Bug#535519: libedit2: huge memory leak in fgetln emulation

2009-07-02 Thread Yuriy M. Kaminskiy
Package: libedit2 Version: 2.9.cvs.20050518-2.2 Severity: important Original semantic of fgetln(3) - return buffer owned by stdio (in fact, it just passes pointer inside internal FILE* buffer), and user should not free that buffer. Next call to stdio function may alter/free this buffer. And

Bug#535519: libedit2: huge memory leak in fgetln emulation

2009-07-02 Thread Yuriy M. Kaminskiy
Ewww. Seem same problem with almost same solution already described in http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=358164#13 Nevertheless, bug still present. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#577031: xpdf: scrolling is very slow on i386 (gcc regression between 4.3 and 4.4?)

2010-05-18 Thread Yuriy M. Kaminskiy
On Fri, 7 May 2010 17:19:04 -0400 Michael Gilbert wrote: On Fri, 07 May 2010 22:32:11 +0200 Michael wrote: I pinpointed it down to file PDFCore.cc line 450 ff.: // if the display properties have changed, create a new PDFCorePage // object if (force || pages-getLength() == 0 ||

Bug#577031: xpdf: scrolling is very slow on i386 (gcc regression between 4.3 and 4.4?)

2010-05-18 Thread Yuriy M. Kaminskiy
On 18.05.2010 16:16, Yuriy M. Kaminskiy wrote: On Fri, 7 May 2010 17:19:04 -0400 Michael Gilbert wrote: On Fri, 07 May 2010 22:32:11 +0200 Michael wrote: Try to convert 'aA != a' - 'fabs(aA - a) 0.001' (fine-tune 0.001 depending on err, sorry, stupid mistake, should be 'fabs(aA - a) = 0.001

Bug#577031: xpdf: scrolling is very slow on i386 (gcc regression between 4.3 and 4.4?)

2010-05-20 Thread Yuriy M. Kaminskiy
On Thu, 20 May 2010 00:54:45 +0200, Michael wrote: If I put the printfs in front of the if-statement, the zoom problem vanishes and the correct output (4x false) is given. Sorry, but this clearly points to described problem with extended precision and floating point comparison. Putting

Bug#611141: Error: /undefined in ff

2014-12-22 Thread Yuriy M. Kaminskiy
MESSAGE- Hash: SHA256 NotDashEscaped: You need GnuPG to verify this message From: Yuriy M. Kaminskiy yum...@gmail.com Subject: [PATCH] tiff2ps: fix unassociated alpha and other extrasamples != 0 See: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=611141 Index: tiff-3.9.4/tools/tiff2ps.c

Bug#715892: [Mayhem] Bug report on libtiff-tools: fax2tiff crashes with exit status 139

2014-12-22 Thread Yuriy M. Kaminskiy
Attached patch fixes issue (improper getopt invocation, -r option requires argument) -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 NotDashEscaped: You need GnuPG to verify this message From: Yuriy M. Kaminskiy yum...@gmail.com Subject: fax2tiff: option -r requires argument Fixes SIGSEGV

Bug#611141: Error: /undefined in ff

2014-12-27 Thread Yuriy M. Kaminskiy
Yuriy M. Kaminskiy wrote: Problem was lack of proper handling for EXTRASAMPLE_UNASSOCALPHA in tiff2ps. Attached patch should fix this and related issues (should be applicable to 3.9.latest and 4.0.latest) Warning: only minimal testing passed, likely should be forwarded to and handled

Bug#787824: uim-input-pad-ja: triggers memory consumption in uim-helper-server

2015-06-05 Thread Yuriy M. Kaminskiy
-gtk none -- no debconf information Description: uim-input-ja: read (and ignore) messages from uim-helper-server to avoid clogging its queue Origin: Bug-Debian: Author: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Lst-Update: 2015-05-29 Index: uim-1.8.6/gtk2/pad/ja.c

Bug#754144: elinks: Saving base64 data URIs locally base64-encodes the content instead of base64-decoding

2015-06-02 Thread Yuriy M. Kaminskiy
Trivial patch attached. From: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Subject: [oneline] fix data:..;base64 protocol decoding Index: elinks-0.12pre6/src/protocol/data.c === --- elinks-0.12pre6.orig/src/protocol/data.c +++ elinks

Bug#728951: fam: Please convert the package to multiarch

2015-06-23 Thread Yuriy M. Kaminskiy
: #728951) + + -- Yuriy M. Kaminskiy yumkam+deb...@gmail.com Mon, 22 Jun 2015 04:28:53 +0300 + fam (2.7.0-17.1) unstable; urgency=medium * Non-maintainer upload. diff -u fam-2.7.0/debian/compat fam-2.7.0/debian/compat --- fam-2.7.0/debian/compat +++ fam-2.7.0/debian/compat @@ -1 +1 @@ -7 +8 diff

Bug#789704: gamin: Please convert the package to multiarch

2015-06-23 Thread Yuriy M. Kaminskiy
/changelog 2015-06-22 02:50:32.0 +0300 @@ -1,3 +1,12 @@ +gamin (0.1.10-4.2~local2) UNRELEASED; urgency=medium + + * Non-maintainer upload. + * Convert to multi-arch. + * Convert to dh-autoreconf. + * Transition to dh-python2 + + -- Yuriy M. Kaminskiy yumkam+deb...@gmail.com Mon, 22

Bug#770263: libbs2b0: please convert to multiarch

2015-06-23 Thread Yuriy M. Kaminskiy
I've followed https://wiki.debian.org/Multiarch/Implementation, -dev packages seems suitable for 'MA: same' (I've co-installed :i386 and :amd64 packages without any problem; from rdepends, I've successfully rebuilt mpv and qmmp packages against patched -dev package); debdiff attached. diff

