Re: 11.7 planning + bookworm planning

2023-04-23 Thread Paul Gevers
Hi, Any FTP master for 10 or 17 June? kibi  - 10, 17, 24    d-i Luna  - 10, 17, 24    CD testing elbrus    - 10, 17, 24    release team adsb  - 10, 17, 24    release team Sledge    - 10, 17, 24    images team donald- 10, 17press Paul OpenPGP_signature Description: Open

Re: 11.7 planning + bookworm planning

2023-04-23 Thread Paul Gevers
Hi all, Let's book June 10 as the bookworm release date. A more formal announcement will follow. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1034733: unblock: irony-mode/1.5.0-5

2023-04-25 Thread Paul Gevers
Hi Nicholas, On 23-04-2023 00:06, Nicholas D Steeves wrote: unblock irony-mode/1.5.0-5 llvm-toolchain-15 isn't expected to change and migration in it's current for is not accepted. Please upload your changes to tpu, with only a new changelog entry targeting 'bookworm', preferably with versio

Bug#1034733: unblock: irony-mode/1.5.0-5

2023-04-25 Thread Paul Gevers
Control: tags -1 moreinfo confirmed Hi, On 26-04-2023 06:39, Paul Gevers wrote: Please upload your changes to tpu, with only a new changelog entry targeting 'bookworm', preferably with version 1.5.0-5+deb12u1. Forgot to say, please remove the moreinfo tag when the package is in th

Bug#1034763: unblock: grub2/2.06-12

2023-04-25 Thread Paul Gevers
Hi Steve, Thanks a lot for the upload. On 23-04-2023 21:43, Steve McIntyre wrote: We've pulled in some really important fixes for GRUB, that I think are important and should definitely be part of the bookworm release: Ack. unblock grub2/2.06-12 unblock grub-efi-amd64-signed/1+2.06+12 unbloc

Bug#1034479: [pre-approval] unblock: rocprim/5.3.3-4

2023-04-25 Thread Paul Gevers
Control: tags -1 moreinfo Hi Christian, On 16-04-2023 14:05, Christian Kastner wrote: This version in itself isn't controversial, but unfortunately the previous version 5.3.3-3 did not yet migrate to testing, so I'm asking for pre-approval to to 5.3.3-4 and allow it to eventually migrate, and o

Bug#1034566: unblock: isc-dhcp/4.4.3-P1-1.1

2023-04-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Control: retitle -1 unblock: isc-dhcp/4.4.3-P1-2 On 18-04-2023 14:11, Santiago R.R. wrote: 2. This is the autopkgtest included in this request applied to the current version in testing: Minor question: I *think* you are configuring the test to use the inter

Bug#1034634: unblock: freetype/2.12.1+dfsg-5

2023-04-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo On 20-04-2023 13:47, Hugh McMaster wrote: An integer overflow vulnerability was discovered in FreeType (specifically, the tt_hvadvance_adjust() function). This is CVE-2023-2004. Please go ahead and remove the moreinfo tag once the package has been uploaded.

Bug#1034639: unblock: spamassassin/4.0.0-5

2023-04-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Noah. On 20-04-2023 18:22, Noah Meyerhans wrote: This is a targeted change that addresses #1034347, Please go ahead and remove the moreinfo tag once the upload happened. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1034640: unblock: spirv-llvm-translator-15/15.0.0-2

2023-04-26 Thread Paul Gevers
Control: tags -1 moreinfo Hi Andreas, On 20-04-2023 19:16, Andreas Beckmann wrote: Looks like I forgot to merge the -fvisibility=hidden changes from src:spirv-llvm-translator-14 (and the corresponding removal of 4500+ useless C++ symbols from the .symbols file) into src:spirv-llvm-translator-15

Bug#1034646: [pre-approval] unblock: fuse3/3.14.0-4

2023-04-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi László, On 20-04-2023 21:21, László Böszörményi (GCS) wrote: There's a memory leak in the high level API [1] and the fuse CLI doesn't propagate the allowed maximum threads to use [2]. Please go ahead and remove the moreinfo tag once the upload happens.

Bug#1034652: unblock: reportbug/12.0.0

2023-04-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Nis, On 20-04-2023 23:03, Nis Martensen wrote: Paul Gevers asked if we can have a version of reportbug that prevents bug 992332 from happening again in bookworm. I'd like to use the opportunity to include a few other small fixes as well if pos

Bug#1033571: unblock: keyman/16.0.139-4

2023-04-26 Thread Paul Gevers
Hi Eberhard, On 01-04-2023 20:23, Paul Gevers wrote: -set -e +# Don't call `set -e`. Even if some commands should fail, it's still +# worth running the rest of the commands. Can you elaborate? Ping. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1033935: unblock: ausweisapp2/1.26.3-1

2023-04-26 Thread Paul Gevers
Hi Adrian, On 20-04-2023 11:00, John Paul Adrian Glaubitz wrote: Could you prepare a debdiff stripping tests (assuming those are not influencing the build itself), stripping the copyright line changes and dropping the changed png files? It seems this might be reviewable when that's done. Thank

