Bug#1007138: libgnutls30: fails on Let's Encrypt chains due to blacklisted expired root certificate

2022-03-11 Thread Andreas Metzler
Control: tags -1 confirmed On 2022-03-11 Paul Gevers wrote: > Package: libgnutls30 > Version: 3.7.3-4+b1 > Severity: normal > Dear maintainers, > Recently ca-certificates 20211016 migrated to testing which included > the following change: > * Blacklist expired root certificate "DST Root CA X3"

Bug#1005024: tin: Hangs, disconnects reproducible on specific

2022-02-12 Thread Andreas Metzler
On 2022-02-07 Urs Janßen wrote: > > The article is not very useful there seem to be problems with MIME, the > > signature does not verify. I have attached a copy from the local > > newsspool. > The issue is that the part with boundary="GvXjxJ+pjyke8COw" is missing > whilst beeing announced. The a

Bug#1005024: tin: Hangs, disconnects reproducible on specific article

2022-02-05 Thread Andreas Metzler
Package: tin Version: 1:2.6.1-1 Severity: normal Hello, I using rtin against a local loeafnode instance. Trying to read (or save) a specific article in gmane.linux.debian.alioth.pkg-gnupg.general makes tin hang. Watching tcpdump, tin sends ARTICLE 543 but at some point seems to stop accepting dat

Bug#1004740: exim4: SIGSEGV (maybe attempt to write to immutable memory) when sending a mail; message frozen

2022-02-02 Thread Andreas Metzler
On 2022-02-01 Vincent Lefevre wrote: > On 2022-02-01 14:44:21 +0100, Vincent Lefevre wrote: > > 2022-02-01 14:23:23 1nEt2b-0008jG-97 SIGSEGV (maybe attempt to write to > > immutable memory) > > 2022-02-01 14:23:23 1nEt2b-0008jG-97 Delivery status for xxx@yyy: got 0 of > > 7 bytes (pipeheader) fr

Bug#1004428: [PATCH] Add remaining options to exiqgrep.8

2022-01-29 Thread Andreas Metzler
Control: tags -1 pending On 2022-01-27 Janne Hess wrote: > Package: exim4 > Version: 4.95-3 > Tags: patch > Hi, > the provided patch adds al yet undocumented options to exiqgrep.8. > I hope the quality matches your expectations. Thank you Janne, committed to GIT. cu Andreas

Bug#1003227: wmnet: diff for version 1.06-2

2022-01-29 Thread Andreas Metzler
le and homepage, point to www.dockapps.net. + * Add Vcs-* fields to control. + * Add DEP5 copyright. + * Fix hardening build. Closes: #668014 + + -- Andreas Metzler Sat, 29 Jan 2022 15:18:41 +0100 + wmnet (1.06-1.2) unstable; urgency=medium * Non-maintainer upload. diff -Nru wmnet-1.06/debia

Bug#1003769: RFS: byacc/1.0-2 [ITA] -- public domain Berkeley LALR Yacc parser generator

2022-01-23 Thread Andreas Metzler
On 2022-01-16 Andreas Metzler wrote: [...] > I will probably followup with further wishes/comments later, not today > but hopefully in next week. [...] Hello Thomas, I think there are just two thing left pre upload: 1. The upload introduces an epoch because the upstream version wen

Bug#1004183: gnutls28 FTCBFS: python3 dependency not installable

2022-01-22 Thread Andreas Metzler
Control: tags -1 pending On 2022-01-22 Helmut Grohne wrote: > Source: gnutls28 > Version: 3.7.3-3 > Severity: important > Justification: gnutls28 is relevant for architecture bootstrap [...] > gnutls28 fails to cross build from source, because the new build > dependency on the host architecture p

Bug#1003997: libksba: reproducible-builds: build path embedded in w64/ming32 build

2022-01-20 Thread Andreas Metzler
Control: tags -1 pending On 2022-01-19 Vagrant Cascadian wrote: [...] > The build path of is embedded in libksba: [...] > The attached patch to debian/rules adds > "CFLAGS=... -ffile-prefix-map=$(CURDIR)=." to the WIN_FLAGS variable. [...] Thank you, applied in GIT. cu Andreas -- `What a good

Bug#1003769: RFS: byacc/1.0-2 [ITA] -- public domain Berkeley LALR Yacc parser generator

2022-01-16 Thread Andreas Metzler
On 2022-01-16 Thomas Dickey wrote: [...] > I reviewed the test-data differences, didn't see a problem, and verified > with cproto (which uses lex/yacc) that there are no differences. > So I updated the debian files to combine the two (just packaging one > "byacc" with backtracking). Great. [...

Bug#1003769: RFS: byacc/1.0-2 [ITA] -- public domain Berkeley LALR Yacc parser generator

2022-01-16 Thread Andreas Metzler
On 2022-01-16 Thomas Dickey wrote: > On Sun, Jan 16, 2022 at 08:03:14AM +0100, Andreas Metzler wrote: [...] > > I would like to question the introduction of another binary package: > > * "byacc2" seems to be a (newly introduced) Debiansm. Googling for > > "

Bug#1003769: RFS: byacc/1.0-2 [ITA] -- public domain Berkeley LALR Yacc parser generator

2022-01-15 Thread Andreas Metzler
On 2022-01-15 Thomas Dickey wrote: [...] > I am looking for a sponsor for my package "byacc": > * Package name: byacc >Version : 1:2.0.20220114-1 >Upstream Author : (Thomas E. Dickey) > * URL : https://invisible-island.net/byacc/ > * License : GPL-3, pu

Bug#1003339: findutils: find manpage definition of "-delete" misses that it can delete directories

2022-01-08 Thread Andreas Metzler
Control: forwared -1 https://savannah.gnu.org/bugs/index.php?61774 On 2022-01-08 Chris Davies wrote: > Package: findutils > Version: 4.8.0-1 > Severity: minor > X-Debbugs-Cc: ch...@roaima.co.uk > Dear Maintainer, > The man page for "find" starts the reference definition "-delete" as, > Del

Bug#1003227: ITS: wmnet

2022-01-06 Thread Andreas Metzler
Package: wmnet Version: 1.06-1.2 Severity: important X-Debbugs-Cc: wma...@packages.debian.org, m...@qa.debian.org Hello, I intend to salvage wmnet, maintaining it under the Debian Window Maker Team umbrella. The last maintainer upload was in 2012, followed by a unacknowledged NMU in Oct 2021. Th

Bug#965880: wmnet: diff for NMU version 1.06-1.2

2022-01-06 Thread Andreas Metzler
65880 + + -- Andreas Metzler Thu, 06 Jan 2022 14:13:30 +0100 + wmnet (1.06-1.1) unstable; urgency=medium * Non-maintainer upload. diff -Nru wmnet-1.06/debian/compat wmnet-1.06/debian/compat --- wmnet-1.06/debian/compat 2012-03-03 20:19:16.0 +0100 +++ wmnet-1.06/debian/compat 1970-01-01

Bug#1003075: gnutls28: HTML API reference documentation is not generated

2022-01-04 Thread Andreas Metzler
Control: tags -1 confirmed On 2022-01-03 Dennis Filder wrote: > Source: gnutls28 > Version: 3.7.2-4 > Tags: patch > Building the HTML api-reference docs seems to have been broken for > quite a while due to XML shenanigans. The first of the attached > patches makes it work again, but fixing make

Bug#1001576: dnsmasq-base: Occassionally hangs at startup with 100% cpu, needs kill -9 to terminate

2021-12-12 Thread Andreas Metzler
Package: dnsmasq-base Version: 2.86-1.1 Severity: important Hello, I have been using dnsmasq for ages but it recenty broke, probably with the ugrade from 2.85. Occassionaly dnsmasq ist stuck at 100% CPU and does not respond to queries or the TERM signal, only kill -9 seems to work. I have rebui

Bug#998498: pfstools: FTBFS: stl_algobase.h:278:56: error: macro "min" passed 3 arguments, but takes just 2

2021-12-05 Thread Andreas Metzler
X-Debbugs-Cc: libnetpbm10-...@packages.debian.org On 2021-11-04 Lucas Nussbaum wrote: > Source: pfstools > Version: 2.2.0-1 > Severity: serious > Justification: FTBFS > Tags: bookworm sid ftbfs > User: lu...@debian.org > Usertags: ftbfs-20211104 ftbfs-bookworm > Hi, > During a rebuild of all pac

Bug#1001013: mutt: 2.1.x regression - SMTP AUTH mandated if available

2021-12-02 Thread Andreas Metzler
Package: mutt Version: 2.1.3-1 Severity: normal After todays mutt upgrade (from 2.0) mutt suddenly *requires* successful SMTP AUTH when sending mail, at least when the SMTP server advertises AUTH support. (My server=localhost offers AUTH, but does not require it). There does not seem to be a way t

Bug#1000843: exim4: set message_id_header_domain cause SIGSEGV (maybe attempt to write to immutable memory)

2021-12-02 Thread Andreas Metzler
Hello, can you get a backtrace? 1. Add deb http://debug.mirrors.debian.org/debian-debug/ sid-debug main to /etc/apt/sources.list 2. Install exim4-daemon-light-dbgsym libgnutls-dane0-dbgsym libgnutls30-dbgsym libhogweed6-dbgsym libnettle8-dbgsym libtasn1-6-dbgsym libp11-kit0-dbgsym 3. root@argena

Bug#1000843: exim4: set message_id_header_domain cause SIGSEGV (maybe attempt to write to immutable memory)

2021-11-30 Thread Andreas Metzler
On 2021-11-30 Youhei SASAKI wrote: > Package: exim4 > Version: 4.95-2 > Severity: important > X-Debbugs-Cc: none, Youhei SASAKI > Dear Maintainer, > When I set 'message_id_header_domain', 'message_id_header_text' > in /etc/exim4/exim4.conf.localmacros, > % sendmail -t < test > 2021-11-

Bug#1000107: exim4: depends on obsolete pcre3 library

2021-11-18 Thread Andreas Metzler
On 2021-11-18 Matthew Vernon wrote: > Source: exim4 > Severity: important > User: matthew-pcre...@debian.org > Usertags: obsolete-pcre3 > Dear maintainer, > Your package still depends on the old, obsolete PCRE3[0] libraries > (i.e. libpcre3-dev). This has been end of life for a while now, and [.

