Bug#780797: openssh-server: modifies the user configuration

2015-03-20 Thread Christoph Anton Mitterer
On Sat, 2015-03-21 at 00:51 -0400, Chris Knadle wrote: > § 10.7.3 Behavior > Configuration file handling must conform to the following behavior: > • local changes must be preserved during a package upgrade Well, strictly speaking, if the user had let that option at it's Debian default

Bug#780764: Acknowledgement (php5-curl: Cookie header not send on request)

2015-03-20 Thread Carlos C Soto
I confirm that using the last update from wheezy/security 5.4.39-0+deb7u1 fixes this bug. -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Bug#780797: openssh-server: modifies the user configuration

2015-03-20 Thread Chris Knadle
The issue here is that the openssh-server package modifies two config files in /etc without any warning to the user, and that's a clear Policy violation IMHO: § 10.7.3 Behavior Configuration file handling must conform to the following behavior: • local changes must be preserved during

Bug#780895: Poor documentation and discoverability

2015-03-20 Thread Brian Julin
Package: bash-completion Version: 1:2.1-4 Severity: minor Tags: upstream patch Figuring out how to customize the pre-installed Debian bash completions is not easy. This is probably what happens to your average CLI user when they get fed up with some of bash completion's defaults and decide to try

Bug#780894: redmine: postinst error on Wheezy to Jessie upgrade

2015-03-20 Thread Dmitry Smirnov
Package: redmine Version: 3.0~20140825-5 I've noticed postinst error on redmine upgrade from Wheezy to Jessie: (I believe database was not configured) Preparing to replace redmine 1.4.4+dfsg1-2+deb7u1 (using .../redmine_3.0~20140825-5_all.deb) ... [...] Setting up redmine (3.0~20140825-5)

Bug#780893: ITP: confargparse -- integrated argument/configuration file parser that follows the syntax of argparser

2015-03-20 Thread Francois Marier
Package: wnpp Severity: wishlist Owner: Francois Marier * Package name: confargparse Version : 1.0.15 Upstream Author : S. Joshua Swamidass * URL : https://bitbucket.org/swamidass/confargparse/ * License : MIT Programming Lang: Python Description : int

Bug#780300: mumble-server: Mumble-server not listening after machine restart

2015-03-20 Thread Chris Knadle
tags -1 - unreproducible moreinfo thanks On 03/11/2015 03:53 PM, Tuxicoman wrote: > Package: mumble-server > Version: 1.2.8-2 > Severity: important > > Dear Maintainer, > > After restart, the mumble-server is started but not listening. > A manual restart of the service (systemctl restart mumble-

Bug#780892: security-tracker: please show unsupported packages as unsupported instead of unimportant

2015-03-20 Thread Paul Wise
Package: security-tracker Severity: important Please change the Urgency field for issues on unsupported packages from "unimportant" to "unsupported". Having "unimportant" in the urgency field is very misleading. Currently the only indication that a package is unsupported is in the notes section of

Bug#780373: Add the ability to set preferred auto IM by locale

2015-03-20 Thread Osamu Aoki
Hi, On Sat, Mar 21, 2015 at 02:39:31AM +0100, Gunnar Hjalmarsson wrote: > Hi Osamu! > I noticed one thing, which has been corrected in the Ubuntu patch. If > LC_CTYPE is set explicitly, its value is not surrounded by quotes in the > output from the locale command. Please see the attached diff. Go

Bug#780373: Add the ability to set preferred auto IM by locale

2015-03-20 Thread Gunnar Hjalmarsson
Hi Osamu! On 2015-03-20 16:29, Osamu Aoki wrote: > On Wed, Mar 18, 2015 at 05:01:15PM +0800, Aron Xu wrote: >> On Tue, Mar 17, 2015 at 11:18 PM, Osamu Aoki wrote: >> We are trying to make Fcitx default for Chinese locales in Ubuntu >> 15.04, as a transition of making it default for everyone in th

Bug#780891: ladvd: FTBFS on hppa: AC_CC_STACK_PROTECTOR check is broken

2015-03-20 Thread John David Anglin
Package: ladvd Version: 1.1.0-1 Severity: normal See: http://buildd.debian-ports.org/status/fetch.php?pkg=ladvd&arch=hppa&ver=1.1.0-1&stamp=1426898307 The following change fixes build: --- ladvd-1.1.0.orig/m4/stack_protector.m4 +++ ladvd-1.1.0/m4/stack_protector.m4 @@ -19,7 +19,7 @@ dnl

Bug#774564: ITP: node-fs-extra -- fs-extra contains methods not included in the Node.js fs module

2015-03-20 Thread Bas Couwenberg
Package: wnpp Followup-For: Bug #774564 Owner: Bas Couwenberg * Package name: node-fs-extra Version : 0.16.5 Upstream Author : JP Richardson * URL : https://github.com/jprichardson/node-fs-extra * License : Expat Programming Lang: JavaScript Description

Bug#780890: ITP: node-jsonfile -- Easily read/write JSON files in Node.js

2015-03-20 Thread Bas Couwenberg
Package: wnpp Severity: wishlist Owner: Bas Couwenberg * Package name: node-jsonfile Version : 2.0.0 Upstream Author : JP Richardson * URL : https://github.com/jprichardson/node-jsonfile * License : Expat Programming Lang: JavaScript Description : Easi

