Bug#1040001: transition: r-base

2023-06-30 Thread Paul Gevers
Hi Andreas, On 30-06-2023 21:35, Andreas Tille wrote: I'm not sure that we are in the right status to ask for a transition bug Anytime is good to ask for a transition, particularly when the transition is already ongoing. https://lists.debian.org/debian-r/2023/06/msg00025.html In

Bug#1040016: discord

2023-06-30 Thread matt quintanilla
They also have a public test build and an alpha build that we could also upload and should we upload the .deb version or the tar.gz version this is the .tar.gz version he/him https://www.mattquintanilla.xyz/

Bug#1040016: discord

2023-06-30 Thread matt quintanilla
fwiw arch got permission to upload it to the arch repos so I think it should be fine to upload to the debian repository he/him https://www.mattquintanilla.xyz/

Bug#1040019: mate-control-center: various memory leaks resolved upstream

2023-06-30 Thread Mike Gabriel
Package: mate-control-center Version: 1.26.0-1 Severity: important In upstream release 1.26.1 various memory leaks have been fixed. This should be cherry-picked to a bookworm pu upload. Mike -- DAS-NETZWERKTEAM c\o Technik- und Ökologiezentrum Eckernförde Mike Gabriel, Marienthaler Str. 17,

Bug#1040018: ITP: discord a modern voice & text chat app

2023-06-30 Thread matt quintanilla
Package: discord Severity: ITP Package name: discord Version: 0.0.27 Upstream Author: https://discord.com URL: https://discord.com License: custom Description: All-in-one voice and text chat for gamers Copyright: https://discord.com/terms#7 depends=('libnotify' 'libxss' 'nspr' 'nss' 'gtk3')

Bug#1040017: ITP: discord a modern voice & text chat a

2023-06-30 Thread matt quintanilla
Package:discord Severity: ITP Package name: discord Version: 0.0.27 Upstream Author: https://discord.com URL: https://discord.com License: custom Description: All-in-one voice and text chat for gamers Copyright: https://discord.com/terms#7 depends=('libnotify' 'libxss' 'nspr' 'nss' 'gtk3')

Bug#1040016: Package:discord ITP: discord a modern voice & text chat app

2023-06-30 Thread matt quintanilla
Package:discord Severity: ITP Package name: discord Version: 0.0.27 Upstream Author: https://discord.com URL: https://discord.com License: custom Description: All-in-one voice and text chat for gamers Copyright: https://discord.com/terms#7 depends=('libnotify' 'libxss' 'nspr' 'nss' 'gtk3')

Bug#1039966: isc-dhcp-server.service: Could not get Tjener LDAP object (but it exists).

2023-06-30 Thread Mike Gabriel
Control: tags -1 - pending Hi Daniel, On Fr 30 Jun 2023 11:17:57 CEST, Daniel Teichmann wrote: Package: debian-edu-config Severity: important Error messages popping up in syslog on newly installed systems.. gber (Guido Berhörster) can reproduce this issue. less /var/log/syslog: ```

Bug#1040015: share/debian-edu-config/tools/edu-icinga-setup: Uses static password for DB setup

2023-06-30 Thread Mike Gabriel
Package: debian-edu-config Version: 2.12.33 Severity: important The script share/debian-edu-config/tools/edu-icinga-setup helps us with setting up an Icinga2 system on the Debian Edu main server for the Debian Edu network. I that script, the MySQL DB for Icinga2 is set up with a hard-coded

Bug#1024997: what kind of bug was it?

2023-06-30 Thread Junichi Uekawa
Hi, On Sat, 01 Jul 2023 06:35:06 +0900, Preuße, Hilmar wrote: > > [1 ] > [1.1 ] > [1.1.1 ] > On 26.06.2023 08:26, Junichi Uekawa wrote: > > Hi Junichi, > > > From my guess it's some kind of buffer management issue; what was the > > bug and is there a minimal fix ? > > > To be honest: I

Bug#1038920: python3-certbot-dns-gandi: Update from Debian 11 -> 12 leaves certificate updates broken

2023-06-30 Thread Norbert Preining
> sed -i -- 's/certbot-plugin-gandi:dns/dns-gandi/g' > /etc/letsencrypt/renewal/*.conf I see a few issues: * First of all, you need to convert some - to _ since these are translated into python modules * Then, does that suffice? Looking into the conf files I have, I also see

Bug#1040014: coreutils: tail: -f with inotify behaves differently than without when watching the same file twice

2023-06-30 Thread наб
Package: coreutils Version: 9.1-1 Severity: normal Dear Maintainer, $ tail -f zupa zupa & sleep 0.1; echo zupa >> zupa [1] 2883746 ==> zupa <== mupa ==> zupa <== mupa ==> zupa <== zupa but $ tail ---disable-inotify -f zupa zupa & sleep 0.1; echo zupa >> zupa [1] 2884513 ==> zupa <== mupa

Bug#1040013: coreutils: tail: -F with inotify trivially misses renaming of directory's directory

