Bug#991566: r-cran-bslib is in NEW now

2022-04-29 Thread Andreas Tille
Hi, just hoping that r-cran-bslib will be accepted soonish to be able to work on this issue. Kind regards Andreas. -- http://fam-tille.de

Bug#1010382: ITP: mkdocstrings-python-legacy -- Legacy Python handler for mkdocstrings

2022-04-29 Thread Carsten Schoenert
Package: wnpp Severity: wishlist Owner: Carsten Schoenert X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: mkdocstrings-python-legacy Version : 0.2.2 Upstream Author : Timothée Mazzucotelli * URL : https://github.com/mkdocstrings/python-legacy * License

Bug#1010365: linux: failure to boot on Raspberry Pi Compute Module 4 (black screen)

2022-04-29 Thread Cyril Brulebois
Cyril Brulebois (2022-04-29): > > I'll try and pinpoint when it broke using the various intermediary > > versions: > > > > - 5.17~rc3-1~exp1 > > The first attempt was sufficient: it breaks as early as that version. Using the same base image as before, and only updating the kernel: I've tested

Bug#1010368: Maybe marshal nondeterminism?

2022-04-29 Thread Keith Amling
>From skimming some of cpython's "marshal" code [1] my best guess is that first difference is between it thinking the `_m` string might have another reference to it (and thus adding 0x80, or FLAG_REF to it) or not. This seems driven by whether or not python's object for the string has other

Bug#1010381: commons-daemon: FTBFS on riscv64: error: Unsupported CPU architecture "riscv64"

2022-04-29 Thread Bo YU
Source: commons-daemon Version: 1.0.15-8 Severity: normal Tags: ftbfs patch User: debian-ri...@lists.debian.org Usertags: riscv64 X-Debbugs-Cc: debian-ri...@lists.debian.org Dear Maintainer, The commons-daemon has a ftbfs issue on riscv64: ``` ... configure:2916: result: none needed

Bug#1010276: parasail: compiles something extra (or less) depending on the CPU features available

2022-04-29 Thread Nilesh Patra
Hi Etienne, would you have some bandwidth to fix this one? Regards Nilesh On Wed, 27 Apr 2022 18:01:01 +0200 Mattia Rizzolo wrote: > Source: parasail > Version: 2.5+dfsg-3 > Severity: serious > User: reproducible-bui...@lists.alioth.debian.org > Usertags: cpu > > Hi! > > While working on the

Bug#1008569: unar: diff for NMU version 1.10.1-3

2022-04-29 Thread Boyuan Yang
Hi all, 在 2022-04-29星期五的 08:20 +0200,Paul Gevers写道: > Dear Boyuan, > > On 25-04-2022 20:44, Sudip Mukherjee wrote: > > > +unar (1.10.1-3) unstable; urgency=medium > > > + > > > +  * QA upload. > > > +  * Orphan the package (take over package maintenance) via > > > +    ITS process. (Closes:

Bug#1008112: fixed in golang-mvdan-sh 3.4.3+ds2-1

2022-04-29 Thread Nilesh Patra
Hi Shengjing, >* Team upload >* Merge shfmt package (Closes: #1008112, #1008186, #1008463) Since you added shfmt binary package to golang-mvdan-sh, now both src: golang-mvdan-sh and src:shfmt are proving a shfmt binary, shouldn't src:shfmt be removed then? Also, as you added a new

Bug#1009632: The QPA plugin package contains the TLS backends

2022-04-29 Thread Lisandro Damián Nicanor Pérez Meyer
Hi! On Fri, 15 Apr 2022 at 13:06, Patrick Franz wrote: > > Hi Robert, > > On Wed, 13 Apr 2022 12:02:36 +0200 Robert Griebl > wrote: > > Package: qt6-qpa-plugins > > Version: 6.2.2 > > > > The new Qt6 plugins for the TLS backend (QSslSocket) got packaged with > > the QPA plugins, which is a bit

Bug#952704: libqt5printsupport5: Printer and queue attributes not available

2022-04-29 Thread Lisandro Damián Nicanor Pérez Meyer
severity 952704 wishlist tag 952704 wontfix thanks On Sun, 17 Apr 2022 at 11:36, Brian Potkin wrote: > > tags 952704 upstream > found 952704 5.15.2+dfsg-16 > thanks > > > In my opinion, the Qt print dialog should support the CUPS temporary > queue facility correctly. CUPS has APIs to do this.

