Bug#1070360: bottleneck new upstream release

2024-05-28 Thread Rebecca N. Palmer
Thanks for the python-tabulate upload. Are you proposing that we leave bottleneck at 1.3.5 and override the minimum version in pandas, or has this been forgotten about? According to the CI, the 1.3.8 on the default branch is broken but the one on my branch isn't: https://salsa.debian.org/p

Bug#1039087: removing embeded version of yajl

2024-05-28 Thread Andrius Merkys
Hi, On 2024-05-28 18:35, PICCA Frederic-Emmanuel wrote: Here the diff between the epics version (debian patch unapplyed) and the current 2.1.0 version of yajl (debian patch unapplyed). It seems EPICS authors have forked yajl and implemented JSON5 support there. As a result, the code diverged

Bug#1072146: libexplain: kill(pid = 42 "sh", sig = SIGTERM) failed, Operation not permitted (EPERM)

2024-05-28 Thread Jochen Sprickerhof
Source: libexplain Version: 1.4.D001-13 Severity: normal Tags: patch Hi, libexplain fails to build in sbuild+unshare now used on some of the buildd: PATH=`pwd`/bin:$PATH /bin/sh test/04/t0462a.sh 1c1 < kill(pid = 42, sig = SIGTERM) failed, Operation not permitted (EPERM) --- > kill(pid = 42 "sh"

Bug#1072012: libxml-libxml-perl: new upstream release 2.0210, addressing test failures with libxml2 >= 2.11

2024-05-28 Thread Aron Xu
Hi, On Wed, May 29, 2024 at 12:16 AM gregor herrmann wrote: > > On Mon, 27 May 2024 22:33:45 +0200, gregor herrmann wrote: > > > … on amd64 and some other architectures; on others the testsuite now > > fails in t/13dtd.t with SIGSEGV or SIGBUS etc.: > > https://buildd.debian.org/status/package.ph

Bug#1072115: ERROR:: Failure to read or parse /usr/share/coot/ui/coot-gtk4.ui

2024-05-28 Thread Andrius Merkys
Control: severity -1 serious Control: owner -1 ! Hi, On 2024-05-28 23:07, Picca Frédéric-Emmanuel wrote: while trying to start coot, I get this error message. $ coot INFO:: built with GTK 4.12.5 pdd /usr/share/coot WARNING:: Coot REFMAC dictionary override COOT_REFMAC_LIB_DIR /usr/share/coot/

Bug#1026898: deprecate QUOTAUSER post-bookworm

2024-05-28 Thread Marc Haber
On Tue, May 28, 2024 at 10:48:54PM +, Merlin Hansen wrote: > Just ran across the notification of deprecation when upgrading Proxmox v2 to > v3. We also use QUOTAUSER in multi-user systems in a post-secondary > environment. While we can modify our account creation process to manually set > th

Bug#1025623: Deprecate GROUPHOMES and LETTERHOMES

2024-05-28 Thread Marc Haber
Hi Merlin, thanks for your comments. On Tue, May 28, 2024 at 10:56:48PM +, Merlin Hansen wrote: > I know of at least one post secondary institution that does use heirarchy > similar to that set up via LETTERHOMES due to the large number of accounts. > I'm not aware of any that use GROUPHOME

Bug#1072145: docker.io: Failing test Can't find mount point of /

2024-05-28 Thread Jochen Sprickerhof
Source: docker.io Version: 20.10.24+dfsg1-1 Severity: normal Tags: patch Hi, The docker.io package carries a patch to disable a test in pbuilder: https://sources.debian.org/src/docker.io/20.10.25%2Bdfsg1-3/debian/patches/test--skip-daemon-oci-linux-pbuilder-tests.patch/ Please skip that test un

Bug#851877: sslh: FTBFS randomly (sbuild hangs)

2024-05-28 Thread Don Armstrong
On Mon, 27 May 2024, Santiago Vila wrote: > found 851877 2.1.1-1 > severity 851877 serious > fixed 851877 1.20-1 > thanks [...] > I hope that you can reproduce the hang in this version. In my > experience, the failure rate is 100% on single-cpu systems, so I > suggest trying GRUB_CMDLINE_LINUX="n

Bug#1071576: bugs.debian.org: bug subscription no longer possible: no "Please confirm subscription" e-mail

2024-05-28 Thread Don Armstrong
On Tue, 28 May 2024, Salvatore Bonaccorso wrote: > Not the most urgent bit, but a question: Once the issue is fixed, will > the replies for subscription requests to bug be send out for those > falling inbetween the broken phase? I suspect you'll have to re-issue them, but I'm not certain. Just an

Bug#1072144: when set BOOT_TIMEOUT, md5sum of ./boot/grub/grub.cfg not match md5sum.txt which in iso

2024-05-28 Thread xiao sheng wen
Package: simple-cdd Version: 0.6.9 Severity: minor Tags: security X-Debbugs-Cc: atzli...@sina.com Hi, When I run md5sum -c md5sum.txt in a mounted iso create by simple-cdd, I get the following errors: md5sum -c md5sum.txt .. md5sum: WARNING: 1 computed checksum did NOT match then run: m

Bug#1072143: Depends: golang-github-labstack-echo.v3-dev but it is not installable

2024-05-28 Thread Reinhard Tartler
Package: golang-opentelemetry-contrib-dev Version: 0.25.0-1 Severity: normal $ apt install -s golang-opentelemetry-contrib-dev NOTE: This is only a simulation! apt needs root privileges for real execution. Keep also in mind that locking is deactivated, so don't depend on the rele

Bug#1072108: linux-image-amd64: Enable CONFIG_PINCTRL_METEORLAKE

2024-05-28 Thread Mark Pearson
On Tue, May 28, 2024, at 2:33 PM, Diederik de Haas wrote: > Control: forcemerge -1 1071551 > > On Tuesday, 28 May 2024 20:20:11 CEST Mark Pearson wrote: >> Package: src:linux >> Version: 6.8.11-1 >> Severity: important >> X-Debbugs-Cc: mpearson-len...@squebb.ca >> >> Dear Maintainer, >> >> Please

Bug#1071501: [PATCH] NFS: add barriers when testing for NFS_FSDATA_BLOCKED

2024-05-28 Thread Trond Myklebust
On Tue, 2024-05-28 at 11:19 +1000, NeilBrown wrote: > On Tue, 28 May 2024, Trond Myklebust wrote: > > On Mon, 2024-05-27 at 13:04 +1000, NeilBrown wrote: > > > > > > dentry->d_fsdata is set to NFS_FSDATA_BLOCKED while unlinking or > > > renaming-over a file to ensure that no open succeeds while th

Bug#1072105: /usr/lib/tmpfiles.d/legacy.conf:13: Duplicate line for path "/run/lock", ignoring.

2024-05-28 Thread Richard Lewis
On Tue, 28 May 2024 17:15:02 +0100 Luca Boccassi wrote: > On Tue, 28 May 2024 17:44:54 +0200 Michael Biebl > > Please do not not ship conflicting configuration for /run/lock > > > > /usr/lib/tmpfiles.d/debian.conf:d /run/lock1777 root root - - > > /usr/lib/tmpfiles.d/legacy.conf:d /run/lock

Bug#1056166: fixed in systemd 256~rc3-3

2024-05-28 Thread Luca Boccassi
On Tue, 28 May 2024 at 14:45, Luca Boccassi wrote: > > On Tue, 28 May 2024 at 14:19, Luca Boccassi wrote: > > > > On Tue, 28 May 2024 at 14:18, Anthony Bourguignon > > wrote: > > > > > > Le mardi 28 mai 2024 à 14:06 +0100, Luca Boccassi a écrit : > > > > On Tue, 28 May 2024 at 14:05, Anthony Bo

Bug#987971: (for post boomworm)

2024-05-28 Thread Richard Lewis
control: tags -1 wontfix control: retitle -1 remove logcheck user on purge Tagging wontfix: debian policy is to not remove system users, since they may still open files

Bug#608457: console setup integration

2024-05-28 Thread Luca Boccassi
Control: tags -1 help These are all variations of the same thing - there are legacy debianisms around, that do not provide anything different than what the rest of the world does, but stop new features from coming in (eg: firstboot). But there would be a lot to convert, and needs somebody who und

Bug#1072141: starjava-datanode: FTBFS: error: package uk.ac.starlink.oldfits does not exist

2024-05-28 Thread Santiago Vila
Package: src:starjava-datanode Version: 1.0+2023.01.18-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules build dh build

Bug#1072140: rust-bytecodec: FTBFS: error: doctest failed

2024-05-28 Thread Santiago Vila
Package: src:rust-bytecodec Version: 0.4.15-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary --builds

Bug#1072139: rust-bytecheck: FTBFS: error: doctest failed

2024-05-28 Thread Santiago Vila
Package: src:rust-bytecheck Version: 0.6.11-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary --builds

Bug#1072138: python-peachpy: FTBFS: dh_sphinxdoc: error: debian/python-peachpy-doc/usr/share/doc/python3-peachpy/html/_static/bootstrap-3.4.1/js/bootstrap.min.js is missing

2024-05-28 Thread Santiago Vila
Package: src:python-peachpy Version: 0.0~git20211013.257881e-1.1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary

Bug#1072136: puddletag: FTBFS: dh_sphinxdoc: error: debian/python-behave-doc/usr/share/doc/python-behave-doc/html/_static/js/jquery-1.12.4.min.js is missing

2024-05-28 Thread Santiago Vila
Package: src:puddletag Version: 2.3.0-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules build dh build --with python3,s

Bug#1072137: py-libzfs: FTBFS: libzfs.c:65161:23: error: too few arguments to function ‘zpool_add’

2024-05-28 Thread Santiago Vila
Package: src:py-libzfs Version: 0.0+git20240117.143b624-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules build dh buil

Bug#1072132: behave: FTBFS: dh_sphinxdoc: error: debian/python-behave-doc/usr/share/doc/python-behave-doc/html/_static/js/jquery-1.12.4.min.js is missing

2024-05-28 Thread Santiago Vila
Package: src:behave Version: 1.2.6-5 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules build dh build --with python3,sphi

Bug#1072135: plotsauce: FTBFS: plotsauce.qbs:11:5 Dependency 'zlib' not found for product 'plotsauce'.