Bug#997911: lintian: bash-term-in-posix-shell false positive for '<<<' in quoted strings

2021-11-14 Thread Andreas Metzler
On 2021-10-27 Andreas Beckmann wrote: > Package: lintian > Version: 2.110.0 > Severity: important > Hi, > src:nvidia-graphics-driver has this in its bug script: > echo "<< $file >>" [...] Hello, The curly-braces check ("{foo,bar} instead of foo bar") also has some false po

Bug#994836: exim: dpkg fatal error due to Debian-exim in statoverride

2021-10-19 Thread Andreas Metzler
On 2021-09-21 Wookey wrote: > Package: exim > Severity: important > whilst trying to install build-deps for therion in an unstable chroot > i.e > apt source therion (6.0.2ds1-3 is downloaded) > cd therion-6.0.2ds1 > sudo apt --no-install-recommends build-dep . > I got (after downloading 887MB of

Bug#996686: libp11-kit-dev: broken symlink: /usr/share/doc/libp11-kit-dev/html

2021-10-17 Thread Andreas Metzler
On 2021-10-17 Paul Wise wrote: > Package: libp11-kit-dev > Version: 0.24.0-4 > Severity: normal > File: /usr/share/doc/libp11-kit-dev/html > Usertags: deps > User: debian...@lists.debian.org > Usertags: adequate broken-symlink > There is now a broken symlink in the package: >$ adequate libp1

Bug#996232: ITP: android-file-transfer-linux -- Android File Transfer for Linux

2021-10-12 Thread Andreas Metzler
On 2021-10-12 YaNing Lu wrote: > Package: wnpp > Severity: wishlist > X-Debbugs-Cc: debian-de...@lists.debian.org > * Package name: android-file-transfer-linux > Version : 4.2.0 > Upstream Author : Vladimir > * URL : https://github.com/whoozle/android-file-transfer-l

Bug#995926: Error validating Let's Encrypt cert chains

2021-10-11 Thread Andreas Metzler
Control: reassign -1 lftp 4.8.4-2 On 2021-10-11 Andreas Metzler wrote: > On 2021-10-08 Andre Heider wrote: >> Source: gnutls28 >> Version: 3.7.2-2 >> Apps using gnutls fail to connect to servers using a Let's Encrypt >> certificate which are cross-signed by the

Bug#995926: Error validating Let's Encrypt cert chains

2021-10-11 Thread Andreas Metzler
X-Debbugs-Cc: Andre Heider , l...@packages.debian.org On 2021-10-08 Andre Heider wrote: > Source: gnutls28 > Version: 3.7.2-2 > Apps using gnutls fail to connect to servers using a Let's Encrypt > certificate which are cross-signed by the now expired DST Root CA X3, see > [0]. > Examples: > $

Bug#930603: libdockapp-dev: pkg-config file Requires xext without dependency on libxext-dev

2021-10-09 Thread Andreas Metzler
On 2021-10-09 Jeremy Sowden wrote: > On 2019-08-13, at 19:09:33 +0200, Andreas Metzler wrote: >> On 2019-06-16 Douglas Torrance wrote: >>> On Sun, Jun 16, 2019 at 7:30 AM Andreas Metzler wrote: >>>> /usr/lib/x86_64-linux-gnu/pkgconfig/dockapp.pc: >>>&

Bug#995793: Info received (Bug#995793: exim4-base: /tmp partition has noexec mount option; exim4-base fails)

2021-10-06 Thread Andreas Metzler
Control: severity -1 normal Control: reassign -1 apt Control: forcemerge 546911 995793 On 2021-10-05 S Egbert wrote: > Actual workaround is to remove ‘noexec” from both /tmp and /var. > Tested it working without “noexec” mount options on ‘apt upgrade > exim4-base’ to versio ‘4.94.2-7’ > This mak

Bug#995162: cannot install together with i386

2021-10-01 Thread Andreas Metzler
Hello Mattia, thank you for providing more background on this. On 2021-09-30 Mattia Rizzolo wrote: [...] > Realistically, package-wise, I think they would good by not placing PNGs > in arch:any packages, that would side-step this issue. And it's the > proper thing to do anyway so why not. If I

Bug#995049: p11-kit: FTBFS on hurd-i386

2021-09-26 Thread Andreas Metzler
On 2021-09-25 Svante Signell wrote: > Source: p11-kit [...] > Hi, > Currently p11-kit FTBFS on GNU/Hurd due to a missing implementation in > common/unix-peer.c. Fortunately the function getpeereid() is available > in the libbsd library. The same function is also available for > kFreeBSD. Hello S

Bug#973759: lintian: False positive: debian-changelog-file-is-a-symlink matches on upstream changelog

2021-09-19 Thread Andreas Metzler
On 2021-09-19 Felix Lechner wrote: [...] > In addition, it is not well-publicized that version numbers for > installation (aka "binary") packages are not necessarily tied to the > version strings for their sources, but I do not remember an example > right now. Hello, gcc-defaults is one of the m

Bug#949395: dpkg: Old packaged files not always removed, causing various issues

2021-09-12 Thread Andreas Metzler
On 2021-09-11 Simon McVittie wrote: [...] > GLib uses a generated postinst where #MULTIARCH# gets replaced > by the multiarch tuple of the package. As far as I know, this > is going to be necessary for any multiarch library that will use > my clean-up-unmanaged-libraries script, because dpkg tells

Bug#949395: dpkg: Old packaged files not always removed, causing various issues

2021-09-11 Thread Andreas Metzler
Control: block 984884 by 949395 On 2020-01-20 Simon McVittie wrote: > Package: dpkg > Version: 1.19.7 > Severity: normal > Tags: unreproducible > Maintainers have seen bugs in various packages where an old file (one > that was shipped in an old .deb, but not under the same name in a new > .deb)

Bug#984884: libgcrypt20: Unknown error executing apt-key [Bullseye]

2021-09-11 Thread Andreas Metzler
On 2021-09-09 Mateusz Rejek wrote: > Interestingly enough got the same problem on ARMHF after moving to bullseye. > I have version 1.8.7-6 installed over 1.8.4-5+deb10u1 > # cat /var/log/dpkg.log.1 | grep libgcrypt > > 2021-09-07 13:07:54 upgrade libgcrypt20:armhf 1.8.4-5+deb10u1 1.8.7-6 > > 202

