Bug#1014575: juce-modules-source: cmake error: missing /usr/lib/bin/JUCE-7.0.0/juce_lv2_helper

2022-07-07 Thread Andreas Beckmann
Package: juce-modules-source Version: 7.0.0~ds0-1 Severity: serious Control: affects -1 src:iem-plugin-suite Hi, iem-plugin-suite/experimental recently started to FTBFS with a cmake error pointing to juce: CMake Error at /usr/lib/x86_64-linux-gnu/cmake/JUCE-7.0.0/LV2_HELPER.cmake:79 (message):

Bug#1014574: sbuild-debian-developer-setup: Don't alias to sid/UNRELEASED if suite is not unstable

2022-07-07 Thread Ben Westover
Package: sbuild-debian-developer-setup Version: 0.83.1 Severity: normal Tags: upstream Dear Maintainer, sbuild-debian-developer-setup aliases all schroots to sid and UNRELEASED. This can cause unexpected problems when using a suite other than unstable. sbuild-debian-developer-setup should only al

Bug#1014573: sbuild-debian-developer-setup: Add option to use a specific mirror instead of apt-cacher-ng

2022-07-07 Thread Ben Westover
Package: sbuild-debian-developer-setup Version: 0.83.1 Severity: normal Tags: upstream Dear Maintainer, I was trying to create an Ubuntu schroot for sbuild using the command sbuild-debian-developer-setup --distribution=ubuntu --suite=jammy and debootstrap failed because it tried to use apt-ca

Bug#1014572: ITP: coq-simple-io -- Coq plugin for purely functional IO

2022-07-07 Thread Julien Puydt
Package: wnpp Severity: wishlist Owner: Julien Puydt X-Debbugs-Cc: Debian OCaml Maintainers , jpu...@debian.org * Package name: coq-simple-io Version : 1.7.0 Upstream Author : Li-yao Xia * URL : https://github.com/coq-community/coq-simple-io * License : Expat

Bug#919903: Package wxWidgets 3.1

2022-07-07 Thread Olly Betts
Control: reassign 919903 wnpp Control: retitle 919903 ITP: wxwidgets3.2 -- wxWidgets Cross-platform C++ GUI toolkit Control: owner 919903 s...@techie.net wxWidgets 3.1 has finally evolved into the stable wxWidgets 3.2.0 release. Scott Talbert is already working on packaging it, so converting th

Bug#1014571: bullseye-pu: package node-log4js/6.3.0+~cs8.3.10-1+deb11u1

2022-07-07 Thread Yadd
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu [ Reason ] node-log4js creates log files with permissive rights (644). This causes a security issue (CVE-2022-21704) [ Impact ] Medium vulnerability [ Tests ] Test passed [ Risk

Bug#1014570: RM: rocm-device-libs/experimental [all] -- ROM; the binary packages are arch-dependent now

2022-07-07 Thread M. Zhou
Package: ftp.debian.org Severity: normal The latest rocm-device-libs package is no longer producing arch-indep binary packages. And we will keep working on arch-specific packages. The arch:all package is no longer useful and it was not automatically removed. Thank you for using reportbug

Bug#1014569: transition: flatbuffers

2022-07-07 Thread M. Zhou
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition PyTorch 1.12 will need flatbuffers 2.X . Specifically I'm going to upload flatbuffers 2.0.6+dfsg1 to unstable. It has three reverse dependencies as per build-rdeps. vast [already ftbfs d

Bug#1013245: RFS: flask-session/0.3.2-1 [ITP] -- Extension for Flask

2022-07-07 Thread Nilson Silva
Hello Bastian! I'm not allowed to create repository in Team python. Unless you grant me. Nilson F. Silva 81-3036-0200 81-991616348 81-98546-9553 De: Bastian Germann Enviado: quinta-feira, 7 de julho de 2022 18:18 Para: 1013...@bugs.debian.org <1013...@bugs.

Bug#1014568: spdlog: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: spdlog Version: 1:1.9.2+ds-0.2 Severity: important X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from /<>/include/spdlog/fmt/fmt.h:25, fro

Bug#1014567: Please ship instructions on how to use this package (and/or sysroot symlinks)

2022-07-07 Thread Faidon Liambotis
On Fri, Jul 08, 2022 at 03:19:03AM +0300, Faidon Liambotis wrote: > It'd be great if the package shipped with such a symlink structure, > and/or came with instructions on how one can use this package (either > with this structure, or, if possible, without). Upon further research, I found the follo

Bug#1014052: ibus:After rebooted, I must do `ibus-daemon -rxd` change japanese to anthy with kanji key.

