Bug#1064839: Consider not using an ephemeral key or document its security model

2024-02-26 Thread Julian Andres Klode
Source: linux Severity: normal X-Debbugs-Cc: j...@debian.org In https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1040901 I asked you to switch to an ephemeral key which was a misunderstanding from a discussion with xnox, which we still need to sort out fully. Please either document how the

Bug#1064838: New package names break APT safety features, ability to co-install different ABIs

2024-02-26 Thread Julian Andres Klode
On Mon, Feb 26, 2024 at 02:20:41PM +0100, Julian Andres Klode wrote: > Source: linux > Severity: serious > X-Debbugs-Cc: j...@debian.org > > After we had discussed the new proposal a couple months ago and were > left with severe open questions and concerns it seems that these h

Bug#1064838: New package names break APT safety features, ability to co-install different ABIs

2024-02-26 Thread Julian Andres Klode
Source: linux Severity: serious X-Debbugs-Cc: j...@debian.org After we had discussed the new proposal a couple months ago and were left with severe open questions and concerns it seems that these have been ignored and the packages uploaded anyway, breaking APT's algorithm that ensures the

Re: How to revoke Debian kernels for secure boot

2023-12-14 Thread Julian Andres Klode
On Wed, Dec 13, 2023 at 10:18:40PM +, Dimitri John Ledkov wrote: > At the moment the best options are: > > - rotate online signing key > - build new shim with old signing key in vendorx (revoked ESL) > - build new kernels with old signing key built-in revoked keyring > > This is to ensure

Bug#1040901: Upcoming changes to Debian Linux kernel packages

2023-10-27 Thread Julian Andres Klode
OK, it seems my original email got lost somewhere in tech hickups, it's possible the kernel crashed before sending the email, AMD just crashes once or twice a day. So I'm writing this email a bit in a hurry, so it's not quite as thought out as the last one weeks ago, but yesterday's email was

Bug#1040901: Upcoming changes to Debian Linux kernel packages

2023-10-27 Thread Julian Andres Klode
On Thu, Oct 26, 2023 at 01:36:50PM +0200, Bastian Blank wrote: > On Fri, Oct 20, 2023 at 05:54:23PM +0200, Bastian Blank wrote: > > Or would it be easier to re-use normal dependency resolving, like: > > Kernel-Provides: linux (>> 6.6.1~), linux (<< 6.6.1.) > > This would allow full flexibility and

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
On Wed, Jul 12, 2023 at 10:05:03AM +0200, Julian Andres Klode wrote: > Source: linux > Version: 6.3.0-7.7 > Severity: grave > Tags: security > X-Debbugs-Cc: j...@debian.org > > I know there's some work in progress but it appears we don't have a bug > for it yet. I rais

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
Control: notfound -1 6.3.0-7.7 On Wed, Jul 12, 2023 at 10:05:03AM +0200, Julian Andres Klode wrote: > Source: linux > Version: 6.3.0-7.7 > Severity: grave > Tags: security > X-Debbugs-Cc: j...@debian.org Sorry about that, it picked up the version from my work system's Ubuntu kern

Bug#1040901: linux modules must not be signed with CA key, bump ABI every upload

2023-07-12 Thread Julian Andres Klode
Source: linux Version: 6.3.0-7.7 Severity: grave Tags: security X-Debbugs-Cc: j...@debian.org I know there's some work in progress but it appears we don't have a bug for it yet. I raised this yesterday in our weekly upstream shim/grub cabal meetings and Debian's current approach to sign modules

Re: [PATCH v2] builddeb: Support signing kernels with the module signing key

2022-02-08 Thread Julian Andres Klode
On Tue, Feb 08, 2022 at 01:10:34PM +, Matthew Wilcox wrote: > On Tue, Feb 08, 2022 at 12:01:22PM +0100, Julian Andres Klode wrote: > > It's worth pointing out that in Ubuntu, the generated MOK key > > is for module signing only (extended key usage 1.3.6.1.4.1.2312.16.1.2), >

Re: [PATCH v2] builddeb: Support signing kernels with the module signing key

2022-02-08 Thread Julian Andres Klode
On Mon, Feb 07, 2022 at 09:33:46PM +0900, Masahiro Yamada wrote: > Added "Ben Hutchings " > > On Wed, Jan 5, 2022 at 3:13 AM Matthew Wilcox wrote: > > > > On Wed, Jan 05, 2022 at 12:39:57AM +0900, Masahiro Yamada wrote: > > > > +vmlinux=$($MAKE -s -f $srctree/Makefile image_name) > > > > +key= >

Bug#875631: linux: [i915/iron lake] Screen flickering instability in 4.9, 4.11 (3.16, 4.12 OK)

2017-09-12 Thread Julian Andres Klode
Source: linux Version: 4.9.30-2 Control: fixed -1 3.16.43-2+deb8u2 Control: fixed -1 4.12.6-1 Control: found -1 4.11.6-1 As I mentioned before on IRC, my system with Iron Lake graphics and a Pentium P6200 (a ThinkPad Edge 15, from 2010 IIRC) is unstable in stretch. It used to work fine in jessie.

Bug#859570: linux 4.10: Please enable CONFIG_BLK_WBT?

2017-04-04 Thread Julian Andres Klode
Source: linux Version: 4.10-1~exp1 Severity: wishlist I think it makes sense to enable writeback throttling. I often see systems basically locking up for minutes with heavy disk access, from the discussion on that feature, it should fix that. -- System Information: Debian Release: 9.0 APT

Bug#854880: firmware-atheros ships binary ath9k_htc firmwares containing GPL code

2017-02-11 Thread Julian Andres Klode
Package: firmware-atheros Severity: serious The binary files Files: ath9k_htc/htc_7010-1.4.0.fw, ath9k_htc/htc_9271-1.4.0.fw were created from files that include GPL components according to the copyright file, specially, the eCos files: eCos is free software; you can redistribute it and/or

Bug#827077: linux: autofs mounts hang after real mount is unmounted

2016-06-16 Thread Julian Andres Klode
Control: reassign -1 systemd 230-1 Control: retitle -1 systemd: autofs mount hang in 230 Control: tag -1 patch fixed-upstream On Mon, Jun 13, 2016 at 12:16:40AM +0200, Julian Andres Klode wrote: > Control: found -1 4.5.5-1 > Control: retitle -1 linux: autofs mounts hang after real

Bug#827077: linux 4.6: Regression: autofs mounts hang after real mount is unmounted

2016-06-11 Thread Julian Andres Klode
Package: src:linux Version: 4.6.1-1 Severity: normal Hi, my system mounts /boot/efi using autofs, so it is automatically unmounted after not being used (for safety reasons). The settings are (from /proc/mounts): systemd-1 /boot/efi autofs

Bug#811352: linux 4.4-rc8: i915: "[drm] stuck on render ring" on resume

2016-01-18 Thread Julian Andres Klode
nux-nonfree pn firmware-myricom pn firmware-netxen pn firmware-qlogic pn firmware-ralink ii firmware-realtek20160110-1 pn xen-hypervisor -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wik

Bug#811352: linux 4.4-rc8: i915: "[drm] stuck on render ring" on resume

2016-01-18 Thread Julian Andres Klode
Control: forwarded -1 https://bugs.freedesktop.org/show_bug.cgi?id=92998 Control: tag -1 upstream On Mon, Jan 18, 2016 at 09:21:50AM +0100, Julian Andres Klode wrote: > Package: src:linux > Version: 4.4~rc8-1~exp1 > Severity: normal > > I'm not sure if that's the right package to

Bug#741989: linux: 3.13.5: known regression: xHCI xhci_drop_endpoint called with disabled ep

2014-03-17 Thread Julian Andres Klode
-qlogic none pn firmware-ralink none ii firmware-realtek0.41 pn xen-hypervisor none -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. Please do not top

Bug#741989: linux: 3.13.5: known regression: xHCI xhci_drop_endpoint called with disabled ep

2014-03-17 Thread Julian Andres Klode
On Tue, Mar 18, 2014 at 12:20:18AM +0100, Julian Andres Klode wrote: Package: src:linux Version: 3.13.5-1 Severity: normal 3.13.5 introduces a regression in the xhci code that causes mass storage to not work correctly. In my case, the experience was that first writes failed misteriously

Bug#727243: linux: 3.11: aufs: au_loopback_init:136:modprobe[24614]: loop_backing_file() is not defined

2013-10-23 Thread Julian Andres Klode
firmware-realtek0.40 pn xen-hypervisor none -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. Please do not top-post if possible. -- To UNSUBSCRIBE, email

Bug#723767: linux: 3.11 Failed to suspend: RCU stall, soft lock-ups

2013-09-19 Thread Julian Andres Klode
On Thu, Sep 19, 2013 at 06:37:59PM +0200, Julian Andres Klode wrote: Package: src:linux Version: 3.11-1~exp1 Severity: important I today tried to suspend my ThinkPad X230, but apparently this did not work. 20 seconds after PM: Preparing system for mem sleep, I get a INFO: rcu_sched self

