Bug#929557: additional point of view

2019-06-03 Thread Geert Stappers
An additional point of view. Prespective is Linux Kernel developer. OOT means Out of Tree. And the tree is the Linux source code directory tree. - Forwarded message from "Enrico Weigelt, metux IT consult" - Date: Wed, 29 May 2019 13:01:09 +0200 From: "Enrico Weigelt, metux IT

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Rene Engelhard
Hi, On Tue, Jun 04, 2019 at 01:22:02PM +1000, Trent W. Buck wrote: > This part isn't important, but I'll address it for the record. > > 1. My original problem is "Australian English users cannot click Tools > > Thesaurus". > > 2. One fix is "apt-get install mythes-en-au" (note "AU" not

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Rene Engelhard
tag 929923 - wontfix retitle 929923 mythes-en-us: add symlinks for en_AU etc. thanks Hi, On Tue, Jun 04, 2019 at 12:51:44PM +1000, Trent W. Buck wrote: > Do you agree so far? Yes > The solution > > I think on non-Debian, LibreOffice knows that en_* should use > th_en_US_v2 because

Bug#927775: monit: CVE-2019-11454 CVE-2019-11455

2019-06-03 Thread Sergey B Kirpichev
On Tue, 23 Apr 2019 06:53:03 +0200 Salvatore Bonaccorso wrote: > CVE-2019-11454[0]: > | Persistent cross-site scripting (XSS) in http/cervlet.c in Tildeslash > | Monit before 5.25.3 allows a remote unauthenticated attacker to > | introduce arbitrary JavaScript via manipulation of an unsanitized

Bug#926540: unblock: xorg-server/2:1.20.4-1

2019-06-03 Thread Cyril Brulebois
Hi, Andreas Boll (2019-05-11): > On Sat, Apr 06, 2019 at 10:25:31PM +0200, Cyril Brulebois wrote: > > Hi, > > > > Andreas Boll (2019-04-06): > > > CCing kibi for unblock-udeb review > > > > This is coming a little late for RC1 that should be published very soon. > > I've added this to my

Bug#926630: unblock: libpng1.6/1.6.36-6

2019-06-03 Thread Cyril Brulebois
Hi, Paul Gevers (2019-05-11): > > debdiff attached > > > > thanks for caring, > > > > unblock libpng1.6/1.6.36-6 > > I am fine with this, but it needs a review by d-i (CC-ed kibi). Apologies for the delay. Based on runtime tests: no objections. Cheers, -- Cyril Brulebois

Bug#929951: php-ast: New upstream version 1.0.1 available

2019-06-03 Thread Jason Hernandez
Package: php-ast Severity: important Dear Maintainer, There is a new version of php-ast available upstream at https://github.com/nikic/php-ast/releases This is a dependency for the static analysis tool phan - https://github.com/phan/phan Thank you. -- System Information: Debian Release: 10.0

Bug#929171: unblock: espeakup/1:0.80-15

2019-06-03 Thread Cyril Brulebois
Niels Thykier (2019-05-18): > Samuel Thibault: > > Package: release.debian.org > > Severity: normal > > User: release.debian@packages.debian.org > > Usertags: unblock > > > > Hello, > > > > As reported on Bug#929169, “the Linux kernel in Buster seems to take > > much longer (as much as

Bug#929132: unblock (pre-approval): dbus/1.12.14-1

2019-06-03 Thread Cyril Brulebois
Niels Thykier (2019-05-19): > Ok. I have added an unblock and age-days 8 hint. Also CC'ing KiBi for > a d-i ack before adding an unblock-udeb hint. Apologies for the delay; no objections. Cheers, -- Cyril Brulebois (k...@debian.org) D-I release manager --

Bug#928732: CVE-2019-11460

2019-06-03 Thread Salvatore Bonaccorso
Hi Simon, On Mon, Jun 03, 2019 at 11:34:36PM +0100, Simon McVittie wrote: > Version: 3.32.1-1 > > On Thu, 09 May 2019 at 22:34:53 +0200, Moritz Muehlenhoff wrote: > > This was assigned CVE-2019-11460: > > https://gitlab.gnome.org/GNOME/gnome-desktop/issues/112 > > This was fixed in 3.32.1, so I

Bug#929215: unblock: systemd/241-5

2019-06-03 Thread Cyril Brulebois
Hi, Michael Biebl (2019-06-03): > 241-5 is waiting for an ack from d-i. Since the AMD related RDRAND > breakage is rather nasty for users of those affected systemd, it would > be good to have that version in testing. > While I don't expect any issues on the udeb/udev related parts, it would > be

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Trent W. Buck
Rene Engelhard wrote: > On Mon, Jun 03, 2019 at 10:04:02PM +0200, Rene Engelhard wrote: > > $ apt-cache show mythes-en-us > > Package: mythes-en-us > > Source: libreoffice-dictionaries > > Sorry, edited and sent too fast. This is the key point here. This mythes > dict is *exactly* what gets

