Bug#782030: Mark the stunnel RC bugs as pending

2015-04-23 Thread intrigeri
Peter Pentchev wrote (23 Apr 2015 11:33:39 GMT) : I think that intrigeri meant that I had actually submitted the request. Exactly :) And yes, I have known for several days now that Laszlo is right, the request should be closed, since the window for merging into testing is closed. From

Bug#783183: init.d reload should fail if the daemon is not running

2015-04-23 Thread LaMont Jones
Package: anope Version: 2.0.2-1 Severity: serious If the daemon is not running, reload should fail. It currently passes. -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Bug#783108: Trivially reproducable

2015-04-23 Thread Lennart Sorensen
Taken from testcase in php bug report and run on amd64 sid. /tmp/test.php: ?php $string = ''; // These two in any order $string .= \r\n; $string .= ; // Total string length 8192 $string .= str_repeat(chr(rand(32, 127)), 8184); // Ending in this string $string .= say; $finfo = new

Bug#783108: Upstream php fix appears to work

2015-04-23 Thread Lennart Sorensen
Applying the patch linked to above (https://git.php.net/?p=php-src.git;a=commitdiff;h=f938112c495b0d26572435c0be73ac0bfe642ecd) makes the segfault go away and the expected output occur. So this bug IS in php (and also exist in file apparently). Reassigning to file is wrong, given the bug exists

Bug#783148: [pkg-wpa-devel] Bug#783148: wpa: CVE-2015-1863: wpa_supplicant P2P SSID processing vulnerability

2015-04-23 Thread Stefan Lippers-Hollmann
Hi On 2015-04-23, Salvatore Bonaccorso wrote: Hi, I'm currently preparing the debdiffs for jessie-security and sid uploads. Thank you for taking care of it, I was about to respond now (and am currently testing the patched packages, successfully so far). Be aware that src:wpa 1.0-3+deb7u1

Bug#783148: wpa: CVE-2015-1863: wpa_supplicant P2P SSID processing vulnerability

2015-04-23 Thread Salvatore Bonaccorso
Hi, I'm currently preparing the debdiffs for jessie-security and sid uploads. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-rc-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Processed: forcibly merging 783174 783193

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: forcemerge 783174 783193 Bug #783174 [tlsdate] tlsdate: Time retrieved from default host (www.ptb.de) jumping all over the place? Bug #783174 [tlsdate] tlsdate: Time retrieved from default host (www.ptb.de) jumping all over the place? Marked as

Bug#783174: tlsdate: Time retrieved from default host (www.ptb.de) jumping all over the place?

2015-04-23 Thread Jacob Appelbaum
Hi Sebastian, On 4/23/15, Sebastian Pipping sebast...@pipping.org wrote: Package: tlsdate Version: 0.0.12-2~bpo70+1 Severity: normal When using debian.org for a host, time is somewhat stable: $ for i in {1..10}; do tlsdate --dont-set-clock --showtime -H debian.org ; done Thu Apr 23

Bug#783193: tlsdate: Sets time wrong

2015-04-23 Thread Kurt Roeckx
On Thu, Apr 23, 2015 at 05:31:56PM +, Jacob Appelbaum wrote: Could you detail which host you're using to fetch the time? I suspect that it clearly is one that randomizes the time field (makes sense, many do now, including the default one). Also it looks like tlsdate failed closed many

Bug#783148: [pkg-wpa-devel] Bug#783148: wpa: CVE-2015-1863: wpa_supplicant P2P SSID processing vulnerability

2015-04-23 Thread Salvatore Bonaccorso
Hi Stefan, On Thu, Apr 23, 2015 at 07:14:01PM +0200, Stefan Lippers-Hollmann wrote: Hi On 2015-04-23, Salvatore Bonaccorso wrote: Hi, I'm currently preparing the debdiffs for jessie-security and sid uploads. Thank you for taking care of it, I was about to respond now (and am

Bug#783193: tlsdate: Sets time wrong

2015-04-23 Thread Kurt Roeckx
Package: tlsdate Version: 0.0.12-2 Severity: grave Hi, I found this in my syslog today: Apr 23 16:09:23 intrepid tlsdated[3408]: [event:action_run_tlsdate] requested re-run of tlsdate while tlsdate is running Apr 23 16:09:23 intrepid tlsdated[3408]: [event:action_tlsdate_status] invalid time

