[Python-modules-team] Bug#821219: marked as done (scitools: Recommends unmaintained python-netcdf)

2016-05-05 Thread Debian Bug Tracking System
Your message dated Fri, 06 May 2016 06:12:58 +
with message-id 
and subject line Bug#823121: Removed package(s) from unstable
has caused the Debian Bug report #821219,
regarding scitools: Recommends unmaintained python-netcdf
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)


-- 
821219: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=821219
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Source: scitools
Version: 0.9.0-2
Severity: serious
Justification: makes the package in question unusable or mostly so

Dear Maintainer,

Please remove python-netcdf from the python-scitools Recommends.

python-netcdf is incompatible with numpy 1.9 and hasn't been in testing
for almost two years. There hasn't been any upstream activity since
2014, making it unlikly to gain compatibility with numpy 1.9.

python-netcdf4 may be a suitable alternative for dolfin, it is actively
maintained by the NetCDF upstream developers.

This bugreport is filed as part of the process to get all reverse
dependencies of python-scientific removed from Debian unstable. If
scitools cannot do without the python-netcdf Recommends, it will also
need to be removed from Debian.

Kind Regards,

Bas
--- End Message ---
--- Begin Message ---
Version: 0.9.0-2+rm

Dear submitter,

as the package scitools has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see https://bugs.debian.org/823121

The version of this package that was in Debian prior to this removal
can still be found using http://snapshot.debian.org/.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmas...@ftp-master.debian.org.

Debian distribution maintenance software
pp.
Scott Kitterman (the ftpmaster behind the curtain)--- End Message ---
___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Bug#823121: Removed package(s) from unstable

2016-05-05 Thread Debian FTP Masters
We believe that the bug you reported is now fixed; the following
package(s) have been removed from unstable:

python-scitools |0.9.0-2 | all
  scitools |0.9.0-2 | source

--- Reason ---
RoQA; RC buggy, inactive upstream, Depends on to-be-removed packages
--

Note that the package(s) have simply been removed from the tag
database and may (or may not) still be in the pool; this is not a bug.
The package(s) will be physically removed automatically when no suite
references them (and in the case of source, when no binary references
it).  Please also remember that the changes have been done on the
master archive and will not propagate to any mirrors until the next
dinstall run at the earliest.

Packages are usually not removed from testing by hand. Testing tracks
unstable and will automatically remove packages which were removed
from unstable when removing them from testing causes no dependency
problems. The release team can force a removal from testing if it is
really needed, please contact them if this should be the case.

We try to close bugs which have been reported against this package
automatically. But please check all old bugs, if they were closed
correctly or should have been re-assigned to another package.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 823...@bugs.debian.org.

The full log for this bug can be viewed at https://bugs.debian.org/823121

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmas...@ftp-master.debian.org.

Debian distribution maintenance software
pp.
Scott Kitterman (the ftpmaster behind the curtain)

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] Bug#823121: Removed package(s) from unstable

2016-05-05 Thread Debian FTP Masters
Version: 0.9.0-2+rm

Dear submitter,

as the package scitools has just been removed from the Debian archive
unstable we hereby close the associated bug reports.  We are sorry
that we couldn't deal with your issue properly.

For details on the removal, please see https://bugs.debian.org/823121

The version of this package that was in Debian prior to this removal
can still be found using http://snapshot.debian.org/.

This message was generated automatically; if you believe that there is
a problem with it please contact the archive administrators by mailing
ftpmas...@ftp-master.debian.org.

Debian distribution maintenance software
pp.
Scott Kitterman (the ftpmaster behind the curtain)

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] django-uwsgi is marked for autoremoval from testing

2016-05-05 Thread Debian testing autoremoval watch
django-uwsgi 0.1.3-2 is marked for autoremoval from testing on 2016-06-04

It (build-)depends on packages with these RC bugs:
821666: uwsgi-plugin-php: PHP 7.0 Transition
821721: uwsgi: PHP 7.0 Transition
822921: uwsgi: FTBFS with latest apache2


___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] [bts-link] source package src:sphinx

2016-05-05 Thread bts-link-upstream
#
# bts-link upstream status pull for source package src:sphinx
# see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html
#

user bts-link-upstr...@lists.alioth.debian.org

# remote status report for #820895 (http://bugs.debian.org/820895)
# Bug title: sphinx: please extend SOURCE_DATE_EPOCH support
#  * https://github.com/sphinx-doc/sphinx/pull/2503
#  * remote status changed: (?) -> closed
#  * closed upstream
tags 820895 + fixed-upstream
usertags 820895 + status-closed

thanks

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] Processed: [bts-link] source package src:sphinx

2016-05-05 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org:

> #
> # bts-link upstream status pull for source package src:sphinx
> # see http://lists.debian.org/debian-devel-announce/2006/05/msg1.html
> #
> user bts-link-upstr...@lists.alioth.debian.org
Setting user to bts-link-upstr...@lists.alioth.debian.org (was 
bts-link-de...@lists.alioth.debian.org).
> # remote status report for #820895 (http://bugs.debian.org/820895)
> # Bug title: sphinx: please extend SOURCE_DATE_EPOCH support
> #  * https://github.com/sphinx-doc/sphinx/pull/2503
> #  * remote status changed: (?) -> closed
> #  * closed upstream
> tags 820895 + fixed-upstream
Bug #820895 [src:sphinx] sphinx: please extend SOURCE_DATE_EPOCH support
Added tag(s) fixed-upstream.
> usertags 820895 + status-closed
There were no usertags set.
Usertags are now: status-closed.
> thanks
Stopping processing here.

Please contact me if you need assistance.
-- 
820895: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=820895
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] audioread 2.1.2-1 MIGRATED to testing

2016-05-05 Thread Debian testing watch
FYI: The status of the audioread source package
in Debian's testing distribution has changed.

  Previous version: 1.0.3-1
  Current version:  2.1.2-1

-- 
This email is automatically generated once a day.  As the installation of
new packages into testing happens multiple times a day you will receive
later changes on the next day.
See https://release.debian.org/testing-watch/ for more information.

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] Bug#777381: Hate CRMs?

2016-05-05 Thread shauli
Hello  I found you in https://bugs.debian.org   We have a great CRM for small businesses. We know you hate CRMs and like using Excel, so we've built an advanced CRM that looks just like a spreadsheet. It's dead simple to use and gives you all the benefits of advanced CRMs.Please see demo at: www.crmizer.comRegister for a free trial at: www.crmizer.com/register.html I'm here to help you with any questions/problems.Best Regards,  Shauli Daon, PhDsha...@crmizer.comwww.crmizer.com(c)2016 CRMizer. 6, Sharet St. Tel Aviv, Israel. You will not receive any more e-mails from us. ___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] python-django-treebeard_4.0.1+dfsg-1_amd64.changes ACCEPTED into unstable

2016-05-05 Thread Debian FTP Masters


Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Thu, 05 May 2016 14:44:20 +0200
Source: python-django-treebeard
Binary: python-django-treebeard python3-django-treebeard 
python-django-treebeard-doc
Architecture: source all
Version: 4.0.1+dfsg-1
Distribution: unstable
Urgency: low
Maintainer: Debian Python Modules Team 

Changed-By: Michael Fladischer 
Description:
 python-django-treebeard - Efficient implementations of tree data structures 
for Django
 python-django-treebeard-doc - Efficient implementations of tree data 
structures for Django (doc
 python3-django-treebeard - Efficient implementations of tree data structures 
for Django (Pyt
Changes:
 python-django-treebeard (4.0.1+dfsg-1) unstable; urgency=low
 .
   [ Ondřej Nový ]
   * Fixed VCS URL (https)
 .
   [ Michael Fladischer ]
   * New upstream release.
   * Refresh patches.
   * Bump Standards-Version to 3.9.8.
   * Update lintian overrides for long line in javascript source.
Checksums-Sha1:
 d43fd411387d41de10230d6084e0ad6e15a8a042 2493 
python-django-treebeard_4.0.1+dfsg-1.dsc
 431f4828689d08f23471e8ab5bb6160fcd9cb003 74349 
python-django-treebeard_4.0.1+dfsg.orig.tar.gz
 5dc1070f951f7078ce7d379560bb16e112c69770 6036 
python-django-treebeard_4.0.1+dfsg-1.debian.tar.xz
 9a64f20130517191905af8019fc9c0730522acdd 119292 
python-django-treebeard-doc_4.0.1+dfsg-1_all.deb
 5b80b5c9a365543e1504e5cd239ac0b414924da8 48666 
python-django-treebeard_4.0.1+dfsg-1_all.deb
 9bcd54548c6cecaaff74a6030b63aacdb21a9f40 48598 
python3-django-treebeard_4.0.1+dfsg-1_all.deb
Checksums-Sha256:
 395a2cf76d549f8b34eefaa5144852d16021f7536d2927e856c8e74b9a59b9fc 2493 
python-django-treebeard_4.0.1+dfsg-1.dsc
 f7b87244283efb1b80d619a91633b9575fc22f35f511c5d401a23e323ba8a88f 74349 
python-django-treebeard_4.0.1+dfsg.orig.tar.gz
 405073188348c5d47d1b21aa5108fea53a15dc89da24c729d4010673f04e2e64 6036 
python-django-treebeard_4.0.1+dfsg-1.debian.tar.xz
 fadaa0177cc371595558d54773ee589a4d73c5256d5d598cb7dc8ba007fa3347 119292 
python-django-treebeard-doc_4.0.1+dfsg-1_all.deb
 b7dd8253724ecbaef6b02ea27fc71772d8a007a6421f04c070580d4fec46 48666 
python-django-treebeard_4.0.1+dfsg-1_all.deb
 1b047e607fbbd2fa731c193893b62cfc6f58b9251f973e6ad18cb07ddaf92436 48598 
python3-django-treebeard_4.0.1+dfsg-1_all.deb
Files:
 94d5d59de6bcf1b9b286931ccbf9c43c 2493 python optional 
python-django-treebeard_4.0.1+dfsg-1.dsc
 8be3631cb39721a6b0b89505ab8946d3 74349 python optional 
python-django-treebeard_4.0.1+dfsg.orig.tar.gz
 9609f135ba396e94aeffe81810976478 6036 python optional 
python-django-treebeard_4.0.1+dfsg-1.debian.tar.xz
 c9fe2a45c6d271ca524b7840b5c74a51 119292 doc optional 
python-django-treebeard-doc_4.0.1+dfsg-1_all.deb
 daab950e19039d1d2961776aaa9e6927 48666 python optional 
python-django-treebeard_4.0.1+dfsg-1_all.deb
 3c4708dfdcc765447a93674e23f2e1ad 48598 python optional 
python3-django-treebeard_4.0.1+dfsg-1_all.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQIcBAEBCgAGBQJXK0ZSAAoJEGlMre9Rx7W2/+EP/RLDmIlWlTQacsCndg6LGls5
gof+NNT+7NF0VdQKFy6RkTln5epb7ombenEhcMZrbN2Ddvptl00V8R7zEOvKT8cI
4YzvMNjvdB4t7ModnaKS52XC2UORxu4ZUHsjBQafZTq6Xvhp7+2cBafPhmRH0upp
7qZalAPzQZpZProf5IDzA31JiFWg8Btb10aeHrf7MeHjBpoA05YzyeVsiO9BFj2Z
ZCZnDDEk7RNtLTikMZ2YcOcqvnRiCHF80b3PXXwkL5wEI0v9xLHNidhneifdYUjH
6j+c8zfNyjism6SuNo98K/q7MIkBtcJ/QSrxE5eLvcyKngf5s3xzEYmJiclDCXZp
DyZhb6QIwvBRWoZAk2vnWIopSqJnMe1y5oS3/TOKRUgzbQi2mX1A75rA0JpBf08v
8+W4meO8zvOzoahfGtPmvBrWyWo/P1qJjSCrHu9x7h6qz1OMq2khVkdI4VD3J2YG
AipOiBraDIiNqLALYaoG+TCQ0Fy+DEcM0Zk2dW4bvnPPSQxykb8ftnw31OuXyUUV
Y9O0zBdtVE3TiunH4CKATPQPU6LjZ+3mDGgJoBSt9a9Uo6cQ7txTS/5Z5WoMOnOW
3N7UV5xhlRlRIOqjV9M7zrkNDEeCDht8cokoMavEITcbv08h68fmT+twgut6qC+B
sGm52L1wUUHv5qrVBK54
=Gn5F
-END PGP SIGNATURE-