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Trent W. Buck
tag 929923 + patch thanks Rene Engelhard wrote: > On Mon, Jun 03, 2019 at 07:21:47PM +1000, Trent W. Buck wrote: >> Upstream, LibreOffice uses a dictionaries.xcu file to say "use the en_US >> thesaurus for ALL en locales". >> AFAICT Debian doesn't ship dictionaries.xcu files, though they are

Bug#929557: Please revert LTS kernel change that will break ZFS for Buster point releases

2019-06-03 Thread Bastian Blank
Control: severity -1 wishlist On Mon, Jun 03, 2019 at 06:39:39PM -0700, Mo Zhou wrote: > I believe this is a kernel bug. Instead of submitting > a grave RC for the 10.1 release, we'd better sort it out > right now before the Buster release. We already stated that we wont change it by marking

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Paul Wise
On Tue, Jun 4, 2019 at 4:12 AM Yves-Alexis Perez wrote: > My gut feeling is that light-locker just uses codepaths not really used > otherwise, like vt-switch at the same time as suspend/resume or screen off/on. > Unfortunately debugging i915 is completely out of my league (and I already > tried

Bug#929255: stretch-pu: package corekeeper/1.7~deb9u1

2019-06-03 Thread Paul Wise
On Mon, 2019-06-03 at 15:12 +0100, Adam D. Barratt wrote: > Please go ahead. Uploaded. -- bye, pabs https://wiki.debian.org/PaulWise signature.asc Description: This is a digitally signed message part

Bug#788104: Info received (RFS: lfdk/2.0.0+git20150619.906338f [ITP])

2019-06-03 Thread You-Sheng Yang
Hi, Gaffa, Colin, I recently created a repository to host debian packaging for lfdk. Would you mind guiding me through the process the include this utility in Debian? Thank you. -- You-Sheng Yang signature.asc Description: OpenPGP digital signature

Bug#929692: RFP: iwlwifi-dkms -- iwlwifi driver backport in DKMS format

2019-06-03 Thread You-Sheng Yang
Renamed source/binary package names to backport-iwlwifi-dkms in my gitlab fork: https://gitlab.com/vicamo/backport-iwlwifi-dkms Thank you. On Thu, 30 May 2019 17:37:30 +0800 Anthony Wong wrote: > Which git tree and branch do you take it from? If it is >

Bug#929557: Please revert LTS kernel change that will break ZFS for Buster point releases

2019-06-03 Thread Mo Zhou
control: severity -1 grave Dear kernel maintainers, Buster will be released with 4.19.37 kernel. That's fine and it doesn't break ZFS. However, the changes introduced in 4.19.38 and linux 5.0 break ZFS. That means the current 0.7.12-2 will fail to build everywhere after the first Buster point

Bug#805711: Info received (light-locker: no login possible after suspend)

2019-06-03 Thread Matthew Crews
This issue is still present in Buster. The workaround (switch to VT8 then back to VT7) also still works in Buster. signature.asc Description: OpenPGP digital signature

Bug#757726: ruby-rchardet: require 'rchardet fails' with invalid multibyte escape

2019-06-03 Thread Marek Veber
This version 1.3.3 is not ready for ruby-1.9 or ruby-2 ... On places with this bug can be inserted: "string[0]" -> "string.bytes[0]", but there is version 1.8 on rubygems (on github's changelog there is declared support for ruby-1.9.3 just in release 1.4.2)

Bug#929950: unblock: guile-2.2/2.2.4+1-2

2019-06-03 Thread Rob Browning
Package: release.debian.org User: release.debian@packages.debian.org Usertags: unblock Severity: normal Please unblock package guile-2.2 See the two bugs mentioned in the changelog. Recent builds (tests) have started failing on additional architectures, including amd64 (locally too) due to

Bug#929903: openssl: m2crypto test case regression

2019-06-03 Thread Sebastian Andrzej Siewior
On 2019-06-02 23:39:22 [+0200], Kurt Roeckx wrote: > > So, I added a small test for RSA_SSLV23_PADDING, as an extra commit, > > since it will likely not cherry-pick in stable branches. > > It's about this change: > -good &= constant_time_lt(threes_in_row, 8); > +good &=

Bug#929829: [Pkg-javascript-devel] Bug#929829: Bug#929829: gulp 4 cannot build node-babel 7 - Cannot convert undefined or null to object

2019-06-03 Thread Xavier
Le 03/06/2019 à 22:23, Xavier a écrit : > Le 01/06/2019 à 12:14, Pirate Praveen a écrit : >> ... >> gulp build >> [15:37:17] Local modules not found in ~/forge/debian/git/js-team/node-babel >> [15:37:17] Try running: npm install >> [15:37:17] Using globally installed gulp >> [15:37:17] Using

Bug#929907: libgnutls30: Connections to older GnUTLS servers break

2019-06-03 Thread Dominik George
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, > Is this reproducile with gnutls-cli or is the respective server > publically accessible? It is reproducible. 1. Create a buster chroot for the server, or something similar. 2. Install gnutls-bin 3.6.6-3 and ssl-cert. 3. Start something

Bug#929781: rkt: CVE-2019-10144 CVE-2019-10145 CVE-2019-10147

2019-06-03 Thread Moritz Mühlenhoff
On Sun, Jun 02, 2019 at 08:12:50AM +1000, Dmitry Smirnov wrote: > On Friday, 31 May 2019 4:46:08 PM AEST Salvatore Bonaccorso wrote: > > The following vulnerabilities were published for rkt. > > > > CVE-2019-10144[0]: > > rkt: processes run with `rkt enter` are given all capabilities during stage

Bug#927672: CVE-2019-11372 CVE-2019-11373

2019-06-03 Thread Moritz Mühlenhoff
On Sun, Apr 21, 2019 at 12:00:08AM +0200, Moritz Muehlenhoff wrote: > Source: libmediainfo > Severity: important > Tags: security > > Please see > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11372 > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11373 What's the status, can we

Bug#929948: CVE-2019-7733

2019-06-03 Thread Moritz Muehlenhoff
Source: liblivemedia Severity: important Tags: security This was assigned CVE-2019-7733: https://github.com/rgaufman/live555/issues/21 Cheers, Moritz

Bug#929949: New upstream version 0.8 available, compatible with python3

2019-06-03 Thread Sebastien Bacher
Package: duplicity Version: 0.7.18.2-1 Upstream rolled out a 0.8 version which is finally compatible with python3, it would be nice to have it uploaded to Debian https://code.launchpad.net/duplicity/0.8-series/0.8.00/+download/duplicity-0.8.00.tar.gz Cheers,

Bug#929829: [Pkg-javascript-devel] Bug#929829: gulp 4 cannot build node-babel 7 - Cannot convert undefined or null to object

2019-06-03 Thread Xavier
Le 01/06/2019 à 12:14, Pirate Praveen a écrit : > ... > gulp build > [15:37:17] Local modules not found in ~/forge/debian/git/js-team/node-babel > [15:37:17] Try running: npm install > [15:37:17] Using globally installed gulp > [15:37:17] Using gulpfile

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Rene Engelhard
Hi, On Mon, Jun 03, 2019 at 10:04:02PM +0200, Rene Engelhard wrote: > $ apt-cache show mythes-en-us > Package: mythes-en-us > Source: libreoffice-dictionaries Sorry, edited and sent too fast. This is the key point here. This mythes dict is *exactly* what gets shipped in LibreOffice itself. So I

Bug#928026: release-notes: document the state of security support for golang packages in Buster

2019-06-03 Thread Paul Gevers
Control: tags -1 patch On Fri, 26 Apr 2019 10:29:58 + Holger Levsen wrote: > package: release-notes > > This is already an issue in Stretch (e.g. #922170), but will be much > > worse in Buster, so unless someone reliably commits to work on > > this ASAP the available options are to drop

Bug#929940: r-cran-rcmdr: Installation needs to install other packages manually

2019-06-03 Thread Dirk Eddelbuettel
On 3 June 2019 at 13:21, Dirk Eddelbuettel wrote: | | On 3 June 2019 at 19:21, jpg wrote: | | Package: r-cran-rcmdr | | Version: 2.5-1-1 | | Severity: normal | | | | Dear Maintainer, | | | | I have already R and several packages installed. | | | | When I installed r-cran-rcmdr and loaded

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, 2019-06-03 at 12:59 -0700, Russ Allbery wrote: > Ah, good call. I was also seeing other problems with the Intel driver in > combination with light-locker where the monitor resolution would be set to > some incorrect value after restore from

Bug#929947: unblock: go-dep/0.5.1+really0.5.0-1

2019-06-03 Thread Dr. Tobias Quathamer
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package go-dep This is part of the effort to re-sync golang package versions in unstable and testing, see https://bugs.debian.org/928227 unblock go-dep/0.5.1+really0.5.0-1

Bug#929923: missing dictionaries.xcu confuses non-US English locales (e.g. en_AU)

2019-06-03 Thread Rene Engelhard
tag 929923 + wontfix thanks Hi, On Mon, Jun 03, 2019 at 07:21:47PM +1000, Trent W. Buck wrote: > Package: mythes-en-us > Version: 1:5.2.5-1 > Severity: normal > > Hi Rene et al. > > My users are in en_AU.UTF-8 locale. > They reported that Tools > Thesaurus doesn't work with mythes-en-us

Bug#928956: Document removal of ecryptfs-utils from Buster

2019-06-03 Thread Paul Gevers
Hi, On 02-06-2019 12:45, Justin B Rye wrote: > Holger Wansing wrote: +The ecryptfs-utils package +is not part of buster due to an unfixed serious bug (>>> +url="765854">#765854). At the time of writing this >>> paragraph,

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Russ Allbery
Yves-Alexis Perez writes: > Actually it seems to me that the bug is a bad interaction with light- > locker/lightdm locking system (which relies on vt switch) and the Intel > driver. It only seems to happens on this driver, and I think it's also > been reproduced just by doing vt-switches (but

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Mon, 2019-06-03 at 21:55 +0200, Yves-Alexis Perez wrote: > I noted Andreas raised the severity, but I hope someone has an idea how to fix > that because I don't. Also, since it was posted on -devel, I guess there's a bit of exposure: if some

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, 2019-05-31 at 18:32 -0700, Russ Allbery wrote: > This appears to be a bug in light-locker specifically, which is the > default screen lock program with XFCE with lightdm. See, for instance: > >

Bug#928987: compiz: make a compiz-boxmenu package

2019-06-03 Thread Samuel Thibault
Hello, Giacomo Boffi, le lun. 03 juin 2019 11:58:38 +0200, a ecrit: > In the hope that this helps, ciao ፨ gb Completely, thanks! I have now uploaded a package, it'll now have to pass through NEW. Samuel

Bug#929889: debootstrap: Support unconventional PATH on foreign distros

2019-06-03 Thread Tianon Gravi
On Sun, 2 Jun 2019 at 11:12, Vagrant Cascadian wrote: > The following patch fixes issues when the hard-coded > PATH=/sbin:/usr/sbin:/bin:/usr/bin does not contain chroot or other > commonly used utilities, by changing to PATH=$PATH:/sbin:... Do you think it would make sense to instead use

Bug#929945: cairo: CVE-2019-6462

2019-06-03 Thread Salvatore Bonaccorso
Source: cairo Version: 1.16.0-4 Severity: important Tags: security upstream Forwarded: https://gitlab.freedesktop.org/cairo/cairo/issues/353 Control: found -1 1.14.8-1 Hi, The following vulnerability was published for cairo, filling for tracking the issue. CVE-2019-6462[0]: | An issue was

Bug#929944: cairo: CVE-2019-6461

2019-06-03 Thread Salvatore Bonaccorso
Source: cairo Version: 1.16.0-4 Severity: important Tags: security upstream Forwarded: https://gitlab.freedesktop.org/cairo/cairo/issues/352 Control: found -1 1.14.8-1 Hi, The following vulnerability was published for cairo, filling for tracking. CVE-2019-6461[0]: | An issue was discovered in

Bug#929943: linux-image-4.19.0-5-amd64: NFS handle leak? Suspend-to-RAM inhibition

2019-06-03 Thread Philipp Marek
Package: src:linux Version: 4.19.37-3 Severity: normal Sequence of events: 1. Notebook is rebooted properly, used for work for some hours 2. Notebook lid was closed, STR works as usual 3. Notebook opened; some work; lid close, STR works 4. Notebook was opened; NFS4 from remote machine

Bug#926118: Alternative for Re: Bug#926118: unblock: libmspack/0.10.1-1

2019-06-03 Thread Paul Gevers
Control: tags -1 moreinfo confirmed Hi Jens, duck, On 01-06-2019 17:47, Jens Reyer wrote: > I'm posting this now because I'm really worried about the lack of > progress with this issue. However as stated before by me in this bug > here, and by the libmspack maintainer in #923885, we both think

Bug#929916: libreswan: CVE-2019-12312

2019-06-03 Thread Salvatore Bonaccorso
Hi Daniel! On Mon, Jun 03, 2019 at 12:24:08PM -0400, Daniel Kahn Gillmor wrote: > On Mon 2019-06-03 06:26:28 +0200, Salvatore Bonaccorso wrote: > > Source: libreswan > > Version: 3.27-4 > > Severity: grave > > Tags: patch security upstream fixed-upstream > > Justification: user security hole > >

Bug#929942: Bug in libreoffice-writer / Biolinum open type font

2019-06-03 Thread Florian Nisbach
Package: libreoffice-writer Version: 1:6.1.5-3 Package: fonts-linuxlibertine Version: 5.3.0-4 When a document contains a lowercase italic "m" in the open type font Linux Biolinum O, the following two things happen: * on prinouts, the m does not appear * if exported to PDF (or printed to PDF),

Bug#538008: dante-server: disregard my message from june 3

2019-06-03 Thread xavier renaut
Package: dante-server Followup-For: Bug #538008 Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** Please disregard my message from june 3 where I wasnt able to start the dante server. on a normal vm (ec2) with stable kernel, with sysv-rc, it starts

Bug#929931: CTDB: Debian Enablement (focus: NFS HA)

