Bug#673727: License changed?

2013-08-24 Thread Jérémy Bobbio
Gustavo Noronha Silva: On Qui, 2013-08-01 at 11:24 -0300, Rogério Brito wrote: It seems that the current JSHint is *not* licensed under the no evil license: https://github.com/jshint/jshint/blob/master/LICENSE It would be lovely to have JSHint and others in our repository.

Bug#719297: RFP: ruby-packetfu -- PacketFu is a mid-level packet manipulation library for Ruby

2013-08-24 Thread Jérémy Bobbio
Control: retitle -1 ITP: ruby-packetfu -- PacketFu is a mid-level packet Control: owner -1 ! intrig...@debian.org: * Package name: ruby-packetfu Version : 1.1.8 Upstream Author : Tod Beardsley * URL or Web page : https://github.com/todb/packetfu

Bug#720709: ITP: ruby-pcaprub -- Ruby bindings for LBL Packet Capture library (libpcap)

2013-08-24 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org Control: block 719297 by -1 * Package name: ruby-pcaprub Version : 0.11.3-1 Upstream Author : shadowbq shado...@gmail.com * URL : https://github.com/shadowbq/pcaprub * License : LGPL-2

Bug#720709: ITP: ruby-pcaprub -- Ruby bindings for LBL Packet Capture library (libpcap)

2013-08-24 Thread Jérémy Bobbio
Hi Paul, Paul van Tilburg: On Sat, Aug 24, 2013 at 06:49:05PM +0200, Jérémy Bobbio wrote: Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org Control: block 719297 by -1 * Package name: ruby-pcaprub Version : 0.11.3-1 Upstream Author : shadowbq

Bug#719315: ITP: taskwarrior-web -- A web interface for the Taskwarrior todo application

2013-08-26 Thread Jérémy Bobbio
Ben Armstrong: lib/taskwarrior-web/public/css/bootstrap.min.css lib/taskwarrior-web/public/css/bootstrap-responsive.min.css lib/taskwarrior-web/public/js/bootstrap.js Copyright 2012 Twitter Inc, ASL 2.0 Packaged in libjs-twitter-bootstrap. lib/taskwarrior-web/public/css/datepicker.css

Bug#716916: [DRE-maint] Bug#716916: ruby-gettext: rxgettext doubles the backslashes in newline '\n' characters

2013-08-27 Thread Jérémy Bobbio
Control: tag -1 + upstream Hi Francesco, Francesco Poli (wintermute): First of all, thanks a lot for fixing the bugs I have previously reported (#684182, #684184, and #692487)! And thanks for your reports! :) I noticed something new in rxgettext, and it looks like a newly introduced bug.

Bug#719844: dpkg-source: Make compresing of {data,control}.tar.gz a deterministic process

2013-08-27 Thread Jérémy Bobbio
Hi! Guillem Jover: I've been thinking about this, and I think you might be trying to solve the problem in the wrong place(s), and possibly there's a need to step back and ponder about what do you really want out of all this, to know where or how to best fix it. […] My ideal scenario is the

Bug#719845: [PATCH] t-deterministic-file-order: new test case

2013-08-27 Thread Jérémy Bobbio
In order to make the build reproducible, we ensure that the files are written to the .deb in a deterministic file order. --- Here is a test case for pkg-tests that should ensure that files are always written in the same order in the control and data tarball, despite what readdir() says.

Bug#719845: [PATCH] t-deterministic-file-order: new test case

2013-08-28 Thread Jérémy Bobbio
Guillem Jover: On Tue, 2013-08-27 at 23:12:34 +0200, Jérémy Bobbio wrote: In order to make the build reproducible, we ensure that the files are written to the .deb in a deterministic file order. --- Here is a test case for pkg-tests that should ensure that files are always written

Bug#719844: dpkg-source: Make compresing of {data,control}.tar.gz a deterministic process

2013-08-28 Thread Jérémy Bobbio
Jérémy Bobbio: Guillem Jover: The timestamp on the ar member let's you know when the package got built. I don't believe this add much value: we have this information in the .changes files already. Anyway, I was thinking of adding a `--timestamp=1377619307` option to `dpkg-deb

Bug#721179: lintian: Please update autopkgtest known restrictions

2013-08-28 Thread Jérémy Bobbio
Package: lintian Version: 2.5.17 Severity: minor Tags: patch Hi dear Lintian maintainers, Could you please update the list of known restrictions for autopkgtest? It looks like `allow-stderr` is missing. I believe the attached patch written against the master branch will do the trick. Thanks!

