Bug#983456: firmware-sof-signed: Firmware files are in wrong directory

2021-02-25 Thread Vincent Bernat
❦ 25 février 2021 08:38 +01, Patrick J.: >> By any chance, maybe you did install the firmwares manually in the past, >> so you already had a intel/sof-tplg directory which then was not >> replaced by the symlink? > > Yes, indeed. I tried some manual approaches in the past before the > firmware-so

Bug#983501: Package available on Salsa

2021-02-25 Thread Adam Cécile
Package is available @Salsa: https://salsa.debian.org/python-team/packages/python-asyncache

Bug#983502: firefox-esr: depends on wrong libnss3 version, TLS hangs with 2:3.58-1

2021-02-25 Thread Adam M. Costello
Package: firefox-esr Version: 78.7.0esr-1 Severity: important Dear Maintainer, firefox-esr (both the latest version 78.8.0esr-1 and the latest testing version 78.7.0esr-1) depends on libnss3 (>= 2:3.53.1~), but that is not sufficient. https fails completely with libnss3 2:3.58-1. It works with 2

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-25 Thread Markus Koschany
Hello security team, hello Hugo, I hope you are doing well! I have just uploaded a NMU for xcftools fixing CVE-2019-5086 and CVE-2019-5087. The new patch also addresses the 32 bit portability issues. The basic idea behind it is to limit possible values of width and height (which can only be posit

Bug#983504: firefox-esr: depends on wrong libnss3 version, TLS hangs with 2:3.58-1

2021-02-25 Thread Adam M. Costello
Package: firefox-esr Version: 78.7.0esr-1 Severity: important Dear Maintainer, firefox-esr (both the latest version 78.8.0esr-1 and the latest testing version 78.7.0esr-1) depends on libnss3 (>= 2:3.53.1~), but that is not sufficient. https fails completely with libnss3 2:3.58-1. It works with 2

Bug#983439: allow to build the package without udebs

2021-02-25 Thread Andrei POPESCU
Control: reassign -1 src:libdebian-installer 0.120 On Mi, 24 feb 21, 07:32:11, Matthias Klose wrote: > Package: src: libdebian-installer > Version: 0.120 > Tags: patch > > allow to build the package without udebs. > > patch at > http://launchpadlibrarian.net/524724757/libdebian-installer_0.120ub

Bug#895201: trousers still uninstallable

2021-02-25 Thread Florian Lohoff
After this bug is open for nearly 3 years trousers is still uninstallable on certain systems with bullseye. Even with no tpm installed trousers is needed for tpm emulation in qemu. This is a current Lenovo Thinkpad T14s with TPM enabled. flo@p5:~$ ls -la /dev/tpm* crw-rw 1 tss tss 10, 2

Bug#977990: os-autoinst: FTBFS on i386: 3/3 Test #3: test-perl-testsuite ..............***Failed 332.81 sec

2021-02-25 Thread Paul Gevers
Control: found -1 4.5.1527308405.8b586d5-4.2 Hi Frédéric, Hideki, On 17-02-2021 22:01, Paul Gevers wrote: > If the forth time worked because of sheer luck, then please no, keep the > bug open until the build is less flaky. We need packages to be build > without failure [1]. Having to baby-sit fla

Bug#983488: O: lftp -- needs new maintainer

2021-02-25 Thread Noël Köthe
Good morning Stefan, Am Donnerstag, dem 25.02.2021 um 01:14 +0100 schrieb Stefan Schindler: > Package: lftp > Version: 4.9.2; reported 2020-02-25 > Severity: important > > The upstream has released multiple packages since 2018 when the last > debian package was fetched. > * https://github.com/lav

Bug#983499: unblock: python3-defaults/3.9.2~rc1-1, python3.9/3.9.2~rc1-1

2021-02-25 Thread Paul Gevers
Control: tags -1 moreinfo Hi Stefano, On 25-02-2021 07:17, Stefano Rivera wrote: > TL;DR: Debian heard of some upstream Python grumpyness about our > standard library splits, recently. We have more upstreams being grumpy how we handle things in Debian. > This is all very badly timed for the > f

Bug#895201: trousers uninstallable / postinst relaxing / fixes

2021-02-25 Thread Florian Lohoff
Hi, As a simple fix - Not beeing able to start trousers should not fail the installation - So the first fix should be to change the invoke-rc.d in postinst to this: invoke-rc.d trousers $_dh_action || exit 0 Then for all checks whether there is a tpm device one could use something like

Bug#945317: xcftools NMU for CVE-2019-5086 and CVE-2019-5087

2021-02-25 Thread Salvatore Bonaccorso
Hi Markus, On Thu, Feb 25, 2021 at 09:11:47AM +0100, Markus Koschany wrote: > Hello security team, hello Hugo, I hope you are doing well! > > I have just uploaded a NMU for xcftools fixing CVE-2019-5086 and > CVE-2019-5087. > The new patch also addresses the 32 bit portability issues. The basic

