Firefox security fixes not installed

Bug #17045 reported by Stuart Bishop
16
This bug affects 2 people
Affects Status Importance Assigned to Milestone
update-manager (Ubuntu)
Fix Released
High
Michael Vogt

Bug Description

Update notifier put the new Firefox security updates in the 'unchanged' section
rather than deciding to apply the fix. There was no feedback on how to apply
these changes. I know that I can force the updates to proceed by doing the
update manually using Synaptic, but demonstrates a failure of the
update-notifier to do its job as ensuring a system remains secure is the primary
use case for it.

In this case, it looks like update-notifier did not want to apply the updates
because upgrading mozilla-firefox-gnome-support would force removal of
mozilla-firefox-dom-inspecter from Universe and the mozilla-psm upgrade forces
removal of a number of things including mozilla and mozilla-calendar.

I think update-notifier needs to cope with this, most likely by asking the user
what do do about difficult upgrades after explaining the side effects -- 'There
is an update for mozilla-firefox, but it would cause removal of blah, blah and
blah. Proceed (Yes/No/Later)?'

The alternative is of course to simply guide the user to, or launch directly,
Synaptic (but this might be deemed to complex for a click'n'drool update procedure).

Revision history for this message
Michael Vogt (mvo) wrote :

Thanks for your bugreport.

This is indeed a big problem. update-manager was designed under the assumption
that a security update will never touch the status of other packages (remove
installed, install new). This used to be the case for debian. I'll fix
update-manager to cope with the changed circumanstances.

I just tried to reproduce the problem and it looks like the packages are now
updated in universe too, so the fixes should now be installable without this
message?

Thanks,
 Michael

Revision history for this message
Stuart Bishop (stub) wrote :

(In reply to comment #1)

> I just tried to reproduce the problem and it looks like the packages are now
> updated in universe too, so the fixes should now be installable without this
> message?

I still get a conflict installing mozilla-calendar, because the version of
mozilla-browser in hoary-security is too recent (the version in hoary though is
fine). I've got a bug open elsewhere on this though.

Revision history for this message
Michael Vogt (mvo) wrote :

For breezy the update-manager will try harder to upgrade but it will still
refuse to remove packages. A version that solves this problem didn't made it in
breezy time.

Revision history for this message
Michael Vogt (mvo) wrote :

The update-manager in dapper will install all -security or -update updates for stable. It will refuse to delete packages but that is a policy decision (because updates never require the removal of packages).

Cheers,
 Michael

Changed in update-manager:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.