Bug#1010369: RediSearch Upstream Needs Swapped out from version 1 to version 2

2022-04-29 Thread Chris Lamb
Hi Kevin, > Currently, this package is obviously packaging the now deprecated > version 1 source at https://github.com/goodform/RediSearch.git > > This should be swapped out for the new version 2 upstream at > https://github.com/RediSearch/RediSearch.git Indeed, and I'd love to be able to do

Bug#1010380: buster-pu: flac/1.3.2-3+deb10u2

2022-04-29 Thread Thorsten Alteholz
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu The attached debdiff for flac fixes CVE-2021-0561 in Buster. This CVE has been marked as no-dsa by the security team. The same patch has been already uploaded to all other

Bug#1010379: snacc: reproducible builds: timestamp embedded in header files

2022-04-29 Thread Vagrant Cascadian
Source: snacc Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Various header files embed the timestamp when it was generated in comments:

Bug#1010340: git: Fails to clone and pull from existign repositories

2022-04-29 Thread Axel Beckert
Hi, Andrea Palazzi wrote: > Package: git > Version: 1:2.36.0-1 > > Dear Maintainer, > > On my test system git is now basically unusable as it fails to clone and to > pull from already cloned repositories with an error "error: git-remote-https > died of signal 4"; e.g.: > > andrea@test:~$

Bug#1010378: leds-alix: reproducible builds: source tarball embeds timestamps and umask

2022-04-29 Thread Vagrant Cascadian
Source: leds-alix Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps umask X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org leds-alix-source embeds the timestamp and file permissions determined by umask in the leds-alix source tarball:

Bug#1010342: Refuses to create directories for unburdening

2022-04-29 Thread Axel Beckert
Control: tag -1 + moreinfo Hi Didier, Didier 'OdyX' Raboud wrote: > With 0.4.2, after noticing my directories didn't get symlinked, I tried to > run unburden-home-dir by hand and I got the following error(s) (with or > without -F): Thanks for the bug report! > WARNING: Can't handle

Bug#1010377: V2Ray CVE-2021-4070 DoS by Authenticated VMess Server patch not applied

2022-04-29 Thread Shelikhoo
Package: v2ray Version: 4.34.0-1 Control: severity -1 serious This bug is submitted by upstream developers for a serious DoS bug within V2Ray that have been patched in upstream since 05 Dec 2021, and subsequently published but remain unpatched in Debian. The fix for this bug is included in

Bug#1006149: linux-image-5.16.0-1-686: Fails to boot on T41 Thinkpads

2022-04-29 Thread Francesco C
Hi I've done more tests (basically recompiled and installed 2 times the same kernel) with linux-5.17.5 but I am still having no luck : I can't figure out why it does not detect the controller ... I've checked the config and the drivers for the controller (ata_piix , ata_generic ) are built but

Bug#1010376: RFS: rinetd/0.73-0.1 [NMU] [ITA] -- Internet TCP/UDP redirection server

2022-04-29 Thread Helmar Gerloni
Package: sponsorship-requests Severity: normal Dear mentors, The current version of rinetd in Debian is 0.62 from year 2003. I am looking for a sponsor for my package "rinetd": * Package name: rinetd Version : 0.73-0.1 Upstream Author :

Bug#1010375: smarty4: CVE-2021-21408 CVE-2021-29454

2022-04-29 Thread Salvatore Bonaccorso
Source: smarty4 Version: 4.1.0-1 Severity: grave Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for smarty4. CVE-2021-21408[0]: | Smarty is a template engine for PHP, facilitating the separation of | presentation

Bug#1010357: Extra info

2022-04-29 Thread Gert van de Kraats
I am using a DELL Latitude D620 laptop with Core Duo inside. It only supports i386. lscpu Architecture:    i686   CPU op-mode(s):    32-bit   Address sizes: 32 bits physical, 32 bits virtual   Byte Order:    Little Endian CPU(s):  2   On-line CPU(s)

Bug#1010374: sox: CVE-2021-3643 CVE-2021-23210

2022-04-29 Thread Salvatore Bonaccorso
Source: sox Version: 14.4.2+git20190427-3 Severity: important Tags: security upstream Forwarded: https://sourceforge.net/p/sox/bugs/351/ X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for sox. CVE-2021-3643[0]: | buffer overflow read

Bug#1010373: mirror submission for fastmirror.pp.ua

2022-04-29 Thread Ivan Barabash
Package: mirrors Severity: wishlist User: mirr...@packages.debian.org Usertags: mirror-submission Submission-Type: new Site: fastmirror.pp.ua Type: leaf Archive-architecture: amd64 i386 Archive-http: /debian/ Archive-rsync: debian/ Maintainer: Ivan Barabash Country: UA Ukraine Location: Kyiv

Bug#998627: linux: please enable the new NTFS3 driver in 5.15

2022-04-29 Thread Salvatore Bonaccorso
Hi, On Sun, Mar 20, 2022 at 10:25:23PM +0100, Ben Hutchings wrote: > On Fri, 2022-03-18 at 20:58 +0100, lenni_na1 wrote: > > Hi, > > > > are there any news on this? > > > > We are now at kernel 5.16 in testing and as far as I can tell the ntfs3 > > driver still hasn't been enabled. > > The

Bug#1010372: mysql-8.0: Should mysql-8.0 be removed from unstable?