Processed (with 1 errors): severity of 783174 is grave, merging 783174 783193

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: severity 783174 grave Bug #783174 [tlsdate] tlsdate: Time retrieved from default host (www.ptb.de) jumping all over the place? Severity set to 'grave' from 'normal' merge 783174 783193 Bug #783174 [tlsdate] tlsdate: Time retrieved from default

Bug#783193: tlsdate: Sets time wrong

2015-04-23 Thread Jacob Appelbaum
On 4/23/15, Kurt Roeckx k...@roeckx.be wrote: Package: tlsdate Version: 0.0.12-2 Severity: grave Hi, I found this in my syslog today: Apr 23 16:09:23 intrepid tlsdated[3408]: [event:action_run_tlsdate] requested re-run of tlsdate while tlsdate is running Apr 23 16:09:23 intrepid

Processed: found 783187 in 2.0.36~rc1~dfsg-6.1+deb7u1, severity of 783187 is critical

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: # not verified, just setting the intended values by the reporter found 783187 2.0.36~rc1~dfsg-6.1+deb7u1 Bug #783187 [libgd2-xpm] libgd2-xpm_2.0.36~rc1~dfsg-6.1+deb7u1 on armhf brakes nginx Marked as found in versions

Bug#725284: hdparm + systemd: Patch to restore configuration after resume

2015-04-23 Thread Ralf Jung
Hi, This doesn't guarantee that the service is run on resume. Those targets are activated on suspend/hibernate, so there is a race and you might actually run /usr/lib/pm-utils/power.d/95hdparm-apm *before* the system is suspended. You'd have to order this service after the *service* which

Bug#765577: debian 8.0 errata (Re: Bug#765577: netboot install writes duplicates to 70-persistent-net.rules)

2015-04-23 Thread Michael Biebl
Hi everyone! I talked to the release team and they prefer to postpone a fix to 8.1. I therefor would like to see a short paragraph added to the d-i 8.0 errata [1]. Afaics, the issue so far only happened for automated installations. There is no real solution/workaround ttbomk besides rebuilding

Bug#783205: clang-3.5: fatal error: 'sys/cdefs.h' file not found

2015-04-23 Thread Jakub Wilk
Package: clang-3.5 Version: 1:3.5-10 Severity: grave User: debian-s...@lists.debian.org Usertags: s390x On s390x, the compiler can't find standard C headers: $ clang-3.5 -c test.c In file included from test.c:1: In file included from /usr/include/stdio.h:27: /usr/include/features.h:374:12:

Bug#783202: [adt-buildvm-ubuntu-cloud] timeout nearly after display Net device info

2015-04-23 Thread Jörg Frings-Fürst
Package: autopkgtest Version: 3.6jessie1 Severity: grave Hi, at $ adt-buildvm-ubuntu-cloud -r vivid -v I get a timeout always after: [ 24.805304] cloud-init[730]: Cloud-init v. 0.7.7 running 'init' at Thu, 23 Apr 2015 19:45:53 +. Up 19.94 seconds. [ 24.805553] cloud-init[730]: ci-info:

Bug#765577: debian 8.0 errata (Re: Bug#765577: netboot install writes duplicates to 70-persistent-net.rules)

2015-04-23 Thread Michael Biebl
Am 23.04.2015 um 22:22 schrieb Cyril Brulebois: Michael Biebl bi...@debian.org (2015-04-23): netboot install writes duplicate entries to 70-persistent-net.rules ~~~ It might be better not to embed the “netboot install”

Bug#765577: debian 8.0 errata (Re: Bug#765577: netboot install writes duplicates to 70-persistent-net.rules)

2015-04-23 Thread Cyril Brulebois
Michael Biebl bi...@debian.org (2015-04-23): Am 23.04.2015 um 22:22 schrieb Cyril Brulebois: Michael Biebl bi...@debian.org (2015-04-23): netboot install writes duplicate entries to 70-persistent-net.rules ~~~ It might

Bug#783183: init.d reload should fail if the daemon is not running

2015-04-23 Thread Dominic Hargreaves
On Thu, Apr 23, 2015 at 08:29:14AM -0600, LaMont Jones wrote: Package: anope Version: 2.0.2-1 Severity: serious If the daemon is not running, reload should fail. It currently passes. Hi, Really? A quick review of init scripts on my system reveal many that behave similarly, and nowhere in

