Bug#1070163: socat: support duplicating data to multiple clients of listening socket?

2024-04-30 Thread Paul Wise
Package: socat Severity: wishlist X-Debbugs-Cc: so...@dest-unreach.org Forwarded: so...@dest-unreach.org socat does not appear to have a way to send data to multiple clients of a listening socket, which would be useful to proxy data from overloaded servers to multiple local clients. For example:

Bug#1070150: texlive-latex-extra: performance regression under emulation with 2023.20240207-1

2024-04-30 Thread Norbert Preining
> When running the hook with the 2023.20240207, this step takes around 3 hours. Ouch, that hurts. > I'm guessing that this is related to enabling lua on aarch64 finally, but I'm > not familiar at all with latex and how to get the smallest possible test case > to > show the issue. If you

Bug#1070146: aria2: The -o option could offer a substitution pattern for the original basename

2024-04-30 Thread Kartik Mistry
forwarded 1070146 https://github.com/aria2/aria2/issues/2207 thanks -- Kartik Mistry | કાર્તિક મિસ્ત્રી kartikm.wordpress.com

Bug#1069997: nginx: NGX_MODULE_SIGNATURE has changed on 32-bit t64 architectures, but the ${nginx:abi} substvar has not

2024-04-30 Thread Jan Mojzis
Thanks for the report, I am preparing nginx release 1.26.0, and the updated ABI version will be part of it. Jan

Bug#1069549: racket: FTBFS on armel: dh_install: error: missing files, aborting

2024-04-30 Thread Lucas Nussbaum
Hi David, On 29/04/24 at 07:25 -0600, David Bremner wrote: > > Control: severity -1 important > > > Source: racket > > Version: 8.12+dfsg1-7 > > Severity: serious > > Justification: FTBFS > > Tags: trixie sid ftbfs > > User: lu...@debian.org > > Usertags: ftbfs-20240420 ftbfs-trixie

Bug#1070162: Nickle man page has residual template variable

2024-04-30 Thread Eric Bavier
Package: nickle Version: 2.97+b1 Severity: minor Tags: patch, upstream The man page "nickle(1)" contains a residual template variable that seems to have missed its substitution: $ man nickle | tail -n1 @RELEASE_DATE@NICKLE(1) $ nickle -e version "2.97" It

Bug#1070161: ITS: ramond

2024-04-30 Thread Boyuan Yang
Source: ramond Version: 0.5-4.2 Severity: important Tags: sid trixie X-Debbugs-CC: nicolas.dandrim...@crans.org Dear package ramond maintainer in Debian, After looking into the package you maintain (ramond, https://tracker.debian.org/pkg/ramond), I found that this package received no maintainer

Bug#1070160: libfmt: Please allow merge requests on Salsa

2024-04-30 Thread Otto Kekäläinen
Package: libfmt Severity: wishlist Hi! Please allow CI and Merge Requests at https://salsa.debian.org/zhsj/fmtlib so that it is easier for others to contribute to the package. I would for example like to submit a Merge Request to include

Bug#1070158: bullseye-pu: package distro-info-data/0.51+deb11u6

2024-04-30 Thread Stefano Rivera
Package: release.debian.org Severity: normal Tags: bullseye X-Debbugs-Cc: distro-info-d...@packages.debian.org Control: affects -1 + src:distro-info-data User: release.debian@packages.debian.org Usertags: pu This is a regular distro-info-data update. [ Reason ] This update adds: 1. bullseye

Bug#1070157: bookworm-pu: package distro-info-data/0.58+deb12u2

2024-04-30 Thread Stefano Rivera
Package: release.debian.org Severity: normal Tags: bookworm X-Debbugs-Cc: distro-info-d...@packages.debian.org Control: affects -1 + src:distro-info-data User: release.debian@packages.debian.org Usertags: pu This is a regular distro-info-data update. [ Reason ] This update adds: 1. bullseye

Bug#1070156: RM: gnome-video-arcade -- ROM; Abandoned upstream, uses oldlibs

2024-04-30 Thread Jordi Mallach
Package: ftp.debian.org Severity: normal X-Debbugs-Cc: gnome-video-arc...@packages.debian.org, jbi...@ubuntu.com Control: affects -1 + src:gnome-video-arcade User: ftp.debian@packages.debian.org Usertags: remove As suggested by Jeremy Bicha, g-v-a should be removed as it is now abandoned

Bug#999957: sniproxy: diff for NMU version 0.6.1+git20240321-0.1

2024-04-30 Thread Boyuan Yang
Control: tags -1 +patch +pending Dear maintainer, I've prepared an NMU for sniproxy (versioned as 0.6.1+git20240321-0.1) and uploaded it to DELAYED/14. Please feel free to tell me if I should delay it longer. Regards. diff -Nru sniproxy-0.6.0/ChangeLog sniproxy-0.6.1+git20240321/ChangeLog ---

Bug#1070152: chkrootkit: duplicate line from ifpromisc

2024-04-30 Thread Vincent Lefevre
On 2024-05-01 01:29:10 +0200, Vincent Lefevre wrote: > For instance, /var/log/chkrootkit/log.expected contains > > WARNING: Output from ifpromisc: > lo: not promisc and no packet sniffer sockets > : PACKET > SNIFFER([systemd-networkd|dhclient|dhcpd|dhcpcd|wpa_supplicant|NetworkManager]{PID}) >

