Re: Bug#404743: CVE-2006-6698: local DoS vulnerability due to insecure tempdir handling

2006-12-28 Thread Josselin Mouette
Le mercredi 27 décembre 2006 à 23:55 +0100, Stefan Fritsch a écrit : Package: gconf2 Version: 2.16.0-3 Severity: important Tags: security A vulnerability has been reported in gconfd: The GConf daemon (gconfd) in GConf 2.14.0 creates temporary files under directories with names based on

request-tracker3.6 hint lost?

2006-12-28 Thread Niko Tyni
Hi release team, request-tracker3.6 3.6.1-3 was unblocked on Dec 12 [1], but it's still not getting into etch. Could somebody please have a look? [1] http://lists.debian.org/debian-release/2006/12/msg00426.html Thanks for your excellent work, -- Niko Tyni [EMAIL PROTECTED] --

etch: twoftpd 1.21-4

2006-12-28 Thread Gerrit Pape
Hi, twoftpd 1.21-4 in sid fixes important bug#400118, and I suggest to let this version into etch. The diff is minimal and straight forward. Additionally I suggest the socklog 2.1.0-7 package in sid to be included in etch, it fixes #401547 with the patch below, no other changes. Regards,

Re: please hint policyd-weight 0.1.14-beta-6 for etch

2006-12-28 Thread Steve Langasek
On Mon, Dec 25, 2006 at 09:55:15PM +0100, Jan Wagner wrote: On Sunday 24 December 2006 00:31, Steve Langasek wrote: This still does not respect certain local changes by the admin. Just because the link in /etc/rc2.d has been left alone doesn't mean that the symlinks for *all* the runlevels

Re: Security updates

2006-12-28 Thread Steve Langasek
On Sun, Dec 24, 2006 at 01:40:37PM +0100, Mike Hommey wrote: I see Alex has uploaded version 1.5.0.9 of icedove. What should we take as a course of action for xulrunner, iceweasel and iceape ? Should we go with newer upstreams (note there's no official xulrunner release, but I fake them

request for upload clearance 404783

2006-12-28 Thread Daniel J. Priem
Hello, i am requesting a clearance to upload a new version of kicad to fix #404783. the fix is attached as patch. please cc on answers Regards Daniel Index: kicad-doc-en.install === --- kicad-doc-en.install (Revision 95) +++

Re: Please unblock slrn 0.9.8.1pl1-23

2006-12-28 Thread Luk Claes
Norbert Tretkowski wrote: * Marc 'HE' Brockschmidt wrote: Norbert Tretkowski [EMAIL PROTECTED] writes: Could you please unblock slrn 0.9.8.1pl1-23 which was uploaded a few days ago? Unblocked. Thanks. Unfortunately, another upload was necessary to fix a build problem on mips and mipsel

Re: Please allow a freeze exception for belpic_2.5.9-7

2006-12-28 Thread Luk Claes
Wouter Verhelst wrote: Hi, As above. Changes are limited to: * adding debian/README.Debian, explaining a few bits about how to use the package; * editing debian/control for documentation (really, add two packages to Recommends:, as explained in README.Debian, and add a few lines to a

Re: please allow ltsp 0.99debian9 into etch

2006-12-28 Thread Luk Claes
Vagrant Cascadian wrote: please allow ltsp 0.99debian9 to migrate to etch. no additional bugs have been reported in the 4 days it has been in the archive. it fixes the following important bugs, adds or updates several translations, and includes a small documentation update. these changes

Re: CD/DVD do not contain Release.gpg files - secure apt complains

2006-12-28 Thread Steve Langasek
On Wed, Dec 27, 2006 at 10:45:58PM +, Steve McIntyre wrote: On Wed, Dec 27, 2006 at 10:53:59PM +0100, Jens Seidel wrote: I noticed that recent DVD images do not contain Release.gpg files so that APT warns all time about insecure packages. An installation using the Debian Installer is

Re: etch: twoftpd 1.21-4

2006-12-28 Thread Luk Claes
Gerrit Pape wrote: Hi, twoftpd 1.21-4 in sid fixes important bug#400118, and I suggest to let this version into etch. The diff is minimal and straight forward. Additionally I suggest the socklog 2.1.0-7 package in sid to be included in etch, it fixes #401547 with the patch below, no

permission to upload new logcheck upstream

2006-12-28 Thread martin f krafft
logcheck is a native package, so when i added some filters, i produced a new upstream version. I'd like to see 1.2.52 in etch and would like to reqest permission to upload it to unstable. I'll get in touch with d-r again when it's time for a freeze exception. Thanks, -- Please do not send

