-1
ii  libglib2.0-cil2.12.40-1
ii  libgpod4  0.8.3-8
ii  libgstreamer-plugins-base1.0-01.10.4-1
ii  libgstreamer1.0-0 1.10.4-1
ii  libgtk-sharp-beans-cil2.14.1-4
ii  libgtk2.0-0   2.24.31-2
ii  libgtk2.0-cil 2.12.40-1
ii  libgudev1.0-cil   0.1-4
ii  libkarma0 0.1.2-2.5
ii  libmono-addins0.2-cil 1.0+git20130406.adcd75b-4
ii  libmono-cairo4.0-cil  4.6.2.7+dfsg-1
ii  libmono-corlib4.5-cil 4.6.2.7+dfsg-1
ii  libmono-posix4.0-cil  4.6.2.7+dfsg-1
ii  libmono-sharpzip4.84-cil  4.6.2.7+dfsg-1
ii  libmono-system-core4.0-cil4.6.2.7+dfsg-1
ii  libmono-system-xml4.0-cil 4.6.2.7+dfsg-1
ii  libmono-system4.0-cil 4.6.2.7+dfsg-1
ii  libmono-zeroconf1.0-cil   0.9.0-6
ii  libmtp9   1.1.12-1+b1
ii  libnotify0.4-cil  0.4.0~r3032-7
ii  libpango-1.0-01.40.4-1
ii  libpangocairo-1.0-0   1.40.4-1
ii  libsoup-gnome2.4-12.56.0-2
ii  libsoup2.4-1  2.56.0-2
ii  libsqlite3-0  3.16.2-3
ii  libtaglib2.1-cil  2.1.0.0-3
ii  libwebkitgtk-1.0-02.4.11-3
ii  libwnck22 2.30.7-5.1
ii  libx11-6  2:1.6.4-3
ii  libxrandr22:1.5.1-1
ii  libxxf86vm1   1:1.1.4-1+b2
ii  mono-runtime  4.6.2.7+dfsg-1

Versions of packages banshee recommends:
ii  avahi-daemon 0.6.32-2
ii  brasero  3.12.1-4
ii  gstreamer1.0-pulseaudio  1.10.4-1
ii  media-player-info22-3

Versions of packages banshee suggests:
pn  banshee-dbg
pn  gstreamer1.0-ffmpeg
ii  gstreamer1.0-plugins-bad   1.10.4-1
ii  gstreamer1.0-plugins-ugly  1.10.4-1

-- no debconf information



Bug#857501: does not work with Orca screen reader and espeak

2017-03-11 Thread Mika Hanhijärvi
Package: mbrola
Version: 3.01h+2-2
Severity: grave

Hi

If I go to Orca screen reader settings and select the "Espeak Mbrola generic"
as a speech synthetiser then Orca speaks nothing. That speech synthetiser did
still work couple of days ago when I used it the last time. Orca did speak
using those more natural sounding mbrola voices. I installed the latest update
to mbrola package yesterday and if I now select that "Espeak Mbrola generic"
then Orca speakks nothing.

I am blind so it is difficult for me to try to solve what is causing this. I
have not changed the Orca and speech-dispatcher settings so that is not causing
the problem.

I have also noticed that if I now start the Gespeaker application and select
one of the mbrola voices then  Gespeaker speaks in wery robotic voice which
does not sound at all like that same mbrolaa voice did sound earlier.

The same happens if I use espeak with mbrola voice from command line. Espeak
speaks in wery robotic voice which does not sound like mbrola voice used to
sound. I also get this error message:

$ espeak -v mb-en1 "hello world"

mbrowrap error: Unable to get .wav header from mbrola
mbrola voice not found

I get the same error if I use some other mbrola voice than mb-en1.

So, any idea what is causing the problem?




-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages mbrola depends on:
ii  dpkg-dev 1.18.23
pn  libc6:i386 | libc6-i386  

mbrola recommends no packages.

Versions of packages mbrola suggests:
pn  cicero 
ii  espeak 1.48.04+dfsg-5+b1
ii  mbrola-ee1 [mbrola-voice]  0.0.20020407-1
ii  mbrola-en1 [mbrola-voice]  19980910-2
ii  mbrola-es1 [mbrola-voice]  0.0.19980610-2
ii  mbrola-fr4 [mbrola-voice]  0.0.19990521-2
ii  mbrola-us1 [mbrola-voice]  0.3-2
ii  mbrola-us2 [mbrola-voice]  0.1-2
ii  mbrola-us3 [mbrola-voice]  0.1-1

-- no debconf information



Bug#838858: firmware-amd-graphics: missing SI/CI smc firmware files

2016-11-24 Thread Mika Pflüger
Hi,

I can confirm that James' patch fixes the issue for me as well, on
4.9.0-rc5. Without the patch, X can't start for me neither on 4.8 nor
on 4.9.0-rc5, but works fine on 4.7. I'm using a pitcairn graphic card.

Would be nice to get the files included soon, as it is effectively
making testing/stretch systems with radeon SI/CI cards unbootable right
now.

Cheers + thanks,

Mika


-- 



pgpOT3VX6ZX8w.pgp
Description: Digitale Signatur von OpenPGP


Bug#844618: ITP: bornagain -- Simulating and fitting X-ray and neutron small-angle scattering at grazing incidence

2016-11-18 Thread Mika Pflüger

Hi Frederic,

I was just accepted in the debian-science team on alioth, my login is 
mikapfl-guest.
Thanks for creating the git repository on alioth, I'll commit what I've 
done so far (mostly some metadata like watchfile and copyright) using 
git-buildpackage soon.
bornagain is a pretty complex program, with a C++ shared library, a qt 
GUI and bindings for python as well as python3. I'll first try to build 
one monolithic package with GUI, library and python bindings, and then 
see how to split it and build the python3 bindings as well.
Another problem might be the bundled libraries, the upstream tarball is 
bundling patched versions of gtest, some fitting routines from other 
packages like ROOT and some themes and widgets from qt.


Cheers

Mika

Am 2016-11-18 08:07, schrieb PICCA Frederic-Emmanuel:

Hello Mika,

VEry glade to hear that you decided to integrate bornagain into Debian.

I created a git repository for it under

ssh://git.debian.org/git/debian-science/packages/bornagain.git

do you have an alioth account, and are you already member of the
debian-science team ?


Cheers


Frederic




Bug#844618: ITP: bornagain -- Simulating and fitting X-ray and neutron small-angle scattering at grazing incidence

2016-11-17 Thread Mika Pflüger
Package: wnpp
Severity: wishlist
Owner: "Mika Pflüger" <deb...@mikapflueger.de>

User: debian-scie...@lists.debian.org
Usertags: field..physics

* Package name: bornagain
  Version : 1.7.0
  Upstream Author : Scientific Computing Group at MLZ Garching: Jan Burle,
Jonathan M. Fisher, Marina Ganeva, Gennady Pospelov, Walter Van Herck and
Joachim Wuttke
* URL : http://bornagainproject.org
* License : GPL3
  Programming Lang: C++, Python
  Description : Simulating and fitting X-ray and neutron small-angle
scattering at grazing incidence

BornAgain is a software package to simulate and fit small-angle scattering at
grazing incidence. It supports analysis of both X-ray (GISAXS) and neutron
(GISANS) data. Calculations are carried out in the framework of the distorted
wave Born approximation (DWBA). BornAgain provides a graphical user interface
for interactive use as well as a generic python and C++ framework for modeling
multilayer samples with smooth or rough interfaces and with various types of
embedded nanoparticles.
..
BornAgain supports:
..
Layers:
* Multilayers without any restrictions on the number of layers
* Interface roughness correlation
* Magnetic materials
..
Particles:
* Choice between different shapes of particles (form factors)
* Particles with inner structures
* Assemblies of particles
* Size distribution of the particles (polydispersity)
..
Positions of Particles:
* Decoupled implementations between vertical and planar positions
* Vertical distributions: particles at specific depth in layers or on top.
* Planar distributions:
  - fully disordered systems
  - short-range order distribution (paracrystals)
  - two- and one-dimensional lattices
..
Input Beam:
* Polarized or unpolarized neutrons
* X-ray
* Divergence of the input beam (wavelength, incident angles) following
different distributions
* Possible normalization of the input intensity
..
Detector:
* Off specular scattering
* Two-dimensional intensity matrix, function of the output angles
..
Use of BornAgain:
* Simulation of GISAXS and GISANS from the generated sample
* Fitting to reference data (experimental or numerical)
* Interactions via Python scripts or Graphical User Interface
..
If you use BornAgain in your work, please cite
C. Durniak, M. Ganeva, G. Pospelov, W. Van Herck, J. Wuttke (2015), BornAgain
— Software for simulating and fitting X-ray and neutron small-angle
scattering at grazing incidence, version ,
http://www.bornagainproject.org

I would like to maintain the package within the debian science team. It would
be great to also get other widely-used free small- and wide-angle scattering
systems into debian, so it would be great to work together with other
interested people to package BornAgain as well as other SAS/WAS software.

Cheers,

Mika



Bug#840634: flashplugin-nonfree: Failed to download fp.11.2.202.637.sha512.amd64.pgp.asc

2016-10-20 Thread Mika
Debian testing is also affected. I just installed a new system on my
friends laptop and got the same error.

Mika


Bug#767233: udisks2: Not mounting with user permissions (even vfat!)

2015-11-05 Thread Mika Rastas
Package: udisks2
Version: 2.1.6-2
Followup-For: Bug #767233

Dear Maintainer,

Just noticed this problem also.

I connected a USB stick to my computer to edit some video files. It automounted
fine but as root and readonly premissions for users.



-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.2.0-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages udisks2 depends on:
ii  dbus   1.10.2-1
ii  libacl12.2.52-2
ii  libatasmart4   0.19-3
ii  libc6  2.19-22
ii  libglib2.0-0   2.46.1-2
ii  libgudev-1.0-0 230-2
ii  libpam-systemd 227-2
ii  libpolkit-agent-1-00.112-2
ii  libpolkit-gobject-1-0  0.112-2
ii  libsystemd0227-2
ii  libudisks2-0   2.1.6-2
ii  parted 3.2-9
ii  udev   227-2

Versions of packages udisks2 recommends:
ii  dosfstools   3.0.28-2
ii  eject2.1.5+deb1+cvs20081104-13.1
ii  gdisk1.0.0-3+b1
ii  ntfs-3g  1:2015.3.14AR.1-1
ii  policykit-1  0.112-2

Versions of packages udisks2 suggests:
pn  btrfs-tools 
ii  cryptsetup-bin  2:1.6.6-5
pn  exfat-utils 
pn  mdadm   
pn  reiserfsprogs   
pn  xfsprogs

-- no debconf information



Bug#799736: python-milter: statically compiled on all architectures besides arm64, ppc64el -> needs at least binNMU

2015-09-21 Thread Mika Pflüger

Package: python-milter
Version: 1.0-1
Severity: normal

Hi,

python-milter compilation seems to have been broken at some time during the 
jessie cycle, and
since it hasn't been recompiled since then, it is still statically compiled 
against libmilter
on most architectures.
See:
$ ldd /usr/lib/python2.7/dist-packages/milter.so
linux-vdso.so.1 (0x7ffd87b9f000)
libpthread.so.0 => /lib/x86_64-linux-gnu/libpthread.so.0 
(0x7efcf3d72000)
libc.so.6 => /lib/x86_64-linux-gnu/libc.so.6 (0x7efcf39c9000)
/lib64/ld-linux-x86-64.so.2 (0x7efcf41a9000)

(There should be also a libmilter.so.1.0.1 in there)

The problems are:
1. python-milter would not pick up security updates of libmilter.
2. python-milter actually _did not_ pick up the last changes in libmilter, 
including the
socket activation patch added to make systemd socket activation possible 
(that's how I found this).
So socket activation works if you write a C program using smfi_setconn(), but 
does not work using
a python program with milter.setconn().

However, the build problem seems to have been fixed somehow already, if I 
recompile in an up-to-date
sid, python-milter picks up the libmilter dependency just fine, so I guess 
python-milter
only needs a binNMU to fix the binary packages in sid (and then testing).

I don't know if this warrants a fix in stable, it is quite annoying, but is 
most likely not
a big problem (until there is a security hole in libmilter). If I recompile in 
an up-to-date
stable chroot, it also picks up the dependency, so also in stable a binNMU 
should fix it.

Cheers,

Mika


-- System Information:
Debian Release: stretch/sid
  APT prefers testing-proposed-updates
  APT policy: (650, 'testing-proposed-updates'), (650, 'testing'), (450, 
'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.1.0-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages python-milter depends on:
ii  libc6   2.19-20
ii  python  2.7.9-1
ii  python-dns  2.3.6-3

python-milter recommends no packages.

Versions of packages python-milter suggests:
ii  postfix2.11.3-1
pn  python-milter-doc  

-- no debconf information


-- 



pgp3XBV9_yU1O.pgp
Description: Digitale Signatur von OpenPGP


Bug#778487: s3ql: Needs python-dugong = 3.4

2015-02-16 Thread Mika Pflüger
Hi Nikolaus,

Am Mon, 16 Feb 2015 09:42:57 -0800
schrieb Nikolaus Rath nikol...@rath.org:

  So please tighten the dependencies of s3ql 2.13 to require
  python3-dugong = 3.4
 
 At least according to
 https://packages.debian.org/source/unstable/s3ql, this is exactly
 what the dependency is.

That shows the dependencies of the s3ql source package (I guess that's
build dependencies, but I'm not sure about that). The dependencies of
the s3ql binary packages are found at
https://packages.debian.org/sid/s3ql
and as you can see, there is no version specified for python3-dugong. I
think the ${python3:Depends} does not  expand to versioned dependencies
by default. The dh_python3 man page says:
If the pydist file contains PEP386 flag or set of (uscan like) rules,
dh_python3 will make the depedency versioned (version requirements are
ignored by default).
So I guess dh_python3 needs a pydist file or a py3dist-overrides file.
Adding debian/s3ql.pydist with the contents
dugong python3-dugong; PEP386
did not do the trick for me, maybe I'm reading the manpage wrong.
However; I couldn't test building in a clean environment because
building s3ql failed for me (with and without the pydist file) in an
unstable pbuilder. I still think a proper pydist file should work.

Cheers,

Mika


-- 



pgpjah7f9TaT9.pgp
Description: Digitale Signatur von OpenPGP


Bug#778487: s3ql: Needs python-dugong = 3.4

2015-02-15 Thread Mika Pflüger
Package: s3ql
Version: 2.13+dfsg-1
Severity: normal

Dear Maintainer,

s3ql version 2.13+dfsg-1 installs without problem on a jessie system, which has 
python3-dugong 3.3+dfsg-3, but it actually requires python3-dugong = 3.4, as 
this traceback shows:

Traceback (most recent call last):
File /usr/lib/python3/dist-packages/pkg_resources.py, line 449, in 
_build_master
ws.require(__requires__)
File /usr/lib/python3/dist-packages/pkg_resources.py, line 745, in require
needed = self.resolve(parse_requirements(requirements))
File /usr/lib/python3/dist-packages/pkg_resources.py, line 644, in resolve
raise VersionConflict(dist, req)
pkg_resources.VersionConflict: (dugong 3.3 (/usr/lib/python3/dist-packages), 
Requirement.parse('dugong=3.4'))

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File /usr/bin/fsck.s3ql, line 5, in module
from pkg_resources import load_entry_point
File /usr/lib/python3/dist-packages/pkg_resources.py, line 2876, in module
working_set = WorkingSet._build_master()
File /usr/lib/python3/dist-packages/pkg_resources.py, line 451, in 
_build_master
return cls._build_from_requirements(__requires__)
File /usr/lib/python3/dist-packages/pkg_resources.py, line 464, in 
_build_from_requirements
dists = ws.resolve(reqs, Environment())
File /usr/lib/python3/dist-packages/pkg_resources.py, line 639, in resolve
raise DistributionNotFound(req)
pkg_resources.DistributionNotFound: dugong=3.4

So please tighten the dependencies of s3ql 2.13 to require python3-dugong = 3.4

Cheers,

Mika
  

-- System Information:
Debian Release: 8.0
  APT prefers testing-proposed-updates
  APT policy: (650, 'testing-proposed-updates'), (650, 'testing'), (450, 
'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.16.0-4-amd64 (SMP w/8 CPU cores)
Locale: LANG=de_DE.utf8, LC_CTYPE=de_DE.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages s3ql depends on:
ii  fuse   2.9.3-15+b1
ii  libc6  2.19-13
ii  libjs-sphinxdoc1.2.3+dfsg-1
ii  libsqlite3-0   3.8.7.1-1
ii  psmisc 22.21-2
ii  python33.4.2-2
ii  python3-apsw   3.8.6-r1-1
ii  python3-crypto 2.6.1-5+b2
ii  python3-defusedxml 0.4.1-2
ii  python3-dugong 3.3+dfsg-3
ii  python3-llfuse 0.40-2+b2
ii  python3-pkg-resources  5.5.1-1
ii  python3-requests   2.4.3-4

s3ql recommends no packages.

s3ql suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#777176: Fixed version uploaded to unstable, please unblock

2015-02-08 Thread Mika Pflüger
Hi,

the fixed version was uploaded to unstable by kobold (the maintainer),
and needs an unblock to migrate. The final debdiff between testing and
unstable is attached. Please unblock if all looks good to you:

unblock phpldapadmin/1.2.2-5.2

Cheers + thanks,

Mika
diff -Nru phpldapadmin-1.2.2/debian/changelog phpldapadmin-1.2.2/debian/changelog
--- phpldapadmin-1.2.2/debian/changelog	2014-05-02 04:30:44.0 +0200
+++ phpldapadmin-1.2.2/debian/changelog	2015-02-07 23:09:25.0 +0100
@@ -1,3 +1,11 @@
+phpldapadmin (1.2.2-5.2) unstable; urgency=medium
+
+  * Non-maintainer upload.
+  * Update the php 5.5 compatibility patch for the password_hash_custom
+setting (Closes: #761637).
+
+ -- Mika Pflüger deb...@mikapflueger.de  Thu, 05 Feb 2015 00:41:07 +0100
+
 phpldapadmin (1.2.2-5.1) unstable; urgency=medium
 
