Bug#989168: unblock: ceph/14.2.21-1 (CVE-2021-3509, CVE-2021-3524, CVE-2021-3531)

2021-05-27 Thread Thomas Goirand
g. Cheers, Thomas Goirand (zigo) unblock ceph/14.2.21-1 diff -Nru ceph-14.2.20/alpine/APKBUILD ceph-14.2.21/alpine/APKBUILD --- ceph-14.2.20/alpine/APKBUILD2021-04-19 16:13:23.0 +0200 +++ ceph-14.2.21/alpine/APKBUILD2021-05-13 19:25:52.0 +0200 @@ -1,7 +1,7 @@ # Contrib

Bug#987081: unblock: puppet-module-puppetlabs-haproxy/2.1.0-3

2021-05-28 Thread Thomas Goirand
please still unblock this fix, which is IMO a way more annoying than just removing the alternatives on removal/disappear. Cheers, Thomas Goirand (zigo) On 5/27/21 9:26 PM, Paul Gevers wrote: > Hi Thomas, > > Ping. > > Paul > Note: without reply, we'll close the bug wi

Bug#989851: pre-approval unblock: uwsgi/2.0.19.1-8

2021-06-14 Thread Thomas Goirand
m [x] attach debdiff against the package in testing Please allow me to unblock uwsgi/2.0.19.1-8 with the attached patch, targetting Bullseye, Cheers, Thomas Goirand (zigo) >From 722db2ea22eb454ed678bd6ff8b1c2f287df4802 Mon Sep 17 00:00:00 2001 From: Thomas Goirand Date: Fri, 11 Jun 20

Bug#989851: pre-approval unblock: uwsgi/2.0.19.1-8

2021-06-16 Thread Thomas Goirand
On 6/16/21 1:14 PM, Graham Inggs wrote: > Control: tags -1 + moreinfo > > Hi Thomas > > On Mon, 14 Jun 2021 at 21:12, Thomas Goirand wrote: >> [x] attach debdiff against the package in testing > > You've attached a debdiff against uwsgi/2.0.19.1-7 in unstable,

Bug#989851: pre-approval unblock: uwsgi/2.0.19.1-7.1

2021-06-17 Thread Thomas Goirand
On 6/16/21 8:04 PM, Jonas Smedegaard wrote: > [ replying via bugreport ] > > Quoting Thomas Goirand (2021-06-16 19:20:44) >> Can I NMU uwsgi as per the discussion with the release team? Should it >> be 2.0.19.1-7.1 or 2.0.19.1-8? Should I also open a merge request on >&

Bug#990470: unblock: neutron/17.1.1-6

2021-06-30 Thread Thomas Goirand
urgency=medium + + * Add fix-rootwrap-does-not-include-python-3.9.patch. + + -- Thomas Goirand Wed, 30 Jun 2021 10:51:00 +0200 + neutron (2:17.1.1-5) unstable; urgency=high * CVE-2021-20267: Anti-spoofing bypass using Open vSwitch. Applied upstream diff -Nru neutron-17.1.1/debian/patches/fix-ro

Bug#990530: unblock: horizon/18.6.2-4 and all of its plugins

2021-07-01 Thread Thomas Goirand
bian/changelog +++ b/debian/changelog @@ -1,3 +1,9 @@ +cloudkitty-dashboard (11.0.0-2) unstable; urgency=medium + + * Fix installation of files in the enable folder. + + -- Thomas Goirand Wed, 30 Jun 2021 11:20:03 +0200 + cloudkitty-dashboard (11.0.0-1) unstable; urgency=medium * New upstream

Bug#990530: Wrong version for vitrage

2021-07-01 Thread Thomas Goirand
vitrage-dashboard/2.0.0-3

Bug#990530: unblock: horizon/18.6.2-4 and all of its plugins

2021-07-04 Thread Thomas Goirand
have a changelog entry. I'll fix these tomorrow morning and let will let you know. Cheers, Thomas Goirand (zigo)

Bug#990530: unblock: horizon/18.6.2-4 and all of its plugins

2021-07-05 Thread Thomas Goirand
On 7/4/21 8:21 PM, Thomas Goirand wrote: > On 7/1/21 10:48 PM, Sebastian Ramacher wrote: >>> magnum-ui/7.0.0-2 >> >> This seems to be missing an upload. > > magnum-ui uploaded. unblock: magnum-ui/7.0.0-2 >>> sahara-dashboard/13.0.0-2 >> >> Th

Bug#990990: unblock: libcgroup/2.0

2021-07-12 Thread Thomas Goirand
omponent mandating these kernel parameters, making it the least convenient platform to run cgroups v1. So yeah, by all means, let's get things fixed! Cheers, Thomas Goirand (zigo)

Bug#991063: unblock: nova/22.0.1-2

2021-07-13 Thread Thomas Goirand
+ * Do not set [glance]/api_servers http://localhost:9292 as default: let +Nova figure it out from the Keystone catalogue. + + -- Thomas Goirand Mon, 12 Jul 2021 12:57:03 +0200 + nova (2:22.0.1-1) unstable; urgency=medium * New upstream point release. diff -Nru nova-22.0.1/debian/cont

Bug#991071: unblock: websockify/0.9.0+dfsg1-3

2021-07-13 Thread Thomas Goirand
3) unstable; urgency=medium + + [ Jochen Sprickerhof ] + * Fix rebind.so not found (Closes: #990359), thanks to Mike Gabriel for the +bug report, and Jochen Sprickerhof for the fix. + + -- Thomas Goirand Mon, 12 Jul 2021 09:18:22 +0200 + websockify (0.9.0+dfsg1-2) unstable; urgency=medium

Bug#991097: unblock: horizon/18.6.2-5

2021-07-14 Thread Thomas Goirand
0 +++ horizon-18.6.2/debian/changelog 2021-07-14 11:19:22.0 +0200 @@ -1,3 +1,11 @@ +horizon (3:18.6.2-5) unstable; urgency=medium + + * Add patches: +- Dont_load_user_role_assignment_or_groups_tabs_for_non-admins.patch +- do-not-create-volume-by-default-when-launching-instance.

Bug#991161: unblock: python-nosehtmloutput/0.0.5-3

2021-07-16 Thread Thomas Goirand
-nosehtmloutput (0.0.5-3) unstable; urgency=medium + + * Added upstream "Python 3 support" patch (Closes: #990816). + + -- Thomas Goirand Fri, 16 Jul 2021 09:23:39 +0200 + python-nosehtmloutput (0.0.5-2) unstable; urgency=medium * Team upload. diff -Nru python-nosehtmloutput-0.0.5/debi

Bug#990990: unblock: libcgroup/2.0

2021-07-20 Thread Thomas Goirand
e cgcreate / cgset without any additional kernel command line parameters (please let me know if I'm mistaking). On the OpenStack side, that's the only thing which is needed. Cinder isn't using any library directly, they just use the cgroup userland binaries. As for Nova, I'm not even sure it's doing anything but using features from Qemu/Libvirt (this would have to be checked). At least, doing a "grep -r cgcreate" in the Nova source code returns nothing. Cheers, Thomas Goirand (zigo)

Bug#992330: bullseye-pu: package nova/22.2.2-1+deb11u1 (CVE-2021-3654)

2021-08-17 Thread Thomas Goirand
his forces having something. After removing the debconf integration for this directive, upgrade to the proposed update isn't breaking deployments anymore, while leaving already configured glance_api_servers alone (so not destroying anyone setup). Please allow me to upload nova/22.2.2-1+deb11u1 to Bullseye, Cheers, Thomas Goirand (zigo)

Bug#992331: buster-pu: package keystone/18.0.0-3+deb11u1 (CVE-2021-38155)

2021-08-17 Thread Thomas Goirand
or Keystone which is usually a very busy componant of any OpenStack deployment, so I very much would like this to be accepted too. Please allow me to upload keystone/18.0.0-3+deb11u1. Cheers, Thomas Goirand (zigo) diff -Nru keystone-18.0.0/debian/changelog keystone-18.0.0/debian/changelog --- keyst

Bug#992330: bullseye-pu: package nova/22.2.2-1+deb11u1 (CVE-2021-3654)

2021-08-20 Thread Thomas Goirand
you see, it is taking way too long to get things updated in Debian as we go through the normal administrative workflow. Also, I do expect OpenStack users to use these unofficial backport repositories. So I have to find ways to cover for production use. Please bare with this. Cheers, Thomas Goirand (zigo)

Re: careless upload of Erlang v24 without a transition tracking with the release team (was: rabbitmq-server fails to start after erlang v24 update)

2021-08-22 Thread Thomas Goirand
g v24 in Unstable, and open a release team bug to get a transition tracker thingy, which is the only sane way to do things in Debian? Not amused... Thomas Goirand (zigo)

Re: careless upload of Erlang v24 without a transition tracking with the release team (was: rabbitmq-server fails to start after erlang v24 update)

2021-08-22 Thread Thomas Goirand
Hi Sergei, Thanks for your quick reply. On 8/22/21 6:14 PM, Sergei Golovan wrote: > Hi Thomas, > > On Sun, Aug 22, 2021 at 6:55 PM Thomas Goirand wrote: >> >> Hi Damir, Sergei, the release team, >> >> First of all, thanks for your bug report, Damir. >>

Re: careless upload of Erlang v24 without a transition tracking with the release team (was: rabbitmq-server fails to start after erlang v24 update)

2021-08-22 Thread Thomas Goirand
On 8/22/21 8:57 PM, Adrian Bunk wrote: > On Sun, Aug 22, 2021 at 07:14:16PM +0200, Thomas Goirand wrote: >> ... >> On 8/22/21 6:14 PM, Sergei Golovan wrote: >> ... >>> I've uploaded Erlang 24 to experimental months ago. If you know that >>> your sof

Bug#993720: bullseye-pu: package automysqlbackup/2.6+debian.4-3

2021-09-05 Thread Thomas Goirand
table [x] the issue is verified as fixed in unstable Cheers, Thomas Goirand (zigo) diff -Nru automysqlbackup-2.6+debian.4/debian/changelog automysqlbackup-2.6+debian.4/debian/changelog --- automysqlbackup-2.6+debian.4/debian/changelog 2020-07-04 20:56:25.0 +0200 +++ automysql

Bug#993793: bullseye-pu: package reportbug/7.10.3

2021-09-06 Thread Thomas Goirand
e issue is verified as fixed in unstable Cheers, Thomas Goirand (zigo) diff -Nru reportbug-7.10.3/debian/changelog reportbug-7.10.3+deb11u1/debian/changelog --- reportbug-7.10.3/debian/changelog 2021-02-24 22:32:29.0 +0100 +++ reportbug-7.10.3+deb11u1/debian/changelog 2021-0

Bug#985430: unblock: ceilometer/1:15.0.0-1->1:15.0.0-3

2021-03-18 Thread Thomas Goirand
copy of the file from /usr/share). So this is mostly cosmetic, but I still think it's important. Debdiff attached. Cheers, Thomas Goirand (zigo) diff --git a/debian/changelog b/debian/changelog index 2bb3032e0..42289490c 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,3

Bug#985431: unblock: cloudkitty/13.0.0-5

2021-03-18 Thread Thomas Goirand
t all, and therefore, it makes it impossible to rate customers. The patch simply disables the rating role feature, and every project/tenant in the deployment gets rated by cloudkitty. unblock cloudkitty/13.0.0-5 Cheers, Thomas Goirand (zigo) Description: Rate everyone The Keystone fetcher

Bug#985789: unblock: openstack-debian-images/1.58

2021-03-23 Thread Thomas Goirand
se unblock openstack-debian-images/1.58 Cheers, Thomas Goirand (zigo) diff -Nru openstack-debian-images-1.57/build-openstack-debian-image openstack-debian-images-1.58/build-openstack-debian-image --- openstack-debian-images-1.57/build-openstack-debian-image 2021-02-19 14:41:23.0 +0100 +++

Bug#985818: unblock: swift/2.26.0-9

2021-03-24 Thread Thomas Goirand
included in Bullseye. Debdiff attached. Please unblock swift/2.26.0-9 Cheers, Thomas Goirand (zigo) diff -Nru swift-2.26.0/debian/changelog swift-2.26.0/debian/changelog --- swift-2.26.0/debian/changelog 2021-02-23 14:11:16.0 +0100 +++ swift-2.26.0/debian/changelog 2021-03-24 10

Bug#985818: unblock: swift/2.26.0-9

2021-03-24 Thread Thomas Goirand
ur production, so it seems to do the trick. Note that thanks to uwsgi, the performances is still ok. Debdiff attached. Sorry that it had to be a follow-up to this bug. Cheers, Thomas Goirand (zigo) diff -Nru swift-2.26.0/debian/changelog swift-2.26.0/debian/changelog --- swift-2.26.0/debian/change

Bug#985885: unblock: ceph/14.2.18-1 (CVE-2020-27839)

2021-03-25 Thread Thomas Goirand
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package ceph This is the point release of the 14.2.x series from upstream, which includes a fix for CVE-2020-27839 (XSS in the dashboard). I didn't even atempted to build a d

Bug#983110: buster-pu: package ipmitool/1.8.18-6 (CVE-2020-5208)

2021-03-27 Thread Thomas Goirand
On 3/26/21 9:24 AM, Salvatore Bonaccorso wrote: > Hi Thomas, > > On Wed, Mar 17, 2021 at 07:01:35PM +, Adam D. Barratt wrote: >> Control: tags -1 + confirmed >> >> On Sat, 2021-02-20 at 22:43 +0100, Thomas Goirand wrote: >>> On 2/19/21 8:38 PM, Salvato

Bug#986138: unblock: octavia/7.1.0-2

2021-03-30 Thread Thomas Goirand
also includes a slightly modified uwsgi configuration file to improve performances of the octavia-api (though I don't think this is very controvertial). Please unblock octavia/7.1.0-2 to fix the agent. Cheers, Thomas Goirand (zigo)

Bug#986146: unblock: rabbitmq-server/3.8.9-2

2021-03-30 Thread Thomas Goirand
loses: #947873). + * Use logrotate daily instead of weekly, and do not override the number of +logs, so we don't keep too much of them. + * Do not use a sharedscripts, as rabbitmq-server detects the log rotation +by itself (LP: #1921425). + + -- Thomas Goirand Fri, 26 Mar 2021 14:2

Bug#986158: unblock: python-oslo.serialization/4.0.2-1

2021-03-30 Thread Thomas Goirand
@@ -1,3 +1,9 @@ +python-oslo.serialization (4.0.2-1) unstable; urgency=medium + + * New upstream release. + + -- Thomas Goirand Tue, 30 Mar 2021 16:51:52 +0200 + python-oslo.serialization (4.0.1-2) unstable; urgency=medium * Uploading to unstable. diff -Nru python-oslo.serialization-4.0.1

Bug#986198: unblock: python-oslo.messaging/12.5.2-1

2021-03-31 Thread Thomas Goirand
.py upstream source code change is relevant to read in the attached debdiff (the rest of is upstream CI configuration). Please unblock python-oslo.messaging/12.5.2-1. Cheers, Thomas Goirand (zigo) diff -Nru python-oslo.messaging-12.5.1/debian/changelog python-oslo.messaging-12.5.2/debian

Bug#986199: unblock: python-oslo.cache/2.6.2-1

2021-03-31 Thread Thomas Goirand
relevant part of upstream code is just this: +if dogpile.__version__ >= '1.1.2': +_backend_choices.append('dogpile.cache.pymemcache') the rest of the debdiff is just distraction. Please unblock python-oslo.cache/2.6.2-1. Cheers, Thomas Goirand (zigo) diff -Nru python-

Bug#986675: unblock: puppet/5.5.22-2

2021-04-09 Thread Thomas Goirand
5 DDs) appreciate if the patch could be included in Bullseye, and probably the DSA team (who's using puppet a lot) will appreciate it as well. Debdiff attached (it's a *very* small patch). Please unblock puppet/5.5.22-2. Cheers, Thomas Goirand (zigo) diff -Nru puppet-5.5.22/debian/

Bug#986846: unblock: rabbitmq-server/3.8.9-3

2021-04-12 Thread Thomas Goirand
maybe) non-functional service that doesn't allocate enough memory. The proposed new release includes a patch from upstream to fix the situation. Please unblock rabbitmq-server/3.8.9-3 Cheers, Thomas Goirand (zigo) diff -Nru rabbitmq-server-3.8.9/debian/changelog rabbitmq-server-3.8.9/debian

Bug#987006: unblock: openstack-debian-images/1.59

2021-04-15 Thread Thomas Goirand
mmand isn't ideal, but at this time, I have no solution, and it's probably a bit too late to investigate. I hope you're ok with this. Please unblock openstack-debian-images/1.59, Cheers, Thomas Goirand (zigo) diff -Nru openstack-debian-images-1.58/build-openstack-debian-image o

Bug#987081: unblock: puppet-module-puppetlabs-haproxy/2.1.0-3

2021-04-17 Thread Thomas Goirand
debdiff attached. Please unblock puppet-module-puppetlabs-haproxy/2.1.0-3. Cheers, Thomas Goirand (zigo) diff -Nru puppet-module-puppetlabs-haproxy-2.1.0/debian/changelog puppet-module-puppetlabs-haproxy-2.1.0/debian/changelog --- puppet-module-puppetlabs-haproxy-2.1.0/debian/changelog 2020-03-24

Bug#987190: unblock: openstack-debian-images/1.60

2021-04-19 Thread Thomas Goirand
r the slave devices, which should not be there. It used to work in Buster, it doesn't in Bullseye. The attached debdiff fixes this. Note that 1.59 has already been unblocked, so I'm attaching a debdiff between 1.59 and 1.60. Please unblock openstack-debian-images/1.60. Cheers, Thomas Goir

Bug#987237: unblock: openstack-cluster-installer/40.1

2021-04-20 Thread Thomas Goirand
he haproxy in controller.pp. Though as soon as one sets a custom URL for the swift proxy so that clients reach the haproxy of the proxies, the puppet run fails in Bullseye. Please unblock openstack-cluster-installer/40.1 to fix this. Debdiff attached. Cheers, Thomas Goirand (zigo)

Bug#987239: unblock: glance/21.0.0-2

2021-04-20 Thread Thomas Goirand
this version of the package has been tested in production. Please unblock glance/21.0.0-2. Cheers, Thomas Goirand (zigo) diff -Nru glance-21.0.0/debian/changelog glance-21.0.0/debian/changelog --- glance-21.0.0/debian/changelog 2020-10-17 15:56:31.0 +0200 +++ glance-21.0.0/debian/ch

Bug#987267: unblock: neutron/17.1.1-3

2021-04-21 Thread Thomas Goirand
Hi, Version -4 add this commit: https://salsa.debian.org/openstack-team/services/neutron/-/commit/4840df25084d28bd010e46e97cb4f4866379392e Did some crap yesterday, backporting the fix from another branch, had to fix... Please unblock neutron/17.1.1-4 Cheers, Thomas Goirand (zigo)

Bug#987329: unblock: ceph/14.2.20-2

2021-04-21 Thread Thomas Goirand
. Please unblock package ceph/14.2.20-2 Cheers, Thomas Goirand (zigo) P.S: bzed, jmm and kilobyte as CC after discussing this update with bzed who co-maintains the Ceph package. Also, this bug is instead of #985885 that I have closed.

Bug#987329: unblock: ceph/14.2.20-2

2021-04-22 Thread Thomas Goirand
nfo > > Hi Thomas, > > On 21-04-2021 22:33, Thomas Goirand wrote: >> I've uploaded version 14.2.20-2 of Ceph. This is the last point release >> from usptream, including the fixes for CVE-2021-20288 and CVE-2020-27839. >> >> With such large software such a

Bug#987239: unblock: glance/21.0.0-2

2021-04-26 Thread Thomas Goirand
us releases of OpenStack. So best is to keep it, but renamed, and tell the user to put what he edited as fragments in /etc/glance/policy.d in yaml format only. Moving the policy.json in the policy.d is not a good idea either, because it keeps the old JSON format, now deprecated by upstream, that we explicitly require users to move away from. I hope it's more clear now. Cheers, Thomas Goirand (zigo)

Bug#987239: unblock: glance/21.0.0-2

2021-04-27 Thread Thomas Goirand
On 4/27/21 11:53 AM, Sebastian Ramacher wrote: > Control: tags -1 + confirmed moreinfo > > On 2021-04-26 21:37:56 +0200, Thomas Goirand wrote: >> On 4/26/21 4:01 PM, Sebastian Ramacher wrote: >>>> The changelog goes like this: >>>> >>>

Bug#987828: unblock: openvswitch/2.15.0+ds1-3 (pre-approval)

2021-04-30 Thread Thomas Goirand
d it. But it is clearly against the release team rules to add a binary package. Which is why I'm asking for pre-approval. What is the release team opinion? Should I upload openvswitch 2.15.0+ds1-3 to unstable with the new binary package? Debdiff attached. Cheers, Thomas Goirand (zigo) d

Bug#987890: unblock: python-babel/2.8.0+dfsg.1-7 CVE-2021-20095

2021-05-01 Thread Thomas Goirand
Cheers, Thomas Goirand (zigo) diff -Nru python-babel-2.8.0+dfsg.1/debian/changelog python-babel-2.8.0+dfsg.1/debian/changelog --- python-babel-2.8.0+dfsg.1/debian/changelog 2021-01-21 13:21:26.0 +0100 +++ python-babel-2.8.0+dfsg.1/debian/changelog 2021-05-01 17:13:14.0 +0200