Bug#719844: dpkg-source: Make compresing of {data,control}.tar.gz a deterministic process

2013-08-31 Thread Jérémy Bobbio
Jonathan Nieder: I disagree that this is important information. Most packages that I have seen so far do not propagate timestamps when copying a file from source. Could you give me an example of one that would do so? See http://www.debian.org/doc/debian-policy/ch-source.html#s-timestamps

Bug#719844: dpkg-source: Make compresing of {data,control}.tar.gz a deterministic process

2013-09-01 Thread Jérémy Bobbio
Jérémy Bobbio: Jonathan Nieder: I disagree that this is important information. Most packages that I have seen so far do not propagate timestamps when copying a file from source. Could you give me an example of one that would do so? See http://www.debian.org/doc/debian-policy/ch

Bug#721574: ruby-gettext: undefined method force_encoding... during apt-listbugs

2013-09-02 Thread Jérémy Bobbio
Ivan Sergio Borgonovo: calling aptitude [] runs apt-listbugs that fails with /usr/lib/ruby/vendor_ruby/gettext/mo.rb:46: undefined method `force_encoding' for \225\004\022\336:String (NoMethodError) from /usr/lib/ruby/vendor_ruby/gettext/text_domain.rb:16:in `require'

Bug#432200: Ruby 1.8 is going away

2013-09-02 Thread Jérémy Bobbio
Control: severity -1 serious Hi! Ruby 1.8 is unsupported upstream and should not be part of Jessie. Please update apt-listbugs to make it works with newer Ruby versions. See also: http://release.debian.org/transitions/html/ruby1.8-removal.html Thanks! -- Lunar

Bug#721618: Ruby 1.8 is going away

2013-09-02 Thread Jérémy Bobbio
Package: schleuder Version: 2.2.1-3 Severity: serious Justification: unsuitable for release Hi! schleuder currently depends on ruby1.8. Ruby 1.8 is unsupported upstream and unsuitable for release. We would like to remove it from the archive soon. See:

Bug#721703: RM: ruby-pcap -- ROM; dead upstream, alternative exists

2013-09-03 Thread Jérémy Bobbio
Package: ftp.debian.org Hi! Please remove ruby-pcap from the archive. It has no reverse dependencies. Upstream is inactive for years. Other developers resumed work around a pcap binding for ruby in the pcaprub project. The later library entered the archive as ruby-pcaprub today. Thanks! --

Bug#690572: localization takes $LANG into account, but ignores $LC_MESSAGES

2013-09-03 Thread Jérémy Bobbio
Hleb Valoshka: The bug really lies in ruby-gettext which does not currently parse LC_MESSAGES at all. It should, just like GNU gettext. Are you sure? GNU gettext uses LC_MESSAGES only indirectly, calling _nl_locale_name (see intl/dcigettext.c), but it never checks its value by itself.

Bug#716796: [Pkg-javascript-devel] Bug#716796: Bug#716796: jQuery needs updating

2013-09-04 Thread Jérémy Bobbio
Hi Raphael, Raphael Hertzog: On Sun, 28 Jul 2013, Marcelo Jorge Vieira wrote: There is a big problem, Grunt depends on the JSHint and it is not DFSG-compatible (Crockford's license). Please read this:

Bug#721811: Florence does not release keys when terminated

2013-09-04 Thread Jérémy Bobbio
Control: forwaded -1 f.agr...@gmail.com Hi Michael, Michael Billington: If florence is killed/terminated, any keys which are down will remain down. I think that the program should release anything it's holding when it is closed. Thanks for your report. I have forwarded your suggestion to

Bug#721910: xul-ext-torbutton: torbutton sets the wrong port number (8118) rather than the correct polipo port (8123)

2013-09-05 Thread Jérémy Bobbio
issues. -- Jérémy Bobbio lu...@debian.org Tue, 16 Oct 2012 20:33:40 +0200 (Note that this package is not in Wheezy for that reason.) -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get install anarchism

Bug#721909: tor does not set properly the polipo option socksParentProxy = localhost:9050

2013-09-05 Thread Jérémy Bobbio
Patrick Zanon: It would be nice if tor installation scripts could ask the user if to change the polipo option socksParentProxy = localhost:9050 so that polipo would start using tor infrastructure... The Tor project recommends against polipo since Firefox finally implemented SOCKS properly.

Bug#711720: [Pkg-roundcube-maintainers] Bug#711720: roundcube: Include -plugins-extra in 0.8.6 package set

2013-06-09 Thread Jérémy Bobbio
-extra: […] I am waiting for Roundcube 0.9 to land in unstable before updating roundcube-plugins-extra. Roundcube 0.9.1 is in the NEW queue right now: https://ftp-master.debian.org/new/roundcube_0.9.1-1.html -- Jérémy Bobbio.''`. lu...@debian.org: :Ⓐ

Bug#724340: e17: Please do not store timestamps in headers of gzipped documentation

2013-09-23 Thread Jérémy Bobbio
Package: e17 Version: 0.17.3-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps Hi! As part of the effort to have byte-to-byte identical reproducible builds [1], I've noticed that e17 currently stores a timestamp in the gzip header of some of

Bug#724481: python-gnupg: Please package gnupg 1.2.2

2013-09-24 Thread Jérémy Bobbio
Package: python-gnupg Severity: wishlist Hi! Would it be possible to package gnupg 1.2.2? The later comes from a new active upstream and is now gnupg on PyPI: https://pypi.python.org/pypi/gnupg Thanks, -- Lunar.''`. lu...@debian.org: :Ⓐ :

Bug#724489: python-qrcode: missing dependency on python-six

2013-09-24 Thread Jérémy Bobbio
Package: python-qrcode Version: 4.0.1-1 Severity: grave Hi! It looks like python-qrcode is missing a Depends on python-six. # apt-get install python-qrcode […] The following NEW packages will be installed: liblcms1 python-imaging python-qrcode […] $ echo 'bla' | qr Traceback (most recent

Bug#725675: ruby-packetfu: Should provide ruby2.0 compatibility

2013-10-07 Thread Jérémy Bobbio
Package: ruby-packetfu Version: 1.1.8-2 Severity: wishlist Forwarded: https://github.com/todb/packetfu/issues/28 Hi! ruby-packetfu should be made compatible with ruby2.0. Hopefully, upstream will sort it out soon. -- Lunar.''`. lu...@debian.org

Bug#722079: hello: Please provide a deterministic Build ID

2013-09-07 Thread Jérémy Bobbio
Package: hello Version: 2.8-4 Severity: wishlist Tags: patch Hi! In the quest to get deterministic/reproducible builds [1], I have noticed that the result of building hello currently varies according to its build path. The attached patch use the debugedit tool to prevent such variation by

Bug#722079: hello: Please provide a deterministic Build ID

2013-09-07 Thread Jérémy Bobbio
Hi! Santiago Vila: In the quest to get deterministic/reproducible builds [1], I have noticed that the result of building hello currently varies according to its build path. […] While I can agree that reproducible builds is a good thing (I added gzip -n recently), the proposed patch makes

Bug#722154: gem2deb: Please use dpkg-buildflags

2013-09-08 Thread Jérémy Bobbio
Package: gem2deb Severity: wishlist Hi! gem2deb should ensure that Ruby extensions are built using the compilation flags available from dpkg-buildflags. Right now, this will enable hardening flags on Debian. In the future, it might help to have deterministic builds:

Bug#722166: bobcat: Please do not write timestamps in gzip files

2013-09-08 Thread Jérémy Bobbio
Package: bobcat Version: 3.15.00-1 Severity: wishlist Hi! In the effort of making Debian binary package build reproducible [1], I have noticed that your package currently ship gz compressed files with a timestamp. Adding the `-n` or `--no-name` flag to the various calls to `gzip` made in

Bug#722166: bobcat: Please do not write timestamps in gzip files

2013-09-08 Thread Jérémy Bobbio
Control: tags -1 + patch tony mancill: Thanks for the suggestion and for looking into the cause of the issue with the bobcat build. I'm suspect that Frank, the upstream developer, will be willing to address this in a future upstream release. Great! Attached is a patch that indeed did the

Bug#722186: dh-buildinfo: Please produce stable output

2013-09-08 Thread Jérémy Bobbio
2013-09-08 23:22:26.0 +0200 @@ -1,3 +1,10 @@ +dh-buildinfo (0.9+nmu2) UNRELEASED; urgency=low + + * Do not record timestamps when compressing buildinfo file. + * Output packages sorted by name. + + -- Jérémy Bobbio lu...@debian.org Sun, 08 Sep 2013 20:59:23 + + dh-buildinfo (0.9+nmu1

Bug#722166: bobcat: Please do not write timestamps in gzip files

2013-09-09 Thread Jérémy Bobbio
Hi Frank, Frank B. Brokken: Of course I am. Could somebody please enlighten me what the problem actually is? This is the first time in my l-o-o-o-o-ng life that I learn about a thing called a `timestamp of a gzip file' and that it may cause problems. In Debian context, it currently can pause

Bug#722528: Coquelicot: support subdirectories

2013-09-12 Thread Jérémy Bobbio
Control: forwarded -1 https://coquelicot.potager.org/TODO Hi Shawn, Shawn Landden: I tried to install coquelicot under /images on my domain using nginx's rewrite directive, and the main page shows up, but I cannot upload as it goes to /upload. There should be an easy way to tell coquelicot

Bug#734622: Please package GeoLiteCity.dat and GeoIPASNum.dat

2014-01-08 Thread Jérémy Bobbio
Source: geoip-database Severity: wishlist Hi! ooni-probe [1] which I am trying to package requires GeoLiteCity.dat and GeoIPASNum.dat for some tests to work. They are respectively available at: http://geolite.maxmind.com/download/geoip/database/GeoLiteCity.dat.gz and:

Bug#719845: [PATCH] Deterministic file order for control and data archives

2014-01-17 Thread Jérémy Bobbio
Control: tags -1 + patch Hi! Here are four patches based on the current master (1e059955) that will write files in deterministic order in the control and data archives. File names are sorted by forking `sort` before being piped to `tar`. They have been tested with the test case previously sent

Bug#735919: florence: Shouldn't this be in 'x11' section, not 'web'?

