Bug#1056752: zfs-linux: CVE-2023-49298

2023-11-25 Thread Salvatore Bonaccorso
Source: zfs-linux Version: 2.1.13-1 Severity: important Tags: security upstream Forwarded: https://github.com/openzfs/zfs/issues/15526 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for zfs-linux. CVE-2023-49298[0]: | OpenZFS through 2.1.13 a

Bug#1056754: bouncycastle: CVE-2023-33202

2023-11-25 Thread Salvatore Bonaccorso
Source: bouncycastle Version: 1.72-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for bouncycastle. CVE-2023-33202[0]: | Bouncy Castle for Java before 1.73 contains a potential Denial of | Service

Bug#1056753: RFS: nihstro/0-20231121-1 [ITP] -- 3DS shader tools - development headers

2023-11-25 Thread David James
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "nihstro": * Package name : nihstro Version : 0-20231121-1 Upstream contact : https://neobrain.github.io/ * URL : https://github.com/neobrain/nihstro/tree/f

Bug#1056697: 12.2 Installation Report, Complete Failure of Network

2023-11-25 Thread Cyril Brulebois
David Hillman (2023-11-25): > Thanks Cyril.  This system is running Debian 12, so there is no > /var/log/syslog.  As I mentioned in the original report, I found nothing > apparently related in the Journal. I'm confused. You filed an installation report regarding a failure to recognize network car

Bug#1056697: 12.2 Installation Report, Complete Failure of Network

2023-11-25 Thread Pascal Hambourg
On 25/11/2023 at 22:29, David Hillman wrote: On 11/25/23 01:37, Cyril Brulebois wrote: Extracting /var/log/syslog would be useful to understand what's going on there. (...) Thanks Cyril.  This system is running Debian 12, so there is no /var/log/syslog. Cyril meant the installer syslog, whic

Bug#1056755: derby: CVE-2022-46337

2023-11-25 Thread Salvatore Bonaccorso
Source: derby Version: 10.14.2.0-2 Severity: important Tags: security upstream Forwarded: https://issues.apache.org/jira/browse/DERBY-7147 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for derby. CVE-2022-46337[0]: | A cleverly devised usern

Bug#1056756: RM: haskell-aeson-compat -- ROM; deprecated

2023-11-25 Thread Ilias Tsitsimpis
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: haskell-aeson-com...@packages.debian.org Control: affects -1 + src:haskell-aeson-compat Please remove haskell-aeson-compat from Debian. * It has no rev dependencies * The current v

Bug#1056757: ITP: solanum -- simple pomodoro time tracking app for GNOME

2023-11-25 Thread Jeremy Bícha
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org, debian-gtk-gn...@lists.debian.org Control: affects -1 src:solanum Owner: jeremy.bi...@canonical.com Package Name: solanum Version: 5.0.0 Upstream Author: Christopher Davis License: GPL-3+ Programming Lang: Rust Descript

Bug#1056758: Removal notice: obsolete

2023-11-25 Thread Ilias Tsitsimpis
Source: haskell-reform-hsp Version: 0.2.7.2-2 Severity: serious I intend to remove this package: * It has no rev dependencies * The current version FTBFS * Seems unmaintained; Last upload more than 3 years ago * It's not part of the latest Stackage LTS If you believe we should keep this

Bug#1056759: python3.10: Remove references to obsolete dpkg avr32 arch

2023-11-25 Thread Guillem Jover
Source: python3.10 Source-Version: 3.10.11-1 Severity: important Tags: patch Hi! Support for this arch got removed from in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architecture. Attached a patch

Bug#1056760: python3.11: Remove references to obsolete dpkg avr32 arch

2023-11-25 Thread Guillem Jover
Source: python3.11 Source-Version: 3.11.6-3 Severity: important Tags: patch Hi! Support for this arch got removed from in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architecture. Attached a patch t

Bug#1056761: python3.12: Remove references to obsolete dpkg avr32 arch

2023-11-25 Thread Guillem Jover
Source: python3.12 Source-Version: 3.12.0-5 Severity: important Tags: patch Hi! Support for this arch got removed from in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architecture. Attached a patch t

Bug#1053700: xarray test failure on s390x

2023-11-25 Thread Rebecca N. Palmer
This fix worked but the new upstream version added another similar issue, so s390x failed again. I have pushed a fix for this, and enabled allow-stderr to fix armel (error output from an already-xfailed test). I don't know what's causing the hang on arm64, so please do _not_ upload this just

Bug#1056762: RFS: srcpd/2.1.6-1 [ITP] -- SRCP server daemon to control digital model railroads

2023-11-25 Thread Hilmar Preusse
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "srcpd": * Package name : srcpd Version : 2.1.6-1 Upstream contact : Guido Scholz * URL : https://srcpd.sourceforge.net/srcpd/index.html * License

Bug#1056763: gdb: Remove references to obsolete dpkg m32r arch

2023-11-25 Thread Guillem Jover
Source: gdb Source-Version: 13.2-1 Severity: important Tags: patch Hi! Support for this arch got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architecture. Attached an untested patch that

Bug#1056764: grub-efi-amd64: can't boot with GRUB 2.12~rc1-12

2023-11-25 Thread Nicolas Haller
Package: grub-efi-amd64 Version: 2.06-13 Severity: critical Justification: breaks the whole system Dear Maintainer, My old laptop (Lenovo 11e) runs Sid and all was right before I updated it the other day (I don't do that very often). After that upgrade, GRUB wasn't able to load any kernel with th

Bug#1050547: Similar stacktrace for this issue.

2023-11-25 Thread Mark Bryars
I've not been able to start gdm3 for quite a while now. I've tried upgrading to the latest nvidia driver in experimental (535.43.02-1) , and WaylandEnable=false in /etc/gdm3/daemon.conf Swapping to the nouveau driver didn't seem to fix it, but then I removed the WaylandEnable=false and it started

Bug#1056757: ITP: solanum -- simple pomodoro time tracking app for GNOME

2023-11-25 Thread David Bremner
Jeremy Bícha writes: > > Package Name: solanum > Version: 5.0.0 > Upstream Author: Christopher Davis > License: GPL-3+ > Programming Lang: Rust > > Description: simple pomodoro time tracking app for GNOME > Solanum is a time tracking app using the pomodoro technique. > Work in four sessions, wit

Bug#1056757: ITP: solanum -- simple pomodoro time tracking app for GNOME

2023-11-25 Thread Jeremy Bícha
On Sat, Nov 25, 2023 at 5:51 PM David Bremner wrote: > > Jeremy Bícha writes: > > > > Package Name: solanum > > Version: 5.0.0 > > Upstream Author: Christopher Davis > > License: GPL-3+ > > Programming Lang: Rust > > > > Description: simple pomodoro time tracking app for GNOME > > Solanum is a t

Bug#1042845: libembperl-perl: FTBFS with Perl 5.38: test failures

2023-11-25 Thread gregor herrmann
On Tue, 01 Aug 2023 22:41:12 +0200, Axel Beckert wrote: > > I assume the diagnostics have changed again and it's just the tests that > > need adjusting, but I haven't checked properly. > Will look into it, but may take a while. Now would be a good time :) As the perl 5.38 transition is immanent,

Bug#1056765: gcc-9: Remove references to obsolete dpkg m32r and tilegx arches

2023-11-25 Thread Guillem Jover
Source: gcc-9 Source-Version: 9.5.0-4 Severity: important Tags: patch Hi! Support for these arches got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architectures. Attached an untested patc

Bug#1056766: gcc-10: Remove references to obsolete dpkg m32r and tilegx arches

2023-11-25 Thread Guillem Jover
Source: gcc-10 Source-Version: 10.5.0-2 Severity: important Tags: patch Hi! Support for these arches got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architectures. Attached an untested pa

Bug#1056767: gcc-11: Remove references to obsolete dpkg m32r and tilegx arches

2023-11-25 Thread Guillem Jover
Source: gcc-11 Source-Version: 11.4.0-5 Severity: important Tags: patch Hi! Support for these arches got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architectures. Attached an untested pa

Bug#1056768: gcc-12: Remove references to obsolete dpkg m32r and tilegx arches

2023-11-25 Thread Guillem Jover
Source: gcc-12 Source-Version: 12.3.0-11 Severity: important Tags: patch Hi! Support for these arches got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architectures. Attached an untested p

Bug#1056769: gcc-13: Remove references to obsolete dpkg m32r and tilegx arches

2023-11-25 Thread Guillem Jover
Source: gcc-13 Source-Version: 13.2.0-7 Severity: important Tags: patch Hi! Support for these arches got removed in dpkg 1.22.0, which means that once the host running dak gets its dpkg upgraded to that version it might start being unhappy about the unknown architectures. Attached an untested pa

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Paul Wise
On Sat, 25 Nov 2023 18:56:03 +0100 Christoph Anton Mitterer wrote: > The most recent upgrade forces people to use > update-smart-drivedb by doing it already in the postinst and not leaving it > up to the user whether he wants to use such a tool. > > Security-wise this is really a bad idea. > > D

Bug#1056770: braillefont: Description in debian/control has a new line in the middle of a sentence

2023-11-25 Thread Carles Pina i Estany
Package: braillefont Version: 1.0-6 Severity: minor Dear Maintainer, Doing: apt show braillentfont It shows: - Description: Prints a bitmapped version of a text using Unicode Braille symbols braillefont runs interactively on the console - one can enter a (short) text, that will be converte

Bug#1056771: braillefont command line options

2023-11-25 Thread Carles Pina i Estany
Package: braillefont Version: 1.0-6 Severity: wishlist Tags: upstream Dear Maintainer, With "braillefont --help" I expected to see some help, but it just waits for the input text. Related: "braillefont /etc/hosts" (or, just a file): I expected to read the file and print it but just waits for the

Bug#1056772: apt-listchanges: [INTL:pt_BR] Brazilian Portuguese translation

2023-11-25 Thread Carlos Henrique Lima Melara
Package: apt-listchanges Version: 3.27 Severity: wishlist Tags: l10n patch X-Debbugs-Cc: charlesmel...@riseup.net Hi, Please, find attached the updated Brazilian Portuguese translation. It is UTF-8 encoded, tested with msgfmt. Best regards, Charles # apt-listchanges Brazilian Portuguese translat

Bug#1056773: ftp.debian.org: Hash mismatch of files in FTP master server in two weeks

2023-11-25 Thread Takahide Nojima
Package: ftp.debian.org Severity: important X-Debbugs-Cc: nozzy123no...@gmail.com Dear ftp-master, I have encountered a problem with apt reporting a hash mismatch in two weeks, - here - Error: http://deb.debian.org/debian sid/contrib DEP-11 48x48 Icons Hash Sum mis

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Dmitry Smirnov
On Sunday, 26 November 2023 4:56:03 AM AEDT Christoph Anton Mitterer wrote: > The most recent upgrade forces people to use > update-smart-drivedb by doing it already in the postinst and not leaving it > up to the user whether he wants to use such a tool. > > Security-wise this is really a bad idea

Bug#932617: fixed in fwupd 1.9.9-2

2023-11-25 Thread Paul Wise
Control: reopen -1 On Sat, 2023-11-25 at 14:40 +, Mario Limonciello wrote: >    * Remove extra confffiles (Closes: #1040350) This didn't work because the wrong version number was used, it should be the version number of the upload you added the removal postinst in, not the version that dropp

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Christoph Anton Mitterer
Control: severity -1 normal Control: tags - security Hey. On Sun, 2023-11-26 at 12:23 +1100, Dmitry Smirnov wrote: > I think you misunderstood that invocation of `update-smart-drivedb` > in postinst is an equivalent of > > ``` > cp -f /usr/share/smartmontools/drivedb.h  > /var/lib/smartmontool

Bug#1056763: gdb: Remove references to obsolete dpkg m32r arch

2023-11-25 Thread Héctor Orón Martínez
Hello Guillem, Thanks for the patch, however, I think we can keep support for this architecture in the multiarch package, therefore drop the snippet below from your patch. diff --git a/debian/rules b/debian/rules index 27b3f9d0e1b..1c0a55fa447 100755 --- a/debian/rules +++ b/debian/rules @@ -19

Bug#1053950: openttd: diff for NMU version 13.4-0.1

2023-11-25 Thread Maytham Alsudany
Hi Matthijs, On Sat, 2023-11-25 at 18:00 +0100, Matthijs Kooijman wrote: > > I'll go through my normal git-based workflow rather than using your NMU > though, nmudiff (from devscripts) did that gigantic diff, but I've followed your workflow in my fork of the repo at [1], if you want to just copy

Bug#1056774: Blank space on copyright page

2023-11-25 Thread Dan Jacobson
Package: viking In /usr/share/doc/viking/copyright it says It was downloaded from and there is a blank space.

