Bug 1217762 - squid-3.5.9 is available
Summary: squid-3.5.9 is available
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: squid
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Luboš Uhliarik
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1230501 1231992 1264450 1264455
TreeView+ depends on / blocked
 
Reported: 2015-05-01 14:26 UTC by Upstream Release Monitoring
Modified: 2015-11-01 02:46 UTC (History)
7 users (show)

Fixed In Version: squid-3.5.9-7.fc23
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-11-01 02:46:12 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
[patch] Update to 3.5.5 (#1217762) (943 bytes, text/x-diff)
2015-05-29 02:04 UTC, Upstream Release Monitoring
no flags Details
Patch which fixes problem with include guards (491 bytes, patch)
2015-09-24 11:39 UTC, Luboš Uhliarik
no flags Details | Diff
Upstream patch (3.51 KB, patch)
2015-09-24 13:12 UTC, Luboš Uhliarik
no flags Details | Diff

Description Upstream Release Monitoring 2015-05-01 14:26:48 UTC
Latest upstream release: 3.5.4
Current version/release in rawhide: 3.5.3-3.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 1 Upstream Release Monitoring 2015-05-01 14:27:31 UTC
Failed to kick off scratch build.

cmd:  spectool -g /var/tmp/thn-euJ58C/squid.spec
return code:  22
stdout:
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.4.tar.xz to ./squid-3.5.4.tar.xz
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.4.tar.xz.asc to ./squid-3.5.4.tar.xz.asc

stderr:
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found

Comment 2 Upstream Release Monitoring 2015-05-29 02:03:58 UTC
Latest upstream release: 3.5.5
Current version/release in rawhide: 3.5.3-4.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 3 Upstream Release Monitoring 2015-05-29 02:04:51 UTC
Created attachment 1031530 [details]
[patch] Update to 3.5.5 (#1217762)

Comment 4 Upstream Release Monitoring 2015-05-29 02:58:01 UTC
Scratch build succeeded http://koji.fedoraproject.org/koji/taskinfo?taskID=9873482

Comment 5 Marcos Mello 2015-05-31 11:06:19 UTC
3.5.4 fixed eDirectory build:

http://bazaar.launchpad.net/~squid/squid/3.5/revision/13794

It can be reenabled in Rawhide.

Comment 6 Upstream Release Monitoring 2015-07-03 13:43:53 UTC
Latest upstream release: 3.5.6
Current version/release in rawhide: 3.5.3-5.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 7 Upstream Release Monitoring 2015-07-03 13:44:42 UTC
Failed to kick off scratch build.

cmd:  spectool -g /var/tmp/thn-KnDi5W/squid.spec
return code:  22
stdout:
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.6.tar.xz to ./squid-3.5.6.tar.xz
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.6.tar.xz.asc to ./squid-3.5.6.tar.xz.asc

stderr:
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:01 --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
100   829  100   829    0     0   2734      0 --:--:-- --:--:-- --:--:--  2726

Comment 8 Upstream Release Monitoring 2015-08-01 12:16:00 UTC
Latest upstream release: 3.5.7
Current version/release in rawhide: 3.5.3-5.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 9 Upstream Release Monitoring 2015-08-01 12:16:46 UTC
Failed to kick off scratch build.

cmd:  spectool -g /var/tmp/thn-oqzlle/squid.spec
return code:  22
stdout:
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.7.tar.xz to ./squid-3.5.7.tar.xz
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.7.tar.xz.asc to ./squid-3.5.7.tar.xz.asc

stderr:
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:01 --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:02 --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
100   829  100   829    0     0   3137      0 --:--:-- --:--:-- --:--:--  3140

Comment 10 Account closed by the user 2015-08-01 16:41:24 UTC
(In reply to Upstream Release Monitoring from comment #8)

> Latest upstream release: 3.5.7
> Current version/release in rawhide: 3.5.3-5.fc23

Please, update it. Latest release fixes a lot of bug.

Changes to squid-3.5.7 (01 Aug 2015):

 - Bug 4293: wrong SNI sent to server after URL-rewrite
 - Bug 4251: incorrect instance name for memory segments in /dev/shm
 - Bug 4227: invalid key in AuthUserHashPointer causing assertation failure
 - Bug 3345: support %un (any available user name) format code for external ACLs.
 - basic_smb_auth: Fix several old issues identified by Debian users
 - Support ssl-bump splicing to origin cache_peer
 - Fix SSL errors relayed using invalid certificates
 - Fix crash in TcpAccepter with profiler enabled
 - Fix some cases of ssl_crtd SSL certificate DB corruption
 - Fix performance regression in SBuf::chop operations
 - Improve handling of client connections on shutdown
 - Handle exceptions during squid.conf parse
 - Make pod2man an optional dependency
 - ... and polishing for several cache.log notification messages
 - ... and all fixes from squid 3.4.14

