NEW changes in oldstable-new

2019-07-27 Thread Debian FTP Masters
Processing changes file: patch_2.7.5-1+deb9u2_amd64.changes ACCEPT Processing changes file: patch_2.7.5-1+deb9u2_arm64.changes ACCEPT Processing changes file: patch_2.7.5-1+deb9u2_armel.changes ACCEPT Processing changes file: patch_2.7.5-1+deb9u2_armhf.changes ACCEPT Processing changes file

NEW changes in stable-new

2019-07-27 Thread Debian FTP Masters
Processing changes file: patch_2.7.6-3+deb10u1_amd64.changes ACCEPT Processing changes file: patch_2.7.6-3+deb10u1_arm64.changes ACCEPT Processing changes file: patch_2.7.6-3+deb10u1_armel.changes ACCEPT Processing changes file: patch_2.7.6-3+deb10u1_armhf.changes ACCEPT Processing changes

Bug#931386: stretch-pu: package fribidi/0.19.7-1.1

2019-07-27 Thread Jonathan Wiltshire
On Wed, Jul 03, 2019 at 07:36:55PM +0200, Samuel Thibault wrote: > As reported on #917909, the text-based debian installer support for > right-to-left languages is completely broken, only due to a path > mismatch. This was fixed in Buster in January with the attached change, > which I have uploaded

NEW changes in oldstable-new

2019-07-27 Thread Debian FTP Masters
Processing changes file: neovim_0.1.7-4+deb9u1_source.changes ACCEPT Processing changes file: neovim_0.1.7-4+deb9u1_all.changes ACCEPT Processing changes file: neovim_0.1.7-4+deb9u1_amd64.changes ACCEPT Processing changes file: neovim_0.1.7-4+deb9u1_arm64.changes ACCEPT Processing changes f

Re: Scheduling 10.1 and maybe 9.10

2019-07-27 Thread Jonathan Wiltshire
On Sat, Jul 20, 2019 at 08:36:30PM -0300, Jonathan Wiltshire wrote: > On Sun, Jul 14, 2019 at 07:35:01PM +0100, Jonathan Wiltshire wrote: > > - Auguest 31st > > - September 7th > > These look like the two options so far. Any other takers? I think we're just awaiting FTP masters now - I'd like t

Bug#931386: stretch-pu: package fribidi/0.19.7-1.1

2019-07-27 Thread Jonathan Wiltshire
On Mon, Jul 22, 2019 at 05:19:56AM +0200, Cyril Brulebois wrote: > Jonathan Wiltshire (2019-07-21): > > On Wed, Jul 03, 2019 at 07:36:55PM +0200, Samuel Thibault wrote: > > > Package: release.debian.org > > > Severity: normal > > > Tags: stretch > > > User: release.debian@packages.debian.org >

Re: Same procedure as every year: GCC defaults change (GCC 9)

2019-07-27 Thread Aurelien Jarno
On 2019-07-27 17:28, Matthias Klose wrote: > GCC 9 was released earlier this year, it is now available in Debian > testing/unstable. I am planning to do the defaults change in mid August, > around > the time of the expected first GCC 9 point release (9.2.0). > > There are only soname changes for

Processed: Re: buster-pu: freeorion/0.4.8-1+deb10u1

2019-07-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > retitle 931199 buster-pu: package freeorion/0.4.8-1+deb10u1 Bug #931199 [release.debian.org] buster-pu: package freeorion/0.4.8-1+deb10u1 Ignoring request to change the title of bug#931199 to the same title > user release.debian@packages.debia

NEW changes in stable-new

2019-07-27 Thread Debian FTP Masters
Processing changes file: unzip_6.0-23+deb10u1_source.changes REJECT

Processed: Re: Bug#933218: stretch-pu: package libsdl2-image/2.0.1+dfsg-2+deb9u2

2019-07-27 Thread Debian Bug Tracking System
Processing control commands: > tags -1 + confirmed Bug #933218 [release.debian.org] stretch-pu: package libsdl2-image/2.0.1+dfsg-2+deb9u2 Added tag(s) confirmed. -- 933218: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=933218 Debian Bug Tracking System Contact ow...@bugs.debian.org with pro

Bug#933218: stretch-pu: package libsdl2-image/2.0.1+dfsg-2+deb9u2

2019-07-27 Thread Adam D. Barratt
Control: tags -1 + confirmed On 2019-07-27 13:32, Hugo Lefeuvre wrote: libsdl2-image is currently affected by the following security issues in stretch: * CVE-2018-3977: Heap buffer overflow. * CVE-2019-5052: integer overflow and subsequent buffer overflow in IMG_pcx.c. * CVE-2019-5051: heap

Bug#932318: buster-pu: package unzip/6.0-23+deb10u1

2019-07-27 Thread Adam D. Barratt
On 2019-07-27 13:18, Santiago Vila wrote: tags 932318 - moreinfo thanks Hello. The problem with Firefox should now be fixed, and it was unzip's fault. If possible, I'd like this upload I did 6.0-23+deb10u1 to be rejected so that I can reuse the +deb10u1 version with all the fixes included.