2014-01-18 Thread Jérémy Bobbio
Control: tags -1 + pending Dylan Thurston: What's the justification for putting florence in the web category? Surely 'x11' would be a better fit? It doesn't seem specific to web browsing at all. Indeed! Thanks for spotting the mistake. -- Lunar.''`.

Bug#736126: /dev/random entropy depletion on a fresh install

2014-01-20 Thread Jérémy Bobbio
Control: reassign -1 tasksel Jeffrey Walton: It would probably be very beneficial to install an entropy gatherer by default. I am unconvinced that haveged is the answer here, but reassigning to the proper package. -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr

Bug#736239: python-sphinx: 'sphinx/pycode' not installed

2014-01-21 Thread Jérémy Bobbio
Stephan Sürken: Maybe 'sphinx/pycode' is new in 1.2.1, but just not installed? # dpkg -L python-sphinx | grep Grammar-py2.txt /usr/share/pyshared/sphinx/pycode/Grammar-py2.txt The file is right there but the code is not properly looking for it. -- Lunar.''`.

Bug#712954: [DRE-maint] Bug#712954: 1.4.3

2014-01-24 Thread Jérémy Bobbio
Axel Wagner: It has been quite a while since jekyll has been updated. Some releases also contain security fixes. Since I would like to use jekyll in $dayjob, I am quite interested in a good health of this package. So if the delay in uploading new versions is for a lack of manpower, I would

Bug#660759: xul-ext-torbutton: torbrowser firefox patches

2013-12-23 Thread Jérémy Bobbio
Hi Robert, Robert Millan: I just wanted to step in and give my point of view, which I think is quite similar to that of the Tor project. […] In the meantime, I believe that providing torbutton does more harm than good, because it provides the *illusion* of security rather than security

Bug#738591: lintian: Add checker for timestamped gzip files

2014-02-11 Thread Jérémy Bobbio
Tomasz Buchert: +Severity: normal It think it should be at most wishlist, perhaps even pedantic. Let's make it pedantic, but hopefully one day it will be normal. Could we go for “wishlist” instead? I know that switching to reproducible builds sounds like a major shift in

Bug#721618: Fix schleuder somehow

2014-02-12 Thread Jérémy Bobbio
Ondřej Surý: Christian Hofstaedtler: Please, if anyhow possible, fix schleuder so it no longer depends on ruby-tmail or ruby-actionmailer (2.3), so we can go ahead with the removal of ruby1.8. It's not in testing, so it doesn't block the removal. Otherwise fill the removal bug, the

Bug#738591: lintian: Add checker for timestamped gzip files

2014-02-12 Thread Jérémy Bobbio
changes. -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr : : : lu...@debian.org `. `'` lu...@torproject.org `- signature.asc Description: Digital signature

Bug#739284: obfsproxy: Please include an AppArmor profile for confining obfsproxy

2014-02-17 Thread Jérémy Bobbio
one. I'll probably take care of this some day. That would be lovely. Thank you! :) -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr : : : lu...@debian.org `. `'` lu...@torproject.org

Bug#739609: ITP: ooniprobe -- probe for the Open Observatory of Network Interference (OONI)

2014-02-20 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org * Package name: ooniprobe Version : 1.0.0-rc7 Upstream Author : Open Observatory of Network Interference ooni-...@torproject.org * URL : https://ooni.torproject.org/ * License : BSD-2

Bug#700048: Log for attempted build of haveged_1.4-4 on m68k (dist=unstable)

2014-02-26 Thread Jérémy Bobbio
Control: tags -1 + moreinfo Thorsten Glaser: Source: haveged Version: 1.4-4 Justification: fails to build from source (but built successfully in the past) Severity: important Please try again with 1.9.1-1. -- Lunar.''`. lu...@debian.org:

Bug#740117: haveged: spinning

2014-02-26 Thread Jérémy Bobbio
:( Been watching it for hours doing that. Uses one CPU at 100%. Upstream version 1.9.0 promisses improvements, although I have no idea if those address the problem I'm reporting. I have just uploaded 1.9.1-1. Please try it. -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr

Bug#740575: typo in README.Debian

2014-03-03 Thread Jérémy Bobbio
that the port is actually 51161. Thanks for noticing! It'll be fixed in the next upload. :) -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr : : : lu...@debian.org `. `'` lu...@torproject.org

Bug#684021: ruby-sinatra: shouldn't break error processing if error logging is failed

2014-04-10 Thread Jérémy Bobbio
Aliaksandr Barouski: When error logging in sinatra fails (with exception), it can't process exception in right way. Example: Our code handles Errno:EROFS: error Errno:EROFS do #some processing end If standard logger (rack.error) starts failing (e.g. filesystem become read only), our

Bug#744975: xul-ext-https-everywhere: all rules lost?

2014-04-17 Thread Jérémy Bobbio
the URL… and the URL will be shown in the rule list. I agree this is a major inconvenience though, especially if you wish to renable CACert-supported rules. -- Jérémy Bobbio.''`. jeremy.bob...@irq7.fr : : : lu...@debian.org

Bug#741421: coquelicot: Debug-style Net::IMAP::NoResponseError output in browser on bad user

2014-03-31 Thread Jérémy Bobbio
Rowan Thorpe: Just adding that this bug seems not to be limited to the IMAP authentication, but is a general behaviour when receiving an exception from any of the authentication modules. I know this because I just implemented LDAP authentication, and any failed authentication from that spills

Bug#723532: ruby-pcaprub link with -L/usr/lib

2014-05-03 Thread Jérémy Bobbio
Control: tags -1 + moreinfo YunQiang Su: This package has one or more -L/usr/lib in its build system, which will make it ftbfs if there is libraries under /usr/lib, while is not the default architecture, mips* for example. Is the problem still present in sid? -- Lunar

Bug#718218: coquelicot: fails to start due to invalid byte sequence error in fast_gettext

2014-05-05 Thread Jérémy Bobbio
Control: reassign -1 ruby-fast-gettext Johannes Schauer: Result: poparser.ry:162:in `===': invalid byte sequence in US-ASCII (ArgumentError) from poparser.ry:162:in `parse' from /usr/lib/ruby/vendor_ruby/fast_gettext/po_file.rb:16:in `to_mo_file' That line says:

Bug#752904: ooniprobe: Cannot run ooniprobe in armhf

2014-06-27 Thread Jérémy Bobbio
in ooniprobe itself from the stacktrace. Could you please try to play with the yaml module or run other software which depends on python-yaml? I'm enclined to think the problem is on your hardware given the amount of armhf users and the fact that no one reported an issue. -- Jérémy Bobbio

Bug#759231: dh-python: Please output dependencies in a stable order

2014-08-25 Thread Jérémy Bobbio
Package: dh-python Version: 1.20140511-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain Hi! It would help the “reproducible efforts” [1] if dh-python would output dependencies in a stable order. Right now they are likely to be different each

Bug#719845: [PATCH] Deterministic file order for control and data archives

2014-08-28 Thread Jérémy Bobbio
Hi! Jérémy Bobbio: Here are four patches based on the current master (1e059955) that will write files in deterministic order in the control and data archives. File names are sorted by forking `sort` before being piped to `tar`. Attached are the same patches rebased on the current master

Bug#757234: xul-ext-https-everywhere: update Debian rules from master and my patches

2014-08-12 Thread Jérémy Bobbio
Paul Wise: I've been submitting changes to the rules for debian.org/debian.net as DSA add more SSL-enabled domains[1]. I'm not sure if upstream will make a release containing them in time for the jessie release so I thought I would submit a diff against 3.5.3 so we can at least have recent

Bug#756935: proot: cwd is not changed when target is bind mounted and matching proot cwd

2014-08-03 Thread Jérémy Bobbio
Package: proot Version: 4.0.0-1 Severity: normal User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain Hi! Some lines of shells are sometimes better than lengthly explainations: $ mkdir -p /tmp/a $ cd /tmp/a $ proot -b /tmp/a:/test -w /test bash -c 'pwd' /tmp/a

Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-30 Thread Jérémy Bobbio
Package: debhelper Version: 9.20140817 User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! As part of the “reproducible builds” project [1], it would be great to get the files shipped in the Debian

Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-30 Thread Jérémy Bobbio
} \\); + } + + complex_doit(find $tmp -newermt '$dh{DATE}' $find_options -print0, + 2/dev/null | xargs -0r touch --no-dereference --date='$dh{DATE}'); +} + +=head1 SEE ALSO + +Ldebhelper(7) + +This program is a part of debhelper. + +=head1 AUTHOR + +Jérémy Bobbio lu...@debian.org + +=cut diff --git a/man

Bug#759895: debhelper: please strip non-deterministic data from static libraries

2014-08-30 Thread Jérémy Bobbio
Package: debhelper Version: 9.20140817 Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! Currently, static libraries shipped in Debian package capture the time when the package is built. As

Bug#759999: dpkg: please set reproducible timestamps in .deb ar file headers

2014-08-30 Thread Jérémy Bobbio
Package: dpkg Version: 1.17.14 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain, timestamps X-Debbugs-Cc: reproducible-bui...@lists.alioth.debian.org Hi! `.deb` are ar archives. The archive internal headers currently capture the time when the