Bug#708832: libgsl0ldbl: Cannot install amd64 and i386 version of the package in parallel

2015-06-24 Thread Yuriy M. Kaminskiy
/changelog 2015-06-25 01:05:05.0 +0300 +++ gsl-1.16+dfsg/debian/changelog 2015-06-24 23:34:06.0 +0300 @@ -1,3 +1,10 @@ +gsl (1.16+dfsg-2+1~local1) UNRELEASED; urgency=medium + + * Non-maintainer upload. + * Add multi-arch support. (Closes: #708832) + + -- Yuriy M

Bug#789322: /usr/bin/pmap: [pmap] integer overflow on maps over 2GiB on 32-bit platform

2015-06-19 Thread Yuriy M. Kaminskiy
-smaps.txt.gz Description: application/gzip From: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Subject: [pmap] fix integer overflow on 2GiB+ maps on 32-bit platforms Index: procps-3.3.9/pmap.c === --- procps-3.3.9.orig/pmap.c +++ procps-3.3.9

Bug#789745: graphicsmagick: please enable WebP suppport

2015-06-23 Thread Yuriy M. Kaminskiy
Package: graphicsmagick Version: 1.3.20-3+deb8u1 Severity: wishlist Tags: patch Dear Maintainer, grapicsmagick has WebP support, but it is not enabled in debian package. It boils down to twiddling Build-Depends (and .symbols), see attached. [Or, converse, it should be explicitly disabled by

Bug#787208: libuim8: uim-helper-server constantly consumes memory due to unclosed socket after exec() in client

2015-05-29 Thread Yuriy M. Kaminskiy
Package: libuim8 Version: 1:1.8.6-8 Severity: normal Dear Maintainer, When uim client exec() to long-running process (e.g. iceweasel restarts), it leaks open socket to uim-helper-server, and by then uim-helper-server begins to constantly consume memory, as it cannot write to those sockets

Bug#790325: libxaw7: obtaining textSink.textProperties by editres triggers sigsegv in application

2015-06-27 Thread Yuriy M. Kaminskiy
2:1.6.2-3 ii libxext6 2:1.3.3-1 ii libxmu62:1.1.2-1 ii libxpm41:3.5.11-1+b1 ii libxt6 1:1.1.4-1+b1 ii multiarch-support 2.19-18 libxaw7 recommends no packages. libxaw7 suggests no packages. -- no debconf information From: Yuriy M

Bug#708832: libgsl0ldbl: Cannot install amd64 and i386 version of the package in parallel

2015-07-01 Thread Yuriy M. Kaminskiy
On 25.06.2015 01:13, Yuriy M. Kaminskiy wrote: Patch (debdiff) to add Multi-Arch support attached (I've followed https://wiki.debian.org/Multiarch/Implementation), passes very limited check (coinstallation of :i386 and :amd64 runtime packages). Current limitations: *-dev is not multi-arch yet

Bug#786576: mpv: --vo=opengl-old:rectangle=1 fails to render OSD

2015-05-24 Thread Yuriy M. Kaminskiy
On 23.05.2015 14:03, Alessandro Ghedini wrote: On sab, mag 23, 2015 at 03:02:17 +0300, Yuriy M. Kaminskiy wrote: Package: mpv Version: 0.6.2-2 Severity: normal Dear Maintainer, mpv --vo=opengl-old fails to render OSD (draws empty rectangles instead) when sub-option rectangle is 1 (it is set

Bug#786718: libmpg123: incorrect check/decoding for utf-16 surrogates in id3 parser

2015-05-24 Thread Yuriy M. Kaminskiy
: libmpg123/id3.c: fix utf-16 decode Author: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Index: mpg123-1.20.1/src/libmpg123/id3.c === --- mpg123-1.20.1.orig/src/libmpg123/id3.c +++ mpg123-1.20.1/src/libmpg123/id3.c @@ -1051,10 +1051,10

Bug#786572: mpv: always dies in assert() on --vo=opengl-old:force-pbo=yes

2015-05-22 Thread Yuriy M. Kaminskiy
information Description: Fix assertion with --vo=opengl-old:force-pbo=yes Origin: vendor Debian-Bug: http://bugs.debian.org/? Forwarded: not-needed Author: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Last-Update: 2015-05-22 Index: mpv-0.6.2/video/out/vo_opengl_old.c

Bug#786576: mpv: --vo=opengl-old:rectangle=1 fails to render OSD

2015-05-22 Thread Yuriy M. Kaminskiy
with --vo=opengl-old:rectangle=1 Origin: vendor Debian-Bug: http://bugs.debian.org/? Forwarded: not-needed Author: Yuriy M. Kaminskiy yumkam+deb...@gmail.com Last-Update: 2015-05-22 Index: mpv-0.6.2/video/out/vo_opengl_old.c

Bug#794798: libnspr4-dev: pthread missing from pkg-config lib deps

2015-08-07 Thread Yuriy M. Kaminskiy
Mike Hommey wrote: On Thu, Aug 06, 2015 at 04:37:06PM -0500, D. Jared Dominguez wrote: On Thu, Aug 06, 2015 at 03:46:39PM -0500, Mike Hommey wrote: On Thu, Aug 06, 2015 at 01:42:55PM -0500, Daniel Jared Dominguez wrote: Package: libnspr4-dev Version: 2:4.10.8-2 Severity: important pkg-config

Bug#793642: sidplay-libs: please add Multi-Arch support

2015-07-25 Thread Yuriy M. Kaminskiy
+++ sidplay-libs-2.1.1/debian/changelog 2015-07-24 16:52:13.0 +0300 @@ -1,3 +1,11 @@ +sidplay-libs (2.1.1-14+1~local1) UNRELEASED; urgency=medium + + * Non-maintainer upload. + * Updated to debhelper 9. + * Added Multi-Arch support. + + -- Yuriy M. Kaminskiy yumkam+deb...@gmail.com Fri, 24 Jul

