Bug#945993: marked as pending in diffoscope

2019-12-02 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #945993 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#945993: diffoscope: FAILED tests/test_source.py::test_code_is_black_clean - assert 228381 == 0

2019-12-02 Thread Chris Lamb
ing against $py" -cp -r tests "$AUTOPKGTEST_TMP" +cp -r tests pyproject.toml "$AUTOPKGTEST_TMP" (cd "$AUTOPKGTEST_TMP"; "$py" -m pytest -vv -l -r a) rm -rf "${AUTOPKGTEST_TMP:?}"/* done … will likely fix this. Regards

Bug#945970: meep: Incomplete debian/copyright?

2019-12-01 Thread Chris Lamb
over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#945299: Bug#945276: lintian: broken pattern matching in debian/source/lintian-overrides

2019-11-22 Thread Chris Lamb
Martin Pitt wrote: […] > But these overrides now stopped working: […] Without looking into too much detail, are the following the same issue? https://bugs.debian.org/945276 https://bugs.debian.org/945299 Regards, -- ,''`. : :' : Chris Lamb `. `'`

Bug#944911: libfiu: FBTFS: Found too many matching python3 bindings

2019-11-19 Thread Chris Lamb
ld but it would be preferable if we could run the tests against all (or "all built") versions of Python. Alberto, would this be possible? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-14 Thread Chris Lamb
Chris Lamb wrote: > > Or, do I need to backport the patch to that specific version? > > If you mean backport it to that particular branch... then no; we just > need to do a regular backport upload. I do that after its migrated to > testing to follow the rules, so we

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-10 Thread Chris Lamb
the rules, so we are a few days off this landing in stretch alas. (As in; I need to do an unstable upload first that includes this commit and let that migrate...) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-10 Thread Chris Lamb
whatever we need to do to weaken this dependency. Felix, can you do the "honours" here? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-07 Thread Chris Lamb
uspect I'm missing something. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-07 Thread Chris Lamb
stretch chroots/Docker images on CI systems, etc. etc. Not everybody is using Lintian the way you are. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#944258: lintian 2.32.0~bpo9+1 in stretch-backports depends on coreutils (>= 8.30), but stretch has only 8.26-3

2019-11-07 Thread Chris Lamb
p this requirement on coreutils for the time being? (I'm afraid I wasn't following the details at the time it was introduced.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#943955: pcb-rnd: /usr/lib/lib*.so.* symlinks point to (absolute) build directory

2019-11-01 Thread Chris Lamb
/build/pcb-rnd-luR6aw/pcb-rnd-2.1.4/debian/pcb-rnd/usr/lib/librnd-poly.so.2.1.4 Discovered as the package is not reproducible too due to this, but solving this obviously-worse problem will implicitly fix this. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la..

Bug#853750: hdfview: HDF5 files appear empty

2019-10-27 Thread Chris Billington
A further update, the Arch Linux AUR package is now building HDFView 3.1 successfully. I'm using it on Arch and it works. If Debian wants to replicate this for their package, see the build script here: https://aur.archlinux.org/cgit/aur.git/tree/PKGBUILD?h=hdfview The AUR package patches

Bug#943509: python-django: FTBFS due to failed tests: failures=7, skipped=891, expected failures=4

2019-10-26 Thread Chris Lamb
bug upstream first (there have been similar short-term issues in other database backends in the past). I would be perfectly happy with downgrading this to important and thus non-RC. > Yeah, you are British. :) Don't quite follow that... :) Best wishes, -- ,''`. : :' :

Bug#943555: wireguard-dkms: Kernel modules don't build with kernel 5.3.0-1-arm64 on Raspberry Pi3

2019-10-26 Thread Chris.
: sub-make] Error 2 make: Leaving directory '/usr/src/linux-headers-5.3.0-1-arm64' Thanks. Chris. -- System Information: Debian Release: bullseye/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: arm64 (aarch64) Kernel: Linux 5.3.0-1-arm64 (SMP w/4 CPU cores) Kernel taint

Bug#943509: python-django: FTBFS due to failed tests: failures=7, skipped=891, expected failures=4

2019-10-26 Thread Chris Lamb
r problems. I'm interested how bad the current situation is? Not quite sure what you mean by bad. It's "bad" in that it's causing an FTBFS in other packages, but I don't think that's quite what you meant here. :) Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#943509: python-django: FTBFS due to failed tests: failures=7, skipped=891, expected failures=4

2019-10-26 Thread Chris Lamb
rds, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#943320: python3-pluggy: missing dependency on python3-importlib-metadata

2019-10-23 Thread Chris Lamb
b_metadata' This appears to be a regression from 0.12.0-1 (which has this dependency). Discovered when trying to release diffoscope on behalf on the Reproducible Builds[0] effort hence the X-Debbugs-CC, but likely affects other packages. [0] https://reproducible-builds.org/ Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#942647: celery-batches: Incomplete debian/copyright, etc.

2019-10-19 Thread Chris Lamb
. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#830726: closed by Chris Lamb (Bug#830726: fixed in xtrlock 2.12)

2019-10-15 Thread Chris Lamb
Hi Antoine, > Looks great! There's a grammar problem "This fix does not the situation" > but it doesn't matter. Whoops, fixed in: https://salsa.debian.org/debian/xtrlock/commit/e578040d4bedf81874cc2bf1c62d6643b36b527d Regards, -- ,''`. : :'

Bug#940973: marked as pending in strip-nondeterminism

2019-10-15 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #940973 in strip-nondeterminism reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#830726: closed by Chris Lamb (Bug#830726: fixed in xtrlock 2.12)

2019-10-14 Thread Chris Lamb
n/xtrlock/commit/34e6c7c6c33ce6b7510172a2e05e710a99fdc146 … so this visibility will be in subsequent releases at the very least. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#885265: Bug#936299: chirp: Python2 removal in sid/bullseye

2019-10-13 Thread Chris Knadle
There has been some discussion about #936299 on the upstream mailing list, and there have been a few upstream commits starting to port the code to Python3. http://intrepid.danplanet.com/pipermail/chirp_devel/2019-August/005580.html -- Chris, KB2IQN -- Chris Knadle chris.kna...@coredump.us

Bug#942252: lintian: No vendor given at /<>/lib/Lintian/Maintainer.pm line 33

2019-10-13 Thread Chris Lamb
e at /<>/lib/Lintian/Maintainer.pm line 43. # BEGIN failed--compilation aborted at /<>/lib/Lintian/Maintainer.pm line 43. t/scripts/pod.t ok # Looks like you failed 1 test of 66. Best wishes, -- ,''`. : :' : Chris Lamb `.

Bug#830726: closed by Chris Lamb (Bug#830726: fixed in xtrlock 2.12)

2019-10-12 Thread Chris Lamb
a deeper fix will be forthcoming. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#942155: backintime: Incomplete debian/copyright, etc.

2019-10-10 Thread Chris Lamb
as it ships /usr/bin/backintime-qt This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. :) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#942154: z3: Incomplete debian/copyright?

2019-10-10 Thread Chris Lamb
. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#942056: openvswitch: Incomplete debian/copyright?

2019-10-10 Thread Chris Lamb
Hi Thomas, > My last upload, which fixes it, goes again through NEW, as we (re-)added > the support for ipsec. This was just ACCEPTED. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#942056: openvswitch: Incomplete debian/copyright?

2019-10-09 Thread Chris Lamb
. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-10-08 Thread Chris Lamb
tags 940973 + fixed-upstream thanks This has apparently been fixed (again) upstream in version 1.67: https://github.com/redhotpenguin/perl-Archive-Zip/issues/51#issuecomment-539679696 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#941474: networkx: Incomplete debian/copyright?

2019-10-01 Thread Chris Lamb
the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-09-23 Thread Chris Lamb
notfound 940973 strip-nondeterminism/1.6.0-1 affects 940973 + strip-nondeterminism tags 940973 + fixed-upstream forwarded 940973 https://github.com/redhotpenguin/perl-Archive-Zip/issues/51 thanks Chris Lamb wrote: > Will investigate soon. This appears to be happening as libarchive-zip-perl 1

Bug#940973: libarchive-zip-perl breaks strip-nondeterminism autopkgtest: error: becoming Archive::Zip::DirectoryMember

2019-09-22 Thread Chris Lamb
://bugs.debian.org/858431 https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/4 https://bugs.debian.org/931730 Will investigate soon. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: Regrabbing (was: Re: Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events)

2019-09-22 Thread Chris Lamb
ng deeper is awry given that locks persist beyond the end of the process. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#940645: marked as pending in diffoscope

2019-09-18 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #940645 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#940471: diffoscope: test failures

2019-09-17 Thread Chris Lamb
the entire log > 2) test being skipped when ocaml-nox is not installed This is the route we have taken elsewhere and I have committed it in: https://salsa.debian.org/reproducible-builds/diffoscope/commit/bf83651d62a9717feba892a4b01d8d7ec28bac49 Best wishes, -- ,''`. : :'

Bug#940471: marked as pending in diffoscope

2019-09-17 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #940471 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#940471: diffoscope: test failures

2019-09-16 Thread Chris Lamb
: 'ocamlc' This does not make immediate sense to me - ocamlc is provided by the ocaml-nox package which is listed in the Build-Depends and in the autopkgtest debian/tests/control file. Any ideas? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#940015: minder: Incomplete debian/copyright?

2019-09-11 Thread Chris Lamb
carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#940017: crypto-policies: Incomplete debian/copyright?

2019-09-11 Thread Chris Lamb
please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#830726: Regrabbing(was: Re: Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events)

2019-09-10 Thread Chris Lamb
ng deeper is awry given that locks persist beyond the end of the process. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-09-08 Thread Chris Lamb
4 days from right now so that we fallback to a previous iteration as you outline regardless of whether I get around to this or they fruitfully reply. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-09-08 Thread Chris Lamb
rs of the Input Extension and see if they have any insight. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#939659: golang-github-paypal-gatt: Incomplete debian/copyright?

2019-09-07 Thread Chris Lamb
for at least linux/socket/*. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939658: printrun: Incomplete debian/copyright?

2019-09-07 Thread Chris Lamb
for posterity and not on this bug report. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939569: icingaweb2-module-statusmap: Incomplete debian/copyright?

2019-09-06 Thread Chris Lamb
, Robert Kieffer and Andrei Mackenzie. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#939568: icingaweb2-module-graphite: Incomplete debian/copyright?

2019-09-06 Thread Chris Lamb
. This is in no way exhaustive so please check over the entire package carefully and address these on your next upload. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-09-02 Thread Chris Lamb
Chris Lamb wrote: > > > +python-django (1:1.11.23-1~deb10u1) buster-security; urgency=high > > > > Thanks, these both look good; please upload to security-master. > > Both uploaded to security-master. There is now a 1.11.24 (ie. 1:1.11.24-1~deb10u1) upstream: htt

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-22 Thread Chris Lamb
something that would want to try a few moments to avoid... (ignore that I'm using "xinput" per se) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-22 Thread Chris Lamb
r, "grabbing\n"); … at the top of the the handle_multitouch function and see whether that's even called when it gets re-enabled? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-21 Thread Chris Lamb
Chris Lamb wrote: > I've been working on an updated patch that detects new devices and > blocks them too. However, "grabbing" devices during the processing of > these "device hierarchy changed" events appears to do something funny > and actually disables all in

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-20 Thread Chris Lamb
ng something wrong and I'll have another run at it ASAP. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-16 Thread Chris Lamb
Chris Lamb wrote: > Patch attached that works for me on my Dell XPS 13 Antoine, does the patch attached to: https://bugs.debian.org/830726#43 … also work for you? If so, I will go ahead and upload. Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.

Bug#934034: Bug#934775: stretch-pu: package monkeysphere/0.41-1+deb9u1

2019-08-16 Thread Chris Lamb
loading agent-transfer-dbgsym_0.41-1+deb9u1_amd64.deb Uploading agent-transfer_0.41-1+deb9u1_amd64.deb Uploading monkeysphere_0.41-1+deb9u1_all.deb Uploading monkeysphere_0.41-1+deb9u1_amd64.buildinfo Uploading monkeysphere_0.41-1+deb9u1_amd64.changes $ echo $? 0 Best wishes, --

Bug#830726: xtrlock: CVE-2016-10894: xtrlock does not block multitouch events

2019-08-16 Thread Chris Lamb
tags 830726 + patch thanks Chris Lamb wrote: > CVE-2016-10894[0]: > | xtrlock through 2.10 does not block multitouch events. Consequently, > | an attacker at a locked screen can send input to (and thus control) > | various programs such as Chromium via events such as pan scrolling

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-14 Thread Chris Lamb
underlying reasons for insisting on such a process. > Thanks for considering to fix bugs in stretch. No problem; thank you for your advice and patient guidance. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-13 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/debian/control b/debian/control index 95750f4..19c4dbb 100644 --- a/debian/control +++ b/debian/control @@ -9,7 +9,7 @@ Build-Depends: cpio, debhelper (>= 10~), dpkg-dev (&

Bug#934034: monkeysphere: FTBFS in stretch

2019-08-13 Thread Chris Lamb
egards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/debian/control b/debian/control index 95750f4..19c4dbb 100644 --- a/debian/control +++ b/debian/control @@ -9,7 +9,7 @@ Build-Depends: cpio, debhelper (>= 10~), dpkg-dev (>= 1.17.

Bug#934034: monkeysphere: FTBFS randomly (failing tests)

2019-08-10 Thread Chris Lamb
tags 934034 + patch tags 861457 - patch thanks [Adding 934...@bugs.debian.org to CC] Hi Santiago, > Maybe you mean #934034 instead of #861457? Wrong bug indeed. Fixing... Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-10 Thread Chris Lamb
curity-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-09 Thread Chris Lamb
although it's not a "re"-build of anything; 1.11.23 won't be in any other suite… :p) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
on we should use? > > 1:1.11.23-1~deb10u1? > > Looks good! Updated debdiff attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/Django.egg-info/PKG-INFO b/Django.egg-info/PKG-INFO index 75a27527c..f6cdde7db

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
PoV Lintian should probably just waive that check > unless the target distro for the upload is "unstable". I took a different approach (to mirror similar existing logic) here: https://salsa.debian.org/lintian/lintian/commit/bcded0a16c1094ae55afdd65caca7f598e3be7fc Regards, -

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
given that > we agreed to follow 1.11.x in buster, shouldn't we rather use that one? D'oh, that makes more sense. Okay, I can prepare a debdiff for that -- however, can you just confirm the version we should use? 1:1.11.23-1~deb10u1? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
about existing releases? How does it > know that 1:1.11.22-1 is missing? debian/changelog. Lintian, as a strict rule, does not query external sources. (I should probably clarify; missing *sequential* releases.) Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-08 Thread Chris Lamb
new debian/buster branch. -- Chris Lamb Wed, 03 Jul 2019 15:18:13 -0300 … and that I've tentatively versioned the updated version to address these new CVEs as 1:1.11.22-1+deb10u1 (ie. with a plus, not a tilde). I mention it specifically as I'm not 100% confident this is correct and Lintian somew

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
[Adding t...@security.debian.org to CC] Chris Lamb wrote: > The following vulnerabilities were published for python-django. > > CVE-2019-14232[0]: > CVE-2019-14233[1]: > CVE-2019-14234[2]: > CVE-2019-14235[3]: I have just fixed this in sid and will fix this in jessie LTS

Bug#934026: marked as pending in python-django

2019-08-06 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #934026 in python-django reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#934026: python-django: CVE-2019-14232 CVE-2019-14233 CVE-2019-14234 CVE-2019-14235

2019-08-06 Thread Chris Lamb
=CVE-2019-14235 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#932339: marked as pending in lintian

