Bug#1033964: smarty3: CVE-2023-28447: Cross site scripting vulnerability in Javascript escaping

2023-04-04 Thread Salvatore Bonaccorso
Source: smarty3 Version: 3.1.47-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: clone -1 -2 Control: reassign -2 src:smarty4 4.3.0-1 Control: retitle -2 smarty4: CVE-2023-28447: Cross site scripting vulnerability in Javascript escaping

Bug#1033942: nmu: ppl_1:1.2-8.1

2023-04-04 Thread Lev Lamberov
Hi Paul, Вт 04 апр 2023 @ 21:42 Paul Gevers : > Control: tags -1 moreinfo > > Hi Lev, > > On 04-04-2023 15:05, Lev Lamberov wrote: >> Please, rebuild ppl against swi-prolog 9.0.4+dfsg-2 in unstable. The >> ppl package in unstable and testing was build against the older >> swi-prolog version,

Bug#1033963: curl: 7.88 breaks --unix connection

2023-04-04 Thread Martin Pitt
Package: curl Version: 7.88.1-7 Severity: important Tags: upstream fixed-upstream Upstream version 7.88 broke the `--unix` option. When doing something like curl -k --unix /run/cockpit/sock https://dummy it now fails with curl: (7) Failed to connect to dummy port 443 after 0 ms:

Bug#1033957: pike8.0: reproducible-builds: machine.h includes non-deterministic value for FB_CPU_TIME_IS_THREAD_LOCAL

2023-04-04 Thread Vagrant Cascadian
Control: retitle 1033957 pike8.0: reproducible-builds: machine.h includes non-deterministic value for FB_CPU_TIME_IS_THREAD_LOCAL Sorry, forgot to fix the title for the new bug. live well, vagrant

Bug#1033962: ITP: node-react-paginate -- ReactJS component to render a pagination

2023-04-04 Thread Yadd
Package: wnpp Severity: wishlist Owner: Yadd X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: node-react-paginate Version : 8.1.5 Upstream Contact: https://github.com/AdeleD/react-paginate/issues * URL : https://github.com/AdeleD/react-paginate * License

Bug#941980: pod2man: Please convert zero-width space (u200B) to \:

2023-04-04 Thread Russ Allbery
Diederik de Haas writes: > $ aptitude show podlators-perl > No candidate version found for podlators-perl > Package: podlators-perl > State: not a real package > Provided by: perl (5.32.1-4+deb11u1), perl (5.32.1-4+deb11u2), perl (5.36.0-7) > Does this mean that this bug is fixed in Stable and

Bug#1033961: dpkg: Please add support for zstd (Zstandard) compressed packages (for stable/oldstable)

2023-04-04 Thread theofficialgman
Package: dpkg Severity: wishlist Dear debian developers, Please backport these changes (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=892664 https://git.dpkg.org/cgit/dpkg/dpkg.git/diff/?id=2c2f7066b) into debian stable (bullseye) and debian oldstable (buster). The lack of tar.zst support is

Bug#1032642: iproute2: ip tunnel change ip6gre to gre crashes with stack smash

2023-04-04 Thread Stephen Hemminger
On Mon, 3 Apr 2023 20:47:01 -0600 David Ahern wrote: > On 4/3/23 9:24 AM, Stephen Hemminger wrote: > > ted > >> > >> This happens because iproute2 just assumes the tunnel is ipv4, but the > >> kernel "knows" it's actually ip6gre so when calling the SIOCGETTUNNEL > >> ioctl it writes back a

Bug#1005369: xserver-xorg-core: Breaks middle button trackpoint scrolling

2023-04-04 Thread Alban Browaeys
I am on a thinkapd (the Yoga S1) and xorg libinput driver works fine (I configure it through gnome-control-center). I really do not know what you mean by "avoid libinput's opinions on how my input should work". Could you give example? https://www.mankier.com/4/libinput these do not count as

Bug#1033960: RFP: btrfs-diff-go -- analyze differences between two BTRFS snapshots (like GNU diff for directories)

2023-04-04 Thread Christoph Anton Mitterer
Package: wnpp Severity: wishlist * Package name: btrfs-diff-go Version : git Upstream Contact: Michael Bideau * URL : https://github.com/mbideau/btrfs-diff-go * License : GPL 3 Programming Lang: Go Description : analyze differences between two BTRFS

Bug#1033959: binutils: reproducible builds: build paths embedded in debug symbols

2023-04-04 Thread Vagrant Cascadian
Source: binutils Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: buildpath X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build path is embedded in debugging symbols:

Bug#1033958: binutils: reproducible builds: files in source tarball in arbitrary order

2023-04-04 Thread Vagrant Cascadian
Source: binutils Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The files in the binutils tarball appear to be in arbitrary order, possibly affected by locale or filesystem differences:

Bug#1033954: pike8.0: reproducible builds: timestamp embedded in .html documentation

2023-04-04 Thread Vagrant Cascadian
On 2023-04-04, Vagrant Cascadian wrote: > A build timestamp is embedded in the data-timestamp field in various > .html documentation files: This additional patch is also needed to avoid additional timestamps in some of the rest of the documentation: From c8d7e168779597eb36cad22b051dea372179c7e5

Bug#1031352: Chromium on Wayland: Cannot join a Microsoft Teams enterprise meeting

2023-04-04 Thread Andres Salomon
Sorry, I've been fighting with chromium 112 not building on bullseye, but this is still on my todo list! On Fri, Mar 31 2023 at 01:02:10 AM +02:00:00, Amr Ibrahim wrote: Info: Microsoft has already phased out the Microsoft Teams Linux desktop clients in favour of the web app. Meaning that

Bug#1033957: pike8.0: reproducible builds: timestamp embedded in .html documentation

2023-04-04 Thread Vagrant Cascadian
Source: pike8.0 Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org A non-deterministic value is set in /usr/include/pike8.0/pike/machine.h based on some build time tests from configure:

Bug#1033917: [pkg-lxc-devel] Bug#1033917: lxc: apparmor profile no longer allows unprivileged guest systemd-logind to start (since bookworm)

2023-04-04 Thread Forest
>What's weird is that the problem was already happening in buster and >bullseye. That doesn't seem to be true, AFAICT. Bullseye (both my usual Bullseye guest and a freshly installed one) does not exhibit the 25 second hang. A freshly installed Buster guest doesn't, either. Not even with the

Bug#1033956: Support for zcfan

2023-04-04 Thread Klaus Ethgen
Package: orphan-sysvinit-scripts Version: 0.14 Severity: normal I was thinking to set this as wishlist but as the main functionality is to support broken packages I set the severity to normal. The zcfan daemon comes with only a systemd startup file which makes it unusable with sysv init. Please

Bug#1033862: nouveau: watchdog: BUG: soft lockup - CPU#0 stuck for 548s! [kscreenlocker_g:19260]

2023-04-04 Thread A. F. Cano
On Tue, Apr 04, 2023 at 10:20:11PM +0200, Salvatore Bonaccorso wrote: > Control: severity -1 important > Control: tags -1 + moreinfo > > Hi, > > On Sun, Apr 02, 2023 at 09:56:52PM -0400, A. F. Cano wrote: > > Package: src:linux > > Version: 6.1.20-1 > > Severity: critical > > File: nouveau > >

Bug#1033955: pike8.0: reproducible builds: kernel version affects buildid

2023-04-04 Thread Vagrant Cascadian
Source: pike8.0 Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build directory includes the running kernel version if PIKE_BUILD_OS is not set, as upstream the Makefile uses "uname -s

Bug#1033954: pike8.0: reproducible builds: timestamp embedded in .html documentation

2023-04-04 Thread Vagrant Cascadian
Source: pike8.0 Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org A build timestamp is embedded in the data-timestamp field in various .html documentation files:

Bug#1033953: unblock: gimp-help/2.10.34-1

2023-04-04 Thread Jordi Mallach
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: gimp-h...@packages.debian.org Control: affects -1 + src:gimp-help This is a pre-upload request to unblock package gimp-help. [ Reason ] The GIMP manual has been stale for

Bug#1020475: Ready to Implement

2023-04-04 Thread Soren Stoutner
The dependencies are finally in place so this can be implemented. To make things simpler for dictionary packagers, we are using a virtual package and an unversioned path for the conversion tool so that dictionary packagers don’t have to make modifications to their packages when the versions

Bug#1033945: unblock: pdns-recursor/4.8.4-1 [pre-approval]

2023-04-04 Thread Sebastian Ramacher
On 2023-04-04 15:33:01 +0200, Chris Hofstaedtler wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: Debian Security Team > > Please unblock package pdns-recursor > > [ Reason ] > > I would like to update

Bug#1033885: unblock: pydevd/2.9.5+ds-4

2023-04-04 Thread Sebastian Ramacher
On 2023-04-03 14:35:35 +0100, Julian Gilbey wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: pyd...@packages.debian.org > Control: affects -1 + src:pydevd > > Please unblock package pydevd > > [ Reason ] >

Bug#1033492: unblock: php8.2/8.2.4-1 ????