Bug#638974: libsqlite3-dev: A call to sqlite3_open() gives a SIGSEGV

2015-07-14 Thread Yuriy M. Kaminskiy
On 14.07.2015 11:23, László Böszörményi (GCS) wrote: Hi, On Tue, Jul 14, 2015 at 2:58 AM, Yuriy M. Kaminskiy yum...@gmail.com wrote: Package: libsqlite3-dev Version: 3.8.7.1-1+deb8u1 Followup-For: Bug #638974 1) I was able to reproduce this bug in jessie's 3.8.7.1 (gdb and valgrind report

Bug#736463: libsqlite3-0: UNIQUE PRIMARY KEY + WITHOUT ROWID = segfault

2015-07-14 Thread Yuriy M. Kaminskiy
Package: libsqlite3-dev Version: 3.8.7.1-1+deb8u1 Followup-For: Bug #736463 (was sent to unrelated bug, resenting, sorry) 1) I was able to reproduce this bug in jessie's 3.8.7.1 (gdb and valgrind report attached); 2) I was *NOT* able to reproduce it in (self-backported) sid's 3.8.10.2-1 (and

Bug#736463: libsqlite3-0: UNIQUE PRIMARY KEY + WITHOUT ROWID = segfault

2015-07-14 Thread Yuriy M. Kaminskiy
On 14.07.2015 14:36, László Böszörményi (GCS) wrote: On Tue, Jul 14, 2015 at 11:41 AM, Yuriy M. Kaminskiy yum...@gmail.com wrote: Package: libsqlite3-dev Version: 3.8.7.1-1+deb8u1 Followup-For: Bug #736463 (was sent to unrelated bug, resenting, sorry) 1) I was able to reproduce this bug

Bug#736463: libsqlite3-0: UNIQUE PRIMARY KEY + WITHOUT ROWID = segfault

2015-07-14 Thread Yuriy M. Kaminskiy
control: tag -1 patch thanks On 14.07.2015 15:34, Yuriy M. Kaminskiy wrote: On 14.07.2015 14:36, László Böszörményi (GCS) wrote: On Tue, Jul 14, 2015 at 11:41 AM, Yuriy M. Kaminskiy yum...@gmail.com wrote: Package: libsqlite3-dev Version: 3.8.7.1-1+deb8u1 Followup-For: Bug #736463 (was sent

Bug#792827: geoip-bin: geoip-generator-asn produces malformed database

2015-07-18 Thread Yuriy M. Kaminskiy
Package: geoip-bin Version: 1.6.2-4 Severity: normal Dear Maintainer, E.g., with geoip-database-extra_20150317-1 $ geoiplookup -i 37.229.162.60 GeoIP Country Edition: UA, Ukraine ... GeoIP ASNum Edition: AS714 Apple Inc. Error Traversing Database for ipnum = 635806267 - Perhaps database is

Bug#638974: libsqlite3-dev: A call to sqlite3_open() gives a SIGSEGV

2015-07-13 Thread Yuriy M. Kaminskiy
Package: libsqlite3-dev Version: 3.8.7.1-1+deb8u1 Followup-For: Bug #638974 FYI: 1) I was able to reproduce this bug in jessie's 3.8.7.1 (gdb and valgrind report attached); 2) I was *NOT* able to reproduce it in (self-backported) sid's 3.8.10.2-1 (and running under valgrind does not show any

Bug#792515: sqlite3: dpkg-shlibdeps: warning: package could avoid a useless dependency

2015-07-15 Thread Yuriy M. Kaminskiy
Package: sqlite3 Version: 3.8.7.1-1+deb8u1 Severity: wishlist Tags: patch Dear Maintainer, When rebuilding package, I noticed dpkg-shlibdeps warnings about unnecessary dependencies on libncurses5, libtinfo5 in sqlite3 package, which could be avoided with --as-needed linker option, see

Bug#808333: transmission-daemon: SIGSEGV due to racing in list node allocation

2015-12-18 Thread Yuriy M. Kaminskiy
Package: transmission-daemon Version: 2.84-0.2 Severity: normal Tags: patch upstream fixed-upstream Dear Maintainer, transmission-daemon died on SIGSEGV (probably triggered by starting torrent with webseed), backtrace seems same as in upstream ticket

Bug#774012: Still is not fixed for jessie (Re: systemd: Program terminated with signal SIGFPE, Arithmetic exception)

2015-12-28 Thread Yuriy M. Kaminskiy
This bug is still present in jessie's systemd 215-17+deb8u1 (backtrace is same).

Bug#825378: perl: freeze on parsing (broken) code

2016-05-28 Thread Yuriy M. Kaminskiy
Control: tags -1 patch thanks On 28.05.2016 17:50, Dominic Hargreaves wrote: On Thu, May 26, 2016 at 04:47:07PM +0100, Dominic Hargreaves wrote: On Thu, May 26, 2016 at 04:22:45PM +0300, Yuriy M. Kaminskiy wrote: Dear Maintainer, I've made typo in code, and found that it freezes perl

Bug#825378: perl: freeze on parsing (broken) code

2016-05-26 Thread Yuriy M. Kaminskiy
Package: perl Version: 5.20.2-3+deb8u4 Severity: normal Tags: jessie Dear Maintainer, I've made typo in code, and found that it freezes perl on attempt to parse: perl -ce 's{foo}{$h->X({->aaa=>"b"},$d)}ge' ( it was meant to be 's{foo}{$h->X({-aaa=>"b"},$d)}ge' ) gdb backtrace

Bug#774012: Still is not fixed for jessie (Re: systemd: Program terminated with signal SIGFPE, Arithmetic exception)