2019-07-19 Thread Chris Lamb
-by: Chris Lamb (this message was generated automatically) -- Greetings https://bugs.debian.org/932339

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
recursively depends on an XS binary Perl module which creates build cycle issues for Perl transitions. Use Sub::Override instead as it has no dependencies outside Perl core. Signed-off-by: Chris Lamb (this message

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931730 in strip-nondeterminism reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-15 Thread Chris Lamb
s to your commit message as well as replaced the reference to "Monkey::Patch" in the Makefile.PL too. I added some comments to the "upstream" bug here: https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8#note_95760 Thanks again. Regards, --

Bug#931730: marked as pending in strip-nondeterminism

2019-07-15 Thread Chris Lamb
recursively depends on an XS binary Perl module which creates build cycle issues for Perl transitions. Use Sub::Override instead as it has no dependencies outside Perl core. Signed-off-by: Chris Lamb (this message

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libmonkey-patch-perl

2019-07-12 Thread Chris Lamb
forwarded 931730 https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8 thanks I've "forwarded" this upstream here: https://salsa.debian.org/reproducible-builds/strip-nondeterminism/issues/8 Regards, -- ,''`. : :' : Chris Lamb `. `

Bug#931881: marked as pending in diffoscope

2019-07-12 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931881 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#931881: diffoscope: undeclared versioned dependency on file

2019-07-12 Thread Chris Lamb
NG_TOOLS="foo bar" → Fails; the required version is missing and unlisted. * DIFFOSCOPE_FAIL_TESTS_ON_MISSING_TOOLS="foo bar file" → Skipped correctly. What am I missing here? :) (Note that I renamed this variable in d5b9daf04). Best wishes, -- ,''`. : :'

Bug#931881: diffoscope: undeclared versioned dependency on file

2019-07-11 Thread Chris Lamb
N_MISSING_TOOLS is not set. I think we need to add "file" to the DIFFOSCOPE_TESTS_MISSING_TOOLS list in debian/tests/pytest. Mattia, can you confirm? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-11 Thread Chris Lamb
be best developed upstream. Archive-Zip seems > to be alive if quiet. But a bug against libarchive-zip-perl would be a > good start (with or without a patch). Nod. I'll work on a proper patch to libarchive-zip-perl over the next few days. Regards, -- ,''`. : :' : Chris Lamb

Bug#917847: ipsec-tools is unsuitable for inclusion in Debian

2019-07-11 Thread Chris Hofstaedtler
Hey Noah, * Noah Meyerhans [190711 14:17]: > If you disagree that ipsec-tools should be removed from future Debian > releases, please say so now. As we haven't really heard from anyone, should I go ahead and ask for final removal via ftpmaster? Cheers, Chris

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-10 Thread Chris Lamb
9u3_amd64.changes * redis_5.0.3-4+deb10u1_amd64.changes Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-10 Thread Chris Lamb
rds, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#931730: libfile-stripnondeterminism-perl: build dependency cycle with libsub-identify-perl

2019-07-09 Thread Chris Lamb
be of use to you? Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#931709: marked as pending in diffoscope

2019-07-09 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931709 in diffoscope reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#931625: redis: CVE-2019-10192 CVE-2019-10193

2019-07-08 Thread Chris Lamb
.org/tracker/CVE-2019-10193 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10193 Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#922027: Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-02 Thread Chris Lamb
t builds for me (with all tests passing) in a stretch chroot. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-diff --git a/debian/changelog b/debian/changelog index fa89c8b21..5bb1d6625 100644 --- a/debian/changelog +++ b/debian/ch

Bug#931316: python-django: CVE-2019-12308: Incorrect HTTP detection with reverse-proxy connecting via HTTPS

2019-07-01 Thread Chris Lamb
e? Best wishes, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#931316: marked as pending in python-django

2019-07-01 Thread Chris Lamb
Control: tag -1 pending Hello, Bug #931316 in python-django reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at:

Bug#931097: installing python3.4 fails

2019-06-26 Thread Chris Lamb
reassign 931097 python3.4 forcemerge 931044 931097 thanks Thanks for filing this. However it was already filed as #931044 and the issue itself was fixed in python3.4 3.4.2-1+deb8u4. Hope that helps. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-10 Thread Chris Wilson
months to fix the issue from when you reported it to me, so unless a package has at least one full-time developer, a month simply isn't enough to fix this issue. Not even close for a hobbyist like myself. Thanks, Chris. On Sun, 9 Jun 2019 at 23:26, Reinhard Tartler wrote: > Agr

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-09 Thread Chris Wilson
carefully whether this course of action was really in the best interests of its users. Thanks, Chris. Sent from my iPhone > On 7 Jun 2019, at 22:26, Reinhard Tartler wrote: > > > >> On Wed, Jun 5, 2019 at 7:46 PM Chris Wilson wrote: >> Hi Reinhard, >> >>

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-06-05 Thread Chris Wilson
Hi Reinhard, Could you have a look at this patch <https://github.com/boxbackup/boxbackup/compare/debian_10_fix_ssl> (documented here <https://github.com/boxbackup/boxbackup/wiki/WeakSSLCertificates#workaround-2>) to see if it's something like what you were hoping for? Thanks, Chris.

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-05 Thread Chris Lamb
[adding 929...@bugs.debian.org to CC] Hi Moritz, > > Sure. Here's my updated patch: Uploaded zookeeper_3.4.9-3+deb9u2_amd64.changes to security-master. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org  chris-lamb.co.uk `-

Bug#929283: zookeeper: CVE-2019-0201: information disclosure vulnerability

2019-06-04 Thread Chris Lamb
ulnerability where users +who were not authorised to read data were able to view the access control +list. (Closes: #929283) + + -- Chris Lamb Fri, 24 May 2019 08:57:53 +0100 + zookeeper (3.4.9-3+deb9u1) stretch-security; urgency=high * Team upload. diff -Nru zookeeper-3.4.9/debia

Bug#929929: zfs smid

2019-06-03 Thread Chris Zubrzycki
Is there any chance to keep the removed exported symbol? Could you guys convince the kernel team? There’s no copyright issue since it’s released code, it’s just keeping a symbol that has been in exported in the kernel for the past 7 years. On top of that, Greg is violating the kernel release

Bug#907135: [Box Backup] Debian now requires 2048bit RSA keys

2019-05-31 Thread Chris Wilson
of not making Debian 10. I could create a special branch with a cut-down version of the solution, e.g. forcing the SecurityLevel to -1 (compatibility and warn) for the time being, in order to get the fix out in time for Debian 10, and then put the full version into backports? Thanks, Chris. On Fri, 31 May

Bug#929297: minissdpd: CVE-2019-12106

2019-05-27 Thread Chris Lamb
Hi Moritz, > > > Chris, thanks for your proposal to update Stretch, I very much > > > appreciate it. […] > This doesn't warrant a DSA, feel free to fix it via a point release instead. Sure thing. Proposed in #929613. Regards, -- ,''`. : :' : Chris Lam

Bug#929269: coturn: overwrites database file /var/lib/turn/turndb on upgrade or reinstall

2019-05-26 Thread Chris Lamb
overwriting it on upgrade/reinstall. (Closes: #929269) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `- diffstat for coturn-4.5.1.1 coturn-4.5.1.1 changelog |9 + control

Bug#929017: mutt: undefined behavior on huge integer in a RFC 2231 header

2019-05-25 Thread Chris Lamb
() function was being called on a number which can potentially overflow and thus can have security implications depending on the atoi() implementation. (Closes: #929017) The full debdiff is attached. Regards, -- ,''`. : :' : Chris Lamb `. `'` la

Bug#929297: minissdpd: CVE-2019-12106

2019-05-25 Thread Chris Lamb
Hey, > > The following vulnerability was published for minissdpd. > > > > CVE-2019-12106[0]: > > | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and > > | 1.5 allows a remote attacker to crash the process due to a Use After > > | Fre

<    1   2   3   4   5   6   7   8   9   10   >