Bug#805821: systemd does not see existing dmraid volumes

2019-03-11 Thread Nikita Youshchenko
>>> Could you send us a "udevadm info" dump for those devices. >> >> root@nyws:~# udevadm info /dev/mapper/jmicron_Main > > [snip] > > Those udevadm info dumps look ok to me. I don't see anything that would > obviously be wrong. > > Can you still reproduce the issue? > Would be great if you can

Bug#924372: O: x4d-icons -- X4D Icon set for various online document types

2019-03-11 Thread Dimitri John Ledkov
Package: wnpp Severity: normal I intend to orphan the x4d-icons package. The package description is: Icon set indicating document types and target versions of those specifications e.g. HTML, XHTML, CSS, MathML, etc. These are metric compatible & naming scheme compatible with other logos used

Bug#924371: RM: libinotify-kqueue -- ROM; FTBFS, never built, not interested

2019-03-11 Thread Dimitri John Ledkov
Package: ftp.debian.org Severity: normal as per subject.

Bug#924279: sbuild-debian-developer-setup fails within docker

2019-03-11 Thread Tong Sun
On Mon, Mar 11, 2019 at 9:00 PM Johannes Schauer wrote: > > Quoting Tong Sun (2019-03-12 01:38:06) > > OH! I found I have to read your comment a second time before realizing what > > you were saying. > > > > OK, going pass that now I'm facing another problem: > > > > $ sudo

Bug#924370: O: libica

2019-03-11 Thread Dimitri John Ledkov
Package: wnpp Severity: normal Description: hardware cryptography support for IBM System z hardware libica library provides hardware acceleration for cryptographic functions and is part of the openCryptoki project. I shall continue to maintain this in Ubuntu, most likely. Regards, Dimitri.

Bug#924369: O: friendly-recovery -- Make recovery boot mode more user-friendly

2019-03-11 Thread Dimitri John Ledkov
Package: wnpp Severity: normal I intend to orphan the friendly-recovery package from Debian. Ubuntu Developer will probably continue to maintain this package in Ubuntu, as it is used there by default. The package description is: Make the recovery boot mode more user-friendly by providing a

Bug#924047: FTBFS: package don't build successful after new GCC version

2019-03-11 Thread أحمد المحمودي
On Sun, Mar 10, 2019 at 08:03:57AM +0100, Carsten Schoenert wrote: > That's the last option in my eyes as it's a step backwards and is > absolutely not needed as I fixed the problem already. ---end quoted text--- Yes, but this needs to be done for every gcc update ! I tried unmangling the c++

Bug#924367: O: mdadm -- tool to administer Linux MD arrays (software RAID)

2019-03-11 Thread Dimitri John Ledkov
Package: wnpp Severity: normal I intend to orphan the mdadm package. The package description is: The mdadm utility can be used to create, manage, and monitor MD (multi-disk) arrays for software RAID or multipath I/O. . This package automatically configures mdadm to assemble arrays during the

Bug#924368: O: btrfs-progs -- Checksumming Copy on Write Filesystem utilities

2019-03-11 Thread Dimitri John Ledkov
Package: wnpp Severity: normal I intend to orphan the btrfs-progs package. The package description is: Btrfs is a new copy on write filesystem for Linux aimed at implementing advanced features while focusing on fault tolerance, repair and easy administration. . This package contains

Bug#924192: ntpsec: at boot ntpsec starts before DNS is available

2019-03-11 Thread Richard Laager
On 3/11/19 9:50 PM, Rick Thomas wrote: > Would unplugging/replugging the ethernet cable work for steps 2 and 4… Sure, that'd be another option. -- Richard

Bug#924192: ntpsec: at boot ntpsec starts before DNS is available

2019-03-11 Thread Rick Thomas
Thanks Richard, I’ll see if I can set up that experiment(s) and report back ASAP. Would unplugging/replugging the ethernet cable work for steps 2 and 4… Enjoy! Rick > On Mar 11, 2019, at 2:53 PM, Richard Laager wrote: > > Can we narrow this down to a reproducer? It sounds like something like

Bug#802210: systemd: Shutdown delay waiting for stop events

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo On Sun, 18 Oct 2015 14:52:12 +0300 Aryeh Leib Taurog wrote: > Package: systemd > Version: 215-17+deb8u2 > Severity: normal > > Dear Maintainer, > > I just recently upgraded from wheezy to jessie. The /home partition > is LUKS encrypted. > > Shutdown always takes

Bug#800707: systemd: Sytem hangs on shutdown when nfs-shares are mounted via autofs

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo On Fri, 02 Oct 2015 21:01:07 +0200 =?utf-8?q?J=C3=BCrgen_Bausa?= wrote: > Package: systemd > Version: 215-17+deb8u2 > Severity: normal > > Dear Maintainer, > > I am running jessie on a laptop with wlan (Networkmanager) and want to use > autofs to mount nfs shares,

Bug#827000: systemd: Shutdown / reboot fails on discless system (booting from iscsitarget)

2019-03-11 Thread Michael Biebl
Control: reassign -1 open-iscsi On Sat, 11 Jun 2016 05:35:52 +0200 Klaus Pieper wrote: > Package: systemd > Version: 230-2 > Severity: normal > > Dear Maintainer, > > * installed on iscsi target with the beta installer which worked perfectly. > Could boot up without any further configuration.

