• key packages RC bugs of the month September

    From Paul Gevers@21:1/5 to All on Thu Sep 1 14:00:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------lPMwxdefLZ5jkpnaSmh11Cpp
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    RGVhciBhbGwsDQoNCkluIHRoZSBzYW1lIHRoZW1lIGFzIG15IGVhcmxpZXIgbWVzc2FnZSBb MF0sIEkgbGlrZSB0byBhc2sgeW91IHRvIHBsZWFzZSANCnNwZW5kIHNvbWUgdGltZSB0cmlh Z2luZyAoYW5kIGlkZWFsbHkgc29sdmluZykgb2xkIFJDIGJ1Z3MuIFNvbWUgDQpwYWNrYWdl cyB5b3UgbWF5IGNhcmUgYWJvdXQgd2VyZSByZW1vdmVkIGZyb20gdGVzdGluZyBiZWNhdXNl IHRoZSANCm1haW50YWluZXIgZGlkbid0IHRyaWFnZSBvciBmaXggdGhlIGJ1Zy4gQW5kIHRo ZW4gdGhlcmUncyBrZXkgcGFja2FnZXMuLi4NCg0KQXMgYSBSZWxlYXNlIFRlYW0gbWVtYmVy LCBJJ20gY29uY2VybmVkIGFib3V0IFJDIGJ1Z3MgZm9yIGtleSBwYWNrYWdlcyANClsxXSB0 aGF0IGRvbid0IGdldCBmaXhlZCBpbiBhIHRpbWVseSBtYW5uZXIuIEl0J3MgcmF0aGVyIHRy aXZpYWwgdG8gDQpyZW1vdmUgbm9uLWtleSBwYWNrYWdlcyBmcm9tIHRlc3RpbmcgKGFsYmVp dCB0aGF0IG5vdCBiZWluZyBuaWNlKSB3aGlsZSANCnJlbW92aW5nIGtleSBwYWNrYWdlcyBp cyBkaWZmaWN1bHQgb3IgaW1wb3NzaWJsZSB3aXRob3V0IG1ha2luZyBib29rd29ybSANCnVz ZWxlc3MuIEFzIHRoZSB0aHJlYXQgb2YgYXV0b3JlbW92YWwgaXNuJ3QgdGhlcmUsIHRoZXJl J3MgcXVpdGUgYSBidW5jaCANCm9mIFJDIGJ1Z3MgaW4ga2V5IHBhY2thZ2VzIGFmZmVjdGlu ZyB0ZXN0aW5nIHRoYXQgbGluZ2VyIHdpdGhvdXQgYSANCnJlc29sdXRpb24uIEFzIHRoZSBm cmVlemUgaXMgZHJhd2luZyBuZWFyZXIgSSdkIGxpa2UgdG8gdHJ5IGFuIA0KZXhwZXJpbWVu dDogSSdkIGxpa2UgdG8gcHJlc2VudCB0byB5b3Ugb24gYSBtb250aGx5IGJhc2lzIHRoZSAi a2V5IA0KcGFja2FnZXMgUkMgYnVncyBvZiB0aGUgbW9udGgiIGluIHRoZSBob3BlIHRvIGRy YXcgc29tZSBhdHRlbnRpb24gdG8gDQp0aGlzIGNsYXNzIG9mIGJ1Z3MuIFJlbWVtYmVyLCBm aXhpbmcgdGhlc2UgYnVncyBpcyBhIGNvbGxlY3RpdmUgZWZmb3J0Lg0KDQpJIGFtIGFza2lu ZyBmb3IgaGVscCB3aXRoIGludmVzdGlnYXRpbmcgUkMgYnVnIHJlcG9ydHMsIGp1ZGdpbmcg DQpzZXZlcml0eSwgcmVwcm9kdWNpbmcgdGhlIGlzc3VlLCBjbGFyaWZ5aW5nIHRoZSBwcm9i bGVtLCBpLmUuIGJ1ZyANCnRyaWFnaW5nIG9mIGFsbCBSQyBidWdzIHRoYXQgaGF2ZW4ndCBz