Processed: Merge duplicates

2017-08-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> unblock 853561 by 853484 841624
Bug #853561 [src:mpd] mpd: ftbfs with GCC-7
853561 was blocked by: 853484 841624
853561 was not blocking any bugs.
Removed blocking bug(s) of 853561: 841624 and 853484
> unblock 841556 by 853484 841624
Bug #841556 [src:mpd] mpd: FTBFS: iso9660.h:277:45: error: flexible array 
member 'iso9660_dir_s::filename' not at end of 'struct iso9660_pvd_s'
841556 was blocked by: 853484 841624
841556 was not blocking any bugs.
Removed blocking bug(s) of 841556: 841624 and 853484
> reassign 853561 src:libcdio
Bug #853561 [src:mpd] mpd: ftbfs with GCC-7
Bug reassigned from package 'src:mpd' to 'src:libcdio'.
No longer marked as found in versions mpd/0.19.21-1.
Ignoring request to alter fixed versions of bug #853561 to the same values 
previously set
> reassign 841556 src:libcdio
Bug #841556 [src:mpd] mpd: FTBFS: iso9660.h:277:45: error: flexible array 
member 'iso9660_dir_s::filename' not at end of 'struct iso9660_pvd_s'
Bug reassigned from package 'src:mpd' to 'src:libcdio'.
No longer marked as found in versions mpd/0.19.19-1.
Ignoring request to alter fixed versions of bug #841556 to the same values 
previously set
> forcemerge 841624 853561 841556
Bug #841624 [src:libcdio] libcdio: FTBFS: ../../include/cdio/iso9660.h:277:45: 
error: flexible array member 'iso9660_dir_s::filename' not at end of 'struct 
iso9660_pvd_s'
Bug #853484 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #841556 [src:libcdio] mpd: FTBFS: iso9660.h:277:45: error: flexible array 
member 'iso9660_dir_s::filename' not at end of 'struct iso9660_pvd_s'
Severity set to 'serious' from 'important'
853476 was blocked by: 841624 853484
853476 was not blocking any bugs.
Added blocking bug(s) of 853476: 841556
Marked as found in versions libcdio/0.83-4.2.
Bug #853561 [src:libcdio] mpd: ftbfs with GCC-7
853476 was blocked by: 841624 841556 853484
853476 was not blocking any bugs.
Added blocking bug(s) of 853476: 853561
Marked as found in versions libcdio/0.83-4.2.
Bug #853484 [src:libcdio] libcdio: ftbfs with GCC-7
Merged 841556 841624 853484 853561
> retitle 841556 libcdio: ftbfs with GCC-7
Bug #841556 [src:libcdio] mpd: FTBFS: iso9660.h:277:45: error: flexible array 
member 'iso9660_dir_s::filename' not at end of 'struct iso9660_pvd_s'
Bug #841624 [src:libcdio] libcdio: FTBFS: ../../include/cdio/iso9660.h:277:45: 
error: flexible array member 'iso9660_dir_s::filename' not at end of 'struct 
iso9660_pvd_s'
Bug #853484 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #853561 [src:libcdio] mpd: ftbfs with GCC-7
Changed Bug title to 'libcdio: ftbfs with GCC-7' from 'mpd: FTBFS: 
iso9660.h:277:45: error: flexible array member 'iso9660_dir_s::filename' not at 
end of 'struct iso9660_pvd_s''.
Changed Bug title to 'libcdio: ftbfs with GCC-7' from 'libcdio: FTBFS: 
../../include/cdio/iso9660.h:277:45: error: flexible array member 
'iso9660_dir_s::filename' not at end of 'struct iso9660_pvd_s''.
Ignoring request to change the title of bug#853484 to the same title
Changed Bug title to 'libcdio: ftbfs with GCC-7' from 'mpd: ftbfs with GCC-7'.
> affects 841556 src:mpd
Bug #841556 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #841624 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #853484 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #853561 [src:libcdio] libcdio: ftbfs with GCC-7
Added indication that 841556 affects src:mpd
Added indication that 841624 affects src:mpd
Added indication that 853484 affects src:mpd
Added indication that 853561 affects src:mpd
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
841556: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=841556
841624: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=841624
853476: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853476
853484: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853484
853561: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853561
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Processing of libebml_1.3.4-2_source.changes

2017-08-05 Thread Debian FTP Masters
libebml_1.3.4-2_source.changes uploaded successfully to localhost
along with the files:
  libebml_1.3.4-2.dsc
  libebml_1.3.4-2.debian.tar.xz
  libebml_1.3.4-2_source.buildinfo

Greetings,

Your Debian queue daemon (running on host usper.debian.org)

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870622: ffmpeg: autopkgtest SIGBUS on armhf with binutils 2.29

2017-08-05 Thread James Cowgill
Hi,

On 04/08/17 09:58, Jiong Wang wrote:
> Change
> 
>   "adreq lr,X(ff_h264_idct_add_neon) +CONFIG_THUMB"
> 
> Into:
> 
> .eqv ff_h264_idct_add_neon_without_func_type, X(ff_h264_idct_add_neon)
> adreq lr,  ff_h264_idct_add_neon_without_func_type +CONFIG_THUMB
> 
> might be a solution.  The idea is we use .eqv to remove the function
> attribute, so the assembler won't set LSB in any case.