Bug#782456: plymouth: With plymouth installed, starting the DM sometimes fails

2015-04-23 Thread Ralf Jung
Hi all, I finally had the time to experiment a bit more. Here are my latest findings: I removed all non-Debian kernels, just to be sure. Immediately after enabling splash in grub again, the behavior of lightdm always fails to start reappeared. Then I changed plymouth to text mode, re-generated

Bug#783183: init.d reload should fail if the daemon is not running

2015-04-23 Thread LaMont Jones
On Thu, Apr 23, 2015 at 11:34:43PM +0100, Dominic Hargreaves wrote: On Thu, Apr 23, 2015 at 08:29:14AM -0600, LaMont Jones wrote: Package: anope Version: 2.0.2-1 Severity: serious If the daemon is not running, reload should fail. It currently passes. Really? A quick review of init

Bug#783169: drive

2015-04-23 Thread Fabio Pedretti
This is a possible alternative, not packaged in Debian: https://github.com/odeke-em/drive

Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Henri Salo
I reported this issue to Debian BTS to notify package maintainers and in the long run trying to get security issues fixed. Maintainers are not always following security issues in upstream and so on (not saying this about PHP). I verified that the segfault condition occurred and did not do more

Bug#783163: CVE-2015-1856: Unauthorized delete of versioned Swift object

2015-04-23 Thread Thomas Goirand
Package: python-swift Version: 2.2.0-1 Severity: grave Tags: security patch Note from maintainer: Upload is following. Affects ~~~ - Swift: versions through 2.2.2 Description ~~~ Clay Gerrard from SwiftStack reported a vulnerability in Swift object versioning. An authenticated user

Processed: Re: Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 783099 -unreproducible Bug #783099 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Bug #783107 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Removed tag(s) unreproducible.

Bug#783169: grive: please remove grive from archive - no longer works after Google API changes of 2015-04-20

2015-04-23 Thread Fabio Pedretti
Package: grive Version: 0.2.0-1.1 Severity: grave Dear Maintainer, after 2015-04-20 Google requires the use of 3.0 API version: https://developers.google.com/google-apps/documents-list/ which grive doesn't support: http://askubuntu.com/questions/611801/grive-sync-error-possibly-google-api-shift

Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Christoph Biedl
tags 783099 unreproducible thanks Henri Salo wrote... When calling finfo::file() or finfo::buffer() with a crafted string, PHP will crash by either segfaulting or trying to allocate an large amount of memory (4GiB). (...)

Processed: Re: Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: tags 783099 unreproducible Bug #783099 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Bug #783107 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Added tag(s) unreproducible. Added

Bug#783164: CVE-2015-1852: S3token incorrect condition expression for ssl_insecure.

2015-04-23 Thread Thomas Goirand
Package: python-keystoneclient Version: 1:0.10.1-2 Severity: grave Tags: security patch Note from maintainer: upload fixing Sid Jessie is comming in a few minutes. Affects ~~~ - python-keystoneclient: versions through 1.3.0 - keystonemiddleware: versions through 1.5.0 Description

Bug#781888: [pkg-cinnamon] Bug#781888: Bug#781888: cinnamon-session: session does not start

2015-04-23 Thread Maximiliano Curia
¡Hola Norbert! El 2015-04-23 a las 09:36 +0900, Norbert Preining escribió: thanks for coming back to that. ** (polkit-gnome-authentication-agent-1:10887): WARNING **: Unable to register authentication agent: GDBus.Error:org.freedesktop.PolicyKit1.Error.Failed: An authentication agent

Bug#783155: marked as done (hspec-discover: fails to upgrade from 'sid' - trying to overwrite /usr/bin/hspec-discover)

2015-04-23 Thread Debian Bug Tracking System
Your message dated Thu, 23 Apr 2015 07:33:36 + with message-id e1ylbdg-0001lt...@franck.debian.org and subject line Bug#783155: fixed in haskell-hspec-discover 2.1.5-2 has caused the Debian Bug report #783155, regarding hspec-discover: fails to upgrade from 'sid' - trying to overwrite

Bug#782456: plymouth: With plymouth installed, starting the DM sometimes fails

2015-04-23 Thread intrigeri
Hi systemd and lightdm maintainer, please have a look at #782456 -- it might be local misconfiguration (in which case, asking Ralf for the debugging info you need would be very nice of you), or a bug in the new DM / systemd integration. Cheers, -- intrigeri -- To UNSUBSCRIBE, email to

