[Bug 1908219] Re: [drm:qxl_enc_commit [qxl]] *ERROR* head number too large or missing monitors config:

2020-12-15 Thread Dariusz Gadomski
** Changed in: linux (Ubuntu Bionic) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1908219 Title: [drm:qxl_enc_commit [qxl]] *ERROR* h

[Bug 1908219] [NEW] [drm:qxl_enc_commit [qxl]] *ERROR* head number too large or missing monitors config:

2020-12-15 Thread Dariusz Gadomski
Public bug reported: [Impact] * Ubuntu 18.04 used as a guest in KVM with Spice/QXL in use may lead to a DRM error displayed during xorg launch: [drm:qxl_enc_commit [qxl]] *ERROR* head number too large or missing monitors config: (ptrval), 0 [Fix] *

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-08-12 Thread Dariusz Gadomski
I can verify that version 2.20.11-0ubuntu27.8 for focal fixes the issue. Running on server install: sudo apt install apport-gtk apt offers gnome-terminal as dependency. sudo apt install apport-kde pulls in konsole as dependency. ** Tags removed: verification-needed verification-needed-focal

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-08-11 Thread Dariusz Gadomski
** Changed in: apport (Ubuntu Focal) Status: Fix Committed => In Progress -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1881976 Title: apport-gtk and apport-kde install xiterm+thai as

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-08-10 Thread Dariusz Gadomski
The fix has been superseded by a security update. In the meantime a concurrent update of pycodestyle broke the apport build. I have backported fixes to the build issue from Groovy and uploaded the patch yesterday. Once the update is reviewed it should be available via the -proposed pocket. --

[Bug 1889556] Re: grub-install failure does not fail package upgrade (and does not roll back to matching modules)

2020-07-31 Thread Dariusz Gadomski
I have run some additional tests on bionic and focal desktop VMs with lvm (and lvm+luks) - no boot issues were observed with the -proposed builds. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1889556] Re: grub-install failure does not fail package upgrade (and does not roll back to matching modules)

2020-07-31 Thread Dariusz Gadomski
xenial verification: Tested with 1.66.27+2.02_beta2-36ubuntu3.27 from -proposed. Boots successfully in BIOS mode. Timestamps updated in EFI mode. ** Tags removed: verification-needed-xenial ** Tags added: verification-done-xenial ** Tags removed: verification-needed ** Tags added:

[Bug 1889556] Re: grub-install failure does not fail package upgrade (and does not roll back to matching modules)

2020-07-31 Thread Dariusz Gadomski
I have also attempted to verify xenial (using version 1.66.27+2.02_beta2-36ubuntu3.27), however grub-efi- amd64-signed_1.66.27+2.02_beta2-36ubuntu3.27 still seems to be unavailable in -proposed (http://archive.ubuntu.com). I have manually downloaded it and tested from here [1], however I'll

[Bug 1889556] Re: grub-install failure does not fail package upgrade (and does not roll back to matching modules)

2020-07-31 Thread Dariusz Gadomski
focal verification: Tested with version 1.142.4+2.04-1ubuntu26.2 from -proposed using the above test case. Boots successfully in BIOS mode. Timestamps updated in EFI mode. ** Tags removed: verification-needed-focal ** Tags added: verification-done-focal -- You received this bug notification

[Bug 1889556] Re: grub-install failure does not fail package upgrade (and does not roll back to matching modules)

2020-07-31 Thread Dariusz Gadomski
bionic-verification: Tested with version 1.93.19+2.02-2ubuntu8.17 from -proposed using the test case in the description. Boots successfully in BIOS mode. Timestamps were updated in EFI mode. ** Tags removed: sts verification-needed-bionic ** Tags added: verification-done-bionic -- You

[Bug 1884265] Re: [fips] ntpq segfaults when attempting to use MD5 from FIPS-openssl library.

2020-07-29 Thread Dariusz Gadomski
I have verified it for Bionic using ntp 1:4.2.8p10+dfsg-5ubuntu7.2. No segfault observed: sudo ntpq -p remote refid st t when poll reach delay offset jitter == 0.ubuntu.pool.n .POOL. 16 p - 64 0 0.000 0.000 0.000

[Bug 1884265] Re: [fips] ntpq segfaults when attempting to use MD5 from FIPS-openssl library.

2020-07-29 Thread Dariusz Gadomski
I have verified it for Bionic using ntp 1:4.2.8p10+dfsg-5ubuntu7.2. No segfault observed: sudo ntpq -p remote refid st t when poll reach delay offset jitter == 0.ubuntu.pool.n .POOL. 16

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-27 Thread Dariusz Gadomski
** Tags added: sts-sponsor-dgadomski -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1885562 Title: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode To manage notifications about this bug

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-07-27 Thread Dariusz Gadomski
** Tags added: sts-sponsor-dgadomski -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1881976 Title: apport-gtk and apport-kde install xiterm+thai as dependency (x -terminal-emulator) To manage

[Bug 1861177] Re: seccomp_rule_add is very slow

2020-07-27 Thread Dariusz Gadomski
Marking Eoan as Won't fix due to EOL. ** Changed in: libseccomp (Ubuntu Eoan) Status: Fix Committed => Won't Fix -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1861177 Title:

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-07-23 Thread Dariusz Gadomski
SRU proposal for focal. ** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1881976/+attachment/5395298/+files/focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1881976] Re: apport-gtk and apport-kde install xiterm+thai as dependency (x-terminal-emulator)

2020-07-23 Thread Dariusz Gadomski
SRU proposal for groovy ** Patch removed: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/apport/+bug/1881976/+attachment/5395109/+files/groovy.debdiff ** Patch removed: "focal.debdiff"

[Bug 1881976] Re: xiterm+thai installed by default in Ubuntu 20.04 (Australian Locale)

2020-07-23 Thread Dariusz Gadomski
New => In Progress ** Changed in: apport (Ubuntu) Importance: Undecided => Medium ** Changed in: apport (Ubuntu Focal) Importance: Undecided => Medium ** Changed in: apport (Ubuntu) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) ** Changed in: apport (Ubuntu Focal

[Bug 1881976] Re: xiterm+thai installed by default in Ubuntu 20.04 (Australian Locale)

2020-07-23 Thread Dariusz Gadomski
** Changed in: xiterm+thai (Ubuntu Focal) Importance: Undecided => Medium ** Changed in: xiterm+thai (Ubuntu) Importance: Undecided => Medium ** Changed in: xiterm+thai (Ubuntu) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) ** Changed in: xiterm+thai (Ubu

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-23 Thread Dariusz Gadomski
I tested libnss3 2:3.49.1-1ubuntu1.3 on focal, however this was not done in FIPS-mode (as there are no FIPS packages for focal available). I did not find a way to trigger the signature verification outside FIPS mode, but in normal usecase (FIPS disabled) everything works as expected, no

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-23 Thread Dariusz Gadomski
Tested with 2:3.35-2ubuntu2.10 on 18.04: sudo chronyd -d 2020-07-23T08:40:19Z chronyd version 3.2 starting (+CMDMON +NTP +REFCLOCK +RTC +PRIVDROP +SCFILTER +SECHASH +SIGND +ASYNCDNS +IPV6 -DEBUG) 2020-07-23T08:40:19Z Frequency -1.068 +/- 0.045 ppm read from /var/lib/chrony/chrony.drift (no

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-23 Thread Dariusz Gadomski
** Tags removed: verification-needed-bionic ** Tags added: verification-done-bionic -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1885562 Title: [fips] freebl_fipsSoftwareIntegrityTest fails in

[Bug 1881976] Re: xiterm+thai installed by default in Ubuntu 20.04 (Australian Locale)

2020-07-23 Thread Dariusz Gadomski
SRU proposal for groovy. ** Description changed: + [Impact] + + * When installing apport-gtk (or apport-kde) on a non-GUI installation (cloud image, server image) as a dependency providing x-terminal-emulator xiterm+thai package is pulled in, which is not appropriate for most locales. + My

[Bug 1881976] Re: xiterm+thai installed by default in Ubuntu 20.04 (Australian Locale)

2020-07-23 Thread Dariusz Gadomski
SRU proposal for focal ** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/xiterm+thai/+bug/1881976/+attachment/5395110/+files/focal.debdiff ** Description changed: [Impact] - * When installing apport-gtk (or apport-kde) on a non-GUI installation (cloud image,

[Bug 1884265] Re: [fips] ntpq segfaults when attempting to use MD5 from FIPS-openssl library.

2020-07-22 Thread Dariusz Gadomski
** Also affects: ntp (Ubuntu) Importance: Undecided Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title: [fips] ntpq segfaults when attempting to use MD5 from

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-17 Thread Dariusz Gadomski
** Description changed: + [Impact] + + * Prevents using some parts of nss in FIPS mode - e.g. + libfreeblpriv3.so (failed asserts). The library during initialization + tries to verify it's own binaries against signatures in chk files + shipped along with it (created at build time). They are

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-15 Thread Dariusz Gadomski
As discussed with Richard outside LP: we agreed that adding symlinks is an acceptable solution to this problem. Debdiffs linked. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1885562 Title: [fips]

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-15 Thread Dariusz Gadomski
** Changed in: nss (Ubuntu) Assignee: Richard Maciel Costa (richardmaciel) => Dariusz Gadomski (dgadomski) ** Changed in: nss (Ubuntu Bionic) Assignee: Richard Maciel Costa (richardmaciel) => Dariusz Gadomski (dgadomski) -- You received this bug notification because you are a

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-07-10 Thread Dariusz Gadomski
Oh, I have found it: ppa:j-latten/joydevppa Works perfectly. Thanks! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title: [fips] Not fully initialized digest segfaulting some client

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-07-10 Thread Dariusz Gadomski
Sure. Sounds good. Do you have it available in a ppa anywhere to give it a try? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title: [fips] Not fully initialized digest segfaulting some

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-08 Thread Dariusz Gadomski
@richardmaciel please let me know if I can help you with anything with regard to this bug. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1885562 Title: [fips] freebl_fipsSoftwareIntegrityTest fails

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-07-08 Thread Dariusz Gadomski
@j-latten: please let me know if I can provide any help with this. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title: [fips] Not fully initialized digest segfaulting some client

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
The patches I've uploaded implement the Solution B from the description. It actually applies only to Bionic, but I believe it's worth having it in Focal if it gets FIPS certification and for Groovy - to keep it for the future releases. -- You received this bug notification because you are a

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
Bionic debdiff reupload ** Patch added: "bionic.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388756/+files/bionic.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
groovy fix ** Patch added: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388751/+files/groovy.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
SRU proposal for Focal May be useful if it gets FIPS-certified. ** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388752/+files/focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
Focal debdiff reupload ** Patch added: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388755/+files/focal.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
Groovy debdiff re-upload ** Patch added: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388754/+files/groovy.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
SRU proposal for bionic ** Patch removed: "focal.debdiff" https://bugs.launchpad.net/ubuntu/+source/nss/+bug/1885562/+attachment/5388752/+files/focal.debdiff ** Patch removed: "groovy.debdiff"

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-07-01 Thread Dariusz Gadomski
** Description changed: In FIPS mode there are some additional checks performed. They lead to verifying binaries signatures. Those signatures are shipped in the libnss3 package as *.chk files installed in /usr/lib/$(DEB_HOST_MULTIARCH)/nss. Along with those files are the libraries

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-06-30 Thread Dariusz Gadomski
I have briefly analyzed nss code - it uses the nspr library for, inter alia, file access abstraction. From what I saw in the docs it does not offer any form of symlink resolution, so it may be nontrivial to safely implement it in nss code. -- You received this bug notification because you are a

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-06-29 Thread Dariusz Gadomski
** Description changed: - When in FIPS mode there some additional checks performed. + In FIPS mode there are some additional checks performed. They lead to verifying binaries signatures. Those signatures are shipped in the libnss3 package as *.chk files installed in

[Bug 1885562] Re: [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-06-29 Thread Dariusz Gadomski
** Summary changed: - freebl_fipsSoftwareIntegrityTest fails in FIPS mode + [fips] freebl_fipsSoftwareIntegrityTest fails in FIPS mode ** Tags added: sts -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1885562] [NEW] freebl_fipsSoftwareIntegrityTest fails in FIPS mode

2020-06-29 Thread Dariusz Gadomski
*** This bug is a security vulnerability *** Public security bug reported: When in FIPS mode there some additional checks performed. They lead to verifying binaries signatures. Those signatures are shipped in the libnss3 package as *.chk files installed in /usr/lib/$(DEB_HOST_MULTIARCH)/nss.

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-06-24 Thread Dariusz Gadomski
** Description changed: In FIPS mode on Bionic MD5 is semi-disabled causing some applications to segfault. Test case: sudo apt install ntp ntpq -p Segmentation fault (core dumped) What happens there is ntpq wants to iterate all available digests (list_digest_names in

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-06-19 Thread Dariusz Gadomski
Changelog in bug #1553309 mentions "- debian/patches/openssl-1.0.2g- fips-md5-allow.patch: [PATCH 3/6] Allow md5 in fips mode." I am however unaware of the context of this change (e.g. MD5 is not included here: [1]) [1]

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-06-19 Thread Dariusz Gadomski
** Changed in: openssl (Ubuntu Bionic) Importance: Undecided => Medium ** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title:

[Bug 1884265] [NEW] [fips] Not fully initialized digest segfaulting some client applications

2020-06-19 Thread Dariusz Gadomski
*** This bug is a security vulnerability *** Public security bug reported: In FIPS mode on Bionic MD5 is semi-disabled causing some applications to segfault. Test case: sudo apt install ntp ntpq -p Segmentation fault (core dumped) What happens there is ntpq wants to iterate all available

[Bug 1884265] Re: [fips] Not fully initialized digest segfaulting some client applications

2020-06-19 Thread Dariusz Gadomski
FTR: EVP_add_digest(EVP_md5()); is not present in the Xenial build, hence there's no crash there. ** Tags added: sts -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1884265 Title: [fips] Not fully

[Bug 1878155] Re: Thunderbird fails to connect to server in FIPS mode

2020-05-15 Thread Dariusz Gadomski
With latest builds from ppa:ubuntu-mozilla-security/ppa: Xenial - 1:68.8.0+build2-0ubuntu0.16.04.2 Bionic - 1:68.8.0+build2-0ubuntu0.18.04.2 this issue is gone. Thank you! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1871214] Re: [SRU] nfsd doesn't start if exports depend on mount

2020-05-14 Thread Dariusz Gadomski
Debian merge request of the fix: https://salsa.debian.org/kernel-team /nfs-utils/-/merge_requests/2 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1871214 Title: [SRU] nfsd doesn't start if exports

[Bug 1871214] Re: [SRU] nfsd doesn't start if exports depend on mount

2020-05-13 Thread Dariusz Gadomski
Rodrigo, I have tried to make it work using --with-systemd flag passed in d/rules, but every time I make a fix something else backfires. I doubt it has ever been used before. As a sidenote: we are lagging a lot behind upstream (they're at 2.4.4 already, we're at 1.3.4 and so is Debian). But we

[Bug 1878155] Re: Thunderbird fails to connect to server in FIPS mode

2020-05-12 Thread Dariusz Gadomski
Sure, thanks Olivier. Can you give me an estimate on when this can be fixed for Xenial and Bionic? For users using FIPS mode currently Thunderbird is currently unusable. ** Changed in: thunderbird (Ubuntu Xenial) Assignee: Dariusz Gadomski (dgadomski) => (unassigned) ** Chan

[Bug 1878155] Re: Thunderbird fails to connect to server in FIPS mode

2020-05-12 Thread Dariusz Gadomski
Groovy fix. ** Patch added: "groovy.debdiff" https://bugs.launchpad.net/ubuntu/+source/thunderbird/+bug/1878155/+attachment/5370320/+files/groovy.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1878155] Re: Thunderbird fails to connect to server in FIPS mode

2020-05-12 Thread Dariusz Gadomski
importance for Xenial and Bionic marked as high as this prevents Thunderbird from being used in FIPS mode on those releases. ** Changed in: thunderbird (Ubuntu Groovy) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) ** Changed in: thunderbird (Ubuntu Focal) Assignee: (unassig

[Bug 1878155] Re: Thunderbird fails to connect to server in FIPS mode

2020-05-12 Thread Dariusz Gadomski
It is already included upstream starting from release 75.0b1. ** Also affects: thunderbird (Ubuntu Groovy) Importance: Undecided Status: New ** Also affects: thunderbird (Ubuntu Eoan) Importance: Undecided Status: New ** Also affects: thunderbird (Ubuntu Focal)

[Bug 1878155] [NEW] Thunderbird fails to connect to server in FIPS mode

2020-05-12 Thread Dariusz Gadomski
Public bug reported: [Impact] * Thunderbird may become useless after booting into FIPS mode - it refuses to connect to server displaying the following message: Unexpected response from the server This document cannot be displayed unless you install the Personal Security Manager (PSM).

[Bug 1871214] Re: [SRU] nfsd doesn't start if exports depend on mount

2020-04-30 Thread Dariusz Gadomski
** Tags added: sts-sponsor-dgadomski -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1871214 Title: [SRU] nfsd doesn't start if exports depend on mount To manage notifications about this bug go to:

[Bug 1733321] Re: network-manager ADT tests fail with on ppc64el with artful/linux 4.13.0.17.18

2020-03-30 Thread Dariusz Gadomski
** Changed in: network-manager (Ubuntu Eoan) Assignee: Dariusz Gadomski (dgadomski) => (unassigned) ** Changed in: network-manager (Ubuntu Focal) Assignee: Dariusz Gadomski (dgadomski) => (unassigned) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1733321] Re: network-manager ADT tests fail with on ppc64el with artful/linux 4.13.0.17.18

2020-03-30 Thread Dariusz Gadomski
Sure Dan, I'm looking into it. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1733321 Title: network-manager ADT tests fail with on ppc64el with artful/linux 4.13.0.17.18 To manage notifications

[Bug 1733321] Re: network-manager ADT tests fail with on ppc64el with artful/linux 4.13.0.17.18

2020-03-30 Thread Dariusz Gadomski
** Changed in: network-manager (Ubuntu Eoan) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) ** Changed in: network-manager (Ubuntu Focal) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) -- You received this bug notification because you are a member of Ubuntu Bugs,

[Bug 1867398] Re: [Regression] unsupported protocol scheme

2020-03-21 Thread Dariusz Gadomski
Hey Jorge, I've checked the bionic patch and it looks ok. I just need to ask you for a couple of minor improvements: 1. Package version number should be rather 1.3.3-0ubuntu1~18.04.2 than 1.3.3-0ubuntu1~18.04.1ubuntu1 2. Patch commit id - the patch says 58769373c5509297749e9e12f0a99fb43653fa07

[Bug 1867398] Re: [Regression] unsupported protocol scheme

2020-03-20 Thread Dariusz Gadomski
** Tags removed: sts-needs-sponsor sts-sponsors ** Tags added: sts-sponsor-dgadomski -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1867398 Title: [Regression] unsupported protocol scheme To manage

[Bug 1867398] Re: [Regression] unsupported protocol scheme

2020-03-20 Thread Dariusz Gadomski
** Tags removed: sts-needs-sponsor ** Tags added: sts-sponsor-dgadomski -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1867398 Title: [Regression] unsupported protocol scheme To manage

[Bug 1862226] Re: /usr/sbin/sss_obfuscate fails to run: ImportError: No module named pysss

2020-02-21 Thread Dariusz Gadomski
I've just run a test against the modified version built in a ppa: === >8 # apt upgrade Reading package lists... Done Building dependency tree Reading state information... Done Calculating upgrade... Done The following NEW packages will be installed: python-sss The following packages

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-20 Thread Dariusz Gadomski
Xenial verification: Similarly to bionic with Xenial version of libapache2-mod-wsgi 4.3.0-1.1ubuntu1 and setting WSGISocketRotation Off in /etc/apache2/conf-enabled/wsgi.conf there's no socket rotation: $ ls -1 /var/run/apache2/wsgi.*.sock /var/run/apache2/wsgi.3170.u33.1.sock $ sudo systemctl