This was the commit which introduced the +CONFIG_THUMB stuff:
https://github.com/FFmpeg/FFmpeg/commit/8986fddc2bab92bd7d77a123ac70c4fb70c96c7c

On the technical side, does having the LSB clear when executing a blx
instruction cause a mode change out of Thumb, or does it retain the
mode? I think all the code in that file is compiled in the same mode, so
if the mode is retained then simply dropping +CONFIG_THUMB might work.

Would it be possible for you or someone with better ARM assembly
experience to submit the fixes upstream? It would help greatly.

On Debian, there is #870676 open about NEON code on ARM. We could "fix"
this bug and that one by disabling NEON but it would be nice if we
didn't have to do that.

Thanks,
James

> On 04/08/17 12:39, Jiong Wang wrote:
>> Hi,
>>
>>   This issue is caused by a recent change in ARM assembler included
>> since Binutils 2.29.
>>
>>   The details of that change can be found at
>> https://sourceware.org/bugzilla/show_bug.cgi?id=21458
>>
>>   The semantics of ADR has changed.  In general, the address generated
>> by ADR will guarantee the LSB be set if it's a thumb function address.
>>
>>I noticed h264idct_neon.S is using something like:
>>
>>  adreq lr,X(ff_h264_idct_add_neon) +CONFIG_THUMB
>>
>>As ADR now will set the LSB automatically, you don't need
>> CONFIG_THUMB any more.
>>
>>I think h264idct_neon.S needs to be updated, and the modification
>> should make sure it works with both old Binutils and the new one.
>>
>> Regards,
>> Jiong



signature.asc
Description: OpenPGP digital signature
___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#853463: marked as done (juce: ftbfs with GCC-7)

2017-08-05 Thread Debian Bug Tracking System
Your message dated Sat, 5 Aug 2017 21:53:38 +0300
with message-id <20170805185338.lhvcdoxsvirzp532@localhost>
and subject line juce builds with gcc 7
has caused the Debian Bug report #853463,
regarding juce: ftbfs with GCC-7
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
853463: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853463
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: src:juce
Version: 4.3.0~repack-1
Severity: normal
Tags: sid buster
User: debian-...@lists.debian.org
Usertags: ftbfs-gcc-7

Please keep this issue open in the bug tracker for the package it
was filed for.  If a fix in another package is required, please
file a bug for the other package (or clone), and add a block in this
package. Please keep the issue open until the package can be built in
a follow-up test rebuild.

The package fails to build in a test rebuild on at least amd64 with
gcc-7/g++-7, but succeeds to build with gcc-6/g++-6. The
severity of this report may be raised before the buster release.
There is no need to fix this issue in time for the stretch release.

The full build log can be found at:
http://people.debian.org/~doko/logs/gcc7-20170126/juce_4.3.0~repack-1_unstable_gcc7.log
The last lines of the build log are at the end of this report.

To build with GCC 7, either set CC=gcc-7 CXX=g++-7 explicitly,
or install the gcc, g++, gfortran, ... packages from experimental.

  apt-get -t=experimental install g++ 

Common build failures are new warnings resulting in build failures with
-Werror turned on, or new/dropped symbols in Debian symbols files.
For other C/C++ related build failures see the porting guide at
http://gcc.gnu.org/gcc-7/porting_to.html

