Bug#819616: RFP: portablesigner -- Tool to embed X.509 signatures in Portable Document Files (PDF)

2019-05-08 Thread Petter Reinholdtsen
I suspect the project now is located at https://github.com/pflaeging/PortableSigner2 >, but is not sure. https://nhs.io/pdf/ > explain how it can be used from the command line to sign PDFs. -- Happy hacking Petter Reinholdtsen

Bug#928697: RFP: node-evacuated-ethereum-client-binaries -- verifies/downloads ethereum client binaries

2019-05-08 Thread Jeff Cliff
Package: wnpp Severity: wishlist * Package name: node-evacuated-ethereum-client-binaries Version : 1.6.4 Upstream Author : Ramesh Nair * URL : http://g4o3i3uhqv2isv7yztojz3xc44zc5ncb5jklojm3qx7jaoadqvu4jtyd.onion/ * License : MIT Programming Lang: javascript

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Bernd Zeimetz
Am 9. Mai 2019 03:15:08 MESZ schrieb "Lisandro Damián Nicanor Pérez Meyer" : >On Wed, 8 May 2019 at 18:16, Bernd Zeimetz wrote: >> Am 8. Mai 2019 22:49:45 MESZ schrieb "Lisandro Damián Nicanor Pérez >Meyer" : >> >El mié., 8 may. 2019 17:42, Bernd Zeimetz escribió: >> > >> >> systemctl edit gp

Bug#927142: Cyrus-Imapd expel from Buster

2019-05-08 Thread Xavier
Hi all, I'm afraid to see that Cyrus-Imapd is going to be out of Buster. Sorry, I can't help here, but can this bug be considered as "important" instead of "serious" to avoid expel? Cheers, Xavier

Bug#928696: vulkan-loader has a dependecy cycle with googletest

2019-05-08 Thread Helmut Grohne
Source: vulkan-loader Version: 1.1.101.0-2 Severity: important Tags: patch User: helm...@debian.org Usertags: rebootstrap vulkan-loader Build-Depends on googletest, which Build-Depends on cmake, which uses qt, which libvulkan1. This is bad for bootstrapping. Fortunately, the dependency on googlete

Bug#928695: libcanary-stability-perl should not Build-Depends: devscripts

2019-05-08 Thread Helmut Grohne
Source: libcanary-stability-perl Version: 2006-1 Severity: important Tags: patch User: helm...@debian.org Usertags: rebootstrap libcanary-stability-perl Build-Depends on devscripts. The (very old) build log of the only ever build shows that it uses licensecheck. licensecheck now moved to its own p

Bug#928694: ITP: libyahc-perl -- Yet another HTTP client

2019-05-08 Thread merkys
Package: wnpp Owner: Andrius Merkys Severity: wishlist * Package name    : libyahc-perl   Version : 0.035   Upstream Author : Ivan Kruglov * URL : https://metacpan.org/release/YAHC * License : MIT   Programming Lang: Perl   Description : Yet another HTTP client  Y

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Norbert Preining
On Thu, 09 May 2019, Marc Lehmann wrote: > Again, the problem in this bug report almost certainly stem from calibre > not removing the .pyc files - the .py files were duly removed by dpkg, But it *removes* the files. I tried it as I wrote. There were .pyc files, and after dpkg --purge calbire the

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Marc Lehmann
On Thu, May 09, 2019 at 11:45:05AM +0900, Norbert Preining wrote: > > to create those files, running calibre as root suffices which is hardly > > impossible, and is exactly what has happened in this case. > > Well, that is something that is not to be expected. And I guess that a > lot of other p

Bug#236857: (no subject)

2019-05-08 Thread dipakdipak44555
DIPAK BARIA vivo સ્માર્ટફોનથી મોકલાયેલ

Bug#928680: [openfortivpn] Since switching to buster openfortivpn can't connect to vpn anymore

2019-05-08 Thread Daniel Echeverry
tags 928680 + moreinfo unreproducible severity 928680 normal thanks Hi! El mié., 8 de may. de 2019 a la(s) 14:15, Michael Meier (c...@rmm.li) escribió: > Package: openfortivpn > Version: 1.8.1-1 > Severity: normal > > I've installed the fortivpn package in debian stable (stretch), and > managed

Bug#928429: dpkg: trigger cycle postgresql-common -> sgml-base while upgrading from stretch to buster

2019-05-08 Thread Guillem Jover
Hi! On Sat, 2019-05-04 at 15:13:58 +0200, Andreas Beckmann wrote: > Package: dpkg > Version: 1.19.6 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > Control: affects -1 + education-desktop-gnome education-desktop-mate > education-desktop-xfce education-main-server edu

Bug#910783: Remove doc-base recommendation

2019-05-08 Thread Paul Wise
On Thu, 11 Oct 2018 17:32:52 -0700 Sean Whitton wrote: > Instead, if there is indeed consensus, we should change it so that it > no longer says that doc-base registration is recommended. We need a cross-distro cross-desktop standard for an index of docs before we can move on from doc-base like we