Bug#813176: "Checking in progress on 1 disk. (0.0%)" doesn't update

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo On Sun, 3 Mar 2019 22:57:29 + (UTC) Pierre Ynard wrote: > reassign 813176 systemd > thanks > > This line is, or was, part of the systemd-fsckd source code: > >

Bug#812916: systemd-ask-password related log messages

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo On Sat, 26 Mar 2016 13:10:45 -0500 "Karl O. Pinc" wrote: > Hi, > > I got the following 2 (contiguous) log messages in /var/log/daemon > that may be useful and seem related to the problem. > They occurred when messages were broadcast to all ttys (excepting > the one

Bug#805821: systemd does not see existing dmraid volumes

2019-03-11 Thread Michael Biebl
Control: tags -1 moreinfo On Mon, 23 Nov 2015 23:17:12 +0300 Nikita Youshchenko wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > > Could you send us a "udevadm info" dump for those devices. > > root@nyws:~# udevadm info /dev/mapper/jmicron_Main [snip] Those udevadm info dumps

Bug#794547: Fwd: cryptsetup: "Operation was cancelled" after LUKS volume hotplug, but mounts successfully

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo Hi Matvey, sorry for not getting back to you earlier. Can you still reproduce the issue on an up-to-date buster system with systemd v241? On Tue, 4 Aug 2015 05:50:55 -0400 Matvey Soloviev wrote: > Package: systemd > Version: 222-2 > Severity: normal > > Dear

Bug#924366: natural sort output on cpuspeed plugin

2019-03-11 Thread Craig Sanders
Package: munin-plugins-core Version: 2.0.47-1 Control: severity -1 wishlist The output of several plugins (including cpusped) is not sorted at all, and a simple numeric iteration (e.g. of cpu cores or network interfaces) results in incorrect sorting (1, 10, 11, 12, ..., 2, 20, 21, etc). I fixed

Bug#915706: 9.6.0 DVD and XFCE CD for mipsel are actually netinst

2019-03-11 Thread YunQiang Su
e. Assign to me... Steve McIntyre 于2019年3月10日周日 上午7:36写道: > > Control: reassign -1 cdimage.debian.org > Control: severity -1 important > > On Thu, Dec 06, 2018 at 05:54:51PM +0800, seam...@debian.org wrote: > >Package: debian-installer > >Severity: serious > > > >I tried

Bug#924357: dillo: ddg search string in dillorc results in non-useful links

2019-03-11 Thread Axel Beckert
Hi, liftof+d...@gmail.com wrote: > When Dillo's search function is used with duckduckgo.com, the > resulting links lead to a blank page. > > By slightly modifying dillorc, the problem is eliminated: > > search_url="dd DuckDuckGo (https) https://duckduckgo.com/lite/?kp=-1=%s; > > needs to be: >

Bug#924161: unblock: lirc/0.10.1-5.1

2019-03-11 Thread Nicolas Braud-Santoni
Hi abe, On Mon, Mar 11, 2019 at 12:31:42AM +0100, Andreas Beckmann wrote: > This needs a lot of more work :-( > > * is this usage of --link-doc valid? the packages don't have a strictly > versioned Depends: lirc (= ${binary:version}), so I can install *only* > liblirc0 and have a dangling

Bug#923273: [pkg-apparmor] Bug#923273: Bug#923273: apparmor: nvidia_modprobe named profile is shipped in complain mode

2019-03-11 Thread Seth Arnold
On Fri, Mar 08, 2019 at 06:57:14PM +0200, Vincas Dargis wrote: > Since LibreOffice is in complain mode by default, so I doubt this issue I strongly dislike the idea of shipping any profiles in complain mode. I would rather the profiles in question be disabled entirely. Complain mode profiles can

Bug#924279: sbuild-debian-developer-setup fails within docker

2019-03-11 Thread Johannes Schauer
Quoting Tong Sun (2019-03-12 01:38:06) > OH! I found I have to read your comment a second time before realizing what > you were saying. > > OK, going pass that now I'm facing another problem: > > $ sudo /usr/bin/sbuild-debian-developer-setup > . . . > I: SUITE: unstable > I: TARGET:

Bug#924365: www.debian.org: FTBFS in buster: turkish vs. tr_TR locale

2019-03-11 Thread Cyril Brulebois
Package: www.debian.org Severity: normal User: www.debian@packages.debian.org Usertags: scripts Hi, While working on rebuilding the website within stretch and buster, I've noticed the following. The turkish subdirectory doesn't build in buster, apparently due to possible locale issues:

Bug#924364: unblock: owasp-java-html-sanitizer/0.1+r88-2

2019-03-11 Thread Markus Koschany
Please find attached the debdiff. diff -Nru owasp-java-html-sanitizer-0.1+r88/debian/changelog owasp-java-html-sanitizer-0.1+r88/debian/changelog --- owasp-java-html-sanitizer-0.1+r88/debian/changelog 2012-03-22 04:54:45.0 +0100 +++ owasp-java-html-sanitizer-0.1+r88/debian/changelog

Bug#924364: unblock: owasp-java-html-sanitizer/0.1+r88-2

2019-03-11 Thread Markus Koschany
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package owasp-java-html-sanitizer The libjsr305-java-doc package was removed from Debian but it is not really required to build owasp-java-html-sanitizer. unblock

Bug#924279: sbuild-debian-developer-setup fails within docker

2019-03-11 Thread Tong Sun
On Sun, Mar 10, 2019 at 11:13 PM Johannes Schauer wrote: > > Quoting Tong Sun (2019-03-10 23:57:17) > > When I run sbuild-debian-developer-setup within docker, this is what I'll > > get: > > > > root/# sbuild-debian-developer-setup > > Please run sudo /usr/bin/sbuild-debian-developer-setup at > >

Bug#923573: more example

2019-03-11 Thread sergio
openwrt% make menuconfig Checking ... ok. ... Checking ... ok. Build dependency: Please build with umask 022 - other values produce broken packages -- sergio.

Bug#894174: gcalcli: --nodeclined error

2019-03-11 Thread Unit 193
Howdy, Can you take a look and see if you can still reproduce this issue with 4.0.4-1? This looks to me as if it should be fixed, and I did not get any traceback when I tried using the aforementioned option. ~Unit 193 Unit193 @ freenode Unit193 @ OFTC

Bug#924363: wget: segfault when using --convert-links [stretch only]

2019-03-11 Thread Christoph Biedl
Package: wget Version: 1.18-5+deb9u2 Severity: important Tags: security Tags: patch Fixed: 1.20.1-1 Dear maintainer, the 09-stretch version of wget --convert-links fails if when encountering an embedded image and trying to parse this as a link. How to repeat Save the following file as

Bug#924362: package fails to configure (postinst)

2019-03-11 Thread Adam Di Carlo
Package: chkrootkit Version: 0.52-3 Severity: important On a system running buster, I just had a failure upgrading the package. I put 'set -x' in chkrootkit.postinst so that we can see where its failing. Here's the output: Setting up chkrootkit (0.52-3) ... + . /usr/share/debconf/confmodule +

Bug#921159: Can't enter second option

2019-03-11 Thread Gabriel F. T. Gomes
On Sun, Mar 10 2019, Gabriel F. T. Gomes wrote: > > https://github.com/scop/bash-completion/pull/291 Fixed upstream [1]. When a new upstream version gets released, I'll close this bug report. [1] https://github.com/scop/bash-completion/commit/dd80f35279afd4f056dc191767b9869c9649d476

Bug#924361: smcroute: racy systemd unit start (and autopkgtest failure)

2019-03-11 Thread Steve Langasek
Source: smcroute Version: 2.4.2-4 Severity: important User: ubuntu-de...@lists.ubuntu.com Usertags: origin-ubuntu disco Hi Joachim, Thanks for the fixes to the smcroute autopkgtests in 2.4.2-4. I've synced this new version into Ubuntu, and the autopkgtests have now passed on all architectures

Bug#924309: RM: passenger/5.0.30-1

2019-03-11 Thread Nicolas Braud-Santoni
On Mon, Mar 11, 2019 at 07:53:44PM +0100, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Nicolas Hi Paul, > On 11-03-2019 13:29, Nicolas Braud-Santoni wrote: > > Passenger has had an open, grave security bug open since December 2017 > > (#884463) > > and hasn't been uploaded to since

Bug#924053: Find /.disk/info patch

2019-03-11 Thread adrian15
I attach a patch that makes Secure Boot minimal image minimal grub.cfg to seach for /disk/.info instead of /live/vmlinuz. This fixes unbootable Secure Boot (even if you boot with Secure Boot turned off) when live-build is setup to build with more than one linux kernel flavour. This has been

Bug#924360: xen-hypervisor-4.11-amd64: HVM Boot failure: "ERR: Bootloader shutdown EFI x64 boot services!"

2019-03-11 Thread Henning
Package: xen-hypervisor-4.11-amd64 Version: 4.11.1+26-g87f51bf366-3 Severity: important Dear Maintainer, * What led up to the situation? unfortunately xen hypervisor does not boot on my machine (Asus Prime B360M-C Mainboard, in Setup only EFI enabled, Intel VMX Virtalization Technology is

Bug#924359: augustus: hardcoded built-using

2019-03-11 Thread Ivo De Decker
package: augustus version: 3.3.2+dfsg-1 severity: serious Hi, Augustus has hardcoded built-using: https://sources.debian.org/src/augustus/3.3.2+dfsg-1/debian/control/?hl=31#L31 "Built-Using: samtools-legacy (= 0.1.19-2)" The built-using information should be determined based on the version

Bug#924358: Dependency problems with logind | consolekit

2019-03-11 Thread Christopher Obbard
Package: lightdm Version: 1.26.0-4 Depends: logind [linux-any] | consolekit these packages are not in the buster/sid archives.

