Bug#1091305: nfdump: FTBFS on armhf: dh_auto_test: error: make -j1 check "TESTSUITEFLAGS=-j1 --verbose" VERBOSE=1 returned exit code 2

2025-01-11 Thread Bernhard Schmidt
Control: tags -1 + moreinfo On 23/12/24 06:41 PM, Lucas Nussbaum wrote: Hi, > During a rebuild of all packages in sid, this package failed to build > on armhf. > > This package currently has binary packages on armhf, so this is a regression. > Also, there are no known issues on amd64 or arm64 a

Bug#1086653: openvpn: FTBFS: FAIL: t_cltsrv.sh

2024-11-03 Thread Bernhard Schmidt
Control: tags -1 + confirmed Control: patch -1 https://github.com/OpenVPN/openvpn/commit/78e0c5f2f57a18e8ea60951696a458a4b3ff3621 Hi, 2024-11-02 17:48:40 VERIFY ERROR: depth=1, error=certificate has expired: C=KG, ST=NA, L=BISHKEK, O=OpenVPN-TEST, emailAddress=me@myhost.mydomain, serial=1162

Bug#1053142: chromium cannot startup after libfreetype6 upgrade to 2.12.1+dfsg-5+deb12u1

2023-09-28 Thread Bernhard Schmidt
Control: affects -1 src:freetype Technically it probably should be the other way around, but I fear this will be missed otherwise. Marking freetype as affected to at least it shows up there.

Bug#1040447: odbc-mariadb cannot set up odcb-mariadb

2023-08-08 Thread Bernhard Schmidt
Control: severity -1 important Control: tags -1 unreproducible Same as Tuukka I cannot reproduce this.

Bug#1040830: ESNET-SECADV-2023-0001: iperf3 memory allocation hazard and crash

2023-07-11 Thread Bernhard Schmidt
Source: iperf3 Version: 3.13-2 Severity: serious Tags: security upstream X-Debbugs-Cc: Debian Security Team A security advisory for iperf3 has been issued. https://downloads.es.net/pub/iperf/esnet-secadv-2023-0001.txt.asc -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 ESnet Software Security

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-08 Thread Bernhard Schmidt
Hi Utkarsh, I've actually managed to prepare a final update that I'm ready to upload - this has quite some fixes plus 2 new CVE fixes. Would you please test the new resulting binaries and make sure they look sane enough? :) The binaries can be found at https://people.debian.org/~utkarsh/lts/rub

Bug#1037178: puppet does not sync files anymore after recent ruby2.5 security upload

2023-06-06 Thread Bernhard Schmidt
Package: libruby2.5 Version: 2.5.5-3+deb10u5 Severity: grave Hi, I can't quite figure out why, but the latest security upload of ruby2.5 in Buster breaks the ability of the puppet agent to pull files from the master With 2.5.5-3+deb10u4: # puppet agent --onetime --server puppet-kom.srv.lrz.de -

Bug#919234: ttls fails with tls 1.3, enabled by default

2023-03-07 Thread Bernhard Schmidt
Control: tags -1 + pending Hi Fabio, Am 07.03.23 um 17:00 schrieb Fabio PEDRETTI: Hi, 3.2.1 currently in testing fixed most issues, however there is still an issue preventing freeradius working with TLS 1.3. The issue was reported upstream at: https://github.com/FreeRADIUS/freeradius-server/is

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-09 Thread Bernhard Schmidt
Hi, not about src:bind9, building the bind9-libs binary package (yes, this is totally confusing, even to Debian tooling) I though that had been already removed: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1011538 But I guess

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-09 Thread Bernhard Schmidt
Am 09.01.23 um 14:30 schrieb Ondřej Surý: Hi Ondrej, Looking at #942501 and #942502, the intention seems to be to not ship bind9-libs in bookworm. I agree, Ccing Ondrej who has done the heavy lifting on this package. AFAICT there is no binary reverse dependency in unstable, and #942501 "just

Bug#1011437: Should bind9-libs be shipped in bookworm?

2023-01-08 Thread Bernhard Schmidt
On 22/05/22 11:47 PM, Adrian Bunk wrote: > Looking at #942501 and #942502, the intention seems to be to not > ship bind9-libs in bookworm. I agree, Ccing Ondrej who has done the heavy lifting on this package. AFAICT there is no binary reverse dependency in unstable, and #942501 "just" needs a NM

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Control: tags -1 + pending Control: tags -1 - moreinfo Hi, I have no problem fixing this up in unstable, but I think this does not warrant a stable update. That would be unfortunate, as it means we will probably never have a stable release without FTBFS bugs. "Never" is too hard, I will fi

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Hi, That's an odd one. I cannot reproduce it in any version, because in all my attempts (1.6.22-2 in a bullseye sbuild, in an sid sbuild, as well as in the build logs of the official buildds for all of 1.6.22-2, 1.6.25-1 and 1.7.1-1) tzdata is actually installed in the build environment, even

Bug#1027379: nfdump: FTBFS in bullseye (missing build-depends on tzdata)

2023-01-02 Thread Bernhard Schmidt
Control: tags -1 + moreinfo Hi Santiago, During a rebuild of all packages in bullseye, your package failed to build: [...] Note: I'm using the "patch" tag because there is an obvious fix > (indicated in the subject). That's an odd one. I cannot reproduce it in any version, because in all

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
On 27/12/22 09:43 PM, Santiago Vila wrote: > > bind-dyndb-ldap has a tight dependency on the upstream version of bind9-libs > > (built by src:bind9) and needs to be rebuilt on every new upstream version > > until https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1014503 is fixed. > > Hello. I sup

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
Control: forwarded -1 https://pagure.io/bind-dyndb-ldap/issue/216 On 27/12/22 06:16 PM, Bernhard Schmidt wrote: Hi, so this is really massively broken :-( > ../../src/log.h:21:9: error: too few arguments to function ‘isc_error_fatal’ >21 | isc_error_fatal(__FILE__, __

Bug#1027094: FTBFS against bind9 9.18.10

2022-12-27 Thread Bernhard Schmidt
Source: bind-dyndb-ldap Version: 11.10-1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) X-Debbugs-Cc: team+...@tracker.debian.org bind-dyndb-ldap has a tight dependency on the upstream version of bind9-libs (built by src:bind9) and need

Bug#1021125: Bug#1021576: linphone-desktop: Core dumped: Program terminated with signal SIGABRT, Aborted.

2022-11-03 Thread Bernhard Schmidt
Hi, I think this Bug can be downgraded and/or closed. We've rebuilt both dependencies in Debian (liblime and linphone). Since soci is not using shlibs the generated dependency is on the 4.0.3 anyway. I don't see a way to fix this without breaking lime/linphone again. Bernhard

Bug#1019233: conserver FTBFS on IPV6-only buildds

2022-10-24 Thread Bernhard Schmidt
After some thoughts on it I've decided to make the test-suite non-fatal in the pending 8.2.7-2 upload. The root cause of the test-suite error appears to be that conserver is using AI_ADDRCONFIG, and fails to resolve localhost to 127.0.0.1 on machines that do not have non-local IPv4 connectivity.

Bug#1021125: Bug#1021576: linphone-desktop: Core dumped: Program terminated with signal SIGABRT, Aborted.

2022-10-12 Thread Bernhard Schmidt
Am 11.10.22 um 18:19 schrieb Dennis Filder: The change in 5.0.37-6 was tiny and I doubt it broke something. But maybe you're running into #1021125: liblinphone10:amd64 5.0.37-6 is already linked against soci/4.0.3-1, but liblime0 5.0.37+dfsg-4 is still linked against soci/4.0.1-5 and there was

Bug#1017148: soci: FTBFS: catch.hpp:6490:33: error: size of array ‘altStackMem’ is not an integral constant-expression

2022-09-05 Thread Bernhard Schmidt
Control: tags -1 + patch upstream fixed-upstream Control: forwarded -1 https://github.com/SOCI/soci/pull/886 On 14/08/22 09:18 AM, Lucas Nussbaum wrote: > During a rebuild of all packages in sid, your package failed to build > on amd64. > > > /<>/tests/catch.hpp:6490:33: error: size of array >

Bug#1018016: bind9-libs not found for sid

2022-09-05 Thread Bernhard Schmidt
Hi, I’ve recently moved, so everything is in but of disarray including my builder machine. The git repository should be up to date, so if this cannot wait a day or two until I connect rest of my network, anybody should be able to build and upload new upstream version using git-buildpackage. Alte

Bug#1014133: asterisk: Asterisk fails to build from source

2022-07-01 Thread Bernhard Schmidt
Control: severity -1 important Control: found -1 1:16.16.1~dfsg-1 Control: fixed -1 1:16.16.1~dfsg+~2.10-1 Hi Ralf, I am not very familiar with asterisk as packaged for Bullseye - only know that it was pretty unusually done. Maybe try build in a pristine build-environment. What do you mean by

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-06-26 Thread Bernhard Schmidt
Control: tags -1 pending Hi, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look a

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-06-26 Thread Bernhard Schmidt
Control: tags -1 pending Hi, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look a

Bug#1012059: bind9: autopkgtest regression on amd64 and armhf: connection refused

2022-05-30 Thread Bernhard Schmidt
Hi Ondrej, With a recent upload of bind9 the autopkgtest of bind9 fails in testing on amd64 and armhf when that autopkgtest is run with the binary packages of bind9 from unstable. It passes when run with only packages from testing. In tabular form: I have had a brief look and it seems we are

Bug#1008015: Bugfix might break some setups

2022-05-23 Thread Bernhard Schmidt
Hi, this is definitely not an issue with the fix for Bug#1008015, which was a very minor security bugfix targeted for You are running unstable, therefor you have been upgraded to OpenVPN 2.6 and OpenSSL 3.0. Could you please file a new bug about this with as much information as available a

Bug#1006519: Already fixed in 2.6.0~git20220510+dco-1 in experimental

2022-05-20 Thread Bernhard Schmidt
Hi Michael, Am 19.05.22 um 16:03 schrieb Michael Biebl: On Sun, 15 May 2022 16:02:48 +0300 Adrian Bunk wrote: Version: 2.6.0~git20220510+dco-1 openvpn (2.6.0~git20220510+dco-1) experimental; urgency=medium ...   * Build against OpenSSL 3.0  -- Bernhard Schmidt   Fri, 13 May 2022 00:01:35