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Paul Wise
On Sun, 2023-11-26 at 02:39 +0100, Christoph Anton Mitterer wrote: > Nevertheless, do you think it would possible to adapt it to check > whether update-smart-drivedb is executable and if not fall back to the > old code? This seems reasonable to me. I would also suggest using --quiet in the posti

Bug#1056763: gdb: Remove references to obsolete dpkg m32r arch

2023-11-25 Thread Guillem Jover
Hi! On Sun, 2023-11-26 at 02:43:34 +0100, Héctor Orón Martínez wrote: > Thanks for the patch, however, I think we can keep support for this > architecture in the multiarch package, therefore drop the snippet > below from your patch. > diff --git a/debian/rules b/debian/rules > index 27b3f9d0e1b

Bug#1056319: RFP: avis-imgv -- Fast and Configurable Rust Image Viewer

2023-11-25 Thread Maytham Alsudany
Control: owner -1 maytha8the...@gmail.com Control: retitle -1 ITP: avis-imgv -- Fast and Configurable Rust Image Viewer Hi, I'm happy to package avis-imgv, it looks like a very useful piece of software. I've let the upstream maintainer know that this RFP exists, and that they should publish thei

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Paul Wise
On Sun, 2023-11-26 at 12:23 +1100, Dmitry Smirnov wrote: > On Sunday, 26 November 2023 4:56:03 AM AEDT Christoph Anton Mitterer wrote: > > Even if the downloader tool does everything right (which is actually quite > > difficult if one assumes things like replay or blocking attacks), there's > > sti

Bug#1056775: debian-archive-keyring: trusted.gpg.d asc fragments not minimal

2023-11-25 Thread Dimitri John Ledkov
Package: debian-archive-keyring Version: 2021.1.1ubuntu2 Severity: wishlist Dear Maintainer, In a sid chroot, # apt-key export 2>/dev/null | wc 11511158 74594 # export GNUPGHOME=$(mktemp -d) # apt-key export 2>/dev/null | gpg --import &>/dev/null # gpg --export --armor --export-options

Bug#1056776: RFS: iotop-c/1.25-1~bpo12+1 -- simple top-like I/O monitor (implemented in C)

2023-11-25 Thread Boian Bonev
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "iotop-c": * Package name : iotop-c Version : 1.25-1~bpo12+1 Upstream contact : Boian Bonev * URL : https://github.com/Tomas-M/iotop * License : GPL

Bug#1056777: firefox: Audio accelerated, popping and crackling

2023-11-25 Thread Alexandre Lymberopoulos
Package: firefox Version: 120.0-2 Severity: normal Dear Maintainer, Everytime I open any video content (eg Youtube) the audio is extremely accelerated, with popping and crackling. Two curious things: 1) when I open speech-dispatcher the audio gets normal. 2) when I open pavucontrol (using pipewi

Bug#1056736: smartmontools: please do not force people to use update-smart-drivedb and install foreign code

2023-11-25 Thread Dmitry Smirnov
On Sunday, 26 November 2023 12:39:09 PM AEDT Christoph Anton Mitterer wrote: > Nevertheless, do you think it would possible to adapt it to check > whether update-smart-drivedb is executable and if not fall back to the > old code? > > Background is that at the university cluster I administrate we h

Bug#1056778: gnome-shell: Leaks memory using Wayland

2023-11-25 Thread Adrian Immanuel Kiess
Package: gnome-shell Version: 44.5-2 Severity: normal Dear Maintainer, * What led up to the situation? Upgrading gnome-shell on Debian/testing * What exactly did you do (or not do) that was effective (or ineffective)? apt -u dist-upgrade * What was the outcome of this acti

Bug#1056384: X server shuts down and doesn't return during upgrade.

