1.9.0.1 / 3.0.1 security stability update

Bug #247494 reported by Alexander Sack
12
Affects Status Importance Assigned to Milestone
firefox-3.0 (Ubuntu)
Fix Released
High
Alexander Sack
Hardy
Fix Released
High
Alexander Sack
Intrepid
Fix Released
High
Alexander Sack
xulrunner-1.9 (Ubuntu)
Fix Released
High
Alexander Sack
Hardy
Fix Released
High
Alexander Sack
Intrepid
Fix Released
High
Alexander Sack

Bug Description

Binary package hint: xulrunner-1.9

1.9.0.1 / 3.0.1 is about to be released. We should update ubuntu packages in hardy and intrepid at least.

see USN-623-1

Alexander Sack (asac)
Changed in xulrunner-1.9:
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
importance: Undecided → High
status: New → Triaged
Changed in firefox-3.0:
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
description: updated
Changed in firefox-3.0:
status: Triaged → In Progress
Changed in xulrunner-1.9:
status: Triaged → In Progress
Revision history for this message
Alexander Sack (asac) wrote :

initiate SRU procedure and subscribed jdstrand from the security team

Changed in xulrunner-1.9:
assignee: nobody → asac
Revision history for this message
Alexander Sack (asac) wrote :

hoilding back intrepid uploads due to alpha-2 freeze. Packages are available in asac's PPA (http://www.launchpad.net/~asac/+archive)

Changed in firefox-3.0:
status: Triaged → Fix Committed
Changed in xulrunner-1.9:
status: Triaged → Fix Committed
Revision history for this message
Steve Langasek (vorlon) wrote :

Accepted into -proposed, please test and give feedback here. Please see https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Changed in firefox-3.0:
status: In Progress → Fix Committed
Changed in xulrunner-1.9:
status: In Progress → Fix Committed
Revision history for this message
FredBezies (fredbezies-deactivatedaccount) wrote :

Translated packages are not accepted. So it is a problem for french, german, spanish - and so on - users.

Revision history for this message
Olivier Prieur (mumbly) wrote :

I can confirm this morning, after the last update, that French language (firefox FR) is not compatible with this new version. My firefox is running in english.

Revision history for this message
FredBezies (fredbezies-deactivatedaccount) wrote :

And as translations files are in language-support packages, it will need upgrade for all of them :/

Revision history for this message
jnygaard (jens-olav-nygaard) wrote :

FYI

I really have no idea about these upgrades, just wanted some more knowledgeable people here to know that an "apt-get distupgrade" just removed my firefox (3.0) and installing it again will not work... Somewhat inconvenient... (As far as I know I use a standard American (English) version of everything, Ubuntu 8.04, w hardy-proposed)

Revision history for this message
Patrice Vetsel (vetsel-patrice) wrote :

These fixes breaks firefox localization !

After installation/upgrades, first launch of firefox disable some languages plugins -> and now all is in english on my french system

Revision history for this message
Martin Pitt (pitti) wrote : Re: [Bug 247494] Re: 1.9.0.1 / 3.0.1 security stability update

Patrice Vetsel [2008-07-13 12:05 -0000]:
> These fixes breaks firefox localization !

That's actually known. We need to provide updated language packs along
with the new Firefox. Arne, can you please build some?

Revision history for this message
Alexander Sack (asac) wrote :

On Mon, Jul 14, 2008 at 08:46:44AM +0100, Martin Pitt wrote:
> Patrice Vetsel [2008-07-13 12:05 -0000]:
> > These fixes breaks firefox localization !
>
> That's actually known. We need to provide updated language packs along
> with the new Firefox. Arne, can you please build some?
>

I actually thought the last PPA packs would go to -proposed. AFAIK,
they work properly. Maybe we can just copy those?

 - Alexander

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package firefox-3.0 - 3.0.1+build1+nobinonly-0ubuntu1

---------------
firefox-3.0 (3.0.1+build1+nobinonly-0ubuntu1) intrepid; urgency=low

  * LP: #247494 - new security/stability release (v3.0.1 build1)
    - see USN-626-1

  [ Alexander Sack <email address hidden> ]
  * bump build dependencies for xulrunner 1.9 dev to >= 1.9+nobinonly-0ubuntu3~
    in order to force jemalloc build; bump binary depends accordingly
    - update debian/control
  * add useragent config file and install it in $pkglibdir/defaults/preferences;
    replace @VENDOR@, @VENDOR_SUB@ and @VENDOR_COMMENT@ tokens with lsb_release
    id, release, codename
    - add debian/ubuntu-useragent.js.tmpl
    - update debian/rules
  * bump maxVersion to 1.9.0.* to ease future upgrades of firefox-3.0/xulrunner-1.9
    tandem and lower minVersion to 1.9.0.1 in post-install; in turn adjust binary
    and build depends accordingly.
    - update debian/rules
    - update debian/control