Bug#1001669: closed by Debian FTP Masters (reply to Aniol Martí ) (Bug#1001669: fixed in openvpn-auth-ldap 2.0.4-2)

2022-03-21 Thread Bernhard Schmidt
Hi, unfortunately this is still happening in 2.0.4-2 https://ci.debian.net/packages/o/openvpn-auth-ldap/unstable/amd64/ Right now this would be preventing the new version of openvpn to migrate (I can retry of course). Bernhard

Bug#983985: bctoolbox: ftbfs with GCC-11

2022-01-30 Thread Bernhard Schmidt
Hi, bctoolbox 5.0.37 builds perfectly with mbedtls 2.28.0-0.1 here, I will test with 2.28.0-0.2 ASAP. 4.4.13-3 (just uploaded) builds fine against mbedtls 2.28.0-0.2 in experimental, so go ahead and sorry for the delay. Bernhard

Bug#991931: CVE-2021-32686 / AST-2021-009: pjproject/pjsip: crash when SSL socket destroyed during handshake

2021-08-06 Thread Bernhard Schmidt
Package: src:asterisk Severity: serious Tags: security upstream patch https://downloads.asterisk.org/pub/security/AST-2021-009.html Summary:pjproject/pjsip: crash when SSL socket destroyed during handshake Nature of Advisory: Denial of service Susceptibility: Remote u

Bug#983365: [PATCH] Re: Bug#983365: linphone-desktop: chat messages

2021-03-17 Thread Bernhard Schmidt
Dear David, >>> I finally found the bug: ... > > Excellent! > > Please make sure you also test a file transfer, which is part of the > chat message interface [I couldn't try since the chat msgs itself > didn't work ...], The file transfer functionality is absolutely > essential as well, afaic at

Bug#982332: Status regarding Dahdi RC bugs?

2021-03-08 Thread Bernhard Schmidt
Hi Tzafrir, what are your plans regarding the three RC bugs filed against dahdi-* (Bug#982332, Bug#982334, Bug#982389)? They would case Asterisk's removal from Bullseye if they are not fixed. Since Asterisk would need to drop a binary package they are not easily reintroduced either. Bernhard

Bug#983365: [PATCH] Re: Bug#983365: linphone-desktop: chat messages

2021-03-03 Thread Bernhard Schmidt
Am 03.03.21 um 18:55 schrieb Dennis Filder: Hi Dennis, > On Sun, Feb 28, 2021 at 11:07:31PM +0100, Bernhard Schmidt wrote: >> an updated liblinphone has been uploaded to sid yesterday. Could you >> please try liblinphone10 and liblinphone++10 from sid (4.4.21-2) and >> re

Bug#983365: Info received (Bug#983365: linphone-desktop: chat messages)

2021-03-02 Thread Bernhard Schmidt
Hi David, Am 01.03.21 um 20:24 schrieb David Pirotte: > Thanks all for having worked on this. Sorry for the little delay in > answering, I actually thought the packages would 'find their way' to > bullseye, so I was (and still am) updating daily, a few times per day > actually, but now I see you

Bug#983365: Info received (Bug#983365: linphone-desktop: chat messages)

2021-02-28 Thread Bernhard Schmidt
Hi, an updated liblinphone has been uploaded to sid yesterday. Could you please try liblinphone10 and liblinphone++10 from sid (4.4.21-2) and report back? If it does not work you might need libsoci-core4.0 and libsoci-sqlite3-4.0 from unstable as well (4.0.1-4). Thanks, Bernhard

Bug#983365: linphone-desktop: chat messages

2021-02-26 Thread Bernhard Schmidt
Am 26.02.21 um 15:19 schrieb Bill Blough: Hi Bill, > Hi, > >> Have you reached out to the SOCI maintainer in private already? I don't >> see a bug report on this. If we can get a targeted fix uploaded for this >> within the next days (next step of the freeze is on March 10th, with a >> migration

Bug#983365: linphone-desktop: chat messages

2021-02-26 Thread Bernhard Schmidt
Hi Dennis, thanks a lot for debugging this! BTW, linphone is in desperate need of co-maintainers :-) That's a lot more useful than complaining about the package not being tested (it is, but I do not know anyone using the Chat feature, and I certainly don't). Honestly I don't know why there is E

Bug#983365: linphone-desktop: chat messages

2021-02-23 Thread Bernhard Schmidt
Control: tags -1 help Dear David, > 1- chat messages (history) are not displayed when I launch the app, > although I can see they are in the .local/share/linphone/linphone.db > file (using sqliteb or sqlitebrowser); > > 2- when someone sends me a message, it 'pops' a notification with the > mess

Bug#978616: mediastreamer2: doesn't build correct libraries with cmake?

