Bug#995216: simple-scan: B Text scans saved as gibberish

2021-09-30 Thread Felix Lechner
Hi, On Tue, Sep 28, 2021 at 2:49 AM Jörg Frings-Fürst wrote: > > First of all, I set the severity to normal, because there is no data > loss in the sense of grave, but only an erroneous output. Well, I am trying to read over a month's worth of scanned personal and business documents. I may have

Bug#995370: pidgin: segmentation fault on malloc/free

2021-09-30 Thread Richard Laager
On 9/30/21 7:16 AM, Vaclav Ovsik wrote: after ugprade of pidgin:amd64 to 2.14.7-1 from 2.14.1-1+b1 Are you in any position to bisect this by building the intermediate 2.14.x versions of Pidgin? -- Richard

Bug#994969: jackd2: segfaults after today's upgrade of other Debian testing packages

2021-09-30 Thread Ryan Thoryk
I tried force-downgrading the libglibmm package to the Debian Bullseye version (2.66 back to 2.64), the crash goes away, and my audio hardware works again with Jack. -- Ryan Thoryk r...@thoryk.com r...@tliquest.net

Bug#995428: openuniverse FTCBFS: secondary ./configure invocation does not pass --host

2021-09-30 Thread Helmut Grohne
Source: openuniverse Version: 1.0beta3.1+dfsg-7 Tags: patch User: debian-cr...@lists.debian.org Usertags: ftcbfs Thank you for applying my previous cross build patch. Unfortunately, it fails again. This time, ./configure is invoked twice. Once via dh_auto_configure and another time explicitly via

Bug#994969: jackd2: segfaults after today's upgrade of other Debian testing packages

2021-09-30 Thread Ryan Thoryk
I wanted to chime in on this bug, since I'm getting basically the same issue. I'm running Debian Testing. My situation is a little different, because I'm using an M-Audio firewire device with Jack2 on a VIA VT6315 card, and so I need the firewire module. I recently swapped out the firewire

Bug#994828: bullseye-pu: package node-prismjs/1.23.0+dfsg-1+deb11u1

2021-09-30 Thread Yadd
Control: tags -1 - moreinfo Le 30/09/2021 à 20:58, Adam D. Barratt a écrit : > Control: tags -1 + moreinfo > > On Tue, 2021-09-21 at 14:49 +0200, Yadd wrote: >> node-prismjs is vulnerable to a Regex Denial of Service (ReDoS) >> (CVE-2021-40438) >> > > According to the Security Tracker, that's

Bug#995341: release.debian.org: Xen dom0 does not power off on bullseye (stable)

2021-09-30 Thread Chuck Zmudzinski
On 9/29/2021 7:26 PM, Chuck Zmudzinski wrote: Ordinarily, as I understand the process, a bug in the stable version is first fixed in the unstable release and then the fix is migrated (backported) to the stable release. But it appears to me a fix in the unstable release will not be forthcoming

Bug#265211:

2021-09-30 Thread DILIP CHAUDHARI

Bug#995349: ncbi-entrez-direct: FTBFS: no required module provides package github.com/fiam/gounidecode/unidecode

2021-09-30 Thread Aaron M. Ucko
Steve Langasek writes: > rchive.go:40:2: no required module provides package > github.com/fiam/gounidecode/unidecode: go.mod file not found in current > directory or any parent directory; see 'go help modules' [etc.] Thanks for the report! AFAICT, my approach to go.mod and go.sum (moving

Bug#995427: RFA: mrtg -- multi router traffic grapher

2021-09-30 Thread Sandro Tosi
Package: wnpp Severity: normal X-Debbugs-Cc: mo...@debian.org Control: affects -1 src:mrtg I request an adopter for the mrtg package. I no longer use mrtg and there are better solutions out there (grafana + prometheus) Repo is already in the shared Salsa namespace at:

Bug#995426: ITP: textual -- TUI (Text User Interface) framework for Python inspired by modern web development

2021-09-30 Thread Sandro Tosi
Package: wnpp Severity: wishlist Owner: Sandro Tosi X-Debbugs-Cc: debian-de...@lists.debian.org, mo...@debian.org * Package name: textual Version : 0.1.11 Upstream Author : Will McGugan * URL : https://github.com/willmcgugan/textual * License : MIT

Bug#975985: ITA: geda-gaf -- Electronics design software

2021-09-30 Thread Bastian Germann
On Wed, 29 Sep 2021 12:51:18 +0200 (CEST) Roland Lutz wrote: On Mon, 27 Sep 2021, Bastian Germann wrote: > Roland, do you still want the package revived which means having it in > bookworm? > I would then review and upload your version. Sure. Thank you! Kai-Martin did some further work on

