Bug#1031656: Acknowledgement (MariaDB autopkgtest upstream test suite fails on disk / data corruption on ppc64el)

2023-02-21 Thread Otto Kekäläinen
A fresh run today passed, proving the Debian autopkgtest host hardware/kernel/overload theory is likely the cause. https://ci.debian.net/data/autopkgtest/testing/ppc64el/m/mariadb/31582867/log.gz autopkgtest [05:44:51]: starting date and time: 2023-02-22 05:44:51+ autopkgtest [05:44:51]:

Bug#972146: /usr/share/applications/mono-runtime-common.desktop: should not handle MIME type by executing arbitrary code

2023-02-21 Thread Salvatore Bonaccorso
Hi Gabriel, On Sat, Feb 18, 2023 at 12:04:27PM +0100, Gabriel Corona wrote: > Hi! > > > A while has passed, and have now proposed the same change for bullseye > > as well, cf. #1031527. > > Great! > > > There is no CVE assigned, if you feel strong about it, can you try to > > get one allocated

Bug#1029821: change gnome-desktop's default choice of Japanese input methods

2023-02-21 Thread ken...@xdump.org
Hi, On Sat, 28 Jan 2023 16:46:35 +0900 YOSHINO Yoshihito wrote: > Package: libgnome-desktop-4-2 > Followup-For: Bug #1029821 > X-Debbugs-Cc: yy.y.ja...@gmail.com > snip > > Attaching a patch to change the Japanese default to mozc. I've tested with attached patch on d-i Alpha2 on GNOME desktop

Bug#1027130: Bug may still be open

2023-02-21 Thread Stephen Lyons
Dear Maintainer; This "grave" bug has been marked as closed in 1.0.0-dfsg-1 however it is still open in 0.103.7-dfsg-0+deb11u1 and there is no indication that it has been resolved in 0.103.8+dfsg-0+deb11u1 which is promulgated to solve the "serious" CVEs handled in

Bug#1031760: autopkg tests fail with python3.11

2023-02-21 Thread Matthias Klose
Package:sqlobject Version: 3.10.1+dfsg-1 Severity: serious Tags: sid bullseye the autopkg tests fail with python3.11: [...] autopkgtest [03:29:29]: test testdb-setuptools: [--- error: externally-managed-environment × This environment is externally managed ╰─> To install

Bug#1031733: libcommons-fileupload-java: CVE-2023-24998

2023-02-21 Thread tony mancill
On Tue, Feb 21, 2023 at 04:10:16PM +0100, Moritz Mühlenhoff wrote: > Source: libcommons-fileupload-java > X-Debbugs-CC: t...@security.debian.org > Severity: important > Tags: security > > Hi, > > The following vulnerability was published for libcommons-fileupload-java. > > CVE-2023-24998[0]: >

Bug#1031759: autopkg tests fail with python3.11

2023-02-21 Thread Matthias Klose
Package: src:spyder Version: 5.4.2+ds-2 Severity: serious Tags: sid bullseye the autopkg tests fail with python3.11: [...] autopkgtest [03:30:32]: test pytest-mainwindow: [--- Testing with python3.11: error: externally-managed-environment × This environment is externally

Bug#1031758: autopkg tests broken with python3.11 (timeout)

2023-02-21 Thread Matthias Klose
Package: src:python-oslo.db Version: 12.1.0-3 Severity: serious Tags: sid bullseye the autopkg tests fail with a timeout, please see https://ci.debian.net/data/autopkgtest/testing/amd64/p/python-oslo.db/31558294/log.gz

Bug#1031757: autopkg tests broken with python3.11

2023-02-21 Thread Matthias Klose
Package: src:python-formencode Version: 2.0.1-1 Severity: serious Tags: sid bullseye the autopkg tests are broken with python3.11: [...] autopkgtest [02:13:40]: test testfe-setuptools: [--- error: externally-managed-environment × This environment is externally managed ╰─>

Bug#964279: [deluge] TypeError: '>' not supported between instances of 'NoneType' and 'NoneType'

2023-02-21 Thread Daniel Baumann
close 964279 2.1.1-1 thanks Hi Lyndon, thanks for the feedback, I'll close the bug then. Regards, Daniel

Bug#927196: errors with username debian-deluged

2023-02-21 Thread Daniel Baumann
close 927196 thanks Hi, thank you for your report. Like Robert explained, this isn't actually a bug but intended behaviour, hence closing. Regards, Daniel

Bug#1028654: dpkg: add loongarch64 architecture GNU triplet

2023-02-21 Thread Guillem Jover
Hi! On Mon, 2023-02-20 at 21:30:14 +0800, zhangdandan wrote: > We decide to use "loongarch64-linux-gnu" as the value of the Debian loong64 > port's multiarch tuple. > The reasons for using "loongarch64-linux-gnu" are as follows: > > Firstly, we note that many of the major architectures use the