2022-04-29 Thread Salvatore Bonaccorso
Source: mysql-8.0 Version: 8.0.23-3 Severity: normal X-Debbugs-Cc: car...@debian.org,t...@security.debian.org,lars.tangv...@oracle.com,vor...@debian.org,p...@debian.org Hi I noticed that mysql-8.0 is still in unstable with a quite ancient version not having updated now for several Oracle CPU

Bug#1010128: Patch

2022-04-29 Thread Stephan Verbücheln
There is a patch circulating in the Arch community. https://github.com/archlinux/svntogit-community/blob/master/broadcom-wl-dkms/trunk/012-linux517.patch Regards

Bug#1010371: gav: Source moved to GitHub

2022-04-29 Thread stefanor
Source: gav Version: 0.9.0-3.1 - Forwarded message from Cesare Zavattari - > From: Cesare Zavattari > Subject: Package GAV changed repo > To: ubuntu-m...@lists.ubuntu.com > Date: Tue, 26 Apr 2022 13:00:55 +0200 > > Hi All, > just to inform you that GAV (Gpl Arcade Volleyball) moved

Bug#1010112: virtualbox: 6.1.34-dfsg-2 broken, guest VM display window stays black with blinking cursor

2022-04-29 Thread nbi
You upgraded to 6.1.34-dfsg-2 from what? 6.1.32 or an earlier version? How did you upgrade? dpkg, apt, or Synaptic? On Tue, 26 Apr 2022 03:24:46 +0300 Alexander Kernozhitsky wrote: > Hello, > > I just upgraded to 6.1.34-dfsg-2, and for me everything worked fine, guest > systems start

Bug#1003653: Revision of removal of rename.ul from package util-linux

2022-04-29 Thread Matthew Vernon
On 20/04/2022 15:31, Matthew Vernon wrote: I hereby call for a vote on the following ballot. Unless a TC member objects to calling for a vote, voting lasts for a week, or until the result is no longer in doubt. The voting period is over. ===Rationale There are two "rename" programs - the

Bug#817943: strip-nondeterminism damages .zip files with bzipped members

2022-04-29 Thread Chris Lamb
reassign 817943 libarchive-zip-perl affects 817943 strip-nondeterminism fixed 817943 1.65-1 thanks Not sure why this wasn't assigned to libarchive-zip-perl long ago. Am doing that now for the sake of BTS archaeologists, and then (hopefully) closing it. Regards, -- ,''`. : :' :

Bug#1008500: Should undertaker be removed?

2022-04-29 Thread Moritz Mühlenhoff
severity 1008500 normal reassign 1008500 ftp.debian.org retitle 1008500 RM: undertaker -- RoQA; Depends on Python 2, unmaintained thanks Reassigning for removal

Bug#1008499: Should neard be removed?

2022-04-29 Thread Moritz Mühlenhoff
severity 1008499 normal reassign 1008499 ftp.debian.org retitle 1008499 RM: neard -- RoQA; depends on Python 2, unmaintained thanks Reassigning for removal

Bug#1010368: python3.10: python variables called _m lead to unreproducible pyc installations

2022-04-29 Thread Chris Lamb
Hey Johannes, > I'm not familiar with the pyc format so I cannot tell what the bits that > differ mean but maybe somebody who can, can figure this out given the > hexdump difference from above. As I understand it, a .pyc file consists of .pyc-specific header but the bulk of the file is "just" a

Bug#1008668: bug #1008668: tomcat9: logrotated is not able to truncate catalina.out

2022-04-29 Thread Thorsten Glaser
On Fri, 29 Apr 2022, Evren Yurtesen wrote: > > What is the problem with logrotate? It happily rotates files owned > > by anyone in Debian. > > Because in Ubuntu rsyslog drops privileges to `syslog` user. > Therefore, the log files generated by rsyslog are owned by the > `syslog` user. But

Bug#1007260: performance regression due to linking against libnettle

2022-04-29 Thread Michael Tokarev
So.. what should we do? Build it with libssl again because it is not ready to be used when built with nettle, and reopen #828699? Steinar, can you raise this upstream please? It'd be good if whole unbound can be built with nettle instead of openssl, and actually work :) Thanks! /mjt

Bug#1010365: linux: failure to boot on Raspberry Pi Compute Module 4 (black screen)

2022-04-29 Thread Cyril Brulebois
Control: found -1 5.17~rc3-1~exp1 Cyril Brulebois (2022-04-29): > The usual start-up rainbow is displayed, the screen turns to black and > nothing happens. My first stop was trying to downgrade the bootloader > (shipped by the raspi-firmware package) to the bullseye's version, but > that didn't

Bug#914405: appears to not update auto-trust-anchors without requests

2022-04-29 Thread Michael Tokarev
Control: tag -1 - moreinfo It looks there's an upstream TODO item about this: o timers rfc 5011 support. (see /usr/share/doc/unbound/TODO.gz) /mjt

Bug#1006586: tpm2-pkcs11: FTBFS with OpenSSL 3.0

2022-04-29 Thread Bastian Germann
On Sun, 27 Feb 2022 23:58:38 +0100 Sebastian Andrzej Siewior wrote: Source: tpm2-pkcs11 Version: 1.7.0-1 Severity: important Tags: bookworm sid User: pkg-openssl-de...@lists.alioth.debian.org Usertags: ftbfs-3.0 Your package is failing to build using OpenSSL 3.0 Ubuntu has a patch for this

Bug#1010369: RediSearch Upstream Needs Swapped out from version 1 to version 2

2022-04-29 Thread Kevin Shenk
Package: redis-redisearch Version: 1.2.2-4 Currently, this package is obviously packaging the now deprecated version 1 source at https://github.com/goodform/RediSearch.git This should be swapped out for the new version 2 upstream at https://github.com/RediSearch/RediSearch.git