2016-01-16 Thread Yuriy M. Kaminskiy
On 28.12.2015 16:15, Michael Biebl wrote: Am 28.12.2015 um 13:33 schrieb Yuriy M. Kaminskiy: This bug is still present in jessie's systemd 215-17+deb8u1 (backtrace is same). If someone, who is able to reproduce the issue, is willing to backport the necessary changes to v215, I'd be willing

Bug#813879: systemd: Assertion 's->exec_command[SERVICE_EXEC_START]' failed service_enter_start()

2016-02-07 Thread Yuriy M. Kaminskiy
Package: systemd Version: 215-17+deb8u3 Severity: important Dear Maintainer, systemd crash badly while removing systemd-cron and installing cron. It does not respond anymore and reboot is not working. Installing systemd-cron Feb 05 20:45:48 debir systemd[1]: Reloading. Feb 05 20:45:49

Bug#813879: systemd: Assertion 's->exec_command[SERVICE_EXEC_START]' failed service_enter_start()

2016-02-08 Thread Yuriy M. Kaminskiy
On 08.02.2016 02:15, Yuriy M. Kaminskiy wrote: Package: systemd Version: 215-17+deb8u3 Severity: important Probably related: cron-update.service is triggered by some /etc/cron* directories change and invokes `systemctl daemon-reload` and `systemctl try-restart cron.target`. Maybe

Bug#814239: gcc-4.9: debian/patches/ada-symbolic-tracebacks.diff use snprintf return value without check

2016-02-09 Thread Yuriy M. Kaminskiy
Package: gcc-4.9 Version: 4.9.2-10 Severity: normal Tags: security During code search, I found potentially problematic code in debian/patches/ada-symbolic-tracebacks.diff: it uses snprintf() results without checking its range, like this: +else { + *len += snprintf(s,

Bug#815016: iceweasel: Crashes randomly when playing videos on YouTube

2016-02-17 Thread Yuriy M. Kaminskiy
Backtrace looks similar to (unresolved) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=799632

Bug#817210: systemd-resolve: segfaults upon domain name resolution

2016-03-09 Thread Yuriy M. Kaminskiy
On 03/09/16, Rostislav Pehlivanov wrote: > Upgrading to the latest libnss3 (3.23) fixes the problem. libnss3 is crypto library by mozilla, it is not related anyhow to name resolution and glibc nss subsystem, it is not used by systemd, and very unlikely to affect this bug anyhow. So, if this

Bug#721321: [libgnutls26] Breaks SSL tracker support in Transmission

2016-03-13 Thread Yuriy M. Kaminskiy
1) There are no ssl-specific code in transmission, it is dealt with in curl. So, if any, it is a *curl* bug that affects transmission; 2) curl bug was supposed to be fixed and reappeared several times, last reincarnation is http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=818126 (affects

Bug#818131: curl: broken as-needed workaround (warning: package could avoid a useless dependency)

2016-03-13 Thread Yuriy M. Kaminskiy
Source: curl Version: 7.38.0-4+deb8u3 Severity: normal Tags: patch Dear Maintainer, While rebuilding (jessie) curl package in pbuilder, I noticed some warning: package could avoid a useless dependency [...] (fragment of log attached). curl package is built with -Wl,--as-needed linker flag,

Bug#818126: libcurl3-gnutls: https connection is broken by (harmless) TLS Alert messages

2016-03-13 Thread Yuriy M. Kaminskiy
Package: libcurl3-gnutls Version: 7.38.0-4+deb8u3 Severity: normal Tags: upstream patch jessie Dear Maintainer, TLS Alert processing in curl gnutls backend is broken and return error when server sends (non-fatal) TLS Alert message (e.g. due to unrecognized SNI name). You can test it with

Bug#817247: fatrace: sigsegv on -p option

2016-03-09 Thread Yuriy M. Kaminskiy
Package: fatrace Version: 0.11-1 Severity: normal Tags: patch upstream Dear Maintainer, `fatrace -p 1234` dies with SIGSEGV on line 311, as short-option 'p' is labeled as flag (instead of option-with-argument), so optarg is NULL. Attached trivial patch fixes it. P.S. this regression was

Bug#813879: systemd: Assertion 's->exec_command[SERVICE_EXEC_START]' failed service_enter_start()

2016-03-28 Thread Yuriy M. Kaminskiy
On 08.02.2016 18:18, Yuriy M. Kaminskiy wrote: On 08.02.2016 02:15, Yuriy M. Kaminskiy wrote: Package: systemd Version: 215-17+deb8u3 Severity: important Probably related: cron-update.service is triggered by some /etc/cron* directories change and invokes `systemctl daemon-reload

Bug#820565: nspr: bump minimum PR_*printf version in .symbols to 4.10.9

2016-04-09 Thread Yuriy M. Kaminskiy
Source: nspr Version: 2:4.10.9-1 Severity: wishlist Tags: patch Dear Maintainer, In nspr 4.10.9 [1], PR_*printf (and, implictly, LogPrint) functions was improved to support 'z' (size_t) format modifier. As program that was built with newer version may assume this feature is supported, and

Bug#820206: imlib2: potentially exploitable integer overflows

2016-04-06 Thread Yuriy M. Kaminskiy
Source: imlib2 Version: 1.4.6-2+deb8u1 Severity: important Tags: security jessie upstream fixed-upstream patch Dear Maintainer, imlib2 commit v1.4.6-19-g143f299 fixes potentially exploitable integer overflow. https://git.enlightenment.org/legacy/imlib2.git/commit/?id=143f299 Please apply this

Bug#819290: systemd[1]: Caught , dumped core ...

