Bug#540303: lots of files left in /emul/ after removing ia32-libs

2009-08-06 Thread Christoph Anton Mitterer
Subject: ia32-libs: fdg Package: ia32-libs Severity: normal Hi. Although I've purge ia32-libs I still have lots of stuff in /emul/: /emul/ /emul/ia32-linux /emul/ia32-linux/usr /emul/ia32-linux/usr/lib /emul/ia32-linux/usr/lib/libBrokenLocale.so /emul/ia32-linux/usr/lib/libm.so

Bug#515599: fail2ban inconveniences when using own iptables rules

2009-08-07 Thread Christoph Anton Mitterer
Hi Yaroslav. Sorry for my late reply. On Thu, 2009-07-09 at 00:12 -0400, Yaroslav Halchenko wrote: Should we still discuss the issue of the order of fail2ban vs iptables/firewall startup, and possible fail2ban-aware setup of firewall. imho the problem is clearly not of important severity,

Bug#512079: package structure and signature updates

2009-08-07 Thread Christoph Anton Mitterer
Hi Javier. Sorry for the late reply. On Fri, 2009-06-12 at 14:04 +0200, Javier Fernández-Sanguino Peña wrote: On Sun, Feb 01, 2009 at 03:46:17AM +0100, Christoph Anton Mitterer wrote: Another thing is that many files are not listed as being part of the package, e.g. /etc/tiger/tigerrc

Bug#540363: minor issues and improvements

2009-08-07 Thread Christoph Anton Mitterer
Package: kernel-package Version: 12.017 Severity: minor Hi Manoj. Perhaps some points that could be improved: 1) The *_hook options in the kernel-img manpage: Should be documented, that they (for those where this applies) are executed in addition and after the scripts from /etc/kernel/*

Bug#540375: delete_build_link is perhaps ignored

2009-08-07 Thread Christoph Anton Mitterer
Package: kernel-package Version: 12.017 Severity: minor Hi Manoj. As far as I understand kernel-pkg.conf(5) setting delete_build_link := yes would mean that there's no ./lib/modules/2.6.30-heisenberg/build - something in the resulting image-deb-file, right? It is however ;) Any idea?

Bug#473061: netbase: using ucf to manage /etc/services

2009-08-07 Thread Christoph Anton Mitterer
I've just thought that this would be solved if #46049 was solved, but that's not true, as people might also want to remove entries from the default debian /etc/services,.. and this would still be reverted by upgrades Isn't it possible to simply recommend or suggest ucf, and use it if

Bug#46049: local services

2009-08-07 Thread Christoph Anton Mitterer
Hi. Is this considered as a wontfix-bug in the meantime? I'd be very interested in a solution,... even the services.d/ sounds not so unreasonable to me. It would allow packages to ship their own files which would give us even some sort of stupid conflict resolution if more packages use the

Bug#540417: adding dcap and gsidcap ports to /etc/services

2009-08-07 Thread Christoph Anton Mitterer
Access Protocol # Christoph Anton Mitterer calestyoscientia.net 10 March 2009 gsidcap 22128/tcp GSI dCache Access Protocol # Christoph Anton Mitterer calestyoscientia.net 10 March 2009 which are heavily used within a big fraction

Bug#531315: aptitude seems to use hidden processes, rendering HIDS systems like unhide nearly useless

2009-08-07 Thread Christoph Anton Mitterer
On Mon, 2009-07-20 at 08:41 -0700, Daniel Burrows wrote: Sorry about taking so long to get back to you. No problem ;) I don't know what a hidden process would be, and aptitude certainly doesn't hide any processes that it runs. Yeah,.. of course not I didn't suspect you to have some

Bug#540422: scan fails if lines in the initial tuning data file start with

2009-08-07 Thread Christoph Anton Mitterer
Package: me-tv Version: 0.7.16-1 Severity: normal Hi. When using an initial tuning data file that contains lines starting with withespace (e.g. as in /usr/share/dvb/dvb-t/de-Bayern) me-tv gives an error during the scan and aborts. Best wishes, Chris. -- System Information: Debian Release:

Bug#46049: local services

2009-08-07 Thread Christoph Anton Mitterer
On Fri, 2009-08-07 at 21:39 +0200, Marco d'Itri wrote: I also think that a services.d/ solution wouldn't be that overkill,.. It will never happen, ever. Then,... can we set wontfix? Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#459508: insserv: alternatives for syslog

2009-08-07 Thread Christoph Anton Mitterer
Hi. Hasn't this been resolved? rsyslog provides rsyslog and there's an alternative added to /etc/insserv.conf (though I'm not sure whether this would fit better to as separate file in the insserv.d dir). Can it be closed? Cheers, Chris.

