Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-28 Thread Markus Koschany
Hi, Am 28.09.18 um 00:16 schrieb Salvatore Bonaccorso: > Hi Markus, > > On Thu, Sep 27, 2018 at 10:33:06PM +0200, Markus Koschany wrote: [...] >> The text is correctly displayed now in Jessie but the Stretch version >> shows Chinese characters instead. Hence I would apprecia

Bug#909076: ghostscript: ps2ascii crashes: Error: /typecheck in --.bind--

2018-09-27 Thread Markus Koschany
Hi, I believe I have found the solution to this problem. Apparently they changed the underlying device for ps2ascii to txtwrite last year. http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=2fa6beaa40144c592661a611bf35ff6f06d3354f If I apply this commit in Jessie, ps2ascii appears to work

Bug#909739: php-horde: CVE-2017-16907 XSS via Color field

2018-09-27 Thread Markus Koschany
Package: php-horde X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde. CVE-2017-16907[0]: | In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field | in a Create Task List action. If you fix the

Bug#909738: php-horde-kronolith: CVE-2017-16908 XSS via Name field

2018-09-27 Thread Markus Koschany
Package: php-horde-kronolith X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde-kronolith. CVE-2017-16908[0]: | In Horde Groupware 5.2.19, there is XSS via the Name field during | creation of a new Resource. This can

Bug#909737: php-horde-kronolith: CVE-2017-16906 XSS via URL field

2018-09-27 Thread Markus Koschany
Package: php-horde-kronolith X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for php-horde-kronolith. CVE-2017-16906[0]: | In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a | "Calendar - New Event" action.

Bug#909626: should not pop open a sidebar on first start

2018-09-26 Thread Markus Koschany
Control: forcemerge 909493 909626 Hi, Am 26.09.18 um 01:03 schrieb Antoine Beaupre: > Package: webext-ublock-origin > Version: 1.16.14+dfsg-2 > Severity: minor > > When a clean Firefox profile is started, uBlock has this annoying > habit of showing off and popping open itself as a sidebar. > >

Bug#909493: ublock displays network request log on first startup

2018-09-25 Thread Markus Koschany
Hi, Am 24.09.18 um 15:28 schrieb Laurent Bigonville: > Package: webext-ublock-origin > Version: 1.16.14+dfsg-2 > Severity: normal > > Hi, > > When starting firefox for the first time or with an temporary profile > (ie firefox -profile /tmp/foo -no-remote -new-instance), ublock displays > the

Bug#909540: tomcat8: ignores umask, sudden(?) regression

2018-09-24 Thread Markus Koschany
Hi, Am 24.09.18 um 23:54 schrieb Thorsten Glaser: > Package: tomcat8 > Version: 8.5.14-1+deb9u3 > Severity: important [...] > Apparently, umask is not (no longer?) honoured. On a jessie box: [...] I guess it would help to check the previous version of Tomcat 8 in Jessie again. If you think this

Bug#909526: stretch-pu: package dom4j/1.6.1+dfsg.3-2

2018-09-24 Thread Markus Koschany
be able to modify the +whole XML document. + * Compile with source/target 1.5 to fix a compilation issue with +String.format. + * Add testng to Build-Depends. Build and test AllowedCharsTest to verify that +CVE-2018-1000632 is correctly addressed. + + -- Markus Koschany Mon, 24 Sep

Bug#909000: Enigmail 2.0 needed in Stretch after Thunderbird 60 upload

2018-09-20 Thread Markus Koschany
Hey, just wanted to chime in here. I successfully backported the Buster version of enigmail to Stretch by removing the versioned dependency on gnupg. So far I haven't experienced any difficulties. Of course this isn't a solution for the OpenPGP.js problem but at least to me it seems that the

Bug#909244: kobodeluxe not playable - immediately pauses and can't be resumed

2018-09-20 Thread Markus Koschany
Hi, Am 20.09.18 um 11:00 schrieb Damyan Ivanov: > Package: kobodeluxe > Version: 0.5.1-9 > Severity: grave > Justification: renders package unusable > > Trying to start a game in kobodeluxe results in a "PAUSED" game, with no > possibility to resume it. The only way out is to press Esc and exit

Bug#909215: glusterfs: Multiple security issues

2018-09-19 Thread Markus Koschany
Package: glusterfs X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for glusterfs. CVE-2018-10904[0]: | It was found that glusterfs server does not properly sanitize file | paths in the "trusted.io-stats-dump" extended

Bug#907477: maven-debian-helper: does not substitute values of plugins with maven.rules

2018-09-18 Thread Markus Koschany
Am 06.09.18 um 12:52 schrieb Markus Koschany: > > > Am 06.09.2018 um 00:03 schrieb Emmanuel Bourg: >> Le 28/08/2018 à 15:25, Markus Koschany a écrit : >> For plugins and poms the exact type and version have to be specified in >> the substitution rule. For exampl

Bug#908898: ublock-origin: debian/watch does not work correctly

2018-09-15 Thread Markus Koschany
Control: tags -1 pending Am 15.09.2018 um 20:26 schrieb Sven Joachim: [...] > Still, the watch file is useful for tracker.debian.org. > >> diff --git a/debian/watch b/debian/watch >> index c0a168727..49d51c087 100644 >> --- a/debian/watch >> +++ b/debian/watch >> @@ -1,3 +1,3 @@ >> version=3

Bug#908864: drascula: Incorrect version of the 'drascula.dat' engine data file found. Expected 5.0 but got 4.0.!

