GNU bug report logs - #77460
[PATCH] gnu: torbrowser: Update to 14.0.9 [security-fixes].

Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.

Package: guix-patches; Reported by: André Batista <nandre@HIDDEN>; Keywords: patch; Done: Ian Eure <ian@HIDDEN>; Maintainer for guix-patches is guix-patches@HIDDEN.
bug closed, send any further explanations to 77460 <at> debbugs.gnu.org and André Batista <nandre@HIDDEN> Request was from Ian Eure <ian@HIDDEN> to control <at> debbugs.gnu.org. Full text available.

Message received at 77460 <at> debbugs.gnu.org:


Received: (at 77460) by debbugs.gnu.org; 3 Apr 2025 04:08:45 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Thu Apr 03 00:08:44 2025
Received: from localhost ([127.0.0.1]:60266 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1u0Bsi-0005Gl-Bt
	for submit <at> debbugs.gnu.org; Thu, 03 Apr 2025 00:08:44 -0400
Received: from fout-a8-smtp.messagingengine.com ([103.168.172.151]:38783)
 by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.84_2) (envelope-from <ian@HIDDEN>) id 1u0Bsg-0005GV-OG
 for 77460 <at> debbugs.gnu.org; Thu, 03 Apr 2025 00:08:43 -0400
Received: from phl-compute-09.internal (phl-compute-09.phl.internal
 [10.202.2.49])
 by mailfout.phl.internal (Postfix) with ESMTP id 84B4B138017C;
 Thu,  3 Apr 2025 00:08:37 -0400 (EDT)
Received: from phl-mailfrontend-01 ([10.202.2.162])
 by phl-compute-09.internal (MEProxy); Thu, 03 Apr 2025 00:08:37 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=retrospec.tv; h=
 cc:cc:content-transfer-encoding:content-type:content-type:date
 :date:from:from:in-reply-to:message-id:mime-version:reply-to
 :subject:subject:to:to; s=fm1; t=1743653317; x=1743739717; bh=YA
 B8ZEL81JF1b8V7NYXHEDVm0SYn0vpk9HUkluEaChE=; b=ndBKoHTL1i0I0+Jpbs
 P+lTb7Jd2jegDttAs807Eo0MQsB1QeR8ivByIH6HRnV3yi2ySLPlkf0zOaDaHzV5
 puCZb7523HrL9PA6mciVvJWvrcClbBHztPkAqQ31j8SIU3upjZN0Az8FN5TzUZ5c
 mjTuM5WUkEXEsueUd164fAurOnbl69yWptdZLt4e0SRxmzn1N3t/RQllf0l8SbIq
 hx4Vh/IOOFOlA+xJti2jzEmiwP1cuW2rs6JFbCTOKpHjnN1MTALR7raDWPypBnbo
 4lkhDBzmeK4L45nzlq21cWDQzHuQhxTG4+SRL4C2o8yTHOOPOiR25cvAr9RWoelw
 3ThQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=
 messagingengine.com; h=cc:cc:content-transfer-encoding
 :content-type:content-type:date:date:feedback-id:feedback-id
 :from:from:in-reply-to:message-id:mime-version:reply-to:subject
 :subject:to:to:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=
 fm2; t=1743653317; x=1743739717; bh=YAB8ZEL81JF1b8V7NYXHEDVm0SYn