Bug#1034428: unblock: vmdb2/0.27-1

2023-04-27 Thread Paul Gevers
Control: tags -1 moreinfo Hi Gunnar, On 15-04-2023 03:23, Gunnar Wolf wrote: The debdiff might seem a bit large, at 900 lines, but it is partly due to upstream having included a patch we used to apply at build time. Could you prepare a diff between the sources with patches applied? To verify

Bug#1034428: unblock: vmdb2/0.27-1

2023-04-27 Thread Paul Gevers
Hi, Once more. On 15-04-2023 03:23, Gunnar Wolf wrote: [ Checklist ] [X] all changes are documented in the d/changelog [X] I reviewed all changes and I approve them [X] attach debdiff against the package in testing You (via the janitor) also bumped the debhelper-compat level. That's

Bug#1033935: unblock: ausweisapp2/1.26.3-1

2023-04-27 Thread Paul Gevers
Hi Adrian, On 27-04-2023 10:05, John Paul Adrian Glaubitz wrote: Could you prepare a debdiff stripping tests (assuming those are not influencing the build itself), stripping the copyright line changes and albeit a lot of

Bug#1034505: unblock (pre-approval): libsdl2/2.26.5+dfsg-1

2023-04-27 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Simon, On 17-04-2023 11:53, Simon McVittie wrote: The most serious bug fixed here is a crash for fcitx users if libdbus cannot be initialized (src/core/linux/SDL_fcitx.c, 1-line change). If this upstream stable update is considered too large, I'll cherry-p

Bug#1034764: unblock: spf-engine/3.0.4-1

2023-04-27 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Scott, On 23-04-2023 22:19, Scott Kitterman wrote: The updated package is uploaded to Experimental. If approved, the Unstable upload would have an additional d/changelog entry, but no other changes. Please go ahead and remove the moreinfo tag once it's

Bug#1034785: unblock: gummi/0.8.3-1

2023-04-27 Thread Paul Gevers
Control: tags -1 moreinfo Hi Martin, On Mon, 24 Apr 2023 13:45:42 +0200 Martin Dosch wrote: I don't think there are huge risks as 0.8.1 → 0.8.3 were only bugfixes and no big changes. Your debdiff was so big that the mail didn't even reach the list. 60 files changed, 7341 insertions(+), 624

Bug#1034788: unblock: git-crecord/20220324.0-2

2023-04-27 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Andrej, On 24-04-2023 15:21, Andrej Shadura wrote: I am going to upload a one-line patch to the package git-crecord. Sure. Please remove the moreinfo tag once that happened. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1034757: unblock (pre-approval): scilab/6.1.1+dfsg2-5 libjogl2-java/2.3.2+dfsg-10 gluegen2/2.3.2-9

2023-04-27 Thread Paul Gevers
Control: tags -1 moreinfo Hi Pierre, On Sun, 23 Apr 2023 17:27:30 +0200 Pierre Gruet wrote: This unblock would lead to new upstream versions (with some packaging work more complex than just refreshing patches) of gluegen2 and libjogl2 shipped into Bookworm, which I trust to be OK as they have

Bug#1034634: unblock: freetype/2.12.1+dfsg-5

2023-04-27 Thread Paul Gevers
Control: tags -1 d-i Hi kibi, On 20-04-2023 13:47, Hugh McMaster wrote: [ Reason ] An integer overflow vulnerability was discovered in FreeType (specifically, the tt_hvadvance_adjust() function). This is CVE-2023-2004. [ Impact ] FreeType 2 can crash when getting TrueType font metrics due to t

Bug#1034785: unblock: gummi/0.8.3-1

2023-04-28 Thread Paul Gevers
Hi On 28-04-2023 15:44, Cyril Brulebois wrote: Martin Dosch (2023-04-27): As you can see in a diff from 0.8.1 to 0.8.3 [1] also generated UI files and translations changed which makes the debdiff between both packages huge. I created a diff for the upstream changes in the src folder between 0.

Bug#1032899: unblock: rocm-hipamd/5.2.3-6

2023-04-28 Thread Paul Gevers
Hi Christian, On 28-04-2023 00:58, Christian Kastner wrote: So I split that diff into 02 (patches) and 03 (NOT-patches), also attached. I think you forgot to add them. Would a package with just the patches and the (*) changes be acceptable? I asked you to *also* provide the diff between *c

Re: Bookworm release notes: sssd cache becomes invalid on upgrade

2023-04-28 Thread Paul Gevers
Package: release-notes Hi Harald, On 28-04-2023 16:38, Harald Dunkel wrote: AFAIU the sssd cache becomes invalid on the upgrade to Bookworm due to a new format. If you are using the company account to login on your laptop you might get locked out at upgrade time. This affects FreeIPA and maybe

Bug#1034566: unblock: isc-dhcp/4.4.3-P1-1.1

2023-04-28 Thread Paul Gevers
Hi, On 27-04-2023 23:10, Santiago R.R. wrote: I don't see the need to add the `needs-internet` restriction, but please let me know if you think otherwise. I trust your judgement here. You can leave it out. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1032899: unblock: rocm-hipamd/5.2.3-6

