Bug#1051226: python-django: CVE-2023-41164

2023-09-04 Thread Chris Lamb
ttps://security-tracker.debian.org/tracker/CVE-2023-41164 https://www.cve.org/CVERecord?id=CVE-2023-41164 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1050944: jtreg6: please make the build reproducible

2023-09-01 Thread Chris Lamb
ian/ -type f -name jtreg.jar -print0 | xargs -0tr chmod u-w As you like… Although the `execute_after` portion feels a little redundant to me. After all, it doesn't seem right that the build system is generating read-only build artefacts to begin with. But it's your package. :) Regards, --

Bug#1050973: lastpass-cli: Please update to 1.3.5 upstream to fix certificate error

2023-08-31 Thread Chris Lamb
tags 1050973 + pending thanks Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1050955: rpy2: please make the build reproducible

2023-08-31 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/debian/rules b/debian/rules index dee8be3..980d8a2 100755 --- a/debian/rules +++ b/debian/rules @@ -24,6 +24,9 @@ tarball: # Commented-out again 2023-05-24 # override_dh_auto_test

Bug#1050944: jtreg6: please make the build reproducible

2023-08-31 Thread Chris Lamb
file: jtreg.jar". A patch for both issues is attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1969-12-31 16:00:00.0 -

Bug#1050727: zlib: please make the build reproducible

2023-08-28 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-08-28 08:32:58.504515505 -0700 --- b/debian/rules 2023-08-28 08:44:42.749725457 -0700 @@ -131,6 +131,7 @@ $(MAKE) $(MAKE) -C contrib/minizip

Bug#1050726: pdsh: fix malformed changelog (and make the build reproducible)

2023-08-28 Thread Chris Lamb
by a malformed debian/changelog entry which means that a value for SOURCE_DATE_EPOCH cannot be extracted. A patch is attached that sources this data from the upload. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#1050357: pytds: please make the build reproducible

2023-08-23 Thread Chris Lamb
is attached that cleans up after running the tests. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-08-23 09:19:18.509726887 -0700 --- b/debian/rules 2023-08-23 09

Bug#1043330: tox: please make the build reproducible

2023-08-11 Thread Chris Lamb
vial typo fix was merged as well: https://github.com/tox-dev/tox/pull/3082#event-10051104273 Looking forward to seeing all this in the archive. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1043330: tox: please make the build reproducible

2023-08-09 Thread Chris Lamb
Chris Lamb wrote: > […] (NB. this is distinct from the "notset" value, which, incidentally, > is typod in the --help text.) I've filed *this* trivial bit upstream at: https://github.com/tox-dev/tox/pull/3082 -- ,''`. : :' : Chris Lamb `. `'`

Bug#1043330: tox: please make the build reproducible

2023-08-09 Thread Chris Lamb
nct from the "notset" value, which, incidentally, is typod in the --help text.) [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1970-0

Bug#1042948: O: mtools -- Tools for manipulating MSDOS files

2023-08-04 Thread Chris Lamb
Diederik de Haas wrote: > Would it be useful to move it out of your personal namespace to f.e. 'debian'? Sure thing… Done: https://salsa.debian.org/debian/pkg-mtools Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1042955: zzzeeksphinx: please make the output reproducible

2023-08-03 Thread Chris Lamb
"%c")} ^^ This was affecting the reproduciblity of (at least) the mako in Debian. A patch is attached that makes this use SOURCE_DATE_EPOCH instead. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' :

Bug#1042954: libcerf: please make the build reproducible

2023-08-03 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/CMakeLists.txt2023-08-03 09:45:26.863220289 +0100 --- b/CMakeLists.txt2023-08-03 09:56:16.0 +0100 @@ -74,7 +74,7 @@ add_compile_options(-Wno-sign-compare -fno-omit-frame-pointer

