Bug#1004037: Segmentation fault in plink2 (Was: src:plink2: fails to migrate to testing for too long: autopkgtest regression)

2022-02-19 Thread Andreas Tille
Hi Chris, Am Sat, Feb 19, 2022 at 11:37:34PM -0800 schrieb Chris Chang: > To elaborate: when I look at > https://salsa.debian.org/med-team/plink2/-/tree/master , I can see that > plink2.cc, include/plink2_base.h, and include/plink2_base.cc don't have the > same contents as the v2.00a3-20220218

Bug#1006163: ITP: pyyaml-env-tag -- Custom YAML tag for referencing environment variables

2022-02-19 Thread Carsten Schoenert
Package: wnpp Severity: wishlist Owner: Carsten Schoenert X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: pyyaml-env-tag Version : 0.1 Upstream Author : Waylan Limberg * URL : https://github.com/waylan/pyyaml-env-tag * License : MIT Programming

Bug#1004037: Segmentation fault in plink2 (Was: src:plink2: fails to migrate to testing for too long: autopkgtest regression)

2022-02-19 Thread Chris Chang
To elaborate: when I look at https://salsa.debian.org/med-team/plink2/-/tree/master , I can see that plink2.cc, include/plink2_base.h, and include/plink2_base.cc don't have the same contents as the v2.00a3-20220218 GitHub tag/release. So I don't know where you grabbed the code from this time, but

Bug#1006038: git-remote-hg: FTBFS: dh_auto_test: error: make -j8 test returned exit code 2

2022-02-19 Thread Paul Wise
Control: forwarded -1 https://github.com/mnauw/git-remote-hg/issues/48 On Sat, 2022-02-19 at 07:31 +0100, Lucas Nussbaum wrote: > During a rebuild of all packages in sid, your package failed to build > on amd64. This appears to be caused by git 1:2.35.1-1 in unstable, the autopkgtests regressed

Bug#1006162: expat: autopkgtest regressions (from CVE-2022-25313 fix)

2022-02-19 Thread GCS
Control: tags -1 +confirmed Hi Salvatore, On Sun, Feb 20, 2022 at 8:15 AM Salvatore Bonaccorso wrote: > There appears to be regressions from the CVE-2022-25313 fix in 2.4.5. > They are known already upstream, cf. > https://github.com/NixOS/nixpkgs/pull/160826#issuecomment-1046074523 > > I will

Bug#1006162: expat: autopkgtest regressions (from CVE-2022-25313 fix)

2022-02-19 Thread Salvatore Bonaccorso
Source: expat Version: 2.4.5-1 Severity: serious Justification: autopkgtest regression X-Debbugs-Cc: car...@debian.org Control: affects -1 src:libxml-parser-perl,src:python2.7,src:python3.10,src;python3.9 Hi Laszlo, There appears to be regressions from the CVE-2022-25313 fix in 2.4.5. They are

Bug#1005959: mig-for-host:amd64 should not exist

2022-02-19 Thread Helmut Grohne
Hi Samuel, On Sun, Feb 20, 2022 at 12:01:36AM +0100, Samuel Thibault wrote: > Mmm, it still targets hurd- explicitly, so I'd say it should still > be called mig-x86-64-gnu. I can relate to that, yes. > What I'm wondering is why we added -linux/-kfreebsd since here they are > host, not target.

Bug#1006161: RM: muscle [arm64 armhf armel mips64el mipsel ppc64el s390x alpha hppa hurd-i386 ia64 kfreebsd-amd64 kfreebsd-i386 m68k powerpc ppc64 risc64 sh4 sparc64] -- ROM; Currently FTBFS for non-I

2022-02-19 Thread Andreas Tille
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: debian-med-packag...@lists.alioth.debian.org Hi, the new upstream version of muscle is using some ASM statements which are only available on Intel (and compatible) architectures. This is known to upstream and they are working on this[1].

Bug#993350: xsane: Scanimage detects scanner but Xsane won't start it

2022-02-19 Thread Hans Georg Colle
Hi, after updating libsane1 yesterday xsane works as expected. Georg

Bug#1005861: bullseye-pu: package pdb2pqr/2.1.1+dfsg-7+deb11u1

2022-02-19 Thread Andrius Merkys
On 2022-02-19 19:52, Adam D. Barratt wrote: > Please go ahead. Thanks, uploaded. Best wishes, Andrius

Bug#979407: amd64-microcode: Amd64 microcode is not being loaded by the kernel from early initramfs.

