Bug#1034208: Partman may reset user's choice for ESP partitions use

2023-04-10 Thread Pascal Hambourg
Package: partman-efi Severity: minor Boot method: USB stick Image version: debian-bookworm-DI-rc1-amd64-netinst.iso Dear maintainer, as discussed in #debian-boot (you asked for it), I observed that partman resets the method set by the user on ESP partitions after setting LVM or RAID (and poss

Bug#1034205: wayout: does not do anything

2023-04-10 Thread Willow Barraco
Wayout is a daemon and must keep running for the output to be preserved. The call | wayout is an example to demonstrate it take its input from stdin. Wayout display things above the wallpaper. It is not an overlay that is present above other surfaces. If the pipe shut down, then the stdin is broken

Bug#1034207: okular: typewriter annotation ignores some letters

2023-04-10 Thread Janusz S . Bień
Package: okular Version: 4:20.12.3-2 Severity: normal X-Debbugs-Cc: none, Janusz S. Bień Looks like the annotation ignores non-ASCII letters, cf. the attachment. -- System Information: Debian Release: 11.6 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security

Bug#1034206: unblock: owslib/0.27.2-3

2023-04-10 Thread Bas Couwenberg
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: ows...@packages.debian.org Control: affects -1 + src:owslib Please unblock package owslib It is affected by CVE-2023-27476 reported in #1034182. [ Reason ] Fixes security iss

Bug#856649: suricata: IPv4 defrag evasion issue

2023-04-10 Thread Salvatore Bonaccorso
Source: suricata Source-Version: 3.2.1-1~exp1 Hi Sascha, On Mon, Apr 10, 2023 at 11:11:12PM +0200, Sascha Steinbiss wrote: > Hi Salvatore, > > > > (re: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856649) > > > > > > Can we just close this bug? This has been addressed for years, and I am

Bug#1034205: wayout: does not do anything

2023-04-10 Thread Antoine Beaupre
Package: wayout Version: 0.1.4-1 Severity: normal X-Debbugs-Cc: ~mil/sxmo-de...@lists.sr.ht I can't figure out how to use this program. The upstream README (which is actually not shipped with the Debian package) has a few examples: > Static example for a calendar: > > $ cal | wayout > > Exampl

Bug#1034204: RFP: wlclock -- A digital analog clock for Wayland desktops

2023-04-10 Thread Antoine Beaupre
Package: wnpp Severity: wishlist * Package name: wlclock Version : 1.0.1 Upstream Contact: Leon Plickat * URL : https://git.sr.ht/~leon_plickat/wlclock * License : GPL3 Programming Lang: C Description : A digital analog clock for Wayland desktops wlcloc

Bug#1034203: snmp: specifying -Op /at all/ segfaults all snmpcmd(1) commands

2023-04-10 Thread наб
Package: snmp Version: 5.9+dfsg-4+deb11u1 Version: 5.9.3+dfsg-2 Severity: normal Dear Maintainer, Originally ran into $ snmptranslate -Op TAURON-G13-MIB::tauronG13 Segmentation fault this morning by accident. This happens in all these configurations: $ snmptranslate -Op .1 Segmentation f

Bug#1034202: mirror listing update for linux.purple-cat.net

2023-04-10 Thread Mike Hosken
Package: mirrors Severity: minor User: mirr...@packages.debian.org Usertags: mirror-list Submission-Type: update Site: linux.purple-cat.net Type: leaf Archive-architecture: ALL amd64 arm64 armel armhf hurd-i386 i386 kfreebsd-amd64 kfreebsd-i386 mips mips64el mipsel powerpc ppc64el s390x Archive-h

Bug#1034201: support DANE for HTTPS authentication

2023-04-10 Thread John Scott
Package: apt Version: 2.6.0 Severity: wishlist apt-transport-https only supports the traditional certificate authority model. However, APT uses GnuTLS, which has a convenient interface for validating certificates with DANE. GnuTLS should be used to provide an alternative to the certificate autho

Bug#1034195: filezilla: Filezilla not available anymore at i386

2023-04-10 Thread Philip Wyett
On Mon, 2023-04-10 at 23:23 +0200, Gert van de Kraats wrote: > Source: filezilla > Version: 3.63.0-1 > Severity: important > > Dear Maintainer, > > Recently I automatically upgraded to version 3.63.0-1. > With this version the package and binary filezilla is no longer available at > i386 architec

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Samuel Thibault
Hello, Thanks for the backtrace, I believe I understand what is happening. I came up with another solution that should be way safer. Thanks, Samuel

Bug#1033995: qtbase-opensource-src: Fix accessibility of qt5 applications run as root

2023-04-10 Thread Samuel Thibault
Control: reopen -1 Control: found -1 5.15.8+dfsg-5 Hello, So the patch that was submitted upstream is indeed posing problems: #1034160, #1034169, #1034191. AIUI, I guess that connecting the enabledChanged signal too early is problematic because the code is not actually ready to handle it because

Bug#1034200: lomiri: reproducible builds: results.txt contains arbitrary data

2023-04-10 Thread Vagrant Cascadian
Source: lomiri Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The data in the shipped results.txt file contains arbitrary data: https://tests.reproducible-builds.org/debian/rb-pkg/bookw

Bug#1034199: lomiri: reproducible builds: temporary directories embedded in .sh files

2023-04-10 Thread Vagrant Cascadian
Source: lomiri Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randomness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The files in the lomiri tarball appear to be in arbitrary order, possibly affected by locale or filesystem differences: htt

Bug#1034198: bullseye-pu: package golang-github-containers-common/0.33.4+ds1-1+deb11u1

2023-04-10 Thread Reinhard Tartler
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: golang-github-containers-com...@packages.debian.org, siret...@tauware.de Control: affects -1 + src:golang-github-containers-common [ Reason ] Podman relies on DBUS

Bug#1031439: gcc-sh-elf FTBFS: mystery solved?

2023-04-10 Thread John Scott
Hi, I'm doing the build right now and it got past the part where it's been failing, so I'm pretty sure we're good! Adrian, would you be willing to sponsor my upload? I'll send a second mail when it's ready. The change is extremely small, and to be frank I'll probably skip running the test suit

Bug#1034197: [INTL:ro] Translation of "apt-listchanges" to Romanian

2023-04-10 Thread Remus-Gabriel Chelu
Package: apt-listchanges Version:3.25 Severity: wishlist Tags: l10n, patch Dear Maintainer, Please find attached the Romanian translation of the «apt-listchanges» file. Thanks, Remus-Gabriel apt-listchanges_3.25_ro.po Description: Binary data

Bug#1033913: partman-auto-lvm: Broken "Guided - use entire disk and set up LVM" in UEFI mode

2023-04-10 Thread Steve McIntyre
I've just pushed an update to the code here... On Mon, Apr 10, 2023 at 05:45:15PM +0200, Pascal Hambourg wrote: >On 10/04/2023 at 15:13, Steve McIntyre wrote: >> >> Overall comment: I'm not trying to make the heuristics 100% reliable >> here, as I don't think that's actually possible. Instead, I'

Bug#1030930: podman: DNS resolution fails in 'podman build' but works in 'podman run'

2023-04-10 Thread Reinhard Tartler
Control: tag -1 + unreproducible moreinfo Hi Kevin, great to hear from you in this space! On Thu, Feb 9, 2023 at 8:36 AM Kevin P. Fleming wrote: > Package: podman > Version: 4.3.1+ds1-5+b1 > Severity: important > > Dear Maintainer, > > I am seeing DNS resolution fail when using 'podman build'

Bug#1034195: filezilla: Filezilla not available anymore at i386

2023-04-10 Thread Gert van de Kraats
Source: filezilla Version: 3.63.0-1 Severity: important Dear Maintainer, Recently I automatically upgraded to version 3.63.0-1. With this version the package and binary filezilla is no longer available at i386 architecture (32 bits). This is also visible at the Debian package overview for filez

Bug#1034194: unblock: closure-compiler/20130227+dfsg1-13

2023-04-10 Thread Markus Koschany
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: a...@debian.org Please unblock package closure-compiler [ Reason ] This is related to #1034127 and the unblock request of rhino 1.7.14. If we ship rhino 1.7.14 in Bookworm, t

Bug#856649: suricata: IPv4 defrag evasion issue

2023-04-10 Thread Sascha Steinbiss
Hi Salvatore, (re: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856649) Can we just close this bug? This has been addressed for years, and I am not sure we need to keep these open forever. Can you pin point the upstream version where this was fixed? Sure, you did so yourself in your or

Bug#1034127: unblock: rhino/1.7.14-2.1

2023-04-10 Thread Markus Koschany
Am Sonntag, dem 09.04.2023 um 22:28 +0200 schrieb Paul Gevers: > > [ Risks ] > This is a new upstream release. This is not a small change. And while > typing this unblock request, I'm getting uncomfortable and wonder if > we want this. But as it's all prepared, let's discuss and pull Markus > in t

Bug#996367: pipewire issues with M-Audio 410

2023-04-10 Thread Alexandre Lymberopoulos
Package: pipewire-pulse Dear all, As mentioned in a message sent on Fri, 18 Nov 2022 19:33:34 -0300, the bug reported under the number 996367 (version 0.3.38-2) seems to be solved at that moment (version 0.3.60-1). I'm sorry but can't figure out which version implemented the solution after so lon

Bug#996367: pipewire issues with M-Audio 410

2023-04-10 Thread Alexandre Lymberopoulos
Dear Alban, Unfortunately I can't remember the exact point where the bug I reported was solved, it was more than one year between my bugreport and the answer of the maintainer, and almost five months from that answer to your message. I'll close this bug now. Thanks for writing. Cheers, Alexandre

Bug#1034193: minidlna: Dutch localization error: contains Swedish

2023-04-10 Thread Manuel Bilderbeek
Package: minidlna Version: 1.3.0+dfsg-2.2+b3 Severity: normal Dear Maintainer, Since I am using Dutch (NL) localization on my PC, I noticed that I suddenly see a Swedish text on my TV when browsing my PC's DLNA directories. In particular, I see the text "Nyligen tillagd" appearing in /usr/share/

Bug#1034192: xserver-xorg-video-nouveau: Random system freeze while watching videos (GT710/GK208B)

2023-04-10 Thread Bartosz Skrzypczak
Package: xserver-xorg-video-nouveau Version: 1:1.0.17-2 Severity: important So far I have only reproduced this issue while playing youtube videos in firefox. This did not happen with official nvidia drivers (before it got moved to nvidia-tesla-driver). While playing a video, the X will randomly

Bug#1034191: Alt-F2 fail to open krunner

2023-04-10 Thread Ivan Sergio Borgonovo
Package: libqt5gui5 Version: 5.15.8+dfsg-4 After upgrading from 5.15.8+dfsg-3 to 5.15.8+dfsg-4 opening krunner in lxqt doesn't work anymore. It doesn't seem to be a shortcut problem Alt-F1, F2 etc... works. Launching krunner from konsole get stuck with no debugging info. Downgrading fix the

Bug#1033847: Please update to upstream sources

2023-04-10 Thread Richard B. Kreckel
On 4/10/23 19:55, Sergio Durigan Junior wrote: fix_quote_readline_by_ref.patch, thanks to JuanJo Ciarlante (Closes: #739835) + avoid escaping 1st '~' (LP: #1288314) + avoid quoting if empty, else expansion without args only shows dirs (LP: #1288031)

Bug#1034190: More security bugs in game loading

2023-04-10 Thread Ben Hutchings
Package: sgt-puzzles Version: 20230122.806ae71-1 Severity: serious Tags: security upstream fixed-upstream X-Debbugs-Cc: Debian Security Team Ben Harris found multiple issues in sgt-puzzles where a malformed game description or save file can lead to a buffer overflow, buffer overread, use of an un

Bug#1034189: Support for NVIDIA GeForce FX 5200 in PowerMac G5

2023-04-10 Thread Stan Johnson
Package: src:linux Version: 6.1.0-7-powerpc64 Please add support in future Debian powerpc64 kernels for the NVIDIA GeForce FX 5200 graphics card for PowerMac G5. The applicable option appears to be CONFIG_FB_RIVA=y or CONFIG_FB_RIVA=m. Adding ONFIG_FB_RIVA will allow testing of default Debian ke

Bug#1033593: spyder: does not allow running profiler and says "Please install the Python profiler modules"

2023-04-10 Thread Julian Gilbey
On Sun, Apr 09, 2023 at 11:07:10AM +0100, Julian Gilbey wrote: > On Mon, Mar 27, 2023 at 06:34:27PM -0300, Patrick Zanon wrote: > > Package: spyder > > Version: 5.4.2+ds-5 > > Severity: important > > X-Debbugs-Cc: ne...@libero.it > > > > > > Dear Maintainer, > > > > I'm trying to use spyder's pr

Bug#1034069: /var/log/boot~ is never created

2023-04-10 Thread Mark Hindley
Bjarni, Thanks for this On Fri, Apr 07, 2023 at 09:52:17PM +, Bjarni Ingi Gislason wrote: > Package: bootlogd > Version: 3.06-2 > Severity: important > > Dear Maintainer, > >* What led up to the situation? > > /var/log/boot* was not updated after 28th September 2021. > > File is us

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Samuel Thibault
Antonio, le lun. 10 avril 2023 21:13:59 +0200, a ecrit: > Thread 1 "krunner" received signal SIGSEGV, Segmentation fault. > 0x74a9814a in ?? () from /lib/x86_64-linux-gnu/libdbus-1.so.3 > (gdb) bt > #0  0x74a9814a in ?? () from /lib/x86_64-linux-gnu/libdbus-1.so.3 > #1  0x74

