Bug#1012552: Text on cloud.d.o incorrectly says all checksums are signed

2022-06-08 Thread Ross Vandegrift
Package: cloud.debian.org Severity: normal Hi Olaf, On Fri, Jun 03, 2022 at 10:03:35AM +0200, Olaf Seibert wrote: > The PGP signature files, such as SHA512SUMS.sign, are missing from the pages > https://cdimage.debian.org/images/cloud/bullseye/latest/ and >

Bug#934072: OpenRD images are gone

2022-06-08 Thread Martin Michlmayr
Vagrant, see below: * Martin Michlmayr [2019-08-06 20:10]: > I noticed that there are no pre-built images for OpenRD in buster > anymore. > > I found: > > commit e799d626f45e9c706d05003e3112d481db2870a9 > Author: Vagrant Cascadian > Date: Wed Dec 5 17:45:22 2018 +0100 > > [armel]

Bug#1012550: [Pkg-javascript-devel] Bug#1012550: O: node-node-sass -- Wrapper around libsass

2022-06-08 Thread Nilesh Patra
On 9 June 2022 9:38:59 am IST, Yadd wrote: >On 09/06/2022 05:05, Nilesh Patra wrote: >> Package: wnpp >> Severity: normal >> X-Debbugs-Cc: pkg-javascript-de...@alioth-lists.debian.net >> Control: affects -1 src:node-node-sass >> >> I intend to orphan the node-node-sass package. >> >> This

Bug#1012550: [Pkg-javascript-devel] Bug#1012550: O: node-node-sass -- Wrapper around libsass

2022-06-08 Thread Yadd
On 09/06/2022 05:05, Nilesh Patra wrote: Package: wnpp Severity: normal X-Debbugs-Cc: pkg-javascript-de...@alioth-lists.debian.net Control: affects -1 src:node-node-sass I intend to orphan the node-node-sass package. This was one of the first difficult to do packages that I did, more than 2

Bug#991113: libpam-chroot: pam_chroot.so installed in wrong place - Not able to login after upgrade

2022-06-08 Thread Javier Fernandez-Sanguino
Dear Michael, Thanks for the proposed patch. I will try to review and submit a new package version is the coming days. Saludos, Javier El mié, 8 jun 2022 20:45, M. Buecher escribió: > I had a look at the package source and only the paths in the file > debian/rules [1] have to be changed. >

Bug#1007717: Draft resolution for "Native source package format with non-native version"

2022-06-08 Thread Sean Whitton
Hello, On Wed 08 Jun 2022 at 09:07pm +02, Helmut Grohne wrote: > I find it interesting that you seem to equate git-first with dgit. My > mental model separated those concepts and considered git-first workflows > on salsa as well. And once you equate them, you can derive a lot of > conclusions.

Bug#1012551: O: node-mermaid -- Markdownish syntax for generating flowcharts,

2022-06-08 Thread Nilesh Patra
Package: wnpp Severity: normal X-Debbugs-Cc: pkg-javascript-de...@alioth-lists.debian.net Control: affects -1 src:node-mermaid I intend to orphan the node-mermaid package. It is a pretty cool package that I packaged approx 2 years ago. But owing to lack of personal bandwidth, I need to let it go.

Bug#1012550: O: node-node-sass -- Wrapper around libsass

2022-06-08 Thread Nilesh Patra
Package: wnpp Severity: normal X-Debbugs-Cc: pkg-javascript-de...@alioth-lists.debian.net Control: affects -1 src:node-node-sass I intend to orphan the node-node-sass package. This was one of the first difficult to do packages that I did, more than 2 years ago. But now I have no personal

Bug#997264: seriousproton: ftbfs FIX

2022-06-08 Thread David (Plasma) Paul
Attached is a patch to fix Debian bug #997264. -- Plasma seriousproton_2020.01.15+dfsg-1.1.debdiff Description: Binary data

Bug#1008642: guix pull complains about "No such file or directory"

2022-06-08 Thread Yuxuan Wang
Thank you, Vagrant! That is certainly helpful. I found out that I also need to remove $HOME/.cache/guix, but after that I'm now able to start from scratch again. On Wed, Jun 8, 2022 at 6:50 PM Vagrant Cascadian wrote: > On 2022-06-08, Vagrant Cascadian wrote: > > On 2022-03-29, Yuxuan Wang

Bug#1012549: [riscv] lscpu --all --extended output is empty

2022-06-08 Thread 肖盛文
Package: util-linux Version: 2.38-4 Severity: minor Tags: upstream User: debian-ri...@lists.debian.org Usertags: riscv64 X-Debbugs-Cc: atzli...@sina.com, debian-ri...@lists.debian.org Hi, My board is starfive[1], it's CPU is sifive u74. lscpu --all --extended output is empty: lscpu --all

Bug#1008642: guix pull complains about "No such file or directory"

2022-06-08 Thread Vagrant Cascadian
On 2022-06-08, Vagrant Cascadian wrote: > On 2022-03-29, Yuxuan Wang wrote: >> $ guix pull >> Updating channel 'guix' from Git repository at >> 'https://git.savannah.gnu.org/git/guix.git'... >> Authenticating channel 'guix', commits 9edb3f6 to 1d62b15 (100 new >> commits)... >>