   * Non-maintainer upload.
diff -Nru phpldapadmin-1.2.2/debian/NEWS phpldapadmin-1.2.2/debian/NEWS
--- phpldapadmin-1.2.2/debian/NEWS	1970-01-01 01:00:00.0 +0100
+++ phpldapadmin-1.2.2/debian/NEWS	2015-02-07 23:17:10.0 +0100
@@ -0,0 +1,9 @@
+phpldapadmin (1.2.2-5.2) unstable; urgency=medium
+
+  The setting option 'password_hash' has been renamed to 'password_hash_custom'.
+  Please fix your /etc/phpldapadmin/config.php and replace all references to
+  $servers-setValue('appearance','password_hash',
+  with
+  $servers-setValue('appearance','password_hash_custom',
+
+ -- Mika Pflüger deb...@mikapflueger.de  Sat, 07 Feb 2015 23:09:07 +0100
diff -Nru phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch
--- phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch	2014-05-02 04:28:13.0 +0200
+++ phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch	2015-02-05 01:13:38.0 +0100
@@ -20,9 +20,9 @@
 
 Index: phpldapadmin-1.2.2/lib/PageRender.php
 ===
 phpldapadmin-1.2.2.orig/lib/PageRender.php	2014-05-01 21:01:57.218441026 -0400
-+++ phpldapadmin-1.2.2/lib/PageRender.php	2014-05-01 21:01:57.210441026 -0400
-@@ -286,7 +286,7 @@
+--- phpldapadmin-1.2.2.orig/lib/PageRender.php
 phpldapadmin-1.2.2/lib/PageRender.php
+@@ -286,7 +286,7 @@ class PageRender extends Visitor {
  		break;
  
  	default:
@@ -31,7 +31,7 @@
  }
  
  $vals = array_unique($vals);
-@@ -956,7 +956,7 @@
+@@ -956,7 +956,7 @@ class PageRender extends Visitor {
  		if (trim($val))
  			$enc_type = get_enc_type($val);
  		else
@@ -40,7 +40,7 @@
  
  		$obfuscate_password = obfuscate_password_display($enc_type);
  
-@@ -981,7 +981,7 @@
+@@ -981,7 +981,7 @@ class PageRender extends Visitor {
  		if (trim($val))
  			$enc_type = get_enc_type($val);
  		else
@@ -51,9 +51,9 @@
  
 Index: phpldapadmin-1.2.2/lib/ds_ldap.php
 ===
 phpldapadmin-1.2.2.orig/lib/ds_ldap.php	2014-05-01 21:01:57.218441026 -0400
-+++ phpldapadmin-1.2.2/lib/ds_ldap.php	2014-05-01 21:01:57.210441026 -0400
-@@ -1116,13 +1116,24 @@
+--- phpldapadmin-1.2.2.orig/lib/ds_ldap.php
 phpldapadmin-1.2.2/lib/ds_ldap.php
+@@ -1116,13 +1116,24 @@ class ldap extends DS {
  
  		if (is_array($dn)) {
  			$a = array();
@@ -83,9 +83,9 @@
  	public function getRootDSE($method=null) {
 Index: phpldapadmin-1.2.2/lib/ds_ldap_pla.php
 ===
 phpldapadmin-1.2.2.orig/lib/ds_ldap_pla.php	2014-05-01 21:01:57.218441026 -0400
-+++ phpldapadmin-1.2.2/lib/ds_ldap_pla.php	2014-05-01 21:01:57.210441026 -0400
-@@ -16,7 +16,7 @@
+--- phpldapadmin-1.2.2.orig/lib/ds_ldap_pla.php
 phpldapadmin-1.2.2/lib/ds_ldap_pla.php
+@@ -16,7 +16,7 @@ class ldap_pla extends ldap {
  	function __construct($index) {
  		parent::__construct($index);
  
@@ -96,9 +96,9 @@
  
 Index: phpldapadmin-1.2.2/lib/functions.php
 ===
 phpldapadmin-1.2.2.orig/lib/functions.php	2014-05-01 20:59:08.770437445 -0400
-+++ phpldapadmin-1.2.2/lib/functions.php	2014-05-01 21:04:29.302444259 -0400
-@@ -2126,7 +2126,7 @@
+--- phpldapadmin-1.2.2.orig/lib/functions.php
 phpldapadmin-1.2.2/lib/functions.php
+@@ -2126,7 +2126,7 @@ function password_types() {
   *crypt, ext_des, md5crypt, blowfish, md5, sha, smd5, ssha, or clear.
   * @return string The hashed password.
   */
@@ -107,7 +107,7 @@
  	if (DEBUG_ENABLED  (($fargs=func_get_args())||$fargs='NOARGS'))
  		debug_log('Entered (%%)',1,0,__FILE__,__LINE__,__METHOD__,$fargs);
  
-@@ -2307,7 +2307,7 @@
+@@ -2307,7 +2307,7 @@ function password_check($cryptedpassword
  
  		# SHA crypted passwords
  		case 'sha':
@@ -116,7 +116,7 @@
  return true;
  			else
  return false;
-@@ -2316,7 +2316,7 @@
+@@ -2316,7 +2316,7 @@ function password_check($cryptedpassword
  
  		# MD5 crypted passwords
  		case 'md5':
@@ -125,7 +125,7 @@
  return true;
  			else
  return false;
-@@ -2544,13 +2544,24

Bug#761637: Fixed package

2015-02-07 Thread Mika Pflüger
Hi,

I have uploaded a package containing a fix for #761637 to
mentors.debian.net:
https://mentors.debian.net/package/phpldapadmin
I have asked for pre-approval of the release team to include the fixed
package into testing, Niels Thykier agreed that #761637 looks grave
enough to justify including a fix into Jessie, see
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=777176

As I do not have upload privileges in debian, I can't upload the fixed
package myself. Could you check the fixed package and upload to
unstable? I'll then file the unblock request with the release team.
If you are unable to upload the package atm, I'll start searching for a
sponsor from monday on.

Cheers,

Mika

-- 



pgp0EkehLyetj.pgp
Description: Digitale Signatur von OpenPGP


Bug#777176: pre-approval: unblock: phpldapadmin/1.2.2-5.2

2015-02-05 Thread Mika Pflüger
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock

Hi,

phpldapadmin has bug #761637, which I think is RC for phpldapadmin. The short 
version is: phpldapadmin is a frontend to manage ldap directories. As a 
regression from stable, the version in testing crashes if an entry in the 
managed ldap directory contains a password field. As it is /very/ common to 
have password fields in ldap entries, this renders the package unusable for a 
large portion of the user base.
Fortunately, the fix for this is small, as the issue is already partly fixed by 
version 1.2.2-5.1 which is already in testing. It was missing:
* A single line change in the code.
* An update of the config file
* A NEWS entry to explain users how to update their config.
I have prepared a package containing the fix, which can provisionally be found 
at https://mentors.debian.net/package/phpldapadmin . The meat of the debdiff is:

diff -Nru phpldapadmin-1.2.2/debian/changelog 
phpldapadmin-1.2.2/debian/changelog
--- phpldapadmin-1.2.2/debian/changelog 2014-05-02 04:30:44.0 +0200
+++ phpldapadmin-1.2.2/debian/changelog 2015-02-05 01:02:16.0 +0100
@@ -1,3 +1,11 @@
+phpldapadmin (1.2.2-5.2) unstable; urgency=medium
+
+  * Non-maintainer upload.
+  * Update the php 5.5 compatibility patch for the password_hash_custom
+setting (Closes: #761637).
+
+ -- Mika Pflüger deb...@mikapflueger.de  Thu, 05 Feb 2015 00:41:07 +0100
+
 phpldapadmin (1.2.2-5.1) unstable; urgency=medium
 
   * Non-maintainer upload.
diff -Nru phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch 
phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch
--- phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch  2014-05-02 
04:28:13.0 +0200
+++ phpldapadmin-1.2.2/debian/patches/php-5.5-compat.patch  2015-02-05 
01:13:38.0 +0100
+Index: phpldapadmin-1.2.2/config/config.php.example
+===
+--- phpldapadmin-1.2.2.orig/config/config.php.example
 phpldapadmin-1.2.2/config/config.php.example
+@@ -379,7 +379,7 @@ $servers-setValue('server','name','My L
+ 
+ /* Default password hashing algorithm. One of md5, ssha, sha, md5crpyt, smd5,
+blowfish, crypt or leave blank for now default algorithm. */
+-// $servers-setValue('appearance','password_hash','md5');
++// $servers-setValue('appearance','password_hash_custom','md5');
+ 
+ /* If you specified 'cookie' or 'session' as the auth_type above, you can
+optionally specify here an attribute to use when logging in. If you enter
+@@ -546,7 +546,7 @@ $servers-setValue('sasl','authz_id_rege
+ $servers-setValue('sasl','authz_id_replacement','$1');
+ $servers-setValue('sasl','props',null);
+ 
+-$servers-setValue('appearance','password_hash','md5');
++$servers-setValue('appearance','password_hash_custom','md5');
+ $servers-setValue('login','attr','dn');
+ $servers-setValue('login','fallback_dn',false);
+ $servers-setValue('login','class',null);
+Index: phpldapadmin-1.2.2/lib/TemplateRender.php
+===
+--- phpldapadmin-1.2.2.orig/lib/TemplateRender.php
 phpldapadmin-1.2.2/lib/TemplateRender.php
+@@ -2466,7 +2466,7 @@ function deleteAttribute(attrName,friend
+   if ($val = $attribute-getValue($i))
+   $default = get_enc_type($val);
+   else
+-  $default = 
$this-getServer()-getValue('appearance','password_hash');
++  $default = 
$this-getServer()-getValue('appearance','password_hash_custom');
+ 
+   if (! $attribute-getPostValue())
+   printf('input type=hidden name=post_value[%s][] 
value=%s /',$attribute-getName(),$i);

(the version currently at mentors has a slightly larger debdiff due to quilt 
refresh'ing of the php-5.5-compat.patch, but with no further real changes).

If you pre-approve the unblock request, I will write a NEWS entry, seek a 
sponsor and come back to you. I am using a fixed version at a reasonably busy 
site for two weeks now.

One thing to note is that the version currently in testing deviates from the 
upstream solution, possibly because it predates it. The setting which collides 
with a php-internal function name ('password_hash' in debian stable) was 
[incompletely, hence this bug] changed to 'password_hash_custom' in debian, but 
to 'pla_password_hash' in the 1.2.3 upstream version. That is clearly a 
suboptimal situation, as this will confuse users and will come back to bite us 
later. However, I guess changing 'password_hash_custom' to 'pla_password_hash' 
is a bit intrusive at this stage of the release cycle. If you disagree, I can 
also prepare a patch which aligns with upstream's choice of bike shed colour.

Cheers,

Mika

unblock phpldapadmin/1.2.2-5.2

-- System Information:
Debian Release: 8.0
  APT prefers testing
  APT policy: (650, 'testing'), (450, 'unstable

Bug#763701: config: Check for doveconf does not work

2014-10-01 Thread Mika Pflüger
Package: dovecot-core
Version: 1:2.2.13-5
Severity: normal

Hi,

in dovecot-core.config you use:
if [ ! -z `which doveconf  /dev/null 21` ]; then
which will never be true. As you redirect stderr _and_ stdout of 'which',
the string will always be zero, so the '-z' will always be true and the '!'
will always be false. To fix that, and make stuff more readable, just use:
if which doveconf  /dev/null 21; then
instead. 'which' already returns false if the program does not exist.

If you want to, I can prepare a pull request or even a package, just drop
me a line. I also read you consider redesigning the whole certificate
generation code. If you could articulate your goal of what should happen,
I could try to implement that cleanly.

Cheers,

Mika

-- Package-specific info:

dovecot configuration
-
# 2.2.13: /etc/dovecot/dovecot.conf
# OS: Linux 3.14-2-amd64 x86_64 Debian jessie/sid 
lda_mailbox_autocreate = yes
lda_mailbox_autosubscribe = yes
mail_location = maildir:~/.Maildir
namespace inbox {
  inbox = yes
  location = 
  mailbox Drafts {
special_use = \Drafts
  }
  mailbox Junk {
special_use = \Junk
  }
  mailbox Sent {
special_use = \Sent
  }
  mailbox Sent Messages {
special_use = \Sent
  }
  mailbox Trash {
special_use = \Trash
  }
  prefix = 
}
passdb {
  driver = pam
}
plugin {
  sieve = ~/.dovecot.sieve
  sieve_dir = ~/sieve
}
protocols =  imap
ssl = no
userdb {
  driver = passwd
}

-- System Information:
Debian Release: jessie/sid
  APT prefers testing
  APT policy: (650, 'testing'), (450, 'unstable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.14-2-amd64 (SMP w/2 CPU cores)
Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages dovecot-core depends on:
ii  adduser3.113+nmu3
ii  debconf [debconf-2.0]  1.5.53
ii  libbz2-1.0 1.0.6-7
ii  libc6  2.19-11
ii  liblzma5   5.1.1alpha+20120614-2
ii  libpam-runtime 1.1.8-3.1
ii  libpam0g   1.1.8-3.1
ii  libssl1.0.01.0.1i-2
ii  libwrap0   7.6.q-25
ii  openssl1.0.1i-2
ii  ucf3.0030
ii  zlib1g 1:1.2.8.dfsg-2

dovecot-core recommends no packages.

Versions of packages dovecot-core suggests:
ii  dovecot-gssapi1:2.2.13-5
ii  dovecot-imapd 1:2.2.13-5
ii  dovecot-ldap  1:2.2.13-5
pn  dovecot-lmtpd none
pn  dovecot-lucenenone
pn  dovecot-managesieved  none
ii  dovecot-mysql 1:2.2.13-5
ii  dovecot-pgsql 1:2.2.13-5
pn  dovecot-pop3d none
ii  dovecot-sieve 1:2.2.13-5
pn  dovecot-solr  none
ii  dovecot-sqlite1:2.2.13-5
ii  ntp   1:4.2.6.p5+dfsg-3

Versions of packages dovecot-core is related to:
ii  dovecot-core [dovecot-common]  1:2.2.13-5
pn  dovecot-dbgnone
pn  dovecot-devnone
ii  dovecot-gssapi 1:2.2.13-5
ii  dovecot-imapd  1:2.2.13-5
ii  dovecot-ldap   1:2.2.13-5
pn  dovecot-lmtpd  none
pn  dovecot-managesieved   none
ii  dovecot-mysql  1:2.2.13-5
ii  dovecot-pgsql  1:2.2.13-5
pn  dovecot-pop3d  none
ii  dovecot-sieve  1:2.2.13-5
ii  dovecot-sqlite 1:2.2.13-5

-- debconf information:
* dovecot-core/create-ssl-cert: false
  dovecot-core/ssl-cert-name: localhost
* dovecot-core/ssl-cert-exists:


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#702030: [DSE-Dev] forbid most packages to depend on or recommend apparmor

2014-08-29 Thread Mika Pflüger
Hi,

I certainly can't speak for the whole team, but can offer my thoughts
about the situation of SELinux at the moment.

intrigeri intrig...@debian.org wrote:
  AFAIK this is inconsistent with how selinux is handled, which is
  only enabled via an explicit boot option.
 
  I was not aware of that, thanks for pointing it out.
 
  @SELinux maintainers: is this behavior on purpose, or is it due to
  the historical lack of a facility (recently added by the
  /etc/default/grub.d support) to easily have a package append
  arguments to the kernel command-line?

I think both. Installing the default SELinux policy and enabling it
routinely breaks all kinds of stuff (avahi-things, booting with
systemd, obtaining IP addresses via dhcp, hotplugging of network
interfaces etc. just to name some things that popped up in testing or
stable during the last year), especially things not usually tested on
servers run by the more security-aware part of the linux admin
population. So for the regular user (unfortunately), enabling selinux
simply by installing the policy package would certainly feel a lot like
a grave bug (breaks unrelated software).
 
  Shouldn't we handle our LSMs symmetrically?
 
  Indeed, I think we should. I see several ways of keeping things
  consistent while reaching the aforementioned AppArmor usability
  goal:
 
  a) Having the SELinux equivalent of the apparmor package enable it
  by default too (and then, we'll need conflicts); I've no idea if
  this is feasible; one would need to look at the SELinux packages and
 their chain of reverse-dependencies.

However, I think this could be pretty reasonable, given
1) it would be e.g. a selinux binary package doing this, not the
library or selinux-basics/utils package. This binary package does not
exist at the moment, but could be created.
2) it would ask via debconf before enabling.
 
  b) Implementing the behavior proposed by Patrick via a dedicated
 apparmor-$something configuration package. ftp-masters likely
  won't be happy with it (understandably), unless we demonstrate it's
  the best available solution to reach a sensible goal. The SELinux
  team is then free to create a corresponding package.

This is basically a) for selinux, as there is no standard selinux
package.
 
  c) A new package whose job is to select and enable a LSM (or none).
 Likely none would be the default for now. It's tempting to take
 benefit from debconf here.
 
  d) An apparmor-activate command, very similar to selinux-activate
 (from the selinux-basics package). The resulting user experience
 would be less friendly than just install the apparmor package,
 but perhaps that's acceptable for now.
 
  Other ideas?
 
  SELinux maintainers, any thoughts on this? I've no idea what's the
  current situation wrt. SELinux policies in Debian — are they in
  a shape that warrants thinking of usability matters for the target
  userbase described above, or do potential users anyway have to play
  with a terminal and text editor as root? In other words, should we
  work on a shared solution to this problem, or should the AppArmor
  folks do their bit on their side, merely being careful not to break
  the SELinux usecases?

For the users we are currently targetting, selinux-activate is
adequate, but a debconf question would certainly be easier. We are
(slowly) working on getting better user experience, but yes, people
still have to play with a terminal as root for jessie, I'm afraid.
 
  (Also, what happens if someone has already enabled selinux, then
  installs this apparmor package which is intended to automatically
  enable apparmor?)
 
  The *last* LSM activated on the kernel command-line is the one
  that's enabled in practice (tested both ways). So, installing a
  apparmor package, that automatically enables this LSM, would
  override the previous manual enabling of SELinux. The reciprocal
  applies when running selinux-activate (which is arguably a more
  explicit choice made by the administrator than installing the
  apparmor package).
 
  IMO, both should first check if another LSM is enabled.

That sounds like a good idea. It would be nice to have some kind of
standard way to tell if any other LSM is enabled, otherwise we all have
to maintain some 
selinuxenabled | $apparmorenabled | $whateverelseenabled
shell snippets on our own.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#758600: shibboleth-sp2-utils: postinst fails on initial installation

2014-08-19 Thread Mika Tiainen
Package: shibboleth-sp2-utils
Version: 2.5.3+dfsg-1~bpo70+1
Severity: normal

Hi,

Installing libapache2-mod-shib2 from wheezy backports. shibboleth-sp2-utils
postinst fails on initial installation, because it tries to enable the apache
module, but libapache2-mod-shib2 is not yet configured so
/etc/apache2/mods-available/ contains only shib2.load.dpkg-new.

Attached is a log of the install.