Bug#780889: localepurge: does nothing if path-exclude is enabled

2015-03-20 Thread Adam Borowski
Package: localepurge Version: 0.7.3.4 Severity: normal If path-exclude is enabled, localepurge effectively does nothing. In theory, it would remove locales shipped with eventual packages installed after it, but in typical usage, localepurge is installed last or close to last. Even worse, manuall

Bug#780865: Processed: reassign 780865 to openafs-modules-dkms

2015-03-20 Thread Benjamin Kaduk
On Fri, 20 Mar 2015, Ben Hutchings wrote: > On Fri, 2015-03-20 at 19:48 -0400, Benjamin Kaduk wrote: > > > > I have only become the openafs maintainer relatively recently, so my > > apologies if this is well-trodden ground, but what is supposed to happen > > when the stable KPI changes? Is it rea

Bug#780865: Processed: reassign 780865 to openafs-modules-dkms

2015-03-20 Thread Ben Hutchings
On Fri, 2015-03-20 at 19:48 -0400, Benjamin Kaduk wrote: > Hi Ben, > > I can certainly apply upstream openafs's patch to wheezy-backports, but > the fact remains that a kernel update in stable changed the KPI, which > hardly seems "stable". > > I have only become the openafs maintainer relatively

Bug#778646: Multiple issues

2015-03-20 Thread Peter Selinger
Here's the patch that I am planning to apply upstream. Please comment if you see anything wrong with it. While the general idea is similar to Tomasz's patch, I've solved the details a bit differently. * I prefer to use ssize_t instead of unsigned long long int for memory manipulations. Since s

Bug#780519: tomcat7 build failure

2015-03-20 Thread Miguel Landaeta
tags 780519 + confimed owner 780519 ! thanks On Fri, Mar 20, 2015 at 11:10:28AM +0100, Markus Koschany wrote: > > [...] > > and recompiled openjdk-7 from scratch. But tomcat7 still fails to build > from source even with this older openjdk-7 version. I checked the failing unit tests and all of th

Bug#780888: openssl: x509 manpage and usage page list unsupport -mdc2 option

2015-03-20 Thread Sebastian Stellingwerff
Package: openssl Version: 1.0.1k-1 Severity: minor Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Trying to generate different fingerprints of an ssl certificate & reading the manpage x509 * What exactly did

Bug#780865: Processed: reassign 780865 to openafs-modules-dkms

2015-03-20 Thread Benjamin Kaduk
Hi Ben, I can certainly apply upstream openafs's patch to wheezy-backports, but the fact remains that a kernel update in stable changed the KPI, which hardly seems "stable". I have only become the openafs maintainer relatively recently, so my apologies if this is well-trodden ground, but what is

Bug#746580: sysv-rc: [patch] much improved update-rc.d integration w/ systemd

2015-03-20 Thread Florian Schlichting
Raphael Hertzog wrote: > On Sun, 15 Mar 2015, Christian Seiler wrote: >> Control: severity -1 important >> Control: tags -1 + patch > > I'm tempted to raise the severity to serious as the current behaviour > is really bad for packages that ship both native .service files and > init script. I think

Bug#780887: ITP: python-hammock -- Rest APIs python client

2015-03-20 Thread Brian May
Package: wnpp Severity: wishlist Owner: Brian May * Package name: python-hammock Version : 0.2.4 Upstream Author : Kadir Pekel * URL : https://github.com/kadirpekel/hammock * License : EXPAT Programming Lang: Python Description : Rest APIs python client

Bug#775583: fixed in lvm2 2.02.111-2.1

2015-03-20 Thread Ben Hutchings
On Wed, 2015-03-11 at 20:41 -0400, Mike Miller wrote: > On Mon, Mar 02, 2015 at 12:34:01 +, Ben Hutchings wrote: > > Changes: > > lvm2 (2.02.111-2.1) unstable; urgency=medium > > . > >* Non-maintainer upload > >* Add initramfs-tools boot script for preparing additional block > >

Bug#780571: release-notes: Review from the kernel team

2015-03-20 Thread Ben Hutchings
On Mon, 2015-03-16 at 08:35 +0100, Niels Thykier wrote: > Package: release-notes > Severity: normal > > Dear kernel team, > > I am contacting you to do a final review of the release-notes for the > kernel related topics (as listed on [1]) > > The only items I am currently aware of is: > > * >

Bug#780811: debian-installer: Netinst throws error when MATE is selected in "Software, selection"

2015-03-20 Thread Christian MOMON
Le 19/03/2015 19:55, Cyril Brulebois a écrit : > Hi, > [...] > It looks like 3.6GB is too small for both Gnome and MATE. If installing > with Gnome then MATE once rebooted into the installed system works, I > suspect that's because of the cache directory holding downloaded > packages: holding both

Bug#750837: ITP: moarvm -- virtual machine for Rakudo Perl 6 and NQP

2015-03-20 Thread Daniel Dehennin
Dominique Dumont writes: > On Tuesday 17 March 2015 00:23:51 Daniel Dehennin wrote: >> Now it builds cleanly in a schroot, I even install the package and “moar >> --help” works \o/. > > I've begun to review the package. A couple of comments: > > * I think /usr/lib/moar/libmoar.so should land in a

Bug#597897: Current status of alsa-firmware?