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Antonio
Found this: $ systemctl --user status plasma-krunner ×plasma-krunner.service - KRunner Loaded: loaded (/usr/lib/systemd/user/plasma-krunner.service; static) Active: failed(Result: signal) since Mon 2023-04-10 21:11:08 CEST; 14s ago   Duration: 5.239s    Process: 10623 ExecStart=/usr/bin

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Salvatore Bonaccorso
Hi Santiago, On Mon, Apr 10, 2023 at 08:51:06PM +0200, Santiago Ruano Rincón wrote: > Control: reassign -1 bzip3 > Control: retitle -1 bipz3 CVE-2023-29415 CVE-2023-29416 > CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421 > > Dear Moritz and Sec Team, > > Please, correct me if I am wr

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Santiago Ruano Rincón
Control: reassign -1 bzip3 Control: retitle -1 bipz3 CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421 Dear Moritz and Sec Team, Please, correct me if I am wrong, but it seems a bzip3 bug, instead of a bzip2's. El 10/04/23 a las 19:33, Moritz Mühlenhoff e

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Salvatore Bonaccorso
Hi Moritz, On Mon, Apr 10, 2023 at 07:33:38PM +0200, Moritz Mühlenhoff wrote: > Source: bzip2 > X-Debbugs-CC: t...@security.debian.org > Severity: grave > Tags: security > > Hi, > > The following vulnerabilities were published for bzip2. I think this all should be against src:bzip3 instead? Re

Bug#1033847: Please update to upstream sources

2023-04-10 Thread Gabriel F. T. Gomes
Thanks, Sergio. You're the best archaeologist! S2 On Mon, 10 Apr 2023 13:55:27 -0400 Sergio Durigan Junior wrote: > On Monday, April 10 2023, Gabriel F. T. Gomes wrote: > > > When I took the maintainer role for bash-completion, I did a lot of bug > > archaeology, but the amount of bugs and pat

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Antonio
I confirm this problem, it should be in one of the following packages installed today: 10/04/23 ^ 10:20:56 libqt5opengl5-dev:amd64 (5.15.8+dfsg-3->5.15.8+dfsg-4) 10/04/23 ^ 10:20:57 qtbase5-private-dev:amd64 (5.15.8+dfsg-3->5.15.8+dfsg-4) 10/04/23 ^ 10:21:00 qtbase5-dev:amd64 (5.15.8+dfsg-3->5

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Samuel Thibault
Antonio, le lun. 10 avril 2023 20:40:12 +0200, a ecrit: > I confirm this problem, Ok, but I'd need a way to reproduce it to be able to fix the change... Samuel

Bug#1021490: bookworm: please mention users must migrate off dmraid

2023-04-10 Thread Paul Gevers
Control: tags -1 patch On 09-10-2022 15:15, Chris Hofstaedtler wrote: please add a note to the bookworm release notes, stating that users need to migrate off dmraid during or before the bookworm cycle. New systems cannot be installed with it. bookworm will still have the dmraid package, so user

Bug#1034188: dmraid's last Debian stable release is bookworm

2023-04-10 Thread Paul Gevers
Source: dmraid Severity: serious Tags: sid trixie bookworm bookworm-ignore Hi, As discussed in bug 864423 and soon to be documented in the release-notes, dmraid is not to be shipped in Debian stable after the release of bookworm. This bug should ensure that dmraid will not be in trixie. Pau

Bug#1033847: Please update to upstream sources

2023-04-10 Thread Sergio Durigan Junior
On Monday, April 10 2023, Gabriel F. T. Gomes wrote: > When I took the maintainer role for bash-completion, I did a lot of bug > archaeology, but the amount of bugs and patches was too large, so I > don't know the reason for every packaging bit. I could do some more > digging, but a lot of the his

Bug#1034187: gpac: CVE-2023-0841 CVE-2023-1448 CVE-2023-1449 CVE-2023-1452 CVE-2023-1654 CVE-2023-1655

2023-04-10 Thread Moritz Mühlenhoff
Source: gpac X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for gpac. CVE-2023-1448[1]: | A vulnerability, which was classified as problematic, was found in | GPAC 2.3-DEV-rev35-gbbca86917-master. This affects the functi

Bug#1034185: opendoas: CVE-2023-28339

2023-04-10 Thread Moritz Mühlenhoff
Source: opendoas X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for opendoas. CVE-2023-28339[0]: | OpenDoas through 6.8.2, when TIOCSTI is available, allows privilege | escalation because of sharing a terminal with the orig

Bug#1034186: heat: CVE-2023-1625

2023-04-10 Thread Moritz Mühlenhoff
Source: heat X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for heat. CVE-2023-1625[0]: information leak in API https://bugzilla.redhat.com/show_bug.cgi?id=2181621 https://review.opendev.org/c/openstack/heat/+/868166 https

