Bug#961298: Dropping jodd from bullseye

2021-05-18 Thread Salvatore Bonaccorso
HI, On Tue, May 18, 2021 at 11:05:15PM +0200, Emmanuel Bourg wrote: > Le 2021-05-18 20:39, Moritz Mühlenhoff a écrit : > > > let's remove jodd from bullseye until it gets actually used, ok? I can > > file > > an RM bug with the release team. > > Yes go ahead. For same reason we might consider

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread UN-pi
A morning surprise: After I reset the / usr/ lib/ rsyslog /rsyslog-rotate fileto the original-version the content of kern.log, syslog and messages is almost identical. The syslog file seems to be rotated, but thesystem is writing to syslog.1 while the syslog-file has kern.log-content.Currently

Bug#988742: geographiclib-doc: broken symlinks: /usr/share/doc/geographiclib/html/{C,Fortran}/doxygen.png -> ../doxygen.png

2021-05-18 Thread Sebastiaan Couwenberg
Control: tags -1 pending This is fixed in git. Kind Regards, Bas -- GPG Key ID: 4096R/6750F10AE88D4AF1 Fingerprint: 8182 DE41 7056 408D 6146 50D1 6750 F10A E88D 4AF1

Bug#988755: jikespg FTCBFS: builds for the build architecture

2021-05-18 Thread Helmut Grohne
Source: jikespg Version: 1.3-3 Tags: patch User: debian-cr...@lists.debian.org Usertags: ftcbfs jikespg fails to cross build from source, because it does not pass cross tools to make. The easiest way of fixing that - using dh_auto_build - makes jikespg cross buildable. Please consider applying

Bug#988573: linux-image-5.10.0-6-alpha-smp dereferences a null pointer on boot

2021-05-18 Thread Rich
So it reproduces identically on 5.10.28 and 5.12.4 vanilla, but 5.13.0-rc2 fails differently, so I'm going to report that. On Sun, May 16, 2021 at 11:13 AM Rich wrote: > > Sure, I'll try 5.12.4 once I'm done with the build I'm running. (I > have no idea how long that'll be, though, I've never

Bug#988754: ITP: splinter -- tool for testing web applications using Python

2021-05-18 Thread Joseph Nuthalapati
Package: wnpp Severity: wishlist Owner: Joseph Nuthalapati * Package name: python-splinter Version : 0.14.0 Upstream Author : Andrews Medina * URL : https://splinter.readthedocs.io * License : BSD-3-Clause Programming Lang: Python Description :

Bug#986006: libpdfbox2-java: CVE-2021-27807

2021-05-18 Thread tony mancill
On Tue, May 18, 2021 at 09:01:51PM +0200, Moritz Mühlenhoff wrote: > Am Mon, Apr 05, 2021 at 09:37:41AM -0700 schrieb tony mancill: > > On Sat, Mar 27, 2021 at 07:52:37PM +0100, Salvatore Bonaccorso wrote: > > > Source: libpdfbox2-java > > > Version: 2.0.22-1 > > > Severity: important > > > Tags:

Bug#988753: unblock: libpdfbox2-java/2.0.23-1

2021-05-18 Thread tony mancill
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package libpdfbox2-java [ Reason ] This unblock request addresses these two CVEs in the libpdfbox2-java package: CVE-2021-27807: A carefully crafted PDF file can trigger

Bug#988752: ITP: deepin-manual provides user guides of the deepin system and applications

2021-05-18 Thread Ma Aiguo
Package: deepin-manual Version: 5.7.0.75-1 Severity: wishlist X-Debbugs-Cc: imai...@gmail.com Dear Maintainer, It is part of Deepin software and DDE (Deepin Desktop Environment) I intend to co-maintain this package inside the pkg-deepin group. I work at deepin company,now I want to promote the

Bug#988751: deepin-manual provides user guides of the deepin system and applications

2021-05-18 Thread Ma Aiguo
Package: deepin-manual Version: 5.7.0.75-1 Severity: wishlist X-Debbugs-Cc: imai...@gmail.com Dear Maintainer, I work at deepin company,now I want to promote the DDE desktop for the community for free. -- System Information: Debian Release: 11.0 APT prefers unstable APT policy: (500,

Bug#988689: ITP: 7zip -- 7-Zip file archiver

2021-05-18 Thread yokota
Hi all, > > 7-Zip is a file archiver with a high compression ratio. > is this different from > https://tracker.debian.org/pkg/p7zip "p7zip" is a forked project from "7-Zip" project. My "7zip" package is come from original "7-Zip" project. Both code is something different from each other. > It

Bug#988750: YAML dependencies should be optional/suggested

2021-05-18 Thread dcook
Package: libcgi-session-serialize-yaml-perl Version: 4.26-2 The Debian package requires that libyaml-perl or libyaml-syck-perl be installed, but it is possible to use this package without either of those YAML modules. You can specify your own YAML parser (like YAML::XS). There is some

Bug#988749: regression: upgrade from stable: feh stopped loading canon raw CR2 files

2021-05-18 Thread Attila Kinali
Package: feh Version: 3.6.3-1 Severity: normal Hi, I just upgraded from stable(buster) to testing(bullseye) and feh stopped loading Canon raw CR2 files. Although the manpage says that dcraw is needed, it was not previously installed, but libraw19. feh was upgraded from 3.1.3-1 to 3.6.3-1

Bug#988748: num-utils: provide traditional mean of two middle elements option for mean

2021-05-18 Thread David Bremner
Package: num-utils Version: 0.5-15 Severity: wishlist Tags: upstream -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 In my experience, for median of a data set of of size 2k, people usually want the mean of the element of rank k and the element of rank k+1 (indexing from 1). It would be nice if

Bug#988398: unblock: aprx/2.9.0+dfsg-3

2021-05-18 Thread Dave Hibberd
aprx 2.9.0+dfsg-4 has been uploaded to unstable, and debdiff with 2.9.0+dfsg-3 has been attached. Thanks, -- Hibby MM0RFN On Tue, 18 May 2021, at 9:11 PM, Sebastian Ramacher wrote: > Hi Dave > > On 2021-05-17 22:01:39 +0100, Dave Hibberd wrote: > > Hi, > > > > Thanks for the feedback. >

Bug#988696: installation-reports: No network management in LXDE task

2021-05-18 Thread Holger Wansing
Control: reassign -1 lxde Hi, Andreas Tille wrote (Tue, 18 May 2021 10:37:12 +0200): > I decided for the LXDE task (and unselected Gnome). This ends up with > no network management on the rebootet system. My solution was wo > plug-in the installation USB stick and install network-manager (+

Bug#986590: dbus-test-runner: flaky ppc64el autopkgtest: FAIL test-libdbustest-mock-test (exit status: 1)

2021-05-18 Thread Mike Gabriel
Hi Paul, On Di 18 Mai 2021 20:49:55 CEST, Paul Gevers wrote: Hi Mike, On 18-05-2021 07:38, Mike Gabriel wrote: Would it be a viable solution for now to not run autopkgtests on ppcel64? I really don't have a clue why this issue comes up only on ppcel64. If you think this failure is not

Bug#988747: apache2: README.backtrace gives incorrect instructions

2021-05-18 Thread Peter Chubb
Package: apache2 Version: 2.4.47-1 Severity: normal Dear Maintainer, I'm trying to work out why Apache2 is segfaulting, so want it to generate a core file. The instructures in /usr/share/doc/apache2/README.backtrace are no longer valid: they refer to packages that no longer exist in sid

Bug#961298: Dropping jodd from bullseye

2021-05-18 Thread Emmanuel Bourg
Le 2021-05-18 20:39, Moritz Mühlenhoff a écrit : let's remove jodd from bullseye until it gets actually used, ok? I can file an RM bug with the release team. Yes go ahead.

Bug#736373: using this patch with salsa & openqa

2021-05-18 Thread Philip Hands
Hi Ian, Thanks for the patch. It's proven very useful while seting up pipelines on salsa that can be run when a udeb's git repo is pushed, such that a mini.iso is produced that will make use of a repository containing that udeb. While getting that to work, I noticed that your patch does not deal

Bug#855846: repo: requires software outside of the distribution to function

2021-05-18 Thread Jonas Smedegaard
Package: repo Followup-For: Bug #855846 -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Seems Replicant project might be on to something that might help get this package back in main: https://redmine.replicant.us/issues/2213 - Jonas - -- System Information: Debian Release: 11.0 APT prefers

Bug#988746: RM: jodd/3.8.6-1.1

2021-05-18 Thread Moritz Muehlenhoff
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: rm X-Debbugs-Cc: ebo...@apache.org Please remove jodd from bullseye, it has open security issues and there are currently no rdeps (it was uploaded for jmeter 3, which didn't enter the archive yet).

Bug#988745: vtk-dicom: autodep8-python3 autopkgtest failure

2021-05-18 Thread Étienne Mollier
Source: vtk-dicom Version: 0.8.12-1+b2 Severity: serious Tags: patch Greetings, While looking up the unrelated bug #988643, I noticed that the package triggered an autodep8 python3 autopkgtest failure: autopkgtest [21:45:13]: test autodep8-python3: set -e ; for py in $(py3versions -d

Bug#988744: khard: broken symlinks: /usr/share/doc/khard/html/_static/*.js -> ../../../sphinx-doc/html/_static/*.js

2021-05-18 Thread Andreas Beckmann
Package: khard Version: 0.17.0-1 Severity: normal User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 1m53.4s ERROR: FAIL: Broken symlinks:

Bug#988743: krb5-doc: broken symlinks: /usr/share/doc/krb5-doc/_static/*.js

2021-05-18 Thread Andreas Beckmann
Package: krb5-doc Version: 1.18.3-5 Severity: normal User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 0m37.6s ERROR: FAIL: Broken symlinks:

Bug#988742: geographiclib-doc: broken symlinks: /usr/share/doc/geographiclib/html/{C,Fortran}/doxygen.png -> ../doxygen.png