2023-04-29 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Christian, On 29-04-2023 00:17, Christian Kastner wrote: I asked you to *also* provide the diff between *current* unstable and your proposal (via unstable), because "I was about to propose to upload it to tpu" (2023-04-20). Sure, the 04_ attachment is th

Bug#1034639: unblock: spamassassin/4.0.0-5

2023-04-29 Thread Paul Gevers
Control: tags -1 moreinfo Hi Noah On 27-04-2023 07:41, Paul Gevers wrote: On 20-04-2023 18:22, Noah Meyerhans wrote: This is a targeted change that addresses #1034347, Please go ahead and remove the moreinfo tag once the upload happened. Already several years we don't accept upl

Bug#1032994: unblock: node-webpack/5.76.1+dfsg1+~cs17.16.16-1

2023-05-02 Thread Paul Gevers
Hi Yadd, On 02-05-2023 10:15, Yadd wrote: extracting only CVE patch means:  * keep some (unimportant) bugs in Bullseye  * publish such version number:    5.76.1+dfsg1+~cs17.16.16+really~5.75.0+dfsg+~cs17.16.14-1 Indeed, both are totally acceptable. Can we have a debdiff please? Paul Open

Bug#1033953: unblock: gimp-help/2.10.34-1

2023-05-03 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 03-05-2023 12:03, Jordi Mallach wrote: This is the final .debdiff for this unblock request. There might have been a misunderstanding, but your debdiff misses the vast majority of upstream changes: 4255 files changed, 2256958 insertions(+), 1205010 deletions

Bug#1035377: unblock: libapache2-mod-auth-openidc/2.4.12.3-2

2023-05-03 Thread Paul Gevers
Hi Moritz, On 02-05-2023 13:14, Moritz Schlarb wrote: Please unblock package libapache2-mod-auth-openidc https://qa.debian.org/excuses.php?package=libapache2-mod-auth-openidc says: not blocked: has successful autopkgtest Are you asking for aging, or did you miss the point that you didn't need

Bug#1033571: unblock: keyman/16.0.139-4

2023-05-03 Thread Paul Gevers
Hi Eberhard, On 27-04-2023 16:48, Eberhard Beilharz wrote: After the installation of ibus-keyman the ibus daemon needs to be restarted which is what the `postinst` script tries to do. It restarts or stops ibus-daemon, then checks if ibus-daemon is running - if not it will start it. If any of t

Bug#1034788: unblock: git-crecord/20220324.0-2

2023-05-03 Thread Paul Gevers
Hi, On 27-04-2023 11:25, Paul Gevers wrote: On 24-04-2023 15:21, Andrej Shadura wrote: I am going to upload a one-line patch to the package git-crecord. Sure. Please remove the moreinfo tag once that happened. The moreinfo tag was still attached, so we missed the upload for a while

Bug#1033900: pre-approval: dkms/3.0.10-10

2023-05-04 Thread Paul Gevers
Control: tags -1 moreinfo Hi Andreas, On 27-04-2023 18:53, Andreas Beckmann wrote: So unless something else appears that warrants an unblock, let's not do this. ^^^ I've just uploaded a new upstream release 3.0.11-1 with some additional bugfixes

Bug#1034757: unblock (pre-approval): scilab/6.1.1+dfsg2-5 libjogl2-java/2.3.2+dfsg-10 gluegen2/2.3.2-9

2023-05-05 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Pierre, On 27-04-2023 15:19, Pierre Gruet wrote: In order to get a pre-approval, I only did the change locally (source debdiff attached), will upload to unstable if granted. Please go ahead. Paul OpenPGP_signature Description: OpenPGP digital signatur

Bug#1035515: [pre-approval] unblock: gdb/13.1-2.1

2023-05-05 Thread Paul Gevers
Control: tag -1 moreinfo, Hi, On 06-05-2023 03:24, Cyril Brulebois wrote: The proposed, targeted fix seems very much appropriate; please let us know once it's in the archive. ...by removing the moreinfo tag. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1034428: unblock: vmdb2/0.27-1

2023-05-05 Thread Paul Gevers
Hi Gunnar, On 06-05-2023 08:01, Gunnar Wolf wrote: What I plan to do (but please, others are welcome to do so 😇) is to wait for a month, until bookworm is released, and upload to stable-proposed-uploads a 0.26-2+1 or somesuch, including the following, minimal diff thas has been accpted upstream:

Bug#1034785: Version string

2023-05-07 Thread Paul Gevers
Hi, On 06-05-2023 16:27, Martin Dosch wrote: On 06.05.2023 07:55, Paul Gevers wrote: Your previous upload was as a team member, so 0.8.3+really0.8.1-1 would have been equally well and would also "make lintian happy". Maybe it was fine for the previous one as it was uploaded by

