Bug#1063513: openjdk-17-jre-headless: After upgrading to 17.0.10+7-1~deb12u1, jspawnhelper is missing execute permissions

2024-02-09 Thread Jim Nicholson
Package: openjdk-17-jre-headless Version: 17.0.10+7-1~deb12u1 Severity: normal X-Debbugs-Cc: thejimnichol...@gmail.com Dear Maintainer, After an apt unattended-upgrade installed 17.0.10+7-1~deb12u1, builds started failing on Jenkins build agents with this error: java.io.IOException: Cannot

Bug#1063446: libmozjs-115-dev: cannot call JS::CanonicalizeNaN(double) on mips64el

2024-02-09 Thread Emilio Pozuelo Monfort
Hi Simon, On 08/02/2024 21:59, Simon McVittie wrote: On Thu, 08 Feb 2024 at 10:37:33 +, Simon McVittie wrote: Package: libmozjs-115-dev Justification: makes gjs FTBFS (#1063433) I believe mozjs115_115.7.0-3 should fix this. wb-team: Please could someone with wanna-build access schedule

Bug#1059972: LGTM, added to git

2024-02-09 Thread Christian Ehrhardt
Control: tags 1059972 + patch pending Hi, thank you for your prep work. I've opened [1] to add it to the git branch. The intention is to upload it to experimental once 23.11.1 is around, check if all loong64 builds are correct and then push to unstable. [1]:

Bug#1061740: django-rich: upstream patch to fix the test failure on Python 3.12

2024-02-09 Thread Ravi Kant Sharma
Package: django-rich Version: 1.8.0-1 Followup-For: Bug #1061740 User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch X-Debbugs-Cc: ravi.kant.sha...@canonical.com Control: tags -1 patch Dear Maintainer, In Ubuntu, the attached patch was applied to achieve the following:

Bug#1062567: libpg-query: NMU diff for 64-bit time_t transition

2024-02-09 Thread Christoph Berg
Re: Adrien Nader > I think the most recent version of that script would be in my > repository: https://salsa.debian.org/adrien-n/armhf-time_t/ Hi Adrien, I actually got the script running, I think. I pushed a few https://salsa.debian.org/vorlon/armhf-time_t/-/merge_requests/132 that have not

Bug#1063514: Broken links in the View Trends and the View Histogram menu

2024-02-09 Thread Rubenb
Package: nagios4 Version: 4.4.6-4 The links for the following are broken in the Service Information or the Host Information menus for the following links. View Trends For This Service View Alert Histogram For This Service View Trends For This Host View Alert Histogram For This Host

Bug#1063515: glibc: Please build with -mbranch-protection=standard on arm64 to enable PAC/BTI support

2024-02-09 Thread Emanuele Rocca
Source: glibc Version: 2.37-15 Severity: wishlist Tags: patch User: debian-...@lists.debian.org Usertags: arm64 Control: block -1 by 1057469 Hi, As discussed on the debian-glibc mailing list [1], please consider building glibc on arm64 with -mbranch-protection=standard to enable support for the

Bug#1061440: azure-cosmos-table-python: autopkgtest failure with Python 3.12

2024-02-09 Thread Jérémy Lal
Source: azure-cosmos-table-python Followup-For: Bug #1061440 This package is deprecated, in favor of the python3-azure debian package. Please don't fix this bug, and let's get this eventually autoremoved. -- System Information: Debian Release: trixie/sid APT prefers testing APT policy:

Bug#1063093: ca-certificates: expired certificate: Security_Communication_Root_CA.crt

2024-02-09 Thread Julien Cristau
Control: severity -1 minor On Mon, Feb 5, 2024 at 10:19:10 +0800, Paul Wise wrote: > I noticed that there is one expired certificate in ca-certificates: > >    $ cat test >    now=$(date -u) >    date -d "$now" >    now="$(date -d "$now" +%s)" >    for f in /usr/share/ca-certificates/mozilla/*

Bug#1063517: ITP: adios4dolfinx -- ADIOS2Wrappers for DOLFINx

2024-02-09 Thread Francesco Ballarin
Package: wnpp Severity: wishlist Owner: Francesco Ballarin X-Debbugs-Cc: debian-de...@lists.debian.org, debian-scie...@lists.debian.org, francesco.balla...@unicatt.it * Package name: adios4dolfinx Version : 0.7.3 Upstream Contact: Jørgen S. Dokken * URL :

Bug#1063516: transition: pcl

2024-02-09 Thread Jochen Sprickerhof
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: p...@packages.debian.org Control: affects -1 + src:pcl Hi release team, I would like to transition to the new pcl version. The auto generated ben file looks fine and the

Bug#1061791: comitup fails its autopkg tests with Python 3.12

2024-02-09 Thread Jeremy Bícha
Control: severity -1 serious Control: tags -1 +patch Ubuntu has cherry-picked these 2 commits and it fixed the autopkgtest failure: https://github.com/davesteele/comitup/commit/9ae9c61b https://github.com/davesteele/comitup/commit/5032f44e Thank you, Jeremy Bícha

Bug#1061476: Transition slot for elpi

2024-02-09 Thread Sebastian Ramacher
Hi Julien On 2024-02-09 10:06:28 +0100, julien.pu...@gmail.com wrote: > Hi, > > is there a particular problem with what I'm proposing? I checked and > didn't see any collision with an ocaml transition or some such. Until the time_t transition is done, we won't process other transition. Normal

Bug#1061476: Transition slot for elpi

2024-02-09 Thread julien . puydt
Hi, Le vendredi 09 février 2024 à 10:19 +0100, Sebastian Ramacher a écrit : > Hi Julien > > On 2024-02-09 10:06:28 +0100, julien.pu...@gmail.com wrote: > > Hi, > > > > is there a particular problem with what I'm proposing? I checked > > and > > didn't see any collision with an ocaml transition

Bug#1056227: Fixed Python3.12 issue but astropy issue is pending (Was: aplpy's autopkg tests fail with Python 3.12)

2024-02-09 Thread Andreas Tille
Control: tags -1 pending Hi Ole, I've fixed the distutils issue of Python3.12 in Git but there is an issue pending which you probably can solve way more easier than I: from astropy.config.configuration import ( E ImportError: cannot import name 'update_default_config' from

Bug#1062567: libpg-query: NMU diff for 64-bit time_t transition

2024-02-09 Thread Adrien Nader
On Fri, Feb 09, 2024, Christoph Berg wrote: > Re: Adrien Nader > > I think the most recent version of that script would be in my > > repository: https://salsa.debian.org/adrien-n/armhf-time_t/ > > Hi Adrien, > > I actually got the script running, I think. I pushed a few >

Bug#1062805: RFS ping

2024-02-09 Thread Alexandru Mihail
To clarify, the package to be uploaded is available at: https://mentors.debian.net/package/mini-httpd/ Thanks ! Alexandru Mihail mini-httpd maintainer signature.asc Description: This is a digitally signed message part

Bug#1062567: libpg-query: NMU diff for 64-bit time_t transition

2024-02-09 Thread Adrien Nader
Hi Christoph, The automated assessment uses a script which in turns uses abi-compliance-checker. I think the most recent version of that script would be in my repository: https://salsa.debian.org/adrien-n/armhf-time_t/ The README.md file describes it (it doesn't describe other tools in that repo

Bug#1019980: lintian: source-is-missing check for HTML is much too sensitive

2024-02-09 Thread Colin Watson
On Thu, Feb 08, 2024 at 06:39:18PM +, Bastien Roucariès wrote: > Are you sure it is not embdeded base64 encoded png or minified javascript* ? Yes, I'm absolutely certain. > If not we could try to know why it choke ? I already gave a full explanation of this in my first message, which for

Bug#1063338: [regression 6.1.76] dlm: cannot start dlm midcomms -97 after backport of e9cdebbe23f1 ("dlm: use kernel_connect() and kernel_bind()")

2024-02-09 Thread Valentin Kleibel
Hi Would you be able to confirm that the attached patch fixes your issue as well? Yes it does. @debian maintainers: is it possible to include this patch in the next point release? Thank you for your work, Valentin

Bug#1005765: dgit doesn't handle upstream files with CRLF well

2024-02-09 Thread Ian Jackson
Control: close -1 Thanks for the report. But, having reviewed this bug, I think all of dgit's behaviour here is correct. What's wrong is that the git tree and .orig have mismatched line ending conventions. I've conjectured that this is tolerated by other tooling (eg git-buildpackage) because

Bug#1061740: django-rich: upstream patch to fix the test failure on Python 3.12

2024-02-09 Thread Ravi Kant Sharma
Package: django-rich Version: 1.8.0-1 Followup-For: Bug #1061740 User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch X-Debbugs-Cc: ravi.kant.sha...@canonical.com Control: tags -1 patch Dear Maintainer, In Ubuntu, the attached patch was applied to achieve the following:

