Bug#1073507: postgresql-16-pgnodemx: Incomplete package description

2024-06-17 Thread Christoph Berg
Re: Teemu Hukkanen > The package description is incomplete, both the short and long > description have "FIXME" at the beginning, without a useful description. Oops, thanks for spotting! Christoph

Bug#1073210: systemd-boot-efi: loader.conf default entry incompatibility

2024-06-14 Thread Christoph Ziebuhr
Package: systemd-boot-efi X-Debbugs-Cc: ch...@codefrickler.de Version: 252.22-1~deb12u1 Severity: normal Tags: upstream We are managing IoT devices as a product, which consists of two root partitions with corresponding loader/entries/*.conf file on the EFI partition. On each update, a whole

Bug#1073040: dput: Fails when processing ssh_config_options value: AttributeError: 'list' object has no attribute 'split'

2024-06-14 Thread Christoph Berg
t - it was already failing on the default case. I'd say just upload and I'll report back if it's still failing. Thanks! Christoph

Bug#1073074: firefox: looses previous tabs

2024-06-12 Thread Christoph Anton Mitterer
FYI: I haven't seen that behaviour after upgrading... and I do have quite a few tabs in many windows open. Maybe it happens not in all configurations. Cheers, Chris.

Bug#1059476: postgresql-15: backend crash caused by query in llvm on arm64

2024-06-12 Thread Christoph Berg
Re: Stefan Heine > how can I find, what version of the llvm library a given version of postgres > is linked to? It should be visible in the linker flags: select * from pg_config(); LDFLAGS │ -Wl,-z,relro -Wl,-z,now -L/usr/lib/llvm-16/lib -Wl,--as-needed Christoph

Bug#1061842: fixed in 0.6.7-1

2024-06-12 Thread Hans-Christoph Steiner
control: fixed -1 0.6.7-1

Bug#1072857: dput: Incorrect delayed argument: ValueError: delayed days value must be a decimal integer:

2024-06-11 Thread Christoph Berg
AttributeError: 'list' object has no attribute 'split' Christoph

Bug#918316: nocache: diff for NMU version 1.1-1.1

2024-06-09 Thread Christoph Biedl
Control: tags 918316 - pending Christoph Biedl wrote... > to fix the issues with this package, I've prepared an NMU for nocache > (versioned as 1.1-1.1), debdiff below. Not going to upload this, NMU doesn't make sense without fixing #1069426 as well. Christoph signature.asc Descr

Bug#918316: nocache: diff for NMU version 1.1-1.1

2024-06-09 Thread Christoph Biedl
Control: tags 918316 + patch pending Dear maintainer, to fix the issues with this package, I've prepared an NMU for nocache (versioned as 1.1-1.1), debdiff below. An upload to DELAYED/5 will follow shortly. Please feel free to tell me if I should delay it longer. Regards, Christoph diff

Bug#1072820: slm: Issues in slm documentation strings

2024-06-08 Thread Christoph Brinkhaus
sgid "administrator's e-mail address:" # FIXME: s/administrator's/Administrator's/ #. Type: password #. Description #: ../slm.templates:4001 msgid "administrator's password:" Thank you very much for maintaining this project, Christoph Brinkhaus

Bug#1072819: slm: [L10N,DE] slm 0.8.3-3: german translation

2024-06-08 Thread Christoph Brinkhaus
Package: slm Version: 0.8.3-3 Severity: wishlist Dear Maintainer, please find attached the po file with the german translation. Please consider to apply it to the package. Thank you very much! Kind regards, Christoph Brinkhaus # Translation of the SLM template to German. # This file

Bug#918316: nocache: FTBFS in sid

2024-06-07 Thread Christoph Biedl
As systemd certainly will not move, nocache has to. I'll check out the upstream change and will prepare an NMU upon success. Christoph ¹ https://lists.debian.org/msgid-search/a77c773c1e8cbeadeefbd30f21e7bbeb21a9d9bc.ca...@debian.org signature.asc Description: PGP signature

Bug#1054299: ITP: orphaner -- text menu frontend to deborphan

2024-06-06 Thread Christoph Anton Mitterer
FYI: deborphan has been removed from Debian. Cheers, Chris.

Bug#237925: ITP: cdemu -- emulating optical drives

2024-06-06 Thread Christoph Anton Mitterer
Hey Matteo. I guess this and #705409 can be closed now? Not sure about #983453. Cheers, Chris.

