Re: Bug#1038853: usrmerge: clean up the unused empty biarch directories

2023-06-24 Thread Paul Gevers

Hi Marco,

On 22-06-2023 17:41, Marco d'Itri wrote:

Release managers, I would like to upload to 12.1 a new package to fix
this (and other minor issues).


Please file a proper proposed-updates bug report as our workflow relies 
on them.


Paul


OpenPGP_signature
Description: OpenPGP digital signature


NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: gnome-shell_43.6-1~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_i386-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: mutter_43.6-1~deb12u1_s390x-buildd.changes
  ACCEPT



Bug#1039047: bookworm-pu: package cvs/2:1.12.13+real-28+deb12u1

2023-06-24 Thread Thorsten Glaser
Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: c...@packages.debian.org, t...@mirbsd.de
Control: affects -1 + src:cvs

Pre-approval with debdiff.

[ Reason ]
CVS was always compiled with --with-rsh=ssh but the configure
script ignored that and used rsh because it could not find an
ssh binary in the PATH at compile time. This used to be not a
problem because ssh was aliased to rsh but in bookworm it no
longer is.

[ Impact ]
Users are unable to cvs update or cvs commit or anything else
unless they manually export CVS_RSH=ssh or change their access
method from :ext: to :extssh: (which is a relatively new thing
and may not be universally known, e.g. to frontends).

If this is rejected, I’d suggest the $CVS_RSH workaround be
added to the release notes, if they can be changed at this
point in time.

[ Tests ]
The change switches the cpp macro RSH_DFLT, which is used in
only two places to set the default rsh. I have tested this as
part of the larger changes in tonight’s sid upload, and code
inspection shows this has no effect on unrelated code.

[ Risks ]
See above, this is a no-risk change.

[ Checklist ]
  [✓] *all* changes are documented in the d/changelog
  [✓] I reviewed all changes and I approve them
  [✓] attach debdiff against the package in (old)stable
  [✓] the issue is verified as fixed in unstable

[ Changes ]
Pass the full path to ssh(1) to configure so it’s actually used.
diff -u cvs-1.12.13+real/debian/changelog cvs-1.12.13+real/debian/changelog
--- cvs-1.12.13+real/debian/changelog
+++ cvs-1.12.13+real/debian/changelog
@@ -1,3 +1,9 @@
+cvs (2:1.12.13+real-28+deb12u1) bookworm; urgency=high
+
+  * configure-time hardcode full path for ssh(1) (Closes: #1038926)
+
+ -- Thorsten Glaser   Sat, 24 Jun 2023 19:48:48 +0200
+
 cvs (2:1.12.13+real-28) unstable; urgency=medium
 
   [ Helmut Grohne ]
diff -u cvs-1.12.13+real/debian/rules cvs-1.12.13+real/debian/rules
--- cvs-1.12.13+real/debian/rules
+++ cvs-1.12.13+real/debian/rules
@@ -66,7 +66,7 @@
--without-krb4 \
--with-gssapi \
--with-external-zlib \
-   --with-rsh=ssh \
+   --with-rsh=/usr/bin/ssh \
--with-editor=/usr/bin/editor \
--with-tmpdir=/var/tmp \
--with-umask=002 \


Processed: bookworm-pu: package cvs/2:1.12.13+real-28+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> affects -1 + src:cvs
Bug #1039047 [release.debian.org] bookworm-pu: package 
cvs/2:1.12.13+real-28+deb12u1
Added indication that 1039047 affects src:cvs

-- 
1039047: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039047
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: appstream-glib_0.7.18-1+deb11u1_s390x-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_s390x-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_s390x-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_mips64el-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_s390x-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: dpdk_22.11.2-2~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: gnome-control-center_43.6-2~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: mate-power-manager_1.26.0-2+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_s390x-buildd.changes
  ACCEPT



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: dbus_1.12.28-0+deb11u1_i386-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: aide_0.18.3-1+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: dpdk_22.11.2-2~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_amd64-buildd.changes
  ACCEPT



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: appstream-glib_0.7.18-1+deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: spip_3.2.11-3+deb11u8_all-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_amd64-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_i386-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_mips64el-buildd.changes
  ACCEPT



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: systemd_247.3-7+deb11u4_mipsel-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: aide_0.18.3-1+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: dpdk_22.11.2-2~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_ppc64el-buildd.changes
  ACCEPT



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: appstream-glib_0.7.18-1+deb11u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_arm64-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_armel-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_armhf-buildd.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_ppc64el-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: dpdk_22.11.2-2~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: spip_4.1.9+dfsg-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_armhf-buildd.changes
  ACCEPT



Bug#1039040: bullseye-pu: cups/2.3.3op2-3+deb11u3

2023-06-24 Thread Thorsten Alteholz

Package: release.debian.org
Severity: normal
Tags: bullseye
User: release.debian@packages.debian.org
Usertags: pu


The attached debdiff for cups fixes CVE-2023-32324 and CVE-2023-34241 in 
Bullseye. Both CVE have been marked as no-dsa by the security team.


The same fixes have been already uploaded to Unstable and nobody 
complained yet.


  Thorsten
diff -Nru cups-2.3.3op2/debian/changelog cups-2.3.3op2/debian/changelog
--- cups-2.3.3op2/debian/changelog  2022-05-23 22:03:02.0 +0200
+++ cups-2.3.3op2/debian/changelog  2023-06-24 10:54:05.0 +0200
@@ -1,3 +1,14 @@
+cups (2.3.3op2-3+deb11u3) bullseye; urgency=medium
+
+  * CVE-2023-34241 (Closes: #1038885)
+use-after-free in cupsdAcceptClient()
+
+  * CVE-2023-32324
+A heap buffer overflow vulnerability would allow a remote attacker to 
+lauch a dos attack.
+
+ -- Thorsten Alteholz   Sat, 24 Jun 2023 10:54:05 +0200
+
 cups (2.3.3op2-3+deb11u2) bullseye-security; urgency=high
 
   * CVE-2022-26691
diff -Nru cups-2.3.3op2/debian/patches/0017-CVE-2023-32324.patch 
cups-2.3.3op2/debian/patches/0017-CVE-2023-32324.patch
--- cups-2.3.3op2/debian/patches/0017-CVE-2023-32324.patch  1970-01-01 
01:00:00.0 +0100
+++ cups-2.3.3op2/debian/patches/0017-CVE-2023-32324.patch  2023-06-24 
10:54:05.0 +0200
@@ -0,0 +1,29 @@
+From: Thorsten Alteholz 
+Date: Wed, 31 May 2023 23:20:58 +0200
+Subject: CVE-2023-32324
+
+---
+ cups/string.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/cups/string.c b/cups/string.c
+index 93cdad1..1f81d60 100644
+--- a/cups/string.c
 b/cups/string.c
+@@ -1,6 +1,7 @@
+ /*
+  * String functions for CUPS.
+  *
++ * Copyright © 2023 by OpenPrinting.
+  * Copyright © 2007-2019 by Apple Inc.
+  * Copyright © 1997-2007 by Easy Software Products.
+  *
+@@ -729,6 +730,8 @@ _cups_strlcpy(char   *dst, /* O - 
Destination string */
+ {
+   size_t  srclen; /* Length of source string */
+ 
++  if (size == 0)
++return (0);
+ 
+  /*
+   * Figure out how much room is needed...
diff -Nru cups-2.3.3op2/debian/patches/0018-CVE-2023-34241.patch 
cups-2.3.3op2/debian/patches/0018-CVE-2023-34241.patch
--- cups-2.3.3op2/debian/patches/0018-CVE-2023-34241.patch  1970-01-01 
01:00:00.0 +0100
+++ cups-2.3.3op2/debian/patches/0018-CVE-2023-34241.patch  2023-06-24 
10:54:05.0 +0200
@@ -0,0 +1,57 @@
+From: Thorsten Alteholz 
+Date: Sat, 24 Jun 2023 19:51:21 +0200
+Subject: CVE-2023-34241
+
+---
+ scheduler/client.c | 16 +++-
+ 1 file changed, 7 insertions(+), 9 deletions(-)
+
+diff --git a/scheduler/client.c b/scheduler/client.c
+index 9730eea..48e19b9 100644
+--- a/scheduler/client.c
 b/scheduler/client.c
+@@ -192,13 +192,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+/*
+ * Can't have an unresolved IP address with double-lookups enabled...
+ */
+-
+-httpClose(con->http);
+-
+ cupsdLogClient(con, CUPSD_LOG_WARN,
+-"Name lookup failed - connection from %s closed!",
++"Name lookup failed - closing connection from %s!",
+ httpGetHostname(con->http, NULL, 0));
+ 
++httpClose(con->http);
+ free(con);
+ return;
+   }
+@@ -234,11 +232,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+   * with double-lookups enabled...
+   */
+ 
+-  httpClose(con->http);
+-
+   cupsdLogClient(con, CUPSD_LOG_WARN,
+-  "IP lookup failed - connection from %s closed!",
++  "IP lookup failed - closing connection from %s!",
+   httpGetHostname(con->http, NULL, 0));
++
++  httpClose(con->http);
+   free(con);
+   return;
+ }
+@@ -255,11 +253,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+ 
+   if (!hosts_access(_req))
+   {
+-httpClose(con->http);
+-
+ cupsdLogClient(con, CUPSD_LOG_WARN,
+ "Connection from %s refused by /etc/hosts.allow and "
+   "/etc/hosts.deny rules.", httpGetHostname(con->http, NULL, 
0));
++
++httpClose(con->http);
+ free(con);
+ return;
+   }
diff -Nru cups-2.3.3op2/debian/patches/series 
cups-2.3.3op2/debian/patches/series
--- cups-2.3.3op2/debian/patches/series 2022-05-23 22:03:02.0 +0200
+++ cups-2.3.3op2/debian/patches/series 2023-06-24 10:54:05.0 +0200
@@ -14,3 +14,5 @@
 0014-Debian-Reproducibility-Run-testlang-for-each-provide.patch
 0015-Debian-po4a-infrastructure-and-translations-for-manp.patch
 0016-Fix-certificate-comparison-CVE-2022-26691.patch
+0017-CVE-2023-32324.patch
+0018-CVE-2023-34241.patch


NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: appstream-glib_0.7.18-1+deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_armel-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: appstream-glib_0.7.18-1+deb11u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_armel-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_armel-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_mipsel-buildd.changes
  ACCEPT



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: aide_0.18.3-1+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: aide_0.18.3-1+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: aide_0.18.3-1+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: dbus_1.14.8-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: dpdk_22.11.2-2~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: fai_6.0.3+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: gnome-control-center_43.6-2~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: 
gnome-control-center_43.6-2~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: mate-power-manager_1.26.0-2+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: 
mate-power-manager_1.26.0-2+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: 
mate-session-manager_1.26.0-1+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_armhf-buildd.changes
  ACCEPT



Bug#1039039: bookworm-pu: package multipath-tools/0.9.4-3+deb12u1

2023-06-24 Thread Chris Hofstaedtler
Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: multipath-to...@packages.debian.org, z...@debian.org
Control: affects -1 + src:multipath-tools

[ Reason ]

Packaging bugs #1037292 and #1037539 have been discovered after the release,
this update will fix them in stable.


[ Impact ]

#1037539 causes devices underlying mpath devs to be visible to LVM et al,
confusing LVMs device setup.

#1037292 causes multipathd.service fail to start on fresh installs before a
reboot. Upgrades from older versions are not affected, and after a reboot it
also workes just fine.

[ Tests ]

I've manually verified the fixes in stable (and also for unstable).

[ Risks ]

#1037539 is caused by an upstream filename change that went unnoticed.
#1037292 switches back to the approach used in bullseye, which we know works.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]

#1037539: fix filename, and make sure package build failes if any of the udev
rules are not found at build time

#1037292: re-add modprobe before starting multipathd. Upstream switched its
approach to module loading, but I think that was somewhat unfinished in 0.9.4.

[ Other info ]
(none)

Thanks,
Chris
diff -Nru multipath-tools-0.9.4/debian/changelog 
multipath-tools-0.9.4/debian/changelog
--- multipath-tools-0.9.4/debian/changelog  2023-02-07 11:16:57.0 
+0100
+++ multipath-tools-0.9.4/debian/changelog  2023-06-24 23:07:02.0 
+0200
@@ -1,3 +1,14 @@
+multipath-tools (0.9.4-3+deb12u1) bookworm; urgency=medium
+
+  * [cfa5138] Re-add dm-multipath module loading to ExecStartPre
+(Closes: #1037292)
+  * [1289691] Fail package build if udev rules are missing
+  * [2e45796] Install udev mulitpath.rules again.
+Thanks to Joshua Huber  (Closes: #1037539)
+  * [6b05510] debian/gbp.conf: update branch for bookworm
+
+ -- Chris Hofstaedtler   Sat, 24 Jun 2023 23:07:02 +0200
+
 multipath-tools (0.9.4-3) unstable; urgency=medium
 
   [ Chris Lamb ]
diff -Nru multipath-tools-0.9.4/debian/gbp.conf 
multipath-tools-0.9.4/debian/gbp.conf
--- multipath-tools-0.9.4/debian/gbp.conf   2023-02-07 11:16:57.0 
+0100
+++ multipath-tools-0.9.4/debian/gbp.conf   2023-06-24 23:07:02.0 
+0200
@@ -1,7 +1,7 @@
 [DEFAULT]
 pristine-tar = True
 upstream-tag = upstream/%(version)s
-debian-branch = master
+debian-branch = debian/bookworm
 debian-tag = debian/%(version)s
 debian-tag-msg = %(pkg)s Debian release %(version)s
 
diff -Nru 
multipath-tools-0.9.4/debian/patches/0006-multipathd.service-re-add-ExecStartPre.patch
 
multipath-tools-0.9.4/debian/patches/0006-multipathd.service-re-add-ExecStartPre.patch
--- 
multipath-tools-0.9.4/debian/patches/0006-multipathd.service-re-add-ExecStartPre.patch
  1970-01-01 01:00:00.0 +0100
+++ 
multipath-tools-0.9.4/debian/patches/0006-multipathd.service-re-add-ExecStartPre.patch
  2023-06-24 23:07:02.0 +0200
@@ -0,0 +1,28 @@
+From: Chris Hofstaedtler 
+Date: Sat, 10 Jun 2023 12:42:40 +0200
+Subject: multipathd.service: re-add ExecStartPre
+
+Upstream commit a1eabea75e8e0f6072f2b655cae25ec473b006c5 removed this,
+claiming the modules-load.d snippet would be enough. Maybe it is on other
+distributions, but Debian does not reload modules-load.d snippets on
+package install. Without this, first time installs would need a reboot
+or manual package loading.
+
+Forwarded: no
+Origin: vendor
+---
+ multipathd/multipathd.service | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/multipathd/multipathd.service b/multipathd/multipathd.service
+index aec62db..ae98034 100644
+--- a/multipathd/multipathd.service
 b/multipathd/multipathd.service
+@@ -16,6 +16,7 @@ ConditionVirtualization=!container
+ [Service]
+ Type=notify
+ NotifyAccess=main
++ExecStartPre=-/sbin/modprobe dm-multipath
+ ExecStart=/sbin/multipathd -d -s
+ ExecReload=/sbin/multipathd reconfigure
+ TasksMax=infinity
diff -Nru multipath-tools-0.9.4/debian/patches/series 
multipath-tools-0.9.4/debian/patches/series
--- multipath-tools-0.9.4/debian/patches/series 2023-02-07 11:16:57.0 
+0100
+++ multipath-tools-0.9.4/debian/patches/series 2023-06-24 23:07:02.0 
+0200
@@ -6,3 +6,4 @@
 0009-kpartx-rules-use-Debian-specific-partx-path.patch
 0010-multipath.rules-do-not-assume-usrmerged-paths.patch
 0012-Reproducible-build.patch
+0006-multipathd.service-re-add-ExecStartPre.patch
diff -Nru multipath-tools-0.9.4/debian/rules multipath-tools-0.9.4/debian/rules
--- multipath-tools-0.9.4/debian/rules  2023-02-07 11:16:57.0 +0100
+++ multipath-tools-0.9.4/debian/rules  2023-06-24 23:07:02.0 +0200
@@ -39,15 +39,15 @@
 override_dh_auto_test:
 
 override_dh_auto_install:
-   [ ! -f kpartx/del-part-nodes.rules ] || cp 

Processed: bookworm-pu: package multipath-tools/0.9.4-3+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> affects -1 + src:multipath-tools
Bug #1039039 [release.debian.org] bookworm-pu: package 
multipath-tools/0.9.4-3+deb12u1
Added indication that 1039039 affects src:multipath-tools

-- 
1039039: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039039
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_source.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
firefox-esr_102.12.0esr-1~deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: firefox-esr_102.12.0esr-1~deb11u1_s390x-buildd.changes
  ACCEPT
Processing changes file: spip_3.2.11-3+deb11u8_source.changes
  ACCEPT
Processing changes file: systemd_247.3-7+deb11u4_source.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_source.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: thunderbird_102.12.0-1~deb11u1_s390x-buildd.changes
  ACCEPT



Processed: transition: qtbase-abi-5-15-10

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> block -1 by 1038402 1038737
Bug #1039030 [release.debian.org] transition: qtbase-abi-5-15-10
1039030 was not blocked by any bugs.
1039030 was not blocking any bugs.
Added blocking bug(s) of 1039030: 1038402 and 1038737
> affects -1 + src:qtbase-opensource-src
Bug #1039030 [release.debian.org] transition: qtbase-abi-5-15-10
Added indication that 1039030 affects src:qtbase-opensource-src

-- 
1039030: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039030
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1039030: transition: qtbase-abi-5-15-10

2023-06-24 Thread Dmitry Shachnev
Package: release.debian.org
Severity: normal
User: release.debian@packages.debian.org
Usertags: transition
Control: block -1 by 1038402 1038737
Control: affects -1 + src:qtbase-opensource-src

Dear Release team,

We skipped Qt 5.15.9 release because of the freeze, so now I would like to
upgrade from 5.15.8 to 5.15.10 — a version which was published on June 6th.

Qt 5.15.10 is prepared in experimental. Also, there is a new Qt WebEngine
release — 5.15.14.

I have prepared a merge request with the ben file here:
https://salsa.debian.org/release-team/transition-data/-/merge_requests/40

There are two known blockers, but I can NMU them if the maintainers don't
act until the transition start. Also it makes sense to wait until the re2
transition migrates, because qtwebengine is involved there.

--
Dmitry Shachnev


signature.asc
Description: PGP signature


Processed: systemd 247.3-7+deb11u4 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038451 = bullseye pending
Bug #1038451 [release.debian.org] bullseye-pu: package systemd/247.3-7+deb11u4
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038451: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038451
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038451: systemd 247.3-7+deb11u4 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038451 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==

Package: systemd
Version: 247.3-7+deb11u4

Explanation: fix a calendar spec calculation hang on DST change if 
TZ=Europe/Dublin



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: appstream-glib_0.7.18-1+deb11u1_source.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_source.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_all-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_amd64-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_arm64-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_armel-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_armhf-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_i386-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_mips64el-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_mipsel-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_ppc64el-buildd.changes
  ACCEPT
Processing changes file: asterisk_16.28.0~dfsg-0+deb11u3_s390x-buildd.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_source.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: chromium_114.0.5735.133-1~deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
chromium_114.0.5735.133-1~deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: dbus_1.12.28-0+deb11u1_source.changes
  ACCEPT
Processing changes file: hsqldb_2.5.1-1+deb11u2_source.changes
  ACCEPT
Processing changes file: hsqldb_2.5.1-1+deb11u2_all-buildd.changes
  ACCEPT
Processing changes file: hsqldb1.8.0_1.8.0.10+dfsg-10+deb11u1_source.changes
  ACCEPT
Processing changes file: hsqldb1.8.0_1.8.0.10+dfsg-10+deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: libprelude_5.2.0-3+deb11u1_source.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_multi.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_armel-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: libx11_1.7.2-1+deb11u1_s390x-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_sourceonly.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_amd64-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_arm64-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_armel-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_armhf-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_i386-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_mips64el-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_mipsel-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_ppc64el-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2+deb11u2_s390x-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_source.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_armhf-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_i386-buildd.changes
  ACCEPT
Processing changes file: 
trafficserver_8.1.7+ds-1~deb11u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: trafficserver_8.1.7+ds-1~deb11u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb11u1_source.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb11u1_all-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb11u1_amd64-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb11u1_arm64-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb11u1_armel-buildd.changes
  ACCEPT
Processing changes file: 

NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: dbus_1.14.8-1~deb12u1_source.changes
  ACCEPT
Processing changes file: dpdk_22.11.2-2~deb12u1_source.changes
  ACCEPT
Processing changes file: fai_6.0.3+deb12u1_amd64.changes
  ACCEPT
Processing changes file: gnome-control-center_43.6-2~deb12u1_source.changes
  ACCEPT
Processing changes file: gnome-maps_43.5-2~deb12u1_source.changes
  ACCEPT
Processing changes file: gnome-shell_43.6-1~deb12u1_source.changes
  ACCEPT
Processing changes file: libmatekbd_1.26.0-1+deb12u1_source.changes
  ACCEPT
Processing changes file: mate-power-manager_1.26.0-2+deb12u1_source.changes
  ACCEPT
Processing changes file: mate-session-manager_1.26.0-1+deb12u1_source.changes
  ACCEPT
Processing changes file: mutter_43.6-1~deb12u1_source.changes
  ACCEPT
Processing changes file: postfix_3.7.6-0+deb12u1_source.changes
  ACCEPT
Processing changes file: systemd_252.11-1~deb12u1_source.changes
  ACCEPT
Processing changes file: trafficserver_9.2.0+ds-2+deb12u1_source.changes
  ACCEPT
Processing changes file: trafficserver_9.2.0+ds-2+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: trafficserver_9.2.0+ds-2+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: vte2.91_0.70.6-1~deb12u1_source.changes
  ACCEPT