Bug#1008642: guix pull complains about "No such file or directory"

2022-06-08 Thread Vagrant Cascadian
Control: retitle 1008642 purge /gnu/store and /var/guix when guix is purged On 2022-03-29, Yuxuan Wang wrote: > I have been using both guix and nix-setup-systemd on this machine for a while, > until one day I run out of inodes on the root partition. At the time that > happened I knew it would be

Bug#1012405: guix: Guix command uses less but less does not exist in dependent software

2022-06-08 Thread Taiju HIGASHI
Hi Vagrant, Thanks for checking. I think there is also a problem with the code and will work on a fix. However, I still wonder if we should also change the Debian package definitions. The recommended packages for git include less, but I think it would be more user-friendly to include less in the

Bug#1012548: libwebkit2gtk-4.1-0: Offline renderer SIGSEGV on i386

2022-06-08 Thread karogyoker
Package: libwebkit2gtk-4.1-0 Version: 2.36.3-1 Severity: normal X-Debbugs-Cc: karogyoker2+deb...@gmail.com Dear Maintainer, The problem is reproducible if I try to open this webpage in epiphany-browser: https://www.microsoft.com/en-us/software-download/windows10ISO The problem is that Gnome Web

Bug#1012538: knocked out usability - module 'collections' has no attribute 'Callable'

2022-06-08 Thread Tyler Schwend
The Debian packaged version is much older than the current version. On Wednesday, June 8, 2022, Arnaldo Pirrone wrote: > Package: chirp > Version: 1:20200227+py3+20200213-3 > Severity: grave > X-Debbugs-Cc: it9...@gmail.com > > Just tried using this software to program my radio and found out it

Bug#1012547: linux: disable user namespaces per default

2022-06-08 Thread Philippe Cerfon
Source: linux Version: 5.17.11-1 Severity: normal Tags: security Hi. Some time ago, Debian decided to enable user namespaces per default. Since then we've had numerous security holes which would have been prevented when user namespaces were disabled. I vaguely recall at least around 6-7 such

Bug#1012546: clog: Please implement extended regular expressions with -E command line switch

2022-06-08 Thread Patrik Schindler
Package: clog Version: 1.3.0-1+b1 Severity: wishlist Tags: upstream As said in the subject: Please implement extended regular expressions with -E command line switch. I've finished cleanup of some logcheck rules and wanted to use clog for adding helpful colors. Unfortunately, I need to rework

Bug#1012544: libworkflow1: Broken shared library packaging

2022-06-08 Thread Guillem Jover
Package: libworkflow1 Version: 0.9.10-1 Severity: serious Hi! This package has several problems: - It contains a shared library without a SOVERSION ,--- $ objdump -p /usr/lib/x86_64-linux-gnu/libworkflow.so | grep SONAME SONAME libworkflow.so `--- This means any

Bug#1009169: please package new emacs version 28.1

2022-06-08 Thread Xiyue Deng
Package: emacs Followup-For: Bug #1009169 Hi Rob, Thanks for maintaining Emacs in Debian! I've been a long time Emacs user and would like to help in anyway you prefer. I had some experiences in Debian packaging a few years ago and have been relearning everything from the docs like [1] and

Bug#1012004: srpc: Unorthodox binary package content organization

2022-06-08 Thread Guillem Jover
On Wed, 2022-06-08 at 14:03:06 +, Lance Lin wrote: > > Ideally the .a archive and the .so linked script (which just redirects > > the linker to always use the .a archive, so there's no actual shared > > library), should be moved into the libsrpc-dev package as the usual > > convention. The

Bug#1012541: xdg-desktop-portal: Filesystem 'fuse.portal' is not recognised as a valid filesystem

2022-06-08 Thread tmcconnell168
Well, hopefully the patch gets applied soon. Thanks for the information. Tim On Wed, 2022-06-08 at 23:06 +0100, Simon McVittie wrote: > Control: reassign -1 tiger > Control: forcemerge 987512 -1 > Control: affects -1 + xdg-desktop-portal > > On Wed, 08 Jun 2022 at 16:45:21 -0500, Tim McConnell

Bug#1012536: guix: Debian's guix tries using Guix' glibc locales installed in /var/guix/profiles/... instead of Debian's glibc locales

2022-06-08 Thread Maxime Devos
Vagrant Cascadian schreef op wo 08-06-2022 om 14:43 [-0700]: > So do you now have... > >   ExecStart=/usr/bin/guix-daemon --build-users-group=_guixbuild >   Environment=LC_ALL=C.UTF-8 > > > Does this mean the build environment that guix-daemon creates are > running in the C.UTF-8 locale,

Bug#1012541: xdg-desktop-portal: Filesystem 'fuse.portal' is not recognised as a valid filesystem

2022-06-08 Thread Simon McVittie
Control: reassign -1 tiger Control: forcemerge 987512 -1 Control: affects -1 + xdg-desktop-portal On Wed, 08 Jun 2022 at 16:45:21 -0500, Tim McConnell wrote: > test -x /usr/sbin/tigercron && { [ -r "$DEFAULT" ] && . "$DEFAULT" ; nice > -n$NICETIGER /usr/sbin/tigercron -q ; } > --CONFIG--

Bug#1012543: debhelper: setting HOME/XDG* for {override,execute_{before,after}}_dh_auto_*