Bug#1035298: [Pkg-pascal-devel] Bug#1035298: pre-approval: unblock: Lazarus/2.2.6+dfsg1-2

2023-05-07 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 30-04-2023 11:38, Abou Al Montacir wrote: Binary files /tmp/XPIH2EW9zS/lazarus-2.2.6+dfsg1/docs/chm/fcl.chm and /tmp/eEp2yNOeff/lazarus-2.2.6+dfsg2/docs/chm/fcl.chm differ Binary files /tmp/XPIH2EW9zS/lazarus-2.2.6+dfsg1/docs/chm/fclres.chm and /tmp/eEp2yNOeff

Bug#1035334: unblock: python-selenium/4.9.0+dfsg-1

2023-05-07 Thread Paul Gevers
Control: tags -1 moreinfo Hi Carsten, On 01-05-2023 09:48, Carsten Schoenert wrote: Upstream released another round of update to address some minor updates and fixes of the 4.x series. Do you consider this a targeted fix as meant in the freeze policy [1]? Please consider checking the FAQ [2]

Bug#1035024: unblock: nvidia-cudnn/8.7.0.84~cuda11.8+1 (pre-approval)

2023-05-07 Thread Paul Gevers
Control: tags -1 moreinfo Hi Mo, On 27-04-2023 21:31, M. Zhou wrote: So, generally updating the package is simply to update the binary tarball URL in the script, along with the exact version number, which is very trivial. So why didn't you ask for only this? 4. debconf template default choi

Bug#1033838: release.debian.org: Pre-merge review for devscripts

2023-05-07 Thread Paul Gevers
Hi, On 16-04-2023 22:22, Paul Gevers wrote: On 02-04-2023 16:31, Benjamin Drung wrote: I was discussing with Mattia Rizzolo the open merge requests for devscripts and which of them are material for the bookworm release. *Before* we discuss this, can you please handle the version skew we

Bug#1035757: unblock: org-mode/9.5.2+dfsh-5

2023-05-08 Thread Paul Gevers
Control: tags -1 moreinfo Hi, I haven't thought this trough, but it immediately triggered questions: On 08-05-2023 20:46, Sean Whitton wrote: A number of Emacs addon packages which have their own source packages also have versions shipped in src:emacs's binary packages (upstream calls these "c

Bug#1035024: unblock: nvidia-cudnn/8.7.0.84~cuda11.8+1 (pre-approval)

2023-05-08 Thread Paul Gevers
Hi Mo, On 08-05-2023 00:55, M. Zhou wrote: On Sun, 2023-05-07 at 22:03 +0200, Paul Gevers wrote: On 27-04-2023 21:31, M. Zhou wrote: 4. debconf template default choice is changed to "I Agree". This package is in non-free section. Only by setting the debconf default choice

Bug#1033953: unblock: gimp-help/2.10.34-1

2023-05-08 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Jordi On 04-05-2023 14:02, Jordi Mallach wrote: I honestly thought you were more interested in the packaging changes than the upstream diff, sorry. Understood, but we always ask for the full debdiff (which you can filter if you tell us which filter you

Bug#1035383: unblock (pre-approval): brial/1.2.11-2.1

2023-05-08 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi, [I was hoping another Release Team member would shim in, but alas. Please read till the end.] On 02-05-2023 16:11, plugwash wrote: Elbrus replied to my bug report, challangeing why I had filed it as rc, I explained my position and he seemed somewhat bu

Bug#1035674: pre-approval: unblock: puppetserver/7.9.5-2

2023-05-11 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi Jérôme, On 07-05-2023 17:47, Jérôme Charaoui wrote: I would like to request an unblock to upload puppetserver/7.9.5-2 which fixes two bugs using targeted fixes. - #1032241  puppetserver - service unit fails to realize the main process died - #1035541 p

Bug#1035923: unblock: libmediascan/0~20220401.git.34fc2d-3

2023-05-11 Thread Paul Gevers
t.34fc2d-3) unstable; urgency=medium + + * Depends: add libmediascan0 to libmediascan-dev (Closes: #1035451) + + -- Paul Gevers Wed, 03 May 2023 19:40:30 +0200 + libmediascan (0~20220401.git.34fc2d-2) unstable; urgency=medium * Fix Maintainer field diff -Nru libmediascan-0~20220401.git.3

Bug#1035685: unblock: mpdscribble/0.24-2+b1

2023-05-11 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Control: retitle -1 unblock: mpdscribble/0.24-3 Hi, On 07-05-2023 20:58, kaliko wrote: During bookworm development the package was refactored and a bug was introduced in the conf file management. piuparts recently spotted the issue and #1035603 was reported.