2024-05-28 Thread Santiago Vila
Package: src:plotsauce Version: 0~0.1-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary dh_update_a

Bug#1072133: metakernel: FTBFS: dh_sphinxdoc: error: debian/python-metakernel-doc/usr/share/doc/python3-metakernel/html/_static/js/jquery-1.12.4.min.js is missing

2024-05-28 Thread Santiago Vila
Package: src:metakernel Version: 0.30.2-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary --buildsyste

Bug#1072134: octave-financial: FTBFS: error: parse error near line 64 of file /<>/debian/octave-financial/usr/share/octave/packages/financial-0.5.3/bolling.m

2024-05-28 Thread Santiago Vila
Package: src:octave-financial Version: 0.5.3-4 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary --build

Bug#1058825: waagent: diff for NMU version 2.7.3.0-4.2

2024-05-28 Thread Chris Hofstaedtler
Control: tags 1058825 + patch Control: tags 1058825 + pending Dear maintainer, I've prepared an NMU for waagent (versioned as 2.7.3.0-4.2) and uploaded it to DELAYED/10. Please feel free to tell me if I should delay it longer. Regards. diff -Nru waagent-2.7.3.0/debian/changelog waagent-2.7.3.0/

Bug#1059407: [Debian-on-mobile-maintainers] Bug#1059407: mobile-tweaks: install udev, systemd files below /usr

2024-05-28 Thread Chris Hofstaedtler
Hi, On Tue, Jan 02, 2024 at 03:23:02PM +0100, Arnaud Ferraris wrote: > Le 24/12/2023 à 20:11, Chris Hofstaedtler a écrit : > > Your package installs files into /lib. For the ongoing Debian > > UsrMerge effort [1] these files should move to /usr/lib in the > > trixie cycle. > > > > I'm attaching a

Bug#1061701: nss-pam-ldapd: install PAM and NSS modules into /usr

2024-05-28 Thread Chris Hofstaedtler
Control: reopen -1 Control: severity -1 important Hi, On Sat, Feb 24, 2024 at 05:52:40PM +0100, Arthur de Jong wrote: > On Sun, 2024-01-28 at 20:44 +0100, Michael Biebl wrote: > > We want to finalize the /usr-merge via DEP17 by moving all files to > > /usr. nss-pam-ldapd installs files into /lib;

Bug#1059432: openafs: diff for NMU version 1.8.10-2.2

2024-05-28 Thread Chris Hofstaedtler
Control: tags 1059432 + patch Control: tags 1059432 + pending Dear maintainer, I've prepared an NMU for openafs (versioned as 1.8.10-2.2) and uploaded it to DELAYED/10. Please feel free to tell me if I should delay it longer. Regards. diff -Nru openafs-1.8.10/debian/changelog openafs-1.8.10/deb

Bug#1064430: android-sdk-meta: diff for NMU version 28.0.2+10+nmu1

2024-05-28 Thread Chris Hofstaedtler
Control: tags -1 + pending Dear maintainer, I've prepared an NMU for android-sdk-meta (versioned as 28.0.2+10+nmu1) and uploaded it to DELAYED/10. Please feel free to tell me if I should delay it longer. Chris diff -Nru android-sdk-meta-28.0.2+10/debian/android-sdk-platform-tools-common.install

Bug#1025623: Deprecate GROUPHOMES and LETTERHOMES

2024-05-28 Thread Merlin Hansen
Hi, I just ran across this report during a recent upgrade. I know of at least one post secondary institution that does use heirarchy similar to that set up via LETTERHOMES due to the large number of accounts. I'm not aware of any that use GROUPHOMES though. I have considered switching to a sim

Bug#1064316: rtkit: diff for NMU version 0.13-5.1

2024-05-28 Thread Chris Hofstaedtler
Control: tags 1064316 + patch Control: tags 1064316 + pending Dear maintainer, I've prepared an NMU for rtkit (versioned as 0.13-5.1) and uploaded it to DELAYED/10. Please feel free to tell me if I should delay it longer. Chris diff -Nru rtkit-0.13/debian/changelog rtkit-0.13/debian/changelog -

Bug#1026898: deprecate QUOTAUSER post-bookworm

2024-05-28 Thread Merlin Hansen
Hi, Just ran across the notification of deprecation when upgrading Proxmox v2 to v3. We also use QUOTAUSER in multi-user systems in a post-secondary environment. While we can modify our account creation process to manually set the quota using "edquota -p foo bar", having the QUOTAUSER option co

Bug#966621: Make /tmp/ a tmpfs and cleanup /var/tmp/ on a timer by default [was: Re: systemd: tmpfiles.d not cleaning /var/tmp by default]

2024-05-28 Thread Marco d'Itri
On May 28, Andreas Metzler wrote: > I think it is bad choice to deliberately have different behavior for > freshly installed and upgraded systems. Offering upgrades has always > been one of the major selling points of Debian, and imho this > implicitely includes that you do not get a worse or sec

Bug#1072131: swiftlang: FTBFS: swift-corelibs-foundation/CoreFoundation/Base.subproj/CoreFoundation_Prefix.h:194:1: error: static declaration of 'strlcpy' follows non-static declaration