2022-02-19 Thread Shmerl
On Wed, 06 Jan 2021 10:39:38 + Philip Armstrong wrote: > if I trigger a microcode > load from the shell with > > echo 1 > /sys/devices/system/cpu/microcode/reload > > after booting then the microcode is updated to that newer version. How do you check the current version of microcode in

Bug#1004678: git-lfs: allow offline operation

2022-02-19 Thread Stephen Gelman
Thanks for reporting this. I agree that it sounds useful, though it might be very challenging due to the decentralized nature of git-lfs. I’m happy to keep this bug open, but it seems better served for the upstream tracker at https://github.com/git-lfs/git-lfs/issues. Stephen On Jan 31, 2022 at

Bug#1004452: bullseye-pu: package gnupg2/2.2.27-2+deb11u1

2022-02-19 Thread Daniel Kahn Gillmor
On Sat 2022-02-19 17:09:21 +, Adam D. Barratt wrote: > Control: tags -1 + confirmed d-i > > On Thu, 2022-01-27 at 17:02 -0500, Daniel Kahn Gillmor wrote: >> Please consider an update to GnuPG in debian bullseye, from version >> 2.2.27-2 to 2.2.27-2+deb11u1. >> > > The version mentioned above

Bug#1006159: orphan-sysvinit-scripts: request backport of 0.08 or later to bullseye-backports

2022-02-19 Thread Chen-Yu Tsai
Package: orphan-sysvinit-scripts Version: 0.07 Severity: important Dear Maintainer, rsyslog 8.2110.0-4 was backported to bullseye-backports a couple months ago. This version no longer contains the SysV init script, which was removed in 8.2110.0-2. Anyone still running sysvinit on

Bug#1006158: RFP: webp-pixbuf-loader -- WebP GDK Pixbuf Loader library

2022-02-19 Thread Matti Palmström
Package: wnpp Severity: wishlist * Package name: webp-pixbuf-loader Version : 0.0.3 Upstream Author : Alberto Ruiz * URL : https://github.com/aruiz/webp-pixbuf-loader * License : LGPL-2 Programming Lang: C Description : Add support for WebP to

Bug#1006157: /lib/modules/5.16.0-1-sparc64-smp/kernel/fs/ext4/ext4.ko: [sparc64+ext4] reads see zeros w/ simultaneous write

2022-02-19 Thread Noah Misch
Package: src:linux Version: 5.16.7-2 Severity: normal File: /lib/modules/5.16.0-1-sparc64-smp/kernel/fs/ext4/ext4.ko Dear Maintainer, * What led up to the situation? The context is an ext4 filesystem on a sparc64 host. I've observed this with each of the three sparc64 kernels that I've

Bug#996028: [debian-mysql] Bug#996028: InnoDB: corrupted TRX_NO after upgrading to 10.3.31

2022-02-19 Thread Otto Kekäläinen
Control: reassign -1 mariadb-server-10.3 Control: tags moreinfo Hello! Is the issue https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=996028 still affecting people? Did anybody figure out the root cause or what upstream issue it was, or what version it was fixed in?

Bug#975911: [debian-mysql] Bug#975911: mariadb-client and libedit

2022-02-19 Thread Otto Kekäläinen
Hello! If somebody wants to continue to work on this issue[1], please submit your packaging improvement suggestion as a Merge Request on Salsa[2]. I promise to review them promptly. [1] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=975911 [2]

Bug#917872: Ensure Mroonga plugin install/upgrade/uninstall for MariaDB

2022-02-19 Thread Otto Kekäläinen
Package: mariadb-plugin-mroonga Version: 10.6.5-1 Severity: normal Tags: newcomer Hello! If somebody wants to continue working on this[1] newcomer friendly tagged bug report, please submit Merge Requests[2]. I promise to review them quickly. [1]

Bug#1006111: [debian-mysql] Bug#1006111: mariadb-server: wrong groupby result in newly filled myISAM table

2022-02-19 Thread Otto Kekäläinen
Hello! Thanks for using MariaDB. In the scope of Debian packaging we do not fix upstream bugs. If you have a reproducible test case you could file bug report upstream. We are in the process of uploading 10.3.34, 10.5.15 and 10.6.7 to Debian. If these versions fix the issue then we can mark the

Bug#1005737: Purging sane-utils deletes the scanner group, created by libsane1

2022-02-19 Thread David Ward
Package: sane-utils Version: 1.1.1-2 Severity: serious (The original title and description of this bug were inaccurate; please disregard those. The existing pull request has been updated.) When the libsane1 package is installed, a "scanner" group is created on the system, which has access to

Bug#1002291: bpfcc: Fails to build with libbpf/0.6.1-1

2022-02-19 Thread Sudip Mukherjee
On Sat, Feb 19, 2022 at 5:36 AM Vasudev Kamath wrote: > > Sudip Mukherjee writes: > > > I have now uploaded libbpf/0.7.0 to experimental, can you please try > > building bpfcc and let me know if it works for you. > > > > I'm ending up getting different error now related to deprecation. I am not

Bug#1005402: Abuses netfilter conntrack notifier API

2022-02-19 Thread Ben Hutchings
On Fri, 2022-02-18 at 23:23 +0100, Axel Beckert wrote: > Control: tag -1 - moreinfo > > Hi Ben, > > Ben Hutchings wrote: > > > What would be the impact if I don't disable this feature? Can you > > > please elaborate? > > > > Then the module will not report all the events that might be expected.