Bug#1035916: unblock: node-source-map/0.7.0++dfsg2+really.0.6.1-14

2023-05-11 Thread Paul Gevers
Hi Sebastian, On 11-05-2023 19:06, Sebastian Ramacher wrote: So you're going back to a directory. That would require a symlink_to_dir in the maintscript. Do you want to have symlinks or not? See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1035916#12 Paul OpenPGP_signature Description:

Re: tomcat9 should not be released with Bookworm

2023-05-11 Thread Paul Gevers
Hi Markus, On Tue, 25 Apr 2023 16:04:09 +0200 Markus Koschany wrote: We can only support one major Tomcat version per release. Tomcat9 has been part of Buster and Bullseye already and is superseded by Tomcat 10 in Bookworm. I wanted to wait with the removal request until the issues in [resteasy

Re: Bug#1034824: tomcat9 should not be released with Bookworm

2023-05-12 Thread Paul Gevers
Hi Markus, Thanks for the reply and sorry for my bit grumpy mail yesterday. I was tired and surprised. On 11-05-2023 23:31, Markus Koschany wrote: [...] (all good reply). I'll check on Sunday on the proposal, unless somebody beats me to it. I don't have time before then. Paul OpenPGP_si

Bug#1035056: [pre-approval] plasma-desktop 5.27.X

2023-05-14 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 28-04-2023 15:29, Hefee wrote: before invest time, to do the debdiff and all paperwork for Plasma 5.27.X LTS packages, there's need to be a idea, how to get it into stable. Please read the freeze policy [2] and the FAQ [3] very carefully and make sure your re

Bug#1035843: unblock: jed/0.99.20~pre.178+dfsg-4

2023-05-15 Thread Paul Gevers
Control: tags -1 moreinfo On 10-05-2023 07:33, Rafael Laboissière wrote: The version in unstable fixes the RC bug #1035839. I introduced a regression in the d/jed-common.preinst script when I tried to fix Bug#1035780. And a new RC bug against the version in unstable got filed today. Please re

Bug#1035757: unblock: org-mode/9.5.2+dfsh-5

2023-05-15 Thread Paul Gevers
Control: tag -1 moreinfo Hi, On 10-05-2023 17:21, Sean Whitton wrote: We don't have a real plan for the future, aside from trying to keep these packages up-to-date. It would be good to have a script that we could run right after uploading new versions of Emacs, that would find addons that are

Re: Bug#1034824: tomcat9 should not be released with Bookworm

2023-05-16 Thread Paul Gevers
Hi, On 12-05-2023 21:49, Paul Gevers wrote: I'll check on Sunday on the proposal, unless somebody beats me to it. I don't have time before then. This dropped off my radar and I don't expect I have decent time to look at this until a week from now. Paul OpenPGP_signat

Bug#1035056: [pre-approval] plasma-desktop 5.27.X

2023-05-16 Thread Paul Gevers
Hi, On 16-05-2023 13:37, Aurélien COUDERC wrote: Le dimanche 14 mai 2023, 22:05:19 CEST Paul Gevers a écrit : On 28-04-2023 15:29, Hefee wrote: we know the freeze policy and we know our request doesn’t meet the freeze policy requirements to the letter. People that read a lot of my replies

Bug#1036227: bookworm-pu: package r-cran-shiny/1.7.4+dfsg-3~deb12u1

2023-05-23 Thread Paul Gevers
Control: tags -1 confirmed Hi Andreas, On 17-05-2023 19:48, Andreas Tille wrote: I'd like to announce an upload to testing-proposed-updates You confused me here. I don't see traces of the upload yet, so I assume this is a pre-approval. Thus an upload to testing-proposed-updates seems an a

Bug#1036084: [pre-approval] unblock: android-platform-tools-base/2.2.2-5

2023-05-23 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 15-05-2023 09:21, Emmanuel Bourg wrote: I'd like to suggest downgrading the dependency on adb to recommended if #1034982 isn't fixed in time for the Bookworm release. That seems to be on it's way all right. Please close this bug if it migrates or remove the m

Bug#1036123: [pre-approval] unblock: libcap2/1:2.66-4

2023-05-23 Thread Paul Gevers
Hi Cyril, On 18-05-2023 22:06, Salvatore Bonaccorso wrote: I just realized, that apart gettin the unblock by the release team as it affects d-i as well (shipping libcap2-udeb), CC'ing Cyril here as well. CVE fixes in libcap2. Can you ACK (or udeb-unblock)? Paul OpenPGP_signature Description

Bug#1036306: unblock: ufw/0.36.2-1

2023-05-23 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 19-05-2023 05:33, Jamie Strandboge wrote: It seems that adduser 3.133 has caused problems for a lot of packages in sid, including ufw. See: https://piuparts.debian.org/sid/fail/adduser_3.133.log https://piuparts.debian.org/sid/fail/ https://piuparts.debian.org/

Re: Is an MBF and unblock for packages introducing new files in /bin or /sbin or /lib in Bookworm acceptable at this stage?