2022-06-08 Thread Andreas Beckmann
Package: debhelper Version: 13.7.1 Severity: normal Hi, I just encountered again the execute_after_dh_auto_build-indep target in src:pyopencl which builds the documentation and therefore indirectly calls sphinx which insists on having a writable home directory ... It would be great if debhelper

Bug#1012542: RFS: streamlink/4.1.0-1 -- CLI for extracting video streams from various websites to a video player

2022-06-08 Thread Alexis Murzeau
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "streamlink" for a new upstream version 4.1.0. * Package name: streamlink Version : 4.1.0-1 Upstream Author : Streamlink Team * URL :

Bug#1012537: vim-addon-manager: Error when processing 02tlib plug in

2022-06-08 Thread James McCoy
Control: reassign -1 vim-tlib Control: forcemerge 996477 -1 On Wed, Jun 08, 2022 at 03:25:42PM -0500, Tim McConnell wrote: > What led up to the situation? Unknown, error just started appearing. > > What exactly did you do (or not do) that was effective (or ineffective)? > Unknown if an update

Bug#1012541: xdg-desktop-portal: Filesystem 'fuse.portal' is not recognised as a valid filesystem

2022-06-08 Thread Tim McConnell
Package: xdg-desktop-portal Version: 1.14.4-1 Severity: normal X-Debbugs-Cc: tmcconnell...@gmail.com Dear Maintainer, What led up to the situation? Unsure, I started getting these after Tiger tries to run a cron job. What exactly did you do (or not do) that was effective (or ineffective)? No

Bug#1012536: guix: Debian's guix tries using Guix' glibc locales installed in /var/guix/profiles/... instead of Debian's glibc locales

2022-06-08 Thread Vagrant Cascadian
On 2022-06-08, Maxime Devos wrote: > In /etc/systemd/system/guix-daemon.service, there's the line: > > Environment='GUIX_LOCPATH=/var/guix/profiles/per-user/root/guix-profile/lib/locale' > LC_ALL=en_US.utf8 > > However, I'm using Debian's guix so shouldn't it look for glibc's > locales instead?

Bug#1011875: golang-github-opencontainers-runtime-tools: FTBFS unreproducible

2022-06-08 Thread Reinhard Tartler
My hunch might have been correct, the fresh upload did build successfully on buildds. yay! On Sun, Jun 5, 2022 at 7:12 AM Reinhard Tartler wrote: > Just a hunch, is it possible that your build environment did not have the > package 'ca-certificates' present whereas mine does? > > I wonder

Bug#1012540: pelican: The contents of man of "pelican" and "pelican-plugins" seem to be wrong.

2022-06-08 Thread KenichiroMATOHARA
Package: pelican Version: 4.7.1+dfsg-2 Severity: normal Dear Maintainer, It seems that the content of "man pelican-plugins" is that of "pelican", and the content of "man pelican" is an old version (3.7.1). > $ man pelican-plugins | head -1 > PELICAN(1)

Bug#1011863: guix: FTBFS: tests fail

2022-06-08 Thread Vagrant Cascadian
Control: forwarded 1011863 https://issues.guix.gnu.org/55506 Control: tags 1011863 fixed-upstream On 2022-06-08, Vagrant Cascadian wrote: > On 2022-05-26, Vagrant Cascadian wrote: >> On 2022-05-26, Lucas Nussbaum wrote: >>> During a rebuild of all packages in sid, your package failed to build >>>

Bug#1012405: guix: Guix command uses less but less does not exist in dependent software

2022-06-08 Thread Vagrant Cascadian
Control: forwarded 1012405 https://issues.guix.gnu.org/55845 On 2022-06-06, Taiju HIGASHI wrote: > * What led up to the situation? > A situation that was being verified with the help of an acquaintance. > > Note: This is occurring in a container executed with the following command. > > docker run

Bug#1011863: guix: FTBFS: tests fail

2022-06-08 Thread Vagrant Cascadian
On 2022-05-26, Vagrant Cascadian wrote: > On 2022-05-26, Lucas Nussbaum wrote: >> During a rebuild of all packages in sid, your package failed to build >> on amd64. ... >>> PASS: tests/channels.scm - latest-channel-instances, missing introduction >>> for 'guix' >>> FAIL: tests/channels.scm -

Bug#1012532: inkscape: PDF import no longer works

2022-06-08 Thread Graeme Smecher
Hi Dennis, On 2022-06-08 13:35, Dennis Braun wrote: This looks very similar to this old bug https://bugs.launchpad.net/inkscape/+bug/1276871 On a hunch, I ensured libpoppler was up-to-date - an apt-get upgrade libpoppler* corrected the problem and I am now able to import PDFs again. Please

Bug#1012538: knocked out usability - module 'collections' has no attribute 'Callable'

2022-06-08 Thread Arnaldo Pirrone
Package: chirp Version: 1:20200227+py3+20200213-3 Severity: grave X-Debbugs-Cc: it9...@gmail.com Just tried using this software to program my radio and found out it stopped working. I remember it was everything fine a few months ago. Probably this is caused by changes in Python 3.10.5 -- System

Bug#1007717: Draft resolution for "Native source package format with non-native version"

2022-06-08 Thread Lucas Nussbaum
On 08/06/22 at 21:07 +0200, Helmut Grohne wrote: > Now we've turned a discussion about source package formats into a > discussion about workflows and git. So when I reason about uniformity, I > effectively want those idiosyncratic workflows to go away. If dgit > requires 1.0-with-diff for now,

Bug#1007717: Draft resolution for "Native source package format with non-native version"

2022-06-08 Thread Lucas Nussbaum
On 08/06/22 at 21:07 +0200, Helmut Grohne wrote: > I think I take more issue with non-dgit git-first workflows than with > dgit ones, because dgit is so well documented and is a workflow that is > already shared by a noticeable fraction of the archive. I'm curious: how do you measure dgit usage?

