Bug#991593: fixed in otrs2 6.0.32-6

2021-08-06 Thread Moritz Muehlenhoff
On Fri, Aug 06, 2021 at 08:08:45AM +0200, Salvatore Bonaccorso wrote: > Hi, > > On Thu, Aug 05, 2021 at 11:49:41AM +0200, Moritz Mühlenhoff wrote: > > Am Thu, Aug 05, 2021 at 09:19:14AM + schrieb Debian FTP Masters: > > > Source: otrs2 > > > Source-Version: 6.0.32-6 > > > Done: Patrick

Bug#991593: fixed in otrs2 6.0.32-6

2021-08-06 Thread Salvatore Bonaccorso
Hi, On Fri, Aug 06, 2021 at 09:11:12AM +0200, Moritz Muehlenhoff wrote: > On Fri, Aug 06, 2021 at 08:08:45AM +0200, Salvatore Bonaccorso wrote: > > Hi, > > > > On Thu, Aug 05, 2021 at 11:49:41AM +0200, Moritz Mühlenhoff wrote: > > > Am Thu, Aug 05, 2021 at 09:19:14AM + schrieb Debian FTP

Bug#991930: ifenslave: ifstate command does not exists

2021-08-06 Thread debian-bug-ifenslave
Package: ifenslave  Version: 2.12 Problem while trying to bring up bond0 or any bonding interface. ifup[933]: No iface stanza found for master bond0 The root cause is ifenslave shipped with a script, referring to ifstate command which is not present. Script:/etc/network/if-pre-up.d/ifenslave 

Bug#991811: unblock: libapache2-mod-auth-openidc/2.4.9-1

2021-08-06 Thread Salvatore Bonaccorso
HI Paul, On Fri, Aug 06, 2021 at 08:40:24AM +0200, Paul Gevers wrote: > Hi Christopher, > > On 02-08-2021 13:33, Christoph Martin wrote: > > Please unblock package libapache2-mod-auth-openidc > > > > currently the version 2.4.4.1-2 of libapache2-mod-auth-openidc is in > > testing/bullseye .

Bug#991729: With glibc 2.34, it seems more is broken

2021-08-06 Thread Shachar Shemesh
On 05/08/2021 22:47, Daniel Schepler wrote: On Mon, Aug 2, 2021 at 10:45 PM Shachar Shemesh wrote: Can you run fakeroot-ng with "-l" and attach the generated log file? Here's the log from the run where make fails. The expected happened: 3331985: Unknown syscall 435(NONE) 3331985: Unknown

Bug#991811: unblock: libapache2-mod-auth-openidc/2.4.9-1

2021-08-06 Thread Paul Gevers
Hi Christopher, On 02-08-2021 13:33, Christoph Martin wrote: > Please unblock package libapache2-mod-auth-openidc > > currently the version 2.4.4.1-2 of libapache2-mod-auth-openidc is in > testing/bullseye . Some days ago four CVE security bugs were published > which are fixed in version 2.4.9 .

Bug#991593: fixed in otrs2 6.0.32-6

2021-08-06 Thread Salvatore Bonaccorso
Hi, On Thu, Aug 05, 2021 at 11:49:41AM +0200, Moritz Mühlenhoff wrote: > Am Thu, Aug 05, 2021 at 09:19:14AM + schrieb Debian FTP Masters: > > Source: otrs2 > > Source-Version: 6.0.32-6 > > Done: Patrick Matthäi > > > > We believe that the bug you reported is fixed in the latest version of >

Bug#991920: Acknowledgement (please demote pkg-config to Recommends)

2021-08-06 Thread Dominik George
On Thu, Aug 05, 2021 at 10:21:30PM +0200, Michael Banck wrote: > I've run "dracut --no-kernel" in a minimal lxc container, once with > pkg-config and once without and then diffoscope'd the two generated > initrds. Most of what diffoscope complains about are timestamp > differences in directories

Bug#960304: snapshot.debian.org: Snapshot repo repeatedly cutting off connection, returning partial content

2021-08-06 Thread Julien Cristau
On Fri, Aug 06, 2021 at 05:08:40PM +0900, Mike Hommey wrote: > Package: snapshot.debian.org > Followup-For: Bug #960304 > > Dear Maintainer, > > We're hitting this problem regularly on Mozilla CI (from using dget), > and what is probably a variant of this bug with apt, which fails with, > for

Bug#924912: pristine-tar: Failed to reproduce original tarball python-django_1.11.20.orig.tar.gz

2021-08-06 Thread Roger Shimizu
should be caused by: - https://bugs.debian.org/897653 if you upgrade tar to buster version 1.30+dfsg-6 or later, it should be resolved. -- Roger Shimizu, GMT +9 Tokyo PGP/GPG: 4096R/6C6ACD6417B3ACB1

Bug#969611: node-setimmediate: broken symlinks in /usr/share/doc/node-setimmediate/mocha.{css,js}

2021-08-06 Thread Andreas Beckmann
Followup-For: Bug #969611 node-setimmediate has Suggests: libjs-mocha (>= 3), but that package no longer exists after stretch. A possible replacement is the virtual, versioned node-mocha (= 8.2.1) provided by mocha (8.2.1+ds1+~cs29.4.27-3) which ships /usr/share/nodejs/mocha/lib/mocha.js

Bug#991931: CVE-2021-32686 / AST-2021-009: pjproject/pjsip: crash when SSL socket destroyed during handshake

2021-08-06 Thread Bernhard Schmidt
Package: src:asterisk Severity: serious Tags: security upstream patch https://downloads.asterisk.org/pub/security/AST-2021-009.html Summary:pjproject/pjsip: crash when SSL socket destroyed during handshake Nature of Advisory: Denial of service Susceptibility: Remote

Bug#991933: mokutil: RISC-V build missing

2021-08-06 Thread Heinrich Schuchardt
Package: mokutil Version: 0.4.0-1 Severity: normal Tags: patch Usertags: origin-ubuntu impish ubuntu-patch Dear maintainer, building mokutil for RISC-V only requires debian/control to be adjusted. See Ubuntu package mokutil 0.4.0-1ubuntu1. U-Boot already supports booting via UEFI on RISC-V

Bug#991897: removal of the any/local-rtlddir-cross.diff patch broke cross builds

2021-08-06 Thread Aurelien Jarno
control: reassign -1 cross-toolchain-base-ports-46 control: tag -1 + patch control: tag -1 - moreinfo control: tag -1 - unreproducible On 2021-08-05 18:59, Aurelien Jarno wrote: > control: tag -1 + moreinfo > control: tag -1 + unreproducible > > On 2021-08-04 19:03, Matthias Klose wrote: > >

Bug#991939: libjs-bootstrap4: broken symlinks: /usr/share/javascript/bootstrap4/css/bootstrap*.css.map -> ../../../nodejs/bootstrap/dist/css/bootstrap*.css.map

2021-08-06 Thread Andreas Beckmann
Package: libjs-bootstrap4 Version: 4.5.2+dfsg1-7 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 0m13.9s ERROR: FAIL: Broken

Bug#991932: Please upgrade to new upstream

2021-08-06 Thread Petr Cech
Package: python3-icecream Version: 2.0.0-1 Severity: wishlist Hi, please package the newer upstream release 2.1.1. Thanks, Petr -- System Information: Debian Release: 11.0 APT prefers stable-updates Architecture: amd64 (x86_64) Foreign Architectures: i386 Versions of packages

Bug#991629: cloud.debian.org: Bullseye AWS AMI: cloud-init creates duplicate #includedir in /etc/sudoers

2021-08-06 Thread Chris Boot
On 06/08/2021 02:47, Ross Vandegrift wrote: Hi Chris, On Thu, Jul 29, 2021 at 10:24:22AM +0100, Chris Boot wrote: In the sudoers file there is a duplicate includedir statement; at the end of the file you will find the following contents: """ # See sudoers(5) for more information on "@include"

Bug#983108: Closing power-profiles-daemon ITP?

2021-08-06 Thread intrigeri
Hi, I see that power-profiles-daemon has been in experimental for a while? Is there any particular reason why we should not close this ITP? Thanks a lot for packaging this piece of software, can't wait to try it once GNOME 41 lands in sid with the corresponding GNOME Shell UI bits :)

Bug#990183: libopenscap8: libopenscap.so.8 is missing from libopenscap8 and is expected by scap-workbench

2021-08-06 Thread Hideki Yamane
Hi, I've restructured openscap pacakge to fix Bug#990183 and make it better, upload to https://salsa.debian.org/henrich/openscap I'll upload it to experimental with delay-10, if you want to cancel it, don't hestitate. -- Regards, Hideki Yamane henrich @ debian.org/iijmio-mail.jp

Bug#991934: ITP: rust-liboverdrop -- A simple Rust library to handle configuration fragments

2021-08-06 Thread clay stan
Package: wnpp Severity: wishlist Owner: clay stan X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: rust-liboverdrop Version : 0.0.2 Upstream Author : overdrop * URL : https://github.com/overdrop/liboverdrop-rs License : MIT or Apache-2.0

Bug#991831: unblock: mat2/0.12.1-3

2021-08-06 Thread Georg Faerber
Hi Paul, Thanks for your reply. On 21-08-06 08:32:20, Paul Gevers wrote: > It's too late for changes like this one. Is this due to mat2 being a key package? Besides, would this potentially accepted in 11.1? Cheers, Georg

Bug#991935: 4.4.1-2.3 not in Salsa git repo. upstream/4.4.1 tag also missing

2021-08-06 Thread Nicholas Brown
Package: isc-dhcp Version: 4.4.1-2.3 Severity: normal Report that 4.4.1-2.3 is missing from git: https://qa.debian.org/cgi-bin/vcswatch?package=isc-dhcp upstream/4.4.1 tag missing https://salsa.debian.org/dhcp-team/isc-dhcp/-/tags so gbp build will report an error trying to build master.

