Bug#1067650: davmail: O365Interactive fails with "superclass access check failed: class davmail.exchange.auth.O365InteractiveAuthenticatorFrame"

2024-04-05 Thread Alexandre Rossi
Hi, > Exception in thread "AWT-EventQueue-0" java.lang.IllegalAccessError: > superclass access check failed: class > davmail.exchange.auth.O365InteractiveAuthenticatorFrame$2 (in unnamed module > @0x112d0a71) cannot access class sun.net.www.protocol.https.Handler (in > module java.base)

Bug#1067784: Doesn't contain libpmix.so.2

2024-04-05 Thread Drew Parsons
Package: libpmix2t64 Version: 5.0.2-2 Followup-For: Bug #1067784 Control: affects 1067784 nwchem nwchem-openmpi Control: reopen 1067784 Looks like 5.0.2-2 annihilated the symlink fix made in 5.0.2-1.1 See nwchem tests, https://ci.debian.net/packages/n/nwchem/unstable/amd64/44696719/ 90s

Bug#1068438: giflib: snprintf buffer overflow

2024-04-05 Thread Nathan Pratta Teodosio
Source: giflib Version: 5.2.2-1 Severity: normal Tags: patch upstream X-Debbugs-Cc: nathan.teodo...@canonical.com In Ubuntu giflib failed to build from source due to detection of a buffer overflow in sprintf. This didn't cause build problems in Debian because it uses FORTIFY_SOURCE=2. Here is

Bug#1067675: library package (arch any) depending on a "common" package with too strict version constraint

2024-04-05 Thread Matthias Klose
On 02.04.24 21:54, Jeremy Bícha wrote: Cloning a bug in the way you did is not very helpful. mutter's situation is different than folks. The mutter binary package has Depends: mutter-common (>= ${source:Version}) That allows mutter to be binNMU'd. that works for Debian, but not Ubuntu. A

Bug#1067831: libaio: the t64 package slipped through and is in testing

2024-04-05 Thread Guillem Jover
On Fri, 2024-04-05 at 09:22:04 +0200, Raphael Hertzog wrote: > On mer., 27 mars 2024, Guillem Jover wrote: > > A binNMU would fix that, but given that no one has apparently asked > > for that yet, I think instead I'll just add (later today) a compat > > symlink only for the udeb for the old

Bug#1068022: Document the Testsuite-Triggers field

2024-04-05 Thread Christian Kastner
Hi again, On 2024-03-29 20:30, Christian Kastner wrote: > Policy 5.6.30 lists the Testsuite field, but it doesn't list the > Testsuite-Triggers field that seems to be part of Sources files and is > generated by dpkg-source >= 1.18.8. > > This field is quite useful, as given my package src:foo, I

Bug#1068350: [musl] Re: Bug#1068350: musl: miscompiles (runtime problems) on riscv64 and s390x with static-pie → seems to be a toolchain bug after all, it does too hit glibc

2024-04-05 Thread Szabolcs Nagy
* Thorsten Glaser [2024-04-05 05:04:37 +]: > Markus Wichmann dixit: > > >can check with readelf -r what the relocation types are. If they are not > >relative, they will not be processed. > > Gotcha! They are all R_390_RELATIVE except for: > > 00045ff0 00110016 R_390_64

Bug#1068436: RFS: transmission/4.0.5-1.2 [NMU] [RC] -- lightweight BitTorrent client

2024-04-05 Thread Alexandre Rossi
Package: sponsorship-requests Severity: important Dear mentors, I am looking for a sponsor for the package "transmission": * Package name : transmission Version : 4.0.5-1.2 * URL : https://transmissionbt.com/ * License : GPL-3 or LGPL-2.1, ISC, Expat,

Bug#1067561: FTBFS: Error: symbol `open64' is already defined

2024-04-05 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, 2024-04-05 at 11:25 +0500, Andrey Rakhmatullin wrote: > > Hi, thanks for the patch. It looks a bit strong though, undefining stuff > > like > > that unconditionally. Do you have pointers to the Ubuntu bug or something? > I haven't checked

Bug#1068442: igblast: Package igblast does not contain binary for igblast

2024-04-05 Thread Mateusz K
Package: igblast Version: 1.19.0-1+b1 Severity: normal Dear Maintainer, Package does not contain igblast (igblastn) binary, which means that igblast package does not contain igblast. Regards, -- System Information: Debian Release: trixie/sid APT prefers unstable APT policy: (500,

Bug#1068437: plantuml fails to run due to recent changes to openjdk dependencies in build environment

2024-04-05 Thread Vladimir Petko
Package: plantuml Severity: important Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu noble ubuntu-patch Dear Maintainer, openjdk-*-jre-headless packages now recommend fontmanager dependencies, not depend on them. This breaks plantuml, because the binary package depends

Bug#1068362: uif 1.99.0-4.1+deb12u1 flagged for acceptance

2024-04-05 Thread Jonathan Wiltshire
package release.debian.org tags 1068362 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: uif Version:

Bug#1067831: libaio: the t64 package slipped through and is in testing

2024-04-05 Thread Raphael Hertzog
Hi, On Fri, 05 Apr 2024, Guillem Jover wrote: > > Would it be problematic to add the same compat symlink in the main > > library package? > > I think so yes, because if the intention is to reverse the SONAME > bump (while adding the t64 symlinks also on the reintroduced libaio1 > package), then

Bug#1068288: openjdk-21: bootstrap builds required on armel and armhf

2024-04-05 Thread Wookey
I have bootstrapped openjdk-21 on armhf (via profile nocheck builds for openjdk-20 and 21). This was slow as each build is about 5 hours on the softiron machine I have to hand. jtreg6/7 (which does the tests) being uninstallable until you've got a version of java built against the t64

Bug#1068350: [musl] Re: Bug#1068350: musl: miscompiles (runtime problems) on riscv64 and s390x with static-pie → seems to be a toolchain bug after all, it does too hit glibc

2024-04-05 Thread Thorsten Glaser
Markus Wichmann dixit: >I may not really know what I am talking about, so take this with a grain >of salt, but isn't this missing a -Bsymbolic somewhere? Ironically, that >switch causes ld to not emit symbolic relocations. I seem to remember >reading long ago in Rich's initial -static-pie

Bug#1067561: FTBFS: Error: symbol `open64' is already defined

2024-04-05 Thread Andrey Rakhmatullin
On Fri, Apr 05, 2024 at 08:09:21AM +0200, Yves-Alexis Perez wrote: > > I assume the following patch from Ubuntu fixes this: > > > > --- a/tests/src/libsystem.c > > +++ b/tests/src/libsystem.c > > @@ -1,6 +1,9 @@ > >  #define _GNU_SOURCE > >  #define __USE_GNU > > > > +#undef _FILE_OFFSET_BITS >

Bug#1068440: ITP: emacs-corfu-terminal -- Corfu popup on terminal

2024-04-05 Thread Xiyue Deng
Package: wnpp Severity: wishlist Owner: Xiyue Deng * Package name: emacs-corfu-terminal Version : 0.7 Upstream Author : Akib Azmain Turja * URL or Web page : https://codeberg.org/akib/emacs-corfu-terminal * License : GPL-3 Programming lang: Emacs Lisp Description

Bug#1067830: possible patch for gri to handle time_t on debian

2024-04-05 Thread Daniel Kelley
Hi folks. Below is a commit note. I'm being a bit wordy -- this is a one-line diff after all -- but I wanted to explain my situation, in not being able to test whether this change will work. (It works on macos, but then again the old code worked there too, after I updated auto tools, and

Bug#1067561: FTBFS: Error: symbol `open64' is already defined

2024-04-05 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, 2024-04-01 at 00:37 +0500, Andrey Rakhmatullin wrote: > I assume the following patch from Ubuntu fixes this: > > --- a/tests/src/libsystem.c > +++ b/tests/src/libsystem.c > @@ -1,6 +1,9 @@ >  #define _GNU_SOURCE >  #define __USE_GNU > >

Bug#1068437: plantuml fails to run due to recent changes to openjdk dependencies in build environment

2024-04-05 Thread Vladimir Petko
Hi, Thank you for the fast response The dependencies are : libcups2t64, libfontconfig1, libfreetype6 (>= 2.3.5), libharfbuzz0b (>= 1.2.6). Specifying them directly might introduce an issue with backports due to the t64 library dependency. Best Regards, Vladimir.

Bug#1068439: systemd-cron: cron-update causes re-run of some past timers

2024-04-05 Thread Maximilian Stein
Package: systemd-cron Version: 2.3.4-1 Severity: normal Dear Maintainer, Today I noticed that a run of cron-update.service apparently causes some past cron jobs to re-run. In particular, I have a cron job of "5 5 5 * *" which correctly executed this morning at 2024-04-05T05:05:08.401635+02:00.

Bug#1068441: ITP: emacs-popon -- Pop floating text on an Emacs window

2024-04-05 Thread Xiyue Deng
Package: wnpp Severity: wishlist Owner: Xiyue Deng * Package name: emacs-popon Version : 0.13 Upstream Author : Akib Azmain Turja * URL or Web page : https://codeberg.org/akib/emacs-popon * License : GPL-3 Programming lang: Emacs Lisp Description : Pop floating

Bug#1068435: reportbug: sudo should not reset the DEBIAN_FRONTEND env variable

2024-04-05 Thread sohom
Package: sudo Version: 1.9.13p3-1+deb12u1 Severity: wishlist Dear Maintainer, I use a debian docker container to build Chromium. As of late, the build process has been failing due to the fact that certain new dependencies require user interaction to resolve (selecting keyboard and languages

Bug#1068350: [musl] Re: Bug#1068350: musl: miscompiles (runtime problems) on riscv64 and s390x with static-pie → seems to be a toolchain bug after all, it does too hit glibc

2024-04-05 Thread Markus Wichmann
Am Fri, Apr 05, 2024 at 05:58:15AM + schrieb Thorsten Glaser: > Markus Wichmann dixit: > >In any case, the emission of non-relative relocations is the issue here, > >and it is coming from the linker. > > They are present in the glibc static-pie binary as well, though. > And tbh they look to me

