Bug#1006944: transition: proj

2022-03-23 Thread Sebastiaan Couwenberg
On 3/23/22 08:09, Sebastiaan Couwenberg wrote: On 3/22/22 16:58, Sebastiaan Couwenberg wrote: On 3/22/22 09:44, Sebastiaan Couwenberg wrote: On 3/21/22 22:43, Sebastian Ramacher wrote: Please go ahead Thanks. proj (9.0.0-1) has been uploaded to unstable and is now built & installed on all

Re: Bits from the Release Team: bookworm freeze dates (preliminary)

2022-03-23 Thread Otto Kekäläinen
Hi! On Thu, Mar 17, 2022 at 4:09 AM Paul Gevers wrote: .. > 2023-01-12 - Milestone 1 - Transition and toolchain freeze > 2023-02-12 - Milestone 2 - Soft Freeze > 2023-03-12 - Milestone 3 - Hard Freeze - for key packages and > packages without

Bug#1008184: nmu: unknown packages affected by dpkg-dev bug #1000421

2022-03-23 Thread Adrian Bunk
On Thu, Mar 24, 2022 at 01:01:10AM +0200, Adrian Bunk wrote: >... > FTR, this seems to be a 2 month window (give or take a few days due to > buildd chroots being updated only twice per week): >... 3 month window cu Adrian

Bug#1008184: nmu: unknown packages affected by dpkg-dev bug #1000421

2022-03-23 Thread Adrian Bunk
On Wed, Mar 23, 2022 at 11:29:48PM +0100, Guillem Jover wrote: >... > What unearthed this was a recentish glibc upload that AFAIR has started > merging its libpthread library into libc proper, and added a new symbol > for a variable (__libc_single_threaded@GLIBC_2.32). The merging only happens in

Bug#1008184: nmu: unknown packages affected by dpkg-dev bug #1000421

2022-03-23 Thread Guillem Jover
Package: release.debian.org Severity: important User: release.debian@packages.debian.org Usertags: binnmu Hi! The objdump tool changed its output for copy relocations for versioned symbols (from @@ to @) in binutils 2.26 (uploaded on 2016-01). This has caused dpkg-shlibdeps to ignore some of

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-23 Thread Sebastian Andrzej Siewior
On 2022-03-23 17:40:59 [+], Adam D. Barratt wrote: > Right, let's have another go at this then: > > " > OpenSSL signature algorithm check tightening > = > > The OpenSSL update provided in this point release includes a > change to ensure that the

Bug#1008143: marked as done (nmu: uwsgi-plugin-php_2.0.20+2+0.0.13+b1)

2022-03-23 Thread Debian Bug Tracking System
Your message dated Wed, 23 Mar 2022 19:44:10 +0100 with message-id <058cf01c-ff8e-fb65-1d0f-1882ffde2...@debian.org> and subject line Re: Bug#1008143: nmu: uwsgi-plugin-php_2.0.20+2+0.0.13+b1 has caused the Debian Bug report #1008143, regarding nmu: uwsgi-plugin-php_2.0.20+2+0.0.13+b1 to be marked

Processed: tagging 1008164

2022-03-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 1008164 + bullseye Bug #1008164 [release.debian.org] RM: obfs4proxy/0.0.8-1 Added tag(s) bullseye. > thanks Stopping processing here. Please contact me if you need assistance. -- 1008164:

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-23 Thread Adam D. Barratt
On Tue, 2022-03-22 at 22:13 +0100, Sebastian Andrzej Siewior wrote: > On 2022-03-22 21:47:52 [+0100], Kurt Roeckx wrote: > > On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > > > OpenSSL signature algorithm check tightening > > > = > > >

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_ppc64el-buildd.changes ACCEPT

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_mips64el-buildd.changes ACCEPT

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_armhf-buildd.changes ACCEPT Processing changes file: debian-installer_20190702+deb10u12_mipsel-buildd.changes ACCEPT

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_amd64-buildd.changes ACCEPT Processing changes file: debian-installer_20190702+deb10u12_armel-buildd.changes ACCEPT Processing changes file: debian-installer_20190702+deb10u12_i386-buildd.changes ACCEPT Processing changes file:

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_arm64-buildd.changes ACCEPT Processing changes file: debian-installer_20190702+deb10u12_mips-buildd.changes ACCEPT

Processed: Re: Bug#1007906: transition: mutter

2022-03-23 Thread Debian Bug Tracking System
Processing control commands: > tags -1 - moreinfo Bug #1007906 [release.debian.org] transition: mutter Removed tag(s) moreinfo. -- 1007906: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1007906 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1007906: transition: mutter

2022-03-23 Thread Simon McVittie
Control: tags -1 - moreinfo On Fri, 18 Mar 2022 at 12:00:56 +, Simon McVittie wrote: > As usual, this includes a libmutter ABI break, from libmutter-9-0 to > libmutter-10-0. Suitable versions of gnome-shell and budgie-desktop are > already available in experimental. The GNOME team is ready

Bug#1007905: transition: icu

2022-03-23 Thread Jeremy Bicha
On Wed, Mar 23, 2022 at 10:53 AM Simon McVittie wrote: > On Mon, 21 Mar 2022 at 06:50:34 +0100, László Böszörményi wrote: > > As noted, mozjs78 and 0ad FTBFS in my pbuilder setups. > > That's interesting, 0ad built fine for me against 70.1 on a porterbox > (i386 on barriere) - and its vendored