2020-12-30 Thread Bernhard Schmidt
Dear Gianfranco, Thanks for filing this bug report. I’m away for the next couple of days and could not check, but wouldn’t just patching the pkgconfig file (your second option) be a lot easier? Upstream merged both libraries and they probably just forgot to change the pkgconfig file as well. I

Bug#978489: QML QtQuick dependencies

2020-12-28 Thread Bernhard Schmidt
Hi, I've recently packaged a QML based application (linphone-desktop) and I have been hit with a couple of missing qml-module-* dependencies in the resulting binary package which caused RC bugs. The latest one (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978489) I cannot even reproduce loca

Bug#978489: missing dependency on qml-module-qtquick-controls

2020-12-28 Thread Bernhard Schmidt
Control: tags -1 + pending Hi Marco, Am 28.12.20 um 01:00 schrieb Marco d'Itri: > Package: linphone-desktop > Version: 4.2.5-2 > Severity: grave > > Or else linphone will crash with: > > [00:50:46:566][0x5618e548aed0][Info]app/App.cpp:784: "Open Linphone app." > [00:50:46:566][0x5618e548aed0][I

Bug#957480: libsrtp2: ftbfs with GCC-10

2020-12-25 Thread Bernhard Schmidt
Control: tags -1 patch This might fix it... https://github.com/cisco/libsrtp/commit/716a73862b387a2107f37398c0fb7d9a754c0ccd

Bug#977590: freeradius: After upgrade to buster, freeradius doesn't talk over the network anymore

2020-12-18 Thread Bernhard Schmidt
Control: severity -1 important Control: tags -1 moreinfo Hi Harald, I'm going to downgrade this because - it does not break unrelated software ... The radius server not running might cause other software not to be able to authenticate anymore, but Radius can be easily made redundant. - this is t

Bug#925775: mediastreamer2: ftbfs with GCC-9

2020-12-08 Thread Bernhard Schmidt
Am 06.12.20 um 21:33 schrieb Paul Gevers: Hi Paul, > On Wed, 27 Mar 2019 19:47:03 + Matthias Klose wrote: >> The package fails to build in a test rebuild on at least amd64 with >> gcc-9/g++-9, but succeeds to build with gcc-8/g++-8. The >> severity of this report will be raised before the bu

Bug#925638: Bug#892325: Bug#925638: closed by Debian FTP Masters (reply to Bernhard Schmidt ) (Bug#925638: fixed in belle-sip 4.3.1+dfsg-1)

2020-12-08 Thread Bernhard Schmidt
Am 04.12.20 um 23:45 schrieb Bernhard Schmidt: > Hi, > > > Am 04.12.20 um 19:23 schrieb Bernhard Schmidt: >> Dear Mika, >> >>> belle-sip is currently missing in Debian/testing AKA bullseye >>> because of this issue (which is only fixed in experimental

Bug#925638: closed by Debian FTP Masters (reply to Bernhard Schmidt ) (Bug#925638: fixed in belle-sip 4.3.1+dfsg-1)

2020-12-04 Thread Bernhard Schmidt
Hi, Am 04.12.20 um 19:23 schrieb Bernhard Schmidt: > Dear Mika, > >> belle-sip is currently missing in Debian/testing AKA bullseye >> because of this issue (which is only fixed in experimental yet): >> >> | Migration status for belle-sip (- to 1.6.3-5): BLOCKED: R

Bug#925638: closed by Debian FTP Masters (reply to Bernhard Schmidt ) (Bug#925638: fixed in belle-sip 4.3.1+dfsg-1)

2020-12-04 Thread Bernhard Schmidt
Dear Mika, > belle-sip is currently missing in Debian/testing AKA bullseye > because of this issue (which is only fixed in experimental yet): > > | Migration status for belle-sip (- to 1.6.3-5): BLOCKED: Rejected/violates > migration policy/introduces a regression > | Issues preventing migration

Bug#957470: FTBFS Bugs in Debian revdeps dahdi-tools and libpri

2020-11-16 Thread Bernhard Schmidt
Hi Tzafrir, >> >> could you have a look at Bug#957117 and #957470? They are causing >> Asterisk to be removed from testing. > > Uploaded a fix for dahdi-tools. As for libpri: this is basically using > index from data[0] that is the end of the header. > > My "fix" is to silence those checks (see p

Bug#957470: FTBFS Bugs in Debian revdeps dahdi-tools and libpri

2020-10-14 Thread Bernhard Schmidt
Hi Tzafrir, > could you have a look at Bug#957117 and #957470? They are causing > Asterisk to be removed from testing. > > If you currently don't have time to fix this we should probably tag the > bugs with help and maybe temporarily drop them from the build-deps. Both bugs are still present (I

Bug#969448: bind9: dies with assertion and does not restart

2020-09-07 Thread Bernhard Schmidt
Control: tags -1 + confirmed pending Hi, thanks for the report. > Aug 31 16:47:00 tucano named[786855]: resolver.c:5125: > INSIST(dns_name_issubdomain(&fctx->name, &fctx->domain)) failed, back trace I see that Ondrej has added an upstream patch to fix this in the git repo. https://salsa.debia

Bug#957117: FTBFS Bugs in Debian revdeps dahdi-tools and libpri

2020-08-19 Thread Bernhard Schmidt
Hi Tzafrir, could you have a look at Bug#957117 and #957470? They are causing Asterisk to be removed from testing. If you currently don't have time to fix this we should probably tag the bugs with help and maybe temporarily drop them from the build-deps. Bernhard

Bug#958934: bind9: named fails to start after upgrade to 9.16.2

2020-04-27 Thread Bernhard Schmidt
Am 26.04.20 um 23:42 schrieb R. Scott Bailey: Dear Scott, > Life was good on my DNS server until my recent update to 9.16.2-3. > After upgrading, the exact configuration that was happy now fails to > start. Example: > > # named -g -u bind > 26-Apr-2020 17:25:50.921 Could not open '//run/named/n

Bug#954736: isc-dhcp rebuild enough?