2022-07-07 Thread Yukiharu YABUKI
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, How I do check where started ibus read the ibus configration? I did setup with im-config for ibus. It seems to me that ibus-daemon re-read my home configration. On Thu, 7 Jul 2022 21:51:23 +0200 Gunnar Hjalmarsson wrote: > Control: tags -1

Bug#743694: lintian: Downgrade most of privacy-breach* tags from severity: error to pedantic

2022-07-07 Thread Axel Beckert
Control: tag -1 wishlist Control: tag -1 + wontfix Hi, Paul Wise wrote on 11. Sep. 2021: > I think that the privacy breaches that lintian complains about > represent several sets of bugs that all need fixing: I strongly agree with pabs and his (no more copied) explanations and reasoning. These a

Bug#1014567: Please ship instructions on how to use this package (and/or sysroot symlinks)

2022-07-07 Thread Faidon Liambotis
Package: wasi-libc Version: 0.0~git20210922.ad51334-1 Severity: normal Thank you for maintaining wasi-libc! I am trying to use Debian's clang + wasi-libc to compile a C program into a WASM WASI binary. I am struggling to understand how to exactly use wasi-libc. Most instructions on the web assume

Bug#1014566: massivethreads: FTBFS with glibc 2.34

2022-07-07 Thread Steve Langasek
Package: massivethreads Version: 1.00-4 Severity: serious Tags: patch experimental Justification: FTBFS User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic ubuntu-patch Dear maintainer, In Ubuntu the massivethreads package FTBFS because Ubuntu has moved to glibc 2.34 which include

Bug#1014156: lintian: very-long-line-length-in-source-file for non-text source files

2022-07-07 Thread Axel Beckert
Hi Peter, Peter B wrote: > > The suffix "icns" is already in the blacklist since 2.115.2. With > > which version of Lintian did you generate that list? > > I use Testing, so it was 2.115.1  It is indeed fixed in 2.115.2 Yay! Thanks for the reply. :-) > Trying on duma, I got several hits on bina

Bug#1014565: lvm2: Please reorder "systemd | systemd-tmpfiles" dependency

2022-07-07 Thread GSR
Package: lvm2 Version: 2.03.15-2 Severity: normal Hello: Thanks for supporting other inits, IMO it would be even better if the Depency would be swapped. Those with systemd should see no change, but the rest will have to install before (or at the same time) the systemd-standalone-tmpfiles package

Bug#1010932: wasm-ld-13: unable to find library -lgcc

2022-07-07 Thread Faidon Liambotis
Hi Jérémy, On Sat, May 14, 2022 at 02:44:25PM +0200, Jérémy Lal wrote: > > Addendum: > > "/usr/bin/wasm-ld-13" -m wasm32 -L/usr/lib/wasm32-wasi > > /usr/lib/wasm32-wasi/crt1-reactor.o --entry _initialize -error-limit=0 -O3 > > --lto-O3 --strip-all --allow-undefined --export-dynamic --export-table

Bug#1014564: tvtime: reproducible-builds: embedded build paths in /usr/bin/tvtime

2022-07-07 Thread Vagrant Cascadian
Source: tvtime Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: buildpath X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build path is embedded in /usr/bin/tvtime: https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/diffoscope

Bug#934151: RFS: python-tuf -- plug-and-play library for securing a software updater

2022-07-07 Thread Bastian Germann
On Tue, 20 Apr 2021 22:52:32 +0200 Philippe Coval wrote: https://salsa.debian.org/python-team/packages/tuf It's lintian clean and autopkgtest are enabled for CI/CD Is anyone able to upload it to archive in unstable branch ? Yare you up for a 2nd try? I can sponsor this if you are.

Bug#1013161: lua-lpeg missing 5.4 build crashes corsix-th

2022-07-07 Thread Phil Morrell
Control: clone -1 -2 Control: reassign -2 lua-lpeg Control: retitle -2 lua-lpeg: please build for lua 5.4 Control: severity -2 wishlist Control: block -1 by -2 Firstly my apologies to players of corsix-th in Debian and derivatives for not properly testing the latest upload. lua-lpeg was last updat

Bug#1014562: ITP: pook -- HTTP traffic mocking and testing made easy

2022-07-07 Thread Guilherme de Paula Xavier Segundo
Package: wnpp Severity: wishlist Owner: Guilherme de Paula Xavier Segundo X-Debbugs-Cc: debian-de...@lists.debian.org, guilherme@gmail.com * Package name: pook Version : 1.0.2 Upstream Author : Tomas Aparicio * URL : https://github.com/h2non/pook * License

Bug#1013958: more info

2022-07-07 Thread Chris Waters
I have learned more about this. It turns out that it only happens if the user has not set the xfce default browser app! Without a user-set default, exo-open defaults to using x-www-browser, but xfce4-terminal's context menu prefers chromium! Once a user setting _exists_, the context menu happily u

Bug#1014561: clp: reproducible-builds: Embedded build path in example Makefile

2022-07-07 Thread Vagrant Cascadian
Source: clp Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: buildpath X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build path is embedded in usr/share/doc/coinor-libclp-doc/examples/Makefile.gz: https://tests.reproducible-builds.org/debia