Bug#1070154: bullseye-pu: qtbase-opensource-src/5.15.2+dfsg-9+deb11u1

2024-04-30 Thread Thorsten Alteholz
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu The attached debdiff for qtbase-opensource-src fixes several CVEs in Bullseye. All CVEs are marked as no-dsa by the security team. Thorstendiff -Nru

Bug#1070155: bullseye-pu: package wpa/2.9.0-21+deb11u1

2024-04-30 Thread Bastien Roucariès
Package: release.debian.org Severity: important Tags: bullseye X-Debbugs-Cc: w...@packages.debian.org Control: affects -1 + src:wpa User: release.debian@packages.debian.org Usertags: pu tags: security [ Reason ] CVE-2023-52160 security bug [ Impact ] security bug is present [ Tests ] Test

Bug#1070153: bookworm-pu: qtbase-opensource-src/5.15.8+dfsg-11+deb12u2

2024-04-30 Thread Thorsten Alteholz
Package: release.debian.org Severity: normal Tags: bookworm User: release.debian@packages.debian.org Usertags: pu The attached debdiff for qtbase-opensource-src fixes several CVEs in Bookworm. All CVEs are marked as no-dsa by the security team. The debdiff is based on version

Bug#1070152: chkrootkit: duplicate line from ifpromisc

2024-04-30 Thread Vincent Lefevre
Package: chkrootkit Version: 0.58b-1+b2 Severity: normal In the generated log, I sometimes get a duplicate line from ifpromisc. For instance, /var/log/chkrootkit/log.expected contains WARNING: Output from ifpromisc: lo: not promisc and no packet sniffer sockets : PACKET

Bug#1070151: bookworm-pu: package wpa/2:2.10-12

2024-04-30 Thread Bastien Roucariès
Package: release.debian.org Severity: important Tags: bookworm X-Debbugs-Cc: w...@packages.debian.org Control: affects -1 + src:wpa User: release.debian@packages.debian.org Usertags: pu tags: security [ Reason ] CVE-2023-52160 security bug [ Impact ] security bug is present [ Tests ] Test

Bug#1070150: texlive-latex-extra: performance regression under emulation with 2023.20240207-1

2024-04-30 Thread Steev Klimaszewski
Package: texlive-latex-extra Version: 2023.20240207-1 Severity: wishlist User: de...@kali.org Usertags: origin-kali Dear Maintainer, Since the 2023.20240207-1 release, there is a major performance regression when running the tex-common postinst hook in an arm64 chroot on amd64 host. This was

Bug#1068750: moment-timezone.js: FTBFS everywhere

2024-04-30 Thread Martina Ferrari
Hi Santiago, On 30/04/2024 14:01, Santiago Vila wrote: It fails to build if tzdata is updated, but it never stops working. It just needs to be updated as often as tzdata is. But if you have a suggestion to make this more automatic, I would love to hear it.. Sorry, I still don't get it. Why

Bug#1070149: ITP: jack -- Rip and encode CDs with one command

2024-04-30 Thread Cord Beermann
Package: wnpp Severity: wishlist Owner: Cord Beermann X-Debbugs-Cc: debian-de...@lists.debian.org * Package name: jack Version : 4~git20230906.795fba0 Upstream Contact: Arne Zellentin * URL : https://github.com/jack-cli-cd-ripper/jack * License : GPL-2+

Bug#1070148: sqlparse: CVE-2024-4340: sqlparse parsing heavily nested list leads to Denial of Service

2024-04-30 Thread Salvatore Bonaccorso
Source: sqlparse Version: 0.4.4-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for sqlparse. CVE-2024-4340[0]: | Passing a heavily nested list to sqlparse.parse() leads to a Denial | of Service

Bug#1065688: python-jwcrypto: CVE-2024-28102

2024-04-30 Thread Salvatore Bonaccorso
Hi Steve, On Tue, Apr 30, 2024 at 05:19:22PM +0100, Steve McIntyre wrote: > Hi! > > On Fri, Mar 08, 2024 at 10:42:40PM +0100, Salvatore Bonaccorso wrote: > >Source: python-jwcrypto > >Version: 1.5.4-1 > >Severity: important > >Tags: security upstream > >X-Debbugs-Cc: car...@debian.org, Debian

Bug#1070147: dpkg doesn't allow aborting a package downgrade

2024-04-30 Thread Avram Dorfman
Package: dpkg Version: 1.21.22 Exact text of error: $ sudo dpkg -i etx8-web-2.0.0-29a5f09-b1443.deb dpkg: warning: downgrading etx8-web from 2.1.0 to 2.0.0 (Reading database ... 35531 files and directories currently installed.) Preparing to unpack etx8-web-2.0.0-29a5f09-b1443.deb ... Checking

Bug#1052009: Provide compiler-rt builtins for windows/mingw-64

2024-04-30 Thread Norbert Lange
Am So., 28. Apr. 2024 um 18:17 Uhr schrieb Sylvestre Ledru : > > Hello > > > Le 16/09/2023 à 00:29, Norbert Lange a écrit : > > Package: libclang-rt-16-dev > > Version: 1:16.0.6-3 > > Severity: wishlist > > X-Debbugs-Cc: nolang...@gmail.com > > > > Adding the compiler-rt library for windows /

Bug#1069538: zeroc-ice: FTBFS on armel: Gradle / Java heap space out-of-memory error

2024-04-30 Thread Chris Knadle
retitle 1069538 zeroc-ice: FTBFS on armel: Gradle / Java heap space out-of-memory-error tags 1069538 - moreinfo thanks I've done additional test builds of zeroc-ice-3.7.10-2.2 on armel on porter boxes amdahl and abel and the build fails with the same error which seems to be during a Java

Bug#1070049: closed by Debian FTP Masters (reply to Carlos Henrique Lima Melara ) (Bug#1070049: fixed in kristall 0.4+dfsg-3)

2024-04-30 Thread Helmut Grohne
Control: reopen -1 On Mon, Apr 29, 2024 at 07:51:03PM +, Debian Bug Tracking System wrote: > It has been closed by Debian FTP Masters > (reply to Carlos Henrique Lima Melara ). Unfortunately, my patch got mangled during application to the point where it no longer achieves the desired

Bug#1070146: aria2: The -o option could offer a substitution pattern for the original basename

2024-04-30 Thread Manny
Package: aria2 Version: 1.36.0-1 Severity: wishlist Tags: upstream X-Debbugs-Cc: debbug.ar...@sideload.33mail.com The -o option is documented as follows: ===8< -o, --out= The file name of the downloaded file. It is always relative to the

Bug#1070126: fossil: Do not use embded sqlite

2024-04-30 Thread Barak A. Pearlmutter
The fossil upstream is also the sqlite3 upstream. They could not possibly be more familiar with sqlite3! When you ask fossil to build using an external (system) sqlite3 library, configuration-time checks are performed to see if the external sqlite3 is up to snuff. If not, either because it is too

Bug#1070142: apt: [INTL:nl] Dutch translation for the apt package

2024-04-30 Thread Frans Spiesschaert
Package: apt Severity: wishlist Tags: l10n patch Dear Maintainer, Please find attached the updated Dutch po file for the apt package. A draft has been posted to the debian-l10n-dutch mailing list allowing for review. Please add it to your next package revision. It should be

Bug#1070141: dgit: [INTL:nl] Dutch translation for the dgit package

2024-04-30 Thread Frans Spiesschaert
Package: dgit Severity: wishlist Tags: l10n patch Dear Maintainer, Please find attached the updated Dutch po file for the dgit package. A draft has been posted to the debian-l10n-dutch mailing list allowing for review. Please add it to your next package revision. It should be

Bug#1070140: tpm2-tss: CVE-2024-29040

2024-04-30 Thread Salvatore Bonaccorso
Source: tpm2-tss Version: 4.0.1-7 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for tpm2-tss. CVE-2024-29040[0]. If you fix the vulnerability please also make sure to include the CVE (Common

Bug#1070139: tpm2-tools: CVE-2024-29038 CVE-2024-29039

2024-04-30 Thread Salvatore Bonaccorso
Source: tpm2-tools Version: 5.6-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerabilities were published for tpm2-tools. CVE-2024-29038[0] and CVE-2024-29039[1]. If you fix the vulnerabilities please also make sure to

Bug#1070138: RFS: django-anymail/10.3-1 [ITA] -- Django email backend for multiple ESPs (Python 3)

2024-04-30 Thread Akash Doppalapudi
Package: sponsorship-requests Severity: normal Dear mentors, I am looking for a sponsor for my package "django-anymail":  * Package name : django-anymail    Version  : 10.3-1    Upstream contact : Mike Edmunds  * URL  : https://github.com/anymail/django-anymail  *

Bug#1070137: bullseye-pu: package cloud-init/22.4.2-1

2024-04-30 Thread Noah Meyerhans
Package: release.debian.org Severity: normal Tags: bullseye User: release.debian@packages.debian.org Usertags: pu X-Debbugs-Cc: cloud-i...@packages.debian.org, t...@security.debian.org Control: affects -1 + src:cloud-init Hi folks. This isn't a straightforward stable proposed-updates

Bug#868095: base-files: clean up legacy conffiles

2024-04-30 Thread Santiago Vila
El 20/4/24 a las 20:40, Guillem Jover escribió: Hi! On Mon, 2024-04-15 at 13:15:13 +0200, Santiago Vila wrote: Hi. I'm scared about removing /etc/profile by accident. Guillem: I see that dpkg contains some helper programs to remove "obsolete conffiles". Are they meant to be used for

Bug#1070136: openjdk-17-jre-headless: error creating symbolic link '/usr/share/man/man1/java.1.gz.dpkg-tmp': No such file or directory

2024-04-30 Thread Peter van Dijk
Package: openjdk-17-jre-headless Version: 17.0.11+9-1~deb12u1 Severity: normal X-Debbugs-Cc: pe...@7bits.nl Dear Maintainer, * What led up to the situation? Installing openjdk-17-jre-headless on a very minimal base system. The 12-slim Docker image is not minimal enough to reproduce this

Bug#1070135: Acknowledgement (tempfile.TemporaryDirectory: symlink bug in cleanup (CVE-2023-6597))

2024-04-30 Thread Steve McIntyre
Control: fixed 1070135 3.11.8-1 On Tue, Apr 30, 2024 at 05:45:04PM +, Debian Bug Tracking System wrote: >Thank you for filing a new Bug report with Debian. > >You can follow progress on this Bug here: 1070135: >https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1070135. > >This is an

Bug#1070040: bookworm-pu: package dm-writeboost/???

2024-04-30 Thread Paul Gevers
Hi, On 30-04-2024 8:54 a.m., Andreas Beckmann wrote: Can you point me to the code that evaluates dpkg's Testsuite-Triggers to schedule these tests? Maybe it's possible to convert dpkg's Testsuite field to a (hardcoded) list of additional triggers ... I think you mean this:

Bug#1070135: tempfile.TemporaryDirectory: symlink bug in cleanup (CVE-2023-6597)

2024-04-30 Thread Steve McIntyre
Source: python3.11 Version: 3.11.2-6 Severity: minor Tags: security upstream X-Debbugs-Cc: steve.mcint...@pexip.com, Debian Security Team Quoting https://security-tracker.debian.org/tracker/CVE-2023-6597: An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions

Bug#1052298: metafun broken?

2024-04-30 Thread Preuße
Control: reassign -1 context-modules Control: tags -1 + pending On 30.04.2024 18:28, Preuße...@buxtehude.debian.org, Hilmar wrote: Hi *, I'll upload a context-modules package to Debian experimental, which will contain the legacy mkii packages. This will bring back metafun.mpii, but won't

Bug#1070133: Acknowledgement (python 3.11 zipbomb attack (CVE-2024-0450))

2024-04-30 Thread Steve McIntyre
Control: fixed 1070133 3.11.8-1 On Tue, Apr 30, 2024 at 05:24:04PM +, Debian Bug Tracking System wrote: >Thank you for filing a new Bug report with Debian. > >You can follow progress on this Bug here: 1070133: >https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1070133. > >This is an

Bug#1070130: python3-pycurl: SSL path issues - upstream bug

2024-04-30 Thread Scott Talbert
On Tue, 30 Apr 2024, i...@fernandolucas.info wrote: Package: python3-pycurl Version: 7.45.3-2 Severity: grave Tags: upstream Justification: renders package unusable Dear Maintainer, Please consider https://github.com/pycurl/pycurl/issues/834 pycurl 7.45.3 wheel not working for https in

Bug#1070134: photoqt: Depends missed

2024-04-30 Thread Egor Nechkin
Package: photoqt Version: 4.2+ds-3 Severity: important Tags: patch X-Debbugs-Cc: e.nech...@gmail.com Dear Maintainer, PhotoQt installed from testing and have had some troubles: crash on start, invisible file dialog etc. Installing the following packages makes it operable:

Bug#1070133: python 3.11 zipbomb attack (CVE-2024-0450)

2024-04-30 Thread Steve McIntyre
Source: python3.11 Version: 3.11.2-6 Severity: important Tags: upstream security X-Debbugs-Cc: Debian Security Team Quoting https://security-tracker.debian.org/tracker/CVE-2024-0450: An issue was found in the CPython `zipfile` module affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and

Bug#1069280: Offer to co-maintain or adopt less

2024-04-30 Thread P. J. McDermott
Milan, I see you're at least catching up on src:less bug reports, so I won't pursue the salvaging process. But my offer to help co-maintain still stands. Either way, as a reminder in case it helps you, in my Salsa fork[1] I: * Updated to the latest upstream release version 643, closing bugs

Bug#1059007: python-asyncssh: CVE-2023-48795

2024-04-30 Thread Steve McIntyre
Hi! On Tue, Dec 19, 2023 at 09:31:00AM +0100, Salvatore Bonaccorso wrote: >Source: python-asyncssh >Version: 2.10.1-2 >Severity: important >Tags: security upstream >X-Debbugs-Cc: car...@debian.org, Debian Security Team > > >Hi, > >The following vulnerability was published for python-asyncssh. >

Bug#1070132: sponsorship-requests: libkal/0.9.0-3.1 [NMU] [RC] -- library for converting dates between various calendar systems

2024-04-30 Thread Bo YU
Package: sponsorship-requests Severity: important Dear mentors, I am looking for a sponsor for my package "libkal": * Package name : libkal Version : 0.9.0-3.1 Upstream contact : Petr Tomasek * URL : http://www.etf.cuni.cz/~tomasek/pub/my/ * License

Bug#930168: Confirming the bug on Debian

2024-04-30 Thread Hefee
I can confim the same behaviour on current Debian sid and I found a working solution for me. In the end it was an issue outside discover. appstream data update was disabled, I proplery did that because the files are that big. I sill could search apps via appstream, so I thought that is not the

Bug#1070042: libarchive: archive_entry_stat returns zero size on mips64el with _FILE_OFFSET_BITS=64

2024-04-30 Thread Theodore Ts'o
reassign 1070042 e2fsprogs 1.47.1~rc1-1 retitle mke2fs -d foo.tar is broken on mips64el thanks On Tue, Apr 30, 2024 at 11:12:36AM +0300, Peter Pentchev wrote: > > AC_SYS_LARGEFILE was added to e2fsprogs configure.ac 2 years ago, > > therefore manual > > #define _FILE_OFFSET_BITS 64 > >

Bug#1069672: bookworm-pu: package flatpak/1.14.8-1~deb12u1

2024-04-30 Thread Simon McVittie
Control: retitle -1 bookworm-pu: package flatpak/1.14.8-1~deb12u1 flatpak 1.14.7 has now been released, closely followed by 1.14.8 to revert unintended changes to the libglnx and bubblewrap submodules. I would like to get this into a Debian 12 point release if possible. I'm sorry about the size

Bug#1068415: nghttp2: CVE-2024-28182: Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage

2024-04-30 Thread Guilhem Moulin
Hi Tomasz, On Fri, 5 Apr 2024 at 01:11:41 +0200, Tomasz Buchert wrote: > Looking into older versions and appropriately patching them will take > more time. I'm preparing an update for this issue for Buster LTS and can hand tested debdiffs over to the Security Team for newer suites if you'd like.