Bug#993507: libgnutls30: fails to negotiate X25519 where NSS & OpenSSL succeed, success with X448

2021-09-03 Thread Andreas Metzler
On 2021-09-02 Lionel Élie Mamane wrote: > tags 993507 +upstream > forwarded 993507 https://gitlab.com/gnutls/gnutls/-/issues/1249 > retitle 993507 libgnutls30: client 'illegal parameter' error when both X25519 > and X448 are enabled and the server picks one of those [...] > It is not immediately

Bug#964284: guile-gnutls: update to use guile 3.0

2021-08-29 Thread Andreas Metzler
On 2021-08-28 Vagrant Cascadian wrote: > I talked to rlb breifly who thought recent versions of guile-3.0 in > Debian may work around and/or fix the triggering issue for > guile-gnutls. Would you be up for trying to switch guile-gnutls to > guile-3.0 again? Hello, I just made a test-upload to ex

Bug#992421: dnslookup_relay_to_domains probably needs ignore_target_hosts

2021-08-28 Thread Andreas Metzler
On 2021-08-25 Marc Haber wrote: > On Tue, Aug 24, 2021 at 07:47:46PM +0200, Andreas Metzler wrote: > > According to chapter 3, »8. Recognizing the local host« exim uses the > > local_interfaces setting (unless it is 0.0.0.0 or ::0) to recognize the > > local host. - Are

Bug#992421: dnslookup_relay_to_domains probably needs ignore_target_hosts

2021-08-24 Thread Andreas Metzler
On 2021-08-18 Marc Haber wrote: > Package: exim4-config > Version: 4.94.2-2~zg100+3 > Severity: normal > Hi, > I am not sure whether this is an actual bug. I have observed this > behaviod on an exim that is backup MX for domain.example. The MX records > are like: > domain.example mail is handled

Bug#992172: exim4: CVE-2021-38371

2021-08-14 Thread Andreas Metzler
On 2021-08-14 Salvatore Bonaccorso wrote: > Source: exim4 > Version: 4.94.2-7 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > Hi, > The following vulnerability was published for exim4, this is to start > tracking the issue downstream

Bug#991971: Processed: Re: Bug#991971: [Lynx-dev] bug in Lynx' SSL certificate validation -> leaks password in clear text via SNI (under some circumstances)

2021-08-07 Thread Andreas Metzler
On 2021-08-07 Debian Bug Tracking System wrote: > Processing commands for cont...@bugs.debian.org: > > tags 991971 fixed-upstream > Bug #991971 [lynx] lynx: SSL certificate validation fails with URLs > containing user name or user name and password, i.e. > https://user:password@host/ and https:

Bug#991397: unblock: exim4/4.94.2-7

2021-07-22 Thread Andreas Metzler
from upstream +fixes +branch: Fix re-expansion of custom message with control=fakereject. + + -- Andreas Metzler Tue, 13 Jul 2021 18:04:57 +0200 + exim4 (4.94.2-6) unstable; urgency=medium * Cherrypick diff -Nru exim4-4.94.2/debian/patches/73_05-Fix-tainted-message-for-fakereject.patch

Bug#991204: exim4-daemon-heavy: Please add SPF support

2021-07-17 Thread Andreas Metzler
Control: forcemerge 528344 991204 On 2021-07-17 Wouter Verhelst wrote: > Package: exim4-daemon-heavy > Version: 4.94.2-6 > Followup-For: Bug #528344 > Perhaps important to note is that both DMARC and (currently still > experimental, but...) ARC both depend on the builtin SPF support. While > the

Bug#481081: Maildir appendfile names longer than they need to be

2021-07-17 Thread Andreas Metzler
On 2008-05-13 Andrew Buckeridge wrote: > Package: exim4 > Version: 4.69-2 > Severity: wishlist > In ~/Maildir/cur/ I have: - > 1210666181.H610983P31901.203.161.103.17.static.amnet.net.au >^^^ ^^ > The Microseconds should start with M. [...]

Bug#991026: exim4: DANE error: tlsa lookup DEFER

2021-07-13 Thread Andreas Metzler
On 2021-07-13 Simon Josefsson wrote: > Package: exim4 > Version: 4.92-8+deb10u6 > I got bounces due to delivery failures when mailing someone from my > exim4-based mail server. The log file contains: > 2021-07-13 06:20:20.720 [13321] 1m1lRa-0002RD-DO H=mailcluster.loopia.se > [2a02:250:0:48::1

Bug#990919: unblock: exim4/4.94.2-6

2021-07-11 Thread Andreas Metzler
; option to disable daemon notifier socket. Enforce lockstep ugrade of -base > and *daemon* by temporarily adding a versioned Breaks to exim4-base on > older *daemon*. Closes: #988844 > (change by Andreas Metzler) > This fixes a regression from buster. > Maintai

Bug#990344: exim 4.94.2 update default configuration option breaks MTA

2021-06-27 Thread Andreas Metzler
On 2021-06-26 sawb...@xsmail.com wrote: > On 26 Jun 2021 at 15:12, Andreas Metzler wrote: > > I think that assumption is not correct. dpkg will (should) only ask > > about the confffile if it *was* locally changed, otherwise the files are > > overwritten without asking. > I

Bug#990338: autogen: reproducible-builds: embeds /bin/sh or /bin/bash in autoopts-config

2021-06-27 Thread Andreas Metzler
On 2021-06-26 Vagrant Cascadian wrote: > On 2021-06-26, Andreas Metzler wrote: [...] >> So I think the proper fix (for the very real bug) would be to pass >> CONFIG_SHELL=/bin/bash to configure. > I believe I did at one point try that, but will test again to be sure. diff