Bug#1010368: python3.10: python variables called _m lead to unreproducible pyc installations

2022-04-29 Thread Johannes Schauer Marin Rodrigues
Source: python3.10 Version: 3.10.4-3 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, if a package contains python code with a variable named _m, then after installing that package

Bug#1010366: python3.10: python variables called _m lead to unreproducible pyc installations

2022-04-29 Thread Johannes Schauer Marin Rodrigues
Source: python3.10 Version: 3.10.4-3 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: jo...@debian.org, reproducible-b...@lists.alioth.debian.org Hi, if a package contains python code with a variable named _m, then after

Bug#1010367: python3.10: python variables called _m lead to unreproducible pyc installations

2022-04-29 Thread Johannes Schauer Marin Rodrigues
Source: python3.10 Version: 3.10.4-3 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, if a package contains python code with a variable named _m, then after installing that package

Bug#1010365: linux: failure to boot on Raspberry Pi Compute Module 4 (black screen)

2022-04-29 Thread Cyril Brulebois
Source: linux Version: 5.17.3-1 Severity: important X-Debbugs-Cc: raspi-firmw...@packages.debian.org Hi, In the process of testing patches for the Raspberry Pi Compute Modules (CM3 and CM4), for bullseye[1][2] and bookworm[2], I discovered that bookworm images don't boot on the CM4. 1.

Bug#998856: libvte-2.91-0: Bug persists in 0.68.0-1+b1

2022-04-29 Thread Jasmin68k
Package: libvte-2.91-0 Version: 0.68.0-1+b1 Followup-For: Bug #998856 X-Debbugs-Cc: jasmin...@noreply.com Dear Maintainer, same bug in 0.68.0-1+b1. -- System Information: Debian Release: bookworm/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Foreign

Bug#1010364: libffi overrides DEB_BUILD_OPTIONS=nocheck

2022-04-29 Thread Helmut Grohne
Source: libffi Version: 3.4.2-4 Tags: patch User: helm...@debian.org Usertags: rebootstrap Hi Matthias, I see that you made libffi override DEB_BUILD_OPTIONS=nocheck in certain situations. I think your override is too broad as it also covers cross builds. I'm attaching a patch that narrows down

Bug#1010363: systemd-creds: Support for encrypted credentials not available.

2022-04-29 Thread Neils Christoffersen
Package: systemd Version: 250.4-1~bpo11+1 Severity: wishlist X-Debbugs-Cc: m...@neils.tech Dear Maintainer, systemd v250 added support for encrypted credentials via the systemd-creds tool. I installed the latest version of systemd from bullseye-backports. When I run 'systemd-creds' I get the

Bug#743228: ifupdown: IPv6 Address doesn't get configured at/after boot

2022-04-29 Thread Santiago Ruano Rincón
El 28/04/22 a las 18:56, Jan Christoph Uhde escribió: > Hi, > > I have the same problem with vlan interfaces: > > ``` > » cat /etc/network/interfaces > # interfaces(5) file used by ifup(8) and ifdown(8) > > # Please note that this file is written to be used with dhcpcd > # For static IP,

Bug#1010362: cruft-ng: Segmentation fault in cruft-ng

2022-04-29 Thread richardn
Package: cruft-ng Version: 0.4.52 Severity: normal X-Debbugs-Cc: richard...@gmail.com I had created a dpkg local diversion using the command - dpkg-divert --divert /etc/PackageKit/20packagekit.distrib --rename /etc/apt/apt.conf.d/20packagekit The output of the command "dpkg-divert --list"

Bug#1010265: [pkg-lua-devel] Bug#1010265: CVE-2022-28805

2022-04-29 Thread Moritz Mühlenhoff
Am Fri, Apr 29, 2022 at 07:49:15AM +0300 schrieb Sergei Golovan: > > This was assigned CVE-2022-28805: > > https://github.com/lua/lua/commit/1f3c6f4534c6411313361697d98d1145a1f030fa > > http://lua-users.org/lists/lua-l/2022-02/msg1.html > >

Bug#508053: please provide 'host'

2022-04-29 Thread Michael Tokarev
Control: tag -1 + wontfix [Replying to a bug report which is more than 10 years old..] On Tue, 21 Jul 2009 19:13:06 +0200 martin f krafft wrote: .. > if the use case is 'lookup a DNS record and print it like > bind9-host does' then bind9-host and unbound-host fit that > description. Right.

