Bug#1102754: unblock: ktx/1.45-1

2025-04-12 Thread Lee Garrett
Package: release.debian.org Severity: normal X-Debbugs-Cc: k...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:ktx User: release.debian@packages.debian.org Usertags: unblock Please unblock package mvdsv/1.11-1 and ktx/1.45-1 Due to a slight miscalculation on my side how l

Bug#1102754: unblock: ktx/1.45-1

2025-04-12 Thread Lee Garrett
Package: release.debian.org Severity: normal X-Debbugs-Cc: k...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:ktx User: release.debian@packages.debian.org Usertags: unblock Please unblock package mvdsv/1.11-1 and ktx/1.45-1 Due to a slight miscalculation on my side how l

Debian (E)LTS report for March 2025

2025-04-05 Thread Lee Garrett
ating! Regards, Lee Garrett, Debian LTS Team

[Aptitude-devel] Bug#1101913: `aptitude search '?all-versions(pre)'` matches on package names instead of package version numbers

2025-04-02 Thread Lee Garrett
Package: aptitude Version: 0.8.13-7 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, when searching for "?all-versions(pre)", it will return me all packages which contain the string "pre" in the package name, e.g. aeson-pretty in version 0.8.10-1+b1. "?any-version" seems to exhibit the sam

Bug#1101913: `aptitude search '?all-versions(pre)'` matches on package names instead of package version numbers

2025-04-02 Thread Lee Garrett
Package: aptitude Version: 0.8.13-7 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, when searching for "?all-versions(pre)", it will return me all packages which contain the string "pre" in the package name, e.g. aeson-pretty in version 0.8.10-1+b1. "?any-version" seems to exhibit the sam

Re: Improvement of headless server upgrades

2025-03-06 Thread Lee Garrett
On Tue, 4 Mar 2025 20:39:43 -0500, "Helmut K. C. Tessarek" wrote: Both network "outages" could have been prevented by adding a note at the end of the dist-upgrade output. e.g. something like the following (monospace font required for the "Attention" text): _ _ _ _ _ _ ___

Bug#1099580: autopkgtest-build-qemu reproducibly creates a broken sid image

2025-03-05 Thread Lee Garrett
Package: autopkgtest Version: 5.46 Severity: important X-Debbugs-Cc: deb...@rocketjump.eu Hello, when running `autopkgtest-build-qemu sid sid.img`, the resulting image is unbootable and produces a timeout when using the virt-qemu runner. The relevant lines showing the issue are: ``` autopkgtest

Bug#1099580: autopkgtest-build-qemu reproducibly creates a broken sid image

2025-03-05 Thread Lee Garrett
On 05/03/2025 15:25, Paride Legovini wrote: Control: tags -1 + moreinfo On 2025-03-05 13.53, Lee Garrett wrote: when running `autopkgtest-build-qemu sid sid.img`, the resulting image is unbootable and produces a timeout when using the virt-qemu runner. The relevant lines showing the issue are

Debian (E)LTS report for February 2025

2025-03-05 Thread Lee Garrett
E-2024-56326 I also worked on fixing CVE-2024-11079 in ansible/bullseye, that however introduced regressions and needs more work. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Bug#1099074: bookworm-pu: package jinja2/3.1.2-1+deb12u2

2025-02-27 Thread Lee Garrett
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: jin...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:jinja2 User: release.debian@packages.debian.org Usertags: pu [ Reason ] Fix CVE-2024-56201 Fix CVE-2024-56326 [ Impact ] Two security vulnerab

Bug#1099074: bookworm-pu: package jinja2/3.1.2-1+deb12u2

2025-02-27 Thread Lee Garrett
On 27/02/2025 23:06, Lee Garrett wrote: Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: jin...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:jinja2 User: release.debian@packages.debian.org Usertags: pu [ Reason ] Fix CVE-2024-56201 Fix CVE

Bug#1099074: bookworm-pu: package jinja2/3.1.2-1+deb12u2

2025-02-27 Thread Lee Garrett
On 27/02/2025 23:06, Lee Garrett wrote: Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: jin...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:jinja2 User: release.debian@packages.debian.org Usertags: pu [ Reason ] Fix CVE-2024-56201 Fix CVE

Bug#1099074: bookworm-pu: package jinja2/3.1.2-1+deb12u2

2025-02-27 Thread Lee Garrett
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: jin...@packages.debian.org, deb...@rocketjump.eu Control: affects -1 + src:jinja2 User: release.debian@packages.debian.org Usertags: pu [ Reason ] Fix CVE-2024-56201 Fix CVE-2024-56326 [ Impact ] Two security vulnerab

jinja2 moved to DEP-14 layout

2025-02-27 Thread Lee Garrett
Hi, as part of preparing a security update for jinja2/bookworm, I decided to move the packaging layout to DEP-14 [0] (as this makes my life easier). This means a few branches have been renamed: master-> debian/latest upstream -> upstream/latest {stretch,buster-backports,

