From patchwork Mon Jan 13 22:52:17 2025 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: =?utf-8?q?Andr=C3=A9_Batista?= X-Patchwork-Id: 37054 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 36C4C27BBEA; Mon, 13 Jan 2025 22:53:38 +0000 (GMT) X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-7.6 required=5.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED, RCVD_IN_VALIDITY_CERTIFIED,RCVD_IN_VALIDITY_RPBL,RCVD_IN_VALIDITY_SAFE, SPF_HELO_PASS,URIBL_BLOCKED autolearn=ham autolearn_force=no version=3.4.6 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTPS id 3080727BBE2 for ; Mon, 13 Jan 2025 22:53:37 +0000 (GMT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1tXTJ2-0003bo-VJ; Mon, 13 Jan 2025 17:53:12 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tXTIw-0003ak-Qr for guix-patches@gnu.org; Mon, 13 Jan 2025 17:53:08 -0500 Received: from debbugs.gnu.org ([2001:470:142:5::43]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1tXTIw-0005Z1-I1 for guix-patches@gnu.org; Mon, 13 Jan 2025 17:53:06 -0500 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debbugs.gnu.org; s=debbugs-gnu-org; h=MIME-Version:Date:From:To:Subject; bh=ygco1vfZIJv2i0U6RZFya0ieDbR3xWOvHu5SzWOaulM=; b=etkLgVJtldRMzyZt/Xxu4jACHqpulSaVMFM/DE7LHsbnpWAoTtgAYp1rvFOi+L6K3B2c7N8dhPRWPoCwyG4lobb/fCNbPVPmiDevtCHD4e+69KCmctSSYMoLdE/tY15MTi2gtUchG/hvkU6kUHPQq/CIK+QiatBWhQUZaD3C+vQYF49mU+NvJEkleTYM+i1R6pA5GehpXML0cBFpO/gX8RNTXrM7FHOneEcxPjh9fy5Odf6siiFEhR0pbgLjGP3ztjglx8++s6AFX6gdA4eq8poIRNjxEyO09EseX0++WQJSmPbrfvyd6aPiJmaXGpov55Q5/cIRw5M1+T38/49R8g==; Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1tXTIt-0001PJ-QW; Mon, 13 Jan 2025 17:53:03 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#75548] [PATCH] gnu: mullvadbrowser: Update to 14.0.4 [security fixes]. Resent-From: =?utf-8?b?QW5kcsOp?= Batista Original-Sender: "Debbugs-submit" Resent-CC: clement@lassieur.org, jonathan.brielmaier@web.de, mhw@netris.org, ian@retrospec.tv, guix-patches@gnu.org Resent-Date: Mon, 13 Jan 2025 22:53:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 75548 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 75548@debbugs.gnu.org Cc: =?utf-8?b?QW5kcsOp?= Batista , clement@lassieur.org, jonathan.brielmaier@web.de, mhw@netris.org, ian@retrospec.tv X-Debbugs-Original-To: guix-patches@gnu.org X-Debbugs-Original-Xcc: clement@lassieur.org, jonathan.brielmaier@web.de, mhw@netris.org, ian@retrospec.tv Received: via spool by submit@debbugs.gnu.org id=B.17368087555316 (code B ref -1); Mon, 13 Jan 2025 22:53:03 +0000 Received: (at submit) by debbugs.gnu.org; 13 Jan 2025 22:52:35 +0000 Received: from localhost ([127.0.0.1]:53191 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1tXTIQ-0001Na-M3 for submit@debbugs.gnu.org; Mon, 13 Jan 2025 17:52:35 -0500 Received: from lists.gnu.org ([2001:470:142::17]:47306) by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.84_2) (envelope-from ) id 1tXTIO-0001NG-HQ for submit@debbugs.gnu.org; Mon, 13 Jan 2025 17:52:33 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tXTIJ-0003Vx-6y for guix-patches@gnu.org; Mon, 13 Jan 2025 17:52:27 -0500 Received: from mx1.riseup.net ([198.252.153.129]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1tXTIH-0005WY-Cr for guix-patches@gnu.org; Mon, 13 Jan 2025 17:52:26 -0500 Received: from fews02-sea.riseup.net (fews02-sea-pn.riseup.net [10.0.1.112]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx1.riseup.net (Postfix) with ESMTPS id 4YX6w81JKxzDqBD for ; Mon, 13 Jan 2025 22:52:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=riseup.net; s=squak; t=1736808744; bh=r4WwAb/9bUfTnuDZGsHjf9AzwBD0HLBkyaQ9zMGksfs=; h=From:To:Cc:Subject:Date:From; b=JnpiSF5NQbZ8yPnmO5v/9O/+1oXiqoogITUf8PFGUxugcHJfKPps4Aqfh+4LVTgAR W220iDOurlag5OyPXsdQoHMjEhCrI1p8a2i/NqxAmgmO+lai3zRjBvoGhXM9WtdW2U U35iFAigGx5YGm7+UhnQDEQrMhmFP6k30ds60oy0= X-Riseup-User-ID: 1316DA4A978EE278ADE512EEB6CA41928C055FA50538BE3CCFD1BE47EB0E7E25 Received: from [127.0.0.1] (localhost [127.0.0.1]) by fews02-sea.riseup.net (Postfix) with ESMTPSA id 4YX6w71gJfzFsw4; Mon, 13 Jan 2025 22:52:23 +0000 (UTC) From: =?utf-8?b?QW5kcsOp?