Bug#1012537: vim-addon-manager: Error when processing 02tlib plug in

2022-06-08 Thread Tim McConnell
Package: vim-addon-manager Version: 0.5.10 Severity: normal X-Debbugs-Cc: tmcconnell...@gmail.com Dear Maintainer, What led up to the situation? Unknown, error just started appearing. What exactly did you do (or not do) that was effective (or ineffective)? Unknown if an update caused this.

Bug#1012536: guix: Debian's guix tries using Guix' glibc locales installed in /var/guix/profiles/... instead of Debian's glibc locales

2022-06-08 Thread Maxime Devos
Package: guix Version: 1.2.0-4 Severity: normal Dear Maintainer, * What led up to the situation? Previously, I used a Guix compiled by Guix as the guix daemon. I would like to switch back to Debian's guix and remove the root user's Guix profile (because I didn't use it for anything except

Bug#995636: transition: openssl

2022-06-08 Thread Sebastian Ramacher
On 2022-06-05 19:50:33 +, Sebastian Andrzej Siewior wrote: > On 5 June 2022 19:03:17 UTC, Kurt Roeckx wrote: > >The suggestion was to make an openssl.cnf that's compatible with 1.1.1, > >and so remove or comment out everything related to providers. > > > > Ah okay. In that case let me so

Bug#1012535: cantor: fails to build from source

2022-06-08 Thread Paul Gevers
Source: cantor Version: 4:21.12.3-1 Severity: serious Tags: ftbfs Justification: ftbfs Hi, As part of the pseudo libluajit transition [1] I scheduled a rebuild of cantor. It failed to build everywhere [2]. As can be seen on the reproducible build project page, the build already fails in

Bug#1012534: Description about not saving state across reboots is outdated

2022-06-08 Thread Ari Pollak
Package: power-profiles-daemon Version: 0.10.1-3 Severity: minor The package description says: Note that power-profiles-daemon does not save the currently active profile across system restarts and will always start with the "balanced" profile selected. However, I believe this paragraph can

Bug#1012533: ftp.debian.org: Please consider a firmware component for bookworm

2022-06-08 Thread Jonathan Carter
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: j...@debian.org Dear FTP team Recently, Steve McIntyre initiated a discussion[1] on debian-devel on the future of firmware in Debian, and how we want to address it as a project. There are many viewpoints on this, but, it seems that we have

Bug#1012532: inkscape: PDF import no longer works

2022-06-08 Thread Graeme Smecher
Package: inkscape Version: 1.2-1 Severity: important X-Debbugs-Cc: gsmec...@threespeedlogic.com Dear Maintainer, Versions 1.2-1 and 1.1.2-3+b1 are both currently unable to import PDFs. Searching on-line suggests that a poppler dependency was missing or disabled at build time. Symptoms: (lightly

Bug#1012531: chmod: changing permissions of any.ndb Operation not permitted

2022-06-08 Thread Tim McConnell
Package: clamav-unofficial-sigs Version: 3.7.2-2.1 Severity: normal X-Debbugs-Cc: tmcconnell...@gmail.com Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** What led up to the situation? Installing the package What exactly did you do (or not do)

Bug#1012440: linux-image-amd64: Long time to load ACPI module battery.ko

2022-06-08 Thread Luca
Package: linux-image-5.10.0-14-amd64 Version: 5.10.0-14-amd64 Followup-For: Bug #1012440 X-Debbugs-Cc: macgyv...@gmail.com > If you have a Thinkpad, then you should be able to update fw using fwupd > package. Also see https://fwupd.org/ for more info. > If your device is not supported, then

Bug#1012530: 4ti2: package header files

2022-06-08 Thread Torrance, Douglas
Source: 4ti2 Version: 1.6.9+ds-4 Severity: wishlist X-Debbugs-Cc: dtorra...@debian.org Dear Maintainer, 4ti2 exists as a shared library. Currently, the library files themselves are shipped for the 4ti2 binaries' use, in /usr/lib//4ti2. However, the header files for use with these libraries are

Bug#1012529: libkf5xmlgui5: KDE doesn't remember window sizes

2022-06-08 Thread Felicia P
Package: libkf5xmlgui5 Version: 5.78.0-2 Severity: important Dear Maintainer, This is related to this bug: https://bugs.kde.org/show_bug.cgi?id=427875 and also mentioned here: https://www.reddit.com/r/kde/comments/pp08tg/kde_forgetting_window_size_and_placement/ KDE does not remember window

Bug#1007717: Draft resolution for "Native source package format with non-native version"

2022-06-08 Thread Helmut Grohne
Hi Sean, On Tue, Jun 07, 2022 at 04:35:24PM -0700, Sean Whitton wrote: > I disagree with you that this is primarily about package ownership, and > I think that we agree on more than you realise we do :) Hmm. It's not that obvious. While it would be possible to remove the choice of workflow from

Bug#1012528: plasma-desktop-data: Application Launcher (Kickoff) search not working

2022-06-08 Thread Felicia P
Package: plasma-desktop-data Version: 4:5.20.5-4 Severity: normal Dear Maintainer, The search bar in the Application Launcher (i.e. Kickoff) doesn't work. This is probably related to this bug: https://bugs.kde.org/show_bug.cgi?id=443131 In my case, at one point in time I had an external

Bug#1012527: kde-config-gtk-style: $HOME/.config/gtkrc-2.0 contents overwritten by KDE

2022-06-08 Thread Felicia P
Package: kde-config-gtk-style Version: 4:5.20.5-2 Severity: normal Dear Maintainer, KDE is overwriting the contents of $HOME/.config/gtkrc-2.0 For example, I have interface customizations in the file, yet when the file gets overwritten by KDE, the customizations are erased. The top of the

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Moritz Muehlenhoff
On Wed, Jun 08, 2022 at 07:51:28PM +0200, Yadd wrote: > Hi, > > those CVEs are tagged low/moderate by upstream, why did you tag this bug as > grave ? Anything moderate or above should get fixed by the next Debian release IOW RC severity. Cheers, Moritz

Bug#991113: libpam-chroot: pam_chroot.so installed in wrong place - Not able to login after upgrade

2022-06-08 Thread M. Buecher
I had a look at the package source and only the paths in the file debian/rules [1] have to be changed. Extend all `lib/$(DEB_HOST_MULTIARCH)` to `lib/$(DEB_HOST_MULTIARCH)/security` (added suffix `/security`). [1] https://sources.debian.org/src/libpam-chroot/0.9-5/debian/rules/ Here the

Bug#1012457: calibre: segfault on startup for different locales

2022-06-08 Thread yokota
Tags: confirmed It also reproduce with other non-UTF-8 locales. 1. Edit "/etc/locale.gen" and setup non-UTF-8 locale 2. Use non-UTF-8 locale for Calibre $ LANG=ja_JP.EUC-JP calibre $ LANG=en_US.ISO-8859-15 calibre 3. Segmentation fault > If LC_CTYPE=ro_RO then calibre segfaults on

Bug#1012526: psmisc: killall doesn't work with kernels older than 5.3

2022-06-08 Thread Emil
Package: psmisc Version: 23.5-1 Severity: normal $ killall fetchmail fetchmail(662): Function not implemented fetchmail: no process found __NR_pidfd_send_signal is defined in /usr/include/asm-generic/unistd.h and the my_send_signal function in killall.c will syscall pidfd_send_signal which is

Bug#1011339: [Pkg-javascript-devel] Bug#1011339: [Pkg-openssl-devel] Bug#1011339: openssl: missing errors strings on mipsel

2022-06-08 Thread Jérémy Lal
Hi Sebastian, Le dim. 29 mai 2022 à 16:27, Jérémy Lal a écrit : > > > Le jeu. 26 mai 2022 à 19:23, Sebastian Andrzej Siewior < > sebast...@breakpoint.cc> a écrit : > >> On 2022-05-26 13:49:13 [+0200], Jérémy Lal wrote: >> > Thanks for the feedback. >> np. >> >> > Indeed, the latest nodejs

Bug#1012525: gensquashfs: double free detected in tcache 2

2022-06-08 Thread Marvin Renich
Package: squashfs-tools-ng Version: 1.1.4-1 Severity: minor In mknode.c:fstree_mknode, if the parent directory link count is too large, the tree_node_t that was just calloc'ed is free'd before returning. However, it has already been linked to the parent's children list. This causes a double

Bug#1012524: libass: PGP signature and i386 assembly

2022-06-08 Thread Oneric
Source: libass Version: 1:0.16.0-1 Severity: minor Hi! I noticed 7a4ee5d47246b80de8bb16ee75faf65bd9cd91b5 recently added the PGP key used to sign the last release for future verification. However, as the 0.16.0 release notes and the MAINTAINERS file note, future releases may also be signed with

Bug#1012523: gnuplot: Please review the build-dependencies

2022-06-08 Thread Laurent Bigonville
Source: gnuplot Version: 5.4.2+dfsg2-2 Severity: normal Hello, gnuplot is not building on some ports due to the build-dependencies against some Qt libraries (mainly QtWebkit), but looking in the code it seems that some of these are not needed anymore (removing these BD results in the same binary

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Yadd
Hi, those CVEs are tagged low/moderate by upstream, why did you tag this bug as grave ? Cheers, Yadd Le Mercredi, Juin 08, 2022 17:49 CEST, Moritz Mühlenhoff a écrit: > Source: apache2 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following

Bug#991113: libpam-chroot: pam_chroot.so installed in wrong place - Not able to login after upgrade

2022-06-08 Thread M. Buecher
Package: libpam-chroot Version: 0.9-5 Followup-For: Bug #991113 X-Debbugs-Cc: maddes+deb...@maddes.net Dear Maintainer, the library pam_chroot.so is installed in the wrong location, therefore it cannot be loaded. This prevents anyone (incl. root) to log into systems that require that module.

