Bug#1012033: bullseye-pu: package gnutls28/3.7.1-5+deb11u1

2022-05-28 Thread Andreas Metzler
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Dmitry Baryshkov , gnutl...@packages.debian.org Hello, as requested in #1011246 I would like fix miscalculation of SHA384 in the SSA accelarated implementation.

Bug#1012032: fontconfig: does not respect user configuration

2022-05-28 Thread Santanu
Package: fontconfig Version: 2.13.1-4.4 Severity: important X-Debbugs-Cc: shbi...@gmail.com fontconfig does not read user specific configuration files, only ever `access(2)'es them (revealed by strace(1)) but unlike system-wide configuration never `openat(2)'s them. $ strace fc-match monospace

Bug#1012031: suricata: ftbfs on riscv64 arch, but it is ok on unmatche board

2022-05-28 Thread Bo YU
Package: suricata Version: 1:6.0.5-2 Severity: minor Tags: ftbfs User: debian-ri...@lists.debian.org Usertags: riscv64 X-Debbugs-Cc: debian-ri...@lists.debian.org Justification: fails on some buildd machines (but built successfully on real riscv64 machine) Dear Maintainer, I am verfiy the

Bug#1010857: bullseye-pu: package unrar-nonfree/1:6.0.3-1+deb11u1

2022-05-28 Thread yokota
> > Fix CVE-2022-30333 and its corresponding RC bug. ... > Please go ahead. Thanks. I was uploaded unrar-nonfree/1:6.0.3-1+deb11u1 to bullseye. -- YOKOTA Hiroshi

Bug#1012030: podman: Fails to run any container

2022-05-28 Thread Vicente Olivert Riera
Package: podman Version: 3.0.1+dfsg1-3+deb11u1 Severity: important X-Debbugs-Cc: vincent.olivert.ri...@gmail.com Dear Maintainer, Podman has stopped working (atleast for me) without having modified anything from its configuration. I simply try to run 'bash' from a Debian container, and it

Bug#1012029: RFS: jimtcl/0.81+dfsg0-2 -- small-footprint implementation of Tcl - shared library

2022-05-28 Thread Bo YU
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "jimtcl": * Package name: jimtcl Version : 0.81+dfsg0-2 Upstream Author : [fill in name and email of upstream] * URL : http://jim.tcl.tk/ * License :

Bug#1011913: haskell-swish: FTBFS: make: *** [/usr/share/cdbs/1/class/hlibrary.mk:153: build-ghc-stamp] Error 25

2022-05-28 Thread Scott Talbert
On Sat, 28 May 2022, Jonas Smedegaard wrote: Control: reassign -1 haskell-devscripts Control: retitle -1 haskell-devscripts: DEB_ENABLE_TESTS ignored Control: affects -1 haskell-swish Quoting Lucas Nussbaum (2022-05-26 21:04:50) During a rebuild of all packages in sid, [haskell-swish] failed

Bug#1012028: RFS: dirdiff/2.1-9 [ITA] -- Display and merge changes between two directory trees

2022-05-28 Thread Nilson Silva
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "dirdiff": * Package name: dirdiff Version : 2.1-9 Upstream Author : [fill in name and email of upstream] * URL : https://samba.org/ftp/paulus/ * License

Bug#1012027: RFS: tcpslice/1.5-1 [RC] -- extract pieces of and/or glue together tcpdump files

2022-05-28 Thread Bruno Naibert de Campos
Package: sponsorship-requests Severity: important X-Debbugs-Cc: bruno.naib...@gmail.com Dear mentors, I am looking for a sponsor for my package "tcpslice": * Package name: tcpslice Version : 1.5-1 Upstream Author : https://github.com/the-tcpdump-group/tcpslice/issues * URL

Bug#1011345: transition: rakudo

2022-05-28 Thread M. Zhou
On Sat, 2022-05-28 at 12:16 +0200, Sebastian Ramacher wrote: > Control: tags -1 confirmed > > On 2022-05-20 10:36:34 -0400, M. Zhou wrote: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: transition > > > > Dear release team, > >

Bug#1012026: X segfaults in OsLookupColor+0x135 after upgrade to 2:21.1.3-2+b1

2022-05-28 Thread Iustin Pop
Package: xserver-xorg-core Version: 2:21.1.3-2+b1 Severity: important After upgrading to 2:21.1.3-2+b1, X consistently segfaults with the stacktrage in the attached log. Downgrading selected packages as follows: xserver-xorg-input-evdev=1:2.10.6-2 xserver-xorg-input-mouse=1:1.9.3-1

Bug#993957: (no subject)

2022-05-28 Thread lkcl
i think i know what rhat might be. i flat-out refuse to let a mission critical piece of software developed by pottering run on systems that i manage, particularly after seeing the persistent generation of CVEs on mitre.org, and also in interactions with him where he just does not listen.

Bug#1012025: nftables.conf: trying to import nftables.conf and get unexpected meta or ip6 when trying to start

2022-05-28 Thread Tim McConnell
Package: nftables Version: 1.0.2-1 Severity: important File: nftables.conf Tags: ipv6 X-Debbugs-Cc: tmcconnell...@gmail.com Dear Maintainer, What led up to the situation? Trying to configure and enable nftables to stop ip6 neighbor discovery packets from being rejected by VPN What exactly did

Bug#1012020: trustedqsl: segfault when trying to renew station certificate

2022-05-28 Thread Rick Murphy
This is a bug introduced in TQSL 2.6. Patch to correct this attached. This will go out as part of TQSL 2.6.4. 73, -Rick On Sat, May 28, 2022 at 4:09 PM tony mancill wrote: > Package: trustedqsl > Version: 2.6.2-1 > Severity: normal > > Hi, creating this for visibility. Since I'm

Bug#1005873: [git-buildpackage/master] pq: Check if repo is clean before importing patches

2022-05-28 Thread Ian Jackson
Paul Gevers writes ("Bug#1005873: [git-buildpackage/master] pq: Check if repo is clean before importing patches"): > Control: severity -1 serious ... > Seems like the autopkgtest of dgit is now blocking progression of > git-buildpackage related to this change. Thanks for escalating this. I had

Bug#1012024: Please declare Breaks: dgit (<< 9.16~)

2022-05-28 Thread Ian Jackson
Package: git-buildpackage Version: 0.9.26 Severity: serious Hi. With recent gbp pq (as of 0.9.26), dgit needs to pass new options (well, actually, it does this via the config file so as to still work with older gbp). That's #1005873. dgit 9.16 which I have just uploaded does this (again, sorry

Bug#1011984: liblouis: CVE-2022-31783

2022-05-28 Thread Samuel Thibault
Control: severity -1 normal Hello, Salvatore Bonaccorso, le sam. 28 mai 2022 12:56:30 +0200, a ecrit: > CVE-2022-31783[0]: > | Liblouis 3.21.0 has an out-of-bounds write in compileRule in > | compileTranslationTable.c, as demonstrated by lou_trace. lou_trace takes a braille table as input,

Bug#1011168: linux-image-5.17.0-2-amd64: rebooting KVM guest crashes kernel

2022-05-28 Thread Jon
I found a matching issue on the Arch Linux forum: https://bbs.archlinux.org/viewtopic.php?id=276648 Which ultimately links to this discussion on one of the kernel mailing lists: https://lore.kernel.org/kvm/ynhalvjww6e94...@google.com/

Bug#1011666: groff 1.23.0 build dependencies will change

2022-05-28 Thread G. Branden Robinson
I need to amend my recommendations slightly. pkg-config _will_ need to remain in Build-Depends due to a very recent change in groff upstream. > 2022-05-26 G. Branden Robinson > > * bootstrap.conf: Add "pkg-config" to `buildreq`. Not having it > causes pretty horrible macro

Bug#1011331: bullseye-pu: package node-raw-body/2.4.1-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-05-28 at 22:36 +0200, Yadd wrote: > Control: tags -1 - moreinfo > > On 28/05/2022 20:53, Adam D. Barratt wrote: > > Control: tags -1 + moreinfo > > > > On Fri, 2022-05-20 at 09:47 +0200, Yadd wrote: > > > node-raw-body embeds a patch that creates a

Bug#1011331: bullseye-pu: package node-raw-body/2.4.1-2+deb11u1

2022-05-28 Thread Yadd
Control: tags -1 - moreinfo On 28/05/2022 20:53, Adam D. Barratt wrote: Control: tags -1 + moreinfo On Fri, 2022-05-20 at 09:47 +0200, Yadd wrote: node-raw-body embeds a patch that creates a Denial-of-Service vulnerability into node-express. [ Impact ] Security issue, a simple request can

Bug#1008045: bullseye-pu: package node-mermaid/8.7.0+ds+~cs27.17.17-3+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2022-03-21 at 14:09 +0100, Yadd wrote: > node-mermaid is vulnerable to XSS attack (CVE-2021-23648) > Please go ahead. Regards, Adam

Bug#1012022: fenics-basix: FTBFS during separate binary-indep build

2022-05-28 Thread Andreas Beckmann
Source: fenics-basix Version: 0.4.0-1exp1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) Hi, fenics-basix/experimental FTBFS while performing a separate binary-indep build as would be done by the buildds. You can do that manually with

Bug#1011343: WISHLIST: Offical ALL-IN-ONE images?

2022-05-28 Thread Zhang Boyang
is filtered out by "sed -i -E -e '/[a-f0-9]{32,32}/d' diff.details.txt") Best Regards, Zhang Boyangdiff -r /mnt/.disk/cd_type /groundtruth/.disk/cd_type 1c1 < bluray --- > full_cd diff -r /mnt/.disk/info /groundtruth/.disk/info 1c1 < Debian GNU/Linux 11.0.0 "Bullseye"

Bug#1011609: bogl-bterm: [PATCH] Several improvements

2022-05-28 Thread Zhang Boyang
Hi, Another small patch. :-) Best Regards, Zhang BoyangFrom ae763e89f00575e56a7242e27c9b0789c0de411e Mon Sep 17 00:00:00 2001 From: Zhang Boyang Date: Sun, 29 May 2022 02:45:32 +0800 Subject: [PATCH] Don't call FBIOPAN_DISPLAY when using the vga16fb driver When using vga16fb, there is no need

Bug#1010061: git-buildpackage: FTBFS on bookworm and sid: multiple issues

2022-05-28 Thread Ian Jackson
Guido Günther writes ("Re: Bug#1010061: git-buildpackage: FTBFS on bookworm and sid: multiple issues"): > Thanks. I did an upload a while back but now dgit's tests fail: > >https://tracker.debian.org/pkg/git-buildpackage >

Bug#1009077: bullseye-pu: minidlna/1.3.0+dfsg-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-04-06 at 21:48 +, Thorsten Alteholz wrote: > The attached debdiff for minidlna fixes CVE-2022-26505 in Bullseye. > This > CVE has been marked as no-dsa by the security team. > Please go ahead, thanks. Regards, Adam

Bug#1008268: bullseye-pu: package tigervnc/1.11.0+dfsg-2

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2022-03-25 at 19:57 +0100, Joachim Falk wrote: > This proposed update fixes two regressions: > > (i) https://bugs.launchpad.net/ubuntu/+source/tigervnc/+bug/1929790 > > * TigerVNC 1.11.0 contains a (pixel order) regression that causes >vncviewer to

Bug#1008577: bullseye-pu: golang-github-russellhaering-goxmldsig/1.1.0-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2022-03-28 at 21:51 +, Thorsten Alteholz wrote: > The attached debdiff for golang-github-russellhaering-goxmldsig fixes > CVE-2020-7711 in Bullseye. This CVE has been marked as no-dsa by the > security team. > Please go ahead. Regards, Adam

Bug#1008168: bullseye-pu: package node-url-parse/1.5.3-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2022-04-11 at 16:17 +0200, Yadd wrote: > On 24/03/2022 15:12, Moritz Mühlenhoff wrote: > > Am Wed, Mar 23, 2022 at 02:25:26PM +0100 schrieb Yadd: > > > Package: release.debian.org > > > Severity: normal > > > Tags: bullseye > > > User:

Bug#1008162: bullseye-pu: package node-minimist/1.2.5+~cs5.3.1-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-03-23 at 12:36 +0100, Yadd wrote: > node-minimist is vulnerable to a prototype pollution not totally > fixed > by CVE-2020-7598 patch (pushed in 1.2.5-1 and 1.2.0-1+deb10u1) > Please go ahead. Regards, Adam

Bug#1008153: bullseye-pu: package node-node-forge/0.10.0~dfsg-3+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-03-23 at 11:14 +0100, Yadd wrote: > node-node-forge signature verification code is lenient in checking > the digest > algorithm structure. This can allow a crafted structure that steals > padding > bytes and uses unchecked portion of the PKCS#1 encoded

Bug#1008161: bullseye-pu: package geeqie/1.6-9+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-03-23 at 12:17 +0100, Andreas Rönnquist wrote: > I would like to fix a bug in geeqie in bullseye where selecting > several > items in a file-list and then trying to deselect one item using > Ctrl+click doesn't work as it should. > Please go ahead; sorry

Bug#1012021: yarnpkg: segfault while building greenbone-security-assistant on !amd64

2022-05-28 Thread Andreas Beckmann
Package: yarnpkg Version: 1.22.19+~cs24.27.18-1 Severity: serious Tags: ftbfs Control: affects -1 + src:greenbone-security-assistant Hi, greenbone-security-assistant fails to built on most (all?) architectures except amd64. There seems to be a segmentation fault during a yarnpkg call:

Bug#1004882: crystal: switch to llvm-toolchain-13

2022-05-28 Thread Paul Gevers
Control: severity -1 serious Hi, On Fri, 1 Apr 2022 19:32:34 +0200 Paul Gevers wrote: On Wed, 2 Feb 2022 22:42:10 +0100 Sebastian Ramacher wrote: > The current default version of llvm is llvm-toolchain-13. To reduce the > number of llvm versions, please consider switchting to

Bug#1009659: bullseye-pu: package spyder/4.2.1+dfsg1-3

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-04-13 at 19:46 +0100, Julian Gilbey wrote: > The bug is reported in https://bugs.debian.org/989660 > I didn't spot it at the time because I'm only an uploader, not the > named maintainer, and had forgotten to check the BTS. Sorry about > that. The bug

Bug#1009363: bullseye-pu: package ruby-net-ssh/1:6.1.0-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2022-04-12 at 09:40 -0300, Antonio Terceiro wrote: > OpenSSH 8.8 disables RSA signatures using the SHA-1 hash algorithm, > and > that breaks clients that do not support stronger algorithms, which is > the case of the ruby-net-ssh version in bullseye. > > [

Bug#1009250: bullseye-pu: fribidi/1.0.8-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i On Sat, 2022-04-09 at 23:04 +, Thorsten Alteholz wrote: > > The attached debdiff for fribidi fixes CVE-2022-25308, CVE-2022-25309 > and > CVE-2022-25310 in Bullseye. These CVEs have been marked as no-dsa by > the > security team. This looks OK to me,

Bug#1009345: bullseye-pu: package node-moment/2.29.1+ds-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2022-04-12 at 06:39 +0200, Yadd wrote: > node-moment is vulnerable to path traversal (#1009327, CVE-2022- > 24785) > Please go ahead. Regards, Adam

Bug#1011556: dh-octave: provide dh-sequence-octave virtual package, dh_auto_install to debian/tmp

2022-05-28 Thread Rafael Laboissière
Thanks for this bug report and for the patch, Nicolas. I integrated your commits into the Git repository of the dh-package at Salsa, on a side branch called bug-1011556 [1]. I had to make a series of adjustments to your code, in order to have it working correctly, namely : *

Bug#1012020: trustedqsl: segfault when trying to renew station certificate

2022-05-28 Thread tony mancill
Package: trustedqsl Version: 2.6.2-1 Severity: normal Hi, creating this for visibility. Since I'm experiencing the issue, I will try to resolve it. Also (not related to this bug), I have an update to upstream 2.6.3 ready to upload. I am planning to wait until the auto-openssl transition

Bug#1011146: hipercontracer is marked for autoremoval from testing

2022-05-28 Thread Thomas Dreibholz
Hi, I get the autoremoval notification (see below) for my HiPerConTracer package. HiPerConTracer clearly has no dependency on anything related to NVIDIA drivers. It is a set of simple shell tools. There is probably something wrong with the autoremoval script. Den 26.05.2022 07:02, skrev

Bug#1011146: bibtexconv is marked for autoremoval from testing

2022-05-28 Thread Thomas Dreibholz
Hi, I get the autoremoval notification (see below) for my BibTeXConv package. BibTeXConv clearly has no dependency on anything related to NVIDIA drivers. It is a set of simple shell tools. There is probably something wrong with the autoremoval script Den 26.05.2022 06:40, skrev Debian

Bug#1011146: netperfmeter is marked for autoremoval from testing

2022-05-28 Thread Thomas Dreibholz
Hi, I get the autoremoval notification (see below) for my NetPerfMeter package. NetPerfMeter clearly has no dependency on anything related to NVIDIA drivers. It is a set of simple shell tools. There is probably something wrong with the autoremoval script. Den 26.05.2022 07:27, skrev Debian

Bug#1011146: rsplib is marked for autoremoval from testing

2022-05-28 Thread Thomas Dreibholz
Hi, I get the autoremoval notification (see below) for my RSPLIB package. RSPLIB clearly has no dependency on anything related to NVIDIA drivers. There is probably something wrong with the autoremoval script. Den 26.05.2022 07:48, skrev Debian testing autoremoval watch: rsplib 3.4.1-1 is

Bug#1011146: subnetcalc is marked for autoremoval from testing

2022-05-28 Thread Thomas Dreibholz
Hi, I get the autoremoval notification (see below) for my SubNetCalc package. SubNetCalc clearly has no dependency on anything related to NVIDIA drivers. It is a simple shell tool. There is probably something wrong with the autoremoval script. Den 26.05.2022 07:57, skrev Debian testing

Bug#1010857: bullseye-pu: package unrar-nonfree/1:6.0.3-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2022-05-12 at 02:31 +0900, yokota wrote: > Fix CVE-2022-30333 and its corresponding RC bug. > > [ Impact ] > CVE-2022-30333 is directory traversal vulnerability. > It write to files during an extract operation on outside of > extraction > directory. >

Bug#1010924: bullseye-pu: package node-eventsource/1.0.7-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2022-05-13 at 11:30 +0200, Yadd wrote: > node-eventsource is vulnerable to sensible headers exposure > (CVE-2022-1650) > FWIW, you mean sensitive. :-) Please go ahead. Regards, Adam

Bug#1010531: bullseye-pu: package ldap-account-manager/7.4-1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2022-05-03 at 20:18 +0200, Roland Gruber wrote: > Package: release.debian.org > Severity: important > p-u requests are always "normal" severity. (Fixed earlier.) [...] > Stored XSS and arbitrary image read vulnerability. > See >

Bug#1010439: bullseye-pu: package node-sqlite3/5.0.0+ds1-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-05-01 at 17:34 +0200, Yadd wrote: > node-sqlite3 is vulnerable to denian of service (CVE-2022-21227) > Please go ahead. Regards, Adam

Bug#1010383: bullseye-pu: package node-ejs/2.5.7-3+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-04-30 at 09:11 +0200, Yadd wrote: > node-ejs is vulnerable to server-side template injection > (CVE-2022-29078, #1010359) and probably to prototype pollution. > Please go ahead. Regards, Adam

Bug#1010304: bullseye-pu: package freetype/2.10.4+dfsg-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed d-i On Thu, 2022-04-28 at 22:21 +1000, Hugh McMaster wrote: > This update fixes three security vulnerabilities in FreeType > 2.10.4+dfsg-1. > > - CVE-2022-27404: heap buffer overflow via invalid integer decrement > in > sfnt_init_face() and woff2_open_font(). > -

Bug#1010050: bullseye-pu: package clementine/1.4.0~rc1+git347-gfc4cb6fc7+dfsg-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-04-23 at 10:25 +0200, Florian Ernst wrote: > Clementine fails to start if the package libqt5sql5-sqlite is not > installed, i.e. clementine is missing a Depends. This was reported in > #1008312, an identical fix has already been uploaded to Unstable. > >

Bug#1010211: bullseye-pu: package grunt/1.3.0-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2022-04-26 at 16:42 +0200, Yadd wrote: > grunt is vulnerable to path traversal > Please go ahead. Regards, Adam

Bug#1009726: bullseye-pu: package samba/2:4.13.13+dfsg-1+deb11u4

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2022-04-15 at 17:12 +0300, Michael Tokarev wrote: > Here's the proposed samba package update for bullseye. > I picked up a few patches which were missing when we > did security updates: we only picked up the security- > related patches from upstream but missed

Bug#1012016: libapache-poi-java breaks octave-io autopkgtest: assert (size (d) == [1001, 2]) failed

2022-05-28 Thread Paul Gevers
Source: libapache-poi-java, octave-io Control: found -1 libapache-poi-java/4.0.1-4 Control: found -1 octave-io/2.6.4-1 Severity: serious Tags: sid bookworm User: debian...@lists.debian.org Usertags: breaks needs-update Dear maintainer(s), With a recent upload of libapache-poi-java the

Bug#1012015: breezy: FTBFS: error: can't find Rust compiler

2022-05-28 Thread Andreas Beckmann
Source: breezy Version: 3.3.0~bzr7571-1 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) breezy/experimental did FTBFS on all architectures: https://buildd.debian.org/status/package.php?p=breezy=experimental debian/rules clean dh clean

Bug#1011957: aideinit fails in amanda-server processing

2022-05-28 Thread Hannes von Haugwitz
Hello Barry, On Sat, May 28, 2022 at 11:34:44AM -0500, Barry Trent wrote: > Yes! Removing all blank (and "#" comment) lines from disklist solved the > problem on 3 different machines. > > So you've found the issue but, of course, blanks and comments are valid in > the disklist and are even

Bug#1012014: r8125: fails to build module for Linux 5.17

2022-05-28 Thread Andreas Beckmann
Source: r8125 Version: 9.007.01-3 Severity: serious Tags: ftbfs Justification: fails to build from source Hi, since autopkg tests now actually attempt to build kernel modules, we quickly see that this does not work for Linux 5.17:

Bug#1011942: bullseye-pu: package php-guzzlehttp-psr7/1.7.0-1+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2022-05-27 at 14:19 +0200, David Prévot wrote: > The security team asked me to address #1008236 [CVE-2022-24775] via a > point release, so here I am. > Please go ahead. Regards, Adam

Bug#1011426: bullseye-pu: package tcpdump/4.99.0-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-05-22 at 16:51 +, Romain Francoise wrote: > I would like to update the AppArmor profile for tcpdump in bullseye > to > match the one in bookworm; the changes don't really qualify for a > stable > update per se, but they are trivial and would be

Bug#1011331: bullseye-pu: package node-raw-body/2.4.1-2+deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Fri, 2022-05-20 at 09:47 +0200, Yadd wrote: > node-raw-body embeds a patch that creates a Denial-of-Service > vulnerability into node-express. > > [ Impact ] > Security issue, a simple request can crash any express application > > [ Tests ] > I added a test that

Bug#1011271: bullseye-pu: package nvidia-graphics-drivers-legacy-390xx/390.151-1~deb11u1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2022-05-19 at 12:46 +0200, Andreas Beckmann wrote: > I'd like to update nvidia-graphics-drivers-legacy-390xx/non-free to a > new > upstream release fixing some CVEs. > > It comes with the same packaging fixes and improvements that already > reached stable in

Bug#1012013: yaru-theme: Don't use Canonical Ltd. logo in application menu icon on non-Ubuntu distros

2022-05-28 Thread Mike Gabriel
Package: src:yaru-theme Severity: important The Yaru theme comes with an application menu icon that uses the Ubuntu (3-dots-on-a-circle) logo. This is inappropriate for non-Ubuntu distributions and should be amended for yaru-theme in Debian. Greets, Mike -- DAS-NETZWERKTEAM c\o Technik-

Bug#1011022: bullseye-pu: package htmldoc/1.9.11-4+deb11u3

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-05-15 at 16:40 +0200, Håvard Flaget Aasen wrote: > Fixes three CVE's CVE-2022-24191, CVE-2022-27114 and CVE-2022-28085 > > [ Reason ] > One minor issue, two unimportant, still nice to have them all fixed > at > the same time. > > [ Impact ] > Images is

Bug#1011198: bullseye-pu: package needrestart/3.5-4+deb11u2

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-05-18 at 08:47 +0200, Patrick Matthäi wrote: > we require a small update for stable of needrestart to fix #1005953 > This update already includes the security update from yesterday (3.5- > 4+deb11u1), > to be on the safe side I attached the full debdiff

Bug#1010963: bullseye-pu: package nginx/1.18.0-6.1

2022-05-28 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-05-14 at 09:11 +0200, Jan Mojzis wrote: > fixes ALPACA attack CVE-2021-3618: > ALPACA is an application layer protocol content confusion attack, > exploiting TLS servers implementing different protocols but using > compatible certificates, such as

Bug#1011626: Nearly no icons since several releases

2022-05-28 Thread Mattia Rizzolo
Control: close -1 On Sat, May 28, 2022 at 08:04:28PM +0100, Klaus Ethgen wrote: > Am Sa den 28. Mai 2022 um 19:20 schrieb Mattia Rizzolo: > > I wonder what happened that didn't update that file. > > Me too. As the last update was on 2022-05-01 which obviosly did not add > the svg format. I can

Bug#1012012: RFS: libcaca/0.99.beta19-3 [QA] -- text mode graphics utilities

2022-05-28 Thread Fabio Fantoni
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "libcaca":  * Package name    : libcaca    Version : 0.99.beta19-3    Upstream Author : Sam Hocevar  * URL : http://caca.zoy.org/wiki/libcaca  * License : [fill

Bug#1011626: Nearly no icons since several releases

2022-05-28 Thread Klaus Ethgen
Hi, Am Sa den 28. Mai 2022 um 19:20 schrieb Mattia Rizzolo: > > > If it is, then also check that > > > /usr/lib/x86_64-linux-gnu/gdk-pixbuf-2.0/2.10.0/loaders.cache contains > > > the same entry. > > > > Nope, that is NOT including a similar section. > > > > ~> grep -c svg

Bug#1012011: recap: errors on Cron job

2022-05-28 Thread Tim McConnell
Package: recap Version: 2.1.0-1 Severity: normal X-Debbugs-Cc: tmcconnell...@gmail.com Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation?running cron job * What exactly did you do (or not do) that was effective

Bug#1010349: librecad: CVE-2021-21897 - heap-based buffer overflow loading a DXF file via embedded dxflib

2022-05-28 Thread Sylvain Beucler
Hello Neil, I'm triaging this vulnerability for Debian LTS / stretch. It appears librecad is not affected (all dists): - the package uses system dxflib, cf. debian/patches/debian_build.patch - while there appears to be similar vulnerable code in libraries/jwwlib/src/dl_jww-copy.cpp (grep for

Bug#1012010: matrix-hydrogen: build-depends on no longer available node-commander (< 7)

2022-05-28 Thread Andreas Beckmann
Source: matrix-hydrogen Version: 0.1.30~dfsg-1 Severity: serious Tags: ftbfs Justification: fails to build from source Hi, matrix-hydrogen can no longer be built since one of its Build-Depends has moved on: The following packages have unmet dependencies: builddeps:matrix-hydrogen : Depends:

Bug#1011365: nvidia-cuda-toolkit 11.2.2-3+deb11u2 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1011365 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: nvidia-cuda-toolkit

Bug#994622: network-manager 1.30.6-1+deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 994622 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: network-manager Version:

Bug#1011939: hdmi2usb-mode-switch 0.0.1-2+deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1011939 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: hdmi2usb-mode-switch

Bug#1003713: libtgowt 0~git20210627.91d836d+dfsg-3~deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1003713 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: libtgowt Version:

Bug#1000355: nano 5.4-2+deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1000355 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: nano Version: 5.4-2+deb11u1

Bug#1011626: Nearly no icons since several releases

2022-05-28 Thread Mattia Rizzolo
On Wed, May 25, 2022 at 04:09:51PM +0100, Klaus Ethgen wrote: > > Regardless, please try running: > > /usr/lib/x86_64-linux-gnu/gdk-pixbuf-2.0/gdk-pixbuf-query-loaders > > and verify that you have a section such as this: > > It is included and looks like the section you posted. That's good.

Bug#1011359: python-scrapy 2.4.1-2+deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1011359 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: python-scrapy Version:

Bug#1011287: orca 3.38.2-2 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1011287 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: orca Version: 3.38.2-2

Bug#1003261: postfix 3.5.13-0+deb11u1 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1003261 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: postfix Version:

Bug#1003713: telegram-desktop 3.1.1+ds-1~deb11u2 flagged for acceptance

2022-05-28 Thread Adam D Barratt
package release.debian.org tags 1003713 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details == Package: telegram-desktop Version:

Bug#1012008: Updating the build-essential-mipsen Uploaders list

2022-05-28 Thread Tobias Frost
Source: build-essential-mipsen Version: 12.9 Severity: minor User: m...@qa.debian.org Usertags: mia-teammaint Scott James Remnant has retired, so can't work on the build-essential-mipsen package anymore (at least with this address). We are tracking their status in the MIA team and would like to

Bug#1012007: Updating the build-essential Uploaders list

2022-05-28 Thread Tobias Frost
Source: build-essential Version: 12.9 Severity: minor User: m...@qa.debian.org Usertags: mia-teammaint Scott James Remnant has retired, so can't work on the build-essential package anymore (at least with this address). We are tracking their status in the MIA team and would like to ask you to

Bug#1011962: librust-serde+derive-dev: Installation is broken

2022-05-28 Thread Jonas Smedegaard
Package: librust-serde+derive-dev Version: 1.0.130-2 Followup-For: Bug #1011962 This bug exists in version 1.0.130-2 of librust-serde+derive-dev. Please close with the version that actually solves the reported issue. - Jonas

Bug#1002382: nbsphinx: FTBFS: AttributeError: module 'mistune' has no attribute 'BlockGrammar'

2022-05-28 Thread Dmitry Shachnev
Control: reassign -1 src:nbconvert 6.1.0-1 Control: unarchive 1002372 Control: forcemerge 1002372 -1 Control: archive 1002372 On Wed, Dec 22, 2021 at 09:05:08AM +0100, Lucas Nussbaum wrote: > Source: nbsphinx > Version: 0.8.7+ds-1 > Severity: serious > Justification: FTBFS > Tags: bookworm sid

Bug#1011510: dpkg-statoverride does *not* run chmod

2022-05-28 Thread Guillem Jover
Hi! On Tue, 2022-05-24 at 09:36:45 +0200, Harald Dunkel wrote: > Package: dpkg > Version: 1.20.9 > Severity: wishlist > To avoid confusion the man page to dpkg-statoverride should > mention explicitly that it does *not* run chmod or others to > actually change the access permissions to already

Bug#1010663: RFS: strawberry/1.0.4-1 [ITP] -- Audio player and music collection organizer

2022-05-28 Thread Jeroen Ploemen
Paul, Thomas, thanks for digging up the old reject. Peter, I did some more digging and found one unresolved copyright issue from my previous comment as well as some fresh ones: * copyright holder Pascal Below for various scrobbler-related files is still missing * copyright holder Nick Lanham

Bug#987324: rust-hashbrown: missing ahash feature makes building hashlink crate impossible

2022-05-28 Thread Jonas Smedegaard
Quoting Jonas Smedegaard (2022-05-28 16:18:26) > Quoting peter green (2022-05-28 14:49:00) > > > Package rust-ahash is now in Debian, which should help fix this bug. > > > > > > - Jonas > > > > > > I looked but the new packages don't seem to be installable. > > > > > 2 binary packages have

Bug#1011191: dpkg: let buildinfo record whether host architecture binaries can be executed when cross-compiling

2022-05-28 Thread Guillem Jover
Hi! On Wed, 2022-05-18 at 07:26:02 +0200, Johannes Schauer Marin Rodrigues wrote: > Package: dpkg > Version: 1.21.7 > Severity: wishlist > Tags: patch > X-Debbugs-Cc: jo...@debian.org > when cross compiling, one property of the build system that can > influence the contents of the generate

Bug#1012006: Updating the genetic Uploaders list

2022-05-28 Thread Tobias Frost
Source: genetic Version: 0.1.1b+git20170527.98255cb-3 Severity: minor User: m...@qa.debian.org Usertags: mia-teammaint Angel Ramos has not been working on the genetic package for quite some time. We are tracking their status in the MIA team and would like to ask you to remove them from the

Bug#1011973: node-webpack-sources: autopkgtest failure TypeError: addMapping is not a function

2022-05-28 Thread Akshay S Dinesh
with node-source-map 0.7 built from salsa master branch, there is only 1 failure. 26 tests were failing earlier with node-source-map 0.6. This is a red herring. The autopkgtest fails aren't related to node-source-map at all. Specifically, the tests don't fail in gbp buildpackage, but

Bug#941825: syncthing: 2Gb index-v0.14.0.db

2022-05-28 Thread Nicholas D Steeves
Control: tag -1 -moreinfo Hi Sergio, First, sorry it took me so long to follow up on this bug! [this reply has been sitting in my drafts folder for almost two years :/] With the info you've provided it looks like the issue has been resolved. Rebuilding the index was a good idea :-) That said,

Bug#1009332: maxima-emacs: Imaxima fails to render latex

2022-05-28 Thread Camm Maguire
tags 1009332 +unreproducible thanks Greetings, and thanks for your report. Just tested in a fresh chroot, and all works fine once ghostscript is installed, which is a dependency issue that needs addressing. This would not account for your latex error. More log info please if this is still

Bug#1004658: [Pkg-javascript-devel] Bug#1004658: Bug#1004658: Help to compile a wasm package

2022-05-28 Thread Akshay S Dinesh
anywhere else). The job is done (see debian/rules), we just have to find the good dependencies and fix the build since built wasm isn't exactly what upstream embeds in node-source-map, maybe some unpublished work... I'm not exactly sure if the build is broken. The artifact generated by the

Bug#939229: closed by Dmitry Smirnov (Bug#939229: fixed in golang-gogoprotobuf 1.3.0-1)

2022-05-28 Thread Nicholas D Steeves
Control: affects -1 src:syncthing This bug has not affected syncthing since the following upload: syncthing (1.12.1~ds1-2) unstable; urgency=medium * golang-gogoprotobuf-dev -> golang-github-gogo-protobuf-dev. -- Alexandre Viau Thu, 04 Feb 2021 11:26:39 -0500 Cheers, Nicholas

Bug#1012004: srpc: Unorthodox binary package content organization

2022-05-28 Thread Guillem Jover
Source: srpc Source-Version: 0.9.6-1 Severity: normal Hi! This package has a rather unorthodox package contents organization. There are two binary packages generated: a) libsrpc-dev: Contains the usual headers (but no .a archive nor .so symlink or linker script). b) libsrpc: Is an

Bug#1011957: aideinit fails in amanda-server processing

2022-05-28 Thread Barry Trent
Yes! Removing all blank (and "#" comment) lines from disklist solved the problem on 3 different machines. So you've found the issue but, of course, blanks and comments are valid in the disklist and are even present in the disklist installed as a sample with amanda-server in DailySet1. I had

Bug#857018: schroot: Setup script not running, --session-name not working

2022-05-28 Thread Christoph Biedl
Control: tags 857018 moreinfo Mike Hommey wrote... > I installed a new machine some time ago, and setup schroot for the first > time on it... Hi, it's been a while, and I failed to reproduce your report. Can you please check whether the problems still exist on your side? Quite frankly, this

  1   2   >