[...]
g++  -MMD  -D "LINUX=1" -D "JUCE_DLL_BUILD=1" -D 
'JUCE_APP_CONFIG_HEADER="AppConfig.h"'  -DJUCE_INCLUDE_FLAC_CODE=0 
-DJUCE_INCLUDE_JPEGLIB_CODE=0 -DJUCE_INCLUDE_PNGLIB_CODE=0 
-DPNG_SKIP_SETJMP_CHECK -DJUCE_INCLUDE_OGGVORBIS_CODE=0 
-DJUCE_INCLUDE_ZLIB_CODE=0 -I. -Ibuild -I../../modules  -D "DEBUG=1" -D 
"_DEBUG=1" -g -ggdb -O0  -fPIC -fpermissive  -I/usr/include/libpng16 
-I/usr/include/freetype2 -I/usr/include/libdrm -I/usr/include/alsa 
-I/usr/include/x86_64-linux-gnu -std=c++11 -Wdate-time -D_FORTIFY_SOURCE=2 -g 
-O2 -fdebug-prefix-map=/<>=. -fstack-protector-strong -Wformat 
-Werror=format-security -o build/intermediate/Debug/juce_audio_basics.o -c 
build/juce_audio_basics.cpp
echo '#include "../../modules/juce_audio_devices/juce_audio_devices.cpp"' > 
build/juce_audio_devices.cpp
g++  -MMD  -D "LINUX=1" -D "JUCE_DLL_BUILD=1" -D 
'JUCE_APP_CONFIG_HEADER="AppConfig.h"'  -DJUCE_INCLUDE_FLAC_CODE=0 
-DJUCE_INCLUDE_JPEGLIB_CODE=0 -DJUCE_INCLUDE_PNGLIB_CODE=0 
-DPNG_SKIP_SETJMP_CHECK -DJUCE_INCLUDE_OGGVORBIS_CODE=0 
-DJUCE_INCLUDE_ZLIB_CODE=0 -I. -Ibuild -I../../modules  -D "DEBUG=1" -D 
"_DEBUG=1" -g -ggdb -O0  -fPIC -fpermissive  -I/usr/include/libpng16 
-I/usr/include/freetype2 -I/usr/include/libdrm -I/usr/include/alsa 
-I/usr/include/x86_64-linux-gnu -std=c++11 -Wdate-time -D_FORTIFY_SOURCE=2 -g 
-O2 -fdebug-prefix-map=/<>=. -fstack-protector-strong -Wformat 
-Werror=format-security -o build/intermediate/Debug/juce_audio_devices.o -c 
build/juce_audio_devices.cpp
echo '#include "../../modules/juce_audio_formats/juce_audio_formats.cpp"' > 
build/juce_audio_formats.cpp
g++  -MMD  -D "LINUX=1" -D "JUCE_DLL_BUILD=1" -D 
'JUCE_APP_CONFIG_HEADER="AppConfig.h"'  -DJUCE_INCLUDE_FLAC_CODE=0 
-DJUCE_INCLUDE_JPEGLIB_CODE=0 -DJUCE_INCLUDE_PNGLIB_CODE=0 
-DPNG_SKIP_SETJMP_CHECK -DJUCE_INCLUDE_OGGVORBIS_CODE=0 
-DJUCE_INCLUDE_ZLIB_CODE=0 -I. -Ibuild -I../../modules  -D "DEBUG=1" -D 
"_DEBUG=1" -g -ggdb -O0  -fPIC -fpermissive  -I/usr/include/libpng16 
-I/usr/include/freetype2 -I/usr/include/libdrm -I/usr/include/alsa 
-I/usr/include/x86_64-linux-gnu -std=c++11 -Wdate-time -D_FORTIFY_SOURCE=2 -g 
-O2 -fdebug-prefix-map=/<>=. -fstack-protector-strong -Wformat 
-Werror=format-security -o build/intermediate/Debug/juce_audio_formats.o -c 
build/juce_audio_formats.cpp
echo '#include "../../modules/juce_audio_processors/juce_audio_processors.cpp"' 
> build/juce_audio_processors.cpp
g++  -MMD  -D "LINUX=1" -D "JUCE_DLL_BUILD=1" -D 
'JUCE_APP_CONFIG_HEADER="AppConfig.h"'  -DJUCE_INCLUDE_FLAC_CODE=0 
-DJUCE_INCLUDE_JPEGLIB_CODE=0 -DJUCE_INCLUDE_PNGLIB_CODE=0 
-DPNG_SKIP_SETJMP_CHECK -DJUCE_INCLUDE_OGGVORBIS_CODE=0 
-DJUCE_INCLUDE_ZLIB_CODE=0 -I. -Ibuild -I../../modules  -D "DEBUG=1" -D 
"_DEBUG=1" -g -ggdb -O0  -fPIC -fpermissive  -I/usr/include/libpng16 
-I/usr/include/freetype2 -I/usr/include/libdrm -I/usr/include/alsa 

Bug#870857: soundtouch: CVE-2017-9260

2017-08-05 Thread Salvatore Bonaccorso
Source: soundtouch
Version: 1.9.2-2
Severity: important
Tags: upstream security

Hi,

the following vulnerability was published for soundtouch.

CVE-2017-9260[0]:
| The TDStretchSSE::calcCrossCorr function in
| source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote
| attackers to cause a denial of service (heap-based buffer over-read and
| application crash) via a crafted wav file.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9260
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9260

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870856: soundtouch: CVE-2017-9259

2017-08-05 Thread Salvatore Bonaccorso
Source: soundtouch
Version: 1.9.2-2
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for soundtouch.

CVE-2017-9259[0]:
| The TDStretch::acceptNewOverlapLength function in
| source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote
| attackers to cause a denial of service (memory allocation error and
| application crash) via a crafted wav file.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9259
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9259

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870797: marked as done (libebml4v5: Please rebuild against GCC 7 to fix bug 853553)

2017-08-05 Thread Debian Bug Tracking System
Your message dated Sat, 05 Aug 2017 20:52:46 +
with message-id 
and subject line Bug#870797: fixed in libebml 1.3.4-2
has caused the Debian Bug report #870797,
regarding libebml4v5: Please rebuild against GCC 7 to fix bug 853553
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
870797: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870797
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: libebml4v5
Version: 1.3.4-1
Severity: normal

Dear Maintainer,

Dear Maintainer,

As explained by upstream author libebml need to be rebuilt against GCC 7
to fix mkvtoolnix build with GCC 7

See https://github.com/mbunkus/mkvtoolnix/issues/2067

Christian

-- System Information:
Debian Release: buster/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 4.11.0-1-686-pae (SMP w/4 CPU cores)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C.UTF-8 
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages libebml4v5 depends on:
ii  libc6   2.24-14
ii  libgcc1 1:7.1.0-12
ii  libstdc++6  7.1.0-12

libebml4v5 recommends no packages.

libebml4v5 suggests no packages.