[Git][security-tracker-team/security-tracker][master] LTS: claim qemu in dla-needed.txt

2025-02-23 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: dda71b68 by "Lee Garrett" at 2025-02-23T21:09:13+01:00 LTS: claim qemu in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim ansible in dla-needed.txt

2025-02-23 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 0f2e12f0 by "Lee Garrett" at 2025-02-23T21:07:41+01:00 LTS: claim ansible in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim jinja2 in dla-needed.txt

2025-02-23 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 2a7ecc31 by "Lee Garrett" at 2025-02-23T21:06:37+01:00 LTS: claim jinja2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

Bug#1098367: nmap reports pingable IPv6 host as down

2025-02-19 Thread Lee Garrett
Package: nmap Version: 7.95+dfsg-2 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hello, $ ping -c 3 2a01:4f8:231:161c::1 PING 2a01:4f8:231:161c::1 (2a01:4f8:231:161c::1) 56 data bytes 64 bytes from 2a01:4f8:231:161c::1: icmp_seq=1 ttl=58 time=21.4 ms 64 bytes from 2a01:4f8:231:161c::1: icmp

Bug#1098362: Big warning in dmesg after installation?

2025-02-19 Thread Lee Garrett
Package: hardening-runtime Version: 2 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, after installing this package an rebooting, I get the following: Feb 19 15:55:06 hopper kernel: ** Feb 19 15:55:06 hopper kernel: ** NOTICE NOT

Bug#1098307: Demote dependency on mailx to recommends or suggests?

2025-02-18 Thread Lee Garrett
Package: autopostgresqlbackup Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi Emmanuel, now that recent updates have systemd timer support, can we lower the dependency requirement of bsd-mailx | mailx to recommends or suggests? It should be easy to run this without having a mail user ag

Bug#1098269: Consider shipping apparmor profiles for the binaries

2025-02-18 Thread Lee Garrett
Package: sshguard Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi, since currently all parts of sshguard are run as root, it would make sense to restrict the potential damage that can be done via apparmor profiles. Regards, Lee -- System Information: Debian Release: trixie/sid APT pr

Bug#1098268: sshguard needlessly runs as root by default

2025-02-18 Thread Lee Garrett
Package: sshguard Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, a default install of sshguard runs as root by default, which has certain security implications we should avoid. Most action don't require root: logreading: Reading relevant files in /var/log/ or running journalctl requires

Bug#1096204: sshguard: OR recommend firewalld

2025-02-17 Thread Lee Garrett
Source: sshguard Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hello, sshguard supports various backends, as such I believe it should "Recommends: nftables | firewalld". It also supports ps (*BSD only), ipfw (FreeBSD only). iptables is also supported and packaged, however I'd not add a l

Bug#1096203: libvirt-daemon: suggest firewalld

2025-02-17 Thread Lee Garrett
Package: libvirt-daemon Version: 11.0.0-2 Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi, I believe the libvirt-daemon package should "Suggests: firewalld" to inform users that it can use firewalld for connection handling. (Further info: https://libvirt.org/firewall.html#firewalld-and-t

Bug#1096005: borgmatic borg does not correctly pass return code

2025-02-14 Thread Lee Garrett
Package: borgmatic Version: 1.9.10-1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hello, # borgmatic -c /etc/borgmatic.d/complete_system.yaml borg upgrade --show-rc --check-archives-tam [...] Archive TAM missing: batou_2022-10-19T16:28+02:00 Wed, 2022-10-19 18:30:22 [<>] Archive

Bug#1095997: borgmatic ignores exclude patterns

2025-02-14 Thread Lee Garrett
This issue is likely fixed in borgmatic >= 1.9.7. From the changelog: #977: Fix for "exclude_patterns" and "exclude_from" not supporting explicit pattern styles (e.g., "sh:" or "re:").

Bug#1095997: borgmatic ignores exclude patterns

2025-02-14 Thread Lee Garrett
Package: borgmatic Version: 1.9.3-0.1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, I recently upgraded from bookworm to trixie. To upgrade the config, I dropped the `location:`, `storage:`, and `hooks:` parameters and put the respective keys to the top-level. Running my first full syst

Bug#1095980: pressing ctrl+c no longer terminated borg

2025-02-14 Thread Lee Garrett
Package: borgmatic Version: 1.9.3-0.1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hello! When pressing ctrl+c on a borgmatic command, it no longer terminates the underlying borg process. This leads to borg still running, polluting the terminal, and of course locking the repo until you kil

Bug#1095968: switching the packaging repo to DEP-14 layout

2025-02-14 Thread Lee Garrett
Source: endlessh Version: 1.1-5 Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi, have you considered switching the repo at https://salsa.debian.org/debian/endlessh to DEP-14 layout? There are only minor changes needed: renaming branches: - debian/sid → debian/latest - upstream → upstrea

Bug#1095953: broken systemd unit

2025-02-14 Thread Lee Garrett
Package: endlessh Version: 1.1-5+b3 Severity: serious X-Debbugs-Cc: deb...@rocketjump.eu Hi, I've tested this on both a bookworm and a trixie machine, with the same result. I have no /etc/endlessh/config. Steps to reproduce: - apt install endlessh - systemctl status endlessh - notice that the se

Bug#1095953: broken systemd unit

2025-02-14 Thread Lee Garrett
Package: endlessh Version: 1.1-5+b3 Severity: serious X-Debbugs-Cc: deb...@rocketjump.eu Hi, I've tested this on both a bookworm and a trixie machine, with the same result. I have no /etc/endlessh/config. Steps to reproduce: - apt install endlessh - systemctl status endlessh - notice that the se

Debian (E)LTS report for January 2025

2025-02-12 Thread Lee Garrett
the autopkgtests in the process. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [1] https://tracker.debian.org/news/1600965/accepted-ansible-core-21418-0deb12u2-source-into-proposed-updates/ [2] https://bugs.debian.org/

Bug#1095520: ITP: qwprot -- quakeworld protocol headers

2025-02-08 Thread Lee Garrett
Package: wnpp Severity: wishlist Owner: Lee Garrett X-Debbugs-Cc: debian-de...@lists.debian.org, deb...@rocketjump.eu * Package name: qwprot Version : HEAD Upstream Contact: QW dev group * URL : https://github.com/QW-Group/qwprot * License : GPLv2

Bug#1095520: ITP: qwprot -- quakeworld protocol headers

2025-02-08 Thread Lee Garrett
Package: wnpp Severity: wishlist Owner: Lee Garrett X-Debbugs-Cc: debian-de...@lists.debian.org, deb...@rocketjump.eu * Package name: qwprot Version : HEAD Upstream Contact: QW dev group * URL : https://github.com/QW-Group/qwprot * License : GPLv2

Bug#1095520: ITP: qwprot -- quakeworld protocol headers

2025-02-08 Thread Lee Garrett
Package: wnpp Severity: wishlist Owner: Lee Garrett X-Debbugs-Cc: debian-devel@lists.debian.org, deb...@rocketjump.eu * Package name: qwprot Version : HEAD Upstream Contact: QW dev group * URL : https://github.com/QW-Group/qwprot * License : GPLv2

Bug#1095450: `fwupdmgr --json update` outputs invalid JSON

2025-02-07 Thread Lee Garrett
Package: fwupd Version: 2.0.5-1 Severity: minor X-Debbugs-Cc: deb...@rocketjump.eu Hi, at least one command outputs invalid JSON despite the --json flag: randall@batou:~$ fwupdmgr --json get-devices | jsonlint : ok randall@batou:~$ fwupdmgr --json update | jsonlint :1:0: Error: Unknown identifie

Bug#1095441: wishlist: add a tool to validate sources.list and .sources files

2025-02-07 Thread Lee Garrett
Package: apt Version: 2.9.27 Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi Julian, when using configuration management tools like ansible it's nice to have a method to validate a templated sources.list/.sources file before writing it to it's final location, e.g. apt-validate /tmp/tmp.

Bug#1095430: off-by-one error when setting the account expiry

2025-02-07 Thread Lee Garrett
Package: passwd Version: 1:4.16.0-7 Severity: grave X-Debbugs-Cc: deb...@rocketjump.eu Hi, on a trixie or newer machine, the following happens: root@trixie:~# usermod -e 1970-01-02 ansibulluser root@trixie:~# getent shadow ansibulluser ansibulluser:!:20126:0:9:7::0:

[Pkg-shadow-devel] Bug#1095430: off-by-one error when setting the account expiry

2025-02-07 Thread Lee Garrett
Package: passwd Version: 1:4.16.0-7 Severity: grave X-Debbugs-Cc: deb...@rocketjump.eu Hi, on a trixie or newer machine, the following happens: root@trixie:~# usermod -e 1970-01-02 ansibulluser root@trixie:~# getent shadow ansibulluser ansibulluser:!:20126:0:9:7::0:

Bug#1095430: off-by-one error when setting the account expiry

2025-02-07 Thread Lee Garrett
Package: passwd Version: 1:4.16.0-7 Severity: grave X-Debbugs-Cc: deb...@rocketjump.eu Hi, on a trixie or newer machine, the following happens: root@trixie:~# usermod -e 1970-01-02 ansibulluser root@trixie:~# getent shadow ansibulluser ansibulluser:!:20126:0:9:7::0:

[Git][security-tracker-team/security-tracker][master] LTS: claim jinja2 in dla-needed.txt

2025-01-31 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 1e54567a by "Lee Garrett" at 2025-01-31T17:08:54+01:00 LTS: claim jinja2 in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

[Git][security-tracker-team/security-tracker][master] LTS: claim ansible in dla-needed.txt

2025-01-31 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 51ef8796 by "Lee Garrett" at 2025-01-31T16:58:50+01:00 LTS: claim ansible in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

Bug#1094640: wishlist: Send desktop notification on installation birthday

2025-01-29 Thread Lee Garrett
Source: installation-birthday Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi lamby! A great addition to installation-birthday would be to notify the logged in user via notify-send about the event. Newer desktop installations usually come without a configured MTA, and sometimes even with

Bug#1093770: upstream homepage returns 404

2025-01-22 Thread Lee Garrett
Source: famfamfam-silk Severity: minor X-Debbugs-Cc: deb...@rocketjump.eu Hi, it looks like the upstream URI http://www.famfamfam.com/lab/icons/silk/ is dead, and the main page also just returns a placeholder. A quick search offers two upstream alternatives: https://github.com/legacy-icons/famfa

Bug#1093769: Consider using a packaging repo on salsa.debian.org

2025-01-22 Thread Lee Garrett
Source: famfamfam-silk Severity: minor X-Debbugs-Cc: deb...@rocketjump.eu Hi, please consider setting up a packaging repo for this package on https://salsa.debian.org, to make contributions and attributions easier. Greets, Lee -- System Information: Debian Release: 12.9 APT prefers stable-se

Bug#1093274: Unattended upgrades fails to upgrade dnsmasq due to configuration file changes

2025-01-21 Thread Lee Garrett
On 17/01/2025 15:49, Sven Geuer wrote: On Fri, 17 Jan 2025 12:32:41 +0100 Lee Garrett wrote: this is indeed caused by the one character typo fix in the config file, which prompts for the conffile change you see here. While this is unfortunate, reverting the change in a new update would just

Bug#1093288: feature request: warn when (accidentally) updating conffiles in stable updates

2025-01-17 Thread Lee Garrett
Package: piuparts Version: 1.1.7 Severity: wishlist X-Debbugs-Cc: deb...@rocketjump.eu Hi, when preparing a stable-update, it's good to avoid conffile updates, as those prompt the user, and also prevent those packages from being updated by unattended-upgrades. In my specific case it was a dnsmas

Bug#1093274: Unattended upgrades fails to upgrade dnsmasq due to configuration file changes

2025-01-17 Thread Lee Garrett
On 17/01/2025 10:08, Tianyu Chen wrote: Package: dnsmasq Version: 2.90-4~deb12u1 Severity: serious X-Debbugs-Cc: billchenchina2...@gmail.com, Lee Garrett , Simon Kelley , Sven Geuer Hi, When SSHing to my server, I've received the following message: 1 updates could not be inst

Bug#1093274: Unattended upgrades fails to upgrade dnsmasq due to configuration file changes

2025-01-17 Thread Lee Garrett
On 17/01/2025 10:08, Tianyu Chen wrote: Package: dnsmasq Version: 2.90-4~deb12u1 Severity: serious X-Debbugs-Cc: billchenchina2...@gmail.com, Lee Garrett , Simon Kelley , Sven Geuer Hi, When SSHing to my server, I've received the following message: 1 updates could not be inst

Bug#1080469: ansible will fail to install or upgrade if /etc/ansible is symbolic link

2025-01-11 Thread Lee Garrett
Hi Michał, On Wed, 04 Sep 2024 14:58:06 +0200 =?utf-8?b?TWljaGHFgiBK?= wrote: Package: ansible Version: 7.7.0+dfsg-3+deb12u1 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? apt update *

[DRE-maint] Bug#1092670: autopkgtest failure in bookworm with dnsmasq 2.90-4~deb12u1

2025-01-10 Thread Lee Garrett
Source: vagrant Version: 2.3.4+dfsg-1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, when running vagrant/2.3.4+dfsg-1 autopkgtest on bookworm with dnsmasq 2.90-4~deb12u1 from bookworm-proposed-updates, the autopkgtests fail, due to a dependency on dnsmasq, which itself starts a dnsmasq

Bug#1092670: autopkgtest failure in bookworm with dnsmasq 2.90-4~deb12u1

2025-01-10 Thread Lee Garrett
Source: vagrant Version: 2.3.4+dfsg-1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, when running vagrant/2.3.4+dfsg-1 autopkgtest on bookworm with dnsmasq 2.90-4~deb12u1 from bookworm-proposed-updates, the autopkgtests fail, due to a dependency on dnsmasq, which itself starts a dnsmasq

Bug#1092105: gnome-shell crash when toggling privacy screen and then suspend/resume

2025-01-08 Thread Lee Garrett
Hi Simon, On 06/01/2025 11:30, Simon McVittie wrote: On Sat, 04 Jan 2025 at 16:30:56 +0100, Lee Garrett wrote: I was able to catch a coredump which I can't attach due to size. Can you get a backtrace from this core dump, with gnome-shell and mutter debug symbols available? That's u

Bug#1092105: gnome-shell crash when toggling privacy screen and then suspend/resume

2025-01-04 Thread Lee Garrett
Package: mutter Version: 43.8-0+deb12u1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, steps to reproduce: 1) login to a gnome desktop instance 2) press fn + d to toggle privacy screen 3) suspend 4) resume The TTY which previously has the user instance running will crash, killing all

Bug#1089106: bookworm-pu: package ansible-core/2.14.18-0+deb12u1

2025-01-03 Thread Lee Garrett
(2.14.18-0+deb12u2) bookworm; urgency=medium + + * Update integration test dependencies + * Update integration test restrictions + + -- Lee Garrett Fri, 03 Jan 2025 12:15:50 +0100 + ansible-core (2.14.18-0+deb12u1) bookworm; urgency=medium [ Lee Garrett ] diff --git debian/tests/control de

Bug#1089106: bookworm-pu: package ansible-core/2.14.18-0+deb12u1

2025-01-03 Thread Lee Garrett
(2.14.18-0+deb12u2) bookworm; urgency=medium + + * Update integration test dependencies + * Update integration test restrictions + + -- Lee Garrett Fri, 03 Jan 2025 12:15:50 +0100 + ansible-core (2.14.18-0+deb12u1) bookworm; urgency=medium [ Lee Garrett ] diff --git debian/tests/control de

Debian (E)LTS report for December 2024

2025-01-02 Thread Lee Garrett
lease 2.14.18 (which fixes CVE-2024-8775 and CVE-2024-9902), and also manually patched CVE-2024-11079. For ansible bullseye I also started patching the latter CVE. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

[Git][security-tracker-team/security-tracker][master] LTS: claim ansible in dla-needed.txt

2024-12-31 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: d82ddf3d by "Lee Garrett" at 2024-12-31T12:47:11+01:00 LTS: claim ansible in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

Bug#1079941: bookworm-pu: package dnsmasq/2.90-4~deb12u1

2024-12-31 Thread Lee Garrett
Hi, On 30/12/2024 21:12, Salvatore Bonaccorso wrote: Hi, On Sun, Dec 01, 2024 at 10:14:16PM +0100, Lee Garrett wrote: Hi, these three CVEs are now fixed in buster and bullseye. This means users who upgrade to bookworm will be vulnerable to those issues again. Can we get a decision from the

Bug#1079941: bookworm-pu: package dnsmasq/2.90-4~deb12u1

2024-12-31 Thread Lee Garrett
Hi, On 30/12/2024 21:12, Salvatore Bonaccorso wrote: Hi, On Sun, Dec 01, 2024 at 10:14:16PM +0100, Lee Garrett wrote: Hi, these three CVEs are now fixed in buster and bullseye. This means users who upgrade to bookworm will be vulnerable to those issues again. Can we get a decision from the

Bug#1090832: /etc/security/namespace.init parses umask wrong in sid

2024-12-19 Thread Lee Garrett
Package: libpam-modules Version: 1.5.2-6+deb12u1 Severity: minor X-Debbugs-Cc: deb...@rocketjump.eu /etc/security/namespace.init has this line: mask=$(awk '/^UMASK/{gsub("#.*$", "", $2); print $2; exit}' /etc/login.defs) However, in sid /etc/login.defs does not set UMASK anymore, so mask evaluat

Debian (E)LTS report for November 2024

2024-12-04 Thread Lee Garrett
onsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Bug#1079941: bookworm-pu: package dnsmasq/2.90-4~deb12u1

2024-12-01 Thread Lee Garrett
2024 21:35:44 +0200 Lee Garrett wrote: Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: dnsm...@packages.debian.org, Simon Kelley , Sven Geuer , deb...@rocketjump.eu Control: affects -1 + src:dnsmasq (Please provide

Bug#1079941: bookworm-pu: package dnsmasq/2.90-4~deb12u1

2024-12-01 Thread Lee Garrett
2024 21:35:44 +0200 Lee Garrett wrote: Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: dnsm...@packages.debian.org, Simon Kelley , Sven Geuer , deb...@rocketjump.eu Control: affects -1 + src:dnsmasq (Please provide

[SECURITY] [DLA 3974-1] dnsmasq security update

2024-11-30 Thread Lee Garrett
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 From: Lee Garrett To: debian-lts-announce@lists.debian.org Subject: [SECURITY] [DLA 3974-1] dnsmasq security update - - Debian LTS Advisory DLA-3974-1debian

[Git][security-tracker-team/security-tracker][master] Reserve DLA-3974-1 for dnsmasq

2024-11-29 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 1fdf666a by Lee Garrett at 2024-11-29T16:10:33+01:00 Reserve DLA-3974-1 for dnsmasq - - - - - 3 changed files: - data/CVE/list - data/DLA/list - data/dla-needed.txt Changes

[Git][security-tracker-team/security-tracker][master] Reclaim dnsmasq again

2024-11-29 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 31865531 by Lee Garrett at 2024-11-29T14:39:37+01:00 Reclaim dnsmasq again - - - - - 1 changed file: - data/dla-needed.txt Changes: = data/dla-needed.txt

Bug#1088402: ansible integration test fail using aptsource

2024-11-27 Thread Lee Garrett
Package: python3-apt Version: 2.6.0 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, ansible uses python3-apt in some of the integration tests, where it triggers following traceback on sid: Traceback (most recent call last): File \"\", line 121, in File \"\", line 113, in _ansiballz_

Debian (E)LTS report for October 2024

2024-11-11 Thread Lee Garrett
searchers of the two vulnerabilities who have provided me with a test environment to verify the functionality of the backport. I'm also in the process backporting the last two CVE patches for buster. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team

Bug#1086843: /etc/profile requires implicit PATH set before setting it

2024-11-06 Thread Lee Garrett
Package: base-files Version: 12.4+deb12u8 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, reproducer for the problem: $ mkdir tmp $ sudo debootstrap bookworm tmp/ [...] $ sudo PATH=not-set-correctly /usr/sbin/chroot tmp/ /bin/bash -l bash: id: command not found bash: [: : integer express

[Git][security-tracker-team/security-tracker][master] LTS: claim dnsmasq in dla-needed.txt

2024-11-01 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: ad653b5c by "Lee Garrett" at 2024-11-01T13:27:40+01:00 LTS: claim dnsmasq in dla-needed.txt - - - - - 1 changed file: - data/dla-needed.txt Changes:

Bug#1054230: Please change permissions on /var/lib/libvirt/images/

2024-10-16 Thread Lee Garrett
Upstream has responded, and it's indeed a tad more complicated: https://lists.libvirt.org/archives/list/de...@lists.libvirt.org/message/BUTSYSN22Y57GHHWHJW7FTMEZTJWZ4ZN/ As such, I'm refraining for pushing these changes and will find a different workaround. On 19.10.23 17:12, Lee Gar

Debian LTS report for August 2024

2024-09-04 Thread Lee Garrett
o our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://bugs.debian.org/1079941 [1] https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html

Bug#1079938: sbuild-createchroot creates unmerged /usr for bookworm by default

2024-08-30 Thread Lee Garrett
Hey josch, On 29.08.24 14:47, Johannes Schauer Marin Rodrigues wrote: Hi Lee, there seems to be some confusion (also from my end) -- read further below. Quoting Lee Garrett (2024-08-28 20:35:06) when creating a bookworm schroot e.g. with sbuild-createchroot --merged-usr bookworm /var/lib

Changing permissions for /var/lib/libvirt/images/

2024-08-30 Thread Lee Garrett
Hi everyone, while using virt-v2v I've hit an issue [0], where essentially virt-v2v fails as non-root user, due to /var/lib/libvirt/images/ belonging to root:root. I proposed to change the ownership to root:libvirt, and permission bits to ug=rwx,o=x, as that would allow users of the libvirt gr

Bug#1079938: sbuild-createchroot creates unmerged /usr for bookworm by default

2024-08-28 Thread Lee Garrett
Package: sbuild Version: 0.85.0 Severity: serious X-Debbugs-Cc: deb...@rocketjump.eu Hi, when creating a bookworm schroot e.g. with sbuild-createchroot --merged-usr bookworm /var/lib/schroot/schroots/bookworm-amd64-sbuild http://localhost:3142/deb.debian.org/debian/ the resulting schroot has a

Bug#1079938: sbuild-createchroot creates unmerged /usr for bookworm by default

2024-08-28 Thread Lee Garrett
Package: sbuild Version: 0.85.0 Severity: serious X-Debbugs-Cc: deb...@rocketjump.eu Hi, when creating a bookworm schroot e.g. with sbuild-createchroot --merged-usr bookworm /var/lib/schroot/schroots/bookworm-amd64-sbuild http://localhost:3142/deb.debian.org/debian/ the resulting schroot has a

Bug#1008735: should /etc/os-release contain VERSION variables for testing and unstable?

2024-08-22 Thread Lee Garrett
Hi Santiago, thank you for responding. On 22.08.24 15:54, Santiago Vila wrote: El 22/8/24 a las 15:27, Lee Garrett escribió: The following integration test in the ansible package is an example that breaks when VERSION gets removed from /etc/os-release in the release cycle

Bug#1008735: should /etc/os-release contain VERSION variables for testing and unstable?

2024-08-22 Thread Lee Garrett
Hi, The following integration test in the ansible package is an example that breaks when VERSION gets removed from /etc/os-release in the release cycle: (ansible_distribution == 'Debian' and ansible_distribution_version is version('8', '>=') Link to the upstream source: https://github.com/

Bug#1078560: Document Signed-By: fields in deb822-style .sources file

2024-08-12 Thread Lee Garrett
On 12.08.24 16:48, Julian Andres Klode wrote: Control: severity -1 wishlist On Mon, Aug 12, 2024 at 04:35:38PM GMT, Lee Garrett wrote: Package: apt Version: 2.6.1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, it would be nice if the sources.list man page would write more verbosely

Bug#1078560: Document Signed-By: fields in deb822-style .sources file

2024-08-12 Thread Lee Garrett
Package: apt Version: 2.6.1 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, it would be nice if the sources.list man page would write more verbosely in what format the Signed-By: field in a deb822-styles .sources file should be. I converted a binary key into ASCII-armored via: gpg --enar

Debian LTS report for July 2024

2024-08-02 Thread Lee Garrett
cornercases when using ftf[1] VMs with autopkgtest, and found a rather intricate bug in autopkgtest that I reported in [2]. I fixed a bug in the freexian CLI when displaying available packages. [3] Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett

[Git][security-tracker-team/security-tracker][master] claim dnsmasq and add comment

2024-08-01 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: dd2deafa by Lee Garrett at 2024-08-02T01:12:26+02:00 claim dnsmasq and add comment - - - - - 1 changed file: - data/dsa-needed.txt Changes: = data/dsa

[Git][security-tracker-team/security-tracker][master] Document tools for checking/claiming LTS packages

2024-07-31 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 397d4313 by Lee Garrett at 2024-07-31T14:13:54+02:00 Document tools for checking/claiming LTS packages Explicitely document where the tools are that can be used to check for LTS work, including URIs

[Git][security-tracker-team/security-tracker][master] Fix syntax or dla-needed.txt

2024-07-30 Thread Lee Garrett (@lgarrett)
Lee Garrett pushed to branch master at Debian Security Tracker / security-tracker Commits: 00579092 by Lee Garrett at 2024-07-30T20:45:24+02:00 Fix syntax or dla-needed.txt Prior to ff58fcf817, this file ended in a single line with "--". That commit introduced a change that cause

Bug#684134: Package 'locales' resets pre-set debconf variable 'default_environment_locale' on install

2024-07-27 Thread Lee Garrett
Hi Aurelien! On 26.07.24 13:11, Aurelien Jarno wrote: Hi, On 2024-07-25 00:34, Lee Garrett wrote: So when /etc/locale.gen exists, this file is read, and then the settings in the debconf database overwritten by those value. So once debconf is installed, there's no programmatic way via de

Bug#684134: Package 'locales' resets pre-set debconf variable 'default_environment_locale' on install

2024-07-27 Thread Lee Garrett
Hi Aurelien! On 26.07.24 13:11, Aurelien Jarno wrote: Hi, On 2024-07-25 00:34, Lee Garrett wrote: So when /etc/locale.gen exists, this file is read, and then the settings in the debconf database overwritten by those value. So once debconf is installed, there's no programmatic way via de

Bug#684134: Package 'locales' resets pre-set debconf variable 'default_environment_locale' on install

2024-07-27 Thread Lee Garrett
Hi Aurelien! On 26.07.24 13:11, Aurelien Jarno wrote: Hi, On 2024-07-25 00:34, Lee Garrett wrote: So when /etc/locale.gen exists, this file is read, and then the settings in the debconf database overwritten by those value. So once debconf is installed, there's no programmatic way via de

Bug#684134: Package 'locales' resets pre-set debconf variable 'default_environment_locale' on install

2024-07-24 Thread Lee Garrett
Hi, having run into this issue, I have figured out why locales behaves unexpectedly. Here's a snippet to show the issue: --->8-->8-->8-->8-->8-->8-->8-->8-->8--- root@sid:/tmp/autopkgtest.3hIrFA/build.AZ6/real-tree# apt install locales Installing: locales Sum

Bug#684134: Package 'locales' resets pre-set debconf variable 'default_environment_locale' on install

2024-07-24 Thread Lee Garrett
Hi, having run into this issue, I have figured out why locales behaves unexpectedly. Here's a snippet to show the issue: --->8-->8-->8-->8-->8-->8-->8-->8-->8--- root@sid:/tmp/autopkgtest.3hIrFA/build.AZ6/real-tree# apt install locales Installing: locales Sum

Bug#1070914: closing 1070914

2024-07-23 Thread Lee Garrett
close 1070914 thanks Hi Olivia, I cannot reproduce the bug on Debian. Debian generally does not support any Debian derivatives, as we cannot know what has been changed. While the firefox-esr package might be unforked, many of the underlying libraries are. Feel free to report a bug if you can rep

Bug#1076343: setup-testbed will break networking in certain conditions

2024-07-14 Thread Lee Garrett
On 14.07.24 20:48, Lee Garrett wrote: [...] In a step not completely clear to me network-manager then gets removed in line 620 [1]. I at least can't make out any package there that network-manager depends on. I found the reason; it's because xml-core gets removed.

Bug#1076343: setup-testbed will break networking in certain conditions

2024-07-14 Thread Lee Garrett
Package: autopkgtest Version: 5.28 Severity: normal X-Debbugs-Cc: deb...@rocketjump.eu Hi, issue is that setup-testbed will break networking config of a VM by writing a broken config file, e.g. /etc/network/interfaces/enp0s31f6\nenx482ae3598891 with the following contents: auto enp0s31f6 enx482ae

Re: Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
Hi Chime, On 11.07.24 19:18, Chime Hart wrote: Hi Lee-and-All: I am not a programmer, nor a developer, just an enthusiastic Linux fan. What I am wondering is how do you decide what packages to work on? LTS work is mainly sponsored by Freexian, who in turn has customers paying for long-term s

Debian LTS report for June 2024

2024-07-11 Thread Lee Garrett
-4237 Which I will upload once I have fixed the remaining CVEs. Thanks to our sponsors for financing this work, and to Freexian for coordinating! Regards, Lee Garrett, Debian LTS Team [0] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1069891 [1] https://bugs.debian.org/cgi-bin/bugreport.cgi

Bug#1069768: The 'no-agent-forwarding' key restriction disables server alive message support

2024-07-11 Thread Lee Garrett
On 09.07.24 17:24, Guilhem Moulin wrote: On Tue, 09 Jul 2024 at 14:20:59 +0200, Guilhem Moulin wrote: On Sat, 29 Jun 2024 at 15:52:49 +0200, Lee Garrett wrote: Hi Guilhem, could you give quick feedback on this? I'm also happy to prepare a NMU for bookworm if you can't find the t

Bug#1042768: Stop shipping scripts that don't work with irssi >= 1.4

2024-07-01 Thread Lee Garrett
Hi Daniel, On 31.10.23 00:37, Daniel Echeverri wrote: Hello!! Thanks for the report!. I am working in a new version of irssi-scripts that remove all deprecated scripts, and include a replacements scripts. Do you mean to create a new file debian/NEWS with [0]? Regards [0]: https://irssi.org/

Bug#1069768: The 'no-agent-forwarding' key restriction disables server alive message support

2024-06-29 Thread Lee Garrett
On Wed, 24 Apr 2024 22:00:48 +0200 Lee Garrett wrote: my /etc/dropbear/initramfs/dropbear.conf has: DROPBEAR_OPTIONS="-s -j -k -I 180 -c /usr/bin/cryptroot-unlock" -j and -k are "disable local/remote port forwarding". Seems like we cracked the case. Nice! Is there a ch

Bug#1054544: community.zabbix plugin misses bookworm support and fails with error dict object' has no attribute 'bookworm'

2024-06-28 Thread Lee Garrett
On Wed, 25 Oct 2023 20:36:48 +0530 Pirate Praveen wrote: package: anisble severity: important version: 7.3.0+dfsg-1 : FAILED! => {"msg": "The task includes an option with an undefined variable. The error was: 'dict object' has no attribute 'bookworm'. 'dict object' has no attribute 'bookworm

Bug#1070193: bookworm-pu: package ansible-core/2.14.16-0+deb12u1

2024-06-25 Thread Lee Garrett
On 16.06.24 00:25, Jonathan Wiltshire wrote: Control: tag -1 confirmed On Wed, May 01, 2024 at 05:05:05PM +0200, Lee Garrett wrote: [ Reason ] This is a bugfix-only update from ansible-core 2.14.3 to 2.14.16. This fixes three CVEs: - Address issue where ANSIBLE_NO_LOG was ignored (CVE-2024

  1   2   3   4   5   6   7   >