From unknown Sat Jun 21 10:15:54 2025 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 X-Mailer: MIME-tools 5.509 (Entity 5.509) Content-Type: text/plain; charset=utf-8 From: bug#76129 <76129@debbugs.gnu.org> To: bug#76129 <76129@debbugs.gnu.org> Subject: Status: [PATCH] gnu: mullvadbrowser: Update to 14.0.5 [security fixes]. Reply-To: bug#76129 <76129@debbugs.gnu.org> Date: Sat, 21 Jun 2025 17:15:54 +0000 retitle 76129 [PATCH] gnu: mullvadbrowser: Update to 14.0.5 [security fixes= ]. reassign 76129 guix-patches submitter 76129 Andr=C3=A9 Batista severity 76129 normal tag 76129 patch thanks From debbugs-submit-bounces@debbugs.gnu.org Fri Feb 07 15:27:55 2025 Received: (at submit) by debbugs.gnu.org; 7 Feb 2025 20:27:55 +0000 Received: from localhost ([127.0.0.1]:36818 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tgUx8-0003Rx-Q9 for submit@debbugs.gnu.org; Fri, 07 Feb 2025 15:27:55 -0500 Received: from lists.gnu.org ([2001:470:142::17]:42186) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1tgUx5-0003Rh-Pk for submit@debbugs.gnu.org; Fri, 07 Feb 2025 15:27:52 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tgUx0-0005CV-Bt for guix-patches@gnu.org; Fri, 07 Feb 2025 15:27:46 -0500 Received: from mx1.riseup.net ([198.252.153.129]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tgUww-0003im-LA for guix-patches@gnu.org; Fri, 07 Feb 2025 15:27:46 -0500 Received: from fews02-sea.riseup.net (fews02-sea-pn.riseup.net [10.0.1.112]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx1.riseup.net (Postfix) with ESMTPS id 4YqQWX0djqzDrRK for ; Fri, 7 Feb 2025 20:27:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=riseup.net; s=squak; t=1738960061; bh=pKPwW3wEzkrsBi++2XI+8Ui37KSXYlgv2T0HFX1ltL4=; h=From:To:Cc:Subject:Date:From; b=QtAWp+VjZIn1Kjtnk2G43R6rk+ALj2PUzmi6Ds22XP2u+dmox355d0j7t0vJzWR9F 8hFsVeqsbfHYeT5a01VKCEl9kTtzlyUceurcfQg+w9qOK8DHzrL7md/rGqEG/iee5B ovqbQXlkkl+/oh7arywDNbor7WeBFZCEjAyXbnC8= X-Riseup-User-ID: BB691C46D3F3C40D062F0032EB98D1B75A376B753F1BBD24346F7553289A9DB3 Received: from [127.0.0.1] (localhost [127.0.0.1]) by fews02-sea.riseup.net (Postfix) with ESMTPSA id 4YqQWV72wLzFtKC; Fri, 7 Feb 2025 20:27:34 +0000 (UTC) From: =?UTF-8?q?Andr=C3=A9=20Batista?= To: guix-patches@gnu.org Subject: [PATCH] gnu: mullvadbrowser: Update to 14.0.5 [security fixes]. Date: Fri, 7 Feb 2025 17:27:25 -0300 Message-ID: <20250207202725.20898-1-nandre@riseup.net> MIME-Version: 1.0 X-Debbugs-Cc: nandre@riseup.net, clement@lassieur.org, ian@retrospec.tv, jonathan.brielmaier@web.de, mhw@netris.org Content-Transfer-Encoding: 8bit Received-SPF: pass client-ip=198.252.153.129; envelope-from=nandre@riseup.net; helo=mx1.riseup.net X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Spam-Score: 0.0 (/) X-Debbugs-Envelope-To: submit Cc: =?UTF-8?q?Andr=C3=A9=20Batista?= X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.0 (-) Fixes CVEs 2024-11704, 2025-1009, 2025-1010, 2025-1011, 2025-1012, 2025-1013, 2025-1014, 2025-1016 and 2025-1017. See for details. * gnu/packages/tor-browsers.scm (%mullvadbrowser-build-date): Update to 20250203100000. (%mullvadbrowser-version): Update to 14.0.5. (%mullvadbrowser-firefox-version): Update to 128.7.0esr-14.0-1-build2. (mullvadbrowser-translation-base): Update to 93eddbd3888852c09e130d536fb3c9bd7e4e6f57. Change-Id: I3932142356fd3e44d9a3220953df8ae236b90537 --- gnu/packages/tor-browsers.scm | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/gnu/packages/tor-browsers.scm b/gnu/packages/tor-browsers.scm index 361acc7738..2718622f79 100644 --- a/gnu/packages/tor-browsers.scm +++ b/gnu/packages/tor-browsers.scm @@ -818,17 +818,17 @@ (define %mullvadbrowser-locales (list "ar" "da" "de" "es-ES" "fa" "fi" "fr" "it" ;; We copy the official build id, which can be found there: ;; https://cdn.mullvad.net/browser/update_responses/update_1/release. -(define %mullvadbrowser-build-date "20250106125732") +(define %mullvadbrowser-build-date "20250203100000") ;; To find the last version, look at ;; https://mullvad.net/en/download/browser/linux. -(define %mullvadbrowser-version "14.0.4") +(define %mullvadbrowser-version "14.0.5") ;; To find the last Firefox version, browse ;; https://archive.torproject.org/tor-package-archive/mullvadbrowser/<%mullvadbrowser-version> ;; There should be only one archive that starts with ;; "src-firefox-mullvad-browser-". -(define %mullvadbrowser-firefox-version "128.6.0esr-14.0-1-build1") +(define %mullvadbrowser-firefox-version "128.7.0esr-14.0-1-build2") ;; See tor-browser-build/projects/translation/config. (define mullvadbrowser-translation-base @@ -836,11 +836,11 @@ (define mullvadbrowser-translation-base (method git-fetch) (uri (git-reference (url "https://gitlab.torproject.org/tpo/translation.git") - (commit "bb1df34ec79d55dcd1e0ebc80cb2c72d27c462b7"))) + (commit "93eddbd3888852c09e130d536fb3c9bd7e4e6f57"))) (file-name "translation-base-browser") (sha256 (base32 - "0mhfbmghvdd1rpvpr8ppkdpzwwb9v03a211qgi27j3iwaa04zh9m")))) + "1s0lys5kzdgd1vk8la4vd5kkfpb5kvaf2rhd0vgzq4fva7gflm94")))) ;; See tor-browser-build/projects/translation/config. (define mullvadbrowser-translation-specific @@ -868,7 +868,7 @@ (define mullvadbrowser-assets version "/mullvad-browser-linux-x86_64-" version ".tar.xz")) (sha256 (base32 - "0cycrxil9zbdqrkzzsfx7nlrhs4k5riwi0y7r0ah2snmpcla4nb3")))) + "0l544hl9kbashcx9qrih1qf1zz2cdny733ry1r1v13g85760ipyb")))) (arguments (list #:install-plan @@ -911,7 +911,7 @@ (define-public mullvadbrowser %mullvadbrowser-firefox-version ".tar.xz")) (sha256 (base32 - "0x5q0g62ndy9r7qqrz0p35bq258sn26bdwhzs396v8mrzyf4jywh")))) + "04val15xsfl118d18xpnhhy5cshlgkdpp58y0ja306glx453kcpl")))) (arguments (substitute-keyword-arguments (package-arguments mullvadbrowser-base) ((#:phases phases) base-commit: 70231fe7757f839f6ddd58d3c8a522b2e56fefe5 -- 2.46.0 From debbugs-submit-bounces@debbugs.gnu.org Tue Feb 11 11:50:04 2025 Received: (at control) by debbugs.gnu.org; 11 Feb 2025 16:50:04 +0000 Received: from localhost ([127.0.0.1]:58293 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1thtSV-0001os-St for submit@debbugs.gnu.org; Tue, 11 Feb 2025 11:50:04 -0500 Received: from fhigh-b8-smtp.messagingengine.com ([202.12.124.159]:43003) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1thtSS-0001nz-0f for control@debbugs.gnu.org; Tue, 11 Feb 2025 11:50:01 -0500 Received: from phl-compute-04.internal (phl-compute-04.phl.