Bug#991811: unblock: libapache2-mod-auth-openidc/2.4.9-1

2021-08-06 Thread Christoph Martin
Hi Paul, hi Salvatore, Am 06.08.21 um 09:32 schrieb Salvatore Bonaccorso: >> >> It's *very* late in the freeze so I need an answer *real soon*. You >> didn't tell us how you tested the package, how upstream tested the >> changes and how you *judge* the changes between bullseye and sid. I >> can't

Bug#991941: linux: Don't use nouveau with Nvidia GeForce 8500 GT or alert in dmesg that firmware is needed

2021-08-06 Thread Laura Arjona Reina
Source: linux Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? I have installed Debian 11 (debian installer RC3) on a PC having a Nvidia GeForce 8500 GT as main graphics card. The graphicall

Bug#991940: unblock: munge/0.5.14-6

2021-08-06 Thread Gennaro Oliva
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package munge [ Reason ] * Cherry-pick upstream patch to allow to upgrade from buster to bullseye [ Impact ] Remove some minor tests to fix kfreebsd builds and a useless

Bug#960304: snapshot.debian.org: Snapshot repo repeatedly cutting off connection, returning partial content

2021-08-06 Thread Mike Hommey
Package: snapshot.debian.org Followup-For: Bug #960304 Dear Maintainer, We're hitting this problem regularly on Mozilla CI (from using dget), and what is probably a variant of this bug with apt, which fails with, for example: [task 2021-08-05T21:27:09.094Z] Err:187

Bug#991936: openssh-server: seccomp filter defaults to SIGSYS, could break any libc or kernel upgrade

2021-08-06 Thread Julian Andres Klode
Package: openssh-server Version: 1:8.4p1-5ubuntu2 Severity: serious X-Debbugs-Cc: j...@debian.org seccomp filters are currently setup to kill the process #define SECCOMP_FILTER_FAIL SECCOMP_RET_KILL /* Default deny */ BPF_STMT(BPF_RET+BPF_K, SECCOMP_FILTER_FAIL), this means

Bug#991937: python3-pdfminer: Recommends python3-crypto, which is no longer in Debian

2021-08-06 Thread Simon McVittie
Package: python3-pdfminer Version: 20200726-1 Severity: normal python3-crypto was removed from bullseye in January 2021, and from unstable in July 2021. The removal bug https://bugs.debian.org/979318 says it is no longer maintained upstream and has been superseded by pycryptodome. Note that

Bug#991938: libopenobex:

2021-08-06 Thread Chris Lamb
Source: libopenobex Version: 1.7.2-1 Severity: minor Tags: patch User: reproducible-bui...@lists.alioth.debian.org X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, It looks like libopenobex is missing an *optional* dependency on graphviz to generate a documentation, leading to a large

Bug#954093: desktop-base: Integration with KDE Plasma on Debian 11 no longer works

2021-08-06 Thread Laura Arjona Reina
Package: desktop-base Version: 11.0.3 Followup-For: Bug #954093 Dear Maintainer, I've just installed a PC with KDE Plasma desktop task using the Debian 11 installer RC3 and this bug is still present. My computer is all HomeWorld-themed except the desktop wallpaper (I got the "Shells" one). I

Bug#991948: RFP: virtualbox-completion -- Bash completion support for VirtualBox management utility

2021-08-06 Thread Eugene Kilachkoff
Package: wnpp Severity: wishlist X-Debbugs-Cc: ekilachk...@gmail.com * Package name: virtualbox-completion Version : 6.1.22 Upstream Author : Roman Dobosz * URL : https://github.com/gryf/vboxmanage-bash-completion * License : BSD-3-Clause Programming Lang:

Bug#991952: Acknowledgement (chardet test suite has problematic license)

2021-08-06 Thread Gernot Hillier
I also filed an upstream bug on this: https://github.com/chardet/chardet/issues/231

Bug#991949: xuxen-eu-spell: New upstream version 5.1

2021-08-06 Thread Dimitrij Mijoski
Source: xuxen-eu-spell Version: 0.5.20151110-5 Severity: normal Dear Maintainer, New uptream version is avaliable, see here http://xuxen.eus/eu/deskargatu . Direct link: http://xuxen.eus/static/hunspell/xuxen_5.1_hunspell.zip

Bug#991951: debian-installer: Text installer sporadically hangs when using 512 - 1024 MB of memory.

2021-08-06 Thread Witold Baryluk
Package: debian-installer Severity: important https://www.debian.org/releases/bullseye//amd64/ch03s04.en.html says this should be supported. But when using 512 MB of memory in text mode (which triggers low memory mode), or even 1024 MB of memory, makes it be stuck. Using multi-arch image for

Bug#991952: chardet test suite has problematic license

2021-08-06 Thread Gernot Hillier
Source: chardet Version: 4.0.0-1 During licensing checks of the "chardet" sources, we identified problematic files in tests/. In general, tests/README.txt states: [...] These test feeds were downloaded from random sites while I was developing the Universal Encoding Detector. Each feed is

Bug#991950: postfix.postinst fails if /e/resolv.conf contains `search .`

2021-08-06 Thread Paride Legovini
Source: postfix Version: postinst fails if /e/resolv.conf search domain starts with a "." Severity: normal X-Debbugs-Cc: par...@debian.org Dear Postfix maintainers, When the /etc/resolv.conf search domain considered by postfix.postinst to configure postfix as an "Internet site" (the default

Bug#991945: refind: debian netinst (bullseye): refind fails to install

2021-08-06 Thread Marc Leeman
Great catch! Shouldn't the script also take care of unmounting these > if it's the one who mounted them, though? (It makes the logic a bit > more complex, but seems like the "right" solution to me.) > > I've also added Rod explicitly to CC here, since this is really an > upstream rEFInd bug (and

Bug#991950: postfix.postinst fails if /e/resolv.conf contains `search .`

2021-08-06 Thread Paride Legovini
Control: tags -1 + patch I submitted this MP with a fix: https://salsa.debian.org/postfix-team/postfix-dev/-/merge_requests/12 Cheers! Paride

Bug#991953: golang-github-google-martian-dev: Package github.com/google/martian/v3

2021-08-06 Thread Peymaneh Nejad
Package: golang-github-google-martian-dev Version: 2.1.0+git20181219.d0b5ad3-3 Severity: normal Hi, I need to update another package[1] that requires github.com/google/martian/v3 I'll prepare a release on debian/experimental branch on salsa for a team upload to experimental so I can go on with

Bug#991945: refind: debian netinst (bullseye): refind fails to install

2021-08-06 Thread Tianon Gravi
On Fri, 6 Aug 2021 at 06:42, Marc Leeman wrote: > I am using refind with an netinst installer. Since bullseye this seems > broken because sysfs/efivarfs is no longer mounted by default in the > target and efibootmgr fails > > I've tested this patch on my side (simply trying to mount sys/efivarfs

Bug#991945: refind: debian netinst (bullseye): refind fails to install

2021-08-06 Thread Marc Leeman
Package: refind Version: 0.12.0-2~televic11+3 Severity: normal Dear Maintainer, I am using refind with an netinst installer. Since bullseye this seems broken because sysfs/efivarfs is no longer mounted by default in the target and efibootmgr fails I've tested this patch on my side (simply

Bug#991920: Acknowledgement (please demote pkg-config to Recommends)

2021-08-06 Thread Thomas Lange
> On Fri, 6 Aug 2021 12:34:13 +0200, Dominik George > said: > If Thomas consents, I would make the change in experimental as well > and we will see how it works out. I do not see any reason not to > demote pkg-config. Go for it. -- viele Grüße Thomas

Bug#688716: cron: optionally inherit PATH from parent process

2021-08-06 Thread Graham Inggs
Hi Maintainer This change was recently adopted in Ubuntu, along with the attached patch to update crontab(5) manpage to match the new behaviour. Regards Graham Description: Update crontab(5) manpage to match new behaviour Bug-Debian: https://bugs.debian.org/688716 Bug-Ubuntu:

Bug#991943: klibc: please consider including machine-readable copyright file

2021-08-06 Thread Andrej Shadura
Source: klibc Severity: wishlist Tags: patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, Please consider including the attached machine-readable copyright file. I tried to make it as precise as I can based on the information in the source and accompanying text files; improve it as you

Bug#991941: attaching dmesg and lspci output

2021-08-06 Thread Laura Arjona Reina
I'm attaching the dmesg and lspci output for the case they are useful. Kind regards -- Laura Arjona Reina https://wiki.debian.org/LauraArjona Sent with K-9 mail[0.00] Linux version 5.10.0-8-amd64 (debian-ker...@lists.debian.org) (gcc-10 (Debian 10.2.1-6) 10.2.1 20210110, GNU ld (GNU

Bug#991947: apt-setup: Consider adding $codename-updates configuration to /etc/apt/sources.list (if available even if yet $codename is testing)

2021-08-06 Thread Salvatore Bonaccorso
Source: apt-setup Version: 1:0.166 Severity: wishlist Tags: d-i X-Debbugs-Cc: car...@debian.org Dear Debian Install System Team, When installing bullseye with the current RC3 I noticed that while the debconf menu suggests (and has selected) to add release updates suites ($codename-updates) to

Bug#991942: golang-google-cloud-dev: Outdated package

2021-08-06 Thread Peymaneh Nejad
Package: golang-google-cloud-dev Version: 0.56.0-1 Severity: normal Hi, I am working on packaging github.com/smallstep/certificates which depends on v0.86 of this package. I would prepare an updated version for team upload to experimental so that I can go on with packaging. Please let me

Bug#991921: linux: Please enable CPUFREQ options for RPi 0/0w/1

2021-08-06 Thread Uwe Kleine-König
Hello, On Thu, Aug 05, 2021 at 05:26:09PM +, Diederik de Haas wrote: > At > https://salsa.debian.org/raspi-team/image-specs/-/issues/7#note_206349 > it was reported that CPU frequency scaling was enabled for armhf and > arm64, but not for armel. I (and others) have been able to confirm that.