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Norbert Preining
Hi On Thu, 09 May 2019, Marc Lehmann wrote: > I delete them, calibre recreates them. If you start calibre as root, yes. That is nothing I can do against it. If you start it as non-root, you don't have write permissions. I just *tried* it. > to create those files, running calibre as root suffice

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Marc Lehmann
On Thu, May 09, 2019 at 11:24:15AM +0900, Norbert Preining wrote: > > the .pyc files on first start rather than in post-install (as per policy) > > and > > doesn't remove the files in the pre-remove script (as required by policy). > > How do you come to this assumption? I delete them, calibre

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Norbert Preining
Hi Marc, > I think the reason is that calibre writes files to /usr/lib/calibre on > startup that debian doesn't know about. E.g. in a fresh install: No, not startup. > and after starting calibre, it creates .pyc files: It is the postinst that does that, calling pycompile. > The original proble

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Norbert Preining
> the .pyc files on first start rather than in post-install (as per policy) and > doesn't remove the files in the pre-remove script (as required by policy). How do you come to this assumption? It is in fact impossible, since nothing in calibre is setuid, so a normal user cannot create files in /us

Bug#928693: clang-7: Using --coverage causes "/usr/bin/ld: …: hidden symbol `llvm_gcda_end_file'" error

2019-05-08 Thread James McCoy
Package: clang-7 Version: 1:7.0.1-8 Severity: normal This is easily demonstrated with the libvterm package. $ debcheckout libvterm … $ cd libvterm $ env CC=clang-7 CFLAGS=--coverage make VERBOSE=1 TBL src/encoding/DECdrawing.tbl TBL src/encoding/uk.tbl CC src/encoding.c libtool: compile: clang-7

Bug#928692: lxde: Wicd no longer maintained upstream - should not be default any longer

2019-05-08 Thread Karl Sickendick
Package: lxde Version: 10 Severity: wishlist Dear Maintainer, Wicd currently gets installed as the default network management daemon and tool when LXDE is selected during Debian install. It has a number of bugs that affect basic usability, and the upstream devs are no longer maintaining it. I th

Bug#928497: Acknowledgement (nvidia-persistenced: Error in nvidia-persistenced source (postinst))

2019-05-08 Thread Marcelo Téc .
Using the Debian Stretch plus SID Source repository and satisfying all the dependencies required for a build, everything happens perfectly. The installation of the packages after the compilation is perfect, the modules work correctly. However, in my first compilation of the nvidia-persistenced pack

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Marc Lehmann
After looking at the debian python policy (I don't grok python) this seems pretty obvlously caused by multiple bugs in calibre, namely that it creates the .pyc files on first start rather than in post-install (as per policy) and doesn't remove the files in the pre-remove script (as required by poli

Bug#865879: calibre creates .pyc files in /usr/lib on startup

2019-05-08 Thread Marc Lehmann
I think the reason is that calibre writes files to /usr/lib/calibre on startup that debian doesn't know about. E.g. in a fresh install: ls -l /usr/lib/calibre/calibre -rw-r--r-- 1 root root 10072 Feb 8 09:41 constants.py -rw-r--r-- 1 root root 15317 Feb 8 09:41 debug.py -rw-r--r--

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Lisandro Damián Nicanor Pérez Meyer
On Wed, 8 May 2019 at 18:16, Bernd Zeimetz wrote: > Am 8. Mai 2019 22:49:45 MESZ schrieb "Lisandro Damián Nicanor Pérez Meyer" > : > >El mié., 8 may. 2019 17:42, Bernd Zeimetz escribió: > > > >> systemctl edit gpsd.service > >> > >> Just use common knowledge. > >> > > > >I don't think that's com

Bug#928691: i2p: New version avalable

2019-05-08 Thread Moshe Piekarski
Package: i2p Version: 0.9.38-3.1 Severity: normal -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Please update to i2p version 0.9.40 Thank you for your time. - -- System Information: Debian Release: buster/sid APT prefers testing APT policy: (990, 'testing'), (400, 'unstable') Architecture:

Bug#928026: security support for golang packages in Buster

2019-05-08 Thread Paul Wise
On Wed, May 8, 2019 at 2:45 PM Paul Gevers wrote: > With respect to binNMU'ing, static linking is not a problem, only > arch:all is. Most haskell (4 vs 1048) and ocaml (21 vs 233) aren't > arch:all. haskell and ocaml have a framework in place to at least know > the status in unstable/testing. See

Bug#928687: remmina: Segfaults when recommends is missing on connection

2019-05-08 Thread Bernhard Übelacker
Control: tags 928687 + upstream patch Dear Maintainer, this could be reproduced from a stored RDP connection entry, while the plugin is uninstalled. With the dbgsym package installed the backtrace looks like below. Unfortunately the null pointer in gp->priv->plugin seems to get unconditionally d

Bug#928690: ITP: libsmithlab -- low-level code collection for computational biology

2019-05-08 Thread Steffen Moeller
Package: wnpp Severity: wishlist Owner: Steffen Moeller * Package name: libsmithlab * URL : https://github.com/smithlabcode/smithlab_cpp * License : GPL Programming Lang: C++ Description : low-level code collection for computational biology To be team-maintained o