Bug#463574: insserv: Document why obsolete init.d scripts will block dependency based boot sequencing

2009-08-07 Thread Christoph Anton Mitterer
Hi. Can't this one be closed? As far as I can see, the sudo bug was also fixed. Cheers, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to

Bug#536845: missing defaults / overrides for sysfsutils, hdparm, libdevmapper1.02

2009-08-07 Thread Christoph Anton Mitterer
The problem was likely why this happened, whether it harms, what it means and how one can get rid of it... ;) I've seen the same for some nvidia initscripts... and as far as I can tell a warning is only produced when the currently set stop runlevels differ from the ones configured in the

Bug#540447: README.Debian uses deprecated keyword as example

2009-08-07 Thread Christoph Anton Mitterer
Package: insserv Version: 1.12.0-10 Severity: minor Hi Petter. It seems that README.Debian suggests: # Enable parallel booting echo CONCURRENCY=shell /etc/default/rcS But a least /etc/init.d/rc says: ase $CONCURRENCY in startpar|shell) # shell is obsolete So perhaps one should

Bug#495925: wrong file names in man rcS

2009-08-07 Thread Christoph Anton Mitterer
Hi. It seems as if this has been fixed can the bug be closed? Cheers, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a

Bug#540448: document CONCURRENCY in the rcS(5) manpage and add it to /etc/default/rcS

2009-08-07 Thread Christoph Anton Mitterer
Package: initscripts Version: 2.87dsf-2 Severity: wishlist Hi. It seems that at least /etc/init.d/rc uses the CONCURRENCY which can be set in /etc/default/rcS . I'd suggest to add a line with the default value (which is none as far as I can tell from /etc/init.d/rc) and perhaps short

Bug#540303: [Pkg-ia32-libs-maintainers] Bug#540303: lots of files left in /emul/ after removing ia32-libs

2009-08-07 Thread Christoph Anton Mitterer
Hi Goswin. On Sat, 2009-08-08 at 03:08 +0200, Goswin von Brederlow wrote: And have you asked dpkg to what package they belong (by path without /emul/ia32-linux)? I see stuff from libc6-i386, fakeroot, lib32gcc1, ... in there. I will try this tomorrow (are you still awake? already awake? or

Bug#540422: scan fails if lines in the initial tuning data file start with

2009-08-08 Thread Christoph Anton Mitterer
Hi Michael. On Sat, 2009-08-08 at 15:47 +1000, Michael Lamothe wrote: This issue has been fixed in a more recent version of Me TV. Me TV 1.0.0 is due to be released on the 10 August and a debian package will be uploaded to mentors shortly after. Hopefully it will attract a sponsor then. In

Bug#463574: insserv: Document why obsolete init.d scripts will block dependency based boot sequencing

2009-08-08 Thread Christoph Anton Mitterer
Hi Martin-Éric. On Sat, 2009-08-08 at 05:38 +0300, Martin-Éric Racine wrote: It only makes sens to close it if it has finally been documented in the package's README. Perhaps you could provide a short text/patch what you would expect to be documented? Then the maintainer could decided whether

Bug#540303: [Pkg-ia32-libs-maintainers] Bug#540303: lots of files left in /emul/ after removing ia32-libs

2009-08-08 Thread Christoph Anton Mitterer
On Sat, 2009-08-08 at 09:50 +0200, Goswin von Brederlow wrote: I made a short test with dpkg -S /emul/ia32-libs/usr/lib/libutil.a There's a file with this name in libc6-dev and libc6-dev-i386,.. but both not below /emul Not if you had a /usr/lib32 - /emul/ia32-libs/usr/lib link when

Bug#536592: fstype doen't detect ext4 without journal

2009-08-08 Thread Christoph Anton Mitterer
Hi. I have the same problem, just that it reports ext3 instead of ext2. I'm using the version from sid. This bug is also the reason for at least parts of #540296. Best wishes, Chris. This message was sent using IMP, the

Bug#540296: ext4 related problems

2009-08-08 Thread Christoph Anton Mitterer
Hi Maximilian. I've just found the reason for my second problem (that ext4 is not mounted within the inird). It seems that fstype is not able to detect it. There's already a bug for this. Best wishes, Chris. This message was

Bug#540296: ext4 related problems

2009-08-08 Thread Christoph Anton Mitterer
On Sat, 2009-08-08 at 17:18 +0200, maximilian attems wrote: yes, known. will switch to new util-linux fs utils. Ah :) also you *are* using MODULES=dep Strange,.. is this the setting in /etc/initramfs-tools/initramfs.conf? Because this _really_ says =most btw: I've just changed

Bug#528990: [BTS] Re: ipset modules?