2015-03-20 Thread Ben Hutchings
On Wed, 2015-03-18 at 14:39 +0100, Jaromír Mikeš wrote: > > Unfortunately, some of the blobs in alsa-firmware are purportedly licensed > under the GPLv2, > > but without source code available. > > > The same problem exists for some blobs that were moved out of the linux > > tree, but since they w

Bug#780886: ITP: node-get-stdin -- Easier stdin for Node.js

2015-03-20 Thread Bas Couwenberg
Package: wnpp Severity: wishlist Owner: Bas Couwenberg * Package name: node-get-stdin Version : 4.0.1 Upstream Author : Sindre Sorhus (http://sindresorhus.com) * URL : https://github.com/sindresorhus/get-stdin * License : Expat Programming Lang: JavaScript

Bug#780885: inetutils-ftp: Unable to use alias name in netrc file.

2015-03-20 Thread Mats Erik Andersson
Package: inetutils-ftp Version: 1.9.2.39.3a460-3 Severity: normal Hello there, it was recently observed by the upstream developer, after receiving a bug report, that all versions of the FTP client in GNU Inetutils are replacing any host alias by its canonical name just after having established th

Bug#780884: inetutils-telnetd: Unable to allow autologin without authentication.

2015-03-20 Thread Mats Erik Andersson
Package: inetutils-telnetd Version: 1.9.2.39.3a460-3 Severity: normal It was recently observed by the upstream developer, after a bug report, that the telnet server is unable to hand the user name over to login(1), when not using Kerberos authentication, which whould be need when the client desire

Bug#505628: "locales" are no longer really needed

2015-03-20 Thread Adam Borowski
These days, the C.UTF-8 locale is guaranteed to be available. This makes installation of "locales" unneeded for someone content with an English language system. This serves the purpose of that "locales-base" you wanted. With this functionality built-in into libc, there's no need for localepurge t

Bug#780883: flashcache: please make the build reproducible

2015-03-20 Thread Reiner Herrmann
Source: flashcache Version: 3.1.2+git20140801-1 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps Hi! While working on Debian's “reproducible builds” effort [1], we have noticed that flashcache doesn't build reproducibly. It embeds the current d

Bug#780882: ifupdown: uses current cgroup when spawning processes in ifup/ifdown with systemd

2015-03-20 Thread Simon Ruderich
Package: ifupdown Version: 0.7.53.1 Severity: normal Dear Maintainer, When ifup spawns a new process like wpa_supplicant (e.g. when using the config pasted below), then the spawned wpa_supplicant is created in the current cgroup. This is problematic if ifup/ifdown is executed from another service

Bug#780881: mutt: tls_socket_read (A TLS packet with unexpected length was received.)

2015-03-20 Thread Axel Stammler
Package: mutt Version: 1.5.21-6.2+deb7u3 Severity: normal Dear Maintainer, - Mutt can access other IMAPS servers without problems. - This server (imaps://***@versanet...@mail-ssl.versatel.de/) can be accessed without problems using Evolution. - Mutt reports the error quoted on the Subject line

Bug#780880: inspircd: CVE-2012-1836 patch incorrect

2015-03-20 Thread Adam
Package: inspircd Version: 2.0.5-1+b1 Severity: grave Tags: security Justification: user security hole Hi, I am an upstream maintainer for InspIRCd. The patch you have for CVE-2012-1836 (patches/03_CVE-2012-1836.diff) is not the same patch we released as part of 2.0.7 (there was no 2.0.6) to add

Bug#780879: ITP: node-has-ansi -- Check if a string has ANSI escape codes in Node.js

2015-03-20 Thread Bas Couwenberg
Package: wnpp Severity: wishlist Owner: Bas Couwenberg * Package name: node-has-ansi Version : 1.0.3 Upstream Author : Sindre Sorhus (http://sindresorhus.com) * URL : https://github.com/sindresorhus/has-ansi * License : Expat Programming Lang: JavaScript

Bug#780878: mc: someone perl script is not running under mc

2015-03-20 Thread Maxim Sakharov
Package: mc Version: 3:4.8.3-10 Severity: normal Dear Maintainer, I installed Debian 8 jessie in console mode and examine under this system the book "Perl how to program". Example 3.10, if you enter data attached to it in book, under mc not running, and the naked command prompt works. Version of

Bug#780877: mc: someone perl script not running under mc

2015-03-20 Thread Maxim Sakharov
Package: mc Version: 3:4.8.3-10 Severity: normal Dear Maintainer, I installed Debian 8 jessie in console mode and examine under this system the book "Perl how to program". Example 3.10, if you enter data attached to it in book, under mc not running, and the naked command prompt works. Version of

Bug#780876: ITP: node-escape-string-regexp -- Escape RegExp special characters in Node.js

2015-03-20 Thread Bas Couwenberg
Package: wnpp Severity: wishlist Owner: Bas Couwenberg * Package name: node-escape-string-regexp Version : 1.0.3 Upstream Author : Sindre Sorhus (http://sindresorhus.com) * URL : https://github.com/sindresorhus/escape-string-regexp * License : Expat Program

