Bug#1067582: gnuplot: please provide a profile to break B-D cycle

2024-03-30 Thread Thorsten Glaser
Hi Dima, >- Today leptonlib Build-Depends on gnuplot-nox only if !nocheck. So if > you build leptonlib with testing disabled, there's no dependency on > gnuplot oh, that is maybe new? But I see other packages depending on gnuplot-nox, so this would still be very helpful. >- Today the gnuplot

Bug#1068024: Potential solution to your downgrade problem in dpkg

2024-03-30 Thread Thorsten Glaser
Joshua Hudson dixit: >2) Statically link all the decompressor libraries into dpkg. Yes this means Totally no. Also, at this point in time, I’m pretty sure that new external suggestions are… not very helpful. The situation is being analysed by a cross-team taskforce, please let them do the

Bug#970021: Seeking a small group to package Apache Arrow (was: Bug#970021: RFP: apache-arrow -- cross-language development platform for in-memory analytics)

2024-03-30 Thread Diane Trout
Hi Julian, On Sat, 2024-03-30 at 20:22 +, Julian Gilbey wrote: > Lovely to hear from you, and oh wow, that's amazing, thank you! > > I can't speak for anyone else, but I suggest that pushing your > updates > to the science-team package would be very sensible; it would be silly > for someone

Bug#1068117: dieharder: dab_monobit2 crashes with ntuple > 17

2024-03-30 Thread Lucas Thode
Package: dieharder Version: 3.31.1.4-1.1 Severity: normal X-Debbugs-Cc: thode...@gmail.com Dear Maintainer, `dieharder -d 209 -n $nvalue` crashes for $nvalue>17: $ dieharder -d 209 #=# #dieharder version

Bug#1067952: mes: FTBFS on armhf

2024-03-30 Thread Vagrant Cascadian
Control: forwarded 1067952 https://lists.gnu.org/archive/html/bug-mes/2024-01/msg8.html On 2024-03-29, Kentaro HAYASHI wrote: > mes 0.26-1 fails to build on armhf. > > FYI: > > https://buildd.debian.org/status/fetch.php?pkg=mes=armhf=0.26-1=1704511792=0 Yeah, forwarded this upstream in

Bug#1068024: Potential solution to your downgrade problem in dpkg

2024-03-30 Thread Joshua Hudson
The dpkg -> xz-utils downgrade problem has a suggestion that suggests itself. 1) Downgrade dpkg's dependency to the last known good. It doesn't matter how old so long as it can read the file formats. I understand this is likely to be 5.4.1. 2) Statically link all the decompressor libraries into

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Thorsten Glaser
Christoph Anton Mitterer dixit: >Is anyone on the Debian side trying to figure out how far we've been >practically affected? Yes, a multi-team task force is working on it and will inform users once it is known how to proceed, inclusing how much to throw away and rebuild. bye, //mirabilos --

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Thorsten Glaser
Pierre Ynard dixit: >version into the Debian archive, as seen in #1067708. To quote Thorsten >from that thread: > >> Very much *not* a fan of NMUs doing large changes such as >> new upstream versions. > >I can't say why exactly he would not be a fan, but with hindsight that >was an interesting

Bug#940151: unattended-upgrades: i configure my unattended-upgrade conf with following Origins:

2024-03-30 Thread Wesley Schwengle
Hi, > Unattended-Upgrade::Allowed-Origins { > "o=Debian, a=stable"; > "o=Debian Backports, a=buster-backports"; }; The problem with the example is that it uses a=CODENAME-backports and not a=stable-backports. The a= should be n= or codename= when using the CODENAME. I've

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Thorsten Glaser
Christoph Anton Mitterer dixit: >Can we be confidently sure that going back to 5.4.5 is enough? No. >The last one, still from Lasse Collin seems to be 5.4.1: In this bugreport, we’re discussing going back to before any contributions by the adversary. To see whether it’s an option at all (and

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Christoph Anton Mitterer
One more thing: Is anyone on the Debian side trying to figure out how far we've been practically affected? I mean let's assume we're "lucky", and the backdoor is only in 5.6.0/5.6.1... and that none of the adversary's earlier commits introduced any serious holes[0] which wouldn't be known yet.

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Alberto Garcia
On Sun, Mar 31, 2024 at 01:16:07AM +0100, Christoph Anton Mitterer wrote: > The last one, still from Lasse Collin seems to be 5.4.1: > https://git.tukaani.org/?p=xz.git;a=tag;h=f52502e78bf84f516a739e8d8a1357f27eeea75f There are commits from Jia before that, and some that are authored by Lasse but

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Christoph Anton Mitterer
Hey. Can we be confidently sure that going back to 5.4.5 is enough? At least the git tag for that seems to be still signed by the adversary: https://git.tukaani.org/?p=xz.git;a=tag;h=9e4835399118b98954f110f76af2a0d504d2f531 The last one, still from Lasse Collin seems to be 5.4.1:

Bug#1067376: [nore...@release.debian.org: gforth is marked for autoremoval from testing]

2024-03-30 Thread Bernd Paysan
I had a look at building gforth 0.7.3 from within Debian sid and dpkg- buildpackage. What's happening here is that lt_dlopen() can't find the just generated files; the generated libraries are in the build directory (a subdirectory of it) and fine, they are just in a place where the loader

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-30 Thread Till Kamppeter
On 30/03/2024 23:19, Paul Szabo wrote: Most issues now reported upstream: https://github.com/OpenPrinting/cups/issues/917 https://github.com/OpenPrinting/cups/issues/918 https://github.com/OpenPrinting/cups/issues/919 The issue with pdftopdf not reported upstream, because I could not find the

Bug#1068116: python-pylibdmtx: depends on pre-t64 packages

2024-03-30 Thread Sebastian Ramacher
Source: python-pylibdmtx Version: 0.1.10-1 Severity: serious X-Debbugs-Cc: sramac...@debian.org python3-pylibdtmtx depends on a package that was renamed for the time_t 64 transition. The dependency needs to be updated to the new package name. Cheers -- Sebastian Ramacher

Bug#1068115: tardy: FTBFS on arm{el,hf}: ./tardy/main.cc:282:(.text.startup+0x578): undefined reference to `tardy_mtime(long)'

2024-03-30 Thread Sebastian Ramacher
Source: tardy Version: 1.25-2 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) X-Debbugs-Cc: sramac...@debian.org https://buildd.debian.org/status/fetch.php?pkg=tardy=armel=1.25-2%2Bb2=1711746975=0 g++ -D_LARGEFILE_SOURCE

Bug#1068114: libfluidsynth-dev: package depends on libsystemd-dev

2024-03-30 Thread Gravis
Package: libfluidsynth-dev Version: 2.3.4-1+b3 Severity: important X-Debbugs-Cc: noreply+debian.reportbug.photofilmst...@adaptivetime.com Dear Maintainer, I have libfluidsynth3 installed and it correctly does not depend on libsystemd. However, when trying to install libfluidsynth-dev insists it

Bug#1068100: armci-mpi: autopkgtest spuriously fails

2024-03-30 Thread Samuel Thibault
Samuel Thibault, le sam. 30 mars 2024 16:55:11 +0100, a ecrit: > I have forwarded a fix to upstream > https://github.com/pmodels/armci-mpi/pull/47 > which is already merged. > > Unless somebody objects, I'll NMU it. I have uploaded the attached changes to delayed/2. Samuel diff -Nru

Bug#1066060: libpam-modules: pam_lastlog.so missing

2024-03-30 Thread Colin Watson
On Mon, Mar 11, 2024 at 10:12:29PM +0100, Mourad De Clerck wrote: > I noticed the following line in my logs: > > login[2449]: PAM unable to dlopen(pam_lastlog.so): > /usr/lib/security/pam_lastlog.so: cannot open shared object file: No such > file or directory > > I looked in the deb files from

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-30 Thread Paul Szabo
Most issues now reported upstream: https://github.com/OpenPrinting/cups/issues/917 https://github.com/OpenPrinting/cups/issues/918 https://github.com/OpenPrinting/cups/issues/919 The issue with pdftopdf not reported upstream, because I could not find the corresponding "current" source. Cheers,

Bug#1067122: cups-daemon: cupsd ignores job-originating-host-name

2024-03-30 Thread Paul Szabo
Issue now reported upstream: https://github.com/OpenPrinting/cups/issues/916 Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University:

Bug#1068043: BinNMU 1.11-1+b1 depends on both, libmspack0 and libmspack0t64, and is hence uninstallable (at least on armhf)

2024-03-30 Thread Eric Sharkey
On Fri, Mar 29, 2024 at 6:30 PM Axel Beckert wrote: > This is likely caused by hardcoding a dependency on libmspack0 in > debian/control: > > https://sources.debian.org/src/cabextract/1.11-1/debian/control/#L10 > The hardcoded dependency was added for Debian bug #914263 to work around an issue

Bug#1067582: gnuplot: please provide a profile to break B-D cycle

2024-03-30 Thread Dima Kogan
Hi. I might be misunderstanding what you're asking specifically, but two notes: - Today leptonlib Build-Depends on gnuplot-nox only if !nocheck. So if you build leptonlib with testing disabled, there's no dependency on gnuplot - Today the gnuplot source package has a hard Build-Depends on

Bug#1068113: ITP: libsmb2 -- SMB2/3 client library

2024-03-30 Thread Joe Mondloch
ITP: libsmb2 -- SMB2/3 client library Package: wnpp Severity: wishlist Owner: Joe Mondloch X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: libsmb2 Version : 4.0.0 Upstream Authors: Ronnie Sahlberg URL : https://github.com/sahlberg/libsmb2 * License

Bug#1067096: ITP: galvani -- reads data from a device with graphical plots and evaluation

2024-03-30 Thread Dima Kogan
"Dr. Burkard Lutz" writes: > The actual version ("0.34") is the first which contains all desired > functions, and after extensive testing I hope that there are only > minor bugs left. Thanks for explaining. > Therfore I decided to make an attempt for publishing it on debian. > Should I rename

Bug#1067924: dgit: can't clone/fetch dockerfile-mode past few days

2024-03-30 Thread Ian Jackson
Sean Whitton writes ("Bug#1067924: dgit: can't clone/fetch dockerfile-mode past few days"): > spwhitton@chiark:~/tmp>dgit clone dockerfile-mode > canonical suite name for unstable is sid > fetching existing git history > fatal: Could not read from remote repository. > >

Bug#1068068: Need rebootstrapping on armel and armhf

2024-03-30 Thread tony mancill
On Sat, Mar 30, 2024 at 01:29:42PM +0500, Andrey Rakhmatullin wrote: > Package: icmake,libbobcat6 > Severity: serious > Tags: ftbfs > > As src:icmake B-D:libbobcat-dev, src:bobcat B-D:icmake, there seems to be zero > packaging-level support for bootstrapping, the packages are not >

Bug#1043686: Please provide a proper download location for beads

2024-03-30 Thread Andreas Tille
Ping? Am Thu, Jan 25, 2024 at 12:46:17PM +0100 schrieb Andreas Tille: > Hi Filippo, > > I intended to have a look at bug #1043686 noticing that beads is > shipping a copy of cimg (which is packaged and should probably be > excluded from upstream source in favour of the packaged code). > When

Bug#1068017: util-linux: please ship liblastlog2 packages

2024-03-30 Thread Steve Langasek
On Sat, Mar 30, 2024 at 08:32:40AM +0100, Sven Joachim wrote: > >> So we could either put pam_lastlog2.so into a common-* file from > >> src:pam, or openssh and shadow should switch their setup. > >> What do we all think about that? > > pam should not be adding any modules to common-* that it

Bug#1068112: pcp: CVE-2024-3019

2024-03-30 Thread Salvatore Bonaccorso
Source: pcp Version: 6.2.0-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for pcp. CVE-2024-3019[0]: | A flaw was found in PCP. The default pmproxy configuration exposes | the Redis server

Bug#1068111: wireshark: CVE-2024-2955

2024-03-30 Thread Salvatore Bonaccorso
Source: wireshark Version: 4.2.2-1 Severity: important Tags: security upstream Forwarded: https://gitlab.com/wireshark/wireshark/-/issues/19695 X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for wireshark. CVE-2024-2955[0]: | T.38 dissector

Bug#1060371: git-buildpackage: feature request: gbp sync

2024-03-30 Thread Otto Kekäläinen
Today I filed https://salsa.debian.org/salsa-ci-team/pipeline/-/issues/342 ("Detect missing tags: force maintainer to continue tagging upload commits if it was done before") which would be easy to implement if something like `gbp sync` already existed.

Bug#970021: Seeking a small group to package Apache Arrow (was: Bug#970021: RFP: apache-arrow -- cross-language development platform for in-memory analytics)

2024-03-30 Thread Julian Gilbey
Hi Diane, On Fri, Mar 29, 2024 at 11:49:07AM -0700, Diane Trout wrote: > On Mon, 2024-03-25 at 18:17 +, Julian Gilbey wrote: > > > > > > So this is a plea for anyone looking for something really helpful to > > do: it would be great to have a group of developers finally package > > this! 

Bug#1068110: netty: CVE-2024-29025

2024-03-30 Thread Salvatore Bonaccorso
Source: netty Version: 1:4.1.48-9 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for netty. CVE-2024-29025[0]: | Netty is an asynchronous event-driven network application framework | for rapid

Bug#1068024:

2024-03-30 Thread Jeffrey Walton
It looks like more analysis has revealed this is a RCE with the payload in the modulus of a public key: "The payload is extracted from the N value (the public key) passed to RSA_public_decrypt, checked against a simple fingerprint, and decrypted with a fixed ChaCha20 key before the Ed448 signature

Bug#1068109: sudo: [INTL:pt_BR] Brazilian Portuguese debconf templates translation

2024-03-30 Thread Adriano Rafael Gomes
Package: sudo Tags: l10n patch Severity: wishlist Hello, Could you please update the Brazilian Portuguese translation? Attached you will find the file pt_BR.po. It is UTF-8 encoded and tested with msgfmt and podebconf-display-po. Kind regards. pt_BR.po.gz Description: application/gzip

Bug#1068108: ITP: python-pysocks -- Python SOCKS client module

2024-03-30 Thread Josenilson Ferreira da Silva
Package: wnpp Severity: wishlist Owner: Josenilson Ferreira da Silva X-Debbugs-Cc: debian-de...@lists.debian.org, nilsonfsi...@hotmail.com * Package name: python-pysocks Version : 1.7.1 Upstream Contact: Anorov * URL : https://github.com/Anorov/PySocks * License

Bug#1066438: backuppc-rsync: FTBFS: lib/compat.c:154:16: error: too few arguments to function ‘gettimeofday’

2024-03-30 Thread J. Fernando LAGRANGE
Le 13/03/2024 à 13:02, Lucas Nussbaum a écrit : […] Hi, During a rebuild of all packages in sid, your package failed to build on amd64. […] Thanks for such information. Since no action was taken in last 2 weeks, I opened a bug upstream [1]. [1]

Bug#1068107: cloud.debian.org: pull images with compromised xz packages

2024-03-30 Thread Ross Vandegrift
Package: cloud.debian.org Severity: important X-Debbugs-Cc: rvandegr...@debian.org Hi team, We should probably pull the daily sid and trixie images built with the compromised xz-utils. Looking at the json manifests, this would be: sid: all images since 2024-02-27 trixie: 2024-03-05

Bug#1012325: dialog: Multi-Arch: foreign package should not contain static library

2024-03-30 Thread Thomas Dickey
On Sat, Mar 30, 2024 at 08:02:18PM +0100, Sven Joachim wrote: > On 2024-03-30 12:38 +0100, Santiago Vila wrote: > > > El 30/3/24 a las 9:43, Sven Joachim escribió: > >> I think it would make sense for Debian to follow what Arch and Fedora > >> are doing, introduce a libdialog15 package with the

Bug#1068103: Cannot disable touchpad acceleration after upgrading to GNOME 46

2024-03-30 Thread Jeremy Bícha
On Sat, Mar 30, 2024 at 2:06 PM Josh Triplett wrote: > After upgrading GNOME to 46, the touchpad seems to have some sort of > acceleration enabled: it feels like it has a painfully large amount of > inertia. > > I've tried > gsettings set org.gnome.desktop.peripherals.touchpad accel-profile flat

Bug#1012325: dialog: Multi-Arch: foreign package should not contain static library

2024-03-30 Thread Sven Joachim
On 2024-03-30 12:38 +0100, Santiago Vila wrote: > El 30/3/24 a las 9:43, Sven Joachim escribió: >> I think it would make sense for Debian to follow what Arch and Fedora >> are doing, introduce a libdialog15 package with the shared library and a >> libdialog-dev package with the .so symlink but

Bug#1068106: bookworm-pu: package libarchive/3.6.2-1+deb12u1

2024-03-30 Thread Peter Pentchev
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: libarch...@packages.debian.org, r...@debian.org Control: affects -1 + src:libarchive User: release.debian@packages.debian.org Usertags: pu [ Reason ] Revert a change made by the same person that smuggled the backdoor

Bug#1068105: drop the Python3-Version attribute

2024-03-30 Thread Matthias Klose
Package: src:libsbml Version: 5.20.2+dfsg-2.1 Severity: important Tags: sid trixie ftbfs patch User: debian-pyt...@lists.debian.org Usertags: python3.12 please drop the Python3-Version attribute. we're not using these anymore, and it prevents the package to be built with 3.12. diff -Nru

Bug#1006146: also useful for other Gnome settings

2024-03-30 Thread Ferenc Wágner
For example in my case gsd-rfkill was necessary for enabling the Bluetooth settings in gnome-control-center. It is also provided by /usr/lib/systemd/user/gnome-session@gnome-flashback-metacity.target.d (for xmonad 0.17.1-1 in Debian bookworm). -- Feri.

Bug#1068096: chromium: --temp-profile has no effect if it appears after --ozone-platform=wayland

2024-03-30 Thread Andres Salomon
Thanks for reporting! This is a bug in our wrapper script (/usr/bin/chromium), not in the upstream binary (/usr/lib/chromium). We have some, uh, not great arg checking in the shell script: while [ $# -gt 0 ]; do case "$1" in --temp-profile ) want_temp_profile=1 shift ;;

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Joey Hess
I have prepared a git repository that is a fork of xz from the point I identified before the attacker(s) did anything to it. In my fork, I have renamed liblzma to liblzmaunscathed. That allows it to be installed alongside current dpkg without breaking dpkg with an old version of liblzma. My git

Bug#1068104: pandas: FTBFS on 32-bit architectures with -D_TIME_BITS=64

2024-03-30 Thread Graham Inggs
Source: pandas Version: 2.1.4+dfsg-6 Severity: serious Tags: ftbfs patch Hi Maintainer pandas FTBFS on 32-bit architectures with -D_TIME_BITS=64 (e.g. armel and armhf), due to tests expected to fail, now passing. I've copied what I hope are the relevant parts of the log below. The following is

Bug#1068103: Cannot disable touchpad acceleration after upgrading to GNOME 46

2024-03-30 Thread Josh Triplett
Package: gnome-settings-daemon Version: 46.0-1 Severity: normal X-Debbugs-Cc: j...@joshtriplett.org After upgrading GNOME to 46, the touchpad seems to have some sort of acceleration enabled: it feels like it has a painfully large amount of inertia. I've tried gsettings set

Bug#1068102: FileNotFoundError in process_manpages()

2024-03-30 Thread Andrey Rakhmatullin
Package: dh-debputy Version: 0.1.23 Severity: normal I've tried to convert the cpuid package to dh-sequence-zz-debputy, when building it I got: dh_debputy debputy: info: Loaded plugin debputy debputy: info: The following directories are considered search dirs (in order): debputy: info: *

Bug#1065221: O: py7zr -- pure Python 7-zip library

2024-03-30 Thread Andreas Metzler
On 2024-03-30 yokota wrote: > I'm interested in py7zr because it is required by Calibre. > New py7zr requires some other modules that not packaged by Debian yet. > I make those modules into Debian packages. > https://salsa.debian.org/yokota/python-multivolumefile >

Bug#1067905: mpg321: Does not work on modern system (pipewire)

2024-03-30 Thread Andreas Metzler
On 2024-03-30 Peter B wrote: > "mpg321 simply produces no sound output here on a system running pipewire." > How strange! > Just wondering; have you got pipewire-alsa installed? Hello Peter, yes, I have got the recommended meta-package (pipewire-audio) installed. cu Andreas -- `What a good

Bug#1068047: Suspicious commit merged in 2021 from account responsible for xz backdoor

2024-03-30 Thread Salvatore Bonaccorso
Control: severity -1 serious Control: found -1 3.6.0-1 Hi Russ, On Fri, Mar 29, 2024 at 07:24:13PM -0700, Russ Allbery wrote: > Package: libarchive13t64 > Version: 3.7.2-1.1 > Severity: important > X-Debbugs-Cc: r...@debian.org > > So far it looks like no one has been able to figure out an

Bug#714549: Bug fixed in 1.30-10

2024-03-30 Thread Alexandru Mihail
Hello Alexander, I've incorporated your suggestions into a patch present in the next version of mini-httpd (1.30-10). This is already committed in VCS, I'm waiting for a FTP upload for now. Thanks a lot for your contribution(s)to Debian ! This is what your test commands produce now with the

Bug#1068024:

2024-03-30 Thread Jeffrey Walton
Lasse Collin provided a statement at .

Bug#1068101: RFS: mini-httpd/1.30-10 -- Small HTTP server

2024-03-30 Thread Alexandru Mihail
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "mini-httpd": * Package name : mini-httpd Version : 1.30-10 Upstream contact : Jef Poskanzer j...@mail.acme.com * URL :

Bug#1053196: Please remove librados-dev build-depends on all 32 bits arch

2024-03-30 Thread Sunil Mohan Adapa
Hi, Looks like a patch with fix for this issue is already in the repository. A release with this fix before April 8th would prevent auto-removal of a uwsgi and a large number of dependencies including freedombox from testing. Thank you for all the contributions, -- Sunil

Bug#1068100: armci-mpi: autopkgtest spuriously fails

2024-03-30 Thread Samuel Thibault
Source: armci-mpi Version: 0.3.1~beta-7 Severity: serious Tags: patch upstream fixed-upstream Forwarded: https://github.com/pmodels/armci-mpi/pull/47 Justification: Prevents mpich migration Hello, The test_mpi_indexed_gets test is currently failing spuriously in debian unstable due to an

Bug#1066964: ITA: newlib -- C library and math library for embedded systems

2024-03-30 Thread Petter Reinholdtsen
[Matthias Klose] > Petter, is there a way to move the VCS on salsa? I suspect so, but not sure how. I doubt I have more privileges than you in this regard, but could give it a try if you want me to. -- Happy hacking Petter Reinholdtsen

Bug#981690: gross: Wrong homepage

2024-03-30 Thread Antti Salmela
The homepage is not wrong. It's the page from the original upstream that matches what is shipped in the Debian. The project and page may have been abandoded, but users of the package are better informed by knowledge of that instead of pointing to some random page in the net. In light of recent

Bug#1067905: mpg321: Does not work on modern system (pipewire)

2024-03-30 Thread Peter B
Hi Andreas, "mpg321 simply produces no sound output here on a system running pipewire." How strange! Just wondering; have you got pipewire-alsa installed? Regards, Peter

Bug#1068099: python-cursive: please remove extraneous python3-six dependencies

2024-03-30 Thread Alexandre Detiste
Source: python-cursive Version: 0.2.3-2 Severity: normal It's gone. tchet@brix /tmp/python-cursive $ grep six -r debian/control: python3-six, debian/control: python3-six, tchet@brix /tmp/python-cursive $ Greetings

Bug#1068098: python-sqlalchemy-utils: please remove extraneous python3-six & python3-mock dependencies

2024-03-30 Thread Alexandre Detiste
Source: python-sqlalchemy-utils Version: 0.41.0-2 Severity: normal Six usage has been removed before. tchet@brix /tmp/python-sqlalchemy-utils $ grep six -r CHANGES.rst:- Remove the dependency on the six package. (#605) debian/control: python3-six, debian/control: python3-six, Package uses a bit

Bug#1068097: Please provide a way to open a shell from aptitude

2024-03-30 Thread Josh Triplett
Package: aptitude Version: 0.8.13-6 Severity: wishlist X-Debbugs-Cc: j...@joshtriplett.org Sometimes, when things go horribly wrong in an upgrade (e.g. in the recent t64 transition if a library disappears and makes dpkg and sudo and su unrunnable), it would help to have a root shell available. In

Bug#1068096: chromium: --temp-profile has no effect if it appears after --ozone-platform=wayland

2024-03-30 Thread Daniel Kahn Gillmor
Package: chromium Version: 122.0.6261.57-1 Severity: normal X-Debbugs-Cc: Daniel Kahn Gillmor I regularly launch chromimum with --temp-profile to have a completely isolated, throwaway browsing session. I am experimenting with switching to wayland. To use chromium with wayland, i need to launch

Bug#1068095: python-botocore: please drop python3-mock from the build-dependencies

2024-03-30 Thread Alexandre Detiste
Source: python-botocore Version: 1.34.46+repack-1 Severity: normal This packages has switched to newer unittest.mock from the standard library. Greetings python-botocore $ grep mock -r | grep import | grep -v 'from tests import' tests/__init__.py:from unittest import mock

Bug#1068085: RM: golang-github-go-git-go-git-fixtures -- RoM; possible vector for security vulnerabilities

2024-03-30 Thread Maytham Alsudany
Control: tags -1 + moreinfo There's ongoing discussion regarding the urgency of go-git-fixtures' removal, and whether such drastic action is necessary. Additionally, it has 2 rdeps in testing that need to be dealt with first. The uploader for the go-git-fixtures package also needs to be

Bug#1035595: gl-117: Crash on exit

2024-03-30 Thread Bernhard Übelacker
> malloc(): unsorted double linked list corrupted > abort Hello, I could not reproduce this in a minimal bullseye or trixie amd64 VM, and also not in a bookworm i386 VM. But valgrind shows a few "Mismatched free() / delete / delete []" or "Conditional jump or move depends on uninitialised

Bug#1068045: [Pkg-openssl-devel] Bug#1068045: libssl3: breaks YAPET

2024-03-30 Thread Sebastian Andrzej Siewior
On 30 March 2024 13:14:37 CET, Sean Whitton wrote: >Hello, Hi, >I downgraded, changed the password for my database to 'asdf', >changed it back to the password it had before, upgraded libssl3, >and the bug did not appear. > >I reverted to my original db, downgraded again, deleted an entry

Bug#1068068: Need rebootstrapping on armel and armhf

2024-03-30 Thread Andrey Rakhmatullin
On Sat, Mar 30, 2024 at 02:14:24PM +0100, Frank B. Brokken wrote: > > there seems to be zero packaging-level support for bootstrapping, the > > packages are not cross-buildable and the upstream bootstrapping instructions > > are too tedious, > > So far no issues were encountered when the

Bug#1068094: RFH: sbcl -- Common Lisp compiler and development system

2024-03-30 Thread Sean Whitton
Package: wnpp Severity: normal X-Debbugs-Cc: s...@packages.debian.org, debian-de...@lists.debian.org, debian-emac...@lists.debian.org Control: affects -1 + src:sbcl I request assistance with maintaining SBCL in Debian. It is the most popular Free Software compiler for Common Lisp. So, most

Bug#1068068: Need rebootstrapping on armel and armhf

2024-03-30 Thread Frank B. Brokken
Dear Andrey Rakhmatullin, you wrote: > > Package: icmake,libbobcat6 > Severity: serious > Tags: ftbfs > > As src:icmake B-D:libbobcat-dev, src:bobcat B-D:icmake, there seems to be zero > packaging-level support for bootstrapping, the packages are not > cross-buildable > and the upstream

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Ivan Shmakov
> On 2024-03-30, Guillem Jover wrote: > On Sat, 2024-03-30 at 00:48:34 +, Stephan Verbücheln wrote: >> Subject: Re: Bug#1068024: Or remove xz altogether? >> Maybe the people who criticized xz back in the day for being an amateur >> project implementing a defective file format were

Bug#1068093: ITP: python-cotengrust -- Fast contraction ordering primitives for tensor networks

2024-03-30 Thread Yogeswaran Umasankar
Package: wnpp Severity: wishlist Owner: Yogeswaran Umasankar X-Debbugs-Cc: debian-de...@lists.debian.org, kd8...@gmail.com * Package name: python-cotengrust Version : 0.1.1 Upstream Contact: Johnnie Gray * URL : https://github.com/jcmgray/cotengrust * License

Bug#1068092: www.debian.org: Website states you could install using a live system which is misleading

2024-03-30 Thread doak
Package: www.debian.org Severity: normal X-Debbugs-Cc: tldr+...@posteo.net Dear Maintainer, the website at [1] states that "The live images contain the end-user-friendly Calamares Installer, a distribution-independent installer framework, as alternative to our well known Debian-Installer.". This

Bug#1065221: O: py7zr -- pure Python 7-zip library

2024-03-30 Thread yokota
Hello, I'm interested in py7zr because it is required by Calibre. New py7zr requires some other modules that not packaged by Debian yet. I make those modules into Debian packages. https://salsa.debian.org/yokota/python-multivolumefile https://salsa.debian.org/yokota/python-bcj

Bug#1068091: dh-make-perl: Build fails with invalid git tag when using manual version and epoch

2024-03-30 Thread Andy Beverley
Package: dh-make-perl Version: 0.122 Severity: normal Dear Maintainer, When specifying a version with an epoch, and when a tag is used with a git repo, the build fails with an invalid tag error. For example: cpan2deb --version=1:1.006 --revision=1 PDF::Table Fails with: fatal:

Bug#1068024: revert to version that does not contain changes by bad actor

2024-03-30 Thread Joey Hess
Aurelien Jarno wrote: > Note that reverted to such an old version will break packages that use > new symbols introduced since then. From a quick look, this is at least: > - dpkg > - erofs-utils > - kmod > > Having dpkg in that list means that such downgrade has to be planned > carefully. I agree

Bug#774068: ExtUtils-MakeMaker and NO_PERLLOCAL

2024-03-30 Thread Andrew Beverley
On 11/06/2022 12:58, Damyan Ivanov wrote: -=| Niko Tyni, 30.12.2014 11:47:23 +0200 |=- (cc'ing the debian-perl list) On Tue, Dec 30, 2014 at 08:38:56AM +, Damyan Ivanov wrote: -=| Andrew Beverley, 29.12.2014 00:16:14 + |=- Is there any harm in having the option in there, especially

Bug#1068090: Update Build-Depends for the time64 library renames

2024-03-30 Thread Andrey Rakhmatullin
Source: tetzle Version: 2.2.3-1 Severity: serious Tags: ftbfs The package explicitly Build-Depends: libqt6*, this needs to be changed to libqt6*t64 if it's needed at all. -- System Information: Debian Release: trixie/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500,

Bug#1068089: FTBFS: error: cannot convert ‘long int*’ to ‘const time_t*’ {aka ‘const long long int*’}

2024-03-30 Thread Andrey Rakhmatullin
Source: ukui-control-center Version: 3.22.1.25-2 Severity: serious Tags: ftbfs https://buildd.debian.org/status/fetch.php?pkg=ukui-control- center=armhf=3.22.1.25-2=1711794461=0 plugins/about/aboutinterface.cpp: In member function ‘char* AboutInterface::ntpdate(char*)’:

Bug#1068045: [Pkg-openssl-devel] Bug#1068045: libssl3: breaks YAPET

2024-03-30 Thread Sean Whitton
Hello, On Sat 30 Mar 2024 at 09:29am +01, Sebastian Andrzej Siewior wrote: > On 2024-03-30 09:25:27 [+0800], Sean Whitton wrote: >> Package: libssl3 >> Version: 3.0.13-1~deb12u1 >> Severity: grave >> Justification: renders package unusable >> X-Debbugs-Cc: t...@security.debian.org >> Control:

Bug#1066964: ITA: newlib -- C library and math library for embedded systems

2024-03-30 Thread Matthias Klose
Control: retitle -1 ITA: newlib -- C library and math library for embedded systems placing this package under the GCC Maintainers umbrella. Both nvptx and amdgcn offload compilers are dependent on this. Petter, is there a way to move the VCS on salsa?

Bug#1068088: apscheduler: please drop python3-mock build dependency

2024-03-30 Thread Alexandre Detiste
Source: apscheduler Version: 3.9.1-2 Severity: normal Dear Maintainer, The python3-mock library is obsolete and slowly removed from Debian. apscheduler has switched to using the newer "unittest.mock" from the Python standard library. Please remove the extraneous python3-mock buil dependency.

Bug#1068056: ccls: FTBFS on armhf,i386 (test_response failures)

2024-03-30 Thread Shengjing Zhu
Control: severity -1 wishlist Control: forcemerge 1068055 -1 On Sat, Mar 30, 2024 at 2:57 PM Kentaro HAYASHI wrote: > > Source: ccls > Severity: serious > Tags: ftbfs > Control: found -1 0.20230717-1 > X-Debbugs-Cc: ken...@xdump.org > > Dear Maintainer, > > ccls fails to build on armhf, i386. >

Bug#1068055: ccls: FTBFS on armel (undefined reference to symbol '__atomic_load_8@@LIBATOMIC_1.0')

2024-03-30 Thread Shengjing Zhu
Control: severity -1 wishlist On Sat, Mar 30, 2024 at 3:00 PM Kentaro HAYASHI wrote: > > Source: ccls > Severity: serious > Tags: ftbfs > Control: found -1 2.6.0-1 > X-Debbugs-Cc: ken...@xdump.org > > Dear Maintainer, > > ccls fails to build on armel. (missing linking against with -latomic)

Bug#1068087: ansible-runner: please remove dependency on python3-six (and fix repos on Salsa ?)

2024-03-30 Thread Alexandre Detiste
Source: ansible-runner Version: 2.3.6-1 Severity: normal Dear Miantainer, I'm having a hard time trying to understand what's happening at https://salsa.debian.org/saki/ansible-runner/-/commits/debian It looks like "gbp" is not used and the 'upstream' changes are never merged into the 'debian'

Bug#1012325: dialog: Multi-Arch: foreign package should not contain static library

2024-03-30 Thread Santiago Vila
El 30/3/24 a las 9:43, Sven Joachim escribió: I think it would make sense for Debian to follow what Arch and Fedora are doing, introduce a libdialog15 package with the shared library and a libdialog-dev package with the .so symlink but without libdialog.a, because that requires (if I understood

Bug#1068086: ansible-runner: please drop dependency on python3-mock

2024-03-30 Thread Alexandre Detiste
Source: ansible-runner Version: 2.3.6-1 Severity: normal Dear Maintainer, python3-mock is an old library that is now merged into the Python standard library as unittest.mock. python3-mock is slowly being removed from Debian. Your project use neither "mock" or "unittest.mock", so please remove

Bug#1068085: RM: golang-github-go-git-go-git-fixtures -- RoM; possible vector for security vulnerabilities

2024-03-30 Thread Maytham Alsudany
Package: ftp.debian.org Severity: normal go-git-fixtures is mainly made up of tgz archives containing bare Git repos, which are decompressed and used in the testing of golang-github-go-git-go-git. In light of the recent xz-utils drama, having binary archives without any easy method of

Bug#1068084: bookworm-pu: package intel-microcode/3.20240312.1~deb12u1

2024-03-30 Thread Henrique de Moraes Holschuh
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu [ Reason ] As requested by the security team, I would like to bring the microcode update level for Intel processors in Bullseye and Bookworm to match what we have in Sid and

Bug#1068083: bullseye-pu: package intel-microcode/3.20240312.1~deb11u1

2024-03-30 Thread Henrique de Moraes Holschuh
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] As requested by the security team, I would like to bring the microcode update level for Intel processors in Bullseye and Bookworm to match what we have in Sid and

Bug#1068082: bullseye-pu: package intel-microcode/3.20240312.1~deb11u1

2024-03-30 Thread Henrique de Moraes Holschuh
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu (duplicate submission, this one is signed. sorry about that!) [ Reason ] As requested by the security team, I would like to bring the microcode update level for Intel processors

Bug#1068081: rust-dns-lookup: "lookup::test_rev_localhost' panicked at 'assertion failed" on loong64

2024-03-30 Thread zhangdandan
Source: rust-dns-lookup Version: 1.0.8-4 Severity: wishlist Tags: ftbfs User: debian-loonga...@lists.debian.org Usertags: loong64 Dear maintainers, Compiling the rust-dns-lookup package failed for loong64 in the Debian Package Auto-Building environment, the error log is as follows: ``` test

Bug#1067771: cdk.h file location has changed, breaks application build

2024-03-30 Thread Thomas Dickey
On Fri, Mar 29, 2024 at 01:30:58PM -0500, Steven Robbins wrote: > On Thursday, March 28, 2024 8:04:30 P.M. CDT Thomas Dickey wrote: > > > I suppose that I _could_ have made a symlink in /usr/include/cdk, > > to address both old/new locations. You might consider that for > > the package... > >

Bug#1068080: Depends on a pre-t64 library name: libvdeplug2

2024-03-30 Thread Andrey Rakhmatullin
Package: libvdeslirp0 Version: 0.1.1-1 Severity: serious libvdeslirp0 explicitly Depends on libvdeplug2, this needs to be changed to libvdeplug2t64. -- System Information: Debian Release: trixie/sid APT prefers unstable-debug APT policy: (500, 'unstable-debug'), (500, 'testing-debug'),

Bug#1068079: crash: FTBFS on loong64

2024-03-30 Thread zhangdandan
Source: crash Version: 8.0.4-1 Severity: wishlist Tags: ftbfs User: debian-loonga...@lists.debian.org Usertags: loong64 Dear maintainers, Compiling the crash package failed for loong64 in the Debian Package Auto-Building environment. The full build log can be found at

Bug#1068078: FTBFS on armel: shiboken2:smart::smart_pointer Newly detected Real test failure!

2024-03-30 Thread Andrey Rakhmatullin
Source: pyside2 Version: 5.15.12-6.1 Severity: serious Tags: ftbfs https://buildd.debian.org/status/fetch.php?pkg=pyside2=armel=5.15.12-6.1=1711789575=0 RUN 2: Test project /<>/pyside3_build/py3.11-qt5.15.10-32bit- relwithdebinfo/shiboken2 RUN 2: Start 181: smart_smart_pointer RUN 2: 1/1

Bug#1068077: python3-adal: adal/authentication_parameters.py:92: SyntaxWarning: invalid escape sequence '\s'

2024-03-30 Thread Paul Wise
Package: python3-adal Version: 1.2.7-3 Severity: normal usertags warnings  User: debian-pyt...@lists.debian.org Usertags: python3.12 I got some warnings when upgrading, probably caused by Python 3.12: Preparing to unpack .../python3-adal_1.2.7-3_all.deb ... Unpacking python3-adal (1.2.7-3)

  1   2   >