2023-06-30 Thread наб
Package: coreutils Version: 9.1-1 Severity: normal Dear Maintainer, If ~/uwu$ echo tupa > t/a/i/l/zupa then $ tail -F ~/uwu/t/a/i/l/zupa tupa and when ~/uwu$ mv t q; mkdir -p t/a/i/l; echo trużpan > t/a/i/l/zupa nothing changes. Naturally, $ cat /proc/$(pgrep tail)/fdinfo/4 pos:

Bug#860789: freecad: import of openscad file turns "differences" into "unions"

2023-06-30 Thread Petter Reinholdtsen
Control: found -1 0.20.2+dfsg1-4 I tested the example file, and the problem is still present in the FreeCAD version included in Bookworm. -- Happy hacking Petter Reinholdtsen

Bug#1040012: Possible missing firmware /lib/firmware/i915/dg2_huc_gsc.bin for module i915 that is part of the source

2023-06-30 Thread Daniel Leidert
Package: firmware-misc-nonfree Version: 20230515-2 Severity: normal -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 The file dg2_huc_gsc.bin is part of the source, but it is not shipped as part of firmware-misc-nonfree. I cannot find any reason, why it is not packaged as well. So I wonder if

Bug#1040011: mate-polkit: Allow mate-polkit to be used in Xfce, Cinnamon, and other desktops

2023-06-30 Thread Unit 193
Source: mate-polkit Severity: wishlist Dear Maintainer, As policykit-1-gnome is slated for removal from Trixie (#990271), and it's the most generic policykit agent, it would be quite useful if mate-polkit could be utilized on other desktops. In https://bugs.debian.org/990259 there was a

Bug#1012819: gnome-software: When installing freecad via gnome-software, the freecad-common package is installed instead of freecad

2023-06-30 Thread Petter Reinholdtsen
[PM Eugen Wintersberger 2022-06-14] > when I install freecad via gnome-software the freecad-common package instead > of the freecad package is installed. Therefore, a user cannot run freecad when > installed with gnome-software. Is this still a problem with version 0.20.2+dfsg1-4? The freecad

Bug#1033695: freecad-python3: FreeCAD segfaults instantly

2023-06-30 Thread Petter Reinholdtsen
[Cev Ing] > Dear Maintainer, > > FreeCAD crashes instantly during startup. I can not even use the option -l to > produce a log file. I am not the maintainer, but can add another data point. It is not crashing on startup for me. In the unlikely case that the locale setting was causing this, I

Bug#1031566: freecad-common: inspect.getargspec is used in gui_snapper.py which is no longer supported by python >= 3.10

2023-06-30 Thread Petter Reinholdtsen
I have added this patch to the Debian package git repository, and discovered in the process that the fix was already applied upstream in https://github.com/FreeCAD/FreeCAD/pull/8101, commit fe02d63c8c9b1280978be841d04e68a0a55cceb9. -- Happy hacking Petter Reinholdtsen

Bug#1039862: cpdb-libs 1.2.0-2+deb12u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1039862 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: cpdb-libs Version:

Bug#1040010: [debian-installer] Please support more arm64 boards

2023-06-30 Thread Roman Mamedov
Package: debian-installer Severity: normal Hello, There are 42 DTBs shipped with the installer for Allwinner alone: https://d-i.debian.org/daily-images/arm64/daily/device-tree/allwinner/ But for the bootloader aka firmware aka u-boot:

Bug#1039974: tomcat10: tomcat user has wrong home "/var/lib/tomcat" directory in /etc/passwd

2023-06-30 Thread Markus Koschany
Control: tags -1 moreinfo > deploy .war in tomcat10 > got errors from tomcat10 in "journalctl -f" > >    * What exactly did you do that was effective ? > > change tomcat user home in /etc/passwd to /var/lib/tomcat10 > >    * What was the outcome of this action? > > Problem solved You most

Bug#1038879: proftpd-dfsg 1.3.8+dfsg-4+deb12u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1038879 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: proftpd-dfsg Version:

Bug#1038000: texlive-bin 2022.20220321.62855-5.1+deb12u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1038000 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: texlive-bin Version:

Bug#1038879: bookworm-pu: package proftpd-dfsg/1.3.8+dfsg-4+deb12u1

2023-06-30 Thread Jonathan Wiltshire
On Fri, Jun 30, 2023 at 02:44:54PM +0200, Francesco P. Lovergine wrote: > On Fri, Jun 30, 2023 at 12:54:23PM +0100, Jonathan Wiltshire wrote: > > > > Can I have a source-only upload please? I'll reject the upload for now, you > > can reuse the same version. > > > > Done. You'll need to bump

Bug#1040009: ITP: python-pytest-trio -- Pytest plugin for trio

2023-06-30 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer X-Debbugs-Cc: debian-de...@lists.debian.org -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: python-pytest-trio Version : 0.8.0 Upstream Contact: Emmanuel Leblond * URL :

