Bug#342152: harden-doc: typo in section 4.10.9.2: make sure you that

2005-12-05 Thread Francesco Poli
Package: harden-doc Version: 3.2.4 Severity: minor Hello! I think I found a little typo in section 4.10.9.2 _Using the shell history file_: make sure you that all users are using a shell that supports this s/sure you/sure/ Is that right? -- System Information: Debian Release: 3.1

Bug#342695: eclipse: debian/copyright file doesn't seem to be accurate anymore

2005-12-09 Thread Francesco Poli
Package: eclipse Version: 3.1.1-6 Severity: serious Justification: Policy 2.3 Hi! According to the package debian/copyright file, Eclipse seems to be released under the CPL. But eclipse.org website states that, from version 3.1 on, Eclipse has completed the migration[1] from the CPL to the

Bug#335808: acknowledged by developer (Re: [Pkg-cups-devel] Bug#335808: cupsys: writes to /etc/cups/ppds.dat, should write to somewhere else)

2005-12-18 Thread Francesco Poli
://lists.debian.org/debian-devel-announce/2005/07/msg00010.html -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B

Bug#345604: Undistributable?

2006-01-02 Thread Francesco Poli
the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpbJwUhfcPAM.pgp Description: PGP signature

Bug#331541: gnupg-doc: [NONFREE-DOC:GFDL1.1] includes non-free documents

2005-10-03 Thread Francesco Poli
Package: gnupg-doc Version: 2003.04.06-4 Severity: serious Justification: Policy 2.2.1 Hello! Two included documents are released under the GNU FDL license (version 1.1 or later), although with no unmodifiable unremovable parts (i.e. Invariant Sections, Front/Back-Cover Texts, ...).

Bug#331545: gnupg-doc: little error in copyright file

2005-10-03 Thread Francesco Poli
Package: gnupg-doc Version: 2003.04.06-4 Severity: minor Hi! The copyright file (correctly) states that the GnuPG Mini HOWTO is released under the GNU *Library* General Public License (LGPL) version 2 or later. But then (incorrectly) refers to the GNU General Public License

Bug#332782: release-notes: Where's the license?

2005-10-08 Thread Francesco Poli
Package: release-notes Severity: serious Justification: Policy 2.2.1 The Debian documentation policy (http://www.debian.org/doc/docpolicy) reads: | All manuals of the Debian Documentation Project (DDP) will be released | under DFSG-compliant licenses On the other hand the _Release Notes_ seem

Bug#332941: installation-reports: fails to unpack base-installer component

2005-10-09 Thread Francesco Poli
Package: installation-reports Severity: important Debian-installer-version: Debian GNU/Linux 3.1 r0 (as released when sarge became stable) obtained from http://cdimage.debian.org/debian-cd/current/, IIRC uname -a: Linux (none) 2.6.8-2-386 #1 Mon Jan 24 03:01:58 EST 2005 i586

Bug#332942: kernel-image-2.6.8-2-386: fails to insert floppy.ko claiming io-port 0x03f2 in use

2005-10-09 Thread Francesco Poli
Package: kernel-image-2.6.8-2-386 Version: 2.6.8-16 Severity: normal I installed Debian sarge (3.1 r0) on an old Pentium machine, following the manual debootstrap procedure (described in the Debian sarge installation guide, appendix C.). I could not use debian-installer because I didn't have

Bug#332941: installation-reports: fails to unpack base-installer component

2005-10-09 Thread Francesco Poli
). The debian-installer documentation claims it will run with as little as 24 Mibyte... What did I fail to understand? -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli

Bug#332941: installation-reports: fails to unpack base-installer component

2005-10-10 Thread Francesco Poli
trying to install sarge! As released last june. That's Debian GNU/Linux 3.1 r0, nothing more, nothing less... -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli

Bug#333219: galeon: crashes when loading a particular website (http://www.jobcrawler.it)

2005-10-10 Thread Francesco Poli
Package: galeon Version: 1.3.20-1 Severity: normal Hi! I recently noted that Galeon crashes whenever I try to load http://www.jobcrawler.it Steps to reproduce: $ galeon -n http://www.jobcrawler.it Galeon main window appears, the only tab starts to load the website main page, then a dialog