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-20 Thread Dariusz Gadomski
Bionic verification: After installing libapache2-mod-wsgi 4.5.17-1ubuntu1 and setting WSGISocketRotation Off in /etc/apache2/mods-available/wsgi.conf I confirm there is no socket rotation after reload: $ ls -1 /var/run/apache2/wsgi.*.sock /var/run/apache2/wsgi.4963.u33.1.sock $ sudo systemctl

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-14 Thread Dariusz Gadomski
SRU proposal for Xenial. ** Description changed: - On Apache reloads the daemon tries to rotate wsgi sockets causing - unnecessary log entries, especially in OpenStack context. + [Impact] + + * Lack of option for disabling wsgi socket rotation leads to errors on graceful restarts, making them

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-14 Thread Dariusz Gadomski
SRU proposal for bionic. ** Patch added: "bionic_mod-wsgi_4.5.17-1ubuntu1.debdiff" https://bugs.launchpad.net/ubuntu/+source/mod-wsgi/+bug/1863232/+attachment/5328185/+files/bionic_mod-wsgi_4.5.17-1ubuntu1.debdiff -- You received this bug notification because you are a member of Ubuntu

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-14 Thread Dariusz Gadomski
** Tags added: sts -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1863232 Title: daemon rotates socket on restart To manage notifications about this bug go to:

[Bug 1863232] [NEW] daemon rotates socket on restart

2020-02-14 Thread Dariusz Gadomski
Status: Fix Released ** Affects: mod-wsgi (Ubuntu Xenial) Importance: Undecided Assignee: Dariusz Gadomski (dgadomski) Status: In Progress ** Affects: mod-wsgi (Ubuntu Bionic) Importance: Undecided Assignee: Dariusz Gadomski (dgadomski) Status: In Progress

[Bug 1863232] Re: daemon rotates socket on restart

2020-02-14 Thread Dariusz Gadomski
Since it is already present upstream it's fixed for focal and eoan. -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1863232 Title: daemon rotates socket on restart To manage notifications about this

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-02-10 Thread Dariusz Gadomski
I have repeated verification for eoan (242-7ubuntu3.7) with identical results. ubuntu@eoan:~$ groups ubuntu adm dialout cdrom sudo dip plugdev users lpadmin lxd sambashare -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-02-10 Thread Dariusz Gadomski
Similarly for bionic using version 237-3ubuntu10.39 verification was also successsful: ubuntu@bionic:~$ groups ubuntu adm dialout cdrom sudo dip plugdev users lpadmin sambashare vboxsf ** Tags removed: verification-needed verification-needed-bionic verification-needed-eoan ** Tags added:

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-02-05 Thread Dariusz Gadomski
With identical setup and testcase for eoan I have managed to successfully verify the patch with version 242-7ubuntu3.3: ubuntu@eoan:~$ groups ubuntu adm dialout cdrom sudo dip plugdev users lpadmin lxd sambashare ubuntu@eoan:~$ ** Tags removed: verification-needed-eoan ** Tags added:

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-02-05 Thread Dariusz Gadomski
I have just verified bionic. With version 237-3ubuntu10.34 after replaying test case from the description I see the groups from /etc/security/group.conf (dialout, users) added: ubuntu@bionic:~$ groups ubuntu adm dialout cdrom sudo dip plugdev users lpadmin sambashare vboxsf ** Tags removed:

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-28 Thread Dariusz Gadomski
systemd in Xenial differs to much to cleanly apply the upstream fix. It would require reimplementing it and may be more risky than useful. Marking Won't fix. ** Changed in: systemd (Ubuntu Xenial) Status: New => Won't Fix -- You received this bug notification because you are a member of

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-20 Thread Dariusz Gadomski
SRU proposal for bionic (patches split) ** Patch removed: "bionic_systemd_237-3ubuntu10.34.debdiff" https://bugs.launchpad.net/systemd/+bug/1762391/+attachment/5321138/+files/bionic_systemd_237-3ubuntu10.34.debdiff ** Patch added: "bionic_systemd_237-3ubuntu10.34.debdiff"