Bug#988054: unblock: python-xstatic-angular/1.5.8.0-5

2021-05-04 Thread Thomas Goirand
0 +0200 @@ -1,3 +1,9 @@ +python-xstatic-angular (1.5.8.0-5) unstable; urgency=medium + + * Remove debianize.patch and use provided AngularJS 1.5.8. + + -- Thomas Goirand Tue, 04 May 2021 09:00:08 +0200 + python-xstatic-angular (1.5.8.0-4) unstable; urgency=medium [ Ondřej Nový ] diff

Bug#988188: Ignoring but #987904 for Bullseye: horizon plugin packaging design mistake

2021-05-07 Thread Thomas Goirand
the Horizon packaging in Experimental, and see how it goes. Dear release team, please let share your view on this bug. I remain available if you need more explanations. Cheers, Thomas Goirand (zigo)

Bug#988188: Maybe fix it for Bullseye?

2021-05-07 Thread Thomas Goirand
neutron-vpnaas-dashboard - octavia-dashboard - sahara-dashboard - senlin-dashboard - trove-dashboard - vitrage-dashboard - watcher-dashboard - zaqar-ui Please let me know if you think I should upload such fixes before Bullseye. Cheers, Thomas Goirand (zigo) diff -Nru designate-dashboard-12.0.0/de

Bug#988357: unblock: python-eventlet/0.26.1-7 CVE-2021-21419

2021-05-11 Thread Thomas Goirand
Please unblock python-eventlet/0.26.1-7 Cheers, Thomas Goirand (zigo) diff -Nru python-eventlet-0.26.1/debian/changelog python-eventlet-0.26.1/debian/changelog --- python-eventlet-0.26.1/debian/changelog 2021-02-18 17:07:30.0 +0100 +++ python-eventlet-0.26.1/debian/changelog 2021

Bug#987890: Fixed and uploaded

2021-05-13 Thread Thomas Goirand
Hi, I mishandled the orig tarball, which is why my upload was rejected. Once I understood, I got busy with other (personal) stuff. Sorry that it took so long. Anyways, it should be good now, and hopefully, this last upload will go through. I removed the moreinfo tag... Cheers, Thomas Goirand

Bug#988683: unblock: neutron/17.1.1-5 (CVE-2021-20267)

2021-05-17 Thread Thomas Goirand
iff against the package in testing [ Other info ] unblock neutron/17.1.1-5 Cheers, Thomas Goirand (zigo) diff -Nru neutron-17.1.1/debian/changelog neutron-17.1.1/debian/changelog --- neutron-17.1.1/debian/changelog 2021-04-21 17:26:26.0 +0200 +++ neutron-17.1.1/debian/changelog 2

Bug#988188: Ignoring but #987904 for Bullseye: horizon plugin packaging design mistake

2021-05-19 Thread Thomas Goirand
On 5/19/21 9:21 PM, Sebastian Ramacher wrote: > Control: tags -1 moreinfo > > On 2021-05-07 10:56:51 +0200, Thomas Goirand wrote: >> Package: release.debian.org >> Severity: normal >> >> Hi, >> >> I need to discuss with the release team what

Bug#988828: unblock: cloudkitty/13.0.0-6

2021-05-20 Thread Thomas Goirand
klist ] [x] all changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in testing unblock cloudkitty/13.0.0-6 Cheers, Thomas Goirand (zigo) diff -Nru cloudkitty-13.0.0/debian/changelog cloudkitty-13.0.0/debian/changelo

Bug#988922: unblock: python-openstackclient/5.4.0-4

2021-05-21 Thread Thomas Goirand
ented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in testing Cheers, Thomas Goirand (zigo) unblock python-openstackclient/5.4.0-4 diff -Nru python-openstackclient-5.4.0/debian/changelog python-openstackclient-5.4.0/debian/chan

Bug#994064: bullseye-pu: package python-eventlet/0.26.1-7

2021-09-10 Thread Thomas Goirand
ks ] Hopefully, this wont break anything... :) [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Cheers, Thomas Goirand (zi

Bug#993720: bullseye-pu: package automysqlbackup/2.6+debian.4-3

2021-09-20 Thread Thomas Goirand
On 9/18/21 2:42 PM, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Sun, 2021-09-05 at 15:21 +0200, Thomas Goirand wrote: >> I'd like to fix #986462 in Stable as well. >> >> [ Impact ] >> Crash of the script if using the LATEST=yes opt

Bug#995394: bullseye-pu: package horizon/3:18.6.2-5

2021-09-30 Thread Thomas Goirand
hanges are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Cheers, Thomas Goirand (zigo) diff -Nru horizon-18.6.2/debian/changelog horizon-18.6.2/debian/changelog --- hori

Bug#992331: bullseye-pu: package keystone/18.0.0-3+deb11u1 (CVE-2021-38155)

2021-10-04 Thread Thomas Goirand
both subunit 1.4.0-3 and Keystone 2:14.2.0-0+deb10u2 to Buster? Please let me know your thoughts. Cheers, Thomas Goirand (zigo)

