Bug#928281: unblock: lemonldap-ng/2.0.2+ds-7 (pre-approval)

2019-05-01 Thread Xavier Guimard
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package lemonldap-ng Hi all, upstream authors of lemonldap-ng have updated language translations. I imported updated translation files in a patch. Do you think it is opportu

Bug#928282: filezilla: CVE-2019-5429

2019-05-01 Thread Salvatore Bonaccorso
Source: filezilla Version: 3.39.0-2 Severity: grave Tags: security upstream Hi, The following vulnerability was published for filezilla. CVE-2019-5429[0]: | Untrusted search path in FileZilla before 3.41.0-rc1 allows an | attacker to gain privileges via a malicious 'fzsftp' binary in the | user'

Bug#928283: lintian: false positive pkg-js-tools-test-is-missing for openjk: assumes variables contain --with=nodejs

2019-05-01 Thread Simon McVittie
Package: lintian Version: 2.13.0 Severity: normal lintian emits pkg-js-tools-test-is-missing for the openjk source package in contrib. I believe this is because it uses a variable in the dh invocation, to disable one binary package (which is not considered ready by upstream) unless built for expe

Bug#928284: libxalan2-java: Breaks JOSM with javaws: Provider org.apache.xerces.jaxp.validation.XMLSchemaFactory not found

2019-05-01 Thread Jörn Heissler
Source: libxalan2-java Severity: normal Hello, when libxalan2-java is installed, I cannot run JOSM (https://josm.openstreetmap.de/) through javaws anymore. Reproduce: * apt install icedtea-netx libxalan2-java * Click https://josm.openstreetmap.de/download/josm.jnlp in your browser * Alternative

Bug#928285: rtc.debian.org: uses resiprocate which is no longer in Debian

2019-05-01 Thread Jonas Smedegaard
Package: rtc.debian.org Severity: important -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Paul Wise warns¹ that the rtc.debian.org service uses resiprocate which is no longer in Debian. - Jonas ¹ https://lists.debian.org/caktje6g05y7wxuvryw3rqh4eaytrbfs5j78r1l8rkpqf-mb...@mail.gmail.com -

Bug#850627: Note

2019-05-01 Thread Dominik Stadler
Bug #914217 would fix this one via update to the latest version from Git, see Changelog at https://github.com/afrantzis/bless/blob/master/NEWS

Bug#914217: Update

2019-05-01 Thread Dominik Stadler
This would also fix bugs #767216 and #850627 and maybe one or two more.

Bug#928168: ntp: Wrong path in apparmor profile for samba

2019-05-01 Thread L. van Belle
Hai, We got reports on the samba list of this. See: https://www.spinics.net/lists/samba/msg156739.html And i verified the user his problem and also noticed the wrong path also, and reported it as fix with the change. You said you did follow the wiki, which part? Is windows in you test case s

Bug#928240: etw: Segmentation fault at start

2019-05-01 Thread Steinar H. Gunderson
On Wed, May 01, 2019 at 01:11:32AM +0200, Markus Koschany wrote: > Thanks for providing a solution and a way forward. Could you provide a > trivial fix/patch as well? I'm willing to test it and ask the release > team for an unblock. I currently don't understand the underlying issue > and why it was

Bug#927824: Grisbi 1.2.1-1 always crashes when creating a new transaction

2019-05-01 Thread Jérôme de Bretagne
Thanks Ludovic, the updated version has been unblocked and has now migrated to testing, this fixes the issue. Le mer. 24 avr. 2019 à 17:10, Ludovic Rousseau a écrit : > > Le 24/04/2019 à 15:51, Ludovic Rousseau a écrit : > > debian-release will not accept to migrate 1.2.2 into testing. > > Maybe

Bug#928286: libpam-sss: passwd change does not prompt for new passwd unless using pam_sss.so prompt_always

2019-05-01 Thread J. Pfennig
Package: libpam-sss Version: 1.16.3-3.1 Severity: normal Dear Maintainer, problem: changing SAMBA AD DC passwd using SSSD with AD providers When user runs 'passwd' the old pw is prompted for and validated but not prompt for a new pw is shows. SSSD log and source code indicate that pam_s

Bug#928287: ITP: python-qutip -- python package for simulating the dynamics of open quantum systems

2019-05-01 Thread Drew Parsons
Package: wnpp Severity: wishlist Owner: Drew Parsons * Package name: python-qutip Version : 4.3.1 Upstream Author : Paul D. Nation and Robert J. Johansson * URL : http://qutip.org/ * License : BSD Programming Lang: Python Description : python package fo

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Chris Lamb
Source: knack Version: 0.6.1-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: randoness X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org Hi, Whilst working on the Reproducible Builds effort [0], we noticed that knack could not be built reproducib

Bug#928289: git-flow: empty defaults

2019-05-01 Thread Alessandro -oggei- Ogier
Package: git-flow Version: 1.12.0-1 Severity: normal Dear Maintainer, version 1.12 lost defaults: ## 1.12 behaviour $ mkdir repo && ( cd repo && git init && git flow init -d ) Initialized empty Git repository in /tmp/repo/.git/ Using default branch names. No branches exist yet. Base branc

Bug#787259: Acknowledgement (start error with pbuilder-satisfydepends-gdebi)

2019-05-01 Thread François Poirotte
On Wed, 06 Jul 2016 15:30:26 +0200 Leopold Palomo-Avellaneda wrote:> On Fri, 27 May 2016 20:33:54 + Mattia Rizzolo wrote: > > The question then is why this line could produce the error is some packages > and in other no. > > Leopold > > Hi, I just stumbled across this issue when tryin

Bug#613832:

2019-05-01 Thread Mrs Jemilah
Happy New month and good news greetings my dear. I have been expecting to receive your reply on my previous two emails i sent to you last month, Regarding the welfare of the less privileges . Did you receive my two email? Please am surprise that you did not respond. Urgently get back to me.

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Luca Boccassi
On Wed, 2019-05-01 at 05:32 -0400, Chris Lamb wrote: > Source: knack > Version: 0.6.1-1 > Severity: wishlist > Tags: patch > User: > reproducible-bui...@lists.alioth.debian.org > > Usertags: randoness > X-Debbugs-Cc: > reproducible-b...@lists.alioth.debian.org > > > Hi, > > Whilst working on

Bug#928290: unblock: debian-edu-doc/2.10.16

2019-05-01 Thread Holger Levsen
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock debian-edu-doc, it's a documentation only change: debian-edu-doc (2.10.16) unstable; urgency=medium * Update Debian Edu Buster and Stretch manuals from the wiki. * Updat

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Chris Lamb
[adding reproducible-bui...@lists.alioth.debian.org to CC] Hi Luca, > Also the reprotest on the Gitlab CI didn't flag it as those builds are > run with "nocheck": That's... unfortunate. :) Indeed, there are a non-trivial number of packages that are non-determinstic due to their tests. Could you

Bug#928290: Acknowledgement (unblock: debian-edu-doc/2.10.16)

2019-05-01 Thread Holger Levsen
Hi, attached is the debdiff for this unblock request. -- tschau, Holger --- holger@(debian|reproducible-builds|layer-acht).org PGP fingerprint: B8BF 5413 7B09 D35C F026 FE9D 091A B856 069A

Bug#921688: electrum being actively used for phishing

2019-05-01 Thread Laurent Bigonville
On Tue, 30 Apr 2019 10:59:16 -0400 Sam Hartman wrote: > > I realize that we normally don't care about packages only in sid, but > the version of electrum in sid is apparently only useful to funnel your > bitcoin to attackers. > The issue is that versions prior to 3.3 are vulnerable to mallware, a

Bug#926547: insserv: tests/run-tests are not used

2019-05-01 Thread Dmitry Bogatov
[2019-04-28 21:05] Jesse Smith > > I have been looking into the issues with the insserv test scripts. There > are a few problems here, in brief: > [...] > > In other words, I think there is some difference in expectations between > what I think insserv should be doing and what the scripts we inh

Bug#928291: unblock: signing-party/2.10-1

2019-05-01 Thread Guilhem Moulin
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hi there, gpg-key2ps(1) from signing-party 2.9-1 is vulnerable to CVE-2018-15599: unsafe shell call enabling shell injection via a User ID. Debdiff between 2.9-1 and 2.10-1 attached. (Whi

Bug#928288: knack: please make the build reproducible

2019-05-01 Thread Luca Boccassi
On Wed, 2019-05-01 at 06:18 -0400, Chris Lamb wrote: > [adding > reproducible-bui...@lists.alioth.debian.org > to CC] > > Hi Luca, > > > Also the reprotest on the Gitlab CI didn't flag it as those builds > > are > > run with "nocheck": > > That's... unfortunate. :) Indeed, there are a non-triv

Bug#711853: insserv: Design bug: rcN.d unstable and not, maintainable

2019-05-01 Thread Alessandro Vesely
On Thu 25/Apr/2019 16:12:42 +0200 Dmitry Bogatov wrote: > [2019-04-22 19:07] Alessandro Vesely > >> The point is building every time from scratch, rigidly enjoining specs, >> like it or lump it, versus an incremental, tolerant, minimal changes >> operation. > > What is the point of "incremental,

Bug#928292: stretch-pu: package signing-party/2.5-1

2019-05-01 Thread Guilhem Moulin
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi there, CVE-2019-11627 was recently published for signing-party's gpg-key2ps(1). Unsafe shell call enabling shell injection via a User ID. See also #928256. However the Se

Bug#787259: Acknowledgement (start error with pbuilder-satisfydepends-gdebi)

2019-05-01 Thread Thorsten Glaser
François Poirotte dixit: > this and I'm not sure how this could be fixed (does the Debian policy even > state what the character encoding should be for the control file?) It requires UTF-8 encoding, has been doing so since a couple of years. Can you try rebuilding without your local hack, but wi

Bug#928292: stretch-pu: package signing-party/2.5-1

2019-05-01 Thread Salvatore Bonaccorso
Hi Guilhem [disclaimer: not part of release team, just spotted below a typo] On Wed, May 01, 2019 at 01:27:26PM +0200, Guilhem Moulin wrote: > +signing-party (2.5-1+deb9u1) stretch; urgency=medium > + > + * Backport security fix for CVE-2018-15599: unsafe shell call enabling > shell

Bug#928291: unblock: signing-party/2.10-1

2019-05-01 Thread Guilhem Moulin
On Wed, 01 May 2019 at 12:46:12 +0200, Guilhem Moulin wrote: > gpg-key2ps(1) from signing-party 2.9-1 is vulnerable to CVE-2018-15599: > unsafe shell call enabling shell injection via a User ID. Erm that should be CVE-2019-11627, and the changelog is wrong as well. Would you like me to upload a 2.

Bug#921019: arm64: Please provide sound modules for Allwinner A64 based systems

2019-05-01 Thread Andrei POPESCU
On Jo, 31 ian 19, 17:21:54, Harald Geyer wrote: > Please enable the following Kconfig symbols as modules: > > CONFIG_SND_SUN50I_CODEC_ANALOG > CONFIG_SND_SUN8I_CODEC > CONFIG_SND_SUN4I_I2S > CONFIG_SND_SOC_SIMPLE_AMPLIFIER > CONFIG_SND_SIMPLE_CARD > > These are necessary for sound support on pi

Bug#928293: ITP: ensmallen -- C++ header-only library for mathematical optimization

2019-05-01 Thread Barak A . Pearlmutter
Package: wnpp Owner: Barak A. Pearlmutter Severity: wishlist * Package name: ensmallen Version : 1.14.2 Upstream Author : Ryan Curtin * URL or Web page : https://www.ensmallen.org/ * License : 3-clause BSD Description : C++ header-only library for mathematical optim

Bug#928292: stretch-pu: package signing-party/2.5-1

2019-05-01 Thread Guilhem Moulin
Hi Salvatore, On Wed, 01 May 2019 at 13:37:12 +0200, Salvatore Bonaccorso wrote: > On Wed, May 01, 2019 at 01:27:26PM +0200, Guilhem Moulin wrote: >> +signing-party (2.5-1+deb9u1) stretch; urgency=medium >> + >> + * Backport security fix for CVE-2018-15599: unsafe shell call enabling >> shell >

Bug#904976: Patch for gtk3

2019-05-01 Thread Jörg Sommer
Hello, I'm having an HiRes display and Gtk2 doesn't perform very well with HiRes. Here's a patch to build the package with Gtk3. Regards Jörg #NieWiederCDU – Wir müssen die Zukunft gestalten, statt Überholtes erhalten -- Nutze die Talente, die du hast. Die Wälder wären sehr still, wenn nur di

Bug#928264: [gnome-maps] Gnome Maps crashes as soon as you search for a city.

2019-05-01 Thread Bernhard Übelacker
Control: reassign 928264 libgeocode-glib0 3.20.1-2 Control: tags 928264 + upstream fixed-upstream patch Control: affects 928264 gnome-maps Control: fixed 928264 libgeocode-glib0/3.26.1-1 Dear Maintainer, I just tried to reproduce and hit the segfault below [3]. This seems to be reported in bugs [

Bug#928294: unblock: suricata/4.1.4-1

2019-05-01 Thread Pierre Chifflier
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Although it is an upstream release, please unblock suricata 4.1.4-1 for buster. Suricata is an Intrusion Detection System (IDS), which makes it exposed to malicious traffic by design. The up

Bug#925986: jruby: diff for NMU version 9.1.17.0-2.1

2019-05-01 Thread Salvatore Bonaccorso
Control: tags 925986 + patch Control: tags 925986 + pending Dear maintainer, I've prepared an NMU for jruby (versioned as 9.1.17.0-2.1) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. The reason for this NMU although there are more open unfixed CVEs is tha

Bug#919978: diaspora-installer package fails to install

2019-05-01 Thread Pirate Praveen
On Tue, 30 Apr 2019 23:20:41 +0200 Andreas Beckmann wrote: > that error seems to be unrelated to the bundler version used: This seems unrelated to diaspora-installer then. As I was able to reproduce it with bundler 2.0 and after changing to bundler 1.17.3 it worked. So it seems a fresh installat

Bug#912137: Acer C740 hanging with kernel 4.18.0-0.bpo.1-amd64 from Stretch backports

2019-05-01 Thread Juha Heinanen
I installed 4.19.28-2~bpo9+1 and haven't encountered any hangs with it.

Bug#782001: access granted to /home files of another user

2019-05-01 Thread Ansgar
On Sat, 2019-03-02 at 13:20 +0100, Yves-Alexis Perez wrote: > On Sat, 2019-03-02 at 08:15 +0100, Ansgar wrote: > > I think this problem (having $HOME world-readable by default) should > > really be fixed... In installations sharing $HOME between multiple > > users this means private data of all so

Bug#919161: [Debichem-devel] Bug#927955: Bug#927955: Bug#927955: python-rdkit: missing module pyAvalonTools

2019-05-01 Thread Andrius Merkys
Control: tags 919161 + pending Hi Alex, On 2019-04-30 17:01, Alex Mestiashvili wrote: > may be you also can have a look on #919161. I use python3 bindings for > work and see no reason why the merge request shouldn't be integrated. I have accepted your MR, will upload once it finishes building.

Bug#925496: Fix available upstream

2019-05-01 Thread Mike Crowe
Control: tags -1 + fixed-upstream The workaround is included in upstream v4.19.35 onwards: b787544dc5e707fec86161b881391eb9342806e6. Mike.

Bug#928295: unblock: pythonmagick/0.9.19-3

2019-05-01 Thread Jochen Sprickerhof
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package pythonmagick pythonmagick was patched to compile with ImageMagick 7 in 0.9.19-1 whereas buster is still on 6. This resulted the package failing to import, see #928103

Bug#927687: ITP: golang-gopkg-src-d-go-git.v4 -- highly extensible Git implementation in pure Go

2019-05-01 Thread Jongmin Kim
Control: block -1 by 926172 927675 -- Jongmin Kim OpenPGP key located at https://jongmin.dev/pgp OpenPGP fingerprint: 012E 4A06 79E1 4EFC DAAE 9472 D39D 8D29 BAF3 6DF8 signature.asc Description: PGP signature

Bug#928296: RFS: ghostwriter/1.8.0-1 [ITP]

2019-05-01 Thread Sebastien CHAVAUX
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "ghostwriter" * Package name: ghostwriter Section : editors It builds those binary packages: ghostwriter - Distraction-free, themeable Markdown editor To acces

Bug#925496: Fix available upstream

2019-05-01 Thread Ben Hutchings
Control: tag -1 pending On Wed, 2019-05-01 at 14:04 +0100, Mike Crowe wrote: > Control: tags -1 + fixed-upstream > > The workaround is included in upstream v4.19.35 onwards: > b787544dc5e707fec86161b881391eb9342806e6. This will be in the next update, as we've already rebased on 4.19.37. Ben. -

Bug#927694: ITP: golang-gopkg-src-d-go-git-fixtures.v3 -- several git fixtures to run go-git tests

2019-05-01 Thread Jongmin Kim
Control: block -1 by 924280 927687 -- Jongmin Kim OpenPGP key located at https://jongmin.dev/pgp OpenPGP fingerprint: 012E 4A06 79E1 4EFC DAAE 9472 D39D 8D29 BAF3 6DF8 signature.asc Description: PGP signature

Bug#928297: xserver-xorg-core: miss dependency in libgl1-mesa-glx -> effectively depends on libgl1-mesa-dri

2019-05-01 Thread Jonas Smedegaard
Package: xserver-xorg-core Version: 2:1.19.3-2 Severity: important -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 xserver-xorg-core 2:1.19.3-2 has Depends: libgl1-mesa-glx | libgl xserver-xorg-core 2:1.19.4-1 has Depends: libgl That change makes it impossible to install Xorg without DRI module

Bug#928298: LUKS1 encrypting does not work

2019-05-01 Thread Paul van der Vlis
Package: zulucrypt-gui Version: 5.4.0-3 When I try to encrypt an USB-stick with the default-settings it gives an error and it does not work. First when I choose "LUKS2" it works. Using LUKS1 is the default in Zulucrypt-gui. ( When I insert an not-encrypted USB-stick Zulucrypt-gui does not see it.

Bug#928295: unblock: pythonmagick/0.9.19-3

2019-05-01 Thread Paul Gevers
Control: tags -1 moreinfo confirmed On 01-05-2019 15:06, Jochen Sprickerhof wrote: > pythonmagick was patched to compile with ImageMagick 7 in 0.9.19-1 > whereas buster is still on 6. This resulted the package failing to > import, see #928103 (missed to close this in the changelog). > I disabled t

Bug#925314: unblock: wordpress/5.0.3+dfsg1-1

2019-05-01 Thread Paul Gevers
Control: tags -1 - moreinfo On Mon, 8 Apr 2019 17:25:24 +0200 Ivo De Decker wrote: > Remove the moreinfo tag from this bug once the upload is in t-p-u. Somehow forgotten as the upload happened on 2019-04-18. Paul signature.asc Description: OpenPGP digital signature

Bug#928297: xserver-xorg-core: miss dependency in libgl1-mesa-glx -> effectively depends on libgl1-mesa-dri

2019-05-01 Thread Jonas Smedegaard
Quoting Jonas Smedegaard (2019-05-01 15:25:16) > xserver-xorg-core 2:1.19.3-2 has Depends: libgl1-mesa-glx | libgl > > xserver-xorg-core 2:1.19.4-1 has Depends: libgl > > That change makes it impossible to install Xorg without DRI modules. > > In Debian stretch/amd64, a core X11 environment requ

Bug#925350: unblock: ubuntu-keyring/2018.09.18.1-5

2019-05-01 Thread Paul Gevers
Hi Hideki, Kind ping. Do you have any intent to follow up on your request for the unblock of ubuntu-keyring? Please respond on my remarks. Paul On 06-04-2019 21:24, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Hideki, > > On Sat, 23 Mar 2019 23:36:50 +0900 Hideki Yamane wrote: > >>

Bug#925936: release.debian.org: Would v4l-utils 1.16.5 match unblocking criteria?

2019-05-01 Thread Paul Gevers
Control: tags -1 - moreinfo On Sun, 14 Apr 2019 20:30:00 + Niels Thykier wrote: > Please go ahead with this patch and remove the moreinfo tag once it has > been fixed. The upload happened (two of them), the removal of the moreinfo tag was missing. Paul signature.asc Description: OpenPGP

Bug#927687: RFS: golang-gopkg-src-d-go-git.v4

2019-05-01 Thread Jongmin Kim
Dear Go team, I'm looking for a sponsor for the package "golang-gopkg-src-d-go-git.v4" (#927687). This package is a prerequisite for some upcoming packages: * golang-gopkg-src-d-go-git-fixtures.v3 (#927694) * lazygit (#908894) * gopasspw (#901133) This package needs some requisites not a

Bug#926556: unblock: yubikey-personalization/1.19.3-3

2019-05-01 Thread Paul Gevers
Hi Nicoo, Ping. On Sun, 14 Apr 2019 06:27:00 + Niels Thykier wrote: > I cannot see these changes in unstable, so we cannot unblock them (nor > do I see them NEW). Please upload this and remove the moreinfo tag once > it is in unstable and ready for unblocking. I noticed in the other bug yo

Bug#927687: RFS: golang-gopkg-src-d-go-git.v4

2019-05-01 Thread Jongmin Kim
On Wed, May 01, 2019 at 10:50:01PM +0900, Jongmin Kim wrote: > Dear Go team, > > I'm looking for a sponsor for the package "golang-gopkg-src-d-go-git.v4" > (#927687). > > This package is a prerequisite for some upcoming packages: > * golang-gopkg-src-d-go-git-fixtures.v3 (#927694) > * lazygi

Bug#928299: installation-reports: network-console doesnt set password hash, ssh not possible

2019-05-01 Thread Marc Haber
Package: installation-reports Severity: important Tags: d-i Dear Maintainer, at least today's daily installer snapshot has a totally broken network-console. It asks for a password and confirmation and then prompts to continue isntallation with ssh installer@. However, no password hash is written

Bug#927867: RM: elilo-installer -- ROM; elilo is no longer in the archive

2019-05-01 Thread John Paul Adrian Glaubitz
Hello! On 4/24/19 12:46 PM, John Paul Adrian Glaubitz wrote: > elilo-installer can be removed from the archive as the bootloader it > installs, elilo, has been removed from the archive almost five > years ago [1]. > > There is no concern of breakage as all architectures which used elilo > in the

Bug#928274: python-openopt: Here is a script to test all of the examples

2019-05-01 Thread Yaroslav Halchenko
Dear Kingsley, I am afraid that openopt is no longer developed upstream... openopt.org is not reachable, I see some clones laying around, e.g. https://github.com/troyshu/openopt pointing to archives of the elderly docs. CCing the last known for upstream email address. Dmitrey -- could you update

Bug#928301: python3-psycopg2: new upstream available

2019-05-01 Thread Karsten Hilbert
Package: python3-psycopg2 Version: 2.7.7-1 Severity: wishlist Tags: upstream Dear maintainers, there is a new upstream version available. May I kindly ask for packaging as time permits ? Thanks, Karsten -- System Information: Debian Release: buster/sid APT prefers testing APT policy: (990

Bug#928300: shim-signed: secure boot via removable media path unavailable

2019-05-01 Thread Christian Bachmaier
Package: shim-signed Severity: normal Dear Maintainer, on my up to date buster system I have installed shim-signed and grub-efi- amd64-singed and their dependencies as described on https://wiki.debian.org/SecureBoot/Testing. However, booting with secure boot option on (in firmware) is not possib

Bug#928302: please provide virt-manager.mo for en instead of en_GB

2019-05-01 Thread Marc Haber
Package: virt-manager Version: 1:2.0.0-3 Severity: normal Hi, virt-manager's English language file is delivered as en_GB. which causes a system with configured LANGUAGE=en_US:de to speak German. Moving the file to en from en_GB causes it to be used for en_US as well. Since it doesn't make much s

Bug#928153: Bug#852963: Cross reference to RM

2019-05-01 Thread Alex Morega
On 30.04.2019 00:34, Geert Stappers wrote: > On Mon, Apr 29, 2019 at 01:53:14PM +0300, Alex Morega wrote: >> On 29.04.2019 03:16, Geert Stappers wrote: >>> >>> In https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=928153 >>> is requested to remove git-sh from the Debian archive >>> >> Are you usi