Bug#923465: Update alternatives fixes problem

2019-03-11 Thread Robert LeBlanc
I followed what John did, except I did not uninstall freecad-python2 and did not install freecad-python3. Running update-alternatives was enough to resolved the issue. If the new package was supposed to do that, I don't think it worked, at least upgrading from -4. rleblanc@riker:~/code$ dpkg -l

Bug#923465: fixed in freecad 0.18~pre1+dfsg1-5

2019-03-11 Thread Robert LeBlanc
On Sat, 02 Mar 2019 10:20:00 + Kurt Kremitzki wrote: > Source: freecad > Source-Version: 0.18~pre1+dfsg1-5 > > We believe that the bug you reported is fixed in the latest version of > freecad, which is due to be installed in the Debian FTP archive. > > A summary of the changes between this

Bug#924357: dillo: ddg search string in dillorc results in non-useful links

2019-03-11 Thread liftof+dbug
Package: dillo Version: 3.0.4-2+b1 Severity: normal Dear Maintainer, When Dillo's search function is used with duckduckgo.com, the resulting links lead to a blank page. By slightly modifying dillorc, the problem is eliminated: search_url="dd DuckDuckGo (https)

Bug#924356: google-authenticator: FTBFS

2019-03-11 Thread peterc
Source: google-authenticator Version: 20170702-2 Severity: serious Tags: ftbfs Justification: fails to build from source (but built successfully in the past) Dear Maintainer, I do: apt-get source google-authenticator cd google-authenticator-20170702 fakeroot make -f debian/rules binary

Bug#924060: Serious regression in systemd 215-17+deb8u10

2019-03-11 Thread Michael Biebl
Am 11.03.19 um 19:17 schrieb Markus Koschany: > > Am 11.03.19 um 15:51 schrieb Dan Poltawski: >> Thanks for your responses. One of my colleagues has been looking into this >> trying to get the bottom of it and we do seem to have identified a memory >> leak which isn't present on stretch. I note

Bug#924355: RM: cuyo/2.0.0brl1-3

2019-03-11 Thread Bernhard R. Link
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm Please consider removing cuyo from buster. The version in testing currently is an old forked version that is in no good shape. While there is an ITA for it (#916692), that didn't got to a new

Bug#924354: unblock: php7.3/7.3.3-1

2019-03-11 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package php7.3 It fixes the recent security issues by following 7.3.x (we'll also follow 7.3.x releases in buster-security as we did with 7.0.x in stretch-security).

Bug#924352: CVE-2018-16384

2019-03-11 Thread Moritz Muehlenhoff
Package: modsecurity-crs Severity: normal Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16384 (It seems questionable to assign a CVE ID to modsecurity-crs for this from my POV) Cheers, Moritz

Bug#924353: CVE-2018-20593

2019-03-11 Thread Moritz Muehlenhoff
Source: mxml Severity: important Tags: security Please see: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20592 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20593 https://github.com/michaelrsweet/mxml/issues/237 Cheers, Moritz

Bug#924192: ntpsec: at boot ntpsec starts before DNS is available

2019-03-11 Thread Richard Laager
Can we narrow this down to a reproducer? It sounds like something like this would work: 0) Configure two different pools where you can tell the servers apart. 1) Stop ntpd. 2) Break your DNS. 3) Start ntpd. Wait a few seconds for it to try to resolve and fail. 4) Fix your DNS. Expected

Bug#924351: CVE-2018-16647 CVE-2018-16648

2019-03-11 Thread Moritz Muehlenhoff
Package: mupdf Version: 1.14.0+ds1-3 Severity: grave Tags: security CVE-2018-16648: https://bugs.ghostscript.com/show_bug.cgi?id=699685 http://www.ghostscript.com/cgi-bin/findgit.cgi?38f883fe129a5e89306252a4676eaaf4bc968824 CVE-2018-16647: https://bugs.ghostscript.com/show_bug.cgi?id=699686

Bug#924312: stunnel4: Fails to stop with sysvinit: start-stop-daemon: matching only on non-root pidfile /var/lib/stunnel4///stunnel4.pid is insecure

2019-03-11 Thread Axel Beckert
Hi Peter, Peter Pentchev wrote: > > […], this looks like a bug in lsb-base. And indeed, it is and > > is also already reported: https://bugs.debian.org/921558 > > > > Reassigning accordingly. > > Thanks for reporting this and for your analysis! You're welcome. > I came up with the same result

Bug#924350: libofx: CVE-2019-9656

2019-03-11 Thread Salvatore Bonaccorso
Source: libofx Version: 1:0.9.14-1 Severity: important Tags: security upstream Forwarded: https://github.com/libofx/libofx/issues/22 Hi, The following vulnerability was published for libofx. CVE-2019-9656[0]: | An issue was discovered in LibOFX 0.9.14. There is a NULL pointer | dereference in

Bug#924349: linux-image-4.19.0-2-amd64: IPv6 reverse path filtering incorrectly removes IPv6 traffic from bridge

2019-03-11 Thread Ralf Jung
Package: src:linux Version: 4.19.16-1 Severity: normal Dear Maintainer, since a recent update, IPv6 communication between two of my VMs stopped working. You can see some of the debugging effort at . It turned out that setting IPv6_rpfilter=no

Bug#924348: CVE-2019-7629

2019-03-11 Thread Moritz Muehlenhoff
Package: tintin++ Severity: grave Tags: security Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7629 Cheers, Moritz

Bug#924347: ITP: golang-github-hashicorp-go-safetemp -- Functions for working safely with temporary files and directories.

2019-03-11 Thread Aman Verma
Package: wnpp Severity: wishlist Owner: Aman Verma * Package name: golang-github-hashicorp-go-safetemp Version : 1.0.0-1 Upstream Author : HashiCorp * URL : https://github.com/hashicorp/go-safetemp * License : MPL-2.0 Programming Lang: Go Description :

Bug#918754: Update

2019-03-11 Thread Andrew Latham
Escalation from 'su' lacked the path. I was able to 'su -' and access the correct paths from the user ENVIRONMENT. -- - Andrew "lathama" Latham -

Bug#923782: Relax dependency on faraday to allow updating ruby-faraday

2019-03-11 Thread Vincent Bernat
Package: ruby-puppet-forge Followup-For: Bug #923782 -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hey! With the provided patch, I am able to use librarian-puppet without any issue. Unless someone protests, I'll do a NMU next week to fix this bug. - -- System Information: Debian Release:

Bug#922938: RFS: python-css-parser/1.0.4-1~bpo9+1

2019-03-11 Thread Nicholas D Steeves
Hi Chris, If you have a minute would you please sponsor this backport and/or grant me DM permissions for it? I maintain it on the DPMT and my key is E2A6261E3900AED7CDC667085A8830475F7D1061 A stretch-backport of python-css-parser is needed to update the bpo of calibre, and a recent version of

Bug#862373: The State of the YAML

2019-03-11 Thread gregor herrmann
On Mon, 11 Mar 2019 22:14:13 +0100, Ivo De Decker wrote: > Control: tags -1 buster-ignore Thanks. > > So I guess we have to consider if we're happy with the ability to > > turn off loading objects and recommend it to consumers and close the > > bugs; or if we want to change the defaults, which

Bug#918754: bash: $PATH in bash does not include /sbin and /usr/sbin

2019-03-11 Thread Andrew Latham
I just hit this on a fresh install. I was concerned something changed but found the usermod tool in /usr/sbin/ when needing to append a group. -- - Andrew "lathama" Latham -

Bug#862475: The State of the YAML

2019-03-11 Thread Ivo De Decker
Control: tags -1 buster-ignore Hi, On Fri, May 18, 2018 at 11:09:23AM +0200, gregor herrmann wrote: > Quick status update on the perl YAML modules and the problem of > instantiating objects: > > * libyaml-syck-perl has $YAML::LoadBlessed since a long time > * libyaml-libyaml-perl since 0.69 and

Bug#924192: ntpsec: at boot ntpsec starts before DNS is available

2019-03-11 Thread Rick Thomas
Hi Richard, My observations follow your quote… > On Mar 11, 2019, at 12:30 PM, Richard Laager wrote: > > On 3/10/19 4:11 AM, Rick Thomas wrote: >> If ntpsec implemented the "preempt" option on "peer" directives, the >> first "peer" would be revisited after a few minutes and all would be >>

Bug#818366: synaptic: fails to start under Wayland

2019-03-11 Thread Paul Gevers
Hi Trevis, all, On Sun, 10 Mar 2019 20:46:02 +0530 Trevis Schiffer wrote: > Check this commit. > > > Looks like it is fixed on version 0.84.3 The reported failure in one of the recent merged bug reports was for

Bug#924346: xmltooling: CVE-2019-9628: XML parser class fails to trap exceptions on malformed XML declaration

2019-03-11 Thread Salvatore Bonaccorso
Source: xmltooling Version: 3.0.3-1 Severity: grave Tags: security upstream Justification: user security hole Forwarded: https://issues.shibboleth.net/jira/browse/CPPXT-143 Control: found -1 1.6.0-4+deb9u1 Control: found -1 1.6.0-4 Hi, The following vulnerability was published for xmltooling,