Bug#1032869: Bug #1032869: libstrophe: connection problem

2024-02-09 Thread Martin
Control: found -1 0.12.2-1 Control: retitle -1 libstrophe: connection problem Control: severity -1 minor Hi Russell, could you check, if the behaviour of libstrophe is better in the current version 0.13.0? Thank you! Cheers

Bug#1061476: Transition slot for elpi

2024-02-09 Thread julien . puydt
Hi, is there a particular problem with what I'm proposing? I checked and didn't see any collision with an ocaml transition or some such. Thanks, J.Puydt

Bug#1062567: libpg-query: NMU diff for 64-bit time_t transition

2024-02-09 Thread Christoph Berg
Re: Adrien Nader > Nice! Watch out though if you don't use a container: the script can > change your system. Hi Adrien, thanks for the detailed answers. I was using a chroot, that seems to have been enough isolation. > You also need to run it on armhf to have the correct > machine definitions.

Bug#1063533: Performance with packages with large numbers of tests

2024-02-09 Thread Ian Jackson
Package: autopkgtest Version: 5.32 Severity: wishlist tl;dr: autopkgtest is slower than it needs to be for packages with many tests. I can see at least one easy opportunity for a potentially substantial improvement, and have another more doubtful idea. Background and factual information:

Bug#1063539: undertow: CVE-2023-4639

2024-02-09 Thread Moritz Mühlenhoff
Source: undertow X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for undertow. CVE-2023-4639[0]: https://bugzilla.redhat.com/show_bug.cgi?id=2166022 If you fix the vulnerability please also make sure to include the CVE

Bug#1063540: libhibernate-validator-java: CVE-2023-1932

2024-02-09 Thread Moritz Mühlenhoff
Source: libhibernate-validator-java X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for libhibernate-validator-java. CVE-2023-1932[0]: rendering of invalid html with SafeHTML leads to HTML injection and XSS

Bug#1063541: acetoneiso: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: acetoneiso Version: 2.4-4 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have

Bug#1063542: python-parsl-doc: please make the build reproducible

2024-02-09 Thread James Addison
Package: python-parsl-doc Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: hostname X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Dear Maintainer, I'm an occasional volunteer with the Reproducible Builds[1] project, and recently noticed that

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread Michael Tokarev
09.02.2024 16:58, ca...@allfreemail.net Package: console-setup Followup-For: Bug #1063518 Consider making all scripts provided by console-setup shellcheck-clean, there are lots of tiny issues that can turn into big issues under the right conditions. Please do not do this. Shellcheck is a

Bug#1063543: amavisd-new: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: amavisd-new Version: 1:2.13.0-3 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They

Bug#1063544: android-platform-external-libunwind: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: android-platform-external-libunwind Version: 10.0.0+r36-4 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be

Bug#1063542: python-parsl-doc: please make the build reproducible

2024-02-09 Thread James Addison
Followup-For: Bug #1063542 Description: improve Sphinx documentation reproducibility by preserving argument defaults The TaskVineManagerConfig dataclass includes an 'address' attribute that is set to the value of socket.gethostname() when the class is loaded. . Meanwhile, the

Bug#1063546: atool: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: atool Version: 0.39.0-13 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been

Bug#1059148: Fixed upstream

2024-02-09 Thread Uli Schlachter
Hi, this issue was now fixed upstream and thus should be solved in an upcoming release: http://cvs.schmorp.de/rxvt-unicode/src/command.C?r1=1.603=1.604=date Cheers, Uli

Bug#1063524: brltty: move aliased files to /usr (DEP17)

2024-02-09 Thread Helmut Grohne
Source: brltty Version: 6.6-4 Tags: patch User: helm...@debian.org Usertags: dep17m2 Hi, we want to finalize the /usr-merge transition by moving all files to /usr via DEP17 and thus remove practical problems arising from aliasing. brltty is involved, because it installs various files in aliased

Bug#1027889: use of dh_dkms without b-d: dh-dkms is a FTBFS

2024-02-09 Thread Helmut Grohne
Control: retitle -1 kpatch FTBFS: please switch to B-D: dh-sequence-dkms (or dh-dkms) Control: tags -1 + ftbfs Using dh_dkms without Build-Depends: dh-dkms makes the package ftbfs: | make[1]: dh_dkms: No such file or directory | make[1]: *** [debian/rules:23: override_dh_install] Error 127 |

Bug#1063525: d-spy FTBFS with nocheck profile: ../meson.build:187:6: ERROR: Program 'update-desktop-database' not found or not executable