2020-04-16 Thread Bernhard Schmidt
Hi Ondrej, > > I think that simple binNMU should be enough. That’s the reason I have > introduced the src:bind9-libs package, so there’s a grace period for > isc-dhcp to either die or adapt. thanks, I've filed Bug#956895 for the binNMU. Bernhard

Bug#954736: isc-dhcp rebuild enough?

2020-04-06 Thread Bernhard Schmidt
Hi, since 9.16 the bind9 package is not building the bind9 shared libraries anymore, which have previously been used by isc-dhcp instead of the bundled bind9 source. Ondrej had filed Bug#942502 about this last October. bind9 9.16 has now been uploaded to unstable, but (among two RC bugs) the unin

Bug#936558: Ping

2019-12-27 Thread Bernhard Schmidt
On Tue, Dec 17, 2019 at 10:44:42PM +0100, Bernhard Schmidt wrote: > Pinging this bug to delay testing removal, the fix is in unstable but > migration is currently blocked by several RC bugs in libxcrypt. And again. Hopefully this will be solved soon. Bernhard

Bug#936558: Ping

2019-12-17 Thread Bernhard Schmidt
Pinging this bug to delay testing removal, the fix is in unstable but migration is currently blocked by several RC bugs in libxcrypt.

Bug#936558: freeradius: Python2 removal in sid/bullseye

2019-11-29 Thread Bernhard Schmidt
Control: tags -1 + pending The change replacing freeradius-python2 with freeradius-python3 has been staged in the py2removal branch at https://salsa.debian.org/debian/freeradius/commits/py2removal and uploaded to experimental in 3.0.20+dfsg-2. It is now waiting in NEW.

Bug#932299: closed by Vincent Danjean (Bug#932299: fixed in owfs 3.2p3+dfsg1-3)

2019-08-05 Thread Bernhard Schmidt
On Thu, Jul 25, 2019 at 10:54:04AM +, Debian Bug Tracking System wrote: Hi Vincent, > This is an automatic notification regarding your Bug report > which was filed against the src:owfs package: > > #932299: owfs: FTBFS: relocation R_X86_64_32 against symbol `_Py_NoneStruct' > can not be use

Bug#933634: FTBFS on armel, mips, mipsel, powerpc, sh4 due to atomics

2019-08-01 Thread Bernhard Schmidt
Package: src:freeradius Version: 3.0.19+dfsg-1 Severity: serious FreeRADIUS 3.0.19 FTBFSes on armel, mips, mipsel, powerpc and sh4 due to /usr/bin/ld: build/lib/.libs/libfreeradius-radius.so: undefined reference to `__atomic_compare_exchange_8' /usr/bin/ld: build/lib/.libs/libfreeradius-radius.s

Bug#927932: bind9: CVE-2018-5743: Limiting simultaneous TCP clients is ineffective

2019-04-24 Thread Bernhard Schmidt
Package: src:bind9 Severity: grave Tags: security, upstream CVE: CVE-2018-5743 Document version:2.0 Posting date:24 April 2019 Program impacted:BIND Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9

Bug#927827: Bug#927747: [Pkg-samba-maint] Bug#927747: bind9_dlz backend is entirely broken in Debian

2019-04-24 Thread Bernhard Schmidt
Control: found -1 1:9.11.5.P4+dfsg-1 Control: tags -1 + pending On Tue, Apr 23, 2019 at 10:24:54PM +0200, Mathieu Parent wrote: > +/var/lib/samba/bind-dns/** rwk, > > But we may do better with something like this (to be tested and improved): > >/var/lib/samba/private/dns.keytab r, >/var

Bug#926958: Proposed security upload for FreeRADIUS

2019-04-24 Thread Bernhard Schmidt
Am 24.04.19 um 21:23 schrieb Salvatore Bonaccorso: Hi Salvatore, >> I've gained access to the FreeRADIUS salsa repo and have pushed a new >> debian/stretch branch containing last years security upload and the >> cherry-picked fixes for #926958 >> >> It applies and builds cleanly, I'm currently wa

Bug#926958: Proposed security upload for FreeRADIUS

2019-04-24 Thread Bernhard Schmidt
Am 24.04.19 um 17:42 schrieb Bernhard Schmidt: > I've gained access to the FreeRADIUS salsa repo and have pushed a new > debian/stretch branch containing last years security upload and the > cherry-picked fixes for #926958 And by the way, it should not be affecting Jessie, as EA

Bug#926958: Proposed security upload for FreeRADIUS

2019-04-24 Thread Bernhard Schmidt
ion bypass) (Closes: #926958) + * d/gbp.conf: set debian-branch for Stretch + + -- Bernhard Schmidt Wed, 24 Apr 2019 17:25:10 +0200 + freeradius (3.0.12+dfsg-5+deb9u1) stretch-security; urgency=high * Apply upstream patches: diff -Nru freeradius-3.0.12+dfsg/debian/gbp.conf freeradius-3.0.12+d