Bug#928303: ITP: lightdm-settings -- LightDM Settings Configuration Tool

2019-05-01 Thread Simon Quigley
Package: wnpp Severity: wishlist Owner: tsimo...@debian.org * Package name: lightdm-settings Version : 1.2.5 Upstream Author : Linux Mint * URL : https://github.com/linuxmint/lightdm-settings * License : GPL-3 Programming Lang: Python Description : Light

Bug#922097: Fwd: Bug#922097: inkscape stops with message complaining about an internal illegal instruction on start

2019-05-01 Thread Bernhard Übelacker
Looping in BTS again. Weitergeleitete Nachricht Betreff: Re: Bug#922097: inkscape stops with message complaining about an internal illegal instruction on start Datum: Wed, 1 May 2019 16:14:36 +0100 Von: André Esteves An: Bernhard Übelacker I have installed inkscape/experiment

Bug#928304: groonga-httpd: Privilege escalation due to insecure use of logrotate

2019-05-01 Thread Wolfgang Hotwagner
Package: groonga-httpd Version: 6.1.5-1 Severity: critical Tags: security Justification: root security hole Dear Maintainer, The path of the logdirectory of groonga-httpd can be manipulated by user groonga: ls -l /var/log/groonga total 8 -rw-r--r-- 1 rootroot1296 Apr 25 18:44 groonga.log

Bug#927270: proftpd-basic: jessie-security (1.3.5e) breaks directive with AuthAliasOnly

2019-05-01 Thread Markus Koschany
Control: tags -1 confirmed Thanks for the report. I can confirm this issue is still present in 1.3.6-4. I have reverted to version 1.3.5 in Jessie again, so this problem should not occur in Jessie anymore. Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#928115: zdbsp FTCBFS: confuses build vs. host

2019-05-01 Thread Jonathan Dowland
Thanks for the report, and the patch. It looks good to me, but as we are in hard freeze for Buster and this (sadly) would not qualify for a freeze exception, I'm going to wait before applying it or uploading a fixed package to sid. Best wishes

Bug#928305: mhc: lack of Japan's new era 令和 (Reiwa) and new holidays

2019-05-01 Thread Tatsuya Kinoshita
Package: mhc Version: 1.2.1-1 Severity: important Please support Japan's new era 令和 (Reiwa) and new holidays. Japan's new era 令和 (Reiwa) started on 2019/5/1. However this package doesn't support it in the function mhc-calendar/inserter-nengo(). Also, new holidays, such as emperor's birthday (23

Bug#928305: mhc: lack of Japan's new era 令和 (Reiwa) and new holidays

2019-05-01 Thread Tatsuya Kinoshita
Control: forwarded -1 https://github.com/yoshinari-nomura/mhc/pull/49 Control: forwarded -1 https://github.com/yoshinari-nomura/mhc/pull/50 Thanks, -- Tatsuya Kinoshita

Bug#928224: Valgrind is broken on armhf

2019-05-01 Thread Bernhard Übelacker
Hello Benjamin Wozniak, I just wanted to help triaging this issue. For this I started a qemu vexpress-a15 emulation with current Buster armhf installed. Unfortunately I could not reproduce this valgrind error. Some more details about my test in attached file. So maybe the valgrind maintainer wil

Bug#928297: xserver-xorg-core: transitively depends on libgl1-mesa-dri

2019-05-01 Thread Simon McVittie
Control: retitle -1 xserver-xorg-core: transitively depends on libgl1-mesa-dri On Wed, 01 May 2019 at 15:42:23 +0200, Jonas Smedegaard wrote: > Quoting Jonas Smedegaard (2019-05-01 15:25:16) > > xserver-xorg-core 2:1.19.3-2 has Depends: libgl1-mesa-glx | libgl > > > > xserver-xorg-core 2:1.19.4-1

Bug#922097: inkscape stops with message complaining about an internal illegal instruction on start

2019-05-01 Thread Bernhard Übelacker
Hello André Isidoro Fernandes Esteves, > I have installed inkscape/experimental,now 1.0~alpha-1 amd64 with no > problems whatsoever. > So now i can't test the bug. Sorry :( Glad to hear it is working. Just to clarify: I guess that on your system the file "/usr/lib/x86_64-linux-gnu/libgtkmm-2.4.s

Bug#927329: Update Arduino from 1.8.2 to 1.8.9

2019-05-01 Thread Rock Storm
Hi all, @Kashif, thanks for volunteering, please let us know if you succeed on packaging it from scratch. IIRC on our last attempt we got stuck packaging some of the java dependencies such as 'mrbean', some info on this bug report [1]. Project is now hosted on Salsa [2]. [1]: https://bugs.debian.

