Adélie Linux issueshttps://git.adelielinux.org/groups/adelie/-/issues2024-01-09T13:37:37Zhttps://git.adelielinux.org/adelie/packages/-/issues/1157user/apache-httpd: multiple vulnerabilities2024-01-09T13:37:37ZZach van Rijnuser/apache-httpd: multiple vulnerabilitiesReference: https://downloads.apache.org/httpd/CHANGES_2.4.58
```
Changes with Apache 2.4.58
*) SECURITY: CVE-2023-45802: Apache HTTP Server: HTTP/2 stream
memory not reclaimed right away on RST (cve.mitre.org)
When a HTTP/2...Reference: https://downloads.apache.org/httpd/CHANGES_2.4.58
```
Changes with Apache 2.4.58
*) SECURITY: CVE-2023-45802: Apache HTTP Server: HTTP/2 stream
memory not reclaimed right away on RST (cve.mitre.org)
When a HTTP/2 stream was reset (RST frame) by a client, there
was a time window were the request's memory resources were not
reclaimed immediately. Instead, de-allocation was deferred to
connection close. A client could send new requests and resets,
keeping the connection busy and open and causing the memory
footprint to keep on growing. On connection close, all resources
were reclaimed, but the process might run out of memory before
that.
This was found by the reporter during testing of CVE-2023-44487
(HTTP/2 Rapid Reset Exploit) with their own test client. During
"normal" HTTP/2 use, the probability to hit this bug is very
low. The kept memory would not become noticeable before the
connection closes or times out.
Users are recommended to upgrade to version 2.4.58, which fixes
the issue.
Credits: Will Dormann of Vul Labs
*) SECURITY: CVE-2023-43622: Apache HTTP Server: DoS in HTTP/2 with
initial windows size 0 (cve.mitre.org)
An attacker, opening a HTTP/2 connection with an initial window
size of 0, was able to block handling of that connection
indefinitely in Apache HTTP Server. This could be used to
exhaust worker resources in the server, similar to the well
known "slow loris" attack pattern.
This has been fixed in version 2.4.58, so that such connection
are terminated properly after the configured connection timeout.
This issue affects Apache HTTP Server: from 2.4.55 through
2.4.57.
Users are recommended to upgrade to version 2.4.58, which fixes
the issue.
Credits: Prof. Sven Dietrich (City University of New York)
*) SECURITY: CVE-2023-31122: mod_macro buffer over-read
(cve.mitre.org)
Out-of-bounds Read vulnerability in mod_macro of Apache HTTP
Server.This issue affects Apache HTTP Server: through 2.4.57.
Credits: David Shoon (github/davidshoon)
```https://git.adelielinux.org/adelie/image/-/issues/408Beta5 Image Fails to Boot on iMac 20112023-12-19T18:51:39ZPeter ShkenevBeta5 Image Fails to Boot on iMac 2011Tried to boot beta5 lxqt image. Boot process stalled after printing "EFI STUB: Loaded initrd from LINUX_EFI_INITRD_MEDIA_GUID device path". I was able to use ctrl-option-delete to reboot.
iMac model: iMac12,2
GPU: AMD Radeon HD 6770M 51...Tried to boot beta5 lxqt image. Boot process stalled after printing "EFI STUB: Loaded initrd from LINUX_EFI_INITRD_MEDIA_GUID device path". I was able to use ctrl-option-delete to reboot.
iMac model: iMac12,2
GPU: AMD Radeon HD 6770M 512 Mb
UPD: it doesn't boot also on my home PC. I don't know what info could be useful, so please ask me to post needed data.https://git.adelielinux.org/adelie/gcompat/-/issues/361fcntl maps to what glibc would consider fcntl642023-12-16T05:49:25ZA. Wilcoxfcntl maps to what glibc would consider fcntl64I'm not sure if musl's fcntl will work with old binaries using the 32-bit (non-LFS64) flock structures. Needs testing at least, and probably a wrapper to translate them to 64-bit flock structures.I'm not sure if musl's fcntl will work with old binaries using the 32-bit (non-LFS64) flock structures. Needs testing at least, and probably a wrapper to translate them to 64-bit flock structures.https://git.adelielinux.org/adelie/gcompat/-/issues/360__fdelt_chk is not found2023-12-14T19:31:02ZKhem Raj__fdelt_chk is not foundWhile running with nvidia binary drivers its not able to map `__fdelt_chk`
```
weston[463]: [11:23:28.908] Failed to load module: Error relocating /usr/lib/libdrm.so.2: __fdelt_chk: symbol not found
```While running with nvidia binary drivers its not able to map `__fdelt_chk`
```
weston[463]: [11:23:28.908] Failed to load module: Error relocating /usr/lib/libdrm.so.2: __fdelt_chk: symbol not found
```https://git.adelielinux.org/adelie/horizon/-/issues/383Installer doesn't notice newly created partitions2023-12-13T17:06:04ZCyberLeoInstaller doesn't notice newly created partitionsRunning installer GUI in MATE live CD.
I used the manual partition editor provided in the installer GUI to create a partition in the free space on a GPT disk that had two other partitions on it already.
The partitions that existed when...Running installer GUI in MATE live CD.
I used the manual partition editor provided in the installer GUI to create a partition in the free space on a GPT disk that had two other partitions on it already.
The partitions that existed when the GUI started show up as options, but the newly created partition will not show up until I restart the installer or back up all the way to the Select Installation Disk step.
Looks like it needs to refresh its cache of available partitions whenever an edit may have occurred.https://git.adelielinux.org/adelie/horizon/-/issues/382Installing for i386-efi platform. grub-install: error: cannot find EFI direct...2023-12-10T23:13:28ZZach van RijnInstalling for i386-efi platform. grub-install: error: cannot find EFI directory.i386 QEMU with `adelie-inst-pmmx-1.0-beta5-20231210.iso`:
```
...
>>> 50-grub
Generating grub configuration file ...
Found linux image: /boot/vmlinuz-5.15.132-mc6-easy
Found initrd image: /boot/initramfs-5.15.132-mc6-easy.img
Warning: o...i386 QEMU with `adelie-inst-pmmx-1.0-beta5-20231210.iso`:
```
...
>>> 50-grub
Generating grub configuration file ...
Found linux image: /boot/vmlinuz-5.15.132-mc6-easy
Found initrd image: /boot/initramfs-5.15.132-mc6-easy.img
Warning: os-prober will not be executed to detect other bootable partitions.
Systems on them will not be added to the GRUB boot configuration.
Check GRUB_DISABLE_OS_PROBER documentation entry.
Adding boot menu entry for UEFI Firmware Settings ...
done
Executing graphviz-2.50.0-r0.trigger
Executing gdk-pixbuf-2.40.0-r0.trigger
Executing gtk-update-icon-cache-2.24.32-r2.trigger
Executing mkfontscale-1.2.2-r0.trigger
Executing vlc-libs-3.0.17.3-r1.trigger
OK: 3786 MiB in 1459 packages
2023-12-10T22:48:28.984 step-end pkgdb
2023-12-10T22:48:28.985 step-start post-metadata
2023-12-10T22:48:29.000 log /etc/horizon/installfile:33: info: rootpw: setting root passphrase
2023-12-10T22:48:29.011 log /etc/horizon/installfile:34: info: language: setting default system language to en_US.UTF-8
2023-12-10T22:48:29.012 log /etc/horizon/installfile:36: info: keymap: setting system keyboard map to us
2023-12-10T22:48:29.014 log internal: info: setting up user account user
2023-12-10T22:48:29.014 log /etc/horizon/installfile:39: info: username: creating account user
2023-12-10T22:48:29.095 log /etc/horizon/installfile:40: info: useralias: setting GECOS name for user
2023-12-10T22:48:29.115 log /etc/horizon/installfile:41: info: userpw: setting passphrase for user
2023-12-10T22:48:29.136 log /etc/horizon/installfile:42: info: usergroups: setting group membership for user
2023-12-10T22:48:29.155 log /etc/horizon/installfile:38: info: timezone: setting system timezone to America/Chicago
2023-12-10T22:48:29.157 log /etc/horizon/installfile:17: info: svcenable: enabling service bluetooth in runlevel 'default'
2023-12-10T22:48:29.158 log /etc/horizon/installfile:20: info: svcenable: enabling service elogind in runlevel 'default'
2023-12-10T22:48:29.159 log /etc/horizon/installfile:21: info: svcenable: enabling service sddm in runlevel 'default'
2023-12-10T22:48:29.159 log /etc/horizon/installfile:28: info: svcenable: enabling service udev in runlevel 'boot'
2023-12-10T22:48:29.160 log /etc/horizon/installfile:29: info: svcenable: enabling service udev-trigger in runlevel 'boot'
2023-12-10T22:48:29.162 log /etc/horizon/installfile:31: info: svcenable: enabling service sysklogd in runlevel 'default'
(1/7) Installing efivar (38-r0)
(2/7) Installing efivar-doc (38-r0)
(3/7) Installing popt (1.19-r0)
(4/7) Installing popt-doc (1.19-r0)
(5/7) Installing efibootmgr (18-r0)
(6/7) Installing efibootmgr-doc (18-r0)
(7/7) Installing grub-efi (2.12_rc1-r1)
Executing mandoc-1.14.6-r1.trigger
OK: 3791 MiB in 1466 packages
Installing for i386-efi platform.
grub-install: error: cannot find EFI directory.