Thank you for your contribution to Debian.

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Bug#823508: Useless in Debian

2016-05-05 Thread David Prévot
Package: python-guzzle-sphinx-theme
Version: 0.7.10-1
Severity: serious

[ Filled as an RC-bug by the maintainer to see the package auto-removed
  from testing. ]

I packaged python-guzzle-sphinx-theme in order to build php-guzzle-doc,
but php-guzzle is going away, see #821698. There is a priori little
point in shipping python-guzzle-sphinx-theme in any Debian stable
release anymore.

I intend to follow up with an RM request once php-guzzle is gone, unless
anyone objects (but feel free to beat me to it).

Regards

David


signature.asc
Description: PGP signature
___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Processing of python-django-treebeard_4.0.1+dfsg-1_amd64.changes

2016-05-05 Thread Debian FTP Masters
python-django-treebeard_4.0.1+dfsg-1_amd64.changes uploaded successfully to 
localhost
along with the files:
  python-django-treebeard_4.0.1+dfsg-1.dsc
  python-django-treebeard_4.0.1+dfsg.orig.tar.gz
  python-django-treebeard_4.0.1+dfsg-1.debian.tar.xz
  python-django-treebeard-doc_4.0.1+dfsg-1_all.deb
  python-django-treebeard_4.0.1+dfsg-1_all.deb
  python3-django-treebeard_4.0.1+dfsg-1_all.deb

Greetings,

Your Debian queue daemon (running on host franck.debian.org)

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] python-feather-format_0.2.0-1_amd64.changes ACCEPTED into unstable

2016-05-05 Thread Debian FTP Masters


Accepted:

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Format: 1.8
Date: Thu, 05 May 2016 19:08:48 +0800
Source: python-feather-format
Binary: python-feather-format python3-feather-format
Architecture: source amd64
Version: 0.2.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Modules Team 

Changed-By: ChangZhuo Chen (陳昌倬) 
Description:
 python-feather-format - Python interface to the Apache Arrow-based Feather 
File Format (P
 python3-feather-format - Python interface to the Apache Arrow-based Feather 
File Format (P
Changes:
 python-feather-format (0.2.0-1) unstable; urgency=medium
 .
   * New upstream release.
   * Bump Standards-Version to 3.9.8.
Checksums-Sha1:
 497d938ee8873e77ffcb741a5213bbbaa365 2340 python-feather-format_0.2.0-1.dsc
 4fa5d72e0e57e27d0adb570ca0b2d519709897b7 98708 
python-feather-format_0.2.0.orig.tar.gz
 cff85cd29b6bf6645ccb5615dc92ba7adc07cd01 2740 
python-feather-format_0.2.0-1.debian.tar.xz
 9dff0e5b7a4b54321a787ba06284a23378379496 632224 
python-feather-format-dbgsym_0.2.0-1_amd64.deb
 7eeec0ddc7b9d6a4193dc1c6cbcfa27b8c4ec28b 74744 
python-feather-format_0.2.0-1_amd64.deb
 bb4e80e5de4317540bc175be9138ed2fda6e8744 642898 
python3-feather-format-dbgsym_0.2.0-1_amd64.deb
 ec64c568ad2c1c8db30dae865af3a15092909490 75406 
python3-feather-format_0.2.0-1_amd64.deb
Checksums-Sha256:
 38336ce2ef9da5764bcb9f8296c44ee3ab45f36a53bf67fc90759fe777bf0788 2340 
python-feather-format_0.2.0-1.dsc
 28f83f3e02eb5b9ff32cea8a8b49905a65e6c1468b78f8a765efcb9fde047472 98708 
python-feather-format_0.2.0.orig.tar.gz
 6d8ae72b89e0819b6a890aeec50254130edf715a7688fb695e154689058decfd 2740 
python-feather-format_0.2.0-1.debian.tar.xz
 de1385522cac164b78cdfa74d8603956733672e2df8488dbd591c642f0a9d246 632224 
python-feather-format-dbgsym_0.2.0-1_amd64.deb
 8ea9db8aabcea636da9bfb4a8cda5e4fa81b49dac9818bbcf8d1e90017609b97 74744 
python-feather-format_0.2.0-1_amd64.deb
 5a92c7599656c4d70b83bbe04578838b34b34f7322059d3b756a79a42bb07e6f 642898 
python3-feather-format-dbgsym_0.2.0-1_amd64.deb
 ca6406323efab16b0373606039309bc774a6cf09cd1d4960d939b82cfe310ed3 75406 
python3-feather-format_0.2.0-1_amd64.deb
Files:
 71b048f2bf989ed0b1f022682df37a7e 2340 python optional 
python-feather-format_0.2.0-1.dsc
 2a66efc5ec856624bc8c66389578a14b 98708 python optional 
python-feather-format_0.2.0.orig.tar.gz
 2734565e3aa1b997879e8652c9be1aae 2740 python optional 
python-feather-format_0.2.0-1.debian.tar.xz
 6b73325350bd935afa32bf0b39585c9b 632224 debug extra 
python-feather-format-dbgsym_0.2.0-1_amd64.deb
 68219207129fa864894c54a388f46d23 74744 python optional 
python-feather-format_0.2.0-1_amd64.deb
 5c839dee99a6791eb0223277c2748301 642898 debug extra 
python3-feather-format-dbgsym_0.2.0-1_amd64.deb
 c6d2ba9206b630ef254ecb9149700db0 75406 python optional 
python3-feather-format_0.2.0-1_amd64.deb

-BEGIN PGP SIGNATURE-
Version: GnuPG v1

iQIcBAEBCgAGBQJXKysZAAoJELTYlw90nD9qRAAQAKDI8NCGIdOuu7K9UArJkFWc
CjS38mrR+wtW1WumqbZKjVCK0TqfoPemhkiHlfnH5Y1rOO1vUnqsY05GOGSG1mfM
oPB1gd2+x36QianUJcxKQ5X5CPsNAp0of+EeaJW/jxnrcKUbhoMxDeHuLWcr+2+6
I9VzU0boH9uqRQAh8JcK/4E4wSBI7nsgNciGNGNRmiXGeKnMDmjFZ7zv+j9rHJEE
BSaXsvcBZaLS1nqGrGulejqZvnHwFt0c5pad9NfCQu8XOpJmDDv2Vw2izw3zDQs/
+1YNJbqqzuEnYsMxGYhNCdJYfIVGA4zMaaRRiVbOlaaqTvL9leE7YbL350RzTX6k
DUG7a1XIWPtanojV/4+rYTyCl8dxXbdPpNf0he7hy1XkCdZsvNY2QT6GPoEOuhzA
2jtl+VvYXYY09xnH3/FZNSwFfEUUXXjC2Wn7pNXU/wKV8CgFEVT6gVNVpF83sPOY
yXuSRuc/K+1/VGlHkcyh537KOjwMz4PSg/1FxzRw7H0BraoUF06kLgmBPBUQQnfG
aDSB06WSqCNAZ6DJT44WH0wLhqhfCOQ/DsHacPC0qB58AX3PXm5to1cdcHDmgCGK
neke+qJpt+RgKo2tcmhofAOn2AzaQ7T/4tiFsPnQlfHl3hoajf2KIup7FGk/omyM
aJfxZgReJta/x9y/+0oV
=aF9V
-END PGP SIGNATURE-


Thank you for your contribution to Debian.