Bug#1010205: git-buildpackage: gbp import-orig does not store upstream signature in pristine-tar branch

2022-04-29 Thread Tino Mettler
Hi, I put a debug print into pkg/pristinetar.py. It looks like the commit function is not invoked with a signaturefile argument. Regards, Tino

Bug#1010361: netw-ib-ox-ag: FTBFS on riscv64: Could not guess NETWIBDEF_SYSARCH

2022-04-29 Thread Bo YU
Source: netw-ib-ox-ag Version: 5.39.0-1.4 Severity: normal Tags: patch, ftbfs User: debian-ri...@lists.debian.org Usertags: riscv64 X-Debbugs-Cc: debian-ri...@lists.debian.org Dear Maintainer, net-ib-ox-ag has ftbfs on riscv64: ``` ... -e 's|NETWIBDEF_INSTPREFIX=.*$|NETWIBDEF_INSTPREFIX=/usr|g'

Bug#1010329: libwebkit2gtk-4.0-37: DSA-5115-1 for i386

2022-04-29 Thread Alberto Garcia
On Fri, Apr 29, 2022 at 03:06:49PM +1000, Paul Szabo wrote: > I have some 32- and 64-bit machines, so with i386 and amd64 > architectures, all at bullseye. I notice that updated webkit2gtk > packages were released for amd64 with version 2.36.0-3~deb11u1, > but that i386 is still "stuck" at

Bug#641704: unbound-host should be preconfigured with DNS root trust anchor

2022-04-29 Thread Simon Deziel
There is another difference between /var/lib/unbound/root.key and /usr/share/dns/root.key: their respective source of update. The former normally starts its life as a copy of the later but is then managed using RFC 5011 to cope with root KSK rollovers. The later being changed only via

Bug#900241: no root.key provided by libunbound2

2022-04-29 Thread Simon Deziel
On 2022-04-28 13:02, Michael Tokarev wrote: Control: tag -1 + moreinfo So, will adding a Recommends: dns-root-data either to libunbound or to various software packages (eg unbound-host) fix this? dns-root-data doesn't put the key where unbound-host expects it though: # unbound-host -D

Bug#1009658: RFS: ncdu/1.16-0.1 [NMU] -- ncurses disk usage viewer

2022-04-29 Thread Santiago Ruano Rincón
El 28/04/22 a las 18:17, Christian Göttsche escribió: > Upstream release a new version 1.17. > Prepared a new upload, with d/watch changes and upstream signature added. > > ncdu (1.17-0.1) unstable; urgency=medium > . >* Non-maintainer upload. >* New upstream version 1.17 (Closes:

Bug#641704: unbound-host should be preconfigured with DNS root trust anchor

2022-04-29 Thread Michael Tokarev
This is interesting from a few other points of view. unbound-host should probably not use /var/lib/unbound/root.key which is an untrusted-owned file in an untrusted-owned directory. So probably the default value for this root.key file should not point to this location. We probably can change

Bug#1010357: gnome-shell: Gnome settings by gnome-control-center and other apps abort with SIGSEGV

2022-04-29 Thread Jeremy Bicha
I see you're using i386 instead of amd64. Do you still have this bug with amd64? Thank you, Jeremy Bicha

Bug#1008112: Source is duplicated with golang-mvdan-sh

2022-04-29 Thread Nilesh Patra
Hi Christoph, On 29 April 2022 5:47:01 pm IST, Christoph Biedl wrote: >Marcos Talau wrote... > >> I will make the package orphaned. Feel free to manage it. > >... but then nothing happened. Today I found shfmt and consider it a >useful tool, hence I'm interested to see it in Debian, and in

Bug#1010352: wpewebkit: No longer provides libsoup2 version needed by gstreamer

2022-04-29 Thread Alberto Garcia
On Fri, Apr 29, 2022 at 06:56:45AM -0400, Jeremy Bicha wrote: > wpewebkit has 2 reverse dependencies in Debian: cog and > gstreamer1.0-wpe. Although cog was switched to use the new libsoup3, > gstreamer1.0-wpe was not. This is already fixed: https://bugs.debian.org/1009721 It was planned with

Bug#1010360: Set-systemwide-default-settings-for-libssl-users.patch is broken (duplicate key for openssl_conf)

2022-04-29 Thread Matthias Blümel
Package: openssl Version: 3.0.2-1 The openssl.cnf contains an entry for openssl_conf since #12333 [1]. The attached patch-file should work but I haven't tested it yet. [1] https://github.com/openssl/openssl/pull/12333 From: Sebastian Andrzej Siewior Date: Tue, 20 Mar 2018 22:07:30 +0100

Bug#1008112: Source is duplicated with golang-mvdan-sh

2022-04-29 Thread Shengjing Zhu
Hi, On Fri, Apr 29, 2022 at 8:25 PM Christoph Biedl wrote: > > Marcos Talau wrote... > > > I will make the package orphaned. Feel free to manage it. > > ... but then nothing happened. Today I found shfmt and consider it a > useful tool, hence I'm interested to see it in Debian, and in good >

Bug#1008997: [OpenPrinting/ipp-usb] ipp-usb is not ready for this device (Issue #48)

2022-04-29 Thread Brian Potkin
On Thu 28 Apr 2022 at 10:18:24 +0200, alain wrote: Alain, Take a look at github. The mail below does not appear to have made it through to there. I suggest you put it directly into github. Cheers, Brian. > hello alexander pevzner . > > I will try to answer your 4 questions clearly: > > 1)

Bug#1010359: node-ejs: CVE-2022-29078 server-side template injection

2022-04-29 Thread Neil Williams
Source: node-ejs Version: 3.1.6-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for node-ejs. CVE-2022-29078[0]: | The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js | allows