Bug#1031756: unblock: imagemagick/8:6.9.11.60+dfsg-1.6

2023-02-21 Thread Jeremy Bícha
in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in testing [ Other info ] unblock imagemagick/8:6.9.11.60+dfsg-1.6 Thank you, Jeremy Bicha imagemagick-unblock-20230221.debdiff Description: Binary data

Bug#1031755: ITP: privacybrowser -- web browser that respects your privacy

2023-02-21 Thread Soren Stoutner
Package: wnpp Severity: wishlist Owner: Soren Stoutner X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: privacybrowser Version : 0.1 Upstream Contact: Soren Stoutner * URL : https://www.stoutner.com/privacy-browser-pc/ * License : (GPLv3+)

Bug#986964: geeqie: View in new window, new window black until zoom in/out

2023-02-21 Thread Rudolf Dovičín
Package: geeqie Version: 1:1.6-9+deb11u1 Followup-For: Bug #986964 X-Debbugs-Cc: rudolf.dovi...@gmail.com Dear Maintainer, I see the same error. I reply to this, because I think that I have additional information. It appears in full-screen mode in the main window, too. When I turn full-screen

Bug#913758: Are you still having issues with hardware wallets?

2023-02-21 Thread Soren Stoutner
It seems that some hardware wallets currently work with Electrum and others require software that is not currently packaged in Debian. I have recently added some documentation that will be included in future versions of Electrum. Could you take a look and see if there is any information you

Bug#1030886: Proposed README file

2023-02-21 Thread Soren Stoutner
I have added a proposed README file, which can be seen at: https://salsa.debian.org/cryptocoin-team/electrum/-/merge_requests/16[1] Let me know if there is anything else I should add or if you think anything should be reworded. Soren -- Soren Stoutner so...@stoutner.com [1]

Bug#734235: Is this bug still an issue?

2023-02-21 Thread Soren Stoutner
I have recently started working on the Electrum package and came across this old bug. Can you confirm that it is still an issue. It looks like at least some aspects of it have already been addressed upstream. https://github.com/spesmilo/electrum/issues/4637[1] -- Soren Stoutner

Bug#1031275: [PATCH v3 1/6] man2/: use IEC or ISO multiples to clarify long numeric digit strings

2023-02-21 Thread Alex Colomar
Hi Rob, On 2/21/23 18:00, Rob Landley wrote: If you're going to tell people to learn something new: 1<<10 is a kilobyte, 1<<20 is a megabyte, 1<<30 is a gigabyte, and so on. I've sometimes used 16*(1<<30) for clarity. That's nice, and for code it might be a good idea (although you have to be

Bug#772060: Is this bug still present

2023-02-21 Thread Soren Stoutner
I recently started working on the Electrum package and noticed this bug report for a very old version. Can you confirm if this is still an issue? -- Soren Stoutner so...@stoutner.com signature.asc Description: This is a digitally signed message part.

Bug#772059: Is this bug still relevant

2023-02-21 Thread Soren Stoutner
I have recently started working on the Element package. I noticed this bug for a really old version. Can you confirm if it still exists in the current package? -- Soren Stoutner so...@stoutner.com signature.asc Description: This is a digitally signed message part.

Bug#792399: Is bug still valid

2023-02-21 Thread Soren Stoutner
I have recently started working on Electrum. I see this bug, which is for a really old version. Can you confirm if it is still a problem? -- Soren Stoutner so...@stoutner.com signature.asc Description: This is a digitally signed message part.

Bug#1031681: libkiwix: bump B-D to libzim-dev (>= 8.1.0+really8.1.0)

2023-02-21 Thread Andreas Beckmann
Followup-For: Bug #1031681 src:kiwix-tools probably needs the same B-D bump. Andreas

Bug#1031754: ncmpc-lyrics: missing dependencies on python3-bs4 and python3-requests

2023-02-21 Thread Diederik de Haas
Package: ncmpc-lyrics Version: 0.47-1 Severity: important Tags: patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On a barebones (arm64) system I installed (mpd,) ncmpc and ncmpc-lyrics and when I switched to the lyrics tab/screen, I got the following error:

Bug#1030600: redis breaks python-fakeredis autopkgtest: Connection refused

2023-02-21 Thread Adrian Bunk
Control: tags -1 ftbfs Control: affects -1 src:beaker On Mon, Feb 06, 2023 at 10:46:52AM -0800, Chris Lamb wrote: > Paul Gevers wrote: > > > With a recent upload of redis the autopkgtest of python-fakeredis fails > > in testing when that autopkgtest is run with the binary packages of > > redis

Bug#1031753: linux-image-5.10.0-21-s390x: user space process hangs on s390 kernel 5.10.162-1

2023-02-21 Thread Dipak Zope
Package: src:linux Version: 5.10.162-1 Severity: normal X-Debbugs-Cc: pk...@debian.org, elb...@debian.org, dipak.zo...@ibm.com Dear Maintainer, What led up to the situation? * Processes does not proceed further, when there is a pending TIF_NOTIFY_SIGNAL signal. The problem is further