2018-09-15 Thread Markus Koschany
Control: tags -1 pending On Sat, 15 Sep 2018 12:45:59 +0200 Reiner Herrmann wrote: > In ScummVM 2.0.0 the version requirement of drascula has been bumped: > https://github.com/scummvm/scummvm/commit/327dcf9 > They also include an updated drascula.dat in this commit. > I tested it, and by

Bug#908835: dom4j: FTBFS because of javadoc error

2018-09-14 Thread Markus Koschany
Source: dom4j Version: 2.1.1-1 Severity: serious I just stumbled upon this bug. Apparently the last upload was never built on our buildd. There is some kind of javadoc error: javadoc: error - Error fetching URL: file:/usr/share/doc/default-jdk/api/ I may look into this later but filing a bug

Bug#908388: stretch-pu: package ublock-origin/1.10.4+dfsg-1

2018-09-12 Thread Markus Koschany
I had to release an update of ublock-origin because of a missing build-dependency. (#908509) The new version is 1.16.14+dfsg-2~deb9u1 Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#868424: gnome-breakout: Port to GooCanvas / GTK+ 3

2018-09-11 Thread Markus Koschany
Control: tags -1 pending Again great work! Looks good to me. The only thing I noticed is, gnome-breakout can't be built twice in a row. ;) I get this error: debian/rules override_dh_auto_install make[1]: Entering directory '/build/gnome-breakout-0.5.3' dh_auto_install make -j1

Bug#908509: Missing build-dependency against python(3)

2018-09-10 Thread Markus Koschany
Control: tags -1 confirmed pending Am 10.09.2018 um 18:28 schrieb Laurent Bigonville: > Package: webext-ublock-origin > Version: 1.16.14+dfsg-1 > Severity: serious > > Hi, > > Looking at the build logs, it seems that the buildsystem is using both > python and python3 (*sigh*) but none of them

Bug#908389: stretch-pu: package https-everywhere/5.2.8-1

2018-09-09 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Dear release team, I would like to update the Firefox addon https-everywhere in Stretch. The XUL extensions are incompatible and do not work with the latest version of Firefox in

Bug#908388: stretch-pu: package ublock-origin/1.10.4+dfsg-1

2018-09-09 Thread Markus Koschany
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Dear release team, I would like to update the Firefox addon ublock-origin in Stretch. The XUL extensions are incompatible and do not work with the latest version of Firefox in

Bug#907834: Some TEG annoyance/bug with the new porting

2018-09-08 Thread Markus Koschany
Control: tags -1 pending Am 08.09.2018 um 09:27 schrieb Yavor Doganov: >> 4) the Button bar can be hidden /or configured > > Fixed with the third patch but it's up to the maintainer whether to > apply it, as it's a deviation from upstream code. (Although it could > be argued that GNOME/GTK+ 3

Bug#908158: [Pkg-mozext-maintainers] Bug#908158: webext-ublock-origin: xul-ext-ublock-origin and webext-ublock-origin should co-exist

2018-09-07 Thread Markus Koschany
Am 07.09.2018 um 21:38 schrieb Mykola Nikishov: > Carsten Schoenert writes: [...] > What am I missing? At least /usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/ublo...@raymondhill.net exists in both packages. That means if you try to install both packages at the same time

Bug#905989: python3-enet: missing python3 dependency

2018-09-07 Thread Markus Koschany
+ + * Non-maintainer upload. + * Add missing Python3 dependencies to python3-enet. +Thanks to Adrian Bunk for the report and patch. (Closes: #905989) + + -- Markus Koschany Fri, 07 Sep 2018 20:49:16 +0200 + python-enet (0.0~vcs.2017.05.26.git-2) unstable; urgency=medium * Upload to unstable

Bug#908201: RM: debian-games -- NBS; games-finest-light no longer built from source

2018-09-07 Thread Markus Koschany
Package: ftp.debian.org Severity: normal Dear ftp team, please remove the games-finest-light binary package. It is no longer built from source but is blocking the migration to testing. Regards, Markus

Bug#908158: webext-ublock-origin: xul-ext-ublock-origin and webext-ublock-origin should co-exist

2018-09-06 Thread Markus Koschany
Am 06.09.2018 um 22:24 schrieb Mykola Nikishov: > Markus Koschany writes: > >> This is correct because the old XUL format does no longer work with >> Firefox 62. It is not possible to install them both at the same time. > > Yes, I know that FF62 and XUL extensions are

