NEW changes in proposedupdates

2010-10-24 Thread Debian FTP Masters
Processing changes file: mantis_1.1.6+dfsg-2lenny3_i386.changes ACCEPT -- To UNSUBSCRIBE, email to debian-release-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/e1pacia-00062u...@franck.debian.org

Bug#601304: unblock: speech-tools/1:2.0.95~beta-2

2010-10-24 Thread Kumar Appaiah
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock package speech-tools (not yet uploaded) I have attached the update diff. The bug being fixed is #601294; a summary is that use of audsp causes festival to crash. Wou

Bug#601293: unblock: devscripts/2.10.69

2010-10-24 Thread James Vega
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package devscripts The upload is primarily translation updates and build system changes to make the translated devscripts.1 contain the same information as the English versio

Freeze exception for Octave

2010-10-24 Thread Thomas Weber
Hi, in order to fix #598227 (http://bugs.debian.org/598227), I would like to upload octave with the attached patch (it adds /usr/include/mpi to the include path used by mkoctfile, the script used for generating 'addons' for Octave). It shouldn't have any influence on other packages. Post-Squeeze

Bug#601284: unblock: griffith/0.12.1-1

2010-10-24 Thread Piotr Ożarowski
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock package griffith Works with python-sqlalchemy 0.6.* (the one in Squeeze). That's the version I wanted to release upstream short after DebConf10. unblock griffith/0.

Bug#601282: unblock: paste/1.7.5.1-1

2010-10-24 Thread Piotr Ożarowski
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock package paste It's a bug fix release, also workarounds a problem with online debugger (libjs-mochikit moved to Recommeds, I will convert whole Pylons stack to dh_pyt

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-24 at 21:22 +0200, sils wrote: > On 10/24/2010 07:36 PM, Adam D. Barratt wrote: > > Have you confirmed with the security team that they do not wish to > > resolve this via a DSA? I realise that the previous XSS issues were > > fixed via p-u, but > > http://security-tracker.debian.o

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread Luk Claes
On 10/24/2010 09:22 PM, sils wrote: > Hi again, > > On 10/24/2010 07:36 PM, Adam D. Barratt wrote: >> Have you confirmed with the security team that they do not wish to >> resolve this via a DSA? I realise that the previous XSS issues were >> fixed via p-u, but >> http://security-tracker.debian.o

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
Hi again, On 10/24/2010 07:36 PM, Adam D. Barratt wrote: Have you confirmed with the security team that they do not wish to resolve this via a DSA? I realise that the previous XSS issues were fixed via p-u, but http://security-tracker.debian.org/tracker/CVE-2010-3303 is not currently marked "no

Bug#600465: unblock: freeradius 2.1.10+dfsg-1

2010-10-24 Thread Josip Rodin
[For Alan: I requested for FreeRADIUS 2.1.10 to replace 2.1.9 in the future Debian 6.0 release; the former came too late in our process to be accepted automatically.] On Sun, Oct 24, 2010 at 05:10:58PM +0100, Adam D. Barratt wrote: > On Sun, 2010-10-17 at 13:45 +0200, Josip Rodin wrote: > > Peopl

Bug#601272: marked as done (unblock: dctrl-tools/2.14.5)

2010-10-24 Thread Debian Bug Tracking System
Your message dated Sun, 24 Oct 2010 20:04:20 +0100 with message-id <1287947060.27210.3008.ca...@hathi.jungle.funky-badger.org> and subject line Re: Bug#601272: unblock: dctrl-tools/2.14.5 has caused the Debian Bug report #601272, regarding unblock: dctrl-tools/2.14.5 to be marked as done. This mea

Bug#601272: unblock: dctrl-tools/2.14.5

2010-10-24 Thread Antti-Juhani Kaijanaho
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock this dctrl-tools translation update: dctrl-tools (2.14.5) unstable; urgency=low * po/es.po: Updated by Javier Fernández-Sanguino Peña (closes: #599858) * po/ca.po: Updat

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
On 10/24/2010 07:36 PM, Adam D. Barratt wrote: On Sun, 2010-10-24 at 18:53 +0200, sils wrote: Attached you will find the diff between mantis_1.1.6+dfsg-2lenny2 (currently in s-p-u) and mantis_1.1.6+dfsg-2lenny3 with the fix for CVE-2010-3303. I did not uploaded any package until receive a conf

Re: Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-24 at 18:53 +0200, sils wrote: > Attached you will find the diff between mantis_1.1.6+dfsg-2lenny2 > (currently in s-p-u) and mantis_1.1.6+dfsg-2lenny3 with the fix for > CVE-2010-3303. > > I did not uploaded any package until receive a confirmation or > guidelines from the rele

Re: Pre-approval request for dpkg sync() changes for squeeze

2010-10-24 Thread Andreas Barth
* Phillip Susi (ps...@cfl.rr.com) [101024 19:15]: > True, but that seems a bit of a contrived corner case. Most of the time > when people are upgrading, I'd wager that they don't have many gb of > dirty cache buffers already sitting in the cache. Though that does make > me wonder why there

Re: Pre-approval request for dpkg sync() changes for squeeze

2010-10-24 Thread Phillip Susi
On 10/24/2010 07:16 AM, Goswin von Brederlow wrote: Or 5 minutes because sync() also needs to write out the 16GB cache data to my usb 1.0 drive that is not involved with dpkg at all. True, but that seems a bit of a contrived corner case. Most of the time when people are upgrading, I'd wager t

Fixed - mantis: CVE-2010-3303 xss vulnerability (Permission to upload)

2010-10-24 Thread sils
Hi Team, Attached you will find the diff between mantis_1.1.6+dfsg-2lenny2 (currently in s-p-u) and mantis_1.1.6+dfsg-2lenny3 with the fix for CVE-2010-3303. I did not uploaded any package until receive a confirmation or guidelines from the release team about how to proceed. Please let me

Bug#600465: unblock: freeradius 2.1.10+dfsg-1

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-17 at 13:45 +0200, Josip Rodin wrote: > People keep coming to the upstream freeradius-users mailing list asking for > help with 2.0.4, and they increasingly get funny looks because it's a > randomly ancient version, by the upstream people's standards. > > Right now we have 2.1.8 in

Re: Security unblock requests

2010-10-24 Thread Adam D. Barratt
On Sat, 2010-10-23 at 23:00 +0200, Moritz Muehlenhoff wrote: > 1. freeradius (#600465) -> CVE-2010-3696 and CVE-2010-3697 Followed-up. > 2. mercurial 1.6.4 fixes #598841. The asked in advance and were told > to upload w/o a guarantee of a later unblock. Please check. Unblocked. Regards, Adam

Re: Fwd: Bug#598850: please consider including mercurial 1.6.4 in squeeze

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-17 at 18:37 +0100, Javi Merino wrote: > On 06/10/10 22:27, Julien Cristau wrote: > > Please upload. (No guarantee of an unblock later, I just want to see > > the actual diff. So you can upload to experimental instead if you > > don't want to take the chance.) > > > > Uploaded. C

Re: Security unblock requests

2010-10-24 Thread Adam D. Barratt
On Sat, 2010-10-23 at 22:32 +0200, Moritz Muehlenhoff wrote: > On 2010-10-18, Julien Cristau wrote: > >> webkit/1.2.5-1 -> Multiple CVE IDs > > > > debian/patches/debian-changes-1.2.5-1 seems to revert the rest of the > > patches, that looks broken. > > Seems fixed in 1.2.5-2. Unblocked by Mehdi

Bug#601199: unblock: mono-debugger/2.6.3-2.1

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-24 at 12:40 +0200, Moritz Muehlenhoff wrote: > Please unblock package mono-debugger. It fixes CVE-2010-3369. I'm not really convinced about the utility of this: ++ tmp=$(echo "$1" | sed -e 's/::\+// ; s/^:// ; s/:$//' ) The code is already using ${LD_LIBRARY_PATH:+:$LD_LIBRARY_

Re: please unblock reprepro 4.2.0-2

2010-10-24 Thread Adam D. Barratt
On Sun, 2010-10-24 at 12:55 +0200, Bernhard R. Link wrote: > * Adam D. Barratt [101023 19:58]: > > On Sat, 2010-10-23 at 16:21 +0200, Bernhard R. Link wrote: > > > - make it compile with gcc-4.5 (#600982) > > > by simple including a header more. > > > (gcc-4.5 is not in squeeze, but I guess it

Re: Pre-upload approval for gThumb

2010-10-24 Thread David Paleino
On Sun, 24 Oct 2010 13:28:29 +0200, Philipp Kern wrote: > On Sat, Oct 23, 2010 at 10:36:08PM +0200, David Paleino wrote: > > today I received #601137 -- i.e. gThumb segfaults because of an unhandled > > situation of a missing Exif tag (the "orientation"). > > I could track it down, and made a patc

