Bug#795836: fixed in qpsmtpd 0.84-11+deb8u1

2016-01-20 Thread Devin Carraway
The release team have accepted it for the next Jessie point release: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=802851 https://release.debian.org/proposed-updates/stable.html http://ftp.debian.org/debian/dists/jessie-proposed-updates/qpsmtpd_0.84-11+deb8u1_amd64.changes -- Devin \

Bug#802851: jessie-pu: package qpsmtpd/0.84-11

2015-11-11 Thread Devin Carraway
since 0.66 from oldstable has the +opposite compatibility problem + + -- Devin Carraway <de...@debian.org> Sat, 24 Oct 2015 07:27:50 + + qpsmtpd (0.84-11) unstable; urgency=low * Add Japanese debconf translation; thanks to victory (Closes: diff -Nru qpsmtpd-0.84/debian/contro

Bug#802851: jessie-pu: package qpsmtpd/0.84-11

2015-10-24 Thread Devin Carraway
Package: release.debian.org Severity: normal Tags: jessie User: release.debian@packages.debian.org Usertags: pu I propose a patch to qpsmtpd in jessie-proposed-updates; this is a one-line patch to address a compatibility breaking API change introduced in libnet-dns-perl 0.81. The effect of

Bug#795836: qpsmtpd: Net::DNS::Header::nextid undefined at /usr/bin/qpsmtpd-forkserver

2015-10-23 Thread Devin Carraway
It is; I'm planning to roll a new package this weekend. Sorry for the delay. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 4096R/9197B5F9: 9C64 37CD 1B7B 029D 0933 49EA 1E52 7672 9197 B5F9 signature.asc Description: Digital signature

Bug#776522: selinux-policy-default: unconfined_t can't use/upgrade gpg-agent

2015-01-28 Thread Devin Carraway
Package: selinux-policy-default Version: 2:2.20140421-7 Severity: normal unconfined_t doesn't seem able to touch gpg_agent_exec_t; this blocks its use, but also prevents dpkg from upgrading gnupg-agent, and thus blocks installation of gnupg2: root@atlantic:/etc/selinux/local# id -Z

Bug#740591: selinux-policy-default: postgresql manpages unlabeled, preventing indexing by mand

2014-03-03 Thread Devin Carraway
] Permission denied: u'/etc/selinux/default/modules/active/file_contexts.local' -- no debconf information commit 00fb07499077baa3cb97764fdb3453ba86e13fb4 Author: Devin Carraway g...@devin.com Date: Mon Mar 3 01:34:08 2014 -0800 Label postgresql manpages under Debian diff --git a/policy/modules

Bug#738946: [DSE-Dev] Bug#738946: selinux-policy-default: Bind's ndc_t denied block_suspend on epollwakeup

2014-02-21 Thread Devin Carraway
This is possibly being triggered by an inherent quirk of ISC's libraries; since host(1) triggers it too, even from unconfined_t: type=AVC msg=audit(1392969683.579:1590): avc: denied { block_suspend } for pid=14446 comm=host capability=36

Bug#739590: selinux-policy-default: ssh bind9 broken by removal of hotplug script initrc labelling

2014-02-20 Thread Devin Carraway
Package: selinux-policy-default Version: 2:2.20140206-1 Severity: important On a jessie system with refpolicy 2:2.20140206-1, and allow-hotplug set on the primary network interface, sshd is left running in udev_t, breaking it thoroughly (and in fact flooding the logs with socket errors until the

Bug#739590: [DSE-Dev] Bug#739590: selinux-policy-default: ssh bind9 broken by removal of hotplug script initrc labelling

2014-02-20 Thread Devin Carraway
On Thu, Feb 20, 2014 at 10:15:54AM +0100, Laurent Bigonville wrote: Could you please attach the AVC denials to the bug. Sure, here you are -- this was taken in permissive mode obviously. The openssh-server command referred to in the first ssh-related denial is

Bug#739590: [DSE-Dev] Bug#739590: selinux-policy-default: ssh bind9 broken by removal of hotplug script initrc labelling

2014-02-20 Thread Devin Carraway
On Thu, Feb 20, 2014 at 12:28:43AM -0800, Devin Carraway wrote: I'll test out restoring the labelling and see if there's more to this. Slightly more -- udev_t also lost the ability to transition to initrc_t, which it will do in the old wheezy refpolicy. Labelling /etc/network/if-*d

Bug#739150: selinux-policy-default: Nonfunctional courier_exec_t domain breaks courier-pop

2014-02-16 Thread Devin Carraway
Package: selinux-policy-default Version: 2:2.20140206-1 Severity: normal The courier suite uses a series of daemons that start one another at various stages in startup and authentication (e.g. a logger starts a tcpd which starts an authentication wrapper which starts an actual imapd). The same

Bug#738950: selinux-policy-default: mailman qrunner starting in initrc_t

2014-02-14 Thread Devin Carraway
Package: selinux-policy-default Version: 2:2.20140206-1 Severity: normal mailman's qrunner and friends aren't being properly labelled and so aren't transitioning properly on startup: system_u:system_r:initrc_t:s03523 ?S 0:00 /usr/bin/python /var/lib/mailman/bin/qrunner

Bug#738946: selinux-policy-default: Bind's ndc_t denied block_suspend on epollwakeup

2014-02-13 Thread Devin Carraway
: Devin Carraway g...@devin.com Date: Thu Feb 13 21:59:54 2014 -0800 Allow ndc_t to prevent suspend on epoll events. Capability background: http://thread.gmane.org/gmane.linux.kernel/1289986 Fixes audit denial: Feb 13 00:46:38 a6 kernel: [ 541.076682] type=1400 audit

Bug#717470: linux-image-3.10-1-kirkwood: Soft lockup in orion_nand booting on dreamplug

2013-07-21 Thread Devin Carraway
Package: src:linux Version: 3.10.1-1 Severity: normal linux-image-3.10-1-kirkwood (also reproduced with 3.9-1-kirkwood) cannot boot on a dreamplug; the boot hangs and the watchdog fires while down in orion_nand code, which so far as I know is not even applicable to this hardware. Boot was off

Bug#705931: qpsmtpd: unable to bind to [::]

2013-07-01 Thread Devin Carraway
Although I didn't explicitly fix it in this patch release, I'm unable to reproduce the problem with 0.84-10, uploaded a few minutes ago - please give it a try with that release and see if you still observe trouble. Devin -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway

Bug#693181: qpsmtpd: sender_permitted_framework plugin hangs on IPv6 clients

2012-12-02 Thread Devin Carraway
tags 693181 + wheezy security severity 693181 serious quit Thanks for the report. I'll roll a release and see if the release team will grant a freeze exemption. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E 65F0 8905 2E43 5395 CA0D

Bug#693103: qpsmtpd: Missing dependency for IPv6 support

2012-12-02 Thread Devin Carraway
severity 693103 important quit Marking 'important' -- this doesn't meet Debian guidelines for 'serious,' quite. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E 65F0 8905 2E43 5395 CA0D E9AB FCD2 signature.asc Description: Digital

Bug#685412: Exploring the possibility of an l10n upload of qpsmtpd to fix pending po-debconf l10n bugs

2012-08-22 Thread Devin Carraway
Ah, version control. Introducing problems that can only be solved with yet more version control. I'll roll a -8 tonight. Devin -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E 65F0 8905 2E43 5395 CA0D E9AB FCD2 -- To UNSUBSCRIBE,

Bug#685412: Exploring the possibility of an l10n upload of qpsmtpd to fix pending po-debconf l10n bugs

2012-08-21 Thread Devin Carraway
On Mon, Aug 20, 2012 at 05:34:43PM -0400, David Prévot wrote: Depending of how much « a few days » are, what do you prefer? If it's about ten days or more, I could go now with the first proposal, but if it's less than five days (if the fix meet the freeze exception criteria of course), or more

Bug#684571: qpsmtpd: SMTP Auth Received: header format causes spam false positives and leaks sensitive information

2012-08-20 Thread Devin Carraway
forwarded 684571 http://www.nntp.perl.org/group/perl.qpsmtpd/2012/08/msg9954.html quit Forwarded upstream for consideration. Upstream has no BTS, linking mailing list thread instead. Devin -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E

Bug#657117: pulseaudio: FTBFS on armel due to linking nonexistent volume library

2012-01-24 Thread Devin Carraway
Sep 17 00:00:00 2001 From: Devin Carraway g...@devin.com Date: Tue, 24 Jan 2012 00:54:24 -0800 Subject: [PATCH] Stop linking nonexistent ARM volume lib --- debian/rules |3 --- 1 files changed, 0 insertions(+), 3 deletions(-) diff --git a/debian/rules b/debian/rules index f850db9..960e85a

Bug#643457: pidgin-librvp: diff for NMU version 0.9.7-1.2

2011-11-20 Thread Devin Carraway
On Sun, Nov 20, 2011 at 02:18:14PM +0100, gregor herrmann wrote: I've prepared an NMU for pidgin-librvp (versioned as 0.9.7-1.2) and uploaded it to DELAYED/2. Please feel free to tell me if I should delay it longer. Nope, thanks for the upload. I've just moved and the build machine with my

Bug#628888: forked-daapd: Undeclared dependency on psmisc from logrotate script

2011-06-02 Thread Devin Carraway
Package: forked-daapd Version: 0.16-1 Severity: normal forked-daapd includes a logrotate config which runs 'killall -q -HUP forked-daapd'. However, it doesn't depend on psmisc which actually contains killall. -- System Information: Debian Release: wheezy/sid APT prefers testing APT

Bug#608749: forked-daapd: Track number not extracted from AAC files

2011-03-08 Thread Devin Carraway
On Sun, Mar 06, 2011 at 03:04:45PM +0100, Julien BLACHE wrote: Forked-daapd does not appear to be correctly extracting track numbers from AAC files, at least not those encoded within iTunes. Can you retry with ffmpeg 0.6 and 0.12~git0.11-125-gca72ee5-4 now that they are both available

Bug#608749: forked-daapd: Track number not extracted from AAC files

2011-03-07 Thread Devin Carraway
On Sun, Mar 06, 2011 at 03:04:45PM +0100, Julien BLACHE wrote: Can you retry with ffmpeg 0.6 and 0.12~git0.11-125-gca72ee5-4 now that they are both available in testing? Yep, will do. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E

Bug#616288: perl-modules: SelfLoader breaks when taint-checking is enabled

2011-03-03 Thread Devin Carraway
Package: perl-modules Version: 5.10.0-19lenny3 Severity: normal Packages using SelfLoader (older ones, generally) seem to have broken recently when taint checking is enabled. I haven't narrowed down exactly where this was introduced, but I don't believe I saw it prior to the 5.0.8 point release

Bug#608749: forked-daapd: Track number not extracted from AAC files

2011-01-03 Thread Devin Carraway
Package: forked-daapd Version: 0.12~git0.11-125-gca72ee5-3 Severity: normal Forked-daapd does not appear to be correctly extracting track numbers from AAC files, at least not those encoded within iTunes. This causes albums to appear in title-order from DAAP clients (Rhythmbox, iTunes tested),

Bug#607472: Bug#606000: libmail-spf-query-perl: Incorrect query results with IPv6 addresses; should warn about missing IPv6 support and/or fail graciously

2010-12-23 Thread Devin Carraway
On Thu, Dec 23, 2010 at 03:36:42PM +0100, Julien Cristau wrote: I see this is now uploaded. Unblocked, should migrate in 5 days if no new RC bugs appear; and removal hint added for libmail-spf-query-perl. I submitted a freeze exception request for qpsmtpd_0.84-5. Thanks for doing the advance

Bug#607909: unblock: qpsmtpd 0.84-5

2010-12-23 Thread Devin Carraway
Package: release.debian.org User: release.debian@packages.debian.org Usertags: freeze-exception I've uploaded qpsmtpd 0.84-5 to unstable; it includes a fix for RC Bug#607472. Terse summary: libmail-spf-query-perl is RC-buggy; qpsmtpd was its only dependency, used by its SPF plugin.

Bug#606000: libmail-spf-query-perl: Incorrect query results with IPv6 addresses; should warn about missing IPv6 support and/or fail graciously

2010-12-21 Thread Devin Carraway
On Sun, Dec 19, 2010 at 12:35:32PM +0100, gregor herrmann wrote: Right, I set #607472 to grave under the assumption that we want to drop libmail-spf-query-perl which would leave qpsmtpd without a dependency. I'm cc'ing the release team to get an opinion if this plan is ok. I've deployed a

Bug#606000: libmail-spf-query-perl: Incorrect query results with IPv6 addresses; should warn about missing IPv6 support and/or fail graciously

2010-12-19 Thread Devin Carraway
I'll try to take a look at this this weekend. Not severity=grave for qpsmtpd, but will let it stay on the presumption that it's blocking another grave bug. Devin -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E 65F0 8905 2E43 5395 CA0D

Bug#602365: unblock: qpsmtpd/0.84-4

2010-11-04 Thread Devin Carraway
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock qpsmtpd_0.84-4 for another translation update. No other changes. qpsmtpd (0.84-4) unstable; urgency=low . * Update Spanish translation; thanks to Francisco

Bug#600331: unblock: qpsmtpd/0.84-3

2010-10-16 Thread Devin Carraway
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock qpsmtpd_0.84-3 for a translation update. No other changes. Changes: qpsmtpd (0.84-3) unstable; urgency=low . * Update Czech debconf translation; thanks to

Bug#599385: unblock: qpsmtpd/0.84-2

2010-10-07 Thread Devin Carraway
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: freeze-exception Please unblock qpsmtpd_0.84-2 for translation update; changelog follows: Changes: qpsmtpd (0.84-2) unstable; urgency=low . * Update Portuguese debconf translation; thanks to

Bug#595576: selinux-policy-default: Quietly prevents mdadm from writing to unconfined terminals

2010-09-05 Thread Devin Carraway
Package: selinux-policy-default Version: 2:0.0.20080702-6 Severity: normal Lenny's refpolicy seems to prevent mdadm from writing to an interactive (unconfined) tty, although I'm somewhat mystified as to the specific cause. mdadm has its own domain, defined by the raid refpolicy module; run as a

Bug#595135: pulseaudio: Cached volume data causes abort previously-working USB DAC

2010-09-01 Thread Devin Carraway
Package: pulseaudio Version: 0.9.21-3 Severity: normal After a recent pulseaudio upgrade to my armel machine (sheevaplug), a previously-working audio device (Burr-Brown Japan PCM2702, the USB DAC inside a consumer-grade JVC amplifier) ceased working; pulseaudio would die on startup or on device

Bug#580194: hugin: Can't un-set image fuser/blender commandline options once set

2010-05-04 Thread Devin Carraway
Package: hugin Version: 2009.4.0+dfsg-2 Severity: normal The hugin UI's Stitcher tab allows one to set arbitrary commandline options to the image fuser and blender apps. However, once set to a non-empty string, the setting can't then be cleared -- reopening the options dialog and deleting the

Bug#578035: CVE-2009-4496: Nonprintable characters not sanitized in boa's error logs

2010-04-16 Thread Devin Carraway
Package: boa Version: 0.94.14rc21-0.2 Severity: important Tags: security CVE-2009-4496 describes a multi-step vulnerability whereby Boa does not escape nonprintable characters from the request when writing to its error log. While not a vulnerability in itself, this provides a vector for an

Bug#574557: qpsmtpd: diff for NMU version 0.83-2.1

2010-04-08 Thread Devin Carraway
On Wed, Apr 07, 2010 at 10:37:31PM +0200, Stefano Zacchiroli wrote: I did the DELAYED NMU just in case you won't have time to fix this by a proper upload anytime soon; if this is the case, you can just let the NMU flow in and later on do a proper upload ack-ing the NMU and adding extra

Bug#574557: Package version is wrong in bug report

2010-03-21 Thread Devin Carraway
On Sun, Mar 21, 2010 at 07:54:13AM +0100, Petter Reinholdtsen wrote: I picked the version number when the bug was introduced according to the changelog, to make sure it is registered against all version where it is present. Are you saying that it is fixed in a later version and reintroduced

Bug#567098: linux-image-2.6.26-2-ixp4xx: adm8511/pegasus usb ethernet device loses mac on nslu2 when cold-plugged

2010-01-30 Thread Devin Carraway
On Fri, Jan 29, 2010 at 12:34:27AM +, Ben Hutchings wrote: Is this reproducible if you plug the adapter into a PC? Did some testing on a PC (Asus M2N-E, MCP55 controller, 2.6.32-trunk-amd64 2.6.32-5) and the problem was not reproducible there. The pegasus adapter comes up with a valid MAC

Bug#567098: linux-image-2.6.26-2-ixp4xx: adm8511/pegasus usb ethernet device loses mac on nslu2 when cold-plugged

2010-01-30 Thread Devin Carraway
I tried one other experiment, plugging the pegasus adapter in at various points in the NSLU2's boot sequence, to see whether the bootloaders might be affecting the device. Based on http://www.cyrius.com/debian/nslu2/boot.html , the MAC came up zeroed out if the device was plugged in anywhere

Bug#567098: linux-image-2.6.26-2-ixp4xx: adm8511/pegasus usb ethernet device loses mac on nslu2 when cold-plugged

2010-01-29 Thread Devin Carraway
On Fri, Jan 29, 2010 at 12:34:27AM +, Ben Hutchings wrote: Is this reproducible if you plug the adapter into a PC? I'll try it and see. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7 199E DD1E 65F0 8905 2E43 5395 CA0D E9AB FCD2 -- To

Bug#567098: linux-image-2.6.26-2-ixp4xx: adm8511/pegasus usb ethernet device loses mac on nslu2 when cold-plugged

2010-01-27 Thread Devin Carraway
Package: linux-image-2.6.26-2-ixp4xx Version: 2.6.26-19lenny2 Severity: normal I've been experimenting with a Pegasus-chipset USB ethernet adapter on an NSLU2 unit. If the adapter is connected prior to system boot, although it will be recognized by the kernel and udev, it starts out with a MAC

Bug#567098: linux-image-2.6.26-2-ixp4xx: adm8511/pegasus usb ethernet device loses mac on nslu2 when cold-plugged

2010-01-27 Thread Devin Carraway
reassign 567098 linux-image-2.6.32-trunk-ixp4xx 2.6.32-5 quit This also manifests with linux-image-2.6.32-trunk-ixp4xx 2.6.32-5 from sid; reassigning there since it's not locked up in stable-land. -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2: 13E7

Bug#560343: qpsmtpd: config script bug setting INTERFACES

2009-12-14 Thread Devin Carraway
On Thu, Dec 10, 2009 at 10:51:04AM -0500, John Bazik wrote: Package: qpsmtpd Version: 0.40-3 Severity: normal There's a minor error in the config script. If you don't set INTERFACES, it is set as follows: INTERFACES=`/sbin/ifconfig -a | \ grep

Bug#540791: Add support for multiple port and/or ip adresses in qpsmtpd startup script

2009-12-14 Thread Devin Carraway
severity 540791 minor tags 540791 +pending quit On Mon, Aug 10, 2009 at 01:31:39PM +0200, kaouete wrote: Can it be possible to add support for multiple port and/or ip adresses in qpsmtpd startup script? For example when using the tls plugin, you can use the port 465 to do SMTP over SSL.

Bug#526254: CVE-2008-4456: mysql client does not escape strings in --html mode

2009-04-30 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Package: mysql-client-5.0 Version: 5.0.51a-24 Severity: grave Tags: security Justification: cross-site scripting vulnerability Upstream is tracking a security flaw in the mysql commandline client, identified as CVE-2008-4456:

Bug#423869: qpsmtpd fails to start

2009-04-19 Thread Devin Carraway
I neglected to close this bug from the changelog, but I've just uploaded 0.81-1 with a patch to address this issue in the clamdscan plugin, by using ClamAV::Client instead; the package now depends on that perl module, so it should start cleanly on a fresh install without further fiddling. --

Bug#524772: Finish supporting prefork

2009-04-19 Thread Devin Carraway
Package: qpsmtpd Version: 0.81-1 0.81-1 included prefork, which was usable via editing the init.d script, but couldn't be selected through debconf, because prefork didn't as of 0.81 support listening on multiple interfaces, and hence would have broken some deployed setups. A patch to support

Bug#498519: Please support the use of qpsmtpd-prefork

2009-04-19 Thread Devin Carraway
On Fri, Sep 12, 2008 at 08:55:46PM +0100, Steve Kemp wrote: OK please find attached a patch which mostly do the job for the version of qpsmtpd which is currently available to Debian unstable, via the introduction of a new debconf setting. Hi Steve -- I uploaded 0.81-1 last night (and -2

Bug#506252: success: d-i lenny rc1 on nslu2 armel

2009-01-06 Thread Devin Carraway
On Tue, Jan 06, 2009 at 05:03:54PM +0100, Martin Michlmayr wrote: Devin, I'm inclined to close this bug report since I believe that d-i is doing the right thing. There are reports that the clock sometimes gets stuck on the NSLU2, but I don't think Debian/debian-installer can do anything about

Bug#506252: success: d-i lenny rc1 on nslu2 armel

2008-11-20 Thread Devin Carraway
On Thu, Nov 20, 2008 at 08:40:59AM -0200, Otavio Salvador wrote: Could you give a try in current daily installer since it has a new kernel version and see if RTC looks OK? If it doesn't it looks like a kernel issue to me. Devin, don't waste your time - nothing has changed in the kernel

Bug#506252: success: d-i lenny rc1 on nslu2 armel

2008-11-19 Thread Devin Carraway
Package: installation-reports Severity: normal -- Package-specific info: Boot method: network (upslug2) Image version: Unofficial nslu2 image (stock lenny image plus onboard ethernet microcode), http://www.slug-firmware.net/d-dls.php Date: Date and time of the install Machine: Linksys NSLU2

Bug#499277: Fix for Etch

2008-09-22 Thread Devin Carraway
On Wed, Sep 17, 2008 at 02:30:43PM -0400, Scott Kitterman wrote: Here is a debdiff for Etch. In addition to fixing this regression, I also switched DNS/Base.py to use the upstream fix for the DNS cache poisoning problem. Their fix is more robust. If you'd rather just deal with this exact

Bug#499277: python-dns security update breaks existing applications

2008-09-17 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, Sep 17, 2008 at 05:28:37PM +0200, Fabio Tranchitella wrote: transaction ID randomization. If instead of reverted to the package that has neither, you change 'self.tid' to '0' in line 199 of

Bug#498519: Please support the use of qpsmtpd-prefork

2008-09-11 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, Sep 10, 2008 at 07:56:53PM +0100, Steve Kemp wrote: It would be wonderful if the Debian package of qpsmtpd could be updated a little from the SVN trunk, and allow you to choose to use the qpsmtpd-prefork version of the server. It would,

Bug#490271: #490271

2008-07-24 Thread Devin Carraway
A tentative fix to refpolicy is here: http://klecker.debian.org/~devin/refpolicy/ Martin, can you test these to confirm that they address the problem and check for trouble during the upgrade? -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \ 1024D/E9ABFCD2:

Bug#492252: Stable fix for CVE-2008-2713 wasn't

2008-07-24 Thread Devin Carraway
Package: clamav Version: 0.90.1dfsg-3etch13 Severity: grave I released clamav 0.90.1dfsg-3etch13 to fix CVE-2008-2713, the DoS exposure via the Petite unpacker. However, I screwed up the build and didn't actually include the patch. I'll be releasing a fixed build shortly. This bug only applies

Bug#490271: #490271

2008-07-15 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, Jul 11, 2008 at 10:59:13PM +0200, Bastian Blank wrote: I'm currently not able to see the problem to push a _fix_, not a _workaround_, through stable-security. Please explain. Pushing a fix to stable-security is easy -- we can patch the

Bug#490271: bind9: security update breaks named running with selinux

2008-07-11 Thread Devin Carraway
On Fri, Jul 11, 2008 at 08:26:53AM +0200, Martin Godisch wrote: bind9 security update 9.3.4-2etch3 breaks named running in a selinux enabled (enforcing) environment: audit(1215756426.448:248): avc: denied { name_bind } for pid=16218 comm=named src=12949 scontext=user_u:system_r:named_t:s0

Bug#480292: CVE-2008-2079: mysql allows local users to bypass certain privilege checks

2008-07-07 Thread Devin Carraway
tags 480292 +patch quit Here's a patch I'm building for an Etch update to address the problem. It's pretty close to the same one used in the first fix to this bug, except that it adds a call to realpath() to resolve all components of the path, and fixes the argument passing so as not to throw

Bug#480292: CVE-2008-2079: mysql allows local users to bypass certain privilege checks

2008-07-06 Thread Devin Carraway
On Fri, Jul 04, 2008 at 02:56:00PM +0200, Tomas Hoger wrote: Looks like upstream patch is incomplete. Have you already notified upstream about the problem? Not yet -- I still need to hand verify it against a pristine upstream; it's reproducible with 5.0.51a from Sid, but the implementation of

Bug#480292: CVE-2008-2079: mysql allows local users to bypass certain privilege checks

2008-07-03 Thread Devin Carraway
reopen 480292 quit I don't believe that the patch applied to address this bug was sufficient. In preparing the stable update I initially applied it, before finding two things: First, fn_format() only calls readlink() once on the entire path, not on any component thereof; hence it will only

Bug#475312: Might other integer-overflow vulnerabilities in malloc() calls be the cause of #475312?

2008-04-10 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, Apr 10, 2008 at 12:44:49AM +0200, Sylvain HITIER wrote: However this looks like a bug against libcairo2... I suggest that other integer-overflow vulnerabilities in malloc() calls be the cause of it. As you've just NMU'ed a security fix

Bug#465072: selinux-policy-refpolicy-targeted installation errors

2008-02-20 Thread Devin Carraway
This happens with strict refpolicy also. I think the entire dependency detection process is broken by the ricci module, whose dependencies aren't satisfiable at all with the module packages installed. Run with the ricci module includes, semodule_deps produces no graphviz output at all: $

Bug#465208: Acknowledgement (refpolicy: Exim policy module not installed due to module/package name mismatch)

2008-02-11 Thread Devin Carraway
Meh. Now that I patch that and actually install the module, I find that it doesn't do anything, because somewhere along the chain of patching and checking the Debian-compatible paths got dropped off. I submitted a ticket to upstream's trac, but in the meantime if you plan on staying with the

Bug#465215: selinux-policy-refpolicy-dev: Installed build.conf specifies MCS build type

2008-02-11 Thread Devin Carraway
Package: selinux-policy-refpolicy-dev Version: 0.0.20071214-1 Severity: normal 0.0.20071214-1's -dev package installs debian/build.conf.targeted as /usr/share/selinux/refpolicy-targeted/include/build.conf, which is then used by the usual Makefile. However, this build.conf file explicitly

Bug#465208: refpolicy: Exim policy module not installed due to module/package name mismatch

2008-02-11 Thread Devin Carraway
Package: refpolicy Version: 0.0.20071214-1 Severity: normal Tags: patch refpolicy 0.0.20071214-1 includes an Exim policy, but doesn't install it on a fresh refpolicy installation, because the module package is exim.pp, while Debian calls its exim package 'exim4'. Attached is the obvious patch.

Bug#460037: Upgrade to dpkg 1.14.15 breaks dpkg-dev 1.14.14 but doesn't conflict

2008-01-10 Thread Devin Carraway
Package: dpkg Version: 1.14.15 Severity: normal On upgrading to dpkg 1.14.15 without upgrading dpkg-dev (APT held it back because of the implied install of lzma), package builds began failing thusly: dpkg-source -b quelcom-0.4.0 compression is not defined in %Dpkg::EXPORT_TAGS at

Bug#459126: quelcom: FTBFS with dash: ln: creating symbolic link `/build/user/quelcom-0.4.0/debian/quelcom/usr/bin/quelcom' to `quelcom': File exists

2008-01-10 Thread Devin Carraway
tags 459126 +unreproducible quit On Fri, Jan 04, 2008 at 01:56:28PM +0100, Lucas Nussbaum wrote: During a rebuild of all packages in sid using /bin/dash as /bin/sh, your package failed to build. I'm unable to reproduce this behavior with 0.4.0-12 (just uploaded), with either dash or bash as

Bug#456722: xmms-xf86audio: should this package be orphaned?

2007-12-21 Thread Devin Carraway
[ upstream author here, not the maintainer ] The xmms-xf86audio plugin is tightly tied to xmms. While it's possible that it could be rewritten to work with another audio player, most others already have the feature this plugin provides. I know audacious does, and last I looked none of the XMMS2

Bug#435783: qpsmtpd: [INTL:fr] French debconf templates translation update

2007-09-16 Thread Devin Carraway
On Fri, Aug 03, 2007 at 08:29:39AM +0200, Christian Perrier wrote: Please find attached the french debconf templates update, proofread by the debian-l10n-french mailing list contributors. Uploaded in 0.40-2 (I forgot to put the Closes: in the changelog). Thanks! -- Devin \

Bug#436286: qpsmtpd: [INTL:de] updated German debconf translation

2007-09-16 Thread Devin Carraway
On Mon, Aug 06, 2007 at 09:37:15PM +0200, Helge Kreutzmann wrote: Please find the updated German debconf translation for qpsmtpd attached. Uploaded in 0.40-2 (forgot to include the Closes: in the changelog). Thanks! -- Devin \ aqua(at)devin.com, IRC:Requiem; http://www.devin.com Carraway \

Bug#430894: NMU patch

2007-08-25 Thread Devin Carraway
On Fri, Aug 24, 2007 at 09:03:52PM -0400, Ari Pollak wrote: I plan to NMU gaim-librvp package to fix this bug. Attached is the patch to do so. Go ahead, thanks. Been totally slagged under with work and everytime I try to detach it gets worse. Sorry if I held up the migration. -- Devin \

Bug#431882: qpsmtpd: Minor errors in Debconf template

2007-07-23 Thread Devin Carraway
Thanks for pointing those out. I've fixed most of them. Ordering of commas with respect to quotations is debated in English composition; the usage in the current template (that is, commas inside the quotation) represents MLA style, the nearest thing to a standard for such things, at least here

Bug#430195: dante-server: Crashes when reporting configuration errors

2007-06-23 Thread Devin Carraway
Package: dante-server Version: 1.1.18-2.1 Severity: normal I haven't ascertained the exact circumstances, but danted crashes quite readily when reporting configuration-related errors. Here's a crash that arises from failure to open a logfile specified in its configuration: Program received

Bug#423869: qpsmtpd fails to start

2007-05-17 Thread Devin Carraway
block 423869 by 405151 tags 405151 +pending quit On Mon, May 14, 2007 at 06:13:04PM +0200, Olaf Zaplinski wrote: # /etc/init.d/qpsmtpd start Starting qpsmtpd: eval Can't locate Clamd.pm in @INC (@INC contains: lib /etc/perl /usr/local/lib/perl/5.8.8 /usr/local/share/perl/5.8.8

Bug#414565: Create /var/run/qpsmtpd in initscript

2007-05-17 Thread Devin Carraway
tags 414565 +unreproducible usertag 414565 +only-in-ubuntu quit On Mon, Mar 12, 2007 at 04:02:32PM +0100, Luca Falavigna wrote: qpsmtpd should create /var/run/qpsmtpd directory with proper permissions in order to preserve files between reboots. Attached debdiff implements this. This is an

Bug#411957: gnome-pilot: File conduit renders gnome-pilot unusable on amd64

2007-02-21 Thread Devin Carraway
Package: gnome-pilot Version: 2.0.15-0.1 Severity: important Tags: patch The gnome-pilot file conduit cannot be safely used on amd64 due to an upstream pointer-size bug (GNOME Bugzilla#410666). If one attempts it, the entire gnome-pilot setup for that user will crash on sync until the file is

Bug#379900: liferea: Sporadic crashes on amd64 -- Please retest with 1.0.27-1

2007-02-10 Thread Devin Carraway
On Fri, Feb 09, 2007 at 12:07:26PM +0100, Lars Lindner wrote: It could be worth to backport it. The simple patch is available from here (md5.patch): http://sourceforge.net/tracker/download.php?group_id=87005atid=581684file_id=213406aid=1636563 I also attached the file. Yugh. Why do

Bug#379900: liferea: Sporadic crashes on amd64 -- Please retest with 1.0.27-1

2007-02-10 Thread Devin Carraway
When using GtkHTML2 or Gecko? From the reports upstream I got the impression that the problem is solved for everyone when Gecko rendering is used. But I got only feedback from a few users. That most recent crash was 1.0.27-1 from sid, with the MD5 integer size patch hand-applied, built with

Bug#379900: liferea: Sporadic crashes on amd64 -- Please retest with 1.0.27-1

2007-02-09 Thread Devin Carraway
FWIW, liferea 1.2.5 was released recently; its changelist cites the fixing of a crash on 64-bit platforms. I've been using it for the past five or six days and haven't crashed it yet, which is better than 1.0.27-1 ever did. This deep in the Etch freeze it's probably not reasonable to try to do a

Bug#404297: Bug#404927: DPT/Adaptec udev info

2007-01-06 Thread Devin Carraway
Here's udevinfo from an etch/sid install with an old Adaptec 2940 (since Dann asked): looking at device '/block/sr0': KERNEL==sr0 SUBSYSTEM==block SYSFS{stat}== 000000 00000

Bug#405103: selinux-policy-refpolicy-targeted: Multiple problems with courier policy

2006-12-31 Thread Devin Carraway
Package: selinux-policy-refpolicy-targeted Version: 0.0.20061018-2 Severity: normal The targeted refpolicy has a number of issues that prevent courier's IMAP and SSL servers from working: * courier.fc specifies labelling for most of courier's files, but virtually all of these have the --

Bug#405151: ITP: libclamav-client-perl -- A client for the ClamAV virus scanner daemon

2006-12-31 Thread Devin Carraway
Package: wnpp Severity: wishlist Owner: Devin Carraway [EMAIL PROTECTED] * Package name: libclamav-client-perl Version : 0.11 Upstream Author : Julian Mehnle [EMAIL PROTECTED] * URL : http://search.cpan.org/dist/ClamAV-Client/ * License : GPL, Artistic

Bug#404895: selinux-policy-refpolicy-targeted: clamav policy forbids clamd_t search on /var/lib

2006-12-28 Thread Devin Carraway
Package: selinux-policy-refpolicy-targeted Version: 0.0.20061018-2 Severity: normal The current refpolicy doesn't allow clamd (in clamd_t) to search var_lib_t. This yields audit errors like this one when clamd starts: Dec 28 06:48:39 atlantic5 kernel: audit(1167317319.154:167): avc: denied {

Bug#404309: selinux-policy-refpolicy-targeted: Policy for dcc misses Debian's FHS paths