Re: Permission for uploading slapd

2006-12-28 Thread Steve Langasek
On Sat, Dec 23, 2006 at 03:38:48PM +0100, Matthijs Mohlmann wrote: Steve Langasek wrote: On Sat, Dec 09, 2006 at 09:48:38PM +0100, Matthijs Mohlmann wrote: I've finished a new upstream version of OpenLDAP. This has 3 binaries: slapd, libldap2.3-0 and ldap-utils. This version is merely to

Re: request for upload clearance 404783

2006-12-28 Thread Luk Claes
Daniel J. Priem wrote: Hello, i am requesting a clearance to upload a new version of kicad to fix #404783. the fix is attached as patch. You don't need to ask permission to upload a revision that is targetted for etch... Anyway, the changes look fine, though please send a migration request

Re: initrd-tools?

2006-12-28 Thread Steve Langasek
On Sat, Dec 23, 2006 at 08:03:29PM +0100, Andreas Barth wrote: * Noah Meyerhans ([EMAIL PROTECTED]) [061218 19:41]: Our options would seem to be to revise the release notes to no longer suggest upgrading aptitude before dist-upgrade, or including an initrd-tools package that doesn't

Re: gibraltar-bootcd fixing FTFBS bug

2006-12-28 Thread Steve Langasek
On Thu, Dec 14, 2006 at 05:12:29PM +, Rene Mayrhofer wrote: Am Donnerstag, 14. Dezember 2006 17:01 schrieb Andreas Barth: gibraltar-bootcd was removed in March from Etch - I don't think it would be appropriate to allow it now back in until there are *very* good reasons for it. Yes, the

freeze exception: mdadm 2.5.6-7

2006-12-28 Thread martin f krafft
mdadm 2.5.6-7 has been in unstable for two weeks and even though the diff between -6 and -7 is not as small as it should be, I feel confident that -7 can go into etch. Changelog: http://packages.qa.debian.org/m/mdadm/news/20061213T144703Z.html None of the changes affect the udeb or d-i. I would

Re: gibraltar-bootcd fixing FTFBS bug

2006-12-28 Thread Andreas Barth
* Steve Langasek ([EMAIL PROTECTED]) [061228 13:16]: On Thu, Dec 14, 2006 at 05:12:29PM +, Rene Mayrhofer wrote: Am Donnerstag, 14. Dezember 2006 17:01 schrieb Andreas Barth: gibraltar-bootcd was removed in March from Etch - I don't think it would be appropriate to allow it now back

Please remove CPS related packages from testing

2006-12-28 Thread Fabio Tranchitella
Dear RMs, zope-cps was removed from testing because it is incompatible with the current zope2.9 package and it is unmaintained upstream. The support packages for CPS are still in testing, and I ask to remove them as they are useless without zope-cps. I already filed removal requests for CPS and

Re: Please remove CPS related packages from testing

2006-12-28 Thread Andreas Barth
* Fabio Tranchitella ([EMAIL PROTECTED]) [061228 14:51]: zope-cps was removed from testing because it is incompatible with the current zope2.9 package and it is unmaintained upstream. The support packages for CPS are still in testing, and I ask to remove them as they are useless without

Re: request-tracker3.6 hint lost?

2006-12-28 Thread Marc 'HE' Brockschmidt
Niko Tyni [EMAIL PROTECTED] writes: request-tracker3.6 3.6.1-3 was unblocked on Dec 12 [1], but it's still not getting into etch. Could somebody please have a look? Looks like aba removed the hint when cleaning up his hint file, even though rt3.6 hadn't transitioned yet. I have readded that

Re: Survex debian package uninstallable on hppa

2006-12-28 Thread Wookey
On 2006-12-26 17:44 +, Olly Betts wrote: On Tue, Dec 26, 2006 at 12:28:47PM +0100, Luk Claes wrote: Olly Betts wrote: The hppa binNMU was 1.0.39+b1. Wookey uploaded 1.0.39-1, which has built for all architectures including hppa, but the hppa upload was rejected because 1.0.39-1

Re: Survex debian package uninstallable on hppa

2006-12-28 Thread Luk Claes
Wookey wrote: On 2006-12-26 17:44 +, Olly Betts wrote: On Tue, Dec 26, 2006 at 12:28:47PM +0100, Luk Claes wrote: Olly Betts wrote: The hppa binNMU was 1.0.39+b1. Wookey uploaded 1.0.39-1, which has built for all architectures including hppa, but the hppa upload was rejected because

Re: Bug#395181: initrd-tools?