Bug#994064: python3-dnspython and eventlet incompatibility

2021-11-05 Thread Thomas Goirand
n (or at least, it will not use dnspython to resolve). Please really let me know (and the Debian bug) if the patched Eventlet fixes your trouble first though, as I didn't have the issue (because my setup always write all the cluster nodes in /etc/hosts), and I need to know if that fixes it. Cheers, Thomas Goirand (zigo)

Bug#999762: bullseye-pu: package lshw/02.18.85-0.7

2021-11-16 Thread Thomas Goirand
n unstable. I'd just upload it as: 02.19.git.2021.06.19.996aaad9c7-2~deb11u1 if you agree. Cheers, Thomas Goirand (zigo)

Bug#994064: Bug#1000862: possible fix

2021-11-30 Thread Thomas Goirand
important bit for the release team: to know that an update doesn't break anything more, and that it's been tested. Hopefully, with your help, the updated 0.26.1-7+deb11u1 version of Eventlet can be approved into Debian Bullseye. Cheers, Thomas Goirand (zigo)

Bug#992330: bullseye-pu: package nova/22.2.2-1+deb11u1 (CVE-2021-3654)

2021-12-03 Thread Thomas Goirand
Hi Julien, Thanks for your (unfortunately late) answer. On 12/3/21 3:11 PM, Julien Cristau wrote: > Control: tag -1 moreinfo > > Hi Thomas, > > On Tue, Aug 17, 2021 at 12:57:50PM +0200, Thomas Goirand wrote: >> Also, I would like to get Nova upgraded to the latest poi

Bug#994064: bullseye-pu: package python-eventlet/0.26.1-7

2021-12-07 Thread Thomas Goirand
On 12/3/21 5:25 PM, Julien Cristau wrote: > Control: tag -1 confirmed > > Hi Thomas, > > A couple of comments on the diff below, otherwise fine to go ahead. > > On Fri, Sep 10, 2021 at 09:50:25PM +0200, Thomas Goirand wrote: >> diff -Nru python-eventlet-0.26.1/debian/

Bug#995394: bullseye-pu: package horizon/3:18.6.2-5

2021-12-07 Thread Thomas Goirand
On 12/3/21 5:47 PM, Adam D. Barratt wrote: > Control: tags -1 + confirmed > > On Thu, 2021-09-30 at 17:03 +0200, Thomas Goirand wrote: >> For some reasons, the compiled .mo translations were >> disabled in the package. This update will re-activate them. >> >> [ Re

Bug#1002956: bullseye-pu: package rabbitmq-server/3.8.9-3 CVE-2021-32718, CVE-2021-32719

2022-01-01 Thread Thomas Goirand
I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable Cheers, Thomas Goirand (zigo) diff -Nru rabbitmq-server-3.8.9/debian/changelog rabbitmq-server-3.8.9/debian/changelog --- rabbitmq-server-3.8.9/debian/changelog 2021-04-10 22:59

Bug#1003058: bullseye-pu: package openvswitch/2.15.0+ds1-2

2022-01-03 Thread Thomas Goirand
e issue is verified as fixed in unstable Cheers, Thomas Goirand (zigo) diff -Nru openvswitch-2.15.0+ds1/debian/changelog openvswitch-2.15.0+ds1/debian/changelog --- openvswitch-2.15.0+ds1/debian/changelog 2021-02-20 21:58:03.0 +0100 +++ openvswitch-2.15.0+ds1/debian/changelog 202

Bug#1004513: bullseye-pu: package rabbitmq-server/3.8.9-3

2022-01-29 Thread Thomas Goirand
for the next point release. Cheers, Thomas Goirand (zigo) diff --git a/debian/README.Debian b/debian/README.Debian new file mode 100644 index 000..9d564c4 --- /dev/null +++ b/debian/README.Debian @@ -0,0 +1,134 @@ +*** WARNING *** + +0/ Intro + +RabbitMQ, in its default configuration, is insecure.

Bug#1002956: New debdiff

2022-01-29 Thread Thomas Goirand
My appologies for opening a new bug. I didn't realize #1002956 was still pending my input. I merged both bugs. Please see, attached to this message, the new debdiff, adding the fix for CVE-2021-22116 as well. Cheers, Thomas Goirand (zigo)diff -Nru rabbitmq-server-3.8.9/debian/chan

Bug#1002956: New debdiff

2022-01-29 Thread Thomas Goirand
On 1/29/22 20:31, Salvatore Bonaccorso wrote: Control: tags -1 + moreinfo Hi Thomas, On Sat, Jan 29, 2022 at 07:55:15PM +0100, Thomas Goirand wrote: My appologies for opening a new bug. I didn't realize #1002956 was still pending my input. I merged both bugs. Please see, attached to

Bug#1003058: bullseye-pu: package openvswitch/2.15.0+ds1-2

2022-02-21 Thread Thomas Goirand
On 2/19/22 19:04, Adam D. Barratt wrote: Control: tags -1 + confirmed On Mon, 2022-01-03 at 14:25 +0100, Thomas Goirand wrote: [ Reason ] Indeed, the updated version I would like to push contains a fix for CVE-2021-36980 (Debian bug #991308), and a fix for having libofproto properly installed

The shape of Puppetserver 7 packaging in Bookworm

2023-01-24 Thread Thomas Goirand
t's a bit late as well in the development process. I do expect that I'll have some puppet manifest last-minute modifications to be done. I do expect these type of change to be "not small"... Cheers, Thomas Goirand (zigo)

