Tor: Update to 0.4.8.7

Message ID 95480272-9077-4259-a302-d8b4c55c2449@ipfire.org
State Staged
Commit 41ac2cd531d7d022b9ad3da625799dc573d5258b
Headers
Series Tor: Update to 0.4.8.7 |

Commit Message

Peter Müller Oct. 8, 2023, 4:26 p.m. UTC
  Changes in version 0.4.8.7 - 2023-09-25
  This version fixes a single major bug in the Conflux subsystem on the client
  side. See below for more information. The upcoming Tor Browser 13 stable will
  pick this up.

  o Major bugfixes (conflux):
    - Fix an issue that prevented us from pre-building more conflux sets
      after existing sets had been used. Fixes bug 40862; bugfix
      on 0.4.8.1-alpha.

  o Minor features (fallbackdir):
    - Regenerate fallback directories generated on September 25, 2023.

  o Minor features (geoip data):
    - Update the geoip files to match the IPFire Location Database, as
      retrieved on 2023/09/25.

Changes in version 0.4.8.6 - 2023-09-18
  This version contains an important fix for onion service regarding congestion
  control and its reliability. Apart from that, uneeded BUG warnings have been
  suppressed especially about a compression bomb seen on relays. We strongly
  recommend, in particular onion service operators, to upgrade as soon as
  possible to this latest stable.

  o Major bugfixes (onion service):
    - Fix a reliability issue where services were expiring their
      introduction points every consensus update. This caused
      connectivity issues for clients caching the old descriptor and
      intro points. Bug reported and fixed by gitlab user
      @hyunsoo.kim676. Fixes bug 40858; bugfix on 0.4.7.5-alpha.

  o Minor features (debugging, compression):
    - Log the input and output buffer sizes when we detect a potential
      compression bomb. Diagnostic for ticket 40739.

  o Minor features (fallbackdir):
    - Regenerate fallback directories generated on September 18, 2023.

  o Minor features (geoip data):
    - Update the geoip files to match the IPFire Location Database, as
      retrieved on 2023/09/18.

  o Minor bugfix (defensive programming):
    - Disable multiple BUG warnings of a missing relay identity key when
      starting an instance of Tor compiled without relay support. Fixes
      bug 40848; bugfix on 0.4.3.1-alpha.

  o Minor bugfixes (bridge authority):
    - When reporting a pseudo-networkstatus as a bridge authority, or
      answering "ns/purpose/*" controller requests, include accurate
      published-on dates from our list of router descriptors. Fixes bug
      40855; bugfix on 0.4.8.1-alpha.

  o Minor bugfixes (compression, zstd):
    - Use less frightening language and lower the log-level of our run-
      time ABI compatibility check message in our Zstd compression
      subsystem. Fixes bug 40815; bugfix on 0.4.3.1-alpha.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 lfs/tor | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)
  

Comments

Adolf Belka Oct. 9, 2023, 7:46 a.m. UTC | #1
Reviewed-by: Adolf Belka <adolf.belka@ipfire.org>