Bug#954093: desktop-base: Integration with KDE Plasma on Debian 11 no longer works

2021-08-06 Thread Cyril Brulebois
Hi, Laura Arjona Reina (2021-08-06): > Package: desktop-base > Version: 11.0.3 > Followup-For: Bug #954093 > > Dear Maintainer, > > I've just installed a PC with KDE Plasma desktop task using the Debian > 11 installer RC3 and this bug is still present. > > My computer is all HomeWorld-themed

Bug#991946: cython: Much newer version available

2021-08-06 Thread Stephen Quinney
Source: cython Severity: wishlist X-Debbugs-Cc: step...@jadevine.org.uk Dear Maintainer, The current packaged version of Cython is 0.29.14 which was released in November 2019. Since then there have been 10 bug fix releases with the latest being 0.29.24 which came out in July 2021. I would so

Bug#984928: Acknowledgement (slurmctld: fails to start on reboot)

2021-08-06 Thread David Bremner
David Bremner writes: > As a workaround, I noticed that setting the main ethernet interface to > "auto" instead of "allow-hotplug" seems to fix the problem. By way of > confirmation, on a different (virtual) machine changing the "auto" to > "allow-hotplog" on the main ethernet interface causes

Bug#991921: linux: Please enable CPUFREQ options for RPi 0/0w/1

2021-08-06 Thread Diederik de Haas
Hi, On vrijdag 6 augustus 2021 15:14:26 CEST Uwe Kleine-König wrote: > On Thu, Aug 05, 2021 at 05:26:09PM +, Diederik de Haas wrote: > > https://salsa.debian.org/raspi-team/image-specs/-/issues/7#note_206349 > > > > So I build my own kernel with the following patch: > >

Bug#991917: python3-wikitrans: Wiki 2 html conversion errors

2021-08-06 Thread Sergey Poznyakoff
Hi Erich, Thanks for your report. > 1. This upstream patch should be included in the package: > > https://git.gnu.org.ua/wikitrans.git/commit/?id=c785e3ad767b12a13ae75a3513ec88a4d1144210 Sure. It will be included when new version is released. > 2. A wrong variable name is used here: > File

Bug#991831: unblock: mat2/0.12.1-3

2021-08-06 Thread Paul Gevers
Hi Georg, On 06-08-2021 11:07, Georg Faerber wrote: > > On 21-08-06 08:32:20, Paul Gevers wrote: >> It's too late for changes like this one. > > Is this due to mat2 being a key package? That's part of the equation, yes. > Besides, would this potentially accepted in 11.1? I won't speak for

Bug#991831: unblock: mat2/0.12.1-3

2021-08-06 Thread Georg Faerber
Hi Paul, On 21-08-06 14:07:00, Paul Gevers wrote: > That's part of the equation, yes. Thanks for clarifying. > I won't speak for SRM, but I would expect so. Thanks! > Tip: reportbug from bullseye has a better template for unblock and p-u > bugs than buster. Please be verbose on impact, tests

Bug#991944: texlive-binaries: man pages: typo in etex, pdftex, aleph and mf pages

2021-08-06 Thread Antanas Vaitkus
Package: texlive-binaries Version: 2018.20181218.49446-1 Severity: minor Dear Maintainer, Description of the '--output-directory' option in the man pages of etex, pdftex, aleph and mf contains: <...> in directory first, the along the normal <...> instead of <...> in directory first, then

Bug#991969: D-I: news for Bullseye: help with firmware installation

2021-08-06 Thread Holger Wansing
Package: release-notes I would like to add a paragraph to the release-notes, describing a bit the new "install-firmware" mechanism via modalias, with a link to the new doc in the installation-guide, for those who experience problems. Please find a patch attached. (Additionally, I updated some

Bug#951902: python3

2021-08-06 Thread Thorsten Alteholz
Just for the record, there is an upstream issue #1794 [1] related to this. [1] https://github.com/svaarala/duktape/issues/1794 [2] https://github.com/svaarala/duktape/pull/2375

Bug#991971: [Lynx-dev] bug in Lynx' SSL certificate validation -> leaks password in clear text via SNI (under some circumstances)

2021-08-06 Thread Axel Beckert
Hi, On Fri, Aug 06, 2021 at 05:14:32PM +, Thorsten Glaser wrote in https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg0.html: > this affects both OpenSSL and Debian’s nonGNUtls builds: > > lynx https://user:pass@host/ > > … will lead to… > > SSL >

Bug#991971: [Lynx-dev] bug in Lynx' SSL certificate validation -> leaks password in clear text via SNI (under some circumstances)