2023-12-10T22:48:47.492 log chroot: error: exited abnormally with status 1
2023-12-10T22:48:47.493 log /etc/horizon/installfile:23: error: bootloader: failed to install GRUB
2023-12-10T22:48:47.493 log bootloader: error: The HorizonScript failed to execute: Check the log file for more details.
2023-12-10T22:48:47.493 log internal: error: Script failed. Stop.
```
[executor.log](/uploads/f599868a65dc5f7e6419e7e26d64f6aa/executor.log)
[installfile](/uploads/f398e43614857408af15befc1b82f0d6/installfile)https://git.adelielinux.org/adelie/packages/-/issues/1156user/kscreen: screen resolution settings not remembered after logging out and in2023-12-06T23:55:01ZZach van Rijnuser/kscreen: screen resolution settings not remembered after logging out and inFound in QEMU with KDE on the `20231027` image with a custom `adelie-wallpapers`:
Initially I set `1440x900` (this works perfectly!), selected "keep", and life seemed great:
![Screenshot_vm1_2023-12-06_17_50_18](/uploads/2d6639eea5cc79...Found in QEMU with KDE on the `20231027` image with a custom `adelie-wallpapers`:
Initially I set `1440x900` (this works perfectly!), selected "keep", and life seemed great:
![Screenshot_vm1_2023-12-06_17_50_18](/uploads/2d6639eea5cc7942e98f906fb9aa55b8/Screenshot_vm1_2023-12-06_17_50_18.png)
Then I logged out and back in, and it defaulted to `1024x768`. The wallpaper was distorted.
![Screenshot_vm1_2023-12-06_17_50_56](/uploads/0f96420d19199cfe0459793e4019347d/Screenshot_vm1_2023-12-06_17_50_56.png)https://git.adelielinux.org/adelie/wallpapers/-/issues/1menu bar margin is calculated before resize but should be calculated after re...2023-12-06T23:31:25ZZach van Rijnmenu bar margin is calculated before resize but should be calculated after resizeMenu bars (such as with KDE) are overlaid on top of the background image and do not cause the image to be stretched (compressed).
Our logo is given a 100px margin when it is initially composited, but the 100px measurement needs to be an...Menu bars (such as with KDE) are overlaid on top of the background image and do not cause the image to be stretched (compressed).
Our logo is given a 100px margin when it is initially composited, but the 100px measurement needs to be an effective 100px after the image has been resized to its target sizes.https://git.adelielinux.org/adelie/spack/-/issues/15elfutils: configure: error: failed to find argp_parse2023-12-04T23:19:32ZZach van Rijnelfutils: configure: error: failed to find argp_parseFound on aarch64:
```
...
checking for getrlimit... yes
checking whether strerror_r is declared... yes
checking whether strerror_r returns char *... no
/tmp/root/spack-stage/spack-stage-elfutils-0.189-erz5idnka4ga7u3tdxi4rfa4iwxrxwno/sp...Found on aarch64:
```
...
checking for getrlimit... yes
checking whether strerror_r is declared... yes
checking whether strerror_r returns char *... no
/tmp/root/spack-stage/spack-stage-elfutils-0.189-erz5idnka4ga7u3tdxi4rfa4iwxrxwno/spack-src/configure: 8748: test: xyes: unexpected operator
checking whether symbol versioning is supported... yes
checking whether gcc accepts -Wstack-usage... yes
checking whether gcc has a sane -Wlogical-op... yes
checking whether gcc accepts -Wduplicated-cond... yes
checking whether gcc accepts -Wnull-dereference... yes
checking whether gcc accepts -Wimplicit-fallthrough... yes
checking whether the compiler accepts -Wimplicit-fallthrough=5... yes
checking whether the compiler accepts -Wtrampolines... yes
checking whether the compiler accepts -Wno-packed-not-aligned... yes
checking whether the compiler accepts -Wuse-after-free=3... no
checking whether the compiler accepts -fno-addrsig... no
checking for library containing argp_parse... no
configure: error: in `/tmp/root/spack-stage/spack-stage-elfutils-0.189-erz5idnka4ga7u3tdxi4rfa4iwxrxwno/spack-src':
configure: error: failed to find argp_parse
See `config.log' for more details
```
and
```
...
configure:9255: /opt/spack/lib/spack/env/gcc/gcc -o conftest -D_FORTIFY_SOURCE=3 -g -O2 -DBAD_FTS=1 -Wl,--build-id conftest.c -largp >&5
/usr/lib/gcc/aarch64-foxkit-linux-musl/8.5.0/../../../../aarch64-foxkit-linux-musl/bin/ld: cannot find -largp: No such file or directory
collect2: error: ld returned 1 exit status
...
```
[spack-build-out.txt](/uploads/fcc774797fd4992c2af4d41bd20aec86/spack-build-out.txt)
[config.log](/uploads/8097f0730ed345100a5fdded692d30c1/config.log)https://git.adelielinux.org/adelie/packages/-/issues/1155user/hyfetch: add package2023-12-05T04:53:38ZZach van Rijnuser/hyfetch: add package@mc680x0 added support for Adélie to Hyfetch, a fork of Neofetch:
* https://github.com/hykilpikonna/hyfetch/pull/218
This was merged and released with `1.4.11`
So let's package it.@mc680x0 added support for Adélie to Hyfetch, a fork of Neofetch:
* https://github.com/hykilpikonna/hyfetch/pull/218
This was merged and released with `1.4.11`
So let's package it.https://git.adelielinux.org/adelie/packages/-/issues/1154user/adelie-wallpapers: new default images need more crop margin for KDE (pos...2023-12-04T04:45:49ZZach van Rijnuser/adelie-wallpapers: new default images need more crop margin for KDE (possibly others)![Screenshot_vm1_2023-12-03_21_32_17](/uploads/2d5f9c788023cbced13addffe95ade66/Screenshot_vm1_2023-12-03_21_32_17.png)![Screenshot_vm1_2023-12-03_21_32_17](/uploads/2d5f9c788023cbced13addffe95ade66/Screenshot_vm1_2023-12-03_21_32_17.png)https://git.adelielinux.org/adelie/packages/-/issues/1153user/adelie-wallpapers: metadata not showing up in KDE2023-12-04T04:46:29ZZach van Rijnuser/adelie-wallpapers: metadata not showing up in KDESeeing these weird repeating entries, and no name/author information.
![Screenshot_vm1_2023-12-03_20_49_28](/uploads/e6048a644c8a1345c11465cc503354d7/Screenshot_vm1_2023-12-03_20_49_28.png)Seeing these weird repeating entries, and no name/author information.
![Screenshot_vm1_2023-12-03_20_49_28](/uploads/e6048a644c8a1345c11465cc503354d7/Screenshot_vm1_2023-12-03_20_49_28.png)https://git.adelielinux.org/adelie/packages/-/issues/1152user/gtkmm+3.0: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):2023-12-05T15:45:56ZZach van Rijnuser/gtkmm+3.0: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):```
ERROR: unable to select packages:
.makedepends-gtkmm+3.0-20231202.215518:
masked in: cache
satisfies: world[.makedepends-gtkmm+3.0=20231202.215518]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-gtkmm+3.0-20231202.215518:
masked in: cache
satisfies: world[.makedepends-gtkmm+3.0=20231202.215518]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: libxslt
required by: .makedepends-gtkmm+3.0-20231202.215518[cmd:xsltproc]
>>> ERROR: gtkmm+3.0: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1151user/pangomm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):2023-12-05T15:45:56ZZach van Rijnuser/pangomm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):```
ERROR: unable to select packages:
.makedepends-pangomm-20231202.203009:
masked in: cache
satisfies: world[.makedepends-pangomm=20231202.203009]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-pangomm-20231202.203009:
masked in: cache
satisfies: world[.makedepends-pangomm=20231202.203009]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: libxslt
required by: .makedepends-pangomm-20231202.203009[cmd:xsltproc]
>>> ERROR: pangomm: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1150user/cairomm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):2023-12-05T15:45:56ZZach van Rijnuser/cairomm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):```
ERROR: unable to select packages:
.makedepends-cairomm-20231202.201622:
masked in: cache
satisfies: world[.makedepends-cairomm=20231202.201622]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-cairomm-20231202.201622:
masked in: cache
satisfies: world[.makedepends-cairomm=20231202.201622]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: libxslt
