Bug#928560: vim-voom: vim-gnome transitional package no longer exists; please use vim-gtk3

2019-05-06 Thread Adam Conrad
Package: vim-voom Version: 5.3-1 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu eoan ubuntu-patch In Ubuntu, the attached patch was applied to achieve the following: * debian/control: Depend on vim-gtk3 instead of obsolte vim-gnome. The patch should

Bug#924624: rclone: remote "crypt" is missing

2019-05-06 Thread Drew Parsons
Package: rclone Followup-For: Bug #924624 crypt is there in your list, Item 9. -- System Information: Debian Release: 10.0 APT prefers unstable APT policy: (500, 'unstable'), (1, 'experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.19.0-4-amd64 (SMP w/4

Bug#928559: manpages: contrary to the manpage, the infinite loop in pldd(1) is no longer present

2019-05-06 Thread Asher Gordon
Package: manpages Version: 4.16-1 Severity: minor Tags: patch Dear Maintainer, The manpage for pldd(1) says BUGS Since glibc 2.19, pldd is broken: it just hangs when executed. It is unclear if it will ever be fixed. However, in glibc 2.28-10, this bug was fixed. The manpage

Bug#928558: reportbug: "message-fetch-field" should be "mail-fetch-field" in reportbug.el

2019-05-06 Thread Asher Gordon
Package: reportbug Version: 7.5.2 Severity: normal Tags: patch Dear Maintainer, When I run "reportbug -G" ("-G" to use the Gnus MUA), it starts up emacs with a buffer containing the message, but it is in text-mode and not in message-mode as one would expect. Here is the relevant part of the

Bug#928557: u-boot: CVE-2019-11690

2019-05-06 Thread Salvatore Bonaccorso
Source: u-boot Version: 2019.01+dfsg-5 Severity: normal Tags: security upstream Forwarded: https://patchwork.ozlabs.org/patch/1092945 Hi Vagrant, The following vulnerability was published for u-boot. I'm not sure how relevant the issue is in Debian context, and we marked the issue at least

Bug#926903: Installation-report addition

2019-05-06 Thread Cyril Brulebois
Ben Hutchings (2019-05-06): > 1. The installer-with-firmware is not installing firmware-amd-graphics >automatically on systems with AMD GPUs that need it. […] > I'm cloning this and will fix the second bug, but I don't know how to > fix the first. src:discover? Cheers, -- Cyril Brulebois

Bug#928555: upgrade to buster from stretch suggests to remove bridge-utils

2019-05-06 Thread Brenden Eng
Please see correction, I ran `apt autoremove` and then restarted. bridge-utils was not automatically removed during the installation, it was after running `apt autoremove` On Mon, 6 May 2019 23:54:05 -0400 Brenden Eng wrote: > Package: upgrade-reports > > Version: buster > > My system has a

Bug#833706: I have a problem in install

2019-05-06 Thread Cyril Brulebois
John Superman (2019-05-05): > Please help me to sucessfully install Kali Linux. Problem:loading > libc6-udeb for unknown reasons Please take this to Kali people. Cheers, -- Cyril Brulebois (k...@debian.org) D-I release manager -- Release team member --

Bug#928506: installation-report: fails to find mirror under OpenBSD vmm(4) hypervisor

2019-05-06 Thread Cyril Brulebois
Control: tag -1 - d-i Hi Matthew, Matthew T Hoare (2019-05-06): > Dear Maintainer, > >* What led up to the situation? >I ran the installer under OpenBSD's vmm(4) hypervisor. >* What exactly did you do (or not do) that was effective (or > ineffective)? >Tried to connect to

Bug#928556: stretch-pu: package gocode/20150303-3+deb9u2

2019-05-06 Thread Andreas Beckmann
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi, the last stretch-pu update of gocode caused a regression on jessie->stretch updates. If I make the recently added Pre-Depends versioned to pull in the version from stretch

Bug#928555: upgrade to buster from stretch suggests to remove bridge-utils

2019-05-06 Thread Brenden Eng
Package: upgrade-reports Version: buster My system has a bridge interface configured in /etc/network/interfaces. I upgraded from stretch to buster. After the successful upgrade in the list of packages to be auto-removed is bridge-utils. "The following packages were automatically installed and

Bug#927245: caveconverter: FTBFS (jh_build: Cannot find "caveconverter")

