Bug#834239: blends-tasks: Add FreedomBox to debian-blends-tasks

2017-08-11 Thread Mike Gabriel
HI James, hi Andreas, On Sa 13 Aug 2016 18:36:02 CEST, James Valleroy wrote: Package: blends-tasks Severity: wishlist Tags: patch Dear Maintainer, The attached patch will add FreedomBox to the blends tasks list, shown in Debian installer. Note one issue: Selecting this item will install

Bug#870725: CVE-2017-11721: read buffer overflow in MSG_ReadBits

2017-08-11 Thread Simon McVittie
On Fri, 11 Aug 2017 at 20:11:46 +0200, Moritz Mühlenhoff wrote: > Thanks, please upload. Generally speaking contrib is not supported, but > it would be silly to fix ioquake, but not iortcw along, so please go ahead. Thanks, both uploaded to security-master targeting stretch-security. > What

Bug#859780: debian-edu: remove education-lang-??-desktop-kde metapackages for Buster

2017-08-11 Thread Mike Gabriel
Control: clone -1 -2 Control: retitle -1 Revisit language tasks in Debian Edu Hi Holger, hi Petter, On Sa 05 Aug 2017 23:12:09 CEST, Petter Reinholdtsen wrote: I no longer remember the details, but I have vague memories of the idea behind these tasks/metapackages being to have a mechanism to

Bug#871834: xfce4: Panel Clock broken

2017-08-11 Thread David Christensen
See Xfce bug report, including source code correction: https://bugzilla.xfce.org/show_bug.cgi?id=11527 David

Bug#853673: swish++: ftbfs with GCC-7

2017-08-11 Thread Tobias Frost
Fixed with upload of  6.1.5-5, forgot to close the bug with the changelog.

Bug#834131: Missing Depends/Recommends ?

2017-08-11 Thread vdanjean . ml
Hi, Installing the libqt5multimedia5-plugins package solved the "the qmediaplayer object does not have a valid service" on my laptop. If that can help... Regards, Vincent

Bug#833303: blends-dev: please don't create prerm scripts which lintian complains about

2017-08-11 Thread Mike Gabriel
Control: close -1 Control: fixed -1 0.6.92.3 Hi Holger, On Di 02 Aug 2016 19:55:40 CEST, Holger Levsen wrote: Package: blends-dev Version: 0.6.93 Severity: normal Hi, tracker.d.o/debian-edu tells me the debian-edu has 21 lintian warnings, which can be found at

Bug#871443: nanomsg questions

2017-08-11 Thread Tom Lee
Hi Harlan, I'm potentially interested in picking up the Debian packaging for nanomsg, just a few questions: First, you mentioned upstream hasn't been especially responsive. Have they simply not looked at / commented on patches that you've offered up, expressed disinterest in figuring out the

Bug#871835: speed up for debootstrap

2017-08-11 Thread Thomas Lange
Package: debootstrap Severity: normal Tags: patch I've wrote some patches, which speed up deboostrap a lot. Changes are only made to /usr/share/debootstrap/functions, mostly in the perl part, but also the number of lines that are proceeded by perl are reduced via egrep. Here are some time

Bug#871831: mono-tools: Depends on libwebkit1.1-cil which is deprecated

2017-08-11 Thread Jeremy Bicha
Here's a slightly improved version of the patch. Thanks, Jeremy Bicha From a4960e84a6ded969b2efde222f287d2fdb03e097 Mon Sep 17 00:00:00 2001 From: Jeremy Bicha Date: Sat, 12 Aug 2017 00:07:16 -0400 Subject: [PATCH] Don't Build-Depend on libwebkit-cil-dev Closes: #871831 ---

Bug#871834: xfce4: Panel Clock broken

2017-08-11 Thread David Christensen
Package: xfce4 Version: 4.12.3 Severity: normal Dear Maintainer, Forwarded Message Subject: Debian 9.1 amd64 Xfce panel clock broken Date: Wed, 9 Aug 2017 17:13:55 -0700 From: David Christensen To: debian-u...@lists.debian.org debian-user: I have a

Bug#871833: conntrack-tools: Fix autopkgtests for compatibility with Ubuntu kernel, containers

2017-08-11 Thread Steve Langasek
Package: conntrack-tools User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu artful ubuntu-patch autopkgtest Version: 1:1.4.4+snapshot20161117-5 Severity: normal Tags: patch Dear maintainers, The conntrack-tools 1.4.4+snapshot20161117 update was blocked from reaching Ubuntu's 17.04

Bug#871831: mono-tools: Depends on libwebkit1.1-cil which is deprecated

2017-08-11 Thread Jeremy Bicha
Control: reassign -1 source:mono-tools Since I misfiled this, I'll repeat my original email. Hi, mono-tools-gui and monodoc-browser depends on libwebkit1.1-cil, which is deprecated in favor of libwebkit2gtk-4.0-37 (provided in Debian by webkit2gtk). These should be ported to the new webkitgtk

Bug#871832: Add an example showing how to dump ~/.config/dconf/user

2017-08-11 Thread 積丹尼 Dan Jacobson
Package: dconf-cli Version: 0.26.0-2+b1 Severity: wishlist File: /usr/share/man/man1/dconf.1.gz Add an example showing how to dump ~/.config/dconf/user .