Bug#1005884: linux-image-5.16.0-1-amd64: Kernel oops (unable to handle page fault) during boot

2022-02-19 Thread Richard B. Kreckel
Hi Salvatore, On 19.02.22 20:31, Salvatore Bonaccorso wrote: > Alright thank you for confirming that. Would it be possible that you > as well build the kernel with > https://git.kernel.org/linus/bea2662e7818e15d7607d17d57912ac984275d94 > applied on top to see if this resolved the issue? Yes that

Bug#1006156: ITP: parolottero -- compose words using a 4x4 grid of letters

2022-02-19 Thread Salvo "LtWorf" Tomaselli
Package: wnpp Severity: wishlist Owner: "Salvo \"LtWorf\" Tomaselli" X-Debbugs-Cc: debian-de...@lists.debian.org, tipos...@tiscali.it * Package name: parolottero Version : 1.0 Upstream Author : Salvo "LtWorf" Tomaselli * URL : https://github.com/ltworf/parolottero *

Bug#1006155: ITP: explosive-c4 -- four in a row game, mostly for phones, but works on desktop too

2022-02-19 Thread Salvo "LtWorf" Tomaselli
Package: wnpp Severity: wishlist Owner: "Salvo \"LtWorf\" Tomaselli" X-Debbugs-Cc: debian-de...@lists.debian.org, tipos...@tiscali.it * Package name: explosive-c4 Version : 1.0 Upstream Author : Salvo "LtWorf" Tomaselli * URL : https://github.com/ltworf/explosive-c4

Bug#1006154: nmu: evolution-rss_0.3.96-4

2022-02-19 Thread Jeremy Bicha
Package: release.debian.org User: release.debian@packages.debian.org Usertags: binnmu Severity: normal Please schedule this rebuild to finish the auto-upperlimit evolution 3.43 mini-transition: nmu evolution-rss_0.3.96-4 . ANY . unstable . -m "Rebuild against evolution 3.43" Thanks, Jeremy

Bug#1005959: mig-for-host:amd64 should not exist

2022-02-19 Thread Samuel Thibault
Hello, Helmut Grohne, le ven. 18 févr. 2022 14:13:09 +0100, a ecrit: > On Fri, Feb 18, 2022 at 12:45:57PM +0100, Guillem Jover wrote: > > Just to spell out, what might perhaps be obvious here, but I think > > they key is that MIG is "kernel independent", so it provides an > > interface which is

Bug#1006148: Chromium constantly tries to access CPUFreq API in VMs

2022-02-19 Thread MichaIng
Package: chromium Version: 98.0.4758.102-1~deb11u1 Ah sorry, my bad, the errors do show up on version 98.0.4758.102-1~deb11u1. So then it is not an upstream issue but a difference between the build or environment on Bullseye vs Bookworm. Best regards, Micha

Bug#1005995: espeakup: not systemd support

2022-02-19 Thread Samuel Thibault
Control: tags -1 +moreinfo Hello, espeakup does have systemd support. Bardot Jerome, le ven. 18 févr. 2022 18:55:45 +0100, a ecrit: > update-rc.d: warning: start and stop actions are no longer supported; falling > back to defaults > Restarting Speakup/espeak connector: espeakup failed! >

Bug#1006140: New version can't load old databases

2022-02-19 Thread Markus Koschany
Am Samstag, dem 19.02.2022 um 23:13 +0100 schrieb Jochen Sprickerhof: > * Markus Koschany [2022-02-19 22:38]: > > Ok. Did you file an upstream bug report already? > > I did not yet. Upstream bundles the old binary version so I don't think > I can convince them to do a quick migration. > But I

Bug#1006152: mozjs91: FTBFS on i386: test262/built-ins/Date/UTC/fp-evaluation-order.js

2022-02-19 Thread Simon McVittie
Source: mozjs91 Version: 91.6.0-1 Severity: serious Tags: ftbfs After applying patches to fix compilation on i386 and mipsel (see commits 3f0f229d, 585dadd4) there is a test failure unresolved on i386: ## test262/built-ins/Date/UTC/fp-evaluation-order.js: rc = 3, run time = 0.022397

Bug#1006151: fakeroot: assumes linuxish stat version

2022-02-19 Thread Samuel Thibault
Package: fakeroot Version: 1.27-1 Severity: important Tags: patch Hello, When redirecting the xstat functions, fakeroot is passing _STAT_VER but it assumes it should pass the Linux values, making it unusable on non-Linux. The attached patch fixes it by checking for __linux__, and add the

Bug#1004407: ITS: dfu-util

2022-02-19 Thread Tormod Volden
dfu-util 0.11-1 has been uploaded to the DELAYED queue with a delay of 7 days, see attached nmudiff. Tormod dfu-util-0.11-1.nmudiff Description: Binary data

Bug#1006150: python3-pip: Error when trying to list packages that need to be updated (local and system-wide)

2022-02-19 Thread Christian Britz
Package: python3-pip Version: 20.3.4-4 Severity: normal X-Debbugs-Cc: cbr...@t-online.de Dear Maintainer, I am trying to list Python3 packages which need to be updated. Running "pip list --user --outdated" I get the following error. This happens also, when I run "sudo pip list --outdated", so I

Bug#1006017: playitslowly doesn't start (hasn't for awhile)

