Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-31 Thread Paul Szabo
> Where did you report them? As mentioned: https://github.com/OpenPrinting/cups/issues/917 https://github.com/OpenPrinting/cups/issues/918 https://github.com/OpenPrinting/cups/issues/919 and also https://github.com/OpenPrinting/cups/issues/916 Cheers, Paul -- Paul Szabo

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-31 Thread Paul Szabo
Dear Till, Thanks for the pointer to libcupsfilters, now that issue reported also: https://github.com/OpenPrinting/libcupsfilters/issues/53 (Sadly, my other issues were "declined" upstream. Maybe they know what they are doing...) Thanks, Paul -- Paul Szabo p...@maths.u

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-30 Thread Paul Szabo
e. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University: www.nteu.au/join

Bug#1067122: cups-daemon: cupsd ignores job-originating-host-name

2024-03-30 Thread Paul Szabo
Issue now reported upstream: https://github.com/OpenPrinting/cups/issues/916 Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University

Bug#1067122: cups-daemon: cupsd ignores job-originating-host-name

2024-03-18 Thread Paul Szabo
Package: cups-daemon Version: 2.4.2-3+deb12u5 Severity: normal Tags: patch I noticed that the cupsd server ignores (overrides) the value of job-originating-host-name sent. I get good results with my proposed patch for this issue, below. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-04 Thread Paul Szabo
file, both as plain-text and as attachment (the latter hopefully preserving blanks and tabs). Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia - --- cups-2.4.2/backend

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-02 Thread Paul Szabo
[Sorry about the previous, incomplete message.] Further testing shows that the bug is not in filter/pstops but in filter/pdftopdf; I do not yet know what the issue is, will try to find out. Please re-assign this bug to package cups-filters-core-drivers. Cheers, Paul -- Paul Szabo p

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-02 Thread Paul Szabo
Further testing shows that the bug is not in filter/pstops but in filter/pdftopdf. (I do not yet know what Maybe this bug should be reassigned to package -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of Sydney

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-01 Thread Paul Szabo
I attach my PPD file below. -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University: www.nteu.au/join my.ppd Description: application/vnd.cups-ppd

Bug#1065157: cups-core-drivers: Filters ignore cupsManualCopies

2024-03-01 Thread Paul Szabo
testing, printing a PDF file causes CUPS to run the filters /usr/lib/cups/filter/pdftopdf /usr/lib/cups/filter/pdftops and then when the PS file gets to the backend /usr/lib/cups/backend/lpd the copies are "done" already. Or maybe, I somehow use those options wrongly? Thanks,

Bug#1060233: libc6: Missing libdl.so

2024-01-08 Thread Paul Szabo
Dear Aurelien, Thanks for the help. Please close this bug report. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University: www.nteu.au

Bug#1060233: libc6: Missing libdl.so

2024-01-07 Thread Paul Szabo
y" libdl.so.2 object, still? Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University: www.nteu.au/join

Bug#1060233: libc6: Missing libdl.so

2024-01-07 Thread Paul Szabo
.so At bullseye, libdl.so.2 was in package libc6, while the symlink libdl.so was in libc6-dev (which seems somewhat wrong already). Cheers, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia -- Sys

Bug#1060056: mariadb-server: mariadb-hotcopy fails for performance_schema and sys

2024-01-06 Thread Paul Szabo
ets this right, while mariadb-backup is extremely(!) chatty on STDERR. But then, these are not this bug... Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia

Bug#1060056: mariadb-server: mariadb-hotcopy fails for performance_schema and sys

2024-01-06 Thread Paul Szabo
, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Join the Union and fight for a better University: www.nteu.au/join

Bug#1060056: mariadb-server: mariadb-hotcopy fails for performance_schema and sys

2024-01-05 Thread Paul Szabo
Dear Otto, Thanks for your quick reply. MDEV-33187 is "new". MDEV-30259 is only year old, though the issue seems ten years old: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=735014 Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/

Bug#1060056: mariadb-server: mariadb-hotcopy fails for performance_schema and sys

2024-01-05 Thread Paul Szabo
made it into bookworm). Please include those patches in the next point release! Thanks, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 12.4 APT prefers

Bug#1057186: tzdata: NTP complains about an expiring leap-seconds.list

2023-12-01 Thread Paul Szabo
found 1057186 2023c-5 thanks Same issue on bookworm, syslog shows: Dec 1 11:04:23 machine ntpd[PID]: CLOCK: leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 27 days with tzdata version 2023c-5. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au

Bug#1050208: libc6: double free detected in tcache 2, then abort

2023-08-21 Thread Paul Szabo
he PXE boot sequence uses sysvinit, not systemd. Thanks Aurelien for suggesting the glibc tunables (in bug #1041836). Did not try gdb since I am not proficient with it, would not know what to look for. Please suggest anything else I should try. Thanks, Paul -- Paul Szabo p...@ma

Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-10 Thread Paul Szabo
quot;, but did not help to fix the issue. I may try to change physical RAM modules, not sure whether have suitable replacements. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia

Bug#1041836: root unable to write un-owned

2023-08-09 Thread Paul Szabo
Bummer. This last "echo x > /tmp/x" issue is probably the result of protected_regular being set in kernel configs, see https://docs.kernel.org/admin-guide/sysctl/fs.html#id12 Sorry about the noise. (Hangs head in shame.) Cheers, Paul

Bug#1041836: root unable to write un-owned

2023-08-09 Thread Paul Szabo
Another oddity that should never happen: root cannot write file that he does not own. Demonstration (root running bash): root# touch /tmp/x root# ls -l /tmp/x -rw-r--r-- 1 root root 0 Aug 10 09:39 /tmp/x root# echo a > /tmp/x root# chown 2:2 /tmp/x root# ls -l /tmp/x -rw-r--r-- 1

Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-09 Thread Paul Szabo
Dear Aurelien, I used LD_PRELOAD=libc_malloc_debug.so for MALLOC_CHECK_. With those extra checks (tried all values of MALLOC_CHECK_ from 0 to 20), glibc did not show any errors, suggesting that the bug is not in inetd. The original poster said his issue shows on some hardware only. I observed my

Bug#1041836: libc6 2.36-9+deb12u1 double free abort

2023-08-08 Thread Paul Szabo
ebug.so "fixes" the issue. Hope this helps to find the cause. Cheers, Paul References: http://btorpey.github.io/blog/2019/07/14/memory-checking/ https://www.gnu.org/software/libc/manual/html_node/Heap-Consistency-Checking.html -- Paul Szabo p...@maths.usyd.edu.au www.mat

Bug#1026790: snmptrapd options in systemd service

2022-12-21 Thread Paul Szabo
that -L cannot be used on its own; and I do not see any meaning for neither -Ow nor for -w. As proof of pudding... it did not work for me with -LOw, nothing went into syslog; things are working well with -Lsd. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz

Bug#1026790: snmptrapd options in systemd service

2022-12-20 Thread Paul Szabo
with option "right" for syslog, and no need for PID file since systemd uses its own MAINPID anyway. I guess this was needed ever since version 5.9, I just failed to report it earlier. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of M

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-31 Thread Paul Szabo
www.debian.org/lts/security/2021/dla-2671 released, a fix for buster and a DSA cannot be that far off.

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-21 Thread Paul Szabo
Dear Ryan, I see 9.22-11 in sid (unstable), but in bullseye (testing) it is 9.22-10 still (and buster is unchaged at 9.22-6). Will 9.22-11 make it into bullseye, will this (non?!-)security bug be fixed soon? Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-21 Thread Paul Szabo
that come to mind: www.debian.org/security/2003/dsa-380 www.debian.org/security/2009/dsa-1694 bugs.debian.org/511516 Anyway, I solved my problem by "apt purge rxvt-unicode" on all my machines. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-21 Thread Paul Szabo
disclosure/2021/May/51 (quoted below for completeness), it seems that this is now fixed upstream in version 9.25, maybe they did consider it a bug. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of Sydney

Bug#988763: rxvt-unicode: Remote(?) code execution via ESC G Q

2021-05-19 Thread Paul Szabo
Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia Quoting messasge: From: def To: Date: Sun, 16 May 2021 15:32:48 +0300 Subject: [FD] (u)rxvt terminal (+bash) remoteish code execution 0day #!/usr/bin

Bug#695182: linux-image-3.2.0-4-686-pae: Write couple of 1GB files for OOM crash

2021-05-01 Thread Paul Szabo
I no longer use 32-bit kernels (but use the 64-bit amd64 kernel, even on my few last remaining 32-bt machines): that seems a suitable workaround or upgrade path. Should I try to test whether the issue with PAE remains? Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au

Bug#949440: Merged 949432 and 949440: does the same workaround solve?