Bug#1039862: bookworm-pu: cpdb-libs/1.2.0-2+deb12u1

2023-06-30 Thread Thorsten Alteholz
On Thu, 29 Jun 2023, Jonathan Wiltshire wrote: Please go ahead. Great, thanks ... ... and uploaded. Thorsten

Bug#1036530: Regression from "ACPI: OSI: Remove Linux-Dell-Video _OSI string"? (was: Re: Bug#1036530: linux-signed-amd64: Hard lock up of system)

2023-06-30 Thread Nick Hastings
Hi, * Limonciello, Mario [230701 06:40]: > > > > Nevertheless: thx for your report your help through this thread. > > > > No problem. I am willing to try to do more, but right now I don't know > > how to do what has been suggested. > > > > Here is where to report Nouveau bugs: > >

Bug#1040008: RFS: vim-rails/5.4-2 -- vim development tools for Rails development

2023-06-30 Thread Thiago Marques
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "vim-rails": * Package name : vim-rails Version : 5.4-2 Upstream contact : [fill in name and email of upstream] * URL :

Bug#1040007: libwww-mechanize-perl: migrate to libhttp-cookiejar-perl?

2023-06-30 Thread Steve Langasek
lib/WWW/Mechanize.pm currently says: You are encouraged to install L and use L as your cookie jar. L provides a better security model matching that of current Web browsers when L is installed. use HTTP::CookieJar::LWP (); my $jar = HTTP::CookieJar::LWP->new; my $agent =

Bug#1040007: libwww-mechanize-perl: migrate to libhttp-cookiejar-perl?

2023-06-30 Thread Steve Langasek
Package: libwww-mechanize-perl Version: 2.16-1 Severity: wishlist User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu mantic Dear maintainers, The libwww-perl package has recently switched from depending on libhttp-cookies-perl, to depending on libhttp-cookiejar-perl, with the upstream

Bug#1040006: pflogsumm: fails to count sent emails

2023-06-30 Thread Yvan Masson
Package: pflogsumm Version: 1.1.5-7 Severity: normal Dear maintainer, I use pflogsumm on a Bullseye system, to analyze Postfix 3.5.17 logs. It is possible my setup has some oddities, but while pflogsumm is globally working, it fails to count sent emails: $ pflogsumm my_log_file [...] 0

Bug#1036530: Regression from "ACPI: OSI: Remove Linux-Dell-Video _OSI string"? (was: Re: Bug#1036530: linux-signed-amd64: Hard lock up of system)

2023-06-30 Thread Limonciello, Mario
Nevertheless: thx for your report your help through this thread. No problem. I am willing to try to do more, but right now I don't know how to do what has been suggested. Here is where to report Nouveau bugs: https://gitlab.freedesktop.org/drm/nouveau/-/issues/

Bug#1036530: Regression from "ACPI: OSI: Remove Linux-Dell-Video _OSI string"? (was: Re: Bug#1036530: linux-signed-amd64: Hard lock up of system)

2023-06-30 Thread Nick Hastings
Hi, * Thorsten Leemhuis [230630 22:02]: > On 27.06.23 00:34, Nick Hastings wrote: > > * Linux regression tracking (Thorsten Leemhuis) > > [230626 21:09]: > >> Hi, Thorsten here, the Linux kernel's regression tracker. Top-posting > >> for once, to make this easily accessible to everyone. > >> >

Bug#1024997: what kind of bug was it?

2023-06-30 Thread Preuße
On 26.06.2023 08:26, Junichi Uekawa wrote: Hi Junichi, From my guess it's some kind of buffer management issue; what was the bug and is there a minimal fix ? To be honest: I don't really care. I know the issue is solved in texinfo 7.0.x, hence I perform no further investigation. Uploading TI

Bug#1037086: dropbear-initramfs: /etc/dropbear/initramfs/dropbear_dss_host_key file not generated

2023-06-30 Thread Guilhem Moulin
On Fri, 30 Jun 2023 at 11:14:35 -0500, Michael Meier wrote: > I had to edit the file /usr/share/initramfs-tools-hooks so it also copies the > dss key: src:dropbear doesn't ship that file, do you mean /usr/share/initramfs-tools/hooks/dropbear? > The option DROPBEAR_OPTIONS="-E" should be

Bug#1040005: ITP:magpie - window manager for the budgie desktop

2023-06-30 Thread David Mohammed
Package: wnpp Severity: wishlist Owner: David Mohammed (fossfree...@ubuntu.com) Package name : magpie Version : 0.9.1 Upstream Author : BuddiesOfBudgie URL : https://github.com/BuddiesOfBudgie/magpie License : GPL-2+ and GPL-3+ and LGPL-2+ and LGPL-2.1+ and Expat and NTP-BSD-variant and

Bug#1038000: bookworm-pu: package texlive-bin/2022.20220321.62855-5.1+deb12u1

2023-06-30 Thread Preuße
On 30.06.2023 13:56, Jonathan Wiltshire wrote: Hi Jonathan, You also need to target bookwork, not bookworm-proposed-updates, so I'll reject the uploads and you can re-use the same version number. Done. The packages are in the "Resolution Pending" queue. Hope I did everything right this time.