2022-02-19 Thread Andreas Beckmann
Followup-For: Bug #1006017 Control: found -1 1.5.0-1 This seems to go back to stretch: # xvfb-run playitslowly Traceback (most recent call last): File "", line 890, in _find_spec AttributeError: 'DynamicImporter' object has no attribute 'find_spec' During handling of the above exception,

Bug#1006140: New version can't load old databases

2022-02-19 Thread Markus Koschany
Hi Jochen, Am Samstag, dem 19.02.2022 um 21:21 +0100 schrieb Jochen Sprickerhof: > Hi Markus, > > thanks for your quick reply. > > * Markus Koschany [2022-02-19 21:01]: > > That means only hibiscus/jameica require our attention. I would try to > > remove > > the obsolete connection setting

Bug#1006149: linux-image-5.16.0-1-686: Fails to boot on T41 Thinkpads

2022-02-19 Thread Diederik de Haas
On Saturday, 19 February 2022 22:04:14 CET Petra R.-P. wrote: > Package: src:linux > Version: 5.16.7-2 > > This new kernel version does not boot on two fairly similar > old IBM T41 Thinkpads. > ... > linux-image-5.15.0-3-686, which I am using to write this > message, runs fine. > > pn

Bug#995224: [Debian-med-packaging] Bug#995224: relion-cuda: FTBFS with cub 1.14

2022-02-19 Thread Andreas Beckmann
On 19/02/2022 20.13, Sascha Steinbiss wrote: 79 | #error The version of CUB in your include path is not compatible with this release of Thrust. CUB is now included in the CUDA Toolkit, so you no longer need to use your own checkout of CUB. Define THRUST_IGNORE_CUB_VERSION_CHECK to ignore

Bug#1006149: linux-image-5.16.0-1-686: Fails to boot on T41 Thinkpads

2022-02-19 Thread Petra R.-P.
Package: src:linux Version: 5.16.7-2 Severity: critical Justification: breaks the whole system Dear Maintainer, This new kernel version does not boot on two fairly similar old IBM T41 Thinkpads. What reproducibly happens is as follows: After the lines Loading Linux 5.16.0-1-686 ...

Bug#1006147: Merge request

2022-02-19 Thread Dave Jones
I've now submitted the following merge request for this issue: https://salsa.debian.org/pkg-debconf/debconf/-/merge_requests/10 Best regards, Dave Jones.

Bug#1006148: Chromium constantly tries to access CPUFreq API in VMs

2022-02-19 Thread MichaIng
Package: chromium Version: 90.0.4430.212-1 Hey guys, I recognised that Chromium on Bullseye is constantly trying to access the CPUFreq API, even when it runs within a VM where this API is expected to be not available. This triggers constant error messages: --- *** stack smashing detected

Bug#1005336: RFS: srpc/0.9.6 [ITP] Sogou RPC Library

2022-02-19 Thread Adam Borowski
On Fri, Feb 11, 2022 at 01:42:57PM +, Lance Lin wrote: > * Package name: srpc >Version : 0.9.6 > dget -x https://mentors.debian.net/debian/pool/main/s/srpc/srpc_0.9.6-1.dsc Hi! I'm afraid the package fails to build, it needs a Build-Depend on liblz4-dev. Some files are

Bug#1005952: [Pkg-javascript-devel] RFP: libjs-vega -- programmed web graphics with JSON

2022-02-19 Thread Nilesh Patra
On 19 February 2022 7:47:29 pm IST, Yadd wrote: >Package is ready in https://salsa.debian.org/js-team/vega.js > >To build package, remove debian/nodejs/extlinks. This is enough for node-vega >but provides probably broken libjs-vega files (I'm unable to test this but >rollup warns). > >If you

Bug#1005952: [Pkg-javascript-devel] RFP: libjs-vega -- programmed web graphics with JSON

2022-02-19 Thread Nilesh Patra
On 19 February 2022 8:22:24 pm IST, Yadd wrote: >Maybe only d3-array should be updated: > 'quantileSorted' is not exported by > ../../../../../usr/share/nodejs/d3-array/src/index.js, > imported by src/quantiles.js > >I moved debian/nodejs/extlinks to debian/nodejs/extcopies to have better

Bug#1006140: New version can't load old databases

2022-02-19 Thread Jochen Sprickerhof
Hi Markus, thanks for your quick reply. * Markus Koschany [2022-02-19 21:01]: That means only hibiscus/jameica require our attention. I would try to remove the obsolete connection setting mentioned in #1005838. Tried that already, did not solve the problem. You could also try to dump the

Bug#1006147: debconf: dpkg-reconfigure fails to restart services after #994204

2022-02-19 Thread Dave Jones
Package: debconf Version: 1.5.73 Severity: important Dear Maintainer, As part of fixing an issue with restarting services in debhelper (#994204), I proposed a patch [1] that, in certain circumstances (when --no-restart-after-upgrade is specified) moves the duty of stopping services from the

Bug#1006146: xmonad: gsd-media-keys doesn't start with gnome-flashback-xmonad session