Bug#829754: bibclean: please make the build reproducible

2021-09-30 Thread Vagrant Cascadian
On 2021-09-30, Vagrant Cascadian wrote: > On 2016-07-05, Reiner Herrmann wrote: >> Source: bibclean >> Version: 2.11.4.1-4 >> Severity: wishlist >> Tags: patch upstream >> User: reproducible-bui...@lists.alioth.debian.org >> Usertags: timestamps username hostname >> X-Debbugs-Cc:

Bug#995425: linux-image-amd64: kernel BUG at fs/ext4/ext4_extents.h:199! (fast_commit feature)

2021-09-30 Thread Nelson G
Package: linux-image-amd64 Version: 5.10.46-5 Severity: normal Hello, There's a bug for the ext4 filesystem, when the fast_commit flag is enabled and you use fallocate or any other task that allocates space. You can easily reproduce this bug on a VM or raw hardware by doing the following: 1°

Bug#995392: ghostscript: ps2pdf trashes some characters

2021-09-30 Thread Vincent Lefevre
Control: tags -1 upstream Control: forwarded -1 https://bugs.ghostscript.com/show_bug.cgi?id=704478 On 2021-09-30 18:49:02 +0200, Jonas Smedegaard wrote: > Quoting Vincent Lefevre (2021-09-30 18:28:51) > > On 2021-09-30 17:18:46 +0200, Jonas Smedegaard wrote: > > > This seems an upstream bug, and

Bug#829754: bibclean: please make the build reproducible

2021-09-30 Thread Vagrant Cascadian
On 2016-07-05, Reiner Herrmann wrote: > Source: bibclean > Version: 2.11.4.1-4 > Severity: wishlist > Tags: patch upstream > User: reproducible-bui...@lists.alioth.debian.org > Usertags: timestamps username hostname > X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org > > Hi! > > While

Bug#995406: [Debian-med-packaging] Bug#995406: bbmap: package does not ship resource files

2021-09-30 Thread Étienne Mollier
Control: found -1 38.90+dfsg-1 Control: tag -1 confirmed Hi all, Andreas Tille, on 2021-09-30: > Am Thu, Sep 30, 2021 at 01:22:23PM -0400 schrieb Robert: > > The bbmap package does not ship the needed resource files which causes some > > of > > the included tools not to work, e.g. bbduk when

Bug#995341: release.debian.org: Xen dom0 does not power off on bullseye (stable)

2021-09-30 Thread Chuck Zmudzinski
On 9/30/2021 2:57 PM, Paul Gevers wrote: Hi Chuck, On 30-09-2021 18:15, Chuck Zmudzinski wrote: ... the debdiff I uploaded to BTS has UNRELEASED rather than bullseye for the distribution field of the changelog, and the new target version is ...deb11u1.1 instead of deb11u2. That is how dch

Bug#995341: release.debian.org: Xen dom0 does not power off on bullseye (stable)

2021-09-30 Thread Chuck Zmudzinski
On 9/30/2021 2:57 PM, Paul Gevers wrote: Hi Chuck, On 30-09-2021 18:15, Chuck Zmudzinski wrote: ... the debdiff I uploaded to BTS has UNRELEASED rather than bullseye for the distribution field of the changelog, and the new target version is ...deb11u1.1 instead of deb11u2. That is how dch

Bug#900244: NVM error information log entry count increase not an error

2021-09-30 Thread Benjamin Poirier
I also see this issue with the following drive, nvme1 on my system: Model Number: Samsung SSD 970 EVO Plus 1TB Firmware Version: 2B2QEXM7 PCI Vendor/Subsystem ID:0x144d This has been going on for months and until recently the output of

Bug#995415: unblock: theano/1.0.5+dfsg-3 - not really a regression

2021-09-30 Thread Rebecca N. Palmer
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal theano 1.0.5+dfsg-3 is currently held in unstable for an autopkgtest "regression" on armhf. The test in question (smoketestgpu) is currently skipped in plain testing because it depends

Bug#995362: zint breaks zbar autopkgtest: unable to open file `/tmp/magick-VxkNk3KeW43pSnBYixIpsF9xU8qRmIzE': No such file or directory @ error/constitute.c/ReadImage/614

2021-09-30 Thread John Scott
On Thu, 2021-09-30 at 09:18 -0400, John Scott wrote: > Outside a minimal chroot, on my desktop system, zbarimg seems to > process SVGs just fine. So this may be a case of a Recommends > (somewhere) not being installed wreaking havok, but in my opinion > zbarimg should still not behave this way

Bug#974789: beignet FTBFS with llvm-toolchain-11

2021-09-30 Thread Rebecca N. Palmer
I'm not aware of a fix for this, and beignet is abandoned upstream and mostly useful for old hardware (on newer hardware it is replaced by intel-opencl-icd). However, I may look at it more later (and at least try llvm-toolchain-12, though I'd expect that to be worse if anything). Hence, I'm

Bug#986709: rsnapshot is stable, not dead

2021-09-30 Thread John Brooks
On 2021-09-30 6:13 p.m., Michael Lustfield wrote: On Sun, 26 Sep 2021 13:49:36 -0400 John Brooks wrote: [...] So... My first response was a wordier version of the message you replied to, emphasizing the bit where my opinion is moot. What's written below is as much as I'm willing to dip back

Bug#995408: transition: libquvi

2021-09-30 Thread Sebastian Ramacher
Control: tags -1 confirmed Control: forwarded -1 https://release.debian.org/transitions/html/auto-libquvi.html On 2021-09-30 14:43:14 -0400, Boyuan Yang wrote: > Package: release.debian.org > User: release.debian@packages.debian.org > Usertags: transition > X-Debbugs-Cc: by...@debian.org

Bug#995424: libgmsh4: SONAME bump without package rename

2021-09-30 Thread Sebastian Ramacher
Package: libgmsh4 Version: 4.8.4+ds1-1 Severity: serious X-Debbugs-Cc: sramac...@debian.org, elb...@debian.org The package name of shared libraries is supposed to follow the SONAME of the library. In the case of libgmsh, the SONAME in testing is libgmsh.so.4.7 and the package should have been

Bug#986709: rsnapshot is stable, not dead

2021-09-30 Thread Michael Lustfield
On Sun, 26 Sep 2021 13:49:36 -0400 John Brooks wrote: > [...] > Michael, > > I think it is important that you clarify or modify your stance given > that upon further inspection by others here, there are no serious > outstanding functional or security issues with the program. Even >

Bug#995423: libyaml-cpp-dev: Incorrect include PATH in CMake configuration script.

2021-09-30 Thread Tomasz Wolak
Package: libyaml-cpp-dev Version: 0.6.3-9 Severity: normal X-Debbugs-Cc: tomas.wo...@gmail.com One of the package config files for CMake: /usr/lib/x86_64-linux-gnu/cmake/yaml-cpp/yaml-cpp-config.cmake contains an incorrect path to the library's header files: 'include' instead of

Bug#995419: rust-utf-8: autopkgtest regression: crate directory not found: /usr/share/cargo/registry/utf-8-0.7.6

2021-09-30 Thread peter green
It passes when run with only packages from testing. This is not entirely correct, the version of rust-utf-8 in testing has no autopkgtests at all. So this is a case of a newly added (by a newer version of debcargo) test failing, not a case of an existing test regressing. Investigating, it

Bug#995392: ghostscript: ps2pdf trashes some characters

2021-09-30 Thread JustAnotherArchivist
Control: notfound -1 9.53.3~dfsg-8 Apologies, I somehow missed the part about pdftotext and the glyph's normal appearance in your original message. I can reproduce that with both files produced by 9.54.0~dfsg-5 but *not* the one produced by 9.53.3~dfsg-8 (attached for reference), using the

Bug#995422: ITP: long-read-assembler -- assembly from long reads against reference genome

2021-09-30 Thread Steffen Moeller
Package: wnpp Severity: wishlist Subject: ITP: long-read-assembler -- assembly from long reads against reference genome Package: wnpp Owner: Steffen Moeller Severity: wishlist * Package name: long-read-assembler Version : 1.3.2 Upstream Author : Copyright: Bonnie Phan Wolfe *

Bug#994218: RFS: r-cran-partitions (NEW)

2021-09-30 Thread Nilesh Patra
On 30 September 2021 10:11:47 pm IST, "Torrance, Douglas" wrote: >On Thu 30 Sep 2021 10:47:16 AM EDT, Nilesh Patra >wrote: > I didn't realize this and just made the change based Lintian's [...] Perfectly understandable. I wonder if it makes sense to open a bug report against lintian to not

Bug#994918: linux-image-5.14.0-1-amd64: Cannot load amdgpu firmware on 5.14 kernel

2021-09-30 Thread Sebastian Reichel
Hi, The amdgpu driver from Linux 5.14 seems to require IOMMU support, which was disabled by default in my system's BIOS. My system (which has a Radeon RX 5700XT GPU) successfully booted 5.14 after enabling it in the BIOS. Previous 5.10 kernel also worked with IOMMU disabled. I did not do any

Bug#994415: tang: Missing xinetd support in tang package

2021-09-30 Thread Christoph Biedl
Control: tags 994415 pending Tom Boven wrote... > And the files are part of the git repo under the units folder. > Could these also be implemented in the debian package (or a seperate > package like tang-xinetd) ? Work is almost done now - but do you have an idea how to automatically enable