Bug#769356: netfilter-persistent.service shouldn't require systemd-modules-load.service

2015-03-20 Thread Roger That
control: thanks I'm not sure how to close this bug. On 20/03/15 11:45, Michael Biebl wrote: Do you have loop in /etc/modules or /etc/modules-load.d/*? If so, the error is expected behaviour, as outlined above. If you don't want the error, either ship a modules.builtin with your kernel or don't

Bug#780756: libzip: diff for NMU version 0.11.2-1.2

2015-03-20 Thread Salvatore Bonaccorso
Control: tags 780756 + patch Control: tags 780756 + pending Hi Fathi, I've prepared an NMU for libzip (versioned as 0.11.2-1.2) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Regards, Salvatore diff -Nru libzip-0.11.2/debian/changelog libzip-0.11.2/debian/

Bug#780300: mumble-server: Mumble-server not listening after machine restart

2015-03-20 Thread Chris Knadle
On 03/11/2015 03:53 PM, Tuxicoman wrote: > Package: mumble-server > Version: 1.2.8-2 > Severity: important > > Dear Maintainer, > > After restart, the mumble-server is started but not listening. > A manual restart of the service (systemctl restart mumble-server) makes > it work. > The bug has bee

Bug#780875: mantis: MantisBT <1.2.19 multiple vulnerabilities (Access control bypass/XSS/SQL injection/etc)

2015-03-20 Thread Michael Taenzer
Package: mantis Version: 1.2.18-1 Severity: grave Tags: security upstream fixed-upstream Justification: user security hole Dear Maintainer, There is an upstream security update that fixes the following security issues: * CVE-2014-9571: XSS in install.php * CVE-2014-9572: Improper Access Control i

Bug#780764: php5-curl fix on it's way

2015-03-20 Thread Carlos C Soto
El 20/03/15 a las 09:16, Ondřej Surý escribió: I have a favor to ask though. Would you be willing to write tests for your breakages that could be included in upstream sources? I am doing full analysis of FAILED TESTS differences before each new PHP release gets pushed to Debian, but those cases w

Bug#777651: RFS: syncterm/20141022+dfsg-1 [ITP]

2015-03-20 Thread Antti Järvinen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ragnarok wrote: > I am looking for a sponsor for my package "syncterm" Great. I'm no DD so I can't sponsor your package but I can give comments nonetheless. So, I have following things I don't understand: - Is there specific need to list libncurses e

Bug#780874: python-django: CVE-2015-2316: Denial-of-service possibility with strip_tags()

2015-03-20 Thread Salvatore Bonaccorso
Source: python-django Version: 1.7.6-1 Severity: important Tags: security upstream patch fixed-upstream Hi, the following vulnerability was published for python-django. CVE-2015-2316[0]: Denial-of-service possibility with strip_tags() AFAICS this actually is only a problem if it would be used w

Bug#750837: ITP: moarvm -- virtual machine for Rakudo Perl 6 and NQP

2015-03-20 Thread Dominique Dumont
On Tuesday 17 March 2015 00:23:51 Daniel Dehennin wrote: > Now it builds cleanly in a schroot, I even install the package and “moar > --help” works \o/. I've begun to review the package. A couple of comments: * I think /usr/lib/moar/libmoar.so should land in a multiarch path (even though libtomm

Bug#780872: [Pkg-utopia-maintainers] Bug#780872: avahi-autoipd: ifupdown script installs route when package is in deinstall/config-files state

2015-03-20 Thread Michael Biebl
Am 2015-03-20 19:17, schrieb Brian Julin: Package: avahi-autoipd Version: 0.6.31-4+b2 Severity: normal Dear Maintainer, The avahi-autoipd package places a script in /etc/network/if-up.d. When the avahi-autoipd package is removed, but not purged, this script still alters the state of the

Bug#780873: python-django: CVE-2015-2317 Mitigated possible XSS attack via user-supplied redirect URLs

2015-03-20 Thread Salvatore Bonaccorso
Source: python-django Version: 1.4.5-1 Severity: important Tags: security upstream patch fixed-upstream Hi, the following vulnerability was published for python-django. CVE-2015-2317[0]: Mitigated possible XSS attack via user-supplied redirect URLs If you fix the vulnerability please also make

Bug#780867: [pkg-fgfs-crew] Bug#780867: flightgear: further restrict nasal permissions

2015-03-20 Thread Rebecca N. Palmer
* write access to /tmp/*.xml is likely unneeded, Fixed upstream: 51bfdc21e0b4528797697d32664eacb15d297449. * symlinks are followed As the remaining write-allowed directories are all under ~/.fgfs, not a bug provided Nasal can't create symlinks (which I think it can't). -- To UNSUBSCRIBE,

Bug#780872: avahi-autoipd: ifupdown script installs route when package is in deinstall/config-files state

2015-03-20 Thread Brian Julin
Package: avahi-autoipd Version: 0.6.31-4+b2 Severity: normal Dear Maintainer, The avahi-autoipd package places a script in /etc/network/if-up.d. When the avahi-autoipd package is removed, but not purged, this script still alters the state of the system, because it performs no checks to ensure t