2023-05-23 Thread Paul Gevers
Hi, On 21-05-2023 21:22, Luca Boccassi wrote: If we were to do a MBF against packages that in _Bookworm_ have introduced new files in /bin, /sbin or /lib*, would you accept the consequent mass unblock request? Short answer is no, it's too late. Paul OpenPGP_signature Description: OpenPGP di

Bug#1036453: unblock: libvirt/9.0.0-4

2023-05-23 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi, On 21-05-2023 12:37, Andrea Bolognani wrote: Fix CVE-2023-2700. Please go ahead. And please remove the moreinfo tag once the upload happened. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1036306: unblock: ufw/0.36.2-1

2023-05-23 Thread Paul Gevers
Hi Gunnar, On 23-05-2023 18:56, Gunnar Hjalmarsson wrote: On 2023-05-23 17:31, Paul Gevers wrote: On 19-05-2023 05:33, Jamie Strandboge wrote: Sure. The migration is currently blocked because the upload happened very recently That description is not quite accurate. ufw has autopkgtest, so

Re: Bug#1036634: RM: monado/stable -- NVIU; 2 years old codebase for very active project targeting recent hardware and software stack (new version didn't make it into stable).

2023-05-23 Thread Paul Gevers
Hi David, On 23-05-2023 16:59, David Heidelberg wrote: Monado package is in very active development, offering support for recent XR headsets. The risk is getting users discouraged by very old and already unsupported package, rather than just using the Monado package from unstable or git. I'm

Bug#1036656: unblock: grub2/2.06-13

2023-05-23 Thread Paul Gevers
Control: tags -1 confirmed d-i Hi Cyril, The following needs your approval too. On 23-05-2023 23:39, Steve McIntyre wrote: Please unblock package grub2 and its derived signed packages. As promised in the -12 ublock request, we now have a lot more translations updated for the changed template

Re: Bug#1036634: RM: monado/stable -- NVIU; 2 years old codebase for very active project targeting recent hardware and software stack (new version didn't make it into stable).

2023-05-24 Thread Paul Gevers
Control: reassign -1 release.debian.org Control: retitle -1 RM: monado -- should not be released with bookworm Hi On 24-05-2023 10:45, David Heidelberg wrote: My goal was to drop the package for the Debian 12 (bookworm); it makes no sense to include the package and confuse users. However, I'll

Bug#1035748: unblock: modsecurity/3.0.9-1

2023-05-24 Thread Paul Gevers
control: tags -1 moreinfo Hi, On Mon, 08 May 2023 18:16:51 +0200 Alberto Gonzalez Iniesta wrote: A new upstream version of modsecurity fixes a security bug (CVE-2023-28882, #1035083). We also fixed a FTBFS in the meantime (#1034760). Also nginx moved to pcre2, which we also did after the curr

Bug#1036081: pre-unblock: mariadb/1:10.11.3-1

2023-05-24 Thread Paul Gevers
Control: tags -1 moreinfo confirmed Hi Otto, On 15-05-2023 07:55, Otto Kekäläinen wrote: This pre-unblock request is to get a decision from the Bookworm release team if you prefer to accept this 10.11.3 into Bookworm, or if you wish it to be postponed to a stable update in Bookworm some time la

Bug#1036081: pre-unblock: mariadb/1:10.11.3-1

2023-05-24 Thread Paul Gevers
Hi Otto, On 24-05-2023 17:44, Otto Kekäläinen wrote: The CI detected a couple days ago a regression in Piuparts, potentially due to recent adduser 1.133 upload, which I still need to debug and decide what to do on. You can ignore it. It's known and being worked on. Paul OpenPGP_signature De

Bug#1036474: unblock: debian-edu-fai/2023.05.16.1

2023-05-24 Thread Paul Gevers
control: tags -1 moreinfo Hi Mike, On 21-05-2023 21:38, Mike Gabriel wrote: In addition to the adduser changes, the diff to testing also includes a simple directory-exists test before writing to it. See below, I see more. Please elaborate. + * bin/debian-edu-faiinstall: Make sure FAI_CONFI

Re: tomcat9 should not be released with Bookworm

2023-05-26 Thread Paul Gevers
Control: clone -1 -2 -3 Control: reassign -2 release-notes Control: reassign -3 debian-security-support Control: tag -1 bookworm-ignore Hi, On 26-05-2023 00:10, Markus Koschany wrote: #1036250 is mainly a logback problem, not a tomcat problem. I still would like to hear Emmanuel's opinion. We s

Re: closure-compiler: #1036159

2023-05-26 Thread Paul Gevers
Hi Markus, On 25-05-2023 23:47, Markus Koschany wrote: Since I could not find a targeted fix I decided to remove the dependency on rhino 1.7.14 and embedded rhino 1.7.7.2 instead, the last version that worked well for closure-compiler. I have rebuilt all reverse-dependencies and this would re

Re: tomcat9 should not be released with Bookworm

2023-05-26 Thread Paul Gevers
Hi, On 26-05-2023 10:58, Moritz Muehlenhoff wrote: Can't we just do the pragmatic fix of updating src:tomcat9 to only ship libtomcat9-java and libtomcat9-embed-java? The maintenance burden for security updates lies within the server stack, the percentage of issues affecting the libtomcat9-java b

Re: Bug#1034824: tomcat9 should not be released with Bookworm

2023-05-26 Thread Paul Gevers
Hi, On 26-05-2023 21:34, Markus Koschany wrote: Do I understand you correctly, that we only ship libtomcat9-java in Bookworm now? Shall I upload a new revision of tomcat9 too? Yes and yes. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1036592: pre-approval: unblock: c-ares/1.18.1-3