Bug#908158: webext-ublock-origin: xul-ext-ublock-origin and webext-ublock-origin should co-exist

2018-09-06 Thread Markus Koschany
Am 06.09.2018 um 21:53 schrieb Mykola Nikishov: > Package: webext-ublock-origin > Severity: normal > > While using Firefox ESR with xul-ext-ublock-origin/stable in a default > profile, user should be able to run Firefox 62 with > webext-ublock-origin in a separate profile. But right now, >

Bug#908091: sweethome3d: Immediate crash upon starting 'sweethome3d'

2018-09-06 Thread Markus Koschany
On Thu, 06 Sep 2018 07:59:41 +0300 nikobit wrote: > Package: sweethome3d > Version: 5.7+dfsg-2 > Severity: normal > Tags: newcomer > > Dear Maintainer, > Same as previous bug reporter I would like to say thank you for maintaining > such extraordinary job. Afraid I'm reporting bug 884057 once

Bug#908135: unknown-horizons: does not start with fife 0.4.1+git20180904-1

2018-09-06 Thread Markus Koschany
Package: unknown-horizons Version: 2017.2-1 Severity: grave Unknown Horizons does not start with the latest fife version. I am currently packaging the Python 3 version and then I will update UH to the latest Git version. Markus

Bug#907477: maven-debian-helper: does not substitute values of plugins with maven.rules

2018-09-06 Thread Markus Koschany
Am 06.09.2018 um 00:03 schrieb Emmanuel Bourg: > Le 28/08/2018 à 15:25, Markus Koschany a écrit : > >> I added a new rule to debian/maven.rules >> >> org.apache.xbean maven-xbean-plugin * s/.*/4\.5/ * * >> >> Expected behavior: >> >> The version i

Bug#907750: freesweep: Hangs very bad when terminal size is changed

2018-09-03 Thread Markus Koschany
Control: forwarded -1 https://github.com/rwestlund/freesweep/issues/3 Thanks for reporting! I can confirm that the game segfaults when the terminal size is smaller than the current board size. However I can't reproduce that the system hangs. Instead I receive this error message from the game:

Bug#907863: libeclipse-osgi-java, libequinox-osgi-java: error when trying to install together

2018-09-03 Thread Markus Koschany
Am 03.09.2018 um 15:38 schrieb Emmanuel Bourg: > Hi Markus, > > Le 03/09/2018 à 14:48, Markus Koschany a écrit : > >> I think this could have been better communicated. I was the one who >> split libequinox-osgi-java off from Eclipse. Why can't we just use the >&g

Bug#907863: libeclipse-osgi-java, libequinox-osgi-java: error when trying to install together

2018-09-03 Thread Markus Koschany
Hi, Am 03.09.2018 um 14:04 schrieb Emmanuel Bourg: > Control: reassign -1 libeclipse-osgi-java > Control: affects -1 libequinox-osgi-java > > libeclipse-osgi-java will replace libequinox-osgi-java. I forgot to add > the proper Breaks/Replaces fields. I think this could have been better

Bug#905000: minetest: does not use fullscreen resolution over VGA

2018-09-01 Thread Markus Koschany
Hi, On Mon, 30 Jul 2018 11:55:19 +0100 Phil Morrell wrote: > Package: minetest > Version: 0.4.17.1+repack-1~bpo9+1 > Severity: normal > > > Hi, > > With my current monitor the maximum resolution is not autodetected, so I > have configured xrandr to add a new mode and this works perfectly for

Bug#907756: freecol: multiple warnings from AppStream metadata

2018-09-01 Thread Markus Koschany
Am 01.09.2018 um 14:53 schrieb Jeremy Bicha: [...] > In my testing, these issues seem to prevent FreeCol from showing up in > the GNOME Software app. Just tested it with GNOME Software in Buster. FreeCol shows up there. signature.asc Description: OpenPGP digital signature

Bug#907756: freecol: multiple warnings from AppStream metadata

2018-09-01 Thread Markus Koschany
Am 01.09.2018 um 14:53 schrieb Jeremy Bicha: > Source: freecol > Version: 0.11.6+dfsg2-2 > > There are still multiple issues with the Appstream metadata for > freecol. See the reference below. > > In my testing, these issues seem to prevent FreeCol from showing up in > the GNOME Software app. >

Bug#907661: freecol: Does not start up with OpenJDK 10

2018-08-31 Thread Markus Koschany
Control: tags -1 pending confirmed Control: severity -1 grave On Thu, 30 Aug 2018 21:42:17 +0100 Johannes Kloos wrote: > Package: freecol > Version: 0.11.6+dfsg2-1 > Severity: important > Tags: patch > > Dear Maintainer, > > The freecol package tries to start up the JVM for freecol with the >

Bug#885751: teg: Port to GooCanvas / GTK+ 3 / GSettings

2018-08-30 Thread Markus Koschany
Am 30.08.2018 um 01:53 schrieb Yavor Doganov: > tags 885751 + patch > thanks > > Attached are patches that should fix this bug completely (removing all > dependencies on old libraries that are scheduled for removal), plus > the following issues of non-RC severity: [...] Yavor, thank you very

Bug#907559: cgview: Does not start

2018-08-29 Thread Markus Koschany
Am 29.08.2018 um 19:31 schrieb Andreas Tille: [...] >> Maybe you should raise this issue with upstream (Batik and/or cgview) > > Well cgview is not actively maintained (but has quite a number of users) > and what exactly should I say to Batik upstream if they decided to move > it to a noew

Bug#907057: neverball: Constant fsync calls seriously degrade performance

2018-08-29 Thread Markus Koschany
Am 29.08.2018 um 15:08 schrieb Uoti Urpala: > On Mon, 2018-08-27 at 23:13 +0200, Markus Koschany wrote: >> Am 27.08.2018 um 03:36 schrieb Uoti Urpala: >>> Neverball is broken so at least a bug blocked by a physfs bug would be >>> appropriate in any case, and I assume

Bug#906350: doxia: FTBFS in buster/sid (Cannot find parent dependency org.apache.maven:maven-parent:pom:27)

2018-08-29 Thread Markus Koschany
Control: tags -1 confirmed > [ERROR] The build could not read 1 project -> [Help 1] > [ERROR] > [ERROR] The project org.apache.maven.doxia:doxia:1.7 > (/<>/pom.xml) has 1 error > [ERROR] Invalid packaging for parent POM > org.apache.maven:maven-parent:27, must be "pom" but is "jar" @

Bug#907554: maven-debian-helper: relocations do not work for packaging type pom

2018-08-29 Thread Markus Koschany
Package: maven-debian-helper Version: 2.3 Severity: normal While I was investigating RC bug #906350 in doxia, I discovered that the root cause of the build failure is the relocation of org.apache.maven:maven-parent in libmaven-parent-java. Apparently the idea was to redirect the current version

Bug#907477: maven-debian-helper: does not substitute values of plugins with maven.rules

2018-08-28 Thread Markus Koschany
Package: maven-debian-helper Version: 2.3 Severity: normal Currently mina2 version 2.0.16-2 fails to build from source because Plugin org.apache.xbean:maven-xbean-plugin:4.1 or one of its dependencies could not be resolved: Cannot access central (https://repo.maven.apache.org/maven2) in offline

Bug#907057: neverball: Constant fsync calls seriously degrade performance

2018-08-27 Thread Markus Koschany
clone 907057 -1 retitle -1 libphysfs: constant fsync calls seriously degrade performance reassign -1 src:libphysfs affects -1 neverball thanks Am 27.08.2018 um 03:36 schrieb Uoti Urpala: > On Sun, 2018-08-26 at 17:59 +0200, Markus Koschany wrote: >> On Thu, 23 Aug 2018 17:56:01 +0300 Uo

Bug#906447: tomcat8: Errors thrown when connecting

2018-08-27 Thread Markus Koschany
Am 27.08.2018 um 07:32 schrieb Per Lundberg: > On 8/26/18 12:46 AM, Markus Koschany wrote: > >> I believe we should tighten the dependency on default-jre-headless. We >> currently have for tomcat8-common: >> >> default-jre-headless | java8-runtime-headless | java8-

Bug#907386: stretch-pu: package libcgroup/0.41-8

2018-08-27 Thread Markus Koschany
: #906308) + + -- Markus Koschany Sun, 19 Aug 2018 23:10:45 +0200 + libcgroup (0.41-8) unstable; urgency=medium * Drop package libcgroup-dbg in favor of automatic dbgsym packages. diff -Nru libcgroup-0.41/debian/patches/CVE-2018-14348.patch libcgroup-0.41/debian/patches/CVE-2018-14348.patch

Bug#907057: neverball: Constant fsync calls seriously degrade performance

2018-08-26 Thread Markus Koschany
On Thu, 23 Aug 2018 17:56:01 +0300 Uoti Urpala wrote: > Package: neverball > Version: 1.6.0-8 > Severity: important > > Neverball automatically saves a replay of the latest run on disk while > playing. In the Debian package, the binary constantly calls fsync() on > this file, which very

Bug#906384: lucene-solr: FTBFS in buster/sid

2018-08-25 Thread Markus Koschany
Am 25.08.2018 um 23:27 schrieb Markus Koschany: > Control: tags -1 pending > > The FTBFS was caused by the latest upgrade of libwoodstox-java. The jar > files were renamed and could not be found anymore. > > I am quite sure this is related to #904063 somehow. Once #906447 is

Bug#906447: tomcat8: Errors thrown when connecting

2018-08-25 Thread Markus Koschany
On Fri, 17 Aug 2018 20:50:14 +0300 Vassilis Virvilis wrote: [...] > With java8 installed I am getting the following. Isn't this the sign that is > compiled again against java9/java10? > > 2018-08-17 16:20:46] [crit] java.lang.NoSuchMethodError: >

