Bug#934901: Please switch to Python 3 or remove your package from Sid/Bullseye

2019-08-16 Thread Thomas Goirand
Package: python-gpiv Version: 2.0.0-4.2 Severity: serious Hi, As we're removing Python 2 from Bullseye, we need your package to be either switched to Python 3, or removed from Sid/Bullseye. Please let everyone know your intention ASAP. Cheers, Thomas Goirand (zigo)

Bug#934858: Please port viewvc to Python 3 or get it removed from Sid/Bullseye

2019-08-15 Thread Thomas Goirand
to do so, or drop the package from Bullseye (and continue to maintain it for the next 5 years in Buster). Your thoughts? Cheers, Thomas Goirand (zigo)

Bug#934787: Please switch to Python 3

2019-08-14 Thread Thomas Goirand
Source: live-wrapper Version: 0.10 Severity: important Hi, We're trying to remove Python 2.x from Bullseye. Please switch this package to Python 3. I had a quick look into it, and it does seem Py3 ready. Is there any blocker? Cheers, Thomas Goirand (zigo)

Bug#849091: Port to Python 3 and python3-gst-1.0

2019-08-14 Thread Thomas Goirand
say? Thomas Goirand (zigo)

Bug#934711: Please package latest upstream, and switch to Python 3

2019-08-13 Thread Thomas Goirand
, and remove Python 2 support / use. Cheers, Thomas Goirand (zigo)

Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-06 Thread Thomas Goirand
eed, it has a single reverse build-depends. Closing the RM bug then. I'd still advise upstream against using this library which is of lower code quality. Cheers, Thomas Goirand (zigo)

Bug#933935: RM: python-tuskarclient -- ROM; Deprecated, not used

2019-08-05 Thread Thomas Goirand
Package: ftp.debian.org Severity: normal Dear FTP masters, The Tuskar project was retired long ago, and no package is using python-tuskarclient anymore. It's time to get this out of Debian. I probably should have done this before Buster... :/ Thomas Goirand (zigo)

Bug#933821: python-tuskarclient (build-)depends on cruft package.

2019-08-05 Thread Thomas Goirand
binary packages which are no > longer built by the corresponding source packages. > > If this is going to stay around it looks like it needs to migrate to > python 3. Hi, I've filled an RM bug for this package, so it will go away... The Tuskar project has been retired a long time ago, so this is overdue. Thomas Goirand (zigo)

Bug#933933: RM: python-tablib -- ROM; Deprecated, unsupported, unused

2019-08-05 Thread Thomas Goirand
python-tablib package from Debian before it starts to really gather too much dust. Cheers, Thomas Goirand (zigo)

Bug#933921: src:python-tablib: Unsafe use of yaml.load()

2019-08-05 Thread Thomas Goirand
e just filed a removal bug for this one, as it's not used by any OpenStack things anymore. Cheers, Thomas Goirand (zigo)

Bug#932943: Missing SHA512 and gpg signature

2019-08-05 Thread Thomas Goirand
-512 only, personally. > > Only one of them. And I would go directly to SHA3 for new stuff. Unfortunately, OpenStack Glance only shows SHA512, not SHA3, so even if we do both, we must keep SHA2 512. Cheers, Thomas Goirand (zigo)

Bug#933641: growpart doesn't work if sfdisk output is in french

2019-08-02 Thread Thomas Goirand
run the way you do, so that's kind of expected. For doing what you're doing, there's more standard tools like parted and such to do it. I'm therefore closing this bug, unless you want to actually patch the software yourself, and explain your use case. Cheers, Thomas Goirand (zigo)

Bug#931173: Also breaks official Openstack Debian

2019-07-30 Thread Thomas Goirand
e eth0 inet static >     address 10.110.10.45/24 >     gateway 10.110.10.1 > > # control-alias eth0 > iface eth0 inet6 dhcp > ---- > > If I pass a dhcp configuration to cloud-config, the image fails to boot. Hi, If you intend to do that, why don't you simply remove /etc/network/interfaces then (maybe with a userscript...)? Cheers, Thomas Goirand (zigo)

Bug#933318: python-os-cloud-config (build-)depends on cruft packages.

2019-07-30 Thread Thomas Goirand
od catch. I just requested its removal, it's of no use in Debian. Cheers, Thomas Goirand (zigo)

Bug#933503: RM: python-os-cloud-config -- ROM; No need for this package in Debian

2019-07-30 Thread Thomas Goirand
Package: ftp.debian.org Severity: normal Hi, We don't need this package in Debian unless someone wants to do the huge task of porting TripleO to Debian. Let's remove it. Cheers, Thomas Goirand (zigo)

Bug#931766: buster-pu: package openvswitch/2.10.0+2018.08.28+git.8ca7c82b7d+ds1-12+deb10u1 - new debdiff

2019-07-29 Thread Thomas Goirand
Closes: #931104). + + -- Thomas Goirand Mon, 24 Jun 2019 08:53:33 +0200 + openvswitch (2.10.0+2018.08.28+git.8ca7c82b7d+ds1-12) unstable; urgency=medium * Add --may-exist in debian/ifupdown.sh as per upstream commit. Without it, diff -Nru openvswitch-2.10.0+2018.08.28+git.8ca7c82b7d+ds1/debian/c

Bug#933215: Please remove Python 2 use in this package

2019-07-27 Thread Thomas Goirand
Package: heudiconv Severity: important Hi, Please get rid of all Python 2 in this package, as we're removing it from Sid. Once done, we can get rid of Py2 support in python-datalad and then, in python-httpretty. I'd appreciate a ping when this is done. Cheers, Thomas Goirand (zigo)

Bug#933146: FTBFS, not Django 2.2 ready

2019-07-26 Thread Thomas Goirand
LEASED; urgency=medium +python-django-rosetta (0.7.6-1) unstable; urgency=medium [ Michael Fladischer ] * New upstream release. @@ -24,7 +24,14 @@ * d/watch: Use https protocol * Convert git repository from git-dpm to gbp layout - -- Michael Fladischer Tue, 04 Aug 2015 09:47:58

Bug#933143: FTBFS, not Django 2.2 ready

2019-07-26 Thread Thomas Goirand
Package: python-django-mptt Version: 0.8.7-1 Severity: serious Tags: patch Hi, Please find attached patch to do the Python 2 removal. After this patch, your package continues to FTBFS. Please get a fix for it. Cheers, Thomas Goirand (zigo) From 373d818427a37e26e91b5e39084c634ce1d3c613 Mon Sep

Bug#933130: FTBFS, not Django 2.2 ready

2019-07-26 Thread Thomas Goirand
ned exit code 13 make[1]: *** [debian/rules:13: override_dh_auto_test] Error 255 make[1]: Leaving directory '/<>' make: *** [debian/rules:9: build] Error 2 dpkg-buildpackage: error: debian/rules build subprocess returned exit status 2 ------------

Bug#932960: python-django don't fix CVE and drop Python 2 support at the same time

2019-07-26 Thread Thomas Goirand
hon 2 support *now* for all the Django packages. I did a lot of that work already (at least a dozen of packages are fixed already), there's not so much remaining. Also, Django 2.2 does *not* have Python 2 support upstream anymore, so there's no way we can maintain this by ourselves. Cheers, Thomas Goirand (zigo)

Bug#932985: Please remove Python 2 support

2019-07-25 Thread Thomas Goirand
@@ -django-session-security (2.6.5+dfsg-2) UNRELEASED; urgency=medium +django-session-security (2.6.5+dfsg-2) unstable; urgency=medium + [ Ondřej Nový ] * Use debhelper-compat instead of debian/compat. * Bump Standards-Version to 4.4.0. + [ Thomas Goirand ] + * Team upload. + * Removed

Bug#932983: Please remove python2 support from your package

2019-07-25 Thread Thomas Goirand
Source: django-restricted-resource Version: 2016.8-2 Severity: serious Tags: patch Hi, Please see attached quick and dirty patch to remove Python 2 support from your module, which is needed since the upload of Django 2.2. in Sid. Cheers, Thomas Goirand (zigo) diff --git a/debian/changelog b

Bug#932981: Please remove Python 2 support for this package

2019-07-25 Thread Thomas Goirand
Source: django-ranged-response Version: 0.2.0-1 Severity: serious Tags: patch Hi, Attached is a patch to remove Python 2 support for this package, needed since the upload of Django 2.2 in Sid. Please apply and upload. Cheers, Thomas Goirand (zigo) diff -Nru django-ranged-response-0.2.0/debian

Bug#932943: Missing SHA512 and gpg signature

2019-07-24 Thread Thomas Goirand
add a SHA512, then we can see later how we can sign the json file. Cheers, Thomas Goirand (zigo)

Bug#932827: django-compat: broken with Django 2.2, FTBFS, not ready

2019-07-23 Thread Thomas Goirand
has to be removed from this package. I tried to work on this, but it doesn't look trivial. Cheers, Thomas Goirand (zigo)

Bug#932806: ITP: golang-github-coreos-discovery-etcd-io -- etcd discovery service

2019-07-23 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: golang-github-coreos-discovery-etcd-io Version : 2+git20190513.6.78fb45d Upstream Author : CoreOS * URL : https://github.com/coreos/discovery.etcd.io * License : Apache-2.0 Programming

Bug#932805: ITP: golang-github-rsc-devweb -- development web server

2019-07-23 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: golang-github-rsc-devweb Version : 0.0~git20160115.0.29cc9e1 Upstream Author : Russ Cox * URL : https://github.com/rsc/devweb * License : BSD-3-clause Programming Lang: Go Description