Bug#983432: debci: sudo is prohibited by user debci

2021-02-25 Thread Simon McVittie
Control: reassign -1 autopkgtest Control: forcemerge 906424 -1 On Wed, 24 Feb 2021 at 09:19:05 -0300, Antonio Terceiro wrote: > On Wed, Feb 24, 2021 at 11:12:30AM +0900, Ryutaroh Matsumoto wrote: > > Autopkg test scripts in some packages assume that > > an ordinary user (e.g. debci) in the testbed

Bug#982987: Call for votes for new CTTE member

2021-02-25 Thread Margarita Manterola
Hi! Sorry I missed voting for this. My email had been broken due to my personal domain being down and I didn't get the emails. Just for the record... > ===BEGIN > > The Technical Committee recommends that Christoph Berg be > appointed by the Debian Project Leader to the Technical Committee. >

Bug#979764: Problem now understood, but potential security problem

2021-02-25 Thread Jürgen Pfennig
Dear Maintainers my bug report contained the neccessary information to understand the whole problem, but it is quite complex. FIXING bullseye NFS4 Kerberos with SAMBA Probably debian uses an outdated version of rpc.gssd , SAMBA behaves 100% correctly and someone removed support for weak rpc.gs

Bug#982892: ITP: binutils-or1k-elf -- GNU binary utilities for the Open RISC 1000 processors

2021-02-25 Thread Nicolas Boulenguez
> > [binutils-or1k-elf] build-depends on gcc-10-source. > Do you mean binutils-source here? Of course. Copy/paste error from the similar ITP bug for gcc-ork1k-elf. > > * Package name: binutils-or1k-elf > I am wondering whether it is a good idea to package this separately from > binutils. Even

Bug#983506: grub2-common: grub-install doesn't install files to /boot/grub/i386-pc

2021-02-25 Thread Vratislav Blazek
Package: grub2-common Version: 2.02+dfsg1-20+deb10u3 Severity: important Dear Maintainer, * We use grub-install while preparing a new system in chrooted environment. * After upgrade from 2.02+dfsg1-20+deb10u2 to 2.02+dfsg1-20+deb10u3, grub-install stopped to install files in /boot/grub

Bug#818432: espresso: FTBFS on armel: hangs during the build

2021-02-25 Thread Paul Gevers
Control: severity -1 serious Hi, On Fri, 27 May 2016 13:59:49 +0200 Andreas Beckmann wrote: > I just had espresso decrufted to remove the outdated armel build, thus > downgrading the severity. Unfortunately there has been a successful build in the mean time and your package now doesn't migrate

Bug#983507: mame FTBFS on armel and mipsel: Cannot allocate memory (armel) / ar failure (mipsel)

2021-02-25 Thread Paul Gevers
Source: mame Version: 0.228+dfsg.1-1 Severity: serious Tags: ftbfs Hi Maintainer, Your last upload of mime FTBFS on armel and mipsel. Paul https://buildd.debian.org/status/package.php?p=mame tail on armel: /usr/bin/ld.gold: fatal error: ../../../../../mame: mmap: failed to allocate 372463976

Bug#983508: nfs-common: Bullseys/Kernel 5.10 SAMBA AD/DC NFSv4 Kerberos Problem with rpc.gssd

2021-02-25 Thread J. Pfennig
Package: nfs-common Version: 1:1.3.4-2.5+deb10u1 Severity: important Tags: upstream Dear Maintainers There is a long standing bug (or wrong documentation) in rpc.gssd Probably debian uses an outdated version (new upstream version). I consider this bug as severe because it breaks backward compa-

Bug#940533: qemu-user-static: MasterCard in /proc/self/stat emulation causes sudo(8) to fail

2021-02-25 Thread Thorsten Glaser
Package: qemu Version: 1:5.2+dfsg-6 Followup-For: Bug #940533 X-Debbugs-Cc: t...@mirbsd.de, Marc Haber This bug is still pertinent. I’ve reproduced it locally right now as: # mount an RPi Debian buster image (pristine Debian/arm64, not Raspian) $ sudo losetup /dev/loop3 ~/tmp/rpi.img $ sudo kpa

Bug#982719: firehol: FTBFS: dh_auto_test: error: make -j1 check VERBOSE=1 returned exit code 2

2021-02-25 Thread Jerome BENOIT
Dear Dennis, thanks for your reply. I was rather wondering if setting Rules-Requires-Root to yes in d/rules will ask to bbuild to act as "needs-root" for autopkgtest. Jerome

Bug#940533: qemu-user-static: MasterCard in /proc/self/stat emulation causes sudo(8) to fail

2021-02-25 Thread Thorsten Glaser
Marc Haber dixit: >> whereas sudo reads the >> tty from it, making it fail in chroots using qemu-user-static. > >How exactly does sudo fail? Is this worth reporting upstream? Basically sudo does not ask for the password because it cannot find its tty. I’ve mailed to the bugreport with you in X-De

Bug#983509: ITP: python-svgelements -- high fidelity SVG parsing and geometric rendering Python library

2021-02-25 Thread Romain Porte
Package: wnpp Severity: wishlist Owner: Romain Porte X-Debbugs-Cc: debian-de...@lists.debian.org, deb...@microjoe.org * Package name: python-svgelements Version : 1.4.3 Upstream Author : tatarize * URL : https://github.com/meerk40t/svgelements * License : Expa