2009-08-08 Thread Christoph Anton Mitterer
Why are the ipset userland tools there anyway when there is no kernel support out-of-the-box? Why not? There's the ipset-source package,.. which provides the sources that can be easily compiled e.g. with m.a. Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#528990: [BTS] Re: ipset modules?

2009-08-08 Thread Christoph Anton Mitterer
On Sat, 2009-08-08 at 20:05 +0200, Jan Engelhardt wrote: Well, shameless ad included, Submitter may try xtables-addons which ships ipset3, including kernel modules. Hm interesting,... didn't know that it includes this. Perhaps the two maintainers should think whether the packages could/should

Bug#520668: procps: Enable syn cookies by default

2009-08-13 Thread Christoph Anton Mitterer
HI. Anything new here? btw: Olaf, have you read http://lkml.org/lkml/2008/2/5/167 ? Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to

Bug#331191: procps: sysctl.conf doesn't take wildcards

2009-08-13 Thread Christoph Anton Mitterer
Hi. Can't this be closed or won't-fixed, or reassigned to the netbase package to improve their description? There's the all-dir as Craig said. The only thing that could/shoud be improved in procps is perhaps better description of what all/default/Interface means. Regards, Chris.

Bug#507788: sysctl.conf read before ipv6 module loaded, so cannot set ipv6 settings

2009-08-13 Thread Christoph Anton Mitterer
Hi. Apart from the question, whether anything new has happened here? The issue that sysctl MUST be loaded BEFORE network interfaces are brought up (for security reasons) is this secured by the LSB init script headers? I mean now that insserv and concurrent booting moves to be the

Bug#541406: change /etc/default/nfs-common default values to not start daemons

2009-08-13 Thread Christoph Anton Mitterer
Package: nfs-common Version: 1:1.2.0-3 Severity: wishlist Hi. May I suggest to change the defaults for the /etc/default/nfs-common as follows: NEED_STATD=no NEED_IDMAPD=no NEED_GSSD=no The reason is purely security. If those are unset the respective daemons start. The novice user might

Bug#540546: insserv changes my system without asking

2009-08-14 Thread Christoph Anton Mitterer
Hi Michael. Is this still the case with the current version of insserv in sid? When I've installed it a week or two ago,... I _was_ asked. I even think that I was asked with the lenny version of sid (IIRC). You meant that your debconf priority is set to low? Regards, Chris.

Bug#511753: insserv: Missing symlinks in rcN.d after removing insserv

2009-08-14 Thread Christoph Anton Mitterer
Im not totally sure (please correct me if I'm wrong) but isn't this desired? When uninstalling insserv, the only thing it can do to recover the old rcN.d/links is, to is the backups it made during its own installation, right? Of course, the ones from packages installed afterwards (like your

Bug#471281: Detects loop involving sysklogd because of obselete conffile

2009-08-14 Thread Christoph Anton Mitterer
Hi Andrew. Does this still not work with the current unstable versions? (At least for me, it does). So can it be closed? Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to

Bug#387450: please provide /etc/tls symlink

2009-08-14 Thread Christoph Anton Mitterer
Uhm,.. well no one will ever start to use the tls if the basic framworks are not provided ;) Could be one reason for adding. Chris ;) This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email

Bug#493376: ca-certificates delivers expired certificates

2009-08-14 Thread Christoph Anton Mitterer
Yes, that's the whole reason for keeping them. And it's a good reason :) Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a

Bug#537382: WARNING: Skipping duplicate certificate

2009-08-14 Thread Christoph Anton Mitterer
I get the same with different filenames, depening on what I do, e.g.: # dpkg-reconfigure ca-certificates Updating certificates in /etc/ssl/certs... WARNING: Skipping duplicate certificate ca.pem 0 added, 1 removed; done. Running hooks in /etc/ca-certificates/update.d updating keystore

Bug#326072: ca-certificates removing sendmail certificates

2009-08-14 Thread Christoph Anton Mitterer
Hi. Is this still a problem for you, or can this bug be closed? Regards, Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a

Bug#393835: ca-certificates: Download CRLs

2009-08-14 Thread Christoph Anton Mitterer
Hi. Anything new here? One option to solve this bug, would perhaps be to package something like: http://dist.eugridpma.info/distribution/util/fetch-crl/ And to let ca-certificates recommend this. btw: I do not want to say, that fetch-crl is the best tool for this (I don't want say the