2006-12-28 Thread maximilian attems
On Thu, Dec 28, 2006 at 04:00:53AM -0800, Steve Langasek wrote: On Sat, Dec 23, 2006 at 08:03:29PM +0100, Andreas Barth wrote: * Noah Meyerhans ([EMAIL PROTECTED]) [061218 19:41]: Our options would seem to be to revise the release notes to no longer suggest upgrading aptitude before

Consider updating discover-data in etch to version 2.2006.12.28

2006-12-28 Thread Petter Reinholdtsen
I just updated discover-data in sid. It should be suitable for etch as well, adding and updating the driver information for some PCI devices. The changelog is included. Please consider including it in etch. Perhaps it should wait 10 days, but I do not expect anything to break while we wait.

SSH upgrade problem

2006-12-28 Thread Martin Schulze
I upgraded a machine from sarge to etch and the process broke over ssh :( Here's the log: Preconfiguring packages ... (Reading database ... 100606 files and directories currently installed.) Unpacking openssh-client (from .../openssh-client_1%3a4.3p2-7_i386.deb) ... Transferring ownership of

Re: SSH upgrade problem

2006-12-28 Thread Russ Allbery
Martin Schulze [EMAIL PROTECTED] writes: I upgraded a machine from sarge to etch and the process broke over ssh :( Here's the log: This is fixed in 1:4.3p2-8, currently in unstable. Several RC bugs have been filed about it, so I expect that we'll want the new version to migrate into etch.

Re: SSH upgrade problem

2006-12-28 Thread Noah Meyerhans
On Thu, Dec 28, 2006 at 06:11:28PM +0100, Martin Schulze wrote: I upgraded a machine from sarge to etch and the process broke over ssh :( I believe this was fixed by 1:4.3p2-8, which should be allowed to enter etch ASAP. noah signature.asc Description: Digital signature

Re: SSH upgrade problem

2006-12-28 Thread Martin Schulze
Noah Meyerhans wrote: On Thu, Dec 28, 2006 at 06:11:28PM +0100, Martin Schulze wrote: I upgraded a machine from sarge to etch and the process broke over ssh :( I believe this was fixed by 1:4.3p2-8, which should be allowed to enter etch ASAP. Cool! Good to know that this problem is

Re: SSH upgrade problem

2006-12-28 Thread Moritz Muehlenhoff
In gmane.linux.debian.devel.release, you wrote: I upgraded a machine from sarge to etch and the process broke over ssh :( Here's the log: Transferring ownership of conffile /etc/init.d/ssh ... Transferring ownership of conffile /etc/pam.d/ssh ... dpkg: error processing

Re: Survex debian package uninstallable on hppa

2006-12-28 Thread Filipus Klutiero
On Thursday 28 December 2006 09:38, Wookey wrote: On 2006-12-26 17:44 +, Olly Betts wrote: On Tue, Dec 26, 2006 at 12:28:47PM +0100, Luk Claes wrote: [...] * Reupload the package as something like 1.0.39.1-1 (or 1.0.39.1 and fix the package to be non-native later when we aren't

playmidi update (new template translation)

2006-12-28 Thread Darren Salt
http://zap.tartarus.org/~ds/playmidi_2.4debian-7.dsc This adds only a Spanish templates translation (bug 404789). Would be nice to have that in etch... -- | Darren Salt| linux or ds at | nr. Ashington, | Toon | RISC OS, Linux | youmustbejoking,demon,co,uk | Northumberland |

Re: why are new upstream versions of glib being uploaded?

