Bug#775891: torbrowser-launcher: Tor Project changed alpha/beta versioning, now tb-l always suggests downloading alphas/betas

2015-01-20 Thread Paul Wise
Package: torbrowser-launcher Version: 0.1.7-1 Severity: important Tags: fixed-upstream patch The Tor Project changed how alphas and betas are versioned and now torbrowser-launcher always suggests downloading available alphas/betas. Please apply this patch from upstream to fix this issue in sid and

Bug#775888: virtualbox: CVE-2014-6588 CVE-2014-6589 CVE-2014-6590 CVE-2014-6595 CVE-2015-0418 CVE-2015-0427

2015-01-20 Thread Ritesh Raj Sarraf
On 01/21/2015 12:53 PM, Moritz Muehlenhoff wrote: > Package: virtualbox > Severity: grave > Tags: security > Justification: user security hole > > No specific details available yet: > http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html > > Cheers, > Moritz > The follo

Bug#775890: assimp: Unresolved symbols in the debian version

2015-01-20 Thread Leopold Palomo-Avellaneda
Package: assimp Version: 3.0~dfsg-3 Severity: important Dear Maintainer, * What exactly did you do (or not do) that was effective (or ineffective)? The debian version of the package shipped in sid or jessie has some symbols dropped. * What was the outcome of this action? A simple program canno

Bug#775889: breaks init scripts with .sh suffix

2015-01-20 Thread Martin Pitt
Package: systemd Version: 215-9 Severity: serious Tags: upstream confirmed patch Michael points out a regression in 215-9 wrt. handling init scripts with a .sh suffix. This is closely related, but not identical to #775404, so let's track it as a separate bug. I posted a fix with a test case to th

Bug#775888: virtualbox: CVE-2014-6588 CVE-2014-6589 CVE-2014-6590 CVE-2014-6595 CVE-2015-0418 CVE-2015-0427

2015-01-20 Thread Moritz Muehlenhoff
Package: virtualbox Severity: grave Tags: security Justification: user security hole No specific details available yet: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a

Bug#775887: objeck-lang-i386/3.3.5-2-1

2015-01-20 Thread Randy Hollines
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "objeck-lang-i386" * Package name: objeck-lang-i386 Version : 3.3.5-2-1 Upstream Author : Randy Hollines * URL : http://www.objeck.org/ * License

Bug#775886: RFS: objeck-lang-amd64/3.3.5-2-1

2015-01-20 Thread Randy Hollines
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "objeck-lang-amd64" * Package name: objeck-lang-amd64 Version : 3.3.5-2-1 Upstream Author : Randy Hollines * URL : http://www.objeck.org/ * License

Bug#775885: muse-el: Include local copy of favicon.ico

2015-01-20 Thread Riley Baird
Package: muse-el Severity: wishlist Tags: newcomer upstream When the file usr/share/doc/muse-el/examples/mwolson/templates/header.html is opened in a browser, the favicon is downloaded from the internet. This has two main problems: privacy, and usage on systems without internet access. The soluti

Bug#775884: icu: CVE-2014-6591

2015-01-20 Thread Moritz Muehlenhoff
retitle 775884 CVE-2014-6591 CVE-2014-6585 thanks On Wed, Jan 21, 2015 at 07:36:51AM +0100, Moritz Muehlenhoff wrote: > Package: icu > Severity: important > Tags: security > > Hi, > the issue CVE-2014-6585 from today's Oracle patch update > (http://www.oracle.com/technetwork/topics/security/cpuja

Bug#775559: [Pkg-gnupg-maint] Bug#775559: gnupg2: New default hashing (SHA256) signing fails with cryptostick/nitrokey (storage version)

2015-01-20 Thread NIIBE Yutaka
Thank you for your report. On 01/17/2015 08:55 PM, Luca Bruno wrote: > With the latest gnupg2 package targeted for the Jessie, defaulting hashing > algorithm has been changed to SHA256. This broke my smartcard setup using a > cryptostick/nitrokey (storage version, latest 0.18 firmware) as signing

Bug#775884: icu: CVE-2014-6591

2015-01-20 Thread Moritz Muehlenhoff
Package: icu Severity: important Tags: security Hi, the issue CVE-2014-6585 from today's Oracle patch update (http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html) is actually a vulnerability in ICU (since Java embeds a copy). Red Hat has tracked this down further and isolated

Bug#670947: Same here

2015-01-20 Thread Vincas Dargis
I have missed that feature too. Bug reported in 2012... is anyone maintaining list search?

Bug#775883: cvsps chokes on servers that print more than one "M" response to "version" command

2015-01-20 Thread Richard Hansen
Package: cvsps Version: 2.1-6 Tags: patch If the CVS server prints more than one "M" response line to the "version" command, cvsps prints "cvs_direct: protocol error reading version" and fails to read the repository. For example, cvsps does not like the following exchange: Client: version Server

Bug#775795: [Pkg-puppet-devel] Bug#775795: puppet: Service's debian provider assumes SysV init

2015-01-20 Thread Russ Allbery
Faidon Liambotis writes: > On Debian systems (i.e. on $::operatingsystem == "debian"), the default > provider is "debian"; this is a separate provider that inherits the > "init" provider but overrides a few methods to add invoke-rc.d support. > The systemd provider, on the other hand, is default

Bug#775882: mariadb-10.0: affected by CVEs of the Oracle Patch Update for January 2015?

2015-01-20 Thread Salvatore Bonaccorso
Source: mariadb-10.0 Version: 10.0.15-3 Severity: grave Tags: security Hi MariaDB maintainers! As you might have seen there is a new Oracle Patch Update including updates for MySQL 5.5. I'm filling this bug to just have it double-checked as mariadb.com does not list yet new versions afaics: http

Bug#775881: mysql-5.5: Multiple security fixes from January 2015 CPU

2015-01-20 Thread Salvatore Bonaccorso
Source: mysql-5.5 Version: 5.5.23-2 Severity: grave Tags: security upstream patch fixed-upstream Hi As usual at this time of the year, there was a new Oracle Patch Update including updates for MySQL, see: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html#AppendixMSQL Reg

Bug#775880: unblock: gaviotatb/0.4-2

2015-01-20 Thread Varun Hiremath
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package gaviotatb Fixes an RC bug: #775699 Last set of changes: http://anonscm.debian.org/cgit/users/varun/gaviotatb.git/commit/?id=c42dc56b8ed203d15368923891af5674b529b9fc

Bug#775879: libgnome-2-0: single-click becomes double-click at random

2015-01-20 Thread westlake
Package: libgnome-2-0 Version: 2.32.1-5 Severity: important https://bugzilla.gnome.org/show_bug.cgi?id=743276 Anyone want to look at this be my guest.. thanks -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lis

Bug#756090: O: irker -- submission tools for IRC notifications

2015-01-20 Thread Daniel Baumann
On 01/21/15 00:52, anarcat wrote: > Is it possible to get a bundle of the git repository to resume working > on the package? no, i don't have it anymore. -- Address:Daniel Baumann, Donnerbuehlweg 3, CH-3012 Bern Email: daniel.baum...@progress-technologies.net Internet: htt

Bug#698508: libseccomp-dev does not provide static library

2015-01-20 Thread Kenton Varda
Hello, I'm the lead developer of Sandstorm.io. We do containerization stuff. Often it's a lot easier to build a static binary than to try to make all the right libraries available in a container. We actually ship our own updates using our own update infrastructure, so the security update benefits

Bug#774862: ciderwebmail: unhandled symlink to directory conversion: /usr/share/ciderwebmail/root/static/images/mimeicons

2015-01-20 Thread Andreas Beckmann
Followup-For: Bug #774862 Control: found -1 1.05-4 The .maintscript needs a small fix to actually work as intended: vvv -symlink_to_dir /usr/share/ciderwebmail/root/static/images/mimeicons ../../../

Bug#611554: Ark no longer allows to "Open with" a suitable application

2015-01-20 Thread Ldten K
The fix has been fixed and released upstream as a part of KDE Applications v14.12 on December 17, 2014. Is it realistic to expect that the fix will be backported to wheezy? Thanks -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Co

Bug#754565: Non free icc profile

2015-01-20 Thread Riley Baird
Package: moodle Followup-For: Bug #754565 Hi, This bug has been open for a while, with no response. Files that forbid modification are not DFSG-free, so you will need to remove lib/tcpdf/include/sRGB.icc from the moodle package. However, note that the file that you want is in the non-free packag

Bug#775702: caff: Using gpg-agent without GPG_TTY causes silent caff failures

2015-01-20 Thread Ewen McNeill
On 21/01/15 13:24, Guilhem Moulin wrote: On Wed, 21 Jan 2015 at 11:12:44 +1300, Ewen McNeill wrote: - MacPorts (OS X) (gpg 1.4.18): works _without_ sderr redirected, fails with stderr redirected (no output, exit code 1), unless GPG_TTY is set then it works again. Wow that's odd. I agree, it'

Bug#775877: gnome-session: No mouse pointer after login

2015-01-20 Thread Aron Podrigal
Package: gnome-session Version: 3.14.0-2 Severity: grave Tags: upstream Justification: renders package unusable Dear Maintainer, * What led up to the situation? I upgraded all packages with apt-get upgrade. after the upgrade, when starting gdm, everything seems fine, but

Bug#775876: ITP: crosswalk -- Crosswalk is an app runtime based on Chromium/Blink

2015-01-20 Thread Xinchao He
Package: wnpp Severity: wishlist Owner: Xinchao He * Package name: crosswalk Version : 11.40.277.2 Upstream Author : Crosswalk Dev * URL : https://crosswalk-project.org * License : BSD Programming Lang: C++ Description : Crosswalk is an app runtime bas

Bug#760916: brltty interferes with getty autostart

2015-01-20 Thread Dave Mielke
[quoted lines by Dave Mielke on 2015/01/20 at 00:34 -0500] >Brltty could delay opening the tty until the user needs to inject a character. >This could be by typing on the braille device, by requesting cursor routing, >etc. The user probably wouldn't do any of that until the login prompt appears.

Bug#775875: My bad

2015-01-20 Thread Manolo Díaz
My bad. You meant "!=" instead. Regards, -- Manolo Díaz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#767028: ovirt-guest-agent: fails to install

2015-01-20 Thread Andreas Beckmann
On 2015-01-10 15:05, Holger Levsen wrote: >> This seems to be an udevadm 'bug' instead, it can't handle unreachable >> /proc/cmdline . Is there any policy that a package should install >> while /proc is unavailable? > > packages may be in non working state, but I'd argue that installation itself

Bug#760916: brltty interferes with getty autostart

2015-01-20 Thread Dave Mielke
[quoted lines by Dave Mielke on 2015/01/20 at 20:32 -0500] >On my Fedora systems - which are managed by systemd - X starts on tty1. As I understand it, X also wants a free vt. Why is it, then, that X is willing to start on tty1 (at least on Fedora systems) even though brltty already has tty1 op

Bug#760916: brltty interferes with getty autostart

2015-01-20 Thread Dave Mielke
[quoted lines by Samuel Thibault on 2015/01/21 at 01:10 +0100] >> But isn't there still the risk that brltty opening tty1 for this purpose may >> prevent systemd-login from starting getty on tty1? > >systemd-login always starts getty on tty1. On my Fedora systems - which are managed by systemd -

Bug#775559: [Pkg-gnupg-maint] Bug#775559: gnupg2: New default hashing (SHA256) signing fails with cryptostick/nitrokey (storage version)

2015-01-20 Thread Daniel Kahn Gillmor
Hi Luca-- On Sat 2015-01-17 06:55:47 -0500, Luca Bruno wrote: > With the latest gnupg2 package targeted for the Jessie, defaulting hashing > algorithm has been changed to SHA256. This broke my smartcard setup using a > cryptostick/nitrokey (storage version, latest 0.18 firmware) as signing now >

Bug#755202: My Fix in Gentoo

2015-01-20 Thread Keivan Moradi
I had the same problem in Gentoo linux. I am by no means a network expert. I had this warning in NM log. error in connection /etc/NetworkManager/system-connections/.keep_net-misc_networkmanager-0: invalid connection: connection.type: property is missing So I removed the the following file /

Bug#775875: nftables: service nftables status fails due a bashim

2015-01-20 Thread Manolo Díaz
Package: nftables Version: 0.4-2 Severity: important Tags: patch Dear Maintainer, service nftables status fails with /etc/init.d/nftables: 67: [: 15: unexpected operator due the use of "==" as equal comparator. Please, use "=" instead, which is posix compliant. Best Regards, Manolo Día

Bug#775579: iceweasel: Clicking Iceweasel's URL bar does not preselect the existing URL

2015-01-20 Thread Daniel Kahn Gillmor
Control: severity -1 wishlist On Sat 2015-01-17 12:21:59 -0500, Alexander Veit wrote: > clicking (activating) Iceweasel's URL bar does not preselect the existing URL. > An input cursor is opened at the click position instead. fwiw, i consider iceweasel's current behavior a feature. Chromium has

Bug#756253: Upgrade from 2.02~beta2-10 to 2.02~beta2-11 left grub unbootable

2015-01-20 Thread Steve McIntyre
On Wed, Jan 21, 2015 at 06:55:05AM +0900, Mike Hommey wrote: >On Tue, Jan 20, 2015 at 01:44:37PM +, Steve McIntyre wrote: >> >> The automatic setup of grub-install calling efibootmgr won't be >> touching the "grub" entry at all - it's set up to only play with >> "debian" entries. So that shoul

Bug#772963: release-notes: cellphone friendly CSS

2015-01-20 Thread Stéphane Blondon
Hi Niels, I've done some improvements based on your previous remarks. I patched the files provided by your online demo. Demos are temporary available : http://stephane.yaal.fr/tmp/installer_docs/Chapter%C2%A01.%C2%A0Introduction.html http://stephane.yaal.fr/tmp/installer_docs/Chapter%C2%A02.%C2%

Bug#775702: caff: Using gpg-agent without GPG_TTY causes silent caff failures

2015-01-20 Thread Guilhem Moulin
Control: retitle -1 caff: The absence of GPG_TTY causes silent caff failures in OSX Control: tag -1 + pending On Wed, 21 Jan 2015 at 11:12:44 +1300, Ewen McNeill wrote: > - MacPorts (OS X) (gpg 1.4.18): works _without_ sderr redirected, fails with > stderr redirected (no output, exit code 1), unl

Bug#774686: ClamAV: Can't create new file

2015-01-20 Thread Andreas Cadhalpun
Control: tags -1 pending Hi Sebastian, On 19.01.2015 21:39, Sebastian Andrzej Siewior wrote: Control: -1 tags + pending That didn't quite work. I finally pushed that change into unstable. Thanks. I hope that clamav upstream releases clamav by the end of the month :) OK. Regarding th

Bug#770492: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks

2015-01-20 Thread James Morris
On Sat, 17 Jan 2015, Ben Hutchings wrote: > chown() and write() should clear all privilege attributes on > a file - setuid, setgid, setcap and any other extended > privilege attributes. > > However, any attributes beyond setuid and setgid are managed by the > LSM and not directly by the filesyste

Bug#760916: brltty interferes with getty autostart

2015-01-20 Thread Samuel Thibault
Dave Mielke, le Tue 20 Jan 2015 00:34:27 -0500, a écrit : > [quoted lines by Samuel Thibault on 2014/12/29 at 18:30 +0100] > >> We could open it on demand rather than immediately? > > > >On which demand? > > Brltty could delay opening the tty until the user needs to inject a > character. Ah, in

Bug#767353: [Pkg-clamav-devel] Bug#767353: clamav: ERROR: Can't save PID to file /var/run/clamav/freshclam.pid: No such file or directory

2015-01-20 Thread Andreas Cadhalpun
Control: tags -1 pending Hi Milko, On 18.01.2015 11:53, Milko Krachounov wrote: On Friday, 30 October 2014 22:14:46 you wrote: As this warning is completely harmless, when systemd is used, I don't think it's worth to invest a lot of time trying to fix this. It is not completely harmless---it

Bug#775044: openjdk-7: FTBFS: java.lang.RuntimeException: time is more than 10 years from present: 1104530400000

2015-01-20 Thread peter green
peter green wrote: I have just prepared a patch against wheezy's openjdk-6 to disable the timebomb code. I have attatched this patch which I am currently in the process of testing. I have tested that my patch results in succesful builds of openjdk-6 and openjdk-7 in raspbian wheezy. Debdiffs

Bug#756090: O: irker -- submission tools for IRC notifications

2015-01-20 Thread anarcat
On Sat, Jul 26, 2014 at 08:37:50AM +0200, Daniel Baumann wrote: > irker is orphaned. Hi Daniel, Is it possible to get a bundle of the git repository to resume working on the package? fatal: remote error: access denied or repository not exported: /git/debian/packages/irker.git thanks a. signa

Bug#756090: O: irker -- submission tools for IRC notifications

2015-01-20 Thread anarcat
Control: retitle -1 ITA: irker -- submission tools for IRC notifications Control: owner -1 anar...@debian.org On Sat, Jul 26, 2014 at 08:37:50AM +0200, Daniel Baumann wrote: > Package: wnpp > > irker is orphaned. I'd be interested in maintaining irker. Jonathan: you did the last upload, would y

Bug#768772: ITP: xkcdpass -- secure passphrase generator inspired by XKCD 936

2015-01-20 Thread Antoine Beaupré
On 2015-01-17 02:54:11, Ben Finney wrote: > Control: summary -1 Copyright status confirmed for all files. Packaging > complete. > > On 10-Jan-2015, Ben Finney wrote: > >> I am considering the copyright implications of the included >> wordlist, which appears to be from a proprietary source and does

Bug#770492: [RFC PATCH RESEND] vfs: Move security_inode_killpriv() after permission checks

2015-01-20 Thread Casey Schaufler
On 1/20/2015 3:17 PM, James Morris wrote: > On Sat, 17 Jan 2015, Ben Hutchings wrote: > >> chown() and write() should clear all privilege attributes on >> a file - setuid, setgid, setcap and any other extended >> privilege attributes. >> >> However, any attributes beyond setuid and setgid are manag

Bug#775859: RFP: pageres -- Capture screenshots of websites in various resolutions on the command-line

2015-01-20 Thread Jérémy Lal
Le mardi 20 janvier 2015 à 22:38 +0100, Axel Beckert a écrit : > Hi Jérémy, > > Jérémy Lal wrote: > > just to say to node-webkitgtk [0] can take screenshots using system > > libwebkit2gtk4 - way nicer than using phantomjs, packaging-wise. > > I have no idea of what is considered nice or not so ni

Bug#775874: debian-installer: Name of encrypted volume is confusing and may lead to inadvertent data-loss

2015-01-20 Thread Rogier
Package: debian-installer Severity: normal Dear Maintainer, Currently, when configuring an encrypted volume, the debian installer names it after the disk and partition it happens to be on at the time of installation e.g. sda3_crypt. If the disk and/or partition names change at a later time, this

Bug#775562: fixed upstream

2015-01-20 Thread Reiner Herrmann
Control: tags -1 + fixed-upstream Patch was applied in upstream version 7.4.586. signature.asc Description: OpenPGP digital signature

Bug#774672: Missing information about copyright

2015-01-20 Thread Antonio Cardoso Martins
Information about copyright Source: https://github.com/antocm/guidedog Comment: Source rewritten from original guidedog 1.0.0 by Simon Edwards Files: * Copyright: 2000-2001 Simon Edwards 2014-2015 Antonio Cardoso Martins License: GPL-2.0+ Files: debian/* Copyright: 2015 Antonio Card

Bug#775873: patch: directory traversal via file rename

2015-01-20 Thread Jakub Wilk
Package: patch Version: 2.7.1-7 Tags: security patch now support git-style patches, which allows renaming files. This feature can be abused for directory traversal. As a proof of concept, applying the attached patch creates a file in /tmp: $ ls /tmp/moo /bin/ls: cannot access /tmp/moo: No suc

Bug#775872: ITP: fcml -- machine code manipulation library

2015-01-20 Thread Stephen Kitt
Package: wnpp Severity: wishlist Owner: Stephen Kitt * Package name: fcml Version : 1.0.0 Upstream Author : Slawomir Wojtasiak * URL : http://fcml-lib.com * License : LGPL-2.1+ Programming Lang: C Description : machine code manipulation library FCML,