Bug#1070129: ITP: web-cache -- Simple Python key-value storage backed up by sqlite3 database

2024-04-30 Thread Antoine Beaupré
Control: retitle -1 ITP: web-cache -- Simple Python key-value storage backed up by sqlite3 database On 2024-04-30 12:26:05, Antoine Beaupre wrote: > * Package name: python3-web-cache Actually, py2dsp makes a package named `web-cache` for this, which seems a tad too generic. Thoughts? --

Bug#1068953: new upstream (10.0)

2024-04-30 Thread Daniel Baumann
On 4/30/24 12:56, David Lamparter wrote: Ok, for the time being I've instead decided to use this as a kick in my ass to finally do the NM procedure to become a Debian Maintainer... https://nm.debian.org/process/1284/ hehe, nice ;) I have no idea what kind of timescale that works on, but I

Bug#1070131: RFS: emacs-cfrs/1.6.0-1 [ITP] -- Child-frame based read-string for Emacs

2024-04-30 Thread Xiyue Deng
Package: sponsorship-requests Severity: wishlist Dear mentors, I am looking for a sponsor for my package "emacs-cfrs": * Package name : emacs-cfrs Version : 1.6.0-1 Upstream contact : Alexander Miller * URL : https://github.com/Alexander-Miller/cfrs * License

Bug#1067077: frr: FTBFS on armel: /usr/bin/ld: ./build/../bgpd/bgp_io.c:476:(.text+0x51c): undefined reference to `__atomic_store_8'

2024-04-30 Thread Daniel Baumann
Hi David, On 4/30/24 18:21, David Lamparter wrote: flipped libatomic to be linked unconditionally. it's not harmful to do so on architectures that don't need it, but imho its cleaner to only be linked on affected architectures (armel m68k powerpc sh4).

Bug#1068951: new upstream (6.x)

2024-04-30 Thread Daniel Baumann
Hi, On 4/30/24 18:12, Jakub Ružička wrote: Secondary reason for that was that there is no upgrade path from 5.x to 6.x so it's unwanted for knot-resolver 5 packages to auto-update to 6. For that, the package probably needs a different name (like knot-resolver6) imho this should be handled

Bug#1052298: metafun broken?

2024-04-30 Thread Preuße
On 23.02.2024 23:31, Hilmar Preuße wrote: On 27.10.23 22:31, Siep Kroonenberg wrote: Hi Stéphane, The standalone context is mostly free from mkii, but cont-tmf.zip still has most of the legacy stuff, which will mostly be added back in, in the form of a context-legacy package for TL. I find

Bug#1070130: python3-pycurl: SSL path issues - upstream bug

2024-04-30 Thread info
Package: python3-pycurl Version: 7.45.3-2 Severity: grave Tags: upstream Justification: renders package unusable Dear Maintainer, Please consider https://github.com/pycurl/pycurl/issues/834 pycurl 7.45.3 wheel not working for https in debian/ubuntu systems I confirm that the debian package for

Bug#1070129: ITP: python3-web-cache -- Simple Python key-value storage backed up by sqlite3 database

2024-04-30 Thread Antoine Beaupre
Package: wnpp Severity: wishlist Owner: Antoine Beaupre X-Debbugs-Cc: debian-de...@lists.debian.org, debian-pyt...@lists.debian.org * Package name: python3-web-cache Version : 1.1.0 Upstream Contact: https://github.com/desbma * URL :

Bug#1067077: frr: FTBFS on armel: /usr/bin/ld: ./build/../bgpd/bgp_io.c:476:(.text+0x51c): undefined reference to `__atomic_store_8'

2024-04-30 Thread David Lamparter
On Mon, Apr 29, 2024 at 06:05:08PM +0200, Daniel Baumann wrote: > my initial attempt in 10.0-0.2 to link with libatomic didn't work, I've > fixed that locally but a build to confirming on an armel porterbox is > runnning before uploading 10.0-0.3 in some minutes.. I've synced in (all of) your

Bug#1065688: python-jwcrypto: CVE-2024-28102

2024-04-30 Thread Steve McIntyre
Hi! On Fri, Mar 08, 2024 at 10:42:40PM +0100, Salvatore Bonaccorso wrote: >Source: python-jwcrypto >Version: 1.5.4-1 >Severity: important >Tags: security upstream >X-Debbugs-Cc: car...@debian.org, Debian Security Team > > >Hi, > >The following vulnerability was published for python-jwcrypto. >

Bug#1070127: rss2email: update of upstream version

2024-04-30 Thread info
Package: rss2email Version: 1:3.13.1-3 Severity: wishlist Tags: upstream Dear Maintainer, The debian webpage https://packages.debian.org/buster/amd64/rss2email references into https://github.com/wking/rss2email as the "homepage" of the project, this github project references,

Bug#1068951: new upstream (6.x)

2024-04-30 Thread Jakub Ružička
On 4/29/24 21:13, Daniel Baumann wrote: On 4/29/24 19:50, Daniel Baumann wrote: pushing to the repo requires me to be added to the salsa project.. would you mind adding me? in the meantime, I've pushed to here: https://git.progress-linux.org/users/daniel.baumann/debian/todo/knot-resolver/log/