Bug#1031752: rust-typenum: autopkgtest regression on 32bit

2023-02-21 Thread Adrian Bunk
Source: rust-typenum Version: 1.16.0-1 Severity: serious https://tracker.debian.org/pkg/rust-typenum ... Issues preventing migration: ∙ ∙ autopkgtest for rust-typenum/1.16.0-1: amd64: Pass, arm64: Pass, armel: Regression ♻ (reference ♻), armhf: Regression ♻ (reference ♻), i386: Regression ♻

Bug#1031634: ITP: gum -- A tool for glamourous shell scripts

2023-02-21 Thread Scarlett Moore
On Tue, Feb 21, 2023, 3:12 PM Ryan Kavanagh wrote: > On Sun, Feb 19, 2023 at 09:01:56AM -0700, Scarlett Moore wrote: > > Description : A tool for glamourous shell scripts > > > > A tool for glamorous shell scripts. Leverage the power of Bubbles and > > Lip Gloss in your scripts and aliases

Bug#1029829: Re: Bug#1029829: amanda: CVE-2022-37704 CVE-2022-37705

2023-02-21 Thread Amanda Trusted
During our security testing of the fixes, we found another attack vector for the issue similar to the one mentioned in CVE-2022-37704. Dump can be manipulated by an attacker through the RSH environment variable, which is used to specify the

Bug#1031751: rust-ahash: autopkgtest failure

2023-02-21 Thread Adrian Bunk
Source: rust-ahash Version: 0.8.3-2 Severity: serious https://ci.debian.net/data/autopkgtest/testing/amd64/r/rust-ahash/31558299/log.gz ... Testing map/aHash-alias thread 'main' panicked at 'attempt to add with overflow', /usr/src/rustc-1.63.0/library/core/src/ops/arith.rs:786:1 stack

Bug#1031750: redis-server: "delaycompess" typo in logrotate file

2023-02-21 Thread Adrian Bunk
Package: redis-server Version: 5:7.0.8-2 Severity: serious https://piuparts.debian.org/sid/fail/redis-server_5:7.0.8-3.log ... error: /etc/logrotate.d/redis-server:7 unknown option 'delaycompess' -- ignoring line ... src:redis has two packages with logrotate files, only the one in

Bug#1031749: afnix FTBFS on 32bit: afnix-bexec: failure t_utility

2023-02-21 Thread Adrian Bunk
Source: afnix Version: 3.8.0-1 Severity: serious Tags: ftbfs https://buildd.debian.org/status/logs.php?pkg=afnix=3.8.0-1 ... running: t_utility afnix-bexec: failure t_utility make[6]: *** [../../../../cnf/mak/afnix-runx.mak:301: t_utility.exe] Error 1

Bug#1031748: zoph fails to purge when adduser is not installed

2023-02-21 Thread Adrian Bunk
Package: zoph Version: 0.9.19-1 Severity: serious https://piuparts.debian.org/sid/fail/zoph_1.0.1-1.log ... Purging configuration files for zoph (1.0.1-1) ... /var/lib/dpkg/info/zoph.postrm: 39: delgroup: not found dpkg: error processing package zoph (--purge): installed zoph package

Bug#1031747: python-socks: autopkgtest regression

2023-02-21 Thread Adrian Bunk
Source: python-socks Version: 2.1.1-1 Severity: serious https://ci.debian.net/data/autopkgtest/testing/amd64/p/python-socks/31564223/log.gz ... autopkgtest [18:13:28]: test unittests: [--- === python3.11 === ImportError while loading conftest

Bug#1031382: RFS: libkysdk-base/1.0.1-1 [ITP] -- Kylin SDK basic library

2023-02-21 Thread Boyuan Yang
Control: tags -1 +moreinfo Indeed, please fix the error listed below before we can proceed. Thanks, Boyuan Yang On Thu, 16 Feb 2023 19:55:44 +0100 Adam Borowski wrote: > On Thu, Feb 16, 2023 at 11:05:42AM +0800, kevin wrote: > >  * Package name : libkysdk-base > >    Version  :

Bug#1023623: dolphin: In file rename dialog: Delete and Backspace act on file, not on text

2023-02-21 Thread 6251d5d9-c833-4b45-8e6e-261c9164db95
Hi I had the same symptoms and found a cause that I want to share with you. For me, the cause was keyboard layouts. When I had German T3 or German E1 enabled or even only in the list of active layouts in Plasma, I observed the described behaviour. I had this configured, because it is given

Bug#1031634: ITP: gum -- A tool for glamourous shell scripts

2023-02-21 Thread Ryan Kavanagh
On Sun, Feb 19, 2023 at 09:01:56AM -0700, Scarlett Moore wrote: > Description : A tool for glamourous shell scripts > > A tool for glamorous shell scripts. Leverage the power of Bubbles and > Lip Gloss in your scripts and aliases without writing any Go code! This long description does not

Bug#983597: Segfault in libqt5quick5.so: QQuickItemLayer::~QQuickItemLayer()

2023-02-21 Thread Dennis Filder
This may have gotten fixed by the fix for QTBUG-107850[1] (commit 7487332)[2]. QTBUG-84858 gets a tacit mention there, but is not among the list of duplicates that got closed through this (even though it probably should be). I hastily backported this to 5.15.8 (see attachment), but have not yet

Bug#1031701: fixed in python-xlrd 2.0.1-1

2023-02-21 Thread Diane Trout
Sorry my coworker got hit by this too, he worked around it by using libreoffice to convert the .xls file to .xlsx. I'd updated the xlrd package to 2.0.1 and pushed it to experimental to see how much it might break, Looks like there was some more discussion while I was fiddling with the package.

