Bug#1104735: libvirt: cannot restore internal snapshots

2025-05-13 Thread intrigeri
rixie, with a freeze exception if necessary :) Cheers -- intrigeri

Bug#1104603: [pkg-apparmor] Bug#1104603: apparmor: crun profile makes crun unusable

2025-05-06 Thread intrigeri
xists to give the # application a name instead of having the label "unconfined" Cheers, -- intrigeri

Bug#1104603: [pkg-apparmor] Bug#1104603: apparmor: crun profile makes crun unusable

2025-05-06 Thread intrigeri
not", which IIRC is tracked upstream somewhere. Other limitations include "'deny' rules will be enforced even in complain mode" (quoting aa-complain(8)). Cheers, -- intrigeri

Bug#1103503: isc-dhcp-client: In /etc/apparmor.d/local, sbin.dhclient should be renamed to usr.sbin.dhclient for consistency

2025-04-22 Thread intrigeri
Hi, Vincent Lefevre (2025-04-19): > On 2025-04-18 13:40:01 +0200, intrigeri wrote: >> What dhclient files have been removed before the upgrade? > > /etc/apparmor.d/sbin.dhclient > /etc/apparmor.d/local/sbin.dhclient > >> How were they removed? > > With "rm&q

Bug#1070674: gnome-settings-daemon: No oom-kill notifications

2025-04-22 Thread intrigeri
I already have on my To-Do list to test this on Trixie, so if there's still any issue I'll open a new bug. Cheers, -- intrigeri

Bug#1103503: isc-dhcp-client: In /etc/apparmor.d/local, sbin.dhclient should be renamed to usr.sbin.dhclient for consistency

2025-04-18 Thread intrigeri
een removed before the upgrade? How were they removed? Can you please describe how the resulting configuration is broken? Cheers, -- intrigeri

Bug#1103044: mat2: unsatisfiable dependency on python2

2025-04-14 Thread intrigeri
Package: mat2 Version: 0.13.5-1.1 Severity: serious Hi! mat2 0.13.5-1.1 has an unsatisfiable dependency on python2, while 0.13.5-1 hadn't. -- System Information: Debian Release: trixie/sid APT prefers unstable APT policy: (990, 'unstable'), (2, 'experimental') Architecture: amd64 (x86_64) K

Bug#1100546: [pkg-apparmor] Bug#1100546: apparmor-profiles: apparmor fails to start: /etc/apparmor.d/usr.bin.chromium-browser depends on removed abstraction

2025-04-05 Thread intrigeri
failure you're experiencing. I'll upload a fix later today. Cheers, -- intrigeri

Bug#1100755: /etc/apparmor.d/usr.sbin.cupsd: cups-daemon: Apparmor profile blocks reading /etc/paperspecs

2025-03-20 Thread intrigeri
ofiles/apparmor/profiles/extras/usr.sbin.cupsd?ref_type=heads#L68 - https://gitlab.com/apparmor/apparmor/-/commit/97d7fa3f5f2ca016f853af6dbb97187f9525adf5 Cheers, -- intrigeri

Bug#1098845: torbrowser-launcher: Some of Tor Browser's security features may offer less protection...

2025-03-18 Thread intrigeri
bled? This is caused by a recent update of the apparmor package. The fix requires updating the AppArmor policy of Tor Browser. I'm going to submit a fix upstream today. In the meantime you can add this rule: userns, … to /etc/apparmor.d/torbrowser.Browser.firefox. Cheers, -- intrigeri

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-17 Thread intrigeri
Control: reassign -1 apparmor Hi, Stefano Brivio (2025-03-14): > On Thu, 13 Mar 2025 18:18:28 +0100 > intrigeri wrote: >> So at this stage, as far as Debian Trixie is concerned, I'm now >> tempted to simply remove the stub podman profile from the apparmor >> pa

Bug#1100546: [pkg-apparmor] Bug#1100546: apparmor-profiles: apparmor fails to start: /etc/apparmor.d/usr.bin.chromium-browser depends on removed abstraction

2025-03-17 Thread intrigeri
missing something: could you please check if a package manages that file on your system, and if so, which package that is? Thanks in advance! -- intrigeri

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-13 Thread intrigeri
;m now tempted to simply remove the stub podman profile from the apparmor package: it seems none of us is super comfortable with the workaround they would have to carry to make it play nicer with pasta. And we would not be losing much value for our users. Does this sound reasonable? Cheers, -- intrigeri

Bug#1100171: libtree-sitter0: Crashes Emacs with "stack smashing detected" when python language grammar is installed

2025-03-13 Thread intrigeri
) [0x5cdcd3d9693c] Mar 12 09:59:57 manticora emacs.desktop[122043]: /home/intrigeri/.cache/emacs/eln-cache/30.1-afa68807/treesit-37439c61-730b72d7.eln(F747265657369742d666f6e742d6c6f636b2d666f6e746966792d726567696f6e_treesit_font_lock_fontify_region_0+0x2b1) [0x7b0de3f92a61] Mar 12 09:59:57 manticora

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-13 Thread intrigeri
Control: reassign -1 passt Hi, Stefano Brivio (2025-03-12): > On Wed, 12 Mar 2025 14:41:14 +0100 > intrigeri wrote: > Thanks for fixing the address, yes, I didn't get the original report. Thanks for the quick reply! >> - It'll be necessary on Ubuntu, where remov

Bug#1100135: [pkg-apparmor] Bug#1100135: Conflict between Podman Profile and Pasta profile breaks rootless network shutdown

2025-03-12 Thread intrigeri
at some point (https://bugs.launchpad.net/ubuntu/+source/passt/+bug/2077158). So we can as well fix this proactively. And the fix should probably be upstreamed. - It's 1 tiny but still useful step towards being able to some day stop accepting signals from unconfined processes. Stefano, what do you think? I believe this (untested) rule should do the job: signal (receive) peer=podman, If we don't do that, then I'm fine with removing the podman profile, which has limited value anyway in the context of Debian. Cheers, -- intrigeri

Bug#1099743: Wayland shell stops repainting the screen until monitor layout (or input devices?) change

2025-03-10 Thread intrigeri
~rc-3 and I did not experience it since a couple hours. I'll let you know if I see it again. Otherwise, in this specific context: silence from me means happy user. Thanks a lot for the quick fix! Cheers, -- intrigeri

Bug#1098869: apparmor: triggers a security warning in Firefox with firejail

2025-03-04 Thread intrigeri
Control: reassign -1 firejail Control: retitle -1 firejail-default AppArmor profile needs userns rule Hi, Vincent Lefevre (2025-03-03): > On 2025-03-03 12:03:22 +0100, intrigeri wrote: >> Can you try adding the "userns," line to the firejail-default AppArmor >> p

Bug#1099085: [pkg-apparmor] Bug#1099085: apparmor: FTBFS on riscv64: subprocess.TimeoutExpired

2025-03-03 Thread intrigeri
Hi, Bo YU (2025-03-03): > On Mon, Mar 3, 2025 at 6:53 PM intrigeri wrote: >> Do you want to submit your patch upstream >> (https://gitlab.com/apparmor/apparmor/) or should I? >> > > In general, I should forward the patch to upstream. But here I am not > sure if t

Bug#1098869: apparmor: triggers a security warning in Firefox with firejail

2025-03-03 Thread intrigeri
it/71c0d1bfdd0556cb8466913d65ca4f6fced14b63 Then reboot the system and try to reproduce. Cheers, -- intrigeri

Bug#1098521: [pkg-apparmor] Bug#1098521: apparmor 4.x breaks systemd user namespacing in lxc containers

2025-03-03 Thread intrigeri
update to work with the feature set update that I applied in the 4.1~* src:apparmor uploads (https://salsa.debian.org/apparmor-team/apparmor/-/commit/71c0d1bfdd0556cb8466913d65ca4f6fced14b63). Adding this rule should be sufficient: userns, I suspect Ubuntu has already hit this problem so hopefully it's fixed upstream already? Cheers, -- intrigeri

Bug#1099085: [pkg-apparmor] Bug#1099085: apparmor: FTBFS on riscv64: subprocess.TimeoutExpired

2025-03-03 Thread intrigeri
d not understand this sentence. Could you please rephrase? Cheers, -- intrigeri

Bug#1095797: gnome-shell-extension-desktop-icons-ng: apparmor configuration file breaks apparmor in debian sid

2025-02-17 Thread intrigeri
we should include is still in beta). So for Trixie I would suggest you adjust the AppArmor policy to be compatible with 3.x. Cheers, -- intrigeri

Bug#1089225: [pkg-apparmor] apparmor.service can't start due to PROC undeclared

2025-02-11 Thread intrigeri
report this 2nd problem separately, since I doubt it's related to the previous one. To that new bug report, please attach the full apparmor.d directory that exposes the problem, so we can try to reproduce and figure out where the problem comes from. Thanks in advance! -- intrigeri

Bug#1084134: python3-dogtail: sniff fails to start on Wayland (No module named 'ponytail')

2025-02-10 Thread intrigeri
Control: tag -1 + patch Hi, intrigeri (2024-12-12): > intrigeri (2024-10-08): >>>> I can't find such ponytail package in Debian archive, and I found the >>>> gnome- >>>> ponytail-daemon [2] project online but I'm not sure that's the correct

Bug#1089225: [pkg-apparmor] Bug#1089225: Bug#1089225: apparmor.service can't start due to PROC undeclared

2025-02-10 Thread intrigeri
from a clean Debian installation Thanks in advance! Cheers, -- intrigeri

Bug#1090734: libmoox-options-perl: Please consider turning dependency on libmoox-configfromfile-perl to a Recommends

2024-12-18 Thread intrigeri
Package: libmoox-options-perl Version: 4.103-4 Severity: wishlist I understand MooX::ConfigFromFile is only used if the consumer code opts-in for the corresponding feature by enabling the with_config_from_file option. I could not find any code with codesearch.debian.net that enables this option.

Bug#1084134: python3-dogtail: sniff fails to start on Wayland (No module named 'ponytail')

2024-12-12 Thread intrigeri
Hi, intrigeri (2024-10-08): >>> I can't find such ponytail package in Debian archive, and I found the gnome- >>> ponytail-daemon [2] project online but I'm not sure that's the correct >>> upstream >>> source. >>> I understand that it sh

Bug#1088561: python-stem: Please consider switching to new upstream

2024-11-28 Thread intrigeri
Source: python-stem Severity: normal Hi, In https://github.com/torproject/stem/issues/154, the previous upstream author, who stopped maintaining the project, confirmed that the new upstream for stem is https://gitlab.torproject.org/tpo/network-health/stem. For additional insight regarding short

Bug#1060378: cups-daemon: apparmor denies net_admin capability

2024-10-10 Thread intrigeri
n. And it looks like that bug was closed merely because someone shared how they *silenced the audit trail locally*, which sounds like a misunderstanding to me. Could perhaps the maintainers take another look at #980974 and check if my conclusions make sense? If they do, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=980974#15 Thanks, -- intrigeri

Bug#1084134: python3-dogtail: sniff fails to start on Wayland (No module named 'ponytail')

2024-10-08 Thread intrigeri
y >> for >> python3-dogtail? > > Yes. Contribution welcome ;) I'll come back to it in a month or so to see if we can help. But if anyone else has the skills & bandwidth, by all means, please go ahead and don't wait for us. Cheers, -- intrigeri

Bug#1081396: libvirt-daemon: AppArmor support for QEMU domains is (mostly silently) disabled unless libvirt-daemon-driver-lxc is installed

2024-09-18 Thread intrigeri
Andrea Bolognani (2024-09-16): >> I'll look into it. I'm fairly sure it will require an upstream fix. > > Fixed upstream with Thanks a lot! -- intrigeri

Bug#1081396: libvirt-daemon: AppArmor support for QEMU domains is (mostly silently) disabled unless libvirt-daemon-driver-lxc is installed

2024-09-11 Thread intrigeri
Package: libvirt-daemon Version: 10.7.0-2 Severity: normal If libvirt-daemon-driver-lxc is not installed, libvirtd logs this on startup: libvirtd[2085]: internal error: template '/etc/apparmor.d/libvirt/TEMPLATE.lxc' does not exist … and then apparently the logic to generate AppArmor profiles

Bug#1080465: Please update ruby-packetfu

2024-09-09 Thread intrigeri
Hi Lucas! Thanks for quickly uploading 2.0.0-1 :) I see it FTBFS though, apparently because a few upstream tests need Internet access, which our buildds block. Cheers, -- intrigeri

Bug#1079540: libtest-simple-perl: Ships files also in package libtest2-suite-perl

2024-08-24 Thread intrigeri
Package: libtest-simple-perl Version: 1.302201-1 Severity: important Dear Maintainer, Unpacking libtest-simple-perl (1.302201-1) over (1.302199-1) ... dpkg: error processing archive /tmp/apt-dpkg-install-J17Wob/31-libtest-simple-perl_1.302201-1_all.deb (--unpack): trying to overwrite '/usr/sha

Bug#1078441: apparmor-profiles: Apparmor profile for sshd blocks incoming connections.

2024-08-12 Thread intrigeri
are not mature enough to be shipped in enforce mode by default on Debian. They are shipped in complain mode so that users can test them, choose which are desired, and help improve them upstream if needed. Cheers, -- intrigeri

Bug#1078068: accerciser: Broken with Python 3.12: ModuleNotFoundError: No module named 'imp'

2024-08-06 Thread intrigeri
r/lib/python3/dist-packages/accerciser/plugin/plugin_manager.py", line 21, in from .view import ViewManager File "/usr/lib/python3/dist-packages/accerciser/plugin/view.py", line 23, in import imp ModuleNotFoundError: No module named 'imp' Installing python3-zombie-imp solves it, for the time being. Cheers, -- intrigeri

Bug#1076782: apparmor: vim syntax file in different package that its manpage (apparmor.vim)

2024-07-23 Thread intrigeri
h moving files across packages. Cheers, -- intrigeri

Bug#1074727: ikiwiki: FTBFS: t/po.t: msgfmt: input file doesn't contain a header entry with a charset specification

2024-07-22 Thread intrigeri
un the test suite from within an upstream Git clone. I did not test it in the context of building the Debian package. Cheers, -- intrigeri >From 9baf09f13c266044e39ac7b9b9ebbdb823dad2a5 Mon Sep 17 00:00:00 2001 From: intrigeri Date: Mon, 22 Jul 2024 09:03:08 + Subject: [PATCH] t/po.t: Add m

Bug#1073177: apparmot profile: Failed to spawn child process “/usr/lib/thunderbird/glxtest” (Permission denied)

2024-06-19 Thread intrigeri
ll? Then I'll submit the fix upstream and will copy the updated profile to Vcs-Git. Thanks in advance, Cheers, -- intrigeri

Bug#1066110: tracker-extract: regular crash

2024-03-26 Thread intrigeri
Alban Browaeys (2024-03-21): > On Thu, 14 Mar 2024 22:04:33 +0100 intrigeri > wrote: > https://gitlab.gnome.org/GNOME/tracker-miners/-/merge_requests/516/diffs >> … which I understand will be included in 3.7 stable. > > > Should be fixed by 3.7.0-1 which is available

Bug#1057087: RFA: ikiwiki -- wiki compiler

2024-03-20 Thread intrigeri
iWiki going. Yes, thanks a lot Simon! Cheers, -- intrigeri

Bug#1066110: tracker-extract: regular crash

2024-03-14 Thread intrigeri
://gitlab.gnome.org/GNOME/tracker-miners/-/merge_requests/516/diffs … which I understand will be included in 3.7 stable. Cheers, -- intrigeri

Bug#1053511: [pkg-apparmor] Bug#1053511: Problem found

2023-11-09 Thread intrigeri
Hi, Debian (2023-11-08): > Am 08.11.23 um 18:14 schrieb Thorsten Alteholz: >> >> But this looks rather like a local problem. If your /var/*/cups is not >> at the default location, you should adapt your apparmor files on your >> own, shouldn't you? > Oh yes - that's true. Embarrassing ... I'm

Bug#1039668: apparmor: prompting due to modified conffiles which were not modified by the user: /etc/apparmor.d/abstractions/ubuntu-browsers.d/chromium-browser

2023-10-25 Thread intrigeri
s right now.) For additional context, all this stuff has never been really maintained in Debian proper; it was once used by Ubuntu, together with their own AppArmor profile for Chromium, but since they moved to shipping Chromium as a Snap and don't use this AppArmor policy anymore. Cheers, -- intrigeri

Bug#1038315: [pkg-apparmor] Bug#1050256: autopkgtest fails on debci

2023-09-16 Thread intrigeri
eports to track workarounds on top of #1050256 that's tracking the root cause, or something. Cheers, -- intrigeri

Bug#1050256: [pkg-apparmor] Bug#1050256: autopkgtest fails on debci

2023-09-16 Thread intrigeri
have added workarounds such as disabling PrivateNetwork=yes for autopkgtests Cheers, -- intrigeri

Bug#1051503: closed by intrigeri (Re: [pkg-apparmor] Bug#1051503: AppArmor blocks Evolution launch)

2023-09-12 Thread intrigeri
reopening the bug report and fixing the metadata to make it clearer what it is about. Cheers, -- intrigeri

Bug#1050256: [pkg-apparmor] Bug#1050256: autopkgtest fails on debci

2023-09-09 Thread intrigeri
Bookworm point-release. If I misunderstood something important, please let me know. Cheers, -- intrigeri

Bug#1050256: [pkg-apparmor] autopkgtest fails on debci

2023-09-09 Thread intrigeri
nect the right people. Cheers, -- intrigeri

Bug#1051503: [pkg-apparmor] Bug#1051503: AppArmor blocks Evolution launch

2023-09-09 Thread intrigeri
his problem to the authors of said profile. If my assumptions are incorrect, please help me understand :) Cheers, -- intrigeri

Bug#712451: [pkg-apparmor] AppArmor ABI incompability - is it a userspace or kernel bug?

2023-08-03 Thread intrigeri
at least track) any remaining problem Cheers, -- intrigeri

Bug#1036691: Acknowledgement (onionshare: Missing .desktop file)

2023-05-24 Thread intrigeri
Hi, The corresponding SVG icon is missing as well. Cheers!

Bug#1036691: onionshare: Missing .desktop file

2023-05-24 Thread intrigeri
ian/sid/desktop/org.onionshare.OnionShare.desktop Cheers, -- intrigeri

Bug#929990: [pkg-apparmor] Bug#929990: apparmor: CVE-2016-1585: mount rules grant excessive permissions

2023-05-24 Thread intrigeri
to fill a bug still in the Debian BTS for it. > intrigeri has already explained the siutation in the upstream bug. > > CVE-2016-1585[0]: > | In all versions of AppArmor mount rules are accidentally widened when > | compiled. Upstream has fixed this: - 2.13.x (Bullseye): https:/

Bug#1029760: evince: AppArmor prevents opening PDF files stored on Google drive

2023-03-01 Thread intrigeri
should consider making them use Desktop Portals (e.g. via GTK_USE_PORTAL=1). This would allow us to make the AppArmor policy much stricter, and would solve the whole class of UX problems that this bug is part of. Cheers, -- intrigeri

Bug#1032020: [pkg-apparmor] Bug#1032020: chromium: Missing character after Chromium AppArmor profile update opens up unrestricted system browsing.

2023-03-01 Thread intrigeri
w this problem could have been directly caused by a Debian package or upgrade. Cheers, -- intrigeri

Bug#1029760: evince: AppArmor prevents opening PDF files stored on Google drive

2023-02-14 Thread intrigeri
pP][sS] r, /**.[eE][pP][sS][fFiI23] r, /**.[tT][iI][fF] r, /**.[tT][iI][fF][fF] r, /**.[xX][pP][mM] r, /**.[gG][zZ] r, /**.[bB][zZ]2r, /**.[cC][bB][rRtTzZ7] r, /**.[xX][zZ] r, Could you please share a bit more about the value of "name" in the error message, possibly privately? Does it end with ".pdf", like name="/run//pdf", or does it look different? Cheers, -- intrigeri

Bug#1029299: puppetserver: Broken symlink: /usr/lib/puppetserver/vendored-jruby-gems/specifications/puppetserver-ca-2.3.6.gemspec

2023-01-20 Thread intrigeri
tserver-ca-cli 2.4.0-1 installed, which includes /usr/share/rubygems-integration/all/specifications/puppetserver-ca-2.4.0.gemspec. This satisfies the current dependency that puppetserver has: ruby-puppetserver-ca-cli (>= 2.3.6) Cheers, -- intrigeri

Bug#1017595: [pkg-apparmor] Bug#1017595: Bug#1017595: please make apparmor less noisy

2022-12-10 Thread intrigeri
at can of course change as I become aware of more data): I'm not convinced that installing auditd by default on Debian would solve more AppArmor usability problems than it would create. But a "Suggests" seems well deserved: at least for some use cases, auditd *is* the best solution. Cheers, -- intrigeri

Bug#923345: evince cannot start default browser due to AppArmor

2022-12-10 Thread intrigeri
Control: forwarded -1 https://gitlab.com/apparmor/apparmor/-/issues/291 Hi, Damien Pous (2022-12-02): > On Sun, 22 May 2022 07:53:43 +0200 intrigeri wrote: >> This suggests it's a bug in the exo-open abstraction. >> Is this problem fixed by adding the following line t

Bug#1020153: magit: FTBFS: make[2]: *** [Makefile:111: test] Error 255

2022-11-22 Thread intrigeri
Vvi/super/repo' failed (in /tmp/magit-6jLVvi/super/)") FAILED 18/20 magit-toplevel:submodule (0.249347 sec) passed 19/20 magit-toplevel:tramp (1.286620 sec) passed 20/20 magit-utils:add-face-text-property (0.50 sec) Ran 20 tests, 18 results as expected, 2 unexpected (2022-

Bug#1023251: pdf-redact-tools: Unusable since imagemagick disabled PDF support by default, unmaintained upstream

2022-11-01 Thread intrigeri
Package: pdf-redact-tools Version: 0.1.2-4 Severity: serious Hi, At least on Bullseye and sid, any pdf-redact-tools operation fails with an error like: convert-im6.q16: attempt to perform an operation not allowed by the security policy `PDF' @ error/constitute.c/IsCoderAuthorized/421. Touss,

Bug#1023175: dino-im: Fails to start: Using libsoup2 and libsoup3 in the same process is not supported

2022-10-31 Thread intrigeri
Feel free to downgrade severity if this does not affect all systems :) Thanks for maintaining Dino in Debian! -- intrigeri

Bug#1020275: dpkg-dev: Please add support for -D_FORTIFY_SOURCE=3 hardening build flag

2022-09-22 Thread intrigeri
Hi, Guillem Jover (2022-09-23): > On Mon, 2022-09-19 at 10:06:11 +0200, intrigeri wrote: >> According to >> https://developers.redhat.com/articles/2022/09/17/gccs-new-fortification-level, >> _FORTIFY_SOURCE=3 improves memory management protections. It requires >> glib

Bug#1020275: dpkg-dev: Please add support for -D_FORTIFY_SOURCE=3 hardening build flag

2022-09-19 Thread intrigeri
Package: dpkg-dev Version: 1.21.9 Severity: wishlist Hi, According to https://developers.redhat.com/articles/2022/09/17/gccs-new-fortification-level, _FORTIFY_SOURCE=3 improves memory management protections. It requires glibc 2.34. It's been supported in Clang "for some time" and support was adde