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id 9E1212540112 for ; Tue, 11 Feb 2025 11:49:51 -0500 (EST) Received: from phl-mailfrontend-02 ([10.202.2.163]) by phl-compute-04.internal (MEProxy); Tue, 11 Feb 2025 11:49:51 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h= cc:content-type:date:date:from:from:in-reply-to:message-id :reply-to:subject:subject:to:to; s=fm2; t=1739292591; x= 1739378991; bh=xmzvPKTK4SLSV0DyMcaF0SZY8MFlXdY4iFaI5U2LzNw=; b=y 1BrUrUEAsD34+PlEcT6wWXC62TqatrVPRwnM64pfHjlTiIOIxbP0nyd33MiKo5er QUP42zzcFf6xyxTJGjTz3GdMbsRYqWtlaCnmJgIM57zRPOuT7R/+KiEEKb7ZEggF FeBv9xHlMyyWJwy0Sa6yH/ExvO9Ke0yYgpmudX4g0/cVuB5O0p/YRDTzXs0W29ii BAHBzxsvG6upgFxN7Eipefga0tL+ZqVIfZ2AtqeBPeznz92XCF0RcRuY48oJQxIs H1+XJCfDC7BIczDD04EphLqGgppPEe7Hi5UpXf4yHEnn3Wj9flyzaCfxG/Ub02O1 J7QFAbRqfB7bJ+XArZ/1Q== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:date:date:feedback-id :feedback-id:from:from:in-reply-to:message-id:reply-to:subject :subject:to:to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm3; t=1739292591; x=1739378991; bh=xmzvPKTK4SLSV0DyMcaF0SZY8MFl XdY4iFaI5U2LzNw=; b=p9x7z5Wf4wxOWoIckqbUhRUtR4rijklyJq334nbznXlw uAi45Lkmm7fuW7QQMiz+r6EZXuPDadRegQWp4BD4A67bLY4IjJ786PDs82rxP+Md gRbXudpv/blBtWmRxucPPImtmpVP6/eg6M/hXuQu2EqOU9TTQJCMA/vsFAyJR8im gGA4tlgfrYT5dlH4lm2KEgnmvAIgloP1NKOvoWaCzxCcUWWpVv12W5KGA+DXUqZO 7RwHsZNcZadLnDMLI2g0spDp9kFjy72n0viTJtLsT4qKRjXLcGqCFvd0g/32Nd/1 aRLTSHofcst0yXKqwTmuNtggD3R2QFABmBCKbOHgMg== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgdegudehvdcutefuodetggdotefrod ftvfcurfhrohhfihhlvgemucfhrghsthforghilhdpggftfghnshhusghstghrihgsvgdp uffrtefokffrpgfnqfghnecuuegrihhlohhuthemuceftddtnecunecujfgurhepfffkvf fhufestddtredttddttdenucfhrhhomhepkfgrnhcugfhurhgvuceoihgrnhesrhgvthhr ohhsphgvtgdrthhvqeenucggtffrrghtthgvrhhnpeetkeejhfefhfetieegkeehheevvd efgffggeevffdtvddufeehiefgteeiueehkeenucevlhhushhtvghrufhiiigvpedtnecu rfgrrhgrmhepmhgrihhlfhhrohhmpehirghnsehrvghtrhhoshhpvggtrdhtvhdpnhgspg hrtghpthhtohepuddpmhhouggvpehsmhhtphhouhhtpdhrtghpthhtoheptghonhhtrhho lhesuggvsggsuhhgshdrghhnuhdrohhrgh X-ME-Proxy: Feedback-ID: id9014242:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA for ; Tue, 11 Feb 2025 11:49:50 -0500 (EST) Date: Tue, 11 Feb 2025 08:49:48 -0800 Message-Id: <87r044toib.fsf@retrospec.tv> To: control@debbugs.gnu.org From: Ian Eure Subject: control message for bug #76129 X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: control X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) close 76129 quit From debbugs-submit-bounces@debbugs.gnu.org Thu Feb 20 15:39:27 2025 Received: (at 76129) by debbugs.gnu.org; 20 Feb 2025 20:39:27 +0000 Received: from localhost ([127.0.0.1]:42408 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tlDKQ-0007zL-Pq for submit@debbugs.gnu.org; Thu, 20 Feb 2025 15:39:27 -0500 Received: from mx1.riseup.net ([198.252.153.129]:49256) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1tlDKO-0007yE-Ms for 76129@debbugs.gnu.org; Thu, 20 Feb 2025 15:39:25 -0500 Received: from fews02-sea.riseup.net (fews02-sea-pn.riseup.net [10.0.1.112]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx1.riseup.net (Postfix) with ESMTPS id 4YzQ922Z8pzDqRd; Thu, 20 Feb 2025 20:39:18 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=riseup.net; s=squak; t=1740083958; bh=VLxej+x73yJENC1xsmdSxJ5yK+6VaN/5nLdif/g6Xdo=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=GRu161iOIra5yKXa/UadrxuJBI7B98sG+ROxEccaFnpqFGlADTXnZwrTn+wj6OLAn YkrGDmAyoF8d+UT82A9znad046+C7dpxxrJh2GJYGl4iqChPgB3GefisjiRCU/tbgO W1T/uc78oTmaQBJ7iD89gE2m9Cp1fBhWEDL3oulM= X-Riseup-User-ID: 92534C5CA4436C360A52CF4EF5E1B68CE3FEE001B91A57887EAC55D7D6F94E5F Received: from [127.0.0.1] (localhost [127.0.0.1]) by fews02-sea.riseup.net (Postfix) with ESMTPSA id 4YzQ910wCczFq3t; Thu, 20 Feb 2025 20:39:16 +0000 (UTC) Date: Thu, 20 Feb 2025 17:39:03 -0300 From: =?iso-8859-1?Q?Andr=E9?