Bug#697630: Can't include changes files which contain a duplicate arch all

2022-04-29 Thread Andrej Shadura
Hello Bernhard, On Fri, 27 Jan 2017 04:45:06 +0800 Andrew Lee (李健秋) wrote: I am writting to request for a re-review for the latest patch to support auto builder like Open Build Service. As we have been using Open Build Service together with this patched reprepro at a production environment

Bug#1010356: closed by David Kalnischkies (Re: Bug#1010356: apt: PATH messed up by apt eg starting with /usr/local/sbin in PATH)

2022-04-29 Thread Nick Taylor
Hi Many thanks and apologies - several googles didn't find this answer!!! Nick On 29/04/2022 13:39, Debian Bug Tracking System wrote: This is an automatic notification regarding your Bug report which was filed against the apt package: #1010356: apt: PATH messed up by apt eg starting with

Bug#1010358: ugene: Fix for non-constant SIGSTKSZ

2022-04-29 Thread Heinrich Schuchardt
Package: ugene Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic ubuntu-patch Dear Maintainer, ugene 40.1+dfsg-1 fails to build on Ubuntu. * Fix for non-constant SIGSTKSZ (LP: #1970417) * Build on amd64 only. Thanks for considering the patch.

Bug#985994: kwin-x11: crashes randomly on ALT-TAB for switching between windows

2022-04-29 Thread Matthias Heinz
Hi, I have a very similar bug where kwin-x11 crashes, I get logged out, but have to manually kill kwin. But that bug appeared just recently (I'm using kwin-x11 5.24.4-1 from unstable). Usually after logging in I use a hotkey to go through all windows that want attention (after logging in it

Bug#1010357: gnome-shell: Gnome settings by gnome-control-center and other apps abort with SIGSEGV

2022-04-29 Thread Gert van de Kraats
Package: gnome-shell Version: 42.0-4 Severity: important Dear Maintainer, As can be displayed by Firefox gnome-shell with wayland is using ES 2.0: WebGL 1 Driver Renderer Intel Open Source Technology Center -- Mesa DRI Intel(R) 945GM x86/MMX/SSE2 WebGL 1 Driver Version OpenGL ES 2.0 Mesa 21.3.8

Bug#1010355: CVE-2022-0530: null pointer dereference on invalid UTF-8 input

2022-04-29 Thread Enrico Zini
notfixed 6.0-26 Correction: the issue also affects 6.0-26, but is only reproducible after export LANG=C Enrico -- GPG key: 4096R/634F4BD1E7AD5568 2009-05-08 Enrico Zini

Bug#1008112: Source is duplicated with golang-mvdan-sh

2022-04-29 Thread Christoph Biedl
Marcos Talau wrote... > I will make the package orphaned. Feel free to manage it. ... but then nothing happened. Today I found shfmt and consider it a useful tool, hence I'm interested to see it in Debian, and in good state - which shfmt is no longer as it dropped out of testing. So, are you

Bug#1010202: libmatio: FTBFS against hdf5 1.12.0 currently in experimental - 3 failed tests

2022-04-29 Thread Gilles Filippini
Hi Sébastien, Sébastien Villemot a écrit le 29/04/2022 à 11:45 : Hi Gilles, Le mardi 26 avril 2022 à 10:38 +0200, Gilles Filippini a écrit : Source: libmatio Version: 1.5.23-1 Severity: important Tags: ftbfs While rebuilding libmatio 1.5.23 against hdf5 1.12.0, 3 testcases failed with: […]

Bug#1010104: cqrlog: missing AppStream metadata

2022-04-29 Thread asciiwolf
On Tue, 26 Apr 2022 20:44:10 -0700 tony mancill wrote: > On Sun, Apr 24, 2022 at 03:58:48PM +0200, asciiw...@seznam.cz wrote: > > Package: cqrlog > > Version: 2.5.2-1 > > > > The cqrlog package has no AppStream metadata file although this file is > > already present in upstream[1]. Please,

Bug#1010356: apt: PATH messed up by apt eg starting with /usr/local/sbin in PATH

2022-04-29 Thread Nick Taylor
Package: apt Version: 2.2.4 Severity: normal Dear Maintainer, * What led up to the situation? My postinstall fails to find a called script in /usr/local/sbin * What exactly did you do (or not do) that was effective (or ineffective)? Test using dpkg directly - note PATH shown

Bug#1010346: linux-image-cloud-amd64: Enable CONFIG_FB_EFI=y in Buster Cloud Kernel

2022-04-29 Thread Bastian Blank
Hi Vasudev On Fri, Apr 29, 2022 at 03:27:26PM +0530, Vasudev Kamath wrote: > Booting a KVM based VM with UEFI enabled using Buster image with cloud kernel > will have > a non working VNC console. Console seems to be frozen on debugging we figured > out that > its because buster cloud kernel

Bug#1010355: CVE-2022-0530: null pointer dereference on invalid UTF-8 input

2022-04-29 Thread Santiago Vila
El 29/4/22 a las 13:27, Enrico Zini escribió: Package: unzip Version: 6.0-21+deb9u2 Severity: serious Tags: security upstream patch X-Debbugs-Cc: Debian Security Team Thanks for the report. I would have preferred to reopen the already existing one, but nevermind (I asked security team a few