On 08/10/2023 18:26, Peter Müller wrote:
> Changes in version 0.4.8.7 - 2023-09-25
>    This version fixes a single major bug in the Conflux subsystem on the client
>    side. See below for more information. The upcoming Tor Browser 13 stable will
>    pick this up.
>
>    o Major bugfixes (conflux):
>      - Fix an issue that prevented us from pre-building more conflux sets
>        after existing sets had been used. Fixes bug 40862; bugfix
>        on 0.4.8.1-alpha.
>
>    o Minor features (fallbackdir):
>      - Regenerate fallback directories generated on September 25, 2023.
>
>    o Minor features (geoip data):
>      - Update the geoip files to match the IPFire Location Database, as
>        retrieved on 2023/09/25.
>
> Changes in version 0.4.8.6 - 2023-09-18
>    This version contains an important fix for onion service regarding congestion
>    control and its reliability. Apart from that, uneeded BUG warnings have been
>    suppressed especially about a compression bomb seen on relays. We strongly
>    recommend, in particular onion service operators, to upgrade as soon as
>    possible to this latest stable.
>
>    o Major bugfixes (onion service):
>      - Fix a reliability issue where services were expiring their
>        introduction points every consensus update. This caused
>        connectivity issues for clients caching the old descriptor and
>        intro points. Bug reported and fixed by gitlab user
>        @hyunsoo.kim676. Fixes bug 40858; bugfix on 0.4.7.5-alpha.
>
>    o Minor features (debugging, compression):
>      - Log the input and output buffer sizes when we detect a potential
>        compression bomb. Diagnostic for ticket 40739.
>
>    o Minor features (fallbackdir):
>      - Regenerate fallback directories generated on September 18, 2023.
>
>    o Minor features (geoip data):
>      - Update the geoip files to match the IPFire Location Database, as
>        retrieved on 2023/09/18.
>
>    o Minor bugfix (defensive programming):
>      - Disable multiple BUG warnings of a missing relay identity key when
>        starting an instance of Tor compiled without relay support. Fixes
>        bug 40848; bugfix on 0.4.3.1-alpha.
>
>    o Minor bugfixes (bridge authority):
>      - When reporting a pseudo-networkstatus as a bridge authority, or
>        answering "ns/purpose/*" controller requests, include accurate
>        published-on dates from our list of router descriptors. Fixes bug
>        40855; bugfix on 0.4.8.1-alpha.
>
>    o Minor bugfixes (compression, zstd):
>      - Use less frightening language and lower the log-level of our run-
>        time ABI compatibility check message in our Zstd compression
>        subsystem. Fixes bug 40815; bugfix on 0.4.3.1-alpha.
>
> Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
> ---
>   lfs/tor | 6 +++---
>   1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/lfs/tor b/lfs/tor
> index d7be53a1c..7a9ca4128 100644
> --- a/lfs/tor
> +++ b/lfs/tor
> @@ -26,7 +26,7 @@ include Config
>   
>   SUMMARY    = Anonymizing overlay network for TCP (The onion router)
>   
> -VER        = 0.4.8.5
> +VER        = 0.4.8.7
>   
>   THISAPP    = tor-$(VER)
>   DL_FILE    = $(THISAPP).tar.gz
> @@ -34,7 +34,7 @@ DL_FROM    = $(URL_IPFIRE)
>   DIR_APP    = $(DIR_SRC)/$(THISAPP)
>   TARGET     = $(DIR_INFO)/$(THISAPP)
>   PROG       = tor
> -PAK_VER    = 80
> +PAK_VER    = 81
>   
>   DEPS       = libseccomp
>   
> @@ -48,7 +48,7 @@ objects = $(DL_FILE)
>   
>   $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
>   
> -$(DL_FILE)_BLAKE2 = 71a4807284ecefc4a18d6bc15ce798844304f860338b786590779fb171f851d630e8af3114dbc84fe854561e0085dcb147b4dd87787988a8fb6c3628bfcc8175
> +$(DL_FILE)_BLAKE2 = 4d0cde752a729c64e380663e4438398fe768a8657e9aa3246bdf0ec9a4b4e01e277cb594ae0cb44cc66ea8c6080f2e58c6daf1bf01dc51b678d228e8e38fc971
>   
>   install : $(TARGET)
>
  

Patch

diff --git a/lfs/tor b/lfs/tor
index d7be53a1c..7a9ca4128 100644
--- a/lfs/tor
+++ b/lfs/tor
@@ -26,7 +26,7 @@  include Config
 
 SUMMARY    = Anonymizing overlay network for TCP (The onion router)
 
-VER        = 0.4.8.5
+VER        = 0.4.8.7
 
 THISAPP    = tor-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -34,7 +34,7 @@  DL_FROM    = $(URL_IPFIRE)
 DIR_APP    = $(DIR_SRC)/$(THISAPP)
 TARGET     = $(DIR_INFO)/$(THISAPP)
 PROG       = tor
-PAK_VER    = 80
+PAK_VER    = 81
 
 DEPS       = libseccomp
 
@@ -48,7 +48,7 @@  objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 71a4807284ecefc4a18d6bc15ce798844304f860338b786590779fb171f851d630e8af3114dbc84fe854561e0085dcb147b4dd87787988a8fb6c3628bfcc8175
+$(DL_FILE)_BLAKE2 = 4d0cde752a729c64e380663e4438398fe768a8657e9aa3246bdf0ec9a4b4e01e277cb594ae0cb44cc66ea8c6080f2e58c6daf1bf01dc51b678d228e8e38fc971
 
 install : $(TARGET)