Bug#923824: libdancer2-plugin-database-perl: FTBFS randomly (failing tests)

2023-02-21 Thread Étienne Mollier
Control: tags -1 patch It turned out I managed to find a workaround. Putting it below for ulterior reference if need be; few more details are available on upstream bug tracker: ---8<--8<--8<--8<--- ---

Bug#1003044: python3-dateutil: python_dateutil get_zonefile_instance functionality is broken (no zoneinfo found)

2023-02-21 Thread Felix Geyer
On 21.02.23 20:46, Sandro Tosi wrote: it produces output on stderr, which many tools consider it an error and fails build. When raising the severity of a bug to grave I would expect some concrete details on what exactly is broken instead of a hand-wavy "breaks some stuff". But anyway let's

Bug#1031415: FAI fix

2023-02-21 Thread Thomas Lange
In FAI, we cannot easily determine which mke2fs or grub version will be used in the target system since we support deb and rpm based and other linux distributions. As I did with the older issues of mke2fs (metadata_csum) I will add a comment, so the user can decide if he needs to add the option

Bug#1029439: feynmf: FTBFS in bookworm (I can't open file `fmfsamp4')

2023-02-21 Thread James Addison
Source: feynmf Followup-For: Bug #1029439 X-Debbugs-Cc: debian-tex-ma...@lists.debian.org Control: tags -1 help I'm adding the 'help' tag to this bug, and am cc'ing the debian-tex-maint list, because it feels like extra brainpower could aid in figuring this one out more quickly. A brief recap of

Bug#1031746: ITP: libdex -- Library for deferred execution

2023-02-21 Thread Jeremy Bícha
Package: wnpp Severity: wishlist X-Debbugs-CC: debian-de...@lists.debian.org, debian-gtk-gn...@lists.debian.org Owner: jeremy.bi...@canonical.com Package Name: libdex-1-1 (etc) Version: 0.1.0 Upstream Author: Christian Hergert License: LGPL-2.1+ Programming Lang: C Description: Library for

Bug#1021582: closed by Piotr Ożarowski (fixed in 1.0.4-1)

2023-02-21 Thread Jelmer Vernooij
On Tue, Feb 21, 2023 at 06:12:30PM +, Debian Bug Tracking System wrote: > Date: Tue, 21 Feb 2023 19:10:43 +0100 > From: Piotr Ożarowski > To: 1021582-d...@bugs.debian.org > Subject: fixed in 1.0.4-1 > > Source: pytest-aiohttp > Source-Version: 1.0.4-1 > > ups, looks like I hijacked your

Bug#1031745: gdb: breaks rustc gdb debuginfo tests

2023-02-21 Thread Fabian Grünbichler
Package: gdb Version: 13.1-1 Severity: serious Control: affects -1 src:rustc Justification: breaks unrelated software While preparing an update to rustc 1.65 for experimental, we noticed that the recent gdb update in sid makes rustc FTBFS by causing 5 of its gdb-integration test cases fail. test

Bug#1031327: gbp-rpm-ch: Wrong changelog header format (missing dash before version)

2023-02-21 Thread Samuel Henrique
Hello Guido, > You need to fixup the tests too though I have updated the Github PR and also attached the new patch with the unit tests fixed. Thank you, -- Samuel Henrique From b2a7100730306d7e333ce84c00ccdaf693e6f081 Mon Sep 17 00:00:00 2001 From: Samuel Henrique Date: Mon, 1 Aug 2022

Bug#1029439: feynmf: FTBFS in bookworm (I can't open file `fmfsamp4')

2023-02-21 Thread James Addison
Source: feynmf Followup-For: Bug #1029439 Assuming that we want to keep the feynmf sources as-is (I think we do; feynmf.dtx hasn't changed[1] since 1996, a sign of stability), then this bug seems like a regression in another component. Looking at the build logs for a failure-to-build[2] in this

Bug#923824: libdancer2-plugin-database-perl: FTBFS randomly (failing tests)

2023-02-21 Thread Étienne Mollier
Control: tags -1 confirmed Control: forwarded -1 https://github.com/bigpresh/Dancer-Plugin-Database/issues/102 It took me several retries before triggering, but I ended up hitting the same case of test failure, so it looks pretty much hardware independent. This looks to affect autopkgtest as

Bug#998105: The issue persists, was Re:

2023-02-21 Thread Sven Geuer
Control: reopen -1 = Hello Christian, On Fri, 20 Jan 2023 11:01:33 + c.bu...@posteo.jp wrote: > Dear Sven, > > there is a new release 1.3.3 in "unstable" branch of Debian. > > Can you please try to reproduce the problem with that version and > then report back. > > Thanks > Christian