Bug#1030113: bullseye-pu: package openvswitch/2.15.0+ds1-2+deb11u2

2023-01-31 Thread Thomas Goirand
ease team feels like it's best to leave d/rules as-is, I can revert that, and we can give-back the package to the buildd if that unit test fails, but I'd prefer blacklisting it. Cheers, Thomas Goirand (zigo) diff -Nru openvswitch-2.15.0+ds1/debian/changelog openvswitch-2.15.0+ds1/debian/

Bug#1032871: unblock: puppet-module-puppetlabs-haproxy/2.1.0-4

2023-03-13 Thread Thomas Goirand
atest version of the +parsing. + + -- Thomas Goirand Mon, 13 Mar 2023 09:01:56 +0100 + puppet-module-puppetlabs-haproxy (2.1.0-4) unstable; urgency=medium * Clean up update-alternatives handling (Closes: #989237). diff -Nru puppet-module-puppetlabs-haproxy-2.1.0/debian/patches/fix-haproxy-ve

Bug#1032872: unblock: puppet-module-puppetlabs-mysql/8.1.0-7

2023-03-13 Thread Thomas Goirand
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package puppet-module-puppetlabs-mysql [ Reason ] The last version of MariaDB removes completely the use of /var/log/mysql, and uses exclusively journald. However, that's now

Bug#1032874: unblock: puppet-module-horizon/21.0.0-3

2023-03-13 Thread Thomas Goirand
path for Horizon's wsgi.py (due to wrong patch rebase). + + -- Thomas Goirand Mon, 06 Mar 2023 14:12:07 +0100 + puppet-module-horizon (21.0.0-2) unstable; urgency=medium [ Olivier Chaze ] diff -Nru puppet-module-horizon-21.0.0/debian/patches/add_dns_v4_variables.patch puppet-modu

Bug#1032873: unblock: ceilometer-instance-poller/0.1.5-1

2023-03-13 Thread Thomas Goirand
e-poller-0.1.4/debian/changelog ceilometer-instance-poller-0.1.5/debian/changelog --- ceilometer-instance-poller-0.1.4/debian/changelog 2023-02-02 23:54:17.0 +0100 +++ ceilometer-instance-poller-0.1.5/debian/changelog 2023-03-03 17:03:43.00000 +0100 @@ -1,3 +1,9 @@ +ceilomete

Bug#1033139: unblock: graphite-web/1.1.8-2

2023-03-17 Thread Thomas Goirand
ng-3.patch. + + -- Thomas Goirand Fri, 17 Mar 2023 14:24:47 +0100 + graphite-web (1.1.8-1.1) unstable; urgency=medium * NMU diff -Nru graphite-web-1.1.8/debian/patches/fix-compat-with-pyparsing-3.patch graphite-web-1.1.8/debian/patches/fix-compat-with-pyparsing-3.patch --- graphite-web-1.

Bug#1033974: unblock: python-uhashring/2.1-2

2023-04-05 Thread Thomas Goirand
-3) unstable; urgency=medium + + * Add Fix-test_distribution-to-be-deterministic.patch (Closes: #1033426). + + -- Thomas Goirand Mon, 03 Apr 2023 08:17:43 +0200 + python-uhashring (2.1-2) unstable; urgency=medium * Uploading to unstable. diff -Nru python-uhashring-2.1/debian/patches/Fix

Bug#1033974: unblock: python-uhashring/2.1-2

2023-04-05 Thread Thomas Goirand
The version to unblock really is 2.1-3. My bug report is then probably wrong... Cheers, Thomas Goirand (zigo)

Bug#1034243: unblock: heat/19.0.0-2 (fix for CVE-2023-1625 / #1034186)

2023-04-11 Thread Thomas Goirand
[x] I reviewed all changes and I approve them [x] attach debdiff against the package in testing Cheers, Thomas Goirand (zigo) unblock heat/19.0.0-2 diff -Nru heat-19.0.0/debian/changelog heat-19.0.0/debian/changelog --- heat-19.0.0/debian/changelog2022-10-06 10:14:02.0 +0200 ++

Bug#1034245: pre-approval: unblock: openvswitch/3.1.1 (CVE-2023-1668)

2023-04-11 Thread Thomas Goirand
9 I would still prefer to include all bugfixes though, if possible. Please let me know ASAP, as this is a grave security fix. Also note that I've already sent to the security team the fix for the version in Bullseye (and I'll probably also attempt to fix in Buster, maybe later on...). Che

Bug#1034245: pre-approval: unblock: openvswitch/3.1.1 (CVE-2023-1668)

2023-04-11 Thread Thomas Goirand
eady present in Bookworm, as I saw offsets when doing "quilt push" (which may be annoying depending on your build env). Not sure (because uploaded by Luca) how it got in. Please let me know your decision (ie: latest point release from upstream or this patch). Cheers, Thomas Goirand (z

Bug#1034343: unblock: rally/3.3.0-2

2023-04-13 Thread Thomas Goirand
2021-11-03 10:39:35.0 +0100 +++ rally-3.3.0/debian/changelog2023-04-13 11:06:02.0 +0200 @@ -1,3 +1,9 @@ +rally (3.3.0-2) unstable; urgency=medium + + * Add install-missing-files.patch. + + -- Thomas Goirand Thu, 13 Apr 2023 11:06:02 +0200 + rally (3.3.0-1) unstable; urgency