Bug#1014560: ygl: reproducible-builds: embedded build paths in libYgl.so.*

2022-07-07 Thread Vagrant Cascadian
Source: ygl Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: buildpath X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build path is embedded in ./usr/lib/libYgl.so.4.2: https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/diffo

Bug#1014551: [Pkg-nagios-devel] Bug#1014551: icinga2: check_apt not working if both master and host are running 2.13.4-1

2022-07-07 Thread Jim Penny
Yes, that does resolve the issue. Thank you very much for your prompt help. jim From: Sebastiaan Couwenberg Sent: Thursday, July 7, 2022 5:17 PM To: Jim Penny ; 1014...@bugs.debian.org <1014...@bugs.debian.org> Subject: Re: [Pkg-nagios-devel] Bug#1014551: icing

Bug#1014551: [Pkg-nagios-devel] Bug#1014551: icinga2: check_apt not working if both master and host are running 2.13.4-1

2022-07-07 Thread Sebastiaan Couwenberg
On 7/7/22 22:18, Jim Penny wrote: Services.conf has this stanza. apply Service "apt" { check_command = "apt" vars.apt_upgrade = false command_endpoint = host.vars.client_endpoint assign where host.vars.do_apt } vars.apt_upgrade passes the false argument along to check_apt. What se

Bug#1013245: RFS: flask-session/0.3.2-1 [ITP] -- Extension for Flask

2022-07-07 Thread Bastian Germann
On Sun, 19 Jun 2022 21:20:05 + Nilson Silva wrote: Alternatively, you can download the package with 'dget' using this command: dget -x https://mentors.debian.net/debian/pool/main/f/flask-session/flask-session_0.3.2-1.dsc git -x https://salsa.debian.org/nilsonfsilva/flask-session Th

Bug#1014559: libloki: reproducible-builds: embedded build paths in libloki.so.*

2022-07-07 Thread Vagrant Cascadian
Source: libloki Severity: normal Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: buildpath X-Debbugs-Cc: reproducible-b...@lists.alioth.debian.org The build path is embedded in /usr/lib/libloki.so.0.1.7: https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64

Bug#444589: strftime(%Y) overflows into the negatives for very positive years

2022-07-07 Thread наб
In my haste I forgot to note, that, unsurprisingly, the same holds for %G and %C: -- >8 -- $ TZ=UTC0 ./a.out '%F %G %C %s' 67768036191676799 -2147481749-12-31 -2147481748 -21474818 67768036191676799 -- >8 -- наб signature.asc Description: PGP signature

Bug#444589: strftime(%Y) overflows into the negatives for very positive years: the most positive and the most negative times are 1 second apart

2022-07-07 Thread наб
Control: retitle -1 strftime(%Y) overflows into the negatives for very positive years Control: found -1 2.33-7 Under TZ=UTC0, the most positive and most negative times glibc accepts (i.e. "doesn't NULL, EOVERFLOW for") are 67768036191676799 (0x00F0C2AB7C54A97F) -67768040609740800 (0xFF0F3D53

Bug#1014551: [Pkg-nagios-devel] Bug#1014551: icinga2: check_apt not working if both master and host are running 2.13.4-1

2022-07-07 Thread Jim Penny
Services.conf has this stanza. apply Service "apt" { check_command = "apt" vars.apt_upgrade = false command_endpoint = host.vars.client_endpoint assign where host.vars.do_apt } A typical barely sanitized entry in hosts.conf doing the apt check is: object Host ".example.com" { che

Bug#839961: libjs-d3: please package new upstream release

2022-07-07 Thread Paul Gevers
Hi, On Mon, 11 Apr 2022 21:50:47 +0200 Paul Gevers wrote: I just spotted the node-d3 package. Has that solved all the issues and can that be considered the replacement of this package? If so, should libjs-d3 be removed from Debian? I have just uploaded the last node-d3-* package that had a

Bug#1014558: ITP: python-duo-client -- Interact with the Duo Auth, Admin, and Accounts APIs

2022-07-07 Thread Michael Fladischer
Package: wnpp Severity: wishlist Owner: Michael Fladischer X-Debbugs-Cc: debian-de...@lists.debian.org -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: python-duo-client Version : 4.4.0 Upstream Author : Duo Security, Inc. * URL : https://github.com/du

Bug#1014557: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: mkvtoolnix Version: 68.0.0-1 Severity: important X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from /usr/include/fmt/format.h:48, from src

Bug#1014052: ibus:After rebooted, I must do `ibus-daemon -rxd` change japanese to anthy with kanji key.

2022-07-07 Thread Gunnar Hjalmarsson
Control: tags -1 - moreinfo Thanks for additional info, Yukiharu YABUKI. Unfortunately it didn't bring us closer to an explanation, since /usr/bin/ibus-daemon --daemonize --xim is basically the same as ibus-daemon -xrd On 2022-07-07 02:49, Osamu Aoki wrote: As you know, recent Debian syste

Bug#1014556: firefox-esr: FTBFS on mipsel ("terminate called after throwing an instance of 'std::bad_alloc'")

2022-07-07 Thread Adam D. Barratt
Source: firefox-esr Version: 91.0esr-1 Severity: serious Tags: ftbfs Control: found -1 91.9.0esr-1~deb11u1 Hi, firefox-esr fails to build on mipsel for some time now. The exact module generating the issue seems to vary, but the general pattern is always: terminate called after throwing an inst

Bug#1014554: Please update speex to 1.2.1 in Debian unstable

2022-07-07 Thread Amr Ibrahim
Package: speex Hello, Please update speex to 1.2.1 in Debian unstable. https://gitlab.xiph.org/xiph/speex/-/releases And please update the watch file. Best, Amr

Bug#1014555: Please update speexdsp to 1.2.1 in Debian unstable

2022-07-07 Thread Amr Ibrahim
Package: speexdsp Hello, Please update speexdsp to 1.2.1 in Debian unstable. https://gitlab.xiph.org/xiph/speexdsp/-/releases And please update the watch file. Best, Amr

Bug#935336: fixed in commons-daemon 1.0.15-9

2022-07-07 Thread Chris Hofstaedtler
Hello tony, >* Add patch to locate recent JDKs (Closes: #935336) Thanks for applying this patch, however it does not seem to work: | % jsvc -debug foo [..] | Attempting to locate Java Home in /usr/lib/jvm/default-java | Attempting to locate VM configuration file /usr/lib/jvm/default-java/jr

Bug#1014551: [Pkg-nagios-devel] Bug#1014551: icinga2: check_apt not working if both master and host are running 2.13.4-1

2022-07-07 Thread Sebastiaan Couwenberg
Control: tags -1 moreinfo On 7/7/22 20:37, Jim Penny wrote: It works with master on 2.13.4-1 and hosts on 2.13.3-1+b2. If both are on 2.13.4-1, icinga2-web reports "'/usr/bin/apt-get false upgrade' exited with non-zero status.". How do you execute check_apt on the hosts? Do you use the icin

Bug#1014553: python3-tk: tkinter core dump crash creating a Label with some Noto fonts

2022-07-07 Thread Akkana Peck
Package: python3-tk Version: 3.10.5-1 Severity: normal X-Debbugs-Cc: d...@shallowsky.com Dear Maintainer, When creating a Tk label with: label = Label(frame, text=item, font=(item, 70)).pack() Tk will dump core if the font is various Noto fonts, including (but not limited to): 'Noto Kufi

Bug#1014552: libsass: symbols file differences when building with -O3

2022-07-07 Thread Steve Langasek
Package: libsass Version: 3.6.5+20211226-1 Severity: normal Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic ubuntu-patch Dear maintainers, The libsass package is failing to build from source on ppc64el in Ubuntu because unlike Debian, in Ubuntu this port is built w

Bug#1014551: icinga2: check_apt not working if both master and host are running 2.13.4-1

2022-07-07 Thread Jim Penny
Package: icinga2 Version: 2.13.4-1 Severity: normal It works with master on 2.13.4-1 and hosts on 2.13.3-1+b2. If both are on 2.13.4-1, icinga2-web reports "'/usr/bin/apt-get false upgrade' exited with non-zero status.". -- System Information: Debian Release: bookworm/sid APT prefers oldol

Bug#934474: package assignment

2022-07-07 Thread Detlef Eppers
I can confirm this issue. Should this be reassigned to apt package? Best regards Detlef

Bug#1014550: claws-mail: Please drop 11mark_trashed_as_read.patch

2022-07-07 Thread David (Plasma) Paul
Source: claws-mail Version: 4.1.0-2 Severity: wishlist Dear Maintainer, Please consider dropping 11mark_trashed_as_read.patch from the set of Debian patches for claws-mail. Whether the 'marked trashed as read' functionality is desirable is, of course, a matter of taste, but I personally would pre

Bug#1014455: systemd-boot: kernel postrm hook runs twice on purge

2022-07-07 Thread Michael Biebl
Am 07.07.22 um 19:02 schrieb Andrea Pappacoda: Il giorno mer 6 lug 2022 alle 14:48:21 +02:00:00, Michael Biebl ha scritto: See https://salsa.debian.org/systemd-team/systemd/-/merge_requests/155 I know about that merge request, I'm the one who submitted it :) Sure, I know that :-) I posted t

Bug#1014533: php8.1: CVE-2022-31625 CVE-2022-31626

2022-07-07 Thread Moritz Muehlenhoff
Hi Ondřej, On Thu, Jul 07, 2022 at 05:57:24PM +0200, Ondřej Surý wrote: > Hi, > > thanks for the poke. > > Would it be also ok to do the php7.4 via bullseye-security or do you > want me specifically to do the stable-updates? The two issues are not the most severe, but we can do a DSA. I'll look