  [ Fabien Tassin <email address hidden> ]
  * Add an empty chrome.manifest in all extensions missing that
    file so it prevents the "failure in Chrome Registration" popup
    - update debian/rules
  * Don't use wildcards to detect xulrunner paths, it fails when
    more that one xulrunner is installed
    - update debian/rules
  * Get DEBIAN_NAME and DEBIAN_APP_NAME from changelog and make more use
    of variables to make the merge with the 3.1 branch easier
    - update debian/rules
    - update debian/firefox-3.0.postinst.in
    - update debian/firefox-3.0.prerm

 -- Alexander Sack <email address hidden> Fri, 18 Jul 2008 17:39:57 +0200

Changed in firefox-3.0:
status: Fix Committed → Fix Released
Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (3.7 KiB)

This bug was fixed in the package xulrunner-1.9 - 1.9.0.1+build1+nobinonly-0ubuntu1

---------------
xulrunner-1.9 (1.9.0.1+build1+nobinonly-0ubuntu1) intrepid; urgency=low

  * LP: #247494 - new upstream stability/security release (v1.9.0.1 build1)
    - see USN-626-1

  [ Fabien Tassin <email address hidden>]
  * Add a build-system for xulrunner application inside the SDK.
    mozilla-devscripts is able to make use of this
    - add debian/create-build-system.sh
    - update debian/rules
  * Rename the ld.so.conf.d file to xulrunner-1.9.conf as it seems
    extension matters
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
  * Get DEB_MOZ_VERSION and DEB_MOZ_VERSION from changelog and make more use
    of variables to make the merge with the 1.9.1 branch easier
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
    - update debian/xulrunner-1.9.postrm
  * Make EM_TRANSLATION_VERSION follow upstream version now that strings are
    hard frozen and bump EM_TRANSLATION_MAX_VERSION to 1.9.0.*
    - update debian/rules

  [ Alexander Sack <email address hidden> ]
  * borrow lockPref patch from debian xulrunner (Debbugs: #469020)
    - add debian/patches/bzXXX_deb469020_lockPref_everywhere.patch
    - update debian/patches/series
  * Debian compatibility patch that is supposed to make xulrunner also
    consider /usr/lib/mozilla/plugins/ in sid as of xulrunner 1.9~rc2-4
    - add debian/patches/bzXXX_sysplugin_support.patch
    - update debian/patches/series
  * prepatch fix for bmo: #120380 - 'needsterminal flag in mailcap
    must be respected'
    - add debian/patches/bz120380_att326044.patch
    - update debian/patches/series
  * add xre part missed by debian for sysplugin support
    - add debian/patches/bzXXX_sysplugin_support_xre_part.patch
    - update debian/patches/series
  * drop patches applied upstream
    - delete debian/patches/bz428848_att319775_fix_venkman_chrome_access.patch
    - update debian/patches/series
  * housekeeping for debian/patches directory; remove obsolete patches from
    debian/patches/ and drop commented patches from series
    - delete debian/patches/bz384304_fix_recursive_symlinks.patch
    - delete debian/patches/bzr423334_att310581_leak_initparser.patch
    - debian/patches/drop_bz418016.patch
    - update debian/patches/series
  * (disabled in intrepid) fix "jemalloc not enabled in --with-xul-sdk= builds": we
    fix this by building libjemalloc as a static lib and linking xulrunner-bin and
    xulrunner-stub against it.
    - add debian/patches/jemalloc_in_xul.patch
    - add debian/patches/jemalloc_static.patch
    - update debian/patches/series
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
  * link nss/nspr include directories to xulrunner-1.9 sdk in order to
    allow upstream extensions to be built against ubuntu xulrunner.
    - add debian/xulrunner-1.9-dev.links
  * add empty xulrunner-dev package to ease sync/merge tasks for ubuntu
    by providing the package name used by debian.
    - update debian/control
  * fix makefile style variable eval in xulrunner-1.9 prerm script and use
    proper sh'ish style
    - update debian/xulrunner-1.9.prerm
 ...

Read more...

Changed in xulrunner-1.9:
status: Fix Committed → Fix Released
Revision history for this message
Martin Pitt (pitti) wrote :

Copied to hardy-updates, verified by Alex.

Changed in xulrunner-1.9:
status: Fix Committed → Fix Released
Changed in firefox-3.0:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.