Bug#1034184: nextcloud-desktop: CVE-2023-28999

2023-04-10 Thread Moritz Mühlenhoff
Source: nextcloud-desktop X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for nextcloud-desktop. CVE-2023-28999[0]: | Nextcloud is an open-source productivity platform. In Nextcloud | Desktop client 3.0.0 until 3.8.0, Nextcl

Bug#1034183: stellarium: CVE-2023-28371

2023-04-10 Thread Moritz Mühlenhoff
Source: stellarium X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for stellarium. CVE-2023-28371[0]: | In Stellarium through 1.2, attackers can write to files that are | typically unintended, such as ones with absolute path

Bug#1034182: owslib: CVE-2023-27476

2023-04-10 Thread Moritz Mühlenhoff
Source: owslib X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for owslib. CVE-2023-27476[0]: | OWSLib is a Python package for client programming with Open Geospatial | Consortium (OGC) web service interface standards, and their

Bug#1034181: nomad: CVE-2023-0821

2023-04-10 Thread Moritz Mühlenhoff
Source: nomad X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for nomad. CVE-2023-0821[0]: | HashiCorp Nomad and Nomad Enterprise 1.2.15 up to 1.3.8, and 1.4.3 | jobs using a maliciously compressed artifact stanza source can

Bug#1034179: qemu: CVE-2023-1544

2023-04-10 Thread Moritz Mühlenhoff
Source: qemu X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for qemu. CVE-2023-1544[0]: | A flaw was found in the QEMU implementation of VMWare's paravirtual | RDMA device. This flaw allows a crafted guest driver to allocat

Bug#1034180: radare2: CVE-2023-1605

2023-04-10 Thread Moritz Mühlenhoff
Source: radare2 X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for radare2. CVE-2023-1605[0]: | Denial of Service in GitHub repository radareorg/radare2 prior to | 5.8.6. https://huntr.dev/bounties/9dddcf5b-7dd4-46cc-abf9-

Bug#1034178: opensmtpd: CVE-2023-29323

2023-04-10 Thread Moritz Mühlenhoff
Source: opensmtpd X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for opensmtpd. CVE-2023-29323[0]: | ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 | before errata 020, and OpenSMTPD Portable before 7

Bug#1034177: bzip2: CVE-2023-29415 CVE-2023-29416 CVE-2023-29418 CVE-2023-29419 CVE-2023-29420 CVE-2023-29421

2023-04-10 Thread Moritz Mühlenhoff
Source: bzip2 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for bzip2. CVE-2023-29415[0]: | An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial | of service (process hang) can occur with a crafted archive

Bug#1032642: iproute2: ip tunnel change ip6gre to gre crashes with stack smash

2023-04-10 Thread Stephen Hemminger
On Mon, 3 Apr 2023 20:47:01 -0600 David Ahern wrote: > On 4/3/23 9:24 AM, Stephen Hemminger wrote: > > ted > >> > >> This happens because iproute2 just assumes the tunnel is ipv4, but the > >> kernel "knows" it's actually ip6gre so when calling the SIOCGETTUNNEL > >> ioctl it writes back a stru

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Samuel Thibault
Hello, Arthur Marsh, le mar. 11 avril 2023 00:43:16 +0930, a ecrit: > krunner alt-F2 shortcut worked again I cannot reproduce the issue. What I did was: - install bookworm with the KDE desktop task - upgrade libqt5core5a to 5.15.8+dfsg-4, that upgraded all other libraries from qt5base. - rebo

Bug#1033847: Please update to upstream sources

2023-04-10 Thread Gabriel F. T. Gomes
On Mon, 10 Apr 2023 14:04:06 +0200 "Richard B. Kreckel" wrote: > > Regarding my hangs: It is because something's broken in my NIS > (yellow-pages) setup (haven't fully analyzed yet). It turns out that, > when doing tab completion, your patch 00-fix_quote_readline_by_ref.patch > tries to match a

Bug#1034167: unblock (pre-approval): mutter/43.4-1

2023-04-10 Thread Sebastian Ramacher
Control: tags -1 moreinfo confirmed On 2023-04-10 15:29:08 +0100, Simon McVittie wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: mut...@packages.debian.org > Control: affects -1 + src:mutter > > I'd like to

Bug#1034166: unblock (pre-approval): gnome-shell/43.4-1

2023-04-10 Thread Sebastian Ramacher
Control: tags -1 moreinfo confirmed On 2023-04-10 15:27:52 +0100, Simon McVittie wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: gnome-sh...@packages.debian.org > Control: affects -1 + src:gnome-shell > > I