= Batista To: Ian Eure Subject: Was [bug#76129], mullvadbrowser: glean, psutil and zstd [security fixes]. Message-ID: References: <87seokttp6.fsf@retrospec.tv> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <87seokttp6.fsf@retrospec.tv> X-Spam-Score: -0.7 (/) X-Debbugs-Envelope-To: 76129 Cc: 76129@debbugs.gnu.org X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: debbugs-submit-bounces@debbugs.gnu.org Sender: "Debbugs-submit" X-Spam-Score: -1.7 (-) Hi Ian, ter 11 fev 2025 às 06:57:41 (1739267861), ian@retrospec.tv enviou: > Hi André, > > The patch looks good; I’m building it now to make sure it passes and seems > to work, and will push today assuming it does. > > I noticed that some python dependencies seem to be missing from > native-inputs, which cause the build to attempt downloading them, printing > messages like: > > WARNING: Retrying (Retry(total=4, connect=None, read=None, > redirect=None, status=None)) after connection broken by > 'NewConnectionError(' object at 0x7ffff56cb520>: Failed to establish a new connection: [Errno > -3] Temporary failure in name resolution')': /simple/glean-sdk/ > > It looks like glean-sdk (seems to be unpackaged in Guix), python-psutil, and > python-zstandard are the missing packages triggering this. This doesn’t > fail the build, so it seems these aren’t critical. If you’re willing to > either add the deps, remove them from wherever they’re listed, or otherwise > stop the download attempts (which take a while to retry and fail), I think > that’d be a good followup. > I've checked the build logs and after those warning messages we get: ------- (...) Could not install glean-sdk, so telemetry will not be collected. Continuing. Could not install psutil, so telemetry will be missing some data. Continuing. Could not install zstandard, so zstd archives will not be possible to extract. Continuing. Configure complete! (...) ------- However, upstream purposefully disables telemetry by unsetting the variable 'MOZ_TELEMETRY_REPORTING' and that's sensible IMO. So glean-sdk and psutil have no place on our build. OTOH, zstandard is used to extract blobs (included/downloaded?) which is also foreign to our goals on guix and a possible threat vector (remember xz-utils?). So I don't think any of them should be included. As for mozilla's warnings, I can live with them. It seems to me that patching the sources to remove those checks/messages would be much trouble for little gain: a couple of seconds at best? Can you live with them as well? Cheers! From unknown Sat Jun 21 10:15:54 2025 Received: (at fakecontrol) by fakecontrolmessage; To: internal_control@debbugs.gnu.org From: Debbugs Internal Request Subject: Internal Control Message-Id: bug archived. Date: Fri, 21 Mar 2025 11:24:11 +0000 User-Agent: Fakemail v42.6.9 # This is a fake control message. # # The action: # bug archived. thanks # This fakemail brought to you by your local debbugs # administrator