Bug#921558: lsb-base: killproc does not pass name parameter to start-stop-daemon

2019-03-11 Thread Axel Beckert
Control: tag -1 + patch Hi Dmitry, Dmitry Bogatov wrote: > > base=${1##*/} > > if [ ! $pidfile ]; then > > name_param="--name $base --pidfile /var/run/$base.pid" > > else > > name_param="--pidfile $pidfile" > > fi > > > > The if clause checks for nonempty $pidfile

Bug#924312: stunnel4: Fails to stop with sysvinit: start-stop-daemon: matching only on non-root pidfile /var/lib/stunnel4///stunnel4.pid is insecure

2019-03-11 Thread Peter Pentchev
On Mon, Mar 11, 2019 at 09:28:04PM +0100, Axel Beckert wrote: > Control: reassign -1 lsb-base > Control: forcemerge 921558 -1 > Control: affects 921558 + stunnel4 > > Hi Paul, > > Paul Gevers wrote: > > On Mon, 11 Mar 2019 14:15:25 +0100 Axel Beckert wrote: > > > Version: 3:5.50-3 > > > >

Bug#924345: xastir-data should be Arch: all

2019-03-11 Thread Christoph Berg
Package: xastir-data Version: 2.1.0-3 Severity: normal The multiarch hinter suggests that xastir-data should actually be "Architecture: all" rather than "any". Looking at the control file, most of xastir-data's package stanza looks like it was copied from xastir, but never updated. Same

Bug#924344: glib2.0: CVE-2019-9633

2019-03-11 Thread Salvatore Bonaccorso
Source: glib2.0 Version: 2.58.3-1 Severity: important Tags: security upstream Forwarded: https://gitlab.gnome.org/GNOME/glib/issues/1649 Control: fixed -1 2.59.2-1 Hi, The following vulnerability was published for glib2.0, filling a bug for tracking. CVE-2019-9633[0]: | gio/gsocketclient.c in

Bug#924312: stunnel4: Fails to stop with sysvinit: start-stop-daemon: matching only on non-root pidfile /var/lib/stunnel4///stunnel4.pid is insecure

2019-03-11 Thread Axel Beckert
Control: reassign -1 lsb-base Control: forcemerge 921558 -1 Control: affects 921558 + stunnel4 Hi Paul, Paul Gevers wrote: > On Mon, 11 Mar 2019 14:15:25 +0100 Axel Beckert wrote: > > Version: 3:5.50-3 > > ^^^ > I don't think the bug is only in this version, is it? No. But for

Bug#786887:

2019-03-11 Thread Andreas Hasenack
New bug opened about this: #924343

Bug#924343: snmpd: default config startup warnings

2019-03-11 Thread Andreas Hasenack
Package: snmpd Version: 5.7.3+dfsg-5 Severity: Normal Dear Maintainer, this is a follow-up to bug https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=786887 which was closed because it was filed against a very old version of this package. I just tried again with an up-to-date debian sid system,

Bug#924341: pygnuplot: FTBFS due to unsatisfiable build-dependency debhelper (= 12)

2019-03-11 Thread Hans Joachim Desserud
Source: pygnuplot Version: 0.11.16-1 Severity: serious Tags: ftbfs Dear Maintainer, pygnuplot fails to build because it cannot install its build dependencies: $ sudo apt build-dep pygnuplot Reading package lists... Done Building dependency tree Reading state information... Done Some packages

Bug#924342: ITP: wf-recorder -- screen recorder for wlroots-based compositors

2019-03-11 Thread Birger Schacht
Package: wnpp Severity: wishlist Owner: Birger Schacht * Package name: wf-recorder Version : no release yet Upstream Author : Ilia Bozhinov * URL : https://github.com/ammen99/wf-recorder * License : MIT Programming Lang: C Description : screen recorder

Bug#923924: Please review and apply attached patch to support shutdown on SIGPWR

2019-03-11 Thread Andras Korn
On Mon, Mar 11, 2019 at 06:12:06PM +, Dmitry Bogatov wrote: > > On Fri, Mar 08, 2019 at 02:39:47PM +, Dmitry Bogatov wrote: > > > [2019-03-07 12:57] Andras Korn > > > > part 1 text/plain 218 > > > > Sorry, I sent an earlier version of the patch by mistake. > > > > > >

Bug#850425: mpt3sas "swiotlb buffer is full" problem only under Xen

2019-03-11 Thread Hans van Kranenburg
On 3/11/19 7:34 AM, Juergen Gross wrote: > > I'm not sure. Patch 3 of this series is basically already there (see > commit c6d4381220a0087ce19dbf6984d92c451bd6b364). So maybe all we need > is patch 4, which should really be easy to do? > > Hans, could you give it a try? You'd need to use a 4.20

Bug#924192: ntpsec: at boot ntpsec starts before DNS is available

2019-03-11 Thread Richard Laager
On 3/10/19 4:11 AM, Rick Thomas wrote: > If ntpsec implemented the "preempt" option on "peer" directives, the > first "peer" would be revisited after a few minutes and all would be > well. But it doesn't. So the first "peer" is as if it never existed. What leads you to this conclusion,