Bug#1034175: libfm-qt12: When connecting to an unknown host using ssh:// or sftp:// target, "Log In Anyway" button is ignored

2023-04-10 Thread Julien ROBIN
Package: libfm-qt12 Version: 1.2.1-1+b1 Severity: normal X-Debbugs-Cc: julien.robi...@free.fr Dear Maintainer, When connecting to ssh:// or sftp:// for the first time, a question message appears, which is normal (described below). But the "Log In Anyway" button causes "Login dialog canceled" inst

Bug#1034134: [pre-approval] unblock: glibc/2.36-9

2023-04-10 Thread Sebastian Ramacher
Control: tags -1 moreinfo confirmed On 2023-04-10 11:02:23 +0200, Aurelien Jarno wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: gl...@packages.debian.org, debian-gl...@lists.debian.org > Control: affects -1

Bug#1034149: unblock: (pre-approval): glib2.0/2.74.6-2

2023-04-10 Thread Sebastian Ramacher
Control: tags -1 confirmed moreinfo On 2023-04-10 13:17:32 +0100, Simon McVittie wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: glib...@packages.debian.org > Control: affects -1 + src:glib2.0 > > I've been

Bug#977945: Can't reproduce

2023-04-10 Thread ng
I can't reproduce this anymore, how should I proceed? I am not sure if it was caused by a bad implementation of start x on tty, I am currently using the following on my .profile file: if [ -z $DISPLAY ] && [ "$(tty)" = "/dev/tty1" ]; then    exec startxfce4 fi It was either that or an update

Bug#1034172: python-cmarkgfm: CVE-2023-26485 CVE-2023-24824

2023-04-10 Thread Moritz Mühlenhoff
Source: python-cmarkgfm X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for python-cmarkgfm. CVE-2023-26485[0]: | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and | rendering library and program in C. A polyn

Bug#1034174: ruby-commonmarker: CVE-2023-26485 CVE-2023-24824

2023-04-10 Thread Moritz Mühlenhoff
Source: ruby-commonmarker X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for ruby-commonmarker. CVE-2023-26485[0]: | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and | rendering library and program in C. A p

Bug#1034173: r-cran-commonmark: CVE-2023-26485 CVE-2023-24824

2023-04-10 Thread Moritz Mühlenhoff
Source: r-cran-commonmark X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for r-cran-commonmark. CVE-2023-26485[0]: | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and | rendering library and program in C. A p

Bug#1034171: cmark-gfm: CVE-2023-26485 CVE-2023-24824

2023-04-10 Thread Moritz Mühlenhoff
Source: cmark-gfm X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for cmark-gfm. CVE-2023-26485[0]: | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and | rendering library and program in C. A polynomial time c

Bug#990703: Bookworm has the fix

2023-04-10 Thread ng
Hello, pinentry-program /usr/bin/pinentry  works again in Bookworm,  I don't have to install pinentry-qt anymore. Bug resolved.

Bug#1034170: netatalk: CVE-2022-43634

2023-04-10 Thread Moritz Mühlenhoff
Source: netatalk X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for netatalk. CVE-2022-43634[0]: | This vulnerability allows remote attackers to execute arbitrary code | on affected installations of Netatalk. Authentication is

Bug#1033913: partman-auto-lvm: Broken "Guided - use entire disk and set up LVM" in UEFI mode

2023-04-10 Thread Pascal Hambourg
On 10/04/2023 at 15:13, Steve McIntyre wrote: Overall comment: I'm not trying to make the heuristics 100% reliable here, as I don't think that's actually possible. Instead, I'm trying to tread the fine line of: * minimising false negatives - let's try to pick up on the most common cases w

Bug#1034169: libqt5core5a: upgrade to 5.15.8+dfsg-4 stops krunner shortcut from working

2023-04-10 Thread Arthur Marsh
Package: libqt5core5a Version: 5.15.8+dfsg-4 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Doing the following upgrade: [UPGRADE] libqt5concurrent5:amd64 5.15.8+dfsg-3 -> 5.15.8+dfsg-4 [UPG

Bug#1032298: tcpdump: apparmor blocks writing to stdout/stderr in lxd container [PATCH]

2023-04-10 Thread Romain Francoise
Hi, On Fri, Mar 3, 2023 at 9:45 AM Gianfranco Costamagna wrote: > + # allow printing to stdout/stderr when inside a container > + # (LP: #1667016) > + /dev/pts/* rw, Thank you for reporting this issue, and the patch. While the change is indeed trivial, giving unfettered rw access to /dev/pts/

Bug#1020479: Ready to Implement

2023-04-10 Thread Soren Stoutner
The dependencies are finally in place so this can be implemented. To make things simpler for dictionary packagers, we are using a virtual package and an unversioned path for the conversion tool so that dictionary packagers don’t have to make modifications to their packages when the versions of