Bug#1003044: python3-dateutil: python_dateutil get_zonefile_instance functionality is broken (no zoneinfo found)

2023-02-21 Thread Sandro Tosi
On Sun, Jan 29, 2023 at 9:45 AM Felix Geyer wrote: > > On Sat, 7 Jan 2023 03:34:19 -0500 Sandro Tosi wrote: > > > python-dateutil expects to have 'dateutil-zoneinfo.tar.gz' in it's > > > directory > > > tree, but this file is removed in the packaging. > > > > > > Error: > > >

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Moritz Muehlenhoff
On Tue, Feb 21, 2023 at 03:32:01PM +, Simon McVittie wrote: > On Tue, 21 Feb 2023 at 16:09:30 +0100, Moritz Mühlenhoff wrote: > > CVE-2019-25104[0]: > > https://github.com/rtcwcoop/rtcwcoop/pull/45 > > This looks like a denial of service via memory exhaustion when running > a multiplayer

Bug#1031706: optuna: test_create_new_trial randomly fails on s390x

2023-02-21 Thread Gard Spreemann
"Rebecca N. Palmer" writes: > test_create_new_trial (both parts) sometimes fails on s390x, failing > the autopkgtest. > > It might make sense to remove this package on s390x, if it isn't > reasonable to actually fix this. Thanks for the report! I've brought this to upstream's attention [1],

Bug#1026508: ca-certificates: FTBFS: TypeError: argument 'data': 'bytearray' object cannot be converted to 'PyBytes'

2023-02-21 Thread Samuel Henrique
Hello Julien, > This is fixed in git, I need to get around to uploading an update. Are you also planning to update the certificates for bookworm? I'm asking as we are already in the freeze and there are a few bugreports about old certificates that need to be dropped[0][1] (and I assume there's

Bug#1031744: httpdirfs: usage of ubsan might introduce vulnerabilities

2023-02-21 Thread Adrian Bunk
Package: httpdirfs Version: 1.2.4-1 Severity: serious Tags: security X-Debbugs-Cc: Debian Security Team Package: httpdirfs Version: 1.2.4-2 Depends: ..., libubsan1 (>= 8), ... This is a bad idea not only due to slower execution, but might even introduce vulnerabilities:

Bug#1031743: python3.11-minimal: Python 3.11 should be compiled as a PIE, but it is not

2023-02-21 Thread j.fikar
Package: python3.11-minimal Version: 3.11.1-2 Severity: normal X-Debbugs-Cc: j.fi...@gmail.com Dear Maintainer, if I understood it correctly, the Python 3.10 and later should be compiled as PIE (position independent executable). That is why there are the new packages python3-nopie,

Bug#826902: Blorbtools

2023-02-21 Thread David Griffith
I've since put these Perl scripts into a package called "Blorbtools". See https://gitlab.com/DavidGriffith/blorbtools -- David Griffith d...@661.org A: Because it fouls the order in which people normally read text. Q: Why is top-posting such a bad thing? A: Top-posting. Q: What is the

Bug#1031742: Please make reboot command configurable

2023-02-21 Thread Andras Korn
Package: unattended-upgrades Version: 2.9.1+nmu3 Severity: wishlist Hi, not all flavours of shutdown(8) support a time argument; for example, runit's only supports 'now' or no time. When unattended-upgrades tries to schedule a reboot on runit systems, shutdown(8) prints an error, causing

Bug#1031716: python3-protobuf: Do reverse dependencies need stricter version constraints?

2023-02-21 Thread GCS
On Tue, Feb 21, 2023 at 1:27 PM Adrian Bunk wrote: > Looking at #1028371, should generated dependencies on python3-protobuf be > python3-protobuf (>= 3.21), python3-protobuf (<< 3.22) You mean on python3-bernhard, right? > to ensure that the binary package is used with the same version > as

Bug#1031741: goxel: usage of sanitizers might introduce vulnerabilities

2023-02-21 Thread Adrian Bunk
Package: goxel Version: 0.10.6-1 Severity: serious Tags: security X-Debbugs-Cc: Debian Security Team Package: goxel Version: 0.10.6-3 Depends: libasan6 (>= 10), ...,libubsan1 (>= 8) This is a bad idea not only due to slow execution and a factor 20 in binary size, but might even introduce

Bug#1031509: [Pkg-clamav-devel] Bug#1031509: ETA on Patch for Buster

2023-02-21 Thread Sebastian Andrzej Siewior
+LTS On 2023-02-20 12:22:48 [+0200], Andries Malan wrote: > Hi There Hi, > Would you be so kind as to provide an ETA for the above mentioned bug that > was reported. > This would be greatly appreciated. I Cced the LTS team because Buster is LTS territory. > Regards Sebastian

Bug#1030273:

2023-02-21 Thread Alexander Beerhoff
Hi, the problem seems solved with linux-image-6.1.0-5-amd64 -- Umi sukoschi Niwa ni izumi no Ko no ma ka na