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 14:56:07 UTC Barak A. Pearlmutter a écrit : > I've uploaded a package with this fixed to unstable, 1:2.24-5, and > it's been autobuilt and pushed out. Seems to work okay, and can be > co-installed with apache2/sid. > > Just uploaded 1:2.24-6 that adds Breaks: apach2-bin

Bug#1070111: mini-buildd wishlist: configurable periodic jobs (or: don't keep complete build results for a full year)

2024-04-30 Thread Stephan Sürken
Hi Magnus, On Tue, 2024-04-30 at 11:40 +0200, Magnus Holmgren wrote: > Package: mini-buildd > Severity: wishlist > coded. Perhaps you've already planned to add some configurability in the > future, but more specifically I'd like to talk about the "Expire no imminent plans to make cron jobs

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 14:56:07 UTC Barak A. Pearlmutter a écrit : > currently Debian sqlite3 is > compiled without SQLITE_ENABLE_JSON1 so the internal version is used.) On this proble could you cross check ? >SQLITE_ENABLE_JSON1 > >This compile-time option is a no-op. Prior to SQLite

Bug#1070126: fossil: Do not use embded sqlite

2024-04-30 Thread Bastien Roucariès
Source: fossil Severity: important Dear Maintainer, > currently Debian sqlite3 is > compiled without SQLITE_ENABLE_JSON1 so the internal version is used.) On this proble could you cross check ? >SQLITE_ENABLE_JSON1 > >This compile-time option is a no-op. Prior to SQLite version 3.38.0

Bug#1070119: gnome-remote-desktop: missing gnome-remote-desktop user setup in salsa upcoming 46 version

2024-04-30 Thread Jeremy Bícha
On Tue, Apr 30, 2024 at 11:29 AM Alban Browaeys wrote: > So I did not mean mixinf gnome-shell/gnome-remote-desktop version. My > interest was into connection via RDP to a not unlocked or already > opened remote Gnome Shell. > > As of now I us the "Allow Locked Remote Desktop" extension and gdm3 >

Bug#1069063: distro-info: Please support distro-info --alias=trixie -r

2024-04-30 Thread Benjamin Drung
On Tue, 2024-04-30 at 15:38 +, Bastien Roucariès wrote: > Le mardi 30 avril 2024, 15:24:11 UTC Benjamin Drung a écrit : > > Hi, > > > > On Mon, 2024-04-15 at 18:58 +, Bastien Roucariès wrote: > > > Package: distro-info > > > Version: 1.7 > > > Severity: minor > > > > > > Dear Maintainer,

Bug#1069890: Resignation & call for votes to elect the Chair

2024-04-30 Thread Helmut Grohne
On Tue, Apr 30, 2024 at 11:09:26AM +0100, Matthew Vernon wrote: > > ===BEGIN > > > > A: Christoph Berg > > B: Matthew Garrett > > C: Helmut Grohne > > D: Stefano Rivera > > E: Timo Röhling > > F: Craig Small > > G: Matthew Vernon > > H: Sean Whitton > > > > ===END > > I vote H > A = B =

Bug#1069065: gcc-14: should -for-host builds move from cross-toolchain build to DEB_STAGE=rtlibs?

2024-04-30 Thread Helmut Grohne
On Mon, Apr 15, 2024 at 06:10:16PM +0200, Helmut Grohne wrote: > In any case, I looked into prototyping this suggested move as a patch to > the gcc packaging. I am attaching a proof-of-concept of this, but I'm > not particularly fond of it as it noticeably increases the packaging > complexity. I

Bug#1069063: distro-info: Please support distro-info --alias=trixie -r

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 15:24:11 UTC Benjamin Drung a écrit : > Hi, > > On Mon, 2024-04-15 at 18:58 +, Bastien Roucariès wrote: > > Package: distro-info > > Version: 1.7 > > Severity: minor > > > > Dear Maintainer, > > > > distro-info --alias=trixie -r is misleading it return trixie instead

Bug#1070125: dmucs FTCBFS: uses the build architecture compiler

2024-04-30 Thread Helmut Grohne
Source: dmucs Version: 0.6.1+dfsg-1 Tags: patch User: debian-cr...@lists.debian.org Usertags: ftcbfs dmucs fails to cross build from source, because it uses the build architecture compiler. override_dh_auto_configure now invokes ./configure without passing --host and hence configure uses the

Bug#1070124: gpm FTBFS: -Werror=implicit-function-declaration makes missing #includes fatal

2024-04-30 Thread Helmut Grohne
Source: gpm Version: 1.20.7-11 Severity: important Tags: ftbfs patch User: helm...@debian.org Usertags: rebootstrap We recently made -Werror=implicit-function-declaration the default. Unfortunately src/daemon/old_main.c is missing some crucial #includes and that makes the build fail in some

Bug#1070123: attr FTBFS: -Werror=implicit-function-declaration triggers on basefile for missing libgen.h

2024-04-30 Thread Helmut Grohne
Source: attr Version: 1:2.5.2-1 Severity: important Tags: ftbfs patch User: helm...@debian.org Usertags: rebootstrap attr may fail to build from source with -Werror=implicit-function-declaration due to using basename without including libgen.h. I'm attaching a patch for your convenience. Helmut