2020-06-18 Thread Paul Szabo
I wonder why 949432 and 949440 were merged? I do not see confirmation whether 949432 is solved by the same workaround of 949440. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics and Statistics University of SydneyAustralia I

Bug#956084: inetutils-telnetd: CVE-2020-10188

2020-04-06 Thread Paul Szabo
or urgent data, because of a buffer overflow involving the netclear and nextitem functions. Seems to me that inetutils contains the same (vulnerable) utility.c functions. Please check. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au www.maths.usyd.edu.au/u/psz School of Mathematics

Bug#949440: chromium: Blank window when used over ssh tunnel

2020-01-22 Thread Paul Szabo
' chromium solves the issue for me. (That code is "ancient", with comments about some old Firefox; the Firefox issue was fixed some time ago.) Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sy

Bug#949440: chromium: Blank window when used over ssh tunnel

2020-01-20 Thread Paul Szabo
com/chrome/thread/23330705 Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 10.2 APT prefers stable APT policy: (500, 'stable') Architecture: amd

Bug#908156: xpra cannot create directories in /run

2019-12-25 Thread Paul Szabo
ter; the error is shown by the work server. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia I support NTEU members taking a stand for workplace rights in the face of poorly-run chang

Bug#908156: xpra cannot create directories in /run

2019-12-25 Thread Paul Szabo
+ "/.xpra" + import sys try: import xpra -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia I support NTEU members taking a stand for workplace rights in the face of poorl

Bug#947158: systemd: After=network.target is ineffective

2019-12-21 Thread Paul Szabo
s as below. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia Contents of /etc/network/if-up.d/00waitup : #!/bin/bash - #V0.1 22 Dec 19 wait for (ensure) interface is up # Paul

Bug#946671: [debian-mysql] Bug#946671: mariadb-server-10.3: mysqlhotcopy and transaction_registry table

2019-12-13 Thread Paul Szabo
Dear Otto, > Since that patch is not about Debian packaging, I suggest you > submit it upstream at https://github.com/mariadb/server branch 10.3 > (or latest 10.5). Done: created https://jira.mariadb.org/browse/MDEV-21317 Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.

Bug#946671: mariadb-server-10.3: mysqlhotcopy and transaction_registry table

2019-12-13 Thread Paul Szabo
tus|schema|general_log|slow_log|transaction_registry)$/ } @dbh_base_tables +# } ## generate regex for tables/files -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2019-09-11 Thread Paul Szabo
grade" sequences, and "start anacron" happens nightly. (Some other systemd commands may also affect.) and the "same" fix applies: new patch file below, for changed sources. (Funny how this bug is not getting fixed, in four years...) Thanks, Paul -- Paul Szabo

Bug#912193: Post message upstream

2019-02-21 Thread Paul Szabo
y "day jobs" to complete first). Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#892105: linux-image-4.9.0-6-amd64: i40e driver still unstable

2019-01-09 Thread Paul Szabo
th similar traffic volumes). Following the hints in this bug report, I will try the Intel i40e driver, from (either) https://downloadcenter.intel.com/download/24411/ https://sourceforge.net/projects/e1000/files/i40e%20stable/ Cheers, Paul -- Paul Szabo p...@maths.usyd.edu

Bug#910479: hpanel: Sometimes busy and unresponsive

2018-12-09 Thread Paul Szabo
This problem seems to be solved by using the patch below. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia Description: Avoid busy Seems hpanel is sometimes busy and non-responsive

Bug#912193: [Pkg-samba-maint] Bug#912193: samba: Ignores UNIX groups

2018-10-30 Thread Paul Szabo
GID, but then also does setgroups(7, [331, 100, 309, 313, 314, 303, 318]) with the "Windows group" GIDs. (The above was when a Windows10 PC did a "map network drive" connecting to a share.) > Can you post your (redacted) smb.conf? Below, a

Bug#912193: [Pkg-samba-maint] Bug#912193: samba: Ignores UNIX groups

2018-10-29 Thread Paul Szabo
Sorry, my typo. I just wrote: ... and does seem to add those ... but of course I meant to say: ... and does NOT seem to add those ... Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sydney

Bug#912193: [Pkg-samba-maint] Bug#912193: samba: Ignores UNIX groups

2018-10-29 Thread Paul Szabo
ly (though not the patch file I posted). > Also please note that we don't accept patches that are not merged > upstream first. > Additionnaly, this patch target stable while it's not a security or > stability patch. Understood. I have been using my own Samba for years, can keep doing tha

Bug#912193: samba: Ignores UNIX groups

2018-10-28 Thread Paul Szabo
s user" belongs to, but that is probably useless or wrong for file accesses.) The following patch seems to solve the issue. (Seems to me that Samba4.9 suffers from the same issue.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Sta

Bug#910479: hpanel: Sometimes busy and unresponsive

2018-10-06 Thread Paul Szabo
nute or so, hpanel will quieten and then act on the clicks that were done during its busy stage. I do not know how to reproduce or elicit this "busy and unresponsive" state, nor have ideas on checking what it is doing during that time. Thanks, Paul Paul Szabo p...@math

Bug#887467: hpanel: x86_64 shows broken icons

2018-08-14 Thread Paul Szabo
Dear Bernhard, Thanks, your patches (this one for icons, and bug#887468 for crash) work perfectly! Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#887468: hpanel: Crashes with SIGSEGV sometimes

2018-08-09 Thread Paul Szabo
Dear Bernhard, I have been using hpanel with your patch for about 2 days now, and no crash has occurred: seems it solves this issue. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#887468: hpanel: Crashes with SIGSEGV sometimes

2018-08-07 Thread Paul Szabo
Dear Bernhard, I now build hpanel with your patch, will let you know how it goes. Hoping this was the right fix... maybe you could look also at the bug#887467 issue of the broken icons? Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Bug#803013: [bts-link] source package systemd

2018-05-31 Thread Paul Szabo
l, I will keep using my "manually patched" systemd. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#886887: unreproducible last crashing

2018-05-21 Thread Paul Szabo
changed from version 2.29.2-1 to 2.29.2-1+deb9u1.) Running the old "last" (but with the current libc.so.6) does not reproduce the problem, and I do not want to downgrade libc6 to test. I guess you may close this bug. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu

Bug#887468: hpanel: Crashes with SIGSEGV sometimes

2018-01-16 Thread Paul Szabo
Package: hpanel Version: 0.3.2-4 Severity: normal Dear Maintainer, Running on x86_64, hpanel sometimes crashes with SIGSEGV. As yet I have not noticed what actions may cause this, so do not know how to make it happen at will. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http

Bug#887467: hpanel: x86_64 shows broken icons

2018-01-16 Thread Paul Szabo
Package: hpanel Version: 0.3.2-4 Severity: normal Dear Maintainer, Hpanel running on x86_64, shows broken icons; though hpanel on i386 shows correct icons. (Fspanel has the same behaviour.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Bug#884945: xdm: opens TCP port for (XDMCP?) LISTEN

2017-12-21 Thread Paul Szabo
#239341. Please let me know if I should investigate further. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia -- System Information: Debian Release: 9.3 APT prefers stable APT policy

Bug#803013: systemd should not destroy application created cgroups

2017-07-22 Thread Paul Szabo
A patch below, functionally identical to my previous. But this seems neater, showing the intent more clearly: clearer that this is a "true" bug in systemd. Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#803013: systemd should not destroy application created cgroups

2017-07-22 Thread Paul Szabo
ere calls with empty strings originate from ... Cheers, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2017-07-21 Thread Paul Szabo
es-created-by-someone-el.patch within systemd_232-25.debian.tar.xz or already in say systemd_215-17+deb8u2.debian.tar.xz No, it is not (and was never) sufficient: that is a different bug. Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and

Bug#803013: systemd should not destroy application created cgroups

2017-07-20 Thread Paul Szabo
fault setup. (Distressing how this bug did not get fixed in two years...) Thanks, Paul -- Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia diff -r -U17 a/src/basic/cgroup-util.c b/src/basic/cgroup

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-02 Thread paul . szabo
ch upgrade). This seems confusing. Would it be worthwhile to handle them both in the same way? Maybe some other things in postinst could get the same treatment. (Simple is easier to keep secure.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of M

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
, is there a need to set it writable? Is there a need to have these owned by group tomcat8, could they be left as root:root and world-accessible? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
from the DEB package, the ownership only to be fixed in postinst? In the current DEB, that directory is not group-writable. Could you kindly explain how this all works. Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
Hmm... I just accused you of being mistaken... but maybe it is I who is wrong. - Now thinking it through again. Cheers, Paul

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
; > https://anonscm.debian.org/cgit/pkg-java/tomcat8.git/commit/?id=02570d6 > > The script still chmods the Catalina directory but this one can't be > replaced by a symlink. You are mistaken. Please re-read the original bug report. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au h

Bug#845393: marked as done (Privilege escalation via upgrade)

2016-12-01 Thread paul . szabo
reopen 845393 thanks Not done. Please fix proper. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845393: Pending fixes for bugs in the tomcat8 package

2016-12-01 Thread paul . szabo
Dear Emmanuel, > No longer make /etc/tomcat8/Catalina/localhost writable ... The bug depends on "Catalina" being writable; the permissions on "localhost" are irrelevant. Please re-open. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.us

Bug#845385: Privilege escalation via removal

2016-11-30 Thread paul . szabo
tice that the Debian bug contraption does not CC me on messages: just being the submitter does not add you to the CC list, you need to explicitly "subscribe". So I missed a number of intermediate messages. --- Markus wrote previously: > ... Besides all tomcat processes are killed on purge. Where does that happen? I do not think that is true. Neither are any possible setuid-tomcat8 or setgid-tomcat8 files removed. --- Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#845385: Privilege escalation via removal

2016-11-22 Thread paul . szabo
rocesses, also. That might be a "good thing": deluser or delgroup might not "work" with left-over, running processes; and might protect against a race. But really... why do you care about leaving some "dangling" useless object, owned by some long-gone UID or GID?

Bug#845393: Privilege escalation via upgrade

2016-11-22 Thread Paul Szabo
her useful attacks might be to make the objects: /root/.Xauthority /etc/ssh/ssh_host_dsa_key world-readable; or make something (already owned by group tomcat8) group-writable (some "policy" setting maybe?). Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/

Bug#845385: Privilege escalation via removal

2016-11-22 Thread Paul Szabo
the world. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-11-09 Thread paul . szabo
Dear Andreas, > I have a completely untested patch sitting in GIT - do you have a > possibility to test packages built from that? I could replace files, or DEB packages, on some test machines. Do not know whether that testing would be exhaustive: do not know how many features of the sendmail

Bug#841371: /usr/bin/install: should use fchown, fchmod

2016-10-19 Thread Paul Szabo
The last two commands should be changed into fchown() and fchmod(), and moved to be prior to the close(). Would it help it I submitted patches? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAus

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-19 Thread paul . szabo
ines always have a process like: USER PID %CPU %MEMVSZ RSS TTY STAT START TIME COMMAND smmsp 2880 0.0 0.0 11956 3236 ?Ss Oct11 0:00 sendmail: Queue runner@00:10:00 for /var/spool/mqueue-client running. Cheers, Paul Paul Szabo p...@maths.us

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-18 Thread paul . szabo
Hmm... you may also need to (once) do: chown smmsp /var/run/sendmail/stampdir/reload when adopting my patch. Cheers, Paul

Bug#841257: sendmail: Privilege escalation from group smmsp to (user) root

2016-10-18 Thread Paul Szabo
su smmsp -s /bin/bash -c "touch > $STAMP_DIR/cron_msp"; 912c912 < touch $STAMP_DIR/cron_mta; --- > su smmsp -s /bin/bash -c "touch $STAMP_DIR/cron_mta"; 938c938 < touch

Bug#840685: TOCTOU race condition in initscript on chown'ing JVM_TMP temporary directory (was: Re: Bug#840685: tomcat8: DSA-3670 incomplete)

2016-10-14 Thread paul . szabo
eed for DSA. (Sorry about the noise.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
ymlink, you do the useless "mkdir -p" and you chown; I win. For your test, you took the rm out of your script: you should see /etc being chowned to tomcat8. Please confirm. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
in less than a day is not very reasonable, > especially when there are things like the time difference between > Australia and Europe. You can do better, if you try. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-14 Thread paul . szabo
whole day... compared to that, Markus replied within the hour to the Debian bug. (But he did not yet reply to my next, private bug/message... seems public messaging works best!) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-13 Thread paul . szabo
are appreciated. ... Maybe the security team will understand (recognize, accept) the issue without a PoC. If they reply with such a need, then I will write one. You or they might accept the suggested patch/fix: mkdir without -p, chown with -h. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://

Bug#840685: tomcat8: DSA-3670 incomplete

2016-10-13 Thread Paul Szabo
"chown -h". (This would protect against the above attack.) The script should use plain mkdir without "-p": not needed as we create a single directory, and should not be used to let mkdir return failure. (This may make it safe.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.

Bug#775541: NFS mounts fail at boot after Debian 8.5 upgrade

2016-09-06 Thread paul . szabo
Dear Vincent, > Could you provide a bit more information about the package versions > on your system? > dpkg -l rpcbind nfs-common nfs-kernel-server systemd psz@como:~$ dpkg -l rpcbind nfs-common nfs-kernel-server systemd Desired=Unknown/Install/Remove/Purge/Hold |

Bug#775541: NFS mounts fail at boot after Debian 8.5 upgrade

2016-08-19 Thread paul . szabo
=rpcbind.service instead? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#735014: closed by Debian FTP Masters <ftpmas...@ftp-master.debian.org> (Bug#811158: Removed package(s) from unstable)

2016-03-09 Thread paul . szabo
. Are you telling me that bugs in mysql 5.5 cannot be reported anymore? It is in use on jessie, so will be "live" for a while still. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#740020: xpdf: printing fails with Floating point exception

2016-02-27 Thread paul . szabo
Issue seems fixed in jessie. Please close/resolve bug. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2016-02-06 Thread paul . szabo
tags 803013 - fixed-upstream usertags 803013 - status-closed thanks I wrote: Please re-do your tags, or may I set tags myself? and received no response. Trying to do myself, please see discussion within bug report for reasons. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http

Bug#803013: Processed: [bts-link] source package systemd

2016-02-04 Thread paul . szabo
t things are NOT "fixed upstream". Please re-do your tags, or may I set tags myself? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: Processed: bug 803013 is forwarded to https://github.com/systemd/systemd/issues/1872

2016-01-28 Thread paul . szabo
> forwarded 803013 https://github.com/systemd/systemd/issues/1872 Is forwarded to an issue marked not-supported and closed. I wonder whether fixes are forthcoming? :-( Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statist

Bug#755048: Could not get screen information

2016-01-17 Thread paul . szabo
> Anybody got a work around ... ? Use arandr (or xrandr): works fine for me. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#736666: /usr/lib/sm.bin/mail.local: lockmailbox failed code 75 EX_TEMPFAIL

2015-12-23 Thread paul . szabo
by giving up privileges early. Please consider adopting this patch or some similar change. Please re-assign this bug back to sendmail. --- I am curious as to how does mail ever work for others: am I the last one still using sendmail and mail.local for local delivery? Thanks, Paul Paul Szabo p

Bug#736666: /usr/lib/sm.bin/mail.local: lockmailbox failed code 75 EX_TEMPFAIL

2015-12-22 Thread paul . szabo
de changed since. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia = /* Testing code mimicking sendmail mail.local . Compile with cc mytest.c -llockfile Fails

Bug#807081: Does not set TCP_NODELAY on X11 forward

2015-12-05 Thread paul . szabo
Sorry, I was wrong... sshd sets TCP_NODELAY correctly: not on the listening socket, but after accept(). What it does not set is IPTOS_LOWDELAY ... but maybe that is not useful anyway. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics

Bug#807081: openssh-server: Does not set TCP_NODELAY on X11 forward

2015-12-04 Thread Paul Szabo
. Quoting from http://www.openssh.com/txt/release-3.1 - TCP_NODELAY set on X11 and TCP forwarding endpoints Is this a bug that could be fixed? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of Sydney

Bug#803013: systemd should not destroy application created cgroups

2015-11-14 Thread paul . szabo
does not go deep enough to find their origin). Would not my patch make systemd more robust? Thanks, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2015-11-12 Thread paul . szabo
up/cpu/mytest/tasks # Check it is there grep . /sys/fs/cgroup/cpu/mytest/tasks # Do the systemd thing systemctl daemon-reload systemctl start anacron # See it gone grep . /sys/fs/cgroup/cpu/mytest/tasks Cheers, Paul Paul Szabo p...@maths.usyd.

Bug#803013: systemd should not destroy application created cgroups

2015-11-12 Thread paul . szabo
ll all seek shelter under the MS umbrella.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Bug#803013: systemd should not destroy application created cgroups

2015-11-12 Thread paul . szabo
Dear Michael, > I would suggest that you raise this upstream ... Done, see: https://github.com/systemd/systemd/issues/1872 Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

  1   2   3   4   5   6   7   >