 0vpk9HUkluEaChE=; b=kypi6poUH1Ysz+aJ4Faap44qOoseRXrJlBE0rIp4vT7V
 NTt15qFap87UN+ZSMjyvkDwsBnTIFC5taooFeJ3EBKU8uLHiqI09B+Q0h4SO0V6x
 31/j1UhuTtw16sWNXid2K7yt/VCANAs5v8tJZA3sk8D89Xp9dzzoLtElq45u3YKp
 QebTghD7vnFyzpdQhulLVigaAf7v8NrX06HEMrFDcHwcE53eSZShd3BdIlXQm3fV
 /rc+vzjcjH2nmr3A+mTPOfK56ksjiR0yrGJgddCGrTwDQamTmiPtjyPJK6OvOqx4
 046zlyLXgn6Dru3ayDxSWEYR9Ca3gSd/se6HDBGiog==
X-ME-Sender: <xms:xQnuZ6ApQHjJX5z1D5hMj8kjlyyOMN-7PHcXX4ta_3mSDsc4oyzNcg>
 <xme:xQnuZ0iVLUDElwSwJ_uFwv6fTnjc4BwVhLG-FstIRK5n6Ael4tk2AqLiDAeju6EJd
 X9bef_sCoRg2G90Sg>
X-ME-Received: <xmr:xQnuZ9mXR01y9_Dg_pOcDQvA2MWmadrZ6vNEOms1aXPpXOmqGCjCWAPgmjV64oM6omoIqCgOfkwIfGahGlpwQ_Nqf9pIBHFjDTkb>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefvddrtddtgddukeejheeiucetufdoteggodetrf
 dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdggtfgfnhhsuhgsshgtrhhisggv
 pdfurfetoffkrfgpnffqhgenuceurghilhhouhhtmecufedttdenucesvcftvggtihhpih
 gvnhhtshculddquddttddmnecujfgurhephffvvefufgffkfggtgfgsehtqhertddtreej
 necuhfhrohhmpefkrghnucfguhhrvgcuoehirghnsehrvghtrhhoshhpvggtrdhtvheqne
 cuggftrfgrthhtvghrnheptdetkeffffefiefhueekvdeiueegieegffdthfelveelgfdt
 vdfhtdduheffuedvnecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilh
 hfrhhomhepihgrnhesrhgvthhrohhsphgvtgdrthhvpdhnsggprhgtphhtthhopeehpdhm
 ohguvgepshhmthhpohhuthdprhgtphhtthhopehmhhifsehnvghtrhhishdrohhrghdprh
 gtphhtthhopehjohhnrghthhgrnhdrsghrihgvlhhmrghivghrseifvggsrdguvgdprhgt
 phhtthhopegtlhgvmhgvnhhtsehlrghsshhivghurhdrohhrghdprhgtphhtthhopeejje
 egiedtseguvggssghughhsrdhgnhhurdhorhhgpdhrtghpthhtohepnhgrnhgurhgvsehr
 ihhsvghuphdrnhgvth
X-ME-Proxy: <xmx:xQnuZ4wJ2KiyNw0f6HInXgXfvz2RyCchAKRJvp5xTZDpY9-ux3n04A>
 <xmx:xQnuZ_Sc421fXn3qxtbn0wsO2480OSaBHxvtBZE78Fsh2fKZW-e9lw>
 <xmx:xQnuZzaowxJxyvezRtO_qeBoqt-0OYaBml8cLX3O4hOHT54qLidvVA>
 <xmx:xQnuZ4S01B7Hax7l8i_m-_mSBPggAVyL9Zs49m6HWgcE3RtF85uZmg>
 <xmx:xQnuZ47hSztHz-p0prRz89g1mivp-FfMDtkTGn3qYUgm2EB-JYH17cCi>
Feedback-ID: id9014242:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Thu,
 3 Apr 2025 00:08:36 -0400 (EDT)
From: Ian Eure <ian@HIDDEN>
To: =?utf-8?Q?Andr=C3=A9?= Batista <nandre@HIDDEN>
Subject: Re: [bug#77460] [PATCH] gnu: torbrowser: Update to 14.0.9
 [security-fixes].
User-Agent: mu4e 1.12.9; emacs 29.4
Date: Wed, 02 Apr 2025 21:08:35 -0700
Message-ID: <87fripevjw.fsf@HIDDEN>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: -0.7 (/)
X-Debbugs-Envelope-To: 77460
Cc: mhw@HIDDEN, jonathan.brielmaier@HIDDEN, clement@HIDDEN,
 77460 <at> debbugs.gnu.org
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -1.7 (-)

Hi Andr=C3=A9,

Pushed as 57afbf0bd8.

Thanks!
  -- Ian




Information forwarded to guix-patches@HIDDEN:
bug#77460; Package guix-patches. Full text available.

Message received at submit <at> debbugs.gnu.org:


Received: (at submit) by debbugs.gnu.org; 2 Apr 2025 14:13:50 +0000
From debbugs-submit-bounces <at> debbugs.gnu.org Wed Apr 02 10:13:50 2025
Received: from localhost ([127.0.0.1]:58686 helo=debbugs.gnu.org)
	by debbugs.gnu.org with esmtp (Exim 4.84_2)
	(envelope-from <debbugs-submit-bounces <at> debbugs.gnu.org>)
	id 1tzyqi-0006jw-19
	for submit <at> debbugs.gnu.org; Wed, 02 Apr 2025 10:13:50 -0400
Received: from lists.gnu.org ([2001:470:142::17]:38038)
 by debbugs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.84_2) (envelope-from <nandre@HIDDEN>) id 1tzyqd-0006jU-9h
 for submit <at> debbugs.gnu.org; Wed, 02 Apr 2025 10:13:45 -0400
Received: from eggs.gnu.org ([2001:470:142:3::10])
 by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <nandre@HIDDEN>) id 1tzyqW-0000Cq-BJ
 for guix-patches@HIDDEN; Wed, 02 Apr 2025 10:13:36 -0400
Received: from mx0.riseup.net ([198.252.153.6])
 by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
 (Exim 4.90_1) (envelope-from <nandre@HIDDEN>) id 1tzyqQ-0003eU-6E
 for guix-patches@HIDDEN; Wed, 02 Apr 2025 10:13:36 -0400
Received: from fews02-sea.riseup.net (fews02-sea-pn.riseup.net [10.0.1.112])
 (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
 key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256)
 (No client certificate requested)
 by mx0.riseup.net (Postfix) with ESMTPS id 4ZSRfv5nqRz9vtR
 for <guix-patches@HIDDEN>; Wed,  2 Apr 2025 14:13:27 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=riseup.net; s=squak;
 t=1743603207; bh=rNekkl9U/UM9woTAVdFIw2pM2Ypqc3C92oFKtDR97FQ=;
 h=From:To:Cc:Subject:Date:From;
 b=j+NhoD5g0+pImHBYOZzz7VSkpQy5DZNA4b8/v8BZ0UV1zB1/0DKql7kAMVQNQ6E4h
 s2FhMZ3R/LoQma5vQP2JrXEojUOxsPTHpbmysuyogkK/xQ+iX6FF02huTdf8Xbvtmx
 3rOfnZEM9XI7ZDTOronUmGqjRVgVuDV3eczttkUw=
X-Riseup-User-ID: AC8D1EA50DF539BCF79A5E537AD7A1D275AF40301A7F45FF9AA6112D3D52A730
Received: from [127.0.0.1] (localhost [127.0.0.1])
 by fews02-sea.riseup.net (Postfix) with ESMTPSA id 4ZSRft3fDjzFtcW;
 Wed,  2 Apr 2025 14:13:26 +0000 (UTC)
From: =?UTF-8?q?Andr=C3=A9=20Batista?= <nandre@HIDDEN>
To: guix-patches@HIDDEN
Subject: [PATCH] gnu: torbrowser: Update to 14.0.9 [security-fixes].
Date: Wed,  2 Apr 2025 11:13:04 -0300
Message-ID: <20250402141304.10636-1-nandre@HIDDEN>
MIME-Version: 1.0
X-Debbugs-Cc: clement@HIDDEN, ian@HIDDEN,
 jonathan.brielmaier@HIDDEN, mhw@HIDDEN
Content-Transfer-Encoding: 8bit
Received-SPF: pass client-ip=198.252.153.6; envelope-from=nandre@HIDDEN;
 helo=mx0.riseup.net
X-Spam_score_int: -27
X-Spam_score: -2.8
X-Spam_bar: --
X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1,
 DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1,
 RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001,
 RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_PASS=-0.001,
 T_SPF_TEMPERROR=0.01 autolearn=ham autolearn_force=no
X-Spam_action: no action
X-Spam-Score: 0.0 (/)
X-Debbugs-Envelope-To: submit
Cc: =?UTF-8?q?Andr=C3=A9=20Batista?= <nandre@HIDDEN>
X-BeenThere: debbugs-submit <at> debbugs.gnu.org
X-Mailman-Version: 2.1.18
Precedence: list
List-Id: <debbugs-submit.debbugs.gnu.org>
List-Unsubscribe: <https://debbugs.gnu.org/cgi-bin/mailman/options/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=unsubscribe>
List-Archive: <https://debbugs.gnu.org/cgi-bin/mailman/private/debbugs-submit/>
List-Post: <mailto:debbugs-submit <at> debbugs.gnu.org>
List-Help: <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=help>
List-Subscribe: <https://debbugs.gnu.org/cgi-bin/mailman/listinfo/debbugs-submit>, 
 <mailto:debbugs-submit-request <at> debbugs.gnu.org?subject=subscribe>
Errors-To: debbugs-submit-bounces <at> debbugs.gnu.org
Sender: "Debbugs-submit" <debbugs-submit-bounces <at> debbugs.gnu.org>
X-Spam-Score: -1.0 (-)

Fixes CVEs 2025-3028, 2025-3029, 2025-3030.  See
<https://www.mozilla.org/en-US/security/advisories/mfsa2025-22/>
for details.

* gnu/packages/tor-browsers.scm (%torbrowser-build-date): Update to
20250331180000.
(%torbrowser-version): Update to 14.0.9.
(%torbrowser-firefox-version): Update to 128.9.0esr-14.0-2-build2.
(torbrowser-translation-base): Update to
d687be19490caa48a46a3e2193bda95d57cbb96d.
(torbrowser-translation-specific): Update to
95b60f2679611d39b035f2e45555c2c3d64d991f.

