[Pkg-utopia-maintainers] flatpak 1.14.6-1~deb13u1 MIGRATED to testing

2024-04-22 Thread Debian testing watch
FYI: The status of the flatpak source package
in Debian's testing distribution has changed.

  Previous version: 1.14.5-1
  Current version:  1.14.6-1~deb13u1

-- 
This email is automatically generated once a day.  As the installation of
new packages into testing happens multiple times a day you will receive
later changes on the next day.
See https://release.debian.org/testing-watch/ for more information.

___
Pkg-utopia-maintainers mailing list
Pkg-utopia-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers


[Pkg-utopia-maintainers] wireplumber_0.5.2-1_source.changes ACCEPTED into experimental

2024-04-22 Thread Debian FTP Masters
Thank you for your contribution to Debian.



Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Mon, 22 Apr 2024 18:25:04 +0200
Source: wireplumber
Architecture: source
Version: 0.5.2-1
Distribution: experimental
Urgency: medium
Maintainer: Utopia Maintenance Team 

Changed-By: Dylan Aïssi 
Changes:
 wireplumber (0.5.2-1) experimental; urgency=medium
 .
   * New upstream version
   * Standards-Version: 4.7.0 (no changes needed)
Checksums-Sha1:
 bfb1a06af70285da816474d9f0d18c22796e1b47 2795 wireplumber_0.5.2-1.dsc
 95443a68cc2fabcea89786395b8c5f6c521aee77 408788 wireplumber_0.5.2.orig.tar.bz2
 2c8a1322a953f2d305bff38f349a3d6226b00ce3 10992 
wireplumber_0.5.2-1.debian.tar.xz
 143f4dd868489400ece964877bc4e66288d0f0ad 16380 
wireplumber_0.5.2-1_amd64.buildinfo
Checksums-Sha256:
 10cc44b4b06b6e11d1dbcb3eb82e89b9c48036f808f83028e393a860732d2f1d 2795 
wireplumber_0.5.2-1.dsc
 f6c21592fc36de710cba869b91a407aaa0e4c74d04fccd9a91643e527c4306bb 408788 
wireplumber_0.5.2.orig.tar.bz2
 05253eb29b74531a100cfd7171b6645d80e7bb1085355113d7b91ea79cd66701 10992 
wireplumber_0.5.2-1.debian.tar.xz
 4c02e22e7caf4302a3e4dcdc153e66e4f50ba5f13a1da7f0b7b0b41436264f2e 16380 
wireplumber_0.5.2-1_amd64.buildinfo
Files:
 71f0119a5ad849a762808f0cade2bd2a 2795 libs optional wireplumber_0.5.2-1.dsc
 6893d7bd1a3ef28781ed8be23fcd1432 408788 libs optional 
wireplumber_0.5.2.orig.tar.bz2
 2eacfef2c9c3df8f1a656013cdb2e3ac 10992 libs optional 
wireplumber_0.5.2-1.debian.tar.xz
 3ba7bea797527c37dc283c9334c0a230 16380 libs optional 
wireplumber_0.5.2-1_amd64.buildinfo

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEmjwHvQbeL0FugTpdYS7xYT4FD1QFAmYmkDsACgkQYS7xYT4F
D1QjLA/8DIkTM06fDAXoq0iS0JJT6BeFCTP/Kk4QiXBWO1pznBlVHaIPsHlV+Z3m
vX3DqrQyqLwhnsrkGQoW+4W2j05slX04PFklnGYiMqvjCalelzuiESc6qNLbiWMT
37RpMXREJs6nCPlG06M30ZuRT5rORTE66v4WIda0ALiJHemlBzUl597bcoaoZVVW
yTcB3+UWe6/bcITFY9+dQIkZxmDRWUkE+HfaucTO1Vc5xxlGLd7BKILT51XyRVWn
tafQhIEktWE68LAsxJKKXGI7nl91bw5djH7FJGiRRrCjxun7f+zh9AIQsNTjdpop
F78xmLQE79OvjPkY4nJ1pGNvQd0FJPsgnEeNoVYESoqp9InY5DoSY49PI+2zHDsz
tL2YxQ5lykpjHtl2iWC++sl8T2nX2DxB0UEYPsaiCdW4JvKmp3wOfqz6MB57AiUW
fWGcBkuGt+2Eeb7gO3of5su2IEnG2DoFSOfGuDF1FhOLdCzvvSecQ6UrsU3Qzk12
2I/lfZ8mwm7J1ttMweyRe6NyvxuzSv146NPdsMrdQ3pCBYhJzHTyJCMDQdqy3Q/w
ROT3T008q702j1bvipIZWwjx89pDdQck2nNMVAErMbGU1uu2NTGgyByqYKBm8gWK
IijnYnzeQFs2xcKdasxWQgHKh4Z9TA/XVIh0UID1sixh31qNMcc=
=UOyS
-END PGP SIGNATURE-



pgpNVVPqjTzFC.pgp
Description: PGP signature
___
Pkg-utopia-maintainers mailing list
Pkg-utopia-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers


[Pkg-utopia-maintainers] Processing of wireplumber_0.5.2-1_source.changes

2024-04-22 Thread Debian FTP Masters
wireplumber_0.5.2-1_source.changes uploaded successfully to localhost
along with the files:
  wireplumber_0.5.2-1.dsc
  wireplumber_0.5.2.orig.tar.bz2
  wireplumber_0.5.2-1.debian.tar.xz
  wireplumber_0.5.2-1_amd64.buildinfo

Greetings,

Your Debian queue daemon (running on host usper.debian.org)

___
Pkg-utopia-maintainers mailing list
Pkg-utopia-maintainers@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers


[Pkg-utopia-maintainers] Bug#1069672: bookworm-pu: package flatpak/1.14.6-1~deb12u1 or 1.14.7-1~deb12u1

2024-04-22 Thread Simon McVittie
Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian@packages.debian.org
Usertags: pu
X-Debbugs-Cc: flat...@packages.debian.org
Control: affects -1 + src:flatpak

After the dust has settled from CVE-2024-32462, I would like to do a
stable-update of Flatpak using the upstream 1.14.x branch.