2021-08-06 Thread Thorsten Glaser
Axel Beckert dixit: >This is more severe than it initially looked like: Due to TLS Server >Name Indication (SNI) the hostname as parsed by Lynx (i.e with >"user:pass@" included) is sent in _clear_ text over the wire even I *ALWAYS* SAID SNI IS A SHIT THING ONLY USED AS BAD EXCUSE FOR NAT BY

Bug#991971: SNI is a security vulnerability all by itself (was Re: [Lynx-dev] bug in Lynx' SSL certificate validation -> leaks password in clear text via SNI (under some circumstances))

2021-08-06 Thread Thorsten Glaser
>Axel Beckert dixit: >>IMHO this nevertheless needs a CVE-ID. I wonder… perhaps the use of SNI, both in the TLSv1.3 standard and in some TLSv1.2 implementations, should receive CVEs as well? It certainly ought to be disabled by default. Perhaps add some environment variable to enable SNI in the

Bug#991668: A learn-emacs-in-moments doc

2021-08-06 Thread Nicholas D Steeves
Hi Karl, "Karl O. Pinc" writes: > > As long a your messing about with the documentation > attached is a 1 page (or 2 if you want to keep reading) > doc on getting started with emacs. If you feel it would > be helpful to include (somewhere), please do. > > I'll license it in the public domain,

Bug#991971: lynx: SSL certificate validation fails with URLs containing user name or user name and password, i.e. https://user:password@host/ and https://user@host/

2021-08-06 Thread Axel Beckert
Package: lynx Version: 2.9.0dev.8-1 Severity: important Tags: upstream, confirmed Control: forwarded -1 https://lists.nongnu.org/archive/html/lynx-dev/2021-08/msg0.html Control: found -1 2.8.9dev1-2+deb8u1 Control: found -1 2.8.9dev11-1 Control: found -1 2.8.9rel.1-3 Control: found -1

Bug#954093: desktop-base: Integration with KDE plasma on debian testing no longer works

2021-08-06 Thread Laura Arjona Reina
Hello again I formerly said that my desktop was all Homeworld-themed except the wallpaper, but I just found out that the lockscreen also had the "Shells" background instead of the proposed Homeworld image for lockscreen. I'm not sure if Plymouth is also well integrated or not because this

Bug#991972: backports.org invalid certificate

2021-08-06 Thread Xan Charbonnet
Package: www.debian.org Some muscle memory from a long time ago kicked in, and I browsed to backports.org instead of to backports.debian.org. backports.org now seems to serve the Debian homepage, and in the process triggers the browser's invalid certificate error, because the certificate is

Bug#991973: dbconfig-common: missing Breaks: pdns-backend-sqlite

2021-08-06 Thread Andreas Beckmann
Package: dbconfig-common Version: 2.0.19 Severity: important User: debian...@lists.debian.org Usertags: piuparts Control: affects -1 + pdns-backend-sqlite Hi, during a test with piuparts I noticed your package causes pdns-backend-sqlite (which may still be around from wheezy which was the last

Bug#991954: /usr/bin/openstack: no man page. Please add python-openstackclient-doc as a Recommends to python3-openstackclient

2021-08-06 Thread Louis-Philippe Véronneau
Package: python3-openstackclient Version: 5.4.0-4 Severity: normal Dear maintainers, When installing python3-openstackclient, the python-openstackclient-doc package is not installed. This results in /usr/bin/openstack not having a man page by default and isn't great UX. Would it be possible to

Bug#991957: /usr/bin/linux.uml: Checking PROT_EXEC mmap in /dev/shm...Operation not permitted

2021-08-06 Thread Ian Jackson
Package: user-mode-linux Version: 5.10um3 Severity: normal File: /usr/bin/linux.uml Observed behaviour: $ linux.uml Core dump limits : soft - 0 hard - NONE Checking that ptrace can change system call numbers...OK Checking syscall emulation patch for ptrace...OK Checking advanced

Bug#991960: /usr/bin/psusan: psusan example ends up with . on PATH due to #991959

2021-08-06 Thread Ian Jackson
Package: putty-tools Version: 0.75-3 Severity: normal File: /usr/bin/psusan psusan(1) suggests this: And the setup script uml-psusan.sh might look like this: #!/bin/bash # Set up vital pseudo-filesystems mount -t proc none /proc mount -t devpts none /dev/pts

Bug#991961: golang-1.15: CVE-2021-36221

2021-08-06 Thread Salvatore Bonaccorso
Source: golang-1.15 Version: 1.15.9-6 Severity: important Tags: security upstream Forwarded: https://github.com/golang/go/issues/46866 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for golang-1.15. CVE-2021-36221[0]: | net/http: panic due

Bug#987277: closing 991705

2021-08-06 Thread Salvatore Bonaccorso
Control: reopen 991705 Control: retitle 991705 exiv2: CVE-2021-29457 Control: found 991705 0.27.3-3 Control: found 991705 0.25-4 Control: forwarded 991705 https://github.com/Exiv2/exiv2/issues/1529 Control: retitle 987277 CVE-2021-29458 Control: forwarded 987277

Bug#991958: /usr/bin/linux.uml: consoles do not work if they are read for reading at startup

