Re: Validating tarballs against git repositories

2024-04-01 Thread Andrey Rakhmatullin
On Mon, Apr 01, 2024 at 04:10:55PM +0200, Alexandre Detiste wrote: > Le lun. 1 avr. 2024 à 15:49, Colin Watson a écrit : > > > > The practice of running "autoreconf -fi" or similar via dh-autoreconf > > has worked extremely well at scale in Debian. I'm sure there are > > complex edge cases where

Re: Validating tarballs against git repositories

2024-04-01 Thread Alexandre Detiste
Le lun. 1 avr. 2024 à 15:49, Colin Watson a écrit : > > The practice of running "autoreconf -fi" or similar via dh-autoreconf > has worked extremely well at scale in Debian. I'm sure there are > complex edge cases where it's caused problems, but it's far from being a > disaster area. It's

Accepted rust-mio 0.8.11-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 09:30:56 -0400 Source: rust-mio Architecture: source Version: 0.8.11-1 Distribution: unstable Urgency: medium Maintainer: Debian Rust Maintainers Changed-By: Alexander Kjäll Changes: rust-mio (0.8.11-1)

Accepted lyx 2.4.0~RC4-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 15:17:48 +0200 Source: lyx Architecture: source Version: 2.4.0~RC4-1 Distribution: unstable Urgency: medium Maintainer: Dr. Tobias Quathamer Changed-By: Dr. Tobias Quathamer Changes: lyx (2.4.0~RC4-1) unstable;

Accepted libgav1 0.19.0-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 15:14:00 +0200 Source: libgav1 Architecture: source Version: 0.19.0-2 Distribution: unstable Urgency: medium Maintainer: Debian Multimedia Maintainers Changed-By: Sebastian Ramacher Closes: 1068180 Changes:

Accepted gnome-online-accounts 3.50.0-3 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 09:29:38 -0400 Source: gnome-online-accounts Built-For-Profiles: noudeb Architecture: source Version: 3.50.0-3 Distribution: unstable Urgency: medium Maintainer: Debian GNOME Maintainers Changed-By: Jeremy Bícha

Accepted gnome-control-center 1:46.0.1-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 09:30:57 -0400 Source: gnome-control-center Built-For-Profiles: noudeb Architecture: source Version: 1:46.0.1-1 Distribution: unstable Urgency: medium Maintainer: Debian GNOME Maintainers Changed-By: Jeremy Bícha

Re: Validating tarballs against git repositories

2024-04-01 Thread Colin Watson
On Mon, Apr 01, 2024 at 11:33:06AM +0200, Simon Josefsson wrote: > Running ./bootstrap in a tarball may lead to different results than the > maintainer running ./bootstrap in pristine git. It is the same problem > as running 'autoreconf -fvi' in a tarball does not necessarily lead to > the same

Re: Command /usr/bin/mv wrong message in German

2024-04-01 Thread Alexandre Detiste
Le lun. 1 avr. 2024 à 10:43, Johannes Schauer Marin Rodrigues a écrit : > > This is the reason I never expect dpkg -S to work and dpkg -L to be > > correct. The (probably) oldest registered bug report about this is #213907, > > from 2003. RPM has %ghost since before that, of course. > > This is

Accepted javaproperties 0.8.1-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 14:04:52 +0100 Source: javaproperties Architecture: source Version: 0.8.1-2 Distribution: unstable Urgency: medium Maintainer: Debian Python Team Changed-By: Luca Boccassi Closes: 1063976 Changes: javaproperties

Accepted shishi 1.0.3-4 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 11:13:12 +0200 Source: shishi Architecture: source Version: 1.0.3-4 Distribution: unstable Urgency: medium Maintainer: Debian Shishi Team Changed-By: Simon Josefsson Changes: shishi (1.0.3-4) unstable;

Accepted libopenmpt 0.7.6-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 14:41:09 +0200 Source: libopenmpt Architecture: source Version: 0.7.6-1 Distribution: unstable Urgency: medium Maintainer: Debian Multimedia Maintainers Changed-By: Sebastian Ramacher Changes: libopenmpt

Accepted hylafax 3:6.0.7-7 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 14:34:59 +0200 Source: hylafax Architecture: source Version: 3:6.0.7-7 Distribution: unstable Urgency: medium Maintainer: Giuseppe Sacco Changed-By: Giuseppe Sacco Closes: 688560 1020349 Changes: hylafax

Re: xz backdoor

2024-04-01 Thread Pierre-Elliott Bécue
De : Ansgar  À : Pierre-Elliott Bécue ; Luca Boccassi Cc : debian-devel@lists.debian.org Date : 1 avr. 2024 12:47:52 Objet : Re: xz backdoor > > Hi, > > On Sun, 2024-03-31 at 14:34 +0200, Pierre-Elliott Bécue wrote: >> The PGP submodule of a Yubikey can host 3 keys, one signing, one >>

Accepted normaliz 3.10.2+ds-2~exp1 (source) into experimental

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 11:47:26 + Source: normaliz Architecture: source Version: 3.10.2+ds-2~exp1 Distribution: experimental Urgency: medium Maintainer: Debian Math Team Changed-By: Jerome Benoit Closes: 1067274 Changes: normaliz

Accepted gdm3 46.0-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 08:03:50 -0400 Source: gdm3 Built-For-Profiles: noudeb Architecture: source Version: 46.0-1 Distribution: unstable Urgency: medium Maintainer: Debian GNOME Maintainers Changed-By: Jeremy Bícha Changes: gdm3

Accepted shared-mime-info 2.4-4 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 07:58:12 -0400 Source: shared-mime-info Built-For-Profiles: noudeb Architecture: source Version: 2.4-4 Distribution: unstable Urgency: medium Maintainer: Debian freedesktop.org maintainers Changed-By: Jeremy

Accepted r-cran-d3network 0.5.2.1-4 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 13:48:26 +0200 Source: r-cran-d3network Architecture: source Version: 0.5.2.1-4 Distribution: unstable Urgency: medium Maintainer: Debian R Packages Maintainers Changed-By: Joost van Baal-Ilić Changes:

Accepted r-cran-bdgraph 2.72+dfsg-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 13:38:01 +0200 Source: r-cran-bdgraph Architecture: source Version: 2.72+dfsg-2 Distribution: unstable Urgency: medium Maintainer: Debian R Packages Maintainers Changed-By: Joost van Baal-Ilić Changes:

Accepted gauche 0.9.14-2 (source amd64 all) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Thu, 28 Mar 2024 15:42:59 +0100 Source: gauche Binary: gauche gauche-dbgsym gauche-dev gauche-dev-dbgsym gauche-doc gauche-gdbm gauche-gdbm-dbgsym gauche-zlib gauche-zlib-dbgsym libgauche-0.98-0 libgauche-0.98-0-dbgsym

Accepted r-cran-ggm 2.5.1-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 13:27:01 +0200 Source: r-cran-ggm Architecture: source Version: 2.5.1-2 Distribution: unstable Urgency: medium Maintainer: Debian R Packages Maintainers Changed-By: Joost van Baal-Ilić Changes: r-cran-ggm

Accepted netpbm-free 2:11.06.00-1 (source) into experimental

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 11:35:30 +0200 Source: netpbm-free Architecture: source Version: 2:11.06.00-1 Distribution: experimental Urgency: medium Maintainer: Debian PhotoTools Maintainers Changed-By: Andreas Metzler Changes:

Accepted libgwenhywfar 5.11.1beta-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 12:29:10 +0200 Source: libgwenhywfar Architecture: source Version: 5.11.1beta-1 Distribution: unstable Urgency: medium Maintainer: Micha Lenk Changed-By: Micha Lenk Changes: libgwenhywfar (5.11.1beta-1)