-- System Information:
Debian Release: 7.6
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages shibboleth-sp2-utils depends on:
ii  adduser3.113+nmu3
ii  libc6  2.13-38+deb7u3
ii  libfcgi0ldbl   2.4.0-8.1
ii  libgcc11:4.7.2-5
ii  liblog4shib1   1.0.4-1
ii  libsaml8   2.5.3-2~bpo70+1
ii  libshibsp-plugins  2.5.3+dfsg-1~bpo70+1
ii  libshibsp6 2.5.3+dfsg-1~bpo70+1
ii  libstdc++6 4.7.2-5
ii  libxerces-c3.1 3.1.1-3
ii  libxmltooling6 1.5.3-2~bpo70+1

Versions of packages shibboleth-sp2-utils recommends:
ii  openssl  1.0.1e-2+deb7u12

shibboleth-sp2-utils suggests no packages.

-- no debconf information
mika@y-moodle:~$ sudo aptitude install -t wheezy-backports libapache2-mod-shib2
The following NEW packages will be installed:
  libapache2-mod-shib2 libfcgi0ldbl{a} liblog4shib1{a} libmemcached10{a}
  libodbc1{a} libsaml8{a} libshibsp-plugins{a} libshibsp6{a}
  libxerces-c3.1{a} libxml-security-c17{a} libxmltooling6{a}
  opensaml2-schemas{a} shibboleth-sp2-common{a} shibboleth-sp2-utils{a}
  xmltooling-schemas{a}
0 packages upgraded, 15 newly installed, 0 to remove and 34 not upgraded.
Need to get 5 547 kB of archives. After unpacking 28,8 MB will be used.
Do you want to continue? [Y/n/?]
Get: 1 http://ftp.fi.debian.org/debian/ wheezy/main libmemcached10 amd64 1.0.8-1
 [117 kB]
Get: 2 http://ftp.fi.debian.org/debian/ wheezy/main libodbc1 amd64 2.2.14p2-5 [2
52 kB]
Get: 3 http://ftp.fi.debian.org/debian/ wheezy/main libxerces-c3.1 amd64 3.1.1-3
 [1 139 kB]
Get: 4 http://ftp.fi.debian.org/debian/ wheezy/main liblog4shib1 amd64 1.0.4-1 [
95,7 kB]
Get: 5 http://ftp.fi.debian.org/debian/ wheezy-backports/main libxml-security-c1
7 amd64 1.7.2-2~bpo70+1 [290 kB]
Get: 6 http://ftp.fi.debian.org/debian/ wheezy-backports/main libxmltooling6 amd
64 1.5.3-2~bpo70+1 [613 kB]
Get: 7 http://ftp.fi.debian.org/debian/ wheezy-backports/main libsaml8 amd64 2.5
.3-2~bpo70+1 [940 kB]
Get: 8 http://ftp.fi.debian.org/debian/ wheezy-backports/main opensaml2-schemas
all 2.5.3-2~bpo70+1 [25,8 kB]
Get: 9 http://ftp.fi.debian.org/debian/ wheezy-backports/main shibboleth-sp2-com
mon all 2.5.3+dfsg-1~bpo70+1 [48,8 kB]
Get: 10 http://ftp.fi.debian.org/debian/ wheezy-backports/main xmltooling-schema
s all 1.5.3-2~bpo70+1 [15,9 kB]
Get: 11 http://ftp.fi.debian.org/debian/ wheezy-backports/main libshibsp6 amd64
2.5.3+dfsg-1~bpo70+1 [1 307 kB]
Get: 12 http://ftp.fi.debian.org/debian/ wheezy/main libfcgi0ldbl amd64 2.4.0-8.
1 [281 kB]
Get: 13 http://ftp.fi.debian.org/debian/ wheezy-backports/main libshibsp-plugins
 amd64 2.5.3+dfsg-1~bpo70+1 [247 kB]
Get: 14 http://ftp.fi.debian.org/debian/ wheezy-backports/main shibboleth-sp2-ut
ils amd64 2.5.3+dfsg-1~bpo70+1 [103 kB]
Get: 15 http://ftp.fi.debian.org/debian/ wheezy-backports/main libapache2-mod-sh
ib2 amd64 2.5.3+dfsg-1~bpo70+1 [72,2 kB]
Fetched 5 547 kB in 0s (6 051 kB/s)
Selecting previously unselected package libmemcached10:amd64.
(Reading database ... 34023 files and directories currently installed.)
Unpacking libmemcached10:amd64 (from .../libmemcached10_1.0.8-1_amd64.deb) ...
Selecting previously unselected package libodbc1:amd64.
Unpacking libodbc1:amd64 (from .../libodbc1_2.2.14p2-5_amd64.deb) ...
Selecting previously unselected package libxerces-c3.1:amd64.
Unpacking libxerces-c3.1:amd64 (from .../libxerces-c3.1_3.1.1-3_amd64.deb) ...
Selecting previously unselected package liblog4shib1:amd64.
Unpacking liblog4shib1:amd64 (from .../liblog4shib1_1.0.4-1_amd64.deb) ...
Selecting previously unselected package libxml-security-c17:amd64.
Unpacking libxml-security-c17:amd64 (from .../libxml-security-c17_1.7.2-2~bpo70+
1_amd64.deb) ...
Selecting previously unselected package libxmltooling6:amd64.
Unpacking libxmltooling6:amd64 (from .../libxmltooling6_1.5.3-2~bpo70+1_amd64.de
b) ...
Selecting previously unselected package libsaml8:amd64.
Unpacking libsaml8:amd64 (from .../libsaml8_2.5.3-2~bpo70+1_amd64.deb) ...
Selecting previously unselected package opensaml2-schemas.
Unpacking opensaml2-schemas (from .../opensaml2-schemas_2.5.3-2~bpo70+1_all.deb)
 ...
Selecting previously unselected package shibboleth-sp2-common.
Unpacking shibboleth-sp2-common (from .../shibboleth-sp2-common_2.5.3+dfsg-1~bpo
70+1_all.deb) ...
Selecting previously unselected package xmltooling-schemas.
Unpacking xmltooling-schemas (from .../xmltooling-schemas_1.5.3-2

Bug#758464: [DSE-Dev] Bug#758464: selinux-policy-default: Impossible to use libvirt(d) if enforcing

2014-08-17 Thread Mika Pflüger
Hi Andreas,

Andreas Florath an...@flonatel.org wrote:
 avc:
 denied  { execstack }

Which SELinux booleans have you set? Does allowing execstack help?
To learn about SELinux booleans, see booleans(8), to see the status of
all booleans, use getsebool -a.
To switch allow_execstack, use setsebool allow_execstack on.

Maybe this helps and it is merely a configuration/documentation issue.

Cheers,

Mika


-- 



signature.asc
Description: PGP signature


Bug#756729: [DSE-Dev] Bug#756729: selinux-policy-default: Setting SELinux to enforce results in not configured network interface at boot time

2014-08-01 Thread Mika Pflüger
Hi,

Andreas Florath an...@flonatel.org wrote:
 Package: selinux-policy-default
 Version: 2:2.20110726-12
 Severity: important
 
 Dear Maintainer,
 
 after enableing SELinux the eth0 network device is not longer
 configured automatically during boot time.
 
 There is a similar bug
  https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=728950
 but it differs in the command. Here it is 'dhclient' there the
 scripts.
 
 IMHO this is an 'important' bug, because systems using dhcp cannot
 switch to enforce - or they will not work properly any more.
 
 The eth0 device is configured as:
 
 allow-hotplug eth0
 iface eth0 inet dhcp
 
 After booting with SELinux set to enforced the eth0 network interface
 is not configured. ifconfig shows only 'lo'.
 
 During boot, the following two AVCs are reported:
 
 Jul 31 12:55:55 debtest kernel: [4.489454] type=1400
 audit(1406804155.296:5): avc:  denied  { name_bind } for  pid=1677
 comm=dhclient src=1356
 scontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023
 tcontext=system_u:object_r:port_t:s0 tclass=udp_socket Jul 31
 12:55:55 debtest kernel: [4.489641] type=1400
 audit(1406804155.296:6): avc:  denied  { name_bind } for  pid=1677
 comm=dhclient src=14762
 scontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023
 tcontext=system_u:object_r:port_t:s0 tclass=udp_socket
 
 When I use these both lines as input to 'audit2allow' and 'semodule
 
 $ audit2allow -M localdhclient
 $ semodule -i localdhclient.pp
 
 after booting, the interface comes up, but it looks that the further
 setup needs 'hostname' and 'ip':
 
 Jul 31 13:39:41 debtest kernel: [4.954371] type=1400
 audit(1406806780.651:5): avc:  denied  { read write } for  pid=1723
 comm=ip path=socket:[7251] dev=sockfs ino=7251
 scontext=system_u:system_r:ifconfig_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 Jul 31 13:39:41 debtest kernel: [4.954457] type=1400
 audit(1406806780.651:6): avc:  denied  { read write } for  pid=1723
 comm=ip path=socket:[7252] dev=sockfs ino=7252
 scontext=system_u:system_r:ifconfig_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 Jul 31 13:39:41 debtest kernel: [5.005695] type=1400
 audit(1406806780.703:7): avc:  denied  { read write } for  pid=1751
 comm=hostname path=socket:[7251] dev=sockfs ino=7251
 scontext=system_u:system_r:hostname_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 Jul 31 13:39:41 debtest kernel: [5.005781] type=1400
 audit(1406806780.703:8): avc:  denied  { read write } for  pid=1751
 comm=hostname path=socket:[7252] dev=sockfs ino=7252
 scontext=system_u:system_r:hostname_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 Jul 31 13:39:41 debtest kernel: [5.007904] type=1400
 audit(1406806780.703:9): avc:  denied  { read write } for  pid=1752
 comm=ip path=socket:[7251] dev=sockfs ino=7251
 scontext=system_u:system_r:ifconfig_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 Jul 31 13:39:41 debtest kernel: [5.007988] type=1400
 audit(1406806780.703:10): avc:  denied  { read write } for  pid=1752
 comm=ip path=socket:[7252] dev=sockfs ino=7252
 scontext=system_u:system_r:ifconfig_t:s0-s0:c0.c1023
 tcontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=udp_socket
 
 After another 'autid2allow' and 'semodule' there are no further AVCs
 in the log after a reboot and the interface works fine.
 


Could you provide the output of
# sestatus
# semodule -l
and also which init system you are using?

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#756731: [DSE-Dev] Bug#756731: selinux-policy-default: Setting SELinux to enforce when using systemd some AVCs are logged during boot

2014-08-01 Thread Mika Pflüger
Hi Andre,

as you can see I set the severity of the cosmetic bug reports, where
AVCs are logged but apparently no functional degradation happens to
minor. Often programs will use different codepaths (or do not
actually care) when something is denied (think of the equivalent of ls
-la|grep etc [or something along the lines which actually makes sense]
where stat'ing /dev will be prohibited. It will log an AVC, but the
program doesn't actually care). Therefore, in policy we have
dontaudit rules, which do deny access, but don't log AVCs. So if
functionality is not degraded, this actually looks like a missing
dontaudit rule, which is arguably only a minor error.

Also please note that updates to Debian stable are only done for at
least important bugs, so it is not really worth reporting minor bugs
against versions in stable (other than for documentation purposes), we
most likely will not actually fix them. If someone finds time, we will
however try to test if they persist in testing/unstable to try to fix
them in testing, such that the next stable release will have fewer
bugs. If you could test minor/normal bugs you find in stable in
testing/unstable (e.g. in a VM), that would actually help us a lot!

If you need some help in setting up a test environment for that, I can
help you with it (or even provide a vm to you which you can use for
testing if you do not have necessary hardware).

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#756729: [DSE-Dev] Bug#756729: selinux-policy-default: Setting SELinux to enforce results in not configured network interface at boot time

2014-08-01 Thread Mika Pflüger
Hi Andre,

most interesting is the output of semodule -l. SELinux refpolicy is
modular, so that you only have to load the policy for the programs you
actually use. Note that in your case you have loaded only some select
modules, pretty much a minimal set of modules, which will provide only
very basic functionality.
Upon installation, the selinux-policy-default package in stable tries to
guess which modules you could need and installs those. If you then
install other software afterwards, you have to enable other modules
yourself.
To enable the dhcp module (which hopefully will fix your problem), use:
# semodule -i /usr/share/selinux/default/dhcp.pp
you will find all available modules in /usr/share/selinux/default/,
just check which one sounds like you need it. You can also install all
of them and then selectively disable some using
# semodule -d dhcp
(or equivalent for other module names, see semodule(8)), which is often
easier.

Note that having loaded too many modules usually only means selinux
is not as effective in preventing acceses (if e.g. you don't have an
ftp server installed, there is no need to allow ftp access), but it
usually will not do much harm.

We recognise that this situation (minimal set of default modules enable
upon installation) is confusing for many users, which is why we changed
this already in debian unstable, such that by default a much larger set
(also including dhcp) of modules is installed.

I hope this helps you to get up and running with selinux.
Unfortunately, there is only very basic documentation about selinux on
debian (the best I know is
http://debian-handbook.info/browse/stable/sect.selinux.html from the
debian administrator's handbook), but it is mostly analogous to how it
works on RHEL and Fedora, so you can also read 
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/SELinux_Users_and_Administrators_Guide/index.html

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#756468: [DSE-Dev] Bug#756468: Please think about fixing this bug in stable

2014-08-01 Thread Mika Pflüger
Hi,

Andreas Florath an...@flonatel.org wrote:
 IMHO this bug should be fixed in stable, because it prevents
 installing packages that use addgroup when SELinux is set to
 enforcing.

I haven't found time to investigate the issue, but if you have loaded
the unconfined module and use normal apt-get (not se_apt-get etc.)
commands as unconfined root, everything should work. You could at least
use this as a workaround for the time being.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#756542: [DSE-Dev] Bug#756542: selinux-policy-default: Installation of systemd from wheezy-backports results in many AVCs

2014-07-30 Thread Mika Pflüger
Hi,

Andreas Florath an...@flonatel.org wrote: 
 using systemd from backports (version see below) many AVCs appear in
 the logging. The system is (partially) unusable - e.g. eth0 works not
 reliable.

Using software from backports usually is not supported by the refpolicy
in stable (we can't see the future, after all), and it is very unlikely
we'll be able to fix that in stable.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#747298: request-tracker4: Missing dependency on libcss-squish-perl

2014-05-07 Thread Mika Tiainen
Package: request-tracker4
Version: 4.2.3-2
Severity: important

Hi,

I did a new clean install of RT 4.2 from unstable on wheezy (with backports).
Needed to install libcss-squish-perl manually, without it RT dies with:

[28346] [Wed May  7 09:32:48 2014] [error]: Base class package CSS::Squish is 
empty.
(Perhaps you need to 'use' the module which defines that package first,
or make that module available in @INC (@INC contains: 
/usr/local/share/request-tracker4/lib /usr/share/request-tracker4/lib /etc/perl 
/usr/lib/perl5 /usr/share/perl5 /usr/lib/perl/5.14 /usr/share/perl/5.14 
/usr/local/lib/site_perl . /etc/apache2).
 at /usr/share/request-tracker4/lib/RT/Squish/CSS.pm line 66
BEGIN failed--compilation aborted at 
/usr/share/request-tracker4/lib/RT/Squish/CSS.pm line 66.

Stack:
  [/usr/share/request-tracker4/lib/RT/Squish/CSS.pm:66]
  [/usr/share/request-tracker4/html/Elements/Header:129]
  [/usr/share/request-tracker4/html/Elements/Login:49]
  [/usr/share/request-tracker4/html/NoAuth/Login.html:56]
  [/usr/share/request-tracker4/lib/RT/Interface/Web.pm:347]
  [/usr/share/request-tracker4/html/autohandler:53]
Compilation failed in require at 
/usr/share/request-tracker4/lib/RT/Interface/Web.pm line 83.

Stack:
  [/usr/share/request-tracker4/lib/RT/Interface/Web.pm:83]
  [/usr/share/request-tracker4/html/Elements/Header:129]
  [/usr/share/request-tracker4/html/Elements/Login:49]
  [/usr/share/request-tracker4/html/NoAuth/Login.html:56]
  [/usr/share/request-tracker4/lib/RT/Interface/Web.pm:347]
  [/usr/share/request-tracker4/html/autohandler:53] 
(/usr/share/request-tracker4/lib/RT/Interface/Web/Handler.pm:212)


-- Package-specific info:
Changed files:

-- System Information:
Debian Release: 7.5
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages request-tracker4 depends on:
ii  dbconfig-common  1.8.47+nmu1
ii  debconf [debconf-2.0]1.5.49
ii  exim44.80-7
ii  exim4-daemon-light [mail-transport-agent]4.80-7
ii  fonts-droid  20111207+git-1
ii  libapache-session-perl   1.89-1
ii  libcgi-emulate-psgi-perl 0.14-1
ii  libcgi-psgi-perl 0.15-1
ii  libclass-accessor-perl   0.34-1
ii  libconvert-color-perl0.08-1
ii  libcrypt-eksblowfish-perl0.008-1+b2
ii  libcrypt-ssleay-perl 0.58-1
ii  libcrypt-x509-perl   0.51-1
ii  libdata-guid-perl0.046-1
ii  libdata-ical-perl0.18+dfsg-1
ii  libdate-extract-perl 0.04-1~bpo70+1
ii  libdate-manip-perl   6.32-1
ii  libdatetime-format-natural-perl  1.00-1
ii  libdatetime-locale-perl  1:0.45-1
ii  libdatetime-perl 2:0.7500-1
ii  libdbi-perl  1.622-1
ii  libdbix-searchbuilder-perl   1.65-1~bpo70+1
ii  libdevel-globaldestruction-perl  0.06-1
ii  libemail-address-list-perl   0.05-1~bpo70+1
ii  libemail-address-perl1.901-1~bpo70+1
ii  libfcgi-procmanager-perl 0.24-1
ii  libfile-sharedir-perl1.00-0.1
ii  libfile-which-perl   1.09-1
ii  libgd-graph-perl 1.48-1~bpo70+1
ii  libgd-text-perl  0.86-8
ii  libgnupg-interface-perl  0.45-1
ii  libgraphviz-perl 2.10-1
ii  libhtml-formattext-withlinks-andtables-perl  0.02-1
ii  libhtml-formattext-withlinks-perl0.14-1
ii  libhtml-mason-perl   1:1.48-1
ii  libhtml-mason-psgihandler-perl   0.52-1
ii  libhtml-quoted-perl  0.03-1
ii  libhtml-rewriteattributes-perl   0.05-1~bpo70+1
ii  libhtml-scrubber-perl0.09-1
ii  libhttp-message-perl 6.03-1
ii  libipc-run-perl  0.92-1
ii  libipc-run3-perl 0.045-1
ii  libjson-perl 2.53-1
ii  liblist-moreutils-perl   0.33-1+b1
ii  liblocale-maketext-fuzzy-perl0.11-1
ii  liblocale-maketext-lexicon-perl  0.91-1
ii  liblog-dispatch-perl 2.32-1
ii  libmailtools-perl2.12-1~bpo70+1
ii  libmime-tools-perl   5.505-1~bpo70+1
ii  libmime-types-perl   1.35-1
ii  libmodule-refresh-perl   0.17-1
ii  

Bug#747111: [DSE-Dev] Bug#747111: selinux-basics: MCS mode is missing in /etc/selinux/config

2014-05-05 Thread Mika Pflüger
Hi,

Victor Porton por...@narod.ru wrote:
 
 From /etc/selinux/config:
 
 # SELINUXTYPE= can take one of these two values:
 # default - equivalent to the old strict and targeted policies
 # mls - Multi-Level Security (for military and educational use)
 # src - Custom policy built from source
 SELINUXTYPE=default
 
 MCS mode is missing in the comments and I am not sure whether it
 is supported at all.
 