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team

[Python-modules-team] Processing of python-feather-format_0.2.0-1_amd64.changes

2016-05-05 Thread Debian FTP Masters
python-feather-format_0.2.0-1_amd64.changes uploaded successfully to localhost
along with the files:
  python-feather-format_0.2.0-1.dsc
  python-feather-format_0.2.0.orig.tar.gz
  python-feather-format_0.2.0-1.debian.tar.xz
  python-feather-format-dbgsym_0.2.0-1_amd64.deb
  python-feather-format_0.2.0-1_amd64.deb
  python3-feather-format-dbgsym_0.2.0-1_amd64.deb
  python3-feather-format_0.2.0-1_amd64.deb

Greetings,

Your Debian queue daemon (running on host franck.debian.org)

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


Re: [Python-modules-team] [Python-modules-commits] [mpmath] 01/01: d/copyright: Changed licence shortname BSD -> BSD-3-clause

2016-05-05 Thread Brian May
Barry Warsaw  writes:

>>announced before:
>>http://lists.alioth.debian.org/pipermail/python-modules-team/2016-March/030256.html
>
> Thanks!  I must have missed it, but you did the right thing.

In future, far better to use the debian-pyt...@lists.debian.org mailing
list; less likely to get missed.

Having said that I did see the email, and I was happy with it. I didn't
notice it was the wrong mailing list though :-(.

It does cause confusion for people who are familar with the team, having
the aloith as the Maintainer field - people use this expecting to be
able to contact the Maintainer... Sometimes I will resend emails to
debian-pyt...@lists.debian.org when I see this happen.
-- 
Brian May 

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team


[Python-modules-team] Bug#823488: python-ldap3: connection switch silently to anonymous bind if password is empty, failing auth

2016-05-05 Thread Simone Piccardi
Package: python-ldap3
Version: 0.9.4.2-1
Severity: important

Dear Maintainer,

*** Reporter, please consider answering these questions, where appropriate ***

   * What led up to the situation?
   * What exactly did you do (or not do) that was effective (or
 ineffective)?
   * What was the outcome of this action?
   * What outcome did you expect instead?

*** End of the template - remove these template lines ***

When creating a connection with the Connection object the code defaults to 
AUTH_ANONYMOUS (doing so an anonymus bind) also when _only_ the password
is empty (not, as said by documentation, when both user and password are 
empty). 

These the lines of /usr/lib/python3/dist-packages/ldap3/core/connection.py
where the problem is:

self.user = user
self.password = password
if self.user and self.password and not authentication:
self.authentication = AUTH_SIMPLE
elif not authentication:
self.authentication = AUTH_ANONYMOUS
elif authentication in [AUTH_SIMPLE, AUTH_ANONYMOUS, AUTH_SASL]:
self.authentication = authentication
else:
self.last_error = 'unknown authentication method'
raise LDAPUnknownAuthenticationMethodError(self.last_error)

If password is empty, according to default of None for authentication, the 
first if fails and then is selected the second elif.

That means that you will get a valid object with anonymous bind, 
the user presence will be simply ignored but, and so when you use 
object also to check autentication, looking if you get a connection 
(as it should be), you will got authentication for every user just 
giving an empty password.

That's plain wrong, contrary to what is said in the documentation here:

http://ldap3.readthedocs.io/connections.html

and very dangerous (the more plain way to use the library will bring people 
to enable empty password access for any user). 


-- System Information:
Debian Release: 8.4
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: i386 (i686)

Kernel: Linux 4.4.6-1-pve (SMP w/8 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: sysvinit (via /sbin/init)

Versions of packages python-ldap3 depends on:
ii  python-pyasn1  0.1.7-1
pn  python:any 

python-ldap3 recommends no packages.

python-ldap3 suggests no packages.

-- no debconf information

___
Python-modules-team mailing list
Python-modules-team@lists.alioth.debian.org
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/python-modules-team