Bug#333453: harden-doc: copyright notice is unclear

2005-10-11 Thread Francesco Poli
Package: harden-doc Version: 3.2.4 Severity: minor Hi! harden-doc copyright file clearly states that the _Securing Debian Manual_ is released under the GNU GPL license (version 2 or later). Good! :) On the other hand, the copyright notice included in the document itself (in the HTML version,

Bug#335220: [Pkg-doc-linux-devel] Bug#335220: doc-linux-text: [NONFREE-DOC] includes non-free documentation

2005-10-23 Thread Francesco Poli
is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpVI7zXW15iq.pgp Description: PGP signature

Bug#335403: libgmp3-doc: [NONFREE-DOC:GFDL] includes non-free documentation

2005-10-23 Thread Francesco Poli
Package: libgmp3-doc Version: 4.1.4-6 Severity: serious Justification: Policy 2.2.1 According to the copyright file (and the texinfo file itself), the GMP documentation is released under the GFDL license (v1.1 or later) and hence does not comply with the DFSG. See

Bug#333219: galeon: crashes when loading a particular website (http://www.jobcrawler.it)

2005-10-23 Thread Francesco Poli
On Sat, 22 Oct 2005 21:34:09 +0200 Loic Minier wrote: Hi, On Sat, Oct 22, 2005, Francesco Poli wrote: As I previously stated, I use a pure stable and would rather avoid using installing backported mozilla packages (with all the related ones). Oh sorry, sometimes I loose

Bug#335808: cupsys: writes to /etc/cups/ppds.dat, should write to somewhere else

2005-10-25 Thread Francesco Poli
Package: cupsys Version: 1.1.23-10 Severity: wishlist Hi! FHS v2.3 chapter 2[1] states, in part: | Static files include binaries, libraries, documentation files | and other files that do not change without system administrator | intervention Later on, section about /etc states, in part: | The

Bug#335185: [Fwd: ITP: newmat -- manipulate matrices using standard operations]

2005-10-25 Thread Francesco Poli
the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp8BjghsEocf.pgp Description: PGP signature

Bug#332942: kernel-image-2.6.8-2-386: fails to insert floppy.ko claiming io-port 0x03f2 in use

2005-10-30 Thread Francesco Poli
On Thu, 13 Oct 2005 11:59:30 +0900 Horms wrote: On Wed, Oct 12, 2005 at 11:41:05PM +0200, Francesco Poli wrote: On Wed, 12 Oct 2005 15:41:27 +0900 Horms wrote: [...] Are you sure that the drive is actually at 0x03f2? How can I check this? Is that a hardware setting (such as a jumper

Bug#332941: installation-reports: fails to unpack base-installer component

2005-11-01 Thread Francesco Poli
On Mon, 10 Oct 2005 23:49:51 +0200 Francesco Poli wrote: On Mon, 10 Oct 2005 06:52:22 +0200 Christian Perrier wrote: Maybe, but, as I said, that machine has a memory capacity equal to 32 Mibyte (and has passed two full memtest86 runs with no errrors). The debian-installer

Bug#332942: kernel-image-2.6.8-2-386: fails to insert floppy.ko claiming io-port 0x03f2 in use

2005-10-12 Thread Francesco Poli
On Wed, 12 Oct 2005 15:41:27 +0900 Horms wrote: On Sun, Oct 09, 2005 at 07:10:24PM +0200, Francesco Poli wrote: [...] # mount -t ext2 /dev/fd0 /media/floppy/ mount: /dev/fd0 is not a valid block device # ls -altrF /dev/fd0 brw-rw 1 root floppy 2, 0 Feb 26 2005 /dev/fd0 # tail -3

Bug#333219: galeon: crashes when loading a particular website (http://www.jobcrawler.it)

2005-10-12 Thread Francesco Poli
with debugging symbols and the place where it crashes Work in progress... ;-) -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint

Bug#238245: Debian website's copyright and license suggestions?

2005-10-16 Thread Francesco Poli
! I've Cc'ed the bug report about the issue, but Mail-followups does not contain bug report. Add it if needed, please. Added. -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli

Bug#333453: harden-doc: copyright notice is unclear

2005-10-16 Thread Francesco Poli
the debian/copyright file. -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B

Bug#334448: bugs.debian.org: returns 500 Internal Server Error when queried for non-free doc bugs

2005-10-17 Thread Francesco Poli
Package: bugs.debian.org Severity: normal Hi! It seems that the non-free doc Status page in the BTS does not work anymore... The corresponding link in http://release.debian.org/removing-non-free-documentation that is to say: http://bugs.debian.org/cgi-bin/pkgreport.cgi?tag=nonfree-doc;[EMAIL

Bug#238245: Debian website's copyright and license suggestions?

2005-10-17 Thread Francesco Poli
? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpbVhY5R6xkP.pgp Description: PGP signature

Bug#333219: galeon: crashes when loading a particular website (http://www.jobcrawler.it)

2005-10-19 Thread Francesco Poli
On Thu, 13 Oct 2005 00:26:31 +0200 Francesco Poli wrote: - get a better stacktrace with debugging symbols and the place where it crashes Work in progress... ;-) OK, this is what I got with an unstripped galeon: $ MALLOC_CHECK_=2 gdb galeon GNU gdb 6.3-debian Copyright 2004 Free

Bug#335104: harden-doc: quotes the version 1.0 of SC, which is superseded by version 1.1

2005-10-21 Thread Francesco Poli
Package: harden-doc Version: 3.4 Severity: minor The Social Contract is quoted in section 2.3 as follows: | We Won't Hide Problems | | We will keep our entire bug-report database open for public view | at all times. Reports that users file on-line will immediately | become visible to others.

Bug#335220: doc-linux-text: [NONFREE-DOC] includes non-free documentation

2005-10-22 Thread Francesco Poli
Package: doc-linux-text Version: 2005.04-1 Severity: serious Justification: Policy 2.2.1 According to the copyright file, some of the included documents do not comply with the DFSG. See below for details. In order to solve these issues, upstream authors of relevant documents should be got in

Bug#333219: galeon: crashes when loading a particular website (http://www.jobcrawler.it)

2005-10-22 Thread Francesco Poli
). Is the second backtrace I sent of any use in understanding the nature of this bug? -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key

Bug#332942: Finally the correct solution

2005-11-20 Thread Francesco Poli
? ;-) .. Francesco Poli GnuPG Key ID = DD6DFCF4 Key fingerprint = C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp7JUq7TV69R.pgp Description: PGP signature

Bug#331541: acknowledged by developer (Bug#331541: fixed in gnupg-doc 2003.04.06-5)

2005-11-22 Thread Francesco Poli
splitting the package into gnupg-doc and gnupg-doc-nonfree would be far better... Don't you agree? -- :-( This Universe is buggy! Where's the Creator's BTS? ;-) .. Francesco Poli GnuPG Key ID

Bug#340535: Typo: Impossed in the section about limits.conf

2005-11-23 Thread Francesco Poli
Package: harden-doc Version: 3.2.4 Severity: minor Hi! I noticed a little typo in section 4.10.2 _Limiting resource usage: the limits.conf file_. It says Resource limits are impossed by the kernel I think s/impossed/imposed/ , right? -- System Information: Debian Release: 3.1 Architecture:

Bug#340538: apache2: includes non-free and possibly undistributable files

2005-11-23 Thread Francesco Poli
Package: apache2 Version: 2.0.54-5 Severity: serious Justification: Policy 2.2.1 Hi! By reviewing the copyright file, I found out that apache2 includes code that does not seem to comply with the DFSG. What is worse, I even found some code that does not seem to be distributable at all...

Bug#401926: harden-doc: wrong regular user prompt ($) for the init command, and some typos

2006-12-06 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: minor Hi! Appendix A _The hardening process step by step_[1] includes the following commands for switching to single user mode and back: | $ init 1 | () | $ init 2 I think that these commands should be issued as root, in order to actually

Bug#376206: No response yet?

2006-12-06 Thread Francesco Poli
. Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp1oBXposSGK.pgp Description: PGP signature

Bug#402040: geomview: no images are displayed in the HTML version of the manual

2006-12-07 Thread Francesco Poli
Package: geomview Version: 1.8.1-8 Severity: normal Hi! The HTML version of the TeXinfo manual fails to display figures: HTML tags are shown instead (rather than interpreted). The fact is that the tags that should be there to display the image are somehow mangled ('' is substituted by its HTML

Bug#402040: geomview: no images are displayed in the HTML version of the manual

2006-12-07 Thread Francesco Poli
On Thu, 7 Dec 2006 12:15:42 -0600 Steve M. Robbins wrote: On Thu, Dec 07, 2006 at 06:42:05PM +0100, Francesco Poli wrote: Package: geomview Version: 1.8.1-8 Severity: normal Hi! The HTML version of the TeXinfo manual fails to display figures: HTML tags are shown instead (rather

Bug#376206: No response yet?