2016-03-26 Thread Yuriy M. Kaminskiy
Disclaimer: not a systemd maintainer. > 2.) A.) Unfortunately, backtrace without symbol information is not exactly useful, especially since introduction of ASLR. If you kept core, please install systemd-dbg/-dbgsym package and redo gdb backtrace. > If I understand correctly Lennart might look

Bug#819290: Stack trace with symbols

2016-03-26 Thread Yuriy M. Kaminskiy
On 27.03.2016 03:36, Kingsley G. Morse Jr. wrote: Hi Yuriy, OK, that all makes sense. Here's the full trace with symbols: #8 0x8017f167 in path_compare (a=, b=0x0) at ../src/basic/path-util.c:390 d = __PRETTY_FUNCTION__ = "path_compare" so, it assert() as `b == NULL`

Bug#819290: Stack trace with symbols

2016-03-26 Thread Yuriy M. Kaminskiy
On 27.03.2016 05:01, Yuriy M. Kaminskiy wrote: On 27.03.2016 03:36, Kingsley G. Morse Jr. wrote: Hi Yuriy, OK, that all makes sense. Here's the full trace with symbols: #8 0x8017f167 in path_compare (a=, b=0x0) at ../src/basic/path-util.c:390 d = __PRETTY_FUNCTION__

Bug#814768: libsqlite3-0: Wrong handle of relative symbolic links

2016-04-02 Thread Yuriy M. Kaminskiy
As sqlite needs to create -journal or -wal/-shm files in same directory as database, if you symlink, hardlink, (and any possible variation, like mount --bind, overlayfs, fuse, network mounts, 9p, etc) database to different names, and attempt to access them at once, things will break. In a hard

Bug#799959: /usr/bin/transmission-daemon: segfaults shortly after hibernate/resume

2016-04-01 Thread Yuriy M. Kaminskiy
My 5 cents after quick look at backtrace and transmission sources: It could be totally wrong (if you still have core file around, please show results from info reg all disas $pc-40,$pc+40 up 2 p *server in gdb), but my current pet theory: 0) There are clearly nonsense in iovec; this

Bug#785369: [SECURITY] libimlib2: GIF loader: out-of-bounds read

2016-03-31 Thread Yuriy M. Kaminskiy
(redundant with CVE-2014-9762.patch). + * Fix out-of-bound read from colormap. (Closes: #785369) + * Drop now-redundant CVE-2014-9762.patch. + + -- Yuriy M. Kaminskiy <yumkam+deb...@gmail.com> Thu, 31 Mar 2016 17:53:34 +0300 + imlib2 (1.4.6-2+deb8u1) jessie-security; urgency=high * Non-main

Bug#819818: libimlib2: off-by-one OOB read in __imlib_MergeUpdate

2016-04-02 Thread Yuriy M. Kaminskiy
Package: libimlib2 Version: 1.4.6-2+deb8u1 Severity: normal Tags: upstream patch Dear Maintainer, 1) I re-compiled imlib2 package with debug information, 2) compiled and installed tests (data, src/bin), 3) run `valgrind imlib2_test`, 4) moved mouse to right lower corner of window; ==16086==

Bug#639414: libimlib2: divide-by-zero on 2x1 ellipse

2016-03-31 Thread Yuriy M. Kaminskiy
based on untrusted input). Description: fix divide-by-zero on drawing 2x1 ellipse Author: Yuriy M. Kaminskiy <yumkam+deb...@gmail.com> Note: resulting images are probably incorrect; but SIGFPE is certainly worse. Index: imlib2-1.4.6/src/lib/ell

Bug#819693: iptables-persistent: [systemd] netfilter is loaded concurrently with ifupdown

2016-03-31 Thread Yuriy M. Kaminskiy
-persistent/autosave_v6: true * iptables-persistent/autosave_v4: true >From 82dc31e1af9e9eede0959e8ce02e5335482031d2 Mon Sep 17 00:00:00 2001 From: "Yuriy M. Kaminskiy" <yum...@gmail.com> Date: Tue, 29 Mar 2016 07:41:14 +0300 Subject: [PATCH] Fix systemd service dependency As

Bug#820947: Probable culprit (Re: smbclient: [regression] pulls the server package "samba" via samba-libs since 2:4.2.10+dfsg-0+deb8u1 (DSA 3548-1))

2016-04-13 Thread Yuriy M. Kaminskiy
Disclaimer: totally untested I think this is fallout from commit http://anonscm.debian.org/cgit/pkg-samba/samba.git/patch/?id=86c240fa29936a5fe0472c906dce487855c52d70 that was fixed by http://anonscm.debian.org/cgit/pkg-samba/samba.git/patch/?id=e66461c503009af5e63cbb9b428 and

Bug#822740: ceph: please use Multi-Arch for libraries

2016-04-26 Thread Yuriy M. Kaminskiy
Package: librados2 Version: 0.80.7-2+deb8u1 Severity: normal Tags: patch Dear Maintainer, Please enable multi-arch for libraries (they are already installed in multi-arch locations, but not marked as multi-arch same). Patch attached (only shared libraries and respective dbg[*] packages are

Bug#822992: squid3: please avoid installing pinger with suid-root when possible

2016-04-29 Thread Yuriy M. Kaminskiy
Package: squid3 Version: 3.5.16-1 Severity: normal Tags: patch Dear Maintainer, Since squid 3.5.16, squid properly handles when pinger helper is installed with raised capabilities instead of setuid-root. Please avoid installing pinger as suid root when possible, patch attached. diff -Nru

Bug#822998: squid3: warning: package could avoid a useless dependency [...]