2024-02-09 Thread Helmut Grohne
Source: d-spy Version: 1.8.0-1 Severity: serious Tags: ftbfs trixie sid d-spy fails to build from source when built with the nocheck build profile. Since trixie such a failure is considered release-critical. A build ends with: | ../meson.build:187:6: ERROR: Program 'update-desktop-database' not

Bug#958587: lockdown FTBFS due to B-D: dh-systemd

2024-02-09 Thread Helmut Grohne
Control: retitle -1 lockdown FTBFS: Build-Depends on deprecated dh-systemd which is no longer available Control: tags -1 + ftbfs This bug has become a FTBFS. Tagging as such. Helmut

Bug#1063478: gem2deb rails assets smoke test should handle links or skip the test during build

2024-02-09 Thread Pirate Praveen
Control: severity -1 serious On Fri, 9 Feb 2024 00:30:03 +0530 Pirate Praveen wrote: For majority of packages that wraps javascript assets, the actual assets are shipped in a libjs-* package and ruby-* package only include a symbolic link. Testing further with ruby-rails-assets-underscore,

Bug#1063527: einsteinpy: test_plotting fails to converge with scipy 1.11

2024-02-09 Thread Drew Parsons
Source: einsteinpy Version: 0.4.0-3 Severity: important Control: block 1061605 by -1 einsteinpy is failing test_plotting with scipy 1.11 from experimental 143s if disp: 143s msg = ("Failed to converge after %d iterations, value is %s." 143s% (itr + 1, p))

Bug#1063528: calling less PAGER a second time after resizing the terminal does not use new size

2024-02-09 Thread VA
Package: ipython3 Version: 8.20.0-1 - Start with a 80x24 terminal - Set "export PAGER=less" - Open "ipython3" - Run "import os" - Run "os??" - Press "q" to quit pager - Maximize terminal window - Run again "os??" - Scroll view with pagedown/pageup With xterm, the text scrolled is clipped into a

Bug#1052455: RE: freetype 2.12.1+dfsg-5+deb12u1 makes chromium segfault at startup

2024-02-09 Thread Hugh McMaster
Hi Jonathan, On Wed, 7 Feb 2024 at 04:47, Jonathan Wiltshire wrote: > What's your plan at this point? We have skipped this update in two point > releases now and it needs a resolution. Thanks for following up. I’d actually forgotten about this. I’d still like to disable the incomplete and

Bug#1060706: linux-image-6.1.0-17-amd64: intel i225 NIC loses PCIe link, network becomes unusable)

2024-02-09 Thread Diederik de Haas
On Friday, 9 February 2024 13:39:23 CET Arno Lehmann wrote: > [Fr Feb 9 13:25:08 2024] CPU: 20 PID: 84300 Comm: kworker/20:0 Not > tainted 6.5.0-0.deb12.4-amd64 #1 Debian 6.5.10-1~bpo12+1 > [Fr Feb 9 13:25:08 2024] Hardware name: ASUS System Product Name/ROG > STRIX X670E-A GAMING WIFI, BIOS

Bug#1063548: check-all-the-things: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: check-all-the-things Version: 2017.05.20+nmu1 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from

Bug#1063549: openstack-cluster-installer: Enhancement: preliminary Ceph radosgw support

2024-02-09 Thread Jim Scadden
Package: openstack-cluster-installer Tags: patch Severity: wishlist I've raised a Merge Request [1] to add Ceph radosgw support to OCI. I've included more detailed information in the MR description, and in the git commit messages. Once omission at present is firewall rules. I wanted to get this

Bug#1052730: ruby-delayed-job: FTBFS: ERROR: Test "ruby3.1" failed: ArgumentError:

2024-02-09 Thread Pirate Praveen
Control: forwarded -1 https://github.com/collectiveidea/delayed_job/pull/1203 On Tue, 26 Sep 2023 14:40:49 +0200 Lucas Nussbaum wrote: Relevant part (hopefully): > ArgumentError: >Invalid Timezone: US/Eastern Forwarded fix upstream

Bug#1063551: dnsmasq: install systemd units below /usr (DEP17)

2024-02-09 Thread Helmut Grohne
Package: dnsmasq Version: 2.89-1 Tags: patch User: helm...@debian.org Usertags: dep17m2 Hi, we want to finalize the /usr-merge transition by moving aliased files from / to /usr via DEP17. dnsmasq is involved, because it contains aliased systemd units. I'm attaching a patch, because dnsmasq

Bug#1063552: libfreebsd-glue-0: move files to /usr (DEP17)