2023-11-25 Thread Adam Dane
On 2023-11-25 06:31, Andreas Beckmann wrote: May I take the lack of comment on nvidia-suspend-common 525.147.05-3 that it now behaves normally? ;-) Yes, all is well. PS: It would be great if someone could confirm that also suspend/resume and hibernate/resume cycles work properly with these ne

Bug#1056779: derby-doc: some javadoc missing from derby-doc

2023-11-25 Thread tony mancill
Package: derby-doc Severity: normal I noticed during the preparation of 10.14.2.0-3 that the javadoc installed in the derby-doc binary package is much less than what is provided in 10.14.2.0-2. This must be due to some change in the toolchain, since rebuilding 10.14.2.0-2 against sid, trixie, or

Bug#1056780: openmsx: Source-less Windows binary in source package (and other packaging issues)

2023-11-25 Thread Aaron Rainbolt
Package: openmsx Version: 19.1-1 Severity: serious Justification: Policy 2.2.1 X-Debbugs-Cc: arraybo...@ubuntu.com Packages in the Debian `main` archive area *must* comply with the DFSG, of which section 2 states "The program must include source code, and must allow distribution in source code as

Bug#1056780: openmsx: Source-less Windows binary in source package (and other packaging issues)

2023-11-25 Thread Aaron Rainbolt
Here's a debdiff between the current version of the openMSX package and a proposed new version that fixes this bug. **Note**: It is necessary to also delete the Contrib/codec/Win32/zmbv.dll file in the source package tree (debdiffs don't seem to communicate deleted binary files very well). --

Bug#1056780: openmsx: Source-less Windows binary in source package (and other packaging issues)

2023-11-25 Thread Aaron Rainbolt
Uh... ok so apparently either Gmail or the Debian BTS ate my patch, so here's a second attempt, this time as a file attachment. Also, it appears that the openMSX maintainer's debian.org email address must be pointing to an Apple support address since I've now gotten two "Thank you for contacti

Bug#1056781: cython3-legacy has an undeclared file conflict

2023-11-25 Thread Helmut Grohne
Package: cython3-legacy Version: 0.29.36-1~exp1 Severity: serious User: debian...@lists.debian.org Usertags: fileconflict Control: affects -1 + cython3-dbg cython3-legacy has an undeclared file conflict. This may result in an unpack error from dpkg. The files * /usr/lib/python3/dist-packages/Cy

Bug#1056782: findutils: VCS repo breaks dpkg-source/gbp-buildpackage

2023-11-25 Thread Gioele Barabucci
Package: src:findutils Tags: patch Dear findutils maintainers, the VCS repo at https://salsa.debian.org/debian/findutils/ contains two issues that make it incompatible as-is with dpkg-souce and with gbp-buildpackage (used, among others, by Salsa-CI), making it impossible to buuild without man

Bug#1053700: xarray test failure on s390x

2023-11-25 Thread Rebecca N. Palmer
I retried the arm64 test and it passed, so it's probably just a random hang (I've seen those before in pytest). Hence, I now _do_ suggest uploading current Salsa.

Bug#1054411: libopenni2-0: move udev rules to /usr

2023-11-25 Thread Helmut Grohne
Control: tags -1 - moreinfo On Mon, Oct 23, 2023 at 04:04:50PM +0200, Helmut Grohne wrote: > So I think this is how it works best, but maybe this is not the final > solution and hence I'm tagging it moreinfo. What do you think? Chris Hofstaedler kindly reviewed this patch we have since applied th

Bug#1054523: RFS: persp-projectile/1:1.0.0+git20210618.4e374d7-1 [RC] [Team] -- integrate perspective.el with projectile

2023-11-25 Thread Xiyue Deng
Xiyue Deng writes: > Hi Sean, > > Thanks for the review! I initially thought d/changelog should mainly be > about user-facing changes. But looks like it's better to be thorough. > Please see replies inline below. > > Sean Whitton writes: > >> control: tag -1 + moreinfo >> control: owner -1 ! >

<    1   2