2023-04-04 Thread Moritz Mühlenhoff
Am Tue, Apr 04, 2023 at 09:14:36PM +0200 schrieb Paul Gevers: > On 04-04-2023 20:07, Moritz Mühlenhoff wrote: > > If we would add the list of source packages which are following micro > releases > > in stable-security to a machine-parseable list (e.g. somewhere in the > > Security Tracker repo),

Bug#1033952: unblock: osgi-core/8.0.0-2

2023-04-04 Thread Jochen Sprickerhof
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: osgi-c...@packages.debian.org Control: affects -1 + src:osgi-core Please unblock package osgi-core [ Reason ] The LoggerFactory and LogEntry interface definitions where added

Bug#1032234: cryptsetup-initramfs: libargon2 0~20190702-0.1 no longer links against libpthread which breaks cryptsetup-initramfs

2023-04-04 Thread Bastian Germann
Hi Ondřej, Please use the original bug. I have changed the BTS address. Am 04.04.23 um 22:25 schrieb Ondřej Surý: I went through the upstream changes between 20171227..20190702 and as far as I can tell, there's nothing important in there: ... Out of these, there are only two commits that

Bug#1033608: Exception: ModuleNotFoundError: No module named 'core.pe.photo'

2023-04-04 Thread Eriberto Mota
Control: severity 1033608 important After several checks and tests, I got the following conclusions: - The symlinks are present in the packages provided via Debian repositories. - The package, when installed via APT on Sid and Bookworm, is working correctly. - Building the package in a fresh

Bug#1033951: unblock: libxt/1:1.2.1-1.1

2023-04-04 Thread Bastian Germann
Package: release.debian.org Control: affects -1 + src:libxt X-Debbugs-Cc: li...@packages.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Please unblock package libxt. [ Reason ] Fixes RC bug #1005272. [ Impact ] Missing license. [ Risks ] None; only

Bug#1033862: nouveau: watchdog: BUG: soft lockup - CPU#0 stuck for 548s! [kscreenlocker_g:19260]

2023-04-04 Thread Salvatore Bonaccorso
Control: severity -1 important Control: tags -1 + moreinfo Hi, On Sun, Apr 02, 2023 at 09:56:52PM -0400, A. F. Cano wrote: > Package: src:linux > Version: 6.1.20-1 > Severity: critical > File: nouveau > Justification: breaks the whole system > X-Debbugs-Cc: af...@comcast.net > > When the above

Bug#1005359: xserver-xorg-core: Intel HD Graphics 610: blank screen

2023-04-04 Thread Alban Browaeys
Your logs shows: [70.057] (EE) dbus-core: error connecting to system bus: org.freedesktop.DBus.Error.FileNotFound (Failed to connect to socket /run/dbus/system_bus_socket: No such file or directory) Do you have dbus-daemon installed and its server running (systemctl status dbus.service)?

Bug#1032948: linux-image-6.1.0-5-amd64: oops in ucsi_acpi_notify

2023-04-04 Thread Diederik de Haas
On Tuesday, 4 April 2023 13:11:16 CEST Julien Cristau wrote: > On Mon, Apr 3, 2023 at 15:16:42 +0200, Diederik de Haas wrote: > > On Saturday, 18 March 2023 23:10:39 CEST Diederik de Haas wrote: > > > > On Monday, 3 April 2023 14:57:02 CEST Julien Cristau wrote: > > > > Not sure why patchwork

Bug#1033492: unblock: php8.2/8.2.4-1 ????

2023-04-04 Thread Ondřej Surý
> On 4. 4. 2023, at 21:14, Paul Gevers wrote: > > Sorry, that wasn't my intention. Maybe I should try to keep a better log, as > there's not many things "pre-negotiated". My memory isn't great. If you would > have pointed me at the earlier discussion, all would have been well I assume. No

Bug#1025789: bullseye-pu: wolfssl/4.6.0+p1-0+deb11u1_4.6.0+p1-0+deb11u2.debdiff

2023-04-04 Thread Bastian Germann
Control: tag -1 - moreinfo X-Debbugs-Cc: sirkilam...@msn.com On Wed, 15 Mar 2023 21:28:46 + Jonathan Wiltshire wrote: On Thu, Dec 08, 2022 at 08:07:09PM -0800, Felix Lechner wrote: > diff -Nru wolfssl-4.6.0+p1/debian/changelog.dch wolfssl-4.6.0+p1/debian/changelog.dch > ---

Bug#1033942: nmu: ppl_1:1.2-8.1

2023-04-04 Thread Paul Gevers
Control: tags -1 moreinfo Hi Lev, On 04-04-2023 15:05, Lev Lamberov wrote: Please, rebuild ppl against swi-prolog 9.0.4+dfsg-2 in unstable. The ppl package in unstable and testing was build against the older swi-prolog version, containing older library. For more information, please see this

Bug#1005369: xserver-xorg-core: Breaks middle button trackpoint scrolling

2023-04-04 Thread Salvo Tomaselli
No the libinput one is bad. libinput's author doesn't want options, so there is no way to have usable input that feels good on thinkpads. I'm using the xserver-xorg-input-evdev one. I guess when Xorg will be kicked out of debian, I will need to move to devuan or something like that, just to

Bug#1033492: unblock: php8.2/8.2.4-1 ????

2023-04-04 Thread Paul Gevers
Hi Ondřej, Moritz, On 04-04-2023 08:58, Ondřej Surý wrote: In all honesty, I thought that the pre-negotiated exception for PHP does apply to all future Debian releases, so it did come as surprise that I have to explain this again. Sorry, that wasn't my intention. Maybe I should try to keep a

Bug#941980: pod2man: Please convert zero-width space (u200B) to \:

2023-04-04 Thread Diederik de Haas
Hi Russ, On Sat, 26 Nov 2022 08:47:59 -0800 Russ Allbery wrote: > Russ Allbery writes: > > Jean-Michel Vourgère writes: > > >> I'm using pod to generate man files in package rrdtool. > > >> I expected pod2man to generate the corect \: escape sequence, but it > >> did not. > > [...] > > >

Bug#1032990: podman: user containers are completely broken with sssd: insufficient UIDs or GIDs available in user namespace

2023-04-04 Thread Martin Pitt
Control: reassign -1 sssd-common 2.8.2-3 Control: affects -1 podman Control: retitle -1 sssd-common" subids nsswitch.conf entry breaks user sub[ug]ids Control: severity -1 serious Matej Marusak [2023-04-03 14:00 +]: > This is easily reproducible by: > - Download newest image, e.g. >

Bug#1033756: wireshark: CVE-2023-1161

2023-04-04 Thread Salvatore Bonaccorso
Hi Bálint, On Tue, Apr 04, 2023 at 06:22:09PM +0200, Bálint Réczey wrote: > Control: tags -1 pending fixed-upstream > > Hi Salvatore, > > Salvatore Bonaccorso ezt írta (időpont: 2023. > márc. 31., P, 21:01): > > > > Source: wireshark > > Version: 4.0.3-1 > > Severity: important > > Tags:

Bug#1033492: unblock: php8.2/8.2.4-1 ????

2023-04-04 Thread Moritz Mühlenhoff
Am Tue, Apr 04, 2023 at 08:58:37AM +0200 schrieb Ondřej Surý: > Hi Paul, Salvatore, > > In all honesty, I thought that the pre-negotiated exception for PHP > does apply to all future Debian releases, so it did come as surprise > that I have to explain this again. Question to the release team: If

Bug#1005368: Re : xserver-xorg-core: Won’t upgrade

2023-04-04 Thread nicolas . patrois
On 04/04/2023 18:50:15, Alban Browaeys wrote: Hi > Are you still unable to install xserver-xorg-core without having to > remove all your drivers packages? Yes. > Can you close the issue if the issue is gone now? You can close the bug now, I upgraded the package (the bug seems to have been

Bug#1033921: debian-installer: Weekly build of d-i fails to find ipw2x00 firmware package

2023-04-04 Thread Cyril Brulebois
Charles Curley (2023-04-04): > I believe that this approach contravenes the spirit if not the letter > of the vote to include proprietary blobs in the Debian Installer. I'm not sure whether you're purposefully trying to demotivate people who have worked a lot to make that happen; if that's the

Bug#1033867: cloud.debian.org: Please add Amazon hibernation agent to EC2 AMIs

2023-04-04 Thread Noah Meyerhans
On 4/4/2023 9:26 AM, Noah Meyerhans wrote: Hi Dirk. Since we don't have this in the archive yet, I've refiled this as an RFP. Once it's packaged, we can add it to the AMIs. Well, *now* I've refiled it as an RFP, now that I can correctly spell "wnpp" :) noah

Bug#1033949:

2023-04-04 Thread Lev Borodin
Control: block 1006561 by -1

Bug#1033949: RFP: rust-peg -- Simple yet flexible parser generator that makes it easy to write robust parsers

2023-04-04 Thread Lev Borodin
Package: wnpp Severity: wishlist X-Debbugs-Cc: debian-r...@lists.debian.org Control: control block 1006561 by -1 * Package name: rust-peg Version : 0.8.1 Upstream Contact: Kevin Mehall * URL : https://docs.rs/peg/latest/peg/ * License : MIT Programming Lang:

Bug#1005368: xserver-xorg-core: Won’t upgrade

2023-04-04 Thread Alban Browaeys
Are you still unable to install xserver-xorg-core without having to remove all your drivers packages? Mind you were on unstable and unstable is supposed to have upgrade path breakages from time to time. Have you waited a few days to confirm the issue was not a transistion in progress? Can you

Bug#1033867: cloud.debian.org: Please add Amazon hibernation agent to EC2 AMIs

2023-04-04 Thread Noah Meyerhans
Control: reassign -1 wnpp.debian.org Control: retitle -1 RFP: amazon-ec2-hibinit-agent -- Amazon EC2 instance hibernation support > So the request is to also ship the agent preinstalled in the Debian AMIs. See > https://packages.ubuntu.com/search?keywords=ec2-hibinit-agent=names > for Ubuntu

Bug#1005369: xserver-xorg-core: Breaks middle button trackpoint scrolling

2023-04-04 Thread Alban Browaeys
Try removing xserver-xorg-input-synaptics then restart xorg. xserver-xorg-input-synaptics i sno longer supported by GNOME as far as know. xserver-xorg-input-libinput is the replacment. Cheers, Alban On Sat, 12 Feb 2022 09:53:16 +0100 "Salvo \"LtWorf\" Tomaselli" wrote: > Package:

Bug#1033756: wireshark: CVE-2023-1161

2023-04-04 Thread Bálint Réczey
Control: tags -1 pending fixed-upstream Hi Salvatore, Salvatore Bonaccorso ezt írta (időpont: 2023. márc. 31., P, 21:01): > > Source: wireshark > Version: 4.0.3-1 > Severity: important > Tags: security upstream > Forwarded: https://gitlab.com/wireshark/wireshark/-/issues/18839 > X-Debbugs-Cc:

Bug#1029218: dkms should perform reproducible build of modules

2023-04-04 Thread Andreas Beckmann
Thanks for checking further. On 02/04/2023 07.31, Daniel Richard G. wrote: │┄ Format-specific differences are supported for ELF binaries but no file-specific differences were detected; falling back to a binary diff. file(1) reports: ELF 64-bit LSB relocatable, x86-64, version 1 (SYSV),

Bug#1032990: podman: Better reproducer

2023-04-04 Thread Martin Pitt
Control: retitle -1 podman: user containers are completely broken with sssd: insufficient UIDs or GIDs available in user namespace Matej Marusak [2023-04-03 14:00 +]: > The original reproducer was not clear how important this failure is. It > efectively means that rootless podman is unusable

Bug#1033921: debian-installer: Weekly build of d-i fails to find ipw2x00 firmware package

2023-04-04 Thread Charles Curley
On Tue, 4 Apr 2023 07:57:34 +0200 Pascal Hambourg wrote: > On 04/04/2023 at 01:46, Cyril Brulebois wrote: > > > > Everything seems to be working as intended… > > Yes. The package is found but rejected because of licence issue. This > is the expected effect of "Fix files removal for

Bug#1033845: u-boot fails to boot on pinebook pro if installed on internal emmc

2023-04-04 Thread Wolfgang Zarre
From: Vagrant Cascadian To: Wolf , 1033...@bugs.debian.org Date: Monday, 3 April 2023 at 21:48 Subject: Bug#1033845: u-boot fails to boot on pinebook pro if installed on internal emmc However, the SPL settings are just precaution, because I have the intention to try again installing u-boot

Bug#1033948: RFS: png2svg/1.5.2-1 [ITP] -- CLI utility for converting small PNG images to SVG Tiny 1.2

2023-04-04 Thread 肖盛文
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "png2svg": * Package name : png2svg Version : 1.5.2-1 Upstream contact : Alexander F. Rødseth * URL : https://github.com/xyproto/png2svg * License : MIT, Unlicense * Vcs :