Bug#1014447: bullseye-pu: package lwip/2.1.2+dfsg1-8

2022-07-07 Thread Joan Lledó
Package: release.debian.org Severity: important Tags: bullseye User: release.debian@packages.debian.org Usertags: pu Hi, This patch fixes CVE-2020-22283 and CVE-2020-22284 in bullseye. Attached is the debdiff. [1] https://security-tracker.debian.org/tracker/CVE-2020-22283 [2] https://sec

Bug#1014549: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: ceph Version: 16.2.7+ds-4 Severity: important X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from /usr/include/fmt/format.h:48, from /usr/i

Bug#1014548: tiledarray build-depends on non-existent libbtas-dev

2022-07-07 Thread Steve Langasek
Source: tiledarray Version: 1.0.0-1 Severity: serious User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic Hi Michael, tiledarray in unstable has added a build-dependency on libbtas-dev. However, this package does not exist anywhere in Debian and there is no sign of it in the NEW

Bug#1014547: mlucas: FTBFS on arm* because of wrong fopen()

2022-07-07 Thread Steve Langasek
Package: mlucas Version: 20.1.1-1 Severity: serious Tags: patch User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic ubuntu-patch Hi Alex, The new version of mlucas in unstable is failing to build on arm* architectures where it previously built, because upstream has introduced some

Bug#1014546: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: restinio Version: 0.6.13-1 Severity: important X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from /usr/include/fmt/format.h:48, from /<>/d

Bug#1014545: Please update fontconfig to 2.14.0 in Debian unstable

2022-07-07 Thread Amr Ibrahim
Package: fontconfig Hello, Please update fontconfig to 2.14.0 in Debian unstable. https://gitlab.freedesktop.org/fontconfig/fontconfig Best, Amr

Bug#1014544: Please update privacybadger to 2021.11.23.1 in Debian unstable

2022-07-07 Thread Amr Ibrahim
Package: privacybadger Hello, Please update privacybadger to 2021.11.23.1 in Debian unstable. https://github.com/EFForg/privacybadger/releases Best, Amr

Bug#1014542: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Vasyl Gello
Hi! Thanks for the report! I wonder how did you get past ffmpeg 5.0 build failures to reach this point. Anyway, I will deal with that PR after it gets merged upstream and we altogether solve the total mess introduced by ffmpeg 5.0 breaking changes. --  Vasyl Gello

Bug#1014543: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: mpd Version: 0.23.6-1 Severity: important X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from ../src/LogBackend.cxx:21: ../src/Log.hxx: In function ‘void Lo

Bug#1014542: FTBFS with fmtlib 9.0.0

2022-07-07 Thread Shengjing Zhu
Source: kodi Version: 2:19.4+dfsg2-2 Severity: important Forwarded: https://github.com/xbmc/xbmc/pull/21649 X-Debbugs-Cc: z...@debian.org Hi, I have uploaded fmtlib 9.0.0 to experimental. During rebuild the reverse dependencies, your package FTBFS. Some relevant logs: In file included from /us

Bug#1006179: clamav: please package 0.104.2

2022-07-07 Thread Martin-Éric Racine
Package: clamav-freshclam Version: 0.103.6+dfsg-0+deb11u1 Followup-For: Bug #1006179 -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Since the above bug report was filed, upstream has moved up to 0.105.0, while Debian is still at 0.103.6, so I was wondering what is going on? Martin-Éric -B

Bug#1014541: python-django: CVE-2022-34265

2022-07-07 Thread Chris Lamb
Package: python-django Version: 1:1.10.7-2+deb9u17 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for python-django. CVE-2022-34265 [0]: | An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before | 4.0.6. The Trunc()

Bug#1014533: php8.1: CVE-2022-31625 CVE-2022-31626

2022-07-07 Thread Ondřej Surý
Hi, thanks for the poke. Would it be also ok to do the php7.4 via bullseye-security or do you want me specifically to do the stable-updates? Ondrej -- Ondřej Surý (He/Him) ond...@sury.org > On 7. 7. 2022, at 17:42, Moritz Mühlenhoff wrote: > > Source: php8.1 > X-Debbugs-CC: t...@security.debi

Bug#1014540: node-mermaid: CVE-2022-31108

2022-07-07 Thread Moritz Mühlenhoff
Source: node-mermaid X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for node-mermaid. CVE-2022-31108[0]: | Mermaid is a JavaScript based diagramming and charting tool that uses | Markdown-inspired text definitions and a ren

Bug#1014539: squirrel3: CVE-2022-30292

2022-07-07 Thread Moritz Mühlenhoff
Source: squirrel3 X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for squirrel3. CVE-2022-30292[0]: | Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to | lack of a certain sq_reservestack call. https://github.c

Bug#1014538: fuse-exfat: CVE-2022-29973

2022-07-07 Thread Moritz Mühlenhoff
Source: fuse-exfat X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for fuse-exfat. CVE-2022-29973[0]: | relan exFAT 1.3.0 allows local users to obtain sensitive information | (data from deleted files in the filesystem) in ce