Bug#1031740: fceux usage of sanitizers might introduce vulnerabilities

2023-02-21 Thread Adrian Bunk
Package: fceux Version: 2.6.5+dfsg1-1 Severity: serious Tags: security X-Debbugs-Cc: Debian Security Team fceux (2.6.5+dfsg1-1) unstable; urgency=medium ... * enable compiler address sanitizer (ASAN) Package: fceux Version: 2.6.5+dfsg1-1 Depends: libasan8, ..., libubsan1 (>= 8),... This is

Bug#1031697: Acknowledgement (libx11-xcb1: Please update to 1.8.4 - Apps crashing under wayland due to bugs caused by patches in 1.8.3)

2023-02-21 Thread Safir Secerovic
Hello again, I forgot to mention that I did leave out: --disable--thread-safety-constructor configure option from debian/rules file along with removing the two patches [1] when rebuilding from the current debian source package (1.8.3). Regards, Safir [1]

Bug#1031739: linux: Please enable DLM kernel module in cloud kernels

2023-02-21 Thread Vincent Caron
Package: linux Severity: normal Dear Maintainer, I am in a situation where I am using a GFS2 cluster in virtual machines and realized I couldn't do it with the 'cloud' kernel because the 'dlm' kernel module is not present in this flavour. It does work when I switch to the bare-metal kernel.

Bug#1031738: installation-guide: documentation about limits to kernel boot parameters is outdated

2023-02-21 Thread James Addison
Source: installation-guide Version: 20220129~deb11u1 Severity: normal Tags: d-i patch Dear Maintainer, Some of the documentation related to limits in Linux kernel boot parameters in the installation guide is outdated. For example, the section describing[1] use of boot parameters for preseeding

Bug#1030047: ruby-sanitize: CVE-2023-23627

2023-02-21 Thread duck
Quack Salvatore, Thanks for the patch, it looks good. I'm in the Ruby team but not involved in this particular package but I think we can let your NMU flow. It's causing havoc on other packages so the sooner the better :-). Regards. \_o< -- Marc Dequènes

Bug#1003044: python3-dateutil: python_dateutil get_zonefile_instance functionality is broken (no zoneinfo found)

2023-02-21 Thread James Addison
Package: python3-dateutil Followup-For: Bug #1003044 Control: tags -1 moreinfo On Tue, 21 Feb 2023 00:35:16 +, James Addison wrote: > The repro step attempted was to open a Python interpreter session and to > enter: > from matplotlib.dates import DateFormatter > > (that succeeded and did

Bug#1031695: dh_installsystemd doesn't handle files in /usr/lib/systemd/system

2023-02-21 Thread Sam Hartman
> "Michael" == Michael Biebl writes: Michael> Am 21.02.23 um 17:45 schrieb Sam Hartman: >>> "Michael" == Michael Biebl writes: Michael> Excluding packages that only ship overrides/drop-ins, this Michael> makes 37 affected packages in bookworm. >> >> If I'm

Bug#1031695: dh_installsystemd doesn't handle files in /usr/lib/systemd/system

2023-02-21 Thread Michael Biebl
Am 21.02.23 um 17:45 schrieb Sam Hartman: "Michael" == Michael Biebl writes: Michael> Excluding packages that only ship overrides/drop-ins, this Michael> makes 37 affected packages in bookworm. If I'm understanding this issue correctly, the concern would be a package that moved from

Bug#1031737: Wrong margin character for changed text in man pages

2023-02-21 Thread Bjarni Ingi Gislason
Package: tcl8.6-doc Version: 8.6.13+dfsg-2 Severity: normal Dear Maintainer, * What led up to the situation? Displaying man page "chan.3tcl" with the next version (candidate) of groff (1.23.0). * What exactly did you do (or not do) that was effective (or ineffective)? (test-nroff

Bug#1031647: git-annex: Bogus build dependency whitelist results in FTBFS on m68k

2023-02-21 Thread Sean Whitton
Hello, On Sun 19 Feb 2023 at 07:52PM +01, John Paul Adrian Glaubitz wrote: > git-annex currently FTBFS on m68k with an error message that indicates that > some > build dependencies are missing: > > Configuring git-annex-10.20230126... > Setup: Encountered missing or private dependencies: >

Bug#1031640: Bug#1030940: e2fsprogs: generates filesystems that grub-install doesn't recognize

2023-02-21 Thread Theodore Ts'o
On Tue, Feb 21, 2023 at 12:17:20PM +, Christopher Obbard wrote: > Control: severity -1 important > Control: retitle -1 e2fsprogs generates filesystems which cannot be > mounted on systems with older e2fsprogs > > It turns out for debos the situation is a bit different. Since debos > uses

Bug#1031275: [PATCH v3 1/6] man2/: use IEC or ISO multiples to clarify long numeric digit strings

