Bug#1022068: linux: kernel NULL pointer dereference in nouveau driver on Thinkpad W541

2022-10-21 Thread Ansgar
On Wed, 2022-10-19 at 18:47 +0200, Ansgar wrote: > After upgrading to linux 6.0.2-1 I see the following message during > boot: [...] > Besides the null pointer dereference above, suspend to RAM also no > longer works properly after the upgrade. I have not investigated that > furt

Bug#1022068: linux: kernel NULL pointer dereference in nouveau driver on Thinkpad W541

2022-10-19 Thread Ansgar
-- I only use the integrated Intel graphics, the Nvidia card is unused. There was no null pointer dereference with the previous kernel (5.19.11-1 (2022-09-24)). Besides the null pointer dereference above, suspend to RAM also no longer works properly after the upgrade. I have not investigated that furth

Bug#1018752: src:linux: new certificate used for Secure Boot

2022-08-30 Thread Ansgar
It can also be found in the code-signing repository: https://salsa.debian.org/ftp-team/code-signing/-/blob/master/etc/debian-prod-2022-linux.pem Please switch to using it with the next src:linux upload (in any suite). Please also do so for src:linux-5.10. Ansgar debian-prod-2022-linux.pem

Re: linux-5.10 code signing in buster

2022-08-03 Thread Ansgar
Hi, Ben Hutchings writes: > As code signing is enabled in buster suites, I think this requires a > change to the configuration of the code signing service. Bastian Blank prepared the required changes on our side (dak, codesigning) and they should be live by now. Ansgar

Bug#1012741: modprobe: ERROR: could not insert 'crc_itu_t': Key was rejected by service

2022-07-10 Thread Ansgar
re bug that was fixed. Ansgar

Bug#1012741: modprobe: ERROR: could not insert 'crc_itu_t': Key was rejected by service

2022-07-05 Thread Ansgar
Hi, On Tue, 2022-07-05 at 09:00 +0200, Bastian Blank wrote: > On Mon, Jul 04, 2022 at 10:34:39PM +0200, Ansgar wrote: > > As a further test I tried a different PKCS#11 module: > > Could you try the same with "openssl cms"?  Just to make sure it's > not sign-fil

Bug#1012741: modprobe: ERROR: could not insert 'crc_itu_t': Key was rejected by service

2022-07-04 Thread Ansgar
Hi, On Mon, 2022-07-04 at 22:00 +0200, Ansgar wrote: > The correct signature (using OpenSSL) has: > > +--- > > 138 256:   OCTET STRING > >    : 00 00 45 75 A8 93 B1 B1 37 0A 53 69 82 BB 1C B6 > +---[ data.ko.p7s.success ] > > The incor

Bug#1012741: modprobe: ERROR: could not insert 'crc_itu_t': Key was rejected by service

2022-07-04 Thread Ansgar
h the same data/key/cert, but it is reproducible with the same key. Ansgar ykcs11-signature-failure.tar.gz Description: application/compressed-tar

Bug#1012741: modprobe: ERROR: could not insert 'crc_itu_t': Key was rejected by service

2022-07-04 Thread Ansgar
one might for a large integer type), but the other side expects a fixed size? If so, the file should validate if one injects two leading 0 bytes in the OCTET STRING (and updates all length values). I would need to check how to manipulate files using ASN.1's DER encoding to try this... Ansgar [1]: https://bugs.debian.org/1012741#48

Bug#1014272: src:linux: sign-file: correct error handling

2022-07-03 Thread Ansgar
signing a kernel module with the patched sign-file and that still worked. Ansgar >From d11fb170c3ec172ce6707baab03b1499f14e0f20 Mon Sep 17 00:00:00 2001 From: Ansgar Burchardt Date: Sun, 3 Jul 2022 11:17:50 +0200 Subject: [PATCH] sign-file: correct error handling The functions CMS_fi

firmware-nonfree_20190114-2~deb9u1_amd64.changes REJECTED

2020-09-15 Thread Ansgar
Accepted on security-master, and synced to ftp-master as we still do that for uploaded accepted from the NEW queue, even though we probably should not. Anyway, it should be rejected on ftp-master. === Please feel free to respond to this email if you don't understand why your files were rej

linux-4.19_4.19.132-1~deb9u1_multi.changes REJECTED

2020-09-07 Thread Ansgar
Upload targeted at stretch which is no longer updated on ftp-master (but uploads from policy queues still end up synced to ftp-master) === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns.

linux-latest-4.19_105+deb10u5~deb9u1_amd64.changes REJECTED

2020-09-07 Thread Ansgar
Upload targeted at stretch which is no longer updated on ftp-master (but uploads from policy queues still end up synced to ftp-master) === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns.