Bug#1014537: unnamed packaging files in a multibinary package should be an error

2022-07-07 Thread Steve Langasek
Package: debhelper Version: 13.8 Severity: wishlist User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu kinetic Hi Niels, I was recently doing work on a package where, for $reasons, I was deleting a binary package from debian/control. This had very bad side effects, because the debian/ d

Bug#1014536: manpages: Hardware capabilities section would need updating to latest glibc

2022-07-07 Thread Mathieu Malaterre
Package: manpages Version: 5.10-1 Severity: normal Dear Maintainer, Currently the manpage for ld.so contains some of the magic strings for proper subfolder names. However this list does not seems to reflect the current glibc (bullseye system) release. Typically: % sudo ldconfig -p | grep hwcap

Bug#1014535: ITP: advene -- Annotate Digital Videos, Exchange on the NEt

2022-07-07 Thread Olivier Aubert
Package: wnpp Severity: wishlist Owner: Olivier Aubert X-Debbugs-Cc: debian-de...@lists.debian.org, cont...@olivieraubert.net * Package name: advene Version : 3.13 Upstream Author : Olivier Aubert * URL : https://www.advene.org/ * License : GPL Programming L

Bug#1014534: dlt-daemon: CVE-2022-31291

2022-07-07 Thread Moritz Mühlenhoff
Source: dlt-daemon X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for dlt-daemon. CVE-2022-31291[0]: | An issue in dlt_config_file_parser.c of dlt-daemon v2.18.8 allows | attackers to cause a double free via crafted TCP packets

Bug#1014533: php8.1: CVE-2022-31625 CVE-2022-31626

2022-07-07 Thread Moritz Mühlenhoff
Source: php8.1 X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for php8.1. CVE-2022-31625[0]: | In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x | below 8.1.7, when using Postgres database extension, supp

Bug#1014532: libstb: CVE-2021-42715 CVE-2021-42716

2022-07-07 Thread Moritz Mühlenhoff
Source: libstb X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for libstb. CVE-2021-42715[0]: | An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR | loader parsed truncated end-of-file RLE scanlines as

Bug#1014530: libstb: CVE-2021-28021

2022-07-07 Thread Moritz Mühlenhoff
Source: libstb X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for libstb. CVE-2021-28021[0]: | Buffer overflow vulnerability in function stbi__extend_receive in | stb_image.h in stb 2.26 via a crafted JPEG file. https://gi

Bug#1014531: libstb: CVE-2022-28041 CVE-2022-28042

2022-07-07 Thread Moritz Mühlenhoff
Source: libstb X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerabilities were published for libstb. CVE-2022-28041[0]: | stb_image.h v2.27 was discovered to contain an integer overflow via | the function stbi__jpeg_decode_block_prog_dc. This vuln

Bug#1014529: u-boot: CVE-2022-34835

2022-07-07 Thread Moritz Mühlenhoff
Source: u-boot X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for u-boot. CVE-2022-34835[0]: | In Das U-Boot through 2022.07-rc5, an integer signedness error and | resultant stack-based buffer overflow in the "i2c md" comma

Bug#1014527: libsixel: CVE-2022-29978

2022-07-07 Thread Moritz Mühlenhoff
Source: libsixel X-Debbugs-CC: t...@security.debian.org Severity: normal Tags: security Hi, The following vulnerability was published for libsixel. CVE-2022-29978[0]: | There is a floating point exception error in sixel_encoder_do_resize, | encoder.c:633 in libsixel img2sixel 1.8.6. Remote attac

Bug#1014526: libsixel: CVE-2022-29977

2022-07-07 Thread Moritz Mühlenhoff
Source: libsixel X-Debbugs-CC: t...@security.debian.org Severity: normal Tags: security Hi, The following vulnerability was published for libsixel. CVE-2022-29977[0]: | There is an assertion failure error in stbi__jpeg_huff_decode, | stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers

Bug#1014528: u-boot: CVE-2022-33103

2022-07-07 Thread Moritz Mühlenhoff
Source: u-boot X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for u-boot. CVE-2022-33103[0]: | Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an | out-of-bounds write via the function sqfs_readdir(). ht

Bug#1014524: mutt: Mutt depends on moreutils package, but, it is not listed on dependencies, nor suggestions

2022-07-07 Thread Marcelo Laia
Package: mutt Version: 2.2.4-1+b1 Severity: normal Dear Maintainer, Mutt depends on moreutils package, but, it is not listed on dependencies, nor suggestions. I see that pee is necessary to open html messages. With out moreutils package, when I try to open a html messages, it shows: sh: 1: pee

Bug#1014523: strawberry: Fails to index a few songs

2022-07-07 Thread Alberto Fuentes
Package: strawberry Version: 1.0.5-1 Severity: normal X-Debbugs-Cc: paj...@gmail.com Dear Maintainer, When i try to index my music collection i get this error Unable to execute SQL query: NOT NULL constraint failed: songs.ctime Unable to fetch rowFailed query: INSERT INTO songs (title, album, ar