2019-06-03 Thread Rafael David Tinoco
https://bugs.launchpad.net/debian/+source/ctdb/+bug/722201/comments/19 Future possible issue While ctdb is not merged to *at least* samba-4.9.7 (in Debian): commit 022b9a6ca7d8cb6f541b1b24b27da4e1a3bea04b Author: Martin Schwenke Date: Tue Mar 26 00:49:49 2019 ctdb-scripts: Add test

Bug#929597: CVE-2019-12211 CVE-2019-12212 CVE-2019-12213 CVE-2019-12214

2019-06-03 Thread Anton Gladky
There is no upstream fix still available. I am planning to decrease the severity of the ticket to normal and track it as a simple security issue. Anton Am Mo., 27. Mai 2019 um 23:01 Uhr schrieb Anton Gladky : > > CVE-2019-12214 does not affect buster and stretch. > Jessie should be double

Bug#929941: [INTL:da] Danish translation of the template debian-security-support

2019-06-03 Thread Joe Dalton
Package: debian-security-support Severity: wishlist Tags: l10n patch Please include the attached Danish debian-security-support translation joe@debianbuster:~/over/debianp/debian-security-support$ msgfmt --statistics -c -v -o /dev/null da.po da.po: 21 oversatte tekster. bye Joe da.po.tar.bz2

Bug#929525:

2019-06-03 Thread Aidan Sojourner
Hello, I have the same bug. I believe the issue is due to the primus package recommending the legacy driver in addition to the current driver. Is this the intended behavior? Note that I _was_ able to upgrade my nvidia packages with --no-install-recommends.

Bug#929940: r-cran-rcmdr: Installation needs to install other packages manually

2019-06-03 Thread jpg
Package: r-cran-rcmdr Version: 2.5-1-1 Severity: normal Dear Maintainer, I have already R and several packages installed. When I installed r-cran-rcmdr and loaded Rcmdr with "library(Rcmdr), a dialogbox said that the following packages were missing : r-cran-aplpack r-cran-leaps

Bug#929907: libgnutls30: Connections to older GnUTLS servers break

2019-06-03 Thread Andreas Metzler
Control: severity -1 serious On 2019-06-03 Dominik George wrote: > Package: libgnutls30 > Version: 3.6.7-3 > Severity: grave > Justification: renders package unusable > The update to 3.6.7-3 reproducibly breaks ldap-utils (or, maybe,the ldap > client library) when connecting to a server with

Bug#538008: dante-server: dante won't start at boot

2019-06-03 Thread xavier renaut
Package: dante-server Version: 1.4.2+dfsg-5 Followup-For: Bug #538008 Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? configuring dante like this : /etc/danted.conf : internal: eth0 port = 1080 external: eth0

Bug#928746: unblock: zfs-linux/0.7.13-1

2019-06-03 Thread Sam Hartman
Please start talking to the kernel team now, and let them know your position. If you strongly suspect you're going to file an RC bug in the future, you should be talking now, not just holding back. I'm available to mediate if that ends up being useful.

Bug#929939: ITP: pizzly -- gene-fusion detection with kallisto

2019-06-03 Thread Steffen Moeller
Package: wnpp Severity: wishlist Owner: Steffen Moeller * Package name: pizzly * URL : http://github.com/pmeisted/pizzly * License : BSD Programming Lang: C++ Description : gene-fusion detection with kallisto Team-maintained on

Bug#929938: linux: please enable CONFIG_XFRM_STATISTICS=y

2019-06-03 Thread Daniel Kahn Gillmor
X-Debbugs-Cc: Paul Wouters Package: linux Version: 4.19.37-3 Control: affects -1 libreswan 0 dkg@alice:~$ grep CONFIG_XFRM_STATISTICS /boot/config-4.19.0-5-amd64 # CONFIG_XFRM_STATISTICS is not set 0 dkg@alice:~$ Paul Wouters, Libreswan upstream developer says: > Still this kernel option is

Bug#781961: systemd-logind integration for XScreenSaver

2019-06-03 Thread Jamie Zawinski
> Jamie, if there is a way to sync on the X server actually completing its > work, then we could do that instead. xscreensaver-command uses XSendEvent to send the ClientMessage to xscreensaver; it then waits up to 10 seconds for a response message to be written to the window. However, that the

Bug#929937: dovecot-lmtpd: _fully_ support RfC 5233 (Sieve Subaddress Extension) for LMTP transport

2019-06-03 Thread Paul Muster
Package: dovecot-lmtpd Version: 1:2.2.27-3+deb9u4 Severity: wishlist Tags: upstream Dear Maintainer, Dovecot's LMTP implementation and Pigeonhole Sieve already do support the format. RfC 5233, the Sieve subaddress extension, also offers . Way forward could be like this: 1) Introduce a new

Bug#929936: dovecot-sieve: _fully_ support RfC 5233 (Sieve Subaddress Extension)

2019-06-03 Thread Paul Muster
Package: dovecot-sieve Version: 1:2.2.27-3+deb9u4 Severity: wishlist Tags: upstream Dear Maintainer, Dovecot's LMTP implementation and Pigeonhole Sieve already do support the format. RfC 5233, the Sieve subaddress extension, also offers . Way forward could be like this: 1) Introduce a new

Bug#929916: libreswan: CVE-2019-12312

2019-06-03 Thread Daniel Kahn Gillmor
On Mon 2019-06-03 06:26:28 +0200, Salvatore Bonaccorso wrote: > Source: libreswan > Version: 3.27-4 > Severity: grave > Tags: patch security upstream fixed-upstream > Justification: user security hole > Forwarded: https://github.com/libreswan/libreswan/issues/246 > Control: fixed -1 3.28-1 > > The

Bug#928746: unblock: zfs-linux/0.7.13-1

2019-06-03 Thread Mo Zhou
control: retitle -1 unblock: zfs-linux/0.7.12-6 (or 0.7.13-1) control: close -1 Hi Release Team, On 2019-06-03 15:05, Mo Zhou wrote: > Patching the kernel is impossible because kernel maintainers > refused to do that. So that's an invalid solution. After a short discussion with Aron Xu, I

Bug#929935: unblock: golang-github-magiconair-properties/1.8.1+really1.8.0-1

2019-06-03 Thread Dr. Tobias Quathamer
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package golang-github-magiconair-properties This is part of the effort to re-sync golang package versions in unstable and testing, see https://bugs.debian.org/928227

Bug#929929: Being unable to build with >= 4.19.38 is an RC

2019-06-03 Thread Mo Zhou
control: close -1 I made a big mistake. It's the ***LTS KERNEL UPDATE*** that breaks ZFS 0.7.12-2. It's not a ZFS bug at all! An LTS KERNEL UPDATE that breaks stuff is where the grave RC lies.

Bug#929934: unblock: golang-github-disintegration-imaging/1.6.0+really1.5.0-1

2019-06-03 Thread Dr. Tobias Quathamer
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package golang-github-disintegration-imaging This is part of the effort to re-sync golang package versions in unstable and testing, see https://bugs.debian.org/928227

Bug#792567: Bug#929747: qa.debian.org: Please add cross-buildability in summary

2019-06-03 Thread Johannes Schauer
Hi, On Mon, 3 Jun 2019 17:12:22 +0200 Helmut Grohne wrote: > On Thu, May 30, 2019 at 05:22:12PM +0200, Helmut Grohne wrote: > > On Thu, May 30, 2019 at 10:57:52AM +0200, Samuel Thibault wrote: > > > https://tracker.debian.org/ has a link to the cross-buildability status > > > of a package. It'd

Bug#926976: [pre-a] unblock: blis/0.5.1-13

2019-06-03 Thread Mo Zhou
control: close -1 Let's just leave the bug for Buster. It's not critical.

Bug#929747: qa.debian.org: Please add cross-buildability in summary

2019-06-03 Thread Samuel Thibault
Helmut Grohne, le lun. 03 juin 2019 17:12:22 +0200, a ecrit: > What we need here is more people working on the difficult issues, not > random maintainers staring at undecipherable cross build failures. Ok :) > What we also need is maintainers replying to bug reports and > converting their

Bug#929931: CTDB: Debian Enablement (focus: NFS HA)

2019-06-03 Thread Rafael David Tinoco
> Initial support enabling CTDB to install/run in Ubuntu Server. > > BUGS: > > CTDB port is not aware of Ubuntu-specific NFS Settings > https://bugs.launchpad.net/ubuntu/+source/samba/+bug/722201 > > Desc: CTDB has been ported from RH-based distribution and its only > partially > aware of

Bug#928741: [pre-a] unblock: julia/1.0.4+dfsg-1

2019-06-03 Thread Mo Zhou
control: close -1 Hi Paul, On 2019-05-30 19:29, Paul Gevers wrote: > On Thu, 09 May 2019 19:26:06 -0700 Mo Zhou wrote: >> The current version in testing is 1.0.3, I'm requesting >> unblock for 1.0.4 (not-yet-released) because Julia's >> 1.0.X series is strictly a bug-fix-only branch. As per >>

Bug#929933: unblock: golang-github-bep-debounce/1.2.0+really1.1.0-1

2019-06-03 Thread Dr. Tobias Quathamer
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package golang-github-bep-debounce This is part of the effort to re-sync golang package versions in unstable and testing, see https://bugs.debian.org/928227 unblock

Bug#929747: qa.debian.org: Please add cross-buildability in summary

2019-06-03 Thread Helmut Grohne
Control: clone -1 -2 Control: retitle -2 qa.debian.org: Please add cross build satisfiability in summary Control: block -1 by -2 On Thu, May 30, 2019 at 05:22:12PM +0200, Helmut Grohne wrote: > On Thu, May 30, 2019 at 10:57:52AM +0200, Samuel Thibault wrote: > > https://tracker.debian.org/ has a