Bug#906384: lucene-solr: FTBFS in buster/sid

2018-08-25 Thread Markus Koschany
Control: tags -1 pending The FTBFS was caused by the latest upgrade of libwoodstox-java. The jar files were renamed and could not be found anymore. I am quite sure this is related to #904063 somehow. Once #906447 is resolved I could try to verify this assumption. Markus signature.asc

Bug#898935: Tomcat 8 security issues in Stretch

2018-08-24 Thread Markus Koschany
A security update has been sent to Debian's security team and we expect that the current open issues in Stretch will be fixed in due time. Please note that Tomcat 7 in Stretch is not vulnerable to any of those issues because we only build the servlet API. Regards, Markus signature.asc

Bug#898935: migrate fix to stretch security

2018-08-24 Thread Markus Koschany
Version: 8.5.32-1 This issue was fixed in 8.5.32-1. I am going to close this bug report now. Markus signature.asc Description: OpenPGP digital signature

Bug#898935: migrate fix to stretch security

2018-08-24 Thread Markus Koschany
Am 24.08.2018 um 09:30 schrieb Bogdan Veringioiu: > Hello all, > > is there any plan to migrate the fix to stretch security ? > > I would be interested in the fixes for CVE-2018-1304, CVE-2018-1305 > (resolved in 7.0.88, and in 8.5.32-1 testing) which are important for a > security certification

Bug#902861: axis: FTBFS with Java 10 due to com.sun.net.ssl removal

2018-08-23 Thread Markus Koschany
Am 24.08.2018 um 01:00 schrieb Emmanuel Bourg: >> This issue was apparently fixed in version 1.10.4-2. Axis can be rebuilt >> from source again. > > Actually the issue was triggered by the automatic use of the --release > javac option in ant/1.10.3-2, the flag removed the internal com.sun.net >

Bug#902570: asm: Package rebuilt from source gets lots of empty jars

2018-08-23 Thread Markus Koschany
Control: tags -1 confirmed On Wed, 27 Jun 2018 21:12:35 -0700 Daniel Schepler wrote: > Source: asm > Version: 6.0-1 > Severity: serious > > When I build src:asm using pbuilder, the build completes without > errors. However, then the generated deb file contains mostly empty > jars - the only

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Am 23.08.2018 um 15:55 schrieb Emmanuel Bourg: > On 23/08/2018 13:14, Markus Koschany wrote: >> Apparently upstream doesn't consider this "to be their problem". Since >> simple-xml has no reverse-dependencies and the current uploader is MIA, >> I think we should

Bug#888547: CVE-2017-1000190

2018-08-23 Thread Markus Koschany
Apparently upstream doesn't consider this "to be their problem". Since simple-xml has no reverse-dependencies and the current uploader is MIA, I think we should consider requesting the removal of simple-xml. Markus signature.asc Description: OpenPGP digital signature

Bug#906911: ublock-origin logger window opens empty

2018-08-22 Thread Markus Koschany
Control: tags -1 confirmed Am 22.08.2018 um 09:51 schrieb mercedes508: > Package: webext-ublock-origin > Version: 1.16.14+dfsg-1 > Severity: normal > > Bug: When using this version of ublock-origin on FF ESR 60 on Debian Buster, > when trying to open its logs by clicking on its corresponding

Bug#885740: gnomekiss: Port to GTK+ 3

2018-08-21 Thread Markus Koschany
Am 21.08.2018 um 11:41 schrieb Yavor Doganov: > Yavor Doganov wrote: >> Please find attached a patch that ports the program to GTK+ 3. > > I wasn't careful enough; my patch introduces memory leaks. Please > find attached an updated version (compressed); please use it instead. > Thanks. Hey,

Bug#906785: version warping patch is overly aggressive

2018-08-21 Thread Markus Koschany
Am 21.08.2018 um 19:47 schrieb Keith Packard: [...] > We only discovered that ant was the source of trouble by comparing the > output of a project built using that and another project build using a > simple Makefile. > > If you're going to stop supporting older API versions, I'd suggest that >

Bug#906785: version warping patch is overly aggressive

2018-08-21 Thread Markus Koschany
Am 21.08.2018 um 18:49 schrieb Bdale Garbee: > Markus Koschany writes: [...] >> I think the patch could be removed for OpenJDK 11 but should be applied >> for OpenJDK 12 again. All build tools already emit a deprecation warning >> for source/target 1.6, so developers and

Bug#906785: version warping patch is overly aggressive

2018-08-21 Thread Markus Koschany
Hi Bdale, we all assumed that OpenJDK 11 will remove support for source/target 1.6. After a discussion on the OpenJDK mailing list they decided to postpone this change for OpenJDK 12. [1] The current patch simplifies our packaging work because we don't have to manually fix packages that still

Bug#906308: CVE-2018-14348

2018-08-19 Thread Markus Koschany
to write to it. (Closes: #906308) + + -- Markus Koschany Sun, 19 Aug 2018 23:10:45 +0200 + libcgroup (0.41-8) unstable; urgency=medium * Drop package libcgroup-dbg in favor of automatic dbgsym packages. diff -Nru libcgroup-0.41/debian/patches/CVE-2018-14348.patch libcgroup-0.41/debian/patches

