2016-02-19 19:29:59 |
Nik Soams |
bug |
|
|
added bug |
2016-02-19 19:32:02 |
Nik Soams |
summary |
Build without libqt5webkit dependancy |
CRITICAL: please remove libqt5webkit dependancy |
|
2016-02-22 12:52:06 |
Alberto Mardegan |
signon-ui (Ubuntu): importance |
Undecided |
Medium |
|
2016-02-22 12:52:11 |
Alberto Mardegan |
signon-ui (Ubuntu): status |
New |
Confirmed |
|
2016-04-06 07:49:21 |
Alberto Mardegan |
branch linked |
|
lp:~mardy/signon-ui/no-webkit-1547647 |
|
2016-05-18 11:12:38 |
Jean-Baptiste Lallement |
bug task added |
|
canonical-devices-system-image |
|
2016-05-18 11:12:54 |
Jean-Baptiste Lallement |
canonical-devices-system-image: status |
New |
Confirmed |
|
2016-05-18 11:13:09 |
Jean-Baptiste Lallement |
bug task deleted |
canonical-devices-system-image |
|
|
2016-05-20 13:54:55 |
Launchpad Janitor |
signon-ui (Ubuntu): status |
Confirmed |
Fix Released |
|
2016-06-17 01:11:31 |
Amr Ibrahim |
tags |
|
xenial |
|
2016-06-29 18:19:06 |
Will Cooke |
signon-ui (Ubuntu): milestone |
|
ubuntu-16.04.1 |
|
2016-06-29 18:25:13 |
Will Cooke |
nominated for series |
|
Ubuntu Xenial |
|
2016-06-29 18:25:13 |
Will Cooke |
bug task added |
|
signon-ui (Ubuntu Xenial) |
|
2016-06-29 18:25:29 |
Will Cooke |
nominated for series |
|
Ubuntu Yakkety |
|
2016-06-29 18:25:29 |
Will Cooke |
bug task added |
|
signon-ui (Ubuntu Yakkety) |
|
2016-06-29 18:27:17 |
Will Cooke |
signon-ui (Ubuntu Xenial): milestone |
|
ubuntu-16.04.1 |
|
2016-06-29 18:27:20 |
Will Cooke |
signon-ui (Ubuntu Yakkety): milestone |
ubuntu-16.04.1 |
|
|
2016-06-30 13:13:58 |
Will Cooke |
signon-ui (Ubuntu Xenial): status |
New |
In Progress |
|
2016-06-30 13:14:10 |
Will Cooke |
signon-ui (Ubuntu Xenial): assignee |
|
Alberto Mardegan (mardy) |
|
2016-06-30 13:14:15 |
Will Cooke |
signon-ui (Ubuntu Yakkety): assignee |
|
Alberto Mardegan (mardy) |
|
2016-06-30 13:16:22 |
Will Cooke |
signon-ui (Ubuntu Xenial): importance |
Undecided |
Medium |
|
2016-06-30 13:59:47 |
David Barth |
description |
signon-ui-x11(http://packages.ubuntu.com/xenial/signon-ui-x11) depends on libqt5webkit5
https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/
Can it be resolved so new LTS wont be released with known webkit1 bugs/security exploits? |
[Impact]
* When declaring online accounts for use by Ubuntu, the system uses a webview to authenticate to online services like Facebook or Google.
* On X11 desktops, that webview currently uses an old qt5webkit component that is now unmaintained
* Backporting this fix will simplify the maintenance work, by removing the need for that old component, and will improve the coherence of the system by using a supported Oxide webview
[Test Case]
To verify the change:
* Go to system settings > Online Accounts
* Add account of type Google, Facebook or Twitter (which uses webview for authentication)
* Verify that a webview opens to log onto the online service
* Verify that the account is listed in the account list at the end of this process
* Verify that the related apps and services can use the online account as before (ie Shotwell photo uploads, Photos scope, etc.)
[Regression Potential]
* On architectures not supported by Oxide, namely ppc64el and s390x, the change will trigger a runtime error when trying to use that part of signon-ui.
* The problem affects users of Ubuntu desktop systems based on X11. The change is already in effect on Unity8/Mir devices for a few months.