2021-08-06 Thread Ian Jackson
Control: found -1 5.10um3 I repro'd this on sid, but I ran reportbug in my buster environment. I forgot to change the version in the report. -- Ian JacksonThese opinions are my own. Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk, that is a private address which

Bug#991956: /usr/bin/linux.uml: Interactive use leaves invoking host terminal messed up

2021-08-06 Thread Ian Jackson
Package: user-mode-linux Version: 5.10um3 Severity: minor File: /usr/bin/linux.uml Observed behaviour: (build)root@zealot:/home/ian# stty -a; bwrap --dev-bind / / --tmpfs /dev/shm linux.uml init=/bin/date; stty -a speed 38400 baud; rows 90; columns 127; line = 0; intr = ^C; quit = ^\; erase =

Bug#991958: /usr/bin/linux.uml: consoles do not work if they are read for reading at startup

2021-08-06 Thread Ian Jackson
Package: user-mode-linux Version: 4.19-1um-1+deb10u1+b1 Severity: normal File: /usr/bin/linux.uml Tags: upstream CCing putty@p.d.o because this makes the user-mode-linux example in the psusan manpage not work. Steps to reproduce: Put the attached scripts "psusan-uml" and "psusan-uml-inside"

Bug#991959: /bin/bash: Built-in default path contains cwd

2021-08-06 Thread Ian Jackson
Package: bash Version: 5.1-3 Severity: important File: /bin/bash Tags: security Observed behaviour: $ env - bash -c 'echo $PATH' /usr/local/bin:/usr/local/sbin:/usr/bin:/usr/sbin:/bin:/sbin:. $ Expected behaviour: $ env - bash -c 'echo $PATH'

Bug#991958: /usr/bin/linux.uml: consoles do not work if they are read for reading at startup

2021-08-06 Thread Ian Jackson
Control: title -1 /usr/bin/linux.uml: consoles do not work if they are ready for reading at startup -- Ian JacksonThese opinions are my own. Pronouns: they/he. If I emailed you from @fyvzl.net or @evade.org.uk, that is a private address which bypasses my fierce spamfilter.

Bug#991965: gpac: CVE-2021-36584

2021-08-06 Thread Salvatore Bonaccorso
Source: gpac Version: 1.0.1+dfsg1-4 Severity: important Tags: security upstream Forwarded: https://github.com/gpac/gpac/issues/1842 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for gpac. CVE-2021-36584[0]: | An issue was discovered in GPAC

Bug#991955: lintian: Check for incorrect Maintainer/Uploader fields for known packaging teams

2021-08-06 Thread Louis-Philippe Véronneau
Package: lintian Version: 2.104.0 Severity: wishlist Dear maintainers, There is currently code in lib/Lintian/Check/Fields/Maintainer/Team.pm to check if a team-maintained package ends up in the wrong team. It would be nice if it were possible to issue another tag when a team-maintained package

Bug#991962: src: prefix should work also with experimental source only

2021-08-06 Thread Patrice Duroux
Package: reportbug Version: 7.10.3 Severity: wishlist Dear Maintainer, * What led up to the situation? $ reportbug src:gtk4 * What exactly did you do (or not do) that was effective (or ineffective)? I would like to report a «bug» that affect both libgtk-4-bin and libgtk-4-1

Bug#991963: pinentry-gnome3: hitting ENTER not equal to clicking "OK" icon

2021-08-06 Thread Per Gunnarsson
Package: pinentry-gnome3 Version: 1.1.0-4 Severity: wishlist Tags: newcomer Dear Maintainer, Hitting ENTER not with equal result as clicking "OK" icon when using for example gpg may cause unnecessary (?) paranoia -- System Information: Debian Release: 11.0 APT prefers testing APT policy:

Bug#991964: libgtk-4-1: the cause of apt-file search /usr/share/doc/@SHARED_PKG@

2021-08-06 Thread Patrice Duroux
Package: libgtk-4-1 Version: 4.3.1+ds-2 Severity: minor Dear Maintainer, I do not know if it is a consequence to solve #985418, but with this update I got the following on my system: $ apt-file search /usr/share/doc/@SHARED_PKG@ libgtk-4-1: /usr/share/doc/@SHARED_PKG@/@NEWS@ libgtk-4-1:

Bug#991959: /bin/bash: Built-in default path contains cwd

2021-08-06 Thread Salvatore Bonaccorso
Control: forcemerge 781367 991959 Hi Ian, On Fri, Aug 06, 2021 at 06:39:21PM +0100, Ian Jackson wrote: > Package: bash > Version: 5.1-3 > Severity: important > File: /bin/bash > Tags: security > > Observed behaviour: > > $ env - bash -c 'echo $PATH' >

Bug#991966: hunspell-an: Change upstream to libreoffice-dictionaries

2021-08-06 Thread Dimitrij Mijoski
Package: hunspell-an Version: 0.2-4 Severity: normal The current package shows a Firefox extension as Homepage (and probably upstream). This is not a very good upstream. The Aragonese dictionary is unmaintained (no updates since 2011) and it has no real upstream. It would be best to use