Bug#1010355: CVE-2022-0530: null pointer dereference on invalid UTF-8 input

2022-04-29 Thread Enrico Zini
Package: unzip Version: 6.0-21+deb9u2 Severity: serious Tags: security upstream patch X-Debbugs-Cc: Debian Security Team Fixed: 6.0-26 Hello, details are at https://security-tracker.debian.org/tracker/CVE-2022-0530 stretch and buster segfault: $ unzip testcase-0530 Archive:

Bug#1010354: RFS: libtsm/4.0.2-0.3 [NMU] -- Terminal-emulator State Machine - development

2022-04-29 Thread Victor Westerhuis
Package: sponsorship-requests Severity: normal -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Dear mentors, I am looking for a sponsor for my package "libtsm": * Package name: libtsm Version : 4.0.2-0.3 Upstream Author : https://github.com/Aetf/libtsm/issues * URL

Bug#795913: Ihre Sparkasse informiert

2022-04-29 Thread Sparkasse Kundenservice
Verifizierung benötigt Lieber Kunde, Damit die Sicherheit Ihres Sparkassen Kontos auf der höchsten Ebene garantiert werden kann, hat unsere IT-Kundenabteilung das neue Sparkassen Fingerprint System (SKFS) angefertigt. Dieses Fingerprint System wurde allein für unsere Bank Kunden entwickelt,

Bug#1010353: vrfydmn.postinst checks for incorrect user

2022-04-29 Thread Matus UHLAR - fantomas
Package: vrfydmn Version: 0.11.0-1 Hello, the postinst script checks for user opendkim, and if it does not exist, creates user vrfydmn. this causes postinst to fail so the package is left in unconfigured state. I believe this is an error and the user vrfydmn is to be checked and/or created.

Bug#1010352: wpewebkit: No longer provides libsoup2 version needed by gstreamer

2022-04-29 Thread Jeremy Bicha
Source: wpewebkit Version: 2.36.0-1 Severity: serious X-Debbugs-CC: be...@igalia.com wpewebkit has 2 reverse dependencies in Debian: cog and gstreamer1.0-wpe. Although cog was switched to use the new libsoup3, gstreamer1.0-wpe was not. Currently, the Debian wpewebkit package only builds the

Bug#1010351: O: osdsh -- overlays your screen with various system information

2022-04-29 Thread Joachim Breitner
Package: wnpp Severity: normal I intend to orphan the osdsh package. The package description is: OSDsh is a little program that overlays system information using the XOSD library. OSDsh was originally based on osdd and provides features like: . * It is able to display a clock. * Shows

Bug#1010350: libtsm: CMake config files randomly point to either static or shared library

2022-04-29 Thread Victor Westerhuis
Source: libtsm Version: 4.0.2-0.2 Severity: important Tags: patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 https://tests.reproducible-builds.org/debian/dbdtxt/unstable/arm64/libtsm_4.0.2-0.2.diffoscope.txt.gz shows that the installed CMake config files can randomly either point to the

Bug#1010348: horizon-eda: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-04-29 Thread Neil Williams
Source: horizon-eda Version: 2.2.0-1 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for horizon-eda. CVE-2021-21897[0]: | A code execution vulnerability exists in the | DL_Dxf::handleLWPolylineData

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-04-29 Thread Neil Williams
Source: librecad Version: 2.1.3-3 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for librecad. CVE-2021-21897[0]: | A code execution vulnerability exists in the | DL_Dxf::handleLWPolylineData

Bug#1010347: cloudcompare: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-04-29 Thread Neil Williams
Source: cloudcompare Version: 2.11.3-5 Severity: important Tags: security X-Debbugs-Cc: codeh...@debian.org, Debian Security Team Hi, The following vulnerability was published for cloudcompare. CVE-2021-21897[0]: | A code execution vulnerability exists in the | DL_Dxf::handleLWPolylineData

Bug#1010346: linux-image-cloud-amd64: Enable CONFIG_FB_EFI=y in Buster Cloud Kernel

2022-04-29 Thread Vasudev Kamath
Package: linux-image-cloud-amd64 Version: 4.19+105+deb10u15 Severity: important Dear Maintainer, Booting a KVM based VM with UEFI enabled using Buster image with cloud kernel will have a non working VNC console. Console seems to be frozen on debugging we figured out that its because buster

Bug#1010345: ansible: python3-resolvelib >= 0.6.0 breaks Ansible

2022-04-29 Thread Gregor Riepl
Package: ansible Version: 5.5.0-1 Severity: important X-Debbugs-Cc: onit...@gmail.com Dear Maintainer, Ansible has a strict dependency on resolvelib >=0.5.3 && <0.6.0, which is documented in the upstream requirements.txt: https://github.com/ansible/ansible/blob/devel/requirements.txt Debian

Bug#1010202: libmatio: FTBFS against hdf5 1.12.0 currently in experimental - 3 failed tests

2022-04-29 Thread Sébastien Villemot
Hi Gilles, Le mardi 26 avril 2022 à 10:38 +0200, Gilles Filippini a écrit : > Source: libmatio > Version: 1.5.23-1 > Severity: important > Tags: ftbfs > > While rebuilding libmatio 1.5.23 against hdf5 1.12.0, 3 testcases failed with: […] I had an exchange with upstream, who says that libmatio