Bug#1033947: unblock: widelands/2:1.1-3

2023-04-04 Thread Tobias Frost
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: widela...@packages.debian.org Control: affects -1 + src:widelands Please unblock package widelands The upload fixes the version constraint in widelands-data.maintscript for

Bug#1033608: Exception: ModuleNotFoundError: No module named 'core.pe.photo'

2023-04-04 Thread Luca Falavigna
tags 1033608 + moreinfo + unreproducible thanks Hi Ionuț, Il giorno mar 28 mar 2023 alle ore 16:03 Ionuț Ciocîrlan ha scritto: > In the debian package these symlinks are missing, and emptu directories > are created instead (although the lib files are built and packaged). I just checked in a

Bug#1033946: unblock: unknown-horizons/2019.1-6

2023-04-04 Thread Tobias Frost
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: unknown-horiz...@packages.debian.org Control: affects -1 + src:unknown-horizons Please unblock package unknown-horizons This updates fixes #1033833: the package font-unifont

Bug#1033945: unblock: pdns-recursor/4.8.4-1 [pre-approval]

2023-04-04 Thread Chris Hofstaedtler
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: Debian Security Team Please unblock package pdns-recursor [ Reason ] I would like to update pdns-recursor 4.8.2 to 4.8.4, to: - fix CVE-2023-26437, sole change in 4.8.4 -

Bug#1033944: sptag: build loops until the disk fills up

2023-04-04 Thread Julien Cristau
Source: sptag Version: 0.0~git20230323.0341c33+ds-1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) X-Debbugs-Cc: jcris...@debian.org The latest sptag upload to experimental broke one of our buildds after its log took up 70G disk space.

Bug#1033943: swupdate: SURICATTA_LUA replaces SURICATTA_HAWKBIT

2023-04-04 Thread Bastian Germann
Package: swupdate Severity: important Version: 2022.12+dfsg-2 X-Debbugs-Cc: quirin.gylsto...@siemens.com The change in https://salsa.debian.org/debian/swupdate/-/commit/086ed5b5dbc71f90767f6ca09d9529046c60b324 does not only add the lua backend for suricatta but replaces the default hawkBit

Bug#1033942: nmu: ppl_1:1.2-8.1

2023-04-04 Thread Lev Lamberov
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu X-Debbugs-Cc: p...@packages.debian.org Control: affects -1 + src:ppl Hi, Please, rebuild ppl against swi-prolog 9.0.4+dfsg-2 in unstable. The ppl package in unstable and testing was build

Bug#1033024: lios hangs when opening Preferences

2023-04-04 Thread Gunnar Hjalmarsson
Nice fix in 2.7.2-5, Samuel. :) (Why didn't I try that?) That version ought to be fine for both Debian 12 and Ubuntu 23.04, and you will be able to consider the 'full upstream approach' in experimental later. -- Cheers, Gunnar

Bug#1033941: pdns-recursor: CVE-2023-26437: Deterred spoofing attempts can lead to authoritative servers being marked unavailable

2023-04-04 Thread Chris Hofstaedtler
Source: pdns-recursor Version: 4.8.2-1 Severity: important Tags: security upstream X-Debbugs-Cc: Debian Security Team The following vulnerability was published for pdns-recursor. CVE-2023-26437: | Deterred spoofing attempts can lead to authoritative servers being | marked unavailable. | When

Bug#950920: [3dprinter-general] trimesh_3.5.25-1_amd64.changes REJECTED

2023-04-04 Thread Gregor Riepl
E TypeError: Cannot cast array data from dtype('int64') to dtype('int32') according to the rule 'safe' Tracked it down to incorrect usage of numpy.bincount: This function requires the native index type, which is int32 on i686 (and probably all other 32-bit architectures). I submitted

Bug#1032948: linux-image-6.1.0-5-amd64: oops in ucsi_acpi_notify

2023-04-04 Thread Julien Cristau
On Mon, Apr 3, 2023 at 15:16:42 +0200, Diederik de Haas wrote: > On Saturday, 18 March 2023 23:10:39 CEST Diederik de Haas wrote: > On Monday, 3 April 2023 14:57:02 CEST Julien Cristau wrote: > > > Not sure why patchwork still shows v2 of the patch as v4 is available > > > here: > > >

Bug#1033940: ITP: sphinx-lint -- sphinx-lint is a reStructuredText linter for sphinx-doc