2021-05-18 Thread Andreas Beckmann
Package: geographiclib-doc Version: 1.51-1 Severity: normal User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 1m34.8s ERROR: FAIL: Broken symlinks:

Bug#988741: glances-doc: broken symlinks: /usr/share/doc/glances/html/_static/fonts/RobotoSlab-*.ttf -> ../../../../../fonts/truetype/roboto/slab/RobotoSlab-*.ttf

2021-05-18 Thread Andreas Beckmann
Package: glances-doc Version: 3.1.5-1 Severity: normal User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package ships (or creates) a broken symlink. >From the attached log (scroll to the bottom...): 0m42.6s ERROR: FAIL: Broken symlinks:

Bug#979765: rdpmc on VIA Nano

2021-05-18 Thread 8vvbbqzo567a
Hello Kazimierz, The rdpmc instruction can't be used to read the fixed counter on some VIA Nano CPU's. We're trying to figure out which ones work and which ones don't work. Can you provide CPU information from /proc/cpuinfo for your VIA Nano U3500 and VIA Eden X2 U4200 CPU's? Can you also

Bug#988740: unblock: glibc/2.31-12

2021-05-18 Thread Aurelien Jarno
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: debian-gl...@lists.debian.org, debian-b...@lists.debian.org Please unblock package glibc [ Reason ] This new version fixes testsuite failures when run on a kernel which has

Bug#922981: tagging 922981 (ca-certificates-java: /etc/ca-certificates/update.d/jks-keystore doesn't update /etc/ssl/certs/java/cacerts)

2021-05-18 Thread Andreas Beckmann
On 18/05/2021 21.38, Paul Gevers wrote: On 08-04-2021 19:33, Julien Cristau wrote: I've started to look at it, I'm afraid building up context on this stuff to understand what it's doing is going to take a while... Just a friendly ping. Did you get anywhere with this yet? Just an additional

Bug#988739: libsidplayfp6: missing Breaks+Replaces: libsidplayfp5

2021-05-18 Thread Sebastian Ramacher
On 2021-05-18 22:14:32 +0200, Andreas Beckmann wrote: > Package: libsidplayfp6 > Version: 2.1.2-1 > Severity: serious > User: debian...@lists.debian.org > Usertags: piuparts > > Hi, > > during a test with piuparts I noticed your package fails to upgrade from > 'sid' to 'experimental'. > It

Bug#988739: libsidplayfp6: missing Breaks+Replaces: libsidplayfp5

2021-05-18 Thread Andreas Beckmann
Package: libsidplayfp6 Version: 2.1.2-1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package fails to upgrade from 'sid' to 'experimental'. It installed fine in 'sid', then the upgrade to 'experimental' fails because it

Bug#988632: audacity: The main drawing area (sound wave) do not refresh

2021-05-18 Thread Dennis Filder
Control: tags -1 moreinfo unreproducible X-Debbugs-CC: d.fil...@web.de, poming...@gmail.com It works perfectly here (under Xorg with KDE). Even running: LANG=zh_TW.UTF8 LC_CTYPE=zh_TW.UTF8 LC_ALL=zh_TW.UTF8 \ LANGUAGE=zh_TW:zh audacity does not produce the behaviour you describe. If

Bug#988398: unblock: aprx/2.9.0+dfsg-3

2021-05-18 Thread Sebastian Ramacher
Hi Dave On 2021-05-17 22:01:39 +0100, Dave Hibberd wrote: > Hi, > > Thanks for the feedback. > > Attached in aprx-3.diff is my proposed changes to the blocked upload as a new > revision - my understanding is now that I've uploaded aprx_2.9.0+dfsg-3, I > need to upload aprx_2.9.0+dfsg-4. >

Bug#988737: libx11: CVE-2021-31535: Missing request length checks

2021-05-18 Thread Salvatore Bonaccorso
Control: severity -1 grave Hi, On Tue, May 18, 2021 at 09:13:18PM +0200, Salvatore Bonaccorso wrote: > Source: libx11 > Version: 2:1.7.0-2 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team > > > Hi, > > The following vulnerability was

Bug#988261: librsvg2-2: Please drop libcroco3 dependency on alpha, hppa, m68k, sh4, x32

2021-05-18 Thread Sebastian Ramacher
On 2021-05-18 13:24:51 +, Vasyl Gello wrote: > Hi Simon! > > I dig deeper in the missing dependency issue and I think the solution is to > mask librsvg2 in ffmpeg build-deps for x32 just like it is masked for hppa. > > Sebastian, what do you think? I can try building ffmpeg on x32 without

Bug#922981: tagging 922981 (ca-certificates-java: /etc/ca-certificates/update.d/jks-keystore doesn't update /etc/ssl/certs/java/cacerts)

2021-05-18 Thread Paul Gevers
Hi Julien, On 08-04-2021 19:33, Julien Cristau wrote: > I've started to look at it, I'm afraid building up context on this > stuff to understand what it's doing is going to take a while... Just a friendly ping. Did you get anywhere with this yet? Paul > Cheers, > Julien > > On Tue, Apr 06,