Bug#990718: RFS: duma/2.5.21-1 [ITA] -- Detect Unintended Memory Access - A Red-Zone memory allocator

2021-09-30 Thread Bastian Germann
Hi Peter, There was one QA (2.5.15-3) upload since you started your packaging effort. Please include the changelog entry in your version. The changes themselves are irrelevant with your upstream change. On Thu, 8 Jul 2021 13:04:29 +0100 Peter wrote:  duma (2.5.21-1) unstable;

Bug#990718: RFS: duma/2.5.21-1 [ITA] -- Detect Unintended Memory Access - A Red-Zone memory allocator

2021-09-30 Thread Bastian Germann
    * DEP-5 copyright The license name has to be GPL-2+ because it has the "or later" clause. Fix trailing whitespace. Some files are licensed under LGPL 2.1+. Please identify them and add the license. There are also some old-style MIT licensed files.

Bug#994828: bullseye-pu: package node-prismjs/1.23.0+dfsg-1+deb11u1

2021-09-30 Thread Salvatore Bonaccorso
Hi, On Thu, Sep 30, 2021 at 07:58:31PM +0100, Adam D. Barratt wrote: > Control: tags -1 + moreinfo > > On Tue, 2021-09-21 at 14:49 +0200, Yadd wrote: > > node-prismjs is vulnerable to a Regex Denial of Service (ReDoS) > > (CVE-2021-40438) > > > > According to the Security Tracker, that's an

Bug#992693: bullseye-pu: package glibc/2.31-13+deb11u1

2021-09-30 Thread Adam D. Barratt
On Mon, 2021-09-27 at 12:38 +0100, Adam D. Barratt wrote: > Control: tags -1 + confirmed d-i > To confirm some IRC conversations - given the closeness of the freeze for 11.1, please feel free to upload and kibi can review the package from stable-new. Regards, Adam > Control: fixed 994042

Bug#992693: bullseye-pu: package glibc/2.31-13+deb11u1

2021-09-30 Thread Aurelien Jarno
Hi, On 2021-09-27 12:38, Adam D. Barratt wrote: > Control: tags -1 + confirmed d-i > Control: fixed 994042 2.32-3 > > Hi, > > On Sun, 2021-09-26 at 22:16 +0200, Aurelien Jarno wrote: > > Hi, > > > > On 2021-09-26 20:46, Adam D. Barratt wrote: > > > On Tue, 2021-09-21 at 23:47 +0200, Aurelien

Bug#995397: Dropped support for 32-bit Xen PV guests should be mentioned in i386 release notes

2021-09-30 Thread Andy Smith
Hi Paul, On Thu, Sep 30, 2021 at 10:21:42PM +0200, Paul Gevers wrote: > This indeed sounds like something that could be mentioned under the > "issues to be aware of" section. A proposal text would help the process > forward. Thanks. I am not sure whether it fits in "Items not limited to the

Bug#995392: ghostscript: ps2pdf trashes some characters

2021-09-30 Thread JustAnotherArchivist
Hi Vincent, For what it's worth, I do not see the corruption you're describing with `gv chartest-gs.pdf` nor when converting it myself from your input file using versions 9.53.3~dfsg-8 or 9.54.0~dfsg-5. I noticed that your file used a different internal conversion command compared to when I

Bug#994697: libgit-annex-perl: Test failure - autopkgtest and build

2021-09-30 Thread Sean Whitton
control: tag -1 + confirmed Hello, On Sun 19 Sep 2021 at 05:30PM +02, gregor herrmann wrote: > Package: libgit-annex-perl > Version: 0.007-1 > Severity: serious > Tags: ftbfs sid bookworm > Justification: fails to build from source (but built successfully in the past) > > -BEGIN PGP SIGNED

Bug#995376: wsjtx: Segfault when use refspec

2021-09-30 Thread Yvan Brodier
$ gdb wsjtx GNU gdb (Debian 10.1-2) 10.1.90.20210103-git Copyright (C) 2021 Free Software Foundation, Inc. License GPLv3+: GNU GPL version 3 or later This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent

Bug#995421: rust-bumpalo: autopkgtest armhf regression: oom_instead_of_bump_pointer_overflow

2021-09-30 Thread Paul Gevers
Source: rust-bumpalo Version: 3.7.0-2 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of rust-bumpalo the autopkgtest of rust-bumpalo fails in testing when that autopkgtest is run with the

Bug#995420: D-Bus crash atk-bridge

2021-09-30 Thread Kai Lüke
Package: epiphany-browser Version: 41.0-2 A few seconds after startup the app crashes with the following error printed on the console: (WebKitWebProcess:2): dbind-WARNING **: 22:39:12.184: AT-SPI: Error retrieving accessibility bus address: org.freedesktop.DBus.Error.ServiceUnknown:

Bug#902167: distro-info: ubuntu-distro-info incorrectly lists the development release in --supported

2021-09-30 Thread Stefano Rivera
Hi Daniel (2018.06.22_18:56:11_-0700) > I've prepared the attached patch against the Ubuntu packaging to fix the > apparently incorrect output for --supported. I will be seeking > sponsorship for it in the coming days. Sorry for never replying to this. I agree that the current behaviour for

Bug#995419: rust-utf-8: autopkgtest regression: crate directory not found: /usr/share/cargo/registry/utf-8-0.7.6

2021-09-30 Thread Paul Gevers
Source: rust-utf-8 Version: 0.7.6-1 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of rust-utf-8 the autopkgtest of rust-utf-8 fails in testing when that autopkgtest is run with the binary

Bug#995308: libcrypt1: symlink points to libpthread

2021-09-30 Thread shichimohedron
On Thursday, September 30th, 2021 at 12:08 PM, Aurelien Jarno wrote: > It could be that this libpthread.so.1 file is actually a copy of an old > > libcrypt.so.1. It's something you can check with: > > readelf --dynamic /lib/x86_64-linux-gnu/libpthread.so.1 | grep SONAME And it actually is:

Bug#978773: bmake: ftbfs with autoconf 2.70

2021-09-30 Thread Andrej Shadura
Hi, On Thu, 30 Sep 2021, at 22:18, Boyuan Yang wrote: > On Thu, 31 Dec 2020 14:26:45 + Matthias Klose wrote: >> Package: src:bmake >> Version: 20200710-5 >> Severity: normal >> Tags: sid bookworm >> User: d...@debian.org >> Usertags: ftbfs-ac270 >> >> [This bug report is not targeted to the

Bug#995397: Dropped support for 32-bit Xen PV guests should be mentioned in i386 release notes

2021-09-30 Thread Paul Gevers
Hi Andy, On 30-09-2021 17:13, Andy Smith wrote: > I think this issue should be mentioned in the i386 release notes in > the upgrading from buster part. I am happy to propose some text for > that if it is agreed. This indeed sounds like something that could be mentioned under the "issues to be

Bug#978773: bmake: ftbfs with autoconf 2.70

2021-09-30 Thread Boyuan Yang
Control: tags -1 +patch X-Debbugs-CC: andre...@debian.org Hi, On Thu, 31 Dec 2020 14:26:45 + Matthias Klose wrote: > Package: src:bmake > Version: 20200710-5 > Severity: normal > Tags: sid bookworm > User: d...@debian.org > Usertags: ftbfs-ac270 > > [This bug report is not targeted to the

Bug#995418: python-colorlog breaks macsyfinder autopkgtest: module 'colorlog' has no attribute 'logging'

2021-09-30 Thread Paul Gevers
Source: python-colorlog, macsyfinder Control: found -1 python-colorlog/6.4.1-1 Control: found -1 macsyfinder/2.0~rc1-3 Severity: serious Tags: sid bookworm X-Debbugs-CC: debian...@lists.debian.org User: debian...@lists.debian.org Usertags: breaks needs-update Dear maintainer(s), With a recent

Bug#995162: cannot install together with i386

2021-09-30 Thread Mattia Rizzolo
On Thu, Sep 30, 2021 at 09:27:50PM +0200, Giovanni Mascellani wrote: > Thanks for the info. Unless I am mistaken, this means that any package which > installs a shared PNG breaks at every binNMU, unless the binNMU is for all > architectures. Wouldn't it be better if dh_strip_nondeterminism used

Bug#994892: evdi-dkms: fails to build for kernel 5.14.0-1

2021-09-30 Thread Justin Searle
I can confirm I am having the same issue for the last few weeks, with the same make.log error messages, resulting in no graphics upon boot. Only solution I've found so far is to remove the 5.14 kernel. All other packages are fully updated to Sid.

Bug#990642: linux-image-4.19.0-17-amd64: kernel panic on xen dom0 with Broadcom Limited NetXtreme II BCM5709

2021-09-30 Thread Hans van Kranenburg
Hi spi, Salvatore, On 8/5/21 1:58 PM, s...@gmxpro.de wrote: > > In preparation for the bug report for upstream I did some more > investigation. > > The kernel panic also occurs without bonding interfaces but needs much > more time to happen. With a bonding interface it happens within some >

Bug#995417: python-requests-oauthlib: please update to current upstream version 1.3.0

2021-09-30 Thread Dominik George
Source: python-requests-oauthlib Version: 1.0.0-1.1 Severity: wishlist Please update this package to the current upstream version. I would also like to suggest moving this to team maintenance under the Python Packaging team. Thanks, Nik -- System Information: Debian Release: bookworm/sid