Bug#723767: linux: 3.11 Failed to suspend: RCU stall, soft lock-ups

2013-09-19 Thread Julian Andres Klode
none -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. kern.edited.log.xz Description: Binary data pgpEH1LyCcFrr.pgp Description: PGP signature

Bug#635007: linux-2.6: Removing USB connection crashes usbnet, USB hotplugging

2011-07-21 Thread Julian Andres Klode
-ralink none (no description available) pn xen-hypervisornone (no description available) -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org

Bug#630474: linux 3.0 package names should probably not include SUBLEVEL

2011-06-14 Thread Julian Andres Klode
none (no description available) -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. pgpd2TmpkLjCZ.pgp Description: PGP signature

Bug#630474: linux 3.0 package names should probably not include SUBLEVEL

2011-06-14 Thread Julian Andres Klode
On Tue, 2011-06-14 at 12:00 +, maximilian attems wrote: On Tue, Jun 14, 2011 at 12:41:13PM +0200, Julian Andres Klode wrote: Package: linux-2.6 Version: 3.0.0~rc2-1~experimental.1 Severity: normal SUBLEVEL is reserved for -stable in kernel 3.0 and newer. As Debian kernels did

Bug#611555: initramfs-tools: Modules needed for btrfs not included in initramfs

2011-01-30 Thread Julian Andres Klode
changed [not included] -- no debconf information -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. pgpZdPJpq2VqX.pgp Description: PGP signature

Bug#591768: linux-2.6: rmdir: failed to remove `/lib/modules/2.6.35-rc6-amd64': Directory not empty

2010-08-05 Thread Julian Andres Klode
available) -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. pgp0Uh2kosKHA.pgp Description: PGP signature

Bug#591777: linux-2.6: Large vaapi performance drop from 2.6.35-rc6 to 2.6.35

2010-08-05 Thread Julian Andres Klode
available) pn xen-hypervisornone (no description available) -- debconf information excluded -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. pgprCQZcAy5iz.pgp Description: PGP signature

Bug#579755: linux-2.6: Please enable CONFIG_CGROUP_DEBUG

2010-04-30 Thread Julian Andres Klode
cores) Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. pgpwJDzVVNgFj.pgp Description: PGP signature

Bug#572341: Use of uninitialized value $type in exists at /var/lib/dpkg/info/linux-base.postinst line 1271, STDIN line 4.

2010-03-03 Thread Julian Andres Klode
-qlogic none (no description available) pn firmware-ralink none (no description available) -- debconf-show failed -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org

Re: Bug#520468: Incorporate fixes for WUSB54GS support from 2.6.33

2010-02-17 Thread Julian Andres Klode
native drivers in mainline. Regards, Julian -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Bug#567965: linux-image-2.6.32-trunk-686: Configuration change to prevent i915 lockup

2010-02-03 Thread Julian Andres Klode
it (as the submitter), and it still happens. The thing is caused by grub not leaving the graphics mode and the kernel drivers unable to set a new mode. You may also want to take a look at grub-pc's Bug#565160. Regards, Julian -- Julian Andres Klode - Debian Developer, Ubuntu Member See http

Bug#567965: i915: KMS framebuffer fails to work, only X works

2010-02-01 Thread Julian Andres Klode
/prerm/would-invalidate-boot-loader-2.6.32-trunk-amd64: true -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org/. signature.asc Description: Digital signature

Bug#567391: Please update aufs2 to new upstream snapshot (aufs2-32 branch)

2010-01-28 Thread Julian Andres Klode
prefers unstable APT policy: (990, 'unstable'), (350, 'experimental') Architecture: amd64 (x86_64) Kernel: Linux 2.6.32-trunk-amd64 (SMP w/2 CPU cores) Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash -- Julian Andres Klode - Debian Developer, Ubuntu

Bug#553472: linux-libc-dev: Include linux/aufs_type.h for aufs2-utils?

2009-10-31 Thread Julian Andres Klode
in linux-headers-2.6.31-common but this package is versioned and would thus require changes to aufs-tools build-dependencies for every new kernel. Regards, Julian -- Julian Andres Klode - Debian Developer, Ubuntu Member See http://wiki.debian.org/JulianAndresKlode and http://jak-linux.org

Bug#553472: linux-libc-dev: Include linux/aufs_type.h for aufs2-utils?

2009-10-31 Thread Julian Andres Klode
Am Samstag, den 31.10.2009, 18:42 + schrieb Ben Hutchings: On Sat, 2009-10-31 at 17:50 +0100, Julian Andres Klode wrote: Package: linux-libc-dev Version: 2.6.31-1 Severity: wishlist Hi, would it be possible to get linux/aufs_type.h included in linux-libc-dev or a similar package

Bug#541828: linux-2.6: Please export symbols for aufs2 (or unionfs2).