Bug#1070119: gnome-remote-desktop: missing gnome-remote-desktop user setup in salsa upcoming 46 version

2024-04-30 Thread Alban Browaeys
Le mardi 30 avril 2024 à 10:37 -0400, Jeremy Bícha a écrit : > > I believe the bug is import as it prevents opening a new desktop > > session > > (but it still works when connection to an existing session). > > Yes, I've bumped the severity but what do you mean about connecting > to > an existing

Bug#1067660: wireplumber: Wireplumber 0.5.0 breaks asahi-audio 1.x

2024-04-30 Thread Andreas Henriksson
Hello Dylan, On Mon, Apr 29, 2024 at 11:53:50AM +0200, Dylan Aïssi wrote: > Hello, > > Le dim. 31 mars 2024 à 15:41, Andreas Henriksson a écrit : > > > > PLEASE NOTIFY US WHEN YOU UPLOAD wireplumber 0.5.x to UNSTABLE, so we > > can do a coordinated transition (uploading asahi-audio 2.x to

Bug#1069063: distro-info: Please support distro-info --alias=trixie -r

2024-04-30 Thread Benjamin Drung
Hi, On Mon, 2024-04-15 at 18:58 +, Bastien Roucariès wrote: > Package: distro-info > Version: 1.7 > Severity: minor > > Dear Maintainer, > > distro-info --alias=trixie -r is misleading it return trixie instead of 13... > > Maybe a feature but should be documented > > I workarround by

Bug#1070121: nmu: coreutils_9.4-3 (trixie), pam_1.5.2-9.1 (trixie)

2024-04-30 Thread Sebastian Ramacher
On 2024-04-30 15:44:51 +0100, Simon McVittie wrote: > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: binnmu > X-Debbugs-Cc: coreut...@packages.debian.org, p...@packages.debian.org, > debian-b...@lists.debian.org > Control: affects -1 +

Bug#1070120: postfix: can't send mail due to obsolete /var/spool/postfix/etc/resolv.conf on new network

2024-04-30 Thread Bastien Roucariès
Le mardi 30 avril 2024, 14:52:46 UTC Vincent Lefevre a écrit : Hi, > Control: tags -1 security > > On 2024-04-30 16:33:14 +0200, Vincent Lefevre wrote: > > If I try to restart postfix, I get: > > > > postfix/postfix-script: warning: /var/spool/postfix/etc/resolv.conf and > > /etc/resolv.conf

Bug#1070122: apt-cache rdepends with an exact match name

2024-04-30 Thread Patrice Duroux
Package: apt Version: 2.9.2 Severity: wishlist Dear Maintainer, Could there be a possibility (by default or with an option) to not get result like: $ apt rdepends libaio1 libaio1 Reverse Depends: Depends: libaio-dev (= 0.3.112-9) Depends: qemu-utils (>= 0.3.93) Depends: qemu-system-x86

Bug#1070069: fossil: CVE-2024-24795 unreleated breakage

2024-04-30 Thread Barak A. Pearlmutter
I've uploaded a package with this fixed to unstable, 1:2.24-5, and it's been autobuilt and pushed out. Seems to work okay, and can be co-installed with apache2/sid. Just uploaded 1:2.24-6 that adds Breaks: apach2-bin per your recent message. Honestly, I'm not confident in my ability to properly

Bug#1065309: transition: gnat (12 -> 13 + time_t64)

2024-04-30 Thread Graham Inggs
Hi Nicholas On Tue, 30 Apr 2024 at 12:33, Nicolas Boulenguez wrote: > The time_t64 transition has triggered #1067453 in the Ada compiler, > which is now fixed by gcc-13/13.2.0-24. > > The patch modifies the sources of the Ada standard library, so most > Ada packages need a rebuild in order to

Bug#1070120: postfix: can't send mail due to obsolete /var/spool/postfix/etc/resolv.conf on new network

2024-04-30 Thread Vincent Lefevre
Control: tags -1 security On 2024-04-30 16:33:14 +0200, Vincent Lefevre wrote: > If I try to restart postfix, I get: > > postfix/postfix-script: warning: /var/spool/postfix/etc/resolv.conf and > /etc/resolv.conf differ BTW, note that this is a security issue, because with wifi, the DNS server

Bug#1055656: A one-liner fix needed before telegram-desktop backporting

2024-04-30 Thread Boyuan Yang
Hi all, On Fri, 2024-04-19 at 11:39 -0400, Boyuan Yang wrote: > Hi Nicolas, > > 在 2024-04-09星期二的 10:51 +0300,Egor Duda写道: > > Hello! > > > > Any news on this one? > > > > It seems that Debian maintainers gave their go-ahead on > > https://bugs.debian.org/1055656 > > > > And, in any case, big

Bug#1070121: nmu: coreutils_9.4-3 (trixie), pam_1.5.2-9.1 (trixie)

2024-04-30 Thread Simon McVittie
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: binnmu X-Debbugs-Cc: coreut...@packages.debian.org, p...@packages.debian.org, debian-b...@lists.debian.org Control: affects -1 + src:coreutils src:pam coreutils_9.4-3.1 and pam_1.5.3-7 aren't

Bug#1070115: libaio1t64: libaio1 and libaio1t64 are co-installed: is this expected?