Bug#907277: autoconf: AC_SEARCH_LIBS for __atomic_foo fails with AC_LANG([C++]) and g++-8

2019-03-11 Thread Paul Gevers
Hi all, On 10-03-2019 13:41, Simon McVittie wrote: > On Thu, 17 Jan 2019 at 11:00:40 -0500, Nick Bowler wrote: >> I'm not familiar with the library in question but the problem >> appears to be specific to these __atomic_xyz builtins which seem >> to get special treatment in g++. Other builtins I

Bug#924340: unblock: python2.7/2.7.16-1 python-stdlib-extensions/2.7.16-1 python-defaults/2.7.16-1

2019-03-11 Thread Matthias Klose
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please consider unblocking the python2 packages to the final 2.7.16 release, basically bumping the version and reporting a final release number in sys.version.

Bug#921952: [Pkg-sass-devel] Bug#921952: Don't include in buster without proper commitment to update in stable

2019-03-11 Thread Moritz Mühlenhoff
On Mon, Mar 11, 2019 at 12:29:10PM +0100, Jonas Smedegaard wrote: > control: reopen -1 > > Quoting Jonas Smedegaard (2019-03-11 12:22:03) > > Quoting Moritz Muehlenhoff (2019-02-10 14:47:49) > > > Source: libsass > > > Severity: serious > > > > > > None of the security bugs filed in the BTS has

Bug#924339: javahelper regressed building -doc packages

2019-03-11 Thread Matthias Klose
Package: javahelper Version: 0.72-5 Severity: serious Tags: sid buster javahelper regressed building -doc packages, as seen with the android-platform-build package. See #924328.

Bug#924312: stunnel4: Fails to stop with sysvinit: start-stop-daemon: matching only on non-root pidfile /var/lib/stunnel4///stunnel4.pid is insecure

2019-03-11 Thread Paul Gevers
Hi Axel, On Mon, 11 Mar 2019 14:15:25 +0100 Axel Beckert wrote: > Version: 3:5.50-3 ^^^ I don't think the bug is only in this version, is it? > This is caused by the following change in dpkg 1.19.3 from 22 Jan 2019: > > * start-stop-daemon: Check whether standalone --pidfile

Bug#924338: unblock: binutils-/gcc -mipsen packages

2019-03-11 Thread Matthias Klose
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please consider unblocking binutils-mipsen, gcc-8-cross-mipsen, gcc-defaults-mipsen (the gcc-* packages are not yet in testing). the mips64 packages were removed from the -ports packages,

Bug#924301: e2fsprogs: e2scrub failure on /

2019-03-11 Thread Theodore Ts'o
On Mon, Mar 11, 2019 at 09:59:05AM +0100, Vincent Lefevre wrote: > Package: e2fsprogs > Version: 1.45.0-1 > Severity: normal > > I got the following mail: > > > Date: Sun, 10 Mar 2019 03:10:04 +0100 (CET) > From:

Bug#924336: dillo: ssl negotiation fails on some sites

2019-03-11 Thread Axel Beckert
Control: tag -1 + confirmed fixed-upstream Control: found -1 3.0.5-3 Control: found -1 3.0.5-5 Control: forwarded -1 http://lists.dillo.org/pipermail/dillo-dev/2018-December/011100.html Hi, liftof+d...@gmail.com wrote: > When I use Dillo to access certain web sites, no content appears > in the

Bug#924337: Please reenable mqtt and varnish

2019-03-11 Thread Bastian Germann
Source: collectd Version: 5.8.1-1.2 Severity: important The mqtt and varnish plugins are disabled because of dependency issues. The blocking bugs #911265, #911266, and #879471 are resolved. Please reenable the plugins.

Bug#924309: RM: passenger/5.0.30-1

2019-03-11 Thread Paul Gevers
Control: tags -1 moreinfo Hi Nicolas On 11-03-2019 13:29, Nicolas Braud-Santoni wrote: > Passenger has had an open, grave security bug open since December 2017 > (#884463) > and hasn't been uploaded to since August 2016. > > As far as I can tell, no other package will be adversely impacted by

Bug#923891: Workarounds?