Bug#942881: Audio on Lenovo X1 Carbon 5th generation stopped working after upgrade to linux-image-5.3.0-1-amd64 ("No response from codec")

2019-10-25 Thread Ansgar
ig a bit deeper. :-) Sadly it looks like this requires more digging. I'll try later :/ At least it is an interesting problem. Ansgar

Bug#942881: Audio on Lenovo X1 Carbon 5th generation stopped working after upgrade to linux-image-5.3.0-1-amd64 ("No response from codec")

2019-10-25 Thread Ansgar
Tomas Janousek writes: > On Fri, Oct 25, 2019 at 09:45:55AM +0200, Ansgar wrote: >> Tomas Janousek suggested in https://bugs.debian.org/942881#41 that the >> file might be truncated and two bytes missing. I think that might be >> the problem, but with three bytes missing: &g

Bug#942881: Audio on Lenovo X1 Carbon 5th generation stopped working after upgrade to linux-image-5.3.0-1-amd64 ("No response from codec")

2019-10-25 Thread Ansgar Burchardt
logged with sha256sum c2a36f35867ae92b8664f4bd2193e70370eb3b92013ea53f3573d2508d3da4cb (which matches snd-hda-codec-hdmi.ko.sig in src:linux-signed-amd64) So linux' sign-file likely produced a truncated file for some reason; note that ftp-master still uses linux-kbuild-4.9/4.9.189-3+deb9u1. Ansgar

Bug#942881: Audio on Lenovo X1 Carbon 5th generation stopped working after upgrade to linux-image-5.3.0-1-amd64 ("No response from codec")

2019-10-25 Thread Ansgar
that is. But then signing stuff producing truncated files also shouldn't happen... Ansgar

Re: Debian Linux kernel uploads

2019-10-22 Thread Ansgar
Hi, Hector Oron writes: > I would like to support Debian Linux kernel team by doing kernel > package uploads. Related to Linux uploads: I've added an exception to allow source-only uploads to NEW for src:linux. Feel free to try. Ansgar

Re: linux-signed-amd64_5.3.7+1_source.changes REJECTED

2019-10-22 Thread Ansgar
le a removal request if src:linux-latest and the packages mentioned above should already be removed. I think it will otherwise be reported as cruft later when the linux-*-rt-* packages are taken over as well. Ansgar

Bug#942089: linux-signed-amd64: version number not handled correctly by dpkg-genchanges

2019-10-09 Thread Ansgar
ady uses this scheme). Ansgar

Re: Bug#913061: systemd: stop shipping /bin/systemd

2019-09-12 Thread Ansgar
Ben Hutchings writes: > On Wed, 2019-09-11 at 19:20 +0200, Ansgar wrote: >> would it be possible to add a fallback to try /lib/systemd/systemd if >> the user provided init=/bin/systemd and the file no longer exists? >> >> I would like systemd to stop shipping the /

Re: Bug#913061: systemd: stop shipping /bin/systemd

2019-09-11 Thread Ansgar
suggested to use init=/bin/systemd for testing purposes in the past (see below). So just removing the symlink might make some systems unbootable. Ansgar Michael Biebl writes: >> Running `systemd` in an interactive shell is not a good idea. To >> avoid this happening by accident, the

Re: last preparations for switching to production Secure Boot key

2019-02-26 Thread Ansgar
Hi, Colin Watson writes: > On Mon, Feb 25, 2019 at 08:13:22PM +0100, Ansgar wrote: >> I added support for listing `trusted_certs`[1] as proposed by Ben >> Hutchings. This means the `files.json` structure *must* list the >> sha256sum of certificates the signed binaries will

last preparations for switching to production Secure Boot key

2019-02-25 Thread Ansgar
] } } } ``` This would allow adding additional top-level keys later should the need arise. (I'll prepare the archive-side changes for this later today.) Could all maintainers (for fwupd, fwupdate, grub2, linux) please ack one last time that their packages are ready for