Bug#1067831: libaio: the t64 package slipped through and is in testing

2024-04-05 Thread Raphael Hertzog
Hi Guillem, On mer., 27 mars 2024, Guillem Jover wrote: > A binNMU would fix that, but given that no one has apparently asked > for that yet, I think instead I'll just add (later today) a compat > symlink only for the udeb for the old SONAME, because the new SONAME is > ABI compatible, but done

Bug#1068437: plantuml fails to run due to recent changes to openjdk dependencies in build environment

2024-04-05 Thread Andrej Shadura
Hi, On Fri, 5 Apr 2024, at 09:06, Vladimir Petko wrote: > openjdk-*-jre-headless packages now recommend fontmanager dependencies, not > depend on them. This breaks plantuml, because the binary package depends on > default-jre-headless and recommended packages are not installed in the build >

Bug#1068407: xfce4-terminal: processes sleep after a while when switching to a different workspace

2024-04-05 Thread Egmont Koblinger
See https://bugs.debian.org/1068339 . e.

Bug#1063077: syslog-ng: identified for time_t transition but no ABI in shlibs

2024-04-05 Thread Attila Szalay
Hello Steve, I do understand your concern about the time_t structure change and I also admit that there are some room of improvement how the syslog-ng package manage the library versioned dependency, but this is not the solution. Based on https://wiki.debian.org/NonMaintainerUpload, the binNMU

Bug#1068444: oar-web-status drawgant-svg does't work with php8.2

2024-04-05 Thread Jean Louis Mas
Package: oar-web-status Version: 2.5.9-1 Severity: important Dear Maintainer, * What led up to the situation? Upgrade to Debian 12 * What exactly did you do (or not do) that was effective (or ineffective)? Restart apache2 with php8.2 modules enabled * What was the outcome of

Bug#1068445: libllvm17t64: misaligned versions between amd64 and i386 make them uninstallable simultaneously

2024-04-05 Thread Giacomo Mulas
Package: libllvm17t64 Version: 1:17.0.6-9 Severity: normal Dear Maintainer, with the latest update, libllvm17t64 has been released in different versions between amd64 and i386 (1:17.0.6-9+b2 and 1:17.0.6-9+b1). This makes them uninstallable simultaneously, since each breaks any other lib for

Bug#1068446: /usr/lib/x86_64-linux-gnu/libetpan.so.20: compile-time options maybe make Claws Mail crash

2024-04-05 Thread Marco Moock
Package: libetpan20t64 Version: 1.9.4-3.2+b3 Severity: normal File: /usr/lib/x86_64-linux-gnu/libetpan.so.20 Dear Maintainer, Claws Mail links against libetpan. Sometimes it crashes. According to the developers this is caused by libetpan compiled without --with-poll

Bug#1067675: library package (arch any) depending on a "common" package with too strict version constraint

2024-04-05 Thread Jeremy Bícha
Control: tags -1 -patch I misunderstood what you were proposing in part because the "patch" you proposed here was not for mutter and the version you pushed into Ubuntu had a hardcoded version instead. And I didn't read carefully enough. To move your idea forward, I proposed

Bug#1065778: libcdio: FTBFS on arm{el,hf}: _cdio_stdio.c:53:20: error: implicit declaration of function ‘fseeko64’; did you mean ‘fseeko’? [-Werror=implicit-function-declaration]

2024-04-05 Thread Jeremy Bícha
Control: tags -1 +patch There was an Ubuntu upload to fix this issue: https://launchpadlibrarian.net/723206207/libcdio_2.1.0-4.1build1_2.1.0-4.1ubuntu1.diff.gz https://launchpad.net/ubuntu/+source/libcdio/2.1.0-4.1ubuntu1 Thank you, Jeremy Bícha

Bug#1068454: qt6-base: CVE-2024-30161

2024-04-05 Thread Moritz Mühlenhoff
Source: qt6-base X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for qt6-base. CVE-2024-30161[0]: | In Qt before 6.5.6 and 6.6.x before 6.6.3, the wasm component may | access QNetworkReply header data via a dangling

Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-05 Thread Moritz Muehlenhoff
On Fri, Apr 05, 2024 at 08:16:43AM +0400, Yadd wrote: > On 4/4/24 22:51, Moritz Mühlenhoff wrote: > > Source: apache2 > > X-Debbugs-CC: t...@security.debian.org > > Severity: grave > > Tags: security > > > > Hi, > > > > The following vulnerabilities were published for apache2. > > > >

Bug#1068412: apache2: CVE-2024-27316 CVE-2024-24795 CVE-2023-38709

2024-04-05 Thread Yadd
On 4/5/24 15:58, Moritz Muehlenhoff wrote: On Fri, Apr 05, 2024 at 08:16:43AM +0400, Yadd wrote: On 4/4/24 22:51, Moritz Mühlenhoff wrote: Source: apache2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for apache2.