Bug#1069176: debhelper: Issues in Debhelper documentation strings

2024-06-01 Thread Christoph Brinkhaus
Hello Niels, Am Sat, Jun 01, 2024 at 03:19:53PM +0200 schrieb Niels Thykier: > Christoph Brinkhaus: > > Package: debhelper > > Version: 13.15.3 > > Severity: minor [...] > > 7. Issue: would no longer installs → no longer installs > > Explanation: Make the descri

Bug#1072249: systemd: leftover files on the underlying /tmp since /tmp became tmpfs

2024-05-30 Thread Christoph Anton Mitterer
Oh and one more: The underlying /tmp (i.e. when not mounted) is now still 1777/drwxrwxrwt . It might make sense to change that to e.g. 0755/drwxr-xr-x? Of course that would leave a defunct /tmp if the tmpfs is unmounted, but at the same time prevent accidental writes there. So depends on

Bug#1072249: systemd: leftover files on the underlying /tmp since /tmp became tmpfs

2024-05-30 Thread Christoph Anton Mitterer
Package: systemd Version: 256~rc3-6 Severity: normal Hey. When /tmp was switched over to tmpfs, it seems that there was no cleanup of the underlying /tmp (i.e. on the underlying fs), so any files that had been there, are still there and will – unless manually removed – remain there forever.

Bug#1067733: iptables: regression in 1.8.9 with -n breaks portblock in resource-agents

2024-05-27 Thread Christoph Böhmwalder
So, how do we move forward here? We have been receiving numerous reports of this issue breaking systems, and we don't have a great workaround either. Please let me know if there is anything we can do to help get this patch applied, thanks.

Bug#1071321: tagging 1071321

2024-05-26 Thread Christoph Biedl
Christoph Biedl wrote... > (and why does the BTS¹ not show Étienne's > message?). Never mind, just a race condition. signature.asc Description: PGP signature

Bug#1071321: tagging 1071321

2024-05-26 Thread Christoph Biedl
ere might be a small chance this breaks packages due to slight implementation differences - but that's what testing and autopkgtests are for. Christoph (affected by this bug via tcpreplay) ¹ https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1071321 signature.asc Description: PGP signature

Bug#1071790: libpcre2-dev: consider moving the non-development related manpages to a non-dev package?

2024-05-24 Thread Christoph Anton Mitterer
Package: libpcre2-dev Version: 10.42-4+b1 Severity: wishlist Hey. Currently, general purpose manpages like pcre2pattern(3) are also in libpcre2-dev. IMO it would make sense to either ship them in a -doc package or perhaps at least one of the lib packages? Thanks, Chris.

Bug#1071693: sbsign should check certificate's expiration

2024-05-23 Thread Christoph Biedl
ration date, warns if it's less than 365 days in the future, and exits non-zero if it's less than 30 days, or even already expired. Todo: * Make the thresholds configurable via command line options. * Documentation, including "Setting the thresholds to 0 (zero) disables the check&qu

Bug#1053004: CVE-2019-10784 and CVE-2023-40619

2024-05-22 Thread Christoph Berg
Re: Moritz Mühlenhoff > Agreed, if the package is actually broken with the version of PostgreSQL > in stable and if there's no sensible backport for the open security issues, > then let's rather remove it by the next point release. Ack. Christoph

Bug#1062209: should not block migration to testing

2024-05-21 Thread Hans-Christoph Steiner
control: severity -1 normal Thanks for reporting! In the Android Tools case, the shared libs and packages that use them are packaged together, often from the same source package, so I can't see why we'd need special versions of it. And when we need to, we can use strictly versioned

Bug#1062110: should not block migration to testing

2024-05-21 Thread Hans-Christoph Steiner
control: severity -1 normal Thanks for reporting! In the Android Tools case, the shared libs and packages that use them are packaged together, often from the same source package, so I can't see why we'd need special versions of it. And when we need to, we can use strictly versioned

Bug#1062209: should not block migration to testing

2024-05-21 Thread Hans-Christoph Steiner
control: severity -1 normal Thanks for reporting! In the Android Tools case, the shared libs and packages that use them are packaged together, often from the same source package, so I can't see why we'd need special versions of it. And when we need to, we can use strictly versioned

Bug#1071335: upstream commits

2024-05-18 Thread Christoph Biedl
ebian packaging. As you'd expect, version 1.5 builds fine again, will do some more checks and upload during the weekend. Christoph signature.asc Description: PGP signature

Bug#761820: RFP: tsmuxer -- mux video to TS/M2TS files or create BD disks

2024-05-17 Thread Christoph Anton Mitterer
Hey. Just a note: In 2019, tsmuxer has been released under Apache 2.0 license. See https://github.com/justdan96/tsMuxer . Cheers, Chris.

Bug#1070891: apt-show-versions: Permission denied on a bad pathname

2024-05-15 Thread Christoph Martin
Am 14.05.24 um 10:39 schrieb Vincent Lefevre: This could explain the error. I'm wondering why apt plays with the permissions. This is confusing. Or should there be a locking mechanism? This reminds me about the long due rewrite to use the apt-API to access these files and not read them

Bug#1071030: postgresql-15: Drop database hang.

2024-05-15 Thread Christoph Berg
fix (at least on the PG side), can we close the bug? Christoph

Bug#1070891: apt-show-versions: Permission denied on a bad pathname

2024-05-14 Thread Christoph Martin
Hi Vincent, Am 13.05.24 um 19:59 schrieb Vincent Lefevre: On 2024-05-13 17:12:57 +0200, Christoph Martin wrote: Please try to access the file e.g. 'less /var/lib/apt/lists//debug.mirrors.debian.org_debian-debug_dists_stable-debug_InRelease' No problems. You could try to prepend strace

Bug#1070891: apt-show-versions: Permission denied on a bad pathname

2024-05-13 Thread Christoph Martin
an you access this files content? Apart from that, I can't spot a problem. Christoph OpenPGP_signature.asc Description: OpenPGP digital signature

Bug#1070891: apt-show-versions: Permission denied on a bad pathname

2024-05-13 Thread Christoph Martin
_InRelease for reading: Permission denied I don't know why could cause the error, but the pathname with "//" is incorrect. // in the path should not be a problem. Can you do a 'ls -l /var/lib/apt/lists/' to see the permissions? Which user does the cronjob run with? Christoph O

Bug#1071051: bash-completion: new upstream version

2024-05-13 Thread Christoph Anton Mitterer
Package: bash-completion Version: 1:2.13.0-1 Severity: wishlist Hey. 2.14.0 is out which allegedly fixes the bug[0] that remote scp file completion was no longer working. Thanks, Chris. [0] https://github.com/scop/bash-completion/issues/1157

Bug#1071030: postgresql-15: Drop database hang.

2024-05-13 Thread Christoph Berg
it wasn't included? Can you pull a backtrace of the hanging process? https://wiki.postgresql.org/wiki/Getting_a_stack_trace_of_a_running_PostgreSQL_backend_on_Linux/BSD Christoph

Bug#1055989: Bug reproduced in 1:29.3+1-2

2024-05-09 Thread Christoph Reichenbach
Hello again, just to keep the records up to date: the bug is still present in 1:29.3+1-2, and the same patch still works around it (for me). All the best, -- Christoph signature.asc Description: PGP signature

Bug#1062105: should not block migration to testing

2024-05-08 Thread Hans-Christoph Steiner
control: severity -1 normal Thanks for reporting! In the Android Tools case, the shared libs and packages that use them are packaged together, often from the same source package, so I can't see why we'd need special versions of it. And when we need to, we can use strictly versioned

Bug#1070386: ITP: pass-import - MediaWiki API client in Python

2024-05-04 Thread Hans-Christoph Steiner
Package: wnpp Severity: wishlist Owner: Hans-Christoph Steiner * Package name: remarkable Version : 1.87+git20240504.e8cc99d Upstream Author : Jamie McGowan * URL : https://github.com/roddhjav/pass-import * License : BSD-2 GPL-2+ LGPL-2.1+ MIT Programming

Bug#1070331: RFS: nq/0.5-0.1 [NMU] -- Lightweight queue system

2024-05-03 Thread Christoph Biedl
Preuße, Hilmar wrote... > On 03.05.2024 22:29, Christoph Biedl wrote: > > Hilmar Preusse wrote... > > > * Bump Standards and dh compat version, no changes needed. > > > > I'm a little surprised why you would change that in a NMU. > > > Well, thi

Bug#1070331: RFS: nq/0.5-0.1 [NMU] -- Lightweight queue system

2024-05-03 Thread Christoph Biedl
programs with different | functionality but with the same filenames. Christoph signature.asc Description: PGP signature