-- no debconf information
--- End Message ---
--- Begin Message ---
Source: libebml
Source-Version: 1.3.4-2

We believe that the bug you reported is fixed in the latest version of
libebml, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 870...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
James Cowgill  (supplier of updated libebml package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@ftp-master.debian.org)


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Sat, 05 Aug 2017 15:54:14 -0400
Source: libebml
Binary: libebml4v5 libebml-dev
Architecture: source
Version: 1.3.4-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Multimedia Maintainers 

Changed-By: James Cowgill 
Description:
 libebml-dev - access library for the EBML format (development files)
 libebml4v5 - access library for the EBML format (shared library)
Closes: 870797
Changes:
 libebml (1.3.4-2) unstable; urgency=medium
 .
   * Team upload.
   * Rebuild with GCC 7 to fix FTBFS of reverse-dependencies. (Closes: #870797)
 - Build-depend on gcc >= 7.
 - Update shlibs to ensure rdeps pull in the new version.
 .
   * debian/compat: Use debhelper compat 10.
   * debian/libebml-dev.files: Remove.
Checksums-Sha1:
 b5597e2fa48aa5cad64dc7a2a5fdb04272b06762 2149 libebml_1.3.4-2.dsc
 4baaac9c1e2c4355ba267e4b5fbb54197455945e 4984 libebml_1.3.4-2.debian.tar.xz
 cf1b8e07cfe2ec23bc7612f4f2b56870ba2e8533 5322 libebml_1.3.4-2_source.buildinfo
Checksums-Sha256:
 07b093b149678371392495cdd685be156d8500c73b96cd09655b6fd2ffdc2880 2149 
libebml_1.3.4-2.dsc
 cbe1f0bda7d84519a346c5702c4eb32f218fa6bb82a3770467aaac89375d8642 4984 
libebml_1.3.4-2.debian.tar.xz
 76583fdbe222b62b5f4ca5989d34d1807102a73f694db150a2bd2f4fcaa5ab7d 5322 
libebml_1.3.4-2_source.buildinfo
Files:
 1cc8fb8de20478019c8fe13ab54e6a08 2149 devel optional libebml_1.3.4-2.dsc
 2128be6f61e87aed23f540af01a887eb 4984 devel optional 
libebml_1.3.4-2.debian.tar.xz
 15829a048dfd46849fd0fcf7a8250ae9 5322 devel optional 
libebml_1.3.4-2_source.buildinfo

-BEGIN PGP SIGNATURE-

iQJIBAEBCgAyFiEE+Ixt5DaZ6POztUwQx/FnbeotAe8FAlmGKOgUHGpjb3dnaWxs
QGRlYmlhbi5vcmcACgkQx/FnbeotAe/CYhAAgUESnUu190tUdb+NC27ycuj/i7cK
03P9kTb21Jsx52kMPldfQwVzpqq/8iH1zeo+EdO/cH6s+7KEW73y83LlN5+4foKI
0FaWXUKv9r5QMgSwxE+B+MZLHPL38vcNTl3b56HAG8WOhglU08aYWFtYc07UKUML
J1ZWAUfGoyaENjvZQxAxh4izv8q+GN2vzELv3K3r3Ew4y4LYa+cSpnvUcw1zl4dt
HifIMruoG+L2s5prIYTzRJYr7dejpKgJ79s29oPtBH7R288r4YlegS3rR5P4iZAq
HqGur+Zb4FqLOPbcks/xBZeXt1ndOGeBJbPd00oFIT9RBW1R44gv77OXbpOSXZfq
F8uAkYJLg6+aArTC+by1mm814fZbaG5vBsXyxUVsvs5vUUxM5KMhqO0a0UYzaoHU
KU262veiSFnrpNICTMvJx1DVRH8VojXKSUYz9e2a1oeAjSabqfPC8jiI7H6JUOJu
ZHMYchf28LrUnwOlv4dhQgmHlE1d47GdevGYALDqJtynuXgzEWaIjkLlRjIhJc7N
HDDnda7b7WFLS8Vd651RTHTdpHeYsOaYJZPjUWdC7SxtdrEfiBmn2KqjWmQ37oox
UmGECARyyE8FF6VFYGa0OowSqsOXGk6pQpq/YSVMb1QfAr04pRbDNTIfrA67Xbvq

Bug#870676: ffmpeg requires NEON on armhf, which is not part of the ARMv7 ABI

2017-08-05 Thread James Cowgill
Hi Steve,

On 03/08/17 21:03, Steve Langasek wrote:
> Package: ffmpeg
> Version: 7:3.3.3-1
> Severity: important
> Tags: patch
> User: ubuntu-de...@lists.ubuntu.com
> Usertags: origin-ubuntu artful ubuntu-patch autopkgtest
> 
> Dear maintainers,
> 
> The latest release of ffmpeg enables NEON support by default when building
> on armhf; however, NEON support is not a standard part of the ARMv7 ABI, and
> Debian supports running armhf on chips that do not implement NEON.
> 
> Using NEON based on runtime detection of support for it is fine, but the
> existing ffmpeg implementation doesn't appear to do this, instead using NEON
> based on build-time configuration with no fallback.

Are you sure this is true? I tried running the failing test on abel.d.o
(which AFAIK does not have NEON) and harris (which does). The test only
caused ffmpeg to crash on harris, which seems to suggest that the
runtime NEON detection is working properly.