2016-04-29 Thread Yuriy M. Kaminskiy
Source: squid3 Version: 3.5.17-1 Severity: minor Tags: patch Dear Maintainer, While rebuilding squid package, I noticed some warnings: ... dpkg-shlibdeps: warning: package could avoid a useless dependency if debian/squidclient/usr/bin/squidclient was not linked against libnettle.so.* (it uses

Bug#650458: rsvg-convert: Error parsing option -b

2016-04-25 Thread Yuriy M. Kaminskiy
This seems was fixed somewhere between wheezy (2.36, only checked sources, likely broken) and jessie (2.40.5, tested, seems fixed): as of jessie `rsvg-convert -b white` works as expected, and there are no traces of base-uri options in sources anymore (by NEWS, probably in 2.39.0, when loading

Bug#824963: systemd-fsck run fsck for same disk in parallel

2016-05-21 Thread Yuriy M. Kaminskiy
Package: systemd Version: 215-17+deb8u4 Severity: wishlist Tags: jessie patch fixed-upstream Dear Maintainer, When mounting several filesystems, systemd runs all fsck in parallel. This is very unoptimal when filesystems shares same (rotational) physical disk. systemd-fsck had provision to

Bug#799916: libjbig2dec0 is not Multi-Arch compatible

2016-05-16 Thread Yuriy M. Kaminskiy
On 16.05.2016 19:24, Jonas Smedegaard wrote: Hi Yuriy, Quoting Yuriy M. Kaminskiy (2016-05-16 17:17:04) Patch (against 0.13-1) attached. I believe your patch is flawed, however: the arch-specific jbig2dec package should not be marked "foreign" as it is unusable by foreign arc

Bug#824483: libjbig2dec0: unused and unrelated Memento memory debugging code

2016-05-16 Thread Yuriy M. Kaminskiy
; urgency=medium + + * Non-maintainer upload. + * Don't compile unrelated and unusable Memento memory debugging code. + + -- Yuriy M. Kaminskiy <yumkam+deb...@gmail.com> Mon, 16 May 2016 17:58:34 +0300 + jbig2dec (0.13-1) unstable; urgency=medium [ upstream ] diff -Nru jbig2dec-0.13/

Bug#799916: libjbig2dec0 is not Multi-Arch compatible

2016-05-16 Thread Yuriy M. Kaminskiy
Control: tags -1 patch thanks Patch (against 0.13-1) attached. diff -Nru jbig2dec-0.13/debian/control jbig2dec-0.13/debian/control --- jbig2dec-0.13/debian/control2016-05-10 17:52:21.0 +0300 +++ jbig2dec-0.13/debian/control2016-05-16 18:05:53.0 +0300 @@ -24,6

Bug#824160: p7zip: CVE-2016-2334 CVE-2016-2335

2016-05-13 Thread Yuriy M. Kaminskiy
> Can you check it actually affects [...] According to http://www.talosintel.com/reports/* (as linked from tracker), CVE-2016-2334 affects HFS+ parser and CVE-2016-2335 UDF parser. Both are *not* part of platform specific code and thus should be part of p7zip. According to upstream changelog,

Bug#765828: x11-utils: xprop -spy leaks memory

2016-04-16 Thread Yuriy M. Kaminskiy
Control: tags -1 fixed-upstream thanks This bug should be fixed upstream by commits from 4f748e3d2b1368ec0590a413ba5f7addc5e3344f to fa732adbbf5e29f4bb230e9b7c0c91ccb4b5af7e (not yet in any released version, AFAIK).

Bug#505893: x11-utils: xmessage ignores locale encoding

2016-04-19 Thread Yuriy M. Kaminskiy
Control: found -1 x11-utils/7.7+2 Control: tags -1 patch thanks For the record: 1) xmessage 1.0.4 was included in 7.7+1 2) ...however, as of jessie, xmessage seems still broken; 3) I've found workaround: python -c 'print u"aix\xf2".encode("utf-8")' | \ xmessage -xrm '*international:true'

Bug#378779: xmessage -default ignores -print

2016-04-19 Thread Yuriy M. Kaminskiy
Control: tags -1 patch Control: found -1 x11-utils/7.7+2 thanks Still present in jessie. Attached patch should fix it. >From f4ef2e191e39c7a2de5902d761e4103dfa571074 Mon Sep 17 00:00:00 2001 From: "Yuriy M. Kaminskiy" <yum...@gmail.com> Date: Wed, 20 Apr 2016 03:51:46 +0

Bug#838420: gifsicle: incorrect escape for 8-bit characters on platforms with signed char

2016-09-20 Thread Yuriy M. Kaminskiy
Package: gifsicle Version: 1.86-1 Severity: minor Tags: upstream patch Dear Maintainer, When showing comment containing non-ASCII characters, `gifsicle -I` shows incorrect escape code (\364 instead of \364) on platforms with signed char (e.g. x86{,_64}). Patches against 1.86 and 1.88

Bug#841935: pbuilder: incorrect permissions on /dev/ptmx breaks openpty()

2016-11-06 Thread Yuriy M. Kaminskiy
Andreas Henriksson writes: It seems /dev/ptmx has incorrect permissions in a pbuilder chroot: # ls -l /dev/ptmx lrwxrwxrwx 1 root root 8 Oct 4 06:43 /dev/ptmx -> pts/ptmx # ls -l /dev/pts/ptmx c- 1 root root 5, 2 Oct 24 14:46 /dev/pts/ptmx Please compare to what's

Bug#841935: pbuilder: incorrect permissions on /dev/ptmx breaks openpty()

2016-11-06 Thread Yuriy M. Kaminskiy
On 06.11.2016 23:41, James Clarke wrote: On 6 Nov 2016, at 20:34, Yuriy M. Kaminskiy <yum...@gmail.com> wrote: Andreas Henriksson <andr...@fatal.se> writes: It seems /dev/ptmx has incorrect permissions in a pbuilder chroot: # ls -l /dev/ptmx lrwxrwxrwx 1 root root 8 Oct 4 06:

Bug#843762: rcs: SIGSEGV on rcs -u1.2 -l1.1 foo

2016-11-09 Thread Yuriy M. Kaminskiy
Control: tag -1 patch thanks On 09.11.2016 13:31, Yuriy M. Kaminskiy wrote: Program received signal SIGSEGV, Segmentation fault. 0x565629a2 in extend (tp=0x0, x=0xd8a2, to=0x565a00b0) at b-esds.c:39 39 EXTEND_BODY (link); I looked a bit more at EXTEND_BODY macro and *extend functions

Bug#843176: libgtk-3-0: "Invalid column number ... added to iter" in GTK+ Inspector

2016-11-04 Thread Yuriy M. Kaminskiy
Package: libgtk-3-0 Version: 3.14.5-1+deb8u1 Severity: normal Tags: upstream jessie patch fixed-upstream Dear Maintainer, While running wireshark from jessie-backports with GTK+ Inspector enabled (`GTK_DEBUG=interactive wireshark-gtk`) I got large number of (wireshark-gtk:3784): Gtk-WARNING

Bug#840510: geoip-generator-asn: broken ASN due to csv misparsing

2016-10-12 Thread Yuriy M. Kaminskiy
Package: geoip-bin Version: 1.6.2-4 Severity: normal Tags: patch Dear Maintainer, I noticed that some ASN looks mangled (first and last character cut off, e.g. `geopiplookup 163.172.217.0|tail -1` -> 'GeoIP ASNum Edition: S1287' [it should've been 'GeoIP ASNum Edition: AS12876']) and

Bug#840510: geoip-generator-asn: broken ASN due to csv misparsing

2016-10-12 Thread Yuriy M. Kaminskiy
On 12.10.2016 13:58, Yuriy M. Kaminskiy wrote: P.S. ASN/ipv6 change in patch is completely untested (it seems produces mangled database [as before]). oops, above ipv6 issue was my patch fault, patch v2 attached, now $ wget -q http://download.maxmind.com/download/geoip/database/asnum

Bug#831467: This "fix" is totally bogus and should be reverted ASAP

2017-03-29 Thread Yuriy M. Kaminskiy
As noted in (forwarded) github issue, this "fix" is totally bogus and (likely) breaks things. ExecStop command is expected to kill daemon (in a friendly way), while (default handler for) kill(SIGSTOP) pauses/freezes/suspends process execution (and transmission-daemon does not override default

Bug#869924: irqbalance: would it be reasonable to make irqbalance Multi-Arch:foreign ?

2017-07-31 Thread Yuriy M. Kaminskiy
Disclaimer: I'm not (this or any package) maintainer, TMMV. There are a number of architecture-dependent #ifdef's in the code (AARCH64 in 1.1.0, __i386__ || __amd64__ in git master), so I think that running foreign-arch irqbalance can be unsafe (well, I guess only practical case when someone

Bug#862338: libsmbclient is not multi-arch co-installable due to samba-libs->python-talloc

2017-05-11 Thread Yuriy M. Kaminskiy
Package: libsmbclient Version: 2:4.2.14+dfsg-0+deb8u5 Severity: normal Dear Maintainer, I tried to install both `libsmbclient:i386` and `libsmbclient:amd64` and failed, as `libsmbclient` (m-a: same) depends on `samba-libs` (m-a: same), and `samba-libs` depends on `python-talloc` (*not*

Bug#863664: uim-gtk2.0: gtk{2,3}/qt/qt5 IM plugins are not multi-arch co-installable

2017-06-22 Thread Yuriy M. Kaminskiy
On 21.06.2017 17:24, d...@debian.org wrote: > Thank you for your detailed reporting! > > On Mon, May 29, 2017 at 11:27:23PM +0300, Yuriy M. Kaminskiy wrote: >> gtk{2,3}, qt and qt5 IM plugins >> /usr/lib/$ARCH/gtk-2.0/2.10.0/immodules/im-uim.so >> /usr/lib/$ARCH/gtk-3.

Bug#865651: par2 is not multi-arch compatible

2017-06-23 Thread Yuriy M. Kaminskiy
Package: par2 Version: 0.6.11-1 Severity: normal Tags: patch Dear Maintainer, Please mark par2 package as Multi-Arch: foreign so that it can satisfy different-arch packages dependency (as it only provides arch-independent interface [cli]). -- System Information: Debian Release: 8.8 APT

Bug#863664: uim-gtk2.0: gtk{2,3}/qt/qt5 IM plugins are not multi-arch co-installable

2017-05-29 Thread Yuriy M. Kaminskiy
Package: uim-gtk2.0 Version: 1:1.8.6-8 Severity: important Dear Maintainer, gtk{2,3}, qt and qt5 IM plugins /usr/lib/$ARCH/gtk-2.0/2.10.0/immodules/im-uim.so /usr/lib/$ARCH/gtk-3.0/3.0.0/immodules/im-uim.so /usr/lib/$ARCH/qt4/plugins/inputmethods/libuiminputcontextplugin.so

Bug#863984: mc: "gzip: No such file or directory" when compressing from menu

2017-06-02 Thread Yuriy M. Kaminskiy
Package: mc Version: 3:4.8.18-1 Severity: normal Tags: upstream patch Dear Maintainer, When compressing file from menu (F2)->y (Gzip or gunzip current file), there are message gzip: No such file or directory This is due to inadequate shell quoting in menu: === cut /etc/mc/mc.menu === y

Bug#864185: sqlite3 built without fts5 support (upstream bug)

2017-06-04 Thread Yuriy M. Kaminskiy
Package: sqlite3 Version: 3.19.2-1 Severity: normal Tags: upstream fixed-upstream patch Dear Maintainer, I noticed that libsqlite3_3.19.2-1 is accidentally built without fts4 and fts5 support due to broken handling of --enable-* flags in configure.ac (already fixed upstream,