2019-05-06 Thread Wookey
On 2019-04-19 00:32 +0100, Wookey wrote: > > jh_build: Compatibility levels before 9 are deprecated (level 7 in use) > > jh_build: Cannot find (any matches for) "caveconverter" (tried in .) > > Confirmed, thanks. I'll work out what's gone wrong there and upload a fix. OK. Seems the issue was

Bug#928554: dgit-nmu-simple should give an example of generating a patches-unapplied nmudiff

2019-05-06 Thread Sam Hartman
package: dgit version: 8.3 severity: wishlist The dgit-nmu-simple man page doesn't give any explicit examples of generating an nmudiff. It's unclear that we actually have a standard on whether an nmudiff should be patches-applied or patches-unapplied. I find that I typically get

Bug#921688: NMU Diff

2019-05-06 Thread Sam Hartman
Dear maintainer. I made the following 0-day NMU of electrum. I suspect that once you update to a new version you will not wish to include these changes, but in the interest of awareness of your package I wanted to make sure you were aware. diff --git a/debian/changelog b/debian/changelog index

Bug#928553: stretch-pu: package libthrift-java/0.9.1-2.1~deb9u1

2019-05-06 Thread Andreas Beckmann
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu The fix for CVE-2018-1320 was in sid (0.9.1-2.1) before the package got removed, and is in jessie-lts (0.9.1-2+deb8u1), leaving stretch at an older version than jessie-lts. So

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Sylvain Beucler
Hi, On 06/05/2019 23:33, Sylvain Beucler wrote: > On 06/05/2019 15:47, Hideki Yamane wrote: >> On Mon, 6 May 2019 15:04:09 +0200 Karsten wrote: >>> Package: firefox-esr >>> Version: 60.6.1esr-1~deb8u1 >> It was already done in unstable and stable-proposed-updates, and >> reporter asks about

Bug#927735: Package nvidia-kernel-dkms unmet dependencies

2019-05-06 Thread Andreas Beckmann
On 2019-04-22 07:09, TarotApprentice wrote: > The one from Stretch-backports... > # apt install -t stretch-backports nvidia-kernel-dkmsReading package lists... > DoneBuilding dependency treeReading state information... DoneSome packages > could not be installed. This may mean that you

Bug#927735: 418.56-2 (now in sid) resolves

2019-05-06 Thread Andreas Beckmann
On 2019-04-28 06:33, TarotApprentice wrote: > Another issue that is possibly related to Buster (using the RC1 iso image) if > one installs Buster and then the 410 version from buster or the 418 version > from sid results in Debian boot hanging and no desktop/logon prompt is > displayed. I can

Bug#928497: nvidia-persistenced: Error in nvidia-persistenced source (postinst)

2019-05-06 Thread Andreas Beckmann
Control: tag -1 moreinfo On 2019-05-06 08:01, Marcelo "Elppans" Klumpp wrote: > There is an ambiguous configuration error in the file > "debian/nvidia-persistenced.postinst": > It means that you should create a "home" folder in /var/run/nvpd/, but at the > end of the code it says DO NOT CREATE

Bug#928552: texlive-fonts-extra-links: missing Breaks+Replaces: texlive-fonts-extra (<< 2019)

2019-05-06 Thread Andreas Beckmann
Package: texlive-fonts-extra-links Version: 2019.20190506-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package fails to upgrade from 'sid' to 'experimental'. It installed fine in 'sid', then the upgrade to 'experimental'

Bug#924591: this requires linking in libsparse, which is from Android sources

2019-05-06 Thread Theodore Ts'o
clone 924591 -1 reassign 924591 fastboot 1:8.1.0+r23-4 retitle -1 e2fsprogs: add support for dynamically loading libsparse severity -1 wishlist thanks I'm reassigning the original bug back to fastboot. I've cloned the bug and made it a feature request of having e2fsprogs dynamically load

Bug#928550: dpkg: warning: while removing openjdk-11-jre-headless:amd64, directory '/usr/lib/jvm' not empty so not removed

2019-05-06 Thread 積丹尼 Dan Jacobson
Package: openjdk-11-jre-headless:amd64 Version: 11.0.3+7-4 Severity: minor dpkg: warning: while removing openjdk-11-jre-headless:amd64, directory '/usr/lib/jvm' not empty so not removed $ find /usr/lib/jvm -type f -ls /usr/lib/jvm/java-9-openjdk-amd64/lib/server/classes.jsa

Bug#928549: golang-github-abbot-go-http-auth: FTBFS: cannot find package "golang.org/x/crypto/bcrypt", "golang.org/x/net/context"