Bug#1034098: Acknowledgement (reportbug: gamemode needs policykit-1 as a dependency)

2023-04-10 Thread Safir Secerovic
Hi Simon, Yes, you are correct. policykit-1 was its own package in stable. For testing and further things have been decentralized. Also, yes, it should depend on pkexec. I have checked with upstream and also verified with other distros. Hopefully, this can be implemented soon. Regards, sapphire

Bug#1034168: RFS: profile-cleaner/2.44-1 [ITP] -- Reduces browser profile size by cleaning their sqlite databases

2023-04-10 Thread Peter B
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "profile-cleaner":  * Package name : profile-cleaner    Version  : 2.44-1    Upstream contact : graysky  * URL  : https://github.com/graysky2/profile-cleaner  * Lice

Bug#1034167: unblock (pre-approval): mutter/43.4-1

2023-04-10 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: mut...@packages.debian.org Control: affects -1 + src:mutter I'd like to upload a new upstream bug fix release of mutter. [ Reason ] Catch up with upstream 43.4 bug fix release

Bug#1034166: unblock (pre-approval): gnome-shell/43.4-1

2023-04-10 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: gnome-sh...@packages.debian.org Control: affects -1 + src:gnome-shell I'd like to upload a new upstream bug fix release of gnome-shell. [ Reason ] Catch up with upstream 43.4

Bug#1034165: unblock: waypipe/0.8.4-3

2023-04-10 Thread Gard Spreemann
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: wayp...@packages.debian.org, g...@nonempty.org Control: affects -1 + src:waypipe Please unblock package waypipe. [ Reason ] Waypipe versions prior to 0.8.6 contain a memory l

Bug#1034164: unblock: teeworlds/0.7.5-2

2023-04-10 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: teewor...@packages.debian.org, Moritz Muehlenhoff , car...@debian.org Control: affects -1 + src:teeworlds Dear release team, Please unblock package teeworlds Moritz Muehlenh

Bug#1034107: RFP: xmpppy -- XMPP implementation in Python

2023-04-10 Thread Alexey Nezhdanov
Hi. I wasn't maintaining the project for at least 12 years. But there are indeed several people who move it forward. You might have better luck contacting them on the GitHub issue tracker. You might also consider doing the debian maintainer work (porting, packaging, etc) yourself (as I did about

Bug#1029210: smartmontools.service fails since bookworm

2023-04-10 Thread Christian Franke
Possible fix for the package: Add '-q nodev0' or '-q never' to ExecStart in smartmontools.service. Workaround for users: Add one of these to smartd_opts in /etc/default/smartmontools. Option '-q nodev0' is available since smartmontools 7.3. Then smartd will exit with status 0 instead of 17 (

Bug#1012218: firefox 111.0.1-1 can be built on Unmatched board

2023-04-10 Thread Bo YU
Source: firefox Version: 111.0.1-1 Followup-For: Bug #1012218 Hi, The firefox now can be built on the Unmatched board with the patch: ``` ... Build Architecture: riscv64 Build Type: binary Build-Space: 16289628 Build-Time: 59070 Distribution: experimental Host Architecture: riscv64 Install-Time:

Bug#1034163: waypipe: Leaks memory

2023-04-10 Thread Gard Spreemann
Package: waypipe Version: 0.8.4-2 Severity: important X-Debbugs-Cc: g...@nonempty.org Upstream commit 9070c4c527c906cb186588ca410d92d2f7f3c7ba fixes and documents a memory leak [1] present in versions prior to 0.8.6. The leak can be reproduced by running e.g. waypipe -d ssh localhost weston-sim

Bug#1023596: bookworm: document changes in default rsyslog configuration

2023-04-10 Thread Richard Lewis
This bug is now fixed in commit 7122b30d https://salsa.debian.org/ddp-team/release-notes/-/commit/7122b30dd1a483379759558faa720db7b570010c (i dont know if the bug should be set closed/pending or if that happens later?)

Bug#1031259: ddcutil requires module i2c-dev

2023-04-10 Thread Sanford Rockowitz
The upstream source has been changed to install file /usr/lib/modules-conf.d/ddcutil, which will ensure that module i2c-dev is loaded.  The change will appear in Debian once the code freeze for bookworm is lifted.