Bug#1066112: weston: Enable support to libseat launcher in weston 10

2024-04-05 Thread Dylan Aïssi
Hi Charles, Sorry for not answering before. Le jeu. 4 avr. 2024 à 16:04, Carlos Henrique Lima Melara a écrit : > > > So, I have good and bad news, but I guess they are mostly good. > > > > THe bad news first, when I was checking the upstream commits, I saw some > > changes in libweston.h which

Bug#1068366: nmu: gyoto_2.0.2-1.1

2024-04-05 Thread Sebastian Ramacher
Control: tags -1 moreinfo On 2024-04-04 09:27:06 +0100, plugwash wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: binnmu > > It seems that the new version of gyoto was built a bit too early and, on most > architectures, picked up

Bug#1068452: request-tracker4: CVE-2024-3262

2024-04-05 Thread Moritz Mühlenhoff
Source: request-tracker4 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for request-tracker4. CVE-2024-3262[0]: | Information exposure vulnerability in RT software affecting version | 4.4.1. This vulnerability allows an

Bug#1068453: request-tracker5: CVE-2024-3262

2024-04-05 Thread Moritz Mühlenhoff
Source: request-tracker5 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for request-tracker5. CVE-2024-3262[0]: | Information exposure vulnerability in RT software affecting version | 4.4.1. This vulnerability allows an

Bug#1068461: freeimage: CVE-2024-28562 CVE-2024-28563 CVE-2024-28564 CVE-2024-28565 CVE-2024-28566 CVE-2024-28567 CVE-2024-28568 CVE-2024-28569 CVE-2024-28570 CVE-2024-28571 CVE-2024-28572 CVE-2024-28

2024-04-05 Thread Moritz Mühlenhoff
Source: freeimage X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for freeimage. They are all only published at https://github.com/Ruanxingzhi/vul-report/tree/master/freeimage-r1909 and don't appear to be forwarded

Bug#1054514: (subset) [PATCH v2 1/1] Revert "drm/qxl: simplify qxl_fence_wait"

2024-04-05 Thread Maxime Ripard
On Thu, 04 Apr 2024 19:14:48 +0100, Alex Constantino wrote: > This reverts commit 5a838e5d5825c85556011478abde708251cc0776. > > Changes from commit 5a838e5d5825 ("drm/qxl: simplify qxl_fence_wait") would > result in a '[TTM] Buffer eviction failed' exception whenever it reached a > timeout. > Due

Bug#1068448: RFS: cairo-dock-plug-ins/3.4.1+git20201022.a0d3415c-1.2 [NMU] [RC] -- Cairo-dock - All plug-ins

2024-04-05 Thread Daniel Kondor
Package: sponsorship-requests Severity: important Dear mentors, I am looking for a sponsor for my package "cairo-dock-plug-ins": * Package name : cairo-dock-plug-ins Version : 3.4.1+git20201022.a0d3415c-1.2 Upstream contact : Matthieu Baerts * URL :

Bug#1063077: syslog-ng: identified for time_t transition but no ABI in shlibs

2024-04-05 Thread Bernd Zeimetz
Hi Attila, On Fri, 2024-04-05 at 09:47 +0100, Attila Szalay wrote: > Based on https://wiki.debian.org/NonMaintainerUpload, the binNMU > should > be careful I think you are confusing binNMUs and NMUs. See https://wiki.debian.org/binNMU They are handled more or less automatic as soon as a rebuild

Bug#1068450: librist: FTBFS of reverse-dependencies with recent mbedtls [PATCH]

2024-04-05 Thread Gianfranco Costamagna
Package: librist Version: 0.2.10+dfsg-1 Severity: normal Tags: patch Hello, I found mbedtls support to be now enabled with mbedtls 2.28.8. So now the pkgconfig file includes it, and fails if it is missing. ffmpeg FTBFS due to it if librist gets rebuilt. diff -Nru

Bug#1063757:

2024-04-05 Thread matte . mb2006 . 9990
I removed the NVIDIA driver but the problem persists.

Bug#1068459: murano: CVE-2024-29156

2024-04-05 Thread Moritz Mühlenhoff
Source: murano X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for murano. CVE-2024-29156[0]: | In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, | the Murano service's MuranoPL extension to the YAQL

Bug#1068458: netdata: build and ship netdata-plugin-systemd-journal

2024-04-05 Thread Didier 'OdyX' Raboud
Source: netdata Version: 1.44.3-2 Severity: wishlist Dear Maintainer, it would be really useful to have netdata-plugin-systemd-journal, especially as a way to circumvent their future requirement to rely on their cloud offer:

Bug#1068456: RFP: aerospike-database -- Distributed, scalable NoSQL database that supports both strict and eventual consistency

2024-04-05 Thread Federico Ceratto
Package: wnpp Severity: wishlist * Package name: aerospike-database Version : 7.0.0.7 Upstream Contact: Aerospike * URL : https://aerospike.com/ * License : AGPL-3.0 Programming Lang: C Description : Distributed, scalable NoSQL database that supports

Bug#1068457: azure-uamqp-python: CVE-2024-29195

2024-04-05 Thread Moritz Mühlenhoff
Source: azure-uamqp-python X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for azure-uamqp-python. CVE-2024-29195[0]: | The azure-c-shared-utility is a C library for AMQP/MQTT | communication to Azure Cloud Services. This

Bug#1068455: varnish: CVE-2024-30156

2024-04-05 Thread Moritz Mühlenhoff
Source: varnish X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for varnish. CVE-2024-30156[0]: | Varnish Cache before 7.3.2 and 7.4.x before 7.4.3 (and before 6.0.13 | LTS), and Varnish Enterprise 6 before 6.0.12r6, allows

Bug#1068460: docker.io: CVE-2024-29018

2024-04-05 Thread Moritz Mühlenhoff
Source: docker.io X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for docker.io. CVE-2024-29018[0]: | Moby is an open source container framework that is a key component | of Docker Engine, Docker Desktop, and other

Bug#974750: imagemagick-6.q16: Convert to .tga (Targa) now flips image upside-down

2024-04-05 Thread Matija Nalis
related graphicsmagick bugreport: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1016653 -- Opinions above are GNU-copylefted.