2023-02-21 Thread Rob Landley
On 2/20/23 09:35, Alex Colomar wrote: > On 2/20/23 15:29, Stefan Puiu wrote: >> Hi Alex, > > Hi Stefan, > >>> 4 KiB is not that much better than 4096, since 4096 is easy to read. >>> For higher numbers such as 33554432, it becomes more important to use 32 >>> KiB. >>> For consistency, using 4

Bug#1031695: dh_installsystemd doesn't handle files in /usr/lib/systemd/system

2023-02-21 Thread Sam Hartman
> "Michael" == Michael Biebl writes: Michael> Excluding packages that only ship overrides/drop-ins, this Michael> makes 37 affected packages in bookworm. If I'm understanding this issue correctly, the concern would be a package that moved from /lib/systemd/system to

Bug#1031718: Same problem with BTS server

2023-02-21 Thread Debian
Maybe this error can be tracked within the Debian BTS email server? (There should be one more reply from the system for this email that will fail.) There could be found other suspect log entries in the exim log: 2023-02-21 13:39:03 TLS error on connection from

Bug#1031712: libnet-server-perl: Use of uninitialized value in numeric eq (==) at /usr/share/perl5/Net/Server/Fork.pm line 168.

2023-02-21 Thread gregor herrmann
Control: forwarded -1 https://rt.cpan.org/Public/Bug/Display.html?id=146575 Control: tag -1 + upstream patch On Tue, 21 Feb 2023 07:54:07 +0100, Dominique Fournier via pkg-perl-maintainers wrote: > > Each time there is a connection in Munin (using the lib-netserver-perl > package as tcp

Bug#1021842: Finalizing 'inhibit-automatic-native-compilation'

2023-02-21 Thread Andrea Corallo
Tatsuya Kinoshita writes: > On 2023-02-20 at 20:22 +, Andrea Corallo wrote: >> I've installed 5d0b45cd67b on emacs-29 in order to use always >> `make-temp-file'. > > Please be careful with the difference between make-temp-file-internal > and make-temp-file. > >> +++ b/lisp/emacs-lisp/comp.el

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Simon McVittie
On Tue, 21 Feb 2023 at 16:09:30 +0100, Moritz Mühlenhoff wrote: > CVE-2019-25104[0]: > https://github.com/rtcwcoop/rtcwcoop/pull/45 This looks like a denial of service via memory exhaustion when running a multiplayer server. For a game from 2001, I would personally say this is normal or even

Bug#1031352: Chromium on Wayland: Cannot join a Microsoft Teams enterprise meeting

2023-02-21 Thread Amr Ibrahim
Package: chromium Version: 110.0.5481.77-2 Followup-For: Bug #1031352 Hallo, Bug still exists in version 110.0.5481.77-2 Best, Amr -- System Information: Debian Release: bookworm/sid APT prefers testing APT policy: (500, 'testing'), (100, 'unstable'), (50, 'experimental') Architecture:

Bug#1031735: oggvideotools: autopkgtest relies on an obsolet location for file Effet_force_magnetique.ogv

2023-02-21 Thread Georges Khaznadar
Package: oggvideotools Version: 0.9.1-6 Severity: normal Dear Maintainer, I am the author and maintainer of package pymecavideo, which yields the binary package python3-mecavideo. The new version (>> 8.0~rc4) will have the file "Effet_force_magnetique.ogv" in a new location:

Bug#1031734: ibus-braille-preferences crashes when run

2023-02-21 Thread T. Joseph Carter
Package: ibus-braille Version: 0.3-7 Severity: important Upon running ibus-braille-preferences, I get this error: ``` aki:~ $ ibus-braille-preferences /usr/share/ibus-braille-preferences/main.py:24: PyGIWarning: Gtk was imported without specifying a version first. Use gi.require_version('Gtk',

Bug#1031733: libcommons-fileupload-java: CVE-2023-24998

2023-02-21 Thread Moritz Mühlenhoff
Source: libcommons-fileupload-java X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for libcommons-fileupload-java. CVE-2023-24998[0]: | Apache Commons FileUpload before 1.5 does not limit the number of | request parts to be

Bug#1031732: iortcw: CVE-2019-25104

2023-02-21 Thread Moritz Mühlenhoff
Source: iortcw X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for rtcwcoop, which seems to be a fork of iortcw, but the patches don't seem to have flown back? CVE-2019-25104[0]: | A vulnerability has been found in rtcwcoop

Bug#1031731: glusterfs: CVE-2023-26253

2023-02-21 Thread Moritz Mühlenhoff
Source: glusterfs X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for glusterfs. CVE-2023-26253[0]: | In Gluster GlusterFS 11.0, there is an xlators/mount/fuse/src/fuse- | bridge.c notify stack-based buffer over-read.

