Processed: Re: Bug#507445: gnupg-doc orig.tar.gz missing in main

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tag 507445 pending
Bug#507445: gnupg-doc orig.tar.gz missing in main
Tags were: patch
Tags added: pending

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507445: gnupg-doc orig.tar.gz missing in main

2008-12-07 Thread Cyril Brulebois
tag 507445 pending
thanks

Steve McIntyre [EMAIL PROTECTED] (01/12/2008):
 I know this is not necessarily *your* bug, but the easiest workaround
 is to simply re-upload with a new upstream version to trigger dak to
 copy the new upstream orig.tar.gz into the right place. Easiest is to
 just rename the current tarball to a new name (e.g.
 gnupg-doc_2003.04.06a.orig.tar.gz).

I chose +dak1 to mark it as being needed because of dak (and that seems
to be a kind of standard practice).

 (Opened as serious as this bug is currently blocking creation of
 source CDs/DVDs/ in the weekly CD build.)

I see, shortening the usual delays a bit, uploading to DELAYED/1.
 
Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507445: gnupg-doc orig.tar.gz missing in main

2008-12-07 Thread Cyril Brulebois
Cyril Brulebois [EMAIL PROTECTED] (07/12/2008):
 tag 507445 pending
 thanks

And the source debdiff for completeness.

Mraw,
KiBi.
diff -Nru gnupg-doc-2003.04.06/debian/changelog 
gnupg-doc-2003.04.06+dak1/debian/changelog
--- gnupg-doc-2003.04.06/debian/changelog   2008-12-07 09:04:33.0 
+0100
+++ gnupg-doc-2003.04.06+dak1/debian/changelog  2008-12-07 09:04:34.0 
+0100
@@ -1,3 +1,11 @@
+gnupg-doc (2003.04.06+dak1-0.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Reupload to include the source tarball, missing since the move to
+main, due to a well-known dak bug (Closes: #507445).
+
+ -- Cyril Brulebois [EMAIL PROTECTED]  Sun, 07 Dec 2008 09:02:32 +0100
+
 gnupg-doc (2003.04.06-6) unstable; urgency=low
 
   * debian/control (Section): move back to main, per GR.  Closes: #406648


signature.asc
Description: Digital signature


Bug#507509:

2008-12-07 Thread Cyril Brulebois
Putting back the submitter in the loop.

Diego Escalante Urrelo [EMAIL PROTECTED] (02/12/2008):
 Install de debug packages for libgtk, libglib, libgconf and similar,
 both the mm (C++) and usual C versions, example:
 
 ii  libglib2.0-0-dbg  2.18.2-0ubuntu2
 ii  libgtk2.0-0-dbg   2.14.4-0ubuntu1
 
 Try to reproduce the trace with that installed.

Hello Diego,

please remember to keep the submitter Cc'd, or use the
[EMAIL PROTECTED] alias for that purpose, otherwise mails
will be unseen.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507711: clamfs: Uninstallable in Sid due to libpoconet soname bump

2008-12-07 Thread Cyril Brulebois
Gunnar Wolf [EMAIL PROTECTED] (03/12/2008):
 Version 1.3.3p1-1 of poco was uploaded to Sid on October. This version
 now provides libpoconet6 - As clamfs depends on libpoconet5, the
 package is now uninstallable.
 
 Rebuilding the package seems to work - I have not yet tried _using_
 clamfs, but at least, the resulting .deb is installable. Note that if
 you rebuild/upload, you might want to change the build-dependencies,
 as it currently mentions libpoco5-dev | libpoco-dev .

Krzysztof, any reason why you didn't open bugs against your reverse
dependencies that no longer build? And why you didn't ask for binNMUs?

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#476210: additional info

2008-12-07 Thread Cyril Brulebois
Robert Lemmen [EMAIL PROTECTED] (03/12/2008):
 there is also
 http://bugs.debian.org/cgi-bin/bugreport.cgi?msg=7;bug=476210 no idea
 why this doesn't show up here, the BTS is surprising sometimes!

Because the bug wasn't Cc'd (:/), only a related instruction got sent to
control@, that's why it's there w/o being shown.

So it looks like this bug is being taken care of, no need to NMU per se.
Peter, if you need a sponsor, just point me to a .dsc, and I'll take
care of it.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507788: sysctl.conf read before ipv6 module loaded, so cannot set ipv6 settings

2008-12-07 Thread martin f krafft
also sprach Didier Raboud [EMAIL PROTECTED] [2008.12.05.1342 +0100]:
 As ipv6 is a release goal, my guess is that a solution has to be found.

Maybe the easiest solution is simply to load the ipv6 module early
on, unconditionally?

-- 
 .''`.   martin f. krafft [EMAIL PROTECTED]  Related projects:
: :'  :  proud Debian developer   http://debiansystem.info
`. `'`   http://people.debian.org/~madduckhttp://vcs-pkg.org
  `-  Debian - when you have better things to do than fixing systems
 
warning at the gates of bill:
abandon hope, all ye who press enter here...


digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)


Processed: bug 507883 is forwarded to http://bugs.digium.com/view.php?id=14019nbn=4

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 forwarded 507883 http://bugs.digium.com/view.php?id=14019nbn=4
Bug#507883: asterisk: Very frequent segfaults on startup
Noted your statement that Bug has been forwarded to 
http://bugs.digium.com/view.php?id=14019nbn=4.


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507944: Suggested removal: xwhois [was: Bug#507944: xwhois: segfaults on start in get_servers()]

2008-12-07 Thread Cyril Brulebois
Submitter put back in recipient list…

Steve Cotton [EMAIL PROTECTED] (06/12/2008):
 xwhois.h:
 #define BUFSIZE 1024
 
 struct serverent {
   char *name;
   char *comment;
 } servers[256];
 
 
 get_servers():
   /*
* Set all struct members to NULL.
*/
 
   for (i=0 ; i  BUFSIZE ; i++)
 {
   servers[i].name = servers[i].comment = NULL;
 }
 
 After setting BUFSIZE to 256, the app started OK.
 
 But pressing Scan locked the app up.  I fired up Wireshark, 90
 seconds later it's still sending out SYN packets to servers that
 don't respond.  After a couple of minutes, it displayed the
 results.  They're mostly along the lines of server did not
 respond, query format not supported, this server only has the
 .FOO and .BAR TLDs.
 
 Popcon is 63 installs, 14 votes, and it has a dependency on GTK-1.2.
 Personally, I think this isn't one to fix.

Agreed, looks like a candidate for removal from testing (-release@ Cc'd
for that), and maybe even from unstable (-qa@ Cc'd for that).

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507850: python-hulahop: Hulahop fails to locate and link against libxul.so

2008-12-07 Thread Cyril Brulebois
Jonas Smedegaard [EMAIL PROTECTED] (05/12/2008):
 Package: python-hulahop
 Version: 0.4.8~dfsg-2
 Severity: grave
 Justification: renders package unusable
 
 As subject says, sugar-hulahop is plain broken at the moment: Attempts
 tos start Browse activity leads to notes in logfile that it can't
 locate libxul.so

Hi,

is it that libxul.so is around and can't be loaded? Or more like a
Depends: on xulrunner-1.9 (which ships libxul.so) is missing?

Mraw,
KiBi.


signature.asc
Description: Digital signature


Processed: Re: Bug#507465: mb2md often misses message boundaries in mbox files

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 severity 507465 wishlist
Bug#507465: mb2md often misses message boundaries in mbox files
Severity set to `wishlist' from `grave'

 retitle 507465 mb2md: Please provide an option to tweak mail separation 
 detection.
Bug#507465: mb2md often misses message boundaries in mbox files
Changed Bug title to `mb2md: Please provide an option to tweak mail separation 
detection.' from `mb2md often misses message boundaries in mbox files'.

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507465: mb2md often misses message boundaries in mbox files

2008-12-07 Thread Cyril Brulebois
severity 507465 wishlist
retitle 507465 mb2md: Please provide an option to tweak mail separation 
detection.
thanks

Putting back the submitter in the loop, please Cc submitters, or use the
[EMAIL PROTECTED] alias…

Bruno De Fraine [EMAIL PROTECTED] (03/12/2008):
 This script intentionally looks for a blank line in between messages
 in the mbox file.  There is no such requirement that I know of;

 There *is* certainly mention of a blank line in the first few
 references that turn up when looking for an mbox file specification:

 http://www.qmail.org/man/man5/mbox.html
 http://en.wikipedia.org/wiki/Mbox

Err, quoting qmail as a reference looks bogus to me… Anyway, looking at
e.g. RFC 4155 (which points to qmail's site too, sigh, with typo, sigh
again), we have:

,--[ Appendix A. The default mbox Database Format ]--
|The default mbox database format uses a linear sequence of Internet
|messages, with each message being immediately prefaced by a separator
|line, and being terminated by an empty line.  More specifically:
| 
|…
| 
|   o Each message in the database MUST be terminated by an empty
| line, containing a single end-of-line marker.
`--

So you're right.

  As is, I got 30% fewer messages in the new Maildir, and lots of
  messages were actually two or three messages run together.  The
  result is so garbled I wonder if anyone else has ever used this
  script...

Requesting an option to make the newline between two sucessive mails
optional makes anyway sense to me, adjusting bug severity and title
accordingly.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be done for `binary-arch'.

2008-12-07 Thread Cyril Brulebois
Martin Zobel-Helas [EMAIL PROTECTED] (27/11/2008):
 Package: newlib
 Version: 1.16.0-2.1
 Severity: serious
 
 That means you are trying to build arch-independ stuff only on buildds, which 
 will not work.

Since we have (in newlib_1.16.0-2.1):
,--
| Package: newlib-spu
| Architecture: powerpc ppc64
| 
| Package: newlib-source
| Architecture: all
`--

it looks like a P-a-s candidate to me. Cc'ing the P-a-s maintainers, the
newlib maintainers, and the NMUer (hrm).

That said, this bug is still a Policy §4.9 violation.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#505755: batv-milter: missing build-dependency on m4

2008-12-07 Thread Cyril Brulebois
tag 505755 patch
thanks

Francisco García [EMAIL PROTECTED] (06/12/2008):
 Yes, m4 must be in Build-Depends.
 I attach the patch.

In which case, you may want to tag the bug accordingly, see above.

 Please, Maintainer, could you make the new package.  If you can't do
 it in some days, I could make a NMU to close this bug.

Note that this bug doesn't affect testing, so you may want to give the
maintainer a bit more time than the usual 1-week delay).

Mraw,
KiBi.


signature.asc
Description: Digital signature


Processed: Re: Bug#505755: batv-milter: missing build-dependency on m4

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tag 505755 patch
Bug#505755: batv-milter: missing build-dependency on m4
There were no tags set.
Tags added: patch

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507509:

2008-12-07 Thread George Kiagiadakis
On Sunday 07 December 2008 11:10:36 Cyril Brulebois wrote:
 Putting back the submitter in the loop.

 Diego Escalante Urrelo [EMAIL PROTECTED] (02/12/2008):
  Install de debug packages for libgtk, libglib, libgconf and similar,
  both the mm (C++) and usual C versions, example:
 
  ii  libglib2.0-0-dbg  2.18.2-0ubuntu2
  ii  libgtk2.0-0-dbg   2.14.4-0ubuntu1

Hi,

I tried to install many gtk/gnome related -dbg packages, but that didn't help.
I tried to run gdb --pid `pidof subtitleeditor` to see which libraries lack 
symbols and I noticed this line:

Reading symbols from /usr/bin/subtitleeditor...(no debugging symbols 
found)...done.

So, I downloaded the source code (via apt-get source) and rebuilt it (after 
commenting out dh_strip in debian/rules) and I got a much better backtrace:

Program received signal SIGABRT, Aborted.
[Switching to Thread 0x7f62d11b46f0 (LWP 16381)]
0x7f62cb2eeed5 in raise () from /lib/libc.so.6
(gdb) bt  
#0  0x7f62cb2eeed5 in raise () from /lib/libc.so.6
#1  0x7f62cb2f03f3 in abort () from /lib/libc.so.6
#2  0x7f62cb330970 in malloc_printerr () from /lib/libc.so.6
#3  0x7f62d0d78b7a in Gtk::RecentManager::add_item (this=0xc08d50, 
[EMAIL PROTECTED], [EMAIL PROTECTED]) at recentmanager.cc:51
#4  0x004d1b82 in 
DocumentManagementPlugin::add_document_in_recent_manager (this=value 
optimized out, doc=value optimized out)
at actions/DocumentManagement.cc:683
  
#5  0x0043b3a2 in DocumentSystem::append (this=value optimized out, 
doc=0xe2e3b0) at /usr/include/sigc++-2.0/sigc++/signal.h:690
#6  0x004d2dd0 in DocumentManagementPlugin::on_recent_item_activated 
(this=value optimized out, rc=value optimized out)   
at actions/DocumentManagement.cc:287
  
#7  0x7f62cf9d1c92 in Glib::SignalProxyNormal::slot0_void_callback 
(self=value optimized out, data=0xc1d870)
at /usr/include/sigc++-2.0/sigc++/functors/slot.h:440   
  
#8  0x7f62ce7b9e9d in IA__g_closure_invoke (closure=0xc162c0, 
return_value=0x0, n_param_values=1, param_values=0x7fffd92f6150,
invocation_hint=0x7fffd92f6050) at 
/build/buildd/glib2.0-2.16.6/gobject/gclosure.c:490 
   
#9  0x7f62ce7cd11e in signal_emit_unlocked_R (node=0xc1c1f0, detail=0, 
instance=0xc1e030, emission_return=0x0, instance_and_params=0x7fffd92f6150)
at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2510  
  
#10 0x7f62ce7ce0ee in IA__g_signal_emit_valist (instance=0xc1e030, 
signal_id=value optimized out, detail=0, var_args=0x7fffd92f63b0)
at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2199  
  
#11 0x7f62ce7ce5f3 in IA__g_signal_emit (instance=0x3ffd, signal_id=16381, 
detail=6) at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2243   
#12 0x7f62ce7b9e9d in IA__g_closure_invoke (closure=0xc19a90, 
return_value=0x0, n_param_values=1, param_values=0x7fffd92f66d0,

invocation_hint=0x7fffd92f65d0) at 
/build/buildd/glib2.0-2.16.6/gobject/gclosure.c:490 
   
#13 0x7f62ce7ccbfd in signal_emit_unlocked_R (node=0xb8cfa0, detail=0, 
instance=0xc07830, emission_return=0x0, instance_and_params=0x7fffd92f66d0)
at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2440  
  
#14 0x7f62ce7ce0ee in IA__g_signal_emit_valist (instance=0xc07830, 
signal_id=value optimized out, detail=0, var_args=0x7fffd92f6930)
at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2199  
  
#15 0x7f62ce7ce5f3 in IA__g_signal_emit (instance=0x3ffd, signal_id=16381, 
detail=6) at /build/buildd/glib2.0-2.16.6/gobject/gsignal.c:2243   
#16 0x7f62d02a39cb in IA__gtk_widget_activate (widget=0xc07830) at 
/scratch/build-area/gtk+2.0-2.12.11/gtk/gtkwidget.c:4709   
#17 0x7f62d01972ad in IA__gtk_menu_shell_activate_item 
(menu_shell=0xc1e030, menu_item=0xc07830, force_deactivate=value optimized 
out)  
at /scratch/build-area/gtk+2.0-2.12.11/gtk/gtkmenushell.c:1150
#18 0x7f62d0198f85 in gtk_menu_shell_button_release (widget=0xc1e030, 
event=0xb4e080) at /scratch/build-area/gtk+2.0-2.12.11/gtk/gtkmenushell.c:674
#19 0x7f62d018a748 in _gtk_marshal_BOOLEAN__BOXED 

Bug#508055: libcups2: Ridiculous dependencies

2008-12-07 Thread Jan Willem Stumpel
Package: libcups2
Version: 1.3.8-1lenny3
Severity: grave

When I try to remove libcups2, I get the message:

The following packages will be REMOVED

abiword abiword-common abiword-help abiword-plugin-grammar
abiword-plugin-mathview acroread acroread-data acroread-debian-files
acroread-dictionary-en acroread-escript acroread-l10n-en acroread-plugins
afterstep amule amule-utils-gui aterm audacity avidemux azureus bluefish
ca-certificates-java camorama choosewm cups desktop-base drgeo driconf
ed2k-gtk-gui evince exo-utils fluxconf gamix gconf-editor ghostscript
ghostscript-x gimp gimp-gnomevfs gimp-python glade gnome-icon-theme
gnome-keyring gnucash gnucash-docs gnuplot gnuplot-x11 gs-common gs-esp
gs-gpl gstreamer0.10-plugins-good gtk-gnutella gtk-theme-switch gtk2-engines
gtk2-engines-pixbuf gtk2-engines-xfce gtkam gucharmap gv homebank html2ps
icedove icedtea-gcjwebplugin iceweasel imagemagick inkscape leafpad
libaccess-bridge-java libafterimage0 libafterstep1 libaiksaurusgtk-1.2-0c2a
libbonoboui2-0 libcommons-cli-java libcommons-lang-java libcups2
libcupsimage2 libcupsys2 libexif-gtk5 libexo-0.3-0 libgail-common
libgail-dev libgail17 libgail18 libgcj8-1-awt libgcj9-0-awt
libgdk-pixbuf2-ruby libgdk-pixbuf2-ruby1.8 libgimp2.0 libgksuui1.0-1
libglade2-0 libglade2-dev libglademm-2.4-1c2a libglademm-2.4-dev
libgladeui-1-7 libgnome-media0 libgnomecanvas2-0 libgnomecanvas2-dev
libgnomecups1.0-1 libgnomeprint2.2-0 libgnomeprintui2.2-0 libgnomeui-0
libgoffice-0-4 libgraphicsmagick++1 libgraphicsmagick1 libgs8 libgtk2.0-0
libgtk2.0-bin libgtk2.0-dev libgtkhtml2-0 libgtkhtml3.8-15
libgtkmathview0c2a libgtkmm-2.4-1c2a libgtkmm-2.4-dev libgtkspell0
libgucharmap6 liblog4j1.2-java liblog4j1.2-java-gcj libmagick++10
libmagick10 libmetacity0 libnautilus-burn3 libnautilus-extension1 libnotify1
libpoppler-glib3 libpoppler0c2-glib librsvg2-2 librsvg2-common libscim8c2a
libspectre1 libswt-gtk-3.1-jni libswt-gtk-3.2-jni libswt-gtk-3.4-java
libswt-gtk-3.4-jni libthunar-vfs-1-2 libvte9 libwmf0.2-7 libwv-1.2-3
libwxgtk2.6-0 libwxgtk2.8-0 libxfcegui4-4 libxine1 libxine1-misc-plugins
libxine1-plugins libxul0d maxima maxima-share maxima-test mjpegtools
mkvtoolnix-gui mlterm mlterm-tools mousepad mozilla-acroread mozilla-mplayer
mplayer obconf ogle-gui openjdk-6-jre openjdk-6-jre-headless
openjdk-6-jre-lib openoffice.org-calc openoffice.org-core
openoffice.org-draw openoffice.org-emailmerge
openoffice.org-filter-binfilter openoffice.org-help-en-gb
openoffice.org-impress openoffice.org-writer orage pan pdf2dj perlmagick
python-glade2 python-gtk2 python-uno python-wxgtk2.6 python-wxversion
quicktime-x11utils rapidsvn realplayer rhino rox-filer rxvt-unicode scim
scim-gtk2-immodule scim-modules-socket scribus sgt-puzzles
sodipodi streamtuner subtitleeditor texmacs thunar transcode uim-gtk2.0
uim-xim xaralx xcdroast xfce4 xfce4-mcs-manager xfce4-mcs-plugins
libxine1-plugins libxul0d maxima maxima-share maxima-test mjpegtools
mkvtoolnix-gui mlterm mlterm-tools mousepad mozilla-acroread mozilla-mplayer
mplayer obconf ogle-gui openjdk-6-jre openjdk-6-jre-headless
openjdk-6-jre-lib openoffice.org-calc openoffice.org-core
openoffice.org-draw openoffice.org-emailmerge
openoffice.org-filter-binfilter openoffice.org-help-en-gb
openoffice.org-impress openoffice.org-writer orage pan pdf2dj perlmagick
python-glade2 python-gtk2 python-uno python-wxgtk2.6 python-wxversion
quicktime-x11utils rapidsvn realplayer rhino rox-filer rxvt-unicode scim
scim-gtk2-immodule scim-modules-socket scribus sgt-puzzles
sodipodi streamtuner subtitleeditor texmacs thunar transcode uim-gtk2.0
uim-xim xaralx xcdroast xfce4 xfce4-mcs-manager xfce4-mcs-plugins
xfce4-mixer xfce4-mixer-alsa xfce4-netload-plugin xfce4-panel xfce4-session
xfce4-systemload-plugin xfce4-terminal xfce4-utils xfdesktop4 xfprint4
xfreecd xfwm4 xfwm4-themes xine-ui xmaxima xscreensaver xscreensaver-dat
xsensors xulrunner-1.9 yelp zeroinstall-injector

This absurd. Many of these programs have nothing at all to do with
printing. And all the others can print very well, thank you, using lprng
instead of CUPS. 

Please remove these ridiculous dependencies.

Regards, Jan


-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686 (SMP w/2 CPU cores)
Locale: LANG=en_GB.UTF-8, LC_CTYPE=en_GB.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libcups2 depends on:
ii  libc6 2.7-16 GNU C Library: Shared libraries
ii  libcomerr21.41.3-1   common error description library
ii  libgnutls26   2.4.2-3the GNU TLS library - runtime libr
ii  libkrb53  1.6.dfsg.4~beta1-4 MIT Kerberos runtime libraries
ii  zlib1g1:1.2.3.3.dfsg-12  compression library - runtime

libcups2 recommends no packages.

Versions of packages libcups2 suggests:
ii  cups-common1.3.8-1lenny3 Common UNIX Printing 

Bug#507850: python-hulahop: Hulahop fails to locate and link against libxul.so

2008-12-07 Thread Jonas Smedegaard
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

On Sun, Dec 07, 2008 at 02:17:09PM +0100, Cyril Brulebois wrote:
Jonas Smedegaard [EMAIL PROTECTED] (05/12/2008):
 As subject says, sugar-hulahop is plain broken at the moment: 
 Attempts tos start Browse activity leads to notes in logfile that it 
 can't locate libxul.so

is it that libxul.so is around and can't be loaded?

Yes.


Or more like a Depends: on xulrunner-1.9 (which ships libxul.so) is 
missing?


If only it was that simple :-)

I am package maintainer of sugar-hulahop, so would have been quicker for 
me to add that dependency than file a bugreport if this was the case.


I may have found the cause of the problem just now: during build 
dh_shlibdeps warns about being unable to locate libxul.so below 
/usr/lib/xulrunner-1.9.0.4 - and the library is in fact not there, but 
below /usr/lib/xulrunner-1.9.

I will go hunt for some wrong hardcoded path somewhere in either 
sugar-hulahop itsef, xulrunner-dev or python-xpcom.


Thanks for your valid question (and sorry for my too short bugreport).


  - Jonas

- -- 
* Jonas Smedegaard - idealist og Internet-arkitekt
* Tlf.: +45 40843136  Website: http://dr.jones.dk/

  [x] quote me freely  [ ] ask before reusing  [ ] keep private
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkk702EACgkQn7DbMsAkQLixtACgi+nJaEJipOYS8L1w5gIXdZAy
5M8AmwTv6T2J2od/dO1EEtfymS0lrDj3
=GazK
-END PGP SIGNATURE-



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#506748: closed by Jose Luis Rivas ghostba...@gmail.com (Fixed in experimental)

2008-12-07 Thread Dmitry E. Oboukhov

Ive made a reopen this bug becouse so that it was closed for 0.7.9.
In open state tags 'found' and 'notfound' point in which versions
there is such a bug and in which there is not. Before you closed this
bug these tags had been set correctly.
:)

On 18:14 Sat 06 Dec , Jose Luis Rivas wrote:
JLR -BEGIN PGP SIGNED MESSAGE-
JLR Hash: SHA1

JLR Dmitry E. Oboukhov wrote:
 reopen 506748
 thanks
 
 But this upload does not fix this bug in the testing :(
 lenny is frozen, version for lenny is 0.7.9
 
 If you want to fix this bug unsing upload version != 0.7.9
 you must receive release-team's permission
 
 
 sorry

JLR Mmm... I'm closing it from 0.8.4-1 so remains open for 0.7.9-1+b2 this
JLR way people on experimental knows this bug is indeed fixed, people in
JLR unstable see this bug is open and in fact keeps as RC in bugs overview
JLR since there's a release on Debian with the bug open.

JLR That's the functionality of found while submitting and version while
JLR setting as done (as long as I know) so I'll not need r-t permission for
JLR closing the bug in _experimental_.

JLR Please, let me know if this is wrong and I'll let then the bug as is
JLR right now, open. If not I in 2 days or something will set it as done,
JLR again :)

JLR Regards.
JLR - --
JLR Jose Luis Rivas. San Cristóbal, Venezuela. GPG 0xCACAB118
JLR http://ghostbar.ath.cx/about - http://debian.org.ve
--
... mpd is off

. ''`.   Dmitry E. Oboukhov
: :’  :   email: [EMAIL PROTECTED] jabber://[EMAIL PROTECTED]
`. `~’  GPGKey: 1024D / F8E26537 2006-11-21
  `- 1B23 D4F8 8EC0 D902 0555  E438 AB8C 00CF F8E2 6537


signature.asc
Description: Digital signature


Bug#507850: python-hulahop: Hulahop fails to locate and link against libxul.so

2008-12-07 Thread Cyril Brulebois
Jonas Smedegaard [EMAIL PROTECTED] (07/12/2008):
 I am package maintainer of sugar-hulahop, so would have been quicker
 for me to add that dependency than file a bugreport if this was the
 case.

Heh, OK.

 I may have found the cause of the problem just now: during build
 dh_shlibdeps warns about being unable to locate libxul.so below
 /usr/lib/xulrunner-1.9.0.4 - and the library is in fact not there, but
 below /usr/lib/xulrunner-1.9.

Yeah, objdump shows the RPATH.

 I will go hunt for some wrong hardcoded path somewhere in either
 sugar-hulahop itsef, xulrunner-dev or python-xpcom.

Oh, easy then:
| ./configure.ac:LIBXUL_DIR=`dirname $LIBXUL_SDK_DIR`/xulrunner-`$PKG_CONFIG 
--modversion libxul`

Just installed xulrunner-dev and:
| $ pkg-config --modversion libxul
| 1.9.0.4

Not digging any further, but that looks like it.

 Thanks for your valid question (and sorry for my too short bugreport).

No problem.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#507381: libev-event-dev: out of date in sid

2008-12-07 Thread Cyril Brulebois
Cyril Brulebois [EMAIL PROTECTED] (07/12/2008):
 Niko Tyni [EMAIL PROTECTED] (30/11/2008):
  There's no libev-libevent-dev/3.43-1 package in the archive,
  apparently because the sourceful upload didn't include arch:all
  binaries.
 
 According to [EMAIL PROTECTED], that's correct.
 
 If nobody objects, I'll reupload with the result of:
 | dch -n 'Reupload with architecture-independant binaries.'

Woopsy, s/independant/independent/

Source debdiff attached, and since the 1-week delay is over already,
uploading to DELAYED/2 so that it doesn't get forgotten.

Mraw,
KiBi.
diff -u libev-3.43/debian/changelog libev-3.43/debian/changelog
--- libev-3.43/debian/changelog
+++ libev-3.43/debian/changelog
@@ -1,3 +1,10 @@
+libev (3.43-1.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Reupload with architecture-independent binaries.
+
+ -- Cyril Brulebois [EMAIL PROTECTED]  Sun, 07 Dec 2008 15:07:16 +0100
+
 libev (3.43-1) unstable; urgency=low
 
   * New upstream release


signature.asc
Description: Digital signature


Bug#507381: libev-event-dev: out of date in sid

2008-12-07 Thread Cyril Brulebois
Cyril Brulebois [EMAIL PROTECTED] (07/12/2008):
 Woopsy, s/independant/independent/

Lalala, yes, we can. With the bugnumber, that's even better…

Mraw,
KiBi.
diff -u libev-3.43/debian/changelog libev-3.43/debian/changelog
--- libev-3.43/debian/changelog
+++ libev-3.43/debian/changelog
@@ -1,3 +1,10 @@
+libev (3.43-1.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Reupload with architecture-independent binaries (Closes: #507381).
+
+ -- Cyril Brulebois [EMAIL PROTECTED]  Sun, 07 Dec 2008 15:26:48 +0100
+
 libev (3.43-1) unstable; urgency=low
 
   * New upstream release


signature.asc
Description: Digital signature


Bug#506961: auctex: reuses old logfile on emacsen upgrades, enabling symlink attack

2008-12-07 Thread Ben Hutchings
You wrote:
 I think this (untested) patch would fix it:
 
 --- /usr/lib/emacsen-common/packages/install/auctex   2008-09-08 
 13:43:54.0 +0200
 +++ auctex2008-11-28 22:08:49.0 +0100
 @@ -79,6 +79,7 @@
   rm -f ${_db_logfile}
   /usr/sbin//update-auctex-elisp ${FLAVOR} ;;
   (File)
 + rm -f ${_db_logfile}
   echo 2 -n update-auctex-elisp: 
   echo 2 Further output will appear in: ${_db_logfile}.
   echo 2 -n auctex: 
 @@ -89,6 +90,7 @@
   ${0##*/}: Unknown Debconf value doautofg = 
 \${_db_doautofg}\. ;;
   esac ;;
   (Background)
 + rm -f ${_db_logfile}
   
 /usr/sbin//update-auctex-elisp ${FLAVOR}  ${_db_logfile} 21 3- 
   echo 2 -n update-auctex-elisp[${!}]: 
   echo 2 Further output will appear in: ${_db_logfile}. ;;
 
 Note that I am neither the maintainer (just a lurker on the PTS), nor do
 I have time to do an NMU in case it is needed. Which might be the case,
 there are weeks where Davide is quite unresponsive.

That reduces the attack window, but it's not a solution.

I think the safe thing to do is to create the log file in
/var/lib/auctex or /var/log instead.

Ben.

-- 
Ben Hutchings
It is impossible to make anything foolproof because fools are so ingenious.


signature.asc
Description: This is a digitally signed message part


Processed: tagging 506961

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tags 506961 - patch
Bug#506961: auctex: reuses old logfile on emacsen upgrades, enabling symlink 
attack
Tags were: patch security
Tags removed: patch


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507883: release critical

2008-12-07 Thread Lars Bensmann
I stripped down my extensions.ael:

context blah {
//lars = std-exten-ael(SIP/lars,123456);
lars = Dial(SIP/lars);
123456 = goto lars|1;
};

The problem seems to be related to the combination of the dial command or
macro and the goto. Either line by itself is fine, but a dial or macro
before a goto triggers the problem. Putting the goto on the first line
solved the problem for me.

I also found a bug upstream that is probably the same:
http://bugs.digium.com/view.php?id=14019

The attached extensions.ael in the bugreport also contains dial statements
before gotos.

-- 
Compatible:
Gracefully accepts erroneous data from any source.



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Processed: setting package to preview-latex-style auctex, tagging 506961

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 #auctex (11.83-7.3) unstable; urgency=high
 #
 #  * Create installation/update log file in /var/log rather than /tmp.
 #Closes: #506961
 #
 package preview-latex-style auctex
Ignoring bugs not assigned to: preview-latex-style auctex

 tags 506961 + pending
Bug#506961: auctex: reuses old logfile on emacsen upgrades, enabling symlink 
attack
Tags were: security
Tags added: pending


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#506961: NMU diff for auctex 11.83-7.3

2008-12-07 Thread Ben Hutchings
I am uploading the following changes to delayed/3.

Ben.

diff -u auctex-11.83/debian/control auctex-11.83/debian/control
--- auctex-11.83/debian/control
+++ auctex-11.83/debian/control
@@ -4,13 +4,13 @@
 Maintainer: Davide G. M. Salvetti [EMAIL PROTECTED]
 Uploaders: OHURA Makoto [EMAIL PROTECTED]
 Standards-Version: 3.7.2
-Build-Depends-Indep: emacs22 | emacs21 | emacs-snapshot, eperl, gs-gpl | gs, 
po-debconf, texlive-latex-base, texinfo, texi2html (=1.76)
+Build-Depends-Indep: emacs22 | emacs21 | emacs-snapshot, eperl, ghostscript, 
po-debconf, texlive-latex-base, texinfo, texi2html (=1.76)
 Homepage: http://www.gnu.org/software/auctex/
 
 Package: auctex
 Architecture: all
 Depends: debconf | debconf-2.0, emacs22 | emacs21 | emacs-snapshot, make, 
preview-latex-style
-Recommends: doc-base, gs-gpl | gs, texlive-latex-recommended, xpdf-reader | 
pdf-viewer
+Recommends: doc-base, ghostscript, texlive-latex-recommended, xpdf-reader | 
pdf-viewer
 Suggests: catdvi, dvipng, lacheck
 Conflicts: emacspeak (= 17.0-1), preview-latex
 Replaces: preview-latex
diff -u auctex-11.83/debian/changelog auctex-11.83/debian/changelog
--- auctex-11.83/debian/changelog
+++ auctex-11.83/debian/changelog
@@ -1,3 +1,14 @@
+auctex (11.83-7.3) unstable; urgency=high
+
+  * Non-maintainer upload
+- High priority since it fixes a security flaw
+  * Create installation/update log file in /var/log rather than /tmp.
+Closes: #506961
+  * Replace build-dependency and recommendation of obsolete packages
+gs|gs-gpl with ghostscript
+
+ -- Ben Hutchings [EMAIL PROTECTED]  Sun, 07 Dec 2008 14:54:46 +
+
 auctex (11.83-7.2) unstable; urgency=low
 
   * Non-maintainer upload.
diff -u auctex-11.83/debian/auctex/config.in 
auctex-11.83/debian/auctex/config.in
--- auctex-11.83/debian/auctex/config.in
+++ auctex-11.83/debian/auctex/config.in
@@ -12,7 +12,7 @@
 
 case ${1} in
 configure|reconfigure)
-   LOGFILE=$(mktemp :=${TMPMASK}:)
+   LOGFILE=/var/log/auctex.log
db_register :=${PACKAGE}:/doauto :=${PACKAGE}:/logfile || true
db_set :=${PACKAGE}:/logfile ${LOGFILE} || true
db_subst :=${PACKAGE}:/doauto LOGFILE ${LOGFILE} || true
--- END ---

-- 
Ben Hutchings
It is impossible to make anything foolproof because fools are so ingenious.


signature.asc
Description: This is a digitally signed message part


Bug#507090: marked as done (newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be done for `binary-arch'.)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Sun, 7 Dec 2008 16:00:32 +0100
with message-id [EMAIL PROTECTED]
and subject line Re: Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on 
buildds: Nothing to be done for `binary-arch'.
has caused the Debian Bug report #507090,
regarding newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be 
done for `binary-arch'.
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
507090: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507090
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: newlib
Version: 1.16.0-2.1
Severity: serious

There was an error while trying to autobuild your package:

 Automatic build of newlib_1.16.0-2.1 on schroeder by sbuild/sparc 99.99
 Build started at 20081127-2157

[...]

 ** Using build dependencies supplied by package:
 Build-Depends: debhelper (= 6), binutils-spu [powerpc ppc64], gcc-spu 
 [powerpc ppc64], texinfo

[...]

 dpkg-buildpackage: host architecture sparc
  /usr/bin/fakeroot debian/rules clean
 dh_testdir
 dh_testroot
 rm -rf src build* *-stamp*
 rm -rf  debian/newlib-source
 dh_clean
  debian/rules build
 make: Nothing to be done for `build'.
  /usr/bin/fakeroot debian/rules binary-arch
 make: Nothing to be done for `binary-arch'.
  dpkg-genchanges -B -mDebian Build Daemon buildd_sparc-schroeder 
 ../newlib_1.16.0-2.1_sparc.changes
 dpkg-genchanges: arch-specific upload - not including arch-independent 
 packages
 dpkg-genchanges: failure: cannot read files list file: No such file or 
 directory
 dpkg-buildpackage: failure: dpkg-genchanges gave error exit status 2

That means you are trying to build arch-independ stuff only on buildds, which 
will not work.

A full build log can be found at:
http://buildd.debian.org/build.php?arch=sparcpkg=newlibver=1.16.0-2.1



---End Message---
---BeginMessage---
tags 507090 + wontfix
thanks

The package has been reintroduced (version 1.16.0-1) to the archive only for
spu (powerpc and ppc64 only) and the testing version is not supposed to build
on anything else.



signature.asc
Description: Digital signature
---End Message---


Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be done for `binary-arch'.

2008-12-07 Thread Arthur Loiret
tags 507090 + wontfix
thanks

The package has been reintroduced (version 1.16.0-1) to the archive only for
spu (powerpc and ppc64 only) and the testing version is not supposed to build
on anything else.



signature.asc
Description: Digital signature


Processed: Re: Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be done for `binary-arch'.

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tags 507090 + wontfix
Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be 
done for `binary-arch'.
There were no tags set.
Tags added: wontfix

 thanks
Stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507707: marked as done (flashplugin-nonfree: Uses invalid URL to download Flash)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Sun, 07 Dec 2008 16:02:03 +
with message-id [EMAIL PROTECTED]
and subject line Bug#507707: fixed in flashplugin-nonfree 1:1.8.1
has caused the Debian Bug report #507707,
regarding flashplugin-nonfree: Uses invalid URL to download Flash
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
507707: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507707
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: flashplugin-nonfree
Version: 1:1.7.2
Severity: grave
Justification: renders package unusable

The package in lenny/sid is unusable:

[EMAIL PROTECTED]:~$ sudo update-flashplugin-nonfree --install
--2008-12-03 20:45:01--
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash_player_9_linux.tar.gz
Résolution de fpdownload.macromedia.com... 92.122.222.70
Connexion vers fpdownload.macromedia.com|92.122.222.70|:80...connecté.
requête HTTP transmise, en attente de la réponse...404 Not Found
2008-12-03 20:45:02 ERREUR 404: Not Found.

wget failed to download
http://fpdownload.macromedia.com/get/flashplayer/current/install_flash_player_9_linux.tar.gz


You should probably push the experimental one to sid and lenny.

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (500, 'testing'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686-bigmem (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages flashplugin-nonfree depends on:
ii  debconf [debconf-2.0]  1.5.24Debian configuration management sy
ii  fontconfig 2.6.0-3   generic font configuration library
ii  gnupg  1.4.9-3   GNU privacy guard - a free PGP rep
ii  libatk1.0-01.22.0-1  The ATK accessibility toolkit
ii  libc6  2.7-16GNU C Library: Shared libraries
ii  libcairo2  1.6.4-6.1 The Cairo 2D vector graphics libra
ii  libexpat1  2.0.1-4   XML parsing C library - runtime li
ii  libfontconfig1 2.6.0-3   generic font configuration library
ii  libfreetype6   2.3.7-2   FreeType 2 font engine, shared lib
ii  libglib2.0-0   2.16.6-1  The GLib library of C routines
ii  libgtk2.0-02.12.11-4 The GTK+ graphical user interface 
ii  libice62:1.0.4-1 X11 Inter-Client Exchange library
ii  libpango1.0-0  1.20.5-3  Layout and rendering of internatio
ii  libpng12-0 1.2.27-2  PNG library - runtime
ii  libsm6 2:1.0.3-2 X11 Session Management library
ii  libx11-6   2:1.1.5-2 X11 client-side library
ii  libxau61:1.0.3-3 X11 authorisation library
ii  libxcursor11:1.1.9-1 X cursor management library
ii  libxdmcp6  1:1.0.2-3 X11 Display Manager Control Protoc
ii  libxext6   2:1.0.4-1 X11 miscellaneous extension librar
ii  libxfixes3 1:4.0.3-2 X11 miscellaneous 'fixes' extensio
ii  libxi6 2:1.1.4-1 X11 Input extension library
ii  libxinerama1   2:1.0.3-2 X11 Xinerama extension library
ii  libxrandr2 2:1.2.3-1 X11 RandR extension library
ii  libxrender11:0.9.4-2 X Rendering Extension client libra
ii  libxt6 1:1.0.5-3 X11 toolkit intrinsics library
ii  wget   1.11.4-2  retrieves files from the web
ii  zlib1g 1:1.2.3.3.dfsg-12 compression library - runtime

flashplugin-nonfree recommends no packages.

Versions of packages flashplugin-nonfree suggests:
ii  iceweasel 3.0.4-1lightweight web browser based on M
pn  konqueror-nsplugins   none (no description available)
pn  msttcorefonts none (no description available)
ii  ttf-dejavu2.25-3 Metapackage to pull in ttf-dejavu-
pn  ttf-xfree86-nonfree   none (no description available)
pn  x-ttcidfont-conf  none (no description available)
pn  xfs   none (no description available)

-- no debconf information


---End Message---
---BeginMessage---
Source: flashplugin-nonfree
Source-Version: 1:1.8.1

We believe that the bug you reported is fixed in the latest version of
flashplugin-nonfree, which is due to be installed in the Debian FTP archive:


Bug#508068: drawterm_0.cvs+20080909-1(mips/unstable):

2008-12-07 Thread Thiemo Seufer
Package: drawterm
Version: 0.cvs+20080909-1
Severity: serious
Tags: patch

There was an error while trying to autobuild your package:

 Automatic build of drawterm_0.cvs+20080909-1 on ball by sbuild/mips 99.99
 Build started at 20081206-1246

[...]

 gcc -Wall -Wno-missing-braces -ggdb -I.. -I../include -I../kern -c 
 -I/usr/X11R6/include -D_THREAD_SAFE -pthread -O2 md5block.c
 gcc -Wall -Wno-missing-braces -ggdb -I.. -I../include -I../kern -c 
 -I/usr/X11R6/include -D_THREAD_SAFE -pthread -O2 sha1block.c
 as  -o tas.o tas.s
 tas.s: Assembler messages:
 tas.s:10: Error: illegal operands `ori t1,zero,12345'
 tas.s:11: Error: opcode not supported on this processor: mips1 (mips1) `ll 
 t0,(a0)'
 tas.s:12: Error: opcode not supported on this processor: mips1 (mips1) `sc 
 t1,(a0)'
 tas.s:13: Error: illegal operands `beq t1,zero,1b'
 tas.s:17: Error: illegal operands `or v0,t0,zero'
 make[2]: *** [tas.o] Error 1
 make[2]: Leaving directory `/build/buildd/drawterm-0.cvs+20080909/posix-mips'
 make[1]: *** [libmachdep.a] Error 2
 make[1]: Leaving directory `/build/buildd/drawterm-0.cvs+20080909'
 make: *** [build-stamp] Error 2
 dpkg-buildpackage: failure: debian/rules build gave error exit status 2

A full build log can be found at:
http://buildd.debian.org/build.php?arch=mipspkg=drawtermver=0.cvs+20080909-1

The package failed to build on most architectures in different ways. The
appended patch fixes the build failure on mips (and presumably mipsel).


Thiemo


diff -urpN drawterm-0.cvs+20080909.old/Make.unix 
drawterm-0.cvs+20080909/Make.unix
--- drawterm-0.cvs+20080909.old/Make.unix   2007-06-23 05:10:01.0 
+0100
+++ drawterm-0.cvs+20080909/Make.unix   2008-12-07 15:55:21.0 +
@@ -2,7 +2,8 @@
 #PTHREAD=  # for Mac
 PTHREAD=-pthread
 AR=ar
-AS=as
+AS=gcc
+ASFLAGS=-xassembler-with-cpp -c
 RANLIB=ranlib
 X11=/usr/X11R6
 CC=gcc
diff -urpN drawterm-0.cvs+20080909.old/posix-mips/tas.s 
drawterm-0.cvs+20080909/posix-mips/tas.s
--- drawterm-0.cvs+20080909.old/posix-mips/tas.s2005-12-29 
23:50:05.0 +
+++ drawterm-0.cvs+20080909/posix-mips/tas.s2008-12-07 14:16:23.0 
+
@@ -5,17 +5,18 @@
 .ent tas 2
 
 tas:
-.set noreorder
 1:
-   ori t1, zero, 12345 /* t1 = 12345 */
-   ll  t0, (a0)/* t0 = *a0 */
+#ifdef __linux__
+   .set mips2
+#endif
+   li  t1, 12345   /* t1 = 12345 */
+   ll  v0, (a0)/* v0 = *a0 */
sc  t1, (a0)/* *a0 = t1 if *a0 hasn't changed; 
t1=success */
-   beq t1, zero, 1b/* repeat if *a0 did change */
-   nop
+   beqzt1, 1b  /* repeat if *a0 did change */
+   jr  $31 /* return */
+#ifdef __linux__
+   .set mips0
+#endif
 
-   j $31   /* return */
-   or  v0, t0, zero/* set return value on way out */
-
-.set reorder
 .end tas
 



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508055: marked as done (libcups2: Ridiculous dependencies)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Sun, 7 Dec 2008 08:33:11 -0800
with message-id [EMAIL PROTECTED]
and subject line Re: [Pkg-cups-devel] Bug#508055: libcups2: Ridiculous 
dependencies
has caused the Debian Bug report #508055,
regarding libcups2: Ridiculous dependencies
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
508055: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508055
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: libcups2
Version: 1.3.8-1lenny3
Severity: grave

When I try to remove libcups2, I get the message:

The following packages will be REMOVED

abiword abiword-common abiword-help abiword-plugin-grammar
abiword-plugin-mathview acroread acroread-data acroread-debian-files
acroread-dictionary-en acroread-escript acroread-l10n-en acroread-plugins
afterstep amule amule-utils-gui aterm audacity avidemux azureus bluefish
ca-certificates-java camorama choosewm cups desktop-base drgeo driconf
ed2k-gtk-gui evince exo-utils fluxconf gamix gconf-editor ghostscript
ghostscript-x gimp gimp-gnomevfs gimp-python glade gnome-icon-theme
gnome-keyring gnucash gnucash-docs gnuplot gnuplot-x11 gs-common gs-esp
gs-gpl gstreamer0.10-plugins-good gtk-gnutella gtk-theme-switch gtk2-engines
gtk2-engines-pixbuf gtk2-engines-xfce gtkam gucharmap gv homebank html2ps
icedove icedtea-gcjwebplugin iceweasel imagemagick inkscape leafpad
libaccess-bridge-java libafterimage0 libafterstep1 libaiksaurusgtk-1.2-0c2a
libbonoboui2-0 libcommons-cli-java libcommons-lang-java libcups2
libcupsimage2 libcupsys2 libexif-gtk5 libexo-0.3-0 libgail-common
libgail-dev libgail17 libgail18 libgcj8-1-awt libgcj9-0-awt
libgdk-pixbuf2-ruby libgdk-pixbuf2-ruby1.8 libgimp2.0 libgksuui1.0-1
libglade2-0 libglade2-dev libglademm-2.4-1c2a libglademm-2.4-dev
libgladeui-1-7 libgnome-media0 libgnomecanvas2-0 libgnomecanvas2-dev
libgnomecups1.0-1 libgnomeprint2.2-0 libgnomeprintui2.2-0 libgnomeui-0
libgoffice-0-4 libgraphicsmagick++1 libgraphicsmagick1 libgs8 libgtk2.0-0
libgtk2.0-bin libgtk2.0-dev libgtkhtml2-0 libgtkhtml3.8-15
libgtkmathview0c2a libgtkmm-2.4-1c2a libgtkmm-2.4-dev libgtkspell0
libgucharmap6 liblog4j1.2-java liblog4j1.2-java-gcj libmagick++10
libmagick10 libmetacity0 libnautilus-burn3 libnautilus-extension1 libnotify1
libpoppler-glib3 libpoppler0c2-glib librsvg2-2 librsvg2-common libscim8c2a
libspectre1 libswt-gtk-3.1-jni libswt-gtk-3.2-jni libswt-gtk-3.4-java
libswt-gtk-3.4-jni libthunar-vfs-1-2 libvte9 libwmf0.2-7 libwv-1.2-3
libwxgtk2.6-0 libwxgtk2.8-0 libxfcegui4-4 libxine1 libxine1-misc-plugins
libxine1-plugins libxul0d maxima maxima-share maxima-test mjpegtools
mkvtoolnix-gui mlterm mlterm-tools mousepad mozilla-acroread mozilla-mplayer
mplayer obconf ogle-gui openjdk-6-jre openjdk-6-jre-headless
openjdk-6-jre-lib openoffice.org-calc openoffice.org-core
openoffice.org-draw openoffice.org-emailmerge
openoffice.org-filter-binfilter openoffice.org-help-en-gb
openoffice.org-impress openoffice.org-writer orage pan pdf2dj perlmagick
python-glade2 python-gtk2 python-uno python-wxgtk2.6 python-wxversion
quicktime-x11utils rapidsvn realplayer rhino rox-filer rxvt-unicode scim
scim-gtk2-immodule scim-modules-socket scribus sgt-puzzles
sodipodi streamtuner subtitleeditor texmacs thunar transcode uim-gtk2.0
uim-xim xaralx xcdroast xfce4 xfce4-mcs-manager xfce4-mcs-plugins
libxine1-plugins libxul0d maxima maxima-share maxima-test mjpegtools
mkvtoolnix-gui mlterm mlterm-tools mousepad mozilla-acroread mozilla-mplayer
mplayer obconf ogle-gui openjdk-6-jre openjdk-6-jre-headless
openjdk-6-jre-lib openoffice.org-calc openoffice.org-core
openoffice.org-draw openoffice.org-emailmerge
openoffice.org-filter-binfilter openoffice.org-help-en-gb
openoffice.org-impress openoffice.org-writer orage pan pdf2dj perlmagick
python-glade2 python-gtk2 python-uno python-wxgtk2.6 python-wxversion
quicktime-x11utils rapidsvn realplayer rhino rox-filer rxvt-unicode scim
scim-gtk2-immodule scim-modules-socket scribus sgt-puzzles
sodipodi streamtuner subtitleeditor texmacs thunar transcode uim-gtk2.0
uim-xim xaralx xcdroast xfce4 xfce4-mcs-manager xfce4-mcs-plugins
xfce4-mixer xfce4-mixer-alsa xfce4-netload-plugin xfce4-panel xfce4-session
xfce4-systemload-plugin xfce4-terminal xfce4-utils xfdesktop4 xfprint4
xfreecd xfwm4 xfwm4-themes xine-ui xmaxima xscreensaver xscreensaver-dat
xsensors xulrunner-1.9 yelp zeroinstall-injector

This absurd. Many of these programs have nothing at all to do with
printing. And all the others can print very well, thank you, using lprng
instead of CUPS. 

Please remove these ridiculous dependencies.

Regards, Jan


-- System 

Bug#507090: newlib_1.16.0-2.1(sparc/unstable): FTBFS on buildds: Nothing to be done for `binary-arch'.

2008-12-07 Thread Cyril Brulebois
Cyril Brulebois [EMAIL PROTECTED] (07/12/2008):
 That said, this bug is still a Policy §4.9 violation.

Eeek, misread “make -f debian/rules -p” output, sorry for that.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Bug#496954: NMU diff for bind9 1:9.5.0.dfsg.P2-4.1

2008-12-07 Thread Ben Hutchings
I intend to upload the following changes to delayed/3 shortly.

Ben.

diff -u bind9-9.5.0.dfsg.P2/debian/changelog 
bind9-9.5.0.dfsg.P2/debian/changelog
--- bind9-9.5.0.dfsg.P2/debian/changelog
+++ bind9-9.5.0.dfsg.P2/debian/changelog
@@ -1,3 +1,12 @@
+bind9 (1:9.5.0.dfsg.P2-4.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Backported upstream ACL fixes from 9.5.1 to fix RC bug. Patch was provided
+by Evan Hunt (upstream bind9 developer) after Emmanuel Bouthenot
+contacted him. Closes: #496954, #501800.
+
+ -- Ben Hutchings [EMAIL PROTECTED]  Sun, 07 Dec 2008 16:30:43 +
+
 bind9 (1:9.5.0.dfsg.P2-4) unstable; urgency=low
 
   * meta: fix typo in Depends: lsb-base.  Closes: #501365
only in patch2:
unchanged:
--- bind9-9.5.0.dfsg.P2.orig/lib/dns/iptable.c
+++ bind9-9.5.0.dfsg.P2/lib/dns/iptable.c
@@ -70,22 +70,39 @@
 
NETADDR_TO_PREFIX_T(addr, pfx, bitlen);
 
-   /* Bitlen 0 means any or none, which is always treated as IPv4 */
-   family = bitlen ? pfx.family : AF_INET;
-
result = isc_radix_insert(tab-radix, node, NULL, pfx);
-
-   if (result != ISC_R_SUCCESS)
+   if (result != ISC_R_SUCCESS) {
+   isc_refcount_destroy(pfx.refcount);
return(result);
+   }
 
-   /* If the node already contains data, don't overwrite it */
-   if (node-data[ISC_IS6(family)] == NULL) {
-   if (pos)
-   node-data[ISC_IS6(family)] = dns_iptable_pos;
-   else
-   node-data[ISC_IS6(family)] = dns_iptable_neg;
+   /* If a node already contains data, don't overwrite it */
+   family = pfx.family;
+   if (family == AF_UNSPEC) {
+   /* any or none */
+   INSIST(pfx.bitlen == 0);
+   if (pos) {
+   if (node-data[0] == NULL)
+   node-data[0] = dns_iptable_pos;
+   if (node-data[1] == NULL)
+   node-data[1] = dns_iptable_pos;
+   } else {
+   if (node-data[0] == NULL)
+   node-data[0] = dns_iptable_neg;
+   if (node-data[1] == NULL)
+   node-data[1] = dns_iptable_neg;
+   }
+   } else {
+   /* any other prefix */
+   if (node-data[ISC_IS6(family)] == NULL) {
+   if (pos)
+   node-data[ISC_IS6(family)] = dns_iptable_pos;
+   else
+   node-data[ISC_IS6(family)] = dns_iptable_neg;
+   }
}
 
+   isc_refcount_destroy(pfx.refcount);
return (ISC_R_SUCCESS);
 }
 
only in patch2:
unchanged:
--- bind9-9.5.0.dfsg.P2.orig/lib/dns/acl.c
+++ bind9-9.5.0.dfsg.P2/lib/dns/acl.c
@@ -148,7 +148,10 @@
return (ISC_FALSE);
 
if (acl-iptable-radix-head-prefix-bitlen == 0 
-   *(isc_boolean_t *) (acl-iptable-radix-head-data[0]) == pos)
+   acl-iptable-radix-head-data[0] != NULL 
+   acl-iptable-radix-head-data[0] ==
+   acl-iptable-radix-head-data[1] 
+   *(isc_boolean_t *) (acl-iptable-radix-head-data[0]) == pos)
return (ISC_TRUE);
 
return (ISC_FALSE); /* All others */
@@ -220,8 +223,6 @@
 
/* Found a match. */
if (result == ISC_R_SUCCESS  node != NULL) {
-   if (node-bit == 0)
-   family = AF_INET;
match_num = node-node_num[ISC_IS6(family)];
if (*(isc_boolean_t *) node-data[ISC_IS6(family)] == ISC_TRUE)
*match = match_num;
@@ -491,9 +492,8 @@
isc_boolean_t secure;
int bitlen, family;
 
-   /* Bitlen 0 means any or none, which is always treated as IPv4 */
bitlen = prefix-bitlen;
-   family = bitlen ? prefix-family : AF_INET;
+   family = prefix-family;
 
/* Negated entries are always secure. */
secure = * (isc_boolean_t *)data[ISC_IS6(family)];
only in patch2:
unchanged:
--- bind9-9.5.0.dfsg.P2.orig/lib/isccfg/aclconf.c
+++ bind9-9.5.0.dfsg.P2/lib/isccfg/aclconf.c
@@ -160,6 +160,51 @@
return (dns_name_dup(dns_fixedname_name(fixname), mctx, dnsname));
 }
 
+/*
+ * Recursively pre-parse an ACL definition to find the total number
+ * of non-IP-prefix elements (localhost, localnets, key) in all nested
+ * ACLs, so that the parent will have enough space allocated for the
+ * elements table after all the nested ACLs have been merged in to the
+ * parent.
+ */
+static int
+count_acl_elements(const cfg_obj_t *caml, const cfg_obj_t *cctx)
+{
+   const cfg_listelt_t *elt;
+   const cfg_obj_t *cacl = NULL;
+   isc_result_t result;
+   int n = 0;
+
+   for (elt = cfg_list_first(caml);
+elt != NULL;
+elt = cfg_list_next(elt)) {
+   const cfg_obj_t *ce = cfg_listelt_value(elt);
+
+   /* 

Processed: tagging 496954

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tags 496954 patch upstream fixed-upstream pending
Bug#496954: bind9: Fails to start due to SIGSEGV
Tags were: upstream
Tags added: patch, upstream, fixed-upstream, pending


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Processed: tagging 501800

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tags 501800 patch upstream fixed-upstream pending
Bug#501800: bind9: bind crashes with a list for allow-update
Tags were: upstream
Tags added: patch, upstream, fixed-upstream, pending


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507711: clamfs: Uninstallable in Sid due to libpoconet soname bump

2008-12-07 Thread Krzysztof Burghardt
2008/12/7 Cyril Brulebois [EMAIL PROTECTED]:
 Krzysztof, any reason why you didn't open bugs against your reverse
 dependencies that no longer build? And why you didn't ask for binNMUs?

I will fix this soon.

-- 
Krzysztof Burghardt [EMAIL PROTECTED]
http://www.burghardt.pl/



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507850: marked as done (python-hulahop: Hulahop fails to locate and link against libxul.so)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Sun, 07 Dec 2008 16:47:08 +
with message-id [EMAIL PROTECTED]
and subject line Bug#507850: fixed in sugar-hulahop 0.4.8~dfsg-3
has caused the Debian Bug report #507850,
regarding python-hulahop: Hulahop fails to locate and link against libxul.so
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
507850: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507850
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: python-hulahop
Version: 0.4.8~dfsg-2
Severity: grave
Justification: renders package unusable

As subject says, sugar-hulahop is plain broken at the moment: Attempts
tos start Browse activity leads to notes in logfile that it can't locate
libxul.so


---End Message---
---BeginMessage---
Source: sugar-hulahop
Source-Version: 0.4.8~dfsg-3

We believe that the bug you reported is fixed in the latest version of
sugar-hulahop, which is due to be installed in the Debian FTP archive:

python-hulahop_0.4.8~dfsg-3_amd64.deb
  to pool/main/s/sugar-hulahop/python-hulahop_0.4.8~dfsg-3_amd64.deb
sugar-hulahop_0.4.8~dfsg-3.diff.gz
  to pool/main/s/sugar-hulahop/sugar-hulahop_0.4.8~dfsg-3.diff.gz
sugar-hulahop_0.4.8~dfsg-3.dsc
  to pool/main/s/sugar-hulahop/sugar-hulahop_0.4.8~dfsg-3.dsc



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jonas Smedegaard [EMAIL PROTECTED] (supplier of updated sugar-hulahop package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Sun, 07 Dec 2008 17:19:51 +0100
Source: sugar-hulahop
Binary: python-hulahop
Architecture: source amd64
Version: 0.4.8~dfsg-3
Distribution: unstable
Urgency: low
Maintainer: Debian OLPC [EMAIL PROTECTED]
Changed-By: Jonas Smedegaard [EMAIL PROTECTED]
Description: 
 python-hulahop - Sugar graphical shell - gecko-based web engine
Closes: 507850
Changes: 
 sugar-hulahop (0.4.8~dfsg-3) unstable; urgency=low
 .
   * Add patches 1001 and 2001 to fix hardcoded libxul path. Closes:
 bug#507850.
Checksums-Sha1: 
 ce624f2169f79858215f369871c8a080d355c248 1534 sugar-hulahop_0.4.8~dfsg-3.dsc
 6ed185cf242cbc027100b39d7a4f9dfb2f247a64 15370 
sugar-hulahop_0.4.8~dfsg-3.diff.gz
 ef60a80d51e9204816968166befe6cd3a45a09d9 194422 
python-hulahop_0.4.8~dfsg-3_amd64.deb
Checksums-Sha256: 
 afb4b39d7653fedddcd3cb71eb34971b3456bc2731f608978e37b3bff4f8b4a6 1534 
sugar-hulahop_0.4.8~dfsg-3.dsc
 dbeee81671aea65f3e8a807aa0ee0141d1ba7e20aed34f14b4dff4573b6f4f9c 15370 
sugar-hulahop_0.4.8~dfsg-3.diff.gz
 5a2cc3570093c0fd18f3305046b66569258c7476c74350c769e79537f690ed69 194422 
python-hulahop_0.4.8~dfsg-3_amd64.deb
Files: 
 bc9a5f7d3b620e3e61542d3ec81a954d 1534 python optional 
sugar-hulahop_0.4.8~dfsg-3.dsc
 dc10f0061cebbf7560c0baddd7aef73c 15370 python optional 
sugar-hulahop_0.4.8~dfsg-3.diff.gz
 73753537c09ad4ecc12eab15da9d729f 194422 python optional 
python-hulahop_0.4.8~dfsg-3_amd64.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkk7+toACgkQn7DbMsAkQLgxtACdEXyXh13APpWIziEUXWVGFEd0
8AwAoIYETsylUWJVMyvenQnRjYcG8ryT
=lfrz
-END PGP SIGNATURE-


---End Message---


Bug#490171: Bug#470416: rtorrent: random crash (grave)

2008-12-07 Thread Jari Aalto
Jose Luis Rivas [EMAIL PROTECTED] writes:

 Jari Aalto wrote:

 
 Confirmed.
 
 There seesm to be more a serious problem. Not just the rtorrent crash, but
 the whole workstation dies: kernel becomes unresponsive to the point
 where nothing happens.

 Can you please try with experimental release? I'm not in position to
 make this test (starting by my lack of bandwith and lack of hardware,
 I'm not always online in my machine).

 I'm about to push experimental to unstable and this one would make
 another good reason to do this. (Besides of #506748)

Same results with 0.8.4-1. Kernel completely freezes after a while.

Jari



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508071: shutdown failed with splashy

2008-12-07 Thread gpe
Package: splashy
Version: 0.3.12-1
Severity: grave
Justification: renders package unusable

when splashy is installed and activated the shutdown failed and we must
power off the PC by the power button. 


-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.26-1-686 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages splashy depends on:
ii  initramfs-tools0.92j tools for generating an initramfs
ii  libc6  2.7-16GNU C Library: Shared libraries
ii  libdirectfb-1.0-0  1.0.1-11  direct frame buffer graphics - sha
ii  libgcc11:4.3.2-1 GCC support library
ii  libglib2.0-0   2.16.6-1  The GLib library of C routines
ii  libmagic1  4.26-1File type determination library us
ii  libsplashy10.3.12-1  Library to draw splash screen on b
ii  lsb-base   3.2-20Linux Standard Base 3.2 init scrip
ii  zlib1g 1:1.2.3.3.dfsg-12 compression library - runtime

splashy recommends no packages.

Versions of packages splashy suggests:
ii  console-common0.7.80 basic infrastructure for text cons
ii  splashy-themes0.4.1  A complete user-space boot splash 
pn  upstart   none (no description available)

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#501800: NMU diff for bind9 1:9.5.0.dfsg.P2-4.1

2008-12-07 Thread Ben Hutchings
On Sun, 2008-12-07 at 16:58 +, Ben Hutchings wrote:
 I intend to upload the following changes to delayed/3 shortly.
 
 Ben.

lintian and my basic testing found some more easy bugs to fix.  Here are
the actual changes.

Ben.

diff -u bind9-9.5.0.dfsg.P2/debian/changelog 
bind9-9.5.0.dfsg.P2/debian/changelog
--- bind9-9.5.0.dfsg.P2/debian/changelog
+++ bind9-9.5.0.dfsg.P2/debian/changelog
@@ -1,3 +1,15 @@
+bind9 (1:9.5.0.dfsg.P2-4.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Backported upstream ACL fixes from 9.5.1 to fix RC bug. Patch was provided
+by Evan Hunt (upstream bind9 developer) after Emmanuel Bouthenot
+contacted him. Closes: #496954, #501800.
+  * Fix library dependencies for bind9utils
+  * Fix minor errors in package descriptions
+  * Add dependency of bind9 on net-tools (ifconfig used in init script)
+
+ -- Ben Hutchings [EMAIL PROTECTED]  Sun, 07 Dec 2008 17:08:28 +
+
 bind9 (1:9.5.0.dfsg.P2-4) unstable; urgency=low
 
   * meta: fix typo in Depends: lsb-base.  Closes: #501365
diff -u bind9-9.5.0.dfsg.P2/debian/control bind9-9.5.0.dfsg.P2/debian/control
--- bind9-9.5.0.dfsg.P2/debian/control
+++ bind9-9.5.0.dfsg.P2/debian/control
@@ -10,7 +10,7 @@
 
 Package: bind9
 Architecture: any
-Depends: ${shlibs:Depends}, debconf | debconf-2.0, netbase, adduser, libdns43 
(=${binary:Version}), libisccfg40 (=${binary:Version}), libisc44 
(=${binary:Version}), libisccc40 (=${binary:Version}), lsb-base (= 3.2-14), 
bind9utils (=${binary:Version}), liblwres40 (=${binary:Version}), libbind9-40 
(=${binary:Version})
+Depends: ${shlibs:Depends}, debconf | debconf-2.0, netbase, adduser, libdns43 
(=${binary:Version}), libisccfg40 (=${binary:Version}), libisc44 
(=${binary:Version}), libisccc40 (=${binary:Version}), lsb-base (= 3.2-14), 
bind9utils (=${binary:Version}), liblwres40 (=${binary:Version}), libbind9-40 
(=${binary:Version}), net-tools
 Conflicts: bind, apparmor-profiles ( 2.1+1075-0ubuntu4)
 Replaces: bind, dnsutils ( 1:9.1.0-3), apparmor-profiles ( 
2.1+1075-0ubuntu4)
 Suggests: dnsutils, bind9-doc, resolvconf, ufw
@@ -22,7 +22,7 @@
 Package: bind9utils
 Architecture: any
 Replaces: bind9 (= 1:9.5.0~b2-1)
-Depends: libbind9-40
+Depends: ${shlibs:Depends}
 Description: Utilities for BIND
  This package provides various utilities that are useful for maintaining a
  working BIND installation.
@@ -55,7 +55,7 @@
 Depends: libbind9-40 (= ${binary:Version}), liblwres40 (= ${binary:Version}) 
 Description: Static Libraries and Headers used by BIND
  This package delivers archive-style libraries, header files, and API man
- pages for libbind, libdns, libisc, and liblwres.  These are are only needed 
+ pages for libbind, libdns, libisc, and liblwres.  These are only needed 
  if you want to compile other packages that need more nameserver API than the 
  resolver code provided in libc.
 
@@ -149,7 +149,7 @@
  This package delivers various client programs related to DNS that are 
  derived from the BIND source tree.
  .
-  - dig- query the DNS in various ways
+  - dig - query the DNS in various ways
   - nslookup - the older way to do it
   - nsupdate - perform dynamic updates (See RFC2136)
 
only in patch2:
unchanged:
--- bind9-9.5.0.dfsg.P2.orig/lib/dns/iptable.c
+++ bind9-9.5.0.dfsg.P2/lib/dns/iptable.c
@@ -70,22 +70,39 @@
 
NETADDR_TO_PREFIX_T(addr, pfx, bitlen);
 
-   /* Bitlen 0 means any or none, which is always treated as IPv4 */
-   family = bitlen ? pfx.family : AF_INET;
-
result = isc_radix_insert(tab-radix, node, NULL, pfx);
-
-   if (result != ISC_R_SUCCESS)
+   if (result != ISC_R_SUCCESS) {
+   isc_refcount_destroy(pfx.refcount);
return(result);
+   }
 
-   /* If the node already contains data, don't overwrite it */
-   if (node-data[ISC_IS6(family)] == NULL) {
-   if (pos)
-   node-data[ISC_IS6(family)] = dns_iptable_pos;
-   else
-   node-data[ISC_IS6(family)] = dns_iptable_neg;
+   /* If a node already contains data, don't overwrite it */
+   family = pfx.family;
+   if (family == AF_UNSPEC) {
+   /* any or none */
+   INSIST(pfx.bitlen == 0);
+   if (pos) {
+   if (node-data[0] == NULL)
+   node-data[0] = dns_iptable_pos;
+   if (node-data[1] == NULL)
+   node-data[1] = dns_iptable_pos;
+   } else {
+   if (node-data[0] == NULL)
+   node-data[0] = dns_iptable_neg;
+   if (node-data[1] == NULL)
+   node-data[1] = dns_iptable_neg;
+   }
+   } else {
+   /* any other prefix */
+   if (node-data[ISC_IS6(family)] == NULL) {
+   if (pos)
+   node-data[ISC_IS6(family)] = dns_iptable_pos;
+

Bug#496411: #496411: nothing was fixed at all

2008-12-07 Thread Luk Claes
Frank Lichtenheld wrote:
 Dear release team,
 
 On Sat, Nov 29, 2008 at 12:31:31PM +0100, Filippo Giunchedi wrote:
 On Sat, Nov 29, 2008 at 11:15:17AM +0100, Frank Lichtenheld wrote:
 On Thu, Nov 27, 2008 at 10:50:25AM +0100, Filippo Giunchedi wrote:
 Indeed, is there an ETA for this bug? At least for the unstable (i.e. with
 maintainer QA) version.

 FWIW as the fix looks trivial I think it is worth keeping the package.
 I disagree. I doubt that the version in unstable/testing is useful for
 anyone, and if it is, it is still available in etch anyway.
 So I would go for removing it from testing.
 Fair enough, given also the low popcon
 
 I recommend to remove ltp/20060918-3 from testing

removal hint added

Cheers

Luk



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507509:

2008-12-07 Thread Diego Escalante Urrelo
On 12/7/08, George Kiagiadakis [EMAIL PROTECTED] wrote:


  ALSO, I tried this with a different user and it seems to work! So, it's
  obviously some problem with the configuration. I tried to move away
  ~/.config/subtitleeditor, but that didn't help and I noticed that it still
  could remember the recently opened files, so it must be saving some
  configuration bits somewhere else. Any ideas where is that?


~/.recently-used*, keep your current copy before deleting so we can
try to debug the problem further (perhaps it's a crash on missing
files being on the r-u list)



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#494328: Maybe unblock acl2 3.4-1

2008-12-07 Thread Luk Claes
Ben Hutchings wrote:
 lenny currently has acl2 3.1-1, the same as etch.  This seems to have a
 bug (or else it triggers a compiler bug) that means rebuilding it in
 lenny fails at self-test (#494328).
 
 This is fixed or otherwise avoided in 3.4-1, but as upstream has no bug
 database or public VCS it is practically impossible to tell how.  The
 changelog also makes no mention of an intentional fix for this bug.
 
 There is currently an unblock rule for acl2 3.3-1, but that was
 superceded by 3.4-1 before it could propagate to lenny.  Perhaps 3.4-1
 should be unblocked?  I really don't know anything about this package so
 I cannot say whether the changes in 3.4-1 are worth having or are high
 or low risk.  But I don't believe this bug can be fixed by a t-p-u
 upload since the changes probably cannot be isolated.

The diff is *HUGE*, contacting the maintainer does not seem to help, so
removal hint added.

Cheers

Luk



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#490999: gcc-4.3 / qt3 misalignment

2008-12-07 Thread Baurzhan Ismagulov
On Mon, Nov 24, 2008 at 10:32:54AM +0100, Sune Vuorela wrote:
 Ben Hutchins did some work on it and ended up filing a bug against gcc:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=506713
 it got a much smaller testcase - and the gcc maintainer asks for additional 
 information that can easiest been given by people with a sparc

Now that #506713 is closed, I have a couple of questions regarding the
process:

* The closing message mentions experimental; will the package be
  available in lenny? If yes, will this happen automatically, or does
  someone need to do something?

* When a newer compiler package is available for a distribution, is
  everything rebuilt with it?

* Are the package versions of everything bumped? Their sources have
  not been changed, but the binaries built with the (now fixed) compiler
  have. How is it ensured that users get the new binaries?

I've looked into the Reference, the Policy Manual, the Developer's
Reference, the New Maintainer's Guide, and Google, but couldn't find
anything even about dak deployment on the Debian servers. I would be
very grateful if anyone could explain this or point me to the right docs
/ mailing list.

Thanks in advance,
-- 
Baurzhan Ismagulov
http://www.kz-easy.com/



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507711: Request for binNMU of clamfs 0.9.1-3

2008-12-07 Thread Krzysztof Burghardt
Hello RMs,

I kindly request rebuild of clamfs on all architectures. This is
needed to fix dependency problems after libpoco's components soname
change [1].

clamfs_0.9.1-3,  Rebuild against newer libpoco fixes #507711, 1, alpha
amd64 arm armel hppa i386 ia64 mips mipsel powerpc s390 sparc

[1] http://bugs.debian.org/507711

(I'm not on list, so CC: me.)

Regards,
-- 
Krzysztof Burghardt [EMAIL PROTECTED]
http://www.burghardt.pl/



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507328: marked as done (activity is installed in the wrong place and thus not found)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Sun, 07 Dec 2008 19:47:09 +
with message-id [EMAIL PROTECTED]
and subject line Bug#507328: fixed in sugar-pippy-activity 25-2
has caused the Debian Bug report #507328,
regarding activity is installed in the wrong place and thus not found
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
507328: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507328
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: sugar
Version: 0.81.2-1
Severity: normal

Hi

I am a member of OLPC-CH (Switzerland). I used to run emulated XO images
from laptop.org.

As a longtime user and supporter of Debian I tried about a week ago to
use
the Debian sugar package. As of today update to unstable I found to my
surprise that #484086: sugar-emulator doesnt work at all has been
resolved.

I removed my $HOME/.sugar directory and got prompted to enter my
username and to select a colour (as expected). But after sugar has come
up neither in the Ring nor the List view I see any activity.

This is for me the same situation when booting from a fresh
devel_ext3.img. Usually I just have a root shell opened by typing return
in my qemu session. Then after typing
# wget http://dev.laptop.org/~erikos/sucrose-activities.py
# python sucrose-activities.py
my activites pop up.

Looking (as the readme suggests) at
http://wiki.laptop.org/go/Sugar_with_sugar-jhbuild
didn't help neither.

It would help also if you document in a README.Debian how one can ssh
into a sugar-emulator.

Best regards and many thanks for your work for Debian.


-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (500, 'stable'), (1, 
'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.25-2-686 (SMP w/2 CPU cores)
Locale: LANG=de_CH.UTF-8, LC_CTYPE=de_CH.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages sugar depends on:
ii  dbus-x11   1.2.1-2   simple interprocess messaging syst
ii  librsvg2-common2.22.2-2  SAX-based renderer library for SVG
ii  matchbox-window-manage 1.2-1 window manager for resource-limite
ii  python 2.5.2-1   An interactive high-level object-o
ii  python-cairo   1.4.12-1.0~jones2 Python bindings for the Cairo vect
ii  python-central 0.6.7 register and build utility for Pyt
ii  python-dbus0.82.4-2  simple interprocess messaging syst
ii  python-gnome2-desktop  2.22.0-1  Python bindings for the GNOME desk
ii  python-gobject 2.14.2-1  Python bindings for the GObject li
ii  python-gst0.10 0.10.11-1 generic media-playing framework (P
ii  python-gtk22.12.1-6  Python bindings for the GTK+ widge
ii  python-hippocanvas 0.2.23-4.1Python bindings to hippo-canvas
ii  python-numpy   1:1.0.4-8 Numerical Python adds a fast array
ii  python-simplejson  1.9.1-1   Simple, fast, extensible JSON enco
ii  python-sugar   0.79.1-1  Sugar graphical shell - core funct
ii  python-sugar-toolkit   0.81.3-1  Sugar graphical shell - core widge
ii  python-telepathy   0.15.0-1  python language bindings for telep
ii  telepathy-gabble   0.7.6-1   Jabber/XMPP connection manager
ii  telepathy-salut0.3.3-1   Link-local XMPP connection manager
ii  telepathy-stream-engin 0.5.3-1   stream handler for the Telepathy f

Versions of packages sugar recommends:
ii  gstreamer0.10-plug 0.10.8-4  GStreamer plugins from the good 
ii  net-tools  1.60-19   The NET-3 networking toolkit
ii  network-manager0.6.6-1   network management framework daemo
ii  sugar-artwork  0.79.2-2  Sugar graphical shell - artwork
ii  x11-xserver-utils  7.3+3 X server utilities
ii  xbase-clients  1:7.2.ds2-2   miscellaneous X clients
ii  xserver-xephyr 2:1.4.1~git20080517-1 nested X server

-- no debconf information


---End Message---
---BeginMessage---
Source: sugar-pippy-activity
Source-Version: 25-2

We believe that the bug you reported is fixed in the latest version of
sugar-pippy-activity, which is due to be installed in the Debian FTP archive:

sugar-pippy-activity_25-2.diff.gz
  to pool/main/s/sugar-pippy-activity/sugar-pippy-activity_25-2.diff.gz
sugar-pippy-activity_25-2.dsc
  to pool/main/s/sugar-pippy-activity/sugar-pippy-activity_25-2.dsc
sugar-pippy-activity_25-2_all.deb
  to 

Bug#508091: maintainer address bounces

2008-12-07 Thread Thomas Viehmann
X-Debbugs-CC: [EMAIL PROTECTED]
Package: tuxguitar
Version: 1.0-1
Severity: serious

Hi,

unfortunately, Philippe's mail seems to bounce:

[EMAIL PROTECTED]: host mx.sourceforge.net[216.34.181.68] said:
550 unknown user (in reply to RCPT TO command)

If this is transient, please feel free to close this bug, but otherwise
it should be fixed (also for Philippe's other packages).
I noticed because ftp-master ACCEPT mail bounced.

Kind regards

T.
-- 
Thomas Viehmann, http://thomas.viehmann.net/



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508094: eresi: etrace_geterrfunc implicitly converted to pointer

2008-12-07 Thread dann frazier
Package: eresi
Version: 1:0.8a25-1
Severity: serious
Tags: patch
Usertags: implicit-pointer-conversion

Our automated buildd log filter[1] detected a problem that is likely to
cause your package to segfault on architectures where the size of a
pointer is greater than the size of an integer, such as ia64 and amd64.

  Function `etrace_geterrfunc' implicitly converted to pointer at fini.c:49
  Function `etrace_geterrfunc' implicitly converted to pointer at fini.c:49

This is often due to a missing function prototype definition.
For more information, see [2].

Though it is guaranteed that this codepath will cause a segfault on certain
architectures, it is not guaranteed that this codepath would ever be executed
(e.g., if the returned pointer is never dereferenced). However, this bug
does prevent the ia64 buildd from successfully building this package, resulting
in a practical FTBFS issue and warranting the serious severity.

[1] http://people.debian.org/~dannf/check-implicit-pointer-functions
[2] http://wiki.debian.org/ImplicitPointerConversions

--- eresi-0.8a25/librevm/vm/fini.c.orig 2008-12-07 13:36:35.0 -0700
+++ eresi-0.8a25/librevm/vm/fini.c  2008-12-07 13:36:41.0 -0700
@@ -7,6 +7,7 @@
  * $Id: fini.c,v 1.1 2008-02-16 12:32:27 thor Exp $
  */
 #include revm.h
+#include ../../libetrace/include/libetrace.h
 
 
 /* Some REVM context cleanup when coming back from script to interactive mode 
*/




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507558: Mess in another user's home dir?

2008-12-07 Thread Michael Kiefer
Hello Albert,

sorry for this being extremely vague but I don't remember the details any 
more. I had a similar problem once with LockKDE. There was no hint in the 
lockfiles as I remember but somehow I figured out that something in _another_ 
user's home dir, I think concerning DCOP, was messed up. I think I had to run 
the script performing the actual lock manually in order to find out.

Michael



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507883: release critical

2008-12-07 Thread martin f krafft
also sprach Lars Bensmann [EMAIL PROTECTED] [2008.12.07.1605 +0100]:
 The attached extensions.ael in the bugreport also contains dial
 statements before gotos.

Can you reproduce the bug with an equivalent extensions.conf (the
other format for the dialplans)?

-- 
 .''`.   martin f. krafft [EMAIL PROTECTED]  Related projects:
: :'  :  proud Debian developer   http://debiansystem.info
`. `'`   http://people.debian.org/~madduckhttp://vcs-pkg.org
  `-  Debian - when you have better things to do than fixing systems
 
everyone has a little secret he keeps,
 i like the fires when the city sleeps.
  -- mc 900 ft jesus


digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)


Bug#505271: Bug#505071: login tty mis-determination (see bug#332198)

2008-12-07 Thread Paul Szabo
Dear Nicolas,

On 23 Nov you wrote:

  - alert other Linux distros,
 A new upstream version was released this weekend.

Have not seen any distros make announcements. What distros use that? 
(Am surprised that even Ubuntu has not updated, though normally they
seem responsive.)

Cheers, Paul

Paul Szabo   [EMAIL PROTECTED]   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of SydneyAustralia



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#507788: sysctl.conf read before ipv6 module loaded, so cannot set ipv6 settings

2008-12-07 Thread Craig Small
On Fri, Dec 05, 2008 at 01:42:50PM +0100, Didier Raboud wrote:
 As ipv6 is a release goal, my guess is that a solution has to be found.
 Then, why not getting opininons by consulting -devel about
It will break things, not might, it will. The easiest examples being
anything that uses the /conf/default/ in the network setup and not
/conf/all/ and anything that needs to be there before the interfaces 
are brought online.

There will be a small but definite gap between when an interface is
brought up and when the parameters are applied. Some of those parameters
are security related and so there is a problem right there.

While IPv6 is a release goal, having sysctl handle the fact the module
is not there first is not. There are ways to have the ipv6 module load
late and to have kernel parameters setup in it.

 - Craig
-- 
Craig Small  GnuPG:1C1B D893 1418 2AF4 45EE  95CB C76C E5AC 12CA DFA5
http://www.enc.com.au/ csmall at : enc.com.au
http://www.debian.org/  Debian GNU/Linux, software should be Free 



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#505271: Bug#505071: login tty mis-determination (see bug#332198)

2008-12-07 Thread Nicolas François
On Mon, Dec 08, 2008 at 08:20:36AM +1100, [EMAIL PROTECTED] wrote:
 Dear Nicolas,
 
 On 23 Nov you wrote:
 
   - alert other Linux distros,
  A new upstream version was released this weekend.
 
 Have not seen any distros make announcements. What distros use that? 
 (Am surprised that even Ubuntu has not updated, though normally they
 seem responsive.)

The bug should affect ubuntu and probably gentoo (4.1.2.2 already
packaged). Not RedHat / Mandrake.
I don't know about other distros. I don't know if ubuntu supervises the
bug tagged 'security', and I don't know their milestones.

Best Regards,
-- 
Nekral



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508100: drawterm_0.cvs+20080909-1(unstable/sparc/spontini): /bin/sh: line 1: cd: posix-sparc: No such file or directory

2008-12-07 Thread Marc 'HE' Brockschmidt
Package: drawterm
Version: 0.cvs+20080909-1
Severity: serious

Heya,

Your package failed to build on my buildd:

| Automatic build of drawterm_0.cvs+20080909-1 on spontini by sbuild/sparc 99.99
| Build started at 20081206-1249
| **

[...]

| ar r libc.a charstod.o cleanname.o convD2M.o convM2D.o convM2S.o convS2M.o 
crypt.o dial.o dirfstat.o dirfwstat.o dirmodefmt.o dirstat.o dirwstat.o dofmt.o 
dorfmt.o encodefmt.o fcallfmt.o fltfmt.o fmt.o fmtfd.o fmtfdflush.o fmtlock.o 
fmtprint.o fmtquote.o fmtrune.o fmtstr.o fmtvprint.o fprint.o getfields.o 
getpid.o lock.o mallocz.o nan64.o netmkaddr.o nsec.o pow10.o pushssl.o 
pushtls.o read9pmsg.o readn.o rune.o runefmtstr.o runeseprint.o runesmprint.o 
runesnprint.o runesprint.o runestrchr.o runestrlen.o runestrstr.o runetype.o 
runevseprint.o runevsmprint.o runevsnprint.o seprint.o smprint.o snprint.o 
sprint.o strecpy.o strtod.o strtoll.o sysfatal.o time.o tokenize.o truerand.o 
u16.o u32.o u64.o utfecpy.o utflen.o utfnlen.o utfrrune.o utfrune.o utfutf.o 
vfprint.o vseprint.o vsmprint.o vsnprint.o
| ar: creating libc.a
| ranlib libc.a
| make[2]: Leaving directory `/build/buildd/drawterm-0.cvs+20080909/libc'
| arch=`uname -m|sed 's/i.86/386/;s/Power Macintosh/power/; s/x86_64/amd64/'`; \
|   (cd posix-$arch   make)
| /bin/sh: line 1: cd: posix-sparc: No such file or directory
| make[1]: *** [libmachdep.a] Error 1
| make[1]: Leaving directory `/build/buildd/drawterm-0.cvs+20080909'
| make: *** [build-stamp] Error 2
| dpkg-buildpackage: failure: debian/rules build gave error exit status 2
| **
| Build finished at 20081206-1257
| FAILED [dpkg-buildpackage died]
| Build needed 00:04:40, 9272k disk space

A complete build log can be found at
http://buildd.debian.org/build.php?arch=sparcpkg=drawtermver=0.cvs+20080909-1

Marc
-- 
BOFH #162:
bugs in the RAID



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508091: maintainer address bounces

2008-12-07 Thread Tony Mancill
Hmmm...  I think it's a transient failure - maybe something is going
with SF's MX.  I emailed Philippe earlier today at that address, and his
SF developer page is still active:

https://sourceforge.net/users/rzr

I'll give Philippe a chance to respond and either update the packages or
close the bug.

Thanks,
Tony

Thomas Viehmann wrote:
 X-Debbugs-CC: [EMAIL PROTECTED]
 Package: tuxguitar
 Version: 1.0-1
 Severity: serious
 
 Hi,
 
 unfortunately, Philippe's mail seems to bounce:
 
 [EMAIL PROTECTED]: host mx.sourceforge.net[216.34.181.68] said:
 550 unknown user (in reply to RCPT TO command)
 
 If this is transient, please feel free to close this bug, but otherwise
 it should be fixed (also for Philippe's other packages).
 I noticed because ftp-master ACCEPT mail bounced.
 
 Kind regards
 
 T.




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508101: gobject-introspection_0.6.1-1(unstable/sparc/spontini): OSError: [Errno 2] No such file or directory: '/nonexistent/.cache'

2008-12-07 Thread Marc 'HE' Brockschmidt
Package: gobject-introspection
Version: 0.6.1-1
Severity: serious

Heya,

Your package failed to build on my buildd:

| Automatic build of gobject-introspection_0.6.1-1 on spontini by sbuild/sparc 
99.99
| Build started at 20081206-1318
| **

[...]

| make[3]: Entering directory `/build/buildd/gobject-introspection-0.6.1/gir'
| env PYTHONPATH=..:..:$PYTHONPATH UNINSTALLED_INTROSPECTION_SRCDIR=.. 
UNINSTALLED_INTROSPECTION_BUILDDIR=.. ../tools/g-ir-scanner -v 
--add-include-path=../gir --add-include-path=. \
|   --namespace GLib --nsversion=2.0 \
|   --noclosure \
|   --output GLib-2.0.gir \
|   --strip-prefix=g \
|   --library=glib-2.0 \
|\
|   -I`pkg-config --variable=includedir glib-2.0`/glib-2.0 \
|   -I`pkg-config --variable=libdir glib-2.0`/glib-2.0/include \
|   -DGETTEXT_PACKAGE=Dummy \
|   -D__G_I18N_LIB_H__ \
|   `pkg-config --variable=libdir 
glib-2.0`/glib-2.0/include/glibconfig.h \
|   ./glib-2.0.c \
|   `pkg-config --variable=includedir glib-2.0`/glib-2.0/glib/*.h
| Traceback (most recent call last):
|   File ../tools/g-ir-scanner, line 324, in module
| sys.exit(main(sys.argv))
|   File ../tools/g-ir-scanner, line 272, in main
| cachestore = CacheStore()
|   File /build/buildd/gobject-introspection-0.6.1/giscanner/cachestore.py, 
line 45, in __init__
| self._directory = _get_cachedir()
|   File /build/buildd/gobject-introspection-0.6.1/giscanner/cachestore.py, 
line 30, in _get_cachedir
| os.mkdir(cachedir, 0755)
| OSError: [Errno 2] No such file or directory: '/nonexistent/.cache'
| make[3]: *** [GLib-2.0.gir] Error 1
| make[3]: Leaving directory `/build/buildd/gobject-introspection-0.6.1/gir'
| make[2]: *** [all-recursive] Error 1
| make[2]: Leaving directory `/build/buildd/gobject-introspection-0.6.1'
| make[1]: *** [all] Error 2
| make[1]: Leaving directory `/build/buildd/gobject-introspection-0.6.1'
| make: *** [debian/stamp-makefile-build] Error 2
| dpkg-buildpackage: failure: debian/rules build gave error exit status 2
| **
| Build finished at 20081206-1325
| FAILED [dpkg-buildpackage died]
| Build needed 00:03:32, 9100k disk space

A complete build log can be found at
http://buildd.debian.org/build.php?arch=sparcpkg=gobject-introspectionver=0.6.1-1

Marc
-- 
BOFH #174:
Backbone adjustment



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508104: eresi_1:0.8a25-1(unstable/sparc/schroeder): accessing `/home/buildd/.eresirc': Permission denied

2008-12-07 Thread Marc 'HE' Brockschmidt
Package: eresi
Version: 1:0.8a25-1
Severity: serious

Heya,

Your package failed to build on my buildd:

| Automatic build of eresi_1:0.8a25-1 on schroeder by sbuild/sparc 99.99
| Build started at 20081207-1833
| **

[...]

| make[2]: Leaving directory `/build/buildd/eresi-0.8a25/evarista'
| Evarista has been built successfully.
| cp: accessing `/home/buildd/.eresirc': Permission denied
| make[1]: *** [world] Error 1
| make[1]: Leaving directory `/build/buildd/eresi-0.8a25'
| make: *** [build-stamp] Error 2
| dpkg-buildpackage: failure: debian/rules build gave error exit status 2
| **
| Build finished at 20081207-1844
| FAILED [dpkg-buildpackage died]
| Build needed 00:10:42, 907084k disk space

A complete build log can be found at
http://buildd.debian.org/build.php?arch=sparcpkg=eresiver=1:0.8a25-1

Marc
-- 
Fachbegriffe der Informatik - Einfach erklärt
126: Netzcomputer
   Ein Netzcomputer ist ein Rechner, der vollständig vom Netz
   abhängig ist. (ECONY 2/99)



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508103: collectd_4.4.2-3(unstable/sparc/lebrun): /usr/lib/libupsclient.so: No such file or directory

2008-12-07 Thread Marc 'HE' Brockschmidt
Package: collectd
Version: 4.4.2-3
Severity: serious

Heya,

Your package failed to build on my buildd:

| Automatic build of collectd_4.4.2-3 on lebrun by sbuild/sparc 98
| Build started at 20081207-1620
| **

[...]

| /bin/sh ../libtool --tag=CC   --mode=link sparc-linux-gnu-gcc -Wall -Werror  
-Wall -g -O2 -module -avoid-version -lpthread -lupsclient-o nut.la -rpath 
/usr/lib/collectd nut_la-nut.lo  
| sparc-linux-gnu-gcc -shared  .libs/nut_la-nut.o  -lpthread 
/usr/lib/libupsclient.so  -Wl,-soname -Wl,nut.so -o .libs/nut.so
| sparc-linux-gnu-gcc: /usr/lib/libupsclient.so: No such file or directory
| make[4]: *** [nut.la] Error 1
| make[4]: Leaving directory `/build/buildd/collectd-4.4.2/src'
| make[3]: *** [all-recursive] Error 1
| make[3]: Leaving directory `/build/buildd/collectd-4.4.2/src'
| make[2]: *** [all] Error 2
| make[2]: Leaving directory `/build/buildd/collectd-4.4.2/src'
| make[1]: *** [all-recursive] Error 1
| make[1]: Leaving directory `/build/buildd/collectd-4.4.2'
| make: *** [build-stamp] Error 2
| dpkg-buildpackage: failure: debian/rules build gave error exit status 2
| **
| Build finished at 20081207-1626
| FAILED [dpkg-buildpackage died]
| Build needed 00:03:16, 10948k disk space

A complete build log can be found at
http://buildd.debian.org/build.php?arch=sparcpkg=collectdver=4.4.2-3

Marc
-- 
Fachbegriffe der Informatik - Einfach erklärt
41: Internet
   Das von President Gates erfundene Computernetz. (Kristian Köhntopp)



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#505271: Bug#505071: login tty mis-determination (see bug#332198)

2008-12-07 Thread Paul Szabo
 The bug should affect ubuntu and probably gentoo (4.1.2.2 already
 packaged). Not RedHat / Mandrake.

A quick peek into shadow-utils-4.1.2-8.fc10.src.rpm suggests Fedora is
also affected. I do not know about RHEL.

Ubuntu now notified directly:
https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/306082

Cheers, Paul

Paul Szabo   [EMAIL PROTECTED]   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of SydneyAustralia



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508103: collectd_4.4.2-3(unstable/sparc/lebrun): /usr/lib/libupsclient.so: No such file or directory

2008-12-07 Thread Cyril Brulebois
Marc 'HE' Brockschmidt [EMAIL PROTECTED] (07/12/2008):
 Package: collectd
 Version: 4.4.2-3
 Severity: serious
 
 Your package failed to build on my buildd:
 
 | Automatic build of collectd_4.4.2-3 on lebrun by sbuild/sparc 98
 | Build started at 20081207-1620

Heya Marc,

handholding needed on this arch, as discussed on -release@ already:
[EMAIL PROTECTED]

Since it is:
| sparc 2.2.2-10Installed   Uploaded2008 Dec 07 22:48:30
buildd_sparc-spontini

(See #505101 for the FTBFS that nut's libupsclient-dev is/was causing,
-8 was used for that build attempt.)

I guess a give back would be sufficient? I'll leave it up to you to
close the bug once that done.

Mraw,
KiBi.


signature.asc
Description: Digital signature


Processed: tagging 506961

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 tags 506961 pending
Bug#506961: auctex: reuses old logfile on emacsen upgrades, enabling symlink 
attack
Tags were: pending security
Tags added: pending


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Processed: forcibly merging 508032 503532

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 # this bug has been filed, but how severity is confirmed by upstream, it seems
 forcemerge 508032 503532
Bug#508032: CVE-2008-4311 vulnerability
Bug#503532: send_requested_reply=true allows all non-reply messages
Forcibly Merged 503532 508032.


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508111: devscripts: Insecure tempfile creation (redux).

2008-12-07 Thread Cyril Brulebois
Package: devscripts
Version: 2.10.41
Severity: serious
Tags: patch security
Justification: Vulnerable to symlink attacks (unless I'm mistaken).

Hi,

mktemp(1) says it all:
,--
| The trailing ‘Xs’ are replaced with a combination of  the  cur‐
| rent  process  number  and  random  letters.   The  name chosen
| depends both on the number of ‘Xs’ in the template and the num‐
| ber  of  collisions  with  pre-existing  files.   The number of
| unique filenames mktemp can return depends  on  the  number  of
| ‘Xs’  provided;  ten ‘Xs’ will result in mktemp testing roughly
| 26 ** 10 combinations.
`--

but your usage of mktemp is bogus, since .$2 is appended to the X's. The
attached patch fixes this (I used local set -x/+x to check the filenames).

I only happened to discover this bug after signing was aborted (I wanted to
have an extra look at a package, so I hit “cancel” in pinentry), and when
running debsign the 2nd time on the very same package, nothing was happening.
strace'ing pointed to the same file being tried again and again, with all X's,
since that file didn't go away after the aborted signing step.

Since the filename is predictable, I guess debsign is vulnerable to symlink
attacks and the like (although I'm no security crack, etc., sorry if I'm
overthinking the consequences of this bug).

Mraw,
KiBi.

-- Package-specific info:

--- /etc/devscripts.conf ---

--- ~/.devscripts ---
export BTS_MAIL_READER='mutt -F ~/mail/SOMEFILEYOUDONTHAVETOKNOWABOUT.rc -f %s'

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.28-rc6-kibi-00189-g15d1ff2 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages devscripts depends on:
ii  dpkg-dev  1.14.23Debian package development tools
ii  libc6 2.7-16 GNU C Library: Shared libraries
ii  perl  5.10.0-18  Larry Wall's Practical Extraction

Versions of packages devscripts recommends:
ii  at 3.1.10.2  Delayed job execution and batch pr
ii  bsd-mailx [mailx]  8.1.2-0.20081101cvs-2 A simple mail user agent
ii  bzr1.5-1.1   easy to use distributed version co
ii  curl   7.18.2-7  Get a file from an HTTP, HTTPS or
ii  cvs1:1.12.13-12  Concurrent Versions System
ii  dctrl-tools2.13.0Command-line tools to process Debi
ii  debian-keyring 2008.11.30GnuPG (and obsolete PGP) keys of D
ii  debian-maintainers 1.49  GPG keys of Debian maintainers
ii  dput   0.9.2.36  Debian package upload tool
ii  epiphany-gecko [ww 2.22.3-8+b1   Intuitive GNOME web browser - Geck
ii  equivs 2.0.7-0.1 Circumvent Debian package dependen
ii  fakeroot   1.11  Gives a fake root environment
ii  git-core   1:1.5.6.5-1   fast, scalable, distributed revisi
ii  gnupg  1.4.9-3   GNU privacy guard - a free PGP rep
ii  konqueror [www-bro 4:3.5.9.dfsg.1-5  KDE's advanced file manager, web b
ii  libauthen-sasl-per 2.12-1Authen::SASL - SASL Authentication
ii  libcrypt-ssleay-pe 0.57-1+b1 Support for https protocol in LWP
ii  libparse-debcontro 2.005-2   Easy OO parsing of Debian control-
ii  libsoap-lite-perl  0.710.08-1Client and server side SOAP implem
ii  libterm-size-perl  0.2-4+b1  Perl extension for retrieving term
ii  libtimedate-perl   1.1600-9  Time and date functions for Perl
ii  liburi-perl1.35.dfsg.1-1 Manipulates and accesses URI strin
ii  libwww-perl5.820-1   WWW client/server library for Perl
ii  libyaml-syck-perl  1.05-1Fast, lightweight YAML loader and
ii  links [www-browser 2.2-1 Web browser running in text mode
ii  lintian2.1.0 Debian package checker
ii  lsb-release3.2-20Linux Standard Base version report
ii  man-db 2.5.2-3   on-line manual pager
ii  mercurial  1.0.1-5.1 Scalable distributed version contr
ii  openssh-client [ss 1:5.1p1-4 secure shell client, an rlogin/rsh
ii  patch  2.5.9-5   Apply a diff file to an original
ii  patchutils 0.2.31-4  Utilities to work with patches
ii  strace 4.5.17+cvs080723-2A system call tracer
ii  subversion 1.5.1dfsg1-1  Advanced version control system
ii  unzip  5.52-12   De-archiver for .zip files
ii  w3m [www-browser]  0.5.2-2+b1WWW browsable pager with excellent
ii  wdiff  0.5-18Compares two files word by word
ii  wget   

Bug#508114: fails to build on alpha

2008-12-07 Thread Sune Vuorela
Package: jack-audio-connection-kit
Version: 0.115.6-1
Severity: serious

Hi!

Apparantly, your package failst to build from source on alpha.
See http://buildd.debian.org/fetch.cgi?pkg=jack-audio-connection-
kit;ver=0.115.6-1;arch=alpha;stamp=1228082671 for full details

/usr/bin/make -C . 
make[1]: Entering directory `/build/buildd/jack-audio-connection-kit-0.115.6'
/usr/bin/make  all-recursive
make[2]: Entering directory `/build/buildd/jack-audio-connection-kit-0.115.6'
Making all in jack
make[3]: Entering directory `/build/buildd/jack-audio-connection-
kit-0.115.6/jack'
make[3]: Nothing to be done for `all'.
make[3]: Leaving directory `/build/buildd/jack-audio-connection-
kit-0.115.6/jack'
Making all in libjack
make[3]: Entering directory `/build/buildd/jack-audio-connection-
kit-0.115.6/libjack'
/bin/sh ../libtool --tag=CC   --mode=compile cc -DHAVE_CONFIG_H -I. -I..-
I../config -I.. -I.. -D_REENTRANT -D_POSIX_PTHREAD_SEMANTICS -Wall -g -O2 -g -
Wall -O2 -DJACK_LOCATION=\/usr/bin\ -I../config -I.. -I.. -D_REENTRANT -
D_POSIX_PTHREAD_SEMANTICS -Wall -g -O2 -g -Wall -O2 -c -o libjack_la-client.lo 
`test -f 'client.c' || echo './'`client.c
mkdir .libs
 cc -DHAVE_CONFIG_H -I. -I.. -I../config -I.. -I.. -D_REENTRANT -
D_POSIX_PTHREAD_SEMANTICS -Wall -g -O2 -g -Wall -O2 -
DJACK_LOCATION=\/usr/bin\ -I../config -I.. -I.. -D_REENTRANT -
D_POSIX_PTHREAD_SEMANTICS -Wall -g -O2 -g -Wall -O2 -c client.c  -fPIC -DPIC -
o .libs/libjack_la-client.o
In file included from ../config/sysdeps/atomicity.h:20,
 from ../jack/internal.h:73,
 from client.c:40:
../config/cpu/generic/atomicity.h:23:2: warning: #warning stub atomicity 
functions are not atomic on this platform
In file included from ../config/sysdeps/cycles.h:24,
 from client.c:58:
../config/cpu/generic/cycles.h:25:2: warning: #warning You are compiling JACK 
on a platform for which jack/config/sysdep/cycles.h needs work
client.c: In function 'jack_client_open_aux':
client.c:972: error: used struct type value where scalar is required
client.c: In function 'jack_client_new':
client.c:1120: error: incompatible type for argument 4 of 
'jack_client_open_aux'
make[3]: *** [libjack_la-client.lo] Error 1
make[3]: Leaving directory `/build/buildd/jack-audio-connection-
kit-0.115.6/libjack'
make[2]: *** [all-recursive] Error 1
make[2]: Leaving directory `/build/buildd/jack-audio-connection-kit-0.115.6'
make[1]: *** [all] Error 2
make[1]: Leaving directory `/build/buildd/jack-audio-connection-kit-0.115.6'
make: *** [debian/stamp-makefile-build] Error 2
dpkg-buildpackage: failure: debian/rules build gave error exit status 2
*

And please do *not* upload packages with shlib bumps to unstable in periods 
when lenny is frozen in the future.

/Sune
-- 
Genius, I'm not able to install on the floppy disk of a server from Windows 98, 
how does it work?

From the control options inside ICQ you can't debug the driver to remove from 
a space bar on the computer.




--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#505271: Bug#505071: login tty mis-determination (see bug#332198)

2008-12-07 Thread Paul Szabo
I wrote a little while ago:

 A quick peek into shadow-utils-4.1.2-8.fc10.src.rpm suggests Fedora is
 also affected. I do not know about RHEL.

A quick peek into shadow-utils-4.0.17-14.el5.src.rpm suggests RHEL is
just as bad.

Cheers, Paul

Paul Szabo   [EMAIL PROTECTED]   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of SydneyAustralia



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#490171: Bug#470416: rtorrent: random crash (grave)

2008-12-07 Thread Jose Luis Rivas
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Jari Aalto wrote:
 Jose Luis Rivas [EMAIL PROTECTED] writes:
 
 Jari Aalto wrote:

 Confirmed.

 There seesm to be more a serious problem. Not just the rtorrent crash, but
 the whole workstation dies: kernel becomes unresponsive to the point
 where nothing happens.
 Can you please try with experimental release? I'm not in position to
 make this test (starting by my lack of bandwith and lack of hardware,
 I'm not always online in my machine).

 I'm about to push experimental to unstable and this one would make
 another good reason to do this. (Besides of #506748)
 
 Same results with 0.8.4-1. Kernel completely freezes after a while.
 
 Jari
I just noted something, I've got system freezing too with 2.6.26 (and
only with this kernel) but without using rtorrent.

Please, could you try with another kernel? (I'm right now using 2.6.27
and haven't got any freeze) Just for checking

Regards.
- --
Jose Luis Rivas. San Cristóbal, Venezuela. GPG 0xCACAB118
http://ghostbar.ath.cx/about - http://debian.org.ve
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAkk8jVYACgkQOKCtW8rKsRi2mQCfVbPlpPm7tvouomOKyvVbOJP2
rfQAn3yqgB9aJZOF74au8JCCrOtXkYuP
=1/D5
-END PGP SIGNATURE-



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#504894: marked as done (CVE-2008-5028: Nagios cmd.cgi cross-site request forgery)

2008-12-07 Thread Debian Bug Tracking System

Your message dated Mon, 08 Dec 2008 03:02:06 +
with message-id [EMAIL PROTECTED]
and subject line Bug#504894: fixed in nagios3 3.0.6-1
has caused the Debian Bug report #504894,
regarding CVE-2008-5028: Nagios cmd.cgi cross-site request forgery
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
504894: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=504894
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: nagios3
Severity: grave
Tags: security patch

Hi,

The following SA (Secunia Advisory) id was published for Nagios.

SA32610[1]:
 Andreas Ericsson has discovered a vulnerability in Nagios, which can be
 exploited by malicious people to conduct cross-site request forgery
 attacks.

 The application allows users to perform certain actions via HTTP requests
 to cmd.cgi without performing any validity checks to verify the request.
 This can be exploited to execute certain Nagios commands (e.g. to disable
 notifications) when a logged-in administrator visits a malicious web site.

 The vulnerability is confirmed in version 3.0.5. Other versions may also be
 affected.

A proposed patch is available at [2].

If you fix the vulnerability please also make sure to include the SA id (or 
the CVE id when one is assigned) in the changelog entry.

[1]http://secunia.com/Advisories/32610/
[2]http://git.op5.org/git/?p=nagios.git;a=commit;h=814d8d4d1a73f7151eeed187c0667585d79fea18

Cheers,
-- 
Raphael Geissert - Debian Maintainer
www.debian.org - get.debian.net


signature.asc
Description: This is a digitally signed message part.
---End Message---
---BeginMessage---
Source: nagios3
Source-Version: 3.0.6-1

We believe that the bug you reported is fixed in the latest version of
nagios3, which is due to be installed in the Debian FTP archive:

nagios3-common_3.0.6-1_all.deb
  to pool/main/n/nagios3/nagios3-common_3.0.6-1_all.deb
nagios3-dbg_3.0.6-1_amd64.deb
  to pool/main/n/nagios3/nagios3-dbg_3.0.6-1_amd64.deb
nagios3-doc_3.0.6-1_all.deb
  to pool/main/n/nagios3/nagios3-doc_3.0.6-1_all.deb
nagios3_3.0.6-1.diff.gz
  to pool/main/n/nagios3/nagios3_3.0.6-1.diff.gz
nagios3_3.0.6-1.dsc
  to pool/main/n/nagios3/nagios3_3.0.6-1.dsc
nagios3_3.0.6-1_amd64.deb
  to pool/main/n/nagios3/nagios3_3.0.6-1_amd64.deb
nagios3_3.0.6.orig.tar.gz
  to pool/main/n/nagios3/nagios3_3.0.6.orig.tar.gz



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alexander Wirt [EMAIL PROTECTED] (supplier of updated nagios3 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Format: 1.8
Date: Mon, 08 Dec 2008 02:51:21 +0100
Source: nagios3
Binary: nagios3-common nagios3 nagios3-doc nagios3-dbg
Architecture: source amd64 all
Version: 3.0.6-1
Distribution: unstable
Urgency: high
Maintainer: Debian Nagios Maintainer Group [EMAIL PROTECTED]
Changed-By: Alexander Wirt [EMAIL PROTECTED]
Description: 
 nagios3- A host/service/network monitoring and management system
 nagios3-common - support files for nagios3
 nagios3-dbg - debugging symbols and debug stuff for nagios3
 nagios3-doc - documentation for nagios3
Closes: 504894 505813 506851
Changes: 
 nagios3 (3.0.6-1) unstable; urgency=high
 .
   * New upstream version
 - Even more fixes for CVE-2008-5028
   * Urgency high for security fixes
   * Add ${shlibs:Depends} (Fixes lintian error, as the epn debugger
 should depend on libc)
   * Add ${misc:Depends} to binaries (Fixes lintian warning)
 .
 nagios3 (3.0.5-1) unstable; urgency=low
 .
   [ Christian Perrier ]
   * Fix pending l10n issues. Debconf translations:
 - Italian. Closes: #505813
 - Polish. Closes: #506851
 .
   [ Alexander Wirt ]
   * New upstream version
 - Adds security fix for cmd.cgi (Closes: #504894)
   This security problem is referenced as CVE-2008-5028 and SA32610
Checksums-Sha1: 
 18343fd554c78bc585be812992e67e24336b1fd0 1533 nagios3_3.0.6-1.dsc
 d6bd20cdc22d2b931f9ad7f9cb33ff71d2cb7d71 2735504 nagios3_3.0.6.orig.tar.gz
 2ecf33611e067b819f5d30bcfaf7b42c934d9105 37133 nagios3_3.0.6-1.diff.gz
 1ab06afa4f4e601f2c89c711ca840cd7e2d32e3d 1532000 nagios3_3.0.6-1_amd64.deb
 404c2055d55aaa4cb8ff71b2932df2a0889ed081 2537396 nagios3-dbg_3.0.6-1_amd64.deb
 

Bug#374644: xine-ui: ctrl/shift key press emulation implementation broken

2008-12-07 Thread Ben Hutchings
On Wed, 2008-11-26 at 04:13 +, Ben Hutchings wrote:
 There's an easy way to fix this:
 
 --- xine-ui-0.99.5+cvs20070914.orig/src/xitk/videowin.c
 +++ xine-ui-0.99.5+cvs20070914/src/xitk/videowin.c
 @@ -2275,6 +2275,7 @@
  
if(gGui-ssaver_enabled  (xitk_get_last_keypressed_time() = (long int) 
 gGui-ssaver_timeout)) {
  
 +#if 0
  #ifdef HAVE_XTESTEXTENSION
  if(gVw-have_xtest == True) {

 @@ -2291,6 +2292,7 @@
  }
  else 
  #endif
 +#endif
  {
/* Reset the gnome screensaver. Look up the command in PATH only once 
 to save time, */
/* assuming its location and permission will not change during run 
 time of xine-ui. */
 --- END ---
 
 but then the feature only works for GNOME users.
 
 Alternately, we can delegate the hackery to xdg-screensaver, which
 supports the X server screensaver, xscreensaver, GNOME and KDE:

I've made a few important fixes to avoid zombie processes (an existing
bug) and file descriptor leakage.  The new version of this patch is
below.

Unfortunately when I gave this code some serious testing I found a race
condition in xdg-screensaver that can leave child processes hanging
around if the user toggles between pause and play rapidly.  There also
seems to be a bug in xprop, which it relies on, that means the
screensaver might not be resumed when we quit.  So I can't recommend
this fix at the moment.

Ben.

diff -u xine-ui-0.99.5+cvs20070914/debian/control 
xine-ui-0.99.5+cvs20070914/debian/control
--- xine-ui-0.99.5+cvs20070914/debian/control
+++ xine-ui-0.99.5+cvs20070914/debian/control
@@ -17,6 +17,7 @@
 Package: xine-ui
 Architecture: any
 Depends: ${shlibs:Depends}, libxine1-ffmpeg, libxine1-x | libxine1 ( 1.1.8-2)
+Recommends: xdg-utils
 Description: the xine video player, user interface
  This is an X11 based GUI for the libxine video player library.
  It provides xine, a skin based media player that can play all the
only in patch2:
unchanged:
--- xine-ui-0.99.5+cvs20070914.orig/src/xitk/common.h
+++ xine-ui-0.99.5+cvs20070914/src/xitk/common.h
@@ -332,7 +332,6 @@
   const char   *snapshot_location;
   
   int   ssaver_enabled;
-  int   ssaver_timeout;
 
   int   skip_by_chapter;
 
only in patch2:
unchanged:
--- xine-ui-0.99.5+cvs20070914.orig/src/xitk/main.c
+++ xine-ui-0.99.5+cvs20070914/src/xitk/main.c
@@ -1385,6 +1385,8 @@
   if (sigprocmask (SIG_BLOCK,  vo_mask, NULL))
 fprintf (stderr, sigprocmask() failed.\n);
 
+  signal(SIGCHLD, SIG_IGN);
+
   gGui = (gGui_t *) xine_xmalloc(sizeof(gGui_t));
   
   gGui-stream = NULL;
only in patch2:
unchanged:
--- xine-ui-0.99.5+cvs20070914.orig/src/xitk/panel.c
+++ xine-ui-0.99.5+cvs20070914/src/xitk/panel.c
@@ -363,7 +363,6 @@
  * Update slider thread.
  */
 static void *slider_loop(void *dummy) {
-  int screensaver_timer = 0;
   int status, speed;
   int pos, secs;
   int i = 0;
@@ -450,20 +449,7 @@
else
  video_window_set_mrl((char *)gGui-mmk.mrl);

-   if(!xitk_is_window_iconified(gGui-video_display, gGui-video_window)) {
- 
- if(gGui-ssaver_timeout) {
-   
-   if(!(i % 2))
- screensaver_timer++;
-   
-   if(screensaver_timer = gGui-ssaver_timeout) {
- screensaver_timer = 0;
- video_window_reset_ssaver();
- 
-   }
- }  
-   }
+   
video_window_suspend_ssaver(!xitk_is_window_iconified(gGui-video_display, 
gGui-video_window));
 
if(gGui-logo_mode == 0) {
  
@@ -503,6 +489,8 @@
stream_infos_update_infos();
 
}
+  } else {
+   video_window_suspend_ssaver(0);
   }
 }
 
only in patch2:
unchanged:
--- xine-ui-0.99.5+cvs20070914.orig/src/xitk/videowin.c
+++ xine-ui-0.99.5+cvs20070914/src/xitk/videowin.c
@@ -1095,6 +1095,9 @@
 
   /* The old window should be destroyed now */
   if(old_video_window != None) {
+/* Screensaver control is tied to our window id */
+video_window_suspend_ssaver(0);
+
 XDestroyWindow(gGui-video_display, old_video_window);
  
 if(gGui-cursor_grabbed)
@@ -2271,68 +2274,34 @@
 
 }
 
-void video_window_reset_ssaver(void) {
+void video_window_suspend_ssaver(int do_suspend) {
+  static int was_suspended;
 
-  if(gGui-ssaver_enabled  (xitk_get_last_keypressed_time() = (long int) 
gGui-ssaver_timeout)) {
+  do_suspend = do_suspend  gGui-ssaver_enabled;
 
-#ifdef HAVE_XTESTEXTENSION
-if(gVw-have_xtest == True) {
-  
-  gVw-fake_key_cur++;
-  
-  if(gVw-fake_key_cur = 2)
-   gVw-fake_key_cur = 0;
-
-  XLockDisplay(gGui-video_display);
-  XTestFakeKeyEvent(gGui-video_display, 
gVw-fake_keys[gVw-fake_key_cur], True, CurrentTime);
-  XTestFakeKeyEvent(gGui-video_display, 
gVw-fake_keys[gVw-fake_key_cur], False, CurrentTime);
-  XSync(gGui-video_display, False);
-  XUnlockDisplay(gGui-video_display);
+  if(was_suspended != 

Bug#506684: NMU diff for guile-1.8 1.8.5+1-4.1

2008-12-07 Thread Ben Hutchings
I uploaded the following changes to delayed/3.

Ben.

diff -u guile-1.8-1.8.5+1/debian/changelog guile-1.8-1.8.5+1/debian/changelog
--- guile-1.8-1.8.5+1/debian/changelog
+++ guile-1.8-1.8.5+1/debian/changelog
@@ -1,3 +1,12 @@
+guile-1.8 (1.8.5+1-4.1) unstable; urgency=low
+
+  * Non-maintainer upload.
+  * Add dont-redefine-jmp_buf.diff: adds 'scm_' prefix to jmp_buf
+replacements so they don't affect clients with their own uses for
+jmp_buf.  (closes: #506684)
+
+ -- Ben Hutchings [EMAIL PROTECTED]  Mon, 08 Dec 2008 04:15:25 +
+
 guile-1.8 (1.8.5+1-4) unstable; urgency=medium
 
   * Change Architectures back to any where appropriate (i.e. include
diff -u guile-1.8-1.8.5+1/debian/patches/series 
guile-1.8-1.8.5+1/debian/patches/series
--- guile-1.8-1.8.5+1/debian/patches/series
+++ guile-1.8-1.8.5+1/debian/patches/series
@@ -8,2 +8,3 @@
 fix-ia64-continuations.diff
+dont-redefine-jmp_buf.diff
 autofiles.diff
only in patch2:
unchanged:
--- guile-1.8-1.8.5+1.orig/debian/patches/dont-redefine-jmp_buf.diff
+++ guile-1.8-1.8.5+1/debian/patches/dont-redefine-jmp_buf.diff
@@ -0,0 +1,97 @@
+--- guile-1.8-1.8.5+1.orig/libguile/__scm.h
 guile-1.8-1.8.5+1/libguile/__scm.h
+@@ -386,21 +386,23 @@
+ 
+ #ifdef vms
+ # ifndef CHEAP_CONTINUATIONS
+-   typedef int jmp_buf[17];
+-   extern int setjump(jmp_buf env);
+-   extern int longjump(jmp_buf env, int ret);
+-#  define setjmp setjump
+-#  define longjmp longjump
++   typedef int scm_jmp_buf[17];
++   extern int setjump(scm_jmp_buf env);
++   extern int longjump(scm_jmp_buf env, int ret);
++#  define scm_setjmp setjump
++#  define scm_longjmp longjump
++#  define SCM_DEFINES_JMP_BUF
+ # else
+ #  include setjmp.h
+ # endif
+ #else /* ndef vms */
+ # ifdef _CRAY1
+-typedef int jmp_buf[112];
+-extern int setjump(jmp_buf env);
+-extern int longjump(jmp_buf env, int ret);
+-#  define setjmp setjump
+-#  define longjmp longjump
++typedef int scm_jmp_buf[112];
++extern int setjump(scm_jmp_buf env);
++extern int longjump(scm_jmp_buf env, int ret);
++#  define scm_setjmp setjump
++#  define scm_longjmp longjump
++#  define SCM_DEFINES_JMP_BUF
+ # else/* ndef _CRAY1 */
+ #  if defined (__ia64__)
+ /* For IA64, emulate the setjmp API using getcontext. */
+@@ -409,15 +411,19 @@
+ typedef struct {
+   ucontext_t ctx;
+   int fresh;
+-} jmp_buf;
+-#   define setjmp(JB) \
++} scm_jmp_buf;
++#   define scm_setjmp(JB) \
+   ( (JB).fresh = 1,   \
+ getcontext (((JB).ctx)), \
+ ((JB).fresh ? ((JB).fresh = 0, 0) : 1) )
+-#   define longjmp(JB,VAL) scm_ia64_longjmp ((JB), VAL)
+-void scm_ia64_longjmp (jmp_buf *, int);
++#   define scm_longjmp(JB,VAL) scm_ia64_longjmp ((JB), VAL)
++void scm_ia64_longjmp (scm_jmp_buf *, int);
++#   define SCM_DEFINES_JMP_BUF
+ #  else   /* ndef __ia64__ */
+ #   include setjmp.h
++typedef jmp_buf scm_jmp_buf;
++#   define scm_setjmp setjmp
++#   define scm_longjmp longjmp
+ #  endif  /* ndef __ia64__ */
+ # endif   /* ndef _CRAY1 */
+ #endif/* ndef vms */
+--- guile-1.8-1.8.5+1.orig/libguile/_scm.h
 guile-1.8-1.8.5+1/libguile/_scm.h
+@@ -41,6 +41,12 @@
+ #include errno.h
+ #include libguile/__scm.h
+ 
++#ifdef SCM_DEFINES_JMP_BUF
++typedef scm_jmp_buf jmp_buf;
++#define setjmp(JB) scm_setjmp(JB)
++#define longjmp(JB,VAL) scm_longjmp(JB,VAL)
++#endif
++
+ /* Include headers for those files central to the implementation.  The
+rest should be explicitly #included in the C files themselves.  */
+ #include libguile/error.h   /* Everyone signals errors.  */
+--- guile-1.8-1.8.5+1.orig/libguile/continuations.h
 guile-1.8-1.8.5+1/libguile/continuations.h
+@@ -43,7 +43,7 @@
+ typedef struct 
+ {
+   SCM throw_value;
+-  jmp_buf jmpbuf;
++  scm_jmp_buf jmpbuf;
+   SCM dynenv;
+ #ifdef __ia64__
+   void *backing_store;
+--- guile-1.8-1.8.5+1.orig/libguile/threads.h
 guile-1.8-1.8.5+1/libguile/threads.h
+@@ -107,7 +107,7 @@
+   /* For keeping track of the stack and registers. */
+   SCM_STACKITEM *base;
+   SCM_STACKITEM *top;
+-  jmp_buf regs;
++  scm_jmp_buf regs;
+ #ifdef __ia64__
+   void *register_backing_store_base;
+   scm_t_contregs *pending_rbs_continuation;
--- END ---

-- 
Ben Hutchings
All extremists should be taken out and shot.


signature.asc
Description: This is a digitally signed message part


Processed: user devscri...@packages.debian.org, usertagging 508111 ...

2008-12-07 Thread Debian Bug Tracking System
Processing commands for [EMAIL PROTECTED]:

 user [EMAIL PROTECTED]
Setting user to [EMAIL PROTECTED] (was [EMAIL PROTECTED]).
 usertags 508111 debsign
Bug#508111: devscripts: Insecure tempfile creation (redux).
There were no usertags set.
Usertags are now: debsign.
 retitle 508111 [debsign] Insecure tempfile creation (redux)
Bug#508111: devscripts: Insecure tempfile creation (redux).
Changed Bug title to `[debsign] Insecure tempfile creation (redux)' from 
`devscripts: Insecure tempfile creation (redux).'.


End of message, stopping processing here.

Please contact me if you need assistance.

Debian bug tracking system administrator
(administrator, Debian Bugs database)


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508111: devscripts: Insecure tempfile creation (redux).

2008-12-07 Thread Adam D. Barratt
On Mon, 2008-12-08 at 01:31 +0100, Cyril Brulebois wrote:
 Package: devscripts
 Version: 2.10.41
 Severity: serious
 Tags: patch security
 Justification: Vulnerable to symlink attacks (unless I'm mistaken).
[...]
 but your usage of mktemp is bogus, since .$2 is appended to the X's. The
 attached patch fixes this (I used local set -x/+x to check the filenames).

Ugh. One possibly mitigating factor is that the broken call is only used
if the caller can't write to the directory containing the package,
although that will be the case in e.g. default pbuilder setups.

Fixed, thanks; will upload shortly.

[...]
 Since the filename is predictable, I guess debsign is vulnerable to symlink
 attacks and the like (although I'm no security crack, etc., sorry if I'm
 overthinking the consequences of this bug).

I'm not 100% sure myself, to be honest. Security team?

This particular mktemp call was introduced in devscripts 2.10.31, which
means it exists in lenny (as do the issues raised in #507482, although
that's currently marked important).

Regards,

Adam



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#508132: disks-admin : crash

2008-12-07 Thread Damien Courousse

Distribution: Debian 4.0
Package: gnome-system-tools
Severity: critical
Version: GNOME2.14.3 unspecified
Gnome-Distributor: Debian
Synopsis: disks-admin : crash
Bugzilla-Product: gnome-system-tools
Bugzilla-Component: general
Bugzilla-Version: unspecified
BugBuddy-GnomeVersion: 2.0 (2.14.1)


Description:
Description of the crash:

This happens on a powerpc laptop (iBook 12 G4), with Debian Etch PPC.

In the disks-admin window (Disks manager), I have two hard disks
displayed on the left column; whereas my laptop has only one.
The first Hard Drive is OK and is entitled correctly according to my 
hardware.

However, there shouldn't be a second HD displayed.

The crash happens when I try to select the second HD displayed;

Steps to reproduce the crash:
1. Open the Disks Manager tool
2. Entering the root passwd
3. Selecting the second Hard Drive displayed

Expected Results:
Crash of the application


How often does this happen?
always; the crash is reproducible

Additional Information:



Debugging Information:

Backtrace was generated from '/usr/bin/disks-admin'

(no debugging symbols found)
Using host libthread_db library /lib/libthread_db.so.1.
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
[Thread debugging using libthread_db enabled]
[New Thread 805547200 (LWP 5079)]
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
0x0ea01254 in __waitpid_nocancel () from /lib/libpthread.so.0
#0  0x0ea01254 in __waitpid_nocancel () from /lib/libpthread.so.0
#1  0x0ffa2728 in gnome_gtk_module_info_get () from
/usr/lib/libgnomeui-2.so.0
#2  signal handler called
#3  0x0e958c44 in g_list_first () from /usr/lib/libglib-2.0.so.0
#4  0x100089f4 in ?? ()
#5  0x100061ac in ?? ()
#6  0x1000670c in ?? ()
#7  0x100109a8 in ?? ()
#8  0x10008e48 in ?? ()
#9  0x10007eec in ?? ()
#10 0x100124f8 in ?? ()
#11 0x0eb83150 in g_cclosure_marshal_VOID__VOID ()
  from /usr/lib/libgobject-2.0.so.0
#12 0x0eb7235c in g_closure_invoke () from /usr/lib/libgobject-2.0.so.0
#13 0x0eb869e4 in g_signal_chain_from_overridden ()
  from /usr/lib/libgobject-2.0.so.0
#14 0x0eb87cec in g_signal_emit_valist () from
/usr/lib/libgobject-2.0.so.0
#15 0x0eb87ebc in g_signal_emit () from /usr/lib/libgobject-2.0.so.0
#16 0x0f67b998 in _gtk_tree_selection_internal_select_node ()
  from /usr/lib/libgtk-x11-2.0.so.0
#17 0x0f68f5c8 in gtk_tree_view_scroll_to_cell ()
  from /usr/lib/libgtk-x11-2.0.so.0
#18 0x0f69d484 in _gtk_tree_view_column_autosize ()
  from /usr/lib/libgtk-x11-2.0.so.0
#19 0x0f5975b8 in _gtk_marshal_BOOLEAN__BOXED ()
  from /usr/lib/libgtk-x11-2.0.so.0
#20 0x0eb7057c in g_value_set_boxed () from
/usr/lib/libgobject-2.0.so.0
#21 0x0eb7235c in g_closure_invoke () from /usr/lib/libgobject-2.0.so.0
#22 0x0eb86b30 in g_signal_chain_from_overridden ()
  from /usr/lib/libgobject-2.0.so.0
#23 0x0eb87a7c in g_signal_emit_valist () from
/usr/lib/libgobject-2.0.so.0
#24 0x0eb87ebc in 

Bug#508111: marked as done ([debsign] Insecure tempfile creation (redux))

2008-12-07 Thread Debian Bug Tracking System

Your message dated Mon, 08 Dec 2008 06:47:09 +
with message-id [EMAIL PROTECTED]
and subject line Bug#508111: fixed in devscripts 2.10.43
has caused the Debian Bug report #508111,
regarding [debsign] Insecure tempfile creation (redux)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
508111: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=508111
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
---BeginMessage---
Package: devscripts
Version: 2.10.41
Severity: serious
Tags: patch security
Justification: Vulnerable to symlink attacks (unless I'm mistaken).

Hi,

mktemp(1) says it all:
,--
| The trailing ‘Xs’ are replaced with a combination of  the  cur‐
| rent  process  number  and  random  letters.   The  name chosen
| depends both on the number of ‘Xs’ in the template and the num‐
| ber  of  collisions  with  pre-existing  files.   The number of
| unique filenames mktemp can return depends  on  the  number  of
| ‘Xs’  provided;  ten ‘Xs’ will result in mktemp testing roughly
| 26 ** 10 combinations.
`--

but your usage of mktemp is bogus, since .$2 is appended to the X's. The
attached patch fixes this (I used local set -x/+x to check the filenames).

I only happened to discover this bug after signing was aborted (I wanted to
have an extra look at a package, so I hit “cancel” in pinentry), and when
running debsign the 2nd time on the very same package, nothing was happening.
strace'ing pointed to the same file being tried again and again, with all X's,
since that file didn't go away after the aborted signing step.

Since the filename is predictable, I guess debsign is vulnerable to symlink
attacks and the like (although I'm no security crack, etc., sorry if I'm
overthinking the consequences of this bug).

Mraw,
KiBi.

-- Package-specific info:

--- /etc/devscripts.conf ---

--- ~/.devscripts ---
export BTS_MAIL_READER='mutt -F ~/mail/SOMEFILEYOUDONTHAVETOKNOWABOUT.rc -f %s'

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.28-rc6-kibi-00189-g15d1ff2 (SMP w/2 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages devscripts depends on:
ii  dpkg-dev  1.14.23Debian package development tools
ii  libc6 2.7-16 GNU C Library: Shared libraries
ii  perl  5.10.0-18  Larry Wall's Practical Extraction

Versions of packages devscripts recommends:
ii  at 3.1.10.2  Delayed job execution and batch pr
ii  bsd-mailx [mailx]  8.1.2-0.20081101cvs-2 A simple mail user agent
ii  bzr1.5-1.1   easy to use distributed version co
ii  curl   7.18.2-7  Get a file from an HTTP, HTTPS or
ii  cvs1:1.12.13-12  Concurrent Versions System
ii  dctrl-tools2.13.0Command-line tools to process Debi
ii  debian-keyring 2008.11.30GnuPG (and obsolete PGP) keys of D
ii  debian-maintainers 1.49  GPG keys of Debian maintainers
ii  dput   0.9.2.36  Debian package upload tool
ii  epiphany-gecko [ww 2.22.3-8+b1   Intuitive GNOME web browser - Geck
ii  equivs 2.0.7-0.1 Circumvent Debian package dependen
ii  fakeroot   1.11  Gives a fake root environment
ii  git-core   1:1.5.6.5-1   fast, scalable, distributed revisi
ii  gnupg  1.4.9-3   GNU privacy guard - a free PGP rep
ii  konqueror [www-bro 4:3.5.9.dfsg.1-5  KDE's advanced file manager, web b
ii  libauthen-sasl-per 2.12-1Authen::SASL - SASL Authentication
ii  libcrypt-ssleay-pe 0.57-1+b1 Support for https protocol in LWP
ii  libparse-debcontro 2.005-2   Easy OO parsing of Debian control-
ii  libsoap-lite-perl  0.710.08-1Client and server side SOAP implem
ii  libterm-size-perl  0.2-4+b1  Perl extension for retrieving term
ii  libtimedate-perl   1.1600-9  Time and date functions for Perl
ii  liburi-perl1.35.dfsg.1-1 Manipulates and accesses URI strin
ii  libwww-perl5.820-1   WWW client/server library for Perl
ii  libyaml-syck-perl  1.05-1Fast, lightweight YAML loader and
ii  links [www-browser 2.2-1 Web browser running in text mode
ii  lintian2.1.0 Debian package checker
ii  lsb-release3.2-20   

Bug#508133: audacity: munmap_chunk(): invalid pointer: 0x00000000026f4eb0

2008-12-07 Thread Max Kellermann
Package: libmad0
Version: 0.15.1b-3
Severity: grave

I generated a raw audio file and tried to load it into audacity
(1.3.5-2).  Audacity crashed with the following message.  Looks like
it attempted to load the file as mp3; the file name had no extension.
This bug is always reproducible (tell me if you need my test file;
/dev/urandom might also do well).

Severity grave because this bug may be a remote vulnerability
(e.g. when playing remote mp3 streams).

*** glibc detected *** audacity: munmap_chunk(): invalid pointer: 
0x024d7950 ***
=== Backtrace: =
/lib/libc.so.6[0x7f4c0a23e948]
/usr/lib/libmad.so.0(mad_frame_finish+0x15)[0x7f4c0d7b3bb5]
/usr/lib/libmad.so.0[0x7f4c0d7b5cd1]
/usr/lib/libmad.so.0(mad_decoder_run+0x5f)[0x7f4c0d7b5b2f]
audacity[0x5ce4c9]
audacity[0x5c9a5c]
audacity[0x4c6680]
audacity[0x4c796c]
audacity[0x4477be]
audacity(_ZN12wxAppConsole10CallOnInitEv+0xd)[0x44812d]
/usr/lib/libwx_baseu-2.6.so.0(_Z7wxEntryRiPPw+0x23)[0x7f4c0b669573]
audacity[0x442dc2]
/lib/libc.so.6(__libc_start_main+0xe6)[0x7f4c0a1e91a6]
audacity(_ZN8wxDCBase22GetMultiLineTextExtentERK8wxStringPiS3_S3_P6wxFont+0x1a9)[0x43]
=== Memory map: 
0040-00896000 r-xp  08:02 50951588   
/usr/bin/audacity
00a95000-00ae1000 rw-p 00495000 08:02 50951588   
/usr/bin/audacity
00ae1000-00b0 rw-p 00ae1000 00:00 0 
01eea000-025fa000 rw-p 01eea000 00:00 0  [heap]
41ea4000-41ea5000 ---p 41ea4000 00:00 0 
41ea5000-426a5000 rw-p 41ea5000 00:00 0 
7f4bfd8d7000-7f4bfd937000 rw-s  00:07 9404421
/SYSV (deleted)
7f4bfd937000-7f4bfd93d000 r-xp  08:02 8494344
/usr/lib/gtk-2.0/2.10.0/loaders/libpixbufloader-xpm.so
7f4bfd93d000-7f4bfdb3d000 ---p 6000 08:02 8494344
/usr/lib/gtk-2.0/2.10.0/loaders/libpixbufloader-xpm.so
7f4bfdb3d000-7f4bfdb3e000 rw-p 6000 08:02 8494344
/usr/lib/gtk-2.0/2.10.0/loaders/libpixbufloader-xpm.so
7f4bfdb3e000-7f4bfdb4 r-xp  08:02 33723161   
/usr/lib/pango/1.6.0/modules/pango-basic-fc.so
7f4bfdb4-7f4bfdd3f000 ---p 2000 08:02 33723161   
/usr/lib/pango/1.6.0/modules/pango-basic-fc.so
7f4bfdd3f000-7f4bfdd4 rw-p 1000 08:02 33723161   
/usr/lib/pango/1.6.0/modules/pango-basic-fc.so
7f4bfdd4-7f4bfdda rw-s  00:07 9338884
/SYSV (deleted)
7f4bfdda-7f4bfdda7000 r-xp  08:02 59226866   
/usr/lib/libgailutil.so.18.0.1
7f4bfdda7000-7f4bfdfa7000 ---p 7000 08:02 59226866   
/usr/lib/libgailutil.so.18.0.1
7f4bfdfa7000-7f4bfdfa8000 rw-p 7000 08:02 59226866   
/usr/lib/libgailutil.so.18.0.1
7f4bfdfa8000-7f4bfdfdc000 r-xp  08:02 59148264   
/usr/lib/libgnomecanvas-2.so.0.2001.0
7f4bfdfdc000-7f4bfe1db000 ---p 00034000 08:02 59148264   
/usr/lib/libgnomecanvas-2.so.0.2001.0
7f4bfe1db000-7f4bfe1dd000 rw-p 00033000 08:02 59148264   
/usr/lib/libgnomecanvas-2.so.0.2001.0
7f4bfe1dd000-7f4bfe221000 r-xp  08:02 59226871   
/usr/lib/libgnomeprintui-2-2.so.0.1.0
7f4bfe221000-7f4bfe421000 ---p 00044000 08:02 59226871   
/usr/lib/libgnomeprintui-2-2.so.0.1.0
7f4bfe421000-7f4bfe424000 rw-p 00044000 08:02 59226871   
/usr/lib/libgnomeprintui-2-2.so.0.1.0
7f4bfe424000-7f4bfe576000 r-xp  08:02 59241068   
/usr/lib/libxml2.so.2.6.32
7f4bfe576000-7f4bfe775000 ---p 00152000 08:02 59241068   
/usr/lib/libxml2.so.2.6.32
7f4bfe775000-7f4bfe77f000 rw-p 00151000 08:02 59241068   
/usr/lib/libxml2.so.2.6.32
7f4bfe77f000-7f4bfe78 rw-p 7f4bfe77f000 00:00 0 
7f4bfe78-7f4bfe797000 r-xp  08:02 59226843   
/usr/lib/libart_lgpl_2.so.2.3.20
7f4bfe797000-7f4bfe996000 ---p 00017000 08:02 59226843   
/usr/lib/libart_lgpl_2.so.2.3.20
7f4bfe996000-7f4bfe997000 rw-p 00016000 08:02 59226843   
/usr/lib/libart_lgpl_2.so.2.3.20
7f4bfe997000-7f4bfea0c000 r-xp  08:02 59812713   
/usr/lib/libgnomeprint-2-2.so.0.1.0
7f4bfea0c000-7f4bfec0b000 ---p 00075000 08:02 59812713   
/usr/lib/libgnomeprint-2-2.so.0.1.0
7f4bfec0b000-7f4bfec0e000 rw-p 00074000 08:02 59812713   
/usr/lib/libgnomeprint-2-2.so.0.1.0
7f4bfec0e000-7f4bfec0f000 rw-p 7f4bfec0e000 00:00 0 
7f4bfec0f000-7f4bfec19000 r-xp  08:02 26811946   
/lib/libnss_files-2.7.so
7f4bfec19000-7f4bfee19000 ---p a000 08:02 26811946   
/lib/libnss_files-2.7.so
7f4bfee19000-7f4bfee1b000 rw-p a000 08:02 26811946   
/lib/libnss_files-2.7.so
7f4bfee1b000-7f4bfee25000 r-xp  08:02 25172845   
/lib/libnss_nis-2.7.so
7f4bfee25000-7f4bff024000 ---p a000 

Bug#508091: sourceforge.net mail service unreliable ?

2008-12-07 Thread Philippe Coval
Hi,

Sorry about this, I know that sf.net is not reliable ...
Am I the only one ?

But I recieve enough spam through it

I just expected sourceforge will fix this , but it's been more than a
year now...

Well I'll may update my email in my packages if you want

Thanx for notifying this

-- 
  #  Philippe Coval mailto:rzr[a]users.sf.netpgp:0x467094BC  #
  #  http://rzr.online.fr/contribs.htm xmpp:rzr[a]jabber.fr irc:RzR  #




signature.asc
Description: OpenPGP digital signature