2024-02-09 Thread Helmut Grohne
Package: libfreebsd-glue-0 Version: 0.2.22+nmu1 Tags: patch User: helm...@debian.org Usertags: dep17m2 Hi, we want to finalize the /usr-merge transition by moving all aliased files from / to /usr via DEP17 to avoid any negative effects arising from aliasing. libfreebsd-glue-0 is involved,

Bug#1063550: dhcp-helper: move files to /usr for DEP17

2024-02-09 Thread Helmut Grohne
Package: dhcp-helper Version: 1.2-3.1 Tags: patch User: helm...@debian.org Usertags: dep17m2 Hi, we want to move all files from aliased to locations to /usr to finalize the /usr-merge transition via DEP17. dhcp-helper is involved, because it installs a systemd unit below /lib. I'm sending you a

Bug#1063553: libexpat1: move files to /usr (DEP17)

2024-02-09 Thread Helmut Grohne
Package: libexpat1 Version: 2.5.0-2 Tags: patch User: helm...@debian.org Usertags: dep17 Hi, we want to finalize the /usr-merge transition by moving aliased files from / to /usr via DEP17 to get rid of problems arising from aliasing. libexpat1 cannot be converted automatically, because it does

Bug#1063554: firmware-linux-free: move files to /usr (DEP17)

2024-02-09 Thread Helmut Grohne
Package: firmware-linux-free Version: 20200122-2 Tags: patch User: helm...@debian.org Usertags: dep17m2 Hi, we want to finalize the /usr-merge transition by moving all aliased files from / to /usr via DEP17 to avoid any negative effects arising from aliasing. firmware-linux-free is involved,

Bug#1063555: crunch: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: crunch Version: 3.6-3 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread Thorsten Bonow
Package: console-setup Version: 1.225 Severity: grave After the upgrade from 1.223, console-setup.service failed to start due to a syntax error in the setupcon script: , | $ setupcon | /usr/bin/setupcon: 1386: Syntax error: Missing '))' ` It looks like dash does not like the

Bug#1063519: Qt.ColorScheme enum is not exposed

2024-02-09 Thread VA
Package: python3-pyqt6 Version: 6.6.1-2 >>> PyQt6.QtCore.Qt.ClipOperation >>> PyQt6.QtCore.Qt.ColorScheme AttributeError: type object 'Qt' has no attribute 'ColorScheme' It's present in the documentation: https://www.riverbankcomputing.com/static/Docs/PyQt6/api/qtcore/qt.html#ColorScheme So

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread Sven Joachim
Package: console-setup Version: 1.225 Severity: grave After the upgrade from 1.223, console-setup.service failed to start due to a syntax error in the setupcon script: , | $ setupcon | /usr/bin/setupcon: 1386: Syntax error: Missing '))' ` It looks like dash does not like the construct

Bug#1060706: linux-image-6.1.0-17-amd64: intel i225 NIC loses PCIe link, network becomes unusable)

2024-02-09 Thread Arno Lehmann
And another instance, and this time I thought about getting messages from an attempted igc module reloading. [Fr Feb 9 13:25:08 2024] igc :0b:00.0 eno1: PCIe link lost, device now detached [Fr Feb 9 13:25:08 2024] [ cut here ] [Fr Feb 9 13:25:08 2024] igc:

Bug#1063545: ark: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: ark Version: 4:23.08.1-2 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been

Bug#1063559: diffoscope: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: diffoscope Version: 255 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread Thorsten Bonow
Thorsten Bonow writes: [...] But what's POSIX take on this? I couldn't find anything. Is this a bug in dash or in setupcon? I'm stupid[1]. It's a bug in setupcon, POSIX requires the space: "The syntax of the shell command language has an ambiguity for expansions beginning with "$((",

Bug#1063562: dt-schema: Please add version dependency for jsonschema

2024-02-09 Thread Sebastian Reichel
Package: dt-schema Version: 2023.11-3 Severity: normal Dear Maintainer, This package completly breaks when using python3-jsonschema from experimental (4.19.2-1). I had a quick look and upstream is aware of the issue. The build script wants a version < 4.18:

Bug#1063534: [Debian-iot-maintainers] Bug#1063534: libjwt: CVE-2024-25189

2024-02-09 Thread Thorsten Alteholz
Hi Moritz, thanks for the bug. Upstream knows about the issue and already fixed it [1] + [2].   Thorsten [1] https://github.com/benmcollins/libjwt/commit/f73bac57c5bece16ac24f1a70022aa34355fc1bf [2] https://github.com/benmcollins/libjwt/commit/a5d61ef4f1b383876e0a78534383f38159471fd6