Bug#928689: initramfs-tools: Fails with "cp: failed to access '/var/tmp/mkinitramfs_URATxd//usr/bin/touch': Too many levels of symbolic links"

2019-05-08 Thread Axel Beckert
Package: initramfs-tools Version: 0.133 Severity: serious Control: affects -1 + fsprotect On an i386 Sid system (non-usrmerge and sysvinit-core), generating the initramfs fails as follows for at least every kernel installed or upgraded since the problem appeared the first time a while ago: /etc/k

Bug#915830: busybox: cp: failed to access '/var/tmp/mkinitramfs_h8da2B//usr/bin/busybox': Too many levels of symbolic links

2019-05-08 Thread Axel Beckert
Hi Ben, Ben Hutchings wrote: > > /etc/kernel/postinst.d/initramfs-tools: > > update-initramfs: Generating /boot/initrd.img-4.19.0-4-686-pae > > cp: failed to access '/var/tmp/mkinitramfs_URATxd//usr/bin/touch': Too many > > levels of symbolic links > > E: /usr/share/initramfs-tools/hooks/fsprotec

Bug#928684: [Pkg-privacy-maintainers] Bug#928684: monkeysphere-host import-key broken due to ssh-keygen change

2019-05-08 Thread Daniel Kahn Gillmor
Control: unarchive 909700 Control: forcemerge 909700 928684 Control: severity 909700 grave Hi Andrei-- On Wed 2019-05-08 20:45:24 +, Andrei Morgan wrote: > # monkeysphere-host import-key /etc/ssh/ssh_host_rsa_key > ssh://server.example.net > RSA.xs:194: OpenSSL error: no start line at /usr/b

Bug#928686: systemd: XFS filesystem errors when using systemd suspend-then-hibernate target

2019-05-08 Thread Michael Biebl
Am 08.05.2019 um 23:06 schrieb Shubhra Prakash Nandi: > Package: systemd > Version: 241-3 > Severity: important > > Dear Maintainer, > > I saw XFS errors in syslog as given below when I updated suspend target in > logind.conf to use suspend-then-hibernate instead. > These errors do not appear w

Bug#923309: cacti-spine_1.1.37-2~bpo9+1 fails to run under non-root user

2019-05-08 Thread Paul Allen
Sorry for the late reply, work became insane after this. I upgraded to the new cacti-spine again and ran the setcap command and it is working for the non-root user now. Thanks for the assistance on this. The bug can now be closed. Paul Allen Inetz Sr. Systems Administrator 801-415-2562 On 3/14/

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Bernd Zeimetz
Am 8. Mai 2019 22:49:45 MESZ schrieb "Lisandro Damián Nicanor Pérez Meyer" : >El mié., 8 may. 2019 17:42, Bernd Zeimetz escribió: > >> systemctl edit gpsd.service >> >> Just use common knowledge. >> > >I don't think that's common knowledge, but I would consider this half >ok if >a proper Readm

Bug#928688: drupal7: Insecure deserialization on bundled third-party library "Phar Stream Wrapper" (SA-CORE-2019-007)

2019-05-08 Thread Gunnar Wolf
Package: drupal7 Version: 7.52-2+deb9u8 Severity: grave Tags: security upstream Justification: user security hole Drupal security advisory SA-CORE-2019-007 was issued today: https://www.drupal.org/SA-CORE-2019-007 It refers to the following advisory in a bundled third-party library: htt

Bug#928675: debhelper: dh_dwz fails on /usr/bin/slt (it has no .debug_info section)

2019-05-08 Thread Niels Thykier
Control: tags -1 moreinfo Daniel Kahn Gillmor: > Package: debhelper > Version: 12.1.1 > Severity: normal > > using debhelper 12 on the slt package, i get the following error: > >dh_dwz -O--buildsystem=golang > dh_dwz: dwz -q -- debian/slt/usr/bin/slt returned exit code 1 > make: *** [debian/

Bug#928687: remmina: Segfaults when recommends is missing on connection

2019-05-08 Thread D Haley
Package: remmina Version: 1.3.3+dfsg-2 Severity: normal Dear Maintainer, I recently upgraded to buster, and during the process remmina-plugin-rdp was removed, but not the main remmina package (I was removing orphan packages, and I recall seeing it being removed). I tried to use remmina to conne

Bug#928622: autodep8 integration with dh

2019-05-08 Thread Daniel Kahn Gillmor
On Wed 2019-05-08 21:25:50 +0200, Paul Gevers wrote: > """ > Automatic test control file for known package types > --- > > There are groups of similarly-structured packages for which the contents > of ``debian/tests/control`` would be mostly identical

Bug#914034: Bug#911938: libhttp-daemon-ssl-perl FTBFS: tests fail: Connection refused

2019-05-08 Thread Dimitri John Ledkov
On Tue, 7 May 2019 19:39:15 +0200 Guilhem Moulin wrote: > Hi Dimitri, > > On Tue, 07 May 2019 at 15:46:25 +0100, Dimitri John Ledkov wrote: > > On Tue, 7 May 2019 14:16:43 +0100 Dimitri John Ledkov > > wrote: > >> This issue concerns me a lot at the moment. I am currently trying to > >> upgrade

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Lisandro Damián Nicanor Pérez Meyer
El mié., 8 may. 2019 17:42, Bernd Zeimetz escribió: > systemctl edit gpsd.service > > Just use common knowledge. > I don't think that's common knowledge, but I would consider this half ok if a proper Readme.Debian would be provided. But again, the way you "fixed" the behavior is not right. Wou

Bug#928684: monkeysphere-host import-key broken due to ssh-keygen change

2019-05-08 Thread Andrei Morgan
Package: monkeysphere Version: 0.43-2 Severity: grave Tags: upstream a11y Justification: renders package unusable Dear Maintainer, On a fresh new install of Debian Buster, I was trying to set up monkeysphere to allow ssh access: # monkeysphere-host import-key /etc/ssh/ssh_host_rsa_key ssh://ser

Bug#928685: unblock: movim/0.14.1-5

2019-05-08 Thread Dominik George
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please unblock package movim The attached debdiff fixes both an important (and mildly security-relevant bug) in what directories the webserv

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Bernd Zeimetz
systemctl edit gpsd.service Just use common knowledge. Bernd Am 8. Mai 2019 22:14:33 MESZ schrieb "Lisandro Damián Nicanor Pérez Meyer" : >El mié., 8 may. 2019 16:39, Bernd Zeimetz escribió: > >> Hi, >> >> gpsd is socket activated by default. It is not supposed to start on >its >> own. >> >

Bug#927747: [Pkg-samba-maint] Bug#927747: bind9_dlz backend is entirely broken in Debian

2019-05-08 Thread Steinar H. Gunderson
On Wed, May 08, 2019 at 10:02:46PM +0200, Mathieu Parent wrote: > Downgrading the severity as the AppArmor side is already fixed it seems in > sid. serious and grave are of equal severity; serious is for Policy violations (e.g. package doesn't install), grave is for functionality issues (e.g. pro

Bug#908747: Default -I and -i option should not exclude .ignore

2019-05-08 Thread Ian Jackson
Simon McVittie writes ("Re: Bug#908747: Default -I and -i option should not exclude .ignore"): > I didn't implement this feature, so I could be wrong, but my understanding > is that the rationale for making it convenient to ignore .gitignore, > .bzrignore and friends is: I think in fact that it w

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Lisandro Damián Nicanor Pérez Meyer
El mié., 8 may. 2019 16:39, Bernd Zeimetz escribió: > Hi, > > gpsd is socket activated by default. It is not supposed to start on its > own. > Except when one wants to use gpsd as a time source (I do). In this case I need gpsd to start at boot time without any clients.

Bug#928683: ITP: perl6-openssl -- OpenSSL bindings for Perl 6

2019-05-08 Thread Robert Lemmen
Package: wnpp Severity: wishlist Owner: Robert Lemmen * Package name: perl6-openssl Version : 0.1.22 Upstream Author : Filip Sergot and others * URL : https://github.com/sergot/openssl * License : MIT Programming Lang: Perl 6 Description : OpenSSL bind

Bug#927747: [Pkg-samba-maint] Bug#927747: bind9_dlz backend is entirely broken in Debian

2019-05-08 Thread Mathieu Parent
severity 927747 serious thanks Le mar. 23 avr. 2019 à 23:12, Steinar H. Gunderson a écrit : > > On Tue, Apr 23, 2019 at 10:24:54PM +0200, Mathieu Parent wrote: > > There are several issues here. Trying a summary. > > 1. We need to patch bind9 apparmor profile (this is the cloned bug) > > Yes. >

Bug#866715: keepassx: KeepassX 2.x shouldn't automatically replace older versions

2019-05-08 Thread marjan cinober
Hi guys See https://bugs.debian.org/812110#25 I believe this solves your problem. Warm regards On Sat, 1 Jul 2017 11:44:24 -0400 Reinhard Tartler wrote: > Hi Victor, > > thank you for your bugreport. > > On 07/01/2017 02:59 AM, Victor Wagner wrote: > > Package: keepassx > > Version: 2.0.3-1 > >

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Bernd Zeimetz
Hi, gpsd is socket activated by default. It is not supposed to start on its own. Bernd Am 8. Mai 2019 21:15:34 MESZ schrieb "Lisandro Damián Nicanor Pérez Meyer" : >Source: gpsd >Version: 3.17-6 >Severity: important >Tags: patch > >Hi! I was debugging some instructions in gpsd-dev mailing lis

Bug#928622: autodep8 integration with dh

2019-05-08 Thread Paul Gevers
Hi Daniel, On 08-05-2019 13:21, Daniel Kahn Gillmor wrote: > That's news to me. I see no such documentation: Hmm. I should check my facts. You're right. What I meant was: """ Automatic test control file for known package types --- There are group

Bug#928682: botch: Recommend wget

2019-05-08 Thread Johannes 'josch' Schauer
Package: botch Version: 0.21-6 Severity: normal botch-download-pkgsrc uses wget and thus botch should at least recommend it