Bug#990344: exim 4.94.2 update default configuration option breaks MTA

2021-06-26 Thread Andreas Metzler
On 2021-06-26 sawb...@xsmail.com wrote: > Hello: > Please excuse me, it happens that english is not my native language > so it is quite probable that I may not have expressed myself > correctly. > > Overwriting local customizations is not an option. > I was referring to whatever files are inst

Bug#990338: autogen: reproducible-builds: embeds /bin/sh or /bin/bash in autoopts-config

2021-06-26 Thread Andreas Metzler
On 2021-06-26 Vagrant Cascadian wrote: > Source: autogen > Severity: normal > Tags: patch > User: reproducible-bui...@lists.alioth.debian.org > Usertags: shell > X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org > Depending on what /bin/sh symlinks to, either /bin/sh or /bin/bash is > embed

Bug#990095: libkcapi-dev: Please ship pkgconfig file

2021-06-20 Thread Andreas Metzler
Package: libkcapi-dev Version: 1.2.1-1 Severity: wishlist Hello, upstream generates a pkgconfig file, please ship it. cu Andreas

Bug#989422: buster-pu: package libgcrypt20/1.8.4-5+deb10u1

2021-06-12 Thread Andreas Metzler
On 2021-06-12 "Adam D. Barratt" wrote: [...] > As we're getting close to the window for 10.10 closing, please feel > free to upload the package and we'll handle the d-i coordination from > there. Thanks for the heads-up. Done. cu Andreas -- `What a good friend you are to him, Dr. Maturin. His o

Bug#989608: Create /var/spool/exim4/msglog.OLD upon installation

2021-06-08 Thread Andreas Metzler
On 2021-06-08 Thomas Landauer wrote: > Package: exim4 > Severity: wishlist > It looks like the /var/spool/exim4/msglog.OLD directory is only created by > Exim itself after the first messagelog is going to be written there. > If you need custom permissions on this directory, it would be nice to b

Bug#989260: exim4-config: Default configuration enables sieve filters but cannot deliver from them

2021-05-30 Thread Andreas Metzler
On 2021-05-30 ano...@users.sourceforge.net wrote: > Package: exim4-config > Version: 4.94.2-6 > The default configuration provided by exim4-config allows for sieve > filters to be used in ~/.forward, but if a user attempts to configure > such a filter their mail delivery will most likely break. >

Bug#989235: p11-kit FTBFS on hurd-any

2021-05-30 Thread Andreas Metzler
On 2021-05-29 Helmut Grohne wrote: > Source: p11-kit [...] > p11-kit fails to build from source on hurd-any. The immediate reason is > an undefined macro SIZE_MAX in p11-kit/lists.c. It happens that this > file fails to #include , which is generally required for > SIZE_MAX. I'm attaching a patch f

Bug#988844: daemon_notifier_socket bind: Address already in use

2021-05-22 Thread Andreas Metzler
Control: tags -1 confirmed On 2021-05-20 Chris Hofstaedtler wrote: > Package: exim4-daemon-heavy > Version: 4.94.2-1~bpo10+1 > Severity: important > Dear Maintainer, > thank you for maintaining exim, also in backports. > I have recently upgraded from the version in buster to > 4.94.2-1~bpo10+1

Bug#988301: exim :include: not working after jessie

2021-05-15 Thread Andreas Metzler
Control: forwarded -1 https://bugs.exim.org/show_bug.cgi?id=2751 On 2021-05-10 Josip Rodin wrote: > Package: exim4 > Version: 4.89-2+deb9u8 > Hi, > After an upgrade to stretch, and likewise buster, the :include: > functionality of the redirect router seems to be broken. > I have include_direct

Bug#988508: buster-pu: package gnutls28/3.6.7-4+deb10u7

2021-05-14 Thread Andreas Metzler
loc.patch + (CVE-2021-20232), both together GNUTLS-SA-2021-03-10. ++ 47_rel3.6.16_05-_gnutls_buffer_resize-account-for-unused-area-if-AGG.patch ++ 47_rel3.6.16_06-str-suppress-Wunused-function-if-AGGRESSIVE_REALLOC-.patch + + -- Andreas Metzler Fri, 14 May 2021 13:33:38 +0200 + gnutls28 (3.6.7-4+deb10u6) b

Bug#988078: release-notes: add information regarding exim4 and 'tainted data' issue

2021-05-13 Thread Andreas Metzler
On 2021-05-13 Paul Gevers wrote: > On 10-05-2021 05:58, Justin B Rye wrote: > > (Is it possible we could shorten this by pointing to some external > > reference here?) > I'd like this too. Hello Paul, sadly I am not aware of an authoritative source which sums it up nicely. The exim specificatio

Bug#988304: exim4: rsyslog log files not getting any new info

2021-05-10 Thread Andreas Metzler
On 2021-05-10 GSR wrote: > Package: exim4 > Version: 4.94.2-2 > Severity: normal > After updating from 4.94.2-1 any info stopped appearing in rsyslog > (8.2102.0-2) files like /var/log/mail.log. Mail can be sent and > received, and /var/log/exim4/mainlog gets new lines. So it seems to be > someth

Bug#988078: release-notes: add information regarding exim4 and 'tainted data' issue

2021-05-09 Thread Andreas Metzler
On 2021-05-05 Paul Muster wrote: > Package: release-notes > Severity: normal > Hi, > please add a new paragraph 5.1.13 (and move existing 5.1.14 to .14) regarding > exim and the new 'tainted data' issue. > Text copied from NEWS.Debian file: [...] Thanks, Paul! The text has been slightly upda