2024-04-30 Thread Patrice Duroux
On Tue, 30 Apr 2024 15:29:15 +0200 Gianfranco Costamagna wrote: > Hello, > quoting changelog: > [...] So how can I install: https://packages.debian.org/source/sid/thin-provisioning-tools if libaio1:amd64 is no more there: https://packages.debian.org/sid/libaio1 and libaio1t64 not providing

Bug#1070119: gnome-remote-desktop: missing gnome-remote-desktop user setup in salsa upcoming 46 version

2024-04-30 Thread Jeremy Bícha
Control: severity -1 important On Tue, Apr 30, 2024 at 9:57 AM Alban Browaeys wrote: > The issue seems to be that the user gnome-remote-desktop is not existing > thus the system wide systemd gnome-remote-desktop.service fails to > start: The gnome-remote-desktop user is new for

Bug#1070077: [Pkg-privacy-maintainers] Bug#1070077: ships files directly in /usr/onionprobe

2024-04-30 Thread Antoine Beaupré
On 2024-04-30 08:25:55, Georg Faerber wrote: > On 24-04-29 16:19:21, Antoine Beaupre wrote: >> Package: onionprobe >> Version: 1.0.0+ds-2.1+deb12u1 >> Severity: serious >> >> The Debian package shipped in bookworm right now changed the path to >> the examples/ directory. It used to be: >> >>

Bug#1065625: libmtp9t64 / libmtp-runtime dependency problem makes dpkg fail with attempt of removal of libmtp-common

2024-04-30 Thread Vincent Lefevre
On 2024-04-30 11:49:57 +0200, Julian Andres Klode wrote: > This bug has since been reassigned to aptitude. Solver limitations > in aptitude wrt t64 handling should not be considered release critical, > it makes no sense to remove aptitude from testing for it; there are > still plenty of other

Bug#1070120: postfix: can't send mail due to obsolete /var/spool/postfix/etc/resolv.conf on new network

2024-04-30 Thread Vincent Lefevre
Package: postfix Version: 3.9.0-2 Severity: important While being connected in the train, mailq gives: -Queue ID- --Size-- Arrival Time -Sender/Recipient--- 24FC2CA011A2232 Tue Apr 30 16:21:46 vinc...@vinc17.net (Host or domain name not found. Name service error for

Bug#1043408: ITP: golang-github-dsnet-compress -- Collection of compression related Go packages.

2024-04-30 Thread Maytham Alsudany
Control: owner -1 ! I will be taking over this ITP and package maintenance as no response has been received from Nisha. Kind regards, Maytham signature.asc Description: This is a digitally signed message part

Bug#1060075: gcc-13 FTCBFS: target system type set to nvptx-unknown-none

2024-04-30 Thread Emanuele Rocca
Control: retitle -1 gcc-13 FTCBFS: nvptx does not cross compile On 2024-01-06 01:10, Matthias Klose wrote: > no, the target is always nvptx-unknown-none. Ack, but in order to cross build nvptx we probably have to set build and host? I tried cross building gcc 13.2.0-23 on a x86 system with:

Bug#1070119: gnome-remote-desktop: missing gnome-remote-desktop user setup in salsa upcoming 46 version

2024-04-30 Thread Alban Browaeys
Package: gnome-remote-desktop Version: 46.1-1 Severity: normal I believe the bug is import as it prevents opening a new desktop session (but it still works when connection to an existing session). The issue seems to be that the user gnome-remote-desktop is not existing thus the system wide

Bug#1070074: several errors on tab completion

2024-04-30 Thread Alban Browaeys
Package: bash-completion Followup-For: Bug #1070074 I doubt this issue is related to util-linux-extra being too old. I had a similar error while pressing "sudo" I got the error: "sudo bash: _comp_initialize : commande introuvable" ie "commande introuvable" is "command not found". It turned out

Bug#1070115: libaio1t64: libaio1 and libaio1t64 are co-installed: is this expected?

2024-04-30 Thread Gianfranco Costamagna
Hello, quoting changelog: +libaio (0.3.113-6) unstable; urgency=medium + + * Switch from future=+lfs to abi=+lfs build flags feature, and Build-Depends +on dpkg-dev >= 1.22.0. + * Add time64 support: +- Remove dead code for syscall handling. +- Refactor code to use an internal

Bug#1070098: openssh-sftp-server: False dependency on openssh-client

2024-04-30 Thread Wolf
On Tue, Apr 30, 2024 at 5:41 AM Colin Watson wrote: > This saves a bit of space if all the packages are installed together, > which is the common case. However, it's true that it's not very much > space (200K or so), so maybe it's not worth the resulting confusion ... > Ah, I'd missed that

Bug#1070118: focuswriter: Freezes randomly during use on 32-bit Debian

2024-04-30 Thread Diogo Oliveira
Package: focuswriter Version: 1.8.6-1 Severity: important X-Debbugs-Cc: dhe...@vivaldi.net Dear Maintainer, Focuswriter randomly hangs and freezes, forcing me to "ps -ax | grep focus" , then "kill [focuswriter process number]". To reproduce the bug: (a) Open Focuswriter and use it until it

Bug#1068750: moment-timezone.js: FTBFS everywhere

2024-04-30 Thread Santiago Vila
# Fail the build if the tzdata package does not match TZVER. grep -q '^# version 2023d$' /usr/share/zoneinfo/tzdata.zi Yes, this is expected after each update to tzdata. I'm curious: Does this package embed the information from tzdata into javascript code, in such a way that a change in

  1   2   >