2006-12-28 Thread Marc 'HE' Brockschmidt
Thomas Bushnell BSG [EMAIL PROTECTED] writes: On Wed, 2006-12-27 at 09:36 +, Marc 'HE' Brockschmidt wrote: Thomas Bushnell BSG [EMAIL PROTECTED] writes: And one seems perhaps to be responsible for a regression in gnucash (see #404585). Yes, this is due to a stricter input validation in

Re: Security updates

2006-12-28 Thread Mike Hommey
On Thu, Dec 28, 2006 at 02:20:34AM -0800, Steve Langasek [EMAIL PROTECTED] wrote: On Sun, Dec 24, 2006 at 01:40:37PM +0100, Mike Hommey wrote: I see Alex has uploaded version 1.5.0.9 of icedove. What should we take as a course of action for xulrunner, iceweasel and iceape ? Should we go

Please unblock rdiff-backup

2006-12-28 Thread Daniel Baumann
Hi, see attached debdiff. -- Address:Daniel Baumann, Burgunderstrasse 3, CH-4562 Biberist Email: [EMAIL PROTECTED] Internet: http://people.panthera-systems.net/~daniel-baumann/ diff -u rdiff-backup-1.1.5/debian/changelog rdiff-backup-1.1.5/debian/changelog ---

Please hint in dwm-tools

2006-12-28 Thread Daniel Baumann
Hi, the same fix which was accepted in dwm here[0] is also required in dwm-tools. I uploaded dwm-tools 2-2 to t-p-u, please hint it into testing, debdiff is attached, thanks. -- Address:Daniel Baumann, Burgunderstrasse 3, CH-4562 Biberist Email: [EMAIL PROTECTED] Internet:

Please unblock samizdat 0.6.0-3

2006-12-28 Thread Dmitry Borodaenko
This version was the first one uploaded to unstable (on Dec 4, a week before the freeze), and was living in experimental since Nov 29 (previous versions were in experimental since August). No reverse depends, no open bugs, popcon 14. -- Dmitry Borodaenko -- To UNSUBSCRIBE, email to [EMAIL

Re: horae_063-3 uploaded [was: Re: horae_063-2 closes RC bug #404006]

2006-12-28 Thread Carlo Segre
Hello again Andi: I was able to discuss with upstream and he produced a new version which does not depend on libtk-filedialog-perl. This would be horae_064-1. The previously uploaded 063-3 is still fine so please let me know if you prefer me to upload 064-1 for etch or just leave

Re: SSH upgrade problem

2006-12-28 Thread Russ Allbery
Russ Allbery [EMAIL PROTECTED] writes: I'm currently looking at another transition issue with the ssh-krb5 package (it looks like it may disable gssapi-keyex because it adds the configuration option conditionally currently and ssh-krb5 may have attempted that unconditionally), so I *may* be

Re: why are new upstream versions of glib being uploaded?

2006-12-28 Thread Thomas Bushnell BSG
On Thu, 2006-12-28 at 20:45 +0100, Marc 'HE' Brockschmidt wrote: As this may break more applications (earlier version broke locale parsing and gnomevfs), we should probably keep that code, reduce it to a warning for etch and then work out (together with upstream) how to solve this for the

glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Thomas Bushnell BSG
Package: glib2.0 Version: 2.12.5-3 This version of glib (both 2.12.5-3 and 2.12.6-1) causes an important regression in gnucash, and therefore should not go into testing. See http://bugs.debian.org/404585. signature.asc Description: This is a digitally signed message part

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Josselin Mouette
Le jeudi 28 décembre 2006 à 14:47 -0800, Thomas Bushnell BSG a écrit : Package: glib2.0 Version: 2.12.5-3 This version of glib (both 2.12.5-3 and 2.12.6-1) causes an important regression in gnucash, and therefore should not go into testing. See http://bugs.debian.org/404585. What if you

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Thomas Bushnell BSG
On Fri, 2006-12-29 at 00:49 +0100, Josselin Mouette wrote: Le jeudi 28 décembre 2006 à 14:47 -0800, Thomas Bushnell BSG a écrit : Package: glib2.0 Version: 2.12.5-3 This version of glib (both 2.12.5-3 and 2.12.6-1) causes an important regression in gnucash, and therefore should not go

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Josselin Mouette
Le jeudi 28 décembre 2006 à 16:18 -0800, Thomas Bushnell BSG a écrit : I don't think I asked for important bug fixes to be blocked outside etch. On the other hand, the upload of 2.12.5 did not fix any bugs, according to the changelog and the BTS. According to the upstream changelog it fixes