 Personally I need MCS (but not MLS) support for my project.

The default policy (from selinux-policy-default) is a mcs policy. It
might be a good idea to reword the documentation to clearly state this
like this:

# default - equivalent to the old strict and targeted policies
(includes multi category security)

on the other hand that would change the config file, triggering
dpkg-questions for users who modified the file for only a small
benefit. Note that the fact that selinux-policy-default uses mcs is
already documented in the package description.
I personally don't think we should update the comments
in /etc/selinux/config unless we are changing that file anyway.

Cheers,

Mika


signature.asc
Description: PGP signature


Bug#728442: #728442 - gnome-control-center crashes gnome-shell trying to raise privileges

2014-05-03 Thread Mika
I haven't been able to reproduce this in the version I am now using.
G-control-center 3.8.3-5 and -data 3.8.3-7

So now raising privileges work as it should. Also running things like
synaptic asks for privileges and password as it should now.

Thanks Upstream packagers


On Mon, Apr 28, 2014 at 7:20 PM, althaser altha...@gmail.com wrote:

 Hey,

 Could you please still reproduce this issue with newer
 gnome-control-center version like 1:3.8.3-7 ?

 I can't reproduce it here with g-c-c-1:3.8.3-7

 cheers,
 althaser



Bug#728442: Gnome-Shell and Libc6 Segfaults on running of any unlock dialog or gksu

2014-03-30 Thread Mika
I have had a similar if not same problem for a long while now. I know
I can get around this by running things from terminal as su to root.
But now that I found this I thought I should join in with info.

So whenever I run synaptic from gnome it takes 15 seconds and crashes
the desktop. Whenever I run a program with admin unlock and press
unlock it crashes.

Here are a few log files. Hope we can find the culprit here and fix this.


dmesg :

[   22.470494] nvidia :01:00.0: irq 89 for MSI/MSI-X
[   23.103680] NVRM: Your system is not currently configured to drive
a VGA console
[   23.103689] NVRM: on the primary VGA device. The NVIDIA Linux graphics driver
[   23.103691] NVRM: requires the use of a text-mode VGA console. Use
of other console
[   23.103693] NVRM: drivers including, but not limited to, vesafb,
may result in
[   23.103694] NVRM: corruption and stability problems, and is not supported.
[ 3498.164413] gnome-shell[2688]: segfault at 7fffcdd1aff8 ip
7f057c289812 sp 7fffcdd1b000 error 6 in
libc-2.18.so[7f057c21+1a]


###  auth.log ###

Mar 30 18:17:01 BirdFarm0 CRON[4451]: PAM unable to
dlopen(pam_ldap.so): /lib/security/pam_ldap.so: cannot open shared
object file: No such file or directory
Mar 30 18:17:01 BirdFarm0 CRON[4451]: PAM adding faulty module: pam_ldap.so
Mar 30 18:17:01 BirdFarm0 CRON[4451]: pam_unix(cron:session): session
opened for user root by (uid=0)
Mar 30 18:17:01 BirdFarm0 CRON[4451]: pam_unix(cron:session): session
closed for user root
Mar 30 18:19:14 BirdFarm0 polkitd(authority=local): Unregistered
Authentication Agent for
unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name
:1.50, object path /org/freedesktop/PolicyKit1/AuthenticationAgent,
locale en_US.utf8) (disconnected from bus)
Mar 30 18:19:14 BirdFarm0 polkitd(authority=local): Operator of
unix-session:/org/freedesktop/ConsoleKit/Session2 FAILED to
authenticate to gain authorization for action
org.gnome.controlcenter.datetime.configure for
unix-process:4476:347791 [gnome-control-center datetime] (owned by
unix-user:miqu)
Mar 30 18:19:15 BirdFarm0 dbus[1136]: [system] Rejected send message,
2 matched rules; type=method_call, sender=:1.82 (uid=1000 pid=5392
comm=/usr/bin/gnome-shell )
interface=org.freedesktop.DBus.Properties member=GetAll error
name=(unset) requested_reply=0 destination=:1.16 (uid=0 pid=2030
comm=/usr/sbin/console-kit-daemon --no-daemon )
Mar 30 18:19:15 BirdFarm0 polkitd(authority=local): Registered
Authentication Agent for
unix-session:/org/freedesktop/ConsoleKit/Session2 (system bus name
:1.82 [/usr/bin/gnome-shell], object path
/org/freedesktop/PolicyKit1/AuthenticationAgent, locale en_US.utf8)
Mar 30 18:19:26 BirdFarm0 su[5556]: PAM unable to dlopen(pam_ldap.so):
/lib/security/pam_ldap.so: cannot open shared object file: No such
file or directory
Mar 30 18:19:26 BirdFarm0 su[5556]: PAM adding faulty module: pam_ldap.so
Mar 30 18:19:30 BirdFarm0 su[5556]: Successful su for root by miqu
Mar 30 18:19:30 BirdFarm0 su[5556]: + /dev/pts/0 miqu:root
Mar 30 18:19:30 BirdFarm0 su[5556]: pam_unix(su:session): session
opened for user root by miqu(uid=1000)

/var/log/kern.log

Mar 30 18:19:13 BirdFarm0 kernel: [ 3498.164413] gnome-shell[2688]:
segfault at 7fffcdd1aff8 ip 7f057c289812 sp 7fffcdd1b000 error
6 in libc-2.18.so[7f057c21+1a]

Please let me know if more info is needed.

Mika


Bug#722217: Updated the Nvidia driver from Experimental

2014-02-21 Thread Mika
 (= 2.14); however:
  Package libc6:amd64 is not configured yet.

dpkg: error processing package man-db (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of libc6-i386:
 libc6-i386 depends on libc6 (= 2.18-1); however:
  Package libc6:amd64 is not configured yet.

dpkg: error processing package libc6-i386 (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of locales:
 locales depends on glibc-2.18-1; however:
  Package glibc-2.18-1 is not installed.
  Package libc6:amd64 which provides glibc-2.18-1 is not configured yet.

dpkg: error processing package locales (--configure):
 dependency problems - leaving unconfigured
dpkg: dependency problems prevent configuration of nscd:
 nscd depends on libc6 ( 2.18); however:
  Package libc6:amd64 is not configured yet.
 nscd depends on libc6 ( 2.19); however:
  Package libc6:amd64 is not configured yet.

dpkg: error processing package nscd (--configure):
 dependency problems - leaving unconfigured
Errors were encountered while processing:
 libc6-dev:amd64
 libc6-dev:i386
 libc6:amd64
 man-db
 libc6-i386
 locales
 nscd

Anyhow thank you for a workaround. I couldnt reproduce it after once
setting mesa diverting. Maybe I could if I went back to the same situation
with istalling libc6 older version, running with Nvidia. But dont have time
right now.

Hope we can still find the culprit and fix it.

Thanks,
Mika


On Tue, Feb 4, 2014 at 10:41 AM, Mika mika.ras...@gmail.com wrote:

 Thanks for the info,

 I updated the drivers from experimental. I will try to find time to try
 replicating the bug later this evening if its fixed or not.



Bug#737681: synaptic: Apt-get, aptitude and synaptic quits with error immediately after start

2014-02-06 Thread Mika Rastas
Package: synaptic
Version: 0.80.4
Followup-For: Bug #737681

Dear Maintainer,

Well I checked and its not Synaptics fault. Other front ends fail also. It
seems to be that my hard drive is failing. So I suppose you can close this bug.

Sorry for the inconvenience,

Mika



-- System Information:
Debian Release: jessie/sid
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.12-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages synaptic depends on:
ii  hicolor-icon-theme   0.13-1
ii  libapt-inst1.5   0.9.15
ii  libapt-pkg4.12   0.9.15
ii  libatk1.0-0  2.10.0-2
ii  libc62.17-92
ii  libcairo-gobject21.12.16-2
ii  libcairo21.12.16-2
ii  libept1.4.12 1.0.12
ii  libgcc1  1:4.8.2-14
ii  libgdk-pixbuf2.0-0   2.28.2-1+b1
ii  libglib2.0-0 2.37.5-1
ii  libgtk-3-0   3.9.14-1
ii  libpango-1.0-0   1.36.0-1+b1
ii  libpangocairo-1.0-0  1.36.0-1+b1
ii  libstdc++6   4.8.2-14
ii  libvte-2.90-91:0.34.9-1
ii  libx11-6 2:1.6.2-1
ii  libxapian22  1.2.17-1
ii  libxext6 2:1.3.2-1
ii  zlib1g   1:1.2.8.dfsg-1

Versions of packages synaptic recommends:
ii  gksu   2.0.2-6
ii  libgtk2-perl   2:1.249-1
ii  policykit-10.105-4
ii  rarian-compat  0.8.1-5

Versions of packages synaptic suggests:
ii  apt-xapian-index 0.46
ii  deborphan1.7.28.8
ii  dwww 1.12.1
ii  menu 2.1.46
ii  software-properties-gtk  0.92.25debian1
ii  tasksel  3.20

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#722217: Updated the Nvidia driver from Experimental

2014-02-04 Thread Mika
Thanks for the info,

I updated the drivers from experimental. I will try to find time to try
replicating the bug later this evening if its fixed or not.


Bug#737681: synaptic: quits with error immediately after start

2014-02-04 Thread Mika Rastas
Package: synaptic
Version: 0.80.4
Severity: important

Dear Maintainer,

I, opened terminal, ran su and then synaptic.

Synaptic tries to start but gives an error and quits after I click on the
error.

Here is the error dialog:

E: Read error - read (5 Input/output error)
E: The package lists or status file could not be parsed or opened.
E: _cache-open() failed, please report.

Here is the console output:

root@Xx:/home/ss# synaptic
Traceback (most recent call last):
  File /usr/sbin/update-apt-xapian-index, line 97, in module
if not indexer.setupIndexing(force=opts.force, system=opts.pkgfile is
None):
  File /usr/lib/pymodules/python2.7/axi/indexer.py, line 518, in
setupIndexing
addon.obj.init(dict(values=self.values), self.progress)
  File /usr/share/apt-xapian-index/plugins/translated-desc.py, line 105, in
init
self.indexers.append(Indexer(lang, file))
  File /usr/share/apt-xapian-index/plugins/translated-desc.py, line 41, in
__init__
for pkg in deb822.Deb822.iter_paragraphs(open(file)):
  File /usr/lib/python2.7/dist-packages/debian/deb822.py, line 371, in
iter_paragraphs
for section in parser:
SystemError: E:Read error - read (5: Input/output error)
Traceback (most recent call last):
  File /usr/sbin/update-apt-xapian-index, line 97, in module
if not indexer.setupIndexing(force=opts.force, system=opts.pkgfile is
None):
  File /usr/lib/pymodules/python2.7/axi/indexer.py, line 518, in
setupIndexing
addon.obj.init(dict(values=self.values), self.progress)
  File /usr/share/apt-xapian-index/plugins/translated-desc.py, line 105, in
init
self.indexers.append(Indexer(lang, file))
  File /usr/share/apt-xapian-index/plugins/translated-desc.py, line 41, in
__init__
for pkg in deb822.Deb822.iter_paragraphs(open(file)):
  File /usr/lib/python2.7/dist-packages/debian/deb822.py, line 371, in
iter_paragraphs
for section in parser:
SystemError: E:Read error - read (5: Input/output error)



-- System Information:
Debian Release: jessie/sid
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.12-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages synaptic depends on:
ii  hicolor-icon-theme   0.13-1
ii  libapt-inst1.5   0.9.15
ii  libapt-pkg4.12   0.9.15
ii  libatk1.0-0  2.10.0-2
ii  libc62.17-92
ii  libcairo-gobject21.12.16-2
ii  libcairo21.12.16-2
ii  libept1.4.12 1.0.12
ii  libgcc1  1:4.8.2-14
ii  libgdk-pixbuf2.0-0   2.28.2-1+b1
ii  libglib2.0-0 2.37.5-1
ii  libgtk-3-0   3.9.14-1
ii  libpango-1.0-0   1.36.0-1+b1
ii  libpangocairo-1.0-0  1.36.0-1+b1
ii  libstdc++6   4.8.2-14
ii  libvte-2.90-91:0.34.9-1
ii  libx11-6 2:1.6.2-1
ii  libxapian22  1.2.17-1
ii  libxext6 2:1.3.2-1
ii  zlib1g   1:1.2.8.dfsg-1

Versions of packages synaptic recommends:
ii  gksu   2.0.2-6
ii  libgtk2-perl   2:1.249-1
ii  policykit-10.105-4
ii  rarian-compat  0.8.1-5

Versions of packages synaptic suggests:
ii  apt-xapian-index 0.46
ii  deborphan1.7.28.8
ii  dwww 1.12.1
ii  menu 2.1.46
ii  software-properties-gtk  0.92.25debian1
ii  tasksel  3.20

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#722217: legacy304 also

2014-01-28 Thread Mika
I have Nvidia's newest driver 331.20-2 so its not only on Legacy drivers.

Dpkg is 1.17.6 now. I don't know did I already try an upgrade with this
dpkg version. I have the libc packages now pinned so I can use my system.

Kernel and kbuild packages are version 3.12.6.

I tried an upgrade a few weeks ago and the bug was still there.


Mika



On Fri, Dec 20, 2013 at 6:35 PM, Wendy J. Elmer webe...@aim.com wrote:



 What version of dpkg are you using?  Could it be this problem?

 dpkg (1.17.5) unstable; urgency=low

   [ Guillem Jover ]
 [...]
   * Fix segfault in update-alternatives when adding or renaming slaves for
 an existing alternative. Regression introduced in dpkg 1.17.2.
 Closes: #731710


  dpkg 1.16.12 from jessie/testing

 Brent



Bug#724890: /usr/sbin/ndiswrapper: Ndiswrapper fails with sh: 1: Syntax error: end of file unexpected

2013-09-29 Thread Mika Rastas
Package: ndiswrapper-common
Version: 1.58-2
Severity: important
File: /usr/sbin/ndiswrapper

Dear Maintainer,

I got a used pci wlan card that happens to be mrv8355 and needs ndiswrapper to 
work. I found that out from the Debian wiki here: 
https://wiki.debian.org/libertas#Supported_Devices

The Ndiswrapper Debian wiki page https://wiki.debian.org/NdisWrapper

I also checked here https://help.ubuntu.com/community/WifiDocs/Driver/mrv8k

So here is what I did and the results on command line.

miqu@TFC-1:~$ su
Salasana: 
root@TFC-1:/home/miqu# cd Lataukset/
root@TFC-1:/home/miqu/Lataukset# ndiswrapper -i mrv8335.
install argument must be .inf file
root@TFC-1:/home/miqu/Lataukset# ndiswrapper -i mrv8335.inf 
driver mrv8335 is already installed
root@TFC-1:/home/miqu/Lataukset# ndiswrapper -l
mrv8335 : driver installed
device (11AB:1FAA) present
root@TFC-1:/home/miqu/Lataukset# modprobe ndiswrapper
root@TFC-1:/home/miqu/Lataukset# iwconfig
usb0  no wireless extensions.

ppp0  no wireless extensions.

eth0  no wireless extensions.

lono wireless extensions.

usbpn0no wireless extensions.

root@TFC-1:/home/miqu/Lataukset# ndiswrapper -m
adding alias wlan0 ndiswrapper to  ...
sh: 1: Syntax error: end of file unexpected
couldn't add module alias:  at /usr/sbin/ndiswrapper-1.9 line 882.
root@TFC-1:/home/miqu/Lataukset# depmod -a
root@TFC-1:/home/miqu/Lataukset# 

After reboot another try no change. I suspected the lines to be added to the 
file /usr/sbin/ndiswrapper-1.9 are needed for things to load up. 

If I can help tracing this down anyhow please let me know.


-- System Information:
Debian Release: jessie/sid
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'unstable'), (500, 'testing'), 
(500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.10-3-amd64 (SMP w/1 CPU core)
Locale: LANG=fi_FI.utf8, LC_CTYPE=fi_FI.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

ndiswrapper-common depends on no packages.

ndiswrapper-common recommends no packages.

Versions of packages ndiswrapper-common suggests:
ii  ndiswrapper-source  1.58-2

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#673589: gnome-online-accounts: Gnome account expired after last update

2013-09-12 Thread Mika Rastas
Package: gnome-online-accounts
Version: 3.8.3-1
Followup-For: Bug #673589

Dear Maintainer,

I updated my Sid system yesterday. After a reboot the accounts were expired. 
Tried to re enter credentials but gnome control center hangs after I enter the 
credentials. I killed gnome control center after waiting for a while and tried 
to run gnome-online-accounts from console and it gave the error libgcr-... not 
found. Then I found this bug and read about that workaround. After a reboot it 
now works.

Here is the list of updates I did yesterday.