Bug#771671: marked as done (/sbin/kexec: Unable to load kdump kernel on i386)

2015-04-23 Thread Debian Bug Tracking System
Your message dated Thu, 23 Apr 2015 10:49:11 + with message-id e1ylegx-0007ty...@franck.debian.org and subject line Bug#771671: fixed in kexec-tools 1:2.0.7-5.1 has caused the Debian Bug report #771671, regarding /sbin/kexec: Unable to load kdump kernel on i386 to be marked as done. This

Bug#782033: marked as done (kexec-tools: Reboots the machine while removing the package)

2015-04-23 Thread Debian Bug Tracking System
Your message dated Thu, 23 Apr 2015 10:49:11 + with message-id e1ylegx-0007td...@franck.debian.org and subject line Bug#782033: fixed in kexec-tools 1:2.0.7-5.1 has caused the Debian Bug report #782033, regarding kexec-tools: Reboots the machine while removing the package to be marked as done.

Bug#783163: marked as done (CVE-2015-1856: Unauthorized delete of versioned Swift object)

2015-04-23 Thread Debian Bug Tracking System
Your message dated Thu, 23 Apr 2015 09:50:51 + with message-id e1yldmv-0005hg...@franck.debian.org and subject line Bug#783163: fixed in swift 2.2.0-2 has caused the Debian Bug report #783163, regarding CVE-2015-1856: Unauthorized delete of versioned Swift object to be marked as done. This

Bug#783164: marked as done (CVE-2015-1852: S3token incorrect condition expression for ssl_insecure.)

2015-04-23 Thread Debian Bug Tracking System
Your message dated Thu, 23 Apr 2015 09:50:36 + with message-id e1yldmg-0005xr...@franck.debian.org and subject line Bug#783164: fixed in python-keystoneclient 1:0.10.1-3 has caused the Debian Bug report #783164, regarding CVE-2015-1852: S3token incorrect condition expression for ssl_insecure.

Bug#771241: Bug#782030: Mark the stunnel RC bugs as pending

2015-04-23 Thread intrigeri
Peter Pentchev wrote (08 Apr 2015 11:16:34 GMT) : I'm now about to ask the release team for a pre-approval for the new version of stunnel to migrate to Jessie. Just for the record, this was done: https://bugs.debian.org/782143 -- To UNSUBSCRIBE, email to

Processed: Bug#782750: make-dfsg: FTBFS: features/archives test fails

2015-04-23 Thread Debian Bug Tracking System
Processing control commands: severity -1 serious Bug #782750 [src:make-dfsg] make-dfsg: FTBFS: features/archives test fails Severity set to 'serious' from 'normal' tags -1 sid stretch Bug #782750 [src:make-dfsg] make-dfsg: FTBFS: features/archives test fails Added tag(s) sid and stretch. --

Bug#783032: Minitube segfaults on startup

2015-04-23 Thread intrigeri
Control: tag -1 + moreinfo Hi, E Taylor wrote (20 Apr 2015 21:09:18 GMT) : $ minitube Segmentation fault I can't reproduce this on current sid. Can you reproduce it in a clean and current testing/sid environment? Note that the upstream links you're providing don't make it obvious to me that

Processed: Re: Bug#783032: Minitube segfaults on startup

2015-04-23 Thread Debian Bug Tracking System
Processing control commands: tag -1 + moreinfo Bug #783032 [minitube] Minitube segfaults on startup Added tag(s) moreinfo. -- 783032: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=783032 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems -- To UNSUBSCRIBE, email to

Bug#771241: Bug#782030: Mark the stunnel RC bugs as pending

2015-04-23 Thread GCS
On Thu, Apr 23, 2015 at 12:33 PM, intrigeri intrig...@debian.org wrote: Peter Pentchev wrote (08 Apr 2015 11:16:34 GMT) : I'm now about to ask the release team for a pre-approval for the new version of stunnel to migrate to Jessie. Just for the record, this was done:

Bug#771241: Bug#782030: Mark the stunnel RC bugs as pending

2015-04-23 Thread Peter Pentchev
On Thu, Apr 23, 2015 at 12:54:12PM +0200, László Böszörményi wrote: On Thu, Apr 23, 2015 at 12:33 PM, intrigeri intrig...@debian.org wrote: Peter Pentchev wrote (08 Apr 2015 11:16:34 GMT) : I'm now about to ask the release team for a pre-approval for the new version of stunnel to migrate to