Bug#1011033: onnx: flaky autopkgtest on armhf: Arrays are not almost equal to 7 decimals

2022-07-07 Thread M. Zhou
Control: severity -1 important I've uploaded 1.12 to unstable. Let's see whether the situation has been changed a little bit for armhf. Floating point precision is sometimes flaky indeed, but I think this would not be that fatal. So changing the severity down to important. If the flaky test no l

Bug#1014521: ITP: displaycal -- Graphical user interface for the Argyll CMS

2022-07-07 Thread Christian Marillat
Package: wnpp Severity: wishlist Owner: Christian Marillat X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: displaycal Version : 3.9.6 Upstream Author : Erkan Ozgur Yilmaz * URL : https://github.com/eoyilmaz/displaycal-py3/ * License : GPL-3 Progra

Bug#993796: bullseye-pu: package knot-resolver/5.3.1-1

2022-07-07 Thread Jakub Ružička
On 7/1/22 19:57, Adam D. Barratt wrote: On Fri, 2021-12-03 at 16:59 +0100, Julien Cristau wrote: Control: tag -1 confirmed On Mon, Sep 06, 2021 at 04:21:15PM +, Jakub Ružička wrote: [ Reason ] Fixing bug #991463 (CVE-2021-40083) - potential DoS. [...] Feel free to go ahead and upload, th

Bug#980746: remove ath9k_htc, provided by libre package firmware-ath9k-htc

2022-07-07 Thread Bastian Germann
On Sat, 23 Jan 2021 16:49:09 -0500 John Scott wrote: Here's a patch for the removal from non-free firmware-atheros. In the firmware-ath9k-htc package the files are named differently: /lib/firmware/ath9k_htc/htc_9271-1.dev.0.fw /lib/firmware/ath9k_htc/htc_9271-1.dev.0.fw Does the kernel know a

Bug#993613: lintian: Complex regular subexpression recursion limit exceeded in cruft check

2022-07-07 Thread Lucas Nussbaum
Hi, This still affects v2.115.2. $ lintian r-cran-swagger_3.33.1-1.dsc Warning in processable r-cran-swagger_3.33.1-1.dsc: Complex regular subexpression recursion limit (65534) exceeded at /usr/share/lintian/lib/Lintian/Check/Cruft.pm line 449. Warning in processable r-cran-swagger_3.33.1-1.dsc

Bug#1014519: RFA: python-canmatrix -- Handle CAN (Controller Area Network) database formats

2022-07-07 Thread Debian/GNU
Package: wnpp Severity: normal Control: affects -1 src:python-canmatrix I request an adopter for the python-canmatrix package. Back in the days I was involved in some automotive projects, which lead me into packaging 'python-can' and 'python-canmatrix' (Python modules dealing with the "Controller

Bug#1014517: apt - Fails in FIPS mode in libgcrypt

2022-07-07 Thread Bastian Blank
Package: apt Version: 2.5.1 Severity: normal "apt update" fails if the system runs in FIPS mode: | # apt update | Hit:2 http://deb.debian.org/debian-debug sid InRelease | fatal error in libgcrypt, file ../../src/misc.c, line 92, function _gcry_fatal_error: requested algo not in md context | | F

Bug#1014518: RFA: python-can -- Controller Area Network (CAN) interface module - Python modules

2022-07-07 Thread Debian/GNU
Package: wnpp Severity: normal Control: affects -1 src:python-can I request an adopter for the python-can package. Back in the days I was involved in some automotive projects, which lead me into packaging 'python-can' and 'python-canmatrix' (Python modules dealing with the "Controller Area Networ

Bug#878091: jq: accepts invalid JSON

2022-07-07 Thread Thorsten Glaser
Package: jq Version: 1.6-2.1 Followup-For: Bug #878091 X-Debbugs-Cc: t...@mirbsd.de Still pertinent in latest version: $ echo '[.1,0.2]' | jq -c . [0.1,0.2] -- System Information: Debian Release: 11.3 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'),

Bug#878091: jq: accepts invalid JSON

2022-07-07 Thread Thorsten Glaser
Package: jq Version: 1.5+dfsg-2+b1 Followup-For: Bug #878091 Same: $ echo '[.1,0.2]' | jq -c . [0.1,0.2] With no flag to turn this off, I’d almost consider this serious. -- System Information: Debian Release: 10.12 APT prefers oldstable-updates APT policy: (500, 'oldstable-updates'), (500,

Bug#1004626: forked-daapd: FTBFS with ffmpeg 5.0

2022-07-07 Thread Diederik de Haas
Control: tag -1 fixed-upstream On 30 Jan 2022 22:48:11 +0100 Sebastian Ramacher wrote: > Source: forked-daapd > Version: 26.4+dfsg1-2 > Tags: sid bookworm ftbfs > Usertags: ffmpeg5.0 > > forked-daapd FTBFS with ffmpeg 5.0 (in experimental): It is fixed upstream in the following commit which is