Commit Log for Thu Sep 12 00:12:45 2013

Upgraded the following packages:
apt (0.9.11.2) to 0.9.11.3
apt-utils (0.9.11.2) to 0.9.11.3
geoclue (0.12.99-2) to 0.12.99-3
geoclue-hostip (0.12.99-2) to 0.12.99-3
geoclue-localnet (0.12.99-2) to 0.12.99-3
geoclue-manual (0.12.99-2) to 0.12.99-3
geoclue-yahoo (0.12.99-2) to 0.12.99-3
gir1.2-goa-1.0 (3.8.2-1) to 3.8.3-1
gnash (0.8.11~git20130903-2) to 0.8.11~git20130903-3
gnash-common (0.8.11~git20130903-2) to 0.8.11~git20130903-3
gnome-online-accounts (3.8.2-1) to 3.8.3-1
libapt-inst1.5 (0.9.11.2) to 0.9.11.3
libapt-pkg4.12 (0.9.11.2) to 0.9.11.3
libclone-perl (0.34-1+b1) to 0.35-1
libgegl-0.2-0 (0.2.0-3+b1) to 0.2.0-4
libgeoclue0 (0.12.99-2) to 0.12.99-3
libgmime-2.6-0 (2.6.16-1) to 2.6.17-1
libgmime2.6-cil (2.6.16-1) to 2.6.17-1
libgoa-1.0-0 (3.8.2-1) to 3.8.3-1
libgoa-1.0-common (3.8.2-1) to 3.8.3-1
libkpathsea6 (2013.20130729.30972-1) to 2013.20130729.30972-2
libnewt0.52 (0.52.15-2+b1) to 0.52.15-3
libparted0debian1 (2.3-15) to 2.3-16
libsqlite3-0 (3.8.0.1-1) to 3.8.0.2-1
libsqlite3-0:i386 (3.8.0.1-1) to 3.8.0.2-1
libsqlite3-dev (3.8.0.1-1) to 3.8.0.2-1
libusb-1.0-0 (2:1.0.16-3) to 2:1.0.17-1
libusb-1.0-0-dev (2:1.0.16-3) to 2:1.0.17-1
libusb-1.0-0:i386 (2:1.0.16-3) to 2:1.0.17-1
p11-kit (0.18.5-1) to 0.18.5-3
parted (2.3-15) to 2.3-16
steam-launcher (1.0.0.41) to 1.0.0.42
steam:i386 (1.0.0.41) to 1.0.0.42
synaptic (0.80.2) to 0.80.3
telepathy-gabble (0.18.0-1) to 0.18.1-1
telepathy-rakia (0.7.4-1) to 0.7.5-1
whiptail (0.52.15-2+b1) to 0.52.15-

Hope this helps,
Mika

-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.10-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages gnome-online-accounts depends on:
ii  libc62.17-92
ii  libgcr-base-3-1  3.8.2-4
ii  libglib2.0-0 2.37.5-1
ii  libgoa-1.0-0 3.8.3-1
ii  libkrb5-31.11.3+dfsg-3
ii  librest-0.7-00.7.12-3
ii  libsoup2.4-1 2.42.2-6

Versions of packages gnome-online-accounts recommends:
ii  gnome-control-center  1:3.8.3-1

gnome-online-accounts suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#673589: gnome-online-accounts: Google account credentials expire immediately after login

2013-09-12 Thread Mika Rastas
Package: gnome-online-accounts
Version: 3.8.3-1
Followup-For: Bug #673589

Dear Maintainer,
*** Please consider answering these questions, where appropriate ***

So my earlier info was incomplete. I found this bug #717945 in libgcr that
might be related to my problem. The workaround was also from that report.

The Gnome upstream had deemed this bug to be related to two factor
authentication with the original reporter. My situation is not related to two
factor authentication as I am not using it. Maybe a name change for this bug
and another bug that links to libgcr would clear things up.

*** End of the template - remove these lines ***



-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.10-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages gnome-online-accounts depends on:
ii  libc62.17-92
ii  libgcr-base-3-1  3.8.2-4
ii  libglib2.0-0 2.37.5-1
ii  libgoa-1.0-0 3.8.3-1
ii  libkrb5-31.11.3+dfsg-3
ii  librest-0.7-00.7.12-3
ii  libsoup2.4-1 2.42.2-6

Versions of packages gnome-online-accounts recommends:
ii  gnome-control-center  1:3.8.3-1

gnome-online-accounts suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#722217: libc6: Update fails halfway with segfault

2013-09-09 Thread Mika Rastas
Package: libc6
Version: 2.17-92+b1
Severity: important

Dear Maintainer,

I was updating my Sid / experimental system through synaptic. Selected update 
all. After some of the libc6 multiarch packages were updated the installation 
of the rest of libc6 packages failed due to a segfault on installation of 
another libc6 dependant package.

Here is the term.log from apt. 

Preparing to replace libc6-dev-x32 2.17-92 (using 
.../libc6-dev-x32_2.17-92+b1_amd64.deb) ...
Unpacking replacement libc6-dev-x32 ...
Preparing to replace libc6-x32 2.17-92 (using 
.../libc6-x32_2.17-92+b1_amd64.deb) ...
Unpacking replacement libc6-x32 ...
Preparing to replace libc6-dev-i386 2.17-92 (using 
.../libc6-dev-i386_2.17-92+b1_amd64.deb) ...
Unpacking replacement libc6-dev-i386 ...
Preparing to replace libc6-i386 2.17-92 (using 
.../libc6-i386_2.17-92+b1_amd64.deb) ...
Unpacking replacement libc6-i386 ...
Replaced by files in installed package libc6:i386 ...
Preparing to replace libc6-dev:i386 2.17-92 (using 
.../libc6-dev_2.17-92+b1_i386.deb) ...
De-configuring libc6-dev:amd64 ...
Unpacking replacement libc6:amd64 ...
Preparing to replace libc6:i386 2.17-92 (using .../libc6_2.17-92+b1_i386.deb) 
...
dpkg: error processing /var/cache/apt/archives/libc6_2.17-92+b1_i386.deb 
(--unpack):
 subprocess new pre-installation script was killed by signal (Segmentation 
fault)
Preparing to replace libgcc1:amd64 1:4.8.1-9 (using 
.../libgcc1_1%3a4.8.1-10_amd64.deb) ...
De-configuring libgcc1:i386 ...
Unpacking replacement libgcc1:amd64 ...
Preparing to replace libgcc1:i386 1:4.8.1-9 (using 
.../libgcc1_1%3a4.8.1-10_i386.deb) ...


I restored the system by manually installing libc6 2.17-92 packages from 
/var/cache/apt/arhives/


-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.10-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#722223: pangoft: GIMP 2.8 segfaults when selecting fonts

2013-09-09 Thread Mika Rastas
Package: libpangoft2-1.0-0
Version: 1.32.5-5+b1
Severity: important
File: pangoft

Dear Maintainer,

Use Gimp to add and edit text. Use toolbar to select font for the text and 
scroll for the one you want. After a while of scrolling Gimp crashes. I 
searched the logs for signs and found this in kern.log.
Sep  6 11:16:52 this kernel: [11329.417012] gimp-2.8[31007]: segfault at 58 ip 
7f0d6403771e sp 7fffb6e23990 error 4 in 
libpangoft2-1.0.so.0.3200.5[7f0d64028000+15000]

Tried again and everytime I scroll fonts it segfaults. I can select font by 
writing the real font name.



-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.10-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages libpangoft2-1.0-0:amd64 depends on:
ii  libc6  2.17-92
ii  libfontconfig1 2.10.2-2
ii  libfreetype6   2.4.9-1.1
ii  libglib2.0-0   2.37.5-1
ii  libharfbuzz0a  0.9.19-1
ii  libpango-1.0-0 1.32.5-5+b1
ii  multiarch-support  2.17-92+b1

libpangoft2-1.0-0:amd64 recommends no packages.

libpangoft2-1.0-0:amd64 suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#721085: graphite-web: Please update to 0.9.12 to work with Django 1.5

2013-08-27 Thread Mika Boström
Package: graphite-web
Version: 0.9.10+debian-2
Severity: normal

The current version does not work with Django 1.5, which has been the
default in unstable since late March. The problem is due to changed
settings and the newly required SECRET_KEY configuration token, which is
not applied even if available in /etc/graphite/local_settings.py

This configuration option is mandatory, so graphite-web no longer starts
when running with Django 1.5:

$ grep SECRET_KEY /etc/graphite/local_settings.py 
SECRET_KEY='XXX123456789'
$ whoami
_graphite
$ /usr/bin/graphite-manage runfcgi socket=/run/graphite/graphite.sock \
  pidfile=/run/graphite/graphite-fcgi.pid daemonize=true umask=002
ImproperlyConfigured: The SECRET_KEY setting must not be empty.


More information and the necessary patch available from
https://github.com/graphite-project/graphite-web/pull/394 ; should be
included in 0.9.12.


-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.10-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=fi_FI.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages graphite-web depends on:
ii  adduser3.113+nmu3
ii  libjs-jquery   1.7.2+dfsg-3
ii  libjs-jquery-flot  0.8.1+dfsg-2
ii  libjs-prototype1.7.1-3
ii  libjs-scriptaculous1.9.0-2
ii  python 2.7.5-4
ii  python-cairo   1.8.8-1+b2
ii  python-django  1.5.2-1
ii  python-django-tagging  0.3.1-2
ii  python-pyparsing   1.5.7+dfsg1-2
ii  python-simplejson  3.3.0-3
ii  python-sqlite  1.0.1-9
ii  python-tz  2012c-1
ii  python-whisper 0.9.10-1

graphite-web recommends no packages.

Versions of packages graphite-web suggests:
ii  graphite-carbon  0.9.10-4
pn  libapache2-mod-wsgi  none
pn  python-ldap  none
pn  python-memcache  none
pn  python-mysqldb   none

-- Configuration Files:
/etc/graphite/local_settings.py changed [not included]

-- no debconf information

-- 
 Mika Boström   Individualisti, eksistentialisti,
 www.iki.fi/bostik  rationalisti ja mulkvisti
 GPG: 0x2AED22CC; 6FC9 8375 31B7 3BA2 B5DC  484E F19F 8AD6 2AED 22CC


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#719743: selinux-policy-default: GDM3 doesn't load in permissive mode

2013-08-15 Thread Mika Pflüger
Hi Kees,

could you post the output of:
# semodule -l
# sestatus
# cat /var/log/gdm3/:0.log
# cat /var/log/gdm3/:0-greeter.log
# cat /var/log/gdm3/:0-slave.log

I am running testing (with the same policy as 7/wheezy) in permissive
mode without problems, so we need to figure out what is different in
your setup.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#503565: [DSE-Dev] Bug#503565: closed by Mika Pflüger deb...@mikapflueger.de (Old and unreproducible)

2013-08-09 Thread Mika Pflüger
Hi,

Am Thu, 8 Aug 2013 23:41:06 +0200
schrieb Julien Cristau jul...@cristau.org:
 With resolvconf installed and the bind hook configured?

With resolvconf installed but without bind hook – the bind hook was
removed some time ago (see #697435). Now, you /can/ of course write
your own hook for bind or copy the one from resolvconf's doc
repository; however, I think than you have to write the relevant parts
of policy yourself (possibly using audit2allow).

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#690087: Can't reproduce with -13

2013-08-08 Thread Mika Pflüger
Hi,

I can't reproduce this bug. What I did:
* Install a fresh wheezy with task standard and openssh-server.
* apt-get install selinux-basics auditd
* selinux-activate; reboot; selinux-config-enforcing; reboot
* adduser unconf
* adduser conf
* semanage login -a -s user_u conf

Then semanage login -l shows:
Login Name SELinux User MLS/MCS Range

__default__unconfined_u SystemLow-SystemHigh
conf   user_u   SystemLow
root   unconfined_u SystemLow-SystemHigh
system_u   system_u SystemLow-SystemHigh

Also, ps -eZ|grep sshd shows that sshd actually has categories:
LABEL   PID  TTY TIME CMD
system_u:system_r:sshd_t:s0-s0:c0.c1023 2585 ?   00:00:00 sshd

I can log in via ssh for both users, unconf and conf:
conf@setest:~$ id -Z
user_u:user_r:user_t:SystemLow

unconf@setest:~$ id -Z
unconfined_u:unconfined_r:unconfined_t:SystemLow-SystemHigh


Either the bug was fixed in the meantime or I don't understand where
the bug actually is.

Cheers,

Mika

-- 


signature.asc
Description: PGP signature


Bug#716753: Not an important bug

2013-08-08 Thread Mika Pflüger
Severity 716753 normal
Thanks

As far as I can see the effect of the missing setsched is only that the
regeneration of ssl dh parameters cannot be nice'd and therefore runs
with higher priority than would be necessary, possibly congesting the
system. As the core functionality (regenerate ssl dh parameters) is not
affected, this is not an important bug. And the spurious AVC denial is
annoying, but not important either.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#707243: Does anything break?

2013-08-08 Thread Mika Pflüger
Hi,

does anything break, or is it just a spurious AVC denial? If no
important functionality of irqbalance is lost, it may not be worth
fixing this in stable, we could just forward a fix upstream and wait
until it trickles back to debian.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#707293: default (chrooted) configuration of postfix is not supported by selinux policy; won't be

2013-08-08 Thread Mika Pflüger
Hi,

as mentioned in the wiki, the debian default configuration of postfix
(chrooted) is not supported by selinux policy. Please use the script
postfix-nochroot to unchroot your configuration.

Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#709752: mplayer: Linked against missing libssl.so.0.9.8

2013-05-25 Thread Mika Mäenpää
Package: mplayer
Version: 2:1.0~rc4.dfsg1+svn34540-1+b2
Severity: grave
Justification: renders package unusable

It seems that mplayer is linked against obsolete package libssl0.9.8 in amd64 
architecture.

When I try to start mplayer, I get the following message:

  mplayer: error while loading shared libraries: libssl.so.0.9.8: cannot open 
  shared object file: No such file or directory

-- System Information:
Debian Release: 7.0
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.2.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=fi_FI.UTF-8, LC_CTYPE=fi_FI.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages mplayer depends on:
ii  libaa11.4p5-40
ii  libasound21.0.25-4
ii  libavcodec-extra-53   6:0.8.6-1
ii  libavformat53 6:0.8.6-1
ii  libavutil51   6:0.8.6-1
ii  libbluray11:0.2.2-1
ii  libc6 2.13-38
ii  libcaca0  0.99.beta18-1
ii  libcdparanoia03.10.2+debian-10.1
ii  libdca0   0.0.5-5
ii  libdirectfb-1.2-9 1.2.10.0-5
ii  libdvdnav44.2.0+20120524-2
ii  libdvdread4   4.2.0+20120521-2
ii  libenca0  1.13-4
ii  libesd0   0.2.41-10+b1
ii  libfaad2  2.7-8
ii  libfontconfig12.9.0-7.1
ii  libfreetype6  2.4.9-1.1
ii  libfribidi0   0.19.2-3
ii  libgcc1   1:4.7.2-5
ii  libgif4   4.1.6-10
ii  libgl1-mesa-glx [libgl1]  8.0.5-4+deb7u1
ii  libjack-jackd2-0 [libjack-0.116]  1.9.8~dfsg.4+20120529git007cdc37-5
ii  libjpeg8  8d-1
ii  liblircclient00.9.0~pre1-1
ii  liblzo2-2 2.06-1
ii  libmp3lame0   3.99.5+repack1-3
ii  libmpeg2-40.4.1-3
ii  libncurses5   5.9-10
ii  libogg0   1.3.0-4
ii  libopenal11:1.14-4
ii  libpng12-01.2.49-1
ii  libpostproc52 6:0.8.6-1
ii  libpulse0 2.0-6.1
ii  libsdl1.2debian   1.2.15-5
ii  libsmbclient  2:3.6.6-6
ii  libspeex1 1.2~rc1-7
ii  libstdc++64.7.2-5
ii  libsvga1  1:1.4.3-33
ii  libswscale2   6:0.8.6-1
ii  libtheora01.1.1+dfsg.1-3.1
ii  libtinfo5 5.9-10
ii  libvdpau1 0.4.1-7
ii  libx11-6  2:1.5.0-1+deb7u1
ii  libx264-123   2:0.123.2189+git35cf912-1
ii  libxext6  2:1.3.1-2+deb7u1
ii  libxinerama1  2:1.1.2-1+deb7u1
ii  libxv12:1.0.7-1+deb7u1
ii  libxvidcore4  2:1.3.2-9
ii  libxvmc1  2:1.0.7-1+deb7u2
ii  libxxf86dga1  2:1.1.3-2+deb7u1
ii  libxxf86vm1   1:1.1.2-1+deb7u1
ii  zlib1g1:1.2.7.dfsg-13

mplayer recommends no packages.

Versions of packages mplayer suggests:
ii  bzip2  1.0.6-4
ii  fontconfig 2.9.0-7.1
ii  fonts-freefont-ttf [ttf-freefont]  20120503-1
pn  mplayer-docnone
pn  netselect | fping  none
ii  ttf-freefont   20120503-1

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#709752: mplayer: Linked against missing libssl.so.0.9.8

2013-05-25 Thread Mika Mäenpää
2013/5/25 Adam D. Barratt a...@adam-barratt.org.uk:

 Please could you run which mplayer and ldd $(which mplayer) and
 provide the result?

 Regards,

 Adam


which mplayer
  /usr/bin/mplayer

ldd $(which mplayer)
linux-vdso.so.1 =  (0x7fff489ff000)
libm.so.6 = /lib/x86_64-linux-gnu/libm.so.6 (0x7fd7406df000)
libncurses.so.5 = /lib/x86_64-linux-gnu/libncurses.so.5
(0x7fd7404bd000)
libtinfo.so.5 = /lib/x86_64-linux-gnu/libtinfo.so.5 (0x7fd740293000)
libsmbclient.so.0 = /usr/lib/x86_64-linux-gnu/libsmbclient.so.0
(0x7fd73fad3000)
libpng12.so.0 = /lib/x86_64-linux-gnu/libpng12.so.0 (0x7fd73f8ac000)
libz.so.1 = /lib/x86_64-linux-gnu/libz.so.1 (0x7fd73f694000)
libjpeg.so.8 = /usr/lib/x86_64-linux-gnu/libjpeg.so.8 (0x7fd73f45a000)
libgif.so.4 = /usr/lib/libgif.so.4 (0x7fd73f251000)
libasound.so.2 = /usr/lib/x86_64-linux-gnu/libasound.so.2
(0x7fd73ef5c000)
libdl.so.2 = /lib/x86_64-linux-gnu/libdl.so.2 (0x7fd73ed58000)
libpthread.so.0 = /lib/x86_64-linux-gnu/libpthread.so.0
(0x7fd73eb3c000)
libbluray.so.1 = /usr/lib/x86_64-linux-gnu/libbluray.so.1
(0x7fd73e90b000)
libdvdread.so.4 = /usr/lib/x86_64-linux-gnu/libdvdread.so.4
(0x7fd73e6ed000)
libcdda_interface.so.0 = /usr/lib/libcdda_interface.so.0
(0x7fd73e4dd000)
libcdda_paranoia.so.0 = /usr/lib/libcdda_paranoia.so.0 (0x7fd73e2d4000)
libfreetype.so.6 = /usr/lib/x86_64-linux-gnu/libfreetype.so.6
(0x7fd73e035000)
libfontconfig.so.1 = /usr/lib/x86_64-linux-gnu/libfontconfig.so.1
(0x7fd73ddfe000)
libfribidi.so.0 = /usr/lib/x86_64-linux-gnu/libfribidi.so.0
(0x7fd73dbe7000)
libenca.so.0 = /usr/lib/libenca.so.0 (0x7fd73d9b4000)
liblzo2.so.2 = /usr/lib/x86_64-linux-gnu/liblzo2.so.2 (0x7fd73d794000)
libspeex.so.1 = /usr/lib/x86_64-linux-gnu/libspeex.so.1
(0x7fd73d57b000)
libtheoradec.so.1 = /usr/lib/x86_64-linux-gnu/libtheoradec.so.1
(0x7fd73d35f000)
libogg.so.0 = /usr/lib/x86_64-linux-gnu/libogg.so.0 (0x7fd73d159000)
libmpeg2.so.0 = /usr/lib/libmpeg2.so.0 (0x7fd73cf3f000)
libdca.so.0 = /usr/lib/libdca.so.0 (0x7fd73cd17000)
libfaad.so.2 = /usr/lib/x86_64-linux-gnu/libfaad.so.2 (0x7fd73cad6000)
libstdc++.so.6 = /usr/lib/x86_64-linux-gnu/libstdc++.so.6
(0x7fd73c7ce000)
libpostproc.so.52 = /usr/lib/x86_64-linux-gnu/libpostproc.so.52
(0x7fd73c5a6000)
libswscale.so.2 = /usr/lib/x86_64-linux-gnu/libswscale.so.2
(0x7fd73c35e000)
libavformat.so.53 = /usr/lib/x86_64-linux-gnu/libavformat.so.53
(0x7fd73c057000)
libavcodec.so.53 = /usr/lib/x86_64-linux-gnu/libavcodec.so.53
(0x7fd73b1d)
libavutil.so.51 = /usr/lib/x86_64-linux-gnu/libavutil.so.51
(0x7fd73afaf000)
libxvidcore.so.4 = /usr/lib/x86_64-linux-gnu/libxvidcore.so.4
(0x7fd73ac77000)
libdvdnavmini.so.4 = /usr/lib/x86_64-linux-gnu/libdvdnavmini.so.4
(0x7fd73aa62000)
libdirectfb-1.2.so.9 =
/usr/lib/x86_64-linux-gnu/libdirectfb-1.2.so.9 (0x7fd73a7dd000)
libXext.so.6 = /usr/lib/x86_64-linux-gnu/libXext.so.6 (0x7fd73a5ca000)
libX11.so.6 = /usr/lib/x86_64-linux-gnu/libX11.so.6 (0x7fd73a28f000)
libXv.so.1 = /usr/lib/x86_64-linux-gnu/libXv.so.1 (0x7fd73a08a000)
libXvMC.so.1 = /usr/lib/libXvMC.so.1 (0x7fd739e86000)
libXvMCW.so.1 = /usr/lib/libXvMCW.so.1 (0x7fd739c82000)
libvdpau.so.1 = /usr/lib/x86_64-linux-gnu/libvdpau.so.1
(0x7fd739a7e000)
libXinerama.so.1 = /usr/lib/x86_64-linux-gnu/libXinerama.so.1
(0x7fd73987b000)
libXxf86vm.so.1 = /usr/lib/x86_64-linux-gnu/libXxf86vm.so.1
(0x7fd739675000)
libXxf86dga.so.1 = /usr/lib/x86_64-linux-gnu/libXxf86dga.so.1
(0x7fd73946f000)
libaa.so.1 = /usr/lib/x86_64-linux-gnu/libaa.so.1 (0x7fd73924e000)
libcaca.so.0 = /usr/lib/x86_64-linux-gnu/libcaca.so.0 (0x7fd739181000)
libvga.so.1 = /usr/lib/x86_64-linux-gnu/libvga.so.1 (0x7fd738f22000)
libSDL-1.2.so.0 = /usr/lib/x86_64-linux-gnu/libSDL-1.2.so.0
(0x7fd738c85000)
libGL.so.1 = /usr/lib/x86_64-linux-gnu/libGL.so.1 (0x7fd738968000)
libesd.so.0 = /usr/lib/x86_64-linux-gnu/libesd.so.0 (0x7fd73875d000)
libpulse.so.0 = /usr/lib/x86_64-linux-gnu/libpulse.so.0
(0x7fd738512000)
libjack.so.0 = /usr/lib/x86_64-linux-gnu/libjack.so.0 (0x7fd7382ba000)
libopenal.so.1 = /usr/lib/x86_64-linux-gnu/libopenal.so.1
(0x7fd73806)
libx264.so.123 = /usr/lib/x86_64-linux-gnu/libx264.so.123
(0x7fd737cd7000)
libmp3lame.so.0 = /usr/lib/x86_64-linux-gnu/libmp3lame.so.0
(0x7fd737a4d000)
liblirc_client.so.0 = /usr/lib/liblirc_client.so.0 (0x7fd737847000)
libgcc_s.so.1 = /lib/x86_64-linux-gnu/libgcc_s.so.1 (0x7fd73763)
libc.so.6 = /lib/x86_64-linux-gnu/libc.so.6 (0x7fd7372a6000)
libtalloc.so.2 = /usr/lib/x86_64-linux-gnu/libtalloc.so.2
(0x7fd73709b000)
libtdb.so.1 = 

Bug#709752: mplayer: Linked against missing libssl.so.0.9.8

2013-05-25 Thread Mika Mäenpää
 librtmp.so.0 = /home/pulmu/lib/librtmp.so.0 (0x7fd735257000)

 This looks like a good candidate. What happens if you move this local
 library out of the way?

 I've confirmed that the equivalent check on a wheezy install here does
 include librtmp.so.0 but does not feature any references to any version
 of libssl.

 Regards,

 Adam


Yes. That was causing the problem. It seems that after I upgraded to
Wheezy I forgot to recompile my local copy of librtmp.
Thanks.


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#706632: Re: Bug#706632: efibootmgr present in Debian Wheezy RC2 is not able to create new entries to boot

2013-05-12 Thread Mika
Thanks Steve,

I Removed the entries of Windows from UEFI with efibootmgr. So it can make
some changes to UEFI. Then I tried to add the entries for Debian again and
still it didn't work. I feel there is some problem in writing entries to
Uefi with the newer versions of efibootmgr. Since Steve's Debian installer
for UEFI update4 boot CD worked on install on the same hardware.

Right now I am using SuperGrub2 CD with uefi boot from CD drive to find the
Debian grubx64.efi and boot that.

I am going to try the old install CD for recovery again.


Bug#707544: synaptic: After Update Synaptic Fails to Change Preferred Version

2013-05-09 Thread Mika Rastas
Package: synaptic
Version: 0.80
Severity: important

Dear Maintainer,

I updated synaptic and tried to check what versions of software are available 
from Experimental. So I went to Settings, Preferences, Distribution and 
selected Prefer versions from Experimental. Clicked apply and Ok. Checked what 
is available in Installed(upgradable) And it didn't reload as before it did. 
Went back to check what is selected in the Preferences menu and its still the 
original value. Tried again and saw that it had dublicated the entries in the 
Prefer versions from: Combobox. 

I expected it to select Experimental and to update the upgradeable software 
item to show the experimental software updates.

Here is the console output from the situation:

[1]+  Stopped synaptic
root@Computer0:/home/Me# fg
synaptic

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_remove: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed

(synaptic:4862): GLib-GObject-WARNING **: invalid cast from `GtkComboBox' to 
`GtkComboBoxText'

(synaptic:4862): Gtk-CRITICAL **: gtk_combo_box_text_get_active_text: assertion 
`GTK_IS_COMBO_BOX_TEXT (combo_box)' failed



-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.8-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages synaptic depends on:
ii  hicolor-icon-theme  0.12-1
ii  libapt-inst1.5  0.9.8
ii  libapt-pkg4.12  0.9.8
ii  libatk1.0-0 2.8.0-1
ii  libc6   2.17-1
ii  libcairo-gobject2   1.12.14-4
ii  libcairo2   1.12.14-4
ii  libept1.4.121.0.9
ii  libgcc1 1:4.8.0-6
ii  libgdk-pixbuf2.0-0  2.28.1-1
ii  libglib2.0-02.36.1-2
ii  libgtk-3-0  3.8.0-1
ii  libpango1.0-0   1.32.5-4
ii  libstdc++6  4.8.0-6
ii  libvte-2.90-9   1:0.34.3-1
ii  libx11-62:1.5.0-1
ii  libxapian22 1.2.12-2
ii  libxext62:1.3.1-2
ii  zlib1g  1:1.2.8.dfsg-1

Versions of packages synaptic recommends:
ii  gksu   2.0.2-6
ii  libgtk2-perl   2:1.247-1
ii  policykit-10.105-3
ii  rarian-compat  0.8.1-5

Versions of packages synaptic suggests:
ii  apt-xapian-index 0.45
ii  deborphan1.7.28.8
ii  dwww 1.11.8
ii  menu 2.1.46

Bug#707658: selinux-policy-default: dhclient fails to bind generic udp ports

2013-05-09 Thread Mika Pflueger
Package: selinux-policy-default
Version: 2:2.20110726-12
Severity: important
Tags: patch

Hi,

with a standard 
 allow-hotplug eth0
 iface eth0 inet dhcp
directive in /etc/network/interfaces, a system with selinux enabled in 
enforcing mode
fails to configure eth0 via dhcp because the dhclient is denied to bind to a 
generic
udp port (from dmesg, auditd is not yet running at this point):
type=1400 audit(1368139483.940:3): avc:  denied  { name_bind } for  pid=1646 
comm=dhclient src=15087 scontext=system_u:system_r:dhcpc_t:s0-s0:c0.c1023 
tcontext=system_u:object_r:port_t:s0 tclass=udp_socket

Looking in the fedora policy, I found that they simply allow dhcpc_t to bind to 
all
udp ports since 2010, so I figured we should, too. However, this change is not
found in upstream refpolicy and might actually grant excessive permissions. So 
if
someone knows which ports are needed exactly, we could maybe do better.
For now I pushed a change with the full permissions to alioth git.

Cheers,

Mika


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#706632: efibootmgr: I confirm this bug

2013-05-08 Thread Mika Rastas
Package: efibootmgr
Version: 0.5.4-5
Followup-For: Bug #706632

Dear Maintainer,

The first install I made with my new or actually used UEFI enabled computer was 
from Steves update 2 of EFI boot network install CD:s. A while later I needed 
to do it again so I did it from update4 as it was the latest at that point. 
Both worked. After I updated the kernel and grub I ended up in Windows without 
any grub menu. So to fix this I came back to my Debian install with SuperGrub2 
CD. After several tries with efibootmgr and different ways I cannot add an 
entry to the UEFI Boot table.

When running this command I expect to get an entry to the table: 

#efibootmgr --create --gpt --disk /dev/sda --part 4 --write-signature --label 
GRUB2 --loader '\EFI\debian\grubx64.efi'


-- System Information:
Debian Release: jessie/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.8-1-amd64 (SMP w/8 CPU cores)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages efibootmgr depends on:
ii  libc62.17-1
ii  libpci3  1:3.1.9-6
ii  zlib1g   1:1.2.8.dfsg-1

efibootmgr recommends no packages.

efibootmgr suggests no packages.

-- no debconf information


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#706228: PTS: Please provide a link to the NEWS file if it exists

2013-04-26 Thread Mika Pflueger
Package: qa.debian.org
Severity: wishlist
User: qa.debian@packages.debian.org
Usertags: pts

Hi,

it would be really nice if it was possible to link to the NEWS file
of a package in the PTS (probably near the link to the changelog). Often it
is useful to know what /important/ happened to a package, if any.

Cheers,

Mika


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#702877: Uploaded to unstable; please unblock

2013-03-15 Thread Mika Pflüger
Hi release team,

Thomas Goirand was so nice to upload the fixed package to unstable. He
added a small change to fix building twice in a row, such that the full
changelog now reads:

  [ Mika Pflüger ]
  * Team upload.
  * debian/patches/05_ssl.patch: Add upstream patch to force building
SSL support with newer MySQL client libraries. Thanks to Eldon Koyle
for isolating the fix in the upstream VCS. (Closes: #678169)
  * Delete now obsolete debian/patches/README.source which referred to
dpatch.

  [ Thomas Goirand ]
  * Added a debian/rules clean: rm MySQL_python.egg-info/PKG-INFO, so
  it is possible to build the package twice.

The debdiff between the version in testing and stable is attached,
it would be very nice if you could unblock it.

Cheers,

Mika

unblock python-mysqldb/1.2.3-2

-- 

diff -Nru python-mysqldb-1.2.3/debian/changelog python-mysqldb-1.2.3/debian/changelog
--- python-mysqldb-1.2.3/debian/changelog	2011-10-18 12:46:05.0 +0200
+++ python-mysqldb-1.2.3/debian/changelog	2013-03-15 07:02:21.0 +0100
@@ -1,3 +1,19 @@
+python-mysqldb (1.2.3-2) unstable; urgency=low
+
+  [ Mika Pflüger ]
+  * Team upload.
+  * debian/patches/05_ssl.patch: Add upstream patch to force building
+SSL support with newer MySQL client libraries. Thanks to Eldon Koyle
+for isolating the fix in the upstream VCS. (Closes: #678169)
+  * Delete now obsolete debian/patches/README.source which referred to
+dpatch.
+
+  [ Thomas Goirand ]
+  * Added a debian/rules clean: rm MySQL_python.egg-info/PKG-INFO, so it is
+possible to build the package twice.
+
+ -- Mika Pflüger deb...@mikapflueger.de  Mon, 11 Mar 2013 18:03:06 +0100
+
 python-mysqldb (1.2.3-1) unstable; urgency=low
 
   * Merge with package from Ubuntu, thanks to Mario Limonciello.
diff -Nru python-mysqldb-1.2.3/debian/patches/05_ssl.patch python-mysqldb-1.2.3/debian/patches/05_ssl.patch
--- python-mysqldb-1.2.3/debian/patches/05_ssl.patch	1970-01-01 01:00:00.0 +0100
+++ python-mysqldb-1.2.3/debian/patches/05_ssl.patch	2013-03-15 06:51:49.0 +0100
@@ -0,0 +1,21 @@
+Description: Force HAVE_OPENSSL if the client library is 5.5 or newer.
+Origin: http://sourceforge.net/p/mysql-python/svn/656/tree//branches/MySQLdb-1.2/MySQLdb/_mysql.c?diff=5059d1f5bfc09e26e1a66617:655
+Bug: http://sourceforge.net/p/mysql-python/bugs/323/
+Reviewed-by: Eldon Koyle eko...@gmail.com
+Last-Update: 2013-03-11
+
+Index: python-mysqldb-argh/_mysql.c
+===
+--- python-mysqldb-argh.orig/_mysql.c	2010-06-17 09:21:56.0 +0200
 python-mysqldb-argh/_mysql.c	2013-03-11 18:30:38.839269635 +0100
+@@ -102,6 +102,10 @@
+ #define check_server_init(x) if (!_mysql_server_init_done) _mysql_server_init_done = 1
+ #endif
+ 
++#if MYSQL_VERSION_ID = 50500
++#define HAVE_OPENSSL 1
++#endif
++
+ PyObject *
+ _mysql_Exception(_mysql_ConnectionObject *c)
+ {
diff -Nru python-mysqldb-1.2.3/debian/patches/series python-mysqldb-1.2.3/debian/patches/series
--- python-mysqldb-1.2.3/debian/patches/series	2011-10-18 11:38:40.0 +0200
+++ python-mysqldb-1.2.3/debian/patches/series	2013-03-15 06:51:49.0 +0100
@@ -1,2 +1,3 @@
 01_converters_boolean.patch
 03_converters_set2str.patch
+05_ssl.patch
diff -Nru python-mysqldb-1.2.3/debian/rules python-mysqldb-1.2.3/debian/rules
--- python-mysqldb-1.2.3/debian/rules	2011-10-18 12:53:10.0 +0200
+++ python-mysqldb-1.2.3/debian/rules	2013-03-15 07:02:45.0 +0100
@@ -17,7 +17,7 @@
 	python$* setup.py clean
 	find . -name *.py[co] -exec rm -f {} \;
 	dh_testroot
-	rm -fr build build-python$*
+	rm -fr build build-python$* MySQL_python.egg-info/PKG-INFO
 	dh_clean
 
 build: $(PYVERS:%=build-python%)


signature.asc
Description: PGP signature


Bug#678169: even more corrected debdiff

2013-03-12 Thread Mika Pflüger
Hi,

The corrected debdiff still had a bogus changelog whitespace-only
change, thanks to Julien Cristau for noticing it. So here is an even
more corrected version. (-;

Cheers,

Mika

-- 

diff -Nru python-mysqldb-1.2.3/debian/changelog 
python-mysqldb-1.2.3/debian/changelog
--- python-mysqldb-1.2.3/debian/changelog   2011-10-18 12:46:05.0 
+0200
+++ python-mysqldb-1.2.3/debian/changelog   2013-03-12 13:51:34.0 
+0100
@@ -1,3 +1,14 @@
+python-mysqldb (1.2.3-2) unstable; urgency=low
+
+  * Team upload.
+  * debian/patches/05_ssl.patch: Add upstream patch to force building
+SSL support with newer MySQL client libraries. Thanks to Eldon Koyle
+for isolating the fix in the upstream VCS. (Closes: #678169)
+  * Delete now obsolete debian/patches/README.source which referred to
+dpatch.
+
+ -- Mika Pflüger deb...@mikapflueger.de  Mon, 11 Mar 2013 18:03:06 +0100
+
 python-mysqldb (1.2.3-1) unstable; urgency=low
 
   * Merge with package from Ubuntu, thanks to Mario Limonciello.
diff -Nru python-mysqldb-1.2.3/debian/patches/05_ssl.patch 
python-mysqldb-1.2.3/debian/patches/05_ssl.patch
--- python-mysqldb-1.2.3/debian/patches/05_ssl.patch1970-01-01 
01:00:00.0 +0100
+++ python-mysqldb-1.2.3/debian/patches/05_ssl.patch2013-03-11 
18:32:15.0 +0100
@@ -0,0 +1,21 @@
+Description: Force HAVE_OPENSSL if the client library is 5.5 or newer.
+Origin: 
http://sourceforge.net/p/mysql-python/svn/656/tree//branches/MySQLdb-1.2/MySQLdb/_mysql.c?diff=5059d1f5bfc09e26e1a66617:655
+Bug: http://sourceforge.net/p/mysql-python/bugs/323/
+Reviewed-by: Eldon Koyle eko...@gmail.com
+Last-Update: 2013-03-11
+
+Index: python-mysqldb-argh/_mysql.c
+===
+--- python-mysqldb-argh.orig/_mysql.c  2010-06-17 09:21:56.0 +0200
 python-mysqldb-argh/_mysql.c   2013-03-11 18:30:38.839269635 +0100
+@@ -102,6 +102,10 @@
+ #define check_server_init(x) if (!_mysql_server_init_done) 
_mysql_server_init_done = 1
+ #endif
+ 
++#if MYSQL_VERSION_ID = 50500
++#define HAVE_OPENSSL 1
++#endif
++
+ PyObject *
+ _mysql_Exception(_mysql_ConnectionObject *c)
+ {
diff -Nru python-mysqldb-1.2.3/debian/patches/series 
python-mysqldb-1.2.3/debian/patches/series
--- python-mysqldb-1.2.3/debian/patches/series  2011-10-18 11:38:40.0 
+0200
+++ python-mysqldb-1.2.3/debian/patches/series  2013-03-11 18:19:24.0 
+0100
@@ -1,2 +1,3 @@
 01_converters_boolean.patch
 03_converters_set2str.patch
+05_ssl.patch
diff -Nru python-mysqldb-1.2.3/debian/README.source 
python-mysqldb-1.2.3/debian/README.source
--- python-mysqldb-1.2.3/debian/README.source   2011-09-19 12:48:38.0 
+0200
+++ python-mysqldb-1.2.3/debian/README.source   1970-01-01 01:00:00.0 
+0100
@@ -1,2 +0,0 @@
-This package uses dpatch for its patch management, see
-/usr/share/doc/dpatch/README.source.gz if you are unfamiliar with it.


signature.asc
Description: PGP signature


Bug#702877: unblock pre-approval: python-mysqldb/1.2.3-2

2013-03-12 Thread Mika Pflueger
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock

Hi,

I would like to ask if you would unblock a fix for #678169 (python-mysqldb: 
fails to
connect to mysql), where python-mysqldb errorneously does not compile with SSL 
support,
thus securely connecting to a MySQL server from python is not possible. This is 
a
regression from squeeze. The fix is a three-line patch pulled from upstream 
which
forcibly enables SSL support as it is not enabled automatically anymore.