ZWVuIGFjdGl2aXR5IGZvciBhIHdoaWxlIGFuZCB0aGF0IA0KYXJlIHN0aWxsIGFmZmVjdGlu ZyBib29rd29ybS4gT2YgY291cnNlIGlkZWFsbHkgdGhlIGJ1ZyBnZXRzIGZpeGVkLiBUbyAN CmdpdmUgZXhhbXBsZXMsIEkgbWVudGlvbiA1IGJ1Z3MgYmVsb3csIG5leHQgbW9udGggaG9w ZSBJJ2xsIG1haWwgNSBvdGhlciANCm9uZXMuDQoNClRoZSBmdWxsIGxpc3QgSSB1c2UgdG8g Y2hlY2sgZm9yIFJDIGJ1Z3MgaW4ga2V5IHBhY2thZ2VzIGNhbiBiZSBmb3VuZCBhdCANClsy XS4NCg0KIzkxOTI5NiBnaXQtZGFlbW9uLXJ1bg0KZmFpbHMgd2l0aCAnd2FybmluZzogZ2l0 LWRhZW1vbjogdW5hYmxlIHRvIG9wZW4gc3VwZXJ2aXNlL29rOiBmaWxlIGRvZXMgDQpub3Qg ZXhpc3QnDQpodHRwczovL2J1Z3MuZGViaWFuLm9yZy85MTkyOTYNCg0KIzkxOTkxNAlnbm9t ZS1zZXR0aW5ncy1kYWVtb24NCmdub21lLXR3ZWFrcyBub3cgZXF1YXRlcyAiZG9uJ3Qgc3Vz cGVuZCBvbiBsaWQgY2xvc2UiIHdpdGggImRvbid0IGxvY2sgDQpvbiBsaWQgY2xvc2UiIChz ZWN1cml0eSBpc3N1ZSkNCmh0dHBzOi8vYnVncy5kZWJpYW4ub3JnLzkxOTkxNA0KDQojOTYw Njc5IHNyYzpmb250Y29uZmlnDQpzdHJpY3QgZGVwZW5kZW5jeSBvZiBhcmNoOmFueSBsaWJm b250Y29uZmlnMSBvbiBhcmNoOmFsbCANCmZvbnRjb25maWctY29uZmlnIGdvaW5nIHdyb25n DQpodHRwczovL2J1Z3MuZGViaWFuLm9yZy85NjA2NzkNCg0KIzkzNTE4MiBsaWJyZW9mZmlj ZS1jb3JlDQpDb25jdXJyZW50IGZpbGUgb3BlbiBvbiB0aGUgc2FtZSBob3N0IHJlc3VsdHMg ZmlsZSBkZWxldGlvbg0KaHR0cHM6Ly9idWdzLmRlYmlhbi5vcmcvOTM1MTgyDQoNCiM5NDQ4 NzEgc3JjOmRvY2Jvb2steHNsDQpyZWFkZHMgY2F0YWxvZ3MgdG8gdGhlIHN1cGVyIGNhdGFs b2cgb24gZXZlcnkgdXBncmFkZQ0KaHR0cHM6Ly9idWdzLmRlYmlhbi5vcmcvOTQ0ODcxDQoN ClBhdWwNCg0KWzBdIGh0dHBzOi8vbGlzdHMuZGViaWFuLm9yZy9kZWJpYW4tZGV2ZWwvMjAy Mi8wNy9tc2cwMDEzMy5odG1sDQpbMV0gaHR0cHM6Ly9yZWxlYXNlLmRlYmlhbi5vcmcva2V5 LXBhY2thZ2VzLmh0bWwNClsyXSANCmh0dHBzOi8vdWRkLmRlYmlhbi5vcmcvZGV2L2J1Z3Mu Y2dpP3JlbGVhc2U9Ym9va3dvcm1fYW5kX3NpZCZtZXJnZWQ9aWduJmtleXBhY2thZ2VzPW9u bHkmZm5ld2VydmFsPTcmZmxhc3Rtb2R2YWw9NyZyYz0xJmN0YWdzPTEmY2RlZmVycmVkPTEm Y2xhc3R1cGxvYWQ9MSZjd2h5a2V5PTEmc29ydGJ5PWxhc3RfbW9kaWZpZWQmc29ydG89YXNj JmZvcm1hdD1odG1sI3Jlc3VsdHMNCg==