Bug#928612: u-boot-sunxi: Enable support for NanoPi NEO2

2019-05-08 Thread Domenico Andreoli
On Wed, May 08, 2019 at 06:28:28PM +0200, Domenico Andreoli wrote: > On Tue, May 07, 2019 at 09:50:58AM -0700, Vagrant Cascadian wrote: > > On 2019-05-07, Domenico Andreoli wrote: > > > Salsa MR #5 enables support for NanoPi NEO 2. I tested it with Buster > > > RC1 installer, althought it resulte

Bug#928681: gpsd.service files lacks WantedBy=multi-user.target

2019-05-08 Thread Lisandro Damián Nicanor Pérez Meyer
Source: gpsd Version: 3.17-6 Severity: important Tags: patch Hi! I was debugging some instructions in gpsd-dev mailing list and found out that gpsd.service was lacking some entries, due to: It turns out that this

Bug#928679: rinse: please update for Fedora 30

2019-05-08 Thread Eric Wong
Package: rinse Version: 3.4 Severity: wishlist I tried updating things myself by symlinking the existing post-install.sh and copying the package list from fedora-28, but it failed during the post-install. Anyways, this is the error I hit when I tried to update to Fedora 30 myself: Running post-i

Bug#928680: [openfortivpn] Since switching to buster openfortivpn can't connect to vpn anymore

2019-05-08 Thread Michael Meier
Package: openfortivpn Version: 1.8.1-1 Severity: normal I've installed the fortivpn package in debian stable (stretch), and managed to get it working with a vpn connection. Somewhen I updated my System to buster and now realized that openfortivpn can't connect to the vpn anymore. While another

Bug#810384: crda: /lib/crda/setregdomain fails with exit code 2, /sbin/crda with exit code 255

2019-05-08 Thread Thorsten Glaser
I ran into the same issue: May 8 20:31:30 tglase-nb vmunix: [ 13.348678] systemd-udevd[380]: Process '/lib/crda/setregdomain' failed with exit code 2. May 8 20:31:47 tglase-nb vmunix: [ 32.728410] systemd-udevd[2259]: Process '/sbin/crda' failed with exit code 255. I had only seen the crd

Bug#928678: Enable Remote DB Support

2019-05-08 Thread Thomas Ward
Source: xca Severity: wishlist Hello. The default package as-is does not allow for the use of Remote DB for the Certificates storage.  This means we only can use XCA Database 'flat files'. This differs from the Windows and Mac executables built upstream which include that support. This can be s

Bug#928172: debian-security-support: fails to upgrade from 'testing': dpkg: error: error executing hook

2019-05-08 Thread Holger Levsen
On Wed, May 08, 2019 at 02:06:20PM -0400, Gabriel Filion wrote: > so in order to unblock things one might want to run: > > apt purge debian-security-support > apt update && apt upgrade > apt install debian-security-support thanks for sharing this. I'll find time for the proper fix eventually - o

Bug#914094: This bug seems to be solved

2019-05-08 Thread Nikolaos Pantazis
Typo: *appearing (This bug stopped appearing on my system possibly after some resent update.)

Bug#928304: groonga-httpd: Privilege escalation due to insecure use of logrotate

2019-05-08 Thread Salvatore Bonaccorso
Hi, [please always include team@security.d.o as so any team member can reply] On Wed, May 08, 2019 at 12:03:49PM +0900, Hideki Yamane wrote: > Hi Salvatore, > > Can you follow his question? I guess debian revision should be > 6.1.5-1+deb9u1, but others are okay. I think updating groonga via

Bug#914094: This bug seems to be solved

2019-05-08 Thread Nikolaos Pantazis
This bug stopped spearing on my system possibly after some resent update.

Bug#928172: debian-security-support: fails to upgrade from 'testing': dpkg: error: error executing hook

2019-05-08 Thread Gabriel Filion
Hi again! On Tue, 7 May 2019 02:24:59 -0400 Gabriel Filion wrote: > On Mon, 29 Apr 2019 15:44:39 +0200 Santiago Vila wrote: > > On Mon, Apr 29, 2019 at 01:22:18PM +, Holger Levsen wrote: > > > if we now could please focus on #928172 and ignore #927450 for now, > > > that would be great. (and

Bug#928026: security support for golang packages in Buster

2019-05-08 Thread Moritz Muehlenhoff
On Wed, May 08, 2019 at 08:45:30AM +0200, Paul Gevers wrote: > > 2. binNMU without full source upload for security-master. > > > >It's still not possible, and I don't know there's any effort to > >change the dak. > > > >But I want to know how security team handles other static linked

Bug#928676: unblock: pesign/0.112-5

2019-05-08 Thread Steve McIntyre
Hi! Forgot to add - please *also* urgent this - it will be holding us up on submitting shim for review. Sorry... Steve On Wed, May 08, 2019 at 06:31:29PM +0100, Steve McIntyre wrote: >Package: release.debian.org >Severity: normal >User: release.debian@packages.debian.org >Usertags: unblock

Bug#928676: unblock: pesign/0.112-5

2019-05-08 Thread Steve McIntyre
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package pesign I've fixed a major bug in 0.112-5 which we need for building shim. Submitting our shim for review depends on building and testing in buster. The fix is a singl

Bug#928677: unblock: node-mqtt-packet/6.0.0-2

2019-05-08 Thread Xavier Guimard
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package node-mqtt-packet Hi all, node-mqtt-packet is vulnerable to CVE-2019-5432 (#928673). I imported upstream patch which changes only this on installed files: diff --g

Bug#923661: tt-rss: PHP Fatal error: Uncaught PDOException: SQLSTATE[22001]: String data, right truncated

2019-05-08 Thread Helmut Grohne
Control: severity -1 serious On Sun, Mar 03, 2019 at 01:33:36PM +0100, Stefan Fritsch wrote: > after upgrading from 16.8+git20160826+dfsg-3 (which I had run under > Debian stretch), tt-rss fails to display anything after the login page. > There is this error: > > [Sun Mar 03 13:15:12.954927 2019]

Bug#916690: marked as done (document getrandom changes causing entropy starvation)

2019-05-08 Thread Justin B Rye
> https://salsa.debian.org/ddp-team/release-notes/commit/5f76abd and > follow up commit. A couple of tweaks - -daemons fail to start or system appears to hang during boot +Daemons fail to start or system appears to hang during boot Other titles with initial lowercas

Bug#928674: RFP: evacuated-gulp -- a toolkit that helps you automate painful or time-consuming tasks in your development workflow.

2019-05-08 Thread Jeff Cliff
Package: wnpp Severity: wishlist * Package name: evacuated-gulp Version : 4.0.0.1 Upstream Author : Gulp Team (http://gulpjs.com/) * URL : http://f5eiybw5nxwr4t22k4n5lhwamudqsa3xp5hq33hiahogs4oa47ucl6id.onion/ * License : MIT Programming Lang: javascript D

Bug#928675: debhelper: dh_dwz fails on /usr/bin/slt (it has no .debug_info section)

2019-05-08 Thread Daniel Kahn Gillmor
Package: debhelper Version: 12.1.1 Severity: normal using debhelper 12 on the slt package, i get the following error: dh_dwz -O--buildsystem=golang dh_dwz: dwz -q -- debian/slt/usr/bin/slt returned exit code 1 make: *** [debian/rules:5: binary] Error 1 dpkg-buildpackage: error: debian/rules bi

Bug#928673: node-mqtt-packet: CVE-2019-5432

2019-05-08 Thread Salvatore Bonaccorso
Source: node-mqtt-packet Version: 6.0.0-1 Severity: grave Tags: security upstream Hi, The following vulnerability was published for node-mqtt-packet. CVE-2019-5432[0]: | A specifically malformed MQTT Subscribe packet crashes MQTT Brokers | using the mqtt-packet module versions < 3.5.1, 4.0.0 - 4

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-08 Thread Daniel Kahn Gillmor
On Wed 2019-05-08 09:36:04 -0700, Sean Whitton wrote: > I hope that it will remain possible to write shell scripts repeatedly > (and idempotently) calling `notmuch config` to set config values in the > database. That would be enough for my usecase to continue to work. for sure, i certainly want t

Bug#928672: firmware-misc-nonfree: please include GV100 signed firmware

2019-05-08 Thread Sven Joachim
Package: firmware-misc-nonfree Version: 20190502-1 For a while I have been seeing warnings from update-initramfs: , | # update-initramfs -u -k 4.19.0-5-amd64 | update-initramfs: Generating /boot/initrd.img-4.19.0-5-amd64 | W: Possible missing firmware /lib/firmware/nvidia/gv100/sec2/sig.bin f

Bug#928547: mailscripts: notmuch utilities should be better integrated into notmuch

2019-05-08 Thread Sean Whitton
Hello, On Wed 08 May 2019 at 07:24AM -04, Daniel Kahn Gillmor wrote: > On Tue 2019-05-07 11:19:44 -0700, Sean Whitton wrote: >> I consider my notmuch database just a cache; I do not store any >> nonreproducible data in it. I hope this usecase will continue to be >> supported. > > I'm surprised t

Bug#928026: security support for golang packages in Buster

2019-05-08 Thread Shengjing Zhu
On Wed, May 8, 2019 at 2:45 PM Paul Gevers wrote: > > Hi, > > On 27-04-2019 09:31, Shengjing Zhu wrote: > > Please CC debian...@lists.debian.org and me. > > Done. > > [...] > > > IIUC, there're two concerns for Go packages. > > [...] > > > 2. binNMU without full source upload for security-master.