The proposed debdiff is in the bug report and attached.

Cheers,

Mika

unblock python-mysqldb/1.2.3-2
diff -Nru python-mysqldb-1.2.3/debian/changelog python-mysqldb-1.2.3/debian/changelog
--- python-mysqldb-1.2.3/debian/changelog	2011-10-18 12:46:05.0 +0200
+++ python-mysqldb-1.2.3/debian/changelog	2013-03-12 13:51:34.0 +0100
@@ -1,3 +1,14 @@
+python-mysqldb (1.2.3-2) unstable; urgency=low
+
+  * Team upload.
+  * debian/patches/05_ssl.patch: Add upstream patch to force building
+SSL support with newer MySQL client libraries. Thanks to Eldon Koyle
+for isolating the fix in the upstream VCS. (Closes: #678169)
+  * Delete now obsolete debian/patches/README.source which referred to
+dpatch.
+
+ -- Mika Pflüger deb...@mikapflueger.de  Mon, 11 Mar 2013 18:03:06 +0100
+
 python-mysqldb (1.2.3-1) unstable; urgency=low
 
   * Merge with package from Ubuntu, thanks to Mario Limonciello.
diff -Nru python-mysqldb-1.2.3/debian/patches/05_ssl.patch python-mysqldb-1.2.3/debian/patches/05_ssl.patch
--- python-mysqldb-1.2.3/debian/patches/05_ssl.patch	1970-01-01 01:00:00.0 +0100
+++ python-mysqldb-1.2.3/debian/patches/05_ssl.patch	2013-03-11 18:32:15.0 +0100
@@ -0,0 +1,21 @@
+Description: Force HAVE_OPENSSL if the client library is 5.5 or newer.
+Origin: http://sourceforge.net/p/mysql-python/svn/656/tree//branches/MySQLdb-1.2/MySQLdb/_mysql.c?diff=5059d1f5bfc09e26e1a66617:655
+Bug: http://sourceforge.net/p/mysql-python/bugs/323/
+Reviewed-by: Eldon Koyle eko...@gmail.com
+Last-Update: 2013-03-11
+
+Index: python-mysqldb-argh/_mysql.c
+===
+--- python-mysqldb-argh.orig/_mysql.c	2010-06-17 09:21:56.0 +0200
 python-mysqldb-argh/_mysql.c	2013-03-11 18:30:38.839269635 +0100
+@@ -102,6 +102,10 @@
+ #define check_server_init(x) if (!_mysql_server_init_done) _mysql_server_init_done = 1
+ #endif
+ 
++#if MYSQL_VERSION_ID = 50500
++#define HAVE_OPENSSL 1
++#endif
++
+ PyObject *
+ _mysql_Exception(_mysql_ConnectionObject *c)
+ {
diff -Nru python-mysqldb-1.2.3/debian/patches/series python-mysqldb-1.2.3/debian/patches/series
--- python-mysqldb-1.2.3/debian/patches/series	2011-10-18 11:38:40.0 +0200
+++ python-mysqldb-1.2.3/debian/patches/series	2013-03-11 18:19:24.0 +0100
@@ -1,2 +1,3 @@
 01_converters_boolean.patch
 03_converters_set2str.patch
+05_ssl.patch
diff -Nru python-mysqldb-1.2.3/debian/README.source python-mysqldb-1.2.3/debian/README.source
--- python-mysqldb-1.2.3/debian/README.source	2011-09-19 12:48:38.0 +0200
+++ python-mysqldb-1.2.3/debian/README.source	1970-01-01 01:00:00.0 +0100
@@ -1,2 +0,0 @@
-This package uses dpatch for its patch management, see
-/usr/share/doc/dpatch/README.source.gz if you are unfamiliar with it.


Bug#678169: debdiff for a version -2 fixing this bug

2013-03-11 Thread Mika Pflüger
Hi,

I turned the patch by Eldon Koyle into an update for the debian
package. Attached is the debdiff. I chose to include a small
documentation fix as I was initially confused by the misleading
documentation. If someone could commit this to the DPMT svn and then
upload it to unstable, I'm volunteering to file an unblock request.

Cheers,

Mika

-- 



python-mysqldb-fix-678169.debdiff
Description: Binary data


signature.asc
Description: PGP signature


Bug#678169: corrected debdiff

2013-03-11 Thread Mika Pflüger
Hi,

my last debdiff did not include an appropriate (Closes: #)-Tag, this
one is corrected. Sorry for the noise.

Cheers,

Mika

-- 

diff -Nru python-mysqldb-1.2.3/debian/changelog 
python-mysqldb-1.2.3/debian/changelog
--- python-mysqldb-1.2.3/debian/changelog   2011-10-18 12:46:05.0 
+0200
+++ python-mysqldb-1.2.3/debian/changelog   2013-03-12 03:11:11.0 
+0100
@@ -1,3 +1,14 @@
+python-mysqldb (1.2.3-2) unstable; urgency=low
+
+  * Team upload.
+  * debian/patches/05_ssl.patch: Add upstream patch to force building
+SSL support with newer MySQL client libraries. Thanks to Eldon Koyle
+for isolating the fix in the upstream VCS. (Closes: #678169)
+  * Delete now obsolete debian/patches/README.source which referred to
+dpatch.
+
+ -- Mika Pflüger deb...@mikapflueger.de  Mon, 11 Mar 2013 18:03:06 +0100
+
 python-mysqldb (1.2.3-1) unstable; urgency=low
 
   * Merge with package from Ubuntu, thanks to Mario Limonciello.
@@ -54,7 +65,6 @@
   * Add 02_python_2.6.dpatch to fix python 2.6 related warnings. Thanks to
 Mario Limonciello supe...@ubuntu.com for the patch. (closes: #541719)
   * bump standards-version to 3.8.3, no changes required.
-
  -- Jonas Meurer m...@debian.org  Wed, 26 Aug 2009 01:50:35 +0200
 
 python-mysqldb (1.2.2-8) unstable; urgency=low
diff -Nru python-mysqldb-1.2.3/debian/patches/05_ssl.patch 
python-mysqldb-1.2.3/debian/patches/05_ssl.patch
--- python-mysqldb-1.2.3/debian/patches/05_ssl.patch1970-01-01 
01:00:00.0 +0100
+++ python-mysqldb-1.2.3/debian/patches/05_ssl.patch2013-03-11 
18:32:15.0 +0100
@@ -0,0 +1,21 @@
+Description: Force HAVE_OPENSSL if the client library is 5.5 or newer.
+Origin: 
http://sourceforge.net/p/mysql-python/svn/656/tree//branches/MySQLdb-1.2/MySQLdb/_mysql.c?diff=5059d1f5bfc09e26e1a66617:655
+Bug: http://sourceforge.net/p/mysql-python/bugs/323/
+Reviewed-by: Eldon Koyle eko...@gmail.com
+Last-Update: 2013-03-11
+
+Index: python-mysqldb-argh/_mysql.c
+===
+--- python-mysqldb-argh.orig/_mysql.c  2010-06-17 09:21:56.0 +0200
 python-mysqldb-argh/_mysql.c   2013-03-11 18:30:38.839269635 +0100
+@@ -102,6 +102,10 @@
+ #define check_server_init(x) if (!_mysql_server_init_done) 
_mysql_server_init_done = 1
+ #endif
+ 
++#if MYSQL_VERSION_ID = 50500
++#define HAVE_OPENSSL 1
++#endif
++
+ PyObject *
+ _mysql_Exception(_mysql_ConnectionObject *c)
+ {
diff -Nru python-mysqldb-1.2.3/debian/patches/series 
python-mysqldb-1.2.3/debian/patches/series
--- python-mysqldb-1.2.3/debian/patches/series  2011-10-18 11:38:40.0 
+0200
+++ python-mysqldb-1.2.3/debian/patches/series  2013-03-11 18:19:24.0 
+0100
@@ -1,2 +1,3 @@
 01_converters_boolean.patch
 03_converters_set2str.patch
+05_ssl.patch
diff -Nru python-mysqldb-1.2.3/debian/README.source 
python-mysqldb-1.2.3/debian/README.source
--- python-mysqldb-1.2.3/debian/README.source   2011-09-19 12:48:38.0 
+0200
+++ python-mysqldb-1.2.3/debian/README.source   1970-01-01 01:00:00.0 
+0100
@@ -1,2 +0,0 @@
-This package uses dpatch for its patch management, see
-/usr/share/doc/dpatch/README.source.gz if you are unfamiliar with it.


signature.asc
Description: PGP signature


Bug#697814: [DSE-Dev] Bug#697814: selinux-policy-default: exim4 and bitlbee want access to sysctl_crypto_t

2013-01-09 Thread Mika Pflüger
Hi,

Am Thu, 10 Jan 2013 00:11:17 +0200
schrieb Marius Gavrilescu mar...@ieval.ro:
 For some reason exim4 and bitlbee are trying to read
 /proc/sys/crypto/fips_enabled and SELinux doesn't let them.

Seems to me they are using libgcrypt which tries to
read /proc/sys/crypto/fips_enabled to determine if it should enable
fips mode. Most applications are however not allowed to do so, in
debian atm only
chkpwd_t, rpm_t, rpm_script_t, puppet_t, puppetmaster_t
are allowed access via the kernel_read_crypto_sysctls interface
(defined in kernel.if). In latest upstream git there are quite some
additional types which are allowed access, but exim4 and bitlbee are not
among those.
fedora adds
kernel_read_crypto_sysctls(domain)
which will allow this for a /lot/ of other programs, basically
everybody (for example bitlbee and exim, which are init_daemon_domain).
As (at least on my system) there is only the fips_enabled file
in /proc/sys/crypto, the possible harm from allowing this for everybody
seems very small. It is only the information if the system is in fips
mode.

How should we proceed? Add kernel_read_crypto_sysctls for everyone who
needs it (which could be quite some list considering that libgrypt11
has about 200 reverse dependencies…) or follow the fedora way and allow
it for everybody?

However, this only breaks fips mode for the affected programs so maybe
the impact is so low that we don't fix it for wheezy and therefore
only work for a solution upstream. How many people use system wide fips
mode?


Cheers,

Mika

-- 



signature.asc
Description: PGP signature


Bug#695622: unblock: refpolicy/2:2.20110726-12

2012-12-10 Thread Mika Pflüger
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock

Dear Release Team,

Please unblock package refpolicy version 2:2.20110726-12, changes since
version -11 (which is in testing atm) are:

File label fixes:
   * Label ~/.adobe(/.*)? as mozilla_home_t for flash
   * Label /usr/sbin/opendkim as dkim_milter_exec_t
   * Label postalias as postfix_master_exec_t for newaliases
   * Label port 5546 as dhcpc_port_t and allow dhcpc_t to bind to TCP
  for client control
   * Label /usr/lib/kde4/libexec/* and /usr/lib/gvfs/* as bin_t for
  desktops
   * Label /run/pm-utils(/.*)? as devicekit_var_run_t not hald_var_run_t
   * Label /sbin/xtables-multi (the new iptables)
   * Label /usr/lib/dovecot/auth as dovecot_auth_exec_t.
 Label /usr/lib/dovecot/dovecot-lda as lda_exec_t
 Label /usr/lib/dovecot/libdovecot.*\.so.* as lib_t
 Closes: #690225

All the labelling corrections fix bugs which lead to some important
functionality of the respective program not working if selinux is
installed  enabled. No code/policy is changed, it is only about
labelling the debian locations of files correctly.

   * Allow user roles access to mozilla_t classes shm and sem for
  sharing the sound device
   * Allow user roles access to mozilla_tmp_t

Without this, a confined iceweasel won't be able to use sound
properly, or it won't work at all, respectively.

   * Make postfix.pp not depend on unconfined.pp for strict
  configurations

This fixes loading the postfix policy in strict configurations, which
simply failed previously.

   * Allow lvm_t (systemd-cryptsetup) systemd_manage_passwd_run() access
   * Allow systemd_passwd_agent_t access to search selinuxfs and write
  to the console for getting a password for encrypted filesystems

These fix booting with systemd and selinux enabled on dm-crypt root
filesystems.

   * Allow watchdog_t to read syslog pid files for process watching

Fixing one of the core functionalities of watchdog on selinux-enabled
systems.


Diffstat of the sources (patches applied) ignoring d/changelog and
d/patches:
 policy/modules/apps/mozilla.fc  |1 +
 policy/modules/apps/mozilla.if  |   21 -
 policy/modules/kernel/corecommands.fc   |2 ++
 policy/modules/kernel/corenetwork.te.in |2 +-
 policy/modules/services/devicekit.fc|1 +
 policy/modules/services/dkim.fc |2 ++
 policy/modules/services/dovecot.fc  |2 +-
 policy/modules/services/hal.fc  |1 -
 policy/modules/services/lda.fc  |1 +
 policy/modules/services/postfix.fc  |1 +
 policy/modules/services/postfix.if  |4 +++-
 policy/modules/services/watchdog.te |4 
 policy/modules/system/iptables.fc   |1 +
 policy/modules/system/libraries.fc  |1 +
 policy/modules/system/logging.if|   18 ++
 policy/modules/system/lvm.te|4 
 policy/modules/system/sysnetwork.te |1 +
 policy/modules/system/systemd.te|8 +++-
 18 files changed, 57 insertions(+), 18 deletions(-)


The debdiff is attached.

unblock refpolicy/2:2.20110726-12

Thanks for your work + cheers,

Mika



refpolicy_2.20110726-11,12.debdiff
Description: Binary data


signature.asc
Description: PGP signature


Bug#687848: Currently, only the symlink is removed

2012-12-04 Thread Mika Pflüger
Hi,

Am Tue, 4 Dec 2012 19:57:46 +0100
schrieb Ivo De Decker ivo.dedec...@ugent.be:
 On Wed, Sep 26, 2012 at 11:51:55PM +0200, Mika Pflüger wrote:
  Steps to reproduce:
  1. Fresh wheezy install
  2. apt-get install extlinux
  3. extlinux-update  extlinux-install first-hd
  (4. try reboot: doesn't boot; redo 1.-3. to get working setup again)
  5. add unstable to sources.list and apt-get -t unstable install
  syslinux-themes-debian-wheezy or just download the most recent
  syslinux-themes-debian-wheezy_*.deb from an unstable mirror of your
  choice and dpkg -i it
  6. extlinux-update
  7. try reboot: doesn't boot.
 
 This problem can be reproduced easily with these steps. The problem
 should go away for fresh installs if syslinux-themes-debian-wheezy
 migrates to testing, but it will still be there for older installs.

You are right, now it is not easily reproducible anymore - it probably
is only a problem right now for old installs. And of course it will
again be a problem if syslinux-themes-debian-wheezy has to be fixed for
another problem (if ever).
 
  I don't know if my proposed patch is a very elegant solution (I
  actually suspect it's not), but I tested that it solves the problem.
 
 Removing the directories first isn't very elegant. The following
 patch shoud fix the problem by forcing cp to use the right path
 (adding the -T option):

Yes, that is a much more elegant solution! Thanks a lot for finding the
needed cp option I did not find!

Cheers,

Mika


-- 



signature.asc
Description: PGP signature


Bug#694813: [mtr] Add GeoIP lookup

2012-11-30 Thread Mika Suomalainen
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Package: mtr
Version: 0.82-3
Severity: wishlist

- --- Please enter the report below this line. ---

In some cases it could be useful to see the contry where router is
located.

- --- System information. ---
Architecture: amd64
Kernel:   Linux 3.2.0-4-amd64

Debian Release: wheezy/sid
  500 unstablewww.deb-multimedia.org
  500 unstablehttp.debian.net
  500 unstabledeb.torproject.org
  500 unstabledeb.opera.com
  500 stable  repo.wuala.com
  500 stable  dl.google.com
  500 precise ppa.launchpad.net
  500 all liveusb.info

- --- Package information. ---
Depends  (Version) | Installed
==-+-
libatk1.0-0(= 1.12.4) |
libc6 (= 2.4) |
libcairo2   (= 1.2.4) |
libfontconfig1  (= 2.8.0) |
libfreetype6(= 2.2.1) |
libgdk-pixbuf2.0-0 (= 2.22.0) |
libglib2.0-0   (= 2.12.0) |
libgtk2.0-0 (= 2.8.0) |
libncurses5(= 5.5-5~) |
libpango1.0-0  (= 1.14.0) |
libtinfo5  |


Package's Recommends field is empty.