Bug#983372: Correction of Bug-Report

2021-02-25 Thread user2304
I unfortunately pasted the wrong link to the redhat forum for further description of the bug. The correct one: https://bugzilla.redhat.com/show_bug.cgi?id=1925346 Kind regards, user2304 -- mail: user2...@web.de

Bug#972936: libgcc-s1 needs Breaks: libgcc1 (<< 1:10)

2021-02-25 Thread Graham Inggs
Hi On Mon, 15 Feb 2021 at 10:07, Matthias Klose wrote: > On 2/14/21 5:58 PM, Simon McVittie wrote: >> Obviously, the transitional packages would ideally be built by src:gcc-10 >> rather than being a separate source package, and Ryan only prototyped them >> as a separate source package to be able

Bug#898177: [related feature respect /etc/mailname] Re: please add MAILFROM to cron

2021-02-25 Thread Tomas Pospisek
Javier, seeing that you do not seem to have been working on cron for a few years would it be OK with you if I posted something along these lines to debian-devel: Request for adoption/request for help: cron cron's recently active maintainer has removed himself from its uploaders.

Bug#981485: request to test the upstream release

2021-02-25 Thread Sudip Mukherjee
Hi, There is a change merged in upstream which should fix this issue. Details at: https://github.com/OfflineIMAP/offlineimap3/pull/56 It will be great if you can test the latest HEAD from github and confirm if it fixes the issue. I can give you a deb package if that is easier. But in any case, I t

Bug#983511: cdebootstrap: autopkgtest needs update for new version of debian-archive-keyring:

2021-02-25 Thread Paul Gevers
Source: cdebootstrap Version: 0.7.7 Severity: serious Tags: sid bullseye User: debian...@lists.debian.org Usertags: needs-update Control: affects -1 src:debian-archive-keyring [X-Debbugs-CC: debian...@lists.debian.org, debian-archive-keyr...@packages.debian.org] Dear maintainer(s), With a recent

Bug#983087: sbuild-createchroot misses usr/libexec/qemu-binfmt/ directory

2021-02-25 Thread Christoph Biedl
Roger Leigh wrote... > I was having a think about this last night. To be completely > realistic, schroot maintenance is very low on my list of my > priorities. Work on it is sporadic at best. My interest in it is > also fairly low. I’ve moved on to other things. That's sad to hear. > I don’t

Bug#900874: O: schroot -- Execute commands in a chroot environment

2021-02-25 Thread Christoph Biedl
Control: retitle 900874 ITA: schroot -- Execute commands in a chroot Raphaël Hertzog wrote... > I just orphaned the schroot package. I never really want to assume its > maintainance but it just happened that at some point I was unhappy with > unresolved bugs with pending patches and someone had t

Bug#983512: debuerreotype: autopkgtest needs update for new version of debian-archive-keyring: Release signed by unknown key (key id 7638D0442B90D010)

2021-02-25 Thread Paul Gevers
Source: debuerreotype Version: 0.10-1 Severity: serious Tags: sid bullseye User: debian...@lists.debian.org Usertags: needs-update Control: affects -1 src:debian-archive-keyring [X-Debbugs-CC: debian...@lists.debian.org, debian-archive-keyr...@packages.debian.org] Dear maintainer(s), With a rece

Bug#983513: debuerreotype: autopkgtest seems to hard-code amd64 signature

2021-02-25 Thread Paul Gevers
Source: debuerreotype Version: 0.10-1 Severity: serious X-Debbugs-CC: debian...@lists.debian.org User: debian...@lists.debian.org Usertags: fails-always Dear maintainer(s), Your package has an autopkgtest, great. However, it always fails on non-amd64 architectures. Looking at the error message, i

Bug#983514: cockpit-ws: cockpit tries to write in /etc

2021-02-25 Thread Nicolas George
Package: cockpit-ws Version: 238-1 Severity: normal Dear Maintainer, When trying for a read-only root filesystem, I am blocked by the fact that cockpit tries to write in /etc at startup: Feb 03 17:12:09 kruppe systemd[1]: Starting Cockpit Web Service... Feb 03 17:12:09 kruppe remotectl[693]: rem

Bug#983515: paperwork: autopkgtest armhf regression: Libinsane item->get_options() error: 0x40000006, I/O Error (7)

2021-02-25 Thread Paul Gevers
Source: paperwork Version: 2.0.2-2 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of paperwork the autopkgtest of paperwork fails in testing when that autopkgtest is run with the binary pack

Bug#720096: marked as pending in rsyslog

2021-02-25 Thread Harald Dunkel
On Mon, 22 Feb 2021 20:00:33 +0100 Michael Biebl wrote: Am 22.02.2021 um 18:57 schrieb Harald Dunkel: > Sorry to say, but this is not a fix. A fix would avoid the race > condition, no matter whats written in the config files. > > Your "fix" is just a workaround. If I add If you have a better

Bug#983516: python2.7: autopkgtest regression on amd64, i386 and ppc64el: test_ctypes fails

2021-02-25 Thread Paul Gevers
Source: python2.7 Version: 2.7.18-2 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of python2.7 the autopkgtest of python2.7 fails in testing when that autopkgtest is run with the binary pac

Bug#983435: Just a wild guess...

2021-02-25 Thread bugsgrid+deb
Hi mainteners, Given the observations, I feel it very likely being caused by misfiring of restore_backup_on_exit(), and looking around the source tree I found something suspicious: In the commit 5dec0f2f9cd4d4dd0109c25cd2b399a780179020, | unix exec: avoid atexit handlers when child exits | Needed

Bug#983299: vtk9: FTBFS with PROJ 8.0.0

2021-02-25 Thread Sebastiaan Couwenberg
On 2/22/21 7:29 AM, Bas Couwenberg wrote: > It needs to be ported to use proj.h instead of proj_api.h which has been > removed. While upstream has added support for proj.h this may not be easy to get into the vtk9 Debian package. Like with vtk6 (#931943) & vtk7 (#931943) you may want to use the

Bug#983505: doas: persist option does not work

2021-02-25 Thread Andrea Pappacoda
Package: doas Version: 6.8.1-2 Severity: important The manpage of doas.conf(5) says that the persist option can be user to make doas not ask for the user's password every time the command is ran. Unfortunately, this option seems to be broken, as it doesn't do anything. Thanks for packaging this

Bug#983517: pytorch: Build documentation

2021-02-25 Thread Gard Spreemann
Source: pytorch Version: 1.7.1-7 Severity: wishlist X-Debbugs-Cc: g...@nonempty.org Dear Maintainer, It would be nice to have a python-torch-doc package with the HTML documentation available, if it's not a complicated process. This is of course not urgent. I can look into the matter after the Bu

Bug#983104: RFS: mupdf/1.14.0+ds1-4+deb10u3 [NMU, CVE-2020-16600] -- lightweight PDF viewer

2021-02-25 Thread Bastian Germann
Am 22.02.21 um 10:15 schrieb Sébastien Delafond: On 19/02 13:53, Bastian Germann wrote: * Package name: mupdf Version : 1.14.0+ds1-4+deb10u3 [...] * Avoid a use-after-free in fz_drop_band_writer (CVE-2020-16600) Hi Bastian, thanks for your work on this. We think this update

Bug#983486: zipl: allow other packages to provide config snippets

2021-02-25 Thread Stefan Haberland
Am 25.02.21 um 08:30 schrieb Christian Borntraeger: > > On 24.02.21 23:40, dann frazier wrote: >> Source: s390-tools >> Version: 2.15.1-2 >> >> I'm one of the maintainers of kdump-tools, which has a need to manipulate >> the kernel command line parameters in boot loader configurations. >> Currently

Bug#983416: Error in javascript library

2021-02-25 Thread Alberto Garcia
On Thu, Feb 25, 2021 at 05:28:54PM +0400, Сергей Дмитриенко wrote: > No. I have an account, but the button "Login" doesn't respond when clicked. > > And the same error in kern.log: > > Feb 25 17:07:44 z61t kernel: [21036.696350] do_trap: 7 callbacks suppressed > Feb 25 17:07:44 z61t kernel: [2103

Bug#983518: allow to build without udeb packages

2021-02-25 Thread Matthias Klose
Package: src:cdebconf Version: 0.256 Tags: patch allow to build without udeb packages. patch at http://launchpadlibrarian.net/525019047/cdebconf_0.256ubuntu2_0.256ubuntu3.diff.gz

Bug#983519: allow to build without udeb packages

2021-02-25 Thread Matthias Klose
Package: src:bind9-libs Version: 1:9.11.19+dfsg-2 Tags: patch allow to build without udeb packages. I didn't figure out how to avoid the extra udeb build for that case. So just produce the non udeb binary packages. patch at http://launchpadlibrarian.net/525016225/bind9-libs_1%3A9.11.19+dfsg-2ubun

Bug#983520: ITP: netproc -- tool to monitor network usage by processes

2021-02-25 Thread Mayco Souza Berghetti
Package: wnpp Severity: wishlist Owner: Mayco Souza Berghetti * Package name: netproc Version : 0.5.5 Upstream Author : Mayco Souza Berghetti * URL : https://github.com/berghetti/netproc/ * License : GPL-3+ Programming Lang: C Description : tool to mon

Bug#981685: request to test the upstream release

2021-02-25 Thread Noah Meyerhans
On Thu, Feb 25, 2021 at 11:50:01AM +, Sudip Mukherjee wrote: > There is a change merged in upstream which should fix this issue. > Details at: https://github.com/OfflineIMAP/offlineimap3/pull/56 > > It will be great if you can test the latest HEAD from github and > confirm if it fixes the issu

Bug#983520: ITP: netproc -- tool to monitor network usage by processes

2021-02-25 Thread Daniel Baumann
Hi Mayco On 2/25/21 3:31 PM, Mayco Souza Berghetti wrote: > I intend on maintaining this package, > looking for a sponsor. I'm using netproc myself and I'm happy to sponsor you. Please contact me off-list by sending me link to your packages to review. Regards, Daniel

Bug#983521: Caja active loop causes high cpu loads randomly

2021-02-25 Thread Francesco P. Lovergine
Source: caja Severity: important Due to smart working increase, I recently installed mate for our users at job, with x2go/vnc servers. Soon, I found that caja randomly starts to cause high cpu loads, and having autodir even installed it also started to log tons of messages like: /var/log/syslo

Bug#976244: RFA: sudo -- Provide limited super user privileges to specific users

2021-02-25 Thread Marc Haber
tags #976244 confirmed pending thanks On Tue, Dec 01, 2020 at 10:40:10PM -0500, Bdale Garbee wrote: > So, I think that after nearly a quarter century taking care of sudo in > Debian, it's time someone else took over the package. A new sudo team has formed and will take over the package. As soon a

Bug#983416: Error in javascript library

2021-02-25 Thread Alberto Garcia
On Thu, Feb 25, 2021 at 06:37:28PM +0400, Сергей Дмитриенко wrote: > *$ JavaScriptCoreUseJIT=0 epiphany*** > > Yes! It work! Ok, that's good to know. > Linux z61t 4.19.0-14-amd64 #1 SMP Debian 4.19.171-2 (2021-01-30) x86_64 > GNU/Linux > > Linux debian 4.19.0-14-686-pae #1 SMP Debian 4.19.171-2

Bug#983522: ...

2021-02-25 Thread Sebastien Bacher
Package: libthai Version: 0.1.28-3 Severity: minor Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu hirsute ubuntu-patch Dear maintainers, In Ubuntu, we are in the process of moving the i386 architecture to a compatibility-only layer on amd64, and therefore we are also movi

Bug#983523: general: some WWW sites no longer work neither in Firefox nor in Chrome

2021-02-25 Thread Janusz S. Bień
Package: general Severity: normal I was angry with my Internet provider because on their site since several weeks the chat was reported as not available. It appeared the chat works all the time in any Windows browser. Today I tried to order some goods by Internet, by I was unable to select the in

Bug#983510: dovecot-core: repeated user enumeration fails with sssd backend (and probably others)

2021-02-25 Thread Heiko Schlittermann (HS12-RIPE)
Package: dovecot-core Version: 2.3.4.1-5+deb10u1 Severity: important Tags: patch upstream Dear Maintainer, the issue can be found on the dovecot mailing list: https://dovecot.org/pipermail/dovecot/2021-February/121478.html When using sssd as nss plugin, fast repeating calls to `doveadm user *`

Bug#983524: live-boot-doc: The spanish translation of live-boot.7 has a typo on the URL

2021-02-25 Thread cheche
Package: live-boot-doc Version: 1:20210208 Severity: normal Dear Maintainer, Reading information about booting using PXE and live cd. Found out that the spanish translation is wrong, The url as example should read as the english version: http://1.2.3.4/ On /usr/share/man/es/man7 --- live-boot.

Bug#983525: Update to 1.1 in experimental

2021-02-25 Thread Sebastien Bacher
Package: libhandy-1 Version: 1.0.3-2 Could you update to 1.1 in experimental? That's required by some GNOME 40~beta updates which we are uploading to experimental

Bug#983486: zipl: allow other packages to provide config snippets

2021-02-25 Thread dann frazier
On Thu, Feb 25, 2021 at 6:21 AM Stefan Haberland wrote: > > Am 25.02.21 um 08:30 schrieb Christian Borntraeger: > > > > On 24.02.21 23:40, dann frazier wrote: > >> Source: s390-tools > >> Version: 2.15.1-2 > >> > >> I'm one of the maintainers of kdump-tools, which has a need to manipulate > >> the

Bug#796399:

2021-02-25 Thread WILLSON MUTANDA
Drogi przyjacielu Przepraszam za niedogodności; Nazywam się Willson J. Mutanda, z Pretorii, osobista pomoc dla (pana Andrew Bretta Marczaka), jak ci wcześniej wyjaśniłem. Pan Andrew jest wykonawcą wydobycia złota i diamentów oraz biznesmenem w Afryce Południowej, który zmarł kilka lat temu. Piszę

Bug#983427: libpam-runtime: please add support for DPKG_ROOT

2021-02-25 Thread Johannes Schauer Marin Rodrigues
Hi, I don't want to start a discussion. So no need to reply. I just wanted to clarify some things. Quoting Sam Hartman (2021-02-24 23:12:11) > I'm not at all convinced this is a good idea. We're replacing a great, > well-tested facility--namely running maintainer scripts in root directories > wi

Bug#924361: smcroute: racy systemd unit start (and autopkgtest failure)

2021-02-25 Thread Micha Lenk
Hi all, Am 12.03.19 um 19:06 schrieb Joachim Nilsson: Yes indeed, that seems to be the case. The tests require a bit of love and encouragement to get into shape. Just a short update. In today's upload I removed the requirement of machine level isolation which will make the autopkgtest run in

Bug#983526: buster-pu: package python-django/1:1.11.29-1+deb10u1

2021-02-25 Thread Chris Lamb
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Dear stable release managers, Please consider python-django (1:1.11.29-1+deb10u1) for buster: python-django (1:1.11.29-1+deb10u1) buster; urgency=high . * CVE-2021-23336:

Bug#945366: sudoers permits arguments beyond what is normally expected

2021-02-25 Thread Marc Haber
tags #945366 - patch thanks On Sat, Nov 23, 2019 at 06:01:51PM +, Edward Neville wrote: > Entries in sudoers files that include * do not behave like shell globs. > When mistakenly used in the argument list it can expand to protected > content, such as /etc/shadow. Most users do not expect this

Bug#983090: python-django: CVE-2021-23336

2021-02-25 Thread Chris Lamb
Sébastien Delafond wrote: > > > Django is vulnerable because it embeds parse_qsl: > > > > > > https://www.djangoproject.com/weblog/2021/feb/19/security-releases/ > > > > Security team, let me know if you would like an update for stable. […] > we think this should rather go via s-p-u. ACK. Hav

Bug#983427: libpam-runtime: please add support for DPKG_ROOT

2021-02-25 Thread Sam Hartman
I'm setting a calendar note to come back tho this in May. Apologies for not having time sooner; I'm in the middle of planning for a move and trying to deal with bullseye issues.

Bug#945366: sudoers permits arguments beyond what is normally expected

2021-02-25 Thread Ed Neville
On 2021-02-25 17:43+0100, Marc Haber wrote: > ... > I am removing the patch tag since Debian is not going to take this > patch if upstream doesn't. The functionality will be included in > Debian when upstream makes a release with the functionality included. > > The patch has been forwarded to up

Bug#954066: Workaround is working

2021-02-25 Thread user2304
The proposed Workaround to /usr/share/hplip/data/models/ and alter [hp_laserjet_cp1025] to [hp_laserjet_cp_1025] is working. Thanks. user2304 -- mail: user2...@web.de

Bug#893022: adequate doesn't find missing pkg-config dependencies

2021-02-25 Thread Andreas Beckmann
Control: reassign -1 piuparts-slave-from-git-deps On Mon, 14 May 2018 11:34:37 +0200 Jakub Wilk wrote: * Adrian Bunk , 2018-03-15, 21:22: >adequate already seems to try to check this, but for some reason it >doesn't find the libinput-dev problem. adequate checks these dependencies only if th

Bug#982035: Please consider reverting (i.e. re-adding dependency)

2021-02-25 Thread Helge Kreutzmann
Hello Paul, hello Holger, manpages-it comes back, just from a new source package (manpages-l10n). The reason this was delayed is that I cannot get this through NEW myself, as I'm only a Debian Maintainer, so I needed a sponsor (Toddy is currently unavailable). This has been resolved, so now manpage

Bug#983527: buster-pu: package redis/5:5.0.3-4+deb10u3

2021-02-25 Thread Chris Lamb
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Dear stable release managers, Please consider redis (5:5.0.3-4+deb10u3) for buster: redis (5:5.0.3-4+deb10u3) buster; urgency=medium . * CVE-2021-21309: Fix a series of int

Bug#983528: reports false positives for missing -fPIE

2021-02-25 Thread Marc Haber
Package: blhc Version: 0.12-2 Severity: normal Hi, for the aide package, blhc complains about missing CFLAGS (-fPIE), see https://buildd.debian.org/status/fetch.php?pkg=aide&arch=amd64&ver=0.17.3-1&stamp=1613025725&raw=0 However, aide uses dpkg-buildflags correctly, it is just the case that dpk

Bug#983529: Backport mailman3 for buster

2021-02-25 Thread Thomas Koch
Package: mailman3 Version: 3.2.1-1 What do you think about providing a backport of mailman3 3.3.3-1 for Buster? I'm about to setup mailman for a German organization that would like to have localized messages. But those are only available in 3.3.3. This would of course only make sense together w

Bug#983399: filter for portscans detected by scanlogd

2021-02-25 Thread Sylvestre Ledru
Hello Could you please try to have it merged upstream ? thanks Cheers, S Le 23/02/2021 à 16:15, Mike Gabriel a écrit : Package: fail2ban Severity: whislist Tags: patch Hi, today I worked on a fail2ban filter rule that is able to filter out log lines from scanlogd. The scanlogd daemon is a

Bug#983446: redis: CVE-2021-21309

2021-02-25 Thread Chris Lamb
Hi Moritz, > given that this only affects 32 bit archs and only with an inherently insecure > setup (opening up the default bulk size to such high values might impact all > kinds of stability / availability I guess) I don't think this needs a DSA. > So s-p-u or piggybacking with the next DSA seems

Bug#983365: linphone-desktop: chat messages

2021-02-25 Thread Dennis Filder
Control: tag -1 + confirmed sid bullseye I looked into this the past days, and I think this is actually a bug in d/rules in src:linphone. I'm beginning to suspect that this is due to this line: -DENABLE_DB_STORAGE=NO \ Apparently the code for the once separate chat history and c

Bug#982356: (no subject)

2021-02-25 Thread Emmanuel Kasper
I think this bug is due to the switch to fai for testing/bullseye. IIRC with fai, we run a dhcp client for each interface, which would cause the double IP adresses you see (one set up by DHCP, one set up by Vagrant directly over ssh when booting the VM)

Bug#982719: firehol: FTBFS: dh_auto_test: error: make -j1 check VERBOSE=1 returned exit code 2

2021-02-25 Thread Dennis Filder
On Thu, Feb 25, 2021 at 12:05:39PM +0100, Jerome BENOIT wrote: > I was rather wondering if setting Rules-Requires-Root to yes in d/rules > will ask to bbuild to act as "needs-root" for autopkgtest. No. Rules-Requires-Root is only to tell the build scripts that some parts of the build requires rea

Bug#983236: magics++: FTBFS with PROJ 8.0.0

2021-02-25 Thread Sebastiaan Couwenberg
Control: tags -1 patch On 2/21/21 1:21 PM, Bas Couwenberg wrote: > Your package FTBFS with PROJ 8.0.0: > > /usr/include/proj.h:123:4: error: #error "The proj_api.h header has been > removed from PROJ with version 8.0.0" >123 | #error "The proj_api.h header has been removed from PROJ with

Bug#982060: run-mailcap: special characters in file names break "open"

2021-02-25 Thread Charles Plessy
Le Sat, Feb 06, 2021 at 07:35:16AM +0100, Marriott NZ a écrit : > > run-mailcap fails if run as "open" on file names containing special > characters. > It also allows shell command injection from file names (again: > https://www.debian.org/security/2014/dsa-3114). Thanks Mariott for the head-up

Bug#983530: fastboot: please update fastboot. Current version hangs with my smartphone

2021-02-25 Thread Michael Meier
Package: fastboot Version: 1:10.0.0+r36-7 Severity: normal X-Debbugs-Cc: schissdra...@rmm.li When trying to flash a recovery to my smartphone (poco x3). It hangs forever at Sending 'recovery' (131072 KB) After a while an error appears in dmesg: [227526.825738] INFO: task fastboot:960640 blocked f

Bug#983523: general: some WWW sites no longer work neither in Firefox nor in Chrome

2021-02-25 Thread William Unruh
This really is a useless bug report. How can anyone try to duplicate it? You do not tell anyone who your internet provider is, How you try to get the "chat", what internet site you go to, and what kind of goods you select. In linux.debian.devel, you wrote: > Package: general > Severity: normal >

Bug#983523: general: some WWW sites no longer work neither in Firefox nor in Chrome

2021-02-25 Thread Janusz S. Bień
On Thu, Feb 25 2021 at 10:27 -08, William Unruh wrote: > This really is a useless bug report. How can anyone try to duplicate it? > You do not tell anyone who your internet provider is, How you try to get > the "chat", what internet site you go to, and what kind of goods you > select. The chat is

Bug#983531: buster-pu: package python2.7/2.7.16-2+deb10u2

2021-02-25 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: d...@debian.org debdiff below fixes three security issues, which don't warrant a DSA by itself. Update has been tested on a Buster few systems (and verified with the P

Bug#983210: atlas-ecmwf: FTBFS with PROJ 8.0.0

2021-02-25 Thread Sebastiaan Couwenberg
Control: tags -1 patch On 2/21/21 7:23 AM, Bas Couwenberg wrote: > Your package FTBFS with PROJ 8.0.0: > > /usr/include/proj.h:345:23: error: type alias redefinition with different > types ('struct pj_ctx' vs 'struct projCtx_t') [clang-diagnostic-error] > typedef struct pj_ctx PJ_CONTEXT; >

Bug#983530: fastboot: please update fastboot. Current version hangs with my smartphone

2021-02-25 Thread Michael Meier
Package: fastboot Version: 1:10.0.0+r36-7 Followup-For: Bug #983530 X-Debbugs-Cc: schissdra...@rmm.li I've just realized. It doesn't have anything to do with the fastboot version. It only accidentally worked with the new one. As it seems the only way to make it work is (independently the version):

Bug#983499: unblock: python3-defaults/3.9.2~rc1-1, python3.9/3.9.2~rc1-1

2021-02-25 Thread stefanor
Hi Paul (2021.02.25_08:58:36_+) > > Including a python3-full and python3.x-full packages, that Depends on > > the entire stdlib, is a compromise position to help them to support > > Python users on Debian (and derivative) platforms. > > This is the piece we're missing. What is it in Debian tha

Bug#655211: sudo: add non EBNF'ed manpages

2021-02-25 Thread Marc Haber
Version: 1.9.5-1 On Mon, Jan 09, 2012 at 11:35:35AM +0100, Michael Schmitt wrote: > please consider adding a more descriptive manpage avoiding EBNF syntax. The sudoers man page still has EBNF, but has become a lot more descriptive. I am therefore closing this bug for version 1.9.5, because I cann

Bug#983532: freecad: Version number not shown correctly in Help -> About FreeCAD

2021-02-25 Thread Andrew Atkinson
Package: freecad Version: 0.19~pre1+git20210207.a3fb41502b+dfsg-1 Severity: normal X-Debbugs-Cc: a...@wotcc.org.uk Dear Maintainer, When following Help -> About FreeCAD The version number is blank Using the copy to clipboard button it shows the version but not the build number. Shown is Vers

Bug#983429: mosquitto: /run/mosquitto is on a tmpfs and should be created dynamically

2021-02-25 Thread Roger Light
The systemd unit file should recreate the folder each time the service is started. It uses /var/run/mosquitto instead of /run/mosquitto, but that should work through the /var/run symlink. Does this definitely not work for you? On Wed, 24 Feb 2021 at 01:15, Alexandre Detiste wrote: > > Package: m

Bug#982530: libpam-modules: unable to login when using pam_tally2 after upgrade to libpam-modules >1.4.0

2021-02-25 Thread Sam Hartman
In adapting your first patch, I narrowed things down a bit. I search /etc/pam.d files containing only a-z0-9A-Z, which I believe should catch all the active pam.d files but not editor backups, .pam-new files and the like. I also specifically recommend looking at pam_faillock. --Sam

Bug#974828: Fwd: Bug#974828: printer-driver-hpcups: SIGABRT with "free(): invalid next size (normal)" in HPCupsFilter::cleanup

2021-02-25 Thread Ian Campbell
Control: found -1 3.20.11+dfsg0-2 Control: found -1 3.21.2+dfsg1-1 On Thu, 2021-02-25 at 18:32 +, Ian Campbell wrote: > I'll see if I can upgrade and repeat. Confirmed I see this with both the current bullseye and sid versions of printer-driver-hpcups. Ian.

Bug#192522: sudo: should validate sudoers on upgrade and abort if incompatible

2021-02-25 Thread Marc Haber
notforwarded #192522 thanks # this is not an upstream issue On Thu, May 08, 2003 at 10:11:03PM +0100, James Troup wrote: > [? maybe not but it left me with one dead box, so I'm inclined to > inflate right now, downgrade if you want...] > > I just upgraded a hideous potato/sid hybrid box to woody

Bug#983254: openorienteering-mapper: FTBFS with PROJ 8.0.0

2021-02-25 Thread Kai Pastor, DG0YT
Found this in the junk e-mails today... Am 23.02.21 um 19:20 schrieb Sebastiaan Couwenberg: There is still a test failure, though. Refer to the attached buildlog for details. This seems unrelated to PROJ 8.0.0. The failing test creates a QTemporaryFile, removes all permissions from the file

Bug#983090: python-django: CVE-2021-23336

2021-02-25 Thread Salvatore Bonaccorso
Hi Chris, On Thu, Feb 25, 2021 at 04:47:34PM +, Chris Lamb wrote: > Sébastien Delafond wrote: > > > > > Django is vulnerable because it embeds parse_qsl: > > > > > > > > https://www.djangoproject.com/weblog/2021/feb/19/security-releases/ > > > > > > Security team, let me know if you would

Bug#983535: sbuild: source-only-changes only includes most recent changelog entry despite -v arg

2021-02-25 Thread William Blough
Package: sbuild Version: 0.79.1-1~bpo10+1 Severity: normal Hi, When passing -v via debbuildopt in conjunction with --source-only-changes, the source-only changes file only includes the most recent changelog entry as if the -v option was not present. The arch-specific changes file does include the

Bug#983526: buster-pu: package python-django/1:1.11.29-1+deb10u1

2021-02-25 Thread Salvatore Bonaccorso
Hi Chris, On Thu, Feb 25, 2021 at 04:42:55PM +, Chris Lamb wrote: > Package: release.debian.org > Severity: normal > Tags: buster > User: release.debian@packages.debian.org > Usertags: pu > > Dear stable release managers, > > Please consider python-django (1:1.11.29-1+deb10u1) for buster

Bug#881671: sudo: please ship Apport hook

2021-02-25 Thread Marc Haber
On Tue, Nov 14, 2017 at 12:24:58AM +0100, Balint Reczey wrote: > Please consider shipping an Apport hook like many other packages in Debian. > I attached the patch carried in Ubuntu for adding the hook, please > consider merging it. Your python script has a shebang line /usr/bin/python, which many

Bug#983512: Bug#983513: debuerreotype: autopkgtest seems to hard-code amd64 signature

2021-02-25 Thread Tianon Gravi
On Thu, 25 Feb 2021 at 04:18, Paul Gevers wrote: > Your package has an autopkgtest, great. However, it always fails on > non-amd64 architectures. Looking at the error message, it seems to > compare the build tar ball with a pre-computed hash that's only valid on > amd64. (And then the log becomes

Bug#983365: linphone-desktop: chat messages

2021-02-25 Thread Dennis Filder
The file rules.patch got mangled in transit. Attached is the integrous version. rules.patch.gz Description: application/gzip

Bug#983100: libboost-python1.74-dev: multiarchify python dependency

2021-02-25 Thread Giovanni Mascellani
Hi, Il 18/02/21 20:46, Helmut Grohne ha scritto: The affected packages cannot satisfy their cross Build-Depends, because their transitive dependency on the host architecture Python interpreter is not installable. The host architecture Python interpreter is required from libboost-python1.74-dev -

  1   2   >