Bug#1017595: [pkg-apparmor] Bug#1017595: please make apparmor less noisy

2022-09-06 Thread intrigeri
Control: tag -1 + moreinfo Hi, Harald Dunkel (2022-08-18): > apparmor writes a bazillion of log entries to dmesg and /var/log/\ > kern.log I don't see this here so I'd like to understand where this comes from. Could you please share the output of "sudo aa-status" or of "ls /etc/apparmor.d/" (wh

Bug#1017776: elpa-ledger: Breaks upgrade to Emacs 28.1

2022-08-20 Thread intrigeri
Package: elpa-ledger Version: 3.1.2~pre3+g5067e408-2 Severity: serious Hi, When upgrading my sid system today, which included the upgrade to Emacs 28.1, byte-compilation of the ledger .el files failed, which broke the upgrade. See log below. I understand that's because define-obsolete-function-a

Bug#1017774: elpa-dimmer: Breaks upgrade to Emacs 28.1

2022-08-20 Thread intrigeri
Package: elpa-dimmer Version: 0.4.2+repack-2 Severity: serious Forwarded: https://github.com/gonewest818/dimmer.el/issues/50 Hi, When upgrading my sid system today, which included the upgrade to Emacs 28.1, this broke: Install emacsen-common for emacs emacsen-common: Handling install of emac

Bug#1017704: python3-bandit: Please update to 1.7.1 or newer, for pyproject.toml support

2022-08-19 Thread intrigeri
Package: python3-bandit Version: 1.6.2-1 Severity: wishlist Hi! In 1.7.1, upstream added support for configuring bandit via pyproject.toml, which is nice: it allows configuring various static analysis tools, linters, etc. in 1 single place. It would be sweet if the package was updated in time fo

Bug#1016028: vagrant-libvirt: allow_existing for disks is broken with recent versions of libvirt

2022-08-17 Thread intrigeri
Hi, anonym (2022-07-25): > The attached patch fixes this, and is in fact already merged > upstream, but not released yet. Update: the fix was released in 0.10.0 upstream (and 0.10.1 was released since). Cheers!

Bug#1016056: src:linux: Please enable CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT=y

2022-07-26 Thread intrigeri
/hypermail/linux/kernel/2104.3/01302.html Ubuntu 22.04 LTS has this setting enabled by default. KSPP recommends enabling it: https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project/Recommended_Settings Thanks for your attention, cheers! -- intrigeri

Bug#869416: [pkg-gnupg-maint] Bug#869416: pinentry-gtk2: fails to request passphrase when importing OpenPGP secret key with Seahorse

2022-07-23 Thread intrigeri
Hi, NIIBE Yutaka (2017-09-27): > intrigeri wrote: >> Can you please take a look, and maybe attach an updated patch? > > OK. > > Attached is updated patch for gcr to fix this issue, by simply supplying > parent's environ untouched, intended to be put under debian

Bug#1014509: apt install lets me fill the filesystem

2022-07-12 Thread intrigeri
Julian Andres Klode (2022-07-07): > My plan is to assume that Installed-Size is close enough to "size in > /usr", and just compare that with free space in /usr with like a 100MB > padding. > > This does not work for kernels which install in /boot, and if anything > were to install stuff to /opt or

Bug#1014509: apt install lets me fill the filesystem

2022-07-07 Thread intrigeri
Package: apt Version: 2.5.1 Severity: wishlist Hi, On a system with a very simple partition layout (/boot and /), with 2GB available on the root filesystem, APT lets me try to install packages that will fill the filesystem: 0 upgraded, 355 newly installed, 0 to remove and 0 not upgraded. Nee

Bug#988204: [pkg-apparmor] Bug#988204: Improved patch

2022-07-05 Thread intrigeri
Hi, intrigeri (2022-02-13): > Alistair J R Young (2022-02-12): >>> So yeah, Alistair, please submit your last patch a merge request upstream, >>> as >>> Christian suggested :) >> >> I've done this now and it has been merged: >> >>

Bug#923345: evince cannot start default browser due to AppArmor

2022-05-21 Thread intrigeri
Hi, This bug report seems to be about 2 distinct problems: 1. Evince cannot start external applications on XFCE because the exo-open abstraction lacks permission to execute /usr/bin/xfce4-mime-helper. A cursory look at the sources suggests that recent exo-open needs to execute xfce4-

Bug#971424: gsd-usb-protection fails to add rule to allow USB devices

2022-03-21 Thread intrigeri
Hi, Tobias Mueller (2021-08-13): > This has been reported as > https://gitlab.gnome.org/GNOME/gnome-settings-daemon/-/issues/582. > > And it has already been fixed, but not yet released. > The patch reverts a workaround for a bug in usbguard<0.7.7. I understand the fix was released in 41.rc. Sa

Bug#1006872: RFH: apparmor -- user-space parser utility for AppArmor

2022-03-09 Thread intrigeri
Hi Andrej, Andrej Shadura (2022-03-07): > This reminded me I promised to work on dh-apparmor. I should find > time for that, Great! > maybe also for apparmor itself. Sounds good. Please keep me updated as you think about it :)

Bug#1006872: RFH: apparmor -- user-space parser utility for AppArmor

2022-03-07 Thread intrigeri
Package: wnpp Severity: normal X-Debbugs-Cc: debian-de...@lists.debian.org, pkg-apparmor-t...@alioth-lists.debian.net Control: affects -1 src:apparmor Hi, I request assistance with maintaining the apparmor package. AppArmor has been enabled by default on the Linux ports of Debian since Buster.