Bug#929714: python-acora: FTBFS: dpkg-buildpackage: error: dpkg-source -b . subprocess returned exit status 2

2019-06-03 Thread Hideki Yamane
control: tags -1 +patch On Wed, 29 May 2019 16:29:31 +0200 Lucas Nussbaum wrote: > > dpkg-source -b . > > dpkg-source: info: using source format '3.0 (quilt)' > > dpkg-source: info: building python-acora using existing > > ./python-acora_2.2.orig.tar.gz > > dpkg-source: info: local changes

Bug#928746: unblock: zfs-linux/0.7.13-1

2019-06-03 Thread Mo Zhou
Hi Paul, On 2019-05-30 19:51, Paul Gevers wrote: > or more severe in Debian BTS terms. I may have been wrong, but then > please point me to the changes so important that you want them in > buster. Please also be prepared to undo the new upstream release and > just fix the bugs that are so

Bug#859874: Reproducible on stretch?

2019-06-03 Thread Patrik Schindler
Hello, thank you for your patience. Unfortunately I didn't record details to my test setup, so I created a new Tunes Library on Stretch and tested to access it. I get frequent messages that the iTunes Library could not be saved. No messages in log.smbd, though. What do you need me to do to

Bug#929929: zfs smid

2019-06-03 Thread Chris Zubrzycki
Is there any chance to keep the removed exported symbol? Could you guys convince the kernel team? There’s no copyright issue since it’s released code, it’s just keeping a symbol that has been in exported in the kernel for the past 7 years. On top of that, Greg is violating the kernel release

Bug#928292: stretch-pu: package signing-party/2.5-1

2019-06-03 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2019-05-01 at 13:52 +0200, Guilhem Moulin wrote: > Hi Salvatore, > > On Wed, 01 May 2019 at 13:37:12 +0200, Salvatore Bonaccorso wrote: > > On Wed, May 01, 2019 at 01:27:26PM +0200, Guilhem Moulin wrote: > > > +signing-party (2.5-1+deb9u1) stretch;

Bug#928553: stretch-pu: package libthrift-java/0.9.1-2.1~deb9u1

2019-06-03 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2019-05-07 at 04:02 +0200, Andreas Beckmann wrote: > The fix for CVE-2018-1320 was in sid (0.9.1-2.1) before the package > got > removed, and is in jessie-lts (0.9.1-2+deb8u1), leaving stretch at an > older version than jessie-lts. So let's get it in stretch

Bug#929931: CTDB: Debian Enablement (focus: NFS HA)

2019-06-03 Thread Rafael David Tinoco
Package: ctdb Version: 2:4.9.5+dfsg-4 Severity: important Tags: upstream patch -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Initial support enabling CTDB to install/run in Ubuntu Server. BUGS: CTDB port is not aware of Ubuntu-specific NFS Settings

Bug#929255: stretch-pu: package corekeeper/1.7~deb9u1

2019-06-03 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2019-05-20 at 12:19 +0800, Paul Wise wrote: > I'd like to backport the security fixes and hardening in corekeeper > from buster to stretch. > Please go ahead. Regards, Adam

Bug#929613: stretch-pu: package minissdpd/1.2.20130907-4.1+deb9u1

2019-06-03 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2019-05-27 at 10:17 +0100, Chris Lamb wrote: >   minissdpd (1.2.20130907-4.1+deb9u1) stretch; urgency=medium >    > * CVE-2019-12106: Prevent a use-after-free vulnerability that > would allow a >   remote attacker to crash the process. (Closes:

Bug#929930: libreswan: replace xfrm_stats with xfrm_acq_expires

2019-06-03 Thread Daniel Kahn Gillmor
Package: libreswan Version: 3.28-1 libreswan tries to detect XFRM support by lookng at /proc/net/xfrm_stat, but that's only relevant on kernels with CONFIG_XFRM_STATISTICS enabled. /proc/sys/net/core/xfrm_acq_expires is a more robust way to test for xfrm support. This probably needs to be

Bug#929887: /usr/lib/qgis/crssync: error while loading shared libraries: libhdf5_serial_hl.so.100: cannot open shared object file: No such file or directory

2019-06-03 Thread 積丹尼 Dan Jacobson
It turns out that all you need to do is simply add a dependency on libhdf5-100 and then the package is perfectly installable! (Otherwise I don't understand the point of uploading a package that nobody can install using apt.) Here is what I successfully installed: Package: qgis Version:

Bug#781961: systemd-logind integration for XScreenSaver

2019-06-03 Thread Martin Lucina
> Note that after using this for 15 days now, I still occasionally (say 1 in > 10 times?) get a flash of the unlocked screen content on resume, followed > by the XScreenSaver password dialog. Unclear to me what is going on here > other than "random scheduling races" but that's precisely what this