Bug#541620: /etc/adduser.conf is not handled at all

2009-08-14 Thread Christoph Anton Mitterer
Package: adduser Version: 3.110 Severity: normal Hi. It seems that /etc/adduser.conf is not marked as conffile for the package (but there's some file in /usr/share... ?!)... Why this? There seems to be no other handling for merging changes from maintainers version, which makes it

Bug#541622: cleaned up /etc/anacrontab

2009-08-14 Thread Christoph Anton Mitterer
Package: anacron Version: 2.3-13.2 Severity: wishlist Tags: patch Hi. May I suggest to apply the attached patch to /etc/anacrontab. I does not change anything semantically, just removes some useless empty lines and spaces and adds some tabs to align the indenting. I'd even suggest to

Bug#541631: improving default options file

2009-08-14 Thread Christoph Anton Mitterer
Package: apg Version: 2.2.3.dfsg.1-2 Severity: wishlist Tags: patch Hi. Just a suggestion: You may replace the current /etc/apg.conf with the attached one, which provides some reasonable examples and another default. The reason for replaceing -s by -c /dev/urandom: I think without options,

Bug#541634: stale entries in ca-certificates.conf

2009-08-14 Thread Christoph Anton Mitterer
Package: ca-certificates Version: 20090814 Severity: minor Hi. It seems that some blocked certificates were removed, but their entries in ca-certificates.conf was not removed: # grep ^! ca-certificates.conf !cacert.org/class3.crt !cacert.org/root.crt !mozilla/UTN_USERFirst_Object_Root_CA.crt

Bug#541636: outdated info in /etc/checksecurity.conf

2009-08-14 Thread Christoph Anton Mitterer
Package: checksecurity Version: 2.0.13 Severity: minor Hi. checksecurity.conf says this: # If the CHECKSECURITY_EMAIL is set, the report is mailed to the given # address. Note that if you set this, it is *assumed* that you have # /usr/bin/mail that accepts -s; the mailx package provides this;

Bug#541728: several minor improvement ideas

2009-08-15 Thread Christoph Anton Mitterer
Package: adduser Version: 3.110 Severity: wishlist Hi. The following are several minor ideas for improvement. Some of them are really pedantic so be warned ;) 1) When creating a user and the homedir already exists, adduser gives a warning, that it does not copy /etc/skel. It should also

Bug#260323: does not handle change on power status

2009-08-15 Thread Christoph Anton Mitterer
Wasn't this solved in 2.3-13.2 and can thus be closed? Chris. This message was sent using IMP, the Internet Messaging Program. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#426294: anacron: fails to start if on battery

2009-08-15 Thread Christoph Anton Mitterer
I think anacron (and the same for corn, at) should always be started, regardless of AC or not. It's the duty of the respective cron-job to determine, whether the sys is on battery and whether the job is so important to have it run anyway. Apart from that, I cannot believe that this severe

Bug#540363: minor issues and improvements

2009-08-17 Thread Christoph Anton Mitterer
Hi. On Wed, 2009-08-12 at 09:25 -0500, Manoj Srivastava wrote: 3) in the /u/s/doc dir: - It seems that Rational is available twice (one gzipped, once plain). I have not been able to track this down. I can see it being explicitly installed in kernel-source packages, but then I do

Bug#540546: insserv changes my system without asking

2009-08-17 Thread Christoph Anton Mitterer
On Mon, 2009-08-17 at 13:36 +0200, Petter Reinholdtsen wrote: There is a medium priority debconf question being asked. The default is set to convert if the testing indicate that it is safe to convert, and the default is set to not convert if there is a problem. Yeah,... I've already assumed

Bug#542490: RFP: iceweasel-tabmixplus -- adds dozens of new capabilities to tabbed browsing

2009-08-19 Thread Christoph Anton Mitterer
Package: wnpp Severity: wishlist * Package name: iceweasel-tabmixplus Version : 0.3.8.1 Upstream Author : Gary Reyes d...@tmp.garyr.net * URL : http://tmp.garyr.net/ (and https://addons.mozilla.org/en-US/firefox/addon/1122) * License : MPL 1.1 Programming

Bug#535469: sks does not longer start

2009-08-20 Thread Christoph Anton Mitterer
Hi Christoph. Sorry for forgetting to mention this. It works now again, and you can close the bug :) thx, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#542724: add default js-bookmark that allows users to force remembering passwords on a given site

2009-08-20 Thread Christoph Anton Mitterer
Package: iceweasel Version: 3.0.12-1 Severity: wishlist Hi. Some sites, e.g. PayPal prevent users from using the password manager, by adding autocomplete=off to their forms. There are quite some was to circumvent this starting from patching

Bug#542889: nvidia-kernel-source: kernel panic on amd64 with 185.18.31 drivers, Quadro card

2009-08-23 Thread Christoph Anton Mitterer
Hi. This does not only affect Quadro cards... btw: Could you please hurry up to upload the fixed version? Or could you please reupload the older version? Best wishes, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#529863: RFP: keyboardcast -- Allow you to send keystrokes to multiple X windows (e.g. Terminals) at once.