Bug#991968: firmware-brcm80211: security updates for wifi FragAttacks

2021-08-06 Thread Andres Salomon
Package: firmware-brcm80211 Version: 20210315-3 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team A whole bunch of wifi (protocol-level) security flaws were published here: https://www.fragattacks.com/ Cypress (AKA Infineon), who maintains some of the broadcom firmware

Bug#991730: libapache2-mod-auth-mellon: CVE-2021-3639: open redirect vulnerability

2021-08-06 Thread Thijs Kinkhorst
Hi Salvatore, > CVE-2021-3639[0]: > | Prevent redirect to URLs that begin with '///' I have a fixed package prepared and tested for sid but can only upload this next week when I return from holiday. I consider this (open redirect in general) a minor issue so I don't think it's needed to

Bug#991970: piuparts: ftbfs with golang-1.16

2021-08-06 Thread Brian Murray
Package: piuparts Version: 1.1.4 Severity: important User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu impish Dear Maintainer, The attached patch will fix a FTBFS with golang-1.16. This bug report was also filed in Ubuntu and can be found at http://launchpad.net/bugs/1939171 The

Bug#991460: vcmi: aborts when hovering over campaign selection figures

2021-08-06 Thread Johannes Schauer Marin Rodrigues
Control: tag -1 + patch Hi, Quoting fulvio ciriaco (2021-07-24 17:24:37) > steps to reproduce: > 1. select new -> campaign > 2. move the mouse to select the campaign > vcmi aborts immediately with the following message: > > Initializing VCMI_Lib: 313 ms > Screen handler: 8 ms > Main graphics:

Bug#991951: debian-installer: Text installer sporadically hangs when using 512 - 1024 MB of memory.

2021-08-06 Thread Samuel Thibault
Control: Tags -1 + unreproducible Hello, Witold Baryluk, le ven. 06 août 2021 16:29:50 +0200, a ecrit: > https://www.debian.org/releases/bullseye//amd64/ch03s04.en.html says this > should be supported. Yes, that should be working, and does work in my tests. > Using multi-arch image for

Bug#991961: golang-1.15: CVE-2021-36221

2021-08-06 Thread Paul Gevers
Hi Shengjing, On 06-08-2021 22:01, Shengjing Zhu wrote: > Should we fix it before the bullseye release? No, at least not in 11.0. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#991970: piuparts: ftbfs with golang-1.16

2021-08-06 Thread Brian Murray
I also tested building the patch with golang-1.15 and it also succeeded. -- Brian Murray

Bug#991967: linux-src 4.19.194-3 breaks Xen Dom0 powerdown and reboot

2021-08-06 Thread Elliott Mitchell
Package: src:linux Version: 4.19.194-3 Control: affects -1 src:xen SSIA. Previous versions of 4.19 had no issues (4.19.181-1 according to notes), but this cropped up with 4.19.194-3 (-1 and -2 weren't tested). When a Xen domain 0 tries to reboot or powerdown the computer, it hangs with the

Bug#991961: golang-1.15: CVE-2021-36221

2021-08-06 Thread Shengjing Zhu
Hi, On Sat, Aug 7, 2021 at 1:51 AM Salvatore Bonaccorso wrote: > > Source: golang-1.15 > Version: 1.15.9-6 > Severity: important > Tags: security upstream > Forwarded: https://github.com/golang/go/issues/46866 > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > Hi, > > The following

Bug#991908: popcon-upload: fails with https SUBMITURLS: Unable to parse url (unable to submit report)

2021-08-06 Thread Bill Allombert
On Thu, Aug 05, 2021 at 01:42:03AM +0200, Thorsten Glaser wrote: > Package: popularity-contest > Version: 1.71 > Severity: normal > X-Debbugs-Cc: t...@mirbsd.de > > When SUBMITURLS has an https URL (or one not with http:// anyway, > see /usr/share/popularity-contest/popcon-upload line 38 for why,

Bug#991974: unblock: twitter-bootstrap4/4.5.2+dfsg1-8

2021-08-06 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: 991...@bugs.debian.org Please unblock package twitter-bootstrap4 [ Reason ] 4.5.2+dfsg1-7 changes missed some .map files (scss-to-css). This version reinstall them (RC bug

Bug#991969: D-I: news for Bullseye: help with firmware installation

2021-08-06 Thread Paul Gevers
Hi, On 06-08-2021 21:52, Holger Wansing wrote: > I would like to add a paragraph to the release-notes, describing a bit the > new "install-firmware" mechanism via modalias, with a link to the new doc > in the installation-guide, for those who experience problems. > > Please find a patch

Bug#991975: unblock: node-setimmediate/1.0.5-6

2021-08-06 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: 969...@bugs.debian.org Please unblock package node-setimmediate [ Reason ] node-setimmediate is RC-buggy (#969611): * broken symlinks in node-setimmediate documentation *