2024-05-28 Thread Santiago Vila
Package: src:swiftlang Version: 5.6.3-3 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary dh_update_a

Bug#1072130: geary: FTBFS: MESA: error: ZINK: vkCreateInstance failed (VK_ERROR_INCOMPATIBLE_DRIVER)

2024-05-28 Thread Santiago Vila
Package: src:geary Version: 46.0-1 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binary dh_update_autoto

Bug#1072129: android-platform-art: FTBFS: libartbase/base/strlcpy.h:31:22: error: static declaration of 'strlcpy' follows non-static declaration

2024-05-28 Thread Santiago Vila
Package: src:android-platform-art Version: 14.0.0+r15-2 Severity: serious Tags: ftbfs Dear maintainer: During a rebuild of all packages in unstable, your package failed to build: [...] debian/rules binary dh binar

Bug#1072105: (no subject)

2024-05-28 Thread Michael Biebl
please do find a proper solution. wontfix is it not. OpenPGP_signature.asc Description: OpenPGP digital signature

Bug#978607: Please drop empty /etc/udev/udev.conf

2024-05-28 Thread Josh Triplett
Package: udev Version: 255.5-1 Followup-For: Bug #978607 X-Debbugs-Cc: j...@joshtriplett.org Josh Triplet wrote: > Luca Bocassi wrote: > > On Mon, 1 Feb 2021 21:59:22 -0800 Josh Triplett > > wrote: > > > On Tue, 29 Dec 2020 14:56:42 -0800 Josh Triplett > > joshtriplett.org> wrote: > > > > It lo

Bug#1072128: ITP: ruby-omniauth-shibboleth-redux -- OmniAuth Shibboleth strategies for OmniAuth 2.x

2024-05-28 Thread Ananthu C V
Package: wnpp Severity: wishlist Owner: Ananthu C V X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: ruby-omniauth-shibboleth-redux Version : 2.0.0 Upstream Contact: Bobby McDonald * URL : https://github.com/omniauth/omniauth-shibboleth-redux * License

Bug#1006655: [PATCH] Implement rm_conffile_if_unmodified

2024-05-28 Thread Josh Triplett
tags 1006655 + patch thanks I've attached a patch implementing an rm_conffile_if_unmodifed command for dpkg-maintscript-helper, as well as a declarative version for debian/conffiles. I've included documentation and tests for both. Using this has the same effect as rm_conffile if the file is unmo

Bug#1072127: sharutils: shar.1: some remarks and editorial changes for this man page

2024-05-28 Thread Bjarni Ingi Gislason
Package: sharutils Version: 1:4.15.2-9 Severity: minor Tags: patch Dear Maintainer, here are some notes and editorial fixes for the manual. The patch is in the attachment. -.- The concerned man page was autogenerated (autogen). -.- Any program (person), that produces man pages, should

Bug#1072126: frr: CVE-2024-31948

2024-05-28 Thread Moritz Mühlenhoff
Source: frr X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for frr. CVE-2024-31948[0]: | In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix | SID attribute in a BGP UPDATE packet can cause the bgpd daemon to |

Bug#1072124: gnome-shell: CVE-2024-36472

2024-05-28 Thread Moritz Muehlenhoff
On Tue, May 28, 2024 at 05:33:32PM -0400, Jeremy Bícha wrote: > Control: forwarded -1 https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/7688 > > On Tue, May 28, 2024 at 5:24 PM Moritz Mühlenhoff wrote: > > CVE-2024-36472[0]: > > | In GNOME Shell through 45.7, a portal helper can be launched > >

Bug#1072125: frr: CVE-2024-31949

2024-05-28 Thread Moritz Mühlenhoff
Source: frr X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for frr. CVE-2024-31949[0]: | In FRRouting (FRR) through 9.1, an infinite loop can occur when | receiving a MP/GR capability as a dynamic capability because | malfo

Bug#1070377: frr: CVE-2024-34088

2024-05-28 Thread Moritz Mühlenhoff
Am Sat, May 04, 2024 at 06:00:24PM +0200 schrieb Moritz Mühlenhoff: > Source: frr > X-Debbugs-CC: t...@security.debian.org > Severity: important > Tags: security > > Hi, > > The following vulnerability was published for frr. > > CVE-2024-34088[0]: > | In FRRouting (FRR) through 9.1, it is possib

Bug#1072124: gnome-shell: CVE-2024-36472

2024-05-28 Thread Jeremy Bícha
Control: forwarded -1 https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/7688 On Tue, May 28, 2024 at 5:24 PM Moritz Mühlenhoff wrote: > CVE-2024-36472[0]: > | In GNOME Shell through 45.7, a portal helper can be launched > | automatically (without user confirmation) based on network responses >

Bug#1072124: gnome-shell: CVE-2024-36472

2024-05-28 Thread Moritz Mühlenhoff
Source: gnome-shell X-Debbugs-CC: t...@security.debian.org Severity: normal Tags: security Hi, The following vulnerability was published for gnome-shell. CVE-2024-36472[0]: | In GNOME Shell through 45.7, a portal helper can be launched | automatically (without user confirmation) based on network