2009-08-16 Thread Julian Andres Klode
policy: (990, 'unstable'), (350, 'experimental') Architecture: amd64 (x86_64) Kernel: Linux 2.6.30-1-amd64 (SMP w/2 CPU cores) Locale: LANG=de_DE.UTF-8, LC_CTYPE=de_DE.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash -- Julian Andres Klode - Debian Developer, Ubuntu Member See http

Re: unification filesystems -- packaging aufs2, etc.

2009-07-07 Thread Julian Andres Klode
the module yet. It should work. -- Julian Andres Klode - Free Software Developer Debian Developer - Contributing Member of SPI Ubuntu Member - Fellow of FSFE Website: http://jak-linux.org/ XMPP: juli...@jabber.org Debian: http://www.debian.org/ SPI: http://www.spi-inc.org/ Ubuntu

Re: unification filesystems -- packaging aufs2, etc.

2009-07-07 Thread Julian Andres Klode
On Mon, Jul 06, 2009 at 06:10:32PM +0200, Daniel Baumann wrote: Julian Andres Klode wrote: Proposal - It seems to be the best idea to use unionfs-fuse for now (like Ubuntu) until a new kernel-based solution has been packaged. It may also be a good idea to coordinate

unification filesystems -- packaging aufs2, etc.

2009-07-06 Thread Julian Andres Klode
both distros can use the same method of filesystem unification. 1. The Debian Live project adds support for unionfs-fuse. 2. A new filesystem will be packaged (unionfs2 OR aufs2). 3. aufs will be removed from unstable (or be replaced by aufs2 under the same name). Regards, Julian Andres Klode

Bug#535959: linux-2.6: Please enable libata for PATA/piix

2009-07-06 Thread Julian Andres Klode
) can be supported by just one subsystem (it reduces the amount of code running on the system). -- Julian Andres Klode - Free Software Developer Debian Developer - Contributing Member of SPI Ubuntu Member - Fellow of FSFE Website: http://jak-linux.org/ XMPP: juli...@jabber.org Debian

Bug#533550: i915: kernel mode setting -- wrong resolution

2009-06-19 Thread Julian Andres Klode
On Fri, Jun 19, 2009 at 01:35:56PM +0200, Julien Cristau wrote: On Thu, Jun 18, 2009 at 17:55:17 +0200, Julian Andres Klode wrote: [1.793657] [drm] TV-13: set mode 1024x768 18 Is a TV really connected? If not this should be fixed with: I don't even have a TV output, so none can

Bug#533550: i915: kernel mode setting -- wrong resolution

2009-06-18 Thread Julian Andres Klode
-link-2.6.30-1-amd64: true -- Julian Andres Klode - Free Software Developer Debian Developer - Contributing Member of SPI Ubuntu Member - Fellow of FSFE Website: http://jak-linux.org/ XMPP: juli...@jabber.org Debian: http://www.debian.org/ SPI: http://www.spi-inc.org/ Ubuntu: http

Bug#385553: linux-modules-extra-2.6: Please provide pre-built ndiswrapper modules

2008-07-09 Thread Julian Andres Klode
upstream version 1.53 in the archive ASAP. Sorry, I wasn't at home in the last 2 weeks. Should get uploaded this week. I will do some final builds and tests and see if my AM sponsors it, else I will look for another sponsor. ETA: 3d (maximum) -- Julian Andres Klode, Fellow of the Free Software

Bug#385553: linux-modules-extra-2.6: ndiswrapper requires rules target override

2008-06-20 Thread Julian Andres Klode
-*. why/what is it so difficult to add/adjust the toplevel makefile to do that? Fixed locally. I will publish the new package soon and it should be uploaded soon. Using the patch from https://bugs.edge.launchpad.net/ndiswrapper/+bug/241547 -- Julian Andres Klode, Fellow of the Free Software

Bug#480354: sendfile support missing in aufs

2008-05-09 Thread Julian Andres Klode
On Fri, May 09, 2008 at 05:42:20PM +0300, Laszlo Bako-Szabo wrote: Package: linux-image-2.6.24-1-amd64 Severity: important aufs no longer has the sendfile capability, which seems to be because the kernel is missing a patch, that is needed for 2.6.23+ kernels. (

Bug#473430: sendfile support missing in aufs

2008-03-30 Thread Julian Andres Klode
*in return in-f_op-splice_read(in, ppos, pipe, len, flags); } +EXPORT_SYMBOL(do_splice_to); /** * splice_direct_to_actor - splices data directly between two non-pipes -- Julian Andres Klode, Fellow of the Free Software Foundation Europe Debian Maintainer