Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Ondřej Surý
On Wed, Aug 15, 2012 at 4:34 AM, Christoph Anton Mitterer cales...@scientia.net wrote: On Wed, 2012-08-15 at 09:02 +0900, Charles Plessy wrote: For the moment there is the draft proposed by Christoph at http://bugs.debian.org/674089#66 I should note perhaps, that this draft expected all the

Bug#684824: apr: FTBFS: rm: cannot remove `libtoolT': No such file or directory

2012-08-15 Thread Stefan Fritsch
Hi Lucas, On Tuesday 14 August 2012, Lucas Nussbaum wrote: WARNING: This is Linux but configure did not detect POSIX semaphores. ERROR: POSIX semaphores not usable and /dev/shm not mounted. ERROR: Aborting. HINT: If you are using pbuilder or cowbuilder, add /dev/shm to BINDMOUNTS HINT:

Bug#670945: libapache2-mod-php5: Bug #589384 breaks default behaviour for MultiViews

2012-08-15 Thread Stefan Fritsch
FWIW, this bug has been open for 4 months. It would have been nice if you (or the php maintainers) could have sent a note to debian- apache@l.d.o a bit earlier. If mod_negotiation requires some mime-type for .php to work, then the obvious solution would be to add a non-magic type, for example

Bug#684268: marked as done (libaprutil1: apr_password_validate mangles sha512_crypt hashes)

2012-08-15 Thread Debian Bug Tracking System
Your message dated Wed, 15 Aug 2012 18:47:42 + with message-id e1t1id4-0004pb...@franck.debian.org and subject line Bug#684268: fixed in apr-util 1.4.1-3 has caused the Debian Bug report #684268, regarding libaprutil1: apr_password_validate mangles sha512_crypt hashes to be marked as done.

Processing of apr-util_1.4.1-3_i386.changes

2012-08-15 Thread Debian FTP Masters
apr-util_1.4.1-3_i386.changes uploaded successfully to localhost along with the files: apr-util_1.4.1-3.dsc apr-util_1.4.1-3.debian.tar.gz libaprutil1_1.4.1-3_i386.deb libaprutil1-ldap_1.4.1-3_i386.deb libaprutil1-dbd-mysql_1.4.1-3_i386.deb libaprutil1-dbd-sqlite3_1.4.1-3_i386.deb

Processed: reassign 670945 to libapache2-mod-php5

2012-08-15 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: reassign 670945 libapache2-mod-php5 Bug #670945 [apache2.2-bin] libapache2-mod-php5: Bug #589384 breaks default behaviour for MultiViews Bug reassigned from package 'apache2.2-bin' to 'libapache2-mod-php5'. Ignoring request to alter found

apr-util_1.4.1-3_i386.changes ACCEPTED into unstable

2012-08-15 Thread Debian FTP Masters
Accepted: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Format: 1.8 Date: Wed, 15 Aug 2012 20:10:55 +0200 Source: apr-util Binary: libaprutil1 libaprutil1-ldap libaprutil1-dbd-mysql libaprutil1-dbd-sqlite3 libaprutil1-dbd-odbc libaprutil1-dbd-pgsql libaprutil1-dbd-freetds libaprutil1-dev

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Stefan Fritsch
Thanks for coming up with some wording. On Wednesday 15 August 2012, Ondřej Surý wrote: In order to avoid any problems when not using Apache PHP5 module, and if you relied on MIME type definitions, read the README.Debian from the php5-common package on how to correctly configure PHP 5

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Christoph Anton Mitterer
On Wed, 2012-08-15 at 10:40 +0200, Ondřej Surý wrote: With the exception of RemoteType php they are all in the place. I've just had a look into git (I guess that's the canonical location?): http://anonscm.debian.org/gitweb/?p=pkg-php/php.git;a=blob_plain;f=debian/php5-common.README.Debian;hb=HEAD

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Christoph Anton Mitterer
On Wed, 2012-08-15 at 21:07 +0200, Stefan Fritsch wrote: Since we have gone to great pains to not use the magic MIME types anymore, I think we should not recommend them here. Or at least not as the first option. Stefan, can you please elaborate on what you mean with magic MIME types? (you're

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Stefan Fritsch
On Wednesday 15 August 2012, Christoph Anton Mitterer wrote: On Wed, 2012-08-15 at 21:07 +0200, Stefan Fritsch wrote: Since we have gone to great pains to not use the magic MIME types anymore, I think we should not recommend them here. Or at least not as the first option. Stefan, can you

Re: [php-maint] Bug#674089: Bug#674089: mime-support: removed application/x-httpd-* can lead to immense security problems

2012-08-15 Thread Christoph Anton Mitterer
On Thu, 2012-08-16 at 00:24 +0200, Stefan Fritsch wrote: Stefan, can you please elaborate on what you mean with magic MIME types? (you're talking about MIME type discovery via libmagic or similar? That would be not what's suggested above!) The mime types that are also handler names and