Bug#1072123: jayway-jsonpath: CVE-2023-51074

2024-05-28 Thread Moritz Mühlenhoff
Source: jayway-jsonpath X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for jayway-jsonpath. CVE-2023-51074[0]: | json-path v2.8.0 was discovered to contain a stack overflow via the | Criteria.parse() method. https://github

Bug#1072122: bookworm-pu: package cloud-init/22.4.2-1

2024-05-28 Thread Noah Meyerhans
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: cloud-i...@packages.debian.org Control: affects -1 + src:cloud-init In #1070137 we introduced a backport of cloud-init 22.4.2-1 to bullseye as a versioned package clo

Bug#1071574: netcfg 1.187+deb12u1 flagged for acceptance

2024-05-28 Thread Adam D Barratt
package release.debian.org tags 1071574 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: netcfg Version: 1.187+deb12u

Bug#1072098: systemd 252.26-1~deb12u1 flagged for acceptance

2024-05-28 Thread Adam D Barratt
package release.debian.org tags 1072098 = bookworm pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bookworm. Thanks for your contribution! Upload details == Package: systemd Version: 252.26-1~de

Bug#1072121: node-ip: CVE-2024-29415

2024-05-28 Thread Moritz Mühlenhoff
Source: node-ip X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for node-ip. CVE-2024-29415[0]: | The ip package through 2.0.1 for Node.js might allow SSRF because | some IP addresses (such as 127.1, 01200034567, 012.1.2.3,

Bug#1072120: zabbix: CVE-2024-22120

2024-05-28 Thread Moritz Mühlenhoff
Source: zabbix X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for zabbix. CVE-2024-22120[0]: | Zabbix server can perform command execution for configured scripts. | After command is executed, audit entry is added to "Audit Log"

Bug#1072119: python-aiosmtpd: CVE-2024-34083

2024-05-28 Thread Moritz Mühlenhoff
Source: python-aiosmtpd X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for python-aiosmtpd. CVE-2024-34083[0]: | aiosmptd is a reimplementation of the Python stdlib smtpd.py based | on asyncio. Prior to version 1.4.6, servers

Bug#1072118: liboqs: CVE-2024-31510

2024-05-28 Thread Moritz Mühlenhoff
Source: liboqs X-Debbugs-CC: t...@security.debian.org Severity: important Tags: security Hi, The following vulnerability was published for liboqs. CVE-2024-31510[0]: | An issue in Open Quantum Safe liboqs v.10.0 allows a remote attacker | to escalate privileges via the crypto_sign_signature para

Bug#1071992: sqlmodel: please make this package compatible with SQL Alchemy 2.x

2024-05-28 Thread Bastian Germann
Control: notfound -1 sqlmodel/0.0.16-1 Control: fixed -1 sqlmodel/0.0.16-1 Control: found sqlmodel/0.0.8-6 The experimental version is actually already compatible with sqlalchemy 2.0.x. Please move it to unstable.

Bug#1072117: /usr/bin/keepassxc: KeePassXC stores its .lock/.socket file in /tmp

2024-05-28 Thread James McCoy
Package: keepassxc-full Version: 2.7.7+dfsg.1-3 Severity: important File: /usr/bin/keepassxc Especially given the recent change to have automated cleaning of /tmp at runtime, keepassxc shouldn't be using /tmp to store these files. They should probably be under $XDG_RUNTIME_DIR. -- System Inform

Bug#1072116: RM: python-shade -- ROM; RC buggy, low popcon, obsolete, newer alternative

2024-05-28 Thread Alexandre Detiste
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: python-sh...@packages.debian.org, Thomas Goirand Control: affects -1 + src:python-shade User: ftp.debian@packages.debian.org Usertags: remove Hi, https://pypi.org/project/shade/ "Warning shade has been superceded by openstacksdk and no

Bug#1072115: ERROR:: Failure to read or parse /usr/share/coot/ui/coot-gtk4.ui

2024-05-28 Thread picca
I forgot to add that you start this script like this Test-Command: xvfb-run -s "-screen 0 1024x768x24 -ac +extension GLX +render -noreset" sh debian/tests/gui Depends: mesa-utils, coot, xauth, xvfb, Restrictions: allow-stderr

Bug#1072115: ERROR:: Failure to read or parse /usr/share/coot/ui/coot-gtk4.ui

2024-05-28 Thread Picca Frédéric-Emmanuel
Package: coot Version: 1.1.08+dfsg-2 Severity: important X-Debbugs-Cc: pi...@debian.org while trying to start coot, I get this error message. $ coot INFO:: built with GTK 4.12.5 pdd /usr/share/coot WARNING:: Coot REFMAC dictionary override COOT_REFMAC_LIB_DIR /usr/share/coot/lib failed to find

Bug#1072114: dxvk: please package DXVK Native when its stable ABI becomes available

2024-05-28 Thread Simon McVittie
Source: dxvk Severity: wishlist Recent versions of DXVK have support for being compiled as native Linux libraries, so that native Linux games (particularly those that were ported from Windows) can use the Direct3D APIs on both platforms. Windows-specific parts of the APIs are implemented via eithe

Bug#1072113: openssl: CVE-2024-4741

2024-05-28 Thread Salvatore Bonaccorso
1 [1] https://www.openssl.org/news/secadv/20240528.txt Please adjust the affected versions in the BTS as needed. Regards, Salvatore

Bug#1072112: freerdp2: CVE-2024-32658 CVE-2024-32659 CVE-2024-32660 CVE-2024-32661

2024-05-28 Thread Salvatore Bonaccorso
Source: freerdp2 Version: 2.11.5+dfsg1-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for freerdp2. CVE-2024-32658[0]: | FreeRDP is a free implementation of the Re

Bug#1061570: libscrypt: New upstream release available

2024-05-28 Thread Bastian Germann
I am uploading a NMU to DELAYED/10 in order to fix this.diff -Nru libscrypt-1.21/Makefile libscrypt-1.22/Makefile --- libscrypt-1.21/Makefile 2015-07-09 10:59:57.0 + +++ libscrypt-1.22/Makefile 2021-12-11 06:19:10.0 + @@ -5,27 +5,28 @@ INSTALL_DATA ?= install CC

Bug#1071755: RFS: open62541/1.4.1-1 [ITP] -- open62541 () is an open source implementation

2024-05-28 Thread Julius Pfrommer
> The upstream should track the ABI compatibility properly and adjust the > SONAMEs accordingly. This is not what Debian prefers but a generic > requirement for Linux shared library projects. Got it. Then we install the patches proposed for the Debian package into the upstream and come back. This

Bug#1072049: please provide a link to the artifacts on the page displaying the log

2024-05-28 Thread Antonio Terceiro
On Tue, May 28, 2024 at 08:38:04PM +0200, Paul Gevers wrote: > Hi, > > Unfortunately > > On 28-05-2024 2:46 p.m., Antonio Terceiro wrote: > > FWIW given this is pretty simple I also live patched the server. > > ..the link now is: > https://ci.debian.net/packages/r/reform-setup-wizard/testin

Bug#1071739: marked as done (packages.debian.org: Removal of spam domain from download mirror page)

2024-05-28 Thread Boyuan Yang
On Sat, 2024-05-25 at 10:06 +0200, Holger Wansing wrote: > > > Am 24. Mai 2024 20:16:35 MESZ schrieb Holger Wansing : > > > > > > Am 24. Mai 2024 20:10:35 MESZ schrieb Thomas Lange : > > > > > > > > On Fri, 24 May 2024 20:02:35 +0200, Holger Wansing > > > > > > > > said: > > > > > >    > Hi

Bug#1072097: nfs-common: NFS mounted share via DNS name crashed OS kernel

2024-05-28 Thread Salvatore Bonaccorso
Control: reassign -1 src:linux 6.1.90-1 Control: tags -1 + moreinfo Hi, On Tue, May 28, 2024 at 02:42:43PM +0300, Дмитрий Сергеевич wrote: > > Package: nfs-common > Version: 1:2.6.2-4 > Severity: normal >   > Dear Maintainer, >   > *** Reporter, please consider answering these questions, where a

Bug#1072111: malcontent: New upstream version

2024-05-28 Thread Matheus Polkorny
Package: malcontent Version: 0.11.1-3 Severity: wishlist Dear Maintainer, Please import the new upstream version 0.12.0 I just opened this bug because the d/watch is broken

Bug#1067303: trash-cli in Debian: test problems again

2024-05-28 Thread Boyuan Yang
X-Debbugs-CC: j...@debian.org stef...@karapetsas.com and...@andreafrancia.it Hi Jonathan, Stefano, On Sun, 26 May 2024 14:04:40 +0200 Andrea Francia wrote: > Hi Jonathan and Lucas, >   I solved the problem in the new release (0.24.5.26). > > I tested it with these commands: > git clone https:/

Bug#1034812: Unbootable after install: UEFI installed to wrong ESP

2024-05-28 Thread Jmkr
Pascal Hambourg wrote: > > You can run grub-install with --no-nvram to install GRUB without writing > EFI boot variables. The Debian installer also has an option for this in > expert mode. Then you can create a custom boot entry with efibootmgr. Thanks, this is very nice => I am definitely going

Bug#1072110: glslang breaks shaderc autopkgtest: undefined reference: ABI breakage??

2024-05-28 Thread Paul Gevers
Source: glslang, shaderc Control: found -1 glslang/14.2.0-1 Control: found -1 shaderc/2023.2-1 Severity: serious Tags: sid trixie User: debian...@lists.debian.org Usertags: breaks needs-update Dear maintainer(s), With a recent upload of glslang the autopkgtest of shaderc fails in testing when t

Bug#1072109: python-awkward: Tries to access Internet during build

2024-05-28 Thread Santiago Vila
Package: src:python-awkward Version: 2.6.1-1 Severity: serious Tags: ftbfs Dear maintainer: Your package tries to access Internet during build, which is not allowed. I discovered this by building the package in 2028, as the SSL certificate for https://pypi.org is perceived in such case as expir

Bug#1072108: linux-image-amd64: Enable CONFIG_PINCTRL_METEORLAKE

2024-05-28 Thread Diederik de Haas
Control: forcemerge -1 1071551 On Tuesday, 28 May 2024 20:20:11 CEST Mark Pearson wrote: > Package: src:linux > Version: 6.8.11-1 > Severity: important > X-Debbugs-Cc: mpearson-len...@squebb.ca > > Dear Maintainer, > > Please enable the CONFIG_PINCTRL_METEORLAKE kernel option. This is needed to