2022-02-19 Thread Chung-chieh Shan
Package: xmonad Version: 0.15-4+b2 Severity: normal Within the last few months, gnome-flashback-xmonad stopped starting gsd-media-keys when I log in. Even when I start gsd-media-keys manually, it fails to adjust screen brightness. This turns out to fix it: cd /usr/lib/systemd/user sudo

Bug#1005813: debian-edu-config: apparmor blocks cups-browsed.conf from being read

2022-02-19 Thread Wolfgang Schweer
[ Petter Reinholdtsen, 2022-02-19 ] > [Wolfgang Schweer] > > As the symlink seems to be the problem, another solution would be to > > let cfengine copy the file instead: > > Sure. The reason a symlink was used was to ensure upgrades would take > effect. Right. In case an upgraded

Bug#1003894: fixed in h2database 2.1.210-1

2022-02-19 Thread Markus Koschany
Control: fixed -1 1.4.197-4+deb10u1 Control: fixed -1 1.4.197-4+deb11u1 signature.asc Description: This is a digitally signed message part

Bug#1006140: New version can't load old databases

2022-02-19 Thread Markus Koschany
Hi, Am Samstag, dem 19.02.2022 um 18:52 +0100 schrieb Jochen Sprickerhof: > Package: libh2-java > Version: 2.1.210-1 > Severity: important > X-Debbugs-Cc: jspri...@debian.org, Markus Koschany > Control: -1 affects mediathekview jameica hibiscus > > Hi, > > the new version of libh2-java uses a

Bug#1005884: linux-image-5.16.0-1-amd64: Kernel oops (unable to handle page fault) during boot

2022-02-19 Thread Martin Dickopp
On Sat, Feb 19, 2022 at 03:55:20PM +0100, Salvatore Bonaccorso wrote: > This is possibly the same as reported in > https://lore.kernel.org/stable/05b11936073c8d6b7a28c07cc...@stwm.de/ > where the reporter found that the culprit is ab07506b0454 ("iwlwifi: > fix leaks/bad data after failed

Bug#1006145: RM: primer3 [s390x] -- ROM; Please remove temporarily for s390x to enable testing migration

2022-02-19 Thread Andreas Tille
Package: ftp.debian.org Severity: normal Hi, it would be great if primer3 could migrate to testing. For some reason which is not fully understood the build time test fails on s390x[1]. Please remove primer3 on s390x where it is probably not used in practical applications anyway. Kind regards

Bug#1006144: pychromecast: autopkgtest regression: ModuleNotFoundError: No module named 'requests'

2022-02-19 Thread Paul Gevers
Source: pychromecast Version: 9.4.0-1 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of pychromecast the autopkgtest of pychromecast fails in testing when that autopkgtest is run with the

Bug#1006143: kas: autopkgtest regression: ModuleNotFoundError: No module named 'snack'

2022-02-19 Thread Paul Gevers
Source: kas Version: 2.6.3-1 X-Debbugs-CC: debian...@lists.debian.org Severity: serious User: debian...@lists.debian.org Usertags: regression Dear maintainer(s), With a recent upload of kas the autopkgtest of kas fails in testing when that autopkgtest is run with the binary packages of kas

Bug#1004265: buster-pu: package rsyslog/8.1901.0-1+deb10u1

2022-02-19 Thread Michael Biebl
On Sun, 23 Jan 2022 22:59:21 +0200 Adrian Bunk wrote: Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: Michael Biebl , t...@security.debian.org * CVE-2019-17041: Heap overflow in the AIX message parser.

Bug#1006121: (no subject)

2022-02-19 Thread Francesco Muzio
I do not agree, because Xine using hardware acceleration (if I don't force to disable it by setting LIBVA_DRIVER_NAME,VDPAU_DRIVER ) and playing entire sample only with a glitch. VLC must do it with the same behaviour

Bug#1005884: linux-image-5.16.0-1-amd64: Kernel oops (unable to handle page fault) during boot

2022-02-19 Thread Salvatore Bonaccorso
Hi Richard, On Sat, Feb 19, 2022 at 07:40:42PM +0100, Richard B. Kreckel wrote: > Hi, > > I'm running a AMD Ryzen 3 4300U with Radeon Graphics system and found > myself suddenly unable to boot linux-image-5.16.0-1-amd64 until a point > where I could log in. (linux-image-5.15.0-3-amd64 and

Bug#1005993: Add additional command line options

2022-02-19 Thread Oliver Sauder
Diodon is a desktop utility and not a command line tool. So far the only two things you can do from the command line is to open diodon or to open it in debug mode by setting `G_MESSAGES_DEBUG` to `all`. Both those options are documented in the man page. It would be great to have more

Bug#1001454: buster-pu: package privoxy/3.0.28-2+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Fri, 2021-12-10 at 13:00 +0100, Roland Rosenfeld wrote: > This fixes CVE-2021-44540 and CVE-2021-44543. > Since all are tagged "minor issue" in the security-tracer, I tend to > send this into the next point release of buster. > Please go ahead. Sorry for the

Bug#1004575: bullseye-pu: package mutter/3.38.6-2~deb11u2

2022-02-19 Thread Simon McVittie
On Sat, 19 Feb 2022 at 17:32:40 +, Adam D. Barratt wrote: > On Sun, 2022-01-30 at 17:45 +, Simon McVittie wrote: > > Bug fix updates from upstream gnome-3-38 branch, prompted by user > > request in #1002651. > > Please go ahead; thanks. Uploaded. smcv

Bug#1003826: buster-pu: package libjackson-json-java/1.9.13-2~deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-16 at 14:17 +0200, Adrian Bunk wrote: > * Add upstream fixes. > - Serializing types for deeply nested Maps. > - Set Secure Processing flag on DocumentBuilderFactory. > - Set setExpandEntityReferences(false). (Fixes: CVE-2019-10172) >

Bug#1003825: buster-pu: package libetpan/1.9.3-2+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-16 at 13:59 +0200, Adrian Bunk wrote: > * CVE-2020-15953: STARTTLS response injection that > affects IMAP, SMTP, and POP3. (Closes: #966647) Please go ahead. Regards, Adam

Bug#1003795: buster-pu: package evolution-data-server/3.30.5-1+deb10u2

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-16 at 00:27 +0200, Adrian Bunk wrote: > * CVE-2020-16117: Crash on malformed server response with > minimal capabilities. Please go ahead. Regards, Adam

Bug#1005694: bullseye-pu: package gtk+3.0/3.24.24-4+deb11u1

2022-02-19 Thread Simon McVittie
On Sat, 19 Feb 2022 at 17:49:13 +, Adam D. Barratt wrote: > That looks OK to me, but will need a d-i ack as gtk+3.0 builds > a udeb Since kibi confirmed that d-i doesn't actually use GTK 3, I've uploaded. smcv

Bug#1003841: buster-pu: package cimg/2.4.5+dfsg-1+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: clone -1 -2 Control: retitle -2 nmu: beads/1.1.18+dfsg-3 Control: tags -1 + confirmed On Sun, 2022-01-16 at 20:51 +0200, Adrian Bunk wrote: > * CVE-2020-25693: Fix multiple heap buffer overflows. > (Closes: #973770) > Please go ahead. > This is a headers-only library, the only

Bug#1003827: buster-pu: package wireshark/2.6.20-0+deb10u3

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-16 at 15:08 +0200, Adrian Bunk wrote: > * CVE-2021-22207: Excessive memory consumption in the MS-WSP > dissector. > (Closes: #987853) > * CVE-2021-22235: Crash in the DNP dissector. > * CVE-2021-39921: NULL pointer exception in the Modbus

Bug#995224: [Debian-med-packaging] Bug#995224: relion-cuda: FTBFS with cub 1.14

2022-02-19 Thread Sascha Steinbiss
Hi all, greetings from the Debian Med Sprint 2021! [...] > /usr/bin/nvcc -M -D__CUDACC__ > /build/relion-cuda-3.1.0/src/acc/cuda/cuda_projector_plan.cu -o >

Bug#1004055: buster-pu: package raptor2/2.0.14-1.1~deb10u2

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-01-19 at 22:30 +, Thorsten Alteholz wrote: > The attached debdiff for raptor2 fixes CVE-2020-25713 in Buster. This > CVE > is marked as no-dsa by the security team. > Please go ahead. Regards, Adam

Bug#1003842: buster-pu: package flac/1.3.2-3+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-16 at 21:03 +0200, Adrian Bunk wrote: > * CVE-2020-0499: Out of bounds read due to a heap buffer overflow. > (Closes: #977764) Please go ahead. Regards, Adam

Bug#1004050: bullseye-pu: package zziplib/0.13.62-3.3+deb11u1.debdiff

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-01-19 at 22:19 +, Thorsten Alteholz wrote: > The attached debdiff for zziplib fixes CVE-2020-18442 in Bullseye. > This > CVE is marked as no-dsa by the security team. > Please go ahead. Regards, Adam

Bug#1004249: buster-pu: package weechat/2.3-1+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 17:27 +0200, Adrian Bunk wrote: > * CVE-2020-8955: A crafted irc message 324 (channel mode) could > result in a crash. (Closes: #951289) > * CVE-2020-9759: A crafted irc message 352 (who) could result > in a crash. > *

Bug#982869: This might be related to a Fedora Bug reported on bug-datam...@gnu.org

2022-02-19 Thread Erik Auerswald
Hi, the error message the test matches on occurs only once in the GNU datamsh sources. That same line has resulted in a build failure on Fedora for the armv7hl platform[1], which is 32bit. I have suggested two possible fixes[2], but cannot test them, since I do not have an ARM system for build

Bug#1004267: buster-pu: package libpcap/1.8.1-6+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 23:07 +0200, Adrian Bunk wrote: > * CVE-2019-15165: Improper PHB header length validation. > (Closes: #941697) Please go ahead. Regards, Adam

Bug#1004261: buster-pu: package opensc/0.19.0-1+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 20:21 +0200, Adrian Bunk wrote: > * CVE-2019-15945: Out-of-bounds access of an ASN.1 Bitstring. > (Closes: #939668) > * CVE-2019-15946: Out-of-bounds access of an ASN.1 Octet string. > (Closes: #939669) > * CVE-2019-19479: Incorrect

Bug#1004265: buster-pu: package rsyslog/8.1901.0-1+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 22:59 +0200, Adrian Bunk wrote: > * CVE-2019-17041: Heap overflow in the AIX message parser. > (Closes: #942067) > * CVE-2019-17042: Heap overflow in the Cisco log message parser. > (Closes: #942065) Please go ahead. Regards, Adam

Bug#1004268: buster-pu: package libextractor/1:1.8-2+deb10u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 23:15 +0200, Adrian Bunk wrote: > * CVE-2019-15531: Invalid read for malformed DVI files. > (Closes: #935553) The reformatting in the patch makes things rather noisier than they need be, given that so far as I can tell the actual changes

Bug#1005218: buster-pu: package spip/3.2.4-1+deb10u6

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Wed, 2022-02-09 at 03:31 -0400, David Prévot wrote: > Two security issues (XSS) have been fixed in the latest upstream > version. As agreed with the security team, those are not worth a DSA. > > [ Impact ] > Without these fixes, websites are vulnerable to already

Bug#1002051: bullseye-pu: package heartbeat/1:3.0.6-11+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2021-12-21 at 00:27 +0100, Valentin Vidic wrote: > heartbeat deamon starts correctly after installation, but not > after reboot because of missing /run/heartbeat directories. > The change reintroduces a tempfiles configuration for creating > the required

Bug#1001740: bullseye-pu: package fcitx5-chinese-addons/5.0.4-1+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Tue, 2021-12-14 at 20:39 -0500, Boyuan Yang wrote: > Currently the table input methods provided by fcitx5-table (in > src:fcitx5- > chinese-addons) will not work due to missing dependencies on fcitx5- > module- > pinyinhelper and fcitx5-module-punctuation. This is

Bug#1004459: bullseye-pu: package lxc/1:4.0.6-2+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Thu, 2022-01-27 at 21:32 -0300, Antonio Terceiro wrote: > This update fixes the download of container images using the > "download" > template. pool.sks-keyservers.net is not active anymore, so the patch > (already included in the upstream release present in

Bug#1005813: debian-edu-config: apparmor blocks cups-browsed.conf from being read

2022-02-19 Thread Petter Reinholdtsen
[Wolfgang Schweer] > As the symlink seems to be the problem, another solution would be to > let cfengine copy the file instead: Sure. The reason a symlink was used was to ensure upgrades would take effect. Perhaps dpkg-divert can be used? I have vague memories of divert on conffiles being a

Bug#1004247: bullseye-pu: package weechat/3.0-1+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-23 at 17:18 +0200, Adrian Bunk wrote: > * CVE-2021-40516: A crafted WebSocket frame could result in a crash > in the Relay plugin. (Closes: #993803) Please go ahead. Regards, Adam

Bug#1003765: bullseye-pu: package node-markdown-it/10.0.0+dfsg-2+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sat, 2022-01-15 at 12:52 +0100, Yadd wrote: > [ Reason ] > node-markdown-it is vulnerable to regex denial of service > (CVE-2022-21670) > Please go ahead. Regards, Adam

Bug#1005884: linux-image-5.16.0-1-amd64: Kernel oops (unable to handle page fault) during boot

2022-02-19 Thread Richard B. Kreckel
Hi, I'm running a AMD Ryzen 3 4300U with Radeon Graphics system and found myself suddenly unable to boot linux-image-5.16.0-1-amd64 until a point where I could log in. (linux-image-5.15.0-3-amd64 and previous versions all had worked fine.) After reading your link

Bug#1005694: bullseye-pu: package gtk+3.0/3.24.24-4+deb11u1

2022-02-19 Thread Cyril Brulebois
Hi, Adam D. Barratt (2022-02-19): > Thanks. That looks OK to me, but will need a d-i ack as gtk+3.0 builds > a udeb; tagging and CCing accordingly. d-i in bullseye is still on gtk2 (sorry), so gtk3 should be a no-brainer. :) Cheers, -- Cyril Brulebois (k...@debian.org)

Bug#1006121: (no subject)

2022-02-19 Thread Sebastian Ramacher
Control: reassign -1 mesa-va-drivers 20.3.5-1 On 2022-02-19 18:38:32 +0100, Francesco Muzio wrote: > gdb stack trace of the crash: > > Thread 25 "vlc" received signal SIGSEGV, Segmentation fault. > [Switching to Thread 0x7fffbc7fb700 (LWP 9949)] > 0x7fffab507cb3in ??() from

Bug#1004921: libtsm: Package too old for kmscon

2022-02-19 Thread Victor Westerhuis
Source: libtsm Followup-For: Bug #1004921 -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Aetf has released version 4.0.2 of their fork. I have updated the version in my Salsa repository as well. -BEGIN PGP SIGNATURE- iQJHBAEBCAAxFiEE6OxII3T+o0Ujs6ECQz2Rq5dHQPsFAmIRLJoTHHZpY3RvckB3