Bug#928612: u-boot-sunxi: Enable support for NanoPi NEO2

2019-05-08 Thread Domenico Andreoli
Hi, On Tue, May 07, 2019 at 09:50:58AM -0700, Vagrant Cascadian wrote: > On 2019-05-07, Domenico Andreoli wrote: > > Salsa MR #5 enables support for NanoPi NEO 2. I tested it with Buster > > RC1 installer, althought it resulted in a non-bootable system u-boot > > worked well enough. > > Just fo

Bug#928660: hyperv-daemons matching linux-image-4.9-amd64 in jessie-security are missing

2019-05-08 Thread Ben Hutchings
Control: severity -1 wishlist Control: tag -1 wontfix Control: notfound -1 4.9.168-1 Control: found -1 3.16.64-2 On Wed, 2019-05-08 at 15:18 +0200, Christoph Martin wrote: > Package: hyperv-daemons > Version: 4.9.168-1 > > jessie-security has linux-image-4.9-amd64 but is missing the > correspondi

Bug#928671: --refuse-downgrade not honored when specified in dpkg.cfg

2019-05-08 Thread Roderich Schupp
Package: dpkg Version: 1.19.6 Severity: normal Scenario $ dpkg -l firefox ... ii firefox67.0~b18-0 amd64Mozilla Firefox web browser $ sudo dpkg --refuse-downgrade -i firefox_66.0.4-1_amd64.deb dpkg: will not downgrade firefox from 67.0~b18-0 to 66.0.4-1, skipping This is expe

Bug#915830: busybox: cp: failed to access '/var/tmp/mkinitramfs_h8da2B//usr/bin/busybox': Too many levels of symbolic links

2019-05-08 Thread Ben Hutchings
On Wed, 2019-05-08 at 00:27 +0200, Axel Beckert wrote: > Hi, > > > cp: failed to access '/var/tmp/mkinitramfs_mSMoqa//usr/bin/busybox': Too > > many levels of symbolic links > > E: /usr/share/initramfs-tools/hooks/zz-busybox failed with return 1. > > I'm having a very similar issue which makes m

Bug#928670: RFP: openocl -- Open Optimal Control Library

2019-05-08 Thread Alessandro Barbieri
Package: wnpp Severity: wishlist * Package name: openocl Version : 4.20 Upstream Author : Jonas Koenemann jonas.koenem...@yahoo.de * URL : https://openocl.org/ * License : GPL-3.0 Programming Lang: MATLAB/Octave Description : Open Optimal Control Library

Bug#928669: RFP: golang-github-erroneousboat-slack-term -- Slack client for your terminal

2019-05-08 Thread Alessandro Barbieri
Package: wnpp Severity: wishlist * Package name: golang-github-erroneousboat-slack-term Version : 0.4.1 Upstream Author : Jean Pieter Bruins Slot * URL : https://github.com/erroneousboat/slack-term/ * License : MIT Programming Lang: Go Description : Slac

Bug#928647: Solved...

2019-05-08 Thread Marco Gaiarin
Looking at similar traouble with OpenVPN, i've found: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=876979 and a similar solution seems to work also for arpwatch, eg it is needed to create the file: /etc/systemd/system/arpwatch.service.d/after-network-online.conf With the

Bug#928668: gnome-keyring: passphrase prompt in GNOME 3 does not take correct passphrase for ed25519 key

2019-05-08 Thread 魏銘廷
Package: gnome-keyring Version: 3.28.2-5 Severity: normal Maintainers, The passphrase prompt in GNOME3 cannot take correct passphrase if the ssh key is ed25519. Here's the procedure I tried: 1. Generate an ed25519 key with ssh-keygen 2. Copy the public key to a remote host 3. ssh to the remote

Bug#928667: ITP: r-cran-fontquiver -- set of installed fonts for GNU R

2019-05-08 Thread Andreas Tille
Package: wnpp Severity: wishlist Subject: ITP: r-cran-fontquiver -- set of installed fonts for GNU R Package: wnpp Owner: Andreas Tille Severity: wishlist * Package name: r-cran-fontquiver Version : 0.2.1 Upstream Author : Lionel Henry, * URL : https://cran.r-project.

Bug#928666: Want dgit FAQ

2019-05-08 Thread Ian Jackson
Package: dgit Version: 8.4 -- Ian JacksonThese opinions are my own. If I emailed you from an address @fyvzl.net or @evade.org.uk, that is a private address which bypasses my fierce spamfilter.

Bug#928386: syslinux: possible regression bug 'Undef symbol FAIL: memset'

2019-05-08 Thread Holger Levsen
Hi, On Mon, May 06, 2019 at 12:43:10AM +0200, Lukas Schwaighofer wrote: > Andreas Steinel wrote: > > In version 6.04~git20190206.bf6db5b4+dfsg1-1, the bug that was closed > > in 6.04~git20171011.af7e95c3+dfsg1-6 is back - at least in the 64-bit > > UEFI part, legacy works fine: thanks for the bu

Bug#928665: ITP: python-pybigwig -- read/write chromosomal sequence data in bigWig files

2019-05-08 Thread Steffen Moeller
Package: wnpp Severity: wishlist Owner: Steffen Moeller * Package name: python-pybigwig Version : 0.3.15 * URL : https://github.com/deeptools/pyBigWig * License : MIT Programming Lang: Python Description : read/write chromosomal sequence data in bigWig fi

Bug#907175: linux-image-4.9.0-8-686-pae: swapon() fails with "invalid argument", likely due to recent L1 terminal patch