2009-05-21 Thread Christoph Anton Mitterer
Package: wnpp Severity: wishlist *** Please type your report below this line *** * Package name: keyboardcast Version : 0.1.1 Upstream Author : Ryan Lortie de...@desrt.ca * URL : https://launchpad.net/keyboardcast and/or http://desrt.mcmaster.ca/code/keyboardcast/

Bug#499303: open-vm-source: fails to build against 2.6.26: error: linux/autoconf.h: No such file or directory

2009-02-06 Thread Christoph Anton Mitterer
Uhm it seems that it works again now... have no idea why... I changed nothing. The system where I tested it (and where it worked) is a lenny/AMD64, with all packages upgraded. But the open-vm-* are the most recent ones from sid. hth, Chris smime.p7s Description: S/MIME cryptographic signature

Bug#514660: resolv.conf not available after when doing if-post-up

2009-02-09 Thread Christoph Anton Mitterer
Package: resolvconf Version: 1.43 Severity: important Hi. I'm not sure if this is actually resolvconf's fault but at least it seems to be somehow connected. The resolvconf hooks are in /etc/network/if-up.d/000resolvconf and I'd assume from this, that /etc/resolv.conf should be set up already,

Bug#514663: shouldn't the package contain default zones for ipv6

2009-02-09 Thread Christoph Anton Mitterer
Package: bind9 Severity: wishlist Hi. The bind9 package already contains the zones.rfc1918 file. Shouldn't another file be added, with the corresponding zones for IPv6? Are these the following? 0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA

Bug#515146: bind9: default config is not as documented

2009-02-13 Thread Christoph Anton Mitterer
Package: bind9 Version: 1:9.5.1.dfsg.P1-1 Severity: normal Hi. It seems that there are several options that have actually a different default value as described in the documentation. If you look in the sources in bin/named/config.c serial-queries 20; = BIND 9 does not limit the number of

Bug#515146: bind9: default config is not as documented

2009-02-13 Thread Christoph Anton Mitterer
On Fri, 2009-02-13 at 23:54 +0100, Ondřej Surý wrote: dnssec-validation yes; = The default is no. The default is yes since 9.5.0. Sure? https://www.isc.org/software/bind/documentation/arm95 says something different. And what is with the others? Thanks, Chris :-) smime.p7s Description:

Bug#515146: bind9: default config is not as documented

2009-02-13 Thread Christoph Anton Mitterer
On Sat, 2009-02-14 at 00:09 +0100, Ondřej Surý wrote: Yeah, I am pretty sure. This is documentation bug on ISC side. I know that from more authoritative source than docs :). Ok than perhaps the file bind9-doc should be corrected. And what is with the others? Personally I think you

Bug#512087: #512087 - trigger automatic properties update after apt only when watched

2009-02-15 Thread Christoph Anton Mitterer
On Thu, 2009-02-12 at 20:58 +0100, Julien Valroff wrote: It would be nice if rkhunter recognizes which packages were upgraded/installed/removed/etc. any only trigger the update-process when one or more of its watched files is part of these packages. We would first need to precisely know

Bug#512087: #512087 - trigger automatic properties update after apt only when watched

2009-02-15 Thread Christoph Anton Mitterer
On Sun, 2009-02-15 at 20:31 +0100, Julien Valroff wrote: That was the plan for the last upload, upstream having now improved the --propupd option. However, I have found that running 'rkhunter --propupd' with one file or for all files almost takes the same time. That was totally wrong, my

Bug#511498: #511498 - rkhunter does not find files like /etc/.java

2009-02-15 Thread Christoph Anton Mitterer
On Sun, 2009-02-15 at 23:20 +0100, Christoph Anton Mitterer wrote: On Thu, 2009-02-12 at 20:40 +0100, Julien Valroff wrote: Just in case you haven't subscribed to the bug (forgot to cc you in my oroginal answer) Thanks =), normally I should have been subscribed,.. but I wasn't,.. strange

Bug#511485: #511485 - rkhunter: whitlist /usr/share/man/man5/.k5login.5.gz

2009-02-16 Thread Christoph Anton Mitterer
On Mon, 2009-02-16 at 08:11 +0100, Julien Valroff wrote: Added to SVN - will be part of the next upload. What a strange name for a man page ! Yeah it is :-) Thanks. Actually that's a bigger problem here. There are many packages in Debian which produce suspicious files or so. e.g. I have to add:

Bug#512087: #512087 - trigger automatic properties update after apt only when watched

2009-02-16 Thread Christoph Anton Mitterer
On Mon, 2009-02-16 at 08:06 +0100, Julien Valroff wrote: You are 100% right, nothing is logged when using propupd. I have committed this change to SVN. And are you sure that we don't miss any warnings/errors in case of them? Or was there really _never_ any logging? Chris. smime.p7s

Bug#511930: Re #511930 - set /var/lib/rkhunter/tmp rwx------

2009-02-16 Thread Christoph Anton Mitterer
On Mon, 2009-02-16 at 06:13 +0100, Julien Valroff wrote: This might be unnoticed by the sysadmin and thus be a security problem. You are right, though I am quite confident that upstream would pay attention to this. I hence reopen the bug and will forward it upstream to get their opinion.

Bug#515599: fail2ban inconveniences when using own iptables rules

2009-02-16 Thread Christoph Anton Mitterer
Package: fail2ban Version: 0.8.3-2sid1 Severity: important Hi. I've marked this as important, as it can make fail2ban unusable. Perhaps the following should also be forwarded upstream. I've also CC'ed this to the Debian iptables maintainer: Laurence, please read this,... it might be a good

Bug#511422: errors in manpages for resolv.conf and hosts.conf

2009-01-10 Thread Christoph Anton Mitterer
Package: manpages Version: 3.15-1 Severity: important Hi. The resolv.conf manpage says that defaults for domain and search are generated when not specified... however it seems that this is simply not the case. The thing with the root domain is assumed might be wrong, too. What is the

Bug#511483: logcheck-database: please add rules for rkhunter

2009-01-11 Thread Christoph Anton Mitterer
Package: logcheck-database Severity: wishlist Hi. Could you please add rules for rkhunter: This email is sent by logcheck. If you no longer wish to receive such mails, you can either deinstall the logcheck package or modify its configuration file (/etc/logcheck/logcheck.conf). System Events

Bug#511485: rkhunter: whitlist /usr/share/man/man5/.k5login.5.gz

2009-01-11 Thread Christoph Anton Mitterer
Package: rkhunter Severity: wishlist Hi. Could you please add a (perhaps even commented) entry to whitelist /usr/share/man/man5/.k5login.5.gz from the krb5-doc package? Thanks, Chris. -- System Information: Debian Release: 5.0 APT prefers unstable APT policy: (500, 'unstable')

Bug#409973: rkhunter leaves copies of /etc/passwd and /etc/groups in $TMPDIR

2009-01-11 Thread Christoph Anton Mitterer
Hi. Isn't this a possible security issue? I mean when someone has set the envionment variable TMPDIR and the files are copied there instead to the location specified in rkhunter.conf? Shouldn't rkhunter completely ignore $TMPDIR? That should be perhaps forwarded upstream?! Chris. smime.p7s

Bug#472295: rkhunter probably needs to check the properties before running apt-get

2009-01-11 Thread Christoph Anton Mitterer
What's the status on this? I mean I'd really prefer that every apt invokation needs more time that leaving this hole open?. I think anyone who installs rkhunter would also give security the higher priority than time,... Perhaps you could make this configurable via debconf? Regards, Chris.

Bug#511498: rkhunter does not find files like /etc/.java

2009-01-11 Thread Christoph Anton Mitterer
Package: rkhunter Severity: important Hi. My rkhunter doesn't find directories like /etc/.java and the corresponding whitelist entry is commented... It also doesn't find wpa_supplicant which is found e.g. by chkrootkit. Any ideas? Chris. -- System Information: Debian Release: 5.0 APT

Bug#531100: after startup, infinite number of nautilus tabs appear in the window list on the panel

2009-05-29 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Justification: renders package unusable Severity: grave Hi. I have this problem on two systems, one a normal laptop (one screen) the other a dual head monitor system (two separate X screens, no Xinerama or something like this): After starting gnome, the

Bug#531101: applications launched on the 2nd (3rd, etc) screens are opened on the 1st

2009-05-29 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Severity: normal Hi. I have this problem on a dual head monitor system (two separate X screens, no Xinerama or something like this): When I start an application on the 2nd screen (e.g. via the main menu from the gnome-panel) its window is opened on the

Bug#531102: workspace switcher on 2nd (3rd, etc) screen control the workspaces on the 1st, and vice-versa

2009-05-29 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Severity: normal Hi. I have this problem on a dual head monitor system (two separate X screens, no Xinerama or something like this): When I use the workspace switcher on the 2nd screen, it actually changes (moves windows, etc.) on the first screen.

Bug#531103: notification area doesn't work on 2nd (3rd, etc.) screens

2009-05-29 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Severity: normal Hi. I have this problem on a dual head monitor system (two separate X screens, no Xinerama or something like this): When I add a notification area on the 2nd screen, and I start e.g. pidgin or ekiga on that screen (which makes use of the

Bug#531103: notification area doesn't work on 2nd (3rd, etc.) screens

2009-05-31 Thread Christoph Anton Mitterer
On Sat, 2009-05-30 at 09:26 +0200, Josselin Mouette wrote: The reason why upstream developers don’t fix this is probably that they don’t run any multi-screen setup. Since TTBOMK Debian GNOME maintainers don’t either, you’re not likely to have more luck. Ok,.. I see,.. Just thought that this

Bug#520254: unhide: segfault when using unhide brute

2009-05-31 Thread Christoph Anton Mitterer
Hi. I'm havin the same problems with unhide burte (at least with the current debian sid package). If you need some help with testing,.. please do not hesitate to ask me ;) Regards, Chris. This message was sent using IMP, the

Bug#531315: aptitude seems to use hidden processes, rendering HIDS systems like unhide nearly useless

2009-05-31 Thread Christoph Anton Mitterer
Package: aptitude Version: 0.4.11.11-1+b1 Justification: user security hole Severity: grave Tags: security Hi. I'm running several intrusion detection systems, e.g. rkhunter (which in turn uses unhide). For quite some time now, unhide gave me false positives (I'm quite sure, that my system

Bug#474191: ITP: iceweasel-downloadstatusbar -- Iceweasel addon that provides an improved download statusbar

2009-06-02 Thread Christoph Anton Mitterer
Hi. Very nice, Eugeniy. Would you also be interested in packaging other iceweasel plugins? E.g. tab mix plus is very nice,... though I was never able to find out its license :-( Regards, Chris. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of

Bug#531100: after startup, infinite number of nautilus tabs appear in the window list on the panel

2009-06-02 Thread Christoph Anton Mitterer
Hi Josselin. It seems that at least this bug itself is solved now,... so you can close it. Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#525718: Work-around for nautilus/gnome-session bug

2009-06-02 Thread Christoph Anton Mitterer
On Sun, 2009-05-31 at 18:35 +0200, Josselin Mouette wrote: OTOH it would be better if all of this could be documented in the README.Debian. I’ll add that to the next upload. This is really nice,.. especially that stuff about using compiz per default. However,.. I'd suggest that you put this

Bug#531638: starting applications directly from the panel on the 2nd (3rd, etc.) screens makes gnome-panel crashing

2009-06-02 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Severity: important Hi Josselin. Unfortunately another bug, that happens on setups with multiple X screens (this is not Xinerama or that like): There's the other bug I've already reported, that when starting applications from the Main Menu, they're opened

Bug#531644: workspache switcher applet shows its line incorrectly when using with compiz and both havin multiple lines configured

2009-06-02 Thread Christoph Anton Mitterer
Package: gnome-panel Version: 2.26.2-1 Severity: normal Hi Josselin. Sorry for always reporting bugs to you, but I think you can much better direct me to the correct package, or whether I should report something upstream. Since one of your last packages compiz is used per default, which

Bug#535469: sks does not longer start

2009-07-16 Thread Christoph Anton Mitterer
Hi. Did you mean 1.1.0-7 or -6 ? The later one would still fail (on i386): # sks db unknown timeout type argument to DB_ENV-rep_get_timeout Segmentation fault # sks recon unknown timeout type argument to DB_ENV-rep_get_timeout Segmentation fault Cheers, Chris.

Bug#537323: Perhaps a critical mistake in the example for chaining with Tor?

2009-07-16 Thread Christoph Anton Mitterer
Package: privoxy Version: 3.0.13-1 Justification: user security hole Severity: grave Tags: security Hi. Since the last release or so, the config template gives this as an example for chaining privoxy with Tor: # To chain Privoxy and Tor, both running on the same system, # you would

Bug#537803: flac cannot decode from file without known extensions

2009-07-20 Thread Christoph Anton Mitterer
Package: flac Version: 1.2.1-1.2 Severity: normal Hi. It seems that flac cannot decode flac files, that have no known extension (ogg/oga/flac). One gets an error like: filename: *** Got error code 0:FLAC__STREAM_DECODER_ERROR_STATUS_LOST_SYNC It can however encode to such files,.. or encode

Bug#537806: should support creating files,where the template is in the middle of the filename

2009-07-20 Thread Christoph Anton Mitterer
Package: coreutils Version: 7.4-2 Severity: wishlist Hi. Currently one can specifies filenames like someTextFollowedByXX where the 's are for the template. It is however not possible to do something like: file..ogg There are probably many reasons why this could be interesting,

Bug#538100: dash makes strange things during command substitution

2009-07-22 Thread Christoph Anton Mitterer
Package: dash Version: 0.5.5.1-2 Severity: normal Hi. I've made some scripts where I pre-process an arbitrary file name for some sed- and grep expressions. As e.g. . and / (which can occur in filenames) may have special meaning to sed and grep, I quote the each character of the filename

Bug#538100: Acknowledgement (dash makes strange things during command substitution)

2009-07-22 Thread Christoph Anton Mitterer
Uhm... I've just noted: http://www.opengroup.org/onlinepubs/009695399/utilities/xcu_chap02.html#tag_02_06_07 The quote characters: '\', ', and '' (backslash, single-quote, double-quote) that were present in the original word shall be removed unless they have themselves been quoted. = int the

Bug#538100: dash makes strange things during command substitution

2009-07-23 Thread Christoph Anton Mitterer
I've just noticed something even more weird When using that weird \.\/\d \/\i\m\g\e\.\o\g string (with the tab and the 0x7's) as grep pattern, it actually matches lines that contain ./data/image.oga. When using --color=auto one sees, that the full ./data/image.oga is matched, and not just

Bug#535469: sks does not longer start

2009-07-25 Thread Christoph Anton Mitterer
Hi Christoph. On Fri, 2009-07-17 at 06:37 +0200, Christoph Martin wrote: This caused the Segfault. 1.1.0-7 and 1.1.0-8 in Debian are build correctly and don't segfault. When will this be uploaded? Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#535469: sks does not longer start

2009-07-02 Thread Christoph Anton Mitterer
Package: sks Version: 1.1.0-5 Justification: renders package unusable Severity: grave Hi. Since 1.1.0-5 sks does not longer work,.. and I see these messages in dmesg: [80773.190585] sks[23453]: segfault at 0 ip (null) sp bfad072c error 4 in sks[8048000+db000] [80785.802317] sks[23450]:

Bug#578824: perhaps using warn would be ok

2010-05-12 Thread Christoph Anton Mitterer
btw: I guess it might be ok to warn (log_warning_msg), given the fact that ekeyd might be security or service relevant (by providing good entropy). Cheers, Chris. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#578824: forgotten

2010-05-12 Thread Christoph Anton Mitterer
But perhaps one should be able to disabled the warning via a configuration option in /etc/defaults/ekeyd (etc.) -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#581434: The default umask in Debian should be changed to '0002' to be fully compliant with user private groups

2010-05-14 Thread Christoph Anton Mitterer
Hi. I guess the last two reports from Vincent and Joey already show quite well that such an open default mask is a very bad idea. Cheers, Chris. smime.p7s Description: S/MIME cryptographic signature

Bug#581666: base-files: default umask 022 is too permissive

2010-05-14 Thread Christoph Anton Mitterer
Package: base-files Version: 5.4 Severity: normal Hi. Even when considering #248140 and #581434 I'd say that a umask of 002 is far too permissive. 1) Generally it's always the best idea to have the strictest or most secure default, which is of course 002. Even when user private groups are

Bug#581667: init script fails when zfs-fuse was disabled

2010-05-14 Thread Christoph Anton Mitterer
Package: zfs-fuse Version: 0.6.0+critical20100301-3 Severity: normal Hi. When zfs-fuse is disabled via ENABLE_ZFS, the initscript fails which leads to a annyoing ...failed printed out when starting. Wouldn't it be better not to fail, as there is no real failure? The admin probably disabled it

Bug#581668: init script is quite chatty in case zfs-fuse was disabled

2010-05-14 Thread Christoph Anton Mitterer
Package: zfs-fuse Version: 0.6.0+critical20100301-3 Severity: wishlist Hi. In case zfs-fuse was disabled via ENABLE_ZFS, the init script is quite chatty by printing out the whole story why it is not started: if [ x$ENABLE_ZFS != xyes ]; then echo Not starting $NAME: ENABLE_ZFS is not

Bug#581669: laptop-mode-tools: laptop mode fails with custom kernels

2010-05-14 Thread Christoph Anton Mitterer
Package: laptop-mode-tools Version: 1.54-1 Severity: important Hi. Since some time, laptop-mode-utils fail with the following message when starting them: $ /etc/init.d/laptop-mode start Enabling laptop mode...Unhandled kernel version: 2.6.33-heisenberg. ('uname -r' = '2.6.33-heisenberg')

<    1   2   3   4   5   6   7   8   9   10   >