Bug#760075: torsocks: SIGSEGV with torsocks 2.0.0 on some browsers, failure to anonimize others

2014-08-31 Thread Jérémy Bobbio
js: I upgraded torsocks from the 1.3.3 to 2.0.0 and it either SIGSEV on some browsers or else fails to anonimize others (in other words, running under tor they cannot access sites blocked by my firewall) Please be aware that browsing the web with anything else than the Tor Browser is not

Bug#759895: [debhelper-devel] Bug#759895: debhelper: please strip non-deterministic data from static libraries

2014-08-31 Thread Jérémy Bobbio
Joey Hess: Jérémy Bobbio wrote: Currently, static libraries shipped in Debian package capture the time when the package is built. As part of the “reproducible builds” project [1], it would be great to have static libriaries normalized. The attached patch will make `dh_strip` replace

Bug#759886: [debhelper-devel] Bug#759886: debhelper: please make mtimes of packaged files deterministic

2014-08-31 Thread Jérémy Bobbio
Joey Hess: Do you have a plan to get packages not using dh or cdbs to use this new command? Its heart is a single find+xargs+touch command. I had in mind that packages not using dh or cdbs could have their own way on how to make the mtimes deterministic. Possibly by adding such a find command

Bug#760594: ITP: golang-siphash-dev -- Go implementation of SipHash-2-4

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: golang-siphash-dev Version : 1.0.0 Upstream Author : Dmitry Chestnykh dmi...@codingrobots.com * URL : https://github.com

Bug#760595: ITP: golang-ed25519-dev -- Go implementation of Ed25519 signature algorithm

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: golang-ed25519-dev Version : HEAD Upstream Author : Adam Langley a...@imperialviolet.org * URL : https://github.com/agl

Bug#760596: ITP: obfs4proxy -- pluggable transport proxy for Tor, implementing obfs4

2014-09-05 Thread Jérémy Bobbio
Package: wnpp Severity: wishlist Owner: Jérémy Bobbio lu...@debian.org X-Debbugs-Cc: pkg-anonymity-to...@lists.alioth.debian.org * Package name: obfs4proxy Version : 0.0.1 Upstream Author : Yawning Angel yawn...@torproject.org * URL : https://gitweb.torproject.org

Bug#766384: debhelper: please register conffiles in a stable order

2014-10-22 Thread Jérémy Bobbio
Package: debhelper Version: 9.20141010 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain fileordering Hi! As part of the “reproducible builds” effort [1], we have noticed that dh_installdeb is registering conffiles depending on the file system

Bug#766736: geoip-database: outdated license information; more databases could be in main!

2014-10-25 Thread Jérémy Bobbio
Package: geoip-database Hi! According to http://dev.maxmind.com/geoip/legacy/geolite/, “The GeoLite databases are distributed under the Creative Commons Attribution-ShareAlike 3.0 Unported License”. This probably means that debian/copyright should be updated. But this also means that all

Bug#764550: ooniprobe: ooniresources fails with ImportError: No module named processors

2014-10-10 Thread Jérémy Bobbio
Control: tags -1 + fixed-upstream Matt Kraai: As described in the ooniprobe README, I ran sudo ooniresources --update-inputs --update-geoip which failed with the following error message: Traceback (most recent call last): File /usr/bin/ooniresources, line 11, in module from

Bug#764721: dpkg-dev: dpkg-shlibdeps does not output the minimum dependency when a package does not use any symbols

2014-10-10 Thread Jérémy Bobbio
Package: dpkg-dev Version: 1.17.16 Severity: minor Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain randomness Hi! As part of the “reproducible builds” effort [1], I came to investigate a couple of failures related to dpkg-shlibdeps. An example is visible in the

Bug#765343: systemd: localed wrote a /etc/default/keyboard withouth XKBMODEL

2014-10-14 Thread Jérémy Bobbio
Package: systemd Version: 215-5+b1 Hi! What happened: 1. Install Debian with GNOME desktop using Jessie d-i beta 2. 2. Upgrade to sid. 3. Add new layouts in Input Sources through the Region Language interface. 4. Install Plymouth. 5. Restart. 6. Be unable to enter disk passphrase. I hadn't

Bug#762388: ifupdown: please make method order deterministic when generating C code

2014-09-21 Thread Jérémy Bobbio
methods in stable order when generating C code to make +builds reproducible. + + -- Jérémy Bobbio lu...@debian.org Sun, 21 Sep 2014 18:19:56 + + ifupdown (0.7.48.1) unstable; urgency=low * Add --ignore-errors option. diff -Nru ifupdown-0.7.48.1/defn2c.pl ifupdown-0.7.48.2~reproducible1

Bug#762397: libgpg-error: please do not capture the current time during the build process