Bug#932573: RM: python-weakrefmethod -- ROM; Python 2 only, no reverse (b-)depends

2019-07-20 Thread Thomas Goirand
Package: ftp.debian.org Severity: normal Hi, python-weakrefmethod is a Python 2 port of a Python 3.4 feature. As the previous (b-)reverse dependencies moved to Python 3, we don't need this anymore. Please remove this package. Cheers, Thomas Goirand (zigo)

Bug#932566: RM: tripleo-image-elements -- ROM; not used in debian

2019-07-20 Thread Thomas Goirand
Package: ftp.debian.org Severity: normal Hi, Please remove tripleo-image-elements, it's not in use anywhere in Debian, unless someone wants to try working on TripleO, which I don't think will happen anytime soon. Thomas Goirand (zigo)

Bug#932545: RM: python-xmlbuilder -- ROM; No upstream, python 2 only

2019-07-20 Thread Thomas Goirand
, but this will anyway wait in the NEW queue, so removing this package is still the way to go. Cheers, Thomas Goirand (zigo)

Bug#932543: Please switch to Python 3

2019-07-20 Thread Thomas Goirand
Package: python-pbcommand Version: 1.1.1-1 Severity: serious Hi, Your package is Python 2 only, please switch it to Python 3 (only), as I'm removing Python 2 support in python-xmlbuilder which is a reverse build dependency. Cheers, Thomas Goirand (zigo)

Bug#932542: Please switch to Python 3

2019-07-20 Thread Thomas Goirand
Source: nipype Severity: serious Hi, Please make nipype use Python 3, as it wont have python-xvfbwrapper support for Python 2 in a few minutes (I'll be uploading in a few minutes a version of python-xvfbwrapper that removes Python 2 support). Cheers, Thomas Goirand

Bug#932197: Please switch to Python 3

2019-07-16 Thread Thomas Goirand
Source: nipype Version: 1.1.9-1 Severity: important Hi, I'd like to switch python-xvfbwrapper to Python 3 only, and noticed that nipype only has Python 2 support. Python 2 is going to be removed from Sid/Testing. Please switch nipype to Python 3 only. Cheers, Thomas Goirand (zigo)

Bug#931789: Available patch

2019-07-10 Thread Thomas Goirand
Hi, Please accept this merge request, then build and upload, or let me NMU. https://salsa.debian.org/matrix-team/python-signedjson/merge_requests/1 Cheers, Thomas Goirand (zigo)

Bug#931789: Please remove Python 2 support

2019-07-10 Thread Thomas Goirand
-signedjson needs python-canonicaljson that needs python-extras. So your package should be fixed first. Cheers, Thomas Goirand (zigo)

Bug#931787: RM: python-django-overextends -- ROM; no reverse dependencies

2019-07-10 Thread Thomas Goirand
python-django-overextends No reverse dependencies found So let's remove this package... Thomas Goirand (zigo)

Bug#931766: buster-pu: package openvswitch/2.10.0+2018.08.28+git.8ca7c82b7d+ds1-12+deb10u1 - new debdiff

2019-07-10 Thread Thomas Goirand
On 7/10/19 9:32 AM, Thomas Goirand wrote: > Package: release.debian.org > Severity: normal > Tags: buster > User: release.debian@packages.debian.org > Usertags: pu > > Hi, > > Please allow me to fixup OVS's missing python3-six dependency, and add > support for

Bug#931766: buster-pu: package openvswitch/2.10.0+2018.08.28+git.8ca7c82b7d+ds1-13

2019-07-10 Thread Thomas Goirand
of doc on how to set things up in /etc/network/interfaces. Cheers, Thomas Goirand (zigo) diff -Nru openvswitch-2.10.0+2018.08.28+git.8ca7c82b7d+ds1/debian/changelog openvswitch-2.10.0+2018.08.28+git.8ca7c82b7d+ds1/debian/changelog --- openvswitch-2.10.0+2018.08.28+git.8ca7c82b7d+ds1/debian

Bug#931616: buster-pu: package puppet-module-cinder/13.1.0-3+deb10u1

2019-07-08 Thread Thomas Goirand
f attached. Cheers, Thomas Goirand (zigo) diff -Nru puppet-module-cinder-13.1.0/debian/changelog puppet-module-cinder-13.1.0/debian/changelog --- puppet-module-cinder-13.1.0/debian/changelog2018-11-28 15:58:01.0 +0100 +++ puppet-module-cinder-13.1.0/debian/changelog2019-07

Bug#931615: buster-pu: package python-autobahn/17.10.1+dfsg1-3+deb10u1

2019-07-08 Thread Thomas Goirand
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, Please accept the update of python-autobahn fixing a problem in the (build-)dependencies. Debdiff attached. Cheers, Thomas Goirand (zigo) diff -Nru python-autobahn-17.10.1

Bug#931614: Fix release names after Buster release

2019-07-08 Thread Thomas Goirand
Package: devscripts Version: 2.19.5+deb10u1 Severity: important Tags: patch Hi, The attached patch fixes dch --bpo so that it does a backport for Buster, and not Stretch by default. Please upload this to Buster ASAP. Cheers, Thomas Goirand (zigo) diff --git a/debian/changelog b/debian

Bug#931608: buster-pu: package cloudkitty/8.0.0-4

2019-07-08 Thread Thomas Goirand
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu Hi, The attached debdiff fixes the FTBS. Details are in the relevant bugs (as per the debian/changelog). Please allow me to upload the fix to Buster. Cheers, Thomas Goirand (zigo

Bug#931609: Update release names after the Buster release.

2019-07-08 Thread Thomas Goirand
to do: "reportbug -b release.debian.org cloudkitty" selected stretch-pu, thinking I'll fix later on, but reportbug just crashed on me trying to fetch version numbers, as cloudkitty isn't in Stretch. This isn't nice at all... :) Cheers, Thomas Goirand (zigo) diff --git a/debian/changelo

Bug#931606: buster-pu: package cloudkitty/8.0.0-4+deb10u1

2019-07-08 Thread Thomas Goirand
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi, Cloudkitty FTBFS is fixed with the attached debdiff. Please allow me to upload this to Buster. Cheers, Thomas Goirand (zigo) diff -Nru cloudkitty-8.0.0/debian/changelog

Bug#931603: buster-pu: package puppet-module-cinder/13.1.0-3+deb10u1

2019-07-08 Thread Thomas Goirand
On 7/8/19 9:37 AM, Thomas Goirand wrote: > Package: release.debian.org > Severity: normal > Tags: stretch > User: release.debian@packages.debian.org > Usertags: pu > > Hi, > > While puppet-module-cinder works well if using the LVM backend, I discovered > that

Bug#931603: stretch-pu: package puppet-module-cinder/13.1.0-3+deb10u1

2019-07-08 Thread Thomas Goirand
is gone...). The attached debdiff fixes it. Please allow me to upload this fix to Buster. Cheers, Thomas Goirand (zigo) diff -Nru puppet-module-cinder-13.1.0/debian/changelog puppet-module-cinder-13.1.0/debian/changelog --- puppet-module-cinder-13.1.0/debian/changelog2018-11-28 15:58

Bug#931214: ImportError: No module named oslo.config

2019-07-01 Thread Thomas Goirand
On 6/30/19 7:40 AM, Paul Gevers wrote: > Hi Thomas, > > On 29-06-2019 23:02, Thomas Goirand wrote: >> On 6/29/19 10:12 AM, Paul Gevers wrote: >>> On Fri, 28 Jun 2019 13:52:43 +0200 =?iso-8859-1?Q?J=F6?= Fahlke >>> wrote: >>>> Package: python-os-collec

Bug#926943: closed by Thomas Goirand (Bug#926943: fixed in python-rtslib-fb 2.1.66-3)

2019-07-01 Thread Thomas Goirand
int release update. I know because I couldn't push an update for another package (cloudkitty, which FTBFS after an update of SQLAlchemy to address a CVE). Feel free to contribute it if you like. Cheers, Thomas Goirand (zigo)

Bug#931214: ImportError: No module named oslo.config

2019-06-29 Thread Thomas Goirand
It is, as long as you install pyhon-oslo.config. Of course, this needs to be fixed, as since it's too late for fixing before buster, I can do such a fix for the first point release. Cheers, Thomas Goirand (zigo)

Bug#930996: Bug#929321: Update for SQLAlchemy to address CVE-2019-7164 CVE-2019-7548

2019-06-28 Thread Thomas Goirand
On 6/27/19 8:39 PM, Paul Gevers wrote: > Hi Thomas, > > On 31-05-2019 01:34, Thomas Goirand wrote: >> Dear package maintainer, >> >> We're about to upgrade SQLAlchemy in Buster to address an SQL injection >> issue. The fixed package is in unstable, under the ve

Bug#931220: unblock: cloudkitty/8.0.0-5

2019-06-28 Thread Thomas Goirand
://review.opendev.org/#/c/668120/1/cloudkitty/storage/v1/sqlalchemy/__init__.py It's a simple one-liner... Cheers, Thomas Goirand (zigo) unblock cloudkitty/8.0.0-5

Bug#930996: Bug#929321: Update for SQLAlchemy to address CVE-2019-7164 CVE-2019-7548

2019-06-28 Thread Thomas Goirand
On 6/27/19 8:39 PM, Paul Gevers wrote: > Hi Thomas, > > On 31-05-2019 01:34, Thomas Goirand wrote: >> Dear package maintainer, >> >> We're about to upgrade SQLAlchemy in Buster to address an SQL injection >> issue. The fixed package is in unstable, under the ve

Bug#930862: Please correctly expose dpdk includes and libs

2019-06-21 Thread Thomas Goirand
how to do this yet. Cheers, Thomas Goirand (zigo)

Bug#930670: unblock: rabbitmq-server/3.7.8-5

2019-06-19 Thread Thomas Goirand
On 6/19/19 6:47 AM, Paul Gevers wrote: > Hi Thomas, > > On 18-06-2019 09:42, Thomas Goirand wrote: >> This last Debian release adds the packaging of rabbitmq-diagnostic in >> /usr/sbin, which is a very useful tool. It'd be a diss-service to our >> users to not have it i

Bug#930670: unblock: rabbitmq-server/3.7.8-5

2019-06-18 Thread Thomas Goirand
-service to our users to not have it in Buster, and I don't think this is controvertial at all. Not counting the removal of debian/gbp.conf (which we don't use anymore), the attached debdiff is a one-liner. unblock rabbitmq-server/3.7.8-5 Cheers, Thomas Goirand (zigo) diff -Nru rabbitmq-server-3.7.8

Bug#930058: unblock: puppet/5.5.10-3

2019-06-17 Thread Thomas Goirand
On 6/17/19 7:41 AM, Jonathan Wiltshire wrote: > On Mon, Jun 17, 2019 at 12:59:10AM +0200, Thomas Goirand wrote: >> I don't think people read more the NEWS than the changelog. > > I'm not sure how you arrive at that conclusion, but here's a consideration: > it's my company's po

Bug#930058: unblock: puppet/5.5.10-3

2019-06-16 Thread Thomas Goirand
On 6/15/19 7:54 PM, Paul Gevers wrote: > Control: tags -1 moreinfo > > Hi Thomas, > > On 06-06-2019 10:36, Thomas Goirand wrote: >> Version 5.5.10-3 adds a tiny cron.daily job which cleans-up the >> /var/lib/puppet/reports folder to avoid that a puppet-master >>

Bug#930357: stretch-pu: package miniupnpd/1.8.20140523-4.1+deb9u2 CVE-2019-12107, CVE-2019-12108, CVE-2019-12109, CVE-2019-12110

2019-06-11 Thread Thomas Goirand
: http://sid.gplhost.com/stretch-proposed-updates/miniupnpd/ Cheers, Thomas Goirand (zigo) diff -Nru miniupnpd-1.8.20140523/debian/changelog miniupnpd-1.8.20140523/debian/changelog --- miniupnpd-1.8.20140523/debian/changelog 2018-02-07 12:18:50.0 +0100 +++ miniupnpd-1.8.20140523

Bug#930134: Please package new upstream version

2019-06-11 Thread Thomas Goirand
On 6/10/19 9:59 PM, Jonas Meurer wrote: > Hi Thomas, > > Thomas Goirand: >>> do you have plans to update the python-falcon packages to a newer >>> upstream version (2.0.0 being the most recent one at the moment) >>> anytime soon? >>> >>> py

Bug#930134: [PKG-Openstack-devel] Bug#930134: Please package new upstream version

2019-06-11 Thread Thomas Goirand
ow, 1.0.0 to 1.4.1 is fine for OpenStack Stein (currently in Experimental). Let's see if I can upgrade to 1.4.1 then. Cheers, Thomas Goirand (zigo)

Bug#930134: Please package new upstream version

2019-06-10 Thread Thomas Goirand
OpenStack Train (ie: the next version, due for early September) also needs version 2.0.0, so I will package that. However, I don't see any urgency during the Buster freeze. Also, the current OpenStack version needs 1.4.1, so uploading 2.0.0 to Experimental would break it. Cheers, Thomas Goirand (zigo)

Bug#930110: unblock: graphite-web/1.1.4-3

2019-06-07 Thread Thomas Goirand
=medium + + * Fix shebang of /usr/bin/graphite-manage. (Closes: #925240) + + -- Thomas Goirand Fri, 07 Jun 2019 09:39:24 +0200 + graphite-web (1.1.4-2) unstable; urgency=medium * Fix README to suggest installation of libapache2-mod-wsgi-py3, and added diff -Nru graphite-web-1.1.4/debian

Bug#922669: fixed in sqlalchemy 1.2.18+ds1-2

2019-06-07 Thread Thomas Goirand
and apparently, only in rare edge cases where there's already an issue. Cheers, Thomas Goirand (zigo)

Bug#930050: miniupnpd: CVE-2019-12107 CVE-2019-12108 CVE-2019-12109 CVE-2019-12110 CVE-2019-12111

2019-06-07 Thread Thomas Goirand
his site: http://sid.gplhost.com/stretch-proposed-updates/miniupnpd/ Please allow me to upload this Stretch update to security-master. As the Jessie version is the same as the Stretch one, I guess the LTS team can just pick-up what's in the git and rebuild. I'd prefer if someone form the LT

Bug#930058: unblock: puppet/5.5.10-3

2019-06-06 Thread Thomas Goirand
+that is older than 30 days to avoid filling-up a puppet-master hard drive +until it's full (Closes: #930033). + + -- Thomas Goirand Thu, 06 Jun 2019 10:24:27 +0200 + puppet (5.5.10-2) unstable; urgency=medium * Make sure oj does not use BigDecimals on data load (Closes: #923976) diff -Nru

Bug#930033: Puppet-master do not clean reports in /var/lib/puppet/reports

2019-06-05 Thread Thomas Goirand
be done, is clean old reports, let's say those that are at least one month old, using a cron.daily job. I believe this should be fixed in both Stretch and Buster if possible. Cheers, Thomas Goirand (zigo)

Bug#929734: unblock: nova/18.1.0-6

2019-06-03 Thread Thomas Goirand
On 5/29/19 9:49 PM, Thomas Goirand wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > > Dear release team, > Please unblock package nova 18.1.0-6. > > During normal operation, it may happen

Bug#929321: Update for SQLAlchemy to address CVE-2019-7164 CVE-2019-7548

2019-05-30 Thread Thomas Goirand
this email to you today: to ask you to please test your application with SQLAlchemy 1.2.18+ds1-2 ASAP, to address any potential unforecast issue before the Buster release. Details about the discussion can be seen here in the Debian bug #929321. Best regards, Thomas Goirand (zigo)

Bug#929321: unblock: sqlalchemy/1.2.18+ds1-2 (CVE-2019-7164 CVE-2019-7548)

2019-05-29 Thread Thomas Goirand
(upstream for SQLAlchemy). On 5/28/19 8:59 PM, Paul Gevers wrote: > Control: tags -1 moreinfo confirmed > > Hi Zigo, > > On Tue, 21 May 2019 17:50:28 +0200 Thomas Goirand wrote: >> Note that it may (or not) break some reverse dependencies, though according >> to upstr

Bug#929734: unblock: nova/18.1.0-6

2019-05-29 Thread Thomas Goirand
be hard to get into the full details of how Nova works. Though please trust me, this is an important patch that really needs to be in Buster, and I have tested this patch with success in production. Cheers, Thomas Goirand (zigo) unblock nova/18.1.0-6 diff -Nru nova-18.1.0/debian/changelog nova

Bug#929361: ITP: puppet-module-debian-archvsync -- Puppet module for maintaining a Debian FTP mirror

2019-05-22 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: puppet-module-debian-archvsync Version : 1.0.0 Upstream Author : Thomas Goirand * URL : https://salsa.debian.org/openstack-team/puppet/puppet-module-debian-archvsync * License : GPL-3

Bug#929321: unblock: sqlalchemy/1.2.18+ds1-2 (CVE-2019-7164 CVE-2019-7548)

2019-05-21 Thread Thomas Goirand
, Thomas Goirand (zigo) diff -Nru sqlalchemy-1.2.18+ds1/debian/changelog sqlalchemy-1.2.18+ds1/debian/changelog --- sqlalchemy-1.2.18+ds1/debian/changelog 2019-02-25 00:01:50.0 +0100 +++ sqlalchemy-1.2.18+ds1/debian/changelog 2019-05-21 16:23:35.0 +0200 @@ -1,3 +1,11

Bug#922669: Debdiff to fix this

2019-05-21 Thread Thomas Goirand
allow me to upload as-is, or build and upload yourself ASAP (preferably, in time for Buster). Cheers, Thomas Goirand (zigo) diff -Nru sqlalchemy-1.2.18+ds1/debian/changelog sqlalchemy-1.2.18+ds1/debian/changelog --- sqlalchemy-1.2.18+ds1/debian/changelog 2019-02-25 00:01:50.0 +0100

Bug#929297: minissdpd: CVE-2019-12106

2019-05-21 Thread Thomas Goirand
version in Sid / Buster isn't affected, as version 1.5.20190210 from upstream already has the patch (ie: *pp = p->next). The security tracker seems to know about it already. Chris, thanks for your proposal to update Stretch, I very much appreciate it. Cheers, Thomas Goirand (zigo)