Bug#885735: gamazons: Port to GooCanvas / GTK+ 3

2018-08-18 Thread Markus Koschany
Control: tags -1 pending Hi, thank you very much for your patch! The game looks playable to me again. I have applied your patch and uploaded a new revision. Good work! Cheers, Markus signature.asc Description: OpenPGP digital signature

Bug#902720: CVE-2018-1000544

2018-08-15 Thread Markus Koschany
be exploited to write arbitrary files to +the filesystem. (Closes: #902720) + * Drop CVE-2017-5946.patch because this one was already fixed in version +1.2.1. + + -- Markus Koschany Mon, 13 Aug 2018 13:57:54 +0200 + ruby-zip (1.2.1-1) unstable; urgency=medium * Team upload diff -Nru ruby-zip

Bug#893184: artemis FTBFS with openjdk-9

2018-08-14 Thread Markus Koschany
Hi, Am 13.08.2018 um 13:23 schrieb Andreas Tille: [...] > I tried hard to add junit4.jar to the classpath but my attempts failed. > It should be done in the latest quilt patch in test/build-test.xml but > I have no idea how to use it properly (I actually think all *.jar in > /usr/share/java are

Bug#903428: javadocs generated by javahelper include jquery

2018-08-11 Thread Markus Koschany
Hi tony, Am 11.08.2018 um 20:12 schrieb tony mancill: [...] > Hi Markus, > > I'm glad that you were able to discuss this directly with Matthias, and > thank you for sharing the gist of that conversation. For our sanity, I > will take a look to see if we can get the severity of the lintian >

Bug#905904: ITP: libmbassador-java -- feature-rich Java event bus optimized for high-throughput

2018-08-11 Thread Markus Koschany
Package: wnpp Severity: wishlist Owner: Markus Koschany * Package name: libmbassador-java Version : 1.3.1 Upstream Author : Benjamin Diedrichsen * URL : https://github.com/bennidi/mbassador * License : MIT Programming Lang: Java Description : feature

Bug#903428: javadocs generated by javahelper include jquery

2018-08-11 Thread Markus Koschany
FTR: I have talked to Matthias Klose (doko) at DebConf18 about the embedding of jquery into javadoc packages. He pointed me to a similar discussion in doxygen which also embeds jquery while building doc packages. In short he doesn't consider it to be a worthwhile task because there is a risk of

Bug#877040: Bug 877040: Transition script for xul-ext-ublock-origin->webext-ublock-origin

2018-08-10 Thread Markus Koschany
Hi folks, I have prepared a new upstream version of ublock-origin which is now available in our Git repository. Regarding #877040 I have installed the ublock_migration.sh script into /usr/share/doc/webext-ublock-origin and explained the usage with a NEWS file. I believe it is best to let the user

Bug#905748: debian-games: Please bring back games-finest-light

2018-08-08 Thread Markus Koschany
Hi Axel, Am 08.08.2018 um 23:02 schrieb Axel Beckert: > Source: debian-games > Severity: wishlist > Version: 2.4 > > The debian/changelog entry for 2.4 says: > >* Remove finest-light binary package. Nowadays modern computers should be > capable of running all free software games in

Bug#830876: A new love version has been released

2018-08-03 Thread Markus Koschany
Hi, Am 03.08.2018 um 03:41 schrieb Reiner Herrmann: [...] > I updated the copyright file (which seems to be the biggest blocker) in > my [merge request] on salsa. It is based on the current 11.1 release and > is building for me with pbuilder, but I haven't tested building reverse > dependencies.

Bug#883950: Next steps on "[GPL-3+]" proposal

2018-08-02 Thread Markus Koschany
Am 03.08.2018 um 00:59 schrieb Russ Allbery: > Markus Koschany writes: > >> You appear more concerned about one parser, Lintian, than about the >> human maintainers who have to update d/copyright again. You argue that >> the maintainers have to update d/copyright anywa

Bug#883950: Next steps on "[GPL-3+]" proposal

2018-08-02 Thread Markus Koschany
Am 02.08.2018 um 16:27 schrieb gregor herrmann: > On Thu, 02 Aug 2018 15:13:26 +0800, Markus Koschany wrote: > >> Nothing will break because no tool besides Lintian checks >> debian/copyright for copyright format 1.0 compatibility. > > This is not correct. >

Bug#883950: Next steps on "[GPL-3+]" proposal

2018-08-02 Thread Markus Koschany
Am 02.08.2018 um 12:43 schrieb Russ Allbery: > Markus Koschany writes: > >> Please keep it simple. I disagree that we would need a version bump of >> copyright format 1.0 which had to be documented in every >> debian/copyright file again by changing the Format field. A s

Bug#904729: Policy 12.5: Must the license grant be included in debian/copyright?

2018-08-01 Thread Markus Koschany
FYI: Here is what one of the ftp-masters, Jörg Jaspert, wrote in response to my proposal to reduce boilerplate in debian/copyright. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883950#80 I believe it shows the generally tendency that they are in favor of the proposal. Regards, Markus

Bug#883950: Next steps on "[GPL-3+]" proposal

2018-08-01 Thread Markus Koschany
First of all let me thank Sean for moving this issue forward. Let me also reiterate what the whole point of this bug report is again. The bug reporter, myself and others would like to reduce the unnecessary amount of boilerplate in debian/copyright. The brackets are not the important part of our

Bug#848165: freeciv-client-qt: crash at exit ...leavegame->quit

2018-08-01 Thread Markus Koschany
Hi Jacob, I have uploaded Freeciv 2.6.0 to Debian unstable. Could you tell me which open Debian bug reports you consider still upstream bugs that you would like to fix at some point it the future? Then I would triage them accordingly. Some of them are very old (like #150757) and I don't know if

Bug#575691: childsplay-alphabet-sounds-fr: Incoherent vocal descriptions and pictures in French version of flashcard

2018-07-30 Thread Markus Koschany
The flashcard game was disabled by upstream. I don't believe this issue will be addressed anytime soon. Markus signature.asc Description: OpenPGP digital signature

Bug#904953: funguloids: Updated mpak.py

2018-07-29 Thread Markus Koschany
Source: funguloids Version: 1.06-13 Severity: wishlist For reference: Hans de Goede submitted an updated mpak.py file to our debian-devel-games mailing list. This might become RC if funguloids starts to FTBFS on Debian too. https://lists.debian.org/debian-devel-games/2018/07/msg00031.html

Bug#899183:

2018-07-27 Thread Markus Koschany
Am 27.07.2018 um 18:21 schrieb Andrea Vacondio: > Ok, I see that 2.0.11-1 works correctly but I'm a bit lost. I compiled > PDFBox using openjdk 10.0.2 with target/source 1.7 but I still get the > issue with my generated fontbox jar... see mine on the left has the > ByteBuffer return type causing

Bug#899183:

2018-07-27 Thread Markus Koschany
Am 27.07.2018 um 15:12 schrieb Andrea Vacondio: > Why not compile with --release 7 ? This way the generated bundle should > work with java 7 and above, or am I missing something? > My app is hit by this > https://bugs.launchpad.net/ubuntu/+source/pdfsam/+bug/1781130 and users > are currently

Bug#904680: Regression in security update deb8u3 - "We're sorry, we hit a bug!"

2018-07-26 Thread Markus Koschany
Control: tags -1 pending Thank you for the report. This issue will be fixed shortly. Regards, Markus signature.asc Description: OpenPGP digital signature

Bug#892058: debian-keyring: please automatically send reminder emails to people whose keys will expire soon

2018-07-24 Thread Markus Koschany
Hello, On Mon, 5 Mar 2018 10:04:22 + Jonathan McDowell wrote: > On Sun, Mar 04, 2018 at 08:02:35PM +0100, Ximin Luo wrote: > > > For security, I set a short validity period on my key and renew this > > every year by repeatedly extending the expiry date. However I keep > > forgetting to send

Bug#883950: Next steps on "[GPL-3+]" proposal

2018-07-23 Thread Markus Koschany
Hello, Am 29.12.2017 um 10:18 schrieb Sean Whitton: > user debian-pol...@packages.debian.org > usertags 883950 = normative discussion > thanks > > Hello, > > On Thu, Dec 28 2017, Markus Koschany wrote: > >> the Policy editors request your attention and a de

Bug#886394:

2018-07-20 Thread Markus Koschany
Hello Andrea, Am 20.07.2018 um 15:52 schrieb Andrea Vacondio: > PDFsam is developed using Java 8 and JavaFX. It should work on higher > versions provided they come with their JavaFX, as far as I know Oracle > JDK still bundles JavaFX, with a plan to separate the two soon. OpenJDK > already

Bug#897885: wbar: ftbfs with GCC-8

2018-07-19 Thread Markus Koschany
On Tue, 17 Jul 2018 22:18:57 +0300 Juhani Numminen wrote: [...] > Ah, it is the lovely -Werror. > > It seems that gcc-8 build succeeds when I add this line in debian/rules: > > export DEB_CXXFLAGS_MAINT_APPEND = -Wno-error I think this is sensible here. I will update the package as soon as

Bug#857939: [libtcnative-1] Does not work without symlink

2018-07-18 Thread Markus Koschany
Am 18.07.2018 um 13:41 schrieb Harald Dunkel: > Asking all Java Standard Edition users to perform some manual > configuration steps is not helpful. They will just dislike both > your package and openjdk for being different to the "real" > Java version they are used to. > > Just my $0.02. Regards

Bug#903428: Got hit by #903428 too

2018-07-17 Thread Markus Koschany
Am 17.07.2018 um 01:15 schrieb Martin Quinson: > Hello, > > I'm building a package that provide some javadoc, so I got hit by that > bug myself too. The solution you propose (dropping javadoc packages) > does not exactly fit my needs, I must say ;) [...] A quick solution is to depend on

Bug#903428: javadocs generated by javahelper include jquery

2018-07-17 Thread Markus Koschany
Hi tony, Am 17.07.2018 um 07:00 schrieb tony mancill: [...] > > Hi Markus, > > Fair enough. I can see the value in providing javadoc (or at least a > way to build the javadoc) for older versions of libraries. > > I think Martin Quinson's suggestion of "shim" jquery package has some > merit.

Bug#903916: undertow: Keep it out of Buster

2018-07-16 Thread Markus Koschany
Source: undertow Version: 1.4.25-1 Severity: serious I am filing this bug report to prevent the migration of undertow to testing and subsequently being part of the next stable release Debian 10, "Buster". This was also briefly discussed with the Security Team. Reasons: - Undertow is regularly

Bug#903768: libimlib2: The message "Using O_TMPFILE" is flooding log file

2018-07-14 Thread Markus Koschany
Control: reassign -1 src: xorg-server Control: retitle -1 xorg-server: O_TMPFILE ErrorF should be DebugF Control: found -1 2:1.19.6-1 Control: fixed -1 2:1.20.0-1 Am 14.07.2018 um 16:27 schrieb Dtux: > Package: libimlib2 > Version: 1.4.8-1 > Severity: normal > > Dear Maintainer, > > libimlib2

Bug#903428: javadocs generated by javahelper include jquery

2018-07-11 Thread Markus Koschany
Hi tony, Am 10.07.2018 um 05:22 schrieb tony mancill: [...] > I'm in favor of dropping the -java-doc packages completely and instead > using our time and effort to improve the state of our runtime libraries, > toolchain and application packages. (It would be a different story if > we were

Bug#903428: javadocs generated by javahelper include jquery

2018-07-09 Thread Markus Koschany
Am 09.07.2018 um 23:35 schrieb Emmanuel Bourg: > Le 09/07/2018 à 23:29, Markus Koschany a écrit : > >> We should really aim for the simplest solution. Actually I don't see any >> need to patch the javadoc tool because we could easily solve this at the >> packaging level. J

Bug#903428: javadocs generated by javahelper include jquery

2018-07-09 Thread Markus Koschany
Am 09.07.2018 um 23:26 schrieb Emmanuel Bourg: > Le 09/07/2018 à 23:14, Markus Koschany a écrit : > >> I believe the use case of viewing javadoc outside of a Debian >> system is negligible and we should just symlink jquery. > > Viewing an API documentation from a lib*-

Bug#903428: javadocs generated by javahelper include jquery

2018-07-09 Thread Markus Koschany
Am 09.07.2018 um 23:01 schrieb Emmanuel Bourg: > Le 09/07/2018 à 22:41, Christoph Berg a écrit : > >> Or even better, have javadoc put in the symlink. > > Not a good idea. The javadoc generated would no longer be usable outside > Debian. Developers would no longer be able to generate the javadoc

Bug#902991: tomcat 7.0.56-3+really7.0.88-* regression

2018-07-05 Thread Markus Koschany
Control: retitle -1 jetty8: missing symlink to tomcat-coyote.jar Control: reassign -1 libjetty8-extra-java Control: found -1 8.1.16-4 Am 05.07.2018 um 09:35 schrieb Sébastien QUESSON: [...] > With tomcat-coyote-7.0.56-3+really7.0.88-2, UriUtil class is found: > jar tvf

Bug#902991: tomcat 7.0.56-3+really7.0.88-* regression

2018-07-04 Thread Markus Koschany
Hello, Am 04.07.2018 um 17:54 schrieb Sébastien QUESSON: [...] > Caused by: > javax.servlet.ServletException: java.lang.NoClassDefFoundError: > org/apache/tomcat/util/buf/UriUtil > ... > Caused by: > java.lang.NoClassDefFoundError: org/apache/tomcat/util/buf/UriUtil > at >

Bug#892278: stretch-pu: package reportbug/7.1.7+deb9u1

2018-07-03 Thread Markus Koschany
Am 03.07.2018 um 21:10 schrieb Adam D. Barratt: > Control: tags -1 + confirmed > > On Wed, 2018-03-07 at 17:53 +0100, Markus Koschany wrote: >> as requested in #891918 I am hereby filing another stretch-pu update >> for reportbug, so that we can fix #878088 in stable too. Pl

Bug#892278: stretch-pu: package reportbug/7.1.7+deb9u1

2018-07-03 Thread Markus Koschany
Am 03.07.2018 um 01:36 schrieb Andreas Beckmann: > On Wed, 07 Mar 2018 17:53:39 +0100 Markus Koschany wrote: >> as requested in #891918 I am hereby filing another stretch-pu update >> for reportbug, so that we can fix #878088 in stable too. Please find >> attached the debd

<    5   6   7   8   9   10   11   12   13   14   >