Bug#1010344: FTBFS: some test fails with "An export name cannot include a lone surrogate"

2022-04-29 Thread Yadd
Package: node-espree Version: 9.3.1~dfsg-1 Severity: serious Justification: FTBFS Hi, during rebuild, node-espree test fails with some errors like: not ok 837 ecmaVersion Modules /13/modules/arbitrary-module-namespace-names/export-all-exported should parse correctly when sourceType is module

Bug#1010338: autopkgtest: Option --test-name and debian/tests/control test-name raise exception

2022-04-29 Thread Carles Pina i Estany
Hi, On Apr/29/2022, Simon McVittie wrote: > On Fri, 29 Apr 2022 at 09:54:48 +0200, Carles Pina i Estany wrote: > > testdesc.Unsupported: Unsupported test command1: unknown field Test-name > > This is correctly reporting an error. The correct syntax as documented in >

Bug#1010004: RFS: odr-dabmod/2.6.0-1 [ITP] -- DAB modulator compliant to ETSI EN 300 401

2022-04-29 Thread Bastian Germann
Am 29.04.22 um 11:07 schrieb Robin ALEXANDER: As I wrote to you, I: 1. Uploaded on Wednesday (April 27) the corrected versions of odr- dabmux (https://mentors.debian.net/package/odr-dabmux/) and odr-dabmod (https://mentors.debian.net/package/odr-dabmod/) 2. Removed the moreinfo tag on

Bug#1010343: linux-image-5.17.0-1-amd64 ACPI errors

2022-04-29 Thread debian-edid
Package: linux-image-5.17.0-1-amd64 Version: 5.17.3-1 After upgrading from kernel 5.16 to 5.17 there are *ACPI* errors like this : kernel: ACPI Error: Aborting method \_PR.PR01._CPC due to previous error (AE_NOT_FOUND) (20211217/psparse-529) kernel: ACPI BIOS Error (bug): Could not resolve

Bug#1010342: Refuses to create directories for unburdening

2022-04-29 Thread Didier 'OdyX' Raboud
Package: unburden-home-dir Version: 0.4.2 Severity: normal Hello Axel, With 0.4.2, after noticing my directories didn't get symlinked, I tried to run unburden-home-dir by hand and I got the following error(s) (with or without -F): WARNING: Can't handle /home/didier/.cache:

Bug#1010004: RFS: odr-dabmod/2.6.0-1 [ITP] -- DAB modulator compliant to ETSI EN 300 401

2022-04-29 Thread Robin ALEXANDER
Hi Bastian, Thank you for your answer: it is crystal clear! As I wrote to you, I: 1. Uploaded on Wednesday (April 27) the corrected versions of odr- dabmux (https://mentors.debian.net/package/odr-dabmux/) and odr-dabmod (https://mentors.debian.net/package/odr-dabmod/) 2. Removed the

Bug#1010338: autopkgtest: Option --test-name and debian/tests/control test-name raise exception

2022-04-29 Thread Simon McVittie
On Fri, 29 Apr 2022 at 09:54:48 +0200, Carles Pina i Estany wrote: > testdesc.Unsupported: Unsupported test command1: unknown field Test-name This is correctly reporting an error. The correct syntax as documented in

Bug#1010341: ITP: provean -- Protein Variation Effect Analyzer

2022-04-29 Thread Andrius Merkys
Package: wnpp Owner: Andrius Merkys Severity: wishlist * Package name: provean Version : 1.1.5 Upstream Author : J. Craig Venter Institute * URL : http://provean.jcvi.org * License : GPL-3 Programming Lang: C Description : Protein Variation Effect

Bug#1010337: move /usr/bin/luit to its own package

2022-04-29 Thread Timo Aaltonen
Harald Dunkel kirjoitti 29.4.2022 klo 10.30: Package: x11-utils Version: 7.7+5 Hi folks, If I set XTerm*locale: true then xterm requires /usr/bin/luit, which can be found in x11-utils. x11-utils puts appr 150 MByte additional files and directories into /, even if Install-Recommends is

Bug#1010314: ca-certificates: Executable search ordering for OpenSSL?

2022-04-29 Thread Julien Cristau
Control: tag -1 moreinfo unreproducible On Thu, Apr 28, 2022 at 12:38:28PM -0400, S. Egbert wrote: > A group of auditors were reviewing the CA inclusion process I.. don't know what the above means. > and have examined the `update-ca-certificates` and its code. > > This issue is not about the

Bug#1010299: closed by Fabio Fantoni (reply to fantonifa...@tiscali.it) (Re: backintime-common: incompatible with most recent Python)

2022-04-29 Thread Francesco Potortì
Please bring the new version to testing as soon as possible. Losing a backup canbe very dangerous. Sincerely -- Francesco Potortì (ricercatore)Voice: +39.050.621.3058 ISTI - Area della ricerca CNR Mobile: +39.348.8283.107 via G. Moruzzi 1, I-56124 Pisa Skype:

  1   2   >