required by: .makedepends-cairomm-20231202.201622[cmd:xsltproc]
>>> ERROR: cairomm: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1149user/atkmm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):2023-12-05T15:45:56ZZach van Rijnuser/atkmm: FTBFS: ERROR: unable to select packages: cmd:xsltproc (virtual):```
ERROR: unable to select packages:
.makedepends-atkmm-20231202.194208:
masked in: cache
satisfies: world[.makedepends-atkmm=20231202.194208]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-atkmm-20231202.194208:
masked in: cache
satisfies: world[.makedepends-atkmm=20231202.194208]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: libxslt
required by: .makedepends-atkmm-20231202.194208[cmd:xsltproc]
>>> ERROR: atkmm: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1148user/glibmm: ERROR: unable to select packages: cmd:xsltproc (virtual):2023-12-05T15:45:56ZZach van Rijnuser/glibmm: ERROR: unable to select packages: cmd:xsltproc (virtual):```
ERROR: unable to select packages:
.makedepends-glibmm-20231202.192712:
masked in: cache
satisfies: world[.makedepends-glibmm=20231202.192712]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-glibmm-20231202.192712:
masked in: cache
satisfies: world[.makedepends-glibmm=20231202.192712]
cmd:xsltproc (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: libxslt
required by: .makedepends-glibmm-20231202.192712[cmd:xsltproc]
>>> ERROR: glibmm: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1147user/opengfx: FTBFS: ERROR: unable to select packages: cmd:unix2dos (virtual):2023-12-05T15:45:56ZZach van Rijnuser/opengfx: FTBFS: ERROR: unable to select packages: cmd:unix2dos (virtual):```
ERROR: unable to select packages:
.makedepends-opengfx-20231202.183859:
masked in: cache
satisfies: world[.makedepends-opengfx=20231202.183859]
cmd:unix2dos (virtual):
note: please select one of the 'provided by'
...```
ERROR: unable to select packages:
.makedepends-opengfx-20231202.183859:
masked in: cache
satisfies: world[.makedepends-opengfx=20231202.183859]
cmd:unix2dos (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: dos2unix
required by: .makedepends-opengfx-20231202.183859[cmd:unix2dos]
>>> ERROR: opengfx: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1146user/perl-dbd-pg: FTBFS: ERROR: unable to select packages: cmd:locale (virtual):2023-12-05T15:45:56ZZach van Rijnuser/perl-dbd-pg: FTBFS: ERROR: unable to select packages: cmd:locale (virtual):```
ERROR: unable to select packages:
.makedepends-perl-dbd-pg-20231202.182938:
masked in: cache
satisfies: world[.makedepends-perl-dbd-pg=20231202.182938]
cmd:locale (virtual):
note: please select one of the 'provided by...```
ERROR: unable to select packages:
.makedepends-perl-dbd-pg-20231202.182938:
masked in: cache
satisfies: world[.makedepends-perl-dbd-pg=20231202.182938]
cmd:locale (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: musl-locales
required by: .makedepends-perl-dbd-pg-20231202.182938[cmd:locale]
>>> ERROR: perl-dbd-pg: builddeps failed
```https://git.adelielinux.org/adelie/packages/-/issues/1145[meta] find and fix packages that cannot resolve single virtual dependency2023-12-03T14:08:41ZZach van Rijn[meta] find and fix packages that cannot resolve single virtual dependencySome packages fail to build with:
```
ERROR: unable to select packages:
.makedepends-recode-20231201.134540:
masked in: cache
satisfies: world[.makedepends-recode=20231201.134540]
cmd:lex (virtual):
note: please select o...Some packages fail to build with:
```
ERROR: unable to select packages:
.makedepends-recode-20231201.134540:
masked in: cache
satisfies: world[.makedepends-recode=20231201.134540]
cmd:lex (virtual):
note: please select one of the 'provided by'
packages explicitly
provided by: flex
required by: .makedepends-recode-20231201.134540[cmd:lex]
>>> ERROR: recode: builddeps failed
```
See also:
* apk-tools@3b013f458225c2ad8a0d96ec3eb3dde2533e0312
* https://gitlab.alpinelinux.org/alpine/apk-tools/-/issues/10810
* 64e35b236419b9b654122da04a616d76d6270f7f