Bug#995412: libstring-copyright-perl breaks licensecheck autopkgtest: lots of different outputs

2021-09-30 Thread Jonas Smedegaard
Quoting Paul Gevers (2021-09-30 21:34:54) > With a recent upload of libstring-copyright-perl the autopkgtest of > licensecheck fails in testing when that autopkgtest is run with the > binary packages of libstring-copyright-perl from unstable. It passes > when run with only packages from

Bug#995416: netgen: autopkgtest regression on armhf: Fatal Python error: Bus error

2021-09-30 Thread Paul Gevers
Source: netgen Version: 6.2.2006+really6.2.1905+dfsg-4 X-Debbugs-CC: debian...@lists.debian.org Severity: important User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), Thanks for fixing bug #993533. However, with the introduction of the improved autopkgtest, the test fails

Bug#995308: libcrypt1: symlink points to libpthread

2021-09-30 Thread shichimohedron
>Can you please try to call /usr/sbin/ldconfig.old to check if the wrong link is recreated? That's needed to confirm if ldconfig is the culprit here. >Can you confirm it's libpthread.so.1 and not libpthread.so.0? If so can you please tell how did you install that file? Here is a shell log,

Bug#991632: buster-pu: package node-jszip/3.1.4+dfsg-1+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Thu, 2021-07-29 at 13:07 +0200, Yadd wrote: > node-jszip is vulnerable to a prototype pollution (CVE-2021-23413) > + * Fix a null prototype object for this.files (Closes: CVE-2021- 23413) As far as I can tell, you're fixing an issue by *using* a null prototype

Bug#995414: neomutt: pager sometimes displays the wrong mail content

2021-09-30 Thread Jonathan Dowland
Package: neomutt Version: 20201127+dfsg.1-1.2 Severity: important I think this is going to be a pretty difficult one to figure out! Sometimes, when viewing my INBOX (at least; perhaps other folders too) and selecting a mail to view in the pager, the wrong mail is displayed in the pager. It's a

Bug#995413: fcitx5-chinese-addons: qtwebengine is now also available on mips64el

2021-09-30 Thread Adrian Bunk
Source: fcitx5-chinese-addons Version: 5.0.7-1 Severity: normal qtwebengine5-dev is now available on mips64el, please change debian/control and debian/rules to use it.

Bug#992117: buster-pu: package node-tar/4.4.6+ds1-3+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2021-08-12 at 00:11 +0200, Yadd wrote: > node-tar is vulnerable to 2 CVE: > * #992110, CVE-2021-32803: arbitrary File Creation/Overwrite >vulnerability via insufficient symlink protection > * #992111, CVE-2021-32804: arbitrary File Creation/Overwrite >

Bug#991811: unblock: libapache2-mod-auth-openidc/2.4.9-1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Mon, 2021-08-23 at 14:46 +0200, Salvatore Bonaccorso wrote: > Hi Christoph, > > On Mon, Aug 23, 2021 at 01:17:18PM +0200, Christoph Martin wrote: > > Hi Salvatore, > > > > Am 19.08.21 um 21:32 schrieb Salvatore Bonaccorso: > > > Hi Christoph, > > > > > > On Tue,

Bug#994513: buster-pu: package debconf/1.5.71+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2021-09-17 at 00:16 +0100, Colin Watson wrote: > https://bugs.debian.org/984533 and its clone > https://bugs.debian.org/985572 showed a buster-to-bullseye upgrade > bug in which debconf was unable to execute whiptail between unpacking > the new libslang2 and

Bug#995162: cannot install together with i386

2021-09-30 Thread Giovanni Mascellani
Hi Mattia, Il 29/09/21 19:28, Mattia Rizzolo ha scritto: This is triggered by the binNMU, which varies the date of the changelog, so that dh_strip_nondeterminism will normalize the metadata of the .png to the binNMU build time instead of the time of the source upload as it was before. Thanks

Bug#995412: libstring-copyright-perl breaks licensecheck autopkgtest: lots of different outputs

2021-09-30 Thread Paul Gevers
/bin/licensecheck -m --shortname-scheme=debian --copyright --lines 0 t/devscripts/info-at-eof.h' is 0 ok 4 - Testing stdout ok 5 - No stderr 1..5 } ok t/encoding.t . # Seeded srand with seed '20210930' from local date. 1..13 # locale encoding: UTF-8 ok 1 - Latin-1 in UTF-8 pa

Bug#994583: buster-pu: package node-axios/0.17.1+dfsg-2+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2021-09-18 at 07:36 +0200, Yadd wrote: > Another regex denial of service > Please go ahead. Regards, Adam