Bug#1068192: debian-policy: extended forbidden network access to contrib and non-free

2024-04-05 Thread Holger Levsen
On Wed, Apr 03, 2024 at 10:58:37PM +0200, Aurelien Jarno wrote: > Thanks Philipp. Following that result, please find a patch proposal: > > --- a/policy/ch-source.rst > +++ b/policy/ch-source.rst > @@ -338,9 +338,9 @@ > For example, the build target should pass ``--disable-silent-rules`` > to

Bug#1068447: miniflux: [INTL:nl] Dutch debconf templates translation

2024-04-05 Thread Frans Spiesschaert
Package: miniflux Severity: wishlist Tags: l10n patch X-Debbugs-CC: Maytham Alsudany Dear Maintainer, Please find attached the updated Dutch translation of miniflux debconf messages. A draft has been posted to the debian-l10n-dutch mailing list allowing for review. Please add it

Bug#1068451: bookworm-pu: package libtommath/1.2.0-6+deb12u1

2024-04-05 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: libtomm...@packages.debian.org Control: affects -1 + src:libtommath Addresses CVE-2023-36328, debdiff below. Acked by Dominique before. Cheers, Moritz diff

Bug#1063757:

2024-04-05 Thread matte . mb2006 . 9990
I updated power-profiles-daemon to version 0.21-1 but the problem remains.  The value of "/sys/devices/system/cpu/intel_pstate/no_turbo" is 0, so the kernel supports turbo boost.  I specify that my laptop also has an NVIDIA GPU.

Bug#1068462: gpac: CVE-2024-28318 CVE-2024-28319 CVE-2023-46426 CVE-2023-46427 CVE-2024-24265 CVE-2024-24266 CVE-2024-24267

2024-04-05 Thread Moritz Mühlenhoff
Source: gpac X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for gpac. CVE-2024-28318[0]: | gpac 2.3-DEV-rev921-g422b78ecf-master was discovered to contain a | out of boundary write vulnerability via swf_get_string at |

Bug#1068063:

2024-04-05 Thread Andreas Hasenack
> 1. --- 0x2 != 0x1 >src/tests/cmocka/test_responder_cache_req.c:2505: error: Failure! > >assert_int_equal(test_ctx->result->count, 1); > > apparently there are 2 results returned while expected just one. This is because of time_t now being 64bits and a "%lu" format string is being used

Bug#1068463: procyon: Untrusted code execution via cwd in classpath

2024-04-05 Thread Tomas Tintera
Package: procyon-decompiler Version: 0.6.0-1 Tags: security Severity: grave In the default configuration, procyon prepends current working directory to the java classpath. This is done in the shell script /usr/bin/procyon, which sets, apparently by mistake, CLASSPATH=$CLASSPATH:..., where

Bug#1068464: deal.ii: FTBFS: libgmp not linked, libdeal.ii.g.so.9.5.1: error: undefined reference to '__gmpn_neg'

2024-04-05 Thread Drew Parsons
Source: deal.ii Version: 9.5.1-2 Severity: normal Tags: ftbfs I'm getting an error running deal.ii tests building against petsc 3.20 (from experimental) [100%] Built target dealii_release make -f tests/CMakeFiles/test.dir/build.make tests/CMakeFiles/test.dir/depend make[5]: Entering directory

Bug#1027405: regina-rexx FTCBFS: builds for the build architecture

2024-04-05 Thread Agustin Martin
El mar, 2 abr 2024 a las 13:49, Helmut Grohne () escribió: > On Fri, Mar 29, 2024 at 01:29:04PM +0100, Agustin Martin wrote: > > > However, there is another problem with other arches (e.g. arm64). Some > > binary files containing compiled error messages are built with a > > locally built program

Bug#1033352: sbuild: autokpgtest-virt-server needs host $HOME

2024-04-05 Thread Christian Kastner
On 2024-02-21 09:22, Christian Kastner wrote: > On 2024-02-21 08:02, Johannes Schauer Marin Rodrigues wrote: >> is this a duplicate of #1061388? > > I *think* so, but I'm not sure. > > The cause definitely seems to be the same: on the host, prior to opening > the chroot, $HOME is set to

Bug#1068449: opentracker: libowfat headers have moved

2024-04-05 Thread Bastian Germann
Source: opentracker Version: 0.0~git20210823.110868e-8 Severity: important The package will start to FTBFS when the fix for #932313 arrives. The headers hove to a new place, so opentracker needs to be modified. The debdiff is included. opentracker_0.0~git20210823.110868e-8.1.debdiff Description:

Bug#783011: Skip /etc/awstats/awstats.conf if it's not configured

2024-04-05 Thread Christian Weiske
I created several awstats.mydomain.conf files which all include the default awstats.conf file as base config. I'd prefer that awstats.conf is skipped once domain config files exist. -- Regards/Mit freundlichen Grüßen Christian Weiske

Bug#1064593: issue with Debian-style html theme for sphinx-based documents

2024-04-05 Thread Holger Wansing
Hi, Holger Wansing wrote (Tue, 2 Apr 2024 14:47:12 +0200): > We need a separate copy of 3 packages in our www build tree on > wolkenstein and all www static mirrors (simply let DSA install those > packages on the machines will not work). > And every sphinx-based manual needs relative symlinks in

Bug#1065221: Packaging multivolumefile?

2024-04-05 Thread Andreas Tille
Hi Yokota, Am Tue, Apr 02, 2024 at 08:39:36PM +0200 schrieb Andreas Tille: > > Nevermind, YOKOTA Hiroshi already has done this and more and is looking > > for sponsors. > > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1065221#17 > > Thanks a lot for your packaging work. My very personal

Bug#1068468: tracker: failing autopkgtest

2024-04-05 Thread Jeremy Bícha
Source: tracker Version: 3.7.1-1 Severity: serious Forwarded: https://gitlab.gnome.org/GNOME/tracker/-/issues/434 tracker's autopkgtest began failing after the update from 3.7.0 to 3.7.1. This is preventing tracker from being eligible for migration to Testing. I have reported the issue upstream.

Bug#1061051: RFS: notes-tree/1.2-1 -- a note taking app, which organizes notes in a hierarchical structure

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo There are quite a lot of issues reported by lintian so you should fix at least those before looking for sponsorship. The biggest problem is debian/changelog. Please remove the moreinfo tag after these are addressed. -- WBR, wRAR signature.asc Description: PGP

Bug#1058766: RFS: rdiffweb/2.8.7.dev41+g849af0c+dfsg-1 [ITP] -- web interface to rdiff-backup repositories

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo On Fri, Dec 15, 2023 at 03:36:19PM -0500, Patrik Dufresne wrote: > dget -x > https://mentors.debian.net/debian/pool/main/r/rdiffweb/rdiffweb_2.8.7.dev41+g849af0c+dfsg-1.dsc > > Changes for the initial release: > > rdiffweb (2.8.7.dev41+g849af0c+dfsg-1) unstable;

Bug#1058016: RFS: wasix-libc/0.0~git20230922.d0362cb-1 [ITP] -- wasix libc implementation for WebAssembly

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo Some issues found after a quick review: - It should have only one changelog entry. - Pre-built libclang_rt.builtins-wasm32.a should be removed from the orig.tar, assuming it's not used in the build process. - debian/rules hardcodes llvm-*-16 and clang-16 but B-D are

Bug#1065221: Packaging multivolumefile?

2024-04-05 Thread yokota
Hi Andreas, Thanks a lot for your detailed document. I will try to fixup other packages. PS: If py7zr is done, I will also try package pychm to use for Debian Calibre package. Please sponsor me for pychm package if you have time. > O: pychm -- Python binding for CHMLIB - Python 3 >

Bug#1068117: dieharder: dab_monobit2 crashes with ntuple > 17

2024-04-05 Thread Dirk Eddelbuettel
Hi Lucas, On 30 March 2024 at 22:47, Lucas Thode wrote: | Package: dieharder | Version: 3.31.1.4-1.1 | Severity: normal | X-Debbugs-Cc: thode...@gmail.com | | Dear Maintainer, | | `dieharder -d 209 -n $nvalue` crashes for $nvalue>17: | | $ dieharder -d 209 |

Bug#1013361: Fwd: future of rwhod/rwho/ruptime, and a shell implementation of it called ruptime

2024-04-05 Thread Gürkan Myczko
just to keep all information together… Begin forwarded message: > From: Gürkan Myczko > Date: May 24, 2023 at 20:43:49 GMT+2 > To: debian-de...@lists.debian.org > Subject: future of rwhod/rwho/ruptime, and a shell implementation of it > called ruptime > > hello > > i've always liked the

Bug#1061087: RFS: bash-unit/2.1.0-1 [RFP] -- bash_unit - bash unit testing

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo Control: retitle -1 RFS: bash-unit/2.1.0-1 [ITP] -- bash_unit - bash unit testing Some issues found after a quick review: - The package should be arch:all and shouldn't use ${shlibs:Depends}. - The GPL-3 snippet in d/copyright looks wrong. - The upstream docs should

Bug#1064975: RFS: k3conf/0.3-1 [ITP] -- Powerful Diagnostic Tool for Texas Instruments K3 based Processors

2024-04-05 Thread Andrey Rakhmatullin
I have several suggestions for this: - Can you provide debian/watch? It should be possible. - debian/k3conf.1 has a *roff warning, lintian also catches it. -- WBR, wRAR signature.asc Description: PGP signature

Bug#1066870: RFS: libudis86/0~20221013-1 [ITP] -- Disassembler for x86 and x86-64 class ISA

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo The package FTBFS: /bin/bash: line 1: /usr/bin/python3: No such file or directory Also, debian/watch is empty but present and I'm not sure about __AUTO_PERMISSIVE__ and __UNKNOWN__ in debian/copyright. -- WBR, wRAR signature.asc Description: PGP signature

Bug#1068473: icinga2: crashes on startup on ppc64el

2024-04-05 Thread Aurelien Jarno
Source: icinga2 Version: 2.13.6-2 Severity: grave Justification: renders package unusable X-Debbugs-Cc: d...@debian.org Control: fixed -1 icinga2/2.14.2-1 Dear maintainer, DSA has issues running icinga2 on ppc64el on Bookworm, it fails with a segmentation fault just after startup: | ×

Bug#1067453: gnat: Ada.Calendar.Clock crashes on time_t64 architectures

2024-04-05 Thread Nicolas Boulenguez
Source: gcc-13 Followup-For: Bug #1067453 Hello. In case anyone tries to build attempt3 at https://gcc.gnu.org/bugzilla/show_bug.cgi?id=114065 in Debian, please: * disable debian/patches/libgnat-time64.diff in debian/rules.patch * adapt the current ada-lib-info-source-date-epoch.diff ---

Bug#1068155: lmms: FTBFS on i386: dh_install: warning: Cannot find (any matches for) "usr/lib/*/lmms/libvestige.so" (tried in ., debian/tmp)

2024-04-05 Thread Dmitry Shachnev
Control: reassign -1 libwine-dev 9.0~repack-4 Control: affects -1 + src:lmms Hi all, On Tue, Apr 02, 2024 at 12:16:09PM +0200, Andreas Beckmann wrote: > Comparing bookworm and sid buildlogs shows the following relevant > differences during cmake: > > -Setting up libwine-dev:i386 (8.0~repack-4)

Bug#411059: sash: bad practice of multiple accounts with uid==0 lead to broken system

2024-04-05 Thread Michael Tokarev
Control: title -1 nscd caches "wrong" name for accounts with the same uid Control: found -1 2.37-15 Rehashing this 17-years old bug which biten me today quite hard. On Mon, 12 Feb 2007 22:55:28 -0500 Yaroslav Halchenko wrote: Today, after unsucsessful attempt to login as sashroot, I've got

Bug#1056156: varnish: CVE-2023-44487: VSV00013 Varnish HTTP/2 Rapid Reset Attack

2024-04-05 Thread Salvatore Bonaccorso
Hi Marco, On Thu, Apr 04, 2024 at 11:05:03AM +0200, Marco d'Itri wrote: > On Apr 04, Salvatore Bonaccorso wrote: > > > While I do agree (and it was filled with this severity), the bug > > severity would not be RC, varnish currently seem to lack active > > maintainership. > Not anymore:

Bug#1068474: yforth segfaults immediately on launching

2024-04-05 Thread Sudip Mukherjee
Source: yforth Version: 0.2.1-1 Severity: important X-Debbugs-Cc: sudipm.mukher...@gmail.com Dear Maintainer, yforth is causing a segfault immediately on startup. $ yforth yForth? v0.2 Copyright (C) 2012 Luca Padovani This program comes with ABSOLUTELY NO WARRANTY. This is free software, and

Bug#411059: sash: bad practice of multiple accounts with uid==0 lead to broken system

2024-04-05 Thread Aurelien Jarno
On 2024-04-05 21:59, Michael Tokarev wrote: > Control: title -1 nscd caches "wrong" name for accounts with the same uid > Control: found -1 2.37-15 > > Rehashing this 17-years old bug which biten me today quite hard. > > On Mon, 12 Feb 2007 22:55:28 -0500 Yaroslav Halchenko > wrote: > > > >

Bug#1051402: emacspeak fails byte-compile during install or upgrade since emacs 29

2024-04-05 Thread Michiel
I believe this specific issue (emacspeak-proced.el:156:4: Error: Misplaced t or ‘otherwise’ clause) is fixed upstream by this commit: https://github.com/tvraman/emacspeak/commit/806c044b08ccf8c53ce744a1578103037c622048 Hope this helps in some way, Michiel

Bug#1065222: Adopting pychm (Was: Packaging multivolumefile?)

2024-04-05 Thread Andreas Tille
Hi Hiroshi, Am Sat, Apr 06, 2024 at 02:51:51AM +0900 schrieb yokota: > Thanks a lot for your detailed document. You are welcome. > I will try to fixup other packages. Just ping me once done. > PS: > If py7zr is done, I will also try package pychm to use for Debian > Calibre package. > Please

Bug#1066112: weston: Enable support to libseat launcher in weston 10

2024-04-05 Thread Carlos Henrique Lima Melara
Hi, On Fri, Apr 05, 2024 at 09:28:02PM +0200, Dylan Aïssi wrote: > Hi, > > Le ven. 5 avr. 2024 à 16:00, Dylan Aïssi a écrit : > > Meanwhile, I pinged upstream to ask for their opinion about > > that to make sure we are not going to break stuff. > > launcher-libseat has an higher priority than

Bug#1059643: RFS: wstroke/2.1-1 [ITP] -- Mouse gesture plugin for Wayfire.