2006-12-07 Thread Francesco Poli
! ;-) Thank your for the patch! You're welcome! :) -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4

Bug#376206: No response yet?

2006-12-08 Thread Francesco Poli
On Fri, 08 Dec 2006 03:35:57 +0200 Evgeny Stambulchik wrote: Francesco Poli wrote: No reaction whatsoever from upstream yet? The bug was forwarded on 01 Jul 2006, but still no comment or response seems to have come back... Well, tough times... I'm full-time working since 01 Jun 2006

Bug#357445: [geomview-users] dot-files in /usr/lib/geomview trigger root-kit warnings

2006-12-08 Thread Francesco Poli
name and, in case of failure, check for the old name. That way you would have back-compatibility, wouldn't you? -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli

Bug#402637: harden-doc: appendix on stand-along IDS should be updated and clarified

2006-12-11 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: normal Hi! Appendix C _Setting up a stand-alone IDS_[1] has some flaws that should be fixed. [1] http://www.debian.org/doc/manuals/securing-debian-howto/ap-snort-box.en.html Firstoff: | * Download and manually (with dpkg) install necessary packages

Bug#402040: geomview: no images are displayed in the HTML version of the manual

2006-12-12 Thread Francesco Poli
On Fri, 8 Dec 2006 01:20:01 +0100 Francesco Poli wrote: On Thu, 7 Dec 2006 12:15:42 -0600 Steve M. Robbins wrote: [...] and (b) install version 1.8.1-14 to see if the problem has already been fixed? I'll try to find the time, but I'm afraid it won't be soon... :-( I don't have a testing

Bug#402966: harden-doc: typo in bind conf change script (many any) and suspicious example

2006-12-13 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: minor Hi! Appendix E _Sample script to change the default Bind installation_[1] includes a script where there seems to be a typo: | | This script will not many any changes to your setup. | maybe s/many/apply/ ? Moreover the end of the appendix

Bug#397382: harden-doc: suboptimal explanation for www-data and backup users

2006-11-06 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: wishlist Hi! Section 12.1.12.1 _Are all system users necessary?_[1] lists statically allocated system users and their intended purpose. [1] which is in http://www.debian.org/doc/manuals/securing-debian-howto/ch12.en.html#s12.1 Among the others, the

Bug#397376: harden-doc: suggested command to find unnecessary users seems to do the opposite

2006-11-06 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: normal Hi! Section 12.1.12.1 _Are all system users necessary?_[1] suggests a command intended to easily find users who don't own any files: cut -f 1 -d : /etc/passwd | \ while read i; do find / -user $i | grep -q . echo $i; done I

Bug#397377: harden-doc: typo (an video)

2006-11-06 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: minor Hi! Quoting from section 12.1.12.1 _Are all system users necessary?_[1]: | This group can be used locally to give a set of users access | to an video device. I think that this is a typo and should be fixed by the following substitution: s/an

Bug#397991: harden-doc: please explain the raw socket issue further

2006-11-10 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: wishlist Hi! Section 12.1.14.5 _I have services using port 1 and 6, what are they and how can I remove them?_ talks about processes listening on raw sockets. It's not really clear to me. Firstoff, is having such processes listening on raw sockets

Bug#397990: harden-doc: section 12.1.14 has a typo in its title (Question)

2006-11-10 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: minor Hi! Section 12.1.14 _Question regarding services and open ports_[1] seems to have a typo in its very title: s/Question/Questions/ [1] which is in http://www.debian.org/doc/manuals/securing-debian-howto/ch12.en.html#s12.1 -- To UNSUBSCRIBE,

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-10 Thread Francesco Poli
On Fri, 10 Nov 2006 17:45:36 +0100 Diego Biurrun wrote: On Wed, Nov 01, 2006 at 11:23:43PM +0100, Francesco Poli wrote: [...] There seems to be still a licensing issue, though... :-( According to its debian/copyright[1], mplayer includes a file named mmx.h, whose licensing status

Bug#398235: ffmpeg: permission notice is botched!