Bug#928649: unblock: ipset/6.38-1.2

2019-05-08 Thread Thomas Goirand
-1.2 Cheers, Thomas Goirand (zigo) diff -Nru ipset-6.38/debian/changelog ipset-6.38/debian/changelog --- ipset-6.38/debian/changelog 2018-09-01 19:28:18.0 +0200 +++ ipset-6.38/debian/changelog 2019-05-06 10:55:51.0 +0200 @@ -1,3 +1,18 @@ +ipset (6.38-1.2) unstable; urgency=medium

Bug#929119: unblock: python-oslo.messaging/8.1.3-1

2019-05-17 Thread Thomas Goirand
. So, very much, I'd like this to reach Buster, and so would any OpenStack on Debian user. Debdiff attached. Cheers, Thomas Goirand (zigo) unblock python-oslo.messaging/8.1.3-1 diff -Nru python-oslo.messaging-8.1.2/debian/changelog python-oslo.messaging-8.1.3/debian/changelog --- python-os

Bug#929120: unblock: python-amqp/2.4.0-2

2019-05-17 Thread Thomas Goirand
ebdiff attached, Cheers, Thomas Goirand (zigo) unblock python-amqp/2.4.0-2 diff -Nru python-amqp-2.4.0/debian/changelog python-amqp-2.4.0/debian/changelog --- python-amqp-2.4.0/debian/changelog 2019-01-22 15:29:00.0 +0100 +++ python-amqp-2.4.0/debian/changelog 2019-05-17 14:26:02.

Bug#929321: unblock: sqlalchemy/1.2.18+ds1-2 (CVE-2019-7164 CVE-2019-7548)

2019-05-21 Thread Thomas Goirand
, Thomas Goirand (zigo) diff -Nru sqlalchemy-1.2.18+ds1/debian/changelog sqlalchemy-1.2.18+ds1/debian/changelog --- sqlalchemy-1.2.18+ds1/debian/changelog 2019-02-25 00:01:50.0 +0100 +++ sqlalchemy-1.2.18+ds1/debian/changelog 2019-05-21 16:23:35.0 +0200 @@ -1,3 +1,11

Bug#929734: unblock: nova/18.1.0-6

2019-05-29 Thread Thomas Goirand
rk, but it'd be hard to get into the full details of how Nova works. Though please trust me, this is an important patch that really needs to be in Buster, and I have tested this patch with success in production. Cheers, Thomas Goirand (zigo) unblock nova/18.1.0-6 diff -Nru nova-18.1.0/d

Bug#929321: unblock: sqlalchemy/1.2.18+ds1-2 (CVE-2019-7164 CVE-2019-7548)

2019-05-29 Thread Thomas Goirand
Mike Bayer (upstream for SQLAlchemy). On 5/28/19 8:59 PM, Paul Gevers wrote: > Control: tags -1 moreinfo confirmed > > Hi Zigo, > > On Tue, 21 May 2019 17:50:28 +0200 Thomas Goirand wrote: >> Note that it may (or not) break some reverse dependencies, though according >>

Bug#929321: Update for SQLAlchemy to address CVE-2019-7164 CVE-2019-7548

2019-05-30 Thread Thomas Goirand
;m writing this email to you today: to ask you to please test your application with SQLAlchemy 1.2.18+ds1-2 ASAP, to address any potential unforecast issue before the Buster release. Details about the discussion can be seen here in the Debian bug #929321. Best regards, Thomas Goirand (zigo)

Bug#929734: unblock: nova/18.1.0-6

2019-06-03 Thread Thomas Goirand
On 5/29/19 9:49 PM, Thomas Goirand wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > > Dear release team, > Please unblock package nova 18.1.0-6. > > During normal operation, it may happen

Bug#930058: unblock: puppet/5.5.10-3

2019-06-06 Thread Thomas Goirand
for any report +that is older than 30 days to avoid filling-up a puppet-master hard drive +until it's full (Closes: #930033). + + -- Thomas Goirand Thu, 06 Jun 2019 10:24:27 +0200 + puppet (5.5.10-2) unstable; urgency=medium * Make sure oj does not use BigDecimals on data load (Closes

Bug#930110: unblock: graphite-web/1.1.4-3

2019-06-07 Thread Thomas Goirand
=medium + + * Fix shebang of /usr/bin/graphite-manage. (Closes: #925240) + + -- Thomas Goirand Fri, 07 Jun 2019 09:39:24 +0200 + graphite-web (1.1.4-2) unstable; urgency=medium * Fix README to suggest installation of libapache2-mod-wsgi-py3, and added diff -Nru graphite-web-1.1.4/debian

Bug#930357: stretch-pu: package miniupnpd/1.8.20140523-4.1+deb9u2 CVE-2019-12107, CVE-2019-12108, CVE-2019-12109, CVE-2019-12110

2019-06-11 Thread Thomas Goirand
here: http://sid.gplhost.com/stretch-proposed-updates/miniupnpd/ Cheers, Thomas Goirand (zigo) diff -Nru miniupnpd-1.8.20140523/debian/changelog miniupnpd-1.8.20140523/debian/changelog --- miniupnpd-1.8.20140523/debian/changelog 2018-02-07 12:18:50.0 +0100 +++ miniupnpd-1.8.201

Bug#930058: unblock: puppet/5.5.10-3

2019-06-16 Thread Thomas Goirand
On 6/15/19 7:54 PM, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Thomas, > > On 06-06-2019 10:36, Thomas Goirand wrote: >> Version 5.5.10-3 adds a tiny cron.daily job which cleans-up the >> /var/lib/puppet/reports folder to avoid that a puppet-master >>

  1   2   3   4   5   6   >