Bug#1038937: nq package out of date with upstream, 0.5 was released more than a year ago

2024-05-03 Thread Christoph Biedl
est by upstream and following the statements given in <https://github.com/leahneukirchen/nq/issues/48#issuecomment-2091077937>, also there's the LowNMU flag ... I'll upload 0.5-0.1 in the next days. To improve quality and as it was a no-brainer, I'll also add an autopkgtest. Christoph sign

Bug#998627: linux: please enable the new NTFS3 driver in 5.15

2024-05-02 Thread Christoph Anton Mitterer
Hey. Seems there were at least a series of commits from upstream last November and few again this January. And there even seem to be some more in their dev branch. The number of CVEs mentioned by Salvatore is worrying, but it looks even much worse over the years for ntfs-3g:

Bug#1070064: separate columns by 2 spaces in lists

2024-04-29 Thread Christoph Berg
-editables ... which looked like libhwy1-python3-editables to me. Thanks for considering, Christoph

Bug#1069890: Resignation & call for votes to elect the Chair

2024-04-29 Thread Christoph Berg
Re: Sean Whitton > ===BEGIN > > A: Christoph Berg > B: Matthew Garrett > C: Helmut Grohne > D: Stefano Rivera > E: Timo Röhling > F: Craig Small > G: Matthew Vernon > H: Sean Whitton > > ===END I vote H > ABCDEG > F Christoph signature.asc Description: PGP signature

Bug#1069915: file: wrong Breaks/Replaces in libmagic-mgc

2024-04-28 Thread Christoph Biedl
intainer didn't notice either. > The attached patch fixes this mistake, although since the version in > oldoldstable is 1:5.35-4+deb10u2, perhaps you would prefer to drop the > fields instead. Indeed, this was needed in 2016, will remove it in the next upload. Christoph signat

Bug#1068849: cryptsetup: Fails to unlock the filesystem with missing libgcc_s.so.1

2024-04-26 Thread Christoph Anton Mitterer
On Sat, 2024-04-27 at 03:15 +0200, Guilhem Moulin wrote: > Yup that'd make sense to me (and I see you did that already), thanks! :-) Unfortunately I doubt it will be possibly to do some fully generic solution. So best we'll get is probably either an unconditional inclusion or some simpler

Bug#1069912: argon2 tool doesn't properly link against pthread

2024-04-26 Thread Christoph Anton Mitterer
Control: reassign -1 initramfs-tools Control: severity -1 important Control: retitle -1 copy_exec doesn't detect libgcc dependency anymore when pthread is used Hey. I think I found the root cause (thanks to Guilhem Moulin, who pointed[0] me to it). Apparently (which wasn't on my radar at all

Bug#1068849: cryptsetup: Fails to unlock the filesystem with missing libgcc_s.so.1

2024-04-26 Thread Christoph Anton Mitterer
On Sat, 2024-04-27 at 01:48 +0200, Guilhem Moulin wrote: > built using glibc ≥2.34.  AFAICT the “if the ldd output includes > libpthread then run copy_libgcc()” logic from initramfs-tools is > mostly moot > now Ah, I just realised glibc "merged" libpthread ^^ Therefore... > but despite what I

Bug#1068849: cryptsetup: Fails to unlock the filesystem with missing libgcc_s.so.1

2024-04-26 Thread Christoph Anton Mitterer
Hey Guilhem On Sat, 2024-04-27 at 01:48 +0200, Guilhem Moulin wrote: > Even it weren't, libpthread wouldn't show up since src:argon2 from > bookworm > and later is built using glibc ≥2.34. When argon2 builds, it uses -pthread ... not really sure what that does exactly, the manpage merely says it

Bug#1069912: argon2: argon2 tool doesn't properly link against pthread

2024-04-26 Thread Christoph Anton Mitterer
Package: argon2 Version: 0~20190702+dfsg-4+b1 Severity: wishlist Hey. I stumbled over some odd issue, originally described here: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068849#84 In short: I use the argon2 tool inside the initramfs, into which I copy it via initramfs-tools’

Bug#1068849: [pkg-cryptsetup-devel] Bug#1068849: cryptsetup: Fails to unlock the filesystem with missing libgcc_s.so.1

2024-04-26 Thread Christoph Anton Mitterer
Hey guys. I kinda ran into a similar issue. I use my own OpenPGP keyscript which is highly improved upon that ("decrypt_gnupg") shipped by the package. One thing that I do is offer optionally feeding the entered passphrase trough argon2 (the standalone tool from the package of the same name)