Bug#601219: unblock pyxplot/0.8.3-1

2010-10-24 Thread Stuart Prescott
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Dear release team, I think my original request got caught in a race condition between me drafting it, getting the package uploaded (three weeks ago), letting it age and you requesting tha

Please unblock fuse-convmvfs/0.2.6-1

2010-10-24 Thread Stanislav Maslovski
Dear Release Team, About a weak ago I have uploaded a new upstream version of my package fuse-convmvfs that fixes some important symlink dereferencing and owner issues (Debian Bug #594021). Please consider unblocking this package. The packaging changelog: fuse-convmvfs (0.2.6-1) unstable; urgenc

Re: [MBF proposal] Empty packages in the archive

2010-10-24 Thread Luca Falavigna
I've just submitted relevant bugs, list can be found here: http://bugs.debian.org/cgi-bin/pkgreport.cgi?users=debian...@lists.debian.org;tag=empty-package -- .''`. : :' : Luca Falavigna `. `' `- signature.asc Description: OpenPGP digital signature

Re: advice for syncevolution in squeeze

2010-10-24 Thread Patrick Ohly
On Sa, 2010-10-23 at 17:08 +0100, Adam D. Barratt wrote: > On Sun, 2010-10-10 at 14:33 -0300, David Bremner wrote: > > Around the > > time of the freeze, I asked on the upstream list for any serious issues > > with the debian packages, and not receiving any reports, decided to > > stick with the ve

Pre-approval for dblatex: fix for annoying #594601

2010-10-24 Thread Andreas Hoenen
Hi, would you grant me a freeze exception for fixing BTS #594601: dblatex: util.py:8: DeprecationWarning: md5 deprecated; use hashlib instead ? Although the update would not fall into one of the official exception categories, it is comparable to a recent rubber update during the freeze: >

Re: "new" udebs

2010-10-24 Thread Philipp Kern
On Wed, Oct 20, 2010 at 09:13:50PM +0100, Adam D. Barratt wrote: > There are currently some udeb-producing packages which are neither on > the "needs approval from a d-i RM before migrating" list, nor the > explicit "can migrate at will" list; from a quick scan, many of them > appear to be kfreebsd

Re: #600890: Frequent upstream server API changes

2010-10-24 Thread Philipp Kern
On Thu, Oct 21, 2010 at 04:50:53PM +0200, Michael Fladischer wrote: > I'm now stuck on how to proceed, as those version increments can happen > anytime (upstream told me they are planning on further increments in the > near future). Is removing the package from Squeeze and shipping the > latest ver

Re: Pre-upload approval for gThumb

2010-10-24 Thread Philipp Kern
On Sat, Oct 23, 2010 at 10:36:08PM +0200, David Paleino wrote: > today I received #601137 -- i.e. gThumb segfaults because of an unhandled > situation of a missing Exif tag (the "orientation"). > I could track it down, and made a patch [1] for it. [...] > [1]: > http://git.debian.org/?p=collab-main

Re: Pre-approval request for dpkg sync() changes for squeeze

2010-10-24 Thread Goswin von Brederlow
Phillip Susi writes: > On 10/22/2010 5:35 AM, Guillem Jover wrote: >> 1) Switch back from sync() to fsync() before rename() (while keeping > > Don't you WANT to use sync? If you fsync every file that is going to be > rather slow since it forces a disk write for every file, rather than > allowi

Bug#601199: unblock: mono-debugger/2.6.3-2.1

2010-10-24 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package mono-debugger. It fixes CVE-2010-3369. unblock mono-debugger/2.6.3-2.1 -- System Information: Debian Release: squeeze/sid APT prefers unstable APT policy: (500,

please unblock reprepro 4.2.0-2

2010-10-24 Thread Bernhard R. Link
* Adam D. Barratt [101023 19:58]: > On Sat, 2010-10-23 at 16:21 +0200, Bernhard R. Link wrote: > > - make it compile with gcc-4.5 (#600982) > > by simple including a header more. > > (gcc-4.5 is not in squeeze, but I guess it would still nice to > >have things in a release buildable with c

Bug#600210: Freeze Exception: libgda4

2010-10-24 Thread Piotr Pokora
On 23.10.2010 19:44, Adam D. Barratt wrote: Without this release, any derived application or library breaks to build with GObject Introspection enabled. Which of the fixes mentioned in upstream's changelog does the above refer to? * libgda/gda-debug-macros.h, libgda/gda-transaction-status.c: