Bug#1036740: closed by Markus Koschany (Re: Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with valid metadata)

2023-06-03 Thread Salvatore Bonaccorso
Hi Daniel, On Sat, Jun 03, 2023 at 02:56:00PM -0700, Daniel Markstedt wrote: > > -- Forwarded message -- > > From: Markus Koschany > > To: Daniel Markstedt , 1036740-d...@bugs.debian.org > > Cc: debian-...@lists.debian.org > > Bcc: > > Date: Thu, 01 Jun 2023 19:54:55 +0200 > >

Bug#1033341: org-mode: CVE-2023-28617

2023-06-03 Thread Salvatore Bonaccorso
Hi, On Sat, Jun 03, 2023 at 10:02:43PM -0400, Nicholas D Steeves wrote: > fixed 1033341 org/mode/9.5.2+dfsh-5 > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 > thanks > > Dear Salvatore and Security Team, > > Salvatore Bonaccorso writes: > > > Source: org-mode > > Version: 9.5.2+dfsh-4 > >

Bug#1037083: wget: man page lists 'metalink' options but binary not compiled with metalink support

2023-06-03 Thread Stuart Prescott
Package: wget Version: 1.21.3-1+b2 Severity: minor X-Debbugs-Cc: stu...@debian.org Dear Maintainer, A user in #debian on irc.debian.org was asking about how to use wget to download from metalink files. The man page describes the following metalink options: --input-metalink=file

Bug#1035949: mariadb: upgrade issue: mariadb-server-10.5 fails to stop after all other -10.5 packages were removed

2023-06-03 Thread Otto Kekäläinen
Indeed the transitional mariadb-server-10.5 fixes the issue. What do you Andreas suggest we do now? It is already past freeze for Bookworm, and this is not just a small fix but also introduces a new package (albeit transitional). Let me know how you want to proceed and I can immediately tomorrow

Bug#1036657: bridge-utils: inconsistent IPv6 local-link between Ethernet and WiFi

2023-06-03 Thread Martin-Éric Racine
On Sat, Jun 3, 2023 at 8:59 PM Santiago Garcia Mantinan wrote: > > > In Bullseye, Ethernet cards did not have any IPv6 local-link, while Wifi > > adapters did. In Bookworm, it the opposite. > > Wifi is very dependant on how you configure it, but as you say, now on > bookworm you are not getting

Bug#1037082: unblock: kanboard/1.2.26+ds-3

2023-06-03 Thread Joseph Nahmias
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: kanbo...@packages.debian.org, j...@nahmias.net Control: affects -1 + src:kanboard Please unblock package kanboard [ Reason ] Security fix only for CVE-2023-32685 from

Bug#907495: please ship the x11idle binary

2023-06-03 Thread Nicholas D Steeves
Control: tag -1 pending Sébastien Delafond writes: > On 27/03 09:26, Michal Politowski wrote: >> Actually I think there is no need to compile x11idle. As the footnote >> https://orgmode.org/manual/Resolving-idle-time.html#DOCF82 says, >> Debian already provides xprintidle, which seems to work

Bug#1030015: elpa-powerline: lot's of warning when starting emacs

2023-06-03 Thread Gerald Turner
There is a patch in the upstream github project, merged to master branch, but not released: https://github.com/milkypostman/powerline/pull/194 -- Gerald Turner Encrypted mail preferred! OpenPGP: 4096R / CA89 B27A 30FA 66C5 1B80 3858 EC94 2276 FDB8 716D signature.asc Description:

Bug#733061: Bug#734435: notmuch-emacs: Emacs cannot load package notmuch

2023-06-03 Thread Nicholas D Steeves
Ben Finney writes: > found 734435 notmuch-emacs/0.17-3 > found 733061 emacsen-common/2.0.7 > thanks > > On 07-Jan-2014, Olivier Berger wrote: >> I get, in *Messages* : >> Loading /etc/emacs/site-start.d/50notmuch.el (source)... >> Package notmuch not fully installed. Skipping setup. >> >> and

Bug#1033341: org-mode: CVE-2023-28617

2023-06-03 Thread Nicholas D Steeves
fixed 1033341 org/mode/9.5.2+dfsh-5 fixed 1033341 org-mode/9.6.6+dfsg-1~exp1 thanks Dear Salvatore and Security Team, Salvatore Bonaccorso writes: > Source: org-mode > Version: 9.5.2+dfsh-4 > Severity: important > Tags: security upstream > X-Debbugs-Cc: car...@debian.org, Debian Security Team

Bug#1036359: crashes with (wrong-type-argument consp nil)

2023-06-03 Thread Nicholas D Steeves
Nicholas D Steeves writes: > I also confirmed that both the patched version (in the staging branch) > and unpatched version (in bookworm) work correctly with > > > https://gitlab.torproject.org/tpo/tpa/team/-/wikis/policy/tpa-rfc-36-gitolite-gitweb-retirement.md > > when one loads markdown-toc

Bug#1035115: fixed in gpaste 43.2-1

2023-06-03 Thread Amr Ibrahim
On Sun, 30 Apr 2023 09:33:54 + Debian FTP Masters wrote: > Source: gpaste > Source-Version: 43.2-1 > Done: Jérémy Lal > Closes: 1035115 > Changes: >  gpaste (43.2-1) unstable; urgency=medium >  . >    * New upstream version 43.2 >  Closes: #1035115. Avoid crash under heavy memory load > 

Bug#1037081: auto-apt-proxy: detect_apt_cacher_ng fails when behind a proxy/load balancer that modifies HTTP status line

2023-06-03 Thread David Nesting
Package: auto-apt-proxy Version: 14.1 Severity: normal X-Debbugs-Cc: david.nest...@gmail.com Dear Maintainer, When running auto-apt-proxy behind something (like Envoy) that does not preserve the HTTP status line, detect_apt_cacher_ng does not find its expected "406 Usage Information" HTTP

Bug#1037080: expat: Building with profile nodoc (stage1) fails

2023-06-03 Thread Henry N.
Source: expat Version: 2.5.0-1 Severity: normal Tags: ftbfs patch Usertags: rebootstrap Dear Maintainer, building expat from source with profile nodocs fails. # dpkg-buildpackage -B -Pnodoc -uc -us ... dh_fixperms -a chmod 644

Bug#1036740: closed by Markus Koschany (Re: Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with valid metadata)

2023-06-03 Thread Daniel Markstedt
> -- Forwarded message -- > From: Markus Koschany > To: Daniel Markstedt , 1036740-d...@bugs.debian.org > Cc: debian-...@lists.debian.org > Bcc: > Date: Thu, 01 Jun 2023 19:54:55 +0200 > Subject: Re: Bug#1036740: Fix for CVE-2022-23123 causes afpd segfault with > valid metadata >

Bug#1037079: unblock: configobj/5.0.8-2

2023-06-03 Thread Stefano Rivera
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: config...@packages.debian.org Control: affects -1 + src:configobj Please unblock package configobj [ Reason ] Resolves a (minor) security issue. The patch only became

Bug#1037019: [Pkg-utopia-maintainers] Bug#1037019: network-manager requires rfkill but that is not in the apt dependencies

2023-06-03 Thread Michael Biebl
Control: tags -1 + moreinfo Where exactly does NetworkManager require the rfkill binary? Studying the sources, I only see NM using the /dev/rfkill kernel interface via udev. Michael OpenPGP_signature Description: OpenPGP digital signature

Bug#1037078: unblock: dh-python/5.20230603

2023-06-03 Thread Stefano Rivera
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: dh-pyt...@packages.debian.org, pi...@debian.org Control: affects -1 + src:dh-python Please unblock package dh-python [ Reason ] Re-adds some Breaks+Replaces to help upgrade

Bug#1035949: mariadb: upgrade issue: mariadb-server-10.5 fails to stop after all other -10.5 packages were removed

2023-06-03 Thread Otto Kekäläinen
I adjusted your patch a bit as it didn't apply cleanly and pushed it to https://salsa.debian.org/mariadb-team/mariadb-server/-/merge_requests/47 to replace the transitional mariadb-client-10.5 I had earlier. Thanks for diving deep in piuparts testing for MariaDB 10.11 and for the patch! Ideally

Bug#1037042: graphicsmagick: GetImageDepth has a thread arena and memory leak

2023-06-03 Thread Bob Friesenhahn
I am definitely able to confirm that memory consumption builds due to invoking GetImageDepth() via a POSIX thread. The rate that it builds is image sensitive since some images cause GetImageDepth() to perform more OpenMP loops. In /proc/PID/smaps I see multiple memory-mapped regions

Bug#1036657: bridge-utils: inconsistent IPv6 local-link between Ethernet and WiFi

2023-06-03 Thread Santiago Garcia Mantinan
> In Bullseye, Ethernet cards did not have any IPv6 local-link, while Wifi > adapters did. In Bookworm, it the opposite. Wifi is very dependant on how you configure it, but as you say, now on bookworm you are not getting IPv6 on them, so... let's go for ethernet cards... on my machines I don't

Bug#1035543: init-system-helpers: new systemd units may not get enabled on upgrades from bullseye if systemd is installed

2023-06-03 Thread Michael Biebl
Am 01.06.23 um 13:44 schrieb James Addison: Would reverting the Install.WantedBy modification[1][2], restoring e2scrub_reap enablement using 'default.target' on relevant systems, be a sensible approach for bookworm until we can figure out the debhelper-system behaviour when that setting

Bug#1034387: update youtube-dl control file to reflect transitional package

2023-06-03 Thread Jesse Rhodes
Control: retitle -1 update youtube-dl control file to reflect transitional package Control: tags -1 patch thanks Hi, The debian/control fields for youtube-dl still have a lot of leftover information from when it was a binary package, which should be cleaned up to reflect what the package

Bug#1037077: tryton-modules-account-payment-sepa: Non-free xsd schemas

2023-06-03 Thread Mathias Behrle
Control: forwarded -1 https://foss.heptapod.net/tryton/tryton/-/issues/12304 Control: severity -1 normal > Source: tryton-modules-account-payment-sepa > Version: 5.0.1-2 > Severity: serious > > The tests/*.xsd files are non-free. They are probably distributed under terms > specified at

Bug#1036268: gnome-shell: Session crashes, thrown out to login screen, after the session has been idle & screen switched off

2023-06-03 Thread Amr Ibrahim
Am Samstag, dem 03.06.2023 um 17:01 +0200 schrieb Amr Ibrahim: > Am Samstag, dem 27.05.2023 um 21:32 +0100 schrieb Simon McVittie: > > > > What is logged in the systemd journal when this crash occurs? > > log.txt (after the crash) is attached. Attached are the all-log and important-log from

Bug#1036268: gnome-shell: Session crashes, thrown out to login screen, after the session has been idle & screen switched off

2023-06-03 Thread Amr Ibrahim
Am Samstag, dem 27.05.2023 um 21:32 +0100 schrieb Simon McVittie: > > What is logged in the systemd journal when this crash occurs? log.txt (after the crash) is attached. > A backtrace from the crash would be very useful information for this or any > other crash. Please see

Bug#1036957: unblock: openssl/3.0.9-1

2023-06-03 Thread Cyril Brulebois
Hi, Paul Gevers (2023-05-31): > Can you have a look at this onblock request? It's blocked on your > block-udeb. Sorry for the delay; finally run some checks combining openssl and libselinux binaries, everything looks good. unblock-udeb in place, leaving monitoring and closing up to you.

Bug#1037077: tryton-modules-account-payment-sepa: Non-free xsd schemas

2023-06-03 Thread Bastian Germann
Source: tryton-modules-account-payment-sepa Version: 5.0.1-2 Severity: serious The tests/*.xsd files are non-free. They are probably distributed under terms specified at https://www.iso20022.org/intellectual-property-rights or https://www.iso20022.org/terms-use Modified distribution is not

Bug#967921: dracut-core: cryptsetups tmpfile

2023-06-03 Thread Laszlo
Hello, Upstream dracut fix - https://github.com/dracutdevs/dracut/commit/a4cc196467e45f093fab7876c1c6b40798058920 This fix is now included in sid: https://packages.debian.org/sid/dracut-core Perhaps this issue can now be closed. Thanks, Laszlo

Bug#1036713: unblock: xserver-xorg-video-geode/2.11.21-1

2023-06-03 Thread Martin-Éric Racine
On Thu, Jun 1, 2023 at 9:49 AM Paul Gevers wrote: > > control: tags -1 moreinfo > > On 24-05-2023 18:44, Martin-Éric Racine wrote: > > 1) Ensure build from source on recent autoconf. > > What does this mean? Does it now FTBFS? (I checked on reproducible > builds, but that doesn't seem to be the

Bug#769895: init-system-helpers: deb-systemd-helper should remove timestamps on timer unit purge

2023-06-03 Thread Alexandre Detiste
Hi, Some functionality has since been implemented upstream in systemd (namely "systemd clean") but I can't get to work. https://github.com/systemd/systemd/issues/4930 https://github.com/systemd/systemd/commit/89f6fe7b303875307e201449d9d821cdbb9eacac How to reproduce: install for example

Bug#1037076: unblock: dhcpcd5/9.4.1-24

2023-06-03 Thread Martin-Éric Racine
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock X-Debbugs-Cc: dhcp...@packages.debian.org Control: affects -1 + src:dhcpcd5 -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Please unblock package dhcpcd5 [ Reason ] Removed unnecessary

Bug#1037042: graphicsmagick: GetImageDepth has a thread arena and memory leak

2023-06-03 Thread Bob Friesenhahn
I did manage to get the test program compiled on my PC (a laptop). It was challenging since the source code (extracted from email) seemed to have hidden characters in it that the C compiler did not like. I do see the reported RSS very gradually creeping up. It seems to go up and then go back

Bug#999850: More progress

2023-06-03 Thread Jelmer Vernooij
I've gotten a little bit further on this: Now packaged in unstable: * cargo-options * pep440_rs * quoted-printable In NEW: * pep508_rs * python-project In the process of being packaged (in debcargo-conf, not yet uploaded): * python-pkginfo * charset * mailparse * rfc2047-decoder

Bug#1037075: diffoscope: Get's killed trying to diff 2 large images (> 5GB)

2023-06-03 Thread Evangelos Ribeiro Tzaras
I forgot to add how to build the images: On Sat, 03 Jun 2023 14:08:12 +0200 Evangelos Ribeiro Tzaras wrote: > Package: diffoscope > Version: 242 > Severity: normal > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Dear Maintainer, > > I was trying to see if Mobian images build for the

Bug#1037075: diffoscope: Get's killed trying to diff 2 large images (> 5GB)

2023-06-03 Thread Evangelos Ribeiro Tzaras
: > $ ls -l l5-phosh-{1,2}/mobian-librem5-phosh-20230603.img - -rw-r--r-- 1 fortysixandtwo fortysixandtwo 60 Jun 3 06:22 l5-phosh-1/mobian-librem5-phosh-20230603.img - -rw-r--r-- 1 fortysixandtwo fortysixandtwo 60 Jun 3 06:45 l5-phosh-2/mobian-librem5-phosh-20230603.

Bug#932957: release-notes: document how to make the rescue mode usable if no root password is set (buster)

2023-06-03 Thread James Addison
unarchive 977358 reopen 977358 blocks 977358 by 952450 Although this was documented for bullseye, the underlying cause remains, and I think that it could be valuable for users to continue to have this documentation available. I've tested that the previously-added guidance from the bullseye

Bug#773385: Ping

2023-06-03 Thread Niels Thykier
Dima Kogan: This really should work. It's maybe sorta ok for "apt-file list", but it also affects "apt-file find". Look: [...] I.e. I asked it to tell me what package provides a file, and I had to tell it which architecture to look at. The whole point of apt-file is to look up the package

Bug#1036799: sylpheed: unable to send or read email after upgrading to Debian 12

2023-06-03 Thread Ricardo Mones
control: severity -1 important control: tags -1 confirmed control: forwarded -1 https://www.sraoss.jp/pipermail/sylpheed/2023-May/007127.html Hi José Luis, On Fri, 26 May 2023 17:46:44 +0200 José Luis González wrote: > Package: sylpheed > Version: 3.8.0~beta1-1 > Severity: grave > > After

Bug#1037074: upower.service failed to start with exit-code

2023-06-03 Thread Michael Müller
Package: upower Version: 0.99.20-2 Severity: normal X-Debbugs-Cc: tuxp...@web.de Dear Maintainer, upower.service fails to start by systemd. systemd[1]: upower.service: Start request repeated too quickly. systemd[1]: upower.service: Failed with result 'exit-code'. systemd[1]: Failed to start

Bug#1037073: proot: New upstream version available: 5.4.0 - 2023-05-13

2023-06-03 Thread Teodor Milkov
Package: proot Version: 5.1.0-1.3 Severity: normal Dear Maintainer, There's a new upstream version of proot with several fixes and enhancements. For example, proot 5.1.0 that's currently included doesn't recognize the statx() syscall, so "ls" doesn't work with it. -- System Information:

Bug#952450: user-setup: set SYSTEMD_SULOGIN_FORCE=1 in env for rescue/emergency.service when root account is locked

2023-06-03 Thread James Addison
Followup-For: Bug #952450 X-Debbugs-Cc: 1035...@bugs.debian.org, ty...@mit.edu As an experiment, I recently updated a functional Debian bookworm system to boot into the systemd 'rescue.target' by default, to test the single-user / recovery experience as part of #1035543 bug assessment. My

Bug#1037064: maven-verifier depends on downloading sources at build time

2023-06-03 Thread gregor herrmann
On Fri, 02 Jun 2023 21:40:10 -0700, Steve Langasek wrote: > While this is not a build failure, it does mean building the package has a > dependency on software outside of main, which I believe is a serious policy > violation. The network access during build is a policy violation in itself:

Bug#1037071: ncurses: get rid of debian/rxvt.ti

2023-06-03 Thread Sven Joachim
Source: ncurses Version: 6.4-4 Severity: wishlist For historical reasons, Debian has forked off the rxvt* terminfo entries, which are built from a separate file debian/rxvt.ti. This file has rarely seen any updates, and I think it is time to get rid of it, considering that rxvt got superseded by

Bug#1036751: RFS: mini-httpd/1.30-4 [ITA] -- Small HTTP server

2023-06-03 Thread Alexandru Mihail
Hi, Thanks everyone for the input ! Indeed the forking service type is the correct one for this package as daemon() is called as part of the initialization sequence. (if daemon() is not available, plain fork() is called anyway) I've adjusted debian/rules, taking into consideration Lorenzo's

Bug#1037070: RFP: libx1000 -- provides a dynamically-linked workaround for the LOCK prefix bug on Intel X1000 devices

2023-06-03 Thread James Addison
Package: wnpp Severity: wishlist * Package name: libx1000 Version : 0.0.0 Upstream Contact: Ray Kinsella * URL : http://ashroe.eu/x1000/2016/10/21/fixing-lock-prefix-on-x1000.html * License : LGPLv2.1 Programming Lang: C Description : provides a

Bug#1035971: linux-image-6.3.0-0-amd64: IRQ warnings from amdgpu Navi 33 / Radeon RX 7700S ...

2023-06-03 Thread Nathan Schulte
This patch, which now seems upstreamed, does not seem to resolve the IRQ warnings for me. Tried 6.3.5, and 6.4-rc4, and they persist. On Thu, May 18, 2023 at 6:26 AM Diederik de Haas wrote: > > On Thursday, 18 May 2023 13:19:52 CEST Diederik de Haas wrote: > > I _think_ I got the right commit

Bug#1035081: RFC: onnxruntime packaging

2023-06-03 Thread Dylan Aïssi
Hello, I have finalized [1] the package of onnxruntime and have sent it to the NEW queue [2]. I only enabled features I need. A review and/or improvements are welcome :-). Best, Dylan [1] https://salsa.debian.org/deeplearning-team/onnxruntime [2]

Bug#1037069: Netpbm library documentations not been installed to any package

2023-06-03 Thread Torrekie
Package: libnetpbm-dev Source: netpbm-free Version: 2:11.01.00-2 Severity: minor In netpbm-free source package there do present `libnetpbm11-dev.docs` and `libnetpbm11-dev.manpages`, but libnetpbm11-dev was not defined in control file, which causing all netpbm man3 hasn't been installed to any

Bug#1036911: libpsm_infinipath alternative is incompatible with Multi-Arch

2023-06-03 Thread Roland Fehrenbacher
Hi Helmut, Étienne, your plan is fine with me. The expected number of users installing both implementations is definitely low. I have no objection if you do an NMU once your patch is complete. Thanks, Roland On 5/29/23 12:27, Helmut Grohne wrote: Package:

Bug#1037068: sysrepo: world-writable /etc/sysrepo/* after upgrade from 1.4.70-4 in bullseye

2023-06-03 Thread Andreas Beckmann
Package: sysrepo Version: 2.0.53-6 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package has world-writable configutation files after upgrading from 1.4.70-4 in bullseye to 2.0.53-6 in sid. >From the attached log (scroll to

Bug#1037067: libocct-data-exchange-dev,libocct-foundation-dev: both ship /usr/lib/x86_64-linux-gnu/libTKXDE.so

2023-06-03 Thread Andreas Beckmann
Package: libocct-data-exchange-dev,libocct-foundation-dev Version: 7.7.1+dfsg1-1~exp1 Severity: serious User: debian...@lists.debian.org Usertags: piuparts Hi, during a test with piuparts I noticed your package failed to install because it tries to overwrite other packages files without

Bug#1037058: mergerfs: Mounting as non-root user fails with EPERM due to missing setuid bit

2023-06-03 Thread Patrice Duroux
Hi, Just a small remark about a similar case with glusterfs-client also providing its own fusermount command: $ ls -lt /usr/bin/fusermount-glusterfs -rwxr-xr-x 1 root root 34976 24 mai 10:48 /usr/bin/fusermount-glusterfs* (no setuid here) There is a closed upstream issue:

Bug#1035748: marked as done (unblock: modsecurity/3.0.9-1)

2023-06-03 Thread Salvatore Bonaccorso
Hi Paul, On Sat, Jun 03, 2023 at 06:12:04AM +, Debian Bug Tracking System wrote: [...] > > Hi, > > On 02-06-2023 22:50, Ervin Hegedüs wrote: > > And these are the generated lines: > > > > https://github.com/SpiderLabs/ModSecurity/blob/v3/master/src/parser/Makefile.am#L36-L42 > > And

Bug#1035542: libreswan: CVE-2023-30570: Incorrect aggressive mode interaction causes the pluto daemon to crash

2023-06-03 Thread Salvatore Bonaccorso
Hi Daniel, On Fri, Jun 02, 2023 at 06:59:35PM -0400, Daniel Kahn Gillmor wrote: > Hi Salvatore-- > > On Fri 2023-06-02 21:20:50 +0200, Salvatore Bonaccorso wrote: > > Thanks for having a closer look and for your assessment. Then I > > believe we can have a fix scheduled via respective point

Bug#1037066: ITP: in-place -- In-place file processing with Python

2023-06-03 Thread Edward Betts
Package: wnpp Severity: wishlist Owner: Edward Betts X-Debbugs-Cc: debian-de...@lists.debian.org, debian-pyt...@lists.debian.org * Package name: in-place Version : 0.5.0 Upstream Author : John Thorvald Wodder II * URL : https://github.com/jwodder/inplace * License