Bug#986527: sagemath: FTBFS: /<>/sage/src/bin/sage: line 549: exec: cython: not found

2021-05-18 Thread Jochen Sprickerhof
* Julien Puydt [2021-05-18 17:47]: Upstream manages to ship version with no error because they ship hundreds of deps to an exact version for which they fitted the testsuite to pass. We ship those deps as separate packages, because they're actually not sagemath-specific [look at the list, it's

Bug#988696: installation-reports: No network management in LXDE task

2021-05-18 Thread Andreas Tille
Hi Holger, On Tue, May 18, 2021 at 09:00:55PM +0200, Holger Wansing wrote: > Control: reassign -1 lxde > > Andreas Tille wrote (Tue, 18 May 2021 10:37:12 +0200): > > I decided for the LXDE task (and unselected Gnome). This ends up with > > no network management on the rebootet system. My

Bug#988617: Acknowledgement (unblock: kodi-pvr-hts/8.3.0+ds1-1)

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 confirmed On 2021-05-18 08:36:30 +, Vasyl Gello wrote: > Fixes in this request: > > * 8.2.3: Fixed: Timer settings: Add missing duplicate detection values > * 8.3.0: Fixed regular expression in search dialog Please go ahead and remove the moreinfo tag once the upload is

Bug#988738: eyeD3: depends on unpackaged Python package “grako”

2021-05-18 Thread Thorsten Glaser
Package: eyed3 Version: 0.8.10-1.1 Severity: serious Justification: fails to work X-Debbugs-Cc: t...@mirbsd.de $ eyeD3 -P display -p %a% *.mp3 eyed3.plugins:WARNING: Plugin '('lastfm.py', '/usr/lib/python3/dist-packages/eyed3/plugins')' requires packages that are not installed: cannot import

Bug#988737: libx11: CVE-2021-31535: Missing request length checks

2021-05-18 Thread Salvatore Bonaccorso
Source: libx11 Version: 2:1.7.0-2 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for libx11. CVE-2021-31535[0]: | Missing request length checks If you fix the vulnerability please also make sure

Bug#988621: Acknowledgement (unblock: kodi-pvr-nextpvr/8.2.3+ds1-1)

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 confirmed On 2021-05-18 08:49:03 +, Vasyl Gello wrote: > This release adds missing "break" statement (bugfix) and re-adds recording > directories dropped in 7.4.0 (regression fix). Please go ahead and remove the moreinfo tag once the upload is available in unstable. Cheers

Bug#988625: Acknowledgement (unblock: kodi-vfs-libarchive/2.0.1+ds1-1)

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 confirmed On 2021-05-18 09:04:03 +, Vasyl Gello wrote: > This is a maintenance release dropping ISO playback support because Kodi now > plays ISO / BD natively to avoid unnecessary heisenbugs. Please go ahead and remove the moreinfo tag once the new version is available in

Bug#988624: Acknowledgement (unblock: kodi-pvr-zattoo/19.7.9+ds1-1)

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 confirmed On 2021-05-18 08:58:05 +, Vasyl Gello wrote: > Thos paych release fixes handling of a changed EPG format returned by Zattoo > OTT provider. Please go ahead and remove the moreinfo tag once the new version is available in unstable. Cheers > --  > Vasyl Gello >

Bug#875531: "editor +42 filename" -- accept or reject?

2021-05-18 Thread Sean Whitton
Hello, On Tue 18 May 2021 at 01:42PM +02, Mattia Rizzolo wrote: > Seconded. Thanks. I looked at applying this patch but the version we have in git doesn't apply to 'next' without first applying the patch in #682347. Mattia, would you be interested in reviewing and seconding that one too, so I

Bug#988727: CVE-2021-3514 CVE-2021-3480

2021-05-18 Thread Salvatore Bonaccorso
Control: clone -1 -2 Control: retitle -1 389-ds-base: CVE-2021-3514 Control: reassign -2 src:slapi-nis 0.56.5-1 Control: retitle -2 slapi-nis: CVE-2021-3480 Hi, On Tue, May 18, 2021 at 08:30:52PM +0200, Moritz Muehlenhoff wrote: > Package: 389-ds-base > Severity: grave > Tags: security >

Bug#988726: [Pkg-javascript-devel] Bug#988726: CVE-2020-28496

2021-05-18 Thread Yadd
Le 18/05/2021 à 20:28, Moritz Muehlenhoff a écrit : > Source: three.js > Severity: important > Tags: security > X-Debbugs-Cc: Debian Security Team > > This was assigned CVE-2020-28496: > https://github.com/mrdoob/three.js/issues/21132 >

Bug#988611: Acknowledgement (unblock: kodi/2:19.1+dfsg1-1)

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 moreinfo On 2021-05-18 07:17:51 +, Vasyl Gello wrote: > Dear colleagues, > > As Sebastian pointed in #988615, let me expand why the package is an > improvement for bullseye. > > The 19.1 point release has 80 bug fixes >

Bug#986006: libpdfbox2-java: CVE-2021-27807

2021-05-18 Thread Moritz Mühlenhoff
Am Mon, Apr 05, 2021 at 09:37:41AM -0700 schrieb tony mancill: > On Sat, Mar 27, 2021 at 07:52:37PM +0100, Salvatore Bonaccorso wrote: > > Source: libpdfbox2-java > > Version: 2.0.22-1 > > Severity: important > > Tags: security upstream > > X-Debbugs-Cc: car...@debian.org, Debian Security Team >

Bug#988735: pglogical: CVE-2021-3515

2021-05-18 Thread Salvatore Bonaccorso
Source: pglogical Version: 2.3.3-2 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for pglogical, please lower the severity if you strongly disagree. CVE-2021-3515[0]:

Bug#988459: unblock: digimend-dkms/10-3

2021-05-18 Thread Sebastian Ramacher
Control: tags -1 moreinfo On 2021-05-13 21:02:36 +0900, Kentaro Hayashi wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > X-Debbugs-Cc: ken...@xdump.org > > Please unblock package digimend-dkms > > [ Reason ] > > If

Bug#986590: dbus-test-runner: flaky ppc64el autopkgtest: FAIL test-libdbustest-mock-test (exit status: 1)

2021-05-18 Thread Paul Gevers
Hi Mike, On 18-05-2021 07:38, Mike Gabriel wrote: > Would it be a viable solution for now to not run autopkgtests on > ppcel64? I really don't have a clue why this issue comes up only on > ppcel64. If you think this failure is not representative for the package behavior on ppc64el, it is.

Bug#988734: CVE-2020-24370

2021-05-18 Thread Moritz Muehlenhoff
Package: lua5.3 Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-24370: http://lua-users.org/lists/lua-l/2020-07/msg00324.html Patch: https://github.com/lua/lua/commit/b5bc89846721375fe30772eb8c5ab2786f362bf9 Cheers, Moritz

Bug#988733: CVE-2020-24392

2021-05-18 Thread Moritz Muehlenhoff
Package: ruby-twitter-stream Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-24392: https://securitylab.github.com/advisories/GHSL-2020-097-voloko-twitter-stream Cheers, Moritz

Bug#988732: CVE-2020-36326

2021-05-18 Thread Moritz Muehlenhoff
Package: libphp-phpmailer Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team Please see http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36326 Patches: https://github.com/PHPMailer/PHPMailer/commit/26f2848d3bbb57add5f34a467a1e3b2f9ce5cd2a (v6.4.1)

Bug#988731: exiv2: CVE-2021-32617

2021-05-18 Thread Salvatore Bonaccorso
Source: exiv2 Version: 0.27.3-3 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for exiv2. CVE-2021-32617[0]: | Exiv2 is a command-line utility and C++ library for reading, writing, | deleting, and

Bug#988730: CVE-2017-18641

2021-05-18 Thread Moritz Muehlenhoff
Package: lxc-templates Severity: important Tags: security X-Debbugs-Cc: Debian Security Team https://bugs.launchpad.net/ubuntu/+source/lxc/+bug/1661447 This was originally for LXC, but with 3.0.2 the templates are now in lxc-templates. Cheers, Moritz

Bug#988729: CVE-2021-21299

2021-05-18 Thread Moritz Muehlenhoff
Source: rust-hyper Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2021-21299: https://github.com/hyperium/hyper/security/advisories/GHSA-6hfq-h8hq-87mf https://rustsec.org/advisories/RUSTSEC-2021-0020.html Cheers, Moritz

Bug#961298: Dropping jodd from bullseye

2021-05-18 Thread Moritz Mühlenhoff
Am Mon, Mar 01, 2021 at 10:54:31AM +0100 schrieb Salvatore Bonaccorso: > Hi Emmanuel, > > On Sat, May 30, 2020 at 02:50:32PM +0200, Emmanuel Bourg wrote: > > Control: severity -1 important > > > > Le 22/05/2020 à 22:51, Salvatore Bonaccorso a écrit : > > > > > The following vulnerability was

Bug#988722: postgresql-common: Upgrading cluster with postgis does not migrate tables using postgis

2021-05-18 Thread Dennis Filder
On Tue, May 18, 2021 at 06:47:38PM +0200, Christoph Berg wrote: > Can you share the apt command and output that led to this removal? One more observation: Bullseye's gdal-data 3.2.1+dfsg-1 defines a Breaks: libgdal20 (< 2.5.0~), but the libgdal20 in Buster is 2.4.0, and postgresql-11-postgis-2.5

Bug#988728: CVE-2020-17523 CVE-2020-17510 CVE-2020-11989

2021-05-18 Thread Moritz Muehlenhoff
Source: shiro Severity: important Tags: security X-Debbugs-Cc: Debian Security Team CVE-2020-17523: https://www.openwall.com/lists/oss-security/2021/02/01/3 https://issues.apache.org/jira/browse/SHIRO-797 CVE-2020-17510: https://www.openwall.com/lists/oss-security/2020/11/04/7