Bug#780856: gnome-settings-daemon: >1000 tcp connections to ipp port in CLOSE-WAIT state

2015-03-20 Thread Ansgar Burchardt
Control: tag -1 + patch upstream On 03/20/2015 04:11 PM, Ansgar Burchardt wrote: > gnome-settings-daemon keeps >1000 tcp connections to a remote ipp port > in CLOSE-WAIT state. From the output from `ss -t': The bug can be triggered by printing stuff: every time I send a document to the remote pri

Bug#780827: xerces-c: diff for NMU version 3.1.1-5.1

2015-03-20 Thread Salvatore Bonaccorso
Control: tags 780827 + pending Hi Jay! I've prepared an NMU for xerces-c (versioned as 3.1.1-5.1) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. It is the same patch as used for the wheezy-security upload. Regards, Salvatore diff -Nru xerces-c-3.1.1/debia

Bug#780871: libxdo-dev: Please wrap in extern "C" guards

2015-03-20 Thread Geoffrey Thomas
Package: libxdo-dev Version: 1:3.20130111.1-3.1 Hi maintainer, isn't directly usable in C++ source files because it doesn't wrap functions in extern "C" {} when __cplusplus is defined. This means that a call to, say, xdo_init will resolve to the name-mangled version of the function, but libx

Bug#780773: Please backport EDAC_IE31200 to Linux 3.16.x

2015-03-20 Thread Vincent Blut
Le jeu. 19 mars 2015 à 7:59, Paul Menzel a écrit : […] Is that something that has to go over the Canonical Kernel Tree or does Debian also carry such backports separately? Hi Paul, The Canonical kernel team follows the stable upstream acceptance rules¹, thus backporting this new driver² wo

Bug#780870: backintime-common: Backintime doesn't start on a new installation

2015-03-20 Thread G. Kruse
Package: backintime-common Version: 1.0.36-1 Severity: important Dear Maintainer, backintime doesn't start on a fresh installation of Debian Jessie. The console output shows the following error: gkruse@Datengrab:~$ backintime Traceback (most recent call last): File "/usr/share/backintime/comm

Bug#780869: fonts-lato: Lato Bold causes crash on scribus

2015-03-20 Thread malenki
Package: fonts-lato Version: 2.0-1 Severity: important How to reproduce in scribus: create a text frame edit it Select font "Lato Black" scroll down the fonts just using the mouse wheel (not the drop down list) go past "Lato Bold" tested with scribus 1.5.0svn201503130201-30 scribus 1.4.4 The fo

Bug#780763: (nut install won't complete because of service start check)

2015-03-20 Thread Arnaud Quette
Le 19 mars 2015 14:21, "Stomptemp" a écrit : > > > Hello, I just saw bug#747863 which looks like it is the same thing, but for the nut-client package. Maybe the same issue exists in the nut-server package? > Josh Exactly Josh. Arno

Bug#780591: ltsp-client-builder fails when installing Debian Edu combined server in virtualbox environment

2015-03-20 Thread Vagrant Cascadian
Control: severity -1 serious Control: tags -1 patch On 2015-03-20, Wolfgang Schweer wrote: > Control: reassign -1 ltsp-client-builder-udeb > > On Wed, Mar 18, 2015 at 07:48:05PM +0100, Wolfgang Schweer wrote: >> On Tue, Mar 17, 2015 at 10:00:08PM +0100, Wolfgang Schweer wrote: >> > With this (triv

Bug#780868: unblock: leafnode/1.11.10-2

2015-03-20 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock leafnode. It fixes 759869 (which was filed with severity "important", but could just as well have been filed with RC severity; if the Cron job isn't executed news messages old

Bug#780866: dpkg-dev: dpkg-buildpackage -jN often fails

2015-03-20 Thread Guillem Jover
Control: severity -1 wishlist Hi! On Fri, 2015-03-20 at 17:22:46 +, Edmund Grimley Evans wrote: > Package: dpkg-dev > Version: 1.17.24 > The problem is that when I tried to build a random sample of packages > with sbuild -j4 there were quite a lot of failures. Yes, that's to be expected, no

Bug#780719: unblock: flightgear/3.0.0-5

2015-03-20 Thread Markus Wanner
Adam, On 03/20/2015 06:41 PM, Adam D. Barratt wrote: > Well, they're related to the extent that they suggest potential room to > tighten up the security fix. Agreed. I opened #780867 to keep track of this. > Indeed, I agree that the new version is certainly an improvement over > the version curr

Bug#780867: flightgear: further restrict nasal permissions

2015-03-20 Thread Markus Wanner
Package: flightgear Version: 3.0.0-5 Severity: important Tags: confirmed Hi, as discovered by Adam D. Barratt, FlightGear's script language Nasal could better sandbox the scripts executed: * write access to /tmp/*.xml is likely unneeded, see the upstream discussion, here: http://sourceforge.net

Bug#769356: netfilter-persistent.service shouldn't require systemd-modules-load.service