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-20 Thread Dariusz Gadomski
SRU proposal for eoan (patches split) ** Patch removed: "eoan_systemd_242-7ubuntu3.3.debdiff" https://bugs.launchpad.net/systemd/+bug/1762391/+attachment/5321139/+files/eoan_systemd_242-7ubuntu3.3.debdiff ** Patch added: "eoan_systemd_242-7ubuntu3.3.debdiff"

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-17 Thread Dariusz Gadomski
SRU proposal for eoan. ** Patch added: "eoan_systemd_242-7ubuntu3.3.debdiff" https://bugs.launchpad.net/systemd/+bug/1762391/+attachment/5321139/+files/eoan_systemd_242-7ubuntu3.3.debdiff ** Description changed: [Impact] - pam_setcred call was missing in systemd making it's

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-17 Thread Dariusz Gadomski
SRU proposal for bionic. ** Patch added: "bionic_systemd_237-3ubuntu10.34.debdiff" https://bugs.launchpad.net/systemd/+bug/1762391/+attachment/5321138/+files/bionic_systemd_237-3ubuntu10.34.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-17 Thread Dariusz Gadomski
** Description changed: + [Impact] + + pam_setcred call was missing in systemd making it's implementation of the PAM protocol problematic. It could manifest in different ways, but one particularly problematic for enterprise environments was the fact that + processes were never getting group

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-16 Thread Dariusz Gadomski
SRU proposal for focal. Upstream regression has been resolved and the fix is integrated in the patch. ** No longer affects: gnome-terminal (Ubuntu Eoan) ** Patch removed: "focal_systemd_244-3ubuntu4.debdiff"

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-15 Thread Dariusz Gadomski
Train verification successful: 14.2.2-0ubuntu3~cloud0 $ time ceph-volume lvm list ... real0m14.446s 14.2.4-0ubuntu0.19.10.1~cloud0 $ time ceph-volume lvm list ... real0m2.400s ** Tags removed: verification-train-needed ** Tags added: verification-train-done ** Tags removed:

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-15 Thread Dariusz Gadomski
Stein verification successful: 13.2.6-0ubuntu0.19.04.4~cloud0 $ time ceph-volume lvm list ... real 0m10.533s 13.2.7-0ubuntu0.19.04.1~cloud0 $ time ceph-volume lvm list ... real 0m2.048s ** Tags removed: verification-stein-needed ** Tags added: verification-stein-done -- You received this bug

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-15 Thread Dariusz Gadomski
Rocky verification successful: 13.2.6-0ubuntu0.18.10.3~cloud0 $ time ceph-volume lvm list ... real0m10.061s 13.2.7-0ubuntu0.18.10.1~cloud0 $ time ceph-volume lvm list ... real0m1.952s ** Tags removed: verification-rocky-needed ** Tags added: verification-rocky-done -- You received

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-15 Thread Dariusz Gadomski
Queens verification successful: 12.2.12-0ubuntu0.18.04.3~cloud0 $ time ceph-volume lvm list ... real0m12.613s 12.2.12-0ubuntu0.18.04.4~cloud0 $ time ceph-volume lvm list ... real0m1.647s ** Tags removed: verification-queens-needed ** Tags added: verification-queens-done -- You

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-15 Thread Dariusz Gadomski
I've just verified disco. ceph-osd 13.2.6-0ubuntu0.19.04.4 $ time ceph-volume lvm list ... real 0m12.893s ceph-osd 13.2.7-0ubuntu0.19.04.1 $ time ceph-volume lvm list ... real 0m1.775s ** Tags removed: verification-needed-disco ** Tags added: verification-done-disco -- You received this bug

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-14 Thread Dariusz Gadomski
I have verified eoan: ceph-osd 14.2.2-0ubuntu3 $ time ceph-volume list ... real 0m4.788s ceph-osd 14.2.4-0ubuntu0.19.10.1 $ time ceph-volume list ... real 0m1.189s ** Tags removed: verification-needed-eoan ** Tags added: verification-eoan-eoan ** Tags removed: verification-eoan-eoan ** Tags

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2020-01-14 Thread Dariusz Gadomski
I have just verified bionic on an OSD with 20x10G disks with minimal load. ceph-osd 12.2.12-0ubuntu0.18.04.3 $ time ceph-volume lvm list ... real0m21.900s 12.2.12-0ubuntu0.18.04.4 $ time ceph-volume lvm list ... real0m2.580s ** Tags removed: verification-needed-bionic ** Tags added:

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-14 Thread Dariusz Gadomski
** No longer affects: gnome-terminal (Ubuntu) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1762391 Title: pam_group.so is not evaluated by gnome-terminal To manage notifications about this bug go

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-14 Thread Dariusz Gadomski
Please hold on with uploading until https://github.com/systemd/systemd/issues/14567 is resolved. ** Bug watch added: github.com/systemd/systemd/issues #14567 https://github.com/systemd/systemd/issues/14567 -- You received this bug notification because you are a member of Ubuntu Bugs, which

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-14 Thread Dariusz Gadomski
SRU proposal for Focal (upstream backport). ** Patch added: "focal_systemd_244-3ubuntu4.debdiff" https://bugs.launchpad.net/ubuntu/+source/gnome-terminal/+bug/1762391/+attachment/5320077/+files/focal_systemd_244-3ubuntu4.debdiff -- You received this bug notification because you are a member

[Bug 1762391] Re: pam_group.so is not evaluated by gnome-terminal

2020-01-14 Thread Dariusz Gadomski
signee: (unassigned) => Dariusz Gadomski (dgadomski) ** Changed in: systemd (Ubuntu Bionic) Assignee: (unassigned) => Dariusz Gadomski (dgadomski) ** Also affects: gnome-terminal (Ubuntu Eoan) Importance: Undecided Status: New ** Also affects: systemd (Ubuntu Eoan) Importanc

[Bug 1850754] Re: ceph-volume lvm list is O(n^2)

2019-11-26 Thread Dariusz Gadomski
James, I assume that debdiff is not symlink-aware and it does produce the duplicated output. From what I see dpkg-source --commit produced a correct patch. Is there a trick to make debdiff skip it? Or simply removing duplicated lines from debdiff output is the correct way to go? I'd appreciate

[Bug 1851407] Re: NetworkManager 1.10.6-2ubuntu1.2 breaks VPN DNS

2019-11-13 Thread Dariusz Gadomski
Thanks Joe. There has to be another factor coming into play, as my setup contains "use only for resources on its network". $ nmcli connection show my-vpn | grep -e ipv4.never-default -e ipv4.dns-priority ipv4.dns-priority: -30 ipv4.never-default: yes

[Bug 1851407] Re: NetworkManager 1.10.6-2ubuntu1.2 breaks VPN DNS

2019-11-13 Thread Dariusz Gadomski
Joe, I still can't reproduce your issue. Can you please verify against what I'm trying: 1. Setup a VPN that provides DNS via DHCP 2. Connect to that VPN and verify DNS by: $ systemd-resolve --status (...) Link 4 (tun0) (...) DNS Servers: X.X.X.X (...) 3. Disconnect VPN and edit connection: $ nmcli

[Bug 1851793] Re: NetworkManager OpenVPN No longer sets up DNS if "Use this connection only for resources on its network" is ticked

2019-11-12 Thread Dariusz Gadomski
Can you connect to that VPN with the same settings, but from a virtual machine with a freshly installed system? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1851793 Title: NetworkManager OpenVPN

[Bug 1851793] Re: NetworkManager OpenVPN No longer sets up DNS if "Use this connection only for resources on its network" is ticked

2019-11-12 Thread Dariusz Gadomski
The behavior described in this bug seems to be consistent with what is the default in Eoan (19.10). Uros, are you able to check if 19.10 network-manager is also affected with this? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1851793] Re: NetworkManager OpenVPN No longer sets up DNS if "Use this connection only for resources on its network" is ticked

2019-11-08 Thread Dariusz Gadomski
I examined the differences between bionic and upstream NetworkManager source around systemd-resolved interactions. I did not see any significant differences to blame for this. I have just tested it on a build from nm-1-10 branch of upstream NetworkManager and the behavior seems to be identical:

<    1   2   3   4   5   6   7   8   >