Bug#1069692: nfs-ganesha: FTBFS on arm{el,hf}: /usr/include/features-time64.h:26:5: error: #error "_TIME_BITS=64 is allowed only with _FILE_OFFSET_BITS=64"

2024-04-23 Thread Christoph Martin
/SETLKW64. Currently GPFS kernel module doesn't work * with these 64 bit macro values through ganesha interface. Undefine it * here to use plain F_GETLK/SETLK/SETLKW values. */ #undef _FILE_OFFSET_BITS I'll exclude the GPFS module for armel and armhf. Regards Christoph OpenPGP_signature.asc

Bug#1069705: lilypond man-page has defective link on Debian

2024-04-23 Thread Christoph Brinkhaus
uld be better. Please fix the issue in one of the next updates. Thank you very much for taking care of the project, Christoph Brinkhaus

Bug#1069183: [Aptitude-devel] Bug#1069183: aptitude: already running package installs/upgrade get interrupted because of lost dpkg lock

2024-04-22 Thread Christoph Anton Mitterer
Hey. Just upgraded (via aptitude) to the most recent apt in sid on a number of nodes (this time, all *without* any Icinga/Prometheus stuff)... and on all nodes the locking issue showed up: # aptitude Performing actions... Retrieving bug reports... Done Parsing Found/Fixed information... Done

Bug#1064293: less: CVE-2022-48624

2024-04-20 Thread Christoph Anton Mitterer
On Sat, 2024-04-20 at 07:54 -0400, P. J. McDermott wrote: > Then the salvage procedure can play out for the full 28+ days > specified > by developers-reference (21 days to allow the maintainer to object > followed by a DELAYED/7 adoption upload).  I've already soft-proposed > to > salvage in bug

Bug#1068024: revert to version that does not contain changes by bad actor

2024-04-19 Thread Christoph Anton Mitterer
Hey. On Sun, 2024-03-31 at 01:46 +, Thorsten Glaser wrote: > Yes, a multi-team task force is working on it and will inform users > once it is known how to proceed, inclusing how much to throw away > and rebuild. Kindly wanted to ask whether anything has come out meanwhile of that? I've

Bug#1069251: ca-certificates-java: keystore is not updated

2024-04-18 Thread Christoph Anton Mitterer
Package: ca-certificates-java Version: 20230710~deb12u1 Severity: important Hey. Actually I think this should have a higher severity, since the trusted certs may very well be quit security critical. Nevertheless: I just traced a bug for some hours, where it eventually turned out that

Bug#1069183: [Aptitude-devel] Bug#1069183: aptitude: already running package installs/upgrade get interrupted because of lost dpkg lock

2024-04-17 Thread Christoph Anton Mitterer
Hey David. Thanks for your elaborate mail On Wed, 2024-04-17 at 21:55 +0200, David Kalnischkies wrote: > > Unpacking util-linux-extra (2.38.1-5+deb12u1) over (2.38.1-5+b1) > > ... > > Setting up util-linux-extra (2.38.1-5+deb12u1) ... > > dpkg: error: dpkg frontend lock was locked by another

Bug#994220: base-files: add /etc/local and /usr/local/libexec

2024-04-17 Thread Christoph Anton Mitterer
On Thu, 2024-04-18 at 00:34 +0200, Santiago Vila wrote: > > > I think you might be overestimating the importance of this. Well I haven't said it would be super important (not at least that the dirs are created - what might be more important is, if e.g. owners are changed, like when stuff was

Bug#994220: base-files: add /etc/local and /usr/local/libexec

2024-04-17 Thread Christoph Anton Mitterer
On Wed, 2024-04-17 at 23:43 +0200, Santiago Vila wrote: > Yes. An empty $2 means that the package is installed for the > very first time, i.e. installed by debootstrap. > > This is actually explained in the last question here: > > /usr/share/doc/base-files/FAQ Isn't that quite unfortunate? It

Bug#994220: base-files: add /etc/local and /usr/local/libexec

2024-04-17 Thread Christoph Anton Mitterer
Hey. FYI: I have upgraded to 13.1, but still didn't get a /usr/local/libexec. Guess that's because $2 in the script is not empty? Cheers, Chris.

Bug#1069198: RFS: chr/0.1.78-1 [RC] -- terminal-based text editor

2024-04-17 Thread Christoph Hueffelmann
Package: sponsorship-requests Severity: important X-Debbugs-CC:textsh...@uchuujin.de Dear mentors, I am looking for a sponsor for my package "chr": * Package name : chr Version : 0.1.78-1 Upstream contact : Christoph Hueffelmann * URL :https://

Bug#1069183: aptitude: already running package installs/upgrade get interrupted because of lost dpkg lock

2024-04-17 Thread Christoph Anton Mitterer
btw: There already is #586486 but to me it looked rather like a different issue.

Bug#1069185: xserver-xorg-core: new upstream version (which has a nice fix)

2024-04-17 Thread Christoph Anton Mitterer
Package: xserver-xorg-core Version: 2:21.1.12-1 Severity: wishlist Hey. Joking: " Debin's xorg lacks critical security patches, I demand make me maintainer immediately " Too soon for XZ jokes? O:-P Seriously, there's a new upstream version out (21.1.13), which incorporates not only the fix

Bug#1069183: aptitude: already running package installs/upgrade get interrupted because of lost dpkg lock

2024-04-17 Thread Christoph Anton Mitterer
Package: aptitude Version: 1.21.22 Severity: important Hey. May very well be an issue in APT or rather dpkg, still, since I always see it from aptitude, I report it here. Please re-assign accordingly. I'm seeing this since quite some releases and also every now and then in unstable (though

Bug#1069176: debhelper: Issues in Debhelper documentation strings

2024-04-17 Thread Christoph Brinkhaus
the documentation is updated I will be happy to update the translation accordingly. Thank you very much for maintaining this huge project, Christoph Brinkhaus 1. Issue: s/source/B/ Explanation: The fix should correct the appearance to be bold. Occurance: debhelper.pod:517 Current string: "

Bug#1069175: Mention "megacli" in Description

2024-04-17 Thread Christoph Berg
"megacli" tool. ... Christoph

Bug#1067831: libaio: the t64 package slipped through and is in testing

2024-04-15 Thread Christoph Berg
he past few decades, so this rename is going to confuse quite a few people if not reverted. Christoph

Bug#1069037: less: new upstream version

2024-04-15 Thread Christoph Anton Mitterer
Package: less Version: 590-2 Severity: wishlist Hey. Less 590 is quite outdated (from somewhere mid 2021)... would be nice to have the current version. There's been quite some changes meanwhile including improvements to follow mode. Cheers, Chris.

Bug#632868: base-files: derive PATH in /etc/profile from /etc/login.defs

2024-04-15 Thread Christoph Anton Mitterer
Hey. I mostly forgot the details of this issue ^^ On Mon, 2024-04-15 at 13:08 +0200, Santiago Vila wrote: > I'd like to be sure that things will not break horribly > for somebody. What I can say at least (which is of course not a definite answer) is, that I personally run my systems since quite

Bug#1064293: less: CVE-2022-48624

2024-04-12 Thread Christoph Anton Mitterer
Hey. There seems to be a somewhat similar issue reported by Jakub Wilk on oss-security: https://www.openwall.com/lists/oss-security/2024/04/12/5 where quoting causes troubles (though I couldn't replay the demo). Any chance to get both fixed in Debian unstable? Cheers, Chris.

Bug#1068825: apt: possible super minor security issue in apt-get source

2024-04-11 Thread Christoph Anton Mitterer
On Thu, 2024-04-11 at 22:12 +0200, Julian Andres Klode wrote: > >   => First, I'm not sure whether this is the right behaviour, as > > the > > "original/modified" file seems to get removed, but it - being > > a > > local file - may actually be something of value to the user. > > So

Bug#1068826: vobcopy: homepage seems dead

2024-04-11 Thread Christoph Anton Mitterer
Source: vobcopy Version: 1.2.1-4 Severity: minor Hey. The site listed in the homepage field: Homepage: http://vobcopy.org seems dead and links eventually to some (I guess) Turikish football website. Should perhaps be removed and replaced with the github repo:

Bug#1068825: apt: possible super minor security issue in apt-get source

2024-04-11 Thread Christoph Anton Mitterer
Package: apt Version: 2.7.14 Severity: normal Tags: security Hey. I noted the following behaviour - which may or may not be regarded as security relevant. So this is rather a heads up, and in case you think it's fine as it is, just close it. I always remembered that apt-get source was ought to

Bug#1002458: "version in VCS newer than in repository" might be a bit overzealous