Package's Suggests field is empty.
- -- 
Mika Suomalainen
http://mkaysi.github.com/
-BEGIN PGP SIGNATURE-
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Homepage: http://mkaysi.github.com/
Comment: Public key: http://mkaysi.github.com/PGP/0x82A46728.txt
Comment: gpg --fetch-keys http://mkaysi.github.com/PGP/0x82A46728.txt
Comment: Fingerprint = 24BC 1573 B8EE D666 D10A  AA65 4DB5 3CFE 82A4 6728
Comment: I have personal problem with PGP/MIME...
Comment: ...so signature *IS* long. See http://git.io/6FLzWg
Comment: Please remove PGP lines in replies. http://git.io/nvHrDg
Comment: Charset of this message should be UTF-8.
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJQuNtGAAoJEE21PP6CpGcoK54P/0mUpsn9T/PwAxGliYDUwKbC
i9l2+yCQvP4ftqSGRgttOBMV9YhoMif+gx2Fc0VSsrtNUbwVeEBqqn0Z5awt8gVN
6RYbChUIj94Kz73fPHtrRRSKFbQCK09fHYNep3OYiP8/TgVLzWgt6WASLADTMwK0
j+y0CMuesf35pHRQjdR9QH3Ac1DuJ2lp6TVJGHEFmNBedafgMlRUzKqIHSW0T51U
+oqO4w7F09BnOjg2ia7PqVCOeAgf/dHpmeIdGH3PwmdR/zU3Dl6B8ATWOK3u305h
Dk5hEfYumE6I1u20MQ1mOzslH/n1sHjd6Bdn7TBrMF/SkBiXBMBRrqKdqnRc0KBS
uSNMblfJZXU+oX3Oi7nui8rFXgmVSpJJ1HCURY+Emn+OqL50dgH7Csacq5EFj2JY
mgFjJedt7d7ntoQCiws9XOZo2iOB+pcHlcZK51fIeFOQyb58zS/Mvbwm+Xb9aIxH
hH3h63ZXC6KtdBBMwzyLz8ImgfwOn3p2+cBZVJIqivydEWYbx7hh0yOai5VNvxn+
wqE9amrUY8FawcQnbsBwzTUl4LDnKZ/1p+fvpSv0WEpffQlh2ddAOSVG2dW+Fl+T
fwydFTBH8y6EYDyPHw9wmEbKhhmfNDBzrm5lu4WBjb+LpATqAoxSOTAvhbJqYSDV
N9XIECcCftz+XlGuMqdN
=oICx
-END PGP SIGNATURE-


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org



Bug#692836: [wicd-gtk] Suggests invalid subnet mask when IP is entered

2012-11-09 Thread Mika Suomalainen
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Package: wicd-gtk
Version: 1.7.2.4-3
Severity: normal

- --- Please enter the report below this line. ---

When you go to static IP settings and enter IP address 10.0.0.5,
wicd-gtk puts 255.255.255.0 as subnet mask automatically. It should
be 255.0.0.0.

There isn't IP 10.0.0.5 with subnet mask 255.255.255.0.

It automatically offers correct default gateway 10.0.0.1.
- --- System information. ---
Architecture: amd64
Kernel:   Linux 3.2.0-4-amd64

Debian Release: wheezy/sid
  500 unstablewww.deb-multimedia.org
  500 unstablehttp.debian.net
  500 unstabledeb.torproject.org
  500 unstabledeb.opera.com
  500 stable  repo.wuala.com
  500 stable  dl.google.com
  500 precise ppa.launchpad.net
  500 all liveusb.info

- --- Package information. ---
Depends  (Version) | Installed
==-+-===
python   (= 2.6.6-7~) | 2.7.3-3
python-gtk2| 2.24.0-3
python-glade2  | 2.24.0-3
wicd-daemon  (= 1.7.2.4-3) | 1.7.2.4-3
wicd-daemon  (= 1.7.2.4-3) | 1.7.2.4-3
wicd-gtk(= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-curses (= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-cli(= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-client|
python   (= 2.6.6-7~) | 2.7.3-3
wicd-daemon  (= 1.7.2.4-3) | 1.7.2.4-3
python   (= 2.6.6-7~) | 2.7.3-3
python-gtk2| 2.24.0-3
python-glade2  | 2.24.0-3
wicd-daemon  (= 1.7.2.4-3) | 1.7.2.4-3
python   (= 2.6.6-7~) | 2.7.3-3
python-urwid   | 1.0.2-1
wicd-daemon  (= 1.7.2.4-3) | 1.7.2.4-3
python   (= 2.6.6-7~) | 2.7.3-3
python-dbus| 1.1.1-1
python-gobject | 3.2.2-1
dbus   | 1.6.8-1
wpasupplicant  | 1.0-3+b2
wireless-tools | 30~pre9-8
dhcpcd |
 OR isc-dhcp-client| 4.2.4-3
 OR pump   |
 OR udhcpc |
net-tools  | 1.60-24.2
 OR ethtool|
net-tools  | 1.60-24.2
 OR iproute| 20120521-3
adduser| 3.113+nmu3
lsb-base   (= 3.2-13) | 4.1+Debian8
psmisc | 22.20-1
iputils-ping   | 3:20101006-3
 OR inetutils-ping |
python-wicd  (= 1.7.2.4-3) | 1.7.2.4-3
python   (= 2.6.6-7~) | 2.7.3-3
python( 2.8) | 2.7.3-3


Recommends (Version) | Installed
-+-===
gksu | 2.0.2-6
python-notify| 0.1.1-3
sudo | 1.8.5p2-1
gksu | 2.0.2-6
python-notify| 0.1.1-3
sudo | 1.8.5p2-1
wicd-gtk  (= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-curses   (= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-cli  (= 1.7.2.4-3)  | 1.7.2.4-3
 OR wicd-client  |
rfkill   | 0.4-1


Suggests  (Version) | Installed
===-+-===
pm-utils| 1.4.1-9





- -- 
Mika Suomalainen
http://mkaysi.github.com/
-BEGIN PGP SIGNATURE-
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Homepage: http://mkaysi.github.com/
Comment: Public key: http://mkaysi.github.com/PGP/0x82A46728.txt
Comment: gpg --fetch-keys http://mkaysi.github.com/PGP/0x82A46728.txt
Comment: Fingerprint = 24BC 1573 B8EE D666 D10A  AA65 4DB5 3CFE 82A4 6728
Comment: I have personal problem with PGP/MIME...
Comment: ...so signature *IS* long. See http://git.io/6FLzWg
Comment: Please remove PGP lines in replies. http://git.io/nvHrDg
Comment: Charset of this message should be UTF-8.
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCgAGBQJQnSmgAAoJEE21PP6CpGcoLBkQAIF0LEUVbDctduo1Te7idvsy
6hcIsvmD67rLrbQVCNScXrpbPseuRO6kSvXXEYxejelI/It72sHIrwus+UzaO0s0
7laFFtGsnnrno/JrTk6+OF8VQc3tdtYPhpFLZYGvMXjGDK1z40r7qACDdxCS2j6I
UoGsxdQnuhUODMCnwttWeKSs1OrTwQIz/Zs/H7QpMnyJDgXUgrskAqiR6mEYUakT
ArQmSdjNw5AzDeZCafX8IkrVrgS2Q7ko1NTLxRQNq5GqRWeqkqICFB4Zg8bx7uDS
87v4grlBSt1McL9U8OUBmS3y4Ynf0Ql6naTvlJ8TeekITyrslp4jC3mLnwMlKbAo
Svj0m+SnwGgejQfasdYauVN3MtqFOfVYa076dktNNb2SRS9vsWBGMeBdW1cIZdRc
izsTIaUe1dxMvaDNP0Dpc+3Q+oVcw4iCXYz0ATFnLS0JR0yUx1z9oUOnUn6WqmAi
KoNEGcZ5f8etn/Yi+U5GKoQGMAWWj7EQvj24EiVJX35T3/+VxOP+kRJy0ShLhRbC
FdP3JsxwbCaRosCmuj6uYD4g2UQODciXJQwKRyeWfaRLK+NToefhBJLbj3TUeGeJ
DK2RwnpxDHLt15wkwFpk8S13o+LuctHDptlZCSc/qWzFPL8dgG+FH4gB2L0CCUWm
o5l/yh8G6/7TRymn2yAa
=kanL
-END PGP SIGNATURE-


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact

Bug#689952: More info

2012-10-08 Thread Mika Pflüger
tags 689952 +moreinfo
thanks

Hi,

could you post the output of
# semodule -l
and
# check-selinux-installation
?

This will hint at common problems and will show your installed selinux
modules. Maybe we can spot the missing one.

Cheers,

Mika

-- 
Own your own computer. Don't use Windows 7. http://windows7sins.org


signature.asc
Description: PGP signature


Bug#689582: ExtractTar: 100 char long path names get truncated to 99 chars

2012-10-04 Thread Mika Eloranta
Package: apt
Version: 0.9.7.5
Severity: important

Dear Maintainer,

When a data.tar.{gz,xz} contains a path name that is exactly
100 characters long, it will get truncated to 99 chars upon
extraction in ExtractTar::Go().

It seems in older gnu tar versions (pre-wheezy) the behavior
was more conservative and to use the 100 byte path field only
for path names less than 100 chars long, and to switch to
using long names already at 100 chars. In wheezy the
behavior seems to be different and path names of exactly
100 chars long can fill the whole reserved space in the tar
and then get truncated in ExtractTar::Go():

  // Grab the filename
  if (LastLongName.empty() == false)
 Itm.Name = (char *)LastLongName.c_str();
  else
  {
 Tar-Name[sizeof(Tar-Name)-1] = 0;
 Itm.Name = Tar-Name;
  }

Quick way to reproducing the problem using a generated dummy
deb package and python-apt is included as an attachment.

-- System Information:
Debian Release: wheezy/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-3-amd64 (SMP w/11 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages apt depends on:
ii  debian-archive-keyring  2012.4
ii  gnupg   1.4.12-4+b1
ii  libapt-pkg4.12  0.9.7.5
ii  libc6   2.13-35
ii  libgcc1 1:4.7.1-7
ii  libstdc++6  4.7.1-7

apt recommends no packages.
#! /usr/bin/python
import os
import apt_inst

paths = []
for i in range(98,103):
	path = (%03d % i).ljust(i,x)
file(path, w)
paths.append(path)

assert not os.system(tar zcf data.tar.gz %s %  .join(paths))
file(control.tar.gz, w)
file(debian-binary, w)
assert not os.system(ar cr test.deb data.tar.gz control.tar.gz debian-binary)

def cb(a, b):
print %3d %s  % (len(a.name), a.name)

apt_inst.DebFile(file(test.deb, rb)).data.go(cb)


Bug#689313: python-debian: arfile.ArFile.extractfile is broken

2012-10-01 Thread Mika Eloranta
Package: python-debian
Version: 0.1.18+squeeze1
Severity: normal
Tags: patch

arfile.ArFile.extractfile(self, member) will only find the matching
member if
it happens to be the first file in the archive. The method returns from
the
search loop during the first iteration.

The fix is trivial and is attached as a patch.


-- System Information:
Debian Release: 6.0.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 3.2.0-0.bpo.2-amd64 (SMP w/16 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages python-debian depends on:
ii  python  2.6.6-3+squeeze7 interactive high-level
object-orie
ii  python-chardet  2.0.1-1  universal character
encoding detec
ii  python-support  1.0.10   automated rebuilding
support for P

Versions of packages python-debian recommends:
ii  python-apt0.7.100.1+squeeze1 Python interface to
libapt-pkg

Versions of packages python-debian suggests:
ii  gpgv  1.4.10-4   GNU privacy guard -
signature veri

-- no debconf information


python-debian.patch
Description: Binary data


Bug#689264: unblock: refpolicy/2:2.20110726-11

2012-09-30 Thread Mika Pflüger
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: unblock

Dear Release Team,

Please unblock package refpolicy version 2:2.20110726-11, changes since
version -9 (which is in testing atm) are:

* Fix #683756 (selinux in permissive mode breaks gdm and X)
 The problem arouse due to debian specific gdm3 locations.  In version
 2:2.20110726-10 a patch to fix this was introduced, but it was
 incomplete (fixed only some contexts, not all) and therefore in
 version -11 it was replaced by a correct patch, which is also already
 accepted upstream. The bug is only severity: normal in the BTS, but as
 installing and enabling selinux in permissive mode completely breaks
 the ability to log in via gdm I'd consider it important, at least.
 Regressions are very unlikely as this patch only touches file context
 definitions, no code.

* Update the Vcs-* fields
 The Vcs-* fields in d/control were pointing to an old location,  which
 doesn't work anymore.

* Fix #686670 (Cannot load alsa.pp module)
 debian/patches/0048-Alsa-debian-locations.patch had been merged
 upstream but weren't dropped, leading to duplication and breaking the
 alsa module loading. Dropping the patch fixes this.

* Drop debian/patches/0079-Allow-iptables_t-to-do-module_request.patch
 As in the previous fix, the code present in this one-line patch had
 already been introduced upstream. Dropping the patch removes
 duplicates and thereby avoids problems.

* Fix watch file uversionmangle in debian/watch.


Diffstat of the sources (patches applied) ignoring d/changelog:
 debian/control|4 ++--
 debian/patches/series |3 +--
 debian/watch  |5 +
 policy/modules/admin/alsa.fc  |   14 --
 policy/modules/kernel/corecommands.fc |1 +
 policy/modules/services/xserver.fc|   20 +++-
 policy/modules/system/iptables.te |1 -
 7 files changed, 20 insertions(+), 28 deletions(-)


The debdiff is attached.

unblock refpolicy/2.20110726-11

Thanks for your work + cheers,

Mika

diff -Nru refpolicy-2.20110726/debian/changelog 
refpolicy-2.20110726/debian/changelog
--- refpolicy-2.20110726/debian/changelog   2012-06-30 11:42:53.0 
+0200
+++ refpolicy-2.20110726/debian/changelog   2012-09-30 22:47:31.0 
+0200
@@ -1,3 +1,30 @@
+refpolicy (2:2.20110726-11) unstable; urgency=low
+
+  * Team upload
+  [ Mika Pflüger ]
+  * Drop incomplete patch adding debian specific gdm3 locations and
+cherry-pick Laurent's complete patch from upstream instead. Slightly
+edit the patch to work around an issue in file context ordering.
+
+ -- Laurent Bigonville bi...@debian.org  Sun, 30 Sep 2012 22:43:12 +0200
+
+refpolicy (2:2.20110726-10) unstable; urgency=low
+
+  * Team upload.
+  [ Mika Pflüger ]
+  * xserver.fc: Add debian specific /usr/sbin/gdm3 as a location for gdm3.
+Closes: #683756
+  * debian/control: Update Vcs-* fields.
+
+  [ Laurent Bigonville ]
+  * d/p/0079-Allow-iptables_t-to-do-module_request.patch: Dropped, the code
+present in this patch was already present later in the code.
+  * d/p/0048-Alsa-debian-locations.patch: Dropped, changes merged upstream,
+and was breaking module loading due to duplicate paths (Closes: #686670)
+  * debian/watch: Fix watch file uversionmangle
+
+ -- Laurent Bigonville bi...@debian.org  Fri, 07 Sep 2012 17:51:13 +0200
+
 refpolicy (2:2.20110726-9) unstable; urgency=high
 
   * Enable UBAC as roles aren't useful.  I recommend using only roles user_r
@@ -10,8 +37,8 @@
   * Change readahead policy to support memlockd.
   * Allow devicekit_power_t, devicekit_disk_t, kerneloops_t, and policykit_t
 to send dbus messages to users.
-  * Grant systemd utilities access to selinuxfs so they can correctly label 
directories
-Closes: #678392
+  * Grant systemd utilities access to selinuxfs so they can correctly label
+directories. Closes: #678392
   * Assigned type consolekit_var_run_t to /var/run/console(/.*)? because it's
 created and managed by consolekit nowadays.
   * Created tunable allow_ssh_connect_reserved_ports to allow ssh client to
@@ -41,7 +68,7 @@
   * Add tcsd.pp (for trousers) to the policy packages
   * Add nut.pp for the nut-server package to the policy packages
   * Load irqbalance.pp if irqbalance Debian package is installed, same for
-kerneloops, tcsd.pp/trousers, nut.pp/nut-server, 
+kerneloops, tcsd.pp/trousers, nut.pp/nut-server,
 and smartmon.pp/smartmontools.
   * High urgency because the support for tcsd and nut really needs to be
 tested (and it's broken badly for those people) and portslave.pp is also
diff -Nru refpolicy-2.20110726/debian/control 
refpolicy-2.20110726/debian/control
--- refpolicy-2.20110726/debian/control 2012-06-11 14:32:03.0 +0200
+++ refpolicy-2.20110726/debian/control 2012-09-30 22:47:31.0 +0200
@@ -1,6 +1,6 @@
 Source: refpolicy
-VCS-Git: git

Bug#687848: Currently, only the symlink is removed

2012-09-26 Thread Mika Pflüger
reopen 687848
thanks

Hi,

Looking at the code and especially the rm -rf you are referring to, I
see that only the symlink is removed:
Layout before:
/boot/extlinux/themes/debian - debian-wheezy
/boot/extlinux/themes/debian-wheezy: the old theme
the extlinux configuration has the standard values, namely:
/etc/default/extlinux: EXTLINUX_THEME=debian.

So the rm -rf ${_EXTLINUX_DIRECTORY}/themes/${EXTLINUX_THEME}
deletes /boot/extlinux/themes/debian, which is only the symlink. Then
EXTLINUX_THEME_ORIG is populated and the subsequent cp -al (and
regeneration of the symlink) leads to this layout:
/boot/extlinux/themes/debian - debian-wheezy
/boot/extlinux/themes/debian-wheezy: the old theme
/boot/extlinux/themes/debian-wheezy/extlinux: the new theme.

Of course, only the old theme is found when booting, leading to no boot
at all.

Steps to reproduce:
1. Fresh wheezy install
2. apt-get install extlinux
3. extlinux-update  extlinux-install first-hd
(4. try reboot: doesn't boot; redo 1.-3. to get working setup again)
5. add unstable to sources.list and apt-get -t unstable install
syslinux-themes-debian-wheezy or just download the most recent
syslinux-themes-debian-wheezy_*.deb from an unstable mirror of your
choice and dpkg -i it
6. extlinux-update
7. try reboot: doesn't boot.

Note this is completely standard behaviour for anyone actually
installing extlinux in a wheezy right now and following the
README.Debian, finding it doesn't work, switching back to grub, waiting
for the fixes in syslinux-themes-debian hitting testing or installing
it from unstable, and trying again.

I don't know if my proposed patch is a very elegant solution (I
actually suspect it's not), but I tested that it solves the problem.


Cheers,

Mika


-- 
Own your own computer. Don't use Windows 7. http://windows7sins.org


signature.asc
Description: PGP signature


  1   2   3   4   5   >