2014-09-21 Thread Jérémy Bobbio
in order +to get reproducible builds. + + -- Jérémy Bobbio lu...@debian.org Sun, 21 Sep 2014 20:37:15 + + libgpg-error (1.16-1) unstable; urgency=medium * New upstream release diff -Nru libgpg-error-1.16/debian/patches/series libgpg-error-1.16/debian/patches/series --- libgpg-error

Bug#762433: lsof: please stop capturing environment information during the build process

2014-09-22 Thread Jérémy Bobbio
+dfsg-1.0reproducible1) UNRELEASED; urgency=medium + + * Allow LSOF_CCDATE to be overriden by an environment variable. + * Ensure build reproducibility by preventing Configure to capture +username, hostname, kernel version, and build time. + + -- Jérémy Bobbio lu...@debian.org Mon, 22 Sep 2014

Bug#762397: [Reproducible-builds] Bug#762397: libgpg-error: please do not capture the current time during the build process

2014-09-22 Thread Jérémy Bobbio
Jeroen Dekkers: Jérémy actually already wrote a patch for dpkg-buildpackage to export DEB_BUILD_TIMESTAMP: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=75 But if we want to push these things upstream, wouldn't it be better to remove the DEB_ prefix from the name of the

Bug#762622: discount: please mangle email addresses deterministically

2014-09-23 Thread Jérémy Bobbio
Package: discount Version: 2.1.7-1 Severity: wishlist Tags: patches Forwarded: https://github.com/Orc/discount/pull/112 User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness Hi! As part of the “reproducible builds” project [1], we have identified that currently discount output

Bug#762622: [Reproducible-builds] Bug#762622: discount: please mangle email addresses deterministically

2014-09-23 Thread Jérémy Bobbio
Control: tags -1 + patch Jérémy Bobbio: The attached patch changes the `mangle()` function accordingly. For real, this time. -- Lunar.''`. lu...@debian.org: :Ⓐ : # apt-get install anarchism

Bug#762666: cwidget: please stop writing timestamps in Doxygen generated documentation

2014-09-24 Thread Jérémy Bobbio
to be reproducible. + + -- Jérémy Bobbio lu...@debian.org Wed, 24 Sep 2014 09:05:52 + + cwidget (0.5.17-1) unstable; urgency=medium * New upstream release diff -Nru cwidget-0.5.17/debian/patches/do-not-write-timestamps-in-documentation cwidget-0.5.17/debian/patches/do-not-write-timestamps

Bug#762674: python-apt: please don't embed the date and time of the build in apt_pkg

2014-09-24 Thread Jérémy Bobbio
+unreproducible. + + -- Jérémy Bobbio lu...@debian.org Wed, 24 Sep 2014 10:08:36 + + python-apt (0.9.3.10) unstable; urgency=medium * python/tag.cc: ensure that the final \n is there when diff -Nru python-apt-0.9.3.10/python/apt_pkgmodule.cc python-apt-0.9.3.10.0reproducible1/python

Bug#762732: libdebian-installer: please do not write timestamps in Doxygen generated documentation

2014-09-24 Thread Jérémy Bobbio
in Doxygen generated documentation for +reproducibility of the build process. + + -- Jérémy Bobbio lu...@debian.org Wed, 24 Sep 2014 19:08:26 + + libdebian-installer (0.96) unstable; urgency=medium * arm64: Detect UEFI based systems as efi subarch. diff -Nru libdebian-installer-0.96/doc

Bug#762854: groff: please provide a way to specify a creation date

2014-09-25 Thread Jérémy Bobbio
Package: groff Version: 1.22.2-8 Severity: wishlist User: reproducible-bui...@lists.alioth.debian.org Usertags: toolchain timestamps Hi! For the reasons outlined in https://lists.gnu.org/archive/html/groff/2014-08/msg00112.html, it would be great if groff could be given a creation date instead

Bug#762666: cwidget: please stop writing timestamps in Doxygen generated documentation

2014-09-27 Thread Jérémy Bobbio
Manuel A. Fernandez Montecelo: As part of the “reproducible builds” project [1], we have discovered that the documentation generated by Doxygen during cwidget build process contained timestamps. Together with #762622, this prevents cwidget builds to be reproducible. We believe that

Bug#763328: [Reproducible-builds] Bug#763328: RFP: reproducible/misc.git

2014-09-30 Thread Jérémy Bobbio
Control: retitle -1 RFP: debbindiff Holger Levsen: please package git.debian.org/git/reproducible/misc.git - I mostly care about having the diffp tool installable via apt-get, so maybe move this into an existing package instead? But then I believe the other stuff is also useful, hence this

Bug#763699: keepassx: please use source mtime as creation date when generating icons

2014-10-01 Thread Jérémy Bobbio
-maintainer upload. + * Use source file mtime as creation and modfication time while converting +icons for build reproducibility. + + -- Jérémy Bobbio lu...@debian.org Wed, 01 Oct 2014 21:54:51 + + keepassx (0.4.3+dfsg-0.1) unstable; urgency=high * Non-maintainer upload. diff -Nru