Bug#1003153: [pkg-apparmor] Bug#1003153: /etc/apparmor.d/usr.sbin.apache2: Apache profile complains when ss -tnlp is run

2022-02-17 Thread intrigeri
Control: forwarded -1 https://gitlab.com/apparmor/apparmor/-/merge_requests/852 Craig Small (2022-02-17): > Not sure if Debian BTS handles forwards to MR, I've only ever done it for > issues. I don't know if the code that will automatically sync the upstream state here works, but apart of that th

Bug#1003153: [pkg-apparmor] Bug#1003153: Bug#1003153: /etc/apparmor.d/usr.sbin.apache2: Apache profile complains when ss -tnlp is run

2022-02-16 Thread intrigeri
Hi, Craig Small (2022-02-17): > On Sat, 12 Feb 2022 at 20:35, intrigeri wrote: > >> So it seems to me a good solution may be to allow being ptraced >> in the "apache2-common" abstraction. >> > That makes sense. :) >> Would one of you be intereste

Bug#1005758: hiera-eyaml: eyaml command is unusable with ruby-rubygems 3.3.5-2

2022-02-14 Thread intrigeri
Package: hiera-eyaml Version: 3.2.2-2 Severity: serious Hi, I usually use "eyaml edit FILE.eyaml" to edit files. It's currently broken for me on sid. Even this simpler command fails: $ eyaml version Traceback (most recent call last): 7: from /bin/eyaml:25:in `' 6: from /bin/

Bug#995367: Re-enable apparmor on Debian Live?

2022-02-14 Thread intrigeri
Control: tag -1 + moreinfo Hi, Trent W. Buck (2021-09-30): > The original bug report complained about LibreOffice and Evince. > I tested those specifically. > > LibreOffice is in "complain" mode. > It's rules fail, but there is no user-visible impact. > > Evince is in "enforce" mode. > I couldn't

Bug#988204: [pkg-apparmor] Bug#988204: Bug#988204: Bug#988204: Improved patch

2022-02-12 Thread intrigeri
Alistair J R Young (2022-02-12): >> So yeah, Alistair, please submit your last patch a merge request upstream, as >> Christian suggested :) > > I've done this now and it has been merged: > > https://gitlab.com/apparmor/apparmor/-/merge_requests/812 Awesome, thanks!

Bug#988204: [pkg-apparmor] Bug#988204: Bug#988204: Improved patch

2022-02-12 Thread intrigeri
Control: tag -1 - moreinfo Control: tag -1 + upstream Control: found -1 3.0.3-6 Hi, Sorry for the noise, I missed some context and got stuff wrong in my previous message. intrigeri (2022-02-12): > Christian Boltz (2021-11-08): >> Your patch looks like something that should (also?)

Bug#988204: [pkg-apparmor] Bug#988204: Improved patch

2022-02-12 Thread intrigeri
Hi Christian, Christian Boltz (2021-11-08): > Your patch looks like something that should (also?) be fixed upstream. My understanding is that the problem here is caused by a Debian patch: https://salsa.debian.org/apparmor-team/apparmor/-/blob/debian/master/debian/patches/debian/Make-the-systemd-

Bug#1003153: [pkg-apparmor] Bug#1003153: /etc/apparmor.d/usr.sbin.apache2: Apache profile complains when ss -tnlp is run

2022-02-12 Thread intrigeri
Control: tag -1 + upstream Hi, Craig Small (2022-01-05): > On 2022-01-05 at 12:24, debian-b...@cboltz.de wrote: >> (Nevertheless, the apache hats should allow to be ptraced. OK! >> I'll leave that to the maintainer of the Apache profile in Debian - >> and would love to see the fix upstreamed.)