Bug#1012522: gensquashfs: "creating tree node: Too many links" error message is confusing and uninformative

2022-06-08 Thread Marvin Renich
Package: squashfs-tools-ng Version: 1.1.4-1 Severity: minor The error text "Too many links" from EMLINK is intended to refer to the number of hard links to an inode, but is misused in fstree_mknode (mknode.c) to mean "directory has too many entries" (perhaps a squashfs limit?). This is confusing

Bug#977530: vtk7: reproducible builds bugs not fixed

2022-06-08 Thread Vagrant Cascadian
It does not appear that these bugs were actually fixed in vtk7: vtk7: reproducible builds: unpredictible ordering in documentation vtk7: reproducible builds: Embeds running kernel into XdmfConfig.h vtk7: reproducible builds: build timestamps in documentation It still fails to build

Bug#1012521: RM: python3-freecontact [armel] -- RoQA; broken due to libfreecontact0v5 removal on armel

2022-06-08 Thread Sebastian Ramacher
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: sramac...@debian.org, debian-med-packag...@lists.alioth.debian.org Same as #1012520 Cheers -- Sebastian Ramacher

Bug#1012520: RM: libfreecontact-perl [armel] -- RoQA; broken due to libfreecontact0v5 removal

2022-06-08 Thread Sebastian Ramacher
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: sramac...@debian.org The removal of libfreecontact0v5 on armel (#1008786) renders libfreecontact-perl uninstallable. So please also remove it. Cheers -- Sebastian Ramacher

Bug#1012519: pmdk: FTBFS on ppc64el due to test failure

2022-06-08 Thread Andreas Hasenack
Package: pmdk Version: 1.12.0-1 Severity: normal Dear Maintainer, pmdk is failing[1] to build on ppc64el due to a test failure on that platform: obj_ctl_arenas/TEST3: SETUP (check/pmem/nondebug/drd) obj_ctl_arenas/TEST3 failed with Valgrind. See drd3.log. Last 20 lines below.

Bug#1012492: /etc/adduser.conf.dpkg-save created by postinst

2022-06-08 Thread Jason Franklin
On Wed, Jun 08, 2022 at 06:01:11PM +0200, Marc Haber wrote: > On Wed, Jun 08, 2022 at 10:11:48AM -0400, Jason Franklin wrote: > > Personally, I think we should simply install a default adduser.conf file > > and remove all of the debconf stuff from the post install script. > > That was like the

Bug#1012518: python3-distutils: CFLAGS and CPPFLAGS leaking in LD flags

2022-06-08 Thread Laurent Bigonville
Package: python3-distutils Version: 3.9.12-1 Severity: important Hello, When trying to build matplotlib (that uses hardening +pie) on x32, -specs=/usr/share/dpkg/pie-compile.specs ends up being added to the flags passed to the linker. This breaks the build with: x86_64-linux-gnux32-g++ -pthread

Bug#1012517: rust-coreutils: FTBFS on some platforms

2022-06-08 Thread Sylvestre Ledru
Package: rust-coreutils Version: 0.0.6-1~exp1 Severity: normal Hello myself, Opening this bug to list dependencies to unbreak the builds on other platforms We are blocked by: https://github.com/byllyfish/exacl/issues/107 https://github.com/rust-num/num-traits/issues/239 (at least) Cheers,

Bug#790943: Root and local certificate location clash

2022-06-08 Thread Sergey Ponomarev
You made a very good investigation on the topic. I agree that a public cert shouldn't be placed into the same folder as CA certs. There is some mention of a weird bug https://serverfault.com/a/840191/442430 Instead I think that both private key and cert should be merged into a one file and placed

Bug#1009431: skimage: FTBFS: dh_auto_test: error: pybuild --test -i python{version} -p "3.9 3.10" returned exit code 13

2022-06-08 Thread Graham Inggs
Control: tags -1 + patch ftbfs Control: unblock -1 by 1010595 The attached patch, based on an imageio upstream commit [1], fixes the issue with Pillow 9.1 for me. [1] https://github.com/imageio/imageio/pull/775 Description: handle PIL palettes with <256 colors based on

Bug#1012347: arm64 CPU Phytium FT-2000/4 cpuinfo

2022-06-08 Thread Helge Kreutzmann
Hello Punit, On Wed, Jun 08, 2022 at 09:40:08AM +0100, Punit Agrawal wrote: > Helge Kreutzmann writes: > > On Tue, Jun 07, 2022 at 09:47:03AM +0100, Punit Agrawal wrote: > >> "xiao sheng wen(肖盛文)" writes: > >> > >> > 在 2022/6/5 21:18, Helge Kreutzmann 写道: > >> >>> CPU implementer: 0x70

Bug#1012490: zh_CN.po translate for linuxinfo package

2022-06-08 Thread Helge Kreutzmann
Hello xiao, On Wed, Jun 08, 2022 at 05:51:18PM +0800, xiao sheng wen (肖盛文) wrote: > O, the attachment file zh_CN.po is repeat in the last bugreport, sorry! > > Only need use one. thanks a lot! I'll include it on the weekend. Greetings Helge -- Dr. Helge Kreutzmann

Bug#1012494: gdb: FTBFS on ppc family: No rule to make target 'info' in build/default/sim/ppc

2022-06-08 Thread Simon McVittie
Control: tags -1 + fixed-upstream patch On Wed, 08 Jun 2022 at 12:53:42 +0100, Simon McVittie wrote: > I think the solution to this might be upstream commit acbf56d7 (trying it > now on the ppc64el porterbox). That seems to have been successful. MR available here:

Bug#1012502: [Pkg-sssd-devel] Bug#1012502: sssd: authentication fails with latest sssd

2022-06-08 Thread Michael Stone
On Wed, Jun 08, 2022 at 05:41:00PM +0300, Timo Aaltonen wrote: Did you have 2.7.0 at some point? 2.7.0-1 was installed 2022-05-27 2.7.0-1+b1 was installed 2022-05-29 no issues with either of those; I reverted to 2.6.3 just because it was easier to grab from the mirrors.

Bug#1012492: /etc/adduser.conf.dpkg-save created by postinst

2022-06-08 Thread Marc Haber
On Wed, Jun 08, 2022 at 10:11:48AM -0400, Jason Franklin wrote: > Personally, I think we should simply install a default adduser.conf file > and remove all of the debconf stuff from the post install script. That was like the gist of a short discussion I initiated in March, see

Bug#1012516: sox: CVE-2022-31650 CVE-2022-31651

2022-06-08 Thread Moritz Mühlenhoff
Source: sox X-Debbugs-CC: t...@security.debian.org Severity: normal Tags: security Hi, The following vulnerabilities were published for sox. CVE-2022-31650[0]: | In SoX 14.4.2, there is a floating-point exception in | lsx_aiffstartwrite in aiff.c in libsox.a. CVE-2022-31651[1]: | In SoX

Bug#1012515: dwarfutils: CVE-2022-32200

2022-06-08 Thread Moritz Mühlenhoff
Source: dwarfutils X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for dwarfutils. CVE-2022-32200[0]: | libdwarf 0.4.0 has a heap-based buffer over-read in | _dwarf_check_string_valid in dwarf_util.c.

Bug#1012513: apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556

2022-06-08 Thread Moritz Mühlenhoff
Source: apache2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for apache2. CVE-2022-31813[0]: | Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* | headers to the origin server based on client side

Bug#1012512: libengine-gost-openssl1.1: CVE-2022-29242

2022-06-08 Thread Moritz Mühlenhoff
Source: libengine-gost-openssl1.1 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for libengine-gost-openssl1.1. CVE-2022-29242[0]: | GOST engine is a reference implementation of the Russian GOST crypto | algorithms for

Bug#1012511: www.debian.org: securing-debian-manual mentions "nessus" which has been removed from Debian due to license issues in 2009

2022-06-08 Thread Axel Beckert
Package: www.debian.org Severity: important Hi, https://www.debian.org/doc/manuals/securing-debian-manual/sec-tools.en.html mentions "nessus" as being part of Debian (and actually even recommends it) despite nessus has been removed from Debian due to license issues back in 2009:

Bug#995636: transition: openssl

2022-06-08 Thread Nilesh Patra
Hi, Is there an ETA for this? Asking since openssl is blocking a number of rev-deps from migrating for almost a month by now. -- Best, Nilesh signature.asc Description: PGP signature

Bug#1012510: firejail: CVE-2022-31214: local root exploit reachable via --join logic

2022-06-08 Thread Salvatore Bonaccorso
Source: firejail Version: 0.9.68-3 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for firejail. CVE-2022-31214[0]: | local root exploit reachable via --join logic If

Bug#1007717: Draft resolution for "Native source package format with non-native version"

2022-06-08 Thread Sean Whitton
Hello, On Wed 08 Jun 2022 at 12:06pm +02, Julian Andres Klode wrote: > On Tue, Jun 07, 2022 at 08:19:29PM +0200, Helmut Grohne wrote: >> Please keep in mind that this is about trade-offs. It is a question of >> how we value "package ownership". If we favour the strong ownership >> approach that

Bug#1012502: [Pkg-sssd-devel] Bug#1012502: sssd: authentication fails with latest sssd

2022-06-08 Thread Timo Aaltonen
Michael Stone kirjoitti 8.6.2022 klo 15.44: Package: sssd Version: 2.7.1-1 Severity: critical Justification: breaks the whole system Installing sssd 2.7.1-1 causes IPA/krb5 authentication to fail with messages such as the following in /var/log/sssd/sssd_DOMAIN.log (2022-06-07 18:31:36):

Bug#1012509: gprconfig-kb: gnatgcc breaks the build of libgnatcoll-bindings

2022-06-08 Thread Nicolas Boulenguez
Package: gprconfig-kb Version: 22.0.0-4 Severity: normal Control: affects -1 libgnatcoll-bindings libncursesada libtexttools 22.0.0-4 compiles C sources with gnatgcc instead of gcc. After this change, gprbuild does not always set -fPIC anymore on the command line compiling C sources for a shared

Bug#996464: ITP: atomic-data-rust -- graph database server to share Atomic Data on the web