2006-11-12 Thread Francesco Poli
Package: ffmpeg Version: 0.cvs20060823-4 Severity: normal Quoting from the debian/copyright file[1]: [1] http://packages.debian.org/changelogs/pool/main/f/ffmpeg/ffmpeg_0.cvs20060823-4/ffmpeg.copyright | Copyright (c) 2000-2004 Fabrice Bellard et al. | | This library is free software; you

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-12 Thread Francesco Poli
On Sun, 12 Nov 2006 05:31:54 +0100 Diego Biurrun wrote: On Sat, Nov 11, 2006 at 12:22:54AM +0100, Francesco Poli wrote: On Fri, 10 Nov 2006 17:45:36 +0100 Diego Biurrun wrote: On Wed, Nov 01, 2006 at 11:23:43PM +0100, Francesco Poli wrote: [...] There seems to be still a licensing

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-12 Thread Francesco Poli
On Sun, 12 Nov 2006 19:18:31 +0100 Diego Biurrun wrote: On Sun, Nov 12, 2006 at 05:56:09PM +0100, Francesco Poli wrote: On Sun, 12 Nov 2006 05:31:54 +0100 Diego Biurrun wrote: On Sat, Nov 11, 2006 at 12:22:54AM +0100, Francesco Poli wrote: [...] Which license is available under

Bug#397186: closed by [EMAIL PROTECTED] (A. Maitland Bottoms) (Bug#397186: fixed in vtk 5.0.2-1)

2006-11-13 Thread Francesco Poli
On Fri, 10 Nov 2006 18:19:11 -0800 Debian Bug Tracking System wrote: [...] * Apply fix for two-dimensional PLOT3D by Francesco Poli (Closes: #397186) [...] Thanks for considering and applying my patch! :-) I think that a description of the changes should be included in README.debian

Bug#398674: harden-doc: unclear sentence (vulnerable to it)

2006-11-14 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: normal Hi! Section 12.2.2 _I've seen an attack in my system's logs. Is my system compromised?_[1] states, in part: | Also, notice that the fact that you see the attacks in the log might | mean your system is already vulnerable to it This sentence is

Bug#397186: closed by [EMAIL PROTECTED] (A. Maitland Bottoms) (Bug#397186: fixed in vtk 5.0.2-1)

2006-11-15 Thread Francesco Poli
On Tue, 14 Nov 2006 11:11:04 -0500 Mathieu Malaterre wrote: Francesco Poli wrote: On Fri, 10 Nov 2006 18:19:11 -0800 Debian Bug Tracking System wrote: [...] * Apply fix for two-dimensional PLOT3D by Francesco Poli (Closes: #397186) [...] Thanks for considering and applying my

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-15 Thread Francesco Poli
On Sun, 12 Nov 2006 20:01:23 +0100 Diego Biurrun wrote: On Sun, Nov 12, 2006 at 07:30:32PM +0100, Francesco Poli wrote: [...] I've not yet seen the file taken from FFmpeg, so I cannot comment on its copyrightability. Take into account that determining whether something

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-15 Thread Francesco Poli
On Wed, 15 Nov 2006 23:04:40 +0100 Diego Biurrun wrote: On Wed, Nov 15, 2006 at 08:28:24PM +0100, Francesco Poli wrote: [...] Hence, I think the Right Thing(TM) to do is properly documenting where the file `mmx.h' came from (that is to say: FFmpeg) and which is the license the project we

Bug#387783: Why was this bug downgraded?

2006-10-17 Thread Francesco Poli
://lists.debian.org/debian-legal/2006/05/msg00298.html -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D

Bug#393760: harden-doc: wrong reference to sarge where woody is meant

2006-10-17 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! In section 10.1.2.1 _Manually checking which security updates are available_[1], there's an example run of apt-get upgrade -s. The relevant part is quoted below: | # apt-get upgrade -s | Reading Package Lists... Done |

Bug#393759: harden-doc: typo (an specific)

2006-10-17 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: minor Hi! Section 10.1.2.1 _Manually checking which security updates are available_[1] includes a typo: | | Debian does have an specific tool | I think you should s/an specific/a specific/ [1] inside

Bug#393761: harden-doc: typo (be sured)

2006-10-17 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: minor Hi! Section 10.1.2.2 _Automatically checking for updates with cron-apt_[1] includes a typo: | Otherwise, you cannot be sured that the downloaded packages really | come from a trusted source. I think s/be sured/be sure/ [1] inside

Bug#393986: harden-doc: wrong URL for Testing Security Team home page?