Bug#1039976: detex.1: some remarks and editorial fixes in a patch for the manual

2023-06-30 Thread Preuße
On 30.06.2023 01:46, Bjarni Ingi Gislason wrote: Dear Bjarni, here are some notes and a patch for the manual. Many thanks for your patches: they are heavily appreciated. It would be nice if you could provide your content as attachment, this would help me to extract the content, even if it

Bug#1040004: netplan.io: autopkgtest fails with iproute2 v6.4

2023-06-30 Thread Luca Boccassi
Package: netplan.io Version: 0.106.1-2 Dear Maintainers, I just uploaded iproute2 6.4-1 and some outputs have changed, so netplan's autopkgtest is failing: 4161s == 4161s FAIL: test_mix_bridge_on_bond

Bug#1040003: jackd: add pipewire-jack to dependency alternativees

2023-06-30 Thread Dominik George
Package: jackd Version: 5+nmu1 Severity: wishlist The pipewire-jack package provides a JACKd implementation based on PipeWire, which I am using on my audio recording workstation. Other packages depend on jackd if they need a JACK daemon to talk to (e.g. qjackctl), and that pulls in jackd2

Bug#1039907: apt-cacher-cleanup.pl clears/removes all cached packages on trixie

2023-06-30 Thread Mark Hindley
Control: tags -1 moreinfo On Thu, Jun 29, 2023 at 01:35:28PM +0200, Chris Nospam wrote: > Package: apt-cacher > Version: 1.7.29 > > As far as I can see, calling /usr/share/apt-cacher/apt-cacher-cleanup.pl > (e.g. after apt-get dist-upgrade which stores some packages to the cache) > under debian

Bug#1036004:

2023-06-30 Thread Nathan Schulte
I believe we've finally tracked down the root cause of this issue, and a set of patches has come across that should resolve it. I haven't yet tried these latest patches but instead an earlier trial based upon v6.4-rc4, which worked well. Two patch sets resolve the issue; I haven't tried just the

Bug#1039926: Will file bug report for complete R transition (Was: Bug#1039926: svglite requires rebuild under R 4.3.*)

2023-06-30 Thread Andreas Tille
Hi Johannes, Am Fri, Jun 30, 2023 at 03:22:19PM +0200 schrieb Johannes Ranke: > I think option 1 from [1] is the way to go, i.e. make r-base provide a > graphics API version according to the R changelog, and have the relevant > packages depend on that graphics API version. How to identify them

Bug#1039958: autopkgtest-build-podman: Image creation fails with "sd-bus call: Permission denied"

2023-06-30 Thread Gioele Barabucci
On 30/06/23 21:15, Simon McVittie wrote: On Fri, 30 Jun 2023 at 12:52:31 +0200, Gioele Barabucci wrote: autopkgtest-build-podman's failure is due to the issue reported in [1], i.e. the Debian setup of podman requires `dbus-user-session`, but none of the podman-related packages Depends on it.

Bug#1040001: transition: r-base

2023-06-30 Thread Andreas Tille
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: r-b...@packages.debian.org, debia...@lists.debian.org Control: affects -1 + src:r-base Hi, I'm not sure that we are in the right status to ask for a transition bug since

Bug#1040002: Drop Felix from Uploaders

2023-06-30 Thread Felix Lechner
Package: nullmailer Severity: wishlist Hi David, I have not used nullmailer in a little while, and I do not plan to work on the package in the near future. Please remove my email address from the Uploaders field at your leisure. Thanks! Kind regards Felix P.S. The proposed change alone did

Bug#1040000: plantuml: CVE-2023-3432

2023-06-30 Thread Salvatore Bonaccorso
Source: plantuml Version: 1:1.2020.2+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for plantuml. CVE-2023-3432[0]: | Server-Side Request Forgery (SSRF) in GitHub repository |

Bug#1039999: plantuml: CVE-2023-3431

2023-06-30 Thread Salvatore Bonaccorso
Source: plantuml Version: 1:1.2020.2+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for plantuml. CVE-2023-3431[0]: | Improper Access Control in GitHub repository plantuml/plantuml prior | to

Bug#1038920: python3-certbot-dns-gandi: Update from Debian 11 -> 12 leaves certificate updates broken

2023-06-30 Thread Harlan Lieberman-Berg
tag 1038920 +patch thanks On Fri, Jun 30, 2023 at 6:35 AM Norbert Preining wrote: > You could still send me the code and I give it an eye ;-) Sold! preinst file is attached. Sincerely, -- Harlan Lieberman-Berg ~hlieberman preinst Description: Binary data

Bug#1039998: kwin-wayland: kwin_wayland_wrapper spams thousands of messages to the journal