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Thomas Bushnell BSG
On Fri, 2006-12-29 at 01:41 +0100, Josselin Mouette wrote: 1) The release team has asked us not to upload changes which are not destined for etch, and making gnucash work with the glib in unstable is therefore a low priority; The glib in unstable is destined for etch, whether you like it

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Steve Langasek
On Thu, Dec 28, 2006 at 04:18:01PM -0800, Thomas Bushnell BSG wrote: 3) The change altered the syntax of the file by adding restrictions. It is therefore a non-backwards-compatible change to the ABI, and therefore it needs an so-name bump. No amount of adding this or that character will

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Josselin Mouette
Le jeudi 28 décembre 2006 à 16:46 -0800, Thomas Bushnell BSG a écrit : What part of the freeze policy do you not understand? You uploaded two new upstream versions which fix no Debian bugs *after* the freeze. Do you want me to report a Debian bug for each upstream issue? Or do you really

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Steve Langasek
On Fri, Dec 29, 2006 at 01:41:17AM +0100, Josselin Mouette wrote: Sorry, but you don't make a soname bump just for the sake of applications ignoring function semantics. Right. You also don't introduce regressions in an indeterminate number of other packages during a freeze just because those

please unblock cupsys 1.2.7-2

2006-12-28 Thread Kenshi Muto
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, Could you unblock cupsys 1.2.7-2 for Etch? changelog: cupsys (1.2.7-2) unstable; urgency=high [ Kenshi Muto ] * Applied upstream patches to fix some (include RC) bugs as dpatch style: - STR2106: Raw PBM files did not print correctly

Unblock request for epiphany-browser

2006-12-28 Thread Jordi Mallach
Hello release team, I just uploaded epiphany-browser, with only dependency changes (added one on xulrunner-gnome-support), so generated error messages show icons (see bug #404755). If the changes are acceptable, it'd be nice to have the package updated in testing when the 5 day wait is over.

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Thomas Bushnell BSG
On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are clearly two plausible solutions to the underlying problem: 1. Change gnucash to conform to the new

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Thomas Bushnell BSG
On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. Here is a sample file; I suspect the offending character is the space, if I'm reading Marc Brockschmidt's regex

Re: Will eclipse be part of etch?

2006-12-28 Thread Steve Langasek
On Tue, Dec 19, 2006 at 02:16:54AM -0800, Peter Ronnquist wrote: It seems like eclipse will not be part of the etch release. Is this a mistake? No, it is not; it's a direct consequence of the eclipse maintainers not having a releasable package at the appropriate point in the release cycle.

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Josselin Mouette
Le jeudi 28 décembre 2006 à 17:29 -0800, Thomas Bushnell BSG a écrit : On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are clearly two plausible solutions

Re: python 2.3

2006-12-28 Thread Steve Langasek
On Fri, Dec 22, 2006 at 12:38:05AM +0100, Matthias Klose wrote: An explicitely stated goal of the release team was to reduce the number of supported python versions for the next stable release. It was? I don't remember this... I certainly wanted to make sure etch didn't release with ancient,

Re: Wesnoth 1.2 uploaded

2006-12-28 Thread Steve Langasek
On Mon, Dec 25, 2006 at 09:16:29PM +0100, Isaac Clerencia wrote: On Sunday, 24 December 2006 10:06, Andreas Barth wrote: Please allow us to remind you once again on the upload policy: If your upload is not meant for Etch, do not upload it to unstable but to experimental. If your upload is

Re: python 2.3

2006-12-28 Thread Frans Pop
On Friday 29 December 2006 03:10, Steve Langasek wrote: It was? I don't remember this... I certainly wanted to make sure etch didn't release with ancient, lingering versions of python like 2.1 and 2.2, but from a release POV I never had strong feelings about getting rid of python 2.3, which

Re: Bug#404888: glib2.0: cannot go into testing; causes gnucash regrsession

2006-12-28 Thread Martin Schulze
Josselin Mouette wrote: Le jeudi 28 décembre 2006 à 17:29 -0800, Thomas Bushnell BSG a écrit : On Fri, 2006-12-29 at 01:56 +0100, Josselin Mouette wrote: Now, if you don't provide us with the necessary data, we won't be able to fix the regression it introduces in gnucash. There are