2023-04-04 Thread Julien Palard
Package: wnpp Severity: wishlist Owner: Julien Palard X-Debbugs-Cc: debian-de...@lists.debian.org, jul...@palard.fr * Package name: sphinx-lint Version : 0.6.7 Upstream Contact: Julien Palard * URL : https://sphinx-contrib/sphinx-lint/ * License : Python

Bug#1033939: unblock: python-tz/2022.7.1-3

2023-04-04 Thread Benjamin Drung
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: bdr...@debian.org Please unblock package python-tz [ Reason ] python-tz contains a hard-coded list of timezones. This causes problems on updates to tzdata. Last example:

Bug#1033938: wayfire: Insufficient deps

2023-04-04 Thread Patrick McFarland
Package: wayfire Version: 0.7.4-2 Severity: important X-Debbugs-Cc: diabl...@gmail.com Dear Maintainer, On a fresh Debian install that has no other desktop components installed, Wayfire will not start unless a supplier of libglx-vendor (eg, libglx-mesa0) is also installed; Wayfire does not give

Bug#1033937: system does a poweroff instead of reboot

2023-04-04 Thread Peter Palfrader
Source: linux-signed-amd64 Version: 6.1.12+1~bpo11+1 Severity: normal Hi! While running linux-image-6.1.0-0.deb11.5-amd64 on bullseye (with stable systemd or with backports systemd), when I type reboot, the system goes down for reboot but then powers off. This issue is not present in the stable

Bug#1033936: fwupd: FuEngine failed to get releases for UEFI dbx ... requires >= 1.8.14

2023-04-04 Thread Daniel Lewart
Package: fwupd Version: 1.5.7-4 Severity: normal Debian EFI Team, Since Apr 1, 2023, new priority 6 (info) fwupd messages are being logged, as shown below. I think these may be caused by Linux Foundation (UEFI Revocation) Secure Boot dbx Version 220 (Released: 2023-03-31 13:40:38):

Bug#1033935: unblock: ausweisapp2/1.26.3-1

2023-04-04 Thread John Paul Adrian Glaubitz
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: ausweisa...@packages.debian.org,aklitz...@gmail.com Control: affects -1 + src:ausweisapp2 Hello! I would like to ask for the package ausweisapp2 to be unblocked for testing.

Bug#1033901: Acknowledgement (unblock: castle-game-engine/7.0~alpha.2+dfsg1-4)

2023-04-04 Thread Abou Al Montacir
Control: retitle -1 unblock: castle-game-engine/7.0~alpha.2+dfsg1-5 On Mon, 2023-04-03 at 20:22 +0200, Abou Al Montacir wrote: > This ticket should be seen as an add > on https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033840 which was > accepted. Unfortunately, I forgot to add the patch of

Bug#1033917: [pkg-lxc-devel] Bug#1033917: lxc: apparmor profile no longer allows unprivileged guest systemd-logind to start (since bookworm)

2023-04-04 Thread Pierre-Elliott Bécue
Forest wrote on 03/04/2023 at 23:18:10+0200: > Package: lxc > Version: 1:5.0.2-1 > Severity: normal > X-Debbugs-Cc: fores...@sonic.net > > Dear Maintainer, > > After upgrading an unprivileged container from bullseye to bookworm, LXC's > AppArmor profiles are no longer sufficient for the guest's

Bug#1033934: ITP: puppet-module-voxpupuli-kmod -- Puppet module for manipulating modprobe and kernel modules

2023-04-04 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: puppet-module-voxpupuli-kmod Version : 3.2.0 Upstream Author : Voxpupuli * URL : https://github.com/voxpupuli/puppet-kmod * License : Apache-2.0

Bug#1033933: llvm-16-dev: cmake findpackage(LLVM) fails due to missing /usr/lib/llvm-16/lib/libomptarget.so.16

2023-04-04 Thread Andreas Beckmann
Package: llvm-16-dev Version: 1:16.0.0-1~exp5 Severity: serious cmake llvm detection is broken due to missing dependencies: The following minimal CMakeLists.txt project(foo) find_package(LLVM 16 REQUIRED) fails with CMake Error at /usr/lib/llvm-16/lib/cmake/llvm/LLVMExports.cmake:1809

Bug#1033931: UB: memcmp is not atomic in C11 either

2023-04-04 Thread Mathieu Malaterre
The bugzilla thread is rather long. But I took the liberty to report the issue as grave following the comment: https://sourceware.org/bugzilla/show_bug.cgi?id=29863#c11 Feel free to downgrade severity if my understanding is incorrect. Thanks