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo Some issues found after a quick review: - There are many issues listed by lintian such as outdated compat level, outdated Standards-Version, an issue with the short description, missing Rules-Requires-Root. - There should be only one changelog entry, and in

Bug#1068470: xorg-server: double free in fix for CVE-2024-31083

2024-04-05 Thread Julien Cristau
Source: xorg-server Version: 2:21.1.11-3 Severity: grave Tags: security upstream patch Justification: user security hole X-Debbugs-Cc: jcris...@debian.org, Debian Security Team The latest security fixes introduced a regression, apparently replacing use-after-free with double-free in some

Bug#1068469: O: gtksheet -- Gtk spreadsheet widget

2024-04-05 Thread Bastian Germann
Package: wnpp I am hereby orphaning gtksheet. I have packaged it to get lepton-eda building with gtk3 but do not have any longer-term interest in the package. Please consider adopting.

Bug#1068412: [ftpmas...@ftp-master.debian.org: Accepted apache2 2.4.59-1 (source) into unstable]

2024-04-05 Thread Salvatore Bonaccorso
Source: apache2 Source-Version: 2.4.59-1 - Forwarded message from Debian FTP Masters - -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Fri, 05 Apr 2024 08:08:11 +0400 Source: apache2 Built-For-Profiles: nocheck Architecture: source Version: 2.4.59-1 Distribution:

Bug#1068471: winff: shell injection

2024-04-05 Thread Jakub Wilk
Package: winff Version: 1.6.3+dfsg-2 Tags: security As a follow-up to #1053373, WinFF still doesn't correctly escape filenames it passes to shell. To reproduce, try converting the file created by this command: touch '\"; cowsay pwned >&2 #.mp3' -- System Information: Architecture: i386

Bug#1053245: fluidsynth: Fluidsynth starts at boot and blocks the sound device, no obvious way to disable it

2024-04-05 Thread Patrice Duroux
Package: fluidsynth Version: 2.3.4-1+b3 Followup-For: Bug #1053245 Hi, I am also having trouble with its systemd service. 1. it seems to fail when opening my user session: avril 05 19:48:44 kos-moceratops systemd[2775]: Listening on pipewire- pulse.socket - PipeWire PulseAudio. avril 05

Bug#1068465: plugin thunderbird_labels and keyboard_shortcuts causing traces

2024-04-05 Thread Christian Schwamborn
Package: roundcube-plugins-extra Version: 1.4.10+1-4 I got an error like this, trying to set a message Flag: [05-Apr-2024 15:16:54 UTC] PHP Warning: Undefined property: rcmail::$imap in /usr/share/roundcube/plugins/thunderbird_labels/thunderbird_labels.php on line 318 [05-Apr-2024 15:16:54 UTC]

Bug#1064672: virt-manager: FTBFS: AssertionError: Command was: ./virt-xml test-for-virtxml --add-device --host-device 0x04b3:0x4485 --update --confirm --debug --connect __virtinst_test__test:///<

2024-04-05 Thread Fabio Fantoni
libvirt 10.1.0 uploaded some days after my patch introduced new issue, I gave a fast look to upstream git but I didn't found a possible fix and I don't have enough time to check better and try to fix OpenPGP_signature.asc Description: OpenPGP digital signature

Bug#1068472: RM: onedrivesdk -- ROM; deprecated upstream; RC-buggy; leaf package

2024-04-05 Thread Bastian Germann
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: onedrive...@packages.debian.org Control: affects -1 + src:onedrivesdk Upstream has given up on the package and it doe not work with current Python versions, see #1025016. Please

Bug#1067569: RFS: libsmb2/4.0.0-1 [ITP]-- SMB2/3 client library

2024-04-05 Thread Andrey Rakhmatullin
Control: tags -1 + moreinfo You should provide a separate -dev package, currently the development files are shipped in the library package. There is a hardcoded Depends: libkrb5-3, why is this needed? There are unused files in debian/, such as libsmb2-dev.* and libsmb21.*. You should remove the

Bug#1068192: debian-policy: extended forbidden network access to contrib and non-freeo

2024-04-05 Thread Aurelien Jarno
On 2024-04-04 22:38, Bill Allombert wrote: > On Thu, Apr 04, 2024 at 01:22:19PM -0700, Russ Allbery wrote: > > I'm not sure what I think about that. We have a general escape hatch > > already for non-free packages in Policy 2.2.3 that says they may not fully > > comply with Policy, which may be

Bug#1068466: libvirt-daemon: libvirt-guests.sh cant connect to default on shutdown/reboot

2024-04-05 Thread invra
Package: libvirt-daemon Version: 9.0.0-4 Severity: important X-Debbugs-Cc: ix1kg8...@mozmail.com Dear Maintainer, It seems like there is some problem with the /usr/lib/libvirt/libvirt-guests.sh script. When rebooting/shutting down the system this message will appear: "libvirt-guests.sh cant

Bug#1068467: libgl1-mesa-dri: GPU hangs and resets while playing 3D games on Framework Laptop 13, AMD Ryzen 7640U

2024-04-05 Thread Ivan Stanton
Package: libgl1-mesa-dri Version: 23.3.5-1 Severity: important Dear Maintainer, I and some others have been unable to play 3D games or run GPU-intensive software on the Framework Laptop 13 AMD 7040 Edition due to GPU resets occurring while doing so. I've previously reported this to the Framework

  1   2   >