Bug#1072049: please provide a link to the artifacts on the page displaying the log

2024-05-28 Thread Paul Gevers
Hi, Unfortunately On 28-05-2024 2:46 p.m., Antonio Terceiro wrote: FWIW given this is pretty simple I also live patched the server. ..the link now is: https://ci.debian.net/packages/r/reform-setup-wizard/testing/s390x/47038806/%7B%20base_url%20%7D/artifacts.tar.gz Note the {base_url}/

Bug#1071182: dracut: requires changes for systemd 256; boot fails otherwise

2024-05-28 Thread Holger Weiss
Package: dracut Followup-For: Bug #1071182 After updating to systemd 256~rc3-2 and dracut 060+5-8, these two messages are logged from initrd: | /bin/dracut-cmdline: 28: //lib/dracut/hooks/cmdline/00-parse-root.sh: cannot create /lib/dracut/hooks/initqueue/finished/devexists-\x2fdev\x2fdisk\x2fb

Bug#1072108: linux-image-amd64: Enable CONFIG_PINCTRL_METEORLAKE

2024-05-28 Thread Mark Pearson
Package: src:linux Version: 6.8.11-1 Severity: important X-Debbugs-Cc: mpearson-len...@squebb.ca Dear Maintainer, Please enable the CONFIG_PINCTRL_METEORLAKE kernel option. This is needed to support Meteorlake based platforms. -- Package-specific info: ** Version: Linux version 6.8.11-amd64 (de

Bug#1071755: RFS: open62541/1.4.1-1 [ITP] -- open62541 () is an open source implementation

2024-05-28 Thread Andrey Rakhmatullin
On Tue, May 28, 2024 at 05:48:10PM +0200, Julius Pfrommer wrote: > > > The intent was to do the SONAME patching entirely in the rules file. > > > Now we instead ship a small patch to the upstream CMakeLists.txt that > > > modifies the linker flags. > > This doesn't answer why are you changing the

Bug#1053348: atop gets a segmentation fault

2024-05-28 Thread Marc Haber
Control: tags -1 unreproducible thanks On Sun, Jan 14, 2024 at 07:38:25PM +0100, Tiger!P wrote: > I have not seen a segfault with 2.10.0-1 yet. > I have updated atop to 2.10.0-1 on multiple system and will report when > I see a crash again. Are you fine with me marking this report as "closed with

Bug#1063698: atop FTBFS: hard codes the build architecture pkg-config

2024-05-28 Thread Marc Haber
Control: tags -1 upstream fixed-upstream patch confirmed thanks On Sat, Feb 10, 2024 at 09:53:28AM +0100, Helmut Grohne wrote: > atop regressed cross building, because its upstream Makefile now hard > codes a build architecture pkg-config. I'm attaching a patch to make it > substitutable. Applying

Bug#1072004: linux: regression in the 9p protocol in 6.8 breaks autopkgtest qemu jobs (affecting debci)

2024-05-28 Thread Paul Gevers
Hi, On 28-05-2024 10:54 a.m., Luca Boccassi wrote: If 6.8 migrates to testing, it will break amd64 debci for unrelated packages for migration tests too. I don't think that's something we want? Paul, wouldn't that qualify as RC? With the kernel team being aware of the issue, I trust the kernel

Bug#1071563: emacs: Don't let test suite failures block the build

2024-05-28 Thread Rob Browning
Sean Whitton writes: > I think it's just that upstream has lots and lots of tests now. Well, sure, but in the past I don't recall having to (re)try very often, (a few cases where I had to track down and (most of the time) mark a test as flaky). But maybe 29 is worse, or maybe I misremember...

Bug#1033733: vkd3d: new upstream release 1.11

2024-05-28 Thread Simon McVittie
Control: retitle -1 vkd3d: new upstream release 1.11 On Fri, 31 Mar 2023 at 11:54:01 +0100, Simon McVittie wrote: > On Fri, 31 Mar 2023 at 10:58:46 +0100, Simon McVittie wrote: > > vkd3d has a new upstream release available, v1.7. Since then there have been several more upstream releases and it i

Bug#979188: RFS: git-subrepo/0.4.3-1 [ITP] -- Alternative to git-submodule(1) and git-subtree(1)

2024-05-28 Thread Daniel Gröber
Hi Samo, On Sat, May 25, 2024 at 07:30:46PM +0200, Samo Pogačnik wrote: > https://salsa.debian.org/spog/git-subrepo/-/commit/42628d43faa4a05eb3dd3c4b75d9d194ce6bda90 I'm not super happy with the approach of putting git-subrepo.d inside /usr/share/git-subrepo tbh. I might be able to let it pass bu

Bug#978607: Please drop empty /etc/udev/udev.conf

2024-05-28 Thread Josh Triplett
Package: udev Version: 255.5-1 Followup-For: Bug #978607 X-Debbugs-Cc: j...@joshtriplett.org Luca Bocassi wrote: > On Mon, 1 Feb 2021 21:59:22 -0800 Josh Triplett > wrote: > > On Tue, 29 Dec 2020 14:56:42 -0800 Josh Triplett > > wrote: > > > It looks like those files are installed upstream by