Bug#988086: Exim delivery process crashes on each mail with NULL-pointer

2021-05-09 Thread Andreas Metzler
On 2021-05-05 Andreas Metzler wrote: [...] > The breakage is caused by the relevant change in -18/-19 (Pull patches > to temporarily add an option to turn taint errors into warnings.) Could you give 4.94.2-2 a spin? It should hit the mirrors in a couple of hours. cu Andreas -- `What

Bug#988086: Exim delivery process crashes on each mail with NULL-pointer

2021-05-05 Thread Andreas Metzler
Control: forwarded -1 https://bugs.exim.org/show_bug.cgi?id=2733 On 2021-05-05 halfdog wrote: [...] > What a weird coincidence that the 4.94-19 > seemed to crash exactly around that part of code that seemed > to related to CVE-2020-28007. Hello, thank you for the very helpful bug report that ma

Bug#987956: libgcrypt20: ECDH decryption fails with "gpg: public key decryption failed: Invalid object" error message

2021-05-02 Thread Andreas Metzler
of updated packages this day, libgcrypt20:amd64 (1.8.7-3, > 1.8.7-4) is the likely culprit. Its changelog states: > libgcrypt20 (1.8.7-4) unstable; urgency=medium > * Update from LIBGCRYPT-1.8-BRANCH: > + 30_07-Fix-previous-commit.patch > + 30_08-ecc-Check-the-input-length-f

Bug#987696: findutils: suggest plocate as an alternative

2021-05-02 Thread Andreas Metzler
Control: tags -1 pending On 2021-05-02 Christoph Anton Mitterer wrote: > On Sun, 2021-05-02 at 13:25 +0200, Andreas Metzler wrote: >> thanks for the report. I think it would be better to simply drop the >> Suggests, it was added eons ago when GNU locate was split-off from >

Bug#987696: findutils: suggest plocate as an alternative

2021-05-02 Thread Andreas Metzler
On 2021-04-28 Christoph Anton Mitterer wrote: > Package: findutils > Version: 4.8.0-1 > Severity: wishlist > plocate advertises itself as a drop-in replacement for mlocate (+ > being faster) and seems to have some active development. > So maybe you should add this as a (preferred?) alternative i

Bug#987924: unblock: exim4/4.94-19

2021-05-01 Thread Andreas Metzler
+ + * Further updates from heiko/exim-4.94+fixes+taintwarn: ++ 75_24-Silence-the-compiler.patch ++ 75_26-Disable-taintchecks-for-mkdir-this-isn-t-part-of-4.9.patch + * Upload to unstable. + + -- Andreas Metzler Mon, 26 Apr 2021 18:35:43 +0200 + +exim4 (4.94-18) experimental; urgency

Bug#987924: unblock: exim4/4.94-19

2021-05-01 Thread Andreas Metzler
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: ex...@packages.debian.org Hello, Please consider exim4/4.94-19 for bullseye. Due to the newly introduced tainting mechanism exim upgrades from buster to bullseye currently req

Bug#987133: marked as done (exim4: Exim 4.94's new tainting-feature will break many running configs)

2021-04-18 Thread Andreas Metzler
Control: reopen -1 Control: found -1 4.93-1 Control: tags -1 moreinfo Control: severity -1 normal On 2021-04-18 Marc Haber wrote: > On Sun, Apr 18, 2021 at 09:57:02AM +, Debian Bug Tracking System wrote: > > From: Andreas Metzler > > Subject: Re: Bug#987133: exim4: Exim 4.94

Bug#986036: par: new release 1.53.0

2021-03-28 Thread Andreas Metzler
On 2021-03-28 Andrea Gelmini wrote: > Package: par > Version: 1.52-5 [...] > I just wanna notify you they release a new version (1.53.0) one > year ago. > It would be nice to have it debianzied. Hello Andrea, Thanks for the heads-up. Our automatic tracking (uscan, watch files)

Bug#985984: unblock: exim4/4.94-17

2021-03-27 Thread Andreas Metzler
hangelog 2021-03-18 13:54:47.0 +0100 @@ -1,3 +1,30 @@ +exim4 (4.94-17) unstable; urgency=medium + + * Let exim4-config Recommend ca-certificates, needed for certificate +verification. + + -- Andreas Metzler Thu, 18 Mar 2021 13:54:47 +0100 + +exim4 (4.94-16) unstable; urgency=medium + +

Bug#985652: libnettle8: New upstream version fixes ECDSA signature verification issue

2021-03-21 Thread Andreas Metzler
Package: libnettle8 Version: 3.7-2.1 Severity: important Hello, nettle 3.7.2 features the following fix: | This is a bugfix release, fixing a bug in ECDSA signature | verification that could lead to a denial of service attack | (via an assertion failure) or possibly incorrect results. It | also

Bug#985466: buster-pu: package libpano13/2.9.19+dfsg-3+deb10u1

2021-03-18 Thread Andreas Metzler
ncy=medium + + * 850_f02459498cb4_Prevent_string_vulnerability_by_refusing.diff +cherry-picked from 2.9.20 rc3: Fixes format string bug, pasing along +format strings in user specified output filename to printf. +Closes: #985249 + + -- Andreas Metzler Thu, 18 Mar 2021 14:12:08 +0100 + libpano13 (2.9.19+dfsg-3) unstable; urge

Bug#985450: buster-pu: package exim4/4.92-8+deb10u5

2021-03-18 Thread Andreas Metzler
tM attacks are possible, but for a stable update documenting +this is the best compromise.) + + -- Andreas Metzler Thu, 18 Mar 2021 09:10:15 +0100 + exim4 (4.92-8+deb10u4) buster-security; urgency=high * Fix authentication bypass in SPA authenticator due to out-of-bound buffer diff -Nru