Bug#994829: buster-pu: package node-prismjs/1.11.0+dfsg-3+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Tue, 2021-09-21 at 14:56 +0200, Yadd wrote: > node-prismjs is vulnerable to a Regex Denial of Service (ReDoS) > (CVE-2021-40438) > As with the bullseye request, that appears to be the wrong CVE number. Regards, Adam

Bug#995144: bullseye-pu: package jailkit/2.21-4+deb11u1

2021-09-30 Thread Eriberto
Em qui., 30 de set. de 2021 às 16:24, Adam D. Barratt escreveu: > > Control: tags -1 + confirmed > > On Sun, 2021-09-26 at 23:01 -0300, Joao Eriberto Mota Filho wrote: > > This update is not for a regression. There are two bugs discovered > > recently. > > With these bugs, jailkit will work

Bug#994943: buster-pu: package atftp/0.7.git20120829-3.2~deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2021-09-23 at 17:47 +0200, Andreas B. Mundt wrote: > I would like to ask for permission to upload a new atftpd > package 0.7.git20120829-3.2+deb10u2 to fix #994895, buffer > overflow, CVE-2021-41054. > The diff here has the same s/save/safe/g issue as the

Bug#994862: buster-pu: package node-ansi-regex/3.0.0-1+deb10u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2021-09-22 at 09:15 +0200, Yadd wrote: > node-ansi-regex is vulnerable to a ReDoS (CVE-2021-3807) > Please go ahead. Regards, Adam

Bug#995406: bbmap: package does not ship resource files

2021-09-30 Thread Andreas Tille
Control: tags -1 pending Hi Robert, thanks a lot for the Am Thu, Sep 30, 2021 at 01:22:23PM -0400 schrieb Robert: > The bbmap package does not ship the needed resource files which causes some of > the included tools not to work, e.g. bbduk when trying to process some fastq > data, crashes with

Bug#995304: bullseye-pu: package pmdk/1.10-2

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2021-09-29 at 15:47 +0200, Adam Borowski wrote: > There's a bug in pmdk versions 1.9..1.11, that can cause data loss > when > power to the CPU is lost (ie, an unclean shutdown of the machine). > > It's caused by a clash between a macro named "barrier" vs

Bug#995144: bullseye-pu: package jailkit/2.21-4+deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2021-09-26 at 23:01 -0300, Joao Eriberto Mota Filho wrote: > This update is not for a regression. There are two bugs discovered > recently. > With these bugs, jailkit will work partially. The bugs are #992420 > and #992422. > + * debian/patches/: + -

Bug#995411: ruby-omniauth-ultraauth: autopkgtest needs update for new version of ruby-omniauth-openid-connect: Could not find 'omniauth_openid_connect' (~> 0.3.0)

2021-09-30 Thread Paul Gevers
Source: ruby-omniauth-ultraauth Version: 0.0.2-1.1 Severity: serious X-Debbugs-CC: debian...@lists.debian.org, ruby-omniauth-openid-conn...@packages.debian.org Tags: sid bookworm User: debian...@lists.debian.org Usertags: needs-update Control: affects -1 src:ruby-omniauth-openid-connect Dear

Bug#995410: breezy: FTBFS:

2021-09-30 Thread Steve Langasek
Source: breezy Version: 3.2.1-1 Severity: serious User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu impish Hi Jelmer, While tracking a build failure of breezy 3.2.1 in Ubuntu, I found that it is currently also reproducible in Debian unstable: [...]

Bug#995376: wsjtx: Segfault when use refspec

2021-09-30 Thread Christoph Berg
Re: Yvan Brodier > Yes : > > > recvmsg(6, {msg_namelen=0}, 0) = -1 EAGAIN (Ressource > > temporairement non disponible) I meant a backtrace from gdb: https://wiki.debian.org/HowToGetABacktrace Christoph

Bug#994285: libseccomp: FTBFS on arm64, armhf, mips64el and mipsel

2021-09-30 Thread Felix Geyer
Hi, On 30.09.21 08:40, Johannes Schauer Marin Rodrigues wrote: Hi Felix, On Fri, 17 Sep 2021 07:15:16 +0200 Johannes Schauer Marin Rodrigues wrote: you set the upstream bug to https://github.com/seccomp/libseccomp/issues/336 but I don't think that is correct. The failures is not the same

Bug#994086: transition: netcdf

2021-09-30 Thread Sebastiaan Couwenberg
On 9/29/21 4:19 PM, Sebastiaan Couwenberg wrote: > On 9/29/21 10:02 AM, Sebastian Ramacher wrote: >> Please go ahead > > Thanks. netcdf (1:4.8.1-1) has been uploaded to unstable and is built & > installed on all release architectures. eccodes and gdal have been fixed, dependency level 3 can be

