changelog 330 KB
Newer Older
intrigeri's avatar
intrigeri committed
1 2
tails (3.2) UNRELEASED; urgency=medium

anonym's avatar
anonym committed
3 4 5 6 7
  * Major changes
    - Upgrade Linux packages to the Debian kernel 4.12.0-2, based on
      mainline Linux 4.12.12 (Closes: #12732, #14673).

  * Security fixes
anonym's avatar
anonym committed
8
    - Upgrade Tor Browser to 7.0.6-build3 (Closes: #14696).
anonym's avatar
anonym committed
9 10 11 12 13 14 15 16 17 18 19 20 21
    - Upgrade to Thunderbird 52.3.0 (Closes: #12639).
    - Deny access to Pidgin's D-Bus service (Closes: #14612). That D-Bus
      interface is dangerous because it allows _any_ application running
      as `amnesia' that has access to the session bus to extract
      basically any information from Pidgin and to reconfigure it:
      https://developer.pidgin.im/wiki/DbusHowto
    - Block loading of Bluetooth kernel modules (Closes: #14655) and
      block Bluetooth devices with rfkill (Closes: #14655).
    - Add localhost.localdomain to the hosts file to prevent loopback
      leaks to Tor circuits (Closes: #13574). Thanks to tailshark for
      the patch!

  * Minor improvements
anonym's avatar
anonym committed
22
    - Upgrade to Tails Installer 5.0.1 (Closes: #8859, #8860). This
anonym's avatar
anonym committed
23 24
      version gets rid of the splash screen, detects when Tails is already
      installed on the target device (and then proposes to upgrade),
anonym's avatar
anonym committed
25 26 27
      and generally improves the UX.
    - Deprecate Thunderbird's preferences/0000tails.js (Closes: #12680).
    - Install the BookletImposer PDF imposition toolkit (Closes: #12686).
anonym's avatar
anonym committed
28 29 30 31
    - Tor Browser:
      * Fallback to ~/Tor Browser for uploads (Closes: #8917).
      * Silence some common operations that always are denied and
        otherwise would spam the journal (Closes: #14606)
anonym's avatar
anonym committed
32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111
    - Shell library: remove now unused functions (Closes: #12685).
    - Add pppoe to the installed packages (Closes #13463). Thanks to geb
      for the patch!
    - Replace syslinux:i386 with syslinux:amd64 in the ISO9660
      filesystem (Closes: #13513).
    - htpdate: fix date header regexp (Closes: #10495). It seems that
      some servers (sometimes) do not send their headers with first
      letter uppercased, hence a lot of failures to find the date in it.
    - Install aufs-dkms from Debian unstable (Closes: #12732).
    - Install vim-tiny instead of vim-nox (Closes: #12687). On Stretch,
      vim-nox started pulling ruby and rake in the ISO. I think vim-tiny
      would be good enough, and would save a few MiB in the ISO. Those
      who use vim more intensively and want another flavour of vim are
      likely to need persistence anyway, and can thus install a more
      featureful vim with the additional software packages feature.
    - Remove gksu and its and gconf's dependencies (Closes: #12738). We
      use pkexec instead of gksudo. gksu is unmaintained, buggy
      (e.g. #12000), and it is the only reason we ship GConf, which we
      want to remove. The other removals are:
      * libgnomevfs2-extra, which was previously used for SSH/FTP support in
        Nautilus, but isn't needed for that any more.
      * libgnome2-bin which provides gnome-open, which isn't required by
        any application in Tails (as far as we know).
      * Configurations and scripts that become obsolete because of these
        removals.
    - Refresh torbrowser-AppArmor-profile.patch to apply cleanly on top
      of torbrowser-launcher 0.2.8-1 (Closes: #14602).
    - Switch from Florence to GNOME's on-screen keyboard (Closes: #8281)
      and incidentally improve accessibility in GTK+ 2.0 and Qt
      applications. This drops Florence and the corresponding GNOME
      Shell extension.
    - Make ./HACKING.mdwn a symlink again (Closes: #13600).
    - Implement refresh-translations --force .
    - Rework how we handle the individual POT files of our applications.
      Comparing the new temporary POT files we generate with the
      temporary POT files we generated last time (if ever, and if we
      did, for which branch?) is not relevant; these POT files are only
      used for merging into a new tails.pot and *that* one is relevant
      to diff against the old tails.pot.
    - Reproducibility:
      * Ensure reproducible permissions for /etc/hostname (Closes:
        #13623).
      * Patch desktop-file-utils to make its mimeinfo.cache reproducible
        (Closes: #13439).
      * Patch glib2.0 to make its giomodule.cache reproducible (Closes:
        #13441).
      * Patch gdk-pixbuf to make its loaders.cache reproducible (Closes:
        #13442).
      * Patch gtk2.0 and gtk3.0 to make their immodules.cache
        reproducible (Closes: #13440).
      * Remove GCconf: it is a source of non-determinism in the
        filesystem (element order in /var/lib/gconf/defaults/%gconf-tree-*.xml)
        which made Tails unreproducible.
      * Ignore comment updates in POT files, which was a source of
        non-determinism and therefore prevented Tails from being
        reproducible (Closes: #12641).
    - Kernel hardening:
      * Increase mmap randomization to the maximum supported value
        (Closes: #11840). This improves ASLR effectiveness, and makes
        address-space fragmentation a bit worse.
      * Stop explicitly enabling kaslr: it's enabled by default in
        Debian, and this kernel parameter is not supported anymore.
      * Disable kexec, to make our attack surface a bit smaller.

  * Bugfixes
    - Start Nautilus silently in the background when run as root
      (Closes: #12034). Otherwise, after closing Nautilus one gets the
      prompt back only after 5-15 seconds, which confuses users and makes
      our doc more complicated than it should.
    - Ensure pinentry-gtk2 run by Seahorse has the correct $DISPLAY set
      (Closes: #12733).

  * Build system
    - build-manifest-extra-packages.yml: remove squashfs-tools version
      we don't use anymore (Closes: #12684). Apparently our
      apt-get/debootstrap wrapper tricks are enough to detect the
      version of squashfs-tools we actually install and use.
    - Merge base branch earlier, i.e. in auto/config instead of
      auto/build (Closes: #14459). Previously, a given build from a topic
      branch would mix inconsistent versions of things.
anonym's avatar
anonym committed
112 113 114 115 116 117 118 119
    - Fail builds started before SOURCE_DATE_EPOCH (Closes:
      #12352). Such builds would not be reproducible, and this is an
      assumption (a reasonable one!) that we do all over the place, so
      let's fail early. While we're at it, let's fail if
      SOURCE_DATE_EPOCH is not set as well. Actually we would fail any
      way if that was the case when reaching our
      99-zzzzzz_reproducible-builds-post-processing build hook, but
      let's fail early.
anonym's avatar
anonym committed
120 121 122

  * Test suite
    - Test the GNOME Root Terminal.
anonym's avatar
anonym committed
123
    - Take into account that Tails Installer 5.0.1 refuses to install
anonym's avatar
anonym committed
124 125 126 127 128 129 130 131 132 133 134
      Tails to devices smaller than 8 GiB. It'll still allow *upgrading*
      such sticks though.
    - Use 7200 MiB virtual USB drives when we really mean 8 GiB. In the
      real world, USB sticks labeled "8 GB" can be much smaller, so
      Tails Installer will accept anything that's at least 7200 MiB.
      This commit makes us exercise something closer to what happens in
      the real world, and incidentally it'll save storage space on our
      isotesters and improve test suite performance a bit. :)
    - Have unclutter poll every 0.1s instead of continuously. On current
      sid, virt-viewer eats a full CPU and doesn't do its job when
      "unclutter -idle 0" is running.
anonym's avatar
anonym committed
135
    - Adapt tests for Tails Installer 5.0.1.
anonym's avatar
anonym committed
136 137 138
    - Workaround Pidgin's DBus interface being blocked since we actually
      depend on it for some tests.
    - Test that Pidgin's DBus interface is blocked.
anonym's avatar
anonym committed
139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156
    - Save more data on test suite failures (Refs: #13541):
      * When Tor fails to bootstrap, save Tor logs and chutney nodes
        data.
      * When Htpdate fails to synchronize the clock, save its logs.
      * Always save the systemd journal on failure.
    - When testing emergency shutdown, wait longer for Tails to tell
      us it has finished wiping the memory. The goal here is to help
      us understand whether (Refs: #13462) is a bug in the emergency
      shutdown feature or in our test suite.
    - Restart nautilus-desktop if Desktop icons are not visible
      (Closes: #13461).
    - Test suite: fix assert_raise() when using ruby-test-unit >=
      3.2.5 (Closes: #14654). ruby-test-unit 3.2.5 added native Java
      exception support for JRuby. The fact we defined the :Java
      constant was enough to trigger that JRuby-specific code, which
      failed.
    - Test suite: take into account that click-to-play is not required
      anymore for WebM videos in Tor Browser (Closes: #14586).
intrigeri's avatar
intrigeri committed
157

anonym's avatar
anonym committed
158
 -- Tails developers <tails@boum.org>  Mon, 25 Sep 2017 19:58:21 +0200
intrigeri's avatar
intrigeri committed
159

160 161 162 163 164 165
tails (3.1.1) UNRELEASED; urgency=medium

  * Dummy entry