Bug#929120: unblock: python-amqp/2.4.0-2

2019-05-17 Thread Thomas Goirand
, Cheers, Thomas Goirand (zigo) unblock python-amqp/2.4.0-2 diff -Nru python-amqp-2.4.0/debian/changelog python-amqp-2.4.0/debian/changelog --- python-amqp-2.4.0/debian/changelog 2019-01-22 15:29:00.0 +0100 +++ python-amqp-2.4.0/debian/changelog 2019-05-17 14:26:02.0 +0200 @@ -1,3

Bug#929119: unblock: python-oslo.messaging/8.1.3-1

2019-05-17 Thread Thomas Goirand
like this to reach Buster, and so would any OpenStack on Debian user. Debdiff attached. Cheers, Thomas Goirand (zigo) unblock python-oslo.messaging/8.1.3-1 diff -Nru python-oslo.messaging-8.1.2/debian/changelog python-oslo.messaging-8.1.3/debian/changelog --- python-oslo.messaging-8.1.2/debian

Bug#929081: Sosreport installs without compiling the .py files

2019-05-16 Thread Thomas Goirand
Package: sosreport Version: 3.6-1 Severity: important Hi, Could you please add this to your packaging: override_dh_python3: dh_python3 /usr otherwise, the python files aren't being built. Cheers, Thomas Goirand (zigo)

Bug#928999: ITP: puppet-module-magnum -- Puppet module for OpenStack Magnum

2019-05-14 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: puppet-module-magnum Version : 14.4.0 Upstream Author : OpenStack Foundation * URL : https://github.com/openstack/puppet-magnum * License : Apache-2.0 Programming Lang: Puppet

Bug#928649: unblock: ipset/6.38-1.2

2019-05-08 Thread Thomas Goirand
-1.2 Cheers, Thomas Goirand (zigo) diff -Nru ipset-6.38/debian/changelog ipset-6.38/debian/changelog --- ipset-6.38/debian/changelog 2018-09-01 19:28:18.0 +0200 +++ ipset-6.38/debian/changelog 2019-05-06 10:55:51.0 +0200 @@ -1,3 +1,18 @@ +ipset (6.38-1.2) unstable; urgency=medium

Bug#928561: Updating the python-seamicroclient Uploaders list

2019-05-07 Thread Thomas Goirand
On 5/7/19 8:08 AM, Tobias Frost wrote: > Source: python-seamicroclient > Version: 0.4.0-3 > Severity: minor > User: m...@qa.debian.org > Usertags: mia-teammaint > > Julien Danjou has retired, so can't work on > the python-seamicroclient package anymore (at least with this address). > > We are

Bug#927722: fixed in ipset 6.38-1.1

2019-05-06 Thread Thomas Goirand
> > Thanks, > > Ivo Looks like it took the previous upload I did. I did a dcut and re-uploaded, though the old one got in. I'm fixing and re-uploading (this time without delay). Cheers, Thomas Goirand (zigo)

Bug#922669: sqlalchemy: CVE-2019-7164 CVE-2019-7548 (SQL injection)

2019-05-06 Thread Thomas Goirand
ng the patch is attached. It builds and the tests pass. > However, the fix requires removing previously supported behavior. Consumers > that depend on this have been found [3], so I'm not sure if this should be > shipped in buster. Hi, I'm sorry, but where exactly do you see a list of aff

Bug#927722: fixed in ipset 6.38-1.1

2019-05-06 Thread Thomas Goirand
there. > > Thanks, > > Ivo Which was fixed on the upload (ie: conffile was replaced). Adding "ipset" at the end should work, as that's the name of the package. Or am I wrong there? Cheers, Thomas Goirand (zigo)

Bug#927722: Correct fix for this bug

2019-04-25 Thread Thomas Goirand
Hi, Please fine attached to this message the *CORRECT* debdiff to fix it. I've uploaded it to DELAYED/7 (after dcuting the wrong package...). Let me know if you think it's still wrong and I should still dcut it... Cheers, Thomas Goirand (zigo) diff -Nru ipset-6.38/debian/changelog ipset-6.38

Bug#927722: Fixing the changelog entry

2019-04-25 Thread Thomas Goirand
Woops, I'm fixing the bad changelog entry (ie: dcut, rebuild and reupload). Sorry for this. Cheers, Thomas Goirand (zigo)

Bug#927722: Uploaded to delayed/7

2019-04-25 Thread Thomas Goirand
Hi, I've uploaded the fix to DELAYED/7. Debdiff attached. Let me know if I should dcut rm the upload. Cheers, Thomas Goirand (zigo) diff -Nru ipset-6.38/debian/changelog ipset-6.38/debian/changelog --- ipset-6.38/debian/changelog 2018-09-01 19:28:18.0 +0200 +++ ipset-6.38/debian