Bug#1042948: O: mtools -- Tools for manipulating MSDOS files

2023-08-03 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org `-

Bug#1042404: redis-server postinst script gets stuck when disk is low

2023-07-28 Thread Chris Lamb
ream developers to address. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1042404: redis-server postinst script gets stuck when disk is low

2023-07-28 Thread Chris Lamb
t to restart?) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1041842: guidata: please make the build reproducible

2023-07-24 Thread Chris Lamb
forwarded 1041842 https://github.com/Codra-Ingenierie-Informatique/guidata/pull/61 thanks I've forwarded this upstream here: https://github.com/Codra-Ingenierie-Informatique/guidata/pull/61 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris

Bug#1041840: ruby-babosa: please make the build reproducible

2023-07-24 Thread Chris Lamb
forwarded 1041840 https://github.com/norman/babosa/pull/74 thanks I've forwarded this upstream here: https://github.com/norman/babosa/pull/74 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1041842: guidata: please make the build reproducible

2023-07-24 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/0002-Cleanup-after-tests.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/0002-Cleanup-after-tests.patch 2023-07-24 09:14:08.232984650 +0100 @@ -0,0 +1,24

Bug#1041840: ruby-babosa: please make the build reproducible

2023-07-24 Thread Chris Lamb
attribute. A patch is attached that moves the assignment of cert_chain to match the conditional of signing_key, thereby excluding it from the binary package and thus making the package reproducible. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' :

Bug#1040941: android-platform-tools: libandroidfw.so.0: undefined symbol: _Z18ExtractEntryToFileP10ZipArchiveP8ZipEntryi

2023-07-12 Thread Chris Lamb
/resources1.arsc aapt2: symbol lookup error: /usr/lib/x86_64-linux-gnu/android/libandroidfw.so.0: undefined symbol: _Z18ExtractEntryToFileP10ZipArchiveP8ZipEntryi This is currently affecting diffoscope (see #1040916). Regards, -- ,''`. : :' : Chris Lamb `. `'` la

Bug#1024902: android-platform-tools: missing version prefix in shlibs dependencies

2023-07-12 Thread Chris Lamb
ifferent bug. (I suspect it might be, as I've upgraded all packages in this chroot, so it's unlikely to be a 'missing' upgrade due to incomplete dependencies.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1040916: diffoscope: FTBFS with new android-platform-tools (33.0.3-1)

2023-07-12 Thread Chris Lamb
2 I'll followup to the second bug presently. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1040904: unity-java: please make the build reproducible

2023-07-12 Thread Chris Lamb
if it is available. Patch attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/Reproducible-build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/Reproducible

Bug#1040232: dotenv-cli: please make the build reproducible

2023-07-03 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/rules 2023-07-03 18:36:04.013796172 +0100 --- b/debian/rules 2023-07-03 18:46:43.430088575 +0100 @@ -9,6 +9,9 @@ %: dh $@ --with python3,bash-completion --buildsystem

Bug#1040225: python-django: CVE-2023-36053

2023-07-03 Thread Chris Lamb
ntry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2023-36053 https://www.cve.org/CVERecord?id=CVE-2023-36053 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1039932: python-bitstring: please make the build reproducible

2023-06-29 Thread Chris Lamb
forwarded 1039932 https://github.com/scott-griffiths/bitstring/pull/269 thanks I've forwarded this upstream here: https://github.com/scott-griffiths/bitstring/pull/269 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1039932: python-bitstring: please make the build reproducible

2023-06-29 Thread Chris Lamb
lue on SOURCE_DATE_EPOCH if available. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/0002-reproducible-build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/0

Bug#1038957: jtreg7: please make the build reproducible

2023-06-23 Thread Chris Lamb
that it is ignored by strip-nondeterminism and thus the timestamps are not normalised. A patch is attached that addresses both issues. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian

Bug#1038730: fribidi: please make the build reproducible

2023-06-20 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-06-20 17:52:39.441913687 +0100 --- b/debian/rules 2023-06-20 17:57:00.402466109 +0100 @@ -15,7 +15,7 @@ dh $@ override_dh_auto_configure