Bug#988727: CVE-2021-3514 CVE-2021-3480

2021-05-18 Thread Moritz Muehlenhoff
Package: 389-ds-base Severity: grave Tags: security X-Debbugs-Cc: Debian Security Team CVE-2021-3514: https://github.com/389ds/389-ds-base/issues/4711 CVE-2021-3480: https://bugzilla.redhat.com/show_bug.cgi?id=1944640

Bug#988726: CVE-2020-28496

2021-05-18 Thread Moritz Muehlenhoff
Source: three.js Severity: important Tags: security X-Debbugs-Cc: Debian Security Team This was assigned CVE-2020-28496: https://github.com/mrdoob/three.js/issues/21132 https://github.com/mrdoob/three.js/pull/21143/commits/4a582355216b620176a291ff319d740e619d583e Cheers, Moritz

Bug#988725: libzmq3-dev: cppzmq headers aren't actually from version 4.7.0

2021-05-18 Thread Lukas K.
Package: libzmq3-dev Version: 4.3.4-1 Severity: important X-Debbugs-Cc: deb...@0x83.eu Dear Maintainer, The zeromq package includes the zmq.hpp header from the cppzmq project: https://github.com/zeromq/cppzmq The version reported by CPPZMQ_VERSION_MAJOR/MINOR/PATCH is 4.7.0, so it should

Bug#986803: [Pkg-rust-maintainers] Bug#986803: CVE-2021-28875 CVE-2021-28876 CVE-2021-28877 CVE-2021-28878 CVE-2021-28879 CVE-2020-36317 CVE-2020-36318

2021-05-18 Thread Moritz Mühlenhoff
Sorry for the late reply, got backlogged in my inbox. Am Mon, Apr 12, 2021 at 11:18:16AM +0100 schrieb Ximin Luo: > It looks like these CVEs affect all versions up to 1.52 (which is not yet > released). > > Do you have links to patches fixing these bugs that can be backported to > 1.48? We've

Bug#988722: postgresql-common: Upgrading cluster with postgis does not migrate tables using postgis

2021-05-18 Thread Julien Cristau
Control: reassign -1 hdf5 1.10.5+repack-1~exp6 On Tue, May 18, 2021 at 07:48:08PM +0200, Dennis Filder wrote: > X-Debbugs-CC: d.fil...@web.de > > On Tue, May 18, 2021 at 06:47:38PM +0200, Christoph Berg wrote: > > > Can you share the apt command and output that led to this removal? > > I

Bug#988722: postgresql-common: Upgrading cluster with postgis does not migrate tables using postgis

2021-05-18 Thread Dennis Filder
X-Debbugs-CC: d.fil...@web.de On Tue, May 18, 2021 at 06:47:38PM +0200, Christoph Berg wrote: > Can you share the apt command and output that led to this removal? I attached the output from "apt full-upgrade" until the "Do you want to continue?" Having gimp-gmic (recommended by

Bug#972785: zeromq3: Include cmake files for cppzmq

2021-05-18 Thread Lukas K.
On Mon, 26 Oct 2020 08:58:22 + Gordon Ball wrote: > On Sun, Oct 25, 2020 at 05:13:52PM +0100, László Böszörményi (GCS) wrote: > > On Fri, Oct 23, 2020 at 4:57 PM Gordon Ball wrote: > > > src:zeromq3 and libzmq3-dev currently embed headers from the separate > > > cppzmq repository. However,

Bug#696332: lsb-release: release/codename depend on a successful apt-get

2021-05-18 Thread Thorsten Glaser
On Tue, 18 May 2021, Benjamin Drung wrote: > In case /usr/lib/os-release sets VERSION_CODENAME or > /etc/debian_version specifies only one codename, lsb-release takes the > information from there. base-files 11 don't set these values (and > therefore trigger this bug), but base-files 11.1 does

Bug#988724: firefox: Firefox 88 unusable on intel gpu

2021-05-18 Thread Kamil Jońca
Package: firefox Version: 87.0-2 Severity: important X-Debbugs-Cc: kjo...@poczta.onet.pl Dear Maintainer, *** Reporter, please consider answering these questions, where appropriate *** * What led up to the situation? Upgrade to 88.0.1 version * What exactly did you do (or not do) that was

Bug#988723: ITP: python-datacache -- helpers for transparently downloading datasets

2021-05-18 Thread Steffen Möller
Subject: ITP: python-datacache -- Package: wnpp Owner:  Steffen Severity: wishlist * Package name    : python-datacache   Version : 0.4.7   Upstream Author : Copyright: Alex Rubinsteyn * URL : https://github.com/openvax/datacache * License : Apache-2.0   Programming

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread UN-pi
Yes, it is very easy.But I think that I will only be able to see in a few days whether the old behavior will return.Please be patient. On Tue, 18 May 2021 18:18:37 +0200 Michael Biebl wrote: > Am 18.05.21 um 17:05 schrieb Michael Biebl: > > Am 18.05.21 um 16:37 schrieb UN-pi: > >> "systemctl