    --------------lPMwxdefLZ5jkpnaSmh11Cpp--

    -----BEGIN PGP SIGNATURE-----

    wsB5BAABCAAjFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAmMQnUUFAwAAAAAACgkQnFyZ6wW9dQp0 dAgAvuqZje1vV7vrhCkyH84jbgkqA8yOM84hMl+z3YCn9q0HpPukPU4cVsUmtgGBo6TEatDm8kqg X35I/IcpeNtCSpjVEq0rBmWYuGk1iz7JrV4ayR7ovMQyLV5YFo+sPps0fpGp8KI8aXA5SJ8jvzgZ zpsguZO0IAA+XGoeZ19U9L4Ca96oWJtKcHQ5B589Gbxkhp5s7Eo6Et5nHZC04+oiIRR7w7Zmtz6W veYwgNy/yPdRHvQUbagSvJLHWf1eq7atev/bYv3cDNLLIuHELd/QFgnjLIhG9OCquvXF3JNQmUr6 K+oVRWbq4/Lxbgo579Xe7DSz9twmxRSxsUpBV2A4bA==
    =hNN/
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Simon McVittie@21:1/5 to Paul Gevers on Thu Sep 1 17:00:02 2022
    On Thu, 01 Sep 2022 at 13:53:41 +0200, Paul Gevers wrote:
    #919914 gnome-settings-daemon
    gnome-tweaks now equates "don't suspend on lid close" with "don't lock on
    lid close" (security issue)
    https://bugs.debian.org/919914

    Honestly, I don't think this one is really RC. The
    bug reporter asserts that it's a RC security issue,
    but there are two contradictory user expectations (summary at https://gitlab.gnome.org/GNOME/gnome-settings-daemon/-/merge_requests/84#note_502354)
    and the current behaviour has been the same since Debian 10 if I'm
    reading the bug history correctly.

    smcv

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Rene Engelhard@21:1/5 to All on Thu Sep 1 21:20:01 2022
    Hi

    Am 01.09.22 um 13:53 schrieb Paul Gevers:
    #935182 libreoffice-core
    Concurrent file open on the same host results file deletion https://bugs.debian.org/935182

    This one has been open so long, is forwarded upstream. Has to do with
    samba *and* two persons on the same host doing it at the same time.

    This either should be ignored (like for bullseye) or downgrade, imho,
    but I didn't do it myself. I don't think there's anything actionable here...


    Regards,


    Rene

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Paul Gevers@21:1/5 to All on Thu Sep 1 22:20:01 2022
    This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------t90h9F0ieNTNEh4b2ptDeXpJ
    Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64

    SGkgYWxsLA0KDQpPbiAwMS0wOS0yMDIyIDIxOjEwLCBSZW5lIEVuZ2VsaGFyZCB3cm90ZToN Cj4gVGhpcyBlaXRoZXIgc2hvdWxkIGJlIGlnbm9yZWQgKGxpa2UgZm9yIGJ1bGxzZXllKSBv ciBkb3duZ3JhZGUsIGltaG8sIA0KPiBidXQgSSBkaWRuJ3QgZG8gaXQgbXlzZWxmLiBJIGRv bid0IHRoaW5rIHRoZXJlJ3MgYW55dGhpbmcgYWN0aW9uYWJsZSANCj4gaGVyZS4uLg0KDQpP biAwMS0wOS0yMDIyIDE2OjUyLCBTaW1vbiBNY1ZpdHRpZSB3cm90ZToNCiA+PiAjOTE5OTE0 CWdub21lLXNldHRpbmdzLWRhZW1vbg0KID4+IGdub21lLXR3ZWFrcyBub3cgZXF1YXRlcyAi ZG9uJ3Qgc3VzcGVuZCBvbiBsaWQgY2xvc2UiIHdpdGggImRvbid0IA0KbG9jayBvbg0KID4+ IGxpZCBjbG9zZSIgKHNlY3VyaXR5IGlzc3VlKQ0KID4+IGh0dHBzOi8vYnVncy5kZWJpYW4u b3JnLzkxOTkxNA0KID4gSG9uZXN0bHksIEkgZG9uJ3QgdGhpbmsgdGhpcyBvbmUgaXMgcmVh bGx5IFJDLiBUaGUNCiA+IGJ1ZyByZXBvcnRlciBhc3NlcnRzIHRoYXQgaXQncyBhIFJDIHNl Y3VyaXR5IGlzc3VlLA0KID4gYnV0IHRoZXJlIGFyZSB0d28gY29udHJhZGljdG9yeSB1c2Vy IGV4cGVjdGF0aW9ucyAoc3VtbWFyeSBhdA0KID4gDQpodHRwczovL2dpdGxhYi5nbm9tZS5v cmcvR05PTUUvZ25vbWUtc2V0dGluZ3MtZGFlbW9uLy0vbWVyZ2VfcmVxdWVzdHMvODQjbm90 ZV81MDIzNTQpDQogPiBhbmQgdGhlIGN1cnJlbnQgYmVoYXZpb3VyIGhhcyBiZWVuIHRoZSBz YW1lIHNpbmNlIERlYmlhbiAxMCBpZiBJJ20NCiA+IHJlYWRpbmcgdGhlIGJ1ZyBoaXN0b3J5 IGNvcnJlY3RseS4NCg0KSWYgSSByZWFkIHRoZXNlIGNvcnJlY3RseSwgdGhpcyBpcyBleGFj dGx5IHRoZSBraW5kIG9mIGFjdGlvbiB0aGF0IGEgDQptYWludGFpbmVyIGNhbiB0YWtlIHRv IG1ha2UgdGhlIHJlbGVhc2UgcHJvY2VzcyBzbW9vdGhlci4gSWYgKnlvdSogYXMgYSANCm1h aW50YWluZXIgdGhpbmsgdGhlIGJ1ZyBzaG91bGRuJ3QgYmUgUkMsIGJ5IGFsbCBtZWFucyBk b3duZ3JhZGUgaXQgDQooaWRlYWxseSB3aXRoIGFuIGV4cGxhbmF0aW9uIGp1c3QgaW4gY2Fz ZSBpdCdzIGRpc3B1dGVkIGxhdGVyIG9uKS4gVGhlIA0KUmVsZWFzZSBUZWFtIGRvZXNuJ3Qg KndhbnQqIHRvIGdvIG92ZXIgYWxsIFJDIGJ1Z3MgYW5kIGRlY2lkZSB0byBpZ25vcmUgDQp0 aGVtLCB3ZSBkb24ndCBoYXZlIHRoZSBpbnRpbWF0ZSBrbm93bGVkZ2Ugb2YgeW91ciBwYWNr YWdlIHRvIGp1ZGdlIGFuZCANCml0IHRha2VzIHRpbWUgdG8gYnVpbGQgdXAgZW5vdWdoIGtu b3dsZWRnZSB0byBtYWtlIHRoZSBqdWRnZW1lbnQgY2FsbC4gDQpJZiBpdCdzIGRpc3B1dGVk LCB3ZSBjYW4ganVkZ2UgaXQgKGFuZCByYWlzZSBzZXZlcml0eSBpZiBuZWVkZWQpIGxhdGVy IA0Kb24gd2l0aCBvdXIgUmVsZWFzZSBUZWFtIG1lbWJlciBoYXQgb24sIGJ1dCB0aGUgZmly c3QgY2FsbCBpcyBvbiB0aGUgDQptYWludGFpbmVyLg0KDQpQbGVhc2UuDQoNClBhdWwNCg==