Bug#926043: CVE-2019-0816

2019-04-25 Thread Thomas Goirand
On 4/24/19 10:02 PM, Salvatore Bonaccorso wrote: > Hi Thomas, > > On Tue, Apr 02, 2019 at 10:29:33PM +0200, Moritz Mühlenhoff wrote: >> severity 926043 important >> thanks >> >> On Tue, Apr 02, 2019 at 01:56:35PM +0200, Thomas Goirand wrote: >>> On

Bug#926043: CVE-2019-0816

2019-04-25 Thread Thomas Goirand
On 4/24/19 10:02 PM, Salvatore Bonaccorso wrote: > Hi Thomas, > > On Tue, Apr 02, 2019 at 10:29:33PM +0200, Moritz Mühlenhoff wrote: >> severity 926043 important >> thanks >> >> On Tue, Apr 02, 2019 at 01:56:35PM +0200, Thomas Goirand wrote: >>> On

Bug#926697: [Pkg-puppet-devel] Bug#926697: No answer, means approval?

2019-04-23 Thread Thomas Goirand
On 4/24/19 12:12 AM, Thomas Goirand wrote: > I'd be nice as well if I could be added to the team at: > https://salsa.debian.org/groups/puppet-team/-/group_members > > so I could also push my changes to the Git (which really, is just > upgrading to the last upstream release...).

Bug#926697: No answer, means approval?

2019-04-23 Thread Thomas Goirand
(which really, is just upgrading to the last upstream release...). Cheers, Thomas Goirand (zigo)

Bug#925298: ceilometer: CVE-2019-3830: ceilometer-agent prints sensitive data from config files through log files

2019-04-20 Thread Thomas Goirand
? > > Stretch is not affected. > > Cheers, > Moritz Hi Moritz, Salavatore, The fix that Moritz linked to is already included in Ceilometer 12.0.0 which is in Experimental. I've just uploaded 1:11.0.1-5 with the fix (with urgency=high). Cheers, Thomas Goirand (zigo)

Bug#918648: watcher: FTBFS (autobuilder hangs)

2019-04-17 Thread Thomas Goirand
o fix the timezone > issue by explicitly setting TZ in debian/rules as suggested by > Adrian Bunk. That way we could see if reproducible-builds autobuilders > can get past that point or not ]. Excuse me, but I missed that TZ thing. Is it a bug against the package as well? Cheers, Thomas Goirand (zigo)

Bug#927248: ITP: redfishtool -- redfish command-line client

2019-04-16 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: redfishtool Version : 1.0.8 Upstream Author : DMTF, https://www.dmtf.org/standards/feedback * URL : https://github.com/DMTF/Redfishtool * License : BSD-3-clause Programming Lang: Python

Bug#927107: unblock: openvswitch/2.10.0+2018.08.28+git.8ca7c82b7d+ds1-12

2019-04-15 Thread Thomas Goirand
). + + -- Thomas Goirand Sun, 14 Apr 2019 00:25:19 +0200 + openvswitch (2.10.0+2018.08.28+git.8ca7c82b7d+ds1-11) unstable; urgency=medium * Removes network.service from openvswitch-switch.service to avoid a diff -Nru openvswitch-2.10.0+2018.08.28+git.8ca7c82b7d+ds1/debian/ifupdown.sh openvswitch-2.10.0

Bug#926943: python3-rtslib-fb: package doesn't ship service unit or init script

2019-04-13 Thread Thomas Goirand
retch. So I'm inclined to believe this is a bug, after all. Hi, The issue is that the init script is available in the python-rtslib-fb package, but not on its python3 version. I'm not really sure how to fix though, and also, if you could provide a .sevice file, that be nice, I'll add it and make sure the pack

Bug#926769: ITP: puppet-module-placement -- Puppet module for OpenStack Placement

2019-04-10 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: puppet-module-placement Version : 1.2.0 Upstream Author : OpenStack Foundation * URL : https://github.com/openstack/puppet-placement * License : Apache-2.0 Programming Lang: Python

Bug#926697: Please package version >=6.0.0 <9.0.0

2019-04-09 Thread Thomas Goirand
ld you allow me to NMU such an update? Cheers, Thomas Goirand (zigo)

Bug#926638: ITP: python-pure-sasl -- pure Python client SASL implementation

2019-04-08 Thread Thomas Goirand
Package: wnpp Severity: wishlist Owner: Thomas Goirand * Package name: python-pure-sasl Version : 0.5.1 Upstream Author : Tyler Hobbs * URL : https://github.com/thobbs/pure-sasl * License : Expat Programming Lang: Python Description : pure Python

Bug#926502: neutron: CVE-2019-10876: Unable to install new flows on compute nodes when having broken security group rules

2019-04-06 Thread Thomas Goirand
ease update the security tracker. I have uploaded a fix for Rocky (currently in Sid/Buster), and will ask for the unblock on Monday. Cheers, Thomas Goirand (zigo)

<    6   7   8   9   10   11   12   13   14   15   >