1.9.0.1 / 3.0.1 security stability update

Bug #247494 reported by Alexander Sack on 2008-07-11
12
Affects Status Importance Assigned to Milestone
firefox-3.0 (Ubuntu)
High
Alexander Sack
Hardy
High
Alexander Sack
Intrepid
High
Alexander Sack
xulrunner-1.9 (Ubuntu)
High
Alexander Sack
Hardy
High
Alexander Sack
Intrepid
High
Alexander Sack

Bug Description

Binary package hint: xulrunner-1.9

1.9.0.1 / 3.0.1 is about to be released. We should update ubuntu packages in hardy and intrepid at least.

see USN-623-1

Alexander Sack (asac) on 2008-07-11
Changed in xulrunner-1.9:
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
importance: Undecided → High
status: New → Triaged
Changed in firefox-3.0:
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
assignee: nobody → asac
importance: Undecided → High
status: New → Triaged
description: updated
Changed in firefox-3.0:
status: Triaged → In Progress
Changed in xulrunner-1.9:
status: Triaged → In Progress
Alexander Sack (asac) wrote :

initiate SRU procedure and subscribed jdstrand from the security team

Changed in xulrunner-1.9:
assignee: nobody → asac
Alexander Sack (asac) wrote :

hoilding back intrepid uploads due to alpha-2 freeze. Packages are available in asac's PPA (http://www.launchpad.net/~asac/+archive)

Changed in firefox-3.0:
status: Triaged → Fix Committed
Changed in xulrunner-1.9:
status: Triaged → Fix Committed
Steve Langasek (vorlon) wrote :

Accepted into -proposed, please test and give feedback here. Please see https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Changed in firefox-3.0:
status: In Progress → Fix Committed
Changed in xulrunner-1.9:
status: In Progress → Fix Committed

Translated packages are not accepted. So it is a problem for french, german, spanish - and so on - users.

Olivier Prieur (mumbly) wrote :

I can confirm this morning, after the last update, that French language (firefox FR) is not compatible with this new version. My firefox is running in english.

And as translations files are in language-support packages, it will need upgrade for all of them :/

jnygaard (jens-olav-nygaard) wrote :

FYI

I really have no idea about these upgrades, just wanted some more knowledgeable people here to know that an "apt-get distupgrade" just removed my firefox (3.0) and installing it again will not work... Somewhat inconvenient... (As far as I know I use a standard American (English) version of everything, Ubuntu 8.04, w hardy-proposed)

Patrice Vetsel (vetsel-patrice) wrote :

These fixes breaks firefox localization !

After installation/upgrades, first launch of firefox disable some languages plugins -> and now all is in english on my french system

Patrice Vetsel [2008-07-13 12:05 -0000]:
> These fixes breaks firefox localization !

That's actually known. We need to provide updated language packs along
with the new Firefox. Arne, can you please build some?

Alexander Sack (asac) wrote :

On Mon, Jul 14, 2008 at 08:46:44AM +0100, Martin Pitt wrote:
> Patrice Vetsel [2008-07-13 12:05 -0000]:
> > These fixes breaks firefox localization !
>
> That's actually known. We need to provide updated language packs along
> with the new Firefox. Arne, can you please build some?
>

I actually thought the last PPA packs would go to -proposed. AFAIK,
they work properly. Maybe we can just copy those?

 - Alexander

Launchpad Janitor (janitor) wrote :

This bug was fixed in the package firefox-3.0 - 3.0.1+build1+nobinonly-0ubuntu1

---------------
firefox-3.0 (3.0.1+build1+nobinonly-0ubuntu1) intrepid; urgency=low

  * LP: #247494 - new security/stability release (v3.0.1 build1)
    - see USN-626-1

  [ Alexander Sack <email address hidden> ]
  * bump build dependencies for xulrunner 1.9 dev to >= 1.9+nobinonly-0ubuntu3~
    in order to force jemalloc build; bump binary depends accordingly
    - update debian/control
  * add useragent config file and install it in $pkglibdir/defaults/preferences;
    replace @VENDOR@, @VENDOR_SUB@ and @VENDOR_COMMENT@ tokens with lsb_release
    id, release, codename
    - add debian/ubuntu-useragent.js.tmpl
    - update debian/rules
  * bump maxVersion to 1.9.0.* to ease future upgrades of firefox-3.0/xulrunner-1.9
    tandem and lower minVersion to 1.9.0.1 in post-install; in turn adjust binary
    and build depends accordingly.
    - update debian/rules
    - update debian/control

  [ Fabien Tassin <email address hidden> ]
  * Add an empty chrome.manifest in all extensions missing that
    file so it prevents the "failure in Chrome Registration" popup
    - update debian/rules
  * Don't use wildcards to detect xulrunner paths, it fails when
    more that one xulrunner is installed
    - update debian/rules
  * Get DEBIAN_NAME and DEBIAN_APP_NAME from changelog and make more use
    of variables to make the merge with the 3.1 branch easier
    - update debian/rules
    - update debian/firefox-3.0.postinst.in
    - update debian/firefox-3.0.prerm

 -- Alexander Sack <email address hidden> Fri, 18 Jul 2008 17:39:57 +0200

Changed in firefox-3.0:
status: Fix Committed → Fix Released
Launchpad Janitor (janitor) wrote :
Download full text (3.7 KiB)

This bug was fixed in the package xulrunner-1.9 - 1.9.0.1+build1+nobinonly-0ubuntu1

---------------
xulrunner-1.9 (1.9.0.1+build1+nobinonly-0ubuntu1) intrepid; urgency=low

  * LP: #247494 - new upstream stability/security release (v1.9.0.1 build1)
    - see USN-626-1

  [ Fabien Tassin <email address hidden>]
  * Add a build-system for xulrunner application inside the SDK.
    mozilla-devscripts is able to make use of this
    - add debian/create-build-system.sh
    - update debian/rules
  * Rename the ld.so.conf.d file to xulrunner-1.9.conf as it seems
    extension matters
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
  * Get DEB_MOZ_VERSION and DEB_MOZ_VERSION from changelog and make more use
    of variables to make the merge with the 1.9.1 branch easier
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
    - update debian/xulrunner-1.9.postrm
  * Make EM_TRANSLATION_VERSION follow upstream version now that strings are
    hard frozen and bump EM_TRANSLATION_MAX_VERSION to 1.9.0.*
    - update debian/rules

  [ Alexander Sack <email address hidden> ]
  * borrow lockPref patch from debian xulrunner (Debbugs: #469020)
    - add debian/patches/bzXXX_deb469020_lockPref_everywhere.patch
    - update debian/patches/series
  * Debian compatibility patch that is supposed to make xulrunner also
    consider /usr/lib/mozilla/plugins/ in sid as of xulrunner 1.9~rc2-4
    - add debian/patches/bzXXX_sysplugin_support.patch
    - update debian/patches/series
  * prepatch fix for bmo: #120380 - 'needsterminal flag in mailcap
    must be respected'
    - add debian/patches/bz120380_att326044.patch
    - update debian/patches/series
  * add xre part missed by debian for sysplugin support
    - add debian/patches/bzXXX_sysplugin_support_xre_part.patch
    - update debian/patches/series
  * drop patches applied upstream
    - delete debian/patches/bz428848_att319775_fix_venkman_chrome_access.patch
    - update debian/patches/series
  * housekeeping for debian/patches directory; remove obsolete patches from
    debian/patches/ and drop commented patches from series
    - delete debian/patches/bz384304_fix_recursive_symlinks.patch
    - delete debian/patches/bzr423334_att310581_leak_initparser.patch
    - debian/patches/drop_bz418016.patch
    - update debian/patches/series
  * (disabled in intrepid) fix "jemalloc not enabled in --with-xul-sdk= builds": we
    fix this by building libjemalloc as a static lib and linking xulrunner-bin and
    xulrunner-stub against it.
    - add debian/patches/jemalloc_in_xul.patch
    - add debian/patches/jemalloc_static.patch
    - update debian/patches/series
    - update debian/rules
    - update debian/xulrunner-1.9.postinst
  * link nss/nspr include directories to xulrunner-1.9 sdk in order to
    allow upstream extensions to be built against ubuntu xulrunner.
    - add debian/xulrunner-1.9-dev.links
  * add empty xulrunner-dev package to ease sync/merge tasks for ubuntu
    by providing the package name used by debian.
    - update debian/control
  * fix makefile style variable eval in xulrunner-1.9 prerm script and use
    proper sh'ish style
    - update debian/xulrunner-1.9.prerm
 ...

Read more...

Changed in xulrunner-1.9:
status: Fix Committed → Fix Released
Martin Pitt (pitti) wrote :

Copied to hardy-updates, verified by Alex.

Changed in xulrunner-1.9:
status: Fix Committed → Fix Released
Changed in firefox-3.0:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers