[Bug 2064685] Re: write says write: effective gid does not match group of /dev/pts/5

2024-05-02 Thread Alex Murray
For context, this change was introduced in https://ubuntu.com/security/notices/USN-6719-2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2064685 Title: write says write: effective gid does not match

[Bug 2063271] Re: Illegal opcode in libssl

2024-04-23 Thread Alex Murray
Thanks for reporting this issue - but it is strange since this update has been published since 2024-02-27 and this is the first such report of any issues. Also given this update has been available for nearly 2 months it is surprising you are seeing errors from it so much later - I wonder if

[Bug 2063079] Re: samba smbd.service is missing ExecStartPre for update-apparmor-samba-profile

2024-04-22 Thread Alex Murray
There should not be much risk of regression - this feature was only supported on samba in mantic, not jammy etc so not many users will upgrade from mantic to noble - and the current behaviour where this is broken in noble is the same behaviour as we have in jammy etc. And then even for users

[Bug 2063079] Re: samba smbd.service is missing ExecStartPre for update-apparmor-samba-profile

2024-04-22 Thread Alex Murray
Forwarded to debian in https://bugs.debian.org/cgi- bin/bugreport.cgi?bug=1069661 ** Bug watch added: Debian Bug tracker #1069661 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1069661 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 2063079] Re: samba smbd.service is missing ExecStartPre for update-apparmor-samba-profile

2024-04-22 Thread Alex Murray
** Patch added: "samba_4.19.5+dfsg-4ubuntu9.1.debdiff" https://bugs.launchpad.net/ubuntu/+source/samba/+bug/2063079/+attachment/5769340/+files/samba_4.19.5+dfsg-4ubuntu9.1.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2063079] [NEW] samba smbd.service is missing ExecStartPre for update-apparmor-samba-profile

2024-04-22 Thread Alex Murray
Public bug reported: In mantic, the smbd.service unit file contained the line: ExecStartPre=/usr/share/samba/update-apparmor-samba-profile As such, the associated AppArmor profile for smbd etc would be automatically updated to include permissions for the various shares etc on the local files

[Bug 2061155]

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2061208] Re: package nvidia-dkms-535-server 535.161.08-0ubuntu2.22.04.1 failed to install/upgrade: installed nvidia-dkms-535-server package post-installation script subprocess returned error exit

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2061191]

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2061305] Re: Can't update to Ubuntu 22.04.4 LTS (Jammy Jellyfish)

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2061856]

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 2061856] Re: gnome terminal

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2061894] Re: package linux-image-6.8.0-22-generic 6.8.0-22.22 failed to install/upgrade: run-parts: /etc/kernel/postinst.d/dkms exited with return code 11

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2062011] Re: Please update libjxl to newest version in 24.04 to address security vulnerabilities

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is

[Bug 2062440] Re: A few days ago I realized that the time was four hours behind despite it being automatic with the correct time zone.

2024-04-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 2060035] Re: [MIR] msgraph

2024-04-15 Thread Alex Murray
I reviewed msgraph 0.2.1-0ubuntu3 as checked into noble. This shouldn't be considered a full audit but rather a quick gauge of maintainability. msgraph is a library written in C using the glib, libgoa, and libsoup for providing access to the Microsoft Graph API services. - CVE History - None

[Bug 2060575] [NEW] gnome-keyring fails to automatically unlock login keyring after recent updates in noble

2024-04-08 Thread Alex Murray
Public bug reported: After installing recent updates in 24.04, upon logging in the gnome- shell based UI pops up saying that the login keyring was not unlocked and asking for the users password to be input to unlock it. Similarly a second, non-gnome-shell based UI is also present asking the same

[Bug 2059417] Re: Sync xz-utils 5.6.1-1 (main) from Debian unstable (main)

2024-03-29 Thread Alex Murray
Given this has been reverted in Debian, it should not be synced into Ubuntu. ** Changed in: xz-utils (Ubuntu) Status: New => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2059417

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-20 Thread Alex Murray
Ok whilst I still can't see the /StatusNotifierItem object listed via d-feet I can reproduce the denials when launching element-desktop so I have added some additional changes to the aforementioned PR which resolve these as well. With all the changes from that PR in place all of these mentioned

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-20 Thread Alex Murray
Ah although it seems I can reboot the VM at this point and whilst Calamares appeared to run again again in the rebooted vm if I choose Install Calamares closes and I see the installed kubuntu environment - weird Anyway I think I will be able to use this to debug the original issue further -

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-20 Thread Alex Murray
The subsequent error is: Main script file /usr/lib/x86_64-linux- gnu/calamares/modules/automirror/main.py for python job automirror raised an exception. Is there any way I can debug this further? -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-20 Thread Alex Murray
Yes I hit that exact issue in Calamares but after fixing it I then hit another similar crash in a different script in calamares - will see if I can reproduce and provide you with details. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-19 Thread Alex Murray
So I installed kubuntu-desktop on an up-to-date noble VM and then after logging into the kubuntu session I was able to reproduce the issue for Notifications but I couldn't see anything owning the /StatusNotifierItem dbus path. For notifications I submitted

[Bug 2058329] [NEW] Update apparmor to 4.0.0-beta3 in noble

2024-03-19 Thread Alex Murray
Public bug reported: Latest upstream release https://gitlab.com/apparmor/apparmor/-/releases/v4.0.0-beta3 Contains only bug fixes since 4.0.0-beta2 which is currently in noble- proposed thus does not require a FFe. ** Affects: apparmor (Ubuntu) Importance: Undecided Status: New

[Bug 2056696] Re: All Snaps are denied the ability to use DBus for notifications and apptray indicators in KDE-based flavors

2024-03-14 Thread Alex Murray
> Log: apparmor="DENIED" operation="dbus_method_call" bus="session" path="/org/freedesktop/DBus" interface="org.freedesktop.DBus" member="ListActivatableNames" mask="send" name="org.freedesktop.DBus" pid=2950 label="snap.element-desktop.element-desktop" peer_label="unconfined" This is provided by

[Bug 2056496] Re: [FFe] AppArmor 4.0-beta2 + prompting support for noble

2024-03-12 Thread Alex Murray
Uploaded to noble-proposed yesterday https://launchpad.net/ubuntu/+source/apparmor/4.0.0~beta2-0ubuntu3 ** Changed in: apparmor (Ubuntu) Status: Triaged => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2056458] Re: upgrade to thunderbird snap, missing snapd depdency

2024-03-07 Thread Alex Murray
** Information type changed from Private Security to Public -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2056458 Title: upgrade to thunderbird snap, missing snapd depdency To manage notifications

[Bug 2055761] Re: tracker-extract-3 crashed with SIGSYS in epoll_wait()

2024-03-06 Thread Alex Murray
Ah fair enough ;) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055761 Title: tracker-extract-3 crashed with SIGSYS in epoll_wait() To manage notifications about this bug go to:

[Bug 2055761] Re: tracker-extract-3 crashed with SIGSYS in epoll_wait()

2024-03-06 Thread Alex Murray
> Why do we keep having to fix these crashes one by one over such a long period of time? In this case I think this is a consequence of the allow-list nature of the seccomp filters - as glibc changes to implement various functions via different primitive system calls / or the kernel changes to add

[Bug 2054924] Re: color emoji are broken with fontconfig 2.15

2024-03-06 Thread Alex Murray
As per https://gitlab.freedesktop.org/fontconfig/fontconfig/-/issues/409#note_2298588 this can also be fixed by adding an additional rule to /etc/fonts/conf.d/70-no-bitmaps.conf of the form: false ** Bug watch added: gitlab.freedesktop.org/fontconfig/fontconfig/-/issues #409

[Bug 2055114] Re: fail2ban is broken in 24.04 Noble

2024-02-26 Thread Alex Murray
Relevant upstream issue https://github.com/fail2ban/fail2ban/issues/3487 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2055114 Title: fail2ban is broken in 24.04 Noble To manage notifications

[Bug 2055114] Re: fail2ban is broken in 24.04 Noble

2024-02-26 Thread Alex Murray
So whilst in Ubuntu we do have python-pyasyncore which provides asyncore, we don't have asynchat so this might need to be packaged separately OR vendored into fail2ban -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 2055114] Re: fail2ban is broken in 24.04 Noble

2024-02-26 Thread Alex Murray
asynchat was removed in python 3.12, which just became the default python3 in 24.04 ** Information type changed from Private Security to Public ** Bug watch added: github.com/fail2ban/fail2ban/issues #3487 https://github.com/fail2ban/fail2ban/issues/3487 -- You received this bug

[Bug 2003864] Re: freshclam assert failure: *** stack smashing detected ***: terminated

2023-03-01 Thread Alex Murray
Turns out clamav-1.0.0 includes a transition from libclamav9 -> libclamav11 so this is taking a bit longer than expected - but I will keep plugging away. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 2003864] Re: freshclam assert failure: *** stack smashing detected ***: terminated

2023-02-15 Thread Alex Murray
Looking at the upstream repo for clamav I suspect the following commit is required to be backported to clamav in lunar https://github.com/Cisco- Talos/clamav/commit/375ecf678c714623e6fb5c0119d1bec98dc700dd - or that a merge is done of clamav-1.0.0+dfsg-6 to lunar. The merge is likely the best

[Bug 2003864] Re: freshclam assert failure: *** stack smashing detected ***: terminated

2023-02-14 Thread Alex Murray
FWIW I can't reproduce this on a debian sid install of clamav which also uses the same version of libtfm / tomsfastmath. However, Debian is using a newer version of clamav than Ubuntu 23.04 so perhaps this may be fixed by merging that version to Ubuntu (or perhaps even a no-change rebuild of

[Bug 2003864] Re: freshclam assert failure: *** stack smashing detected ***: terminated

2023-02-13 Thread Alex Murray
This crash seems to be from libtfm -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/2003864 Title: freshclam assert failure: *** stack smashing detected ***: terminated To manage

[Bug 2003864] Re: freshclam assert failure: *** stack smashing detected ***: terminated

2023-02-13 Thread Alex Murray
FWIW I was able to get the following backtrace from this crash: (gdb) bt full #0 s_fp_sub (a=0x7ffe3ea481a0, b=, c=0x7ffe3ea481a0) at src/addsub/s_fp_sub.c:30 x = oldbused = oldused = 483582409 t = #1 0x7fa0134db9e1 in fp_add (a=a@entry=0x7ffe3ea48640,

[Bug 1810241] Re: NULL dereference when decompressing specially crafted archives

2022-09-26 Thread Alex Murray
Thanks I have updated the status of this CVE in the Ubuntu CVE tracker. ** Changed in: tar (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1977701] Re: Update to latest upstream release 20220510 / IPU 2022.1 to fix multiple security vulnerabilities

2022-06-06 Thread Alex Murray
** Description changed: Intel released version 20220510 / IPU 2022.1 earlier in May to address multiple vulnerabilities, including: - - CVE-2022-21151, INTEL-SA-00617 - - CVE-2021-0146, INTEL-SA-00528 - - CVE-2021-0127, INTEL-SA-00532 + - CVE-2022-21151, INTEL-SA-00617 +  

[Bug 1977701] Re: Update to latest upstream release 20220510 / IPU 2022.1 to fix multiple security vulnerabilities

2022-06-05 Thread Alex Murray
** Changed in: intel-microcode (Ubuntu Bionic) Status: New => Fix Committed ** Changed in: intel-microcode (Ubuntu Focal) Status: New => Fix Committed ** Changed in: intel-microcode (Ubuntu Impish) Status: New => Fix Committed ** Changed in: intel-microcode (Ubuntu Jammy)

[Bug 1977701] [NEW] Update to latest upstream release 20220510 / IPU 2022.1 to fix multiple security vulnerabilities

2022-06-05 Thread Alex Murray
Public bug reported: Intel released version 20220510 / IPU 2022.1 earlier in May to address multiple vulnerabilities, including: - CVE-2022-21151, INTEL-SA-00617 - CVE-2021-0146, INTEL-SA-00528 - CVE-2021-0127, INTEL-SA-00532 This version is already packaged in Ubuntu 22.10

[Bug 1970228] Re: Multiple vulnerabilities in Bionic, Focal and Jammy

2022-05-27 Thread Alex Murray
Removing ubuntu-security-sponsors since there is no debdiff to sponsor. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report. https://bugs.launchpad.net/bugs/1970228 Title: Multiple vulnerabilities in Bionic, Focal and Jammy To

[Bug 1970228] Re: Multiple vulnerabilities in Bionic, Focal and Jammy

2022-05-27 Thread Alex Murray
Setting impish to Incomplete since there is no debdiff to sponsor at this stage. ** Changed in: subversion (Ubuntu Impish) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1973322] Re: Bacula for 22.04/Jammy

2022-05-24 Thread Alex Murray
FYI I have rebuilt the version of bacula for jammy in a PPA - https://launchpad.net/~alexmurray/+archive/ubuntu/lp1973322 - if anyone could give this a test and let me know how it works for you, then we can look at trying to release it via an SRU. Thanks. -- You received this bug notification

[Bug 1971767] Re: [MIR] libfreeaptx

2022-05-24 Thread Alex Murray
I reviewed libfreeaptx 0.1.1-1ubuntu1 as checked into kinetic. This shouldn't be considered a full audit but rather a quick gauge of maintainability. libfreeaptx is an implementation of the audio processing technology (aptX) codec. It is a fork of the libopenatpx library (which is in universe) -

[Bug 1871148] Re: services start before apparmor profiles are loaded

2022-05-23 Thread Alex Murray
@mardy I thought we had snapd.apparmor specifically to avoid this scenario but I can't see that service mentioned at all in systemd- analyze plot... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1970228] Re: Multiple vulnerabilities in Bionic, Focal and Jammy

2022-05-22 Thread Alex Murray
Thanks for the updated patches - they look a lot better. Note, one thing we try and do is to add references to the patch files to indicate where they came from as per https://dep-team.pages.debian.net/deps/dep3/ - as an example see the update in

[Bug 1975407] Re: pulseaudio is getting crashed

2022-05-22 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1975408] Re: Performance is much worse than expected (Normal friendly behaviors)

2022-05-22 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1975381] Re: firewall gets disabled

2022-05-22 Thread Alex Murray
Thank you for taking the time to report this bug and helping to make Ubuntu better. Unfortunately we can't fix it, because your description didn't include enough information. You may find it helpful to read 'How to report bugs effectively' http://www.chiark.greenend.org.uk/~sgtatham/bugs.html.

[Bug 1974181] Re: package libreoffice-common 1:7.3.3-0ubuntu0.22.04.1 failed to install/upgrade: installed libreoffice-common package post-installation script subprocess returned error exit status 128

2022-05-19 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1974074] Bug is not a security issue

2022-05-18 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1973322] Re: Bacula for 22.04/Jammy

2022-05-18 Thread Alex Murray
As can be seen at https://launchpad.net/ubuntu/+source/bacula/+publishinghistory bacula was removed from Ubuntu during the jammy development cycle as it failed to compile: > FTBFS, removed from Debian testing, blocks libssl transition; Debian bug #997139 The process to get this back into jammy

[Bug 1972043] Re: Please add -ftrivial-auto-var-init=zero to default build flags

2022-05-18 Thread Alex Murray
doko can you please provide more details on why you think this should be done in dpkg instead of gcc (as we have done for almost all the other hardening options)? As Kees says, adding it to gcc means not only does this benefit Ubuntu archive packages, but also any software which is built on a

[Bug 1973827] Re: Laptop freezes when recovering from suspend / sleep mode

2022-05-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1973654] Re: Using debian-installer on a server with a Let's Encrypt cert dies

2022-05-16 Thread Alex Murray
I believe this is caused by debootstrap - it only uses packages from the release pocket (and this is frozen from the time Ubuntu 20.04 LTS was originally released). This is a known issue https://askubuntu.com/questions/744684/latest-security-updates-with- debootstrap but I am not sure if there is

[Bug 1973644] Re: package nvidia-340 (not installed) failed to install/upgrade: trying to overwrite '/usr/bin/nvidia-bug-report.sh', which is also in package nvidia-utils-470 470.103.01-0ubuntu0.20.04

2022-05-16 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1973028] Re: gnome-remote-desktop user service is always running

2022-05-16 Thread Alex Murray
I am not sure I agree with the statement that this is "harmless" for the user service to be running if remote desktop sharing is not enabled - on my jammy system I can see the RDP port open thanks to gnome-remote- desktop: $ ss -tlp | grep gnome-remote LISTEN 0 10

[Bug 1973574] Re: The system has become much choppier and no audio is being heard

2022-05-16 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1973472] Re: Vea la página de manual apt-secure(8) para los detalles sobre la creación de repositorios y la configuración de usuarios. W: El objetivo Sources (main/source/Sources) está configura

2022-05-16 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. Your bug report is more likely to get attention if it is made in English, since this is the language understood by the majority of Ubuntu developers. Additionally, please only mark a bug as "security" if it shows

[Bug 1972043] Re: Please add -ftrivial-auto-var-init=zero to default build flags

2022-05-08 Thread Alex Murray
+1 from the Security team on this - looks like a good easy win for security with no overhead or other impact from what I can see. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1972043 Title: Please

[Bug 1971288] Re: Merge libseccomp from Debian unstable for kinetic

2022-05-03 Thread Alex Murray
I uploaded https://launchpad.net/ubuntu/+source/libseccomp/2.5.4-1ubuntu1 earlier today. ** Changed in: libseccomp (Ubuntu) Status: New => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1968556] Re: nvidia-kernel-source-465 465.27-0ubuntu0.20.04.2: nvidia kernel module failed to build

2022-04-11 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1964449] Re: Recordmydesktop Crashing With Segmentation Fault

2022-04-10 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1968450] Re: snapd hangs startup with an infinite loop of start failures and breaks all user-created symlinks

2022-04-10 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1968397]

2022-04-10 Thread Alex Murray
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1968397] Re: bootloader

2022-04-10 Thread Alex Murray
Thank you for taking the time to report this bug and helping to make Ubuntu better. Unfortunately we can't fix it, because your description didn't include enough information. You may find it helpful to read 'How to report bugs effectively' http://www.chiark.greenend.org.uk/~sgtatham/bugs.html.

[Bug 1968402] Re: Ubuntu 20.04.3 boots to black screen, no TTY available

2022-04-10 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1968373] Re: Bug

2022-04-10 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-04-07 Thread Alex Murray
Yep with this patch applied I can no longer reproduce the crash and the valgrind output is clean - have just uploaded this as 2.9.4-1ubuntu1 to jammy-proposed. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-04-07 Thread Alex Murray
Ok so this looks to be the same as https://github.com/storaged- project/udisks/pull/926 which was fixed upstream - and according to the comment there causes exactly the type of issue we are seeing: "leading to memory corruption causing random failures of further atexit handlers such as cryptsetup

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-04-07 Thread Alex Murray
Sadly running it under valgrind doesn't detect this memory corruption - we see an invalid memory read on shutdown but that is all: $ sudo valgrind /usr/libexec/udisks2/udisksd ==567833== Memcheck, a memory error detector ==567833== Copyright (C) 2002-2017, and GNU GPL'd, by Julian Seward et al.

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-04-06 Thread Alex Murray
I can reproduce this by just running `sudo systemctl restart udisks2.service` - will see if I can perhaps run it under valgrind and see where the memory corruption is happening. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1968043] Re: Open CVE-2021-4048 with critical severity

2022-04-06 Thread Alex Murray
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1968043 Title: Open CVE-2021-4048 with critical severity To manage notifications

[Bug 1967840] Re: System is super breached and many things are changing and specially in chromium based applications

2022-04-05 Thread Alex Murray
Thank you for using Ubuntu and taking the time to report a bug. Your report should contain, at a minimum, the following information so we can better find the source of the bug and work to resolve it. Submitting the bug about the proper source package is essential. For help see

[Bug 1967884] Re: several snap-confine denials for capability net_admin and perfmon on 22.04

2022-04-05 Thread Alex Murray
Thanks for the heads up @jdstrand - I am seeing this too - I also have one more - fsetid: $ journalctl -b0 -t audit --grep DENIED.*snap-confine Apr 06 08:48:06 graphene audit[3733]: AVC apparmor="DENIED" operation="capable" profile="/usr/lib/snapd/snap-confine" pid=3733 comm="snap-confine"

[Bug 1452115] Re: Python interpreter binary is not compiled as PIE

2022-04-04 Thread Alex Murray
Nice - thanks @sdeziel -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1452115 Title: Python interpreter binary is not compiled as PIE To manage notifications about this bug go to:

[Bug 1953363] Re: [MIR] python-xmlschema, elementpath, importlib-resources

2022-03-28 Thread Alex Murray
I reviewed python-xmlschema 1.4.2-1 as checked into jammy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. python-xmlschema is a python package which provides XML schema support to allow XML schemas to be parsed/loaded and queried etc. It also allow XML

[Bug 1966588] Re: Huge numbers of newlines in bash after snap install command

2022-03-27 Thread Alex Murray
*** This bug is a duplicate of bug 1964442 *** https://bugs.launchpad.net/bugs/1964442 ** This bug has been marked a duplicate of bug 1964442 [jammy][regression] gnome-shell PolicyKit password prompt sends keys to the terminal -- You received this bug notification because you are a

[Bug 1966349] [NEW] FFe: Enable PIE for python 3.10 in jammy

2022-03-24 Thread Alex Murray
Public bug reported: As per LP: #1452115 enabling the python interpreter to be compiled as a position independent executable (PIE) has been a long standing request for Ubuntu. Various testing[1] has shown this to have a minimal performance impact for amd64. However, due to ongoing concerns around

[Bug 1452115] Re: Python interpreter binary is not compiled as PIE

2022-03-24 Thread Alex Murray
Thanks @doko :) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1452115 Title: Python interpreter binary is not compiled as PIE To manage notifications about this bug go to:

[Bug 1887187] Re: [MIR] nftables

2022-03-23 Thread Alex Murray
I reviewed nftables 1.0.2-1ubuntu1 as checked into jammy. This shouldn't be considered a full audit but rather a quick gauge of maintainability. nftables is a replacement for iptables etc - it provides userspace tooling to control the Netfilter packet classification system within the Linux

[Bug 1966017] Re: enable upstream python testsuite in autopkgtests

2022-03-23 Thread Alex Murray
Attaching the updated debdiff in case we do decide we want this (even in the broken state) ** Patch added: "nftables_1.0.2-1ubuntu2.debdiff" https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/1966017/+attachment/5572129/+files/nftables_1.0.2-1ubuntu2.debdiff -- You received this bug

[Bug 1966017] Re: enable upstream python testsuite in autopkgtests

2022-03-23 Thread Alex Murray
Turns out I wasn't looking closely enough at the autopkgtest logs from my local testing - I was trying to run the tests with the pre-built binary packages and whilst it would indicate the internaltest-py.sh tests were passing, they were actually completely failing without any error indication:

[Bug 1966017] Re: enable upstream python testsuite in autopkgtests

2022-03-22 Thread Alex Murray
** Patch added: "nftables_1.0.2-1ubuntu2.debdiff" https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/1966017/+attachment/5572061/+files/nftables_1.0.2-1ubuntu2.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1966017] [NEW] enable upstream python testsuite in autopkgtests

2022-03-22 Thread Alex Murray
Public bug reported: Currently the upstream python-based testsuite for nftables is disabled in the autopkgtests in debian/tests/control as follows: # Disable test until we decide what to do with the nftables python module #Tests: internaltest-py.sh #Depends: @, python #Restrictions: needs-root,

[Bug 1964442] Re: [jammy][regression] gnome-shell PolicyKit password prompt sends keys to the terminal

2022-03-21 Thread Alex Murray
Upstream bug filed https://gitlab.gnome.org/GNOME/gnome- shell/-/issues/5242 ** Bug watch added: gitlab.gnome.org/GNOME/gnome-shell/-/issues #5242 https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/5242 -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1964442] Re: [jammy][regression] gnome-shell PolicyKit password prompt sends keys to the terminal

2022-03-21 Thread Alex Murray
I personally don't think this should be low priority - this affects any application which ends up causing the gnome shell prompt dialog to appear - so in my case when reading my email and opening a GPG encrypted email I get prompted for my GPG passphrase - whilst this is happening my email client

[Bug 1965837] [NEW] Erroneous / extra input generated in requesting application when prompting to unlock keys

2022-03-21 Thread Alex Murray
Public bug reported: Recently I have noticed that when I am being prompted for the passphrase for to unlock a GPG/SSH key via the gnome-shell prompter, whilst the prompt is visible the requesting window seems to get spammed by input - this can be reproduced via running the following (but replace

[Bug 1965837] Re: Erroneous / extra input generated in requesting application when prompting to unlock keys

2022-03-21 Thread Alex Murray
If it is not clear from the video - watch the terminal window in the background when the prompt for the passphrase appears - it keeps scrolling as though getting input by newlines all the time - and this then persists even after the prompt is dismissed until I manually provide some input myself.

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-03-21 Thread Alex Murray
This looks to be the same as LP: #1955758 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1964532 Title: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected To

[Bug 1964532] Re: /usr/libexec/udisks2/udisksd:malloc_consolidate(): unaligned fastbin chunk detected

2022-03-21 Thread Alex Murray
See attached - it looks like the crash happens during shutdown - see line 11443 ** Attachment added: "journalctl-udisks-crash.log.gz" https://bugs.launchpad.net/ubuntu/+source/udisks2/+bug/1964532/+attachment/5571201/+files/journalctl-udisks-crash.log.gz ** Changed in: udisks2 (Ubuntu)

[Bug 1965235] Re: list-oem-metapackages crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages'

2022-03-18 Thread Alex Murray
*** This bug is a duplicate of bug 1964923 *** https://bugs.launchpad.net/bugs/1964923 ** This bug has been marked a duplicate of bug 1964923 list-oem-metapackages crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages' -- You received this bug

[Bug 1965235] Re: list-oem-metapackages crashed with AttributeError in packages_for_modalias(): 'Cache' object has no attribute 'packages'

2022-03-17 Thread Alex Murray
Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross

[Bug 1897454] Re: [snap] Chromium has Wayland support disabled

2022-03-09 Thread Alex Murray
The priority of this bug is Low but since Wayland is now the default session this means chromium runs via XWayland and then when doing window/screen sharing on say Google Meet I can only share windows which are also using XWayland, not native ones - which is the majority of the rest of the

[Bug 1964325] Re: Fails to print due to apparmor denied connect operation for cupsd - /run/systemd/userdb/io.systemd.Machine

2022-03-09 Thread Alex Murray
I have proposed a fix for this upstream - https://gitlab.com/apparmor/apparmor/-/merge_requests/861 - once that is reviewed then we can include the fix in jammy. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1963590] Re: Missing entry for new Launchpad PPAs (ppa.launchpadcontent.net)

2022-03-03 Thread Alex Murray
** Patch added: "squid-deb-proxy_0.8.15+nmu1ubuntu2.debdiff" https://bugs.launchpad.net/ubuntu/+source/squid-deb-proxy/+bug/1963590/+attachment/5565432/+files/squid-deb-proxy_0.8.15+nmu1ubuntu2.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1963590] [NEW] Missing entry for new Launchpad PPAs (ppa.launchpadcontent.net)

2022-03-03 Thread Alex Murray
Public bug reported: squid-deb-proxy comes with the existing ppa.launchpad.net entry commented out in mirror-dstdomain.acl.d/10-default but does not include the new ppa.launchpadcontent.net that also supports https - https://blog.launchpad.net/ppa/new-domain-names-for-ppas ProblemType: Bug

[Bug 1957716] Re: Update for CVE-2021-43860 and CVE-2022-21682

2022-03-01 Thread Alex Murray
@ahayzen - thanks for the impish debdiff - I was going to sponsor it but I notice you have used a separate set of patches than those linked to by debian and NVD for CVE-2022-21682 - does this also need: https://github.com/flatpak/flatpak/commit/445bddeee657fdc8d2a0a1f0de12975400d4fc1a ? Also

  1   2   3   4   5   6   7   8   9   10   >