Bug#985343: libvigraimpex-doc: unhandled symlink to directory conversion: /usr/share/doc/libvigraimpex-dev/html -> ../libvigraimpex-doc/html

2021-03-17 Thread Andreas Metzler
On 2021-03-16 Andreas Beckmann wrote: > Package: libvigraimpex-doc > Version: 1.11.1+dfsg-8 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > Hi, > an upgrade test with piuparts revealed that your package installs files > over existing symlinks and possibly overwrites

Bug#985343: libvigraimpex-doc: unhandled symlink to directory conversion: /usr/share/doc/libvigraimpex-dev/html -> ../libvigraimpex-doc/html

2021-03-17 Thread Andreas Metzler
On 2021-03-16 Andreas Beckmann wrote: > Package: libvigraimpex-doc > Version: 1.11.1+dfsg-8 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > Hi, > an upgrade test with piuparts revealed that your package installs files > over existing symlinks and possibly overwrites

Bug#985212: dh_installdeb: Check for dpkg-maintscript-helper args misparses shell code, cannot handle filenames with spaces

2021-03-15 Thread Andreas Metzler
On 2021-03-14 Niels Thykier wrote: > Andreas Metzler: >> Package: debhelper [...] >> in #929165 Hideki wanted to use rm_conffile to remove junk from earlier >> versions, notably files containing spaces and wildcards in their name: >> ./etc/apt/trusted.gpg.d/ubuntu

Bug#985212: dh_installdeb: Check for dpkg-maintscript-helper args misparses shell code, cannot handle filenames with spaces

2021-03-14 Thread Andreas Metzler
Package: debhelper Version: 13.3.4 Severity: normal Hello, in #929165 Hideki wanted to use rm_conffile to remove junk from earlier versions, notably files containing spaces and wildcards in their name: ./etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cloud-archive, ubuntu-cloud-removed-keys.gpg ./e

Bug#929165: How to use rm_conffile to remove files that contain empty " ", comma "," and wildcard "*"?

2021-03-14 Thread Andreas Metzler
On 2021-03-14 Hideki Yamane wrote: > On Sun, 7 Mar 2021 08:47:05 +0100 > Andreas Metzler wrote: >> I think that might be a dh_installdeb error, it seems to check whether >> the first character is a '/', and does not account for possible quoting >> character

Bug#852051: libvigraimpex: captures build path (doesn't build reproducible)

2021-03-13 Thread Andreas Metzler
On 2021-03-13 Nilesh Patra wrote: [...] > Thanks, that explains my email bouncing from his mailbox. libvigraimpex > still does not build reproducibly unfortunately. > Are you working on this bug? No, I have not yet looked at it. cu Andreas -- `What a good friend you are to him, Dr. Maturin. Hi

Bug#852051: libvigraimpex: captures build path (doesn't build reproducible)

2021-03-13 Thread Andreas Metzler
On 2021-03-13 Nilesh Patra wrote: > On Sat, 21 Jan 2017 07:34:35 +0100 Daniel Stender > wrote: [...] > > libvigraimpex doesn't build reproducible [1] because the build path is > > captured during build [2]. I'll get into this shortly. > I know it's been quite a while, but any progress on this o

Bug#941199: Upstream has valid debian packaging

2021-03-11 Thread Andreas Metzler
Control: unblock 941199 by 958509 On 2020-04-17 Seunghun Han wrote: [...] > Dear Laurent Bigonville and Christian Ehrhardt, > I would like to package this one. > Best regards, Hello Seunghun, are you still working on this or should I retitle this to ITP? cu Andreas -- `What a good friend yo

Bug#984884: libgcrypt20: Unknown error executing apt-key [Bullseye]

2021-03-09 Thread Andreas Metzler
Control: tags -1 moreinfo Control: severity -1 normal On 2021-03-09 Davide Prina wrote: [...] > Some users in Italian mailing list have reported that they have an error > when they try upgrade/install packages: [...] > dig the problem we found that they have the following files on their system: [

Bug#929165: How to use rm_conffile to remove files that contain empty " ", comma "," and wildcard "*"?

2021-03-06 Thread Andreas Metzler
On 2021-03-07 Hideki Yamane wrote: > X-debbugs-CC: debian-de...@lists.debian.org > I've tried to remove files that was accidentally containts empty " ", > comma "," and wildcard "*" via rm_conffile from dpkg-maintscript-helper. > However, it returns an error like below. > > dh_installdeb: err

Bug#983209: lynx: differences in documentation when built in parallel

2021-03-02 Thread Andreas Metzler
Control: tags -1 fixed-upstream On 2021-02-27 Andreas Metzler wrote: > On 2021-02-21 Vagrant Cascadian wrote: > [...] > > The lynx documentation has many differences between two builds: [...] > > All of the documentation differences disappeared for me when disabling > >

Bug#983209: lynx: differences in documentation when built in parallel

2021-02-27 Thread Andreas Metzler
On 2021-02-21 Vagrant Cascadian wrote: [...] > The lynx documentation has many differences between two builds: > > https://tests.reproducible-builds.org/debian/rb-pkg/bullseye/amd64/diffoscope-results/lynx.html > /usr/share/doc/lynx-common/lynx_help/body.html.gz > In one of the builds, the