2006-10-18 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! Section 10.1.4 _Security support for the testing branch_[1] states, in part: | Additionally, the Debian Security Testing Team can issue Debian | Security Testing Advisories (DTSAs) for packages in the testing | branch In this sentence,

Bug#393986: harden-doc: wrong URL for Testing Security Team home page?

2006-10-18 Thread Francesco Poli
On Wed, 18 Oct 2006 23:38:30 +0200 Javier Fernández-Sanguino Peña wrote: On Wed, Oct 18, 2006 at 10:08:29PM +0200, Francesco Poli wrote: I don't know whether the right URL for the Testing Security Team home page has changed somehow (if this is the case the link should be fixed accordingly

Bug#394151: harden-doc: mentions dselect which is sort-of deprecated

2006-10-20 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! Section 10.1.5 _Automatic updates in a Debian GNU/Linux system_[1] mentions dselect as a possible means to mark packages as /hold/. IIUC, dselect is deprecated (sort of): I think you should mention aptitude instead, which can also mark

Bug#394157: harden-doc: Configure *cron* so that debconf ?!?

2006-10-20 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi again! Section 10.1.5 _Automatic updates in a Debian GNU/Linux system_[1] states, in part: | * Configure cron so that debconf will not ask for any input during | upgrades, that way they are done non-interactively. :-? Configure *cron*? I

Bug#394483: mayavi: Scalar Coloring fails to work with DRI drivers on Radeon 9250 graphics chipset

2006-10-21 Thread Francesco Poli
Package: mayavi Version: 1.5-4~frx.1 Severity: normal Hi! I noticed a bug while running MayaVi under Debian sarge. My system is an IA32 machine with a Radeon 9250 based video card, running XFree86 (version 4.3.0.dfsg.1-14sarge2) with DRI radeon driver and radeon DRM module (Linux kernel version

Bug#394570: mayavi: lintian complains

2006-10-21 Thread Francesco Poli
Package: mayavi Version: 1.5-4~frx.1 Severity: minor Hi again! After backporting mayavi 1.5-4 to sarge, I checked it with lintian and got some complaints, so I thought I should report them... Take into account that this is what _sarge's_ version of lintian says, hence some of the following

Bug#292231: acknowledged by developer (Bugs fixed in NMU, documenting versions)

2006-10-22 Thread Francesco Poli
log, for further details. -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpQluSmNHHct.pgp

Bug#396271: harden-doc: fenris? Where is fenris?

2006-10-30 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! Section 11.4 _Forensic analysis_[1] mentions fenris as a tool provided in the Debian distribution, but I was unable to find any package that includes this tool: the package search web interface currently gives no results[2]. If the tool is

Bug#395961: gabber: Links with GPL-incompatible licensed OpenSSL

2006-10-30 Thread Francesco Poli
-- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpaFFrzbSR2k.pgp Description: PGP signature

Bug#396387: harden-doc: reference to XFree should perhaps be changed in Xorg; dead link for Ramen or Lion worms

2006-10-31 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! Section 12.1.1.1 _Is Debian more secure than other Linux distributions (such as Red Hat, SuSE...)?_[1] mentions XFree: this should probably be changed into Xorg to reflect the X11 implementation currently in unstable and testing (and

Bug#383481: Must source code be easy to understand to fall under DFSG?

2006-10-31 Thread Francesco Poli
etch is out. -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp760nf9rvFI.pgp Description: PGP

Bug#383481: Must source code be easy to understand to fall under DFSG?

2006-10-31 Thread Francesco Poli
. Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpAY1XcwVIyD.pgp Description: PGP signature

Bug#383481: Must source code be easy to understand to fall under DFSG?

2006-10-31 Thread Francesco Poli
* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpHCWsq2CpeV.pgp Description: PGP signature

Bug#383481: Must source code be easy to understand to fall under DFSG?

