ubuntu/+source/tor:ubuntu/artful

Last commit made on 2017-08-13
Get this branch:
git clone -b ubuntu/artful https://git.launchpad.net/ubuntu/+source/tor
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/artful
Repository:
lp:ubuntu/+source/tor

Recent commits

2c882b3... by Peter Palfrader on 2017-08-13

Import patches-unapplied version 0.3.0.10-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 6c674f42bbdbd327154dff36bc403e6ccf2faf8e

New changelog entries:
  * New upstream version.
  * Update apparmor profile: replace CAP_DAC_OVERRIDE with
    CAP_DAC_READ_SEARCH to match the systemd capability bounding set
    changed with 0.3.0.4-rc-1. This change will allow tor to start
    again under apparmor if hidden services are configured.
    Patch by intrigeri. (closes: #862993)
  * Remove tor-dbg binary package. Nowadays Debian's toolchain
    automatically builds packages containing debugging symbols. The new
    tor-dbgsym package will end up in the debian-debug archive.
    This tor-dbgsym package will Replace/Break tor-dbg versions
    prior to 0.3.1.5-alpha for now (to match the version in experimental
    with the same change), but as we keep providing backported builds for
    older suites, and since those keep the tor-dbg package for now,
    we'll likely keep increasing this version in future releases.
    (closes: #867547)
  * The dbgsym migration options require debhelper >= 9.20160114; update
    build dependency list accordingly.

6c674f4... by Peter Palfrader on 2017-07-01

Import patches-unapplied version 0.3.0.9-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 9f16dd2e005e803601df6b3268e9fcbfed3c5f84

New changelog entries:
  * New upstream version, upload 0.3.0.x tree to unstable.
    - Fixes TROVE-2017-006: Regression in guard family avoidance
      (closes: #866799; CVE-2017-0377).
  * Remove debian/README.{polipo,privoxy} as using them is not recommended.
    (Torbrowser is the better option for users browsing the web.)

9f16dd2... by Peter Palfrader on 2017-06-08

Import patches-unapplied version 0.3.0.8-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 888b6e6f9786df6e2d5592ab7175b88f1552d647

New changelog entries:
  * New upstream version.
    - Fix a remotely triggerable assertion failure when a hidden service
      handles a malformed BEGIN cell. Fixes bug 22493, tracked as
      TROVE-2017-004 and as CVE-2017-0375; bugfix on 0.3.0.1-alpha.
    - Fix a remotely triggerable assertion failure caused by receiving a
      BEGIN_DIR cell on a hidden service rendezvous circuit. Fixes bug
      22494, tracked as TROVE-2017-005 and CVE-2017-0376; bugfix
      on 0.2.2.1-alpha. (closes: #864424)

888b6e6... by Peter Palfrader on 2017-05-18

Import patches-unapplied version 0.3.0.7-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 56a8dfee7f76e1ce5d54476c739474ad9c40c75a

New changelog entries:
  * New upstream version.

56a8dfe... by Peter Palfrader on 2017-04-08

Import patches-unapplied version 0.3.0.5-rc-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 04501fe3b9c46968e2338d5c23de6499407c0e32

New changelog entries:
  * New upstream version.
    - Run the entry_guard_parse_from_state_full() test with the time set
      to a specific date. (closes: #858534).

04501fe... by Peter Palfrader on 2017-03-04

Import patches-unapplied version 0.3.0.4-rc-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: a56b53531c052054c9ea8135a28887695917e8c0

New changelog entries:
  * New upstream version.
  * Replace CAP_DAC_OVERRIDE with CAP_DAC_READ_SEARCH in systemd's service
    capability bounding set. Read access is sufficient for Tor (as root on
    startup) to check its onion service directories (see #847598).
  * Change default log target to syslog. We still keep /var/log/tor and
    the logrotation configuration around in case the admin prefers normal
    log files. Also update README.Debian accordingly. (closes: #852716).

a56b535... by Peter Palfrader on 2017-02-04

Import patches-unapplied version 0.3.0.3-alpha-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 7c0b030441473f1f3d107ef83534eb36bc08e459

New changelog entries:
  * New upstream version.

7c0b030... by Peter Palfrader on 2017-01-23

Import patches-unapplied version 0.3.0.2-alpha-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: c2abe9a3a17d69c0e43004ad8cc5412f2d9e22f7

New changelog entries:
  * New upstream version.

c2abe9a... by Peter Palfrader on 2016-12-25

Import patches-unapplied version 0.3.0.1-alpha-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 4f47074d5456340f609f39fb8202b6c35fad02a7

New changelog entries:
  * New upstream tree.

4f47074... by Peter Palfrader on 2016-12-19

Import patches-unapplied version 0.2.9.8-2 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 06d94e93ea83eea4ba6b599b72892655ee0b2d81

New changelog entries:
  * Actually target unstable.
  * New upstream version, upload 0.2.9.x tree to unstable.
  * Add a comment to tor@.service explaining why we cannot limit to
    /var/lib/tor-instances/<instance> but only to /var/lib/tor-instances --
    systemd does not do instance expansion in ReadWriteDirectories lines --
    cf. #781730.
  * Update README.Debian to mention a good location to put onion service
    UNIX sockets. Note that neither systemd nor apparmor limits access
    to them -- cf. #846275.
  * Use -Z (Apply SE-Linux labels) to install when creating instance datadirs
    in tor-instance-create.