These are the commands to reproduce the autopkgtest fail if you want to
try it:

ffmpeg -f lavfi -i testsrc=s=32x32:d=0.1 -strict -2 -c:v libx264rgb -f avi 
libx264rgb.avi -y -hide_banner -nostdin
ffmpeg -strict -2 -i libx264rgb.avi -t 1 -c:v rawvideo -c:a pcm_s32le -f nut 
/dev/null -y -hide_banner -nostdin

> This issue was noticed in Ubuntu only because the autopkgtests for ffmpeg
> and x264 triggered an unaligned access in the NEON code, which is *also* not
> a portable assumption on armhf; however, if the NEON code had not had any
> unaligned access, the fact that NEON was used would have gone unnoticed on
> Ubuntu infrastructure.
> 
>   http://autopkgtest.ubuntu.com/packages/f/ffmpeg/artful/armhf
>   http://autopkgtest.ubuntu.com/packages/x/x264/artful/armhf
> 
> (And if upstream does fix their code to support runtime detection of NEON
> support, then there will be a different bug for us to worry about fixing!)

This is #870622 BTW. If possible, I would much rather fix these bugs
without having to disable all the NEON optimizations.

Thanks,
James



signature.asc
Description: OpenPGP digital signature
___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#870676: ffmpeg requires NEON on armhf, which is not part of the ARMv7 ABI

2017-08-05 Thread Steve Langasek
Control: forcemerge 870622 -1

Hi James,

On Sat, Aug 05, 2017 at 02:40:12PM -0400, James Cowgill wrote:

> > The latest release of ffmpeg enables NEON support by default when building
> > on armhf; however, NEON support is not a standard part of the ARMv7 ABI, and
> > Debian supports running armhf on chips that do not implement NEON.

> > Using NEON based on runtime detection of support for it is fine, but the
> > existing ffmpeg implementation doesn't appear to do this, instead using NEON
> > based on build-time configuration with no fallback.

> Are you sure this is true? I tried running the failing test on abel.d.o
> (which AFAIK does not have NEON) and harris (which does). The test only
> caused ffmpeg to crash on harris, which seems to suggest that the
> runtime NEON detection is working properly.

Nope, not sure at all, I only know what I saw from code inspection where I
failed to find where the code falls back on non-NEON systems.

I see you're right that abel does not have NEON (it's not exposed in
/proc/cpuinfo feature flags for the CPU), so if ffmpeg runs without crashing
there, I guess that's pretty clear evidence that there is a runtime fallback
that I overlooked.

> These are the commands to reproduce the autopkgtest fail if you want to
> try it:

> ffmpeg -f lavfi -i testsrc=s=32x32:d=0.1 -strict -2 -c:v libx264rgb -f avi 
> libx264rgb.avi -y -hide_banner -nostdin
> ffmpeg -strict -2 -i libx264rgb.avi -t 1 -c:v rawvideo -c:a pcm_s32le -f nut 
> /dev/null -y -hide_banner -nostdin

> > This issue was noticed in Ubuntu only because the autopkgtests for ffmpeg
> > and x264 triggered an unaligned access in the NEON code, which is *also* not
> > a portable assumption on armhf; however, if the NEON code had not had any
> > unaligned access, the fact that NEON was used would have gone unnoticed on
> > Ubuntu infrastructure.
> > 
> >   http://autopkgtest.ubuntu.com/packages/f/ffmpeg/artful/armhf
> >   http://autopkgtest.ubuntu.com/packages/x/x264/artful/armhf
> > 
> > (And if upstream does fix their code to support runtime detection of NEON
> > support, then there will be a different bug for us to worry about fixing!)
> 
> This is #870622 BTW. If possible, I would much rather fix these bugs
> without having to disable all the NEON optimizations.

So, marking this bug as a duplicate of the real bug (the unaligned trap
problem due to binutils).

Thanks,
-- 
Steve Langasek   Give me a lever long enough and a Free OS
Debian Developer   to set it on, and I can move the world.
Ubuntu Developerhttp://www.debian.org/
slanga...@ubuntu.com vor...@debian.org


signature.asc
Description: PGP signature
___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Processed (with 1 error): Re: Bug#870676: ffmpeg requires NEON on armhf, which is not part of the ARMv7 ABI

2017-08-05 Thread Debian Bug Tracking System
Processing control commands:

> forcemerge 870622 -1
Bug #870622 [src:ffmpeg] ffmpeg: autopkgtest SIGBUS on armhf with binutils 2.29
Unable to merge bugs because:
package of #870676 is 'ffmpeg' not 'src:ffmpeg'
Failed to forcibly merge 870622: Did not alter merged bugs.


-- 
870622: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870622
870676: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870676
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Processed: reassign 870676 to src:ffmpeg, forcibly merging 870622 870676

2017-08-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> reassign 870676 src:ffmpeg
Bug #870676 [ffmpeg] ffmpeg requires NEON on armhf, which is not part of the 
ARMv7 ABI
Bug reassigned from package 'ffmpeg' to 'src:ffmpeg'.
No longer marked as found in versions ffmpeg/7:3.3.3-1.
Ignoring request to alter fixed versions of bug #870676 to the same values 
previously set
> forcemerge 870622 870676
Bug #870622 [src:ffmpeg] ffmpeg: autopkgtest SIGBUS on armhf with binutils 2.29
Bug #870676 [src:ffmpeg] ffmpeg requires NEON on armhf, which is not part of 
the ARMv7 ABI
Marked as found in versions ffmpeg/7:3.3.3-1.
Added tag(s) buster and sid.
Bug #870622 [src:ffmpeg] ffmpeg: autopkgtest SIGBUS on armhf with binutils 2.29
Added tag(s) patch.
Merged 870622 870676
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
870622: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870622
870676: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870676
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870859: jaaa FTCBFS: hardcodes the build architecture compiler in one place

2017-08-05 Thread Helmut Grohne
Source: jaaa
Version: 0.8.4-3
Tags: patch
User: helm...@debian.org
Usertags: rebootstrap

jaaa fails to cross build from source, because its final link step hard
codes the build architecture compiler (g++) in the upstream build
system. After making that substitutable, it cross builds successfully.
Please consider applying the attached patch.

Helmut
diff --minimal -Nru jaaa-0.8.4/debian/changelog jaaa-0.8.4/debian/changelog
--- jaaa-0.8.4/debian/changelog 2016-12-22 13:52:44.0 +0100
+++ jaaa-0.8.4/debian/changelog 2017-08-05 21:53:50.0 +0200
@@ -1,3 +1,10 @@
+jaaa (0.8.4-3.1) UNRELEASED; urgency=medium
+
+  * Non-maintainer upload.
+  * Fix FTCBFS: Do not hard code g++. (Closes: #-1)
+
+ -- Helmut Grohne   Sat, 05 Aug 2017 21:53:50 +0200
+
 jaaa (0.8.4-3) unstable; urgency=medium
 
   * Set dh 10.
diff --minimal -Nru jaaa-0.8.4/debian/patches/jaaa-rzr.patch 
jaaa-0.8.4/debian/patches/jaaa-rzr.patch
--- jaaa-0.8.4/debian/patches/jaaa-rzr.patch2013-08-12 21:34:53.0 
+0200
+++ jaaa-0.8.4/debian/patches/jaaa-rzr.patch2017-08-05 21:53:31.0 
+0200
@@ -4,11 +4,11 @@
  Makefile |   10 +-
  1 file changed, 5 insertions(+), 5 deletions(-)
 
 Index: jaaa/source/Makefile
 ===
 --- jaaa.orig/source/Makefile  2013-08-07 13:38:13.937342777 +0200
 +++ jaaa/source/Makefile   2013-08-07 14:01:17.176201895 +0200
-@@ -19,13 +19,13 @@
+@@ -19,26 +19,27 @@
  #  --
  
  
@@ -25,7 +25,14 @@
  LDFLAGS += -L/usr/X11R6/$(LIBDIR)
  LDLIBS += -lzita-alsa-pcmi -lclthreads -lclxclient -lpthread -lfftw3f -ljack 
-lasound -lpthread -lXft -lX11 -lrt
  
-@@ -39,6 +39,7 @@
+ 
+ JAAA_O = jaaa.o styles.o spectwin.o audio.o rngen.o
+ jaaa: $(JAAA_O)
+-  g++ $(LDFLAGS) -o $@ $(JAAA_O) $(LDLIBS)
++  $(CXX) $(LDFLAGS) -o $@ $(JAAA_O) $(LDLIBS)
+ 
+ $(JAAA_O):
+ -include $(JAAA_O:%.o=%.d)
  
  
  install:  jaaa
___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#870862: directfb FTCBFS: configure: error: Could not find a directfb-csource in your PATH

2017-08-05 Thread Helmut Grohne
Source: directfb
Version: 1.2.10.0-9
Tags: patch
User: helm...@debian.org
Usertags: rebootstrap

directfb fails to cross build from source:

| checking for directfb-csource... no
| configure: error: Could not find a directfb-csource in your PATH

It seems that for cross builds directfb expects to be able to run a
system-provided directfb-csource. That lives in libdirectfb-bin. So
directfb is missing a cross-specific dependency on libdirectfb-bin.
Since it wants to run directfb-csource, it needs to be installed for the
build architecture. That can be achieved by either marking the
libdirectfb-bin dependency with :native or by marking libdirectfb-bin
Multi-Arch: foreign. I think the latter is appropriate here, because
libdirectfb-bin contains only command line utilities. As far as I
understand their behaviour does not depend on the architecture of the
package. If that statement is wrong, it must not be marked M-A:foreign.
Please consider applying the attached patch after verifying that
M-A:foreign is indeed correct on libdirectfb-bin.

Helmut
diff --minimal -Nru directfb-1.2.10.0/debian/changelog 
directfb-1.2.10.0/debian/changelog
--- directfb-1.2.10.0/debian/changelog  2017-01-30 20:56:58.0 +0100
+++ directfb-1.2.10.0/debian/changelog  2017-08-05 22:10:01.0 +0200
@@ -1,3 +1,12 @@
+directfb (1.2.10.0-9.1) UNRELEASED; urgency=medium
+
+  * Non-maintainer upload.
+  * Fix FTCBFS: (Closes: #-1)
++ Add missing cross build dependency on libdirectfb-bin.
++ Mark libdirectfb-bin Multi-Arch: foreign.
+
+ -- Helmut Grohne   Sat, 05 Aug 2017 22:10:01 +0200
+
 directfb (1.2.10.0-9) unstable; urgency=medium
 
   * debian/libdirectfb-1.2-9.install: Fix architecture-based filter to
diff --minimal -Nru directfb-1.2.10.0/debian/control 
directfb-1.2.10.0/debian/control
--- directfb-1.2.10.0/debian/control2017-01-30 20:53:05.0 +0100
+++ directfb-1.2.10.0/debian/control2017-08-05 22:10:01.0 +0200
@@ -6,6 +6,7 @@
 Build-Depends:
  debhelper (>= 10),
  dh-exec,
+ libdirectfb-bin ,
  libfreetype6-dev,
  libgl1-mesa-dev,
  libjpeg-dev,
@@ -61,6 +62,7 @@
 
 Package: libdirectfb-bin
 Architecture: any
+Multi-Arch: foreign
 Depends:
  ${misc:Depends},
  ${shlibs:Depends}
___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers

Bug#870854: soundtouch: CVE-2017-9258

2017-08-05 Thread Salvatore Bonaccorso
Source: soundtouch
Version: 1.9.2-2
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for soundtouch. There is as
well CVE-2017-9259 and CVE-2017-9260, but since I have not verified if
the issues are all commont back to jessie, fill individual bugs. OTOH
I do not think they deserve a DSA, let us know though if you disagree.

CVE-2017-9258[0]:
| The TDStretch::processSamples function in
| source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote
| attackers to cause a denial of service (infinite loop and CPU
| consumption) via a crafted wav file.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9258
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9258

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Processed: Bug#870797 marked as pending

2017-08-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> tag 870797 pending
Bug #870797 [libebml4v5] libebml4v5: Please rebuild against GCC 7 to fix bug 
853553
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
870797: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870797
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


libebml_1.3.4-2_source.changes ACCEPTED into unstable

2017-08-05 Thread Debian FTP Masters


Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Sat, 05 Aug 2017 15:54:14 -0400
Source: libebml
Binary: libebml4v5 libebml-dev
Architecture: source
Version: 1.3.4-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Multimedia Maintainers 

Changed-By: James Cowgill 
Description:
 libebml-dev - access library for the EBML format (development files)
 libebml4v5 - access library for the EBML format (shared library)
Closes: 870797
Changes:
 libebml (1.3.4-2) unstable; urgency=medium
 .
   * Team upload.
   * Rebuild with GCC 7 to fix FTBFS of reverse-dependencies. (Closes: #870797)
 - Build-depend on gcc >= 7.
 - Update shlibs to ensure rdeps pull in the new version.
 .
   * debian/compat: Use debhelper compat 10.
   * debian/libebml-dev.files: Remove.
Checksums-Sha1:
 b5597e2fa48aa5cad64dc7a2a5fdb04272b06762 2149 libebml_1.3.4-2.dsc
 4baaac9c1e2c4355ba267e4b5fbb54197455945e 4984 libebml_1.3.4-2.debian.tar.xz
 cf1b8e07cfe2ec23bc7612f4f2b56870ba2e8533 5322 libebml_1.3.4-2_source.buildinfo
Checksums-Sha256:
 07b093b149678371392495cdd685be156d8500c73b96cd09655b6fd2ffdc2880 2149 
libebml_1.3.4-2.dsc
 cbe1f0bda7d84519a346c5702c4eb32f218fa6bb82a3770467aaac89375d8642 4984 
libebml_1.3.4-2.debian.tar.xz
 76583fdbe222b62b5f4ca5989d34d1807102a73f694db150a2bd2f4fcaa5ab7d 5322 
libebml_1.3.4-2_source.buildinfo
Files:
 1cc8fb8de20478019c8fe13ab54e6a08 2149 devel optional libebml_1.3.4-2.dsc
 2128be6f61e87aed23f540af01a887eb 4984 devel optional 
libebml_1.3.4-2.debian.tar.xz
 15829a048dfd46849fd0fcf7a8250ae9 5322 devel optional 
libebml_1.3.4-2_source.buildinfo

-BEGIN PGP SIGNATURE-

iQJIBAEBCgAyFiEE+Ixt5DaZ6POztUwQx/FnbeotAe8FAlmGKOgUHGpjb3dnaWxs
QGRlYmlhbi5vcmcACgkQx/FnbeotAe/CYhAAgUESnUu190tUdb+NC27ycuj/i7cK
03P9kTb21Jsx52kMPldfQwVzpqq/8iH1zeo+EdO/cH6s+7KEW73y83LlN5+4foKI
0FaWXUKv9r5QMgSwxE+B+MZLHPL38vcNTl3b56HAG8WOhglU08aYWFtYc07UKUML
J1ZWAUfGoyaENjvZQxAxh4izv8q+GN2vzELv3K3r3Ew4y4LYa+cSpnvUcw1zl4dt
HifIMruoG+L2s5prIYTzRJYr7dejpKgJ79s29oPtBH7R288r4YlegS3rR5P4iZAq
HqGur+Zb4FqLOPbcks/xBZeXt1ndOGeBJbPd00oFIT9RBW1R44gv77OXbpOSXZfq
F8uAkYJLg6+aArTC+by1mm814fZbaG5vBsXyxUVsvs5vUUxM5KMhqO0a0UYzaoHU
KU262veiSFnrpNICTMvJx1DVRH8VojXKSUYz9e2a1oeAjSabqfPC8jiI7H6JUOJu
ZHMYchf28LrUnwOlv4dhQgmHlE1d47GdevGYALDqJtynuXgzEWaIjkLlRjIhJc7N
HDDnda7b7WFLS8Vd651RTHTdpHeYsOaYJZPjUWdC7SxtdrEfiBmn2KqjWmQ37oox
UmGECARyyE8FF6VFYGa0OowSqsOXGk6pQpq/YSVMb1QfAr04pRbDNTIfrA67Xbvq
SOal/avNh6njs4o=
=NkY5
-END PGP SIGNATURE-


Thank you for your contribution to Debian.