Bug#978830: https://gitlab.com/kalilinux/packages/gtkhash

2021-09-30 Thread Arnaud Rebillout
Dear maintainer, I had to update this package for Kali Linux. I updated it to latest upstream version 1.4, and cherry-picked an upstream patch to fix this FTBFS. You can find this package at https://gitlab.com/kalilinux/packages/gtkhash. Please feel free to cherry-pick all the commits you

Bug#994946: bullseye-pu: package atftp/0.7.git20120829-3.3

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2021-09-23 at 18:07 +0200, Andreas B. Mundt wrote: > I would like to ask for permission to upload a new atftpd > package 0.7.git20120829-3.3+deb11u1 to fix #994895, buffer > overflow, CVE-2021-41054. > I'm assuming this is from upstream, but as a small

Bug#994828: bullseye-pu: package node-prismjs/1.23.0+dfsg-1+deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Tue, 2021-09-21 at 14:49 +0200, Yadd wrote: > node-prismjs is vulnerable to a Regex Denial of Service (ReDoS) > (CVE-2021-40438) > According to the Security Tracker, that's an Apache mod-proxy issue. Regards, Adam

Bug#994861: bullseye-pu: package node-ansi-regex/5.0.1-1~deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2021-09-22 at 09:05 +0200, Yadd wrote: > node-ansi-regex is vulnerable to a ReDoS (CVE-2021-3807) > Please go ahead. Regards, Adam

Bug#994710: bullseye-pu: package nautilus/3.38.2-1+deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2021-09-20 at 11:19 +0100, Simon McVittie wrote: > On Mon, 20 Sep 2021 at 11:08:49 +0100, Simon McVittie wrote: > > It seems #994710 didn't make it to the list because the diff was > > too big. > > Here's another try, removing the translation updates from the

Bug#994490: bullseye-pu: package node-set-value/3.0.1-2+deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2021-09-16 at 18:21 +0200, Yadd wrote: > node-set-value is vulnerable to prototype pollution (#994448, CVE- > 2021-23440) > Please go ahead. Regards, Adam

Bug#994555: bullseye-pu: package node-object-path/0.11.5-3+deb11u1

2021-09-30 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2021-09-17 at 18:49 +0200, Yadd wrote: > node-object-path is vulnerable to prototye pollution (CVE-2021-23434 > and > CVE-2021-3805 > The noise in the patches - spacing changes and removal of terminating semi-colons at least - makes review quite annoying.

Bug#995409: ball: Please build depend on qtwebengine5-dev also on mips64el

2021-09-30 Thread Adrian Bunk
Source: ball Version: 1.5.0+git20180813.37fc53c-7 Severity: normal qtwebengine5-dev is now available on mips64el.

Bug#995331: perl 5.32.1-4+deb11u2 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 995331 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: perl Version:

Bug#995306: dpdk 20.11.3-1~deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 995306 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: dpdk Version:

Bug#995025: pam 1.4.0-9+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 995025 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: pam Version: 1.4.0-9+deb11u1

Bug#995062: speech-dispatcher 0.10.2-2+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 995062 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: speech-dispatcher Version:

Bug#994885: glewlwyd 2.5.2-2+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 994885 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: glewlwyd Version:

Bug#994881: rhonabwy 0.9.13-3+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 994881 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: rhonabwy Version:

Bug#994880: ulfius 2.7.1-1+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 994880 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: ulfius Version:

Bug#994627: debian-edu-config 2.11.56+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 994627 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: debian-edu-config Version:

Bug#993564: dlt-viewer 2.21.2+dfsg-2+deb11u1 flagged for acceptance

2021-09-30 Thread Adam D Barratt
package release.debian.org tags 993564 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: dlt-viewer Version:

Bug#995271: nvidia-kernel-dkms: does not install with linux-image-5.14-amd64

2021-09-30 Thread Krzysztof Marczak
Hi I'm getting the same errors when installing nvidia-kernel-dkms with kernel 5.14 Here is content of build log: /var/lib/dkms/nvidia-current/470.57.02/build/dkms.log I hope it will help. For now I'm forced to use older kernel (5.10.0-8) which works fine. DKMS make.log for

Bug#995408: transition: libquvi

2021-09-30 Thread Boyuan Yang
Package: release.debian.org User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: by...@debian.org ans...@debian.org alejan...@debian.org Severity: normal Dear Debian release team, I request to start the transition as listed on

Bug#995388: ITP: ruby-glob -- Create a list of hash paths that match a given pattern

2021-09-30 Thread Vivek K J
Package: wnpp Severity: wishlist Owner: Vivek K J X-Debbugs-Cc: debian-de...@lists.debian.org, vive...@protonmail.com * Package name: ruby-glob Version : 0.2.0 Upstream Author : 2020 Nando Vieira * URL : https://github.com/fnando/glob * License : Expat

  1   2   3   >