Accepted libaqbanking 6.5.8beta-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 12:47:05 +0200 Source: libaqbanking Architecture: source Version: 6.5.8beta-1 Distribution: unstable Urgency: medium Maintainer: Micha Lenk Changed-By: Micha Lenk Changes: libaqbanking (6.5.8beta-1) unstable;

Re: xz backdoor

2024-04-01 Thread Bastian Blank
Hi On Mon, Apr 01, 2024 at 12:40:51PM +0200, Ansgar  wrote: > For OpenSSH it might also be more convenient to use Webauthn, that is, > the keys generated using `ssh-keygen -t ed25519-sk` or `-t ecdsa-sk`. Also those key types allow two different uses. Persistent or non-persistent keys differ

Re: Validating tarballs against git repositories

2024-04-01 Thread Bastian Blank
On Mon, Apr 01, 2024 at 12:03:48PM +0200, Bastian Blank wrote: > On Mon, Apr 01, 2024 at 02:31:47AM +0200, gregor herrmann wrote: > > That's not mutually exclusive. When adding an additional git remote > > and using gbp-import-orig's --upstream-vcs-tag you get the best of > > both worlds. > And

Accepted inn2 2.7.2~20240325-1 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 12:29:55 +0200 Source: inn2 Architecture: source Version: 2.7.2~20240325-1 Distribution: unstable Urgency: medium Maintainer: Marco d'Itri Changed-By: Marco d'Itri Changes: inn2 (2.7.2~20240325-1) unstable;

Re: xz backdoor

2024-04-01 Thread Ansgar 
Hi, On Sun, 2024-03-31 at 14:34 +0200, Pierre-Elliott Bécue wrote: > The PGP submodule of a Yubikey can host 3 keys, one signing, one > authent, and one encrypt. ISTR accessing the signing key is always > prompting for the PIN. Same for the encryption key. (I think both can > be configured

Accepted rust-zxcvbn 2.2.2-2 (source) into experimental

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 06:21:52 -0400 Source: rust-zxcvbn Architecture: source Version: 2.2.2-2 Distribution: experimental Urgency: medium Maintainer: Debian Rust Maintainers Changed-By: Alexander Kjäll Changes: rust-zxcvbn (2.2.2-2)

Re: xz backdoor

2024-04-01 Thread Iustin Pop
On 2024-03-31 22:23:10, Arto Jantunen wrote: > Didier 'OdyX' Raboud writes: > > > Le dimanche, 31 mars 2024, 14.37:08 h CEST Pierre-Elliott Bécue a écrit : > >> I would object against creating a PGP key on the HSM itself. Not having > >> the proper control on the key is room for disaster as soon

Re: Validating tarballs against git repositories

2024-04-01 Thread Bastian Blank
On Mon, Apr 01, 2024 at 02:31:47AM +0200, gregor herrmann wrote: > That's not mutually exclusive. When adding an additional git remote > and using gbp-import-orig's --upstream-vcs-tag you get the best of > both worlds. And this will error out if there are unexpected changes in the tarball? How

Re: xz backdoor

2024-04-01 Thread Bastian Blank
Hi On Sun, Mar 31, 2024 at 07:48:35PM +0300, Adrian Bunk wrote: > > What we can do unilaterally is to disallow vendoring those files. > These files are supposed to be vendored in release tarballs, > the sane approach for getting rid of such vendored files would > be to discourage tarball uploads

Re: xz backdoor

2024-04-01 Thread Stephan Verbücheln
On Mon, 2024-04-01 at 10:59 +0200, tho...@goirand.fr wrote: > Only for the signing operation, one can turn on the "force-sig" > option so that the key always prompt for a pin. And that is not the > default. There are two levels. In the OpenPGP protocol, the smartcard can be configured to require

Accepted smb4k 3.2.70-1 (source) into experimental

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 11:37:31 +0200 Source: smb4k Architecture: source Version: 3.2.70-1 Distribution: experimental Urgency: medium Maintainer: Debian KDE Extras Team Changed-By: Pino Toscano Changes: smb4k (3.2.70-1) experimental;