Bug#926737: Possible memory leak after upgrading from 16.1.1 to 16.2.1

2019-04-09 Thread Bernhard Schmidt
Source: asterisk Version: 1:16.2.1~dfsg-1 Severity: serious Hi, I intend to look at this myself, but I'm short on time right now. Filing this bug so I don't forget (and maybe someone else can look at it). After having upgraded one of my test systems from 16.1.1 to 16.2.1 shows the Asterisk proce

Bug#925919: RFT: linux with fix for VMware regression

2019-03-30 Thread Bernhard Schmidt
Am 30.03.19 um 05:15 schrieb Ben Hutchings: Hi Ben, > I've uploaded a new version of linux to: > https://people.debian.org/~benh/packages/jessie-security/ > which I believe will fix this regression (bug #925919). Please let me > know whether it works for you. Had been hit by the crash before, w

Bug#925263: Do not release with Buster

2019-03-21 Thread Bernhard Schmidt
Package: src:pjproject Version: 2.7.2~dfsg-4 Severity: serious Hi, as the sole Uploader of src:pjproject for the last two years I think we should not release Buster with src:pjproject. Reasons: - pjsip is a library where a lot of functionality and behaviour is selected at compile time using #d

Bug#921266: Could this simple typo be the reason: "ream" <-> "realm"?

2019-03-10 Thread Bernhard Schmidt
Control: severity -1 important Control: tags -1 moreinfo Hi Alf, > I now tried to collect debug info with the cli-version - it crashes the > same way with segfault: > > linphonec -d 5 -l linphone-debug > > the last lines in the debug output after password enty and before crash are: > > Authent

Bug#908595: krb5-subdomain and ms-subdomain update policy rules ineffective

2019-03-10 Thread Bernhard Schmidt
Control: severity -1 important Control: tags -1 + wontfix Control: tags -1 - patch Hi Dominik, > I discovered the following security bug in bind9 a few weeks ago, and > responsibly disclosed it to the ISC security officer. Unfortunately, until > today they did not acknowledge it is a security iss

Bug#918543: ring build depends on libsrtp-dev that is not in buster

2019-01-07 Thread Bernhard Schmidt
Am 07.01.19 um 10:56 schrieb Adrian Bunk: > Source: ring > Version: 20180119.1.9e06f94~ds120181001.4.a99aaec~ds6-2 > Severity: serious > Tags: ftbfs > Control: block 910292 by -1 > > ring build depends on libsrtp-dev that is not in buster, > see #910292 for background. > According to the buildlo

Bug#910292: transition: libsrtp0-rm

2019-01-03 Thread Bernhard Schmidt
Hi, > Considering that your rdep is indirectly kde-standard, you should imho > ask for removal from testing only once kopete is fixed… FTR, kopete is fixed and I've filed Bug#918136 for the removal of src:srtp from testing. Bernhard

Bug#913609: bpfcc FTBFS on amd64: No such file or directory: 'bcc-0.7.0'

2018-11-27 Thread Bernhard Schmidt
On Mon, Nov 26, 2018 at 03:46:17PM +0100, Bernhard Schmidt wrote: > > Source: bpfcc > > Version: 0.7.0-1 > > Severity: serious > > Tags: ftbfs > > > > https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/bpfcc.html > > > > ... &

Bug#913609: bpfcc FTBFS on amd64: No such file or directory: 'bcc-0.7.0'

2018-11-26 Thread Bernhard Schmidt
On Tue, Nov 13, 2018 at 12:05:05AM +0200, Adrian Bunk wrote: Hi, > Source: bpfcc > Version: 0.7.0-1 > Severity: serious > Tags: ftbfs > > https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/bpfcc.html > > ... > removing 'bcc-0.7.0' (and everything under it) > removing 'bcc-0.7.0'

Bug#913614: gnupg2 fails with "cannot open '/dev/tty': No such device or address"

2018-11-13 Thread Bernhard Schmidt
Hi, confirmed, I see this as well after the point release. Passing "--no-tty" to gpg works around this issue. Bernhard

Bug#909689: asterisk: autopkgtest regression

2018-11-12 Thread Bernhard Schmidt
Control: severity -1 important Am 05.11.18 um 23:33 schrieb Bernhard Schmidt: Hi, >> this is where asterisk is actually segfaulting (not during the >> testsuite, but when collecting the results). I haven't managed to pull >> the backtrace from the autopkgtest worker yet

Bug#909689: asterisk: autopkgtest regression

2018-11-05 Thread Bernhard Schmidt
Hi, > > this is where asterisk is actually segfaulting (not during the > testsuite, but when collecting the results). I haven't managed to pull > the backtrace from the autopkgtest worker yet. Backtrace: #0 ___fprintf_chk (fp=fp@entry=0x0, flag=flag@entry=1, format=format@entry=0x555981d58a08

Bug#909689: asterisk: autopkgtest regression

2018-11-05 Thread Bernhard Schmidt
Hi, > I don't know how much time I'll have to check on this in the next days. > Raising severity to block testing migration for now. Okay, I tried to have a look at this and I have to admit I'm a bit confused. First, I do see a failing unittest in MY autopkgtest qemu instance that is not visible

Bug#908483: fixed upstream

2018-09-12 Thread Bernhard Schmidt
Control: tags -1 fixed-upstream This is fixed in ZFS/SPL 0.7.10 https://github.com/zfsonlinux/zfs/releases/tag/zfs-0.7.10 There are at least two patches to ZFS and one to SPL, it is probably easier to import the new version.