Bug#1063520: ITP: codetiming -- A Timer package for Python code

2024-02-09 Thread Alastair McKinstry
Package: wnpp Severity: wishlist Owner: Alastair McKinstry X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: codetiming Version : 1.4.0 Upstream Contact: David Beazley * URL : https://pypi.python.org/pypi/codetiming * License : MIT Programming

Bug#1063521: ITP: pymbolic -- Easy Expression Trees and Term Rewriting library

2024-02-09 Thread Alastair McKinstry
Package: wnpp Severity: wishlist Owner: Alastair McKinstry X-Debbugs-Cc: debian-de...@lists.debian.org, debian-pyt...@lists.debian.org * Package name: pymbolic Version : 2022.2 Upstream Contact: Andreas Klöckner * URL : https://github.com/inducer/pymbolic * License

Bug#1063523: duo-unix FTCBFS: uses AC_RUN_IFELSE

2024-02-09 Thread Helmut Grohne
Source: duo-unix Version: 1.11.3-1 Tags: patch upstream User: debian-cr...@lists.debian.org Usertags: ftcbfs duo-unix fails to cross build from source, because it uses AC_RUN_IFELSE to determine whether an openssl function exists. As it does not check the return value of the function, a link

Bug#1063531: RFS: mplayer/2:1.5+svn38446-2 -- movie player for Unix-like systems

2024-02-09 Thread Lorenzo
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "mplayer": * Package name : mplayer Version : 2:1.5+svn38446-2 Upstream contact : [fill in name and email of upstream] * URL : https://mplayerhq.hu * License

Bug#1063530: node-undici: FTBFS with nodejs 18.19.0+dfsg-6~deb12u1

2024-02-09 Thread Dylan Aïssi
Source: node-undici Version: 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3 Severity: serious Tags: bookworm Usertags: apertis-ftbfs Justification: FTBFS Hello, While doing a rebuild of some node packages in Bookworm, it appears several packages (at least ~ 50 pkgs) no longer build with nodejs

Bug#1063534: libjwt: CVE-2024-25189

2024-02-09 Thread Moritz Mühlenhoff
Source: libjwt X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for libjwt. CVE-2024-25189[0]: | libjwt 1.15.3 uses strcmp (which is not constant time) to verify | authentication, which makes it easier to bypass

Bug#1063535: node-ip: CVE-2023-42282

2024-02-09 Thread Moritz Mühlenhoff
Source: node-ip X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for node-ip. CVE-2023-42282[0]: | An issue in NPM IP Package v.1.1.8 and before allows an attacker to | execute arbitrary code and obtain sensitive information

Bug#1063536: ckeditor: CVE-2024-24815 CVE-2024-24816

2024-02-09 Thread Moritz Mühlenhoff
Source: ckeditor X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for ckeditor. CVE-2024-24815[0]: | CKEditor4 is an open source what-you-see-is-what-you-get HTML | editor. A cross-site scripting vulnerability has been

Bug#1063537: ckeditor3: CVE-2024-24815 CVE-2024-24816

2024-02-09 Thread Moritz Mühlenhoff
Source: ckeditor3 X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for ckeditor3. CVE-2024-24815[0]: | CKEditor4 is an open source what-you-see-is-what-you-get HTML | editor. A cross-site scripting vulnerability has been

Bug#1063538: python-multipart: CVE-2024-24762

2024-02-09 Thread Moritz Mühlenhoff
Source: python-multipart X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for python-multipart. CVE-2024-24762[0]: | FastAPI is a web framework for building APIs with Python 3.8+ based | on standard Python type hints. When

Bug#1061468: gloo: attempts to build on unsupported 32 bit systems

2024-02-09 Thread Dan Bungert
[Paul Wise] > The right way to do this is to Build-Depend: architecture-is-64-bit Thanks Paul, I didn't know about that. Clearly architecture-is-64-bit is the better solution. [Petter Reinholdtsen] > [Dan Bungert] > > I suggest adjusting the control file to reflect this state so that > > builds

Bug#1063556: [INTL:sv] Swedish strings for firebuild debconf

2024-02-09 Thread Martin Bagge / brother
package: firebuild severity: wishlist tags: patch l10n Please consider to add this file to translation of debconf. -- brother# Translation of firebuild debconf template to Swedish # Copyright (C) 2024 Martin Bagge # This file is distributed under the same license as the firebuild package. # #

Bug#1063557: deepin-boot-maker: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: deepin-boot-maker Version: 5.7.8+dfsg-3 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian.

Bug#1063558: pgpainless 1.6.6 is available

2024-02-09 Thread Daniel Kahn Gillmor
Package: src:pgpainless Version: 1.6.5-1 Severity: wishlist pgpainless 1.6.6 is available upstream. it would be great to have it in debian. Thanks, --dkg signature.asc Description: PGP signature

Bug#1063561: dtrx: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: dtrx Version: 8.5.3-1 Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been

Bug#1063522: file: does not recognize unified diff file with binary data

2024-02-09 Thread Vincent Lefevre
Package: file Version: 1:5.45-2+b1 Severity: normal Debian's file utility does not recognize unified diff file with binary data. To reproduce, create 2 files a and b with { seq 1 9 && printf "\001"; } > a { seq 2 9 && printf "\002"; } > b Then $ diff -u a b | /usr/bin/file - /dev/stdin:

Bug#1063522: file: does not recognize unified diff file with binary data

2024-02-09 Thread Vincent Lefevre
Control: tags -1 upstream fixed-upstream On 2024-02-09 13:51:20 +0100, Vincent Lefevre wrote: > Debian's file utility does not recognize unified diff file with > binary data. To reproduce, create 2 files a and b with > > { seq 1 9 && printf "\001"; } > a > { seq 2 9 && printf "\002"; } > b >

Bug#1063526: astroml: test_iterative_PCA fails with scipy 1.11: unexpected keyword argument 'sym_pos'

2024-02-09 Thread Drew Parsons
Source: astroml Version: 1.0.2-2 Severity: important Control: block 1061605 by -1 astroml is failing test_iterative_PCA with scipy 1.11 from experimental 82s for i in range(n_samples): 82s VWV = np.dot(VT[:n_ev], (notM[i] * VT[:n_ev]).T) 82s >

Bug#1063529: wdiff: broken when the input contains a null character

2024-02-09 Thread Vincent Lefevre
Package: wdiff Version: 1.2.2-6 Severity: normal wdiff is broken when the input contains a null character. For instance, create 2 files a and b with printf "a\n2\n3\n4\n5\n6\n7\n8\n" > a printf "b\n2\n3\n4\n5\n6\n7\n8\n\000\n" > b $ wdiff a b b 2 3 4 5 6 7 8 instead of something like

Bug#1063532: ITP: ford -- Fortran Documentation tool

2024-02-09 Thread Alastair McKinstry
Package: wnpp Severity: wishlist Owner: Alastair McKinstry X-Debbugs-Cc: debian-de...@lists.debian.org, debian-scie...@lists.debian.org * Package name: ford Version : 7.0.5 Upstream Contact: Christopher MacMackin * URL :

Bug#1063478: gem2deb rails assets smoke test should handle links or skip the test during build

2024-02-09 Thread Pirate Praveen
Control: severity -1 important On 9/2/24 6:48 PM, Pirate Praveen wrote: Without libjs-underscore in build depends, the test should fail, but it is passing. ruby-rails-assets-underscore source package includes underscore.js and it is replaced by symlink to libjs-underscore only in dh_install

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread cacin
Package: console-setup Followup-For: Bug #1063518 Consider making all scripts provided by console-setup shellcheck-clean, there are lots of tiny issues that can turn into big issues under the right conditions. https://tracker.debian.org/pkg/shellcheck

Bug#1063547: avfs: transition from p7zip to 7zip

2024-02-09 Thread cacin
Source: avfs Severity: normal Dear Maintainer, your package Depends/Recommends/Suggests or has some other relation to the p7zip/p7zip-full/p7zip-rar packages, which have become transitional packages in debian trixie and will eventually be removed from debian. They have been replaced by 7zip

Bug#1063560: dt-schema: Package does not work properly for latest upstream kernel

2024-02-09 Thread Sebastian Reichel
Package: dt-schema Version: 2023.11-3 Severity: normal Tags: patch Dear Maintainer, I see a huge amount of warning being reported when running CHECK_DTBS in the kernel tree (latest master). After cherry-picking the following two upstream commits things are working properly:

Bug#1063518: console-setup: setupcon: 1386: Syntax error: Missing '))'

2024-02-09 Thread Michael Tokarev
09.02.2024 17:57, Thorsten Bonow : dash << 'EOF'    [15:28:53] if $( (true) 2>/dev/null); then  echo "42" fi EOF 42 which only works in dash because of the added space between the command substitution $(...) and the subshell (...). Does dash think it

Bug#1063434: 389-ds-base: Build flags for 32bit architectures

2024-02-09 Thread Chris Peterson
Package: 389-ds-base Version: 2.4.4+dfsg1-1 Followup-For: Bug #1063434 User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch X-Debbugs-Cc: chris.peter...@canonical.com Control: tags -1 patch Dear Maintainer, I see this has been marked for autoremoval, but I have recently

Bug#1062596: libqt5qxlsx: NMU diff for 64-bit time_t transition

2024-02-09 Thread Alexander Wolf
The latest stable version of QtXlxs is 1.4.6 and prepelease of 1.4.7 is published now. Probably updating to latest stable may be important. — WBW, Alex

Bug#1061744: ipyparallel: Patch to fix failing unit test

2024-02-09 Thread Chris Peterson
Package: ipyparallel Followup-For: Bug #1061744 User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch X-Debbugs-Cc: chris.peter...@canonical.com Control: tags -1 patch Dear Maintainer, In Ubuntu, the attached patch was applied to achieve the following: * Fix tests

Bug#1063634: minitube: Does not store preview image for subscriptions

2024-02-09 Thread Bruno Kleinert
Package: minitube Version: 3.9.3-2 Severity: normal X-Debbugs-Cc: fu...@debian.org Hi, when subscribing to a channel, minitube does not store a preview image with the subscription. That renders the channel invisible in the 'Subscriptions' tab. It's possible to "blindly" click on them, though.

Bug#1063632: spirv-llvm-translator-17 FTBFS: error: ‘CapabilityLongConstantCompositeINTEL’ was not declared in this scope

2024-02-09 Thread Adrian Bunk
Source: spirv-llvm-translator-17 Version: 17.0.0-3 Severity: serious Tags: ftbfs Forwarded: https://github.com/KhronosGroup/SPIRV-LLVM-Translator/issues/2261 https://buildd.debian.org/status/logs.php?pkg=spirv-llvm-translator-17=17.0.0-3%2Bb1 ... In file included from

Bug#1049982: bullseye-pu: package riemann-c-client/1.10.4-2+b2

2024-02-09 Thread Romain Tartière
Hi Jonathan, On Tue, Feb 06, 2024 at 05:59:10PM +, Jonathan Wiltshire wrote: > This request was approved but not uploaded in time for the previous point > releases (11.8 and 11.9). Should it be included in 11.10, or should this > request be abandoned and closed? I am not sure about the

Bug#1049988: bookworm-pu: package riemann-c-client/1.10.4-2

2024-02-09 Thread Romain Tartière
Hi Jonathan, On Tue, Feb 06, 2024 at 06:12:47PM +, Jonathan Wiltshire wrote: > This request was approved but not uploaded in time for the previous point > release (12.5). Should it be included in 12.6, or should this request be > abandoned and closed? I am not sure about the process, but

Bug#1040375: /usr/lib/x86_64-linux-gnu/simplescreenrecorder/libssr-glinject.so: Segmentation fault when used with anything

2024-02-09 Thread Petter Reinholdtsen
I had a look upstream, and found two issues that seem to be about this crash bug: https://github.com/MaartenBaert/ssr/issues/992 and https://github.com/MaartenBaert/ssr/issues/1013 . The latter have some patch proposals. If the latest upstream git edition work, could the fix be the change

Bug#1063492: openvswitch: CVE-2023-3966: Invalid memory access in Geneve with HW offload

2024-02-09 Thread Tobias Frost
Control: tags -1 fixed-upstream According to this announcment [1], CVE-2023-3966 and CVE-2023-5366 are fixed with versions Latest stable: https://www.openvswitch.org/releases/openvswitch-3.2.2.tar.gz Current LTS series:

Bug#1062805: RFS: mini-httpd/1.30-8 -- Small HTTP server

2024-02-09 Thread Abhijith PA
Hi Alexandru, I can upload this package for you. --abhijith

Bug#1061496: valgrind: Segmentation fault on armhf checking programs built with -fstack-clash-protection or -fstack-check

2024-02-09 Thread Petter Reinholdtsen
Control: affects -1 + libvorbis-dev Control: block 1061501 by -1 This issue cause a failing autopkgtest with libvorbis. I would much prefer a fix in valgrind instead of disabling a autopkgtest check. -- Happy hacking Petter Reinholdtsen

Bug#1063633: ITP: python-autodocsumm -- API that automatically extends sphinx

2024-02-09 Thread Marcos Rodrigues de Carvalho (aka oday)
Package: wnpp Severity: wishlist Owner: "Marcos Rodrigues de Carvalho (aka oday)" X-Debbugs-Cc: debian-de...@lists.debian.org, marcosrcarvalh...@gmail.com * Package name: python-autodocsumm Version : 0.2.12 Upstream Contact: Philipp S. Sommer * URL :

  1   2   3   >