2022-06-08 Thread Jonas Smedegaard
0.32.0 draft 5, needs embedding 105 crates (86 missing, 1 broken, 17 outdated, 1 ahead); builds in ~25 minutes; runs but needs to point to external web assets until those are packaged I managed to nudge code to reuse more system crates, and thus reducing the amount of embedded crates. Quite

Bug#1012191: tzdata: /usr/share/zoneinfo/leap-seconds.list will expire on 2022-06-28 in Debian Stable 11.x/Bullseye

2022-06-08 Thread Paul Slootman
severity 1012191 important thanks The time is ticking, and the leap second data is now due to expire in 20 days. There is a 2022a-1 version in testing. Could this be included in bullseye-updates and perhaps buster-updates? I've downloaded it manually and it seems fine in bullseye. Thanks, Paul

Bug#1012362: transition: luajit

2022-06-08 Thread M. Zhou
https://qa.debian.org/excuses.php?package=luajit autopkgtest on ibm archs encountered somewhat regression, since I only removed Conflicts+Replaces from the src:luajit side. I fixed this issue and uploaded src:luajit2

Bug#1012492: /etc/adduser.conf.dpkg-save created by postinst

2022-06-08 Thread Jason Franklin
On Wed, Jun 08, 2022 at 11:50:53AM +0200, Tomáš Virtus wrote: > Adduser's postinst script creates /etc/adduser.conf.dpkg-save file on > debootstrap's root filesystem, that is, even if /etc/adduser.conf > doesn't exist prior to package installation. Greetings: Personally, I think we should simply

Bug#956752: Bug 956752: linux-image-rt-amd64: No access to EFI variables possible with rt kernels

2022-06-08 Thread Diederik de Haas
Control: found -1 linux/5.10.113-1 Control: found -1 linux/5.15.5-2 Control: found -1 linux/5.16.12-1 On Wednesday, 8 June 2022 15:05:47 CEST David Müller wrote: > Diederik de Haas schrieb am 07.06.22 um 15:11: > > Is this still true with current kernels? At least with 5.10 from Stable, > > but

Bug#1012504: cawbird: doesn't migrate because of autopkgtests failure

2022-06-08 Thread Arnaud Ferraris
Le 08/06/2022 à 15:44, Arnaud Ferraris a écrit : Attached patch 0001 fixes this issue so we can hope for this package to transition normally. Hmmm, this is embarassing, but I attached the wrong file (control file missing "allow-stderr"). The correct patch is attached to this email.

Bug#1012506: opendkim: fails to sign mail messages on S/390

2022-06-08 Thread Waldemar Brodkorb
Package: opendkim Version: 2.11.0~beta2-4 Severity: important Dear Maintainer, OpenDKIM fails to sign mail messages on S/390 system. It fails with following message: dkim_eom(): resource unavailable: unable to allocate -858993455 byte(s) I added some debug code and found following malloc to

Bug#1012505: debmutate: missing runtime python3-pcre dependency?

2022-06-08 Thread Gianfranco Costamagna
Source: debmutate Version: 0.52 Severity: serious Hello, building lintian-brush now fails with something like: fixer test: no-watch-file for debian-watch-file-old-format ... Traceback (most recent call last): File "/<>/fixers/debian-watch-file-old-format.py", line 5, in from

Bug#1012504: cawbird: doesn't migrate because of autopkgtests failure

2022-06-08 Thread Arnaud Ferraris
Package: cawbird Version: 1.5 Severity: important Tags: patch X-Debbugs-Cc: arnaud.ferra...@gmail.com Dear Maintainer, autopkgtests for cawbird currently fail, causing the package to be stuck in unstable. This is due to the normal exit code of the "timeout" command being 124. Attached patch

Bug#1012503: selinux-policy-default - Fails to install: No such file or directory

2022-06-08 Thread Bastian Blank
Package: selinux-policy-default Version: 2:2.20220520-1 Severity: serious Moin selinux-policy-default fails to install into a basic Debian unstable system: Setting up selinux-policy-default (2:2.20220520-1) ... Updating selinux default policy (this step might take a

Bug#1010747: closed by Debian FTP Masters (reply to Georges Khaznadar ) (Bug#1010747: fixed in pyacidobasic 2.11.1-2)

2022-06-08 Thread Yuri D'Elia
On Wed, May 18 2022, Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > which was filed against the shiboken2 package: > > #1010747: Unusable with current python version > > It has been closed by Debian FTP Masters > (reply to Georges Khaznadar > ).

Bug#1012486: nvme-cli: systemd unit files are packaged in the wrong place

2022-06-08 Thread Daniel Baumann
close 1012486 1.14-1 thanks Hi, On 6/8/22 09:43, Olivier LAHAYE wrote: > systemd unit files are packaged in /usr/lib/systemd/system instead of > /lib/systemd/system. yes, this has been fixed in 1.14-1 and newer. > This make the service files not recognised by systemd. > to check: correct,

Bug#1012318: diffoscope 214 produced no output and was killed after running into timeout after 150m

2022-06-08 Thread Chris Lamb
Mattia Rizzolo wrote: >> * It's unclear whether this fits the semantics of the TERM signal. >> As you yourself ask in your reply, it is unclear whether >> diffoscope *should* actually do this. (If I were on the command-line >> and hit CTRL+C, I'm not entirely sure I'd want it to stop

  1   2   >