2006-11-01 Thread Francesco Poli
On Wed, 1 Nov 2006 01:20:43 +0100 Sven Luther wrote: On Wed, Nov 01, 2006 at 12:55:45AM +0100, Francesco Poli wrote: On Tue, 31 Oct 2006 23:59:18 +0100 Sven Luther wrote: [...] Nope, because you can ship the source code and the object file if you wanted. Already now, major

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-01 Thread Francesco Poli
Package: mplayer Version: 1.0~rc1-1 Severity: serious Justification: Policy 2.2.1 Hi! First of all, many thanks for the hard work that was necessary to get MPlayer into Debian! :-) There seems to be still a licensing issue, though... :-( According to its debian/copyright[1], mplayer includes

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-04 Thread Francesco Poli
at 11:23:43PM +0100, Francesco Poli wrote: There seems to be still a licensing issue, though... :-( According to its debian/copyright[1], mplayer includes a file named mmx.h . Where's the permission to redistribute (DFSG#1)? Where's the permission to modify (DFSG#3)? that file

Bug#397047: libgsm: license should be clarified

2006-11-04 Thread Francesco Poli
Package: libgsm Severity: normal Hi! The debian/copyright file of this package[1] quotes the following license: | Copyright 1992, 1993, 1994 by Jutta Degener and Carsten Bormann, | Technische Universitaet Berlin | | Any use of this software is permitted provided that this notice is not |

Bug#396646: mplayer: no permission to modify or redistribute mmx.h

2006-11-04 Thread Francesco Poli
do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp2UWmQHPdQA.pgp Description: PGP signature

Bug#397186: libvtk5: fails to read two-dimensional PLOT3D solution files [patch]

2006-11-05 Thread Francesco Poli
is creative enough to grant copyright protection. Anyway, should it be found to be copyrighted, I hereby release it under the same terms as the rest of VTK, that is to say: | Copyright (c) 1993-2003 Ken Martin, Will Schroeder, Bill Lorensen | Copyright (c) 2006 Francesco Poli | All rights

Bug#392699: harden-doc: the word sixty is repeated twice

2006-10-12 Thread Francesco Poli
Package: harden-doc Version: 3.8 Severity: minor Hi! There seems to be a little typo in section 9.1 _Best practices for security review and design_: the cost in this later phase is sixty sixty times higher The word sixty is repeated twice. I think the fix should be s/sixty sixty/sixty/

Bug#392700: harden-doc: spurious greater than symbol in HTML version

2006-10-12 Thread Francesco Poli
Package: harden-doc Version: 3.8 Severity: minor Hi! There seems to be a little markup mess (or something) in the HTML code of section 9.1 _Best practices for security review and design_: that they follow common security principles, includinggt; This HTML code produces a spurious symbol in

Bug#392822: harden-doc: Section on antivirus tools is outdated

2006-10-13 Thread Francesco Poli
Package: harden-doc Version: 3.9 Severity: normal Hi! Please update section 8.8 _Antivirus tools_: it still refers to woody as the if it were the current stable. The part that rang my alarm bell is: | As you can see, Debian does not currently provide antivirus scanning | software in the main

Bug#392699: harden-doc: the word sixty is repeated twice

2006-10-13 Thread Francesco Poli
On Fri, 13 Oct 2006 00:29:23 +0200 Javier Fernández-Sanguino Peña wrote: On Thu, Oct 12, 2006 at 11:29:45PM +0200, Francesco Poli wrote: [...] There seems to be a little typo in section 9.1 _Best practices for security review and design_: [...] This has been fixed in CVS and in the 3.9

Bug#392699: harden-doc: the word sixty is repeated twice

2006-10-14 Thread Francesco Poli
On Sat, 14 Oct 2006 09:58:56 +0200 Javier Fernández-Sanguino Peña wrote: On Fri, Oct 13, 2006 at 07:35:28PM +0200, Francesco Poli wrote: if you could foolproof the full manual I would really appreciate it Well, I'm (slowly) reading it and I am reporting bugs whenever I see something

Bug#392867: xpdf-reader: Error: Unimplemented shading type 4

2006-10-14 Thread Francesco Poli
*must* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgp7jpAddCeRp.pgp Description: PGP signature

Bug#354622: Is the bug fixed for Firefox too?

2006-10-14 Thread Francesco Poli
* and always do change, my friend. -- from _Coming to America_ . Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpmLN9INLQDy.pgp Description: PGP signature

Bug#392699: harden-doc: the word sixty is repeated twice

2006-10-15 Thread Francesco Poli
On Sun, 15 Oct 2006 15:44:56 +0200 Javier Fernández-Sanguino Peña wrote: On Sat, Oct 14, 2006 at 11:33:27PM +0200, Francesco Poli wrote: [...] Fine, I see that it has a version number in the footer (currently 3.9): should I go on mentioning *that* number in the Version: pseudo-header

Bug#391262: harden-doc: mentions queso, but doesn't list it

2006-10-05 Thread Francesco Poli
Package: harden-doc Version: 3.8 Severity: normal Hi! Section 8.2 _Network scanner tools_ names queso, but that tool is not (anymore?) included in the bulleted list. I think that this inconsistency should be fixed by either stopping mentioning queso or by including queso in the list of tools.