Bug#1034158: geocode-glib: geolocation not working in Initial Setup, Weather

2023-04-10 Thread Jeremy Bícha
The patch fixes the bug for Initial Setup and the GNOME Clocks app. I wasn't able to reproduce the bug in some other GNOME apps that depend on geocode-glib: Maps and Weather. Thank you, Jeremy Bícha

Bug#1034162: unblock: cinnamon/5.6.8-1

2023-04-10 Thread Fabio Fantoni
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: cinna...@packages.debian.org, fantonifa...@tiscali.it Control: affects -1 + src:cinnamon Please unblock package cinnamon 5.6.8-1 include a new bugfix release with some fixes:

Bug#1034161: unblock: muffin/5.6.4-1

2023-04-10 Thread Fabio Fantoni
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: muf...@packages.debian.org, fantonifa...@tiscali.it Control: affects -1 + src:muffin Please unblock package muffin 5.6.4-1 include a new bugfix release with some fixes: - met

Bug#1033913: partman-auto-lvm: Broken "Guided - use entire disk and set up LVM" in UEFI mode

2023-04-10 Thread Steve McIntyre
Hey Pascal, and thanks for the review! Overall comment: I'm not trying to make the heuristics 100% reliable here, as I don't think that's actually possible. Instead, I'm trying to tread the fine line of: * minimising false negatives - let's try to pick up on the most common cases where people

Bug#856649: suricata: IPv4 defrag evasion issue

2023-04-10 Thread Salvatore Bonaccorso
Hi, On Sun, Apr 09, 2023 at 01:16:34PM +0200, Sascha Steinbiss wrote: > Hi, > > (re: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856649) > > Can we just close this bug? This has been addressed for years, and I am not > sure we need to keep these open forever. Can you pin point the upstrea

Bug#1032469: smartmontools: startup takes too long for systemd

2023-04-10 Thread Christian Franke
A note for upcoming smartmontools release 7.4: It NOTIFY_SOCKET is set in environment, smartd 7.4 will sd_notify "EXTEND_TIMEOUT_USEC=2000" for each disk during device registration and then for each disk during first device checks.No such calls will occur after "READY=1" has been notified.

Bug#1034160: libkscreenlocker5: Screen locker crashes asking for loginctl command

2023-04-10 Thread Adilson dos Santos Dantas
Package: libkscreenlocker5 Version: 5.27.2-1 Severity: grave Justification: renders package unusable Dear Maintainer, After some libraries updates, I cannot lock my plasma session anymore. It shows a black screen with a message asking to go to a virtual terminal and run a 'loginctl unlock-sessi

Bug#1033755: heimdal: CVE-2022-3116

2023-04-10 Thread Salvatore Bonaccorso
On Sat, Apr 08, 2023 at 01:44:33PM +0200, Salvatore Bonaccorso wrote: > Hi Brian, > > On Sat, Apr 08, 2023 at 07:56:55PM +1000, Brian May wrote: > > Salvatore Bonaccorso writes: > > > > > Version: 7.8.git20221117.28daf24+dfsg-1.1 > > > > Are you sure this applies to the unstable version? > > >

Bug#1034159: Kernel support for more ChromeOS devices

2023-04-10 Thread Alper Nebi Yasak
Source: linux Version: 6.1.20-2 Severity: wishlist Hi, I've been going through ChromiumOS kernel configs [1] in hope that I could reach a reasonable list of things to enable for hardware support for more chromebooks. What I did is roughly: - Prepend base.config, /common.config to /*.flavour.conf

Bug#1034158: geocode-glib: geolocation not working in Initial Setup, Weather

2023-04-10 Thread Jeremy Bícha
Source: geocode-glib Version: 3.26.3-5 Severity: serious Forwarded: https://gitlab.gnome.org/GNOME/geocode-glib/-/issues/30 Automatic geolocation isn't working in the GNOME Weather or GNOME Initial Setup Apps. This is a regression from the libsoup3 migration. Thank you, Jeremy Bícha

Bug#1034157: unblock: pci.ids/0.0~2023.03.17-1

2023-04-10 Thread Guillem Jover
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: pci@packages.debian.org Control: affects -1 + src:pci.ids Please unblock package pci.ids [ Reason ] This is a data-only package that provides know PCI IDs and their descr

Bug#1034156: libgpg-error: New upstream version 1.47

2023-04-10 Thread Andreas Metzler
Source: libgpg-error Version: 1.46-1 Severity: wishlist Hello, libgpg-error 1.47 has been released, please find branches on salssa that could be fast-forwarded: debian/experimental-tmp-1.47 --> debian/experimental pristine-tar-tmp-1.47 --> pristine-tar upstream-tmp-1.47 --> upstream cu Andreas

Bug#1034155: ippsample: CVE-2023-28428

2023-04-10 Thread Salvatore Bonaccorso
Source: ippsample Version: 0.0~git20220607.72f89b3-1 Severity: normal Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for ippsample. CVE-2023-28428[0]: | PDFio is a C library for reading and writing PDF files. In versio

  1   2   >