Bug#775871: torbrowser-launcher: TorBrowser Bundle signing key changed

2015-01-20 Thread u
Package: torbrowser-launcher Version: 0.1.7-1 Severity: important The Tor Project changed their Tor Browser Bundle signing key yesterday. Thus, downloading or updating TBB when using torbrowser-launcher will fail. Upstream version 0.1.8 fixes this issue. -- To UNSUBSCRIBE, email to debian-bugs

Bug#775805: reportbug: use the freedesktop icon theme in the menu shortcut

2015-01-20 Thread Sandro Tosi
On Tue, Jan 20, 2015 at 10:02 AM, HJ wrote: > use the system set icon theme care to share in a bit more details what's the effect of this change: -Icon=/usr/share/reportbug/debian-swirl.svg +Icon=debian-swirl Regards, -- Sandro Tosi (aka morph, morpheus, matrixhasu) My website: http://matrixha

Bug#775870: libfile-stripnondeterminism-perl: Does not strip javadoc's header

2015-01-20 Thread Peter De Wachter
Package: libfile-stripnondeterminism-perl Version: 0.003-1 Severity: normal Javadoc files, at least the ones I've looked at, have, in addition to the "Generated by javadoc" comment, a timestamp in a tag. For example: AbstractAction (Java Platform SE 7 ) I guess nobody

Bug#775702: caff: Using gpg-agent without GPG_TTY causes silent caff failures

2015-01-20 Thread Ewen McNeill
On 21/01/15 6:05, Guilhem Moulin wrote: Your report says you have signing-party 1.1.4-1, but your patch seems to be against a more recent version :-P Yes, the patch was originally written for the version in OS X MacPorts, which is currently between the version in Debian Stable and Debian Unst

Bug#775746: [Python-modules-team] Bug#775746: python-genshi: Bug in Genshi i18n.py prevents uploading attachments in Trac

2015-01-20 Thread W. Martin Borgert
On 2015-01-20 21:41, Johannes Weißl wrote: > But the current status is that the Trac issue tracking system in Debian > Jessie is not unusable if you have Trac users that want a non-English > (or at least German) user interface, which is quite sad. Adding > attachments to tickets is important. This

Bug#726430: apt-listbugs: Does not uses proxy from Acquire::http::ProxyAutoDetect

2015-01-20 Thread Francesco Poli
On Tue, 20 Jan 2015 16:15:01 -0300 Lisandro Damián Nicanor Pérez Meyer wrote: > It times out, but I think acng it not proxying the data as it used to do. > Please give me a few more days to check. No problem, feel free to take the time you need to perform other tests! When you do so, please cons

Bug#775869: wheezy backport requested for openafs-client 1.6.9-2

2015-01-20 Thread Benjamin Kaduk
package: openafs-client Version: 1.6.1-3+deb7u2~bpo60+1 severity: wishlist We have received a request to backport openafs 1.6.9-2 for wheezy, since the current package will not build against the current kernel in wheezy-backports. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debia

Bug#773456: [pkg-cryptsetup-devel] Bug#773456: [cryptsetup] invoke-rc.d not found on boot

2015-01-20 Thread Jonas Meurer
Am 20.01.2015 um 16:17 schrieb Lobko, Eugene: > Hi Jonas, > >> would you mind testing the attached patch? Please report back whether it >> fixes the bug for you. > Sure. Could you please attach the patch? > Oops, sorry. Here it is. Cheers, jonas --- /lib/cryptsetup/cryptdisks.functions +++ /l

Bug#756253: Upgrade from 2.02~beta2-10 to 2.02~beta2-11 left grub unbootable

2015-01-20 Thread Mike Hommey
On Tue, Jan 20, 2015 at 01:44:37PM +, Steve McIntyre wrote: > On Mon, Jan 19, 2015 at 07:42:37AM +0900, Mike Hommey wrote: > >On Sun, Jan 18, 2015 at 11:37:28AM +, Steve McIntyre wrote: > >> The ENOSPC handling has been bad in the past, but it's not clear that > >> was the cause of your ori

Bug#775868: keepalived: reload leaks file descriptors

2015-01-20 Thread Brown, Heather
Package: keepalived Version: 1:1.2.13-1 Severity: wishlist Tags: patch When keepalived is reloaded using service keepalived reload (on controller nodes) it leaks file descriptors. Steps to reproduce: 1. Locate the vrrp keepalived process $ ps -elf |grep -i keepalived 1 S root 15129 1 0 80 0 -

Bug#775461: python-wxgtk3.0: wx.tools.img2py: insecure use of /tmp

2015-01-20 Thread Olly Betts
On Thu, Jan 15, 2015 at 10:35:39PM +0100, Jakub Wilk wrote: > This is how wx.tools.img2py uses temporary files (with boring parts > snipped): > >tfname = tempfile.mktemp() >try: >ok, msg = convert(image_file, maskClr, None, tfname, > wx.BITMAP_TYPE_PNG, ".png") ># ... >

Bug#775866: vlc: multiple vulnerabilities

2015-01-20 Thread Salvatore Bonaccorso
Hi! On Tue, Jan 20, 2015 at 09:47:26PM +0100, Yves-Alexis Perez wrote: > CVEs should follow soon. Also, I guess Wheezy and Jessie are affected too, so > a > DSA might be needed. They were assigned now: http://www.openwall.com/lists/oss-security/2015/01/20/11 Regards, Salvatore -- To UNSUBSCR

Bug#760687: Bug#775859: RFP: pageres -- Capture screenshots of websites in various resolutions on the command-line

2015-01-20 Thread Axel Beckert
Hi Jérémy, Jérémy Lal wrote: > just to say to node-webkitgtk [0] can take screenshots using system > libwebkit2gtk4 - way nicer than using phantomjs, packaging-wise. I have no idea of what is considered nice or not so nice in node.js packaging. :-) > It's as simple as > > #!/usr/bin/nodejs > >

Bug#775867: ITP: libtomsfastmath -- Fast multiple-precision integer library.