Bug#976048: ITP: seatd -- Minimal user, seat and session management daemon

2021-05-18 Thread debian
Le lun 17 mai 2021 à 16:21, Mark Hindley a écrit : Henry-Nicolas, Hello Mark, Thanks for following up with this. Thanks for packaging it :-) On Mon, May 17, 2021 at 04:26:58PM +0200, Henry-Nicolas Tourneur wrote: Hello Mark, libseat will become a dependency for wlroots as of

Bug#987566: ghostscript: PDF Interpreter error on armel

2021-05-18 Thread Bernhard Übelacker
Hello Guilhem, hello Jonas, might this be a similar or the same issue as in #942055 ? I took the example file from this issue, created an armel buster chroot and ran it once at my arm5tel device, and once at a armv7l cpu android device (unfortunately with a non-debian kernel). - with the

Bug#988722: postgresql-common: Upgrading cluster with postgis does not migrate tables using postgis

2021-05-18 Thread Christoph Berg
Re: Dennis Filder > During an upgrade from Buster to Bullseye I also had to upgrade a > cluster from postgresql 11 to 13. The cluster had the postgis > extension enabled (postgis 2.5.1) and one table with columns of types > from postgis. My typescript tells me that during "apt full-upgrade" >

Bug#720096: marked as pending in rsyslog

2021-05-18 Thread Michael Biebl
On Thu, 25 Feb 2021 13:30:40 +0100 Harald Dunkel wrote: > On Mon, 22 Feb 2021 20:00:33 +0100 Michael Biebl wrote: > > Am 22.02.2021 um 18:57 schrieb Harald Dunkel: > > > Sorry to say, but this is not a fix. A fix would avoid the race > > > condition, no matter whats written in the config files.

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread Michael Biebl
Am 18.05.21 um 17:05 schrieb Michael Biebl: Am 18.05.21 um 16:37 schrieb UN-pi: "systemctl status rsyslog.service" say:   rsyslog.service - System Logging Service     Loaded: loaded (/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)     Active: active (running) since Wed

Bug#988722: postgresql-common: Upgrading cluster with postgis does not migrate tables using postgis

2021-05-18 Thread Dennis Filder
Package: postgresql-common Architecture: amd64 Version: 225 Severity: serious Justification: Potential data loss (lower at your discretion) Tags: bullseye X-Debbugs-CC: d.fil...@web.de During an upgrade from Buster to Bullseye I also had to upgrade a cluster from postgresql 11 to 13. The cluster

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread Christian Göttsche
Control: notfixed -1 logrotate/3.18.0-2 Control: reassign -1 src:rsyslog Control: tags -1 -newcomer Control: affects -1 logrotate > I noticed that some log files in /var/log are not being rotated. > e.g. kern.log, syslog etc. > There are no files ending with .1 or .gz. The files keep getting

Bug#988721: firebird3.0-utils: Utils naming is inconsistent - fbstat, isql-fb

2021-05-18 Thread fr0st
Package: firebird3.0-utils Version: 3.0.5.33100.ds4-2 Severity: wishlist Dear Maintainer, naming of utils originally named isql and gstat is unpredictable and inconsistent - isql-fb and fbstat. It's very hard to find out what command should be used to invoke gstat. Please could you consider

Bug#986527: sagemath: FTBFS: /<>/sage/src/bin/sage: line 549: exec: cython: not found

2021-05-18 Thread Julien Puydt
Hi, Le mardi 18 mai 2021 à 15:31 +0200, Jochen Sprickerhof a écrit : > > * Julien Puydt [2021-05-18 07:56]: > > 1) Upstream itself uses the testsuite in the sense of "shouldn't > > have > > too many failing tests", and it still allows to detect when a build > > is > > utterly broken, so we

Bug#983289: ITP: traefik -- The Cloud Native Application Proxy

2021-05-18 Thread Roland Mas
Hi Aloïs, I'm working on packaging Jupyterhub, which uses Traefik as its proxy. I have prototype packages for all other dependencies of Jupyterhub, but I currently install Traefik with wget (ugh). Do you have any public repository frow which I could fetch preliminary packages for Traefik?

Bug#988720: ITP: python-typechecks -- express constraints on types

2021-05-18 Thread Steffen Möller
Package: wnpp Severity: wishlist * Package name    : python-typechecks   Version : 0.1.0   Upstream Author : Copyright: * URL : https://github.com/openvax/typechecks * License : Apache-2.0   Programming Lang: Python   Description : express constraints on types  

Bug#988703: Acknowledgement (O: ooo-thumbnailer -- thumbnailer for OpenOffice.org documents)

2021-05-18 Thread David D Lowe
Deletion of this package from Debian unstable has been requested. See: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988709

Bug#988709: RM: ooo-thumbnailer -- RoQA; orphaned, abandoned upstream

2021-05-18 Thread David D Lowe
I'm the former maintainer of ooo-thumbnailer in Debian, and the upstream author. This project is no longer maintained or developed upstream. I agree with deleting it from Debian unstable.