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Chris Lamb
No, please go ahead and do both: my availability is spotty for the next 18 hours. :) (on mobile) Utkarsh Gupta wrote: > Hi Chris, > > On Wed, Jun 7, 2023 at 9:01 PM Chris Lamb wrote: >> I see your 2.5.5-3+deb10u6 update on the debian/buster branch which >> fixes the b

Bug#1037216: mkdocstrings-python-handlers: please make the build reproducible

2023-06-07 Thread Chris Lamb
nd "writable", which the labels.html template (in this package) then naïvely iterates over. A patch is attached that simply sorts these when rendering using Jinja's "|sort" filter. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb

Bug#1037205: multipath-tools: please make the build reproducible

2023-06-07 Thread Chris Lamb
endency resolution to recreate it again. A patch to this end is attached, which also removes the --max-parallel calls. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/rules 2023-

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-07 Thread Chris Lamb
gh you mentioned you were going to wait a bit more, I'm just 100%-checking you aren't waiting on anything from me to upload that? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1037159: elinks: please make the build reproducible

2023-06-06 Thread Chris Lamb
│ A patch is attached that exports FORCE_SOURCE_DATE in debian/rules, a LaTeX-specific variable to ensure that LaTeX tools respect the SOURCE_DATE_EPOCH environment variable. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#1037075: diffoscope: Get's killed trying to diff 2 large images (> 5GB)

2023-06-05 Thread Chris Lamb
forwarded 1037075 https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/342 thanks I've forwarded this "upstream" here: https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/342 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@

Bug#1036221: mfem: please make the build reproducible

2023-05-17 Thread Chris Lamb
-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-05-17 08:25:54.810285060 -0700 --- b/debian/rules 2023-05-17 09:06:24.996983917 -0700 @@ -59,6 +59,7 @@ sed -i "s,/.

Bug#1036220: refnx: please make the build reproducible

2023-05-17 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/rules 2023-05-17 08:25:37.906258599 -0700 --- b/debian/rules 2023-05-17 08:30:04.930630993 -0700 @@ -3,6 +3,7 @@ # This file was automatically generated by stdeb 0.10.0 at # Fri, 14 Apr 2023 16:57:18

Bug#1035520: unblock: python-django/3:3.2.19-1

2023-05-04 Thread Chris Lamb
Closes: #1035467) . * Bump Standards-Version to 4.6.2. The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- debdiff Description: Binary data

Bug#1035467: python-django: CVE-2023-31047

2023-05-03 Thread Chris Lamb
multiple files. — <https://www.djangoproject.com/weblog/2023/may/03/security-releases/> Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1035375: mtools: interprets SOURCE_DATE_EPOCH in system timezone instead of UTC

2023-05-02 Thread Chris Lamb
d and forwarded this to the mtools mailing list here: https://lists.gnu.org/archive/html/info-mtools/2023-05/msg0.html Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1035328: unblock: redis/5:7.0.11-1

2023-04-30 Thread Chris Lamb
the Redis server on access. (Closes: #1034613) For more information, please see: https://raw.githubusercontent.com/redis/redis/7.0/00-RELEASENOTES * Refresh patches. § The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `

Bug#1034504: diffoscope: Wrong binary called for the Procyon Java decompiler

2023-04-17 Thread Chris Lamb
forwarded 1034504 https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/338 thanks I've forwarded this 'upstream' here: https://salsa.debian.org/reproducible-builds/diffoscope/-/issues/338 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#1034147: ruby-regexp-parser: please make the build reproducible

2023-04-10 Thread Chris Lamb
lude the -L argument that suppresses these additions. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/

Bug#1034128: memcached breaks cachelib autopkgtest: TimeoutError

2023-04-10 Thread Chris Lamb
: https://cachelib.readthedocs.io/en/stable/changes/ * A similar-looking report on cachelib's Issue Page: https://github.com/pallets-eco/cachelib/issues/39 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1034034: Does not know about Linux kernel module signatures

2023-04-07 Thread Chris Lamb
. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1030600: redis breaks python-fakeredis autopkgtest: Connection refused

2023-03-20 Thread Chris Lamb
st wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1032759: gle-graphics-manual: please make the build reproducible

2023-03-11 Thread Chris Lamb
-manual could not be built reproducibly. Patch attached that exports FORCE_SOURCE_DATE to ensure TeX actually uses the SOURCE_DATE_EPOCH environment variable. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris

Bug#1032409: esda: please make the build reproducible

2023-03-06 Thread Chris Lamb
://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/patches/003.reproducible.build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/003.reproducible.build.patch 2023

Bug#1032058: certmonger: Does not respect 'nocheck' in DEB_BUILD_OPTIONS

2023-02-27 Thread Chris Lamb
attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diff --git a/debian/rules b/debian/rules index ea79d27..e16941b 100755 --- a/debian/rules +++ b/debian/rules @@ -28,7 +28,9 @@ override_dh_auto_install: certutil -N -d debian/tmp/etc/cert

Bug#1032057: pyproject-api: please make the build reproducible

2023-02-26 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1970-01-01 01:00:00.0 +0100 --- b/debian/patches/reproducible-build.patch 2023-02-27 07:50:58.360366831 + @@ -0,0 +1,26

Bug#1031829: gawk: please make the build reproducible

2023-02-23 Thread Chris Lamb
reproducibly. This is because the gawkbug script contained the contents of the CFLAGS environment variable, and this can contain the full build path via/by embedding -ffile-prefix-map. Patch attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb

Bug#1031412: pysdl2: please make the build reproducible

2023-02-16 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/0003-reproducible-build.patch 1969-12-31 16:00:00.0 -0800 --- b/debian/patches/0003-reproducible-build.patch 2023-02-16 12:38:14.656545296 -0800 @@ -0,0 +1,28 @@ +Description

Bug#1031290: python-django: CVE-2023-24580 (denial-of-service vulnerability in file uploads)

2023-02-14 Thread Chris Lamb
2023-24580 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1031030: ruby-pgplot: please make the build reproducible

2023-02-10 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible-build.patch 1969-12-31 16:00:00.0 -0800 --- b/debian/patches/reproducible-build.patch 2023-02-10 08:00:17.285056814 -0800 @@ -0,0 +1,15 @@ +Description: Make the build

Bug#970278: smartlist: please make the build reproducible

2023-02-07 Thread Chris Lamb
don't think it's related to the rationale I gave above. I therefore think keeping this "- patch" and "+ moreinfo" is correct. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1030785: Reproducibility of ocaml...

2023-02-07 Thread Chris Lamb
or…? Best wishes, -- o ⬋ ⬊ Chris Lamb o o reproducible-builds.org  ⬊ ⬋ o

Bug#1030727: multipath-tools: please make the build reproducible

2023-02-06 Thread Chris Lamb
to locate a deep fix, but a patch is attached that forces the build to be single-threaded via the addition of the --parallel=1 switch. I found that both the build and udeb build variants need to have this option. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' :

Bug#1030724: node-marked-man: please make the build reproducible

2023-02-06 Thread Chris Lamb
forwarded 1030724 https://github.com/kapouer/marked-man/pull/32 thanks I've forwarded this upstream here: https://github.com/kapouer/marked-man/pull/32 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1030724: node-marked-man: please make the build reproducible

2023-02-06 Thread Chris Lamb
name gulp --date="$(dpkg-parsechangelog --show-field=Date)" docs/CLI.md | head -n1 .TH "GULP" "1" "November 2022" "4.0.2" $ TZ="/usr/share/zoneinfo/Etc/GMT+11" marked-man --name gulp --date="$(dpkg-parsechangelog --show-fi

Bug#1030600: redis breaks python-fakeredis autopkgtest: Connection refused

2023-02-06 Thread Chris Lamb
are more interconnected that one might initially believe. * Here are the release notes for Redis, showing the difference between 7.0.7 in testing and 7.0.8 in unstable: https://raw.githubusercontent.com/redis/redis/7.0/00-RELEASENOTES Regards, -- ,''`. : :' : Chris Lamb `. `'

Bug#1030715: adacgi: please make the build reproducible

2023-02-06 Thread Chris Lamb
s file just prior to installation, but the better solution may actually belong somewhere else in Debian's Ada toolchain. Unfortunately, I lack the knowledge to know precisely where, but hopefully this helps demonstrate the problem and a route to a solution. [0] https://reproducible-builds.org/ Regards,

Bug#1030714: cwltool: please make the build reproducible

2023-02-06 Thread Chris Lamb
). This, therefore, is a more generic solution to #1030713. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-02-06 08:37:40.811072429 -0800 --- b/debian/rules 2023

Bug#1030713: cwltool: Installs the text of 'Moby-Dick' under /usr/lib/python3/dist-packages

2023-02-06 Thread Chris Lamb
epic tale of the monomaniacal quest of Ahab on the whaling ship Pequod is in the public domain (and thus Debian's distribution of it does not constitute a copyright violation), I suspect its inclusion in the binary package is a bug. Patch attached. Regards, -- ,''`. : :' : Chris

Bug#1030708: gap-browse: please make the build reproducible

2023-02-06 Thread Chris Lamb
to get the variable, which also means that we can drop the manual call to parse/generate SOURCE_DATE_EPOCH. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-02

Bug#1030251: python-django: CVE-2023-23969 Potential denial-of-service via Accept-Language headers

2023-02-01 Thread Chris Lamb
tps://security-tracker.debian.org/tracker/CVE-2023-23969 https://www.cve.org/CVERecord?id=CVE-2023-23969 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1029297: python-graphviz: please make the build reproducible

2023-01-20 Thread Chris Lamb
] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-01-20 11:05:01.682844889 -0800 --- b/debian/rules 2023-01-20 11:15:48.332534092 -0800 @@ -16,3 +16,4 @@ rm

Bug#1029295: python-miio: Compatibility with python3-click > 8.0 (& make the build reproducible)

2023-01-20 Thread Chris Lamb
ack": https://click.palletsprojects.com/en/8.1.x/api/#click.MultiCommand.result_callback Patch attached that simply renames these methods. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Bug#1029066: diffoscope: FTBFS if no internet is available (using internet connection during build)

2023-01-19 Thread Chris Lamb
Hi all, > […] As Mattia writes on the Salsa bug [0], I now don't think this is a network issue. In other words, the package FTBFS regardless of whether you have network access or not. To make debugging this easier, I've split out the inline Python code in c341b63a [1], and simply running the

Bug#1028515: accel-config: please make the build reproducible

2023-01-12 Thread Chris Lamb
Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk ` a/debian/rules 2023-01-12 07:54:17.129640378 + --- b/debian/rules 2023-01-12 07:58:20.452930026 + @@ -5,6 +5,9 @@ export DEB_CFLAGS_MAINT_APPEND = -Wall -pedant

Bug#1001853: nanomsg: reproducible-builds: BuildId differences triggered by RPATH

2023-01-10 Thread Chris Lamb
in RPATH. (Closes: #1001853) This was because the previous upload did not include the actual/required change to debian/rules. The full debdiff, which reflects this, is attached. Thanks, Vagrant! Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk

Bug#1001853: nanomsg: reproducible-builds: BuildId differences triggered by RPATH

2023-01-10 Thread Chris Lamb
Vagrant Cascadian wrote: > This seems to be missing some diff other than the debian/changelog... > does the upload contain the patch? Great spot; I will fix this right away. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1010845: logapp: please make the build reproducible