2015-01-20 Thread Sebastian Andrzej Siewior
Package: wnpp Owner: Sebastian Andrzej Siewior Severity: wishlist * Package name: libtomsfastmath0 Version : 0.12 Upstream Author : Tom St Denis * URL : http://www.libtom.net/?page=features&newsitems=5&whatfile=tfm * License : Public Domain Programming Lang:

Bug#771841: surf crash backtrace

2015-01-20 Thread Herminio Hernandez, Jr.
I read the thread you sent. It looks like the developers are not sure if they can get webkitgtk patched for powerpc users. On Tue, Jan 20, 2015 at 3:26 PM, Alberto Garcia wrote: > On Tue, Jan 20, 2015 at 02:59:17PM -0600, Herminio Hernandez, Jr. wrote: > > > is 2.6 available in unstable? > > Yes

Bug#771841: surf crash backtrace

2015-01-20 Thread Alberto Garcia
On Tue, Jan 20, 2015 at 02:59:17PM -0600, Herminio Hernandez, Jr. wrote: > is 2.6 available in unstable? Yes but it only supports the WebKit 2 API, and I think none of the browsers you mentioned (midori, luakit, etc.) use it. Epiphany does use the WebKit 2 API. Berto -- To UNSUBSCRIBE, email

Bug#768001: Icedove crashes on mime_decode_qp_buffer()

2015-01-20 Thread Roland Hieber
Hi, I had attached the respective mail in my second comment, base64-encoded so the bugtracker does not convert it in any kind: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768001#12 - Roland -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubsc

Bug#774068: ExtUtils-MakeMaker and NO_PERLLOCAL

2015-01-20 Thread Dominic Hargreaves
On Tue, Dec 30, 2014 at 02:17:51PM +0200, Niko Tyni wrote: > On Tue, Dec 30, 2014 at 10:27:44AM +, Andrew Beverley wrote: > > On Tue, 2014-12-30 at 11:47 +0200, Niko Tyni wrote: > > > > Packages not using the short form dh rules would need to be modified > > > before the patch could be removed

Bug#771841: surf crash backtrace

2015-01-20 Thread Herminio Hernandez, Jr.
is 2.6 available in unstable? On Tue, Jan 20, 2015 at 2:52 PM, Alberto Garcia wrote: > On Tue, Dec 30, 2014 at 10:30:02AM -0600, Herminio Hernandez, Jr. wrote: > > > Has there been any update to this? I know this bug is impact not > > only surf but any webkit based browser I used on Jessie (ie m

Bug#771841: surf crash backtrace

2015-01-20 Thread Alberto Garcia
On Tue, Dec 30, 2014 at 10:30:02AM -0600, Herminio Hernandez, Jr. wrote: > Has there been any update to this? I know this bug is impact not > only surf but any webkit based browser I used on Jessie (ie midori > luakit, dwb). I think this is the same as #771098 Unfortunately there's a patch avail

Bug#775746: [Python-modules-team] Bug#775746: python-genshi: Bug in Genshi i18n.py prevents uploading attachments in Trac

2015-01-20 Thread Johannes Weißl
On Tue, Jan 20, 2015 at 03:26PM -0500, Barry Warsaw wrote: > It's not clear to me that such an exception would be granted in this case: > > https://release.debian.org/jessie/freeze_policy.html You are right, it might not be a critical, grave, or serious bug, because it does not render the whole p

Bug#775866: vlc: multiple vulnerabilities

2015-01-20 Thread Yves-Alexis Perez
Source: vlc Version: 2.1.5-1 Severity: grave Tags: security Justification: user security hole Hi, multiple vulnerabilities were reported against vlc 2.1.5. The complete mail is at http://seclists.org/oss-sec/2015/q1/187 but at least the following vulnerabilities are fixed in vlc master branch: *

Bug#744369: java.lang.NoClassDefFoundError: java/nio/file/InvalidPathException

2015-01-20 Thread Nicolas Le Cam
Package: netbeans Version: 7.0.1+dfsg1-5 Followup-For: Bug #744369 Dear Maintainer, I was able to fix the problem by installing openjdk-7-jdk. Should the package depend on at least java7-jdk ? -- System Information: Debian Release: 8.0 APT prefers testing APT policy: (900, 'testing'), (600,

Bug#775356: Evolved patch

2015-01-20 Thread Thomas Hood
Here's a cosmetically evolved patch which I'll commit and release shortly. Thanks! -- Thomas diff --git a/etc/dhcp/dhclient-enter-hooks.d/resolvconf b/etc/dhcp/dhclient-enter-hooks.d/resolvconf index 529504b..cf61615 100644 --- a/etc/dhcp/dhclient-enter-hooks.d/resolvconf +++ b/etc/dhcp/dhclient-e