At the moment bookworm-security has 1.14.4 plus the patches for
CVE-2024-32462. The current upstream release is 1.14.6 (also available in
unstable and in testing-proposed-updates), which moves the security fix
from patches into the upstream source and fixes various less serious bugs.

We are also hoping to do a 1.14.7 upstream release soon, perhaps this
week. Would the stable release team prefer this to be proposed as one
big update from 1.14.4 to 1.14.7, or two smaller updates
1.14.4 → 1.14.6 → 1.14.7, or do you not mind either way?

[ Impact ]
If not accepted, several known bugs remain present in stable.
The highest-visibility is that the developer name of an app appears
in the CLI where the app name should be, for example "The Chromium Authors"
instead of the correct "Chromium Web Browser".

Also, if we keep up with upstream stable releases, then next time there
is a CVE, we can take upstream's stable release directly instead of
having to backport individual patches.

[ Tests ]
There is a fairly comprehensive test suite. It cannot be run under schroot
or lxc due to limitations of nested containers, but I run in
autopkgtest-virt-qemu before each upload, and ci.debian.net has now been
configured to run flatpak's tests under autopkgtest-virt-qemu has well.

I will test a final version manually on a bookworm system before upload.

[ Risks ]
Somewhat low risk, all changes are targeted bug fixes. I would say that
the highest-risk are the alterations to how AppStream metadata is parsed
and displayed, but several distributions are already using those changes
via the 1.15.x branch and we have not had regression reports.

[ Checklist ]
The changes in 1.14.7 will not be finalized until the release actually
happens, but I have reviewed and attached a proposed diff.

  [½] *all* changes are documented in the d/changelog
  [½] I reviewed all changes and I approve them
  [½] attach debdiff against the package in (old)stable
  [½] the issue is verified as fixed in unstable

[ Changes in 1.14.5 and 1.14.6 ]
See attached flatpak-1.14.6-bookworm.diff.gz

* Makefile.am,
  configure.ac,
  data/Makefile.am.inc,
  data/tmpfiles.d/flatpak.conf,
  debian/flatpak.install,
  sideload-repos-systemd/Makefile.am.inc:
  - Delete obsolete /var/tmp/flatpak-cache-* (if any) during boot

* app/flatpak-builtins-build.c,
  common/flatpak-dir.c,
  common/flatpak-run.c,
  tests/test-run.sh:
  - Fix CVE-2024-32462 (previously done via a patch)

* app/flatpak-builtins-remote-info.c:
  - Fix display of app info in `flatpak remote-info`
  - Fix some uses of deprecated libappstream API
  - Forward-compatibility with libappstream 0.17.x and 1.0

* app/flatpak-builtins-remote-ls.c,
  app/flatpak-builtins-search.c,
  app/flatpak-builtins-utils.c,
  app/flatpak-builtins-utils.h,
  config.h.in,
  configure.ac:
  - Fix some uses of deprecated libappstream API
  - Forward-compatibility with libappstream 0.17.x and 1.0

* app/flatpak-builtins-run.c,
  common/flatpak-dir.c,
  tests/testlibrary.c:
  - Silence some compiler warning false-positives

* common/flatpak-appdata.c,
  tests/make-test-app.sh,
  tests/test-info.sh:
  - Don't parse the app developer name as though it was the app name

* common/flatpak-run.c,
  doc/flatpak-run.xml:
  - Don't let the sandboxed app inherit a wrong value for $VK_DRIVER_FILES,
$VK_ICD_FILENAMES

* common/flatpak-utils-http.c:
  - Cancel downloads if they become very slow

* common/flatpak-utils.c,
  tests/test-exports.c,
  tests/test-instance.c:
  - Forward-compatibility with newer GLib releases

* NEWS,
  common/flatpak-version-macros.h,
  configure.ac,
  tests/package_version.txt:
  - The usual release management noise

* debian/test.sh:
  - Unset proxy environment variables to make sure a test http server on
localhost is reachable

* doc/flatpak-metadata.xml:
  - Provide anchors for internal linking
  - Clarify documentation on which D-Bus names are allowed by default

* doc/reference/html/*.html:
  - Regenerated with Debian 12 toolchain
(these are also re-regenerated during build)
  (Filtered from debdiff)

* po/*.po,
  po/flatpak.pot:
  - Regenerated during upstream release procedure (different line numbering)
  (Filtered from debdiff)

* portal/flatpak-portal.c:
  - Save the original environment before setting GIO_USE_VFS, and restore it
before starting sandboxed programs, so that GVfs can work

* revokefs/main.c:
  - Forward-compatibility with libostree 2023.4

* session-helper/flatpak-session-helper.c:
  - Same as portal/, but for programs run on the host system by trusted
Flatpak apps

* tests/make-test-runtime.sh:
  - Fail tests earlier, with a better error message, if a