Re: aptitude: should consistently choose between signed and unsigned kernels

2018-12-20 Thread Ansgar Burchardt
unsigned version. This doesn't look like a bug in apt to me. The easiest way to avoid this would be to drop the Provides from the unsigned image. Is there any downside for doing so? Ansgar

linux_3.16.59-1_multi.changes REJECTED

2018-10-08 Thread Ansgar Burchardt
Jessie LTs no longer updated on ftp-master === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns.

Re: linux-4.9_4.9.110-1~deb8u1_multi.changes REJECTED

2018-08-18 Thread Ansgar Burchardt
Ben Hutchings writes: > On Sat, 2018-08-18 at 15:00 +0000, Ansgar Burchardt wrote: >> Jessie no longer maintained on ftp-master > > This was uploaded to security-master so I don't know why you're seeing > it on ftp-master as well. The security-master -> ftp-mast

linux-latest-4.9_80+deb9u5~deb8u1_amd64.changes REJECTED

2018-08-18 Thread Ansgar Burchardt
Jessie no longer maintained on ftp-master === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns.

linux-4.9_4.9.110-1~deb8u1_multi.changes REJECTED

2018-08-18 Thread Ansgar Burchardt
Jessie no longer maintained on ftp-master === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns.

Re: Scheduling 9.5

2018-06-25 Thread Ansgar Burchardt
ther or both of those dates? > > The 7th is looking like the favourite so far (although would mean > freezing next weekend), but we still need an ftp-master (N)ACK on > either / both date. I still have time on either weekend. Ansgar

Re: Scheduling 9.5

2018-06-11 Thread Ansgar Burchardt
fine with me; Joerg wanted to do the 8.11 one, but if he has time restrictions on June 23rd and doing 8.11 after 9.5 would be too late for him, I could probably also do both. (If Joerg wants to do both, that's also fine with me.) Ansgar

Re: Secure boot signing infrastructure - feedback request

2017-10-10 Thread Ansgar Burchardt
't like requiring access to a signing service on buildds either. It also makes it harder to trust the build process less in the future (for example by moving it to a VM so it is restricted to do evil stuff only the the current build, not having access to private keys and removing access to network services). Ansgar

Re: Kernel debug symbols are always NEW

2016-11-22 Thread Ansgar Burchardt
-debug will help? I set the override suite for {unstable,experimental}-debug to unstable; and for testing-debug to testing. Please tell if this doesn't work. It should work for -dbgsym packages that are listed in d/control contrary to the assumption they are always automatically built. Ansgar

linux_3.16.2-1_multi.changes REJECTED

2014-09-08 Thread Ansgar Burchardt
As requested on IRC. === Please feel free to respond to this email if you don't understand why your files were rejected, or if you upload new files which address our concerns. -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact

Re: Bug#725975: RM: xen-system-amd64 [i386] -- NBS; no longer built on i386

2013-10-11 Thread Ansgar Burchardt
xen-system-amd64:i386 should be removed. xen-linux-system-3.10-3-amd64 still depends on xen-system-amd64: # Broken Depends: linux: xen-linux-system-3.10-3-amd64 With xen-system-amd64 gone on i386, xen-linux-system-*-amd64 should probably also be dropped (on i386). Ansgar -- To

Re: Linux kernel hardening - link restrictions

2012-03-03 Thread Ansgar Burchardt
ase that was getting backported kernels (with >> link restrictions) built for it. > > Ansgar, are you happy to do a stable update for this? If so, we can put > 'Breaks: at (<< 3.1.12-1+squeeze1)' in the kernel packages for wheezy > and hopefully APT will just do the right

Bug#607617: src:linux-latest-2.6: no linux-headers-2.6-all package

2010-12-20 Thread Ansgar Burchardt
. Regards, Ansgar -- To UNSUBSCRIBE, email to debian-kernel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20101220102148.2219.94217.report...@pc-kmaurisc.mathi.uni-heidelberg.de