2019-05-06 Thread Andreas Beckmann
Package: golang-github-abbot-go-http-auth Version: 0.4.0-1 Severity: serious Tags: ftbfs Justification: fails to build from source Hi, golang-github-abbot-go-http-auth/experimental FTBFS with debian/rules build dh build --buildsystem=golang --with=golang --builddirectory=_build

Bug#928498: gitg: Crash with assertion failed

2019-05-06 Thread Bernhard Übelacker
Control: reassign 928498 gtksourceview3 3.24.9-2 Control: tags + 928498 upstream fixed-upstream patch Control: affects 928498 gitg gedit Dear Maintainer, this crash seems to be described in upstream bugs [1] and [2]. And upstream seems to have a fix commited to the 3.24 branch [3] too. A

Bug#920563: dracut: fails to boot with bash 5 as /bin/sh

2019-05-06 Thread Lehel Bernadt
Hi Thomas, Yes it does. Applied fix-bash-5.patch with "patch -p1" under /usr/lib/dracut, then ran "dracut --force" to regenerate the initramfs image. After restarting, no problems at boot. Regards, Lehel On 2019-05-05 21:34, Thomas Lange wrote: Hi Lehel, hi Ingo, it would be nice if you

Bug#928548: unblock: libetpan/1.9.3-2

2019-05-06 Thread Ricardo Mones
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package libetpan The upload just adds an upstream patch to fix serious bug #927709. Full debdiff attached, thanks in advance! unblock libetpan/1.9.3-2 -- System

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-06 Thread Daniel Kahn Gillmor
Package: mailscripts Severity: wishlist Control: affects -1 notmuch notmuch-{import-patch,extract-patch,slurpdebbug} could all be "notmuch" subcommands, similar to the way that notmuch-emacs-mua is. their configuration could also be stored in notmuch's own configuration, rather than in

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Sylvain Beucler
Hi, On 06/05/2019 15:47, Hideki Yamane wrote: > On Mon, 6 May 2019 15:04:09 +0200 Karsten wrote: >> Package: firefox-esr >> Version: 60.6.1esr-1~deb8u1 > It was already done in unstable and stable-proposed-updates, and > reporter asks about oldstable, so CC:ed to lts mailing list. > > LTS

Bug#519076: lightyears: gameplay becomes too fast (for me)

2019-05-06 Thread Steve Cotton
On Tue, Mar 10, 2009 at 10:44:32PM +1300, Jasen Betts wrote: > Package: lightyears > Version: 1.3a-4 > > help! how can I slow down the gameplay or is it meant to be frantic? This bug report is now 10 years old, but some comments (based on version 1.4): The game can be treated as a puzzle,

Bug#928546: /etc/fstab.d

2019-05-06 Thread john.pseudonym1
Package: util-linux Version: 2.29.2-1 Severity: normal Hi, As part of the hardening of an anonymity focused operating system called Whonix, we need to add different mount options for different filesystems e.g. hidepid=2 on /proc or noexec on /home. To make sure that a user's own fstab

Bug#870644: openjpeg2: Make source package bootstrappable

2019-05-06 Thread Helmut Grohne
Source: openjpeg2 Version: 2.3.0-2 Followup-For: Bug #870644 Tags: patch Here is a patch to demote the java stuff to Build-Depends-Indep. There is no build profile necessary for these dependencies as one can simply perform an arch-only build first and a full build later. Helmut diff --minimal

Bug#928353: Fwd: release-notes: document mutt vs neomutt in buster

2019-05-06 Thread Justin B Rye
Antonio Radici wrote: > This is what I propose to write down in the release notes, feel free to adjust > as you see fit Thanks! > > > Starting from Buster, the mutt package will be shipped again from the original > sources from https://www.mutt.org, this means that some of the features that

Bug#928526: linux-image-4.19.0-4-amd64: data corruption when swapping to encrypted SSD with LVM and TRIM enabled

2019-05-06 Thread Simon Richter
Hi, On 06.05.19 21:35, Simon Richter wrote: > I can probably test intermediate versions and/or changes in setup, but this > is difficult to automate because "bad" runs require manual file system > repairs and every run requires LUKS setup to be repeated. FWIW, using a separate LV and swapon

Bug#928401: [pre-approval] unblock: manpages/4.16-2

2019-05-06 Thread Paul Gevers
Control: tags -1 confirmed moreinfo On 03-05-2019 23:28, Dr. Tobias Quathamer wrote: > Am 03.05.19 um 22:58 schrieb Dr. Tobias Quathamer: >> I've attached the .dsc debdiff. I can confirm that the debdiff of the >> binary packages shows the newly included manpages. > > ... however, the