Bug#871831: mono-tools: Depends on libwebkit1.1-cil which is deprecated

2017-08-11 Thread Jeremy Bicha
Source: blam Severity: serious Tags: sid buster patch User: pkg-webkit-maintain...@lists.alioth.debian.org Usertags: oldlibs libwebkitgtk-1.0-0 webkit1 Hi, mono-tools-gui and monodoc-browser depends on libwebkit1.1-cil, which is deprecated in favor of libwebkit2gtk-4.0-37 (provided in Debian by

Bug#866649: Read-119 removes gir1.2-webkit-3.0 dependency

2017-08-11 Thread James Cameron
Upstream release v119 has removed this dependency. -- James Cameron http://quozl.netrek.org/

Bug#871830: ITP: pylci -- Python-based Linux Control Interface

2017-08-11 Thread W. Martin Borgert
Package: wnpp Severity: wishlist Owner: Python Applications Packaging Team * Package name: pylci Version : 2017-03-10 Upstream Author : Pičugins Arsenijs * URL : https://github.com/CRImier/pyLCI * License : Apache 2.0

Bug#844431: Reproducibility in Policy

2017-08-11 Thread Russ Allbery
Daniel Kahn Gillmor writes: > On Fri 2017-08-11 16:08:47 -0700, Sean Whitton wrote: >> - a version of a source package unpacked at a given path; > I don't like the idea of hard-coding a fixed build path requirement into > debian policy. We're over 80% with variable

Bug#871829: blam: depends on libwebkit1.1-cil which is deprecated

2017-08-11 Thread Jeremy Bicha
Source: blam Severity: serious Tags: sid buster User: pkg-webkit-maintain...@lists.alioth.debian.org Usertags: oldlibs libwebkitgtk-1.0-0 webkit1 Hi, blam depends on libwebkit1.1-cil, which is deprecated in favor of libwebkit2gtk-4.0-37 (provided in Debian by webkit2gtk). blam should be ported

Bug#871828: gplaycli: new upstream version available

2017-08-11 Thread Andres Salomon
Package: gplaycli Severity: wishlist Version: 0.2.1-1 There's a newer version of gplaycli available upstream (0.2.9). It has a bunch of authentication improvements. If you're looking for a co-maintainer, I'd be happy to help out with this package.

Bug#549485: emacs25-common: description of -fn in emacs(1) man page is not up-to-date

2017-08-11 Thread Vincent Lefevre
Control: reopen -1 Control: reassign -1 emacs25-common 25.2+1-5 Control: retitle -1 emacs25-common: description of -fn in emacs(1) man page is not up-to-date On 2009-10-03 20:47:47 +0200, Vincent Lefevre wrote: > The emacs (emacs23) man page says: > > -fn font, --font font >Set the

Bug#430951: vserver is gone

2017-08-11 Thread Adam Borowski
The vserver project is dead. The last kernels it supported were 3.14 and 3.18, and even those were considered experimental. In fact, the last kernel for which vserver's upstream labelled their patchset as "stable" was 2.6.22. One of servers I deal with still uses vserver (despite my insistence

Bug#595036: #595036: GConf-WARNING when starting emacs as root

2017-08-11 Thread Vincent Lefevre
A note about this bug: emacs25 had the same issue, but it was eventually fixed a few days ago in: emacs25 (25.2+1-3) unstable; urgency=medium [...] * Completely remove gconf support. Build --without-gconf for the emacs25 flavor (as we already do for lucid and nox), since GConf has been

Bug#871629: thunderbird UI unusable with many widgets not drawn

2017-08-11 Thread Carsten Schoenert
Hello, On Thu, Aug 10, 2017 at 04:21:10PM +1200, Ben Caradoc-Davies wrote: > Package: thunderbird > Version: 1:52.2.1-4+b1 > Severity: grave > Justification: renders package unusable > > Dear Maintainer, > > the thunderbird UI is unusable with many widgets not drawn. See > attached screenshot.

Bug#871827: ITP: message-templ -- templates for Emacs message-mode

2017-08-11 Thread Sean Whitton
Package: wnpp Severity: wishlist Owner: Sean Whitton * Package name: message-templ Version : 0.3.20161104 Upstream Author : ARISAWA Akihiro * URL : git://pivot.cs.unb.ca/message-templ.git * License : GPL-2+

Bug#871629: same here

2017-08-11 Thread Adilson dos Santos Dantas
2017-08-11 14:32:27 -0400 Daniel Kahn Gillmor >I used the snapshots service to get the old version. > >I put the following line in /etc/apt/sources.list.d/snapshots.list : > >deb [signed-by=/usr/share/keyrings/debian-archive-keyring.gpg] >

Bug#844431: Reproducibility in Policy

2017-08-11 Thread Daniel Kahn Gillmor
Thanks for the proposal. I like it! A few nit-picks below: On Fri 2017-08-11 16:08:47 -0700, Sean Whitton wrote: > - a version of a source package unpacked at a given path; I don't like the idea of hard-coding a fixed build path requirement into debian policy. We're over 80% with

Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
Sébastien Delafond dixit: >Would you be able to produce debdiffs for jessie and stretch, so we can >review them and give you the go-ahead to upload to security-master ? OK, now that I’m waiting on the multi-hour testsuite results on sid. (It’s mostly that, due to the extra checks, the testsuite

Bug#844431: Reproducibility in Policy

2017-08-11 Thread Russ Allbery
Sean Whitton writes: > Proposal: > This is what Holger and I think we should add to Policy, after > readability tweaks: > Packages should build reproducibly, which for purposes of this > document means that given > - a version of a source

Bug#871795: debhelper: please document that debian/dirs is handled by dh_installdirs

2017-08-11 Thread Johannes Schauer
Hi, Quoting Sven Joachim (2017-08-12 01:41:40) > On 2017-08-12 01:23 +0900, Johannes Schauer wrote: > > Currently, the man page of dh_installdirs only documents that it takes care > > of debian/package.dirs. But it also takes care of debian/dirs. > > This is documented in debhelper(7): > >

Bug#871806: uscan: (dpkg, git-buildpackage) accept/mangle/store signed git tags in cases where upstream does not publish detached sigs on tarballs

2017-08-11 Thread Osamu Aoki
On Fri, Aug 11, 2017 at 06:59:02PM -0400, Daniel Kahn Gillmor wrote: > On Fri 2017-08-11 15:09:41 -0400, Osamu Aoki wrote: > > I was just talking about similar things on > > debian-pol...@lists.debian.org and Bug#811565. > > thanks for the pointer! 811565 seems to be about repos without tags, >

Bug#871263: libmspack: CVE-2017-6419

2017-08-11 Thread Stuart Caie
On 11/08/17 19:07, Sebastian Andrzej Siewior wrote: [0] https://security-tracker.debian.org/tracker/CVE-2017-6419 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6419 [1] https://github.com/vrtadmin/clamav-devel/commit/a83773682e856ad6529ba6db8d1792e6d515d7f1 Stuart, is this

Bug#867020: auctex: fails to remove: auctex/remove: Removing parsed (La)TeX macros for emacs25...rm: cannot remove '/var/lib/auctex/emacs25': Directory not empty

2017-08-11 Thread Davide G. M. Salvetti
tags 867020 + confirmed patch pending thanks > AB == Andreas Beckmann [2017-7-3] AB> Package: auctex AB> Version: 11.90-1 AB> Severity: serious AB> User: debian...@lists.debian.org AB> Usertags: piuparts AB> Hi, AB> during a test with piuparts I noticed your package fails to remove. >>

Bug#844431: Reproducibility in Policy

2017-08-11 Thread Chris Lamb
Dear Sean & Holger, Thank you so much for working on this at the end of a tiring DebConf! > […] > Later, we could narrow the definition of build environment by adding > more constraints, but we're not there yet. That makes sense. Indeed, that even feels like the optimal approach as it allows

Bug#871826: php7.1: Please remove unused libxmltok1-dev from Build-Depends

2017-08-11 Thread Guillem Jover
Source: php7.1 Source-Version: 7.1.8-1 Tags: patch Control: block 691755 by -1 Hi! While checking what would be needed to remove the old libxmltok1-dev (expat 1.x), noticed that this package Build-Depends on it, but does not seem to use it. Attached an untested patch, although a git grep seems

Bug#837808: gnome-online-accounts: 30% CPU Load with a Google account

2017-08-11 Thread gpe
Package: evolution-data-server Version: 3.22.7-1 Followup-For: Bug #837808 Dear Maintainer, I've always this problem with Debian 9. Regards. -- System Information: Debian Release: 9.1 APT prefers stable APT policy: (500, 'stable') Architecture: amd64 (x86_64) Foreign Architectures: i386

Bug#869645: ssss: Please add simple autopkgtest

2017-08-11 Thread Chris Lamb
Dear Tomasz, > Thank you Chris and late congrats for becoming our DPL. :) > I'm about to upload a new version of with your patch. Great stuff; thanks for uploading and your kind congratulations :) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org

Bug#871825: php7.0: Please remove unused libxmltok1-dev from Build-Depends

2017-08-11 Thread Guillem Jover
Source: php7.0 Source-Version: 7.0.22-2 Tags: patch Control: block 691755 by -1 Hi! While checking what would be needed to remove the old libxmltok1-dev (expat 1.x), noticed that this package Build-Depends on it, but does not seem to use it. Attached an untested patch, although a git grep seems

Bug#871824: nx-libs: Please remove unused libxmltok1-dev and expat from Build-Depends

2017-08-11 Thread Guillem Jover
Source: nx-libs Source-Version: 2:3.5.99.8-1 Tags: patch Control: block 691755 by -1 Hi! While checking what would be needed to remove the old libxmltok1-dev (expat 1.x), noticed that this package Build-Depends on it, but does not seem to use it. Attached an untested patch, although a git grep

Bug#865272: pristine-tar: fails to reproduce mingw-w64-v5.0.2.tar.bz2

2017-08-11 Thread Tomasz Buchert
On 20/06/17 09:17, Stephen Kitt wrote: > > [...] > > Steps to reproduce: > > wget > http://sourceforge.net/projects/mingw-w64/files/mingw-w64/mingw-w64-release/mingw-w64-v5.0.2.tar.bz2 > mkdir mingw-w64 && cd mingw-w64 > git init > gbp import-orig --pristine-tar

Bug#857540: scite: Scroll bar not moving when scrolling

2017-08-11 Thread Andreas Ronnquist
This seems to be fixed in 4.0, which were advertised on the Scintilla mailinglist earlier today. From the changelist: * On GTK+ fix drawing problems including incorrect scrollbar redrawing and flickering of text. Bug #1876. I have installed it on my unstable virtual machine, and the problems as

Bug#858125: e1000: ethernet interface hangs occasionally, kernel reports hang

2017-08-11 Thread Bruce Momjian,,,
I have determined that Debian was complaining about my ethernet port because I had flow control enabled on the switch, and the switch was getting easily overwhelmed and hanging, so the Debian resets were valid. Thank you for the research on this. I think you can close this case.

Bug#871807: libsdl1.2debian links to incompatible licensed libs indirectly

2017-08-11 Thread Manuel A. Fernandez Montecelo
2017-08-12 0:38 GMT+02:00 Thomas Charron : > libsdl is an LGPL licensed library, *NOT* a GPL licensed library. An LGPL > library cannot be linked to a GPL library in the first place, to use your > words. I am not aware of any restriction on linking. The only effect is that

Bug#869645: ssss: Please add simple autopkgtest

2017-08-11 Thread Tomasz Buchert
On 25/07/17 11:00, Chris Lamb wrote: > Hi, > > > Patch attached. > > Somehow this got dropped initially. Attaching now. > > > Regards, > Thank you Chris and late congrats for becoming our DPL. :) I'm about to upload a new version of with your patch. Tomasz signature.asc Description: PGP

Bug#871809: Please allow to store detached tarball signatures as well

2017-08-11 Thread Guido Günther
Hi, On Sat, Aug 12, 2017 at 01:07:26AM +0200, Tomasz Buchert wrote: > On 11/08/17 16:36, Guido Günther wrote: > > Package: pristine-tar > > Version: 1.40 > > Severity: wishlist > > > > Hi, > > as proposed by maxy on debian-devel it would be great if pristine-tar > > would store the tarball

Bug#871787: [Pkg-zsh-devel] Bug#871787: Bug#871787: zsh: error "defining function based on alias ..."

2017-08-11 Thread Vincent Lefevre
On 2017-08-11 18:20:13 +, Daniel Shahaf wrote: > Vincent Lefevre wrote on Fri, Aug 11, 2017 at 18:15:21 +0200: > > OK, but perhaps this should be announced then, since there are > > legitimate uses and this is a change in the behavior. > > It is mentioned in the list of incompatibilities in

Bug#871785: python3-dask: Version 0.15.1-2 not working

2017-08-11 Thread Diane Trout
Version: 0.15.1-3 tags: pending Thank you for your report, sorry about the mistake. It looks like this problem is fixed in 0.15.1-3 Diane On Fri, 2017-08-11 at 15:41 +0100, magnunor wrote: > Package: python3-dask > Version: 0.15.1-1 > Severity: important > > Dear Maintainer, > > The current

Bug#844431: Reproducibility in Policy

2017-08-11 Thread Sean Whitton
control: user debian-pol...@packages.debian.org control: usertag = normative proposal Hello, Proposal: This is what Holger and I think we should add to Policy, after readability tweaks: Packages should build reproducibly, which for purposes of this document means that given

Bug#871787: [Pkg-zsh-devel] Bug#871787: zsh: error "defining function based on alias ..."

2017-08-11 Thread Vincent Lefevre
On 2017-08-11 21:59:12 +0200, Axel Beckert wrote: > Vincent Lefevre wrote: > > > So you should either add this option or change the syntax of your > > > startup scripts. I hence consider this to be a non-bug. > > > > OK, but perhaps this should be announced then, > > Granted. Actually I thought

Bug#871806: uscan: (dpkg, git-buildpackage) accept/mangle/store signed git tags in cases where upstream does not publish detached sigs on tarballs

2017-08-11 Thread Daniel Kahn Gillmor
On Fri 2017-08-11 15:09:41 -0400, Osamu Aoki wrote: > I was just talking about similar things on > debian-pol...@lists.debian.org and Bug#811565. thanks for the pointer! 811565 seems to be about repos without tags, and i'm interested in repos signed tags, so i think the use cases are slightly

Bug#871809: Please allow to store detached tarball signatures as well

2017-08-11 Thread Tomasz Buchert
On 11/08/17 16:36, Guido Günther wrote: > Package: pristine-tar > Version: 1.40 > Severity: wishlist > > Hi, > as proposed by maxy on debian-devel it would be great if pristine-tar > would store the tarball signtures as well: > > >

Bug#871787: [Pkg-zsh-devel] Bug#871787: zsh: error "defining function based on alias ..."

2017-08-11 Thread Vincent Lefevre
On 2017-08-11 22:33:00 +0200, Axel Beckert wrote: > Vincent Lefevre wrote: > > Control: tag -1 - moreinfo unreproducible > > while I'm fine with removing the moreinfo tag on additional > information, I don't like reporters removing the unreproducible tag. > That tag shows if the maintainer(s) of

Bug#871808: [PATCH 1/2] u-a: Get altdir using DPKG_ROOT

2017-08-11 Thread chrysn
Previously, an update-alternatives run in a maintscript when installing with `dpkg --root` would have worked on /etc/alternatives rather than /install-dir/etc/alternatives. This patch is not complete yet because an unmodified version of altdir would actually be required for symlink targets.

Bug#869416: [pkg-gnupg-maint] Bug#869416: pinentry-gtk2: fails to request passphrase when importing OpenPGP secret key with Seahorse

2017-08-11 Thread intrigeri
Hi, NIIBE Yutaka: > It seems that the most likely case is the following scenario: > (1) Upon login, gpg-agent is invoked with no DISPLAY. This doesn't seem to be the case: # tr '\0' '\n' < /proc/$(pgrep gpg-agent)/environ | grep -E '^(GPG|DISPLAY|TTY)' DISPLAY=:0 I've verified that

Bug#871808: [PATCH 2/2] u-a: Fix link targets for DPKG_ROOT != ""

2017-08-11 Thread chrysn
--- utils/update-alternatives.c | 18 -- 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/utils/update-alternatives.c b/utils/update-alternatives.c index 8a3bff1dd..982d1b954 100644 --- a/utils/update-alternatives.c +++ b/utils/update-alternatives.c @@ -51,6 +51,7 @@

Bug#869416: pinentry-gtk2: fails to request passphrase when importing OpenPGP secret key with Seahorse

2017-08-11 Thread intrigeri
Control: reassign -1 gnupg-agent Control: found -1 2.1.18-8 Control: found -1 2.1.22-1 Hi again! NIIBE & I just spent some time debugging this. After some strace & shell wrapping fun, we identified that for some reason, gpg-agent runs pinentry-gtk2 without $DISPLAY set in its environment,

Bug#871823: unblock: git/1:2.14.1-1

2017-08-11 Thread Jonathan Nieder
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package git. This update fixes CVE-2017-1000117 (arbitrary code execution issues via URLs, https://public-inbox.org/git/xmqqh8xf482j@gitster.mtv.corp.google.com/T/#u).

Bug#869670: Depends: linux-headers-4.11.0-2-common ... but it is not going to be installed

2017-08-11 Thread Kurthy Gyula
Package: linux-headers-4.11.0-2-all Followup-For: Bug #869670 Dear Maintainer, I have tried to install nvidia drivers and run virtualbox, but for building DKMS I needed linux-headers and I couldn't install them. And when I try with my graphic card Gigabyte GTX 960 4GB to boot the system, it

Bug#871807: libsdl1.2debian links to incompatible licensed libs indirectly

2017-08-11 Thread Manuel A. Fernandez Montecelo
Hi, 2017-08-11 22:01 GMT+02:00 Thomas Charron : > So in the meantime, every application which has been used, as you pointed > out, for the last decade or two has been in violation of the GPL... > > I'm not trying to sound like a jerk here, but it's kind of an issue... >

Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
Sébastien Delafond dixit: >On Aug/11, Thorsten Glaser wrote: >> For {,{,old}old}stable-security, this should suffice: >> [...] > >Would you be able to produce debdiffs for jessie and stretch, so we can >review them and give you the go-ahead to upload to security-master ? Yes, although they’d

Bug#871629: same here

2017-08-11 Thread Daniel Kahn Gillmor
On Fri 2017-08-11 10:38:10 +0200, Adrian Ban wrote: > Yesterday after upgrading my Laptop and a VM both on Debian Sid I've > notice exactly the same issues mentioned here. > . > In the begging I thought is my Laptop issue > but after checking the VM I've notice that is a Thunderbird/system

Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Sébastien Delafond
On Aug/11, Thorsten Glaser wrote: > For {,{,old}old}stable-security, this should suffice: > [...] Would you be able to produce debdiffs for jessie and stretch, so we can review them and give you the go-ahead to upload to security-master ? Cheers, --Seb

Bug#871446: jemalloc: FTBFS on hurd-i386: aligned_alloc test hangs

2017-08-11 Thread Aaron M. Ucko
Faidon Liambotis writes: > In general, jemalloc is (copying from the package description): "a > library providing a malloc(3) implementation for multi-threaded > processes on multi-processor systems". Given that Hurd right now doesn't > even support SMP, I wonder if there is

Bug#871810: cvs: CVE-2017-12836: CVS and ssh command injection

2017-08-11 Thread Thorsten Glaser
tags 871810 + patch pending thanks Salvatore Bonaccorso dixit: >Severity: grave Probably not as severe, the attack vector seems minimal. >[0] https://security-tracker.debian.org/tracker/CVE-2017-12836 >https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12836 >[1]

Bug#864718: fsdev emulation security_model=none not handling mode 000

2017-08-11 Thread Greg Kurz
On Tue, 8 Aug 2017 10:58:29 +0300 Michael Tokarev wrote: > I'm forwarding this upstream. > It looks like the same issue is present in 2.10-tobe. > Now fixed upstream. Will be in 2.10.

Bug#871822: debhelper: Ignore .install files for "Section: doc" packages when the nodoc build option is set

2017-08-11 Thread Emmanuel Bourg
Package: debhelper Version: 10.7.2 Severity: normal Hi, I started implementing the new "nodoc" build option in maven-debian-helper but it led to build failures because even if the javadoc generation is skipped, the .install files are still interpreted and dh_install fails due to the missing

Bug#778662: closed by Debian FTP Masters <ftpmas...@ftp-master.debian.org> (Bug#871627: Removed package(s) from unstable)

2017-08-11 Thread James McCoy
Control: reassign -1 emacs25 24.4+1-4.1 Control: found -1 25.2+1-5 On Fri, Aug 11, 2017 at 06:46:30PM +, Debian Bug Tracking System wrote: > This is an automatic notification regarding your Bug report > which was filed against the emacs24 package: > > #778662: emacs should not return 0 when

Bug#871821: mention where to report upstream bugs

2017-08-11 Thread 積丹尼 Dan Jacobson
Package: alsa-utils Version: 1.1.3-1 Severity: wishlist File: /usr/share/doc/alsa-utils/README.Debian Please mention in this file where to report upstream bugs. The https://www.alsa-project.org/ on the package Description should be http://www.alsa-project.org/ , as HTTPS does not connect. On it

Bug#871820: openorienteering-mapper FTBFS: Test map_t Failed

2017-08-11 Thread Adrian Bunk
Source: openorienteering-mapper Version: 0.6.7-1 Severity: serious Tags: buster sid Some recent change in unstable makes openorienteering-mapper FTBFS: https://tests.reproducible-builds.org/debian/history/openorienteering-mapper.html

Bug#871764: snappy-java: Make source package bootstrappable

2017-08-11 Thread Emmanuel Bourg
On 08/11/2017 07:55 AM, Daniel Schepler wrote: > Currently, src:snappy-java Build-Depends on maven-debian-helper, which > indirectly Depends on libsnappy-java (through > libplexus-archiver-java), which Depends on libsnappy-jni. Good point. I think plexus-archiver should be modified such that the

Bug#871787: [Pkg-zsh-devel] Bug#871787: Bug#871816: zsh: error "defining function based on alias ..."

2017-08-11 Thread Axel Beckert
Hi Daniel, Daniel Shahaf wrote: > It is mentioned in the list of incompatibilities in the upstream > README. Thanks for that hint. I've updated the entry for the NEWS.Debian as follows and will commit and push that soon: zsh (5.4.1-1) unstable; urgency=medium From the upstream README of

Bug#853444: ht: diff for NMU version 2.1.0+repack1-2.1

2017-08-11 Thread Stephen Kitt
Hi Anton, On Fri, 11 Aug 2017 22:24:00 +0200, Anton Gladky wrote: > thanks a lot for the patch! I have just applied it and uploaded together > with some other changes. Please cancel your upload. Done (I think). Regards, Stephen pgpgePRtYUkRx.pgp Description: OpenPGP

Bug#802658: libesmtp: diff for NMU version 1.0.6-4.3

2017-08-11 Thread Salvatore Bonaccorso
Control: tags 802658 + pending Dear maintainer, I've prepared an NMU for libesmtp (versioned as 1.0.6-4.3) and uploaded it to DELAYED/10. Please feel free to tell me if I should delay it longer. Regards, Salvatore diff -Nru libesmtp-1.0.6/debian/changelog libesmtp-1.0.6/debian/changelog ---

Bug#871782: Patch for fife to plug memory leak

2017-08-11 Thread Petter Reinholdtsen
Here is a tested quilt patch to be stored in debian/patches/1000-icon-mem-leak.patch. I could not verify that all leaks are plugged, as the program is still increasing in size while playing, and I do not know if this is normal or not. But the code in question make sense and is from upstream, so

Bug#871819: os-autoinst: FTBFS when debhelper does not export PERL_USE_UNSAFE_INC

2017-08-11 Thread Dominic Hargreaves
Source: os-autoinst Version: 4.3+git20160919-3 Severity: normal User: debian-p...@lists.debian.org Usertags: debhelper-use-unsafe-inc-removal This package FTBFS when debhelper is changed to not export PERL_USE_UNSAFE_INC to the build environment. This export was added in 2016 at the same time

Bug#871764: snappy-java: Make source package bootstrappable

2017-08-11 Thread Daniel Schepler
On Fri, Aug 11, 2017 at 1:33 PM, Emmanuel Bourg wrote: > Good point. I think plexus-archiver should be modified such that the > snappy dependency becomes optional. I don't think it's used anyway. > Would that fix the bootstrapping issue? I believe it would - in my recent

Bug#871780: live-build: support for apt-transport-https

2017-08-11 Thread Andreas Heinlein
Am 11.08.2017 um 15:06 schrieb Ronny Standtke: > Package: live-build > Version: 1:20170807 > Severity: normal > Tags: patch > > Debian Live currently doesn't support https archives (needed for e.g. the > upstream archives of itch.io or jitsi). > > The attached patch fixes this issue. > > Cheers >

Bug#871787: [Pkg-zsh-devel] Bug#871787: zsh: error "defining function based on alias ..."

2017-08-11 Thread Axel Beckert
Control: forcemerge 871816 -1 Hi Vincent, Vincent Lefevre wrote: > Control: tag -1 - moreinfo unreproducible while I'm fine with removing the moreinfo tag on additional information, I don't like reporters removing the unreproducible tag. That tag shows if the maintainer(s) of a package can

Bug#821905: lynx-cur: accesses network on normal start

2017-08-11 Thread Denis Briand
tags 821905 pending thanks Hello Thorsten, Thank you for this information. It will be fixed in the next pending version. Best regards Denis Briand pgpOCPmvkVFDx.pgp Description: PGP signature

Bug#871818: debian-zh-faq FTBFS with perl 5.26

2017-08-11 Thread Adrian Bunk
Source: debian-zh-faq Version: 1.13 Severity: serious Tags: buster sid https://tests.reproducible-builds.org/debian/rb-pkg/unstable/amd64/debian-zh-faq.html ... # For LaTeX ./tocn.pl < debian-zh-faq.zh_CN.tex.tmp \ > debian-zh-faq.zh_CN.tex ./tocn.pl < debian-zh-faq.en.tex.tmp \

Bug#859867: [buildd-tools-devel] Bug#859867: Bug#859867: Bug#859867: Bug#859867: Please add a package which automatically configures sbuild for Debian packaging

2017-08-11 Thread Raphael Hertzog
Hello, FYI, while watching the autopkgtest BoF at debconf, I discovered vectis by Simon McVittie: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=843486 Arguably it covers some common grounds since it does setup sbuild in a VM. Maybe there's room for collaboration here as well? Simon, you

Bug#853444: ht: diff for NMU version 2.1.0+repack1-2.1

2017-08-11 Thread Anton Gladky
Hi Stephen, thanks a lot for the patch! I have just applied it and uploaded together with some other changes. Please cancel your upload. Best regards Anton 2017-08-10 22:57 GMT+02:00 Stephen Kitt : > Control: tags 853444 + patch > Control: tags 853444 + pending > > Dear

Bug#871037: UH leaks

2017-08-11 Thread Petter Reinholdtsen
Here is a tested quilt patch to be stored in debian/patches/1000-icon-mem-leak.patch. I could not verify that all leaks are plugged, as the program is still increasing in size while playing, and I do not know if this is normal or not. But the code in question make sense and is from upstream, so

Bug#870869: Segfault during libc-l10n install on kirkwood (armel)

2017-08-11 Thread Martin Michlmayr
* Peter Mogensen [2017-08-05 22:23]: > While trying to install stretch on a QNAP 419PII, the installation > consistently fails with a segfault in dpkg when it tries to install > locales and libc-l10n. I received one other report about a segfault on QNAP (when running anna) a

Bug#871817: [lvm2] --mirrorlog is not accepted for mirrored volumes

2017-08-11 Thread mirq-deboogs
Package: lvm2 Version: 2.02.168-2 Severity: important --- Please enter the report below this line. --- lvcreate and lvconvert don't allow specifying --mirrorlog/--corelog when creating/modifying mirrored LV. # lvcreate -L 256m -n test -m 1 --nosync --mirrorlog core araid --mirrorlog is

Bug#829172: security-tracker: New 'postponed' tag for issues warranting a DSA but postponed while waiting for more serious issues

2017-08-11 Thread Salvatore Bonaccorso
this has been implemented during Debconf17 by Sebastien Delafond. Closing the bug. Regards, Salvatore

Bug#869722: CVE-2017-12664

2017-08-11 Thread Bastien ROUCARIES
control: retitle -1 Imagemagick: memory leak in quantize On Fri, Aug 11, 2017 at 9:32 PM, Salvatore Bonaccorso wrote: > Hi Bastien, > > On Fri, Aug 11, 2017 at 05:41:22PM +0200, Bastien ROUCARIES wrote: >> control: retitle -1 CVE-2017-12664 >> >> This is CVE-2017-12664 > > Not

Bug#803089: This affects emacs25, too, and should remain open

2017-08-11 Thread James Cloos
This should be reassigned from emacs24 to emacs25. -JimC -- James Cloos OpenPGP: 0x997A9F17ED7DAEA6

Bug#871815: asn1c FTBFS on ppc64el: FAIL: check-REAL

2017-08-11 Thread Adrian Bunk
Source: asn1c Version: 0.9.28+dfsg-1 Severity: serious https://buildd.debian.org/status/fetch.php?pkg=asn1c=ppc64el=0.9.28%2Bdfsg-1=1502306601=0 ... check-REAL: check-REAL.c:58: check_str_representation: Assertion `!strcmp(s0, sample)' failed. 361: Checking 0->["0"] against ["0"] (canonical

Bug#871739: stretch-pu: package openldap/2.4.44+dfsg-5+deb9u1

2017-08-11 Thread Ryan Tandy
On Fri, Aug 11, 2017 at 10:39:05AM -0400, Adam D. Barratt wrote: Please go ahead. Uploaded and accepted.

Bug#871787: [Pkg-zsh-devel] Bug#871787: zsh: error "defining function based on alias ..."

2017-08-11 Thread Axel Beckert
Control: clone -1 -2 Control: retitle -2 zsh: error "defining function based on alias ..." Control: tag -2 - moreinfo unreproducible + confirmed pending Hi Vincent, Vincent Lefevre wrote: > > So you should either add this option or change the syntax of your > > startup scripts. I hence consider

Bug#871807: libsdl1.2debian links to incompatible licensed libs indirectly

2017-08-11 Thread Thomas Charron
So in the meantime, every application which has been used, as you pointed out, for the last decade or two has been in violation of the GPL... I'm not trying to sound like a jerk here, but it's kind of an issue... It's hidden by libcaca. Thomas On Fri, Aug 11, 2017 at 3:57 PM, Manuel A.

Bug#871219: Unreproducible

2017-08-11 Thread Anton Gladky
tag 871219 +unreproducible +moreinfo thanks Hi, thanks for the bugreport. I am not able to reproduce this bug on two of my machines. Could you please verify it, whether the bug is reproducible on your side? Thanks Anton

Bug#871814: csound-manual FTBFS: python: Command not found

2017-08-11 Thread Adrian Bunk
Source: csound-manual Version: 1:6.09.0~dfsg-1 Severity: serious https://buildd.debian.org/status/fetch.php?pkg=csound-manual=all=1%3A6.09.0~dfsg-1=1502411845=0 ... dh_auto_build make -j4 make[2]: Entering directory '/<>' [ -d "/usr/share/xml/docbook/stylesheet/nwalsh/" ] || ( \ echo

Bug#871813: isync: please allow the usage of TLS1.1+ by default

2017-08-11 Thread Sebastian Andrzej Siewior
Package: isync Version: 1.2.1-2 Severity: important Tags: patch User: pkg-openssl-de...@lists.alioth.debian.org Usertags: TLS1.0_1.1_removal The package uses TLS1.0 by default. The patched should allow using TLS1.0+ by default. Could someone please test this? Sebastian From: Sebastian Andrzej

Bug#871807: libsdl1.2debian links to incompatible licensed libs indirectly

2017-08-11 Thread Manuel A. Fernandez Montecelo
Control: severity -1 wishlist Control: tags -1 + wontfix Hi, 2017-08-11 20:25 GMT+02:00 Thomas Charron : > > Package: libsdl1.2debian > Version: 1.2.15+dfsg1-4 > Severity: important > > Dear Maintainer, > > After inspecting my application for library issues, I found that it

Bug#871812: ITP: gajim-rostertweaks -- allows user to tweak Gajim roster window appearance

2017-08-11 Thread W. Martin Borgert
Package: wnpp Severity: wishlist Owner: Debian Gajim Maintainers * Package name: gajim-rostertweaks Version : 0.6.3 Upstream Author : Denis Fomin * URL :

Bug#870376: jessie-pu: package sudo/1.8.10p3-1+deb8u5

2017-08-11 Thread Salvatore Bonaccorso
Control: tags -1 - moreinfo On Tue, Aug 08, 2017 at 09:03:46PM +0200, Salvatore Bonaccorso wrote: > Hi Adam, > > On Tue, Aug 08, 2017 at 11:25:53AM -0400, Adam D. Barratt wrote: > > Control: tags -1 + confirmed > > > > On Tue, 2017-08-01 at 15:55 +0200, Salvatore Bonaccorso wrote: > > > sudo in

Bug#299324: marked as done (emacs24 should build a GNUstep flavor)

2017-08-11 Thread Axel Beckert
Control: reopen -1 Control: reassign -1 emacs25 Control: retitle -1 emacs25 should build a GNUstep flavor This is a generic issue with the most current (or actually any) emacs version in Debian until resolved. Hence reopening and reassigning to emacs25. Regards, Axel -- ,''`.

Bug#871811: FTBFS with CGAL 4.10

2017-08-11 Thread Joachim Reichel
Source: rheolef Version: 6.7-3 Severity: normal Tags: upstream, patch Hi, your package fails to build with CGAL 4.10 in experimental. The following patch fixes the problem: --- rheolef-6.7.orig/nfem/geo_element/cgal_kernel.h +++ rheolef-6.7/nfem/geo_element/cgal_kernel.h @@ -247,7 +247,7 @@

  1   2   3   >