Bug#1031729: resteasy3.0: CVE-2023-0482

2023-02-21 Thread Moritz Mühlenhoff
Source: resteasy3.0 X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for resteasy3.0. CVE-2023-0482[0]: | In RESTEasy the insecure File.createTempFile() is used in the | DataSourceProvider, FileProvider and Mime4JWorkaround

Bug#1031730: emacs: CVE-2022-48339 CVE-2022-48338 CVE-2022-48337

2023-02-21 Thread Moritz Mühlenhoff
Source: emacs X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for emacs. CVE-2022-48339[0]: | An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has | a command injection vulnerability. In the

Bug#1031728: resteasy: CVE-2023-0482

2023-02-21 Thread Moritz Mühlenhoff
Source: resteasy X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for resteasy. CVE-2023-0482[0]: | In RESTEasy the insecure File.createTempFile() is used in the | DataSourceProvider, FileProvider and Mime4JWorkaround

Bug#1031727: epiphany-browser: CVE-2023-26081

2023-02-21 Thread Moritz Mühlenhoff
Source: epiphany-browser X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for epiphany-browser. CVE-2023-26081[0]: | In Epiphany (aka GNOME Web) through 43.0, untrusted web content can | trick users into exfiltrating

Bug#1031726: hdf5: CVE-2022-26061 CVE-2022-25972 CVE-2022-25942

2023-02-21 Thread Moritz Mühlenhoff
Source: hdf5 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for hdf5. The reports mentioned a vendor disclosure, but not sure when/how. CVE-2022-26061[0]: | A heap-based buffer overflow vulnerability exists in the gif2h5 |

Bug#1031725: unblock: accountsservice/22.08.8-6

2023-02-21 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: accountsserv...@packages.debian.org Control: affects -1 + src:accountsservice accountsservice could benefit from some appropriate age-days to get it into testing a bit sooner.

Bug#1031695: dh_installsystemd doesn't handle files in /usr/lib/systemd/system

2023-02-21 Thread Michael Biebl
For bookworm we have $ apt-file search -x ^/usr/lib/systemd/system/ amazon-ec2-net-utils: /usr/lib/systemd/system/policy-routes@.service amazon-ec2-net-utils: /usr/lib/systemd/system/refresh-policy-routes@.service amazon-ec2-net-utils: /usr/lib/systemd/system/refresh-policy-routes@.timer

Bug#1031695: dh_installsystemd doesn't handle files in /usr/lib/systemd/system

2023-02-21 Thread Michael Biebl
Hi Niels On Tue, 21 Feb 2023 10:47:09 +0100 Niels Thykier wrote: Sorry for being terse, I should be working on something else right now but prioritized a short message over nothing. Duplicate of #995569. Sorry, missed that... My concerns from back then still applies and I will not

Bug#1029720: [Pkg-nagios-devel] Bug#1029720: Bug#1029720: monitoring-plugins-contrib: false positive w bookworm kernel: "running kernel does not match on-disk kernel image'

2023-02-21 Thread Jan Wagner
Thanks for all your input. As the release is coming closer and I'm very short on time at the moment patches are very appreciated. Thanks Jan

Bug#1031724: fava: frontend is not built from source; missing source

2023-02-21 Thread Bastian Germann
Source: fava Version: 1.18-1 Severity: serious The package's frontend node package is not built from source. It cannot be built from source as the svelte framework seems to be missing from Debian. Additionally, some of the node packages' dependencies (see frontend/package.json) are included in

Bug#1031723: ITP: obs-command-source -- plugin for OBS Studio providing a dummy source to execute commands

2023-02-21 Thread Joao Eriberto Mota Filho
Package: wnpp Severity: wishlist Owner: Joao Eriberto Mota Filho X-Debbugs-Cc: debian-de...@lists.debian.org, Norihiro Kamae * Package name: obs-command-source Version : 0.3.2 Upstream Contact: Norihiro Kamae * URL :

Bug#1030298: #1030298: Patch backported from upstream, 10-day delayed NMU uploaded

2023-02-21 Thread Roland Mas
Hi all, Upstream has a patch that I successfully tested on barriere.d.o (i386 porterbox) after a minor tweak (the tolerance was not enough). I've committed it to a forked repository on salsa and submitted a merge request at

Bug#1031722: gdb: changelog missing in binary packages

2023-02-21 Thread Christian Göttsche
Source: gdb Version: 13.1-1 Severity: serious Justification: violates Debian Policy 12.7. The binary packages, e.g. gdb[1], do not contain a changelog file, required by the Debian Policy 12.7.[2]. [1]: https://packages.debian.org/sid/amd64/gdb/filelist [2]:

Bug#1031719: Output from a bullseye host with pulseaudio

2023-02-21 Thread Landry Minoza
Additionally this is what I see from a Bullseye desktop in the same network $ cat /etc/os-release PRETTY_NAME="Debian GNU/Linux 11 (bullseye)" NAME="Debian GNU/Linux" VERSION_ID="11" VERSION="11 (bullseye)" VERSION_CODENAME=bullseye ID=debian HOME_URL="https://www.debian.org/;

Bug#956804:

2023-02-21 Thread Valerio Bozzolan
I just want to mention that, I don't see ANY way at all to expose any custom environment variable to the Tomcat process itself. Feature? Unsure. AFAIK If you push an environment variable inside your catalina.sh, (for example via the previously mentioned setenv.sh), that variable just die in

  1   2   >