2023-06-30 Thread mister01x
Package: kwin-wayland Version: 4:5.27.5-3 Severity: minor X-Debbugs-Cc: mister...@web.de Dear Maintainer, kwin_wayland_wrapper writes thousands of lines a day to the journal. A majority of those lines read: Jun 30 13:10:11 kwin_wayland_wrapper[5999]: kwin_screencast: Dropping a screencast frame

Bug#1039958: autopkgtest-build-podman: Image creation fails with "sd-bus call: Permission denied"

2023-06-30 Thread Simon McVittie
On Fri, 30 Jun 2023 at 12:52:31 +0200, Gioele Barabucci wrote: > autopkgtest-build-podman's failure is due to the issue reported in [1], i.e. > the Debian setup of podman requires `dbus-user-session`, but none of the > podman-related packages Depends on it. > > [1] https://bugs.debian.org/1013344

Bug#1039997: RFP: go-mega -- A client library in go for mega.nz storage service, required for rclone

2023-06-30 Thread Alastair
Package: wnpp Severity: wishlist * Package name: go-mega Version : Unknown Upstream Contact: See https://github.com/t3rm1n4l/go-mega * URL : https://github.com/t3rm1n4l/go-mega * License : MIT Programming Lang: Go Description : A client library in Go

Bug#1025552: Bug#1037295: live-config: starting Calamares installer requires a password (which is 'live')

2023-06-30 Thread Simon McVittie
On Fri, 30 Jun 2023 at 16:01:49 +0200, Roland Clobus wrote: > On 10/06/2023 19:14, Simon McVittie wrote: > > On Sat, 10 Jun 2023 at 15:10:35 +0100, Simon McVittie wrote: > > > * Boot debian-live-12.0.0-amd64-gnome.iso (the version used for > > >release-day testing) > > >- KDE has a similar

Bug#1039996: steam-installer: steam/need-nvidia-i386 template refers to a non-existing nvidia-driver-libs-i386 package

2023-06-30 Thread Ricardo Pérez
Package: steam-installer Version: 1:1.0.0.78~ds-2 Severity: normal X-Debbugs-Cc: rica...@ubuntu.com Dear Maintainer, The steam/need-nvidia-i386 debconf template, found in `/var/lib/dpkg/info/steam-installer.templates`, asks the user to install the non-existing `nvidia-driver-libs-i386` package.

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-06-30 Thread Salvatore Bonaccorso
Hi [CC'ing the security team alias] On Fri, Jun 30, 2023 at 08:12:37PM +0200, Jérémy Lal wrote: > Hi, > > Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a > écrit : > > > Source: nodejs > > Version: 18.13.0+dfsg1-1 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc:

Bug#1036829: libretro-mgba: Audio stutters horribly and sounds distorted

2023-06-30 Thread Ryan Tandy
Hello, I'm preparing an update for mgba in bookworm to fix this issue. Can I ask you to test the proposed package and confirm that it works for you? On my system, the current bookworm package has no audio at all in retroarch, which is different from what you reported, so I'd like to be sure

Bug#1039995: RM: iceoryx [armhf] -- ANAIS; 32-bit architectures broken and unsupported

2023-06-30 Thread Timo Röhling
Package: ftp.debian.org Severity: normal User: ftp.debian@packages.debian.org Usertags: remove X-Debbugs-Cc: iceo...@packages.debian.org Control: affects -1 + src:iceoryx -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear FTP team, please remove the armhf binaries of src:iceoryx as they

Bug#1039994: bullseye-pu: package logrotate/3.18.0-2+deb11u2

2023-06-30 Thread Christian Göttsche
Package: release.debian.org Control: affects -1 + src:logrotate User: release.debian@packages.debian.org Usertags: pu Tags: bullseye Severity: normal [ Reason ] The previous upload (3.18.0-2+deb11u1) cherry picked several commits around the state file handling of logrotate. In particular

Bug#1039990: [Pkg-javascript-devel] Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-06-30 Thread Jérémy Lal
Hi, Le ven. 30 juin 2023 à 19:21, Salvatore Bonaccorso a écrit : > Source: nodejs > Version: 18.13.0+dfsg1-1 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team < > t...@security.debian.org> > > Hi, > > The following vulnerabilities were

Bug#1039993: apparmor policy for tcpdump does not allow reading of "pcapng" files

2023-06-30 Thread Chris Kuethe
Package: tcpdump Version: 4.99.1-3ubuntu0.1 I originally reported this as an Ubuntu bug and was redirected here. https://bugs.launchpad.net/ubuntu/+source/tcpdump/+bug/2024017 As the title says, the stock apparmor policy for tcpdump does not allow "pcapng" files - such as those produced by

Bug#1036400: partman-jfs: JFS is on its way out, please remove from the installer

2023-06-30 Thread John Paul Adrian Glaubitz
Hello! On Sat, 2023-05-20 at 15:07 +0200, Adam Borowski wrote: > The JFS filesystem is deprecated in the kernel: on life support since 2009 > and with talks of removal altogether. Not sure where you got this information from, but JFS [1] unlike ReiserFS [2] is not marked as deprecated in the