Bug#1004375: onionshare: Please consider demoting dependency on obfs4proxy to Recommends

2022-01-25 Thread intrigeri
Package: onionshare Version: 2.2-3 Severity: wishlist Hi, onionshare currently Depends: obfs4proxy. But at least recent versions of OnionShare (I did not check which ones exactly) have code to cope just fine when obfs4proxy is not available, so "Depends" seems a bit too strong here and it sounds

Bug#1004374: obfs4proxy: Traffic is trivially distinguishable (Elligator2 public key representative leak)

2022-01-25 Thread intrigeri
Package: obfs4proxy Version: 0.0.8-1+b6 Severity: important Tags: security Hi, Please see https://lists.torproject.org/pipermail/anti-censorship-team/2022-January/000213.html tl;dr: > All existing versions prior to the migration to the new code […] are > fatally broken, and trivial to distingui

Bug#1004012: tor: AppArmor policy needs update for recent obfs4proxy

2022-01-19 Thread intrigeri
rom e5711ee98c5115cc24fe61b7346de92473b65199 Mon Sep 17 00:00:00 2001 From: intrigeri Date: Wed, 19 Jan 2022 10:28:03 + Subject: [PATCH] AppArmor: allow access to /sys/kernel/mm/transparent_hugepage/hpage_pmd_size obfs4proxy 0.0.11 needs this. --- debian/tor.apparmor-profile.abstraction | 1 + 1 file changed

Bug#982436: procps: Please allow overriding protect-links.conf settings via /etc/sysctl.conf

2022-01-14 Thread intrigeri
Hi, Since then, a duplicate bug report was filed (#1000908) and promptly fixed in 2:3.3.17-6 ⇒ this bug report can now be closed :) Cheers!

Bug#995909: python3-fava: Fails to start with jinja2 3.0.1

2021-12-13 Thread intrigeri
Hi, Dr. Tobias Quathamer (2021-12-13): > thanks a lot for your work! I've added some more tweaks and uploaded the > new version to unstable. Thanks! > As a side note: in your local repository, there's probably a tag for > upstream/1.20.1, which is missing on salsa. Could you please push that

Bug#1001173: Moo: Should use Depends for libclass-xsaccessor-perl (instead of Recoomends)

2021-12-05 Thread intrigeri
Hi, Graham Knop (2021-12-05): > I'm the maintainer of Moo. I'm seizing this opportunity to thank you for your work. Moo is one of the few reasons why I still enjoy writing Perl code when possible :) > The reason Class::XSAccessor isn't listed as a hard prerequisite is > that Moo is intended to b

Bug#1001173: Moo: Should use Depends for libclass-xsaccessor-perl (instead of Recoomends)

2021-12-05 Thread intrigeri
Hi, Felix Lechner (2021-12-05): > Moo performs faster when Class::XSAccessor is available [1] but > libmoo-perl only Recommends it. More important, Moo's behavior changes > when Class::XSAccessor is installed. [1] For consistency as well as > performance, Moo should probably Depend on libclass-xs

Bug#995909: python3-fava: Fails to start with jinja2 3.0.1

2021-12-05 Thread intrigeri
Hi, intrigeri (2021-12-05): >> I understand this is upstream bug >> https://github.com/beancount/fava/issues/1266, >> that's been fixed in the 1.19 release. > > Upgrading fava requires python3-flask-babel (>= 1). > > I'll try to update it. I'

Bug#995909: Acknowledgement (python3-fava: Fails to start with jinja2 3.0.1)

2021-12-05 Thread intrigeri
Hi, > I understand this is upstream bug > https://github.com/beancount/fava/issues/1266, > that's been fixed in the 1.19 release. Upgrading fava requires python3-flask-babel (>= 1). I'll try to update it.

Bug#997707: fava: FTBFS: help2man: can't get `--help' info from PYTHONPATH="/<>/src" python3 -m fava.cli

2021-12-05 Thread intrigeri
Control: tag 995909 + ftbfs Control: tag 995909 + bookworm Control: tag 995909 + sid Control: severity 995909 serious Control: reassign 995909 src:fava Control: merge -1 995909 Hi, Lucas Nussbaum (2021-10-24): >> help2man: can't get `--help' info from PYTHONPATH="/<>/src" >> python3 -m fava.cli

Bug#1000924: libclang-perl: Please upgrade to llvm-toolchain-12 or 13

2021-11-30 Thread intrigeri
Hi, Sylvestre Ledru (2021-12-01): > As part of the effort to limit the number of llvm packages in the > archive, it would be great if you could upgrade to -13 (or -12). > > Bookworm won't ship with llvm-toolchain-11 > > llvm-defaults is now pointing to -13. I understand a binNMU would be sufficie

Bug#998686: [pkg-apparmor] Bug#998686: apparmor: b-d on python3-all-dev, but not built for all supported Python3 versions

2021-11-08 Thread intrigeri
Control: clone -1 -2 Control: retitle -1 Python bindings fail to build with Python 3.10 Control: tag -1 + upstream Control: forwarded -1 https://gitlab.com/apparmor/apparmor/-/issues/202 Control: retitle -2 Failure to build for 1 of the supported Python 3 versions does not trigger FTBFS, while it

  1   2   3   4   5   6   7   8   9   10   >