2023-05-26 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi, On 23-05-2023 08:44, Gregor Jasny wrote: yesterday a version 1.19.1 of c-ares was release which fixes four CVEs. Please go ahead, taking into account that the build needs to be done before tomorrow 12:00 UTC. Remove the moreinfo tag once the upload hap

Re: Upcoming OpenSSL release

2023-05-27 Thread Paul Gevers
Hi, On 28-05-2023 07:21, Salvatore Bonaccorso wrote: On Sat, May 27, 2023 at 02:17:54PM +0200, Sebastian Andrzej Siewior wrote: For Bookworm I would much rather prefer to upload 3.0.9 to unstable and open a unblock bug for Bookworm. Looking at the history it contains 169 commits and only fixes

Bug#1035056: [pre-approval] plasma-desktop 5.27.X

2023-05-27 Thread Paul Gevers
Control: tags -1 confirmed moreinfo Hi all, [For those following at home, I had multiple live discussions with Aurélien at the Debian Reunion Hamburg.] On 27-05-2023 22:44, Aurélien COUDERC wrote: I don’t have particular bugs in mind, I think the selection that upstream makes of bugs that de

should the Release Notes be updated concerning bookworm security

2023-05-29 Thread Paul Gevers
Dear security team, I know it's a bit late, but are you aware of issues that are worth mentioning in the release notes from your point of view? We have updated the text about golang and rustc in this cycle, chromium got a mention about reduce support time wise and I updated the openjdk versi

Bug#1036957: unblock: openssl/3.0.8-1

2023-05-31 Thread Paul Gevers
Control: tags -1 d-i Hi kibi, Can you have a look at this onblock request? It's blocked on your block-udeb. Paul On 30-05-2023 22:52, Sebastian Andrzej Siewior wrote: control: retitle -1 unblock: openssl/3.0.9-1 On 2023-05-30 22:16:53 [+0200], To sub...@bugs.debian.org wrote: Please unbl

Bug#1036713: unblock: xserver-xorg-video-geode/2.11.21-1

2023-05-31 Thread Paul Gevers
control: tags -1 moreinfo On 24-05-2023 18:44, Martin-Éric Racine wrote: 1) Ensure build from source on recent autoconf. What does this mean? Does it now FTBFS? (I checked on reproducible builds, but that doesn't seem to be the case). Without an extremely good reason I'm currently not seein

Bug#1036885: unblock: hipsparse/5.3.3+dfsg-2

2023-05-31 Thread Paul Gevers
control: tags -1 moreinfo Hi Christian, On 31-05-2023 20:05, Christian Kastner wrote: I'm willing to do what it takes to get this fixed in testing, but I'm not sure which solution, if any, is agreeable to the RT: (6) Alternatives? Please upload hipsparse to tpu (targeting bookworm in the c

Bug#1035757: unblock: org-mode/9.5.2+dfsh-5

2023-06-01 Thread Paul Gevers
Dear David, On 20-05-2023 15:34, David Bremner wrote: I dove down this rabbit-hole a bit, not enough to figure the ultimate cause, but enough to notice these files are also because of "apt install systemd". So no related to org-mode. FWIW, systemd is pulled in by emacs-gtk. Earlier this week y

Bug#1032994: unblock: node-webpack/5.76.1+dfsg1+~cs17.16.16-1

2023-06-01 Thread Paul Gevers
control: tags -1 moreinfo Hi Yadd, On 29-05-2023 05:58, Yadd wrote: On 5/28/23 10:29, Graham Inggs wrote: On Wed, 3 May 2023 at 04:51, Yadd wrote: How about reverting and providing a fix only for that CVE please? instead of reverting and have a too long version (5.76.1+dfsg1+~cs17.16.16+r

Bug#1035757: unblock: org-mode/9.5.2+dfsh-5

2023-06-01 Thread Paul Gevers
Hi, On 01-06-2023 13:50, David Bremner wrote: Uploaded and built: And unblocked. Paul OpenPGP_signature Description: OpenPGP digital signature

Bug#1036081: unblock: mariadb/1:10.11.3-1

2023-06-01 Thread Paul Gevers
Dear Otto, While you may not agree with how the Release Team is managing the release process and with the guidelines that we have created to make that process manageable, we are delegated by the Debian Project Leader to do exactly that. I'm very disappointed to see that you keep on insisting

Bug#1035748: unblock: modsecurity/3.0.9-1

2023-06-01 Thread Paul Gevers
control: tags -1 moreinfo Hi, On 28-05-2023 21:30, Alberto Gonzalez Iniesta wrote: 2) The risks on the release quality are almost zero. Only libnginx-mod-http-modsecurity depends on it (being modsecurity a library). That's not the only part that we mean here. We also mean, how big is the ris