    --------------t90h9F0ieNTNEh4b2ptDeXpJ--

    -----BEGIN PGP SIGNATURE-----

    wsB5BAABCAAjFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAmMRE4cFAwAAAAAACgkQnFyZ6wW9dQqv 7gf/Z2GggL1LUNc4p1NuqlYQ8E7ktkJ17/qTfkbEON163JOP7t5uoo1xW7qYykj3R2kzRVt36JtE kc1bZwkpFEZbij1bajXYyAKP+zLToyjzAEvCuCcjTSJqqtvOEeHM6rdYS15TgQtnZdCAs6Bn82ti e9fpWNrcIyH7hSjI6VNA1cXhBdFh85NJqGwNeYDk+yTZH4enaGr5sWStHdFE+l4c4baTIqQW33OT gSbv1uNwv8Gl1PY+FECfcExAed4FUYcEp91VJFS5R/PHwbXHif27ycN42pI6D+kjSa94Z2aQJlY9 fBh0/wSKnh0cqKmXRCol0jIXF4sAgfalOkG4WOUb6Q==
    =Y8oI
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Rene Engelhard@21:1/5 to All on Thu Sep 1 22:40:01 2022
    Hi,

    Am 01.09.22 um 22:18 schrieb Paul Gevers:
    On 01-09-2022 21:10, Rene Engelhard wrote:
    This either should be ignored (like for bullseye) or downgrade, imho,
    but I didn't do it myself. I don't think there's anything actionable
    here...
    [...]
    If I read these correctly, this is exactly the kind of action that a maintainer can take to make the release process smoother. If *you* as
    a maintainer think the bug shouldn't be RC, by all means downgrade it (ideally with an explanation just in case it's disputed later on).

    I understand that...

    But well, strictly speaking it *is* a data loss... If someone had a
    terminal server and several users and has the file on a samba share this potentially could still happen...

    I just don't belive this is a reason  to  block LO on this.

    Especially as it already was bullseye-ignore'd, so can't we just bookworm-ignore it?

    Regards,

    Rene

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)