Bug#863818: nocache is not multi-arch co-installable

2017-05-31 Thread Yuriy M. Kaminskiy
+ + * Add Multi-Arch support. + + -- Yuriy M. Kaminskiy <yumkam+deb...@gmail.com> Wed, 31 May 2017 15:23:17 +0300 + nocache (1.0-1) unstable; urgency=medium * New upstream release [May 2016]. diff -Nru nocache-1.0/debian/control nocache-1.0/debian/control --- nocache-1.0/debian/control 2016-05

Bug#902792: torsocks: does not support and fails catastrophically with muliarch

2018-06-30 Thread Yuriy M. Kaminskiy
Package: torsocks Version: 2.2.0-1+deb9u1 Severity: important Tags: patch Dear Maintainer, On multi-arch systems, torsocks fails catastrophically with other-arch binaries. E.g. with torsocks:i386 and wget:amd64, torsocks wget https://check.torproject.org just spits ERROR: ld.so: object

Bug#609427: FYI: race condition

2018-06-22 Thread Yuriy M. Kaminskiy
I'd like to note that `mount -obind --make-private` is not atomic and implemented internally as mount -o bind $src $target # 1 mount --make-private $target # 2 So, if two mounts are executed in parallel, there are (much smaller) racing window between them. (FWIW, I just run pbuilders

Bug#904848: apulse: please add Multi-Arch support

2018-07-28 Thread Yuriy M. Kaminskiy
Package: apulse Version: 0.1.12-1 Severity: normal Tags: patch Dear Maintainer, Please add support for co-installation of apulse package for multi-arch systems. Patch attached; I've briefly tested without any apparent problems (in self-compiled backport on stretch system). -- System

Bug#566326: duplicate of #551968 (fixed as of 3.6.19-2)

2018-08-15 Thread Yuriy M. Kaminskiy
This seems to be duplicate of 551968 (which was "fixed"^[] as of 3.6.19-2, somewhere before wheezy), so I guess this bug should be merged/closed. ^[] which annoyed me to no end, as this option provides only snake oil privacy [(1) it is useless on SSD; (2) it does nothing about leaking data

Bug#855444: (likely) fixed upstream

2018-08-16 Thread Yuriy M. Kaminskiy
This looks like was triggered by upstream bug 3437, fixed in 1:4.2.8p11+dfsg-1 (aside of selinux noise, it triggered series of modprobe requests for net-pf-0 every few minutes).

Bug#676653: Patch attached

2018-07-18 Thread Yuriy M. Kaminskiy
Control: tags -1 patch Now that tor uses automatic -dbgsym, too weak dependency is not even tor maintainer issue (FWIW, I opened https://bugs.debian.org/903158 with solution). If you install dbgsym for mismatching arch, it is useless, but don't break anything. On other hand, lack of proper

Bug#904433: tesseract-ocr: please mark as Multi-Arch: foreign

2018-07-24 Thread Yuriy M. Kaminskiy
Package: tesseract-ocr Version: 4.00~git2481-555f6ffc-1 Severity: normal Tags: patch Dear Maintainer, tesseract-ocr package provides arch-independent service (cli), please mark it as Multi-Arch: foreign; (trivial) patch attached. -- System Information: Debian Release: 9.5 APT prefers

Bug#901095: patch

2018-07-22 Thread Yuriy M. Kaminskiy
. + * Add sqlite3-analyzer package. (Closes: #901095) + + -- Yuriy M. Kaminskiy Sun, 22 Jul 2018 20:05:56 +0300 + sqlite3 (3.24.0-1) unstable; urgency=medium * New upstream release. diff -Nru sqlite3-3.24.0/debian/control sqlite3-3.24.0/debian/control --- sqlite3-3.24.0/debian/control

Bug#903158: Multi-Arch: foreign and -dbgsym: too weak dependency

2018-07-07 Thread Yuriy M. Kaminskiy
Package: debhelper Version: 10.2.5 Severity: minor Tags: patch Dear Maintainer, On Multi-Arch i386+amd64 system, when I have foo:amd64 (Multi-Arch: foreign), I can install useless foo-dbgsym:i386 (and reverse). I think (at least, 'Multi-arch: foreign' *and* 'Architecture' != all) packages

Bug#332578: Fixed as of less release 487

2018-07-13 Thread Yuriy M. Kaminskiy
After 13 years, less bug 273 marked as fixed in (beta?) version 485, and it seems everything works as of debian package version 487-0.1 (in ja_JP.UTF-8 locale; in non-utf-8 locales - e.g. ja_JP.EUC-JP or ja_JP.SJIS - it seems still broken, but debian consider them deprecated anyway).

Bug#829527: youtube-dl: don't "call home" by default

2018-02-27 Thread Yuriy M. Kaminskiy
> Can you please clarify your question? When does it "phone home"? (Not original bug reporter), out of curiosity, I looked at sources (as of version 2018.01.27), 1) this option seems off by default; 2) it only affects running in verbose (debug) mode, 3) when it is on, it fetches

Bug#917616: openssl: `openssl speed foobar` segfaults

2018-12-29 Thread Yuriy M. Kaminskiy
Package: openssl Version: 1.1.0j-1~deb9u1 Severity: minor Tags: patch stretch upstream Dear Maintainer, * What led up to the situation? Invoking `openssl speed` with unrecognized/unsupported algorithm, e.g. openssl speed foobar or even openssl speed help * What was the outcome of

Bug#917158: qemubuilder mishandles multiple entries in OTHERMIRROR

2018-12-23 Thread Yuriy M. Kaminskiy
Package: qemubuilder Version: 0.87 Severity: normal Tags: patch Dear Maintainer, When OTHERMIRROR contains multiple entries, separated by | character (as documented in pbuilderrc(5)), qemubuilder fails to handle them and produces incorrect /etc/apt/sources.list.d/other.list file, resulting in

  1   2   >