Bug#1033902: ulogd2 debian package missing PCAP output plugin from upstream

2023-04-04 Thread Harald Welte
On Tue, Apr 04, 2023 at 08:31:42AM +0100, Chris Boot wrote: > On 03/04/2023 19:37, Harald Welte wrote: > > However, I was surprised to see that the ulogd2 package both in Debian > > stable as well > > as unstable doesn't contain the PCAP output plugin. Is that a conscious > > decision? I would

Bug#1033932: unblock: calamares-settings-debian/10.0.5-2

2023-04-04 Thread Jonathan Carter
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: calamares-settings-deb...@packages.debian.org Control: affects -1 + src:calamares-settings-debian Please unblock package calamares-settings-debian This addresses serious bug

Bug#1033931: Fwd: Novice needs help submitting a bug report

2023-04-04 Thread Mathieu Malaterre
Package: libc-bin Version: 2.36-8 Severity: grave Justification: renders package unusable Dear Maintainer, There is a bug in glibc 2.36 that has been fixed in 2.37. The two links below detail the original bug report and the fix. - Upstream bug report -

Bug#1033930: calamares-settings-debian: needs dependency on pkexec (which is no longer provided on KDE iso images)

2023-04-04 Thread Jonathan Carter
Package: calamares-settings-debian Severity: important During testing of the RC1 live images, it was found that Calamares doesn't start on the KDE images. This was due to a missing pkexec, which was previously supplied on the KDE plasma desktop image. On the Debian configuration for

Bug#1033902: ulogd2 debian package missing PCAP output plugin from upstream

2023-04-04 Thread Chris Boot
On 03/04/2023 19:37, Harald Welte wrote: However, I was surprised to see that the ulogd2 package both in Debian stable as well as unstable doesn't contain the PCAP output plugin. Is that a conscious decision? I would think it's a rather useful feature to have. It's included in the

Bug#1033929: unblock: node-interpret/2.2.0-3

2023-04-04 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: node-interp...@packages.debian.org Control: affects -1 + src:node-interpret Please unblock package node-interpret [ Reason ] node-interpret uses network for its autopkgtest.

Bug#1032984:

2023-04-04 Thread Stefan Schippers
On Sun, Mar 26, 2023 at 22:03:25 +0200, Stefan Schippers wrote: I have closed upstream bug: https://gitlab.freedesktop.org/xorg/lib/libx11/-/issues/186 since i got no feedback at all and it seems affecting only the specific libX11 1.8.4 - fvwm2 combination that very few people use, I

Bug#1033928: debian-security-support: [INTL:tr] turkish translation of debconf messages

2023-04-04 Thread Atila KOÇ
Package: debian-security-support Severity: wishlist Tags: l10n patch Hello, Find attached the updated Turkish translation of the debian-security-support debconf messages. It has been submitted for review to the debian-l10n-turkish mailing list. Please include it in your next upload. Regards,

Bug#1033927: unblock: node-sinon/14.0.2+ds+~cs74.13.25-2

2023-04-04 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: node-si...@packages.debian.org Control: affects -1 + src:node-sinon Please unblock package node-sinon [ Reason ] node-sinon is a package used during JS tests. In Debian JS

Bug#1033492: unblock: php8.2/8.2.4-1 ????

2023-04-04 Thread Ondřej Surý
Hi Paul, Salvatore, I've finally got some time here. In all honesty, I thought that the pre-negotiated exception for PHP does apply to all future Debian releases, so it did come as surprise that I have to explain this again. The quality of PHP in Debian has increased since we started using

Bug#1033820: node-snapdragon: autopkgtest regression: Cannot find module 'snapdragon-node'

2023-04-04 Thread Yadd
On 4/4/23 07:08, Yadd wrote: On 4/3/23 21:55, Paul Gevers wrote: Hi yadd, On 03-04-2023 05:42, Yadd wrote: I'm unable to reproduce this issue: there is a link that provides snapdragon-node inside snapdragon-capture-set: I could by running the following on my laptop: paul@mulciber ~ $

Bug#1033921: debian-installer: Weekly build of d-i fails to find ipw2x00 firmware package

2023-04-04 Thread Pascal Hambourg
On 04/04/2023 at 01:46, Cyril Brulebois wrote: Everything seems to be working as intended… Yes. The package is found but rejected because of licence issue. This is the expected effect of "Fix files removal for non-accepted firmware packages (#1032377)", although it might be seen by users as