Bug#1035748: unblock: modsecurity/3.0.9-1

2023-06-02 Thread Paul Gevers
Hi, On 01-06-2023 22:39, Ervin Hegedüs wrote: sorry to join this conversation :), No, not at all. On Thu, Jun 01, 2023 at 09:52:06PM +0200, Paul Gevers wrote: I think there is absolutely no risk. Bot package (libmodsecurity3 and libnginx-mod-http-modsecurity) is totally new packages, we

Bug#1037024: nmu: modsecurity-apache_2.9.7-1

2023-06-02 Thread Paul Gevers
Hi Ervin, On 01-06-2023 22:54, Ervin Hegedüs wrote: Now the module complains during the startup process, and users wondering why. I wonder why too. What issues would this rebuild be papering over? Do you have a bug report number? Paul OpenPGP_signature Description: OpenPGP digital signatu

Bug#1037002: unblock: forensics-all/3.45

2023-06-02 Thread Paul Gevers
Control: tags -1 moreinfo Hi, On 31-05-2023 23:20, Joao Eriberto Mota Filho wrote: [ Reason ] forensics-all (like forensics-extra) is a metapackage to install several tools to aid in forensics activities. Due an issue in reaver (see #1036809), forensics-all is marked for autoremoval. Given th

preparing bookworm release message?

2023-06-04 Thread Paul Gevers
Hi, Our checklist [1] mentions to both notify you of the upcoming bookworm release next weekend (which I'm pretty sure doesn't come as a surprise) and to prepare the press release. I'm pretty sure that for the previous release (bullseye) the press release was prepared by your team, could you

Bug#1037263: unblock: php8.2/8.2.7-1

2023-06-09 Thread Paul Gevers
Hi Ondřej, On 09-06-2023 18:58, Ondřej Surý wrote: php8.2 8.2.7-1 is a security release, so it would be pretty wrong to release bookworm with the old PHP. I am sorry for the timing, but that's just coincidence. Sorry, but this is really about 1 week too late (we are in the quite periode to p

Bug#1031332: marked as done (transition: librnd)

2023-06-12 Thread Paul Gevers
control: reopen -1 Hi Bdale, On 12-06-2023 03:33, Debian Bug Tracking System wrote: > librnd (4.0.1-2) unstable; urgency=medium > . > * move new upstream version from experimental to unstable, > closes: #1031332, $1031445, #1031459 Please never close transition bugs in uploads. Transiti

Re: gcc-11: generate bad code for matplotlib with -O1/-O2 on mips64el

2023-06-20 Thread Paul Gevers
Hi YunQiang, mips porters, On 28-04-2023 15:51, YunQiang Su wrote: Paul Gevers 于2023年4月27日周四 04:26写道: On Fri, 24 Feb 2023 23:10:29 + James Addison wrote: Hi Frederic: I'm linking a forwarded GCC GNU bug report that I _think_ is the upstream report matching this bug. I found it f

Re: rust-base64 migration dependency adjustment

2023-06-20 Thread Paul Gevers
Hi Ian, On 21-06-2023 02:30, Ian Jackson wrote: Therefore I am tagging this bug trixie-ignore to avoid getting autoremoval warnings etc. As the rust-base64 migration seems to be just waiting (AFAIK at this moment) on rust-ruma-common autopkgtest-ing on ppc64el, I agree that this is OK. Pau

Bug#1038115: transition: gdal

2023-06-23 Thread Paul Gevers
Hi, On 23-06-2023 08:49, Sebastiaan Couwenberg wrote: To make the libgdal-grass autopkgtest pass it needs both gdal and libgdal-grass from unstable. I'll schedule it. I've scheduled jobs for this, but it seems britney ignores tests it hasn't scheduled itself. That's mostly correct as any a

Re: Bug#1038853: usrmerge: clean up the unused empty biarch directories

2023-06-24 Thread Paul Gevers
Hi Marco, On 22-06-2023 17:41, Marco d'Itri wrote: Release managers, I would like to upload to 12.1 a new package to fix this (and other minor issues). Please file a proper proposed-updates bug report as our workflow relies on them. Paul OpenPGP_signature Description: OpenPGP digital sign

Bug#1039870: release.debian.org: Help eccodes migrate to testing

2023-06-29 Thread Paul Gevers
Hi, On 29-06-2023 06:35, Bas Couwenberg wrote: Please help to remove these old binaries to unblock the testing migration of eccodes and its rdeps. I think we just need patience. The britney2 run of 4:00 UTC removed eccodes-python and that still (is now?) needs to be propagated to the mirror

Bug#803633: britney-tests-live-data/live-2012-05-09 fails randomly

2023-06-29 Thread Paul Gevers
Hi, On 26-01-2023 17:45, Paul Gevers wrote: On Sun, 01 Nov 2015 10:42:49 +0100 Emilio Pozuelo Monfort wrote: If run in a loop, live-2012-05-09 will eventually fail with: AssertionError: NUNINST OUT OF SYNC This issue was fixed in 2016 with this commit: https://salsa.debian.org/release

<    8   9   10   11   12   13   14   15   16   17   >