Bug#739293: RFP: dudle -- privacy-enhanced web-based event scheduling

2017-12-21 Thread Johannes Schauer
Control: retitle -1 ITP: dudle -- privacy-enhanced web-based event scheduling Control: owner -1 jo...@debian.org The project is now nearly 10 years old and still alive and kicking. I used to have it installed on my server in the past but now I wanted to properly package it for Debian. Especially

Bug#884905: graphicsmagick: CVE-2017-17782: heap-based buffer over-read in ReadOneJNGImage

2017-12-21 Thread Salvatore Bonaccorso
Source: graphicsmagick Version: 1.3.27-1 Severity: important Tags: patch security upstream Forwarded: https://sourceforge.net/p/graphicsmagick/bugs/530/ Hi, the following vulnerability was published for graphicsmagick. CVE-2017-17782[0]: | In GraphicsMagick 1.3.27a, there is a heap-based buffer

Bug#881097: To be removed from wheezy as well

2017-12-21 Thread Chris Lamb
Hi Raphael, > would still be nice to see what it involves to actually update the > Packages* files when we want to remove a source package. Indeed. I had a poke but I'm afraid I'm not terribly «au fait» with that part of dak and related infrastructure… Thorsten, do you have any pointers or

Bug#884909: ITP: subethasmtp -- Java library for receiving SMTP mail

2017-12-21 Thread Christopher Hoskin
Package: wnpp Severity: wishlist Owner: Christopher Hoskin * Package name: subethasmtp Version : 4.0 Upstream Author : David Moten * URL : https://github.com/davidmoten/subethasmtp * License : Apache-2.0

Bug#694081: carnivore: should not import name from revoked gpg key

2017-12-21 Thread Christoph Berg
Re: Gürkan Myczko 2017-12-18 <744486b1512e878ce59eb3e507812...@phys.ethz.ch> > Hi Bart and Duck > > I think I have a similar issue. Is it possible to fix my qa page as well? The issue here is within your packages, I think: $ grep Sengün deb_debian_dists_sid_main_source_Sources | sort | uniq -c

Bug#884908: Nepali Keyboard Layout incomplete.

2017-12-21 Thread Sagar Chalise
Package: xkb-data Version: 2.19-1.1 The symbols file located at '/usr/share/X11/xkb/symbols/np' doesnot seem to work for zero width joiner. The 'equal' key in line 22 should work as zero width joiner. 'पर्=यो' is the output while it should be 'पर्‍यो' । The workout seems to be replacing

Bug#881097: To be removed from wheezy as well

2017-12-21 Thread Raphael Hertzog
On Tue, 19 Dec 2017, Emilio Pozuelo Monfort wrote: > > Chris or Thorsten, could you possibly look into what it involves and see > > whether > > it's doable on the ftpmaster side ? > > Another, easier option would be to declare these packages as unsupported > security-wise. I pushed a commit

Bug#884911: ohcount: Please update the Homepage to point to GitHub and package version 3.1.0

2017-12-21 Thread Raphaël Hertzog
Source: ohcount Severity: normal When I tried to triage the last security issue, I went through sourceforge but it looks like the project is abandoned there. You should replace that URL with https://github.com/blackducksoftware/ohcount which is where developement is happening nowadays. There's a

Bug#884904: graphicsmagick: CVE-2017-17783: buffer over-read in ReadPALMImage

2017-12-21 Thread Salvatore Bonaccorso
Source: graphicsmagick Version: 1.3.27-1 Severity: normal Tags: patch security upstream Forwarded: https://sourceforge.net/p/graphicsmagick/bugs/529/ Hi, the following vulnerability was published for graphicsmagick, this is basically to track the upstream source fix as we build with

Bug#884897: dbus-x11: .xinitrc requires "dbus-update-activation-environment --all"

2017-12-21 Thread Simon McVittie
Control: tags -1 + moreinfo On Thu, 21 Dec 2017 at 01:34:32 -0200, Carlos Eduardo M. Santos wrote: > The following problems started after dist-upgrading from jessie to buster I hope you upgraded from jessie to stretch first, and then from stretch to buster. Upgrades that skip a release are not

Bug#884906: bugs.debian.org: user defined key=value pairs

2017-12-21 Thread Andreas Beckmann
Package: bugs.debian.org Severity: wishlist [There had been some previous discussion around Debconf17 ... finally filing the corresponding wishlist bug.] For the BTS I'd like to have something like userdefined "key=value" pairs - an extension to the existing usertags (which only allow to add

Bug#884907: debian-security-support: Please mark jasperreports as unsupported

2017-12-21 Thread Raphaël Hertzog
Package: debian-security-support Severity: normal Looking at the discussion in #880467, it seems to me that we should mark jasperreports as unsupported. -- System Information: Debian Release: buster/sid APT prefers oldoldstable APT policy: (500, 'oldoldstable'), (500, 'unstable'), (500,

Bug#884910: libjs-requirejs: does not install script ‘r.js’

2017-12-21 Thread Ben Finney
Package: libjs-requirejs Version: 2.3.2-1 Severity: normal The package description says: This package also provides a script r.js, that has two major functions […] The file ‘r.js’ is not installed by this package. It should, by that description, be installed as

Bug#883764: lintian: false positive for source-includes-file-in-files-excluded

2017-12-21 Thread Chris Lamb
Hi, FYI these patch-system related false-positives are being tracked here: https://bugs.debian.org/884848 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#882372: Processed: Bug fix for ohcount #882372

2017-12-21 Thread Raphael Hertzog
Hello Sylvestre, On Thu, 07 Dec 2017, Sylvestre Ledru wrote: > I don't see the patch fixing the issue?! The debian security tracker has a note with this patch: https://github.com/blackducksoftware/ohcount/commit/6bed45d6fb7c080ae5c163c12b4eb8749a3492ac It looks like the problematic "file"

Bug#884922: Support cleartext signed InRelease files with CRLF line endings

2017-12-21 Thread Lukas Wunner
Package: apt Version: 0.8.15.2 Severity: important Tags: patch Commit 89c4c588b275 ("fix from David Kalnischkies for the InRelease gpg verification code (LP: #784473)") amended verification of cleartext signatures by a check whether the file to be verified actually starts with "-BEGIN PGP

Bug#884747: Info received (Bug#884747: fails to start when .config is a symlink, with misleading error message about permissions)

2017-12-21 Thread Rene Engelhard
found 884747 1:5.4.3-1 close 884747 1:5.4.3-3 thanks On Tue, Dec 19, 2017 at 05:07:55PM +0100, Rene Engelhard wrote: > On Tue, Dec 19, 2017 at 11:52:22AM -0400, Joey Hess wrote: > > Disabling apparmor avoids this bug. > > As I guessed. As it's disabled per default, can we close this bug? Let's

Bug#788100: The bug is still there on new version

2017-12-21 Thread Apostolos Kefalas
On Sun, 14 Jun 2015 20:59:26 +0200 Eric Valette wrote: > On 14/06/2015 11:49, Eric Valette wrote: > > On 14/06/2015 11:35, Tobias Grimm wrote: > > > >> I'm afraid there's nothing I can do right now. Upstream probably will not > >> create a workaround and I can't do this

Bug#884917: nvidia-driver: Black screen after SDDM login

2017-12-21 Thread MH
Package: nvidia-driver Version: 384.98-3 Severity: important Dear Maintainer, Video is broken when passed from PC through AVR. No problem when video is passed directly to TV using the same HDMI cabling. Hardware setup as follows: HTPC>HDMI>AVR>HDMI>HDTV Black screen after logging in via SDDM.

Bug#884893: newsboat: FTBFS: Error opening terminal: unknown.

2017-12-21 Thread Nikos Tsipinakis
Control: tags -1 pending fixed-upstream Bug has been fixed upstream, upload pending until I figure out how to handle the other 3 open bugs.

Bug#884787: apparmor-profiles-extra: Pidgin fails to load plugin from home directory

2017-12-21 Thread intrigeri
Control: tag -1 + upstream Control: tag -1 + patch Hi Adrian, Adrian Heine: > Dez 19 19:04:05 kernel: audit: type=1400 audit(1513706645.170:80): > apparmor="DENIED" operation="file_mmap" profile="/usr/bin/pidgin" > name="~/.purple/plugins/lurch.so" pid=11948 comm="pidgin" requested_mask="m" >

Bug#880665: "transfered" is wrong, but not complained about

2017-12-21 Thread Rene Engelhard
reassogn 880665 hunspell-en-us found 880665 20070829-7 close 880665 1:2017.08.24 thanks Hi, On Fri, Nov 03, 2017 at 02:51:17PM +0100, Leon Meier wrote: > 1. Open a fresh document. > 2. Type in "transfered". > 3. Mark the word as English (USA). > 4. Run the spellchecker. > > Observe that no

Bug#884921: wrong version, misses debian revision

2017-12-21 Thread Rene Engelhard
Package: hunspell-en-us,hunspell-en-ca,hunspell-en-au Version: 1:2017.08.24 Severity: important Tags: patch Hi Don, hunspell-en-us | 1:2017.08.24 | testing| all hunspell-en-us | 1:2017.08.24 | unstable | all looks very wrong compares to wamerican | 2017.08.24-1

Bug#880665: "transfered" is wrong, but not complained about

2017-12-21 Thread Rene Engelhard
On Thu, Dec 21, 2017 at 01:27:09PM +0100, Leon Meier wrote: > On 21.12.2017 13:25, Rene Engelhard wrote: > > reassogn 880665 hunspell-en-us > > > You probably wanted to say "reassign", not "reassogn"... Yeah.. Regards, Rene

Bug#882531: xorg-server FTCBFS: assumes CLOCK_MONOTONIC to be unavailable

2017-12-21 Thread Emilio Pozuelo Monfort
Hi Helmut, On 23/11/17 19:33, Helmut Grohne wrote: > Source: xorg-server > Version: 2:1.19.5-1 > Tags: patch upstream > User: helm...@debian.org > Usertags: rebootstrap > > xorg-server fails to cross build from source, because its configure > checks for CLOCK_MONOTONIC with AC_RUN_IFELSE and

Bug#884916: /usr/bin/ddrescue: An option to append to the ddrescue.log file when recovering partitions one by one

2017-12-21 Thread Veek M
Package: gddrescue Version: 1.21-1 Severity: important File: /usr/bin/ddrescue Dear Maintainer, This is important. My disk had crashed and about 132KB of sectors were damaged: http://pix.toile-libre.org/upload/original/1513821694.png I decided to recover my data, partition by partition sdc4,

Bug#884915: firejail-profiles: conffiles not removed

2017-12-21 Thread Paul Wise
Package: firejail-profiles Version: 0.9.52-1 Severity: normal User: debian...@lists.debian.org Usertags: obsolete-conffile adequate The recent upgrade did not deal with obsolete conffiles properly. Please use the dpkg-maintscript-helper support provided by dh_installdeb to remove these obsolete

Bug#884866: Bug#884867: Package libspreadsheet-readsxc-perl is ready

2017-12-21 Thread Andrius Merkys
Dear Gregor, I have implemented your suggestions for the package libspreadsheet-readsxc-perl. Could you please review it once more to make sure that I have done everything correctly? PS: I have removed points from TODO as I moved on with the corrections. Many thanks for help! Andrius On

Bug#853783: Reopen 853783

2017-12-21 Thread Svante Signell
On Wed, 2017-12-13 at 23:24 +, Brian Potkin wrote: > On Wed 13 Dec 2017 at 22:17:27 +0100, Svante Signell wrote: > > > reopen 853783 > > thanks > > > > Since I have not obtained a mail from you about the scanner problems since > > Tue, > > 28 Feb 2017 I reopen this bug. Your replies have not

Bug#874662: Pending fixes for bugs in the libxmlrpc3-java package

2017-12-21 Thread pkg-java-maintainers
tag 874662 + pending thanks Some bugs in the libxmlrpc3-java package are closed in revision 354053c99c6584856354a02baca1048496882abf in branch 'master' by Markus Koschany The full diff can be seen at https://anonscm.debian.org/cgit/pkg-java/libxmlrpc3-java.git/commit/?id=354053c Commit message:

Bug#884912: global: CVE-2017-17531 possible command injection

2017-12-21 Thread Raphael Hertzog
Package: global X-Debbugs-CC: t...@security.debian.org secure-testing-t...@lists.alioth.debian.org Severity: important Tags: security Hi, the following vulnerability was published for global. CVE-2017-17531[0]: | gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before | launching the

Bug#768073: [pkg-lxc-devel] Bug#768073: LXD packaging

2017-12-21 Thread Evgeni Golov
Hi, On Wed, Dec 20, 2017 at 05:59:42PM +0100, Clément Hermann wrote: > On 17/12/2017 21:39, Clément Hermann wrote: > > > On 04/12/2017 21:40, Clément Hermann wrote: > >> So, I did some work on golang-gopkg-flosch-pongo2 > >>

Bug#855879: Please add blapi.h to libnss3-dev

2017-12-21 Thread Timo Aaltonen
On 14.06.2017 01:27, Timo Aaltonen wrote: > On 23.02.2017 00:14, Mike Hommey wrote: >> On Wed, Feb 22, 2017 at 09:51:50PM +0200, Timo Aaltonen wrote: >>> Package: libnss3-dev >>> Severity: normal >>> >>> Hi, I need to package nss-pem for certmonger to actually be able to >>> renew certificates,

Bug#863663: Letter to Santa

2017-12-21 Thread Sebastian Dröge
On Wed, 2017-12-20 at 23:57 +0100, Francesco Poli wrote: > > ;-) > > Seriously: is there any progress (not documented on the bugzilla > bug)? Please let me know. The mailing list is no bug tracker and mails like this are not going to motivate anybody, and at least in my case got rid of any

Bug#812228: what if $DPKG_MAINTSCRIPT_ARCH is empty

2017-12-21 Thread Piotr Ożarowski
FTR: (as I had to dig into my branch comments to see why I didn't merge it) What if $DPKG_MAINTSCRIPT_ARCH is empty?