2015-03-20 Thread Michael Biebl
Am 2015-03-20 17:36, schrieb Roger That: control: tag -1 - moreinfo On 19/03/15 19:55, Michael Biebl wrote: On Wed, 12 Nov 2014 16:28:47 -0700 Rother That wrote: [...] Linode doesn't provide /lib/modules/kernel-linode/modules.builtin, but this shouldn't be a problem. Why should that no

Bug#778993: Many 'l' syntax options

2015-03-20 Thread G A Craig Carey
* (Subject: Many 'l' syntax options) Apparently, there is much more than "~a" .. "~z" & "~ahold" & "~o" I found a list help page here: * http://aptitude.alioth.debian.org/doc/en/ch02s04s05.html * file:///usr/share/doc/aptitude/html/en/ch02s04s05.html I am on the bug report's topic of displayi

Bug#780591: ltsp-client-builder fails when installing Debian Edu combined server in virtualbox environment

2015-03-20 Thread Wolfgang Schweer
Control: reassign -1 ltsp-client-builder-udeb On Wed, Mar 18, 2015 at 07:48:05PM +0100, Wolfgang Schweer wrote: > On Tue, Mar 17, 2015 at 10:00:08PM +0100, Wolfgang Schweer wrote: > > With this (trivial) modification installation succeeded. > > > > --- a/postinst 2015-03-06 10:00:00.

Bug#769356: netfilter-persistent.service shouldn't require systemd-modules-load.service

2015-03-20 Thread Roger That
control: tag -1 - moreinfo On 19/03/15 19:55, Michael Biebl wrote: On Wed, 12 Nov 2014 16:28:47 -0700 Rother That wrote: [...] Linode doesn't provide /lib/modules/kernel-linode/modules.builtin, but this shouldn't be a problem. Why should that not be a problem if modules.builtin is missing

Bug#780169: jessie-pu: package youtube-dl/2014.08.05-1jessie0.1

2015-03-20 Thread Rogério Brito
Dear Stefano, I kept meaning to thank you for this upload, but lacked the time. Here it goes, then: thanks for caring about uploads of youtube-dl to jessie. P.S.: Sorry if this e-mail goes formatted as HTML, but it is beyond my control right now.

Bug#780866: dpkg-dev: dpkg-buildpackage -jN often fails

2015-03-20 Thread Edmund Grimley Evans
Package: dpkg-dev Version: 1.17.24 I'm not sure that this is a bug in dpkg-buildpackage, but there's a problem which could perhaps be fixed there, or at least documented in dpkg-buildpackage's man page. The problem is that when I tried to build a random sample of packages with sbuild -j4 there we

Bug#780860: 780860 was using DEBIAN_FRONTEND noninteractive

2015-03-20 Thread Gaudenz Steinlin
Just to avoid any doubts about this report, the initial installation and the upgrade where done using DEBIAN_FRONTEND=noninteractive. This is the recommended way to avoid reconfigurations due to Debconf inputs for OpenStack packages. Without this the wrong setting would have been displayed at high

Bug#780841: Please approve `unshare -r` fix for Jessie

2015-03-20 Thread Kirill Smelkov
( this is the first time I write to release@ , so please forgive me if I do something wrong ) Hello up there, I've discovered today that, though it used to work in 2014, `unshare -r` (make a new namespace and become root there) both when initially run by root or usual users got broken because

Bug#780865: linux-headers-amd64: openafs-modules-dkms no longer builds

2015-03-20 Thread cwseys
Package: linux-headers-amd64 Version: 3.2+46 Severity: normal Hello, openafs-modules-dkms no longer builds with linux-headers-3.2.0-4-[amd64,common] version 3.2.65-1+deb7u2. Reverting to version 3.2.65-1 allows the build to complete. Online [1] I read that reverting to version 3.2.65-1+deb7u1

Bug#780719: unblock: flightgear/3.0.0-5

2015-03-20 Thread Markus Wanner
Adam, On 03/20/2015 05:19 PM, Adam D. Barratt wrote: > The latter's potentially a fairly important point. One of the reasons > that insecure tempfile handling is an issue is that if you write to or > truncate a file in /tmp and that file is a symlink to another file the > result can be that the de

Bug#780864: cryptsetup: please make the build reproducible

2015-03-20 Thread Dhole
Source: cryptsetup Version: 2:1.6.6-5 Severity: wishlist Tags: patch User: reproducible-bui...@lists.alioth.debian.org Usertags: timestamps Hi, I noticed that the package cryptsetup[1] could not be build reproducibly. The attached patch fixes the timestamp included in the man pages (taken from t

Bug#780719: unblock: flightgear/3.0.0-5

2015-03-20 Thread Rebecca N. Palmer
Symlinks are followed, but I don't think Nasal can create symlinks (and if it could, I agree we'd have a bigger problem). I'm assuming that there's no good reason for anyone ever to be running flightgear in a privileged context Agreed: that's one reason I have a 'create an unprivileged user' h

Bug#780863: debbindiff 10 crashes and exits with error 1

2015-03-20 Thread Holger Levsen
package: debbindinff version: 10 Hi Lunar, from https://reproducible.debian.net/rbuild/experimental/amd64/bibtool_2.59+ds-1.rbuild.log Fri Mar 20 16:38:44 UTC 2015 - debbindiff 10 will be used to compare the two builds now. Traceback (most recent call last): File "/usr/bin/debbindiff", line