Bug#773896: monkeyscan: identity menu has no indicator for expired keys

2015-01-20 Thread Vagrant Cascadian
On 2014-12-24, Paul Wise wrote: > I have an expired key in my local keyring but monkeyscan doesn't > indicate that it is expired in the menu. I would expect the menu item to > be either greyed or crossed out or not be visible in the Identity menu > at all. I don't have any revoked keys but I would

Bug#775746: [Python-modules-team] Bug#775746: python-genshi: Bug in Genshi i18n.py prevents uploading attachments in Trac

2015-01-20 Thread Barry Warsaw
On Jan 19, 2015, at 03:51 PM, W. Martin Borgert wrote: >I can confirm both the bug and the solution sent by Johannes. Barry, would >you fix this bug and ask for freeze exception? If not, I can try it, even if >my SVN knowledge is rusty :~( It's not clear to me that such an exception would be gr

Bug#773421: lxc: can't start container

2015-01-20 Thread Tiago Teresa Teodosio
I faced a similar issue (if not the same), after a recent update and switching from systemd to sysvinit. Although I had cgmanager installed and running, I had to install cgroupfs-mount to make lxc-start work again. And I can reproduce the failure by stopping cgroupfs-mount service. Could cgroupfs

Bug#775865: Kernel Bug: rcu_bh detected stall on CPUxxx (t=0 jiffies)

2015-01-20 Thread Adrian Minta
Package: linux-image-3.2.0-4-amd64 Version: 3.2.65-1+deb7u1 I have found this kernel panic on multiple servers. All of them have manifested this after upgrade and none of them had this problem with previous kernel version. The kernel panic appears when the server is under load. [146876.785593

Bug#770955: wheezy-pu: package openvswitch/1.4.2+git20120612-9.1~deb7u1.1

2015-01-20 Thread Adam D. Barratt
Control: tags -1 + pending On Sat, 2015-01-17 at 11:48 +, Adam D. Barratt wrote: > On 2014-12-14 20:52, Adam D. Barratt wrote: > [...] > > Hmmm, okay. It looks like the package in unstable uses yet another > > slightly different approach. > > > > Please go ahead. > > Gentle ping. Uploaded a

Bug#775864: ITP: php-facedetect -- Detect faces with PHP

2015-01-20 Thread Mathieu Parent
Package: wnpp Severity: wishlist Owner: Mathieu Parent * Package name: php-facedetect Version : 1.1.0 Upstream Author : Robert Eisele (infusion) * URL : http://www.xarg.org/project/php-facedetect/ * License : BSD-3-clause Programming Lang: C Description

Bug#775693: RFS: python-cligj/0.1.0-1 [ITP]

2015-01-20 Thread Sebastiaan Couwenberg
Hi Johan, Sorry for not doing this sooner, but I have reviewed the package now. Some comments follow. The copyright file only documents the upstream copyright, documenting the copyright & license for debian/* is a good idea unless you want to assign the copyright to MapBox. There seems to be an

Bug#775859: RFP: pageres -- Capture screenshots of websites in various resolutions on the command-line

2015-01-20 Thread Jérémy Lal
Le mardi 20 janvier 2015 à 20:25 +0100, Axel Beckert a écrit : > Package: wnpp > Severity: wishlist > > * Package name: pageres > Version : 1.1.0 > Upstream Author : Sindre Sorhus > * URL or Web page : https://github.com/sindresorhus/pageres > * License : MIT > Programmi

Bug#775863: ITP: php5-php-facedetect -- Usage: /usr/share/pkg-php-tools/scripts/phppkginfo [options] package|package_type|channel|summary|description|maintainers dir|package.xml /usr/share/pkg-

2015-01-20 Thread Mathieu Parent
Package: wnpp Severity: wishlist Owner: Mathieu Parent Package name: Usage: /usr/share/pkg-php-tools/scripts/phppkginfo [options] package|package_type|channel|summary|description|maintainers dir|package.xml /usr/share/pkg-php-tools/scripts/phppkginfo [options] date|version|license|c

Bug#775862: ITP: php5-php-facedetect -- Usage: /usr/share/pkg-php-tools/scripts/phppkginfo [options] package|package_type|channel|summary|description|maintainers dir|package.xml /usr/share/pkg-

2015-01-20 Thread Mathieu Parent
Package: wnpp Severity: wishlist Owner: Mathieu Parent Package name: Usage: /usr/share/pkg-php-tools/scripts/phppkginfo [options] package|package_type|channel|summary|description|maintainers dir|package.xml /usr/share/pkg-php-tools/scripts/phppkginfo [options] date|version|license|c

Bug#775861: ITP: swarm-cluster -- robust and fast clustering method for amplicon-based studies

2015-01-20 Thread Andreas Tille
Package: wnpp Severity: wishlist Owner: Andreas Tille * Package name: swarm-cluster Version : 1.2.19 Upstream Author : Torbjørn Rognes * URL : https://github.com/torognes/swarm * License : Affero-GPL-3 Programming Lang: C Description : robust and fast