Bug#763822: ftp.debian.org: please include .buildinfo file in the archive

2014-10-02 Thread Jérémy Bobbio
Package: ftp.debian.org Severity: wishlist User: ftp.debian@packages.debian.org Usertags: archive Hi! As part of the “reproducible builds” effort [1], we came up with the idea of a new control file, currently named “.buildinfo” .buildinfo files would capture from the build environment as

Bug#719845: [PATCH] Deterministic file order for control and data archives

2014-10-06 Thread Jérémy Bobbio
Jérémy Bobbio: Here are four patches based on the current master (1e059955) that will write files in deterministic order in the control and data archives. File names are sorted by forking `sort` before being piped to `tar`. Attached are the patch based on current master (36eda4c1bc

Bug#759999: dpkg: please set reproducible timestamps in .deb ar file headers

2014-10-06 Thread Jérémy Bobbio
Jérémy Bobbio: The first patch will modify `dpkg-deb` to use the same timestamp for every member of the ar archive. The second patch will: 1. Make `dpkg-deb` try to look for a timestamp to use in the DEB_BUILD_TIMESTAMP environment variable in epoch format. If not set

Bug#764251: socat: please set the build timestamp to a deterministic time

2014-10-06 Thread Jérémy Bobbio
the build date to be set externally, +and set it to the latest debian/changelog entry for reproducibility. + + -- Jérémy Bobbio lu...@debian.org Mon, 06 Oct 2014 17:55:47 +0200 + socat (1.7.2.4-1) unstable; urgency=low * New upstream release, update patches. diff -Nru socat-1.7.2.4/debian

Bug#764251: socat: please set the build timestamp to a deterministic time

2014-10-06 Thread Jérémy Bobbio
Ian Jackson: Jérémy Bobbio writes (Bug#764251: socat: please set the build timestamp to a deterministic time): As part of the “reproducible builds” effort, we have discovered that socat is using the __DATE__ and __TIME__ C pre-processor macro to record the time of the build. This prevent

Bug#769844: linux: please make linux build reproducibly

2014-11-16 Thread Jérémy Bobbio
Source: linux Version: 3.16.7-2 Severity: wishlist User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps randomness Control: block -1 by 759886 Hi! I have been doing some experimentation on making linux build reproducibly [1]. With the attached patches, we are down to three

Bug#769844: linux: please make linux build reproducibly

2014-11-17 Thread Jérémy Bobbio
Bastian Blank: On Mon, Nov 17, 2014 at 12:46:45AM +0100, Jérémy Bobbio wrote: The first patch adds call to `dh_strip_nondeterminism` and `dh_fixmtimes`, both being part of the custom toolchain currently used for reproducible builds. Hence not tagging the bug with “patch” until

Bug#769893: ghc: Make compilation deterministic

2014-11-17 Thread Jérémy Bobbio
user reproducible-bui...@lists.alioth.debian.org usertags 769893 + toolchain randomness Joachim Breitner: It'd be much appreciated if this was applied to 7.6.3, which would affect 300 Haskell packages that are currently not reproducible. glad to hear this! Very good news! :) So

Bug#770213: jenkins.d.n: please create a milestone page for build reproducibility of core packages

2014-11-19 Thread Jérémy Bobbio
Package: qa.debian.org Severity: wishlist Control: user qa.debian@packages.debian.org Control: usertags -1 jenkins Control: user reproducible-bui...@lists.alioth.debian.org Control: usertags -1 infrastructure Hi! As part of the reproducible build pages on jenkins.d.n, it would be great to

Bug#770365: debsources: 403 on /src/beignet/1.0.0-1/README.md/

2014-11-20 Thread Jérémy Bobbio
Package: qa.debian.org Severity: normal User: qa.debian@packages.debian.org Usertags: debsources Hi! When visiting https://sources.debian.net/src/beignet/1.0.0-1/README.md/ I'm told “403 Permission Denied”. This is a bit annoying as the file is listed on

Bug#772029: [Reproducible-builds] Bug#772029: debbindiff: please avoid hardcoded use of VIm

2014-12-04 Thread Jérémy Bobbio
Control: severity -1 wishlist Jonas Smedegaard: I am not a VIm user, however, and its hardcoded use of that editor is strongly discouraging for me (no, I do not use emacs either). Please consider recoding¹ to not rely on VIm-specific features, to appeal also to users of other interactive

Bug#773916: libical: Ship different constant values accross builds

2014-12-25 Thread Jérémy Bobbio
Package: libical-dev Version: 1.0-1.1 Severity: critical User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness Hi! While working on the “reproducible builds” effort [1], we have noticed that libical could not be built reproducibly:

<    3   4   5   6   7   8   9   10   11   >