Processed: dbus 1.12.28-0+deb11u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037196 = bullseye pending
Bug #1037196 [release.debian.org] bullseye-pu: package dbus/1.12.28-0+deb11u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037196: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037196
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: spip 3.2.11-3+deb11u8 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038153 = bullseye pending
Bug #1038153 [release.debian.org] bullseye-pu: package spip/3.2.11-3+deb11u8
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038153: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038153
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: libprelude 5.2.0-3+deb11u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037187 = bullseye pending
Bug #1037187 [release.debian.org] bullseye-pu: package 
libprelude/5.2.0-3+deb11u1
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037187: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037187
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038153: spip 3.2.11-3+deb11u8 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038153 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==

Package: spip
Version: 3.2.11-3+deb11u8

Explanation: several security fixes



Processed: appstream-glib 0.7.18-1+deb11u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037214 = bullseye pending
Bug #1037214 [release.debian.org] bullseye-pu: package 
appstream-glib/0.7.18-1+deb11u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037214: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037214
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1037214: appstream-glib 0.7.18-1+deb11u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037214 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==

Package: appstream-glib
Version: 0.7.18-1+deb11u1

Explanation: handle  and  tags in metadata



Bug#1037196: dbus 1.12.28-0+deb11u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037196 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==

Package: dbus
Version: 1.12.28-0+deb11u1

Explanation: new upstream stable release; fix denial of service issue 
[CVE-2023-34969]



Bug#1037187: libprelude 5.2.0-3+deb11u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037187 = bullseye pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bullseye.

Thanks for your contribution!

Upload details
==

Package: libprelude
Version: 5.2.0-3+deb11u1

Explanation: make Python module usable



Processed: systemd 252.11-1~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037420 = bookworm pending
Bug #1037420 [release.debian.org] bookworm-pu: package systemd/252.11-1~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037420: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037420
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1037420: systemd 252.11-1~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037420 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: systemd
Version: 252.11-1~deb12u1

Explanation: new upstream bugfix release



Processed: vte2.91 0.70.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038390 = bookworm pending
Bug #1038390 [release.debian.org] bookworm-pu: package vte2.91/0.70.6-1~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038390: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038390
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038390: vte2.91 0.70.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038390 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: vte2.91
Version: 0.70.6-1~deb12u1

Explanation: new upstream bugfix release



Processed: mutter 43.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1036856 = bookworm pending
Bug #1036856 [release.debian.org] bookworm-pu: package mutter/43.6-1~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1036856: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036856
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: postfix 3.7.6-0+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037305 = bookworm pending
Bug #1037305 [release.debian.org] bookworm-pu: package postfix/3.7.5-2
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037305: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037305
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: mate-session-manager 1.26.0-1+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038714 = bookworm pending
Bug #1038714 [release.debian.org] bookworm-pu: package 
mate-session-manager/1.26.0-1+deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038714: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038714
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1036856: mutter 43.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1036856 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: mutter
Version: 43.6-1~deb12u1

Explanation: new upstream bugfix release



Bug#1038714: mate-session-manager 1.26.0-1+deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038714 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: mate-session-manager
Version: 1.26.0-1+deb12u1

Explanation: fix several memory leaks; allow clutter backends other than x11



Bug#1037305: postfix 3.7.6-0+deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037305 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: postfix
Version: 3.7.6-0+deb12u1

Explanation: new upstream bugfix release



Processed: libmatekbd 1.26.0-1+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038433 = bookworm pending
Bug #1038433 [release.debian.org] bookworm-pu: package 
libmatekbd/1.26.0-1+deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038433: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038433
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038605: mate-power-manager 1.26.0-2+deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038605 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: mate-power-manager
Version: 1.26.0-2+deb12u1

Explanation: fix serveral memory leaks



Bug#1036858: gnome-shell 43.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1036858 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: gnome-shell
Version: 43.6-1~deb12u1

Explanation: new upstream bugfix release



Processed: mate-power-manager 1.26.0-2+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038605 = bookworm pending
Bug #1038605 [release.debian.org] bookworm-pu: package 
mate-power-manager/1.26.0-2+deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038605: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038605
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: gnome-shell 43.6-1~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1036858 = bookworm pending
Bug #1036858 [release.debian.org] bookworm-pu: package 
gnome-shell/43.6-1~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1036858: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036858
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038433: libmatekbd 1.26.0-1+deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038433 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: libmatekbd
Version: 1.26.0-1+deb12u1

Explanation: fix memory leaks



Processed: gnome-control-center 43.6-2~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038777 = bookworm pending
Bug #1038777 [release.debian.org] bookworm-pu: package 
gnome-control-center/1:43.6-2~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038777: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038777
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: fai 6.0.3+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1039019 = bookworm pending
Bug #1039019 [release.debian.org] bookworm-pu: package fai/6.0.3+deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1039019: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039019
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: dpdk 22.11.2-2~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038209 = bookworm pending
Bug #1038209 [release.debian.org] bookworm: package dpdk/22.11.2-2~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038209: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038209
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: gnome-maps 43.5-2~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038780 = bookworm pending
Bug #1038780 [release.debian.org] bookworm-pu: package gnome-maps/43.5-2~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038780: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038780
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038780: gnome-maps 43.5-2~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038780 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: gnome-maps
Version: 43.5-2~deb12u1

Explanation: new upstream bugfix release



Bug#1039019: fai 6.0.3+deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1039019 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: fai
Version: 6.0.3+deb12u1

Explanation: fix IP address lifetime



Processed: dbus 1.14.8-1~deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037194 = bookworm pending
Bug #1037194 [release.debian.org] bookworm-pu: package dbus/1.14.8-1~deb12u1
Added tag(s) pending.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037194: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037194
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038777: gnome-control-center 43.6-2~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038777 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: gnome-control-center
Version: 43.6-2~deb12u1

Explanation: new upstream bugfix release



Bug#1038209: dpdk 22.11.2-2~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1038209 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: dpdk
Version: 22.11.2-2~deb12u1

Explanation: new upstream stable release



Bug#1037194: dbus 1.14.8-1~deb12u1 flagged for acceptance

2023-06-24 Thread Adam D Barratt
package release.debian.org
tags 1037194 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: dbus
Version: 1.14.8-1~deb12u1

Explanation: new upstream stable release; fix denial of service issue 
[CVE-2023-34969]



Bug#1039026: bookworm-pu: cups/2.4.2-3+deb12u1

2023-06-24 Thread Thorsten Alteholz

Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu


The attached debdiff for cups fixes CVE-2023-32324 and CVE-2023-34241 in 
Bookworm. Both CVE have been marked as no-dsa by the security team.


The same fixes have been already uploaded to Unstable and nobody 
complained yet.


  Thorsten
diff -Nru cups-2.4.2/debian/changelog cups-2.4.2/debian/changelog
--- cups-2.4.2/debian/changelog 2023-03-26 10:54:05.0 +0200
+++ cups-2.4.2/debian/changelog 2023-06-24 10:54:05.0 +0200
@@ -1,3 +1,14 @@
+cups (2.4.2-3+deb12u1) bookworm; urgency=medium
+
+  * CVE-2023-34241 (Closes: #1038885)
+use-after-free in cupsdAcceptClient()
+
+  * CVE-2023-32324
+A heap buffer overflow vulnerability would allow a remote attacker to 
+lauch a dos attack.
+
+ -- Thorsten Alteholz   Sat, 24 Jun 2023 10:54:05 +0200
+
 cups (2.4.2-3) unstable; urgency=medium
 
   [ Helge Kreutzmann ]
diff -Nru cups-2.4.2/debian/patches/0013-CVE-2023-32324.patch 
cups-2.4.2/debian/patches/0013-CVE-2023-32324.patch
--- cups-2.4.2/debian/patches/0013-CVE-2023-32324.patch 1970-01-01 
01:00:00.0 +0100
+++ cups-2.4.2/debian/patches/0013-CVE-2023-32324.patch 2023-06-24 
10:54:05.0 +0200
@@ -0,0 +1,29 @@
+From: Thorsten Alteholz 
+Date: Sat, 24 Jun 2023 11:06:49 +0200
+Subject: CVE-2023-32324
+
+---
+ cups/string.c | 3 +++
+ 1 file changed, 3 insertions(+)
+
+diff --git a/cups/string.c b/cups/string.c
+index 93cdad1..1f81d60 100644
+--- a/cups/string.c
 b/cups/string.c
+@@ -1,6 +1,7 @@
+ /*
+  * String functions for CUPS.
+  *
++ * Copyright © 2023 by OpenPrinting.
+  * Copyright © 2007-2019 by Apple Inc.
+  * Copyright © 1997-2007 by Easy Software Products.
+  *
+@@ -729,6 +730,8 @@ _cups_strlcpy(char   *dst, /* O - 
Destination string */
+ {
+   size_t  srclen; /* Length of source string */
+ 
++  if (size == 0)
++return (0);
+ 
+  /*
+   * Figure out how much room is needed...
diff -Nru cups-2.4.2/debian/patches/0014-CVE-2023-34241.patch 
cups-2.4.2/debian/patches/0014-CVE-2023-34241.patch
--- cups-2.4.2/debian/patches/0014-CVE-2023-34241.patch 1970-01-01 
01:00:00.0 +0100
+++ cups-2.4.2/debian/patches/0014-CVE-2023-34241.patch 2023-06-24 
10:54:05.0 +0200
@@ -0,0 +1,57 @@
+From: Thorsten Alteholz 
+Date: Sat, 24 Jun 2023 11:07:10 +0200
+Subject: CVE-2023-34241
+
+---
+ scheduler/client.c | 16 +++-
+ 1 file changed, 7 insertions(+), 9 deletions(-)
+
+diff --git a/scheduler/client.c b/scheduler/client.c
+index e7e419f..441c1d7 100644
+--- a/scheduler/client.c
 b/scheduler/client.c
+@@ -193,13 +193,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+/*
+ * Can't have an unresolved IP address with double-lookups enabled...
+ */
+-
+-httpClose(con->http);
+-
+ cupsdLogClient(con, CUPSD_LOG_WARN,
+-"Name lookup failed - connection from %s closed!",
++"Name lookup failed - closing connection from %s!",
+ httpGetHostname(con->http, NULL, 0));
+ 
++httpClose(con->http);
+ free(con);
+ return;
+   }
+@@ -235,11 +233,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+   * with double-lookups enabled...
+   */
+ 
+-  httpClose(con->http);
+-
+   cupsdLogClient(con, CUPSD_LOG_WARN,
+-  "IP lookup failed - connection from %s closed!",
++  "IP lookup failed - closing connection from %s!",
+   httpGetHostname(con->http, NULL, 0));
++
++  httpClose(con->http);
+   free(con);
+   return;
+ }
+@@ -256,11 +254,11 @@ cupsdAcceptClient(cupsd_listener_t *lis)/* I - Listener 
socket */
+ 
+   if (!hosts_access(_req))
+   {
+-httpClose(con->http);
+-
+ cupsdLogClient(con, CUPSD_LOG_WARN,
+ "Connection from %s refused by /etc/hosts.allow and "
+   "/etc/hosts.deny rules.", httpGetHostname(con->http, NULL, 
0));
++
++httpClose(con->http);
+ free(con);
+ return;
+   }
diff -Nru cups-2.4.2/debian/patches/series cups-2.4.2/debian/patches/series
--- cups-2.4.2/debian/patches/series2023-03-26 10:54:05.0 +0200
+++ cups-2.4.2/debian/patches/series2023-06-24 10:54:05.0 +0200
@@ -10,3 +10,5 @@
 0015-Debian-Reproducibility-Do-not-run-stp-tests-as-root.patch
 0016-Debian-po4a-infrastructure-and-translations-for-manp.patch
 0012-add-pt.patch
+0013-CVE-2023-32324.patch
+0014-CVE-2023-34241.patch


Bug#1038879: bookworm-pu: package proftpd-dfsg/1.3.8+dfsg-4+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 moreinfo

On Thu, Jun 22, 2023 at 02:29:54PM +0200, Francesco P. Lovergine wrote:
> diff -Nru proftpd-dfsg-1.3.8+dfsg/debian/changelog 
> proftpd-dfsg-1.3.8+dfsg/debian/changelog
> --- proftpd-dfsg-1.3.8+dfsg/debian/changelog  2023-03-14 10:16:31.0 
> +0100
> +++ proftpd-dfsg-1.3.8+dfsg/debian/changelog  2023-06-22 11:15:57.0 
> +0200
> @@ -1,3 +1,15 @@
> +proftpd-dfsg (1.3.8+dfsg-4+deb12u1) bookworm-proposed-updates; urgency=medium

You should target `bookworm`, not the admin suites.

> diff -Nru proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.prerm 
> proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.prerm
> --- proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.prerm 1970-01-01 
> 01:00:00.0 +0100
> +++ proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.prerm 2023-06-22 
> 11:13:30.0 +0200
> @@ -0,0 +1,11 @@
> +#!/bin/sh
> +
> +set -e
> +
> +if [ -z "${DPKG_ROOT:-}" ] && [ "$1" = remove ] && [ -d /run/systemd/system 
> ] ;
> +then
> +deb-systemd-invoke stop 'proftpd.service' >/dev/null || true
> +deb-systemd-invoke stop 'proftpd.socket' >/dev/null || true
> +fi

This gives rise to a race condition where the socket starts the service
again before the socket is stopped.

> diff -Nru proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.proftpd-run.service 
> proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.proftpd-run.service
> --- proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.proftpd-run.service   
> 1970-01-01 01:00:00.0 +0100
> +++ proftpd-dfsg-1.3.8+dfsg/debian/proftpd-core.proftpd-run.service   
> 2023-06-22 11:12:42.0 +0200
> @@ -0,0 +1,14 @@
> +[Unit]
> +Description=ProFTPD FTP Server in standalone/socket mode
> +Documentation=man:proftpd(8)
> +OnFailure=proftpd.socket
> +OnSuccess=proftpd.service
> +
> +[Service]
> +Type=oneshot
> +Environment=CONFIG_FILE=/etc/proftpd/proftpd.conf
> +EnvironmentFile=-/etc/default/proftpd
> +ExecStart=/usr/bin/grep -iqE 
> '^[[:space:]]*ServerType[[:space:]]+standalone$' $CONFIG_FILE

Maybe I missed something important, but this seems a very odd way of doing
things. Do you really set up a dummy service unit which is expected to fail
in standalone mode, and therefore starts the socket instead?

Why not use an ExecStartPre= or ExecCondition= in your normal units to
prevent starting when in inetd mode?


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1038879: bookworm-pu: package proftpd-dfsg/1.3.8+dfsg-4+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 moreinfo
Bug #1038879 [release.debian.org] bookworm-pu: package 
proftpd-dfsg/1.3.8+dfsg-4+deb12u1
Added tag(s) moreinfo.

-- 
1038879: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038879
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038041: bookworm-pu: package unixodbc/2.3.11-2+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Thu, Jun 15, 2023 at 09:59:25PM +1000, Hugh McMaster wrote:
> (1) Users who upgrade their system from old versions of Debian (e.g. Lenny,
> Squeeze, Wheezy etc.) with odbcinst1debian1 installed are unable to upgrade to
> bookworm due to a missing Breaks+Replaces against two binary packages.
> 
> Although odbcinst1debian1 hasn't existed for years, dpkg complains because
> /etc/odbc.ini is also in unixodbc-common, and /usr/bin/odbcinst is also in
> odbcinst.
> 
> (2) Due to an oversight on my part, the stable version of unixodbc-common has
> an obsolete conffile.

Please go ahead.

Thanks,


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1038041: bookworm-pu: package unixodbc/2.3.11-2+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038041 [release.debian.org] bookworm-pu: package unixodbc/2.3.11-2+deb12u1
Added tag(s) confirmed.

-- 
1038041: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038041
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Re: Bug#1038727: bookworm-pu: package nftables/1.0.6-2+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038727 [release.debian.org] bookworm-pu: package nftables/1.0.6-2+deb12u1
Added tag(s) confirmed.

-- 
1038727: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038727
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038727: bookworm-pu: package nftables/1.0.6-2+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Tue, Jun 20, 2023 at 05:27:03PM +0200, Arturo Borrero Gonzalez wrote:
> There has been a behavior regression reported in nftables when
> upgrading from Debian 11 Bullseye to Debian 12 Bookworm.
> 
> The change is in how nftables prints the set definitions, with
> or without set elements by default.
> 
> Some user tools relying on 'nft -j list sets' fail after upgrading
> to Debian Bookworm from Debian Bullseye because the behavior change.
> 
> The small upstream fix makes the behavior coherent and predictable for the
> set listing action.

It would be good to mention *what* the patch does and why in the changelog,
but in general please go ahead.

Thanks,


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Re: 11.8 planning

2023-06-24 Thread Steve McIntyre
On Sat, Jun 24, 2023 at 03:17:22PM +0100, Jonathan Wiltshire wrote:
>On Tue, Jun 20, 2023 at 06:15:30PM +0100, Adam D. Barratt wrote:
>> The traditional cadence for oldstable point releases is four months,
>> rather than two. That technically means that 11.8 would be due
>> somewhere in late August to mid-September. So we could either punt 11.8
>> so it aligns with 12.2 rather than 12.1, or do 11.8 together with 12.1
>> and then align 11.9 with 12.3.
>> 
>> I think I'd prefer the latter option, i.e. we do 11.8+12.1 in July,
>> 12.2 probably September, then 11.9+12.3 Novemberish.
>> 
>
>Yes, I had forgotten about the transition to oldstable candece. I was going
>to suggest, though, that 11.8 gets pushed back to cadence with 12.2 and we
>just do 12.1 on its own first. How does that sound?

WFM.

-- 
Steve McIntyre, Cambridge, UK.st...@einval.com
"...In the UNIX world, people tend to interpret `non-technical user'
 as meaning someone who's only ever written one device driver." -- Daniel Pead



Bug#1039020: bullseye-pu: package schleuder/3.6.0-3+deb11u2

2023-06-24 Thread Georg Faerber
Package: release.debian.org
Severity: normal
Tags: bullseye
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: gitcom...@henk.geekmail.org
Control: affects -1 + src:schleuder

Dear release team,

[ Reason ]
Missing versioning of the ruby-activerecord dependency might lead to
failing upgrades from buster to bullseye if done in two stages, in
contrast to only one stage. This issue was reported by Hendrik Jäger and
Andreas Beckmann, both privately and in Debian via #1036950.

It was fixed in unstable via 4.0.3-8.

[ Impact ]
Severe, as upgrades might fail, depending on how these are done.

[ Tests ]
Tests were done both manually and via Salsa CI. Additionally, to ease
future maintenance and ensure upgrades work as expected, a new "piuparts
multi distro upgrade" CI test job was introduced. [2]

[ Risks ]
There should be none, I believe.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
Add missing versioning on ruby-activerecord dependency, to ensure
correct ordering during upgrades.

For details, see the attached debdiff of 3.6.0-3+deb11u1, as currently
present in bullseye, and 3.6.0-3+deb11u2.

Thanks for your work!

Cheers,
Georg


[1] 
https://salsa.debian.org/ruby-team/schleuder/-/commit/08fd9a91a938346f5cad3cf216f8225b6f6cdd0e
diff -Nru schleuder-3.6.0/debian/changelog schleuder-3.6.0/debian/changelog
--- schleuder-3.6.0/debian/changelog	2021-12-26 16:28:29.0 +
+++ schleuder-3.6.0/debian/changelog	2023-06-24 15:02:25.0 +
@@ -1,3 +1,14 @@
+schleuder (3.6.0-3+deb11u2) bullseye; urgency=medium
+
+  * debian/control:
+- Add missing versioning on ruby-activerecord dependency. Before, upgrades
+  from buster to bullseye might have failed if done in two stages, in
+  contrast to only one stage, which worked as expected. Thanks to
+  Hendrik Jäger and Andreas Beckmann for reporting this issue.
+  (Closes: #1036950)
+
+ -- Georg Faerber   Sat, 24 Jun 2023 15:02:25 +
+
 schleuder (3.6.0-3+deb11u1) bullseye; urgency=medium
 
   * debian/patches:
diff -Nru schleuder-3.6.0/debian/control schleuder-3.6.0/debian/control
--- schleuder-3.6.0/debian/control	2021-12-26 16:28:29.0 +
+++ schleuder-3.6.0/debian/control	2023-06-24 15:02:25.0 +
@@ -39,7 +39,7 @@
  lsb-base,
  rake,
  ruby | ruby-interpreter,
- ruby-activerecord,
+ ruby-activerecord (>= 2:6~),
  ruby-charlock-holmes,
  ruby-gpgme,
  ruby-mail,


Processed: bullseye-pu: package schleuder/3.6.0-3+deb11u2

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> affects -1 + src:schleuder
Bug #1039020 [release.debian.org] bullseye-pu: package schleuder/3.6.0-3+deb11u2
Added indication that 1039020 affects src:schleuder

-- 
1039020: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039020
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Re: Bug#1038906: bookworm-pu: package mailman3/3.3.8-1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038906 [release.debian.org] bookworm-pu: package mailman3/3.3.8-1
Added tag(s) confirmed.

-- 
1038906: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038906
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Re: Bug#1038899: bookworm-pu: package nfdump/1.7.1-2+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038899 [release.debian.org] bookworm-pu: package nfdump/1.7.1-2+deb12u1
Added tag(s) confirmed.

-- 
1038899: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038899
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038899: bookworm-pu: package nfdump/1.7.1-2+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Thu, Jun 22, 2023 at 10:29:34PM +0200, Bernhard Schmidt wrote:
> [ Reason ]
> This update fixes two errors reported in #1038644
> - a segfault when using a particular option
> - a wrong 'failed' indication in the sysvinit initscript
> 
> The segfault fix is straight forward and just an error in the option
> parsing.

Please go ahead.

Thanks,

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1038824: bookworm-pu: package openvpn/2.6.3-1+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038824 [release.debian.org] bookworm-pu: package openvpn/2.6.3-1+deb12u1
Added tag(s) confirmed.

-- 
1038824: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038824
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038906: bookworm-pu: package mailman3/3.3.8-1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Fri, Jun 23, 2023 at 01:12:57AM +0200, Pierre-Elliott Bécue wrote:
> Multiple small bugs could have been fixed before the bookworm release,
> but having been elsewhere in my mind, I let those slip.
> 
> I'd therefore like to submit this debdiff for a stable-pu.

Please go ahead.

Thanks,


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Bug#1038824: bookworm-pu: package openvpn/2.6.3-1+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Wed, Jun 21, 2023 at 10:04:49PM +0200, Bernhard Schmidt wrote:
> This -pu cherry-picks two fixes from upstream. One fixing a memory
> leak that is noticable on long running servers, and one dangling pointer that
> might lead to crashes. Both have been in 2.6.3-2 for about a month now,
> migrated to testing flawlessly and are part of the recent upstream stable
> release. 
> 
> There is nothing else in 2.6.3-2 that is not suitable for bookworm, I have 
> just
> changed the version and set the correct branch in gbp.conf

Please go ahead.

Thanks,


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Bug#1038387: bookworm-pu: package groonga/13.0.0+dfsg-2~deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Sat, Jun 17, 2023 at 10:01:19PM +0900, Kentaro Hayashi wrote:
> The installed document will not be rendered correctly.
> 
> It is against upstream developer's intention.
> This bug only affect the Groonga's documentaion and sample application.
> groonga-doc will be installed by default when groonga
> package is installed, so it affects for all Groonga users.

As this is a direct backport from trixie, you should include the changelog
entry for 13.0.0+dfsg-3 and add one on top, version 13.0.0+dfsg-3~deb12u1
and a description "Backport to bookworm" or similar. With that change,
please go ahead.

Thanks,

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1038387: bookworm-pu: package groonga/13.0.0+dfsg-2~deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038387 [release.debian.org] bookworm-pu: package 
groonga/13.0.0+dfsg-2~deb12u1
Added tag(s) confirmed.

-- 
1038387: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038387
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1039019: bookworm-pu: package fai/6.0.3+deb12u1

2023-06-24 Thread Thomas Lange


Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: f...@packages.debian.org
Control: affects -1 + src:fai


This upload fixes #1037329


[ Reason ]
A change from FAI 5.10.3 (in bullseye) to 6.0 (currently 6.0.3 in bookworm)
removed some code which sets the lifetime for IP addresses to forever. This 
change must be reversed.

[ Impact ]
A network installation hangs completly after the lease time of the IP address 
expires.
FAI does not run a dhclient, because it uses a nfsroot.

[ Tests ]
Since we used this code years before, and I only reverted the commit which 
removes the code, no tests are needed.

[ Risks ]
No risks,.

[ Checklist ]
  [X ] *all* changes are documented in the d/changelog
  [X ] I reviewed all changes and I approve them
  [X ] attach debdiff against the package in (old)stable
  [X] the issue is verified as fixed in unstable

[ Changes ]
For each network interface, set IP address filetime to forever.


 bin/fai  |6 ++
 debian/changelog |6 ++
 2 files changed, 12 insertions(+)

diff -Nru fai-6.0.3/bin/fai fai-6.0.3+deb12u1/bin/fai
--- fai-6.0.3/bin/fai   2023-01-12 10:22:03.0 +0100
+++ fai-6.0.3+deb12u1/bin/fai   2023-06-24 12:57:09.0 +0200
@@ -126,6 +126,12 @@
 
 cat /proc/kmsg >/dev/tty4 &
 
+# fix IP address lifetime
+   ip -4 -br a | awk '/UP / {if ($3) print $3 " " $1}' | \
+while read addr iface; do
+ip -4 addr change "$addr" dev "$iface" valid_lft forever 
preferred_lft forever
+done
+
 # enable EFI variables
 if [ -d /sys/firmware/efi ]; then
mount -t efivarfs none /sys/firmware/efi/efivars
diff -Nru fai-6.0.3/debian/changelog fai-6.0.3+deb12u1/debian/changelog
--- fai-6.0.3/debian/changelog  2023-05-24 11:57:11.0 +0200
+++ fai-6.0.3+deb12u1/debian/changelog  2023-06-24 13:02:26.0 +0200
@@ -1,3 +1,9 @@
+fai (6.0.3+deb12u1) bookworm; urgency=low
+
+  * fai: set IP address lifetime to forever, Closes: #1037329
+
+ -- Thomas Lange   Sat, 24 Jun 2023 13:02:26 +0200
+
 fai (6.0.3) unstable; urgency=high
 
   *  get-boot-info: write $SERVER only if string is non-epmty



Processed: bookworm-pu: package fai/6.0.3+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> affects -1 + src:fai
Bug #1039019 [release.debian.org] bookworm-pu: package fai/6.0.3+deb12u1
Added indication that 1039019 affects src:fai

-- 
1039019: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1039019
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: aide_0.18.3-1+deb12u1_source.changes
  ACCEPT
Processing changes file: spip_4.1.9+dfsg-1+deb12u1_source.changes
  ACCEPT
Processing changes file: 
xerial-sqlite-jdbc_3.40.1.0+dfsg-1+deb12u1_source.changes
  ACCEPT



Processed: xerial-sqlite-jdbc 3.40.1.0+dfsg-1+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037542 = bookworm pending
Bug #1037542 [release.debian.org] bookworm-pu: package 
xerial-sqlite-jdbc/3.40.1.0+dfsg-1+deb12u1
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037542: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037542
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: spip 4.1.9+dfsg-1+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1038154 = bookworm pending
Bug #1038154 [release.debian.org] bookworm-pu: package spip/4.1.9+dfsg-1+deb12u1
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1038154: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038154
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: aide 0.18.3-1+deb12u1 flagged for acceptance

2023-06-24 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> package release.debian.org
Limiting to bugs with field 'package' containing at least one of 
'release.debian.org'
Limit currently set to 'package':'release.debian.org'

> tags 1037945 = bookworm pending
Bug #1037945 [release.debian.org] bookworm-pu: package 
aide/aide_0.18.3-1+deb12u1
Added tag(s) pending; removed tag(s) confirmed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
1037945: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037945
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1038154: spip 4.1.9+dfsg-1+deb12u1 flagged for acceptance

2023-06-24 Thread Jonathan Wiltshire
package release.debian.org
tags 1038154 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: spip
Version: 4.1.9+dfsg-1+deb12u1

Explanation: various security issues



Bug#1037945: aide 0.18.3-1+deb12u1 flagged for acceptance

2023-06-24 Thread Jonathan Wiltshire
package release.debian.org
tags 1037945 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: aide
Version: 0.18.3-1+deb12u1

Explanation: properly handle creating the system user



Bug#1037542: xerial-sqlite-jdbc 3.40.1.0+dfsg-1+deb12u1 flagged for acceptance

2023-06-24 Thread Jonathan Wiltshire
package release.debian.org
tags 1037542 = bookworm pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into 
the proposed-updates queue for Debian bookworm.

Thanks for your contribution!

Upload details
==

Package: xerial-sqlite-jdbc
Version: 3.40.1.0+dfsg-1+deb12u1

Explanation: use a UUID for connection ID



Bug#1038140: bookworm-pu: package onionshare/2.6-5

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Thu, Jun 15, 2023 at 10:52:28PM +0200, Hefee wrote:
> Do I need to do update the version with a stable extension ~deb12u1 as there 
> won't be any diff?

Yes, you should add a changelog entry with target bookworm and version
2.6-5~deb12u1. Other than that addition, please go ahead.

Thanks,

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1038140: bookworm-pu: package onionshare/2.6-5

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1038140 [release.debian.org] bookworm-pu: package onionshare/2.6-5
Added tag(s) confirmed.

-- 
1038140: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1038140
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Processed: Re: Bug#1037078: closed by Paul Gevers (closing still open unblock requests)

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1037078 [release.debian.org] bookworm-pu: package 
dh-python/5.20230130+deb12u1
Added tag(s) confirmed.

-- 
1037078: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1037078
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1037078: closed by Paul Gevers (closing still open unblock requests)

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Tue, Jun 06, 2023 at 03:01:35PM +, stefa...@debian.org wrote:
> OK, let's re-target to PU. Updated debdiff atteched.
> 
> If you're interested in having this change to ease upgrades, we can get
> in in the first point release.
> 
> It probably doesn't make sense to carry the patch into trixie.

Please go ahead.

Thanks,


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Processed: Re: Bug#1036978: bookworm-pu: package node-undici/5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1

2023-06-24 Thread Debian Bug Tracking System
Processing control commands:

> tag -1 confirmed
Bug #1036978 [release.debian.org] bookworm-pu: package 
node-undici/5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1
Added tag(s) confirmed.

-- 
1036978: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1036978
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems



Bug#1036978: bookworm-pu: package node-undici/5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1

2023-06-24 Thread Jonathan Wiltshire
Control: tag -1 confirmed

On Wed, May 31, 2023 at 04:00:47PM +0400, Yadd wrote:
> [ Reason ]
> node-undici is vulnerable to:
>  * CVE-2023-23936: "Host" HTTP header isn't protected against CLRF injection
>  * CVE-2023-24807: Regex Denial of Service on headers set/append

Please update the changelog to mention the CVE identifiers; other than
that, go ahead.

Thanks,

-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



NEW changes in stable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: hsqldb_2.7.1-1+deb12u1_source.changes
  ACCEPT
Processing changes file: hsqldb_2.7.1-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: hsqldb1.8.0_1.8.0.10+dfsg-11+deb12u1_source.changes
  ACCEPT
Processing changes file: hsqldb1.8.0_1.8.0.10+dfsg-11+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_multi.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: libx11_1.8.4-2+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_sourceonly.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: minidlna_1.3.0+dfsg-2.2+deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_source.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: webkit2gtk_2.40.2-1~deb12u1_s390x-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_source.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_all-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_amd64-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_arm64-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_armel-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_armhf-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_i386-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_mips64el-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_mipsel-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_ppc64el-buildd.changes
  ACCEPT
Processing changes file: xmltooling_3.2.3-1+deb12u1_s390x-buildd.changes
  ACCEPT



Re: 11.8 planning

2023-06-24 Thread Jonathan Wiltshire
On Tue, Jun 20, 2023 at 06:15:30PM +0100, Adam D. Barratt wrote:
> The traditional cadence for oldstable point releases is four months,
> rather than two. That technically means that 11.8 would be due
> somewhere in late August to mid-September. So we could either punt 11.8
> so it aligns with 12.2 rather than 12.1, or do 11.8 together with 12.1
> and then align 11.9 with 12.3.
> 
> I think I'd prefer the latter option, i.e. we do 11.8+12.1 in July,
> 12.2 probably September, then 11.9+12.3 Novemberish.
> 

Yes, I had forgotten about the transition to oldstable candece. I was going
to suggest, though, that 11.8 gets pushed back to cadence with 12.2 and we
just do 12.1 on its own first. How does that sound?


-- 
Jonathan Wiltshire  j...@debian.org
Debian Developer http://people.debian.org/~jmw

4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC  74C3 5394 479D D352 4C51
ed25519/0x196418AAEB74C8A1: CA619D65A72A7BADFC96D280196418AAEB74C8A1



Bug#1037945: bookworm-pu: package aide/aide_0.18.3-1+deb12u1

2023-06-24 Thread Marc Haber
On Sat, Jun 24, 2023 at 11:11:18AM +0100, Adam D. Barratt wrote:
> Please feel free to upload.

Done (for bookworm).

Greetings
Marc

-- 
-
Marc Haber | "I don't trust Computers. They | Mailadresse im Header
Leimen, Germany|  lose things."Winona Ryder | Fon: *49 6224 1600402
Nordisch by Nature |  How to make an American Quilt | Fax: *49 6224 1600421



NEW changes in oldstable-new

2023-06-24 Thread Debian FTP Masters
Processing changes file: fai_6.0.3+deb12u1_amd64.changes
  REJECT



Bug#1037945: bookworm-pu: package aide/aide_0.18.3-1+deb12u1

2023-06-24 Thread Adam D. Barratt
On Sat, 2023-06-24 at 11:53 +0200, Marc Haber wrote:
> On Sat, Jun 24, 2023 at 10:47:31AM +0100, Adam D. Barratt wrote:
> > Looking at the upstream issue linked from #1037436, it suggests
> > that
> > the extended attributes fix is likely to create a large amount of
> > noise
> > on the next aide run. If that's correct, is it worth adding a
> > NEWS.Debian entry to warn users that this is expected?
> 
> I deliberately didnt do that to keep the debdiff small, but I can add
> a paragraph if you think that's a good idea. I'd do the same for the
> bullseye-pu upload and the next sid upload then.
> 
> However, this bug only shows itself if both the symlink AND the
> target of the symlink do have extended attributes. I dont think
> that's a very commmon case.
> 

Thanks for clarifying - the detail there wasn't clear to me, and the
upstream issue sounded like it would be much noisier.

Please feel free to upload.

Regards,

Adam



Bug#1037945: bookworm-pu: package aide/aide_0.18.3-1+deb12u1

2023-06-24 Thread Marc Haber
On Sat, Jun 24, 2023 at 10:47:31AM +0100, Adam D. Barratt wrote:
> Looking at the upstream issue linked from #1037436, it suggests that
> the extended attributes fix is likely to create a large amount of noise
> on the next aide run. If that's correct, is it worth adding a
> NEWS.Debian entry to warn users that this is expected?

I deliberately didnt do that to keep the debdiff small, but I can add a
paragraph if you think that's a good idea. I'd do the same for the
bullseye-pu upload and the next sid upload then.

However, this bug only shows itself if both the symlink AND the target
of the symlink do have extended attributes. I dont think that's a very
commmon case.

Greetings
Marc

-- 
-
Marc Haber | "I don't trust Computers. They | Mailadresse im Header
Leimen, Germany|  lose things."Winona Ryder | Fon: *49 6224 1600402
Nordisch by Nature |  How to make an American Quilt | Fax: *49 6224 1600421



  1   2   >