Bug#928545: graphite2 has a dependency cycle with python3-fonttools

2019-05-06 Thread Helmut Grohne
Source: graphite2 Version: 1.3.13-7 Severity: important Tags: patch graphite2 Build-Depends on python3-fonttools, whose installation set contains libgraphite2-3. That's bad for bootstrapping. It turns out that graphite2 only needs python3-fonttools for running tests. Thus the dependency can be

Bug#928351: unblock dhcpcd5/7.1.0-2

2019-05-06 Thread Paul Gevers
Control: tags -1 moreinfo confirmed Hi Scott, On 06-05-2019 05:30, Scott Leggett wrote: > On 2019-05-05.20:47, Salvatore Bonaccorso wrote: >> As for all those CVEs are known (see respective bugs and >> security-tracker), can you please add the rspective CVE ids as well to >> the debian/changelog

Bug#926878: Bug

2019-05-06 Thread Paul Gevers
Hmm. On 06-05-2019 21:52, Paul Gevers wrote: > Also make sure you can help them moving forward with their unblock > request, by making sure your *targeted* fixes are available in unstable. > sa-exim would need to be unblocked first or at the same time, so don't > add unnecessary changes to your

Bug#928353: Fwd: release-notes: document mutt vs neomutt in buster

2019-05-06 Thread Antonio Radici
This is what I propose to write down in the release notes, feel free to adjust as you see fit Starting from Buster, the mutt package will be shipped again from the original sources from https://www.mutt.org, this means that some of the features that were previously available due to patches

Bug#928544: debsources: wheezy gone missing

2019-05-06 Thread Jakub Wilk
Package: qa.debian.org User: qa.debian@packages.debian.org Usertags: debsources Some (all?) wheezy packages have disappeared from sources.d.o. For example, there's no wheezy package here: https://sources.debian.org/src/bash/ It used to be there in the past:

Bug#928543: ucarp should depend on ifupdown|ifupdown2 instead of versioned ifupdown only

2019-05-06 Thread George Diamantopoulos
Package: ucarp Version: 1.5.2-2.2 Severity: important Dear Maintainer, ucarp has the following 'Depends:' directive in its control file: Depends: ifupdown (>= 0.7.1) ifupdown2 provides this as a virtual package: Provides: ifupdown Since ifupdown2 does not use a versioned 'Provides:'

Bug#926878: Bug

2019-05-06 Thread Paul Gevers
Hi Magnus, On 05-05-2019 23:42, Magnus Holmgren wrote: > after some investigation, I believe I have the issues in sa-exim under > control. The broken spool files were due to a memory corruption that could > easily be worked around. The issue with CHUNKING was mainly that SpamAssassin > uses

Bug#928539: O: wmail -- WindowMaker docklet watching your inbox

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of wmail, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928538: O: xpyb -- Python bindings to XCB

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of xpyb, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer, please

Bug#928541: O: commando -- wrapper for argparse to define declaratively (Python 2)

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of commando, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928540: O: webcamd -- Capture images from video devices

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of webcamd, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928542: O: python-fswrap -- unified object oriented interface to file system objects

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of python-fswrap, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new

Bug#928537: O: el-get -- install and manage elisp code for Emacs

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of el-get, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928529: O: sysrqd -- small daemon intended to manage Linux SysRq over network

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of sysrqd, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928535: O: libapache2-mod-defensible -- module for Apache2 which provides DNSBL usage

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of libapache2-mod-defensible, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the

Bug#928531: O: varmon -- VA RAID monitor

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of varmon, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928530: O: duma -- library to detect buffer overruns and under-runs in C and C++ programs

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of duma, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer, please

Bug#928536: O: python-first -- simple function that returns the first true value from an iterable

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of python-first, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new

Bug#928532: O: rebuildd -- build daemon aiming at rebuilding Debian packages

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of rebuildd, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928533: O: tetrinetx -- game server for Tetrinet

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of tetrinetx, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928528: O: gsutil -- configure and manage Grandstream BudgeTone 100 VOIP and GX2000 phones

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of gsutil, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer,

Bug#928534: O: pisg -- Perl IRC Statistics Generator

2019-05-06 Thread Tobias Frost
Package: wnpp The current maintainer of pisg, Julien Danjou , has retired. Therefore, I orphan this package now. Maintaining a package requires time and skills. Please only adopt this package if you will have enough time and attention to work on it. If you want to be the new maintainer, please

