Bug#928185: unblock: openjdk-11/11.0.3+7-4

2019-06-11 Thread tony mancill
On Wed, Jun 12, 2019 at 12:37:11AM +0200, Moritz Mühlenhoff wrote: > On Mon, Jun 10, 2019 at 09:46:41PM -0700, tony mancill wrote: > > I am not a member of the OpenJDK team and contributed far less to the > > JDK 8 -> 11 transition than Emmanuel has. If he and Matthias are in > > agreement and

Bug#930404: [Meta] move gitlab back to main from contrib

2019-06-11 Thread Pirate Praveen
Package: gitlab Version: 11.8.10+dfsg-1 Severity: wishlist Control: block -1 by 863293 Control: block -1 by 930372 This is a meta bug to track progress of packaging node dependencies. -- Sent from my Android device with K-9 Mail. Please excuse my brevity.

Bug#927851: no empty promises

2019-06-11 Thread andrew glaeser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Just not my fault, if you cannot read this inside of your mobile app, that you love the most, although might be you have to adapt your preferences and behaviour to the realities of life: > andrew@a68n:~$ ssh root@detst > Linux detst 4.19.0-5-amd64

Bug#930403: ibod FTCBFS: strips with the wrong strip

2019-06-11 Thread Helmut Grohne
Source: ibod Version: 1.5.0-6 Tags: patch User: debian-cr...@lists.debian.org Usertags: ftcbfs ibod fails to cross build from source, because its make install passes the -s flag to install and thus uses the wrong strip. Beyond breaking cross compilation, this also breaks DEB_BUILD_OPTIONS=nostrip

Bug#930402: kball FTCBFS: uses the build architecture compiler

2019-06-11 Thread Helmut Grohne
Source: kball Version: 0.0.20041216-10 Tags: patch User: debian-cr...@lists.debian.org Usertags: ftcbfs kball fails to cross build from source, because it uses the build architecture compiler. It uses a non-standard variable GCC for the compiler while debhelper passes it as CXX. After renaming

Bug#930401: mutter: Crashes on restart if Static Workspaces are enabled (gnome-shell)

2019-06-11 Thread Matthew Gabeler-Lee
Package: mutter Version: 3.30.2-7 Severity: normal Tags: upstream If you enable static instead of dynamic workspaces, then gnome-shell segfaults if you restart it. This has been reported and fixed upstream in 3.32.x, it would be nice if this fix could be backported to Debian's 3.30.x release.

Bug#930399: python-mode: Pychecker will be removed after buster

2019-06-11 Thread Kenneth Pronovici
Package: python-mode Severity: normal Hi, This is one of 3 packages in the archive that still depends on pychecker. I intend to have the pychecker package removed from unstable a little while after buster is released. Besides its lack of support for Python 3, pychecker has been completely

Bug#930398: spe: Pychecker will be removed after buster

2019-06-11 Thread Kenneth Pronovici
Package: spe Severity: normal Hi, This is one of 3 packages in the archive that still depends on pychecker. I intend to have the pychecker package removed from unstable a little while after buster is released. Besides its lack of support for Python 3, pychecker has been completely unsupported

Bug#930400: boa-constructor: Pychecker will be removed after buster

2019-06-11 Thread Kenneth Pronovici
Package: boa-constructor Severity: normal Hi, This is one of 3 packages in the archive that still depends on pychecker. I intend to have the pychecker package removed from unstable a little while after buster is released. Besides its lack of support for Python 3, pychecker has been completely

Bug#930397: [pre-approval] unblock: nano/3.2-3

2019-06-11 Thread Jordi Mallach
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Hi release team, Nano's upstream has been focusing on fixing some crashers and hangs lately, and as nano froze a while back, he was kind enough to backport all the fixes he deems

Bug#930341: rotix FTCBFS: does not use cross tools

2019-06-11 Thread Raúl Benencia
Hi Helmut, On Tue, Jun 11, 2019 at 06:10:28AM +0200, Helmut Grohne wrote: > Please consider applying the attached patch. Thanks for the report and, especially, for the patch. I've applied it along with other routine maintenance changes. Best wishes, -- Raúl Benencia signature.asc

Bug#881544: Epydoc will be removed after buster

2019-06-11 Thread Kenneth Pronovici
I intend to have the eypdoc package removed from unstable a few weeks after buster is released. Besides its lack of support for Python 3, epydoc has been completely unsupported upstream for close to a decade. It really should have been removed from the archive years ago. If you are in the

Bug#881566: Epydoc will be removed after buster

2019-06-11 Thread Kenneth Pronovici
Hi, This bug report is now over 18 months old with no reply. I intend to have the eypdoc package removed from unstable a few weeks after buster is released. Besides its lack of support for Python 3, epydoc has been completely unsupported upstream for close to a decade. It really should have

Bug#881558: Intending to remove epydoc after buster

2019-06-11 Thread Kenneth Pronovici
Hi, I just wanted you to know that I am intending to have epydoc removed from unstable a few weeks after buster is released, along with several other obsolete Python packages that I maintain. Besides its lack of support for Python 3, epydoc has been completely unsupported upstream for close to a

Bug#881546: Epydoc will be removed after buster

2019-06-11 Thread Kenneth Pronovici
Hi, This bug report is now over 18 months old with no reply. I intend to have the eypdoc package removed from unstable a few weeks after buster is released. Besides its lack of support for Python 3, epydoc has been completely unsupported upstream for close to a decade. It really should have

Bug#929182: fluidsynth: no sound by default - soundfont location doesn't exist

2019-06-11 Thread Erich Eickmeyer
This bug was noticed in the Ubuntu package (inherited from Debian) and reported at . That bug has been linked to this bug. Erich Eickmeyer Project Leader Ubuntu Studio ubuntustudio.org

Bug#930396: ITP: libdata-dumper-compact-perl -- Uber compact perl5 Data::Dumper wrapper

2019-06-11 Thread Utkarsh Gupta
Package: wnpp Severity: wishlist Owner: Utkarsh Gupta * Package name : libdata-dumper-compact-perl Version : 0.004000-1 Upstream Author : Matt S Trout * URL : https://github.com/shadow-dot-cat/Data-Dumper-Compact * License : Artistic or GPL-1+

Bug#930168: Confirming the bug on Debian

2019-06-11 Thread Alexander Kernozhitsky
I also encounter this bug on Debian Buster. But I manually disabled all the AppStream and DEP-11 metadata from apt configs, so this may be the reason. Can anyone reproduce this on a clean system? -- Alexander Kernozhitsky

Bug#928185: unblock: openjdk-11/11.0.3+7-4

2019-06-11 Thread Moritz Mühlenhoff
On Mon, Jun 10, 2019 at 09:46:41PM -0700, tony mancill wrote: > I am not a member of the OpenJDK team and contributed far less to the > JDK 8 -> 11 transition than Emmanuel has. If he and Matthias are in > agreement and the plan is palatable to the Release and Security Teams, > that's ideal. I

Bug#930395: u-boot-menu doesn't allow setting U_BOOT_MENU_LABEL

2019-06-11 Thread Steev Klimaszewski
Package: u-boot-menu Version: 3 Tags: patch The default file shows that we should be able to set the U_BOOT_MENU_LABEL option in /etc/default/u-boot however, in the actual u-boot-update script, U_BOOT_MENU_LABEL is hardcoded to "Debian GNU/Linux kernel" instead of allowing it to be different

Bug#911844: okular: Prints to the wrong printer

2019-06-11 Thread Martin Steigerwald
Martin Steigerwald - 11.06.19, 23:37: > > I used the neon-user-20190606-1138.iso (okular 19.04.1). Everything > > behaved normally. No observed bug there. Okular 18.04 from > > experimental wouldn't install because of unmet depenencies. Another > > time, perhaps. > > Hmmm, so it works okay with

Bug#911844: okular: Prints to the wrong printer

2019-06-11 Thread Martin Steigerwald
Hi Brian. Brian Potkin - 11.06.19, 21:13: > On Tue 11 Jun 2019 at 13:20:40 +0200, Martin Steigerwald wrote: > > Brian Potkin - 11.06.19, 10:42: > > > On Tue 11 Jun 2019 at 09:53:50 +0200, Martin Steigerwald wrote: > > […] > > > > > > Two ways to use your (and our) time in a more productive

Bug#771339: linux: linux-headers 3.16 Makefile contains VERSION=2 PATCHLEVEL=6

2019-06-11 Thread Fab Stz
Le mardi 11 juin 2019, 21:41:25 CEST Ben Hutchings a écrit : > They should be using "make kernelversion" instead of looking for > variable assignments the Makefile. > > This is not even a Debian-specific problem any more. Looking for > variable assignments in the Makefile will break whenever the

Bug#930394: unblock: usrmerge/22

2019-06-11 Thread Marco d'Itri
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package usrmerge to support installing the fixed molly-guard in buster. unblock usrmerge/22 diff -Nru usrmerge-21/debian/changelog usrmerge-22/debian/changelog ---

Bug#771339: linux: linux-headers 3.16 Makefile contains VERSION=2 PATCHLEVEL=6

2019-06-11 Thread Ben Hutchings
On Tue, 2019-06-11 at 17:01 +0200, Fab Stz wrote: > Source: linux > Version: 4.9.0 or 4.19... probably any > Followup-For: Bug #771339 > > Dear Maintainer, > > This bug still exists in linux 4.9 and 4.19 (stretch, stretch-backports and > also buster) > > Like the first reporter, I tried

Bug#930351: linux-image-4.9.0-9-amd64: soft lockup / stuck in pid_revalidate

2019-06-11 Thread Ben Hutchings
On Tue, 2019-06-11 at 10:13 +0200, Bernhard M. Wiedemann wrote: [...] > kernel:[1616241.072680] NMI watchdog: BUG: soft lockup - CPU#5 stuck for > 22s! [ps:28525] > > [1626796.848128] CPU: 5 PID: 28525 Comm: ps Tainted: G D L > 4.9.0-9-amd64 #1 Debian 4.9.168-1+deb9u2 [...] Please

Bug#930392: unblock: ibus-sunpinyin/2.0.3+git20181120-4

2019-06-11 Thread Boyuan Yang
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-CC: debian-input-met...@lists.debian.org idaob...@gmail.com Please unblock ibus-sunpinyin 2.0.3+git20181120-4. This upload fixes https://bugs.debian.org/929078 , which caused

Bug#930393: RFS: aqemu/0.9.2-2.3 [NMU] [RC] -- Fix #927126 including suggestion from #929342 - aqemu: after updating can't open VMs

2019-06-11 Thread Alexis Murzeau
Package: sponsorship-requests Severity: important X-Debbugs-CC: Ignace Mouzannar X-Debbugs-CC: Abhijith PA Dear mentors, I am looking for a sponsor for a NMU of "aqemu" to fix this RC bug: #927126 - aqemu: after updating can't open VMs [0]. This bug was fixed in previous NMU aqemu/0.9.2-2.2

Bug#927126: Fwd: Bug#929342: unblock: aqemu/0.9.2-2.2

2019-06-11 Thread Alexis Murzeau
Le 11/06/2019 à 21:58, Paul Gevers a écrit : > Hi Alexis, > > [Note: when you think you have covered questions asked, please remove > the moreinfo tag, as it will make the bug show up in the list of bugs > that need attention from us]. Ok, I guess that tag should be removed once aqemu/0.9.2-2.3

Bug#930390: patch

2019-06-11 Thread dann frazier
From: Robert McMahon Subject: [PATCH] fix latent bug in signal handling, per POSIX calling exit() in signal handler is not safe. Use _exit() instead. Also, detect the user signal SIGINT for the case of server needing two invocations to stop server threads. Note: the server threads still

Bug#927126: Fwd: Bug#929342: unblock: aqemu/0.9.2-2.2

2019-06-11 Thread Paul Gevers
Hi Alexis, [Note: when you think you have covered questions asked, please remove the moreinfo tag, as it will make the bug show up in the list of bugs that need attention from us]. On 06-06-2019 22:16, Alexis Murzeau wrote: > The modification I've done in version aqemu/0.9.2-2.3 specifically fix

Bug#930391: frei0r-plugins-dev: Missing header files in /usr/include directory

2019-06-11 Thread Laurent BRULET
Package: frei0r-plugins-dev Version: 1.6.1-2 Severity: important Dear Maintainer, I was trying to build a frei0r plugin I wrote in C++. But the compilation failed because the header file frei0r.hpp was not present in /usr/include The unique present header file is frei0r.h which allows to build

Bug#930390: iperf server will not exit

2019-06-11 Thread dann frazier
Package: iperf Version: 2.0.12+dfsg1-2 Severity: important Tags: patch, upstream After running some iperf testing, ^c'ing the server fails: $ iperf -s Server listening on TCP port 5001 TCP window size: 128 KByte (default)

Bug#930389: twisted: CVE-2019-12387

2019-06-11 Thread Salvatore Bonaccorso
Source: twisted Version: 18.9.0-3 Severity: important Tags: security upstream Hi, The following vulnerability was published for twisted. CVE-2019-12387[0]: | In Twisted before 19.2.1, twisted.web did not validate or sanitize | URIs or HTTP methods, allowing an attacker to inject invalid |

Bug#930388: ruby-openid: CVE-2019-11027

2019-06-11 Thread Salvatore Bonaccorso
Source: ruby-openid Version: 2.7.0debian-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://github.com/openid/ruby-openid/issues/122 Hi, The following vulnerability was published for ruby-openid. CVE-2019-11027[0]: | Ruby OpenID (aka ruby-openid)

Bug#926434: fixed (in my point of view) & not listetd in "netinst.iso-image Debian 9.9"

2019-06-11 Thread Martin Kubiak
Hi Julian, I answered your question of defining the upstream-mirror correctly at "05.04.2019, 18:07". So I thought it is done. Isn't it? It seems to be open:  * https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=926434 And another part: Today I installed a new machine and wondered that

Bug#930373: Shotwell: double clicking on the image viewer freezes an image of the picture. Reboot required

2019-06-11 Thread Fran Glais
Hello Jörg, Thank you for your prompt reply. You can find the output requested below. As for reproducing this bug, it was mentioned upstream that it could be hardware related. I'm running Debian with Sandybridge integrated graphics (2450M to be more specific). Upstream issue:

Bug#930386: patch

2019-06-11 Thread dann frazier
From: Robert McMahon Subject: [PATCH] increase listen backlog limit to much larger value Bug-Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=930386 Bug-Ubuntu: https://bugs.launchpad.net/bugs/1832399 Last-Update: 2019-06-11 Applied-Upstream:

Bug#928770: closed by Laszlo Boszormenyi (GCS) (Bug#928770: fixed in sqlite3 3.27.2-3)

2019-06-11 Thread Salvatore Bonaccorso
Hi! On Tue, Jun 11, 2019 at 07:24:06AM +0200, László Böszörményi (GCS) wrote: > Hi Salvatore, > > On Tue, Jun 11, 2019 at 6:18 AM Salvatore Bonaccorso > wrote: > > On Mon, Jun 10, 2019 at 05:06:07PM +, Debian Bug Tracking System wrote: > > > sqlite3 (3.27.2-3) unstable; urgency=high > > >

Bug#930387: rdekstop: security issues fixed in 1.8.5 and 1.8.6

2019-06-11 Thread Salvatore Bonaccorso
Source: rdesktop Version: 1.8.4-1 Severity: grave Tags: security upstream fixed-upstream Justification: user security hole Control: fixed -1 1.8.6-1 Hi 1.8.6-1 mentions a new upstream release with many security fixes, but none of those apparently have (yet) a CVE. Filling this bug for having an

Bug#930386: hangs and connection resets w/ high thread count

2019-06-11 Thread dann frazier
Package: iperf Version: 2.0.12+dfsg1-2 Severity: important Tags: upstream patch When attempting an iperf run with 24 threads, I either hit a hang [*] or a bunch of "write failed: Connection reset by peer" errors [**]. These are both resolved by the following upstream commit:

Bug#930385: RFP: container-diff -- Diff your Docker containers

2019-06-11 Thread Varac
Package: wnpp Severity: wishlist -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: container-diff Version : latest Upstream Author : ? * URL : https://github.com/GoogleContainerTools/container-diff * License : Apache-2.0 Programming Lang:

Bug#911844: okular: Prints to the wrong printer

2019-06-11 Thread Brian Potkin
On Tue 11 Jun 2019 at 13:20:40 +0200, Martin Steigerwald wrote: > Brian Potkin - 11.06.19, 10:42: > > On Tue 11 Jun 2019 at 09:53:50 +0200, Martin Steigerwald wrote: > […] > > > Two ways to use your (and our) time in a more productive manner are: > > > > > > 1) Retest with Okular 18.04 from

Bug#930384: debian-security-support: [l10n:cs] Updated Czech PO package translation

2019-06-11 Thread Michal Simunek
Package: debian-security-support Version: 2019.05.23 Severity: wishlist Tags: patch l10n Dear Maintainer, In attachment there is updated Czech (cs.po) PO translation for package debian- security-support, please include it. -- System Information: Debian Release: 9.9 APT prefers

Bug#905772: For me it needs sysV drop and --no-stop-on-upgrade and --no-restart-after-upgrade

2019-06-11 Thread Christian Ehrhardt
Testing now confirmed, that for the version in experimental I need to do both: a) drop the sysV - as Ubuntu has done for a while - without the sysV to systemd mapping still restarts the services - something like [1], I haven an MP up for that on salsa, might be slightly outdated b) Specify both

Bug#911844: okular: Prints to the wrong printer

2019-06-11 Thread Martin Steigerwald
Brian Potkin - 11.06.19, 10:42: > On Tue 11 Jun 2019 at 09:53:50 +0200, Martin Steigerwald wrote: […] > > Two ways to use your (and our) time in a more productive manner are: > > > > 1) Retest with Okular 18.04 from Debian experimental (in case you > > run > > buster/sid). Or start KDE Neon in a

Bug#930194: unblock: openssl/1.1.1c-1

2019-06-11 Thread Paul Gevers
Control: tags -1 d-i Hi Sebastian, On 08-06-2019 21:39, Paul Gevers wrote: > Control: tags -1 moreinfo confirmed > > On 08-06-2019 10:50, Sebastian Andrzej Siewior wrote: >>> Even if we were to unblock, can we get the m2crypto fix available, such >>> that they can migrate together? I understood

Bug#916610: spacenavd: diff for NMU version 0.6-1.1

2019-06-11 Thread sur5r
Control: tags 916610 + pending Dear maintainer, I've prepared an NMU for spacenavd (versioned as 0.6-1.1) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards. diff -Nru spacenavd-0.6/debian/changelog spacenavd-0.6/debian/changelog ---

Bug#930373: Shotwell: double clicking on the image viewer freezes an image of the picture. Reboot required

2019-06-11 Thread Jörg Frings-Fürst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, Am Dienstag, den 11.06.2019, 20:19 +0200 schrieb Jörg Frings-Fürst: [...] > Hello Fran, > 8...] > Please can you send me the output of > > dconf dump /org/yorba/shotwell > [...] Sorry this must be dconf dump /org/yorba/shotwell/ CU

Bug#930373: Shotwell: double clicking on the image viewer freezes an image of the picture. Reboot required

2019-06-11 Thread Jörg Frings-Fürst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 tags 930373 + moreinfo severity 930373 important thanks Hello Fran, thank you for spending your time helping to make Debian better with this bug report. I have checked your bug on my 3 and on 2 external machines with gnome / wayland. On 4

Bug#930348: chromium: missing intrinsics on armhf

2019-06-11 Thread Riku Voipio
The build is fixed in: https://salsa.debian.org/chromium-team/chromium/commits/arm-fixes/debian I can make an upload if you prefer, or I can wait for you. Cheers, Riku

Bug#930383: sniffit: New upstream homepage

2019-06-11 Thread Joao Eriberto Mota Filho
Package: sniffit Severity: normal Please see: https://github.com/resurrecting-open-source-projects/sniffit Regards, Eriberto

Bug#930382: outguess: New upstream homepage

2019-06-11 Thread Joao Eriberto Mota Filho
Package: outguess Severity: normal Please, see: https://github.com/resurrecting-open-source-projects/outguess Regards, Eriberto

Bug#930381: txt2html: New upstream homepage

2019-06-11 Thread Joao Eriberto Mota Filho
Package: txt2html Severity: normal Please, see: https://github.com/resurrecting-open-source-projects/txt2html Regards, Eriberto

Bug#920567: bash: dpkg-reconfigure: command not found

2019-06-11 Thread Jiri Palecek
On Sun, 27 Jan 2019 09:12:32 +0600 Thulium Equasman wrote: > Package: python3-reportbug > Version: 7.5.1 > Severity: normal > Tags: d-i > > Hi, > I got the message "bash: dpkg-reconfigure: command not found > " when I ran `dpkg-reconfigure fontconfig-config`. I ran this command as root. > I then

Bug#930380: calligraflow: crash on startup (when run under gnome?)

2019-06-11 Thread Zack Weinberg
Package: calligraflow Version: 1:2.9.11+dfsg-4+b1 Severity: important calligraflow crashes on startup - possibly only when run under a GNOME desktop session and/or with KDE persistent state not properly initialized, since a stack trace fingers the KDE most-recently-used-files implementation.

Bug#930379: xfdesktop4: Deskop icons order resets at login

2019-06-11 Thread Simon
Package: xfdesktop4 Version: 4.12.4-2.1 Severity: important Dear Maintainer, Current xfdesktop4 version still suffers from a bug opened in 2014 and now (at last!) solved upstream in version 4.12.5. https://bugzilla.xfce.org/show_bug.cgi?id=11266 Since it makes life of XFCE users a lot easier,

Bug#930378: ITP: qunit-selenium -- Run QUnit tests through Selenium WebDriver

2019-06-11 Thread Jongmin Kim
Package: wnpp Severity: wishlist Owner: Jongmin Kim * Package name: qunit-selenium Version : 0.0.4 Upstream Author : Silvio Montanari * URL : https://github.com/smontanari/qunit-selenium * License : Expat Programming Lang: Ruby Description : Run QUnit

Bug#905772: we might also need --no-restart-after-upgrade in addition to --no-stop-on-upgrade

2019-06-11 Thread Christian Ehrhardt
Was: systemctl --system daemon-reload >/dev/null || true if [ -n "$2" ]; then _dh_action=restart else _dh_action=start fi deb-systemd-invoke $_dh_action 'libvirt-guests.service' 'virtlockd-admin.socket' 'virtlockd.service' 'virtlockd.socket'

Bug#930377: unblock: haskell-argon2/1.3.0.1-5

2019-06-11 Thread Sean Whitton
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package haskell-argon2. Fixes a stretch->buster upgrade bug caused by libargon2-0-dev becoming a virtual package. unblock haskell-argon2/1.3.0.1-5 -- System Information:

Bug#929708: Reopen the accidentially-closed ITP report

2019-06-11 Thread Boyuan Yang
Control: reopen -1 Seems that my new upload came with a wrong number of bug report. Reopening this ITP bug to fix this problem. Sorry for the noise. Regards, Boyuan Yang signature.asc Description: This is a digitally signed message part

Bug#910143:

2019-06-11 Thread Emmanuel Kasper
For virtualbox vagrant boxes, please find new box releases at https://app.vagrantup.com/debian Libvirt boxes are pending. Extending the disk image to 20GB slows the build process a bit, as we need to zero free a bigger filesystem, but it is still acceptable. -- Diese Nachricht wurde von

Bug#930375: CVE-2019-12749: DBusServer DBUS_COOKIE_SHA1 authentication bypass

2019-06-11 Thread Simon McVittie
Version: 1.12.16-1 On Tue, 11 Jun 2019 at 17:34:40 +0100, Simon McVittie wrote: > For buster this has been fixed in libdbus-1-3 1.12.16-1. I'll close this > bug when I have a bug number.

Bug#930376: gvfsd GetConnection() missing authorization check

2019-06-11 Thread Simon McVittie
Package: gvfs-daemons Version: 1.14.1-1 Severity: grave Tags: security fixed-upstream patch Forwarded: https://gitlab.gnome.org/GNOME/gvfs/commit/70dbfc68a79faac49bd3423e079cb6902522082a While looking for services that might be vulnerable to CVE-2019-12749 or a similar vulnerability, I noticed

Bug#930311: lintian: Possible exception to package-contains-documentation-outside-usr-share-doc

2019-06-11 Thread Chris Lamb
Hi Niels, > Re: > https://salsa.debian.org/lintian/lintian/commit/a16cd3a1c812c8894bddf9b920561eb0dd602d85 > > I suspect we should probably match usr/lib/R/site-library/ as a prefix > rather than an exact match. Whoops. Fixed in:

Bug#930311: lintian: Possible exception to package-contains-documentation-outside-usr-share-doc

2019-06-11 Thread Niels Thykier
Chris Lamb: > Hi Niels, > >> My question is: Should we move this exception to lintian itself and >> stop having people automate overrides > > Oh, without any doubt here — the idea of automatically-generated > overrides simply makes me squirm. > > (Shall we begin by cloning this bug "against"

Bug#930375: CVE-2019-12749: DBusServer DBUS_COOKIE_SHA1 authentication bypass

2019-06-11 Thread Simon McVittie
Package: libdbus-1-3 Version: 1.0.0-1 Severity: grave Tags: security fixed-upstream patch Forwarded: https://gitlab.freedesktop.org/dbus/dbus/issues/269 Joe Vennix of Apple Information Security discovered an implementation flaw in the DBUS_COOKIE_SHA1 authentication mechanism. A malicious client

Bug#930373: Shotwell: double clicking on the image viewer freezes an image of the picture. Reboot required

2019-06-11 Thread Fran Glais
Package: shotwell Version: 0.30.1-1 Severity: critical Tags: patch Justification: breaks unrelated software Dear Maintainer, In a Wayland session (gnome-shell in my case), double-clicking on an image when using the Shotwell Viewer fullscreens the image, but then fails to close the picture. This

Bug#929821: libgd2: CVE-2019-11038: Uninitialized read in gdImageCreateFromXbm

2019-06-11 Thread Jonas Meurer
Jonas Meurer wrote: > Salvatore Bonaccorso wrote: > > The following vulnerability was published for libgd2. > > > > CVE-2019-11038[0]: > > Uninitialized read in gdImageCreateFromXbm > > > > If you fix the vulnerability please also make sure to include the > > CVE (Common Vulnerabilities &

Bug#930372: Provide node-bootstrap (install package.json and symlink dist to /usr/lib/nodejs)

2019-06-11 Thread Pirate Praveen
Package: libjs-bootstrap4 severity: wishlist version: 4.3.1+dfsg2-1 gitlab uses webpack and expects bootstrap node module. Please provide this in addition to libjs.

Bug#930371: unblock: dbus/1.12.16-1

2019-06-11 Thread Simon McVittie
Package: release.debian.org Severity: normal Tags: d-i User: release.debian@packages.debian.org Usertags: unblock Please unblock package dbus to fix CVE-2019-12749. I forgot to set high urgency, so you might want to adjust its age-days too. Filtered and full diffs are attached (the former

Bug#930363: faad2: fix build with gcc-9 [patch]

2019-06-11 Thread Fabian Greffrath
Control: forwarded -1 https://github.com/knik0/faad2/commit/920ec985a74c6f88fe507181df07a0cd7e51d519 Control: tags -1 +upstream +fixed-upstream Applied upstream, thanks! Am Dienstag, den 11.06.2019, 16:05 +0200 schrieb Gianfranco Costamagna: > control: tags -1 - moreinfo > > Hello Sebastian >

Bug#930367: cloud.debian.org: vagrant images: use systemd-networkd for virtualbox provider

2019-06-11 Thread Antonio Terceiro
Control: retitle -1 vagrant images: network setup in libvirt images are not consistent with Debian defaults On Tue, Jun 11, 2019 at 04:15:12PM +0200, Nicolas Quiniou-Briand wrote: > Package: cloud.debian.org > Severity: normal > > Dear Maintainer, > > I noticed a difference between providers

Bug#771339: linux: linux-headers 3.16 Makefile contains VERSION=2 PATCHLEVEL=6

2019-06-11 Thread Fab Stz
Source: linux Version: 4.9.0 or 4.19... probably any Followup-For: Bug #771339 Dear Maintainer, This bug still exists in linux 4.9 and 4.19 (stretch, stretch-backports and also buster) Like the first reporter, I tried compiling the amdgpu driver provided by AMD (through DKMS) and it is

Bug#929821: libgd2: CVE-2019-11038: Uninitialized read in gdImageCreateFromXbm

2019-06-11 Thread Jonas Meurer
Hello, Salvatore Bonaccorso wrote: > The following vulnerability was published for libgd2. > > CVE-2019-11038[0]: > Uninitialized read in gdImageCreateFromXbm > > If you fix the vulnerability please also make sure to include the > CVE (Common Vulnerabilities & Exposures) id in your changelog

Bug#930311: lintian: Possible exception to package-contains-documentation-outside-usr-share-doc

2019-06-11 Thread Chris Lamb
Niels Thykier wrote: > If we intend to create the exception in lintian, I would personally > probably go with making the exception first and then filing the bug > against dh-r to remove the auto-generation. Good call. I've done the former task and filed the latter as #930369. Regards, --

Bug#930370: debconf: Overriding debconf db with file fails with a message "access to disallowed key Filename in restricted hash"

2019-06-11 Thread Jiri Palecek
Package: debconf Version: 1.5.71 Severity: normal Dear Maintainer, while trying to debug some difficulties with unattended package installation, I came accross an interesting problem. While debconf(7) says you can use DEBCONF_DB_OVERRIDE like this:

Bug#930369: dh-r: Please drop automated package-contains-documentation-outside-usr-share-doc Lintian override generation

2019-06-11 Thread Chris Lamb
Package: dh-r Version: 20190121 Severity: wishlist X-Debbugs-CC: lintian-ma...@debian.org Hi, In #930311, Niels Thykier mentions that he: > noticed that the dh-r package by default creates an override for > package-contains-documentation-outside-usr-share-doc when the R > package puts

Bug#905772: Not Fixed by dh* in the meantime, actually got worse in experimental

2019-06-11 Thread Christian Ehrhardt
Hi, I checked this issue for Ubuntu bug 1786179 as I wanted to drop the related delta that we formerly had. That is the same topic as https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=905772 that we discuss here. At first I thought the changes to dh_ resolved this sysV-vs-systemd fight as I've

Bug#930368: gatb-core: FTBFS due to inaccurate symbols file

2019-06-11 Thread Gilles Filippini
Source: gatb-core Version: 1.4.1+git20181225.44d5a44+dfsg-2 Severity: serious Justification: FTBFS -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, During a rebuild of gatb-core for unstable on amd64 I experienced a FTBFS at the dh_makeshlibs step: dh_makeshlibs

Bug#930367: cloud.debian.org: vagrant images: use systemd-networkd for virtualbox provider

2019-06-11 Thread Nicolas Quiniou-Briand
Package: cloud.debian.org Severity: normal Dear Maintainer, I noticed a difference between providers for the same box (debian/stretch64): * with libvirt provider, `systemd-networkd` service is enabled and started after first boot of VM. * with virtualbox provider, `systemd-networkd` service

Bug#930366: initramfs-tools: unmkinitramfs fails to unpack lz4 compressed initrd

2019-06-11 Thread Dimitri John Ledkov
Package: initramfs-tools Version: 0.133 Severity: normal Tags: patch Dear Maintainer, unmkinitramfs fails to unpack lz4 compressed initrd, ie.: $ sudo apt install initramfs-tools lz4 file $ mkinitramfs -c lz4 -o foo.img $ unmkinitramfs foo.img bar cpio: premature end of archive $ echo $? 2 I

Bug#930363: faad2: fix build with gcc-9 [patch]

2019-06-11 Thread Gianfranco Costamagna
control: tags -1 - moreinfo Hello Sebastian do you like the attached version then? :) thanks for the quick update, I think a CFLAG passed as LIB doesn't matter that much, while the opposite hurts more, but you are right, we should keep them separate indeed. thanks for pointing it out!

Bug#930350: marked as done (gnome-shell: Play/pause keyboard button stops controlling Rhythmbox/Totem)

2019-06-11 Thread Simon McVittie
Mike Crowe wrote: > It appears that functionality of the play/pause keyboard button returns to > normal if I close Google Chrome This probably means Google Chrome uses GNOME's D-Bus APIs to register itself as a media player, so that the play/pause/etc. keys can control sites like Youtube and

Bug#929469: systemd-networkd: systemd-networkd: fails with "could not set address: Permission denied"

2019-06-11 Thread Raphael Hertzog
Hi, On Wed, 05 Jun 2019, Michael Biebl wrote: > systemd-networkd.service in v241 is locked down more tightly then v232. > It might be worth a try to comment out the hardening features one by one > to see if one of them causes your problem. Thanks for the idea! I tried that but it did not help. I

Bug#930350: Not related to the Media Player Indicator extension

2019-06-11 Thread Mike Crowe
I disabled the Media Player Indicator extension in Tweaks, yet the play/pause button has just stopped working again. I probably should have mentioned earlier that I'm running on Wayland. This appears to mean that I can't try restarting gnome-shell to see if that fixes the problem. Mike.

Bug#930365: CUDA 10.1 Update 1 is now available

2019-06-11 Thread Graham Inggs
Source: nvidia-cuda-toolkit Version: 9.2.148-6 Severity: wishlist Hi Maintainers CUDA 10.1 Update 1 (10.1.168) was released at the end of May, 2019. The minimum NVIDIA driver version remains at 418.39 and support is added for Clang 8. As per the release notes [1]: "CUDA 10.1 Update 1 is a

Bug#930364: unblock: gvfs/1.38.1-5

2019-06-11 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package gvfs to fix a missing authorization check on a private D-Bus socket (no CVE ID yet). This also adds some security hardening that was applied upstream at the same

Bug#930363: faad2: fix build with gcc-9 [patch]

2019-06-11 Thread Sebastian Ramacher
Control: tags -1 + moreinfo On 2019-06-11 15:06:01, Gianfranco Costamagna wrote: > Source: faad2 > Version: 2.8.8-3 > Severity: normal > tags: patch > > Hello, looks like gcc-9 is adding wl,asneeded flag in compilation, so libs > passed as CFLAGS are not correctly > used by gcc anymore, because

Bug#930363: faad2: fix build with gcc-9 [patch]

2019-06-11 Thread Gianfranco Costamagna
Source: faad2 Version: 2.8.8-3 Severity: normal tags: patch Hello, looks like gcc-9 is adding wl,asneeded flag in compilation, so libs passed as CFLAGS are not correctly used by gcc anymore, because only LIBS is added at the end of the compilation line. The following patch fixes the issue, and

Bug#930362: new post: Help the Java Team Distribute your project!

2019-06-11 Thread Laura Arjona Reina
Package: press Severity: normal X-Debbugs-CC: debian-public...@lists.debian.org, debian-j...@lists.debian.org Hi Thanks Hans-Christoph Steiner for resuming the work on this post. This bug is the continuation of the !16 merge request in Salsa [1], I have merged the work so far, and turned the

Bug#930361: More to add

2019-06-11 Thread Brent Clark
Sorry, just to add, I used the following link to test. https://www.openwall.com/lists/oss-security/2019/06/06/1 Please read points 3 and 4 under section 'Default configuration' HTH Regards Brent Clark

Bug#930361: exim4: Further on to CVE-2019-10149

2019-06-11 Thread Brent Clark
Package: exim4 Version: 4.89-2+deb9u4 Severity: important Dear Maintainer, This is just a FYI and I sure hope its nothing. In light of CVE-2019-10149 What I did was build a vagrant instance with Exim 4.89-2+deb9u3 to replicate the POC. Please see https://pastebin.com/raw/EiLbpsH4 for

Bug#930343: libgcr410 FTCBFS: uses the wrong compiler

2019-06-11 Thread Peter 'p2' De Schrijver
Go ahead. Peter. On 2019-06-11 06:13:16 (+0200), Helmut Grohne wrote: > Source: libgcr410 > Version: 2.4.0-9.2 > Tags: patch > User: debian-cr...@lists.debian.org > Usertags: ftcbfs > > libgcr410 fails to cross build from source, because it does not pass > cross tools to make. The easiest

Bug#775029: Processed: reassign 775029 to src:trac

2019-06-11 Thread W. Martin Borgert
I assume, that the bug is not present in Debian >= 8, i.e. Trac >= 1. It has been fixed upstream seven years ago. If the bug is still present in Debian 10, please reopen.

Bug#730572: reprepro: support for ddebs (debug symbols)

2019-06-11 Thread Simon McVittie
On Sun, 20 Dec 2015 at 08:53:16 +, Niels Thykier wrote: > In the actual implementation we got live now, there are a couple of > changes though. > > * The dbgsym packages use the .deb extension For the non-Debian projects for which I developed this patch, we still need at least basic support

Bug#930360: pelican warnings when building bits.d.o in Buster

2019-06-11 Thread Laura Arjona Reina
Package: press Severity: normal X-Debbugs-CC: debian-public...@lists.debian.org Hi all I've tried to build bits.debian.org in a machine with Debian Buster (currently testing, but it will be stable soon) and I get these pelican warnings: WARNING: %s usage in TRANSLATION_FEED_ATOM is

Bug#930359: xwayland: Sluggish performance with Intel 520

2019-06-11 Thread tkoeck
Package: xwayland Version: 2:1.20.4-1 Severity: normal Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** I upgraded from Debian 9 to Debian 10. I am using a Thinkpad with a 0:02.0 VGA compatible controller: Intel Corporation HD Graphics 520 (rev

Bug#924155: icewm-common: broken-symlink /usr/share/doc/icewm-common/FAQ/index.html -> IceWM-FAQ.html

2019-06-11 Thread Thorsten Glaser
Package: icewm-common Version: 1.5.5+git20190610-1 Followup-For: Bug #924155 This bug is still pertinent, as reported by adequate. (Also, why do you upload a new upstream version to sid during deep freeze?) -- System Information: Debian Release: 10.0 APT prefers unreleased APT policy: (500,

Bug#930358: qmodbus: Qt-based ModBus master application

2019-06-11 Thread Cédric
Package: wnpp Severity: wishlist Package name: qmodbus Version : 0.3.0 Upstream Author : Karl-Heinz Reichel URL : https://github.com/ed-chemnitz/qmodbus License : GPL2+ Programming Lang: C++ Description : ModBus master GUI QModBus is a free Qt-based

  1   2   >