Bug#929929: Being unable to build with >= 4.19.38 is an RC

2019-06-03 Thread Mo Zhou
Source: zfs-linux Version: 0.7.12-2 Severity: grave Clarification: a foreseeable stable RC is grave enough. Buster will be released with 4.19.37 kernel. That's fine and it doesn't break ZFS. However, the changes introduced in 4.19.38 and linux 5.0 break ZFS. That means the current 0.7.12-2 will

Bug#929928: coreutils: nohup segfaults with command line

2019-06-03 Thread Stefan Schwarzer
Package: coreutils Version: 8.30-3 Severity: normal Dear Maintainer, I am trying to run a program detached in the background from an ssh login, like nohup where is my executable and a configuration file. The combination runs without issue. As far as I understand from the documentation

Bug#929834: lightdm-gtk-greeter: After locking screen, display is turned off and unlock prompt is not visible

2019-06-03 Thread Andreas Tille
Control: severity -1 grave Hi, I've set the severity of this bug to grave. It has turned out that in combination with xfce light-locker leaves the user with a black screen leading normal users to the assumption that the computer is frozen. I have observed users pressing power button of their

Bug#929927: python-django: CVE-2019-12308: AdminURLFieldWidget XSS

2019-06-03 Thread Salvatore Bonaccorso
Source: python-django Version: 1:1.11.20-1 Severity: important Tags: security upstream Control: found -1 2:2.2.1-1 Hi, The following vulnerability was published for python-django. CVE-2019-12308[0]: AdminURLFieldWidget XSS If you fix the vulnerability please also make sure to include the CVE

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Russ Allbery
(This probably belonged on debian-user, but since I have background on this specific problem and already did the research.) Raj Kiran Grandhi writes: > In a fresh install of Buster with XFCE desktop, locking the screen > blanks the monitor and the monitor enters a power save state. After >

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Raj Kiran Grandhi
Hi, In a fresh install of Buster with XFCE desktop, locking the screen blanks the monitor and the monitor enters a power save state. After that, neither moving the mouse nor typing on the keyboard would turn the monitor back on. I could find two ways to get the display back on: 1. Typing the

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Jonathan Carter
Hey Adam On 2019/06/01 18:29, Adam Borowski wrote: > At the time of the xscreensaver debacle, there was no sane alternative > (candidates depended on 80% of GNOME, offered no feedback nor discoverable > controls to the user, etc). There _is_ a wonderful alternative now: > xfce4-screensaver,

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Adam Borowski
On Sat, Jun 01, 2019 at 11:06:42AM +0200, Andreas Tille wrote: > > This appears to be a bug in light-locker specifically, which is the > > default screen lock program with XFCE with lightdm. See, for instance: > > > > https://github.com/the-cavalry/light-locker/issues/114 > > > > Switching to

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Holger Levsen
On Sat, Jun 01, 2019 at 06:29:31PM +0200, Adam Borowski wrote: > Using unstable myself, I'm not sure what to recommend for Buster. https://tracker.debian.org/pkg/physlock signature.asc Description: PGP signature

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Russ Allbery
Adam Borowski writes: > But, the culprit is light-locker. In general, it's in such a buggy > state that I believe it shouldn't be in the distribution at all, much > less a default of any kind. After it replaced xscreensaver[1] as the > xfce's dependency, I went into some pretty heated

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Theodore Ts'o
On Sat, Jun 01, 2019 at 06:16:58AM +0530, Raj Kiran Grandhi wrote: > > In a fresh install of Buster with XFCE desktop, locking the screen > blanks the monitor and the monitor enters a power save state. After > that, neither moving the mouse nor typing on the keyboard would turn > the monitor back

Bug#929834: Buster/XFCE unlock screen is blank

2019-06-03 Thread Russ Allbery
Georg Faerber writes: > On 19-06-01 11:04:28, Russ Allbery wrote: >> I did some research on that a while back and ended up not filing a bug >> about it because it looked relatively pointless. It appeared to be a >> deep design choice on both sides, and not something anyone was likely >> to

Bug#929926: lxc-cgroup didn't show cpu usage

2019-06-03 Thread Leonid Balioshenko
Package: lxc Version: 1:3.1.0+really3.0.3-8 Severity: normal Dear Maintainer, * What led up to the situation? "lxc-cgroup -n example_container cpuacct.stat" provides no output Looks like this was fixed in in version 3.0.4: https://github.com/lxc/lxc/issues/2742 Please, update version of lxc

Bug#903759: [Debian-med-packaging] Bug#903759: Bug#903759: 903759: marking as pending

2019-06-03 Thread Andrius Merkys
Hi Graham, On 2019-06-03 14:04, Graham Inggs wrote: > Thanks for the upload, and congratulations! Thanks a lot! :) > I filed an unblock request (#929924). Great - I forgot to do so. Best, Andrius -- Andrius Merkys Vilnius University Institute of Biotechnology, Saulėtekio al. 7, room V325

  1   2   >