Changes to squid-3.5.6 (03 Jul 2015):

 - Bug 4274: ssl_crtd.8 not being installed
 - Bug 4193: memory leak on FTP listings
 - Bug 4183: segfault when freeing https_port clientca on reconfigure or exit
 - Bug 3875: bad mimeLoadIconFile error handling
 - Bug 3483: assertion failed store.cc:1866: 'isEmpty()'
 - Bug 3329: pinned server connection is not closed properly
 - TLS: Disable client-initiated renegotiation
 - ext_edirectory_userip_acl: fix uninitialized variable
 - Support custom OIDs in *_cert ACLs
 - Fix CONNECT failover to IPv4 after trying broken IPv6 servers
 - Use relative-URL in errorpage.css for SN.png
 - Do not blindly forward cache peer CONNECT responses
 - Fix assertion String.cc:221: "str"
 - Fix assertion comm.cc:759: "Comm::IsConnOpen(conn)" in ConnStateData::getSslContextDone
 - Translations: add Spanish US dialect alias

Changes to squid-3.5.5 (28 May 2015):

 - Regression Bug 4132: short_icon_urls with global_internal_static on
 - Bug 4238: assertion Read.cc:205: "params.data == data"
 - Bug 4236: SSL negotiation error of 'success'
 - Bug 3930: assertion 'connIsUsable(http->getConn())'
 - Fix assertion MemBuf.cc:380: "new_cap > (size_t) capacity" in SSL I/O buffer
 - Fix assertion errorpage.cc:600: "entry->isEmpty()"
 - Fix comm_connect_addr on failures returns Comm:OK
 - Fix missing external ACL helper notes
 - Fix "Not enough space to hold server hello message" error message
 - Fix segmentation fault inside Adaptation::Icap::Xaction::swanSong
 - Prevent unused ssl_crtd helpers being run
 - ... and some code cleanup and portability updates
 - ... and several documentation updates

Changes to squid-3.5.4 (01 May 2015):

 - Bug 4234: comm_connect_addr uses errno incorrectly
 - Bug 4231: fd_open() not correctly handling UDS socket descriptions
 - Bug 4226: digest_edirectory_auth: found but cannot be built
 - Bug 4198: assertion failed: client_side.h:364: "sslServerBump == srvBump"
 - Bug 3775: Disable HTTP/1.1 pipeline feature for pinned connections
 - Fix require-proxy-header preventing HTTPS proxying and ssl-bump
 - Fix Negotiate/Kerberos authentication request size exceeds output buffer size
 - Fix SQUID_X509_V_ERR_DOMAIN_MISMATCH errors while accessing sites with valid certificates
 - Add server_name ACL matching server name(s) obtained from various sources
 - Add Kerberos support for MAC OS X 10.x
 - Support for resuming TLS sessions
 - ... and some portability and compile fixes
 - ... and several documentation updates
 - ... and all fixes from squid 3.4.13

Comment 11 Account closed by the user 2015-08-14 12:22:58 UTC
(In reply to Xose Vazquez Perez from comment #10)

> (In reply to Upstream Release Monitoring from comment #8)
> 
> > Latest upstream release: 3.5.7
> > Current version/release in rawhide: 3.5.3-5.fc23
> 
> Please, update it. Latest release fixes a lot of bug.

Also, 3.5.3 is affected by two security bugs: CVE-2015-5400 and CVE-2015-3455 :
http://www.squid-cache.org/Advisories/

Comment 12 Luboš Uhliarik 2015-08-17 14:54:03 UTC
I'm not able to build this version because of double inclusion error. Trying to solve this problem with upstream.

Comment 14 Andrew Peek 2015-08-24 12:21:56 UTC
Would it be possible to build 3.5.4 (or another version earlier than 3.5.7) to fix bug,

- Bug 4198: assertion failed: client_side.h:364: "sslServerBump == srvBump"

which I'm encountering alot with my installation ?

Comment 15 Luboš Uhliarik 2015-08-24 13:11:08 UTC
It is not possible now to build it due to kernel-headers update in Rawhide. Build is now failing with double inclusion error.

I'm working with upstream on a solution.

Comment 16 Upstream Release Monitoring 2015-09-02 00:16:07 UTC
Latest upstream release: 3.5.8
Current version/release in rawhide: 3.5.3-5.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 17 Upstream Release Monitoring 2015-09-02 00:16:54 UTC
Failed to kick off scratch build.

cmd:  spectool -g /var/tmp/thn-QXdLwK/squid.spec
return code:  22
stdout:
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.8.tar.xz to ./squid-3.5.8.tar.xz
Getting http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.8.tar.xz.asc to ./squid-3.5.8.tar.xz.asc

stderr:
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:01 --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:02 --:--:--     0
  0     0    0     0    0     0      0      0 --:--:--  0:00:02 --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed

  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
  0     0    0     0    0     0      0      0 --:--:-- --:--:-- --:--:--     0
curl: (22) The requested URL returned error: 404 Not Found

Comment 18 Luboš Uhliarik 2015-09-11 07:59:30 UTC
The same problem with building on Gentoo:

http://bugs.squid-cache.org/show_bug.cgi?id=4323

Comment 19 Upstream Release Monitoring 2015-09-18 00:17:31 UTC
Latest upstream release: 3.5.9
Current version/release in rawhide: 3.5.3-5.fc23
URL: ftp://ftp.squid-cache.org/pub/squid/

Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/Updates_Policy

More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstream_release_monitoring

Please keep in mind that with any upstream change, there may also be packaging changes that need to be made. Specifically, please remember that it is your responsibility to review the new version to ensure that the licensing is still correct and that no non-free or legally problematic items have been added upstream.

Comment 20 Upstream Release Monitoring 2015-09-18 00:18:19 UTC
Failed to kick off scratch build.

cmd:  sha256sum /var/tmp/thn-0e_nSS/100.0%
return code:  1
stdout:

stderr:
sha256sum: /var/tmp/thn-0e_nSS/100.0%: No such file or directory

Comment 21 Luboš Uhliarik 2015-09-24 11:39:03 UTC
Created attachment 1076480 [details]
Patch which fixes problem with include guards

Comment 22 Luboš Uhliarik 2015-09-24 13:12:55 UTC
Created attachment 1076545 [details]
Upstream patch

Comment 23 Upstream Release Monitoring 2015-09-24 14:43:26 UTC
luhliarik's squid-3.5.9-1.fc24 completed http://koji.fedoraproject.org/koji/buildinfo?buildID=687729

Comment 24 Fedora Update System 2015-09-25 11:04:43 UTC
squid-3.5.9-6.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-1781d1322a

Comment 25 Fedora Update System 2015-09-27 00:55:40 UTC
squid-3.5.9-6.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
$ su -c 'dnf --enablerepo=updates-testing update squid'
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-1781d1322a

Comment 26 Fedora Update System 2015-10-06 14:01:07 UTC
squid-3.5.9-7.fc23 has been submitted as an update to Fedora 23. https://bodhi.fedoraproject.org/updates/FEDORA-2015-8d643c4d18

Comment 27 Fedora Update System 2015-10-07 16:28:00 UTC
squid-3.5.9-7.fc23 has been pushed to the Fedora 23 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
$ su -c 'dnf --enablerepo=updates-testing update squid'
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2015-8d643c4d18

Comment 28 Account closed by the user 2015-10-24 17:33:59 UTC
3.5.10 was released time ago(01 Oct 2015):

Changes to squid-3.5.10:

	- Regression Fix cache_peer login=PASS(THRU) after CVE-2015-5400
	- Regression Bug 4326: base64 binary encoder rejects data
           beginning with nil byte
	- Bug 4323: Netfilter broken cross-includes with Linux 4.2
	- Bug 4328: %un format code does not work for external ACLs in
           credentials-fetching rules
	- Bug 4208: more than one port in wccp2_service_info line causes error
	- Bug 4304: PeerConnector.cc:743 "!callback" assertion.
	- Bug 4330: Do not use SSL_METHOD::put_cipher_by_char to determine
           size of SSL hello ciphers
	- Relicense ntlm_fake_auth.pl to GPLv2+
	- Relicense smb_lm auth helper to GPLv2+
	- Relicense SSPI helper to GPLv2+
	- ... and several minor performance optimizations

Comment 29 Luboš Uhliarik 2015-10-26 10:23:47 UTC
(In reply to Xose Vazquez Perez from comment #28)
> 3.5.10 was released time ago(01 Oct 2015):
> 
> Changes to squid-3.5.10:
> 
> 	- Regression Fix cache_peer login=PASS(THRU) after CVE-2015-5400
> 	- Regression Bug 4326: base64 binary encoder rejects data
>            beginning with nil byte
> 	- Bug 4323: Netfilter broken cross-includes with Linux 4.2
> 	- Bug 4328: %un format code does not work for external ACLs in
>            credentials-fetching rules
> 	- Bug 4208: more than one port in wccp2_service_info line causes error
> 	- Bug 4304: PeerConnector.cc:743 "!callback" assertion.
> 	- Bug 4330: Do not use SSL_METHOD::put_cipher_by_char to determine
>            size of SSL hello ciphers
> 	- Relicense ntlm_fake_auth.pl to GPLv2+
> 	- Relicense smb_lm auth helper to GPLv2+
> 	- Relicense SSPI helper to GPLv2+
> 	- ... and several minor performance optimizations

I will wait for 3.5.11 because of this bug:

http://master.squid-cache.org/Versions/v4/changesets/squid-4-14363.patch

Comment 30 Fedora Update System 2015-11-01 02:45:51 UTC
squid-3.5.9-7.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.