Bug#983208: lynx: embeds path to various binaries that differ with usrmerge

2021-02-22 Thread Andreas Metzler
On 2021-02-21 Vagrant Cascadian wrote: > On 2021-02-21, Andreas Metzler wrote: [...] > Thanks for applying. > > I don't get the point of trying to do reproducible builds on systems > > that differ significantly (usrmerge or not), it feels like make-work. > I get that

Bug#983208: lynx: embeds path to various binaries that differ with usrmerge

2021-02-21 Thread Andreas Metzler
Control: tags -1 pending On 2021-02-21 Vagrant Cascadian wrote: > Source: lynx > Severity: normal > Tags: patch > User: reproducible-bui...@lists.alioth.debian.org > Usertags: usrmerge > X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org > The paths to various binaries are embedded in /usr/

Bug#982482: libnettle8: chacha breakage on ppc64(el)

2021-02-21 Thread Andreas Metzler
On 2021-02-13 Andreas Metzler wrote: [...] > Find attached a proposed debdiff. Uploaded to delayed/5. cu Andreas

Bug#982482: libnettle8: chacha breakage on ppc64(el)

2021-02-12 Thread Andreas Metzler
On 2021-02-10 Andreas Metzler wrote: > Package: libnettle8 > Version: 3.7-1 > Severity: serious > Tags: upstream patch fixed-upstream > nettle 3.7 breaks GnuTLS testsuite on ppc64(el). I had forwarded this > upstream > https://lists.lysator.liu.se/pipermail/nettle-bugs

Bug#982482: libnettle8: chacha breakage on ppc64(el)

2021-02-10 Thread Andreas Metzler
Package: libnettle8 Version: 3.7-1 Severity: serious Tags: upstream patch fixed-upstream nettle 3.7 breaks GnuTLS testsuite on ppc64(el). I had forwarded this upstream https://lists.lysator.liu.se/pipermail/nettle-bugs/2021/009418.html and there is now a fix (+ testsuite coverage) in nettle GIT ma

Bug#982207: gnupg-utils: obsolete package Priority: Extra

2021-02-07 Thread Andreas Metzler
Control: reassign -1 ftp.debian.org Control: forcemerge 948575 -1 On 2021-02-07 Andreas Metzler wrote: > On 2021-02-07 Martin-Éric Racine wrote: >> Package: gnupg-utils >> Version: 2.2.20-1 >> Since Debian policy 10.11. released in August 2017, section 2.5 marks >>

Bug#982217: Disable scm_install_gmp_memory_functions (was: Bug#964284: guile-gnutls: update to use guile 3.0])

2021-02-07 Thread Andreas Metzler
Package: guile-3.0 Version: 3.0.4-2 Let's track this properly … - Forwarded message from Ludovic Courtès - Date: Fri, 05 Feb 2021 16:16:41 +0100 From: Ludovic Courtès Subject: Bug#964284: guile-gnutls: update to use guile 3.0 Message-ID: <87y2g235pi@gnu.org> I forgot to mention th

Bug#982207: gnupg-utils: obsolete package Priority: Extra

2021-02-07 Thread Andreas Metzler
On 2021-02-07 Martin-Éric Racine wrote: > Package: gnupg-utils > Version: 2.2.20-1 > Severity: normal > Since Debian policy 10.11. released in August 2017, section 2.5 marks > the package priority Extra as deprecated. Priority Optional should be > used instead. Hello, afaik priorities are effec

Bug#982170: libassuan: autopkgtest regression: undefined reference to symbol 'gpg_strerror@@GPG_ERROR_1.0'

2021-02-07 Thread Andreas Metzler
See https://salsa.debian.org/debian/libassuan/-/merge_requests/1 cu Andreas -- `What a good friend you are to him, Dr. Maturin. His other friends are so grateful to you.' `I sew his ears on from time to time, sure' signature.asc Description: PGP signature

Bug#982170: libassuan: autopkgtest regression: undefined reference to symbol 'gpg_strerror@@GPG_ERROR_1.0'

2021-02-07 Thread Andreas Metzler
On 2021-02-07 Paul Gevers wrote: > Source: libassuan > Version: 2.5.4-1 > X-Debbugs-CC: debian...@lists.debian.org > Severity: serious > User: debian...@lists.debian.org > Usertags: regression > Dear maintainer(s), > With a recent upload of libassuan the autopkgtest of libassuan fails in > testi

Bug#981581: nmu: sa-exim_4.2.1-19

2021-02-01 Thread Andreas Metzler
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu nmu sa-exim_4.2.1-19 . ANY . unstable . -m "Rebuild against current exim localscan ABI. (See #981398)" That is necessary to let sa-exim work again in sid and bulleye. The wrong Provides of

Bug#981385: offlineimap3: CRAM-MD5 authentication broken - encoding without a string argument

2021-02-01 Thread Andreas Metzler
On 2021-01-31 Sudip Mukherjee wrote: [...] > Thanks for attaching offlineimaprc in upstream issue. I think I was able to > reproduce the error with offlineimap3. And, in my setup the rootcause of the > issue is same as #981063 and is fixed when I use the patch attached there. > Can you please try

Bug#980630: libvigraimpex: FTBFS: UnicodeDecodeError: 'utf-8' codec can't decode byte 0xb3 in position 138922: invalid start byte

2021-01-30 Thread Andreas Metzler
On 2021-01-20 Lucas Nussbaum wrote: > Source: libvigraimpex > Version: 1.11.1+dfsg-7 > Severity: serious > Justification: FTBFS on amd64 [...] > > File "/usr/lib/python3.9/codecs.py", line 322, in decode > > (result, consumed) = self._buffer_decode(data, self.errors, final) > > UnicodeDecode

<    1   2   3   4   5   6   7   8   9   10   >