Bug#775860: gnome-online-accounts: icons inculde trademarks

2015-01-20 Thread HJ
Package: gnome-online-accounts Version: 3.14.2-1 Severity: important Dear Maintainer, I'm pretty sure that the facebook, google, flicker etc. icons/logos are tradmarked which would make them non-free see also: * http://commons.wikimedia.org/wiki/Commons:Copyright_rules_by_subject_matter#Tradema

Bug#743420: sane-utils: scanimage fails when avahi is enabled

2015-01-20 Thread Leopold BAILLY
Jörg Frings-Fürst writes: > Hello Leopold, > > please can you attach the following files: > > - /etc/sane.d/net.conf > - /etc/sane.d/dll.conf > - /etc/avahi/avahi-daemon.conf > - /etc/avahi/hosts Here they are. I attach also /etc/sane.d/dll.d/libsane-extras (which is the only file in /etc/sane.d

Bug#766310: [Pkg-xfce-devel] Bug#766310: xfce4-weather-plugin: PlugIn don't show any data

2015-01-20 Thread Mechtilde
now it works for me -- Mechtilde Stehmann ## PGP encryption welcome ## Key-ID 0x141AAD7F signature.asc Description: OpenPGP digital signature

Bug#775859: RFP: pageres -- Capture screenshots of websites in various resolutions on the command-line

2015-01-20 Thread Axel Beckert
Package: wnpp Severity: wishlist * Package name: pageres Version : 1.1.0 Upstream Author : Sindre Sorhus * URL or Web page : https://github.com/sindresorhus/pageres * License : MIT Programming Lang: JavaScript (PhantomJS) Description : Capture screenshots of websit

Bug#739676: systemd-user PAM config breaks some libpam-* modules

2015-01-20 Thread Christian Kastner
On 2015-01-20 19:28, Felipe Sateler wrote: > For reference, the inclusion of common-session is a local debian > patch[1]. The original file referenced system-auth, which apparently > debian does not use. > > > [1] > http://anonscm.debian.org/cgit/pkg-systemd/systemd.git/commit/debian/patches/Adj

Bug#775480: scowl: text files should be encoded in UTF-8

2015-01-20 Thread Don Armstrong
Control: tag -1 moreinfo On Fri, 16 Jan 2015, Ben Finney wrote: > The data files of SCOWL are text, and are installed as simple text > files on the system. > > A reasonable assumption for Debian programs reading text files is that > they are encoded as UTF-8. That assumption is broken, and the pr

Bug#726430: apt-listbugs: Does not uses proxy from Acquire::http::ProxyAutoDetect

2015-01-20 Thread Lisandro Damián Nicanor Pérez Meyer
It times out, but I think acng it not proxying the data as it used to do. Please give me a few more days to check. -- You know it's love when you memorize her IP number to skip DNS overhead. Anonymous Lisandro Damián Nicanor Pérez Meyer http://perezmeyer.com.ar/ http://perezmeyer.blogspot.com/

Bug#766801: mate-applets: battery charge monitor icon goes the reverse order while charging

2015-01-20 Thread Mike Gabriel
Control: tag -1 - moreinfo Control: close -1 - Original message - > Well, this is strange. The issue is gone. > > I'm not sure when, but I think since I reinstalled mate-applets after > playing with it a bit (compiling from source etc.), the applet behaves > exactly as expected now. So ma

Bug#775702: caff: Using gpg-agent without GPG_TTY causes silent caff failures

2015-01-20 Thread Guilhem Moulin
Hi Ewen, Your report says you have signing-party 1.1.4-1, but your patch seems to be against a more recent version :-P But anyway I agree that the standard output shouldn't be thrown away like that. That said the absence of GPG_TTY in the environment doesn't seem to bother my gpg(1); doesn't the

Bug#775858: Alt-Enter to enter line break in cells doesn't work under XFCE4

2015-01-20 Thread Tomas Pospisek
Package: gnumeric Version: 1.12.18-1 Severity: normal Tags: patch Hello, as reported upstream [1] pressing Alt-Enter in a (Text-)cell to insert a line break doesn't work at least under jessie's xfce4. Upstream has commited a fix [2]. After patching the current Debian sources myself I verified th

Bug#769797: marked as done (gnat-4.9: FTBFS: Needs update for gcc-4.9-4.9.2)

2015-01-20 Thread Neil Williams
On Mon, 19 Jan 2015 11:45:28 +0100 Matthias Klose wrote: > reopen 769797 > found 769797 4.9.1-4 > thanks > > On 01/18/2015 11:51 AM, Debian Bug Tracking System wrote: > > Your message dated Sun, 18 Jan 2015 10:46:31 + > > with message-id <20150118104631.13a3ecaf@sylvester.codehelp> > > and s

Bug#775781: mesa 10.4.2 from unstable won't build packages on jessie

2015-01-20 Thread Sven Joachim
Control: notfound -1 10.4.2 Control: found -1 10.4.2-1 On 2015-01-20 08:37 +0100, Timo Aaltonen wrote: > On 19.01.2015 22:01, Darius Spitznagel wrote: >> Source: mesa >> Version: 10.4.2 >> Severity: normal >> >> Dear Maintainer, >> >> since Mesa 10.4.x landed in Debian I cannot compile mesa any

  1   2   3   >