Bug#922669: sqlalchemy: CVE-2019-7164 CVE-2019-7548 (SQL injection)

2019-05-06 Thread Ross Vandegrift
On Mon, May 06, 2019 at 10:20:25AM +0200, Thomas Goirand wrote: > On 5/6/19 5:09 AM, Ross Vandegrift wrote: > > Source: sqlalchemy > > Version: 1.2.18+ds1 > > Followup-For: Bug #922669 > > > > I've confirmed that 1.2.18+ds1 is affected despite the description at [1]. > > Upstream has a patch for

Bug#928527: unblock: peek/1.3.1-6

2019-05-06 Thread Boyuan Yang
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock peek 1.3.1-6. This upload fixes https://bugs.debian.org/926386 , which caused the application to crash when recording GIF using the ffmpeg backend. The full debdiff is

Bug#928526: linux-image-4.19.0-4-amd64: data corruption when swapping to encrypted SSD with LVM and TRIM enabled

2019-05-06 Thread Simon Richter
Package: src:linux Version: 4.19.28-2 Severity: grave Tags: upstream Justification: causes non-serious data loss Hi, I have an older laptop with an SSD and an encrypted LVM setup with TRIM passthrough through the crypto layers. Normally I run without swap space, but occasionally I will set up a

Bug#926594: (no subject)

2019-05-06 Thread Gordon Ball
Since this has been open for a month I have gone ahead and uploaded 5.7.8-1 to unstable, rather than leave the CVEs unfixed there. Accordingly, please consider this now to be an unblock request.

Bug#928525: sshguard: Default configuration does not work as intended, needs configuration update

2019-05-06 Thread Andreas Stempfhuber
Package: sshguard Version: 2.3.1-1 Severity: important Dear Maintainer, the default configuration shipped with the Debian package causes sshguard to count it's own attach messages as another attack and hence all hosts are blocked on their first login failure, e.g.: Apr 24 01:42:52 vsn

Bug#928524: lxqt-panel starts with a delay of approx. 30s when the statusnotifier plugin is enabled

2019-05-06 Thread Alf Gaida
Package: lxqt-panel Version: 0.14.1-1 Severity: important Dear Maintainer, lxqt-panel will be displayed at systemstart with a 30s delay - in this time lxqt-runner is also not usable. Reason is the statusnotifier plugin. Solution: adding a recommend to sni-qt, so old-fashioned applications can

Bug#928523: nvidia-driver: frequent black screen and screen shudder

2019-05-06 Thread Mathias Warnier
Package: nvidia-driver Version: 390.116-1 Severity: important Dear Maintainer, After upgrade to latest stable driver version (390.116) I experience frequent black screens and screen shudders. I've already re-installed the complete driver package but to no avail. No issues when using previous

Bug#928511: [Pkg-privacy-maintainers] Bug#928511: torbrowser-launcher hasn't updated itself to 60.6.2esr

2019-05-06 Thread shirish शिरीष
Hi all, Seems https://bugzilla.mozilla.org/show_bug.cgi?id=1548973 is tracking parts of the bug. I also saw https://blog.torproject.org/noscript-temporarily-disabled-tor-browser but it doesn't indicate that a new release is supposed to be out soon. Of the new comments the only thing I could

Bug#928518: RM: electrum -- RoQA; Actively exploited for phishing

2019-05-06 Thread Andrey Rahmatullin
On Mon, May 06, 2019 at 12:00:22PM -0400, Sam Hartman wrote: > Package: ftp.debian.org > Severity: normal > > Hi. As discussed in > https://cointelegraph.com/news/phishing-attack-on-electrum-wallet-nets-hacker-almost-1-million-in-hours-report > the version of electrum in sid is vulnerable to

Bug#928235: Reason for omission of client-pending patch?

2019-05-06 Thread Bryce Harrington
For CVE-2019-11494, three patches were provided by the vendor: https://seclists.org/oss-sec/2019/q2/82 In Ubuntu we included the three patches, but in updating our merge with Debian I notice you included only the latter two. Is this because the first one suppresses a warning, and is

Bug#812110: KeePassX 0.4 and KeePassX 2.0 should be in different packages

2019-05-06 Thread marjan cinober
Hi guys I was irritated by this name collision for long time until I finally did something about it. Here is my solution. Hope somebody with upload privileges will publish it for everybody. Run the attached script ant it will download latest release, patch it to a new name keepassx1, build it

Bug#928522: pinyin-database: impossible to install the Pinyin add-on via the 'software application' debian stretch