[Other Info]
* signon-ui-x11(http://packages.ubuntu.com/xenial/signon-ui-x11) depends on libqt5webkit5
* See also: https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/ |
|
2016-06-30 14:00:50 |
David Barth |
description |
[Impact]
* When declaring online accounts for use by Ubuntu, the system uses a webview to authenticate to online services like Facebook or Google.
* On X11 desktops, that webview currently uses an old qt5webkit component that is now unmaintained
* Backporting this fix will simplify the maintenance work, by removing the need for that old component, and will improve the coherence of the system by using a supported Oxide webview
[Test Case]
To verify the change:
* Go to system settings > Online Accounts
* Add account of type Google, Facebook or Twitter (which uses webview for authentication)
* Verify that a webview opens to log onto the online service
* Verify that the account is listed in the account list at the end of this process
* Verify that the related apps and services can use the online account as before (ie Shotwell photo uploads, Photos scope, etc.)
[Regression Potential]
* On architectures not supported by Oxide, namely ppc64el and s390x, the change will trigger a runtime error when trying to use that part of signon-ui.
* The problem affects users of Ubuntu desktop systems based on X11. The change is already in effect on Unity8/Mir devices for a few months.
[Other Info]
* signon-ui-x11(http://packages.ubuntu.com/xenial/signon-ui-x11) depends on libqt5webkit5
* See also: https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/ |
This is an SRU request, based on the process documented at https://wiki.ubuntu.com/StableReleaseUpdates
[Impact]
* When declaring online accounts for use by Ubuntu, the system uses a webview to authenticate to online services like Facebook or Google.
* On X11 desktops, that webview currently uses an old qt5webkit component that is now unmaintained
* Backporting this fix will simplify the maintenance work, by removing the need for that old component, and will improve the coherence of the system by using a supported Oxide webview
[Test Case]
To verify the change:
* Go to system settings > Online Accounts
* Add account of type Google, Facebook or Twitter (which uses webview for authentication)
* Verify that a webview opens to log onto the online service
* Verify that the account is listed in the account list at the end of this process
* Verify that the related apps and services can use the online account as before (ie Shotwell photo uploads, Photos scope, etc.)
[Regression Potential]
* On architectures not supported by Oxide, namely ppc64el and s390x, the change will trigger a runtime error when trying to use that part of signon-ui.
* The problem affects users of Ubuntu desktop systems based on X11. The change is already in effect on Unity8/Mir devices for a few months.
[Other Info]
* signon-ui-x11(http://packages.ubuntu.com/xenial/signon-ui-x11) depends on libqt5webkit5
* See also: https://blogs.gnome.org/mcatanzaro/2016/02/01/on-webkit-security-updates/ |
|
2016-06-30 14:02:12 |
David Barth |
summary |
CRITICAL: please remove libqt5webkit dependancy |
[SRU] please remove libqt5webkit dependancy |
|
2016-06-30 14:02:21 |
David Barth |
summary |
[SRU] please remove libqt5webkit dependancy |
[SRU] please remove libqt5webkit dependency |
|
2017-03-23 20:40:37 |
Brian Murray |
signon-ui (Ubuntu Xenial): status |
In Progress |
Fix Committed |
|
2017-03-23 20:40:40 |
Brian Murray |
bug |
|
|
added subscriber Ubuntu Stable Release Updates Team |
2017-03-23 20:40:43 |
Brian Murray |
bug |
|
|
added subscriber SRU Verification |
2017-03-23 20:40:50 |
Brian Murray |
tags |
xenial |
verification-needed xenial |
|
2017-06-23 19:29:16 |
Ubuntu Foundations Team Bug Bot |
tags |
verification-needed xenial |
removal-candidate verification-needed xenial |
|
2017-07-09 20:30:16 |
Steve Langasek |
tags |
removal-candidate verification-needed xenial |
removal-candidate verification-failed-trusty xenial |
|
2018-02-08 09:51:19 |
Łukasz Zemczak |
signon-ui (Ubuntu Xenial): status |
Fix Committed |
Won't Fix |
|
2018-02-08 09:51:26 |
Łukasz Zemczak |
removed subscriber Ubuntu Stable Release Updates Team |
|
|
|