Bug#1003548: transition: libwebp

2022-02-19 Thread Sebastian Ramacher
On 2022-02-18 10:26:26 +0100, Sebastian Ramacher wrote: > On 2022-02-16 20:49:44, Jeff Breidenbach wrote: > > libwebp 1.2.1-7 has been successfully uploaded to unstable. > > > > Anthony and Iustin, help is very strongly appreciated for the NMUs. > > Almost all reverse dependencies have

Bug#1006141: supertuxkart: FTBFS on armhf: Error: selected FPU does not support instruction -- `vldmia.64 r10,{d0-d7}'

2022-02-19 Thread Sebastian Ramacher
Source: supertuxkart Version: 1.3+dfsg1-2 Severity: serious Tags: ftbfs sid bookworm Justification: fails to build from source (but built successfully in the past) X-Debbugs-Cc: sramac...@debian.org supertuxkart FTBFS on armhf: [ 26%] Building ASM object

Bug#1005813: debian-edu-config: apparmor blocks cups-browsed.conf from being read

2022-02-19 Thread Wolfgang Schweer
[ Holger Levsen, 2022-02-19 ] > On Tue, Feb 15, 2022 at 07:20:01PM +, Mike Gabriel wrote: > > Solution 2: > > --- > > Ask the cups src:pkg maintainers to add a line > > /etc/cups/cups-browsed-debian-edu.conf to their > > /etc/appamor.d/usr.sbin.cups-browsed apparmor profile. > > to me

Bug#1005841: debian-edu-config: No TJENER print queues appearing on Debian Edu clients, print queues named not like queue name on TJENER

2022-02-19 Thread Wolfgang Schweer
[ Mike Gabriel, 2022-02-16 ] > The problem is that I think that the cups-browsing (or more strictly spoken > cups-browsed-debian-edu.conf) never got really fully tested, because > cups-browsed fails/failed to read cups-browsed-debian-edu.conf due to > apparmor blocking. Right. > On normal

Bug#1003188: bullseye-pu: package mmdebstrap/0.7.5-2.2

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + moreinfo On Wed, 2022-01-05 at 20:28 +0100, Johannes Schauer Marin Rodrigues wrote: > Currently, when a user happens to have an ASCII armored key in > /etc/apt/trusted.gpg.d, running mmdebstrap without any special > options > will not work. See #1003175 for details. > > The

Bug#1006122: Provide a live image with enlightenment for a smaller image

2022-02-19 Thread Andrew M.A. Cater
On Sat, Feb 19, 2022 at 07:28:46PM +0530, Pirate Praveen wrote: > Package: debian-cd > Severity: wishlist > > Currently all images except the standard image is >= 3.0 GB. I think > providing a smaller graphical image with enlightenment (or icewm or wmaker > or even all three together) to provide

Bug#1006000: transition: draco

2022-02-19 Thread Sebastian Ramacher
Control: tags -1 confirmed Control: forwarded -1 https://release.debian.org/transitions/html/auto-draco.html On 2022-02-18 20:06:20 +0100, Timo Röhling wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: transition > > Dear release

Bug#1003058: bullseye-pu: package openvswitch/2.15.0+ds1-2

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2022-01-03 at 14:25 +0100, Thomas Goirand wrote: > [ Reason ] > Indeed, the updated version I would like to push contains a fix for > CVE-2021-36980 (Debian bug #991308), and a fix for having libofproto > properly installed if activating dpdk (which fixes

Bug#1003018: bullseye-pu: package php-laravel-framework/6.20.14+dfsg-2+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Sun, 2022-01-02 at 21:10 +0100, Robin Gustafsson wrote: > [ Reason ] > Security issues affecting the version in bullseye. > * Bug #1001333 (CVE-2021-43808) > * Bug #1002728 (CVE-2021-43617) > > [ Impact ] > * Users of web applications using certain templating

Bug#1002703: bullseye-pu: package libarchive/3.4.3-2+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2021-12-27 at 22:10 +0200, Peter Pentchev wrote: > This is a future unblock request before I upload > libarchive-3.4.3-2+deb11u1 to fix a couple of bugs that were > fixed in later upstream versions and in unstable. They are all > related to setting permissions

Bug#1003484: bullseye-pu: package openssl/1.1.1m-0+deb11u1

2022-02-19 Thread Adam D. Barratt
On Sat, 2022-02-19 at 18:52 +0100, Sebastian Andrzej Siewior wrote: > On 2022-02-19 17:04:16 [+], Adam D. Barratt wrote: > > Control: tags -1 + confirmed d-i > … > > Thanks. Assuming the above is still accurate, then this looks good > > to > > me. > > > > As the package builds a udeb, it will

Bug#1002685: bullseye-pu: package prips/1.1.1-3+deb11u1

2022-02-19 Thread Adam D. Barratt
Control: tags -1 + confirmed On Mon, 2021-12-27 at 13:21 +0200, Peter Pentchev wrote: > This is a future unblock request before I upload prips-1.1.1- > 3+deb11u1 > to fix two upstream bugs that affect the base functionality of the > program: > an infinite loop if it is asked to print the

  1   2   >