Bug#1007905: transition: icu

2022-03-23 Thread Simon McVittie
On Sat, 19 Mar 2022 at 09:28:49 +0200, Adrian Bunk wrote: > On Fri, Mar 18, 2022 at 06:05:38PM +, Simon McVittie wrote: > > Obviously all these copies of essentially the same codebase are quite > > unfortunate, but mozjs and ICU seem to be sufficiently tightly-coupled > > that perhaps using

Processed: affects 1008143

2022-03-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > affects 1008143 uwsgi-plugin-php Bug #1008143 [release.debian.org] nmu: uwsgi-plugin-php_2.0.20+2+0.0.13+b1 Added indication that 1008143 affects uwsgi-plugin-php > thanks Stopping processing here. Please contact me if you need assistance. --

Bug#1008168: bullseye-pu: package node-url-parse/1.5.3-1+deb11u1

2022-03-23 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-url-parse is vulnerable to an authorization Bypass Through User-Controlled (CVE-2022-0686). [ Impact ] medium vulnerability [ Tests ] Test updated, passed [

Bug#1008166: bullseye-pu: package debian-edu-config/2.11.56+deb11u4

2022-03-23 Thread Mike Gabriel
Hi again, On Mi 23 Mär 2022 13:19:54 CET, Mike Gabriel wrote: [ Tests ] (What automated or manual tests cover the affected code?) I forgot to mention the nature of the performed tests. All code changes were tested in the field on at least 2 sometimes 3 Debian Edu production sites. All

Bug#1008166: bullseye-pu: package debian-edu-config/2.11.56+deb11u4

2022-03-23 Thread Mike Gabriel
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: debian-...@lists.debian.org [ Reason ] While setting up a new Debian Edu school in Dec/Jan 2021/2022 several issues popped up in Debian Edu 11 that have now been

Bug#1008164: RM: obfs4proxy/0.0.8-1

2022-03-23 Thread Ana Custura
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Opening this bug after a recomendation from debian-security. Version 0.0.8 of obfs4proxy has a security bug, which has only been fixed in a later version (0.0.13, see bug number #1004374), and

Bug#1008163: buster-pu: package node-minimist/1.2.0-1+deb10u2

2022-03-23 Thread Yadd
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-minimist is vulnerable to a prototype pollution not totally fixed by CVE-2020-7598 patch (pushed in 1.2.5-1 and 1.2.0-1+deb10u1) [ Impact ] Medium vulnerability [

Bug#1008162: bullseye-pu: package node-minimist/1.2.5+~cs5.3.1-2+deb11u1

2022-03-23 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-minimist is vulnerable to a prototype pollution not totally fixed by CVE-2020-7598 patch (pushed in 1.2.5-1 and 1.2.0-1+deb10u1) [ Impact ] Medium vulnerability

Bug#1008161: bullseye-pu: package geeqie/1.6-9+deb11u1

2022-03-23 Thread Andreas Rönnquist
Package: release.debian.org User: release.debian@packages.debian.org Usertags: pu Tags: bullseye Severity: normal I would like to fix a bug in geeqie in bullseye where selecting several items in a file-list and then trying to deselect one item using Ctrl+click doesn't work as it should.

NEW changes in oldstable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20190702+deb10u12_source.changes ACCEPT

Bug#1008154: buster-pu: package node-node-forge/0.8.1~dfsg-1+deb10u1

2022-03-23 Thread Yadd
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-node-forge signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses

Bug#1008153: bullseye-pu: package node-node-forge/0.10.0~dfsg-3+deb11u1

2022-03-23 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-node-forge signature verification code is lenient in checking the digest algorithm structure. This can allow a crafted structure that steals padding bytes and uses

NEW changes in stable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20210731+deb11u3_armhf-buildd.changes ACCEPT Processing changes file: debian-installer_20210731+deb11u3_mipsel-buildd.changes ACCEPT

NEW changes in stable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20210731+deb11u3_amd64-buildd.changes ACCEPT Processing changes file: debian-installer_20210731+deb11u3_arm64-buildd.changes ACCEPT Processing changes file: debian-installer_20210731+deb11u3_armel-buildd.changes ACCEPT Processing changes file:

NEW changes in stable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20210731+deb11u3_ppc64el-buildd.changes ACCEPT Processing changes file: debian-installer_20210731+deb11u3_s390x-buildd.changes ACCEPT

Bug#1008143: nmu: uwsgi-plugin-php_2.0.20+2+0.0.13+b1

2022-03-23 Thread Alexandre Rossi
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu nmu uwsgi-plugin-php_2.0.20+2+0.0.13+b1 . ANY . unstable . -m "rebuilt against uwsgi-src 2.0.20+4 to fix #1007774" uwsgi-plugin-php is currently broken in unstable (see #1007774).

Processed: tags 1002956 -moreinfo

2022-03-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 1002956 -moreinfo Bug #1002956 [release.debian.org] bullseye-pu: package rabbitmq-server/3.8.9-3 CVE-2021-32718, CVE-2021-32719 Bug #1004513 [release.debian.org] bullseye-pu: package rabbitmq-server/3.8.9-3 Removed tag(s) moreinfo. Removed

Bug#1006944: transition: proj

2022-03-23 Thread Sebastiaan Couwenberg
On 3/22/22 16:58, Sebastiaan Couwenberg wrote: On 3/22/22 09:44, Sebastiaan Couwenberg wrote: On 3/21/22 22:43, Sebastian Ramacher wrote: Please go ahead Thanks. proj (9.0.0-1) has been uploaded to unstable and is now built & installed on all release architectures. Thanks for scheduling

NEW changes in stable-new

2022-03-23 Thread Debian FTP Masters
Processing changes file: debian-installer_20210731+deb11u3_source.changes ACCEPT