2024-04-11 Thread Christoph Berg
, IOW, Myon: my I reassign this back to qa.debian.org > for vcswatch? Done. Christoph

Bug#1068730: Fails to build from source since removal of liblz4-tool

2024-04-09 Thread Christoph Biedl
(build passes, didn't check further). Cheers, Christoph -- System Information: Debian Release: trixie/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Kernel: Linux 6.6.23 (SMP w/8 CPU threads) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap

Bug#1068722: aapt: symbol lookup error: libandroidfw.so.0: undefined symbol: _Z18ExtractEntryToFileP10ZipArchiveP8ZipEntryi

2024-04-09 Thread Hans-Christoph Steiner
Package: aapt Version: 1:10.0.0+r36-10 Severity: important Dear Maintainer, When adb/fastboot is installed from bookworm-backports, those pull in android-libziparchive 1:33.0.3-2~bpo12+1, which does not have the symbols that bookworm's aapt needs to run: $ aapt aapt: symbol lookup error:

Bug#1068674: Document pam_umask change in release notes

2024-04-09 Thread Christoph Anton Mitterer
Hey. Also with respect to having this documented in the release note, you may want to have a look at my comment: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1065806#47 I.e. I think it might be usefull to not just indicate that/how people may use "nousergroups" again, but also to refer to

Bug#1065806: fixed in pam 1.5.3-7

2024-04-09 Thread Christoph Anton Mitterer
My I suggest one further improvement: I think it would be nice if there was a sentence like: "See the pam_umask(8) manpage for alternative means to change the UMASK, for example per-user only." I guess there are users that would actually want to keep the new default, but have it e.g.

Bug#1065806: fixed in pam 1.5.3-7

2024-04-09 Thread Christoph Anton Mitterer
Hey Sam. There's a typ in the NEWS enty: >this user a group name that differs from the user name or add | should probably be "use" Also, I had to think twice what's meant by "pat" ;-) > matches their primary user name (user pat's default group is also >called

Bug#1068569: RM: nfs-ganesha-ceph [armel armhf i386] -- NBS; ceph dropped 32 bit support

2024-04-08 Thread Christoph Martin
Hi Adam, Am 08.04.24 um 19:15 schrieb Adam D. Barratt: On Mon, 2024-04-08 at 11:42 +0200, Christoph Martin wrote: Hi Sebastian, the packages are already removed from testing and unstable. Where do you see a problem? I'm not Sebastian, but the archive disagrees with you about the packages

Bug#1068640: clevis-initramfs: clevis early boot DNS fail, no resolv.conf created by ipconfig

2024-04-08 Thread Christoph Biedl
uploaded yet, will do in the next days). If you have the skills and the time, you could try to backport https://github.com/latchset/clevis/commit/bebb037d664185769c12cd061c2221c2d2bdb432 Christoph signature.asc Description: PGP signature

Bug#1068569: RM: nfs-ganesha-ceph [armel armhf i386] -- NBS; ceph dropped 32 bit support

2024-04-08 Thread Christoph Martin
Hi Sebastian, the packages are already removed from testing and unstable. Where do you see a problem? Regards Christoph Am 07.04.24 um 13:21 schrieb Sebastian Ramacher: Package: ftp.debian.org Severity: normal X-Debbugs-Cc: nfs-gane...@packages.debian.org, sramac...@debian.org User

Bug#1068373: RM: libzia/experimental -- ROM; Merged into tucnak

2024-04-04 Thread Christoph Berg
, but of course it only got removed from unstable. So, here I am again: Please remove libzia from experimental. The library is now part of the tucnak source since it doesn't get released (and used) independently. Thanks, Christoph

Bug#1064708: pygame: FTBFS: AssertionError: "No video mode" does not match "Parameter 'surface' is invalid"

2024-04-02 Thread Christoph Berg
Control: severity -1 serious Re: Peter Michael Green > > severity 1064708 important > Can you explain why you downgraded this bug? it looks rc to me > and is blocking the time_t transition. I think I mistakenly downgraded it along with some other "t64 nmu diff" bugs. Christoph

Bug#1067237: ngircd: missing ssl security patch in debian's ngircd package

2024-03-31 Thread Christoph Biedl
w to deal with this. Christoph signature.asc Description: PGP signature

Bug#1068139: miniflux: [L10N,DE] miniflux_2.1.1-1: german translation

2024-03-31 Thread Christoph Brinkhaus
Package: miniflux Version: miniflux 2.1.2-1 Severity: wishlist X-Debbugs-Cc: maytha8the...@gmail.com Dear Maintainer, please find attached the german translation of the miniflux_2.1.1-1 template. Thank you for taking care of the package! Kind regards, Christoph Brinkhaus # German translation

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Christoph Anton Mitterer
One more thing: Is anyone on the Debian side trying to figure out how far we've been practically affected? I mean let's assume we're "lucky", and the backdoor is only in 5.6.0/5.6.1... and that none of the adversary's earlier commits introduced any serious holes[0] which wouldn't be known yet.

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Christoph Anton Mitterer
Hey. Can we be confidently sure that going back to 5.4.5 is enough? At least the git tag for that seems to be still signed by the adversary: https://git.tukaani.org/?p=xz.git;a=tag;h=9e4835399118b98954f110f76af2a0d504d2f531 The last one, still from Lasse Collin seems to be 5.4.1:

Bug#1067838: Please provide a trivial working example

2024-03-27 Thread Christoph Biedl
file. According to ltrace, none of the RESOLV_WRAPPER_* variables are checked via getenv. Not a big surpise then: Setting RESOLV_WRAPPER_DEBUGLEVEL had no effect either. Using <https://github.com/figiel/hosts>, the above checks work except for the second one. However, this project is not in Debian

Bug#1067457: jose: CVE-2023-50967

2024-03-21 Thread Christoph Biedl
Control: forwarded 1067457 https://github.com/latchset/jose/issues/151 signature.asc Description: PGP signature

Bug#1066067: cl-plus-ssl: hardcoded libssl3 dependency

2024-03-21 Thread Christoph Berg
needs to be > updated. It actually doesn't hard-code the dependency but correctly extracts it from libssl-dev. But since we don't have arch:all binnmus, a new upload was needed anyway. Just did that. Once cl-plus-ssl is installed, please binnmu pgloader to have it pick up the changed dependency. Christoph

Bug#980150: RFA: cyrus-imspd -- Internet Message Support Protocol daemon

2024-03-21 Thread Christoph Berg
or the Internet Message Support > Protocol (imsp), providing central storage for addressbooks and application > config. This didn't have any takers in 3 years, and the package is now FTBFSing (#1066480) with C code so ancient it's a PITA to fix, so let's get it removed. Christoph

Bug#1067144: [3dprinter-general] Bug#1067144: uranium: missing depend on python3-all for autopkgtest

2024-03-21 Thread Christoph Berg
Re: Gregor Riepl > I pushed a simple patch to add the dependency, would be nice if you could > release it, @myon? Thanks in advance. On its way, thanks for the update! Christoph

Bug#1064697: flask-babelex: FTBFS: ImportError: cannot import name '_request_ctx_stack' from 'flask' (/usr/lib/python3/dist-packages/flask/__init__.py)

2024-03-21 Thread Christoph Berg
ah, let's just do that. Thanks for looking into the details! Christoph

Bug#1066980: Please include "notify-send" in package description

2024-03-16 Thread Christoph Berg
ng in the user's way. . This package contains the notify-send command line utility. Thanks, Christoph

Bug#1066850: don't hard-code the name of the shared library

2024-03-15 Thread Christoph Biedl
Control: tags 1066850 -moreinfo +pending Matthias Klose wrote... > On 14.03.24 21:38, Christoph Biedl wrote: > > Do you have an idea, an existing solution how to do that? > dep := $(shell dpkg-query '-f${Depends}' -W libmagic-dev | sed > 's/.*\(libmagic[a-z0-9]*\).*/\1/') > e

Bug#1066850: don't hard-code the name of the shared library

2024-03-14 Thread Christoph Biedl
s was the point to make python3-magic arch:any. So, is all this worth the efforts? FWIW, I maintain the libmagic package as well, so being lazy now will just hurt me later. Christoph signature.asc Description: PGP signature

Bug#1066850: don't hard-code the name of the shared library

2024-03-14 Thread Christoph Biedl
the next uplad. > and derive the name of the shared library package from the > libmagic-dev package. Are you still talking about the build dependency here? Then it's no issue as the -dev dependency will take care of that. Question: What is the justifcation for the bug severity? To me,

Bug#1036559: (no subject)

2024-03-13 Thread Hans-Christoph Steiner
control: fixed 1036559 3.4.0~a1-7

  1   2   3   4   5   6   7   8   9   10   >