2019-05-08 Thread William Salmon
Swap now loads OK with linux-image-4.9.0-8-686-pae Version: 4.9.144-3.1 (2019-02-19) - 32-bit on VMware (VM version 13) Bug fixed at some point between version 4.9.130-1 and Version: 4.9.144-3.1 (2019-02-19) - the last version of release linux-image-4.9.0-8-686-pae Thanks Will Salmon, Systems

Bug#816339: check: Making check/subunit bootstrappable

2019-05-08 Thread Helmut Grohne
Control: reassign -1 src:subunit Control: severity -1 important Control: tags -1 - pending On Tue, Mar 01, 2016 at 12:59:01AM +0100, Samuel Thibault wrote: > check build-depends on subunit, and subunit build-depends on check. It > happens that check has a disable flag against that build, but subun

Bug#928664: lua-system has a dependency cycle with lua-busted

2019-05-08 Thread Helmut Grohne
Source: lua-system Version: 0.2.1-1 Severity: important Tags: patch User: helm...@debian.org Usertags: rebootstrap lua-system Build-Depends on lua-busted, which happens to depend on lua-system. This poses a dependency cycle and makes bootstrapping either impossible. The upshot is that lua-system o

Bug#928663: unblock: piuparts/1.0.0

2019-05-08 Thread Holger Levsen
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock the package piuparts, the changes relevant to normal users of the packages are these: * piuparts.py: - Add '--merged-usr' support when using debootstrap to create th

Bug#908747: Default -I and -i option should not exclude .ignore

2019-05-08 Thread Simon McVittie
On Thu, 13 Sep 2018 at 15:57:48 +0100, Ian Jackson wrote: > Looking more narrowly, it seems to me that: including the .gitignore > (say) is sometimes helpful, and never harmful. So stripping it out is > simply a mistake. I didn't implement this feature, so I could be wrong, but my understanding i

Bug#905048: clamav-daemon: Missing -p argument in ExecStartPre (mkdir)

2019-05-08 Thread Robert Haist
Hi, while looking into this on a current buster system I saw the the default configuration path stated in /etc/clamav/clamd.conf is: LocalSocket /var/run/clamav/clamd.ctl Also the package seems to correctly create /var/run/clamav and sets permissions: $ ll /var/run/ ... drwxr-xr-x 2 clamav

Bug#928223: unblock / pre approval: otrs2/6.0.16-2

2019-05-08 Thread Holger Levsen
control: tags -1 - moreinfo thanks signature.asc Description: PGP signature

Bug#928223: unblock / pre approval: otrs2/6.0.16-2

2019-05-08 Thread Patrick Matthäi
Am 05.05.2019 um 21:55 schrieb pmatth...@debian.org: > Thanks but I have to upload it to testing, because in unstable is > already a new upstream release which was declined for migration > > Thanks but I have to upload it to testing, because in unstable is already a > new upstream release which w

Bug#923702: swaks passes 8bit characters in headers to server without enabling SMTPUTF8

2019-05-08 Thread John Jetmore
This issue really highlights a tension I've been feeling in swaks for a while. The tool was written to test mail servers. From that perspective, I often feel that I've put _too_ much input validation in it. Wanting to see how a mail server reacts when it is passed 8bit chars in headers without S

Bug#928661: UnicodeDecodeError for pyzor -s mbox

2019-05-08 Thread Matus UHLAR - fantomas
Package: pyzor Version: 1:1.0.0-2 when reporting multiple mail in mbox format, pyzor report shows error: % pyzor report -s mbox < ~/mail/probably-spam Traceback (most recent call last): File "/usr/bin/pyzor", line 408, in main() File "/usr/bin/pyzor", line 152, in main if not dispatch(c

Bug#928660: hyperv-daemons matching linux-image-4.9-amd64 in jessie-security are missing

2019-05-08 Thread Christoph Martin
Package: hyperv-daemons Version: 4.9.168-1 jessie-security has linux-image-4.9-amd64 but is missing the corresponding hyperv-daemons. Please always include them with the kernel-uploades for jessie-security. Christoph signature.asc Description: OpenPGP digital signature

Bug#921267: systemd fails to reach shutdown.target when rebooting or shutting down the system after resuming from suspend

2019-05-08 Thread Michael Biebl
William, Am 08.05.19 um 13:52 schrieb Michael Biebl: > > A fixed kernel for buster seems unlikely at this point, so I wonder > whether we should revert > https://github.com/systemd/systemd/commit/cc83d5197ca08d68fa78167b6a64e9f28da3cc96 > i.e. systemd will use getrandom() for uuid generation. up

Bug#928659: systemd: "systemctl reboot " broken since v240 - fixed in v242

2019-05-08 Thread Michael Biebl
Am 08.05.19 um 15:09 schrieb Serge Schneider: > Package: systemd > Version: 241-3+rpi1 > Severity: normal > > Dear Maintainer, > > v240 of systemd broke the mechanism that passes reboot arguments to the > kernel. > https://github.com/systemd/systemd/issues/11828 > > I've tested that adding this

  1   2   >