2006-12-23 Thread Devin Carraway
Package: selinux-policy-refpolicy-targeted Version: 0.0.20061018-1 Severity: normal Tried the targeted refpolicy on dcc-client/dcc-common tonight. Many of the files in these packages are overlooked when labelling files, because refpolicy's dcc module stipulates paths not consistent with the

Bug#398125: gaim-librvp will not run or build with gaim 2.0.0beta5

2006-11-11 Thread Devin Carraway
tags 398125 +pending quit On Sat, Nov 11, 2006 at 04:33:31PM -0500, Ari Pollak wrote: With the upload of gaim 2.0.0beta5, gaim-librvp will not build or run due to a gaim ABI change. Attached is a patch which will fix the problem. Splendid timing for it. Thanks for the warning, I've

Bug#389025: f

2006-11-05 Thread Devin Carraway
tags 389025 + fixed-upstream pending quit A fix for this issue has been checked in upstream. The upstream maintainers were planning on a release within a week or so; if this doesn't happen shortly I'll backport the fix and upload a patched version. Thanks for the report, and sorry for the delay

Bug#389025: /etc/qpsmtpd/plugin_dirs does not work if it contains more than one path

2006-11-05 Thread Devin Carraway
In case upstream doesn't issue a new release as intended, I've prepared packages with a backport of the same fix, and am testing them now. You can find copies here if you'd like to test it yourself (look for qpsmtpd_0.32-5): http://devin.com/debian/ -- Devin \ aqua(at)devin.com,

Bug#393284: ./debian/rules clean doesn't work

2006-10-15 Thread Devin Carraway
Package: gaim-librvp Version: 0.9-2 Severity: minor Preemptory bug filing: as of 0.9-2, the gaim-librvp package can't be cleaned after it's built -- the patch stamp must be removed before the build will succeed. This is caused by Bug#387103 in cdbs, and should fix itself once that's addressed.

Bug#390503: compiz: Missing window borders

2006-10-01 Thread Devin Carraway
Package: compiz Version: 0.0.13+git20060928-2 Followup-For: Bug #390503 The problem is probably conneced to this error, of which compiz (not the decorator) emits several any time gtk-window-decorator is run: /usr/bin/compiz.real: No GLXFBConfig for depth 32 Presuming the non-free nvidia

Bug#384446: selinux-policy-refpolicy-targeted: file_context errors after installing 0.0.20060813-1

2006-08-24 Thread Devin Carraway
Package: selinux-policy-refpolicy-targeted Version: 0.0.20060813-2 Severity: normal (as usual, making a guess as to the likeliest package involved) After upgrading selinux-policy-refpolicy-targeted to 0.0.20060813-1 tonight, I've started seeing errors from everything which checks file_contexts

Bug#383131: checkpolicy: 1.30.10 can no longer compile refpolicy

2006-08-18 Thread Devin Carraway
On Thu, Aug 17, 2006 at 05:07:20PM -0500, Manoj Srivastava wrote: You just need a newer version of refpolicy (see the version uploaded t Sid, for example) Yup. Pulled that one down last night and it builds just fine; I presume that checkpolicy/libsepol just got stricter about rule

Bug#383131: checkpolicy: 1.30.10 can no longer compile refpolicy

2006-08-15 Thread Devin Carraway
Package: checkpolicy Version: 1.30.10-2 Severity: normal After upgrading to checkpolicy 1.30.10-2, refpolicy no longer builds; the build fails when checkmodule is run on the strict policy's base.conf: m4 -D strict_policy -D enable_mcs -D distro_debian -D direct_sysadm_daemon -D

Bug#379559: refpolicy: FTBFS: tmp/generated_definitions.conf:597:ERROR 'syntax error' at token '' on line 3416:

2006-08-14 Thread Devin Carraway
I think this may be caused by an undeclared build dependency on gawk; accoding to the changelog, gawk was added as a build-dep in 20060224-1 by Erich, but doesn't appear there now. Without gawk installed, the build includes this error, which isn't treated as fatal: echo

Bug#379559: Info received (refpolicy: FTBFS: tmp/generated_definitions.conf:597:ERROR 'syntax error' at token '' on line 3416:)

2006-08-14 Thread Devin Carraway
I tried forcing the build over to use a plain awk command (mawk, on my machine), but this produces the same build failure -- mawk produces no output when run in the build, while gawk does. I don't know enough awk to sort this out, so here's the obvious patch to build-depend on gawk again. --

Bug#382753: checkpolicy: checkmodule produces unpackageable policy modules on powerpc

2006-08-13 Thread Devin Carraway
Poking at it a little more, a simpler test case seems to be to get checkmodule to read its own output: $ checkmodule -m -M -o test.mod test.te ; echo $? ; checkmodule -b test.mod ; echo $? checkmodule: loading policy configuration from test.te checkmodule: policy configuration loaded

Bug#382753: Info received (checkpolicy: checkmodule produces unpackageable policy modules on powerpc)

2006-08-13 Thread Devin Carraway
This may have been fixed by the upload of checkpolicy-1.30.10 last night, which build-depends on libsepol1 1.12.24. According to the buildd logs, the previous upload was built against libsepol1 1.12-1. In that version, avrule_block_write() was missing an endian conversion (where num_decls is

  1   2   >