Re: Coordinate response to xz-utils (DSA 5649-1)

2024-03-29 Thread Pierre-Elliott Bécue
Ansgar  wrote on 29/03/2024 at 23:59:38+0100: > Hi, > > how should we react to the compromised xz-utils upload? > > Ubuntu is reverting their amd64 binaries to pre-Feb 25 and rebuilding > stuff. > > On Debian side AFAIU currently amd64 buildds are paused and pending > reinstall (plus rotation

Coordinate response to xz-utils (DSA 5649-1)

2024-03-29 Thread Ansgar 
Hi, how should we react to the compromised xz-utils upload? Ubuntu is reverting their amd64 binaries to pre-Feb 25 and rebuilding stuff. On Debian side AFAIU currently amd64 buildds are paused and pending reinstall (plus rotation of key material, both OpenPGP and SSH). People are starting to

Re: Upcoming stable point release (12.6)

2024-03-29 Thread Steve McIntyre
On Fri, Mar 29, 2024 at 10:24:09PM +, Adam Barratt wrote: >On Fri, 2024-02-16 at 17:35 +, Jonathan Wiltshire wrote: >> The next point release for "bookworm" (12.6) is scheduled for >> Saturday, April 6th. Processing of new uploads into bookworm- >> proposed-updates will be frozen during

Re: Upcoming stable point release (12.6)

2024-03-29 Thread Adam D. Barratt
On Fri, 2024-02-16 at 17:35 +, Jonathan Wiltshire wrote: > The next point release for "bookworm" (12.6) is scheduled for > Saturday, April 6th. Processing of new uploads into bookworm- > proposed-updates will be frozen during the preceeding weekend. Due to recent events, the point release has

Bug#1067821: bookworm-pu: package nvidia-graphics-drivers/535.161.08-1~deb12u1

2024-03-29 Thread Andreas Beckmann
On 29/03/2024 19.40, Adam D. Barratt wrote: libnvidia-pkcs11-openssl3 is a reverse dependency of libcuda1 (seems to get dlopen()ed by it), so we cannot avoid the openssl dependency without risking cuda breakage in sid. Would uploading the 535 stack to testing-proposed-updates be helpful?

Bug#1059535: transition: abseil

2024-03-29 Thread Benjamin Barenblat
On Friday, March 29, 2024, at 1:02 PM +0100, Sebastian Ramacher wrote: > Since the version in unstable fails to build on armel and armhf and > blocks the time_t transition, but the version in experimental builds > fine, let's do this transition now. > > With the upload to unstable, please check

Bug#1068033: bookworm-pu: package gross/1.0.2-4.1~deb12u1

2024-03-29 Thread Adrian Bunk
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Antonio Radici , t...@security.debian.org * CVE-2023-52159: Stack-based buffer overflow (Closes: #1067115) This CVE is marked no-dsa. Building with the bookworm

Bug#1068034: bullseye-pu: package gross/1.0.2-4.1~deb11u1

2024-03-29 Thread Adrian Bunk
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Antonio Radici , t...@security.debian.org * CVE-2023-52159: Stack-based buffer overflow (Closes: #1067115) This CVE is marked no-dsa. diffstat for gross-1.0.2

Bug#1066096: bookworm-pu: package libpod/4.3.1+ds1-8+deb12u1

2024-03-29 Thread Jérôme Charaoui
Le 2024-03-29 à 16 h 09, Jonathan Wiltshire a écrit : Control: tag -1 moreinfo Hi, On Tue, Mar 12, 2024 at 10:24:16AM -0400, Jérôme Charaoui wrote: Low, the patch is small (3 lines) and is strictly designed to gracefully handle the identified race condition. The uploaded package also drops

Processed: Re: Bug#1066096: bookworm-pu: package libpod/4.3.1+ds1-8+deb12u1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > tag -1 moreinfo Bug #1066096 [release.debian.org] bookworm-pu: package libpod/4.3.1+ds1-8+deb12u1 Added tag(s) moreinfo. -- 1066096: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1066096 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1066096: bookworm-pu: package libpod/4.3.1+ds1-8+deb12u1

2024-03-29 Thread Jonathan Wiltshire
Control: tag -1 moreinfo Hi, On Tue, Mar 12, 2024 at 10:24:16AM -0400, Jérôme Charaoui wrote: > Low, the patch is small (3 lines) and is > strictly designed to gracefully handle the > identified race condition. The uploaded package also drops the .gitlab-ci.yml, is that intentional? Thanks,

Bug#1067821: bookworm-pu: package nvidia-graphics-drivers/535.161.08-1~deb12u1

2024-03-29 Thread Adam D. Barratt
On Thu, 2024-03-28 at 18:40 +0100, Andreas Beckmann wrote: > On 27/03/2024 21.10, Adam D. Barratt wrote: > > Please go ahead, bearing in mind that the window for 12.6 closes > > over > > the coming weekend. > > The whole nvidia stack has now been uploaded, > src:nvidia-graphics-drivers is

Processed: tagging 1068016

2024-03-29 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 1068016 + confirmed Bug #1068016 [release.debian.org] bookworm-pu: package node-babel7/7.20.15+ds1+~cs214.269.168-3+deb12u2 Added tag(s) confirmed. > thanks Stopping processing here. Please contact me if you need assistance. -- 1068016:

Processed (with 1 error): Re: Bug#1068016: bookworm-pu: package node-babel7/7.20.15+ds1+~cs214.269.168-3+deb12u2

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confimred Unknown tag/s: confimred. Recognized are: patch wontfix moreinfo unreproducible help security upstream pending confirmed ipv6 lfs d-i l10n newcomer a11y ftbfs fixed-upstream fixed fixed-in-experimental sid experimental potato woody sarge

Bug#1068016: bookworm-pu: package node-babel7/7.20.15+ds1+~cs214.269.168-3+deb12u2

2024-03-29 Thread Adam D. Barratt
Control: tags -1 + confimred On Fri, 2024-03-29 at 17:41 +0100, Andreas Beckmann wrote: > To smoothen some upgrade paths from buster -> bullseye -> bookworm we > need to add some Breaks+Replaces against obsolete packages. Please go ahead. Regards, Adam

Processed: Re: Bug#1067980: bookworm-pu: package gpaste/43.1-3+deb12u1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #1067980 [release.debian.org] bookworm-pu: package gpaste/43.1-3+deb12u1 Added tag(s) confirmed. -- 1067980: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067980 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1067980: bookworm-pu: package gpaste/43.1-3+deb12u1

2024-03-29 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2024-03-29 at 15:57 +0100, Andreas Beckmann wrote: > In order to smoothen upgrade paths I'd like to add some > Breaks+Replaces > to bookworm. This avoids a file conflict in case libgpaste6 (last > released with stretch) is still installed. Please go ahead.

Bug#1068016: bookworm-pu: package node-babel7/7.20.15+ds1+~cs214.269.168-3+deb12u2

2024-03-29 Thread Andreas Beckmann
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Yadd Control: block 1037234 with -1 Control: affects -1 + src:node-babel7 [ Reason ] To smoothen some upgrade paths from buster -> bullseye -> bookworm we need to

Processed: bookworm-pu: package node-babel7/7.20.15+ds1+~cs214.269.168-3+deb12u2

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > block 1037234 with -1 Bug #1037234 {Done: Yadd } [node-babel7] node-babel7: missing Breaks+Replaces: node-babel-traverse (<< 7) 1037234 was not blocked by any bugs. 1037234 was not blocking any bugs. Added blocking bug(s) of 1037234: 1068016 > affects -1 +

Processed: nmu: libevent_2.1.12-stable-8.1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:libevent Bug #1067985 [release.debian.org] nmu: libevent_2.1.12-stable-8.1 Added indication that 1067985 affects src:libevent -- 1067985: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067985 Debian Bug Tracking System Contact

Bug#1067985: nmu: libevent_2.1.12-stable-8.1

2024-03-29 Thread Andrey Rakhmatullin
Package: release.debian.org Severity: normal X-Debbugs-Cc: libev...@packages.debian.org Control: affects -1 + src:libevent User: release.debian@packages.debian.org Usertags: binnmu nmu libevent_2.1.12-stable-8.1 . armhf . unstable . -m "Rebuild on buildd"

Processed: bookworm-pu: package gpaste/43.1-3+deb12u1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:gpaste Bug #1067980 [release.debian.org] bookworm-pu: package gpaste/43.1-3+deb12u1 Added indication that 1067980 affects src:gpaste > block 1038751 with -1 Bug #1038751 {Done: Jérémy Lal } [libgpaste-2-common] libgpaste-2-common: missing

Bug#1067980: bookworm-pu: package gpaste/43.1-3+deb12u1

2024-03-29 Thread Andreas Beckmann
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Jérémy Lal Control: affects -1 + src:gpaste Control: block 1038751 with -1 [ Reason ] In order to smoothen upgrade paths I'd like to add some Breaks+Replaces to

NEW changes in stable-new

2024-03-29 Thread Debian FTP Masters
Processing changes file: linux_6.1.82-1_mipsel-buildd.changes ACCEPT

Bug#1067953: transition: flint

2024-03-29 Thread Torrance, Douglas
Package: release.debian.org Control: affects -1 + src:flint X-Debbugs-Cc: fl...@packages.debian.org User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: dtorra...@piedmont.edu Severity: normal Dear Release Team, I would like to request a transition slot for flint.

Processed: transition: flint

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:flint Bug #1067953 [release.debian.org] transition: flint Added indication that 1067953 affects src:flint -- 1067953: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067953 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Bug#1067917: marked as done (nmu: openssh_1:9.7p1-2+b1)

2024-03-29 Thread Debian Bug Tracking System
Your message dated Fri, 29 Mar 2024 13:15:15 +0100 with message-id and subject line Re: Bug#1067917: nmu: openssh_1:9.7p1-2+b1 has caused the Debian Bug report #1067917, regarding nmu: openssh_1:9.7p1-2+b1 to be marked as done. This means that you claim that the problem has been dealt with. If

Bug#1059535: transition: abseil

2024-03-29 Thread Sebastian Ramacher
Control: tags -1 confirmed Hi Benjamin On 2024-02-14 21:01:40 +0100, Sebastian Ramacher wrote: > On 2024-02-14 14:48:49 -0500, Benjamin Barenblat wrote: > > I’d like to alter this transition request. Instead of transitioning to > > version 20230802, I’d like to transition to version 20240116,

Processed: Re: Bug#1059535: transition: abseil

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > tags -1 confirmed Bug #1059535 [release.debian.org] transition: abseil Added tag(s) confirmed. -- 1059535: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1059535 Debian Bug Tracking System Contact ow...@bugs.debian.org with problems

Processed: Re: Bug#1067943: nmu: qtbase-opensource-src_5.15.10+dfsg-7

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > reopen -1 Bug #1067943 {Done: Sebastian Ramacher } [release.debian.org] nmu: qtbase-opensource-src_5.15.10+dfsg-7 Bug reopened Ignoring request to alter fixed versions of bug #1067943 to the same values previously set -- 1067943:

Bug#1067943: nmu: qtbase-opensource-src_5.15.10+dfsg-7

2024-03-29 Thread Sebastian Ramacher
Control: reopen -1 On 2024-03-29 12:15:11 +0100, Sebastian Ramacher wrote: > On 2024-03-29 11:17:25 +0100, Bas Couwenberg wrote: > > Package: release.debian.org > > Severity: normal > > X-Debbugs-Cc: qtbase-opensource-...@packages.debian.org > > Control: affects -1 + src:qtbase-opensource-src > >

Bug#1067943: marked as done (nmu: qtbase-opensource-src_5.15.10+dfsg-7)

2024-03-29 Thread Debian Bug Tracking System
Your message dated Fri, 29 Mar 2024 12:15:11 +0100 with message-id and subject line Re: Bug#1067943: nmu: qtbase-opensource-src_5.15.10+dfsg-7 has caused the Debian Bug report #1067943, regarding nmu: qtbase-opensource-src_5.15.10+dfsg-7 to be marked as done. This means that you claim that the

Bug#1067941: marked as done (nmu: pkcs11-helper_1.29.0-2+b1)

2024-03-29 Thread Debian Bug Tracking System
Your message dated Fri, 29 Mar 2024 12:14:41 +0100 with message-id and subject line Re: Bug#1067941: nmu: pkcs11-helper_1.29.0-2+b1 has caused the Debian Bug report #1067941, regarding nmu: pkcs11-helper_1.29.0-2+b1 to be marked as done. This means that you claim that the problem has been dealt

Bug#1036884: more trackers

2024-03-29 Thread Sebastian Ramacher
On 2024-03-29 00:39:02 +0500, Andrey Rakhmatullin wrote: > Some additional smaller trackers that apparently didn't have binNMUs: > https://release.debian.org/transitions/html/auto-ogre-1.12.html > https://release.debian.org/transitions/html/auto-ros-ros-comm.html >

Bug#1067943: nmu: qtbase-opensource-src_5.15.10+dfsg-7

2024-03-29 Thread Andrey Rakhmatullin
On Fri, Mar 29, 2024 at 11:17:25AM +0100, Bas Couwenberg wrote: > Package: release.debian.org > Severity: normal > X-Debbugs-Cc: qtbase-opensource-...@packages.debian.org > Control: affects -1 + src:qtbase-opensource-src > User: release.debian@packages.debian.org > Usertags: binnmu > > nmu

Processed: nmu: openjdk-17_17.0.11~7ea-1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:openjdk-17 Bug #1067944 [release.debian.org] nmu: openjdk-17_17.0.11~7ea-1 Added indication that 1067944 affects src:openjdk-17 -- 1067944: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067944 Debian Bug Tracking System Contact

Bug#1067944: nmu: openjdk-17_17.0.11~7ea-1

2024-03-29 Thread Andrey Rakhmatullin
Package: release.debian.org Severity: normal X-Debbugs-Cc: openjdk...@packages.debian.org Control: affects -1 + src:openjdk-17 User: release.debian@packages.debian.org Usertags: binnmu nmu openjdk-17_17.0.11~7ea-1 . armel armhf . unstable . -m "Rebuild on buildds"

Processed: nmu: qtbase-opensource-src_5.15.10+dfsg-7

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:qtbase-opensource-src Bug #1067943 [release.debian.org] nmu: qtbase-opensource-src_5.15.10+dfsg-7 Added indication that 1067943 affects src:qtbase-opensource-src -- 1067943: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067943 Debian Bug

Bug#1067943: nmu: qtbase-opensource-src_5.15.10+dfsg-7

2024-03-29 Thread Bas Couwenberg
Package: release.debian.org Severity: normal X-Debbugs-Cc: qtbase-opensource-...@packages.debian.org Control: affects -1 + src:qtbase-opensource-src User: release.debian@packages.debian.org Usertags: binnmu nmu qtbase-opensource-src_5.15.10+dfsg-7 . armel armhf . unstable . -m "Rebuild for

Processed: nmu: pkcs11-helper_1.29.0-2+b1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:pkcs11-helper Bug #1067941 [release.debian.org] nmu: pkcs11-helper_1.29.0-2+b1 Added indication that 1067941 affects src:pkcs11-helper -- 1067941: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067941 Debian Bug Tracking System Contact

Bug#1067941: nmu: pkcs11-helper_1.29.0-2+b1

2024-03-29 Thread Andrey Rakhmatullin
Package: release.debian.org Severity: normal X-Debbugs-Cc: pkcs11-hel...@packages.debian.org Control: affects -1 + src:pkcs11-helper User: release.debian@packages.debian.org Usertags: binnmu nmu pkcs11-helper_1.29.0-2+b1 . armel armhf . unstable . -m "Rebuild for time_t"

Bug#1067931: marked as done (nmu: openvpn_2.6.9-1)

2024-03-29 Thread Debian Bug Tracking System
Your message dated Fri, 29 Mar 2024 09:06:11 +0100 with message-id and subject line Re: Bug#1067931: nmu: openvpn_2.6.9-1 has caused the Debian Bug report #1067931, regarding nmu: openvpn_2.6.9-1 to be marked as done. This means that you claim that the problem has been dealt with. If this is not

Bug#1067891: marked as done (nmu: memcached_1.6.23-1)

2024-03-29 Thread Debian Bug Tracking System
Your message dated Fri, 29 Mar 2024 09:05:43 +0100 with message-id and subject line Re: Bug#1067891: nmu: memcached_1.6.23-1 has caused the Debian Bug report #1067891, regarding nmu: memcached_1.6.23-1 to be marked as done. This means that you claim that the problem has been dealt with. If this

Bug#1067931: nmu: openvpn_2.6.9-1

2024-03-29 Thread Andrey Rakhmatullin
Package: release.debian.org Severity: normal X-Debbugs-Cc: open...@packages.debian.org Control: affects -1 + src:openvpn User: release.debian@packages.debian.org Usertags: binnmu nmu openvpn_2.6.9-1 . armel armhf . unstable . -m "Rebuild for time_t" https://packages.debian.org/sid/openvpn

Processed: nmu: openvpn_2.6.9-1

2024-03-29 Thread Debian Bug Tracking System
Processing control commands: > affects -1 + src:openvpn Bug #1067931 [release.debian.org] nmu: openvpn_2.6.9-1 Added indication that 1067931 affects src:openvpn -- 1067931: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1067931 Debian Bug Tracking System Contact ow...@bugs.debian.org with

NEW changes in stable-new

2024-03-29 Thread Debian FTP Masters
Processing changes file: linux_6.1.82-1_mips64el-buildd.changes ACCEPT