Bug#1039992: kcm does not initialize kdc_offset, leading to random "Ticket expired" and "Clock skew too great" errors

2023-06-30 Thread Steffen Kieß
Package: heimdal-kcm Version: 7.8.git20221117.28daf24+dfsg-2 Control: found -1 7.7.0+dfsg-2+deb11u3 In kcm/cache.c in kcm_ccache_alloc(), slot->kdc_offset is not initialized. The means that kcm will return an uninitialized values for GET_KDC_OFFSET (the value will often be 0, but sometimes

Bug#1039991: libxml2: CVE-2022-2309

2023-06-30 Thread Salvatore Bonaccorso
Source: libxml2 Version: 2.9.14+dfsg-1.2 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/libxml2/-/issues/378 X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 2.9.10+dfsg-6.7+deb11u4 Control: found -1 2.9.10+dfsg-1 Hi, The following

Bug#1039990: nodejs: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590

2023-06-30 Thread Salvatore Bonaccorso
Source: nodejs Version: 18.13.0+dfsg1-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for nodejs. CVE-2023-30581[0], CVE-2023-30588[1], CVE-2023-30589[2] and CVE-2023-30590[3]. If you fix the

Bug#1039988: Please provide a python3-all-venv package to parallel the python3-all etc packages

2023-06-30 Thread Julian Gilbey
Package: python3-venv Version: 3.11.2-1+b1 Severity: wishlist I have a package whose test suite builds a virtual environment for the test. (This is an integral part of the test.) Unfortunately, though I can depend on python3-all for the build and then attempt to run the tests for all supported

Bug#1039989: plantuml: CVE-2022-1231

2023-06-30 Thread Salvatore Bonaccorso
Source: plantuml Version: 1:1.2020.2+ds-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for plantuml. CVE-2022-1231[0]: | XSS via Embedded SVG in SVG Diagram Format in GitHub repository |

Bug#897933: dhcp-client instead of isc-dhcp-client?

2023-06-30 Thread Beolach
Is there a reason libguestfs0 depends on isc-dhcp-client specifically, instead of the virtual dhcp-client? I prefer dhcpcd over isc-dhcp-client, and there are several other dhcp-client implementations as well. If it really does need something specifically from isc-dhcp-client, could it be

Bug#1039985: libjson-smart-java: buster-lts has a newer version than bullseye/bookworm/sid

2023-06-30 Thread Andreas Beckmann
Package: libjson-smart-java Version: 2.2-2 Severity: serious Tags: bullseye bookworm trixie sid User: debian...@lists.debian.org Usertags: piuparts X-Debbugs-Cc: Bastien Roucariès Hi, during a test with piuparts I noticed your package cannot be upgraded from buster-lts to any newer release

Bug#1037086: dropbear-initramfs: /etc/dropbear/initramfs/dropbear_dss_host_key file not generated

2023-06-30 Thread Michael Meier
I've had the same problem. Took me quite some time to realize why nothing is working. I'm using debian bookworm. dropbear-initramfs: Installed: 2022.83-1 dropbear-bin: Installed: 2022.83-1 I had to edit the file /usr/share/initramfs-tools-hooks so it also copies the dss key: < for

Bug#1039984: yail: CVE-2023-33460: Memory leak in yajl 2.1.0 with use of yajl_tree_parse function

2023-06-30 Thread Tobias Frost
Source: yajl Version: 2.1.0-2 Severity: important Tags: security upstream patch X-Debbugs-Cc: Debian Security Team The following CVE was published for yajl: CVE-2023-33460[0]: There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and

Bug#1039983: cups: Cannot change printer.conf to CMYK

2023-06-30 Thread Kerstin Hoef-Emden
Package: cups Version: 2.4.2-3 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Upgrade from bullseye to bookworm * What exactly did you do (or not do) that was effective (or

Bug#1036400: partman-jfs: JFS is on its way out, please remove from the installer

2023-06-30 Thread Steve McIntyre
On Fri, Jun 30, 2023 at 04:56:37PM +0200, Adam Borowski wrote: >On Sun, May 21, 2023 at 07:35:36AM +0200, Cyril Brulebois wrote: >> Adam Borowski (2023-05-20): >> > The JFS filesystem is deprecated in the kernel: on life support since 2009 >> > and with talks of removal altogether. Thus, we

Bug#1036569: openvswitch-common: leaves alternatives after purge: /usr/sbin/ovs-vswitchd -> /etc/alternatives/ovs-vswitchd

2023-06-30 Thread Andreas Beckmann
Followup-For: Bug #1036569 Control: tag -1 patch find attached a patch to reintroduce openvswictch-common.postinst which clean up the forgotten alternative Andreas >From 082e6d3c316f32e203debc285fa1c20ba460c3b1 Mon Sep 17 00:00:00 2001 From: Andreas Beckmann Date: Fri, 30 Jun 2023 14:19:38

Bug#1039480: [astroplan] Please update to 0.8 for astropy 5.3 compatibility

2023-06-30 Thread Ole Streicher
Hi Vincent, if there are only a few tests, I would disable them and update the package. The main goal for the tests in Debian are that the package works well in that environment - i.e. with the installed astropy etc. This can be tested also with a new tests disabled. I usually just report

Bug#1039982: packages.debian.org: Cannot download package source files due to mixed content URL

2023-06-30 Thread Boyuan Yang
Package: www.debian.org Severity: normal Converting the email to a bug report. Thanks, Boyuan Yang 在 2023-06-26星期一的 17:45 -0700,John Horigan写道: > I tried to download the the source files and debian files for source package > agg, but Chrome blocked the downloads with this message on the error

Bug#1039480: [astroplan] Please update to 0.8 for astropy 5.3 compatibility

2023-06-30 Thread Vincent Prat
Dear Ole, There is this long-running issue in astroplan 0.8: https://github.com/astropy/astroplan/issues/416. It is claimed to be solved, but I just tried and it still fails. I can try to patch the version currently in Debian so that it is compatible with astropy 5.3, or disable the

Bug#1036400: partman-jfs: JFS is on its way out, please remove from the installer

2023-06-30 Thread Adam Borowski
On Sun, May 21, 2023 at 07:35:36AM +0200, Cyril Brulebois wrote: > Adam Borowski (2023-05-20): > > The JFS filesystem is deprecated in the kernel: on life support since 2009 > > and with talks of removal altogether. Thus, we really shouldn't offer to > > format new setups with it. There are

Bug#1039981: graphviz: Please update fonts-liberation v2 dependency (follow-up of #1003006)

2023-06-30 Thread Boyuan Yang
Source: graphviz Severity: minor Version: 2.42.2-7 Tags: trixie sid Dear Debian graphviz package maintainer, Back in https://bugs.debian.org/1003006 , we replaced recommendation of package font-liberation with font-liberation2. Now after Bookworm release, the font maintainers decided to drop

Bug#1039573: cannot authenticate after lock: pam_unix(lightdm:auth): auth could not identify password

2023-06-30 Thread Arturo Borrero Gonzalez
On Wed, 28 Jun 2023 10:58:39 +0200 Arturo Borrero Gonzalez wrote: Thanks for the follow up, I'll keep you updated in the next few days. I have not experienced this problem again since the update.

Bug#1039450: ndctl: Split ndctl-monitor (and cxl-monitor?) into own package

2023-06-30 Thread Adam Borowski
Control: severity -1 wishlist > I often use a custom livecd verision of Debian with various utilities > pre-installed, so they can be easily used offline, or without needing to > reinstall them after each reboot. Such a livecd is a non-standard (but not non-important!) usage, and it already

Bug#1018106: re: sshd: pam_env(sshd:session): deprecated reading of user environment enabled

2023-06-30 Thread Richard van den Berg
On Wed, 1 Feb 2023 04:43:07 -0500 nick black wrote: > the cause of this output is the following line in /etc/pam.d/sshd: > > # In Debian 4.0 (etch), locale-related environment variables were moved to > # /etc/default/locale, so read that as well. > session required pam_env.so user_readenv=1

Bug#1037295: live-config: starting Calamares installer requires a password (which is 'live')

2023-06-30 Thread Roland Clobus
Hello Simon, On 10/06/2023 19:14, Simon McVittie wrote: On Sat, 10 Jun 2023 at 15:10:35 +0100, Simon McVittie wrote: * Boot debian-live-12.0.0-amd64-gnome.iso (the version used for release-day testing) - KDE has a similar issue with slightly different steps to start the installer,

Bug#1039980: puppet-module-puppetlabs-mysql sets password repeatedly on MariaDB 10.3

2023-06-30 Thread Larsen
Package: puppet-module-puppetlabs-mysql Version: 8.1.0-7 Using this puppet module to create MariaDB users leads to Puppet wanting to set a user's password again and again as it doesn't fetch the current password/authentication string correctly: authentication string is always empty (when the

Bug#1039926: Will file bug report for complete R transition (Was: Bug#1039926: svglite requires rebuild under R 4.3.*)

2023-06-30 Thread Charles Plessy
Hi all, pardon me the offence and the noise, but I asked ChatGPT... -- Me: In Debian, updates of the r-base package sometimes break backwards compatibility with a small number of binary packages shipping CRAN packages, which have in common to use R’s graphic API. We

Bug#1039622: nvidia-cuda-toolkit 11.8.0-5~deb12u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1039622 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: nvidia-cuda-toolkit

Bug#1029681: nvidia-legacy-340xx-driver: Qt5 apps fail to launch with a segfault

2023-06-30 Thread Andreas Beckmann
Control: reopen -1 On 29/06/2023 18.16, jim_p wrote: So, can a patch like the one for kodi be applied to qt5? I am mentioning again that arch does not have a seperate -gles package for qt5, so a single lib that works everywhere should be possible. It's unlikely to convince the Qt5 maintainers