Change-Id: Ia943ebe3f84e06e1c9aa85012ab0a2bf184784ab
---
 gnu/packages/tor-browsers.scm | 18 +++++++++---------
 1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/gnu/packages/tor-browsers.scm b/gnu/packages/tor-browsers.scm
index b9197c0892..450af32eb6 100644
--- a/gnu/packages/tor-browsers.scm
+++ b/gnu/packages/tor-browsers.scm
@@ -116,16 +116,16 @@ (define firefox-locales
 
 ;; We copy the official build id, which is defined at
 ;; tor-browser-build/rbm.conf (browser_release_date).
-(define %torbrowser-build-date "20250303093702")
+(define %torbrowser-build-date "20250331180000")
 
 ;; To find the last version, look at https://www.torproject.org/download/.
-(define %torbrowser-version "14.0.7")
+(define %torbrowser-version "14.0.9")
 
 ;; To find the last Firefox version, browse
 ;; https://archive.torproject.org/tor-package-archive/torbrowser/<%torbrowser-version>
 ;; There should be only one archive that starts with
 ;; "src-firefox-tor-browser-".
-(define %torbrowser-firefox-version "128.8.0esr-14.0-1-build2")
+(define %torbrowser-firefox-version "128.9.0esr-14.0-2-build2")
 
 ;; See tor-browser-build/rbm.conf for the list.
 (define %torbrowser-locales (list "ar" "ca" "cs" "da" "de" "el" "es-ES" "fa" "fi" "fr"
@@ -139,11 +139,11 @@ (define torbrowser-translation-base
     (method git-fetch)
     (uri (git-reference
           (url "https://gitlab.torproject.org/tpo/translation.git")
-          (commit "21fed48fc58df9e6c4d9f67b048fcae831df50c9")))
+          (commit "d687be19490caa48a46a3e2193bda95d57cbb96d")))
     (file-name "translation-base-browser")
     (sha256
      (base32
-      "1gs2b9bak7rglpbswkm47jwj3yd76361xblvyxjfsbji9igjj7za"))))
+      "0hb4v0d898h7zxg9iwjvxjzh776wa65inysh4wdla51r0ib91w1b"))))
 
 ;; See tor-browser-build/projects/translation/config.
 (define torbrowser-translation-specific
@@ -151,11 +151,11 @@ (define torbrowser-translation-specific
     (method git-fetch)
     (uri (git-reference
           (url "https://gitlab.torproject.org/tpo/translation.git")
-          (commit "100908b702f92bc001b69cdd70f96a6e63134516")))
+          (commit "95b60f2679611d39b035f2e45555c2c3d64d991f")))
     (file-name "translation-tor-browser")
     (sha256
      (base32
-      "0shlxk55rj9lfw3mrax84zsalrpsbrjc85287ah90cys2lw6d1dx"))))
+      "1lvdy586v0p84lilvx1z0x5y6ng1yy6aw12lg3xphfh0kr1ygi16"))))
 
 (define torbrowser-assets
   ;; This is a prebuilt Torbrowser from which we take the assets we need.
@@ -171,7 +171,7 @@ (define torbrowser-assets
          version "/tor-browser-linux-x86_64-" version ".tar.xz"))
        (sha256
         (base32
-         "0fmh2j6nwi5q7kw3grkwm2lrgig1m4sk6ai70zjy4dbaa3xmc6h9"))))
+         "1s65fr8crhlmgx449686f0s5k28gjia9wdq6d5rhif3d3r696cx1"))))
     (arguments
      (list
       #:install-plan
@@ -213,7 +213,7 @@ (define* (make-torbrowser #:key
          ".tar.xz"))
        (sha256
         (base32
-         "0h5cgwrdavcr4nbg8girdxcdfqd9vfmsjwmjdbrz9zv63dparhwp"))))
+         "1jq6jaiwr2jk7ayylnaha7rqk9g14ryybld817zhcqpldr0xmvyr"))))
     (build-system mozilla-build-system)
     (inputs
      (list lyrebird

base-commit: 5735c278e16517d9be5e26235fe68dea9bae3527
-- 
2.48.1





Acknowledgement sent to André Batista <nandre@HIDDEN>:
New bug report received and forwarded. Copy sent to clement@HIDDEN, ian@HIDDEN, jonathan.brielmaier@HIDDEN, mhw@HIDDEN, guix-patches@HIDDEN. Full text available.
Report forwarded to clement@HIDDEN, ian@HIDDEN, jonathan.brielmaier@HIDDEN, mhw@HIDDEN, guix-patches@HIDDEN:
bug#77460; Package guix-patches. Full text available.
Please note: This is a static page, with minimal formatting, updated once a day.
Click here to see this page with the latest information and nicer formatting.
Last modified: Thu, 3 Apr 2025 04:15:02 UTC

GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997 nCipher Corporation Ltd, 1994-97 Ian Jackson.