Bug#1016131: libapache2-mod-jk: Apache does not start after upgrade (JkWorkersFile only allowed once)

2023-02-06 Thread Markus Koschany
Hello, On Wed, 27 Jul 2022 20:36:06 +0200 Thorsten Glaser wrote: > Package: libapache2-mod-jk > Version: 1:1.2.48-1 > Severity: critical > Justification: breaks unrelated software > X-Debbugs-Cc: t...@mirbsd.de > > After upgrading from buster to bullseye, apache2 does not start any more > if lib

Bug#1030869: tomcat10: Catalina won't deploy applications missing class jakarta.websocket.DeploymentException

2023-02-11 Thread Markus Koschany
Control: tags -1 pending On Wed, 08 Feb 2023 11:38:25 -0500 Jorge Moraleda wrote: > Package: tomcat10 > Version: 10.1.5-1 > Severity: grave > Justification: renders package unusable > X-Debbugs-Cc: jorge.moral...@gmail.com > > Dear Maintainer, > > Catalina is unable to deploy any applications (

Bug#1026639: rhino FTBFS

2023-02-12 Thread Markus Koschany
Control: owner -1 ! signature.asc Description: This is a digitally signed message part

Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-11-22 Thread Markus Koschany
Package: erlang X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for erlang. Initially the security team triaged this issue as minor but further investigation showed the impact might be much more severe. Red Hat and other vendors

Bug#1024632: erlang: CVE-2022-37026 Client Authentication Bypass

2022-11-30 Thread Markus Koschany
request client certification, that +is sets the option {verify, verify_peer}. (Closes: #1024632) + + -- Markus Koschany Wed, 30 Nov 2022 12:53:30 +0100 + erlang (1:23.2.6+dfsg-1) unstable; urgency=medium * New upstream release. diff -Nru erlang-23.2.6+dfsg/debian/patches/CVE-2022-37026

Bug#912485: childsplay: Please migrate to python3-pygame

2022-12-01 Thread Markus Koschany
Am Donnerstag, dem 01.12.2022 um 14:31 +0100 schrieb Bastian Germann: > On Tue, 20 Oct 2020 21:19:16 +0200 Markus Koschany wrote: > > I have started to port childsplay to python3. There are no estimates > > when it's done but I hope I can finish the work before we freeze. >

Bug#1034196: unblock: openrefine/3.6.2-2

2023-04-20 Thread Markus Koschany
Hello, Am Donnerstag, dem 20.04.2023 um 11:57 +0200 schrieb Paul Gevers: > Control: tags -1 moreinfo > > Hi, > > On Mon, 10 Apr 2023 23:55:44 +0200 Markus Koschany wrote: > > This unblock is related to #1034127 and the unblock of rhino. > > rhino is now unblocked.

Bug#1034196: unblock: openrefine/3.6.2-2

2023-04-20 Thread Markus Koschany
Hi Paul, Am Donnerstag, dem 20.04.2023 um 18:07 +0200 schrieb Paul Gevers: > [...] > > Since I already followed the Debian Policy and included the missing sources > > in > > debian/missing-sources, I felt that shipping the 3rdparty directory in > > debian/missing-sources/3rdparty would be a good i

Bug#1033366: resteasy3.0: should migrate to tomcat10

2023-04-21 Thread Markus Koschany
Am Freitag, dem 21.04.2023 um 12:23 +0200 schrieb Andreas Tille: > Hi, > > I tried to rebuild this package which does not work as you can > see in Salsa CI: > >     https://salsa.debian.org/java-team/resteasy/-/jobs/4105287 > > Unfortunately I have no idea how to fix this. Hi Andreas, it seem

Bug#1033366: resteasy3.0: should migrate to tomcat10

2023-04-21 Thread Markus Koschany
Am Freitag, dem 21.04.2023 um 14:50 +0200 schrieb Andreas Tille: > > Ahhh, right, the repository went over to source package resteasy.  So > well, the CI log is not helpful for this bug log.  What I rather want to > know is how to proceed with this bug since some Debian Med package > received a te

Bug#1031055: apache-curator: FTBFS randomly (org.opentest4j.AssertionFailedError: expected: <1> but was: <0>)

2023-04-21 Thread Markus Koschany
I can reproduce the FTBFS here on my system. Apparently some of the tests are not 100 % reliable and reproducible. For now I will just disable them. Markus signature.asc Description: This is a digitally signed message part

Bug#1034693: unblock: apache-curator/5.4.0-3

2023-04-21 Thread Markus Koschany
build-dependency on resteasy3.0. + * Ignore test failures because some tests are not 100 % reliable. +(Closes: #1031055) + + -- Markus Koschany Fri, 21 Apr 2023 15:41:45 +0200 + apache-curator (5.4.0-2) unstable; urgency=medium * Team upload diff -Nru apache-curator-5.4.0/debian/control

Bug#1034824: tomcat9 should not be released with Bookworm

2023-04-25 Thread Markus Koschany
Source: tomcat9 Version: 9.0.70-1 Severity: serious X-Debbugs-Cc: a...@debian.org We can only support one major Tomcat version per release. Tomcat9 has been part of Buster and Bullseye already and is superseded by Tomcat 10 in Bookworm. I wanted to wait with the removal request until the issues i

Bug#1035372: unblock: wbar/2.3.4-13

2023-05-02 Thread Markus Koschany
) unstable; urgency=medium + + * Do not install wbar.glade because it is not required and breaks wbar on +upgrade from Bullseye to Bookworm (leftover from the wbar-config removal). +Thanks to Helmut Grohne for the report. (Closes: #1035001) + + -- Markus Koschany Thu, 27 Apr 2023 15:44:41 +0200

Bug#1035618: dreamchess: please remove artificial limit (15) on number of save slots

2023-05-06 Thread Markus Koschany
Control: forwarded -1 https://github.com/dreamchess/dreamchess/issues/58 Hello, On Sat, 06 May 2023 17:14:08 +0200 Lucio Crusca wrote: > Package: dreamchess > Version: 0.3.0-2 > Severity: wishlist > X-Debbugs-Cc: lu...@sulweb.org > > Dear Maintainer, > > I often find myself copying savegames i

Bug#1004844: games-finest: Consider adding endless-sky

2023-05-06 Thread Markus Koschany
Hi, thanks for the suggestion! On Wed, 02 Feb 2022 03:58:43 -0500 Dave Vasilevsky wrote: > Package: games-finest > Version: 4 > Severity: wishlist > X-Debbugs-Cc: d...@vasilevsky.ca > > Hi, > > Thanks for all your work maintaining debian-games. > > It's been a few years since we've added anyt

Bug#1034824: tomcat9 should not be released with Bookworm

2023-05-11 Thread Markus Koschany
Hello Paul, Am Donnerstag, dem 11.05.2023 um 21:44 +0200 schrieb Paul Gevers: > Hi Markus, > > On Tue, 25 Apr 2023 16:04:09 +0200 Markus Koschany wrote: > > We can only support one major Tomcat version per release. Tomcat9 has > > been part of Buster and Bullseye already

Bug#977027: rhino breaks dojo autopkgtest: Cannot set property "dojo" of null to "[object Object]"

2023-03-26 Thread Markus Koschany
Hello, On Sun, 26 Mar 2023 09:41:48 +0200 Graham Inggs wrote: [...] > To both the rhino and dojo maintainers, please investigate so we can > have this resolved for bookworm. Here are my investigations: 1. There is no transition needed because only shrinksafe is affected by the new rhino version

Bug#977027: rhino breaks dojo autopkgtest: Cannot set property "dojo" of null to "[object Object]"

2023-03-26 Thread Markus Koschany
Hi Graham, Am Sonntag, dem 26.03.2023 um 19:28 +0200 schrieb Graham Inggs: > Hi Markus > > On Sun, 26 Mar 2023 at 16:34, Markus Koschany wrote: > > 1. There is no transition needed because only shrinksafe is affected by the > > new > > rhino version. > How

Bug#1032032: FTBFS: error: AM_INIT_AUTOMAKE expanded multiple times

2023-03-30 Thread Markus Koschany
Control: tags -1 pending Hi Thomas, Am Donnerstag, dem 30.03.2023 um 17:05 +0200 schrieb Thomas Uhle: > Dear maintainers, > > could someone of you please prepare a new version of fenix-plugins with my > patch added to save it from being auto-removed. thanks for your patch! Looks good to me. I'

Bug#1033993: bullseye-pu: package unbound/1.13.1-1

2023-04-05 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: a...@debian.org Hello, I would like to update unbound in Bullseye and fix three no-dsa CVE, namely CVE-2022-3204, CVE-2022-30698 and CVE-2022-30699. The same patches

Bug#1033993: bullseye-pu: package unbound/1.13.1-1

2023-04-05 Thread Markus Koschany
when the delegation information is +about to expire making the rogue delegation information ever-updating. From +now on Unbound stores the start time for a query and uses that to decide if +the cached delegation information can be overwritten. + + -- Markus Koschany Wed, 05 Apr

Bug#977027: rhino breaks dojo autopkgtest: Cannot set property "dojo" of null to "[object Object]"

2023-04-06 Thread Markus Koschany
Hello, Am Donnerstag, dem 06.04.2023 um 12:54 +0200 schrieb Paul Gevers: > Hi, > > On Sun, 26 Mar 2023 16:26:00 +0200 Markus Koschany wrote: > > 1. There is no transition needed because only shrinksafe is affected by the > > new > > rhino version. > > I'

Bug#1034099: unblock: zstd-jni-java/1.5.2-5+ds-3

2023-04-08 Thread Markus Koschany
; urgency=medium + + * Team upload. + * Depend on maven-resources-plugin 3.3.0 and maven-compiler-plugin 3.10.1. +Fixes FTBFS when building zstd-jni-java for binary-arch only. +Thanks to Andreas Beckmann for the report. (Closes: #1034059) + + -- Markus Koschany Sat, 08 Apr 2023 22:46:57

Bug#1034127: unblock: rhino/1.7.14-2.1

2023-04-10 Thread Markus Koschany
Am Sonntag, dem 09.04.2023 um 22:28 +0200 schrieb Paul Gevers: > > [ Risks ] > This is a new upstream release. This is not a small change. And while > typing this unblock request, I'm getting uncomfortable and wonder if > we want this. But as it's all prepared, let's discuss and pull Markus > in t

Bug#1034194: unblock: closure-compiler/20130227+dfsg1-13

2023-04-10 Thread Markus Koschany
) unstable; urgency=medium + + * QA upload. + * Tighten dependency on librhino-java to >= 1.7.14. + * Fix FTBFS with rhino 1.7.14. + * Use canonical VCS URI. + + -- Markus Koschany Tue, 14 Feb 2023 00:18:02 +0100 + closure-compiler (20130227+dfsg1-12) unstable; urgency=medium * QA upl

Bug#1034492: libtcnative-1: Tomcat warning suggesting a minimum version of 2.0.1 for tcnative

2023-04-16 Thread Markus Koschany
Hello, Am Sonntag, dem 16.04.2023 um 16:15 -0400 schrieb Jorge Moraleda: > Package: libtcnative-1 > Version: 1.2.35-1 > Severity: normal > X-Debbugs-Cc: jorge.moral...@gmail.com > > Dear Maintainer, > > When running tomcat 10 (installed from default bookworm repo) it warns that > "An > older ver

Bug#1032591: xarchive error when open or unpack .zst files

2023-03-12 Thread Markus Koschany
Thanks for the report. The bug will be fixed soon. signature.asc Description: This is a digitally signed message part

Bug#1022760: openrefine: localhost:3333 returns HTTP ERROR 404 Not Found

2023-03-17 Thread Markus Koschany
Am Freitag, dem 17.03.2023 um 12:38 +0100 schrieb Robert Jäschke: > Package: openrefine > Version: 3.6.2-1 > Followup-For: Bug #1022760 > X-Debbugs-Cc: jaesc...@l3s.de > > Dear Maintainer, > > I experience the exact same problem with the latest version, that is, > starting openrefine and opening

Bug#1022760: openrefine: localhost:3333 returns HTTP ERROR 404 Not Found

2023-03-17 Thread Markus Koschany
Hi Robert, > > Sorry, I forgot to add this: > >  > dpkg -l | grep rhino > ii  librhino-java   1.7.14-2 > ii  rhino   1.7.14-2 > > I've upgraded (lib)rhino after reading the bug report but this did not help. > > Is there a way to debug Openrefine? I tried both -v debug and -v trace > b

Bug#1022760: openrefine: localhost:3333 returns HTTP ERROR 404 Not Found

2023-03-23 Thread Markus Koschany
Control: reopen -1 Control: severity -1 serious Hello Robert, Am Donnerstag, dem 23.03.2023 um 10:41 +0100 schrieb Robert Jäschke: > Dear Markus, > > I found the problem: the package misses a dependency to libjoda-time-java. thank you for debugging this problem. I will prepare an update for Boo

Bug#1026639: fixed in rhino 1.7.14-1

2023-03-23 Thread Markus Koschany
Hi, Am Donnerstag, dem 23.03.2023 um 15:08 +0100 schrieb Paul Gevers: > Hi, > > On Mon, 13 Feb 2023 14:42:17 + Debian FTP Masters > wrote: > >    * New upstream version 1.7.14. > > - Fix FTBFS with OpenJDK 17. (Closes: #1026639) > > Is it possible to get a targeted fix? This new upstr

Bug#1033363: unblock: xarchiver/1:0.5.4.20-2

2023-03-23 Thread Markus Koschany
table; urgency=medium + + * Fix detection of zstd version 1.5.4 and later. (Closes: #1032591) + + -- Markus Koschany Sun, 12 Mar 2023 12:48:14 +0100 + xarchiver (1:0.5.4.20-1) unstable; urgency=medium * New upstream version 0.5.4.20. diff -Nru xarchiver-0.5.4.20/debian/patches/fix-detecti

Bug#1033364: unblock: logback/1:1.2.11-2

2023-03-23 Thread Markus Koschany
+ + * Team upload. + * Migrate to Tomcat 10. Depend on libtomcat10-java instead of tomcat9-java. +Add tomcat10-migration.patch. + + -- Markus Koschany Sun, 05 Mar 2023 01:43:23 +0100 + logback (1:1.2.11-1) unstable; urgency=medium * New upstream version 1.2.11 diff -Nru logback-1.2.11/debian

Bug#1031817: i2p: Migrate to Tomcat 10

2023-03-23 Thread Markus Koschany
72) I would rather suggest to remove i2p from testing for now because of that. If someone wants to give it a try as well, then just replace libtomcat9-java with libtomcat10-java in debian/control and apply the tomcat10-migration.patch to get you started. From: Markus Koschany Date: Sun, 5 Mar 2023 17:4

Bug#1033366: resteasy3.0: should migrate to tomcat10

2023-03-23 Thread Markus Koschany
Source: resteasy3.0 Version: 3.0.26-5 Severity: serious Tags: help X-Debbugs-Cc: a...@debian.org Hello, currently resteasy3.0 depends on libtomcat9-java but should rather depend on libtomcat10-java. The reasoning for this is the fact that we can only support one tomcat package per release for sec

Bug#1031816: [Pkg-freeipa-devel] Bug#1031816: tomcatjss: Migrate to Tomcat 10

2023-03-23 Thread Markus Koschany
Control: severity -1 serious On Fri, 24 Feb 2023 11:48:36 +0200 Timo Aaltonen wrote: > Upstream doesn't support tomcat10 yet, and tomcatjss fails to build with it. Unfortunately we can only support one Tomcat version per release. We should either migrate to tomcat10 or maybe it is possible to

Bug#1031816: [Pkg-freeipa-devel] Bug#1031816: Bug#1031816: tomcatjss: Migrate to Tomcat 10

2023-03-24 Thread Markus Koschany
Am Freitag, dem 24.03.2023 um 09:21 +0200 schrieb Timo Aaltonen: > Markus Koschany kirjoitti 23.3.2023 klo 19.00: > > Control: severity -1 serious > > > > On Fri, 24 Feb 2023 11:48:36 +0200 Timo Aaltonen > > wrote: > >   > > > Upstream doesn't sup

Bug#1031816: [Pkg-freeipa-devel] Bug#1031816: Bug#1031816: Bug#1031816: tomcatjss: Migrate to Tomcat 10

2023-03-26 Thread Markus Koschany
Am Sonntag, dem 26.03.2023 um 12:15 +0300 schrieb Timo Aaltonen: > Markus Koschany kirjoitti 24.3.2023 klo 15.35: > > Am Freitag, dem 24.03.2023 um 09:21 +0200 schrieb Timo Aaltonen: > > > Markus Koschany kirjoitti 23.3.2023 klo 19.00: > > > > Control: severity -1 s

Bug#1018018: imlib2 FTBFS

2022-12-31 Thread Markus Koschany
Control: severity -1 serious Hello, I have just uploaded imlib2 1.10.0 to unstable. This issue is release critical now. signature.asc Description: This is a digitally signed message part

Bug#1027687: netty: please package 4.1.86 or later

2023-01-01 Thread Markus Koschany
Source: netty Version: 1:4.1.48-5 Severity: wishlist I have uploaded my preliminary packaging work to experimental in Git but could not finish it yet.

Bug#1026695: undertow: FTBFS: make: *** [debian/rules:4: build] Error 25

2023-01-01 Thread Markus Koschany
This is some kind of incompatibility with jboss-classfilewriter 1.3.0. I will look into it after the release of Debian 12. Undertow should not be part of a stable release as long as there is no real demand for another Java web server anyway. signature.asc Description: This is a digitally signed m

Bug#1028247: dart: FTBFS with Bullet 3.24 error in test_skelParser

2023-01-08 Thread Markus Koschany
Source: dart Version: 6.12.1+dfsg4-11 Severity: important X-Debbugs-Cc: a...@debian.org Dear maintainer, I would like to release Bullet 3.24 with Bookworm. Your package fails to build from source because one test fails, test_SkelParser. Error [FCLCollisionDetector.cpp:1074]^[[0m [FCLCollisionDe

Bug#1028248: transition: bullet

2023-01-08 Thread Markus Koschany
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: transition X-Debbugs-Cc: a...@debian.org Hello, I would like to request a transition slot for Bullet 3.24 which is already available in experimental. I have successfully rebuilt all reverse-depend

Bug#1028248: transition: bullet

2023-01-10 Thread Markus Koschany
Short follow-up: The bug in dart (#1028247) has already been fixed. That means only 7 binNMU would be required to complete this transition now. signature.asc Description: This is a digitally signed message part

Bug#1028248: transition: bullet

2023-01-10 Thread Markus Koschany
Am Dienstag, dem 10.01.2023 um 22:34 +0100 schrieb Sebastian Ramacher: > Please go ahead Thank you! Uploaded. Markus signature.asc Description: This is a digitally signed message part

Bug#1028486: bullseye-pu: package jersey1/1.19.3-6

2023-01-11 Thread Markus Koschany
+1,10 @@ +jersey1 (1.19.3-6+deb11u1) bullseye; urgency=medium + + * Team upload. + * Fix FTBFS with libjettison-java 1.5.3. + + -- Markus Koschany Sat, 31 Dec 2022 16:49:13 +0100 + jersey1 (1.19.3-6) unstable; urgency=medium * Fixed the build failure with librome-java >= 1.6 diff -Nru jers

Bug#710117: new version, desktop file

2018-10-13 Thread Markus Koschany
Hi Gürkan, Am 11.10.18 um 17:42 schrieb Gürkan Myczko: > Hello Josue and Markus > > I've prepared a new upstream version of greed, and added the desktop file. > Feel free to use: > > http://phd-sid.ethz.ch/debian/greed/greed_4.2-1.dsc > > Best, Thank you for preparing a new Debian release of g

Bug#911078: triplea: Fails to start with NullPointerException

2018-10-15 Thread Markus Koschany
Package: triplea Version: 1.9.0.0.7062-2 Severity: grave Justification: renders package unusable After the switch to OpenJFX 11, triplea fails to start with a NullPointerException. triplea.engine.version.bin:1.9 java.lang.NullPointerException at org.pushingpixels.substance.internal.utils

Bug#911079: [pdfsam] Window blank

2018-10-15 Thread Markus Koschany
Control: tags -1 unreproducible Control: severity -1 important Am 15.10.18 um 14:11 schrieb Marco Righi: > Package: pdfsam > Version: 1.1.4-4 > Severity: grave > > --- Please enter the report below this line. --- > Hi, > After pdfsam execution appears only a little box (see image_1). > After enla

Bug#886394: pdfsam still shows the same error although it does give the banner as gimp does while starting up.

2018-10-15 Thread Markus Koschany
Control: severity -1 grave Control: block -1 by 910764 Am 15.10.18 um 15:55 schrieb shirish शिरीष: > Dear all, > > The issue is still prevalent even though you do get a > 'banner'/animation or whatever its called similar to when gimp starts > even though there are now versions of openjfx and open

Bug#911098: webext-ublock-origin: missing strings on dashbord

2018-10-15 Thread Markus Koschany
Am 15.10.18 um 19:22 schrieb Jakub Wilk: > Package: webext-ublock-origin > Version: 1.17.0+dfsg-2 > > Some strings are missing on the dashboard page: > * "Shortcuts" tab; > * "Disable JavaScript" checkbox. > > See the attached screenshot. > > Curiously, they both show correctly in a newly create

Bug#910395: mediathekview with openjfx 11

2018-10-15 Thread Markus Koschany
Hi, Am 15.10.18 um 19:45 schrieb Erich Schubert: > Hi, > > It seems the classpath is not set up correctly. > > With Java 11 as my main java, the following works: > > java -cp > /usr/share/mediathekview/MediathekView.jar:/usr/share/java/javafx-base-11.jar:/usr/share/java/javafx-controls-11.jar:/

Bug#784327: python-moinmoin: should (and be adapted to and) recommend ckeditor (not fckeditor)

2018-10-15 Thread Markus Koschany
On Tue, 05 May 2015 14:35:53 +0200 Jonas Smedegaard wrote: > Package: python-moinmoin > Severity: important > > fckeditor has been removed from Jessie, yet is recommended by > python-moinmoin. > > One of the RC bugs against fckeditor - bug#758897 - indicates that > ckeditor is a successor, so ho

Bug#910395: mediathekview with openjfx 11

2018-10-16 Thread Markus Koschany
I have decided to split the issue into smaller parts. I'm going to fix the JavaFX 11 "not found" issue by using the --add-modules option in mediathekview's wrapper script. I don't even have to patch the sources then. Another patch will ensure compatibility with the default-jdk version in Debian. Fo

Bug#911137: mediathekview: please package version 13.2.1

2018-10-16 Thread Markus Koschany
Package: mediathekview Version: 13.0.6-1 Severity: wishlist I am filing this bug report to document the progress on packaging version 13.2.1 of mediathekview. The new version made significant changes under the hood which require new build-dependencies. I have already packaged libmbassador-java an

Bug#907429: neverball: Constant fsync calls seriously degrade performance

2018-10-18 Thread Markus Koschany
Hi Ryan, On Tue, 16 Oct 2018 11:32:34 -0400 "Ryan C. Gordon" wrote: > > Can someone humor me and make a quick change to Neverball for me? > > In neverball/share/fs_physfs.c, there are three calls to > PHYSFS_setBuffer(). Just comment them out and rebuild Neverball with > PhysicsFS support and

Bug#845269: patch to make backspace to 'undo' last move

2018-10-20 Thread Markus Koschany
Hi Bill, On Mon, 21 Nov 2016 23:51:54 +0100 Bill Allombert wrote: > Package: brutalchess > Version: 0.5.2+dfsg-7 > Severity: wishlist > Tags: patch > > Dear Debian Games team, > > I did not find a way to undo the last move, so I made this simple patch > that causes backspace to undo the last mo

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
Package: teeworlds-server Version: 0.6.4+dfsg-1 Severity: grave Tags: security It was discovered that a Teeworlds server could be made inaccessible by forging connection packets. This made it look like the server was always full thus access to the server was effectively denied. My own private serv

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
Hi, Am 20.10.18 um 21:01 schrieb Salvatore Bonaccorso: [...] > For 0.6.5 the following two commits might be the relevant ones (not > found any further possibly releated): > > https://github.com/teeworlds/teeworlds/commit/4c00063b2fd9c25998f3d308723e1ae65c20548d > https://github.com/teeworlds/teew

Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-20 Thread Markus Koschany
I have just requested a CVE id for this issue. Upstream clarified the fixing commits. They are https://github.com/teeworlds/teeworlds/commit/a263185571903ead01f6b351a91ea219ac9d215f https://github.com/teeworlds/teeworlds/commit/aababc63e1bc41672502ca6c7a1dd9f61d94 https://github.com/teeworld

Bug#856086: Patch for monster-masher

2018-10-21 Thread Markus Koschany
Hi! Thanks again for your patches to port monster-masher away from esound and gconfmm. I only noticed that the Close button in the "Info" submenu doesn't work as intended. Otherwise the game seems to work. Minor nitpick: Please consider to submit a debdiff for future patches because it is easier

Bug#856086: Bug#885037: Patch for monster-masher

2018-10-21 Thread Markus Koschany
Am 21.10.18 um 23:51 schrieb Yavor Doganov: > Markus Koschany wrote: >> I only noticed that the Close button in the "Info" submenu doesn't >> work as intended. > > There is no "Info" submenu; I guess you mean the Close button in the > About dia

Bug#886394: pdfsam still shows the same error although it does give the banner as gimp does while starting up.

2018-10-23 Thread Markus Koschany
Control: forwarded -1 https://github.com/torakiki/pdfsam/issues/310 thanks Apparently upstream managed to run PDFsam with OpenJFX 11. I'm currently investigating why it doesn't work for us. signature.asc Description: OpenPGP digital signature

Bug#911709: tomcat7: Security update broke apps with AccessControlException for org.apache.tomcat.util.http

2018-10-23 Thread Markus Koschany
Hello, Am 23.10.18 um 21:20 schrieb Anthony DeRobertis: > Package: tomcat7 > Version: 7.0.56-3+really7.0.91-1 > Severity: important > > After applying the recent security update, the web app we're running > (which is unfortunately a proprietary product provided by a vendor) no > longer works. Ins

Bug#910764: openjfx: segmentation fault in GtkNativeMainLoopThread

2018-10-24 Thread Markus Koschany
I believe I have found a way to workaround this issue for the moment. If I pass -Djdk.gtk.version=2 to PDFsam version 3.3.7 it no longer crashes. However there is another issue with fontawesomefx, so there is still some work to do. I think I will forward this issue to the OpenJFX developers because

Bug#911093: libjetbrains-annotations-java: missing Breaks+Replaces: libintellij-annotations-java (<< 16.0.2-4)

2018-10-25 Thread Markus Koschany
On Mon, 15 Oct 2018 17:48:38 +0200 Andreas Beckmann wrote: > Package: libjetbrains-annotations-java > Version: 16.0.2-4 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts replaces-without-breaks > > Hi, > > during a test with piuparts and DOSE tools I noticed your packag

Bug#892351: Bug#911487: teeworlds: remote DOS by forging connection packets

2018-10-25 Thread Markus Koschany
Control: owner -1 ! I'm currently working on updating Teeworlds to version 0.7. Markus signature.asc Description: OpenPGP digital signature

Bug#914537: openmw: segfault at start

2019-02-04 Thread Markus Koschany
On Sun, 25 Nov 2018 20:15:08 +0100 bret curtis wrote: > Thanks Fred! > > We're tracking it upstream. Will keep this bug posted with results. > > https://gitlab.com/OpenMW/openmw/issues/4737 Hello Bret, we are running out of time for Debian 10 "Buster" because the soft freeze starts next week.

Bug#914537: openmw: segfault at start

2019-02-04 Thread Markus Koschany
Am 04.02.19 um 14:31 schrieb psi...@gmail.com: > Hello Markus, > > as it turns out, we're about to have another release 0.45 that has been in > 'the-works' for the past month. It's been ready for awhile, we've just been > waiting on PR to make a release video and finish up a write-up. > > I'll a

Bug#897945: [Openjdk] Bug#920037: Bug#897945: #897945 still present/breaks with Java 8

2019-02-04 Thread Markus Koschany
Am 04.02.19 um 14:56 schrieb Per Lundberg: > On 2/1/19 11:20 AM, Matthias Klose wrote: >> On 01.02.19 10:03, Emmanuel Bourg wrote: > >>> This is an excellent suggestion. We should file a bug for openjdk-8 to >>> implement that. >> please attach the patch. > > Sure, I should be able to write som

Bug#914537: openmw: segfault at start

2019-02-06 Thread Markus Koschany
Hi Bret, Am 06.02.19 um 11:43 schrieb psi...@gmail.com: > Hello! > > Hot off the presses, OpenMW 0.45.0 > https://salsa.debian.org/games-team/openmw > > I built it against buster and sid, tested both and ran without segfaults. > This should wrap up this bug (closes in changelog entry). > > Plea

Bug#918736: libthrift-java: CVE-2018-1320

2019-02-06 Thread Markus Koschany
-2018-1320.patch 1970-01-01 01:00:00.0 +0100 +++ libthrift-java-0.9.1/debian/patches/CVE-2018-1320.patch 2019-02-06 19:04:12.0 +0100 @@ -0,0 +1,32 @@ +From: Markus Koschany +Date: Wed, 6 Feb 2019 18:59:31 +0100 +Subject: CVE-2018-1320 + +Bug-Debian: https://bugs.debia

Bug#921274: teeworlds: baseline violation on i386

2019-02-06 Thread Markus Koschany
On Sun, 03 Feb 2019 22:35:22 +0200 Adrian Bunk wrote: > Source: teeworlds > Version: 0.7.2-2 > Severity: serious > Tags: patch > > SSE is not part of the i386 baseline, fix attached. Could you go into more detail why this is release-critical and what issue we are trying to solve? Markus sign

Bug#921613: mediathekview: fails to run with openjdk-11

2019-02-07 Thread Markus Koschany
Am 07.02.19 um 08:56 schrieb Alois Schlögl: > Package: mediathekview > Version: 13.2.1-2 > Severity: important > [warning] /usr/bin/mediathekview: JVM flavor 'java9' not understood > [warning] /usr/bin/mediathekview: No java runtime was found > >    * What outcome did you expect instea

Bug#921274: teeworlds: baseline violation on i386

2019-02-10 Thread Markus Koschany
Control: tags -1 moreinfo Control: severity -1 important On Wed, 6 Feb 2019 22:39:02 +0100 Markus Koschany wrote: > On Sun, 03 Feb 2019 22:35:22 +0200 Adrian Bunk wrote: > > Source: teeworlds > > Version: 0.7.2-2 > > Severity: serious > > Tags: patch > >

Bug#921274: teeworlds: baseline violation on i386

2019-02-10 Thread Markus Koschany
Control: severity -1 important Am 10.02.19 um 12:20 schrieb Adrian Bunk: [...] > Teeworlds runs fine on some i386 machines. > > Individual packages cannot just use non-baseline features like > SSE or AVX without runtime detection, this results in nothing > but crashes on hardware officially supp

Bug#922190: netbeans: Illegal reflective access by org.netbeans.core.windows.view.ui.MainWindow

2019-02-13 Thread Markus Koschany
Hi, Am 13.02.19 um 02:45 schrieb Gustavo Castro: > Package: netbeans > Version: 10.0-2 > Severity: normal > > Dear Maintainer, > > netbeans has a failure at the beginning > > WARNING: An illegal reflective access operation has occurred > WARNING: Illegal reflective access by > org.netbeans.core

Bug#919831: Javadoc -link makes broken links if module name matches package name

2019-02-13 Thread Markus Koschany
Hi, Am 26.01.19 um 20:07 schrieb tony mancill: [...] > I'm trying to peel the onion and believe that this is a problem in the > maven-javadoc-plugin package. I found the same issue for a project > outside of Debian, for example [1], which refers to a JIRA ticket for that > plugin [2]. There is a

Bug#922190: Fwd: Bug#922190: netbeans: Illegal reflective access by org.netbeans.core.windows.view.ui.MainWindow

2019-02-14 Thread Markus Koschany
Hi Gustavo, Am 13.02.19 um 23:23 schrieb Gustavo Castro: [...] > java.lang.SecurityException: sealing violation >     at org.netbeans.JarClassLoader.doLoadClass(Unknown Source) >     at org.netbeans.ProxyClassLoader.selfLoadClass(Unknown Source) >     at org.netbeans.ProxyClassLoader.loadClass(Unk

Bug#912231: bnd FTBFS with OpenJDK 11

2018-10-29 Thread Markus Koschany
ava:372) /usr/bin/mh_installpom: line 148: debian/.mh/pom.properties: No such file or directory make: *** [debian/rules:9: binary] Error 1 From: Markus Koschany Date: Mon, 29 Oct 2018 20:36:31 +0100 Subject: java11 Fix biz.aQute.remote/src/aQute/remote/agent/RedirectOutput.java:41: error: nullOutputStrea

Bug#912221: jabref: incompatible with openjdk 11

2018-10-30 Thread Markus Koschany
Am 30.10.18 um 01:15 schrieb Emmanuel Bourg: > Le 30/10/2018 à 00:41, gregor herrmann a écrit : > >> I guess we need to make sure that we build with openjdk-8. >> (You know this better than me but I seem to remember that the plan >> was to keep openjdk-8 in buster for building packages?) > > No p

Bug#911187: axis: FTBFS with Java 11 due to javax.rmi and CORBA removal

2018-10-30 Thread Markus Koschany
I was investigating the Java 11 FTBFS of axis and uddi4j. I wonder if we rather should focus on removing these packages instead of patching them. Axis has seen its last release in 2006. AFAIK Apache CXF would be a better alternative because it is actively maintained. Unfortunately it is not availa

Bug#910764: Forward 910764 OpenJFX 11 segmentation fault

2018-10-30 Thread Markus Koschany
Control: forwarded -1 https://bugs.java.com/bugdatabase/view_bug.do?bug_id=JDK-8213149 thanks Look like upstream can't reproduce this issue with their custom JDK image. signature.asc Description: OpenPGP digital signature

Bug#906837: xul-ext-ublock-origin no longer works with firefox-esr 60

2018-10-30 Thread Markus Koschany
Am 30.10.18 um 18:25 schrieb Thierry: > Adrian Bunk wrote: > >> Package: xul-ext-ublock-origin >> Version: 1.10.4+dfsg-1 >> Severity: serious >> Control: fixed -1 1.16.6+dfsg-1 >> Control: close -1 >> >> XUL addons are no longer supported. >> >> This is already fixed in unstable. > > OK, but w

Bug#910764: Forward 910764 OpenJFX 11 segmentation fault

2018-10-31 Thread Markus Koschany
Control: severity -1 important On Tue, 30 Oct 2018 14:39:11 +0100 Markus Koschany wrote: > Control: forwarded -1 > https://bugs.java.com/bugdatabase/view_bug.do?bug_id=JDK-8213149 > thanks > > Look like upstream can't reproduce this issue with their custom JDK image. >

Bug#912751: jh_installjavadoc: produces incorrect doc-base file

2018-11-03 Thread Markus Koschany
Package: javahelper Version: 0.70 Severity: important I discovered a regression in jh_installjavadoc. This tool will automatically create a doc-base file. In libjackson-json-java 1.9.2-9 the content looks as follows: Format: HTML Index: //usr/share/doc/libjackson-json-java/api Files: //usr/shar

Bug#911194: libbtm-java: FTBFS with Java 11 due to javax.rmi removal

2018-11-03 Thread Markus Koschany
libbtm-java looks like a removal candidate for me. Last release was in 2012, project looks pretty much stalled. https://github.com/bitronix/btm The only r-dep is ehcache which uses libbtm-java for its tests. signature.asc Description: OpenPGP digital signature

Bug#912825: Couldn't open audio: Couldn't set hardware audio parameters: Success

2018-11-04 Thread Markus Koschany
Am 04.11.18 um 06:55 schrieb Harald Dunkel: > Package: bzflag > Version: 2.4.18-1 > > Since the upgrade of alsa-lib to version 1.1.7 bzflag has lost sound > via alsa. At start time there is just a message > > Couldn't open audio: Couldn't set hardware audio parameters: Success > > Moving back t

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-04 Thread Markus Koschany
Package: mysql-connector-java X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for mysql-connector-java. CVE-2018-3258[0]: | Vulnerability in the MySQL Connectors component of Oracle MySQL | (subcomponent: Connector/J). Supported

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-05 Thread Markus Koschany
Am 05.11.18 um 14:13 schrieb Moritz Mühlenhoff: [...] > The Java connector follows the horrible Oracle policy of not disclosing > vulnerability information. Given that we now have mariadb-connector-java > in the archive (with a transparent upstream), can we migrate existing > reverse deps towards

Bug#912997: glusterfs: Several security vulnerabilities

2018-11-05 Thread Markus Koschany
Package: glusterfs X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for glusterfs. CVE-2018-14651[0]: | It was found that the fix for CVE-2018-10927, CVE-2018-10928, | CVE-2018-10929, CVE-2018-10930, and CVE-2018-10926 was inc

Bug#913011: eboard: add Conflicts: eboard-extras-pack1

2018-11-06 Thread Markus Koschany
Control: tags -1 pending Thanks for reporting. The extra packs are included in eboard now. I have updated the Breaks and Replaces fields in debian/control and I am going to request the removal of eboard-extras-pack1 from Debian. Regards, Markus signature.asc Description: OpenPGP digital signa

Bug#912916: mysql-connector-java: CVE-2018-3258: allows low privileged attacker to compromise it

2018-11-08 Thread Markus Koschany
Am 08.11.18 um 19:34 schrieb Moritz Mühlenhoff: [...] > So upon a closer look this seems to only affect the 8.x releases of the > connector (Oracle only lists those affected release series which are > affected and this only lists 8.x, while 5.1.x is still supported; there's > a 5.1.47 release). >

Bug#913307: osmosis: please switch to libmariadb-java

2018-11-09 Thread Markus Koschany
Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Fri, 9 Nov 2018 13:39:08 +0100 Subject: [PATCH 1/2] Switch from libmysql-java to libmariadb-java. --- debian/control | 4 ++-- debian/maven.rules | 1 + debian/patches/02-fix_plexus.patch | 2 +- 3 files chan

Bug#913307: osmosis: please switch to libmariadb-java

2018-11-09 Thread Markus Koschany
There was a mistake in mariadb.patch. s/com/org. Updated patch is attached From: Markus Koschany Date: Fri, 9 Nov 2018 13:55:11 +0100 Subject: mariadb Use MariaDB driver class. Forwarded: no --- .../java/org/openstreetmap/osmosis/apidb/common/DataSourceFactory.java | 2 +- 1 file changed, 1

Bug#913323: igv: please switch to libmariadb-java

2018-11-09 Thread Markus Koschany
:00 2001 From: Markus Koschany Date: Fri, 9 Nov 2018 16:02:33 +0100 Subject: [PATCH] Replace libmysql-java with libmariadb-java. --- debian/control | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/debian/control b/debian/control index a3b5948..97d88d1 100644 --- a/debian/cont

Bug#895765: IGV FTBFS with Java 11

2018-11-09 Thread Markus Koschany
that makes the necessary changes to the Debian packaging without using a patch. Markus From 86feef76191c245ec314f1efc66f0f6dfba1a634 Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Fri, 9 Nov 2018 16:14:47 +0100 Subject: [PATCH 1/2] B-D on libjaxb-api-java and fix FTBFS with Java 11. ---

Bug#913323: igv: please switch to libmariadb-java

2018-11-09 Thread Markus Koschany
On closer inspection I'm not sure why you need the build-dependency on libmysql-java at all. The package builds fine without it. I wonder how igv loads the jdbc driver. It seems to make a runtime connection to a MySQL/MariaDB server though. Could also just be an option. See line 83 in src/main/ja

Bug#913343: jclic: please switch to libmariadb-java

2018-11-09 Thread Markus Koschany
Mon Sep 17 00:00:00 2001 From: Markus Koschany Date: Fri, 9 Nov 2018 18:32:31 +0100 Subject: [PATCH] Switch from libmysql-java to libmariadb-java. --- debian/changelog | 7 +++ debian/control | 2 +- debian/patches/mariadb.patch |

<    1   2   3   4   5   6   7   8   9   10   >