Bug#1039979: base-files: /var/run and /var/lock should not be absolute symlinks

2023-06-30 Thread henrik
Package: base-files Version: 12.4 Severity: normal Dear Maintainer, /var/run is currently an absolute symlink to /run /var/run should be a relative symlink to ../run if /var/run is deleted, then /usr/lib/tmpfiles.d/var.conf recreates /var/run as relative symlink to ../run /var/lock is

Bug#1039926: Will file bug report for complete R transition (Was: Bug#1039926: svglite requires rebuild under R 4.3.*)

2023-06-30 Thread Johannes Ranke
Hi, I think option 1 from [1] is the way to go, i.e. make r-base provide a graphics API version according to the R changelog, and have the relevant packages depend on that graphics API version. How to identify them was discussed previously on this list [2]. Using the codesearch and github URLS

Bug#964941: base-files: please maintain base-files in a VCS such as git on salsa.d.o

2023-06-30 Thread Lee Garrett
Bump. I'm trying to understand why /var/local/ is root:staff (#1039973), and a VCS would really help with that. It would also make it easier for you to accept patches for bugs.

Bug#1039978: axohelp.1: some remarks and editorial fixes for the manual

2023-06-30 Thread Bjarni Ingi Gislason
Package: texlive-binaries Version: 2022.20220321.62855-5.1 Severity: minor Tags: patch Dear Maintainer, here are some notes and a patch for the manual. -.-. The difference between the formatted outputs can be seen with: nroff -man > nroff -man > diff -u and for groff using

Bug#1039977: kpsewhich.1: some remarks and editorial fixes for the manual

2023-06-30 Thread Bjarni Ingi Gislason
Package: texlive-binaries Version: 2022.20220321.62855-5.1 Severity: minor Tags: patch Dear Maintainer, here are some notes and a patch for the man page. -.-. The difference between the formatted outputs can be seen with: nroff -man > nroff -man > diff -u and for groff using

Bug#1039976: detex.1: some remarks and editorial fixes in a patch for the manual

2023-06-30 Thread Bjarni Ingi Gislason
Package: texlive-binaries Version: 2022.20220321.62855-5.1 Severity: minor Tags: patch Dear Maintainer, here are some notes and a patch for the manual. -.-. The difference between the formatted outputs can be seen with: nroff -man > nroff -man > diff -u and for groff using

Bug#1039975: bibtex.original.1: some remarks and editorial fixes for the manual

2023-06-30 Thread Bjarni Ingi Gislason
Package: texlive-binaries Version: 2022.20220321.62855-5.1 Severity: minor Tags: patch Dear Maintainer, here are a few notes and fixes for the man page. -.-. The difference between the formatted outputs can be seen with: nroff -man > nroff -man > diff -u and for groff using

Bug#1039714: gobject-introspection: dh_girepository does not fetch all symbols from GIR files

2023-06-30 Thread Thomas Uhle
On Fri, 30 Jun 2023, أحمد المحمودي wrote: On Wed, Jun 28, 2023 at 05:00:10PM +0200, Thomas Uhle wrote: > 2. dh_girepository does not fetch the 41 symbols from HarfBuzz-0.0.gir >that are compiled into libharfbuzz-gobject.so.0. I have attached a >small patch for it, so that the missing

Bug#1039933: bepasty 1.0.0-1+deb12u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1039933 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: bepasty Version:

Bug#962420: /usr/local/share/fonts owned by group staff even if /etc/staff-group-for-usr-local not present

2023-06-30 Thread henrik
Package: fontconfig Version: 2.14.1-4 Followup-For: Bug #962420 Dear Maintainer, Is there any progress on this bug? It is present in stable release of bookworm too now. -- System Information: Debian Release: 12.0 APT prefers stable-security APT policy: (500, 'stable-security'), (500,

Bug#1037182: bmake 20200710-14+deb11u1 flagged for acceptance

2023-06-30 Thread Jonathan Wiltshire
package release.debian.org tags 1037182 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: bmake Version:

Bug#1036530: Regression from "ACPI: OSI: Remove Linux-Dell-Video _OSI string"? (was: Re: Bug#1036530: linux-signed-amd64: Hard lock up of system)

2023-06-30 Thread Karol Herbst
On Fri, Jun 30, 2023 at 3:02 PM Thorsten Leemhuis wrote: > > On 27.06.23 00:34, Nick Hastings wrote: > > * Linux regression tracking (Thorsten Leemhuis) > > [230626 21:09]: > >> Hi, Thorsten here, the Linux kernel's regression tracker. Top-posting > >> for once, to make this easily accessible

Bug#1039974: tomcat10: tomcat user has wrong home "/var/lib/tomcat" directory in /etc/passwd

2023-06-30 Thread Peter (Stone) Steiner
Package: tomcat10 Version: 10.1.6-1 Severity: important Dear Maintainer, * What led up to the situation? deploy .war in tomcat10 got errors from tomcat10 in "journalctl -f" * What exactly did you do that was effective ? change tomcat user home in /etc/passwd to /var/lib/tomcat10 *

  1   2   >