Bug#988702: Acknowledgement (ooo-thumbnailer: Orphaning this package)

2021-05-18 Thread David D Lowe
Deletion of this package from Debian unstable has been requested. See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=988709

Bug#988599: ITP: kata-containers -- secure container runtime with lightweight virtual machines

2021-05-18 Thread Shengjing Zhu
On Tue, May 18, 2021 at 10:02 PM Hideki Yamane wrote: > > On Mon, 17 May 2021 00:28:51 +0800 > Shengjing Zhu wrote: > > * Package name: kata-containers > > I'm also interested in making its deb package. > Can I join it? > Definitely yes! For a package written in Go and Rust, which both

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread Michael Biebl
Am 18.05.21 um 16:37 schrieb UN-pi: "systemctl status rsyslog.service" say:  rsyslog.service - System Logging Service    Loaded: loaded (/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)    Active: active (running) since Wed 2021-05-12 17:27:41 CEST;5 days ago Docs:

Bug#988719: upstream has debian packages

2021-05-18 Thread 積丹尼 Dan Jacobson
Package: mplayer Severity: wishlist https://www.mplayerhq.hu/design7/news.html announces debian packages. Maybe useful.

Bug#988718: Security fixes from the April 2021 Patch Update

2021-05-18 Thread Lars Tangvald
Source: mysql-8.0 Version: 8.0.23 Severity: grave Tags: security upstream fixed-upstream The Oracle Critical Patch Update for April 2021 lists CVEs affecting MySQL 8.0 that are fixed in 8.0.25 CVE list: CVE-2020-1971 CVE-2021-2144 CVE-2021-2146 CVE-2021-2160 CVE-2021-2162 CVE-2021-2164

Bug#984956: Pmix issues with openmpi-4.1.0

2021-05-18 Thread Nicolas Perrin
Dear Maintainer, I tested mpirun from openmpi-bin 4.1.0-9 and I no longer have the problem. Thank you, -- | Nicolas Perrin Grid'5000 Administrator | | nicolas.per...@inria.fr INRIA / RESIST | On Sun, 16 May 2021 07:25:51 +0100 Alastair McKinstry < mckins...@debian.org>

Bug#988717: lxml: triggers lintian autoreject tag 'license-problem-md5sum-non-free-file'

2021-05-18 Thread Andreas Beckmann
Package: lxml Version: 4.6.3-1 Severity: serious Hi, your package triggers a non-overridable lintian autoreject tag, i.e. if the package would be reuploaded today without changes, it would be automatically rejected by ftp-master.

Bug#988716: platformio 4.3.4 cannot download required frameworks

2021-05-18 Thread Sebastian Reichel
Package: platformio Version: 4.3.4-1 Severity: grave Dear Maintainer, Upstream changed paths for the framework manifest files in recent releases and did not maintain backward compatibility links resulting in 4.3.4 no longer being able to install the frameworks. For example this happens when I

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread UN-pi
"systemctl status rsyslog.service" say:  rsyslog.service - System Logging Service    Loaded: loaded (/lib/systemd/system/rsyslog.service; enabled; vendor preset: enabled)    Active: active (running) since Wed 2021-05-12 17:27:41 CEST; 5 days ago Docs: man:rsyslogd(8)   

Bug#988715: atmel-firmware: triggers lintian autoreject tag 'file-in-etc-not-marked-as-conffile'

2021-05-18 Thread Andreas Beckmann
Package: atmel-firmware Version: 1.3-4 Severity: serious Hi, your package triggers a non-overridable lintian autoreject tag, i.e. if the package would be reuploaded today without changes, it would be automatically rejected by ftp-master.

Bug#988714: unblock: xserver-xorg-video-geode/2.11.20-6

2021-05-18 Thread Martin-Éric Racine
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Please unblock package xserver-xorg-video-geode This is a small documentation fix. It patches the upstream README to add information about

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread Michael Biebl
Am 18.05.2021 um 16:13 schrieb Michael Biebl: --- So I added :       --kill-who=main -- Ok, thanks for the additional information. I don't see how this is going to fix your issue though. Typically, rsyslog only has a single process, so using main or all shouldn't

Bug#988652: logrotate: kern.log,syslog and other files in /var/log not rotating

2021-05-18 Thread Michael Biebl
[please always CC the bug report on replies] Am 18.05.2021 um 15:58 schrieb UN-pi: This was the original file: --- #!/bin/sh if [ -d /run/systemd/system ]; then     systemctl kill -s HUP rsyslog.service else     invoke-rc.d rsyslog rotate > /dev/null fi

Bug#988713: pipemeter: triggers lintian autoreject tag 'FSSTND-dir-in-usr'

2021-05-18 Thread Andreas Beckmann
Package: pipemeter Version: 1.1.5-1 Severity: serious Hi, your package triggers a non-overridable lintian autoreject tag, i.e. if the package would be reuploaded today without changes, it would be automatically rejected by ftp-master. https://lintian.debian.org/tags/FSSTND-dir-in-usr

  1   2   >