Bug#933218: stretch-pu: package libsdl2-image/2.0.1+dfsg-2+deb9u2

2019-07-27 Thread Hugo Lefeuvre
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu Hi, libsdl2-image is currently affected by the following security issues in stretch: * CVE-2018-3977: Heap buffer overflow. * CVE-2019-5052: integer overflow and subsequent buffe

Bug#932318: buster-pu: package unzip/6.0-23+deb10u1

2019-07-27 Thread Santiago Vila
tags 932318 - moreinfo thanks Hello. The problem with Firefox should now be fixed, and it was unzip's fault. If possible, I'd like this upload I did 6.0-23+deb10u1 to be rejected so that I can reuse the +deb10u1 version with all the fixes included. Thanks.

Processed: Re: Bug#932318: buster-pu: package unzip/6.0-23+deb10u1

2019-07-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 932318 - moreinfo Bug #932318 [release.debian.org] buster-pu: package unzip/6.0-23+deb10u1 Removed tag(s) moreinfo. > thanks Stopping processing here. Please contact me if you need assistance. -- 932318: https://bugs.debian.org/cgi-bin/bugr

Same procedure as every year: GCC defaults change (GCC 9)

2019-07-27 Thread Matthias Klose
GCC 9 was released earlier this year, it is now available in Debian testing/unstable. I am planning to do the defaults change in mid August, around the time of the expected first GCC 9 point release (9.2.0). There are only soname changes for rather unused shared libraries (libgo) involved, and the

Processed: user release.debian....@packages.debian.org, reopening 931199, usertagging 931199, tagging 931199 ...

2019-07-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > user release.debian@packages.debian.org Setting user to release.debian@packages.debian.org (was a...@adam-barratt.org.uk). > reopen 931199 Bug #931199 {Done: Ivo De Decker } [release.debian.org] unblock: freeorion/0.4.8-3 Bug reopened Ig

Processed: tagging 932175

2019-07-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Acked by KiBi > tags 932175 - d-i Bug #932175 [release.debian.org] stretch-pu: package openssh/1:7.4p1-10+deb9u7 Removed tag(s) d-i. > thanks Stopping processing here. Please contact me if you need assistance. -- 932175: https://bugs.debian.or

Processed: tagging 930420

2019-07-27 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > # Acked by KiBi > tags 930420 - d-i Bug #930420 [release.debian.org] stretch-pu: package grub2/2.02~beta3-5+deb9u2 Removed tag(s) d-i. > thanks Stopping processing here. Please contact me if you need assistance. -- 930420: https://bugs.debian.or

Processed: buster-pu: package freetype 2.9.1-3+deb10u1

2019-07-27 Thread Debian Bug Tracking System
Processing control commands: > retitle -1 buster-pu: package freetype 2.9.1-3+deb10u1 Bug #932900 [release.debian.org] buster-pu: package freetype 2.9.1-4 Changed Bug title to 'buster-pu: package freetype 2.9.1-3+deb10u1' from 'buster-pu: package freetype 2.9.1-4'. -- 932900: https://bugs.debia

Bug#933125: buster-pu: package systemd/241-5+deb10u1

2019-07-27 Thread Cyril Brulebois
Hi, Michael Biebl (2019-07-26): > 241-5+deb10u1 is identical to 241-7 which has been uploaded to > unstable/bullseye and we haven't received any regression reports so > far. > > None of those changes should touch udev-udeb, i.e. d-i. > That said, I've added kibi/debian-boot to CC for his ack. N

Bug#930420: stretch-pu: package grub2/2.02~beta3-5+deb9u2

2019-07-27 Thread Cyril Brulebois
Adam D. Barratt (2019-07-26): > Sorry for the delay in getting back to you regarding this. > > While it doesn't sound like the changes should affect d-i, I would > still appreciate an ack on that side, so tagging and CCing > appropriately. No objections, thanks. Cheers, -- Cyril Brulebois (k.

Bug#932900: buster-pu: package freetype 2.9.1-4

2019-07-27 Thread Cyril Brulebois
Hi, Adam D. Barratt (2019-07-26): > -4 has already been uploaded to unstable, so this would need to be > 2.9.1-3+deb10u1. The changelog distribution is also preferred as > "buster", rather than "stable". > > As freetype produces a udeb, this will need an ack from the d-i > release manager, so CC

Bug#932175: stretch-pu: package openssh/1:7.4p1-10+deb9u7

2019-07-27 Thread Cyril Brulebois
Adam D. Barratt (2019-07-26): > On 2019-07-16 06:36, Moritz Muehlenhoff wrote: > > This update for OpenSSH fixes a dead lock in AuthorizedKeysCommand > > (#905226). > > > > The fixed package is running fine on a formerly affected Stretch system > > (https://phabricator.wikimedia.org) > > This lo

Bug#933176: stretch-pu: package fig2dev/1:3.2.6a-2+deb9u1

2019-07-27 Thread Roland Rosenfeld
Package: release.debian.org Severity: normal Tags: stretch User: release.debian@packages.debian.org Usertags: pu This fixes CVE-2019-14275 in stretch. Since this is tagged "unimportant" by the security team on https://security-tracker.debian.org/tracker/CVE-2019-14275 they won't publish a DSA

Bug#933175: buster-pu: package fig2dev/1:3.2.7a-5

2019-07-27 Thread Roland Rosenfeld
Package: release.debian.org Severity: normal Tags: buster User: release.debian@packages.debian.org Usertags: pu This fixes CVE-2019-14275 in buster. Since this is tagged "unimportant" by the security team on https://security-tracker.debian.org/tracker/CVE-2019-14275 they won't publish a DSA,