Bug#897878: ucommon: diff for NMU version 7.0.0-12.1

2018-08-12 Thread Bernhard Schmidt
Control: reopen -1 Control: notfixed -1 7.0.0-13 On 13.08.2018 00:05, Bernhard Schmidt wrote: > On 12.08.2018 19:20, Adrian Bunk wrote: >> Control: tags 897878 + patch >> Control: tags 897878 + pending >> Control: tags 898502 + pending >> >> Dear maintainer, >&

Bug#897878: ucommon: diff for NMU version 7.0.0-12.1

2018-08-12 Thread Bernhard Schmidt
On 12.08.2018 19:20, Adrian Bunk wrote: > Control: tags 897878 + patch > Control: tags 897878 + pending > Control: tags 898502 + pending > > Dear maintainer, > > I've prepared an NMU for ucommon (versioned as 7.0.0-12.1) and uploaded > it to DELAYED/15. Please feel free to tell me if I should ca

Bug#905177: bind9: prompting due to modified conffiles which were not modified by the user: /etc/bind/named.conf.options

2018-08-01 Thread Bernhard Schmidt
Control: tags -1 help Am 01.08.2018 um 18:56 schrieb Andreas Beckmann: Hi, > Suggestion: In the preinst check whether you are upgrading from << > 9.11.2+dfsg-6 and whether the file matches the version installed in > stretch (md5sum/...) and move it aside (maybe there were more possible > files i

Bug#905177: bind9: prompting due to modified conffiles which were not modified by the user: /etc/bind/named.conf.options

2018-08-01 Thread Bernhard Schmidt
Am 01.08.2018 um 12:00 schrieb Andreas Beckmann: Hi, I can reproduce this in a container upgrading Stretch to Buster. Configuration file '/etc/bind/named.conf.options' ==> File on system created by you or by a script. ==> File also in package provided by package maintainer. What would you li

Bug#904983: bind9: Syntax error in /etc/apparmor.d/usr.sbin.named prevents bind9 from starting

2018-07-30 Thread Bernhard Schmidt
Control: tags -1 pending Am 30.07.2018 um 09:55 schrieb Giorgos Skafidas: Hi, > Package: bind9 > Version: 1:9.11.4+dfsg-3 > Severity: grave > Justification: renders package unusable > > Dear Maintainer, > > bind9 9.11.4+dfsg-3's /etc/apparmor.d/usr.sbin.named is missing a comma at > the end o

Bug#903607: pjproject: FTBFS due to d-devlibdeps errors

2018-07-22 Thread Bernhard Schmidt
Control: severity -1 important > I cannot reproduce this locally (using sbuild) and -3 just uploaded > built fine on the autobuilders. Downgrading severity as it has built fine on all architectures, feel free to reopen/upgrade if you still see this. Bernhard

Bug#903607: pjproject: FTBFS due to d-devlibdeps errors

2018-07-19 Thread Bernhard Schmidt
Control: tags -1 moreinfo On 11.07.2018 22:06, Sebastian Ramacher wrote: Hi Sebastian, > Source: pjproject > Version: 2.7.2~dfsg-2 > Severity: serious > Justification: fails to build from source (but built successfully in the past) > Tags: ftbfs > > pjproject currently fails to build: > | d-dev

Bug#894757: libmypaint-common: file conflict with mypaint-data

2018-06-12 Thread Bernhard Schmidt
On Tue, Apr 03, 2018 at 05:43:10PM -0400, Jeremy Bicha wrote: Hi Jeremy, > Package: libmypaint-common > Version: 1.3.0-1 > Severity: serious > Forwarded: https://github.com/mypaint/mypaint/issues/918 > > libmypaint-common ships some of the same file names as mypaint-data > (the libmypaint.mo fil

Bug#888484: clamav: Security release 0.99.3 available

2018-01-26 Thread Bernhard Schmidt
Control: unfixed 888484 0.99.3~beta2+dfsg-1 Control: fixed 888511 0.99.3~beta2+dfsg-1 Hi >> >> We've have started seeing unexpected clamd crashes on a high-traffic mail >> system today, though I've been unable to isolate a test case. It's seems like >> too much of a coincidence that these crash

Bug#879043: dahdi-linux No longer compiled with m-a as of 4.13: unknown field ‘dev_attrs’

2017-12-30 Thread Bernhard Schmidt
On Wed, Oct 18, 2017 at 08:19:26PM +0300, Tzafrir Cohen wrote: Hi Tzafrir, > Version: 1:2.11.1.0.20170917~dfsg-1 > Flags: patch upstream > Forwarded: https://issues.asterisk.org/jira/browse/DAHLIN-356 > Severity: grave > > As of kernel 4.13, build fails with the following error: Any update on t