= Batista Date: Mon, 13 Jan 2025 19:52:17 -0300 Message-ID: <20250113225217.2498-1-nandre@riseup.net> MIME-Version: 1.0 Received-SPF: pass client-ip=198.252.153.129; envelope-from=nandre@riseup.net; helo=mx1.riseup.net X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org X-getmail-retrieved-from-mailbox: Patches Fixes CVEs 2025-0237, 2025-0238, 2025-0239, 2025-0240, 2025-0241, 2025-0242 and 2025-0243. See for details. * gnu/packages/tor-browsers.scm (%mullvadbrowser-build-date): Update to 20250106125732 (%mullvadbrowser-version): Update to 14.0.4. (%mullvadbrowser-firefox-version): Update to 128.6.0esr-14.0-1-build1. (mullvadbrowser-translation-base): Update to bb1df34ec79d55dcd1e0ebc80cb2c72d27c462b7. (mullvadbrowser-translation-specific): Update to 6a1ef41c664a5185e25ca2c4bbf5d7447bd888a7. Change-Id: I1c0b2290b89d59f9d21ac0be273ca686593ee002 --- gnu/packages/tor-browsers.scm | 18 +++++++++--------- 1 file changed, 9 insertions(+), 9 deletions(-) base-commit: 575dc58975281e8c2c779c9b3098746606cfc5dd diff --git a/gnu/packages/tor-browsers.scm b/gnu/packages/tor-browsers.scm index 9608a9cb983..6d74a75f4b5 100644 --- a/gnu/packages/tor-browsers.scm +++ b/gnu/packages/tor-browsers.scm @@ -818,17 +818,17 @@ (define %mullvadbrowser-locales (list "ar" "da" "de" "es-ES" "fa" "fi" "fr" "it" ;; We copy the official build id, which can be found there: ;; https://cdn.mullvad.net/browser/update_responses/update_1/release. -(define %mullvadbrowser-build-date "20241125154204") +(define %mullvadbrowser-build-date "20250106125732") ;; To find the last version, look at ;; https://mullvad.net/en/download/browser/linux. -(define %mullvadbrowser-version "14.0.3") +(define %mullvadbrowser-version "14.0.4") ;; To find the last Firefox version, browse ;; https://archive.torproject.org/tor-package-archive/mullvadbrowser/<%mullvadbrowser-version> ;; There should be only one archive that starts with ;; "src-firefox-mullvad-browser-". -(define %mullvadbrowser-firefox-version "128.5.0esr-14.0-1-build2") +(define %mullvadbrowser-firefox-version "128.6.0esr-14.0-1-build1") ;; See tor-browser-build/projects/translation/config. (define mullvadbrowser-translation-base @@ -836,11 +836,11 @@ (define mullvadbrowser-translation-base (method git-fetch) (uri (git-reference (url "https://gitlab.torproject.org/tpo/translation.git") - (commit "caa431bbea1a76d7ad61eeda94086a1513762605"))) + (commit "bb1df34ec79d55dcd1e0ebc80cb2c72d27c462b7"))) (file-name "translation-base-browser") (sha256 (base32 - "0zdkcykzh8m1rv6valx0mk6yvh2q4jrj2qxk0frh7nwxwc509b5c")))) + "0mhfbmghvdd1rpvpr8ppkdpzwwb9v03a211qgi27j3iwaa04zh9m")))) ;; See tor-browser-build/projects/translation/config. (define mullvadbrowser-translation-specific @@ -848,11 +848,11 @@ (define mullvadbrowser-translation-specific (method git-fetch) (uri (git-reference (url "https://gitlab.torproject.org/tpo/translation.git") - (commit "2f7d98b46ce480cdb4d7e9ddab912650c8673d6c"))) + (commit "6a1ef41c664a5185e25ca2c4bbf5d7447bd888a7"))) (file-name "translation-mullvad-browser") (sha256 (base32 - "08anwb45rxzsdcxwzjflqb1d0f78pi4fsgdvsdlc4fmp8kx10nsd")))) + "0jgxgynyzcph82j3bjkw0qfwkakmz8529lmx7v1ggbh3fvn7wa4l")))) (define mullvadbrowser-assets ;; This is a prebuilt Mullvad Browser from which we take the assets we need. @@ -868,7 +868,7 @@ (define mullvadbrowser-assets version "/mullvad-browser-linux-x86_64-" version ".tar.xz")) (sha256 (base32 - "0jh35vsnyqjg6hhwdlw11pq7i1awr6fy8chgr2w0wnrzm91vvzia")))) + "0cycrxil9zbdqrkzzsfx7nlrhs4k5riwi0y7r0ah2snmpcla4nb3")))) (arguments (list #:install-plan @@ -911,7 +911,7 @@ (define-public mullvadbrowser %mullvadbrowser-firefox-version ".tar.xz")) (sha256 (base32 - "01mm8kxza5rfl4f78xb8n9x7y0p6mm205pxhqrvds0yyj3jvclsb")))) + "0x5q0g62ndy9r7qqrz0p35bq258sn26bdwhzs396v8mrzyf4jywh")))) (arguments (substitute-keyword-arguments (package-arguments mullvadbrowser-base) ((#:phases phases)