2023-01-10 Thread Chris Lamb
m ordering, therefore affecting reproducibility. Sort them using sort(1) instead. (Closes: #1010845) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for logapp-0.16 logapp-0.16 change

Bug#1001853: nanomsg: reproducible-builds: BuildId differences triggered by RPATH

2023-01-10 Thread Chris Lamb
in RPATH. (Closes: #1001853) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for nanomsg-1.1.5+dfsg nanomsg-1.1.5+dfsg changelog |8 1 file changed, 8 insertions(+) diff -Nru

Bug#1020662: log4cpp: reproducible-builds: Embedded build path in log4cpp-config

2023-01-10 Thread Chris Lamb
) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for log4cpp-1.1.3 log4cpp-1.1.3 changelog |8 rules |5 + 2 files changed, 13 insertions(+) diff -Nru log4cpp

Bug#963600: critcl: please make the teapot.txt files reproducible

2023-01-10 Thread Chris Lamb
ile not using CFLAGS (etc.), but exporting them from debian/rules does not seem to make a difference (and the build.tcl script is somewhat opaque). Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#1028310: hamster-time-tracker: please make the build reproducible

2023-01-09 Thread Chris Lamb
a generic build system), so the attached proof-of-concept patch simply removes the line from defs.py.in. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/Reproducible

Bug#1028051: unifrac-tools: please make the build reproducible

2023-01-06 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-01-06 10:46:40.635033129 + --- b/debian/rules 2023-01-06 10:55:34.858553266 + @@ -4,7 +4,8 @@ export DEB_BUILD_MAINT_OPTIONS=hardening=+all export PYBUILD_NAME=unifrac

Bug#1027992: towncrier: Remove temporary files created during build

2023-01-06 Thread Chris Lamb
Hi Ben, > +twisted_trial_cruft = ${MAIN_PYTHON_PACKAGE}.test.* > +export PYBUILD_AFTER_TEST = rm -r "{build_dir}"/${twisted_trial_cruft} Ah, that's much cleaner. Thank you. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1027992: towncrier: please make the build reproducible

2023-01-05 Thread Chris Lamb
, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2023-01-05 17:19:29.738137407 + --- b/debian/rules 2023-01-05 17:26:37.048270769 + @@ -39,3 +39,6 @@ # mode: makefile # End: # vim: fileencoding=utf-8 filetype=make

Bug#1027988: click: please make the build reproducible

2023-01-05 Thread Chris Lamb
installed to. At the very least, the build directory perforce does not exist anymore at package installation time, so this is "no worse", so to speak. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-

Bug#1026982: [PATCH] disambiguate "package" output message

2023-01-01 Thread Chris Lamb
tags 1026982 + pending thanks Fixed in Git, although I made it helpful on other distros as well: https://salsa.debian.org/reproducible-builds/diffoscope/commit/85bf76f0deb398a89512a4675cfc3be8d4511902 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#1026976: Upcoming test suite regression due to changes in file/libmagic

2022-12-28 Thread Chris Lamb
l remain… as would the desire to discriminate between pyzip files and other ZIP files with prepended data. Could another — different — string be emitted in the case that these prepended bytes are a shebang? We could potentially look for the file starting with #! and for that to take precedence

Bug#1026877: opari2: please make the build reproducible

2022-12-23 Thread Chris Lamb
o I'm likely not the best person to ask. Could you quickly try the reproducible-bui...@lists.alioth.debian.org mailing list? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1026877: opari2: please make the build reproducible

2022-12-22 Thread Chris Lamb
reproducibly. Patch attached that exports CFLAGS from dpkg-buildflags(1), ensuring that -fdebug-prefix-map (and similar) to the underlying build system. Patch attached. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris

Bug#1026876: jamin: please make the build reproducible

2022-12-22 Thread Chris Lamb
could not be built reproducibly. Patch attached that exports CFLAGS from dpkg-buildflags(1), ensuring that -fdebug-prefix-map (and similar) to the underlying build system. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#1026520: reprotest: FTBFS: AttributeError: module 're' has no attribute 'sre_parse'