Bug#928306: unblock: liblivemedia/2018.11.26-1.1

2019-05-01 Thread Hugo Lefeuvre
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package liblivemedia Dear Release team, liblivemedia 2018.11.26-1 from Buster is affected by CVE-2019-9215[1] and CVE-2019-7314[2], two security issues in the server part of

Bug#914999: [libc6] Locking problems into libc6

2019-05-01 Thread Roman Savochenko
12.12.18 17:11, Roman Savochenko wrote: There are thousands of packages in different versions between Debian 8 and Debian 9. You have found it's not related to the kernel, but I fail to see how that shows it's a libc6 issue. For example when you have tried the kernel from Debian 9 in Debian 8,

Bug#927329: Update Arduino from 1.8.2 to 1.8.9

2019-05-01 Thread Kashif Shah
@Rock Thanks for the update. My earlier attempt was with packaging the binaries, which is a no-no, I take it? I made an attempt from scratch last night, actually, after looking at the previous patches. I’ll continue with it, but it will be slow going as I am not a Java dev by trade. On Wed, May 1,

Bug#642401: [xmonad] lockup when starting gvim in terminal

2019-05-01 Thread Antoni Villalonga
Hi, I can't reproduce the bug in next stable release. I've also tested installing 1:7.1.314-3+lenny2 version on a debootstrap. More details on how to reproduce the "confirmed" bug would be great. Probably Squeeze fixed the bug. I've also tested 7.2 (Squeeze) and 7.4 (Jessie) versions without prob

Bug#928103: closing 928103

2019-05-01 Thread Jochen Sprickerhof
Hi eamanu, * eamanu [2019-05-01 14:03]: The package is still fail on testing: Should be fixed in -4, thanks for the ping. Cheers Jochen signature.asc Description: PGP signature

Bug#928307: wide-dhcpv6-client: default route not set

2019-05-01 Thread Erich Eckner
Package: wide-dhcpv6-client Version: 20080615-19 Severity: normal Tags: ipv6 Dear Maintainer, currently, my wide-dhcpv6-client successfully gets one ipv6 address and two delegation prefixes from my upstream isp, but it does not set a default route to the next hop, rendering ipv6 to and from the

Bug#927329: Update Arduino from 1.8.2 to 1.8.9

2019-05-01 Thread Rock Storm
On Wed, May 01, 2019 at 01:07:39PM -0500, Kashif Shah wrote: > @Rock Thanks for the update. My earlier attempt was with packaging the > binaries, which is a no-no, I take it? Absolutely, whatever is distributed must be built from source. I tried to reason why on this bug [1]. [1]: https://bugs.de

Bug#926547: insserv: tests/run-tests are not used

2019-05-01 Thread Jesse Smith
On 5/1/19 7:42 AM, Dmitry Bogatov wrote: > [2019-04-28 21:05] Jesse Smith >> I have been looking into the issues with the insserv test scripts. There >> are a few problems here, in brief: >> [...] >> >> In other words, I think there is some difference in expectations between >> what I think insser

Bug#928254: gcc-8: -static-libasan does not work with GNU MPFR

2019-05-01 Thread Matthias Klose
On 30.04.19 19:05, Vincent Lefevre wrote: > Package: gcc-8 > Version: 8.3.0-7 > Severity: minor > > When I build and check GNU MPFR with: > > ./configure CFLAGS="-fsanitize=address -static-libasan" > make > make check > > I get lots of failure with the error: > > Your application is lin

Bug#928308: integrit segfault at 804e48c ip 0804e48c sp bfe178dc error 14

2019-05-01 Thread Tomaz Solc
Package: integrit Version: 4.1-1.1+b1 Severity: normal Dear Maintainer, I've had integrit crash several times with a segmentation fault: $ integrit -C /etc/integrit/integrit.conf -cu Segmentation fault dmesg has: integrit[17557]: segfault at 804e48c ip 0804e48c sp bfb32fbc error 14 Unfortunat

Bug#928295: unblock: pythonmagick/0.9.19-3

2019-05-01 Thread Jochen Sprickerhof
Control: tag -1 - moreinfo * Paul Gevers [2019-05-01 15:29]: pythonmagick was patched to compile with ImageMagick 7 in 0.9.19-1 whereas buster is still on 6. This resulted the package failing to import, see #928103 (missed to close this in the changelog). I disabled the autopkgtest as it was fa

Bug#928309: ITP: android-file-transfer -- reliable MTP client with minimalistic UI

2019-05-01 Thread Dylan Aïssi
Package: wnpp Owner: Dylan Aïssi Severity: wishlist Package name: android-file-transfer Upstream Author : Vladimir Menshakov URL: https://github.com/whoozle/android-file-transfer-linux License: LGPL-2.1+ Description: reliable MTP client with minimalistic UI Android-File-Transfer is a reliable MT

Bug#928310: unblock: wpa/2:2.7+git20190128+0c1e29f-5

2019-05-01 Thread Salvatore Bonaccorso
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hi release team, [Not the maintainer here] Please unblock package wpa. The followup update to unstable for wpa 2:2.7+git20190128+0c1e29f-5 fixes one additional security issue ("EAP-pwd mes

Bug#928310: unblock: wpa/2:2.7+git20190128+0c1e29f-5

2019-05-01 Thread Paul Gevers
Control: tags -1 d-i moreinfo confirmed On 01-05-2019 22:08, Salvatore Bonaccorso wrote: > Please unblock package wpa. The followup update to unstable for wpa > 2:2.7+git20190128+0c1e29f-5 fixes one additional security issue > ("EAP-pwd message reassembly issue with unexpected fragment"). It got >