2019-03-11 Thread Soren Stoutner
Is there a short-term workaround that will fix the broken login system?  For example, can Redmine 4.0.1-1 be safely downgraded to 3.4.6-1 or will that cause database problems? -- Soren Stoutner Small Business Tech Solutions so...@smallbusinesstech.net 623-262-6169

Bug#923446: m2crypto: autopkgtest with new version of openssl: Connection refused

2019-03-11 Thread Daniel Stender
Control: severity -1 serious For this actually is a FTBFS bug I'm raising its severity. Thanks, DS -- 4096R/DF5182C8 https://danielstender.com

Bug#686895: initscripts: /forcefsck: fsck -f undefined (e2fsck-ism)

2019-03-11 Thread Thorsten Glaser
On Mon, 11 Mar 2019, Dmitry Bogatov wrote: > So, you propose that we: > * drop all checks for /forcecheck No! > * document this fact in NEWS file > * write documentation, that e[2-4]fs users should use tune2fs tool >instead Yes. //mirabilos -- tarent solutions GmbH Rochusstraße 2-4,

Bug#924336: dillo: ssl negotiation fails on some sites

2019-03-11 Thread liftof+dbug
Package: dillo Version: 3.0.4-2+b1 Severity: important Dear Maintainer, When I use Dillo to access certain web sites, no content appears in the browser window. When run from an xterm, this message can be seen: Nav_open_url: new url='https://www.raspberrypi.org/'

Bug#924060: Serious regression in systemd 215-17+deb8u10

2019-03-11 Thread Markus Koschany
Am 11.03.19 um 15:51 schrieb Dan Poltawski: > Thanks for your responses. One of my colleagues has been looking into this > trying to get the bottom of it and we do seem to have identified a memory > leak which isn't present on stretch. I note the report posted to the list >

Bug#924132: runit: Add support for runit in init-system-helpers

2019-03-11 Thread Dmitry Bogatov
[2019-03-09 21:05] Lorenzo Puliti > this is for buster +1 > > Here is my proposal for adding runit-init support in > 'init-system-helpers'; please do not reassign to init-system-helpers > as this need also some changes in runit and dh-runit to work properly. > This is still a work in progress

Bug#923924: Please review and apply attached patch to support shutdown on SIGPWR

2019-03-11 Thread Dmitry Bogatov
[2019-03-10 12:09] Andras Korn > On Fri, Mar 08, 2019 at 02:39:47PM +, Dmitry Bogatov wrote: > > [2019-03-07 12:57] Andras Korn > > > part 1 text/plain 218 > > > Sorry, I sent an earlier version of the patch by mistake. > > > > > > I'm attaching the correct one, which I

Bug#686895: initscripts: /forcefsck: fsck -f undefined (e2fsck-ism)

2019-03-11 Thread Dmitry Bogatov
[2019-03-09 21:57] Thorsten Glaser > > But I really want to have some transition plan to get rid of > > /forcecheck, something like: > > … you might like that tune2fs can now (1.45.0-1, not yet in > buster, officially not likely to make it but we can hope) set > a flag force_fsck that next

Bug#924334: ITS: fpart

2019-03-11 Thread Ganael Laplanche
Package: fpart Version: 0.9.2-1+b1 Severity: important Hello, Following : https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881806 and https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=911246 I would like to take ownership and update the fpart package. FYI, I will be using updated

Bug#759339: systemd-cryptsetup-generator: systemd-cryptsetup-generator fails to handle multiple encrypted btrfs volumes in raid1

2019-03-11 Thread Michael Biebl
Control: tags -1 + moreinfo Hi Damien On Tue, 26 Aug 2014 16:58:28 +0200 Damien Clauzel wrote: > Yes. But there is also the problem of assembling the btrfs raid1 arrays > after opening the encrypted volumes. > > Damien Clauzel > > > 2014-08-26 16:41 GMT+02:00 Michael Biebl : > > > Am

Bug#924325: gcc-8-cross: FTBFS for unknown reasons

2019-03-11 Thread Santiago Vila
On Mon, Mar 11, 2019 at 06:34:18PM +0100, Matthias Klose wrote: > I have no clue, I have never seen that before, and it seems to work fine on > the > buildds, and in the cross-toolchain-base* package's autopkg test. Starting > here > a build with -j1 to see if it's reproducible. > > Is this

Bug#924333: FTBFS: missing czech/News/weekly/index.wml

2019-03-11 Thread Cyril Brulebois
Package: www.debian.org Severity: normal User: www.debian@packages.debian.org Usertags: scripts Hi, While working on rebuilding the website within stretch and buster, I've noticed the following. The build fails both in stretch and in buster due to a missing file

Bug#765594: systemd: Attempting to hibernate permanently breaks encrypted swap partition

2019-03-11 Thread Michael Biebl
Hi Rebecca On Thu, 16 Oct 2014 22:22:29 +0100 "Rebecca N. Palmer" wrote: > Control: tags -1 patch > > Looks like the "swap=plain" assumption is at > src/cryptsetup/cryptsetup.c:162; here's a patch (untested as yet, will > try it in the morning if I don't hear anything). > > --- cryptsetup.c

Bug#923976: [Pkg-puppet-devel] Bug#923976: Bug#923976: puppet: Reports submitte

2019-03-11 Thread Kienan Stewart
Hi Apollon, On Sat, Mar 09, 2019 at 11:24:27PM +0200, Apollon Oikonomopoulos wrote: > Control: tags -1 - unreproducible > > Hi, > > > Thanks for the patch, it should do the trick. However, before applying > it I want to be 100% sure that we know what's happening and why. > > So, I managed to

  1   2   3   >