2022-12-21 Thread Chris Lamb
reassign 1026520 python-rstr merge 1026569 1026520 affects 1026520 diffoscope thanks Lucas Nussbaum wrote: > During a rebuild of all packages in sid, your package failed to build > on amd64. Quite so. However, I think the problem is elsewhere: >> File

Bug#1025801: sphinx: please make the build reproducible

2022-12-19 Thread Chris Lamb
forwarded 1025801 https://github.com/sphinx-doc/sphinx/pull/11037 thanks Dmitry Shachnev wrote: > Can you please forward your patch upstream to [1]? > > [1]: https://github.com/sphinx-doc/sphinx/pulls Done. Regards, -- ,''`. : :' : Chris Lamb `. `'

Bug#1026381: python-django-health-check: please make the build reproducible

2022-12-19 Thread Chris Lamb
*/dist-packages/.coverage [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2022-12-19 09:59:12.419691292 + --- b/debian/rules 2022-12-19 10:00:06.647874759

Bug#1025801: sphinx: please make the build reproducible

2022-12-09 Thread Chris Lamb
None: arg1=defaultval" pattern to avoid this. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/patches/reproducible_build.diff1970-01-01 01:00:00.0 +0100 --

Bug#1020651: xmlrpc-epi: reproducible-builds: Embedded build path in libxmlrpc-epi.so.*

2022-12-08 Thread Chris Lamb
-architecture situation. (Closes: #865688) * Move to dpkg-buildflags(1) in order to make the build reproducible. (Closes: #1020651) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat

Bug#1020809: aespipe: reproducible-builds: build path embedded in /usr/bin/aespipe

2022-12-08 Thread Chris Lamb
. (Closes: #661079) - Make the build reproducible by setting -fdebug-prefix-map. (Closes: #1020809) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for aespipe-2.4d aespipe-2.4d

Bug#1025415: cctools: please make the build reproducible

2022-12-04 Thread Chris Lamb
_configure, this is overridden later in override_dh_auto_install when the Python components are built. A patch is attached that also the prefix to same value (ie. /usr). [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.o

Bug#941296: tuxcmd-modules FTCBFS: uses build architecture build tools

2022-11-29 Thread Chris Lamb
Vagrant Cascadian wrote: > Hrm. Seems like the original version without the cross-building patches are > what > actually landed in sid today... Bah, okay. Re-uploading without DELAYED now. Thanks. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@d

Bug#1011500: tuxcmd-modules: reproducible-builds: embedded build paths in various binaries

2022-11-22 Thread Chris Lamb
working out what has happened here, I'll re-upload now without any DELAYED value. Thanks. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#1024352: pykafka: please make the build reproducible

2022-11-18 Thread Chris Lamb
-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- --- a/debian/rules 2022-11-18 07:54:00.259645896 + --- b/debian/rules 2022-11-18 08:00:24.842832228 + @@ -5,7 +5,7 @@ export PYBUILD_NAME=pykafka

Bug#941296: tuxcmd-modules: reproducible-builds: embedded build paths in various binaries

2022-11-17 Thread Chris Lamb
is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for tuxcmd-modules-0.6.70+ds tuxcmd-modules-0.6.70+ds changelog| 10 +++ patches/crossbuild.patch | 130

Bug#1020805: png23d: reproducible-builds: Embedded build paths in binaries

2022-11-17 Thread Chris Lamb
. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for png23d-1.10 png23d-1.10 changelog|8 patches/reproducible_build.patch | 11 +++ patches/series |1

Bug#1020751: waili: reproducible-builds: Embedded build paths in binaries

2022-11-17 Thread Chris Lamb
is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for waili-19990723 waili-19990723 changelog|8 patches/reproducible_build.patch | 11 +++ patches/series

<    1   2   3   4   5   6   7   8   9   10   >