Bug#1014515: installation-reports: bookworm/testing installer can't create RAID 10; libsystemd.so.0 not found

2022-07-07 Thread Steve Newcomb
package: installation-reports Subject: installation-reports: bookworm/testing installer can't create RAID 10; libsystemd.so.0 not found Package: installation-reports Severity: important Tags: d-i -- Package-specific info: Boot method: usb stick Image version: downloaded testing/bookworm ins

Bug#1014080: zutty: crashes on startup

2022-07-07 Thread David Bremner
Ricardo Mones writes: > > Indeed, seems something specific, had never seen a similar error. A list > of questions which I think would be useful to know before forwarding this > upstream: > > • What GPU and drivers are you using? It's an amd RV710 using the "radeon" driver. > • What OpenGL ver

Bug#1008992: xwayland: all X clients hang indefinitely waiting for /tmp/.X11-unix/X0

2022-07-07 Thread Paul Cercueil
Le mer., juil. 6 2022 at 18:56:47 +0200, Michel Dänzer a écrit : On 2022-07-06 18:00, Paul Cercueil wrote: Le mer., juil. 6 2022 at 16:44:46 +0200, Michel Dänzer a écrit : On 2022-07-06 14:33, Paul Cercueil wrote: I don't see it even trying to open the socket… I think Olivier Fou

Bug#1014354: depmod: WARNING: could not open modules.builtin.modinfo

2022-07-07 Thread Michael Biebl
On Tue, 5 Jul 2022 04:37:25 +0200 Marco d'Itri wrote: On Jul 04, Sebastien KALT wrote: > Since update to kmod version 30+20220630-1, I have this warning when launching > (via apt upgrade or manually) : #1014319 actually. It's harmless. Well, not quite. It breaks initramfs-tools' autopkgtest,

Bug#1014319: depmod: WARNING: could not open modules.builtin.modinfo at /var/tmp/mkinitramfs_vBlw4a/lib/modules/5.18.0-2-amd64: No such file or directory

2022-07-07 Thread Michael Biebl
Control: severity -1 important On Mon, 04 Jul 2022 15:01:13 +1000 Konomi Kitten wrote: Package: initramfs-tools Version: 0.141 Severity: minor X-Debbugs-Cc: konomikit...@gmail.com When update-initramfs runs I receive the following message: depmod: WARNING: could not open modules.builtin.mod

Bug#1014513: ITP: pdb-tools -- tools for manipulating and editing PDB files

2022-07-07 Thread Andrius Merkys
Package: wnpp Owner: Andrius Merkys Severity: wishlist Control: block 1014457 by -1 * Package name: pdb-tools Version : 2.5.0 Upstream Author : João Pedro Rodrigues * URL : https://www.bonvinlab.org/pdb-tools/ * License : Apache-2.0 Programming Lang: Python

Bug#1014277: dhcpcd5: dhcpcd fails to chroot and set PID file on startup, systemd eventually kills it after timeout

2022-07-07 Thread Martin-Éric Racine
On Thu, Jul 7, 2022 at 1:40 AM Tobias Klausmann wrote: > On Wed, 06 Jul 2022, Martin-Éric Racine wrote: > > Does the fix suggested by János in response to your bug report restore > > normal operation? > > Yes that seems to do the trick > > Specifically, in /usr/lib/systemd/system/dhcpcd.service >

Bug#1014512: freeipa: FTBFS: AttributeError: module 'collections' has no attribute 'Iterable'

2022-07-07 Thread Andreas Beckmann
Package: freeipa Version: 4.9.8-1+exp1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) Hi, freeipa recently started to FTBFS in experimental (but not in sid) after some (transitive) build dependency got upgraded: ... Making all in css

Bug#1014511: sysvinit: debian/copyright reports incorrect licenses

2022-07-07 Thread Axel Beckert
Hi, binh1.tran...@toshiba.co.jp wrote: > Issue 1: The original debian/copyright reports incorrect licenses in > the most files from debian/ folder as below: > > Files: debian/* > License: GPL-2+ > Copyright: 2015 Adam Conrad >2018 Dmitry Bogatov >...

Bug#1014511: sysvinit: debian/copyright reports incorrect licenses

2022-07-07 Thread binh1.tranhai
Package: sysvinit Version: 3.03-1 Severity: Normal Hello Maintainers, In the original debian/copyright file , I found some issues: Issue 1: The original debian/copyright reports incorrect licenses in the most files from debian/ folder as below: Files: debian/* License: GPL-2+ Copyr

Bug#1014509: apt install lets me fill the filesystem

2022-07-07 Thread Julian Andres Klode
On Thu, Jul 07, 2022 at 11:30:54AM +0200, intrigeri wrote: > Package: apt > Version: 2.5.1 > Severity: wishlist > > Hi, > > On a system with a very simple partition layout (/boot and /), > with 2GB available on the root filesystem, APT lets me try to > install packages that will fill the filesyst

  1   2   >