Accepted debian-reference 2.121 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 18:24:03 +0900 Source: debian-reference Architecture: source Version: 2.121 Distribution: unstable Urgency: medium Maintainer: Osamu Aoki Changed-By: Osamu Aoki Changes: debian-reference (2.121) unstable;

Re: Validating tarballs against git repositories

2024-04-01 Thread Simon Josefsson
"G. Branden Robinson" writes: > At 2024-03-31T22:32:49+, Stefano Rivera wrote: >> Upstreams would probably prefer that we used git repositories >> *directly* as source artifacts, but that comes with a whole other can >> of worms... > > Speaking from my upstream groff perspective, I wouldn't

Accepted tantan 49-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Format: 1.8 Date: Mon, 01 Apr 2024 11:04:08 +0200 Source: tantan Architecture: source Version: 49-2 Distribution: unstable Urgency: medium Maintainer: Debian Med Packaging Team Changed-By: Sascha Steinbiss Changes: tantan (49-2) unstable;

Accepted ivykis 0.43-2 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 10:42:42 +0200 Source: ivykis Architecture: source Version: 0.43-2 Distribution: unstable Urgency: medium Maintainer: Laszlo Boszormenyi (GCS) Changed-By: Laszlo Boszormenyi (GCS) Changes: ivykis (0.43-2)

Accepted exim4 4.97-7 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 10:45:05 +0200 Source: exim4 Architecture: source Version: 4.97-7 Distribution: unstable Urgency: medium Maintainer: Exim4 Maintainers Changed-By: Andreas Metzler Changes: exim4 (4.97-7) unstable; urgency=medium

Re: xz backdoor

2024-04-01 Thread thomas
On Mar 31, 2024 2:37 PM, Pierre-Elliott Bécue Wrote: > The PGP submodule of a Yubikey can host 3 keys, one signing, one > authent, and one encrypt. ISTR accessing the signing key is always > prompting for the PIN. Same for the encryption key. (I think both can be > configured otherwise)

Re: Command /usr/bin/mv wrong message in German

2024-04-01 Thread Johannes Schauer Marin Rodrigues
Hi, Quoting Andrey Rakhmatullin (2024-04-01 09:58:21) > On Mon, Apr 01, 2024 at 01:03:04PM +1000, Russell Stuart wrote: > > On 1/4/24 10:18, gregor herrmann wrote: > > > % dpkg -S $(which mv > coreutils: /usr/bin/mv > > > > On bookworm: > > > > $ dpkg -S $(which mv) > > dpkg-query: no

Re: Command /usr/bin/mv wrong message in German

2024-04-01 Thread Andrey Rakhmatullin
On Mon, Apr 01, 2024 at 01:03:04PM +1000, Russell Stuart wrote: > On 1/4/24 10:18, gregor herrmann wrote: > > % dpkg -S $(which mv > coreutils: /usr/bin/mv > > On bookworm: > > $ dpkg -S $(which mv) > dpkg-query: no path found matching pattern /usr/bin/mv > > This is caused by the /bin

Accepted globus-gridftp-server 13.25-5 (source) into unstable

2024-04-01 Thread Debian FTP Masters
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Format: 1.8 Date: Mon, 01 Apr 2024 06:07:01 +0200 Source: globus-gridftp-server Architecture: source Version: 13.25-5 Distribution: unstable Urgency: medium Maintainer: Mattias Ellert Changed-By: Mattias Ellert Changes: globus-gridftp-server

Re: xz backdoor

2024-04-01 Thread Didier 'OdyX' Raboud
Le dimanche, 31 mars 2024, 21.23:10 h CEST Arto Jantunen a écrit : > Didier 'OdyX' Raboud writes: > > Le dimanche, 31 mars 2024, 14.37:08 h CEST Pierre-Elliott Bécue a écrit : > >> I would object against creating a PGP key on the HSM itself. Not having > >> the proper control on the key is room

<    1   2