Bug#884345: asterisk: CVE-2017-17664: Remote Crash Vulnerability in RTCP Stack

2017-12-29 Thread Bernhard Schmidt
Control: fixed -1 1:13.18.5~dfsg-1 This was fixed in sid with the latest upload, but not properly closed in the changelog. asterisk (1:13.18.5~dfsg-1) unstable; urgency=medium * New upstream release: - CVE-2017-17850 / AST-2017-014 (closes: #885072) - AST-2017-012: Remote Crash Vulnera

Bug#885072: asterisk: CVE-2017-17850: Crash in PJSIP resource when missing a contact header

2017-12-27 Thread Bernhard Schmidt
Control: found -1 1:13.17.0~dfsg-1 Hi, > CVE-2017-17850[0]: > | An issue was discovered in Asterisk 13.18.4 and older, 14.7.4 and > | older, 15.1.4 and older, and 13.18-cert1 and older. A select set of SIP > | messages create a dialog in Asterisk. Those SIP messages must contain a > | contact hea

Bug#884995: [Pkg-dns-devel] Bug#884995: bind9 doesn't start after upgrade. Complains /var/log/bind.log permission denied

2017-12-22 Thread Bernhard Schmidt
Am 22.12.2017 um 16:51 schrieb Noury: Hello Noury, thanks for your report. > When starting bind9, I have error messages and bind doesn't start> Other > packages are unusable because they need it (ex exim4 as it's my MTA) > Dec 22 16:28:39 colibri named[26358]: isc_stdio_open '/var/log/bind.log'

Bug#884069: RFT: Candidate fix for boot failure of Debian 8.10 on various x86 systems

2017-12-12 Thread Bernhard Schmidt
Am 12.12.2017 um 02:57 schrieb Ben Hutchings: Hi Ben, > Apologies for this regression. Salvatore Bonaccorso has tracked down > which change in 3.16-stable triggers the crash, and I identified some > related upstream changes which appear to fix it. An updated package is > available at: > > http

Bug#883938: Bug #883938: linux-image-3.16.0-4-amd64: Kernel panic on boot after upgrading to debian 8.10 kernel 3.16.51

2017-12-11 Thread Bernhard Schmidt
Hi Karsten, Thanks for the test. Can you check whether numa=off on the kernel command line fixes this as well? Bernhard -- Diese Nachricht wurde von meinem Android-Mobiltelefon mit K-9 Mail gesendet.

Bug#883938: linux-image-3.16.0-4-amd64: Kernel panic on boot after upgrading to debian 8.10 kernel 3.16.51

2017-12-11 Thread Bernhard Schmidt
On Mon, Dec 11, 2017 at 09:23:45AM +0100, Salvatore Bonaccorso wrote: > The issue seems not present when rolling back to 3.16.48-1 (this is > one kernel version which was only present in jessie-proposed-update). > > Can someone confirm? If yes it has to be a change between 3.16.48-1 > and 3.16.51

Bug#883938: Workaround available

2017-12-11 Thread Bernhard Schmidt
Control: summary -1 Seems two affect machines with more than one socket. Workaround: set maxcpus=1 on the kernel command line Hi, this seems to affect two-socket boxes. Workaround is to set maxcpus=1 on the kernel command line. Bernhard

Bug#883536: [Pkg-dns-devel] Bug#883536: isc-dhcp FTBFS with libbind-export-dev 1:9.11.2+dfsg-2

2017-12-04 Thread Bernhard Schmidt
Control: tags -1 pending On 04.12.2017 23:41, Adrian Bunk wrote: Hi, > The pattern is clear: > https://tests.reproducible-builds.org/debian/history/isc-dhcp.html > > I am also able to reproduce it locally. > > Am I guessing correct that merged /usr is used in your > successful build? You are,

Bug#883536: [Pkg-dns-devel] Bug#883536: isc-dhcp FTBFS with libbind-export-dev 1:9.11.2+dfsg-2

2017-12-04 Thread Bernhard Schmidt
On 04.12.2017 21:45, Adrian Bunk wrote: Hi Adrian, > Source: isc-dhcp > Version: 4.3.5-3 > Severity: serious > Tags: buster sid > > https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/isc-dhcp.html > > ... > gcc -g -O2 -fstack-protector-strong -Wformat -Werror=format-security -Wa

Bug#877364: pjproject: source file licensed as BSD-4-clause and GPL-2+ effectively unlicensed

2017-11-12 Thread Bernhard Schmidt
Control: tags -1 fixed-upstream Control: forwarded -1 https://trac.pjsip.org/repos/ticket/2062 On Mon, Nov 06, 2017 at 01:27:38PM +0100, Bernhard Schmidt wrote: > > > The file pjlib/src/pj/sock_linux_kernel.c is licensed as both > > > BSD-4-clause and GPL-2+. Not dual-licens

Bug#877364: pjproject: source file licensed as BSD-4-clause and GPL-2+ effectively unlicensed

2017-11-06 Thread Bernhard Schmidt
On Thu, Oct 12, 2017 at 10:24:46AM +0200, Bernhard Schmidt wrote: Hi, > > The file pjlib/src/pj/sock_linux_kernel.c is licensed as both > > BSD-4-clause and GPL-2+. Not dual-licensed, but separately declared. > > Those licenses are incompatible, and therefore the licensing is

  1   2   >