Bug#360496: jack+cdda2wav fail to rip audio CDs that include data tracks

2006-09-22 Thread Francesco Poli
. Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpz1i22w2wf5.pgp Description: PGP signature

Bug#387783: [Debburn-devel] [PATCH] fix debburn/cdrkit GPL violation

2006-09-24 Thread Francesco Poli
because it's still in the moderator queue: I'm not a subscriber...): http://lists.debian.org/debian-legal/2006/09/msg00126.html -- But it is also tradition that times *must* and always do change, my friend. -- from _Coming to America_ . Francesco

Bug#387783: [Debburn-devel] License of cdrkit - GPLv2 + additional restrictions

2006-09-24 Thread Francesco Poli
On Sun, 24 Sep 2006 13:43:39 +0200 Josselin Mouette wrote: Le vendredi 15 septembre 2006 à 23:51 +0200, Francesco Poli a écrit : Because the hard problems that you pointed out have been fixed. We do no longer return schily author ID, etc. You no longer return schily, but it seems

Bug#387783: [Debburn-devel] License of cdrkit - GPLv2 + additional restrictions

2006-09-25 Thread Francesco Poli
On Mon, 25 Sep 2006 13:49:35 +0200 Josselin Mouette wrote: Le dimanche 24 septembre 2006 à 23:32 +0200, Francesco Poli a écrit : [...] Here, the restriction clearly forbids creating a derivative work that is a drop-in replacement of the original, and thus interferes with interoperability

Bug#354622: Renaming Mozilla applications

2006-09-27 Thread Francesco Poli
. Francesco Poli . GnuPG key fpr == C979 F34B 27CE 5CD8 DC12 31B5 78F4 279B DD6D FCF4 pgpLe5pqvXXaY.pgp Description: PGP signature

Bug#400406: libvtk5: fails to correctly read multiblock (Fortran unformatted) PLOT3D solution files

2006-11-25 Thread Francesco Poli
Package: libvtk5 Version: 5.0.2-4 Severity: normal Hi! A bugreport submitted to upstream (bugid=4041)[1] addresses the main issue that I detected and fixed in bug #397186 (see [2]). The purpose of the first patch ('plot3d.patch') that was submitted to upstream in bugid=4041 is indeed to fix the

Bug#397186: closed by [EMAIL PROTECTED] (A. Maitland Bottoms) (Bug#397186: fixed in vtk 5.0.2-1)

2006-11-26 Thread Francesco Poli
On Wed, 15 Nov 2006 21:17:34 +0100 Francesco Poli wrote: On Tue, 14 Nov 2006 11:11:04 -0500 Mathieu Malaterre wrote: [...] Could you please verify the bug report: http://vtk.org/Bug/bug.php?op=showbugid=4041 And tell me if this is enough to fix your issue or does this need some

Bug#400938: harden-doc: section on testing unstable security needs to be updated

2006-11-29 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: normal Hi! Section 12.3.7 _How is security handled for testing and unstable?_[1] still states that security is not handled in testing and unstable. I think that this is becoming more and more outdated, as the Debian testing security team progresses in

Bug#401235: harden-doc: can be sent to repeated twice and missing words

2006-12-01 Thread Francesco Poli
Package: harden-doc Version: 3.10 Severity: minor Hi! Section 12.3.11 _How can I reach the security team?_[1] includes a repetition: | Security information can be sent to can be sent to | [EMAIL PROTECTED], This should fixed: s/can be sent to can be sent to/can be sent to/ Moreover, the same

Bug#401233: debian-installer-manual: how to get the guide source should be clarified

2006-12-01 Thread Francesco Poli
Package: debian-installer-manual Severity: wishlist Hi! It's not clear to me how to get the source for the Debian Installation Guide. At the Debian Documentation Project page[1], there's a Subversion command line that will probably checkout the latest development version (right?). This seems

  1   2   3   4   5   6   7   8   9   10   >