Bug#780852: Patch to fix vcs-info with git rebase -m

2015-03-20 Thread brian m. carlson
tags 780582 + patch kthxbye This is the minimal patch required to get things working with the git in both jessie and sid. It doesn't actually make the feature work in either case, but considering it's a relatively new feature which doesn't work at the moment, I consider that acceptable. You may

Bug#780838: [Pkg-xfce-devel] Bug#780838: xfce4: Some menues in MATLAB and TSM are not working

2015-03-20 Thread Yves-Alexis Perez
On Fri, Mar 20, 2015 at 11:40:28AM +0100, Axel Dürrbaum wrote: > Package: xfce4 > Version: 4.12 > Severity: normal > X-Reportbug-Version: 6.6.3 > > Dear Maintainer, > > some problems with menues under XFCE 4.10 and 4.12: > > In Matlab since R2014a some menues are not working, e.g. in > Matlab->H

Bug#780862: linux-image-3.16.0-4-amd64: please backport 2015 ThinkPad Trackpoint/Touchpad support patches

2015-03-20 Thread Yves-Alexis Perez
Package: src:linux Version: 3.16.7-ckt7-1 Severity: normal Hi, as already reported on IRC, the trackpoint/touchpad in 2015 ThinkPads (X250 for example) is not really supported right now. A patchset was merged into Linus tree this morning (b314acaccd7e0d55314d96be4a33b5f50d0b3344), it'd be nice t

Bug#779789: mpv: free(): invalid pointer: 0xedf28020 ***

2015-03-20 Thread Jakub Wilk
* Alessandro Ghedini , 2015-03-20, 10:50: Upstream has committed a patch [0] that may or may not fix the issue (he can't reproduce either). Would it be possible for you to test it (e.g. by adding the patch to the Debian source package)? I've tried the patch on top of mpv_0.8.3-1. Unfortunately

Bug#780861: mirror listing update for debian.torzilla.net

2015-03-20 Thread alessio
Package: mirrors Severity: minor Submission-Type: update Site: debian.torzilla.net Type: leaf Archive-architecture: ALL amd64 armel armhf hurd-i386 i386 kfreebsd-amd64 kfreebsd-i386 mips mipsel powerpc s390x sparc Archive-ftp: /debian/ Archive-http: /debian/ Archive-rsync: debian/ Backports-ftp:

Bug#780860: upgrade uncomments config file setting volume_group

2015-03-20 Thread Gaudenz Steinlin
Package: cinder-common Version: 2014.1.3-11 Severity: important Upgrading from 2014.1.3-7 to 2014.1.3-11 leads to the following config file change: diff -ur openstack-pre-upgrade/cinder/cinder.conf openstack-post-upgrade/cinder/cinder.conf --- openstack-pre-upgrade/cinder/cinder.conf2015-03

Bug#780719: unblock: flightgear/3.0.0-5

2015-03-20 Thread Adam D. Barratt
On 2015-03-20 14:09, Markus Wanner wrote: Control: tags -1 - moreinfo On 03/18/2015 11:12 PM, Rebecca N. Palmer wrote: Is untrusted scripts being able to write (not read) /tmp/*.xml a security or other RC bug (which would require a new upload of flightgear _and_ flightgear-data with the obviou

Bug#780859: ruby-fog: Missing dependency against ruby-rbvmomi

2015-03-20 Thread Laurent Bigonville
Package: ruby-fog Version: 1.22.0-2 Severity: normal Hi, vmware functionality is not working because rbvmomi gem (which is not in the archive yet) is not installed. And explicity dependency (recommends?) should be added when the package hits the archive. Cheers, Laurent Bigonville -- System I

Bug#780719: unblock: flightgear/3.0.0-5

2015-03-20 Thread Rebecca N. Palmer
I'm not aware of any that do, but haven't specifically looked. I now have: as far as I can tell, no Nasal scripts are currently writing to /tmp, and given that upstream also support Windows, they would probably consider doing so to be a bug. I'll suggest removing this upstream, but currently d

Bug#780858: Massive I/O data corruption on Marvell Armada XP machines

2015-03-20 Thread Steve McIntyre
Package: src:linux Version: 3.16.7-ckt7-1 Severity: grave Tags: upstream Hi folks, We've upgraded a couple of our Marvell Armada XP based (armel/armhf) buildd machines to Jessie, and they've almost immediately fallen over with symptoms of really bad data corruption. On further investigation and d

Bug#779612: [pkg-cryptsetup-devel] Bug#779612: systemd-sysv,cryptsetup: systemd-sysv, cryptsetup should recommend plymouth; without plymouth cryptsetup prompts are unusable

2015-03-20 Thread Gordon Morehouse
On 03/19/2015 06:58 PM, Michael Biebl wrote: > As pointed out, a recommends does not really help for new installs, > since they have no effect when installing the base system. A recommends at least provides users a pointer towards fixing a really nasty problem (which they shouldn't even have, bu

Bug#773731: cache_check should be on root

2015-03-20 Thread Timo Korvola
Looks like the problem on system was not cache_check missing from the initrd, as I was not trying to cache root. The problem was cache_check missing from the actual root fs. vgchange -aay, executed after mounting root but before fsck, failed for the cached volumes. I suppose cache_check should

Bug#780857: installation-report: successful installation

2015-03-20 Thread Andrey Skvortsov
GNU/Linux installer" DISTRIB_RELEASE="8 (jessie) - installer build 20150320-00:04" X_INSTALLATION_MEDIUM=cdrom == Installer hardware-summary: == uname -a: Linux debian7 3.16.0-4-amd64 #1 SMP Debi

Bug#780373: Add the ability to set preferred auto IM by locale

2015-03-20 Thread Osamu Aoki
Hi, On Wed, Mar 18, 2015 at 05:01:15PM +0800, Aron Xu wrote: > On Tue, Mar 17, 2015 at 11:18 PM, Osamu Aoki wrote: > We are trying to make Fcitx default for Chinese locales in Ubuntu > 15.04, as a transition of making it default for everyone in the next. > im-config needs the ability of setting a

Bug#780855: lacks dependency on libnl-3-dev

2015-03-20 Thread Marco d'Itri
On Mar 20, Marco d'Itri wrote: > Package 'libnl-3.0', required by 'libteam', not found But then if I install it I get: libtool: link: gcc -std=gnu99 -Wall -Werror -Wformat -Wformat-security -fPIE -DPIE -D_FORTIFY_SOURCE=2 --param ssp-buffer-size=4 -fstack-protector -g -O2 -fPIE -fstack-protect

Bug#780764: php5-curl fix on it's way

2015-03-20 Thread Ondřej Surý
Folks, I am truly sorry for this breakage that got caused by me fuzzy applying of upstream patch as Arjan has correctly diagnosed in https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=780771#20 PHP 5.4.39 is already built with the patch in question split into two parts (regcomp and pgsql) and the

Bug#780856: gnome-settings-daemon: >1000 tcp connections to ipp port in CLOSE-WAIT state

2015-03-20 Thread Ansgar Burchardt
Package: gnome-settings-daemon Version: 3.14.2-2 Severity: normal Hi, gnome-settings-daemon keeps >1000 tcp connections to a remote ipp port in CLOSE-WAIT state. From the output from `ss -t': + | State Recv-Q Send-Q Local Address:Port Peer Address:

Bug#746580: sysv-rc: [patch] much improved update-rc.d integration w/ systemd

2015-03-20 Thread Christian Seiler
(Sorry for the noise, pressed 'send' to soon...) Am 2015-03-20 15:01, schrieb Raphael Hertzog: On Sun, 15 Mar 2015, Christian Seiler wrote: Control: severity -1 important Control: tags -1 + patch I'm tempted to raise the severity to serious as the current behaviour is really bad for packages

Bug#746580: sysv-rc: [patch] much improved update-rc.d integration w/ systemd

2015-03-20 Thread Christian Seiler
Am 2015-03-20 15:01, schrieb Raphael Hertzog: On Sun, 15 Mar 2015, Christian Seiler wrote: Control: severity -1 important Control: tags -1 + patch I'm tempted to raise the severity to serious as the current behaviour is really bad for packages that ship both native .service files and init scri

Bug#780855: lacks dependency on libnl-3-dev

2015-03-20 Thread Marco d'Itri
Package: libteam-dev Version: 1.12-1 Severity: serious $ pkg-config --exists --print-errors libteam Package libnl-3.0 was not found in the pkg-config search path. Perhaps you should add the directory containing `libnl-3.0.pc' to the PKG_CONFIG_PATH environment variable Package 'libnl-3.0', requ

Bug#780854: wesnoth-server: please provide a systemd service file

2015-03-20 Thread Markus Koschany
Source: wesnoth-1.12 Version: 1:1.12.1-1 Severity: wishlist Hi, wesnoth-server provides a SysV init script. It would be nice if Debian's wesnoth package also provided a systemd service file for better integration with the default init system. Thanks, Markus -- System Information: Debian Rele

Bug#704467: ddclient: Add ipv6 support for dyndns (patch)

2015-03-20 Thread Tim Small
Package: ddclient Version: 3.8.2-2 Followup-For: Bug #704467 Would be good to get something like this merged, too late for Jessie I know. Also if might not be such a great idea as I assign my ppp ipv6 address to a different interface (so perhaps it could fall back to using any Scope:Global addres

Bug#780853: wesnoth: typing chat messages reproducibly crashes the client when using Debian's server package

2015-03-20 Thread Markus Koschany
Package: wesnoth-1.12-core Version: 1:1.12.1-1 Severity: normal Hi, I can reproducibly crash the client when I connect to my own wesnoth-server (version 1.12 but this is also true for version 1.10), click on "Settings", close the settings window again without changing any options and then type so

Bug#780852: zsh: vcs-info produces errors for git rebase -m

2015-03-20 Thread brian m. carlson
Package: zsh-common Version: 5.0.7-5 Severity: normal When rebasing using git rebase -m from git 1:2.1.4+next.20141218-2 in experimental, vcs-info causes complaints in the shell immediately before the prompt: VCS_INFO_get_data_git:208: no such file or directory: .git/rebase-merge/done bmc@vau

  1   2   >