Bug#883949: ntp: no info how to fix the access to a local DCF clock blocked by apparmor

2017-12-21 Thread intrigeri
Hi Peter, Peter Marschall: > Please be so kind to mention the above file and the tunable NTPD_DEVICE > in README.Debian or NEWS.Debian to help people like me with local clocks. Good idea. Would you be so kind to propose something, even a rough draft? I think you're almost there already, only

Bug#884919: O: quagga -- network routing daemons (metapackage)

2017-12-21 Thread Scott Leggett
Package: wnpp Severity: normal I intend to orphan the quagga package, as I no longer have the interest or time required to keep the package in good shape. Note that quagga has recently been forked upstream [0]. [0] https://lwn.net/Articles/718859/ The package description is: GNU Quagga is

Bug#753839: texlive-fonts-extra: Please split Open Sans and either Raleway or all League fonts into separate packages

2017-12-21 Thread Rene Engelhard
unarchive 753839 reopen 753839 thanks Hi, I disagree, but let's not get into that. (In LO I stand the completely opposite position - I am not going to ship fonts. The only exception is the LO-(internal)-developed OpenSymbol) You yourself say in the bug: "If anyone wants to package the fonts

Bug#884909: Pending fixes for bugs in the subethasmtp package

2017-12-21 Thread pkg-java-maintainers
tag 884909 + pending thanks Some bugs in the subethasmtp package are closed in revision 36e9355cf837accf1e4163f0b546d8a61e3ceea4 in branch 'master' by Christopher Hoskin The full diff can be seen at https://anonscm.debian.org/cgit/pkg-java/subethasmtp.git/commit/?id=36e9355 Commit message:

Bug#884914: apt: does not deal well with high request latency web servers

2017-12-21 Thread Philipp Kern
Source: apt Severity: wishlist X-Debbugs-Cc: ma...@debian.org At work our packages and package lists are served by a web service that has relatively high time to first byte latency. Once it starts transmitting the bytes are pushed in a fast way but fetching the bytes in the first place takes a

Bug#884913: node-gulp-babel: fails immediately because of undeclared dependency “babel-core”

2017-12-21 Thread Ben Finney
Package: node-gulp-babel Version: 7.0.0-2 Severity: serious Justification: Policy 3.5 Attempting to run a Gulp build that uses ‘gulp-babel’ fails immediately: = module.js:327 throw err; ^ Error: Cannot find module 'babel-core' at

Bug#880665: "transfered" is wrong, but not complained about

2017-12-21 Thread Leon Meier
On 21.12.2017 13:25, Rene Engelhard wrote: reassogn 880665 hunspell-en-us You probably wanted to say "reassign", not "reassogn"...

Bug#883698: freetype: incorrect shlibs file generation

2017-12-21 Thread Hugh McMaster
Hi Cyril, Assuming I understand the problem correctly, the attached patch should help. After compiling and installing, I have the following in /var/lib/dpkg/info/libfreetype6:amd64.shlibs: libfreetype 6 libfreetype6 (>= 2.8) udeb: libfreetype 6 libfreetype6-udeb (>= 2.8) Hope this

Bug#884923: abiword: CVE-2017-17529

2017-12-21 Thread Salvatore Bonaccorso
Source: abiword Version: 3.0.2-5 Severity: normal Tags: security upstream Hi, the following vulnerability was published for abiword. CVE-2017-17529[0]: | af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings | before launching the program specified by the BROWSER environment |

Bug#874420: [Pkg-javascript-devel] Bug#874420: poking the bugs to delay autorm

2017-12-21 Thread Pirate Praveen
On 2017, ഡിസംബർ 22 12:52:05 AM IST, Mattia Rizzolo wrote: >[08:18:54 PM] if it migrates by then, the issues should be >fixed >[08:20:03 PM] ivodd: ack, will do that. This is blocked by nodejs >= 6 not migrating to testing (one of node-babel dependencies, node-regexpu-core

Bug#884903: libtesseract-dev: headers broken: missing std::; headers missing

2017-12-21 Thread Jeff Breidenbach
We'll get this fixed upstream, and in the meantime I'll try patch enough into the Debian package to get the dependencies to build. For gimagereader, that's a single string -> std::string

Bug#884504: transition: gdal

2017-12-21 Thread Sebastiaan Couwenberg
On 12/18/2017 07:26 PM, Emilio Pozuelo Monfort wrote: > On 18/12/17 19:19, Sebastiaan Couwenberg wrote: >> On 12/17/2017 11:08 PM, Sebastiaan Couwenberg wrote: >>> On 12/17/2017 02:27 PM, Sebastiaan Couwenberg wrote: On 12/17/2017 10:38 AM, Emilio Pozuelo Monfort wrote: > On 15/12/17

Bug#884967: opencv: FTBFS on various architectures

2017-12-21 Thread Bas Couwenberg
Source: opencv Version: 3.2.0+dfsg-4 Severity: serious Justification: makes the package in question unusable or mostly so Control: block 884504 by -1 Dear Maintainer, Your package FTBFS on various architectures, which is blocking the gdal transition (#884504). On most architectures the error is

Bug#884966: lists.debian.org: Add an onion address to every Debian address in every email by bots (if available in onion.debian.org)

2017-12-21 Thread TemTem
Oh no, I fucking revealed my real name in my attachment. Can someone who has access delete the attachment? Please, ASAP. I am very uncomfortable revealing my real name especially in large communities like Debian. If you are reading this, if you are kind, can you please don't open the

Bug#884913: [Pkg-javascript-devel] Bug#884913: node-gulp-babel: fails immediately because of undeclared dependency “babel-core”

2017-12-21 Thread Pirate Praveen
Control: severity -1 normal On 2017, ഡിസംബർ 21 3:28:29 PM IST, Ben Finney wrote: >Package: node-gulp-babel >Version: 7.0.0-2 >Severity: serious >Justification: Policy 3.5 > >Attempting to run a Gulp build that uses ‘gulp-babel’ fails >immediately: > >= >module.js:327

Bug#884965: debsecan: save the report in /var/cache/debsecan

2017-12-21 Thread Paul Wise
Package: debsecan Severity: wishlist I have the debsecan report to notify me via mail of changes to the vulnerabilities present on my system but I would also like debsecan to save the report to the filesystem so that I can use it as a list of TODO items to work on when I have available time and

Bug#884882: Acknowledgement (Please add python3-ldap)

2017-12-21 Thread Timo Aaltonen
On 21.12.2017 22:54, Willem van den Akker wrote: > On Thu, 2017-12-21 at 01:27 +0200, Timo Aaltonen wrote: >> Python3 support has been added upstream in 3.0.0b*. The attached diff >> updates the packaging for the latest release, 3.0.0b3. >> > > Hi, > > Thanks for the diff. > I have made the

Bug#884963: RFS: zssh/1.5c.debian.1-4 [ITA]

2017-12-21 Thread Tobias Frost
Control: owner -1 ! Hi Boyuan, e thanks for adopting so quickly! I will sponsor it on the weekend, (I just cant right now...) After a first glance at the git repository, a few comments: - d/dirs is probably no longer needed - As the package is orphaned, please remove Ben from Uploaders (he

Bug#884968: ITP: commons-email -- Apache Commons Java API for sending email

2017-12-21 Thread Christopher Hoskin
Package: wnpp Severity: wishlist Owner: Christopher Hoskin * Package name: commons-email Version : 1.5 Upstream Author : The Apache Software Foundation * URL : https://commons.apache.org/proper/commons-email/ * License : Apache-2.0

Bug#769366: zssh won't start: "out of pty's"

2017-12-21 Thread Boyuan Yang
Control: tag -1 confirmed stretch buster sid Control: severity -1 grave This bug essentially made zssh unusable; raising the severity to "grave". I intend to investigate into it and get the problem fixed in both buster/sid and stretch. Regards, Boyuan Yang signature.asc Description: This is a

Bug#884963: RFS: zssh/1.5c.debian.1-4 [ITA]

2017-12-21 Thread Boyuan Yang
Package: sponsorship-requests Severity: normal X-Debbugs-CC: pkg-deepin-de...@lists.alioth.debian.org b...@wongs.net Dear mentors, I am looking for a sponsor for my package "zssh" * Package name: zssh Version : 1.5c.debian.1-4 Upstream Author : Matthieu Lucotte

Bug#882561: pyelliptic: Please migrate to openssl1.1 in Buster

2017-12-21 Thread Joseph R. Justice
In random web surfing related to this bug, I noticed the following based on the "homepage" link for this package ( https://github.com/yann2192/pyelliptic/) as shown on the packages page for python-pyelliptic for sid (https://packages.debian.org/sid/python-pyelliptic ). Specifically, that

Bug#839880: proftpd-basic: proftpd server instance crashed with signal 11

2017-12-21 Thread Hilmar Preuße
On 21.12.2017 05:00, Мороз Олег wrote: Hi Олег, you did not tell, if you run stable or unstable. As you use 1.3.5d I assume you run sid. I've packaged the 1.3.5e for sid (it should contain both fixes) and uploaded the full suite here [1]. Please be so kind to report back. Hilmar [1]

Bug#884950: ITP: golang-github-templexxx-reedsolomon -- Reed-Solomon Erasure Code engine in Go

2017-12-21 Thread Alexandre Viau
Package: wnpp Severity: wishlist Owner: Alexandre Viau * Package name: golang-github-templexxx-reedsolomon Version : 0.1.1+git20170927.7092926-1 Upstream Author : Temple3x * URL : https://github.com/templexxx/reedsolomon * License : Expat

Bug#884947: freecad: FreeCad crashes on start due to updated libcoin

2017-12-21 Thread Anton Gladky
control: reassign -1 coin3 3.1.4~abc9f50+dfsg2-1

Bug#884952: ITP: frontaccounting -- web-based double entry accounting and ERP program

2017-12-21 Thread Janusz Dobrowolski
Package: wnpp Severity: wishlist Owner: Janusz Dobrowolski * Package name: frontaccounting Version : 2.4.3 Upstream Author : FrontAccounting Team * URL : http://www.frontaccounting.com/ * License : GPL3 Programming Lang: PHP

Bug#884951: glib2.0: FTBFS on sparc64 landau.east.ru: gio/tests/network-address.c:212

2017-12-21 Thread Simon McVittie
Source: glib2.0 Version: 2.54.2-4 Severity: important X-Debbugs-Cc: debian-sp...@lists.debian.org Some but not all glib2.0 builds on sparc64 fail with: GLib-GIO:ERROR:../../../../../gio/tests/network-address.c:212:test_resolve_address_gresolver: 'test->valid_resolve' should be FALSE which

Bug#884953: vlc: bad window redraw: black lines

2017-12-21 Thread Vincent Lefevre
Package: src:vlc Version: 3.0.0~rc2-1 Severity: normal When I move a window over a VLC window (such as its main window or the Help window), either from right to left or from bottom to top (but not in the other direction), I get black lines (vertical in the former case, horizontal in the latter

Bug#884842: ITP: node-ternary-stream -- Node.JS streams that are controlled by a condition

2017-12-21 Thread Hilko Bengen
Package: wnpp Owner: Hilko Bengen Severity: wishlist Control: block 884842 by -1 * Package name: node-ternary-stream Version : 2.0.1 Upstream Author : Rob Richardson (http://robrich.org/) * URL : https://github.com/robrich/ternary-stream * License

Bug#884503: lintian: Check for packages using more than VCS in Vcs-{Git, Browser}

2017-12-21 Thread Chris Lamb
tags 884503 + pending thanks Fixed in Git: https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=ca4acd2a093faa4037512308397d95c15ee8e921 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#884955: Subject should be "Failed" instead of "Files"

2017-12-21 Thread Terry Roy
Sorry. Spellcheck and my poor typing. -- Terry

Bug#884946: ITA: zssh -- interactive file transfers over ssh

2017-12-21 Thread Boyuan Yang
Control: retitle -1 ITA: zssh -- interactive file transfers over ssh Control: owner -1 Debian Deepin Packaging Team X-Debbugs-CC: pkg-deepin-de...@lists.alioth.debian.org We're going to take over the maintenance of this package since some Deepin

Bug#855972: 2ping: Missing dependency on python-pkg-resources

2017-12-21 Thread Boyuan Yang
Dear Ryan, Is it possible for you to prepare a stable update [1] for package 2ping to fix Debian Bug #855972? That would benefit users of Debian Stable and fix this RC bug for them. Let me know if you have any thoughts on it. Regards, Boyuan Yang [1]

Bug#884816: RFS: frontaccounting/2.4.3-1 [ITA]

2017-12-21 Thread Paul Wise
On Thu, 2017-12-21 at 23:51 +0100, Janusz Dobrowolski wrote: > Taking into account the package is not part of any debian repo, can I > just update the version published on my mentors.debian.net account > without version change, or should I update package version to 2.4.3-2 > before upload? You

Bug#878088: reportbug: please inform security and lts teams about security update regressions

2017-12-21 Thread Salvatore Bonaccorso
Hi Markus, On Wed, Dec 13, 2017 at 01:34:05PM +0100, Markus Koschany wrote: > Hi Salvatore, > > Am 12.12.2017 um 07:19 schrieb Salvatore Bonaccorso: > [...] > > I have made the above change now live/commited. The file is still thus > > extensible and for futher (and future use). Thanks for your

Bug#860995: libpodofo: CVE-2017-8054 fix tested in unstable chroot, PoC generator source attached

2017-12-21 Thread Mattia Rizzolo
Control: tag -1 patch On Thu, Dec 21, 2017 at 04:55:00PM +0100, Matthias Brinke wrote: > I have simplified my fix for CVE-2017-8054 (stack overflow > by infinite recursion from loop in pages tree) and tested > it again in an unstable chroot (entered by sbuild from > jessie-backports), which was

Bug#819811: ITP: leiningen

2017-12-21 Thread Elana Hashman
For those that have been waiting for updates on this, I realize I have mostly been sending updates to pkg-clojure-maintainers, so let me also comment directly on the bug! I have preliminary packaging that builds up at https://anonscm.debian.org/git/pkg-clojure/leiningen-clojure.git/ Hopefully

Bug#884954: Improve sort with „simple byte comparison“ via command line option

2017-12-21 Thread Bob Proulx
H.-Dirk Schmitt wrote: > The sort behaviour depends deeply on the LC_COLLATE settings. > See e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884943 > > This behaviour is not documented in the primary documentation > provided by `sort --help` or `man sort`. But it is mentioned in all three

Bug#883601: auth-tokens are purged if auth-nocache is set (OpenVPN bug #904)

2017-12-21 Thread Bernhard Schmidt
On 05.12.2017 17:00, Jari Turkia wrote: Hi Jari, > This is a known openvpn 2.4 bug, and upstream has it fixed > (https://github.com/OpenVPN/openvpn/commit/3322c558fa742cb823fa919f682486973abc4f8e > and https://community.openvpn.net/openvpn/ticket/904). > This fix has not been backported to

Bug#884503: lintian: Check for packages using more than VCS in Vcs-{Git, Browser}

2017-12-21 Thread Chris Lamb
tags 884503 + pending thanks Fixed in Git: https://anonscm.debian.org/git/lintian/lintian.git/commit/?id=ca4acd2a093faa4037512308397d95c15ee8e921 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#884957: openjdk-9-jre-headless: jrt-fs.jar not compatible with Java 8

2017-12-21 Thread Alex Hvostov
Package: openjdk-9-jre-headless Version: 9.0.1+11-1 Severity: normal The jrt-fs.jar shipped with this package does not work correctly on Java 8. This is needed by some development tools that run on Java 8 but support development for Java 9, such as IntelliJ IDEA. A detailed explanation of this

Bug#884627:

2017-12-21 Thread Jussi Pakkanen
The reason this is happening is that starting with 0.44.0 Meson got stricter about subproject names. Slashes in the names have never been supported but due to an oversight, it was not a proper error earlier even though it should have been.

Bug#884943: Sort should support an option --machine-sort or --byte-sort

2017-12-21 Thread Bob Proulx
H.-Dirk Schmitt wrote: > O.k. I understand that it is working as defined in the 19th century. > So it is maybe not a bug but still a weird behaviour. > > In my case it takes several hour to find out why I don't get rid of > ~ 2.000 false entries in a blocklist for squid. > > Reason for the lost

Bug#884842: Splitting

2017-12-21 Thread Hilko Bengen
Control: clone -1 -2 -3 Control: retitle -2 ITP: node-gulp-match -- Gulp extension for checking file conditions Control: retitle -3 ITP: ITP: node-ternary-stream -- Node.JS streams that are controlled by a condition

Bug#884962: gnome-calendar: Cannot Sync without gnome-control-center

2017-12-21 Thread Jordan Waughtal
Package: gnome-calendar Version: 3.22.4-2 Severity: wishlist Dear Maintainer, I use a very modest computer. I run very minimal openbox desktop. I noticed I could not sync my other accounts with out installing gnome- control-center. I think this should be listed as a recomended/suggested

Bug#878221: linux-image-4.9.0-4-amd64: Screen flickers randomly since upgrade from 4.9.0-3 to 4.9.0-4

2017-12-21 Thread Robin Gareus
Same issue with 4.9.0-4-amd64, same workaround (use 4.9.0-3-amd64) Thinkpad X250 VGA compatible controller: Intel Corporation HD Graphics 5500 (rev 09) What information would be relevant or useful to provide?

Bug#884943: Sort should support an option --machine-sort or --byte-sort

2017-12-21 Thread H.-Dirk Schmitt
Reopen: 884943 Summary: 884943 Sort should support an option --machine-sort Severity: wishlist O.k. I understand that it is working as defined in the 19th century. So it is maybe not a bug but still a weird behaviour. In my case it takes several hour to find out why I don't get rid of ~ 2.000

Bug#884938: XFS: possible memory allocation deadlock in kmem_alloc

2017-12-21 Thread Ben Hutchings
Control: tag -1 upstream On Thu, 2017-12-21 at 11:30 -0500, Jason Gill wrote: > Package: src:linux > Version: 3.16.51-3 > Severity: normal > > Writing a large number of files to an XFS system with a larger > directory block size causes slow performance and kernel log errors re: > memory

Bug#826570: possible fix

2017-12-21 Thread Vincent McIntyre
There is a possible resolution here https://git.fedorahosted.org/cgit/lvm2.git/commit/?id=02628413ca99648e70e38406384be69e20a2a6ce which just takes out a workaround for a now-resolved bug. I have not tested this as I have only ever seen this issue on one host, quite some time ago. Vince

Bug#884816: RFS: frontaccounting/2.4.3-1 [ITA]

2017-12-21 Thread Janusz Dobrowolski
Hi, Thank you for pointing this documentation fragment, I have overlooked it indeed. Now I have prepared slightly changed package version, including additional fixes to bugs found in old BTS reports, but first package version (2.4.3-1) is already uploaded to my mentors account. Taking into

Bug#884958: illegal instruction crash

2017-12-21 Thread Joey Hess
Package: borgbackup Version: 1.1.3-3 Severity: normal joey@elephant:~>borg serve --umask=077 Fatal Python error: Illegal instruction Current thread 0x7f3b0fb7c700 (most recent call first): File "/usr/lib/python3/dist-packages/borg/testsuite/crypto.py", line 91 in test_blake2b_256 File

Bug#884959: RFS: wolfssl/3.13.0+dfsg-1 [requires NEW, fixes CVE] -- wolfSSL encryption library

2017-12-21 Thread Felix Lechner
Package: sponsorship-requests Severity: important Dear mentors, I am looking for a sponsor for my package "wolfssl": * Package name: wolfssl Version : 3.13.0+dfsg-1 Upstream Author : wolfSSL Inc. * URL : www.wolfssl.com * License

Bug#884842: ITP: node-gulp-match -- Gulp extension for checking file conditions

2017-12-21 Thread Hilko Bengen
Package: wnpp Owner: Hilko Bengen Severity: wishlist Control: block 884842 by -1 * Package name: node-gulp-match Version : 1.0.3 Upstream Author : Rob Richardson (http://robrich.org/) * URL : https://github.com/robrich/gulp-match * License :

Bug#884954: Improve sort with „simple byte comparison“ via command line option

2017-12-21 Thread H.-Dirk Schmitt
Package: coreutils Version: 8.25 / 8.26 Severity: wishlist The sort behaviour depends deeply on the LC_COLLATE settings. See e.g. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=884943 This behaviour is not documented in the primary documentation provided by `sort --help` or `man sort`. This

Bug#884955: tuptime: Files to install

2017-12-21 Thread Terry Roy
Package: tuptime Version: 3.3.1 Severity: important Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? The install fails due to the inclusion of '-' in the postinst file. Specifically, line 30 reads "su - tuptime

Bug#884956: vlc: icons are too big

2017-12-21 Thread Vincent Lefevre
Package: src:vlc Version: 3.0.0~rc2-1 Severity: minor Icons appear to be too big (much bigger than the associated text). I don't think this is intentional. VLC 2.x didn't have such a problem. I've attached a screenshot of a part of the main window. Just in case this matters, the configured

Bug#872941: dokuwiki: CVE-2017-12980: Stored XSS in xhtml.php with RSS/Atom feed

2017-12-21 Thread Jérôme
I believe this vulnerability, along with CVE-2017-12979 and CVE-2017-12583, is fixed in latest releases 2017-02-19e and 2016-06-26c. -- Jérôme

Bug#884842: ITP: node-fork-stream -- Fork a stream in multiple directions

2017-12-21 Thread Hilko Bengen
Package: wnpp Owner: Hilko Bengen Severity: wishlist Control: block 884961 by -1 * Package name: node-fork-stream Version : 0.0.4 Upstream Author : Conrad Pankoff (http://www.fknsrs.biz/) * URL :

Bug#884924: perl: include dpkg-vendor information in 'Configured by'

2017-12-21 Thread Niko Tyni
Package: perl Version: 5.26.1-3 Severity: wishlist Looking at https://rt.perl.org/Public/Bug/Display.html?id=132631 it would be clearer if downstream distributions didn't claim their perl is 'Configured by Debian Project', particularly if they have done source changes to our package. My best

Bug#869799:

2017-12-21 Thread rokibul islam
kmne...

Bug#877728: test_elf regression with binutils 2.29.0 on x86-64

2017-12-21 Thread Juliana Oliveira
On Wed, 4 Oct 2017 23:27:57 +0200 Levente Polyak wrote: > Package: diffoscope > > diffoscope git version: 70cb725deb12a2eddc4613b5e3af69ed13434bf7 > binutils: 2.29.0 > architecture: x86-64 > > > objdump --info|grep x86 > elf64-x86-64 > elf32-x86-64 > pei-x86-64 >

Bug#884553: live-build: Foreign architecture package support for linux kernel flavours in Stretch

2017-12-21 Thread Raphael Hertzog
Hi, On Sat, 16 Dec 2017, adrian15 wrote: > Now using: > > --linux-flavours="amd64:amd64 686" > > in a i386 system does install amd64 kernel from amd64 architecture in a > transparent manner. > > Please tell me if there's something to be polished so that it's accepted > upstream. Your patch

Bug#884920: courierpassd: fails to change the password

2017-12-21 Thread Sven Hoexter
On Thu, Dec 21, 2017 at 01:09:05PM +0100, Lucio Crusca wrote: Hello Lucio, > I'm running courier with virtual mailboxes and userdb authentication. I've bad news for you. I'm no longer the maintainer of courierpassd and I ensured that it got removed from Debian in 2015[1]. So it's no longer part

Bug#884932: ufw: cannot preseed package configuration in debian-installer

2017-12-21 Thread Moritz Schlarb
Package: ufw Version: 0.35-4 Severity: important Tags: d-i Hi, based on the README.Debian (https://sources.debian.org/src/ufw/0.35-4/debian/README.Debian/#L23), I tried to preseed ufw to be enabled and allowing SSH while also being installed directly in d-i. Basically this comes down to the

Bug#884606: stretch-pu: package espeakup/1:0.80-5+b2

2017-12-21 Thread Samuel Thibault
Cyril Brulebois, on jeu. 21 déc. 2017 15:37:00 +0100, wrote: > I don't think that's an issue with cherry-picking the relevant commit, > since it doesn't seem to contain any indications the default voice is > getting set to English? IIRC I had issues without it, so it was on purpose, and just

  1   2   >