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


milkytracker 1.01.00+dfsg-1 MIGRATED to testing

2017-08-05 Thread Debian testing watch
FYI: The status of the milkytracker source package
in Debian's testing distribution has changed.

  Previous version: 1.0.0+dfsg-2
  Current version:  1.01.00+dfsg-1

-- 
This email is automatically generated once a day.  As the installation of
new packages into testing happens multiple times a day you will receive
later changes on the next day.
See https://release.debian.org/testing-watch/ for more information.

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


calf 0.0.60-5 MIGRATED to testing

2017-08-05 Thread Debian testing watch
FYI: The status of the calf source package
in Debian's testing distribution has changed.

  Previous version: 0.0.60-4
  Current version:  0.0.60-5

-- 
This email is automatically generated once a day.  As the installation of
new packages into testing happens multiple times a day you will receive
later changes on the next day.
See https://release.debian.org/testing-watch/ for more information.

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


rem 0.5.1-3 MIGRATED to testing

2017-08-05 Thread Debian testing watch
FYI: The status of the rem source package
in Debian's testing distribution has changed.

  Previous version: 0.5.0-3
  Current version:  0.5.1-3

-- 
This email is automatically generated once a day.  As the installation of
new packages into testing happens multiple times a day you will receive
later changes on the next day.
See https://release.debian.org/testing-watch/ for more information.

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870797: libebml4v5: Please rebuild against GCC 7 to fix bug 853553

2017-08-05 Thread Christian Marillat
Package: libebml4v5
Version: 1.3.4-1
Severity: normal

Dear Maintainer,

Dear Maintainer,

As explained by upstream author libebml need to be rebuilt against GCC 7
to fix mkvtoolnix build with GCC 7

See https://github.com/mbunkus/mkvtoolnix/issues/2067

Christian

-- System Information:
Debian Release: buster/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 4.11.0-1-686-pae (SMP w/4 CPU cores)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C.UTF-8 
(charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages libebml4v5 depends on:
ii  libc6   2.24-14
ii  libgcc1 1:7.1.0-12
ii  libstdc++6  7.1.0-12

libebml4v5 recommends no packages.

libebml4v5 suggests no packages.

-- no debconf information

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870799: mpg123: CVE-2017-9545

2017-08-05 Thread Salvatore Bonaccorso
Source: mpg123
Version: 1.23.8-1
Severity: important
Tags: security upstream

Hi,

the following vulnerability was published for mpg123.

CVE-2017-9545[0]:
| The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows
| remote attackers to cause a denial of service (buffer over-read) via a
| crafted mp3 file.

Not sure if the reporter has reported that upstream. 

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-9545
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9545
[1] http://seclists.org/fulldisclosure/2017/Jul/65

Please adjust the affected versions in the BTS as needed, checked only
versions back to 1.23.8-1 in stretch.

Regards,
Salvatore

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#870809: lame: CVE-2017-11720

2017-08-05 Thread Salvatore Bonaccorso
Source: lame
Version: 3.99.5+repack1-7
Severity: important
Tags: security upstream
Forwarded: https://sourceforge.net/p/lame/bugs/460/

Hi,

the following vulnerability was published for lame.

CVE-2017-11720[0]:
| There is a division-by-zero vulnerability in LAME 3.99.5, caused by a
| malformed input file.

This should be/is almost surely a the same as reported in [2].

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-11720
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11720
[1] https://sourceforge.net/p/lame/bugs/460/
[2] 
https://blogs.gentoo.org/ago/2017/06/17/lame-divide-by-zero-in-parse_wave_header-get_audio-c/

Regards,
Salvatore

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Processed: Merge duplicates

2017-08-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> forcemerge 853484 841624
Bug #853484 [src:libcdio] libcdio: ftbfs with GCC-7
Bug #841624 [src:libcdio] libcdio: FTBFS: ../../include/cdio/iso9660.h:277:45: 
error: flexible array member 'iso9660_dir_s::filename' not at end of 'struct 
iso9660_pvd_s'
Severity set to 'serious' from 'important'
853476 was blocked by: 853484
853476 was not blocking any bugs.
Added blocking bug(s) of 853476: 841624
Merged 841624 853484
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
841624: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=841624
853476: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853476
853484: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853484
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers


Bug#853671: supercollider: ftbfs with GCC-7

2017-08-05 Thread Felipe Sateler
Hi Dan,


On Tue, Jan 31, 2017 at 6:36 AM, Matthias Klose  wrote:
> Package: src:supercollider
> Version: 1:3.7.0~repack-4
> Severity: normal
> Tags: sid buster
> User: debian-...@lists.debian.org
> Usertags: ftbfs-gcc-7
>
> The package fails to build in a test rebuild on at least amd64 with
> gcc-7/g++-7, but succeeds to build with gcc-6/g++-6. The
> severity of this report may be raised before the buster release.
> There is no need to fix this issue in time for the stretch release.

The severity was raised so now it is RC. I also see that there are
newer upstream releases. Maybe this issue does not exist in the newer
release?

-- 

Saludos,
Felipe Sateler

___
pkg-multimedia-maintainers mailing list
pkg-multimedia-maintainers@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-multimedia-maintainers