Bug#928310: unblock: wpa/2:2.7+git20190128+0c1e29f-5

2019-05-01 Thread Salvatore Bonaccorso
Hi Attached the debdiff between 2:2.7+git20190128+0c1e29f-4 and 2:2.7+git20190128+0c1e29f-5. Regards, Salvatore diff -Nru wpa-2.7+git20190128+0c1e29f/debian/changelog wpa-2.7+git20190128+0c1e29f/debian/changelog --- wpa-2.7+git20190128+0c1e29f/debian/changelog2019-04-10 19:00:22.000

Bug#928240: etw: Segmentation fault at start

2019-05-01 Thread Markus Koschany
Thank you very much. I have uploaded a new revision with your patch a few minutes ago. The game itself appears to work, the settings menu for the controls is a bit hidden. ETW was originally developed for the AMIGA, so that may explain some of the oddities. Regards, Markus signature.asc Descri

Bug#927825: arm: mvneta driver used on Armada XP GP boards does not receive packets (regression from 4.9)

2019-05-01 Thread Aurelien Jarno
Hi, On 2019-05-01 00:04, Aurelien Jarno wrote: > On 2019-04-30 10:12, Uwe Kleine-König wrote: > > > > More precisely the board is a "Marvell Armada XP Development Board > > > > DB-MV784MP-GP" > > > > > > > > > anymore. Using tcpdump on both the buildd and a remote host, it > > > > > appears > >

Bug#928311: geany-plugin-spellcheck : Depends: geany-abi-18176 but it is not installable

2019-05-01 Thread Aario
Package: geany-plugin-spellcheck Version: 1.33+dfsg-1+b1 Severity: grave Tags: a11y Justification: renders package unusable Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? * What exactly did you do (or not do)

Bug#928281: unblock: lemonldap-ng/2.0.2+ds-7 (pre-approval)

2019-05-01 Thread Niels Thykier
Control: tags -1 moreinfo confirmed Xavier Guimard: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > > Please unblock package lemonldap-ng > > Hi all, > > upstream authors of lemonldap-ng have updated language translations. I

Bug#928312: ITP: osdlyrics -- Show synchronized lyrics with various media players

2019-05-01 Thread Boyuan Yang
Package: wnpp Severity: wishlist Owner: Boyuan Yang * Package name: osdlyrics Version : 0.5.5~rc1 Upstream Author : Tiger Soldier * URL : https://github.com/osdlyrics/osdlyrics * License : GPL-3+ Programming Lang: Python/C Description : Show synchroniz

Bug#927270: proftpd-basic: jessie-security (1.3.5e) breaks directive with AuthAliasOnly

2019-05-01 Thread Hilmar Preuße
On 17.04.19 07:52, Tatsuki Sugiura wrote: Hi Tatsuki, > proftpd-basic package has been updated to 1.3.5e on jessie-security. > It breaks directive in some case. > > In my case, User is not affetcted in if AuthAliasOnly is on. > > This problem is caused on 1.3.5e-0+deb8u1 (jessie-security) and

Bug#926903: Installation-report addition

2019-05-01 Thread Tom Thekathyil
Hi Ben, Thanks for trying to help. You will note from my original report as well as the follow-up on 28 April that I had installed the 'firmware-amd-graphics' package and still get the error message. # apt search firmware-amd-graphics > firmware-amd-graphics/testing, now 201901 14-1 all [install

Bug#924934: connman: add a connmant-tests package

2019-05-01 Thread Alf Gaida
Hi Ritesh, no problem, will do so. Would you be so kind and review and sponsor it for NEW? Thanks, Alf

Bug#927270: proftpd-basic: breaks directive with AuthAliasOnly

2019-05-01 Thread Hilmar Preuße
On 01.05.19 23:26, Hilmar Preuße wrote: > On 17.04.19 07:52, Tatsuki Sugiura wrote: Hi Tatsuki, >> I think this is related with follwing upstream bug; >> >> * http://bugs.proftpd.org/show_bug.cgi?id=4314 >> * https://github.com/proftpd/proftpd/pull/567 >> * https://github.com/proftpd/proftpd/p

Bug#928313: apt-key check for revoked keys

2019-05-01 Thread Kurt Roeckx
Package: apt Version: 1.8.0 I have this in my apt keyring: /etc/apt/trusted.gpg pub rsa4096 2015-06-11 [SC] C35E B17E 1EAE 708E 6603 A9B3 AD05 92FE 47F0 DF61 uid [ unknown] matrix.org (Debian signing key) sub rsa4096 2015-06-11 [E] But I know that that k

Bug#928314: wakeonlan requires netdata as dependency

2019-05-01 Thread sch0rsch
Package: wakeonlan The wakeonlan binary (all versions of all Debian branches) depends on the netdata package. Without netdata, the following error shows up: -- root@VM-Buster:~# wakeonlan XX:XX:XX:XX:XX:XX Use of uninitialized value $proto in socket at /usr/bin/wakeonlan line 121. Use

  1   2   >