Bug#966621: Make /tmp/ a tmpfs and cleanup /var/tmp/ on a timer by default [was: Re: systemd: tmpfiles.d not cleaning /var/tmp by default]

2024-05-28 Thread Andreas Metzler
On 2024-05-28 Luca Boccassi wrote: [...] > - existing installations pre-trixie will get an orphaned tmpfiles.d in > /etc/ that keeps the existing behaviour unchanged (no cleanup of > /var/tmp) [...] Hello, I think it is bad choice to deliberately have different behavior for freshly installed an

Bug#1072107: libarchive: CVE-2024-26256

2024-05-28 Thread Salvatore Bonaccorso
Source: libarchive Version: 3.7.2-2 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Control: found -1 3.6.2-1 Hi, The following vulnerability was published for libarchive. CVE-2024-26256[0]: | libarchive Remote Code

Bug#1071575: dahdi-dkms: module fails to build for Linux 6.8.9: error: implicit declaration of function 'strlcpy'

2024-05-28 Thread Harald Welte
Please note that the osmocom fork does have a CI job to exactly prevent a situation like this: We're continuously building our fork against Linus Torvalds' git, see https://jenkins.osmocom.org/jenkins/job/master-dahdi-linux-torvalds-master/ It seems the strlcpy was fixed in https://gitea.osmocom

Bug#1072106: azure-cli: az ad sp create-for-rbac results in python error

2024-05-28 Thread Michael Banck
Package: azure-cli Version: 2.45.0-1 Severity: normal Running this results in a traceback for me on Debian 12: $ az ad sp create-for-rbac --name foo --role Contributor --scopes /subscriptions/ Creating 'Contributor' role assignment under scope '/subscriptions/' Role assignment creation failed.

Bug#1072012: libxml-libxml-perl: new upstream release 2.0210, addressing test failures with libxml2 >= 2.11

2024-05-28 Thread gregor herrmann
On Mon, 27 May 2024 22:33:45 +0200, gregor herrmann wrote: > … on amd64 and some other architectures; on others the testsuite now > fails in t/13dtd.t with SIGSEGV or SIGBUS etc.: > https://buildd.debian.org/status/package.php?p=libxml-libxml-perl Additionally the upload triggers a gazillion of a

Bug#1072105: /usr/lib/tmpfiles.d/legacy.conf:13: Duplicate line for path "/run/lock", ignoring.

2024-05-28 Thread Luca Boccassi
Control: tags -1 wontfix Control: close -1 On Tue, 28 May 2024 17:44:54 +0200 Michael Biebl wrote: > Package: systemd > Version: 256~rc3-4 > Severity: normal > > > Please do not not ship conflicting configuration for /run/lock > > /usr/lib/tmpfiles.d/debian.conf:d /run/lock    1777 root root -

Bug#1071755: RFS: open62541/1.4.1-1 [ITP] -- open62541 () is an open source implementation

2024-05-28 Thread Julius Pfrommer
> > The intent was to do the SONAME patching entirely in the rules file. > > Now we instead ship a small patch to the upstream CMakeLists.txt that > > modifies the linker flags. > This doesn't answer why are you changing the SONAME in a Debian-specific > patch at all. The upstream currently produ

Bug#1072105: /usr/lib/tmpfiles.d/legacy.conf:13: Duplicate line for path "/run/lock", ignoring.

2024-05-28 Thread Michael Biebl
Package: systemd Version: 256~rc3-4 Severity: normal Please do not not ship conflicting configuration for /run/lock /usr/lib/tmpfiles.d/debian.conf:d /run/lock1777 root root - - /usr/lib/tmpfiles.d/legacy.conf:d /run/lock 0755 root root - triggering unnecessary warnings.

Bug#1039087: Info received (removing embeded version of yajl)

2024-05-28 Thread PICCA Frederic-Emmanuel
Here the diff between the epics version (debian patch unapplyed) and the current 2.1.0 version of yajl (debian patch unapplyed). not that simple...diff --git a/src/yajl.c b/src/yajl.c index d477893..fdad3f6 100644 --- a/src/yajl.c +++ b/src/yajl.c @@ -1,5 +1,5 @@ /* - * Copyright (c) 2007-2014,

Bug#1039087: removing embeded version of yajl

2024-05-28 Thread Andrius Merkys
Hi, On 2024-05-28 17:49, PICCA Frederic-Emmanuel wrote: following a different path..., I added this in the rules file -export POSIX_CFLAGS+=$(CFLAGS) +export POSIX_CFLAGS+=$(CFLAGS) $(shell pkgconf --cflags yajl) export POSIX_CFLAGS+=$(CPPFLAGS) export POSIX_CPPFLAGS+=$(CPPFLAGS) -export POSIX

Bug#1072104: shellinabox: Add ipv6 support

2024-05-28 Thread Daniel
Package: shellinabox Version: 2.21+b2 Severity: wishlist Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** please add support for ipv6 beside of ipv4. -- System Information: Debian Release: 12.5 APT prefers stable-updates APT policy: (500, 'st

  1   2   >