Bug 499438

Summary: tor 0.2.0.34 update
Product: [Fedora] Fedora Reporter: Chris Schanzle <bugzilla>
Component: torAssignee: Enrico Scholz <rh-bugzilla>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: low    
Version: 10CC: bill-bugzilla.redhat.com, rh-bugzilla
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 0.2.0.35-1.fc11 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-06-30 21:25:24 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Chris Schanzle 2009-05-06 16:54:53 UTC
It would be appreciated if the package maintainer would monitor for updates more closely; this security update was announced some three months ago - 2009-02-08

http://archives.seul.org/or/announce/Feb-2009/msg00000.html

Thanks!

Comment 1 Bill McGonigle 2009-06-23 00:56:05 UTC
Enrico was on it within two days:

  http://koji.fedoraproject.org/koji/buildinfo?buildID=82186

but the builds aren't getting pushed to updates-testing.  Could somebody please kick the proper lever?

Comment 2 Enrico Scholz 2009-06-23 07:07:19 UTC
accordingly documentation, updates should be pushed when karma at 

https://admin.fedoraproject.org/updates/F10/FEDORA-2009-1522

reaches a critical level.  But I do not have a clue how it can be modified, and the CLI bodhi client does not work.

Comment 3 Chris Schanzle 2009-06-24 02:52:12 UTC
Does this help?  I'm not a fedora project package contributor (yet), but I found:
http://fedoraproject.org/wiki/Infrastructure/UpdatesSystem/Bodhi-info-DRAFT#Submitting_a_new_update

...maybe specifically:
  "From here your update is in a 'Pending' state. When you are satisfied with the details of your update, you then must chose to "Push to Testing" or "Push to Stable"."

Looks like progress is also being made on F11 update:  http://koji.fedoraproject.org/koji/packageinfo?packageID=4002

Thanks!

Comment 4 Bill McGonigle 2009-06-24 06:24:41 UTC
Thanks, Chris.  Kevin Kofler mentioned to me that all the bodhi functions should be available via the web interface, as implied in the link Chris posted.

Comment 5 Bill McGonigle 2009-06-24 21:48:12 UTC
It looks like there was a bodhi malfunction here.  Luke Macken is going to push this back to testing and investigate why it regressed.  We ought to get a message here when it hits, then as testers we can provide the karma it needs to get out to updates.

Comment 6 Chris Schanzle 2009-06-26 01:21:40 UTC
Tor 0.2.0.35 is released.  Changes in version 0.2.0.35 - 2009-06-24
  o Security fix:
    - Avoid crashing in the presence of certain malformed descriptors.
      Found by lark, and by automated fuzzing.
    - Fix an edge case where a malicious exit relay could convince a
      controller that the client's DNS question resolves to an internal IP
      address. Bug found and fixed by "optimist"; bugfix on 0.1.2.8-beta.

[*duck and cover*]  :-)

Comment 7 Fedora Update System 2009-06-26 19:25:04 UTC
tor-0.2.0.35-1.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/tor-0.2.0.35-1.fc11

Comment 8 Fedora Update System 2009-06-26 19:29:59 UTC
tor-0.2.0.35-1.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/tor-0.2.0.35-1.fc10

Comment 9 Fedora Update System 2009-06-26 19:31:13 UTC
tor-0.2.0.35-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/tor-0.2.0.35-1.fc9

Comment 10 Chris Schanzle 2009-06-26 21:02:48 UTC
Dang, that was fast!  Nice!  Thanks!

Comment 11 Fedora Update System 2009-06-30 21:20:51 UTC
tor-0.2.0.35-1.fc11 has been pushed to the Fedora 11 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update tor'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F11/FEDORA-2009-7061

Comment 12 Fedora Update System 2009-06-30 21:25:14 UTC
tor-0.2.0.35-1.fc10 has been pushed to the Fedora 10 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 13 Fedora Update System 2009-06-30 21:40:23 UTC
tor-0.2.0.35-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 14 Bill McGonigle 2009-07-01 15:07:05 UTC
Cool, it looks like bodhi is working again.  Thanks Enrico!

Comment 15 Fedora Update System 2009-07-03 19:46:39 UTC
tor-0.2.0.35-1.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.