2019-05-06 Thread yifan
Package: pinyin-database Version: pinyin 1.7.3-2 Severity: normal Dear Maintainer, Trying to install this add-on I always end up with E: could not find the repository I don't know to install this to be able to write chinese character. Thx for your help. -- System Information: Debian

Bug#928518: RM: electrum -- RoQA; Actively exploited for phishing

2019-05-06 Thread Sam Hartman
> "Moritz" == Moritz Mühlenhoff writes: Moritz> On Mon, May 06, 2019 at 12:00:22PM -0400, Sam Hartman wrote: >> >> Package: ftp.debian.org Severity: normal >> >> Hi. As discussed in >>

Bug#928518: RM: electrum -- RoQA; Actively exploited for phishing

2019-05-06 Thread Moritz Mühlenhoff
On Mon, May 06, 2019 at 12:00:22PM -0400, Sam Hartman wrote: > > Package: ftp.debian.org > Severity: normal > > Hi. As discussed in > https://cointelegraph.com/news/phishing-attack-on-electrum-wallet-nets-hacker-almost-1-million-in-hours-report > the version of electrum in sid is vulnerable to

Bug#928521: rmlint-gui: File size limits lower than 1 Mb are treated as 0 Mb

2019-05-06 Thread Diego Caraffini
Package: rmlint-gui Version: 2.8.0-3 Severity: normal Tags: patch Dear Maintainer, In an attempt to only delete duplicates fo non-empty files, I set a lower size limit on the duplicate file size of a few bytes, in the Settings view of the gui, but shredder kept reporting them. Clicking on the

Bug#925142: hp-plugin generates libsane udev rules lacking LABEL

2019-05-06 Thread Cristian Ionescu-Idbohrn
On Wed, 20 Mar 2019, Christian Kastner wrote: > > Package: hplip > Version: 3.18.12+dfsg0-2 > Severity: minor > > The utility hp-plugin generated a file S99-2000S1.rules in > /etc/udev/rules.d/, which I've attached. This sets up permissions for my > HP LaserJet Pro MFP 176n. > > Note that in

Bug#928353: Fwd: release-notes: document mutt vs neomutt in buster

2019-05-06 Thread Antonio Radici
Thanks for pinging me, I missed this, let me comment on the bug. On Sun, May 05, 2019 at 02:51:35PM +0200, Paul Gevers wrote: > Hi, > > I'm not sure if this release-notes bug that I addressed to you actually > reached you. > > Paul > > > Forwarded Message > Subject:

Bug#928520: Provide systemd unit for unclutter

2019-05-06 Thread Jörg Sommer
Package: unclutter Version: 8-21 Severity: wishlist Hi, maybe, could you ship this unit file as /usr/lib/systemd/user/unclutter.service? This runs unclutter independent of the window manager and it aggregates all log messages via journal. ``` [Unit] Description=Daemon to remove idle cursor

Bug#928519: Provide systemd unit

2019-05-06 Thread Jörg Sommer
Package: ukui-polkit Version: 1.0.2-1 Severity: wishlist Hi, maybe, could you ship this unit file as /usr/lib/systemd/user/ukui-polkit.service? This runs ukui-polkit independent of the window manager and it aggregates all log messages via journal. ``` [Unit] Description=PolicyKit

Bug#927876:

2019-05-06 Thread Ricardo Pérez
This bug was reported by me one year ago on Launchpad: https://bugs.launchpad.net/ubuntu/+source/command-not-found/+bug/1766068 Since Zsh 5.3, the command_not_found_handler() behavior has changed, as you can see here:

Bug#908589: ITP: gcc-8-doc -- documentation for the GNU compilers (gcc, g++, etc.)

2019-05-06 Thread Mattia Rizzolo
On Tue, Dec 25, 2018 at 12:03:23AM +0300, Dmitry Eremin-Solenikov wrote: > Do you need any kind of help with gcc-8-doc package? An ITP is open > since september without any logged progress on it. And now we are May, and no news about it, we are about to release debian buster, without any

Bug#928518: RM: electrum -- RoQA; Actively exploited for phishing

2019-05-06 Thread Sam Hartman
Package: ftp.debian.org Severity: normal Hi. As discussed in https://cointelegraph.com/news/phishing-attack-on-electrum-wallet-nets-hacker-almost-1-million-in-hours-report the version of electrum in sid is vulnerable to mallware and has been disabled by the electrum servers. So basically the

Bug#928517: current symlink missing for jessie

2019-05-06 Thread Floris Bos
Package: mirrors http://ftp.debian.org/debian/dists/jessie/main/installer-amd64/current/ no longer exists. - It used to be there. - "current" is still there for other Debian releases. (e.g. http://ftp.debian.org/debian/dists/stretch/main/installer-amd64/current/ ) We have some scripts

Bug#652727: ITA: simhash -- generate similarity hashes to find nearly duplicate files

2019-05-06 Thread laokz
Hi, I'd like to adopt this package if Thomas Koch isn't interested in it yet. But it may take a little time for me to dive into this work because I'm a newbie of Debian Maintainerand. Regards, laokz

Bug#928473: dgit: not clear what to do when earlier uploads used dgit but intermediate ones didn't

2019-05-06 Thread Ian Jackson
Colin Watson writes ("Bug#928473: dgit: not clear what to do when earlier uploads used dgit but intermediate ones didn't"): > On Sun, May 05, 2019 at 08:31:14PM +0100, Ian Jackson wrote: > > --overwrite is intended for this situation. The documentation talking > > about "NMU changes" is speaking

Bug#927227: RFS: golang-gopkg-sourcemap.v1/1.0.5-2 [RC]

2019-05-06 Thread Shengjing Zhu
On Mon, May 6, 2019 at 4:42 PM Jongmin Kim wrote: > > Dear Go team, > > I'm looking for a sponsor for the package "golang-gopkg-sourcemap.v1/1.0.5-2". > > This patch makes the package to use jQuery provided by Debian package > (libjs-jquery) instead of getting from Internet, for fixing an RC bug:

Bug#928516: logrotate: Upgrading from stretch breaks logrotate if logrotate.conf was modified

2019-05-06 Thread Santiago Vila
Package: logrotate Version: 3.14.0-4 Dear maintainer: In a stretch system where the /etc/logrotate.conf has been modified slightly, upgrading to buster and keeping the old configuration makes entries for wtmp and btmp to be duplicated, as they are now in separate files in logrotate.d. This makes

Bug#928511: [Pkg-privacy-maintainers] Bug#928511: torbrowser-launcher hasn't updated itself to 60.6.2esr

2019-05-06 Thread shirish शिरीष
at bottom :- On 06/05/2019, intrigeri wrote: >> I looked at #928415 and updated to firefox-esr 60.6.2esr-1 as can be >> seen below - > > I assume you mean "Tor Browser", not torbrowser-launcher. > Tor Browser 8.0.9 is not out yet. It should be released later today. > yup, meant the same. Thank

Bug#908724: please add brcmfmac4356-pcie.txt to the package

2019-05-06 Thread Ben Hutchings
On Thu, 13 Sep 2018 08:21:01 +0200 "W. Martin Borgert" wrote: > Package: firmware-nonfree > Version: 20180825+dfsg-1 > Severity: important > > (Important, because it has a major effect on the usability for > users of a specific hardware. Feel free to adjust.) > > When installing Debian on the

Bug#801655: xorg crashes with "NOUVEAU(0): failed to set mode: Permission denied" when exiting tty2-6 shell

2019-05-06 Thread Ed
On Tue, Oct 13, 2015 at 05:13:03am +0200, Alexandre Hoïde wrote: > [ 6636.047] (EE) NOUVEAU(0): failed to set mode: Permission denied > [ 6636.049] (EE) > Fatal server error: I've also stumbled into this. Did anyone find a workaround? -- Best regards, Ed http://www.s5h.net/ signature.asc

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Karsten
Am 06.05.19 um 15:51 schrieb Antoine Beaupré: > I am not sure I understand the problem you're trying to outline here. The problem is to be spammed with advertisement and to have no No-Script. It's true that i didn't know that the package

Bug#928515: libjs-bootstrap-tour: Bootstrap sanitize breaks buttons in bootstrap-tour

2019-05-06 Thread Karsten Koop
Package: libjs-bootstrap-tour Version: 0.11.0+dfsg-1 Severity: normal Tags: patch Dear Maintainer, A recent security update to Bootstrap 3 (for CVE-2019-8331) brakes bootstrap-tour, because the sanitation removes the next/prev buttons from the popover. A workaround is passing 'sanitize:false'

Bug#928514: python2.7 has a dependency cycle through xvfb

2019-05-06 Thread Helmut Grohne
Source: python2.7 Version: 2.7.16-2 Severity: important Tags: patch Bootstrapping python2.7 is difficult, because it has multiple dependency cycles through xvfb. For instance: src:libunwind Build-Depends texlive-extra-utils, which depends on a package built from src:python2.7, which

Bug#928512: cyrus-sasl2 FTCBFS: multiple reasons

2019-05-06 Thread Helmut Grohne
Source: cyrus-sasl2 Version: 2.1.27+dfsg-1 Severity: important Tags: patch cyrus-sasl2 fails to cross build from source for multiple reasons. The immediate reason is that its Build-Depends are unsatisfiable. In particular, python3-sphinx and libpod-pom-view-restructured-perl are problematic due

Bug#928513: python3.7 has a dependency cycle through xvfb

2019-05-06 Thread Helmut Grohne
Source: python3.7 Version: 3.7.3-2 Severity: important Tags: patch Bootstrapping python3.7 is difficult, because it has multiple dependency cycles through xvfb. For instance: meson depends on a package built from src:python3.7, which Build-Depends on xvfb, which depends on a package built from

Bug#682369: confirmed

2019-05-06 Thread Matija Nalis
Control: found -1 60.6.1esr-1~deb9u1 Just to clarify, this bug happens even on normal browser close, when session restore is *NOT USED* - that is, even when web pages are fully closed before quitting the browser. And it happens even with setting "When Firefox starts" to "Show a blank page"

Bug#928415: could somebody look into #928511

2019-05-06 Thread shirish शिरीष
Dear all, Could somebody look at #928511 . This is though in respect of torbrowser though . -- Regards, Shirish Agarwal शिरीष अग्रवाल My quotes in this email licensed under CC 3.0 http://creativecommons.org/licenses/by-nc/3.0/ http://flossexperiences.wordpress.com E493

Bug#928511: torbrowser-launcher hasn't updated itself to 60.6.2esr

2019-05-06 Thread shirish शिरीष
Package: torbrowser-launcher Version: 0.3.1-2 Severity: grave Dear Maintainer, I looked at #928415 and updated to firefox-esr 60.6.2esr-1 as can be seen below - $ apt-cache policy firefox-esr firefox-esr: Installed: 60.6.2esr-1 Candidate: 60.6.2esr-1 Version table: *** 60.6.2esr-1 500

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Antoine Beaupré
Control: severity 928509 normal On 2019-05-06 15:04:09, Karsten wrote: > Package: firefox-esr > Version: 60.6.1esr-1~deb8u1 > Justification: user security hole > Severity: grave > Tags: security > > Hello Debian-Team, > > this security bug shall show that Firefox is going to be more and more >

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Hideki Yamane
Hi, On Mon, 6 May 2019 15:04:09 +0200 Karsten wrote: > Package: firefox-esr > Version: 60.6.1esr-1~deb8u1 It was already done in unstable and stable-proposed-updates, and reporter asks about oldstable, so CC:ed to lts mailing list. LTS maintainers, could you build it for oldstable, please?

Bug#926903: Installation-report addition

2019-05-06 Thread Ben Hutchings
Control: clone -1 -2 Control: retitle -1 installation-reports: Installer with firmware does not install firmware-amd-graphics Control: reassign -2 firmware-amd-graphics Control: retitle -2 firmware-amd-graphics: Should trigger initramfs rebuild On Thu, 2019-05-02 at 11:10 +0100, Ben Hutchings

Bug#927429: fixed in ghostscript 9.27~dfsg-2

2019-05-06 Thread Hideki Yamane
Hi Jonas, On Sat, 20 Apr 2019 09:18:37 + Jonas Smedegaard wrote: > Source: ghostscript > Source-Version: 9.27~dfsg-2 Do you intend to put it into buster? (probably yes :) If so, please file unblock request for it. -- Regards, Hideki Yamane henrich @ debian.org/iijmio-mail.jp

Bug#926657: [Pkg-openldap-devel] Bug#926657: openldap: slapd process failure is not detected by systemd

2019-05-06 Thread Heitor Alves de Siqueira
Hi Ryan, I'm attaching a patch for this which includes the override file. Do you think this patch can be adopted in Debian until we have the native service file? Please let me know if you think it needs any changes! Thanks, Heitor From 84316f458fb14592085f7e67d6aab349aaa312ff Mon Sep 17 00:00:00

Bug#928509: Firefox insecure because of missing extensions

2019-05-06 Thread Karsten
Package: firefox-esr Version: 60.6.1esr-1~deb8u1 Justification: user security hole Severity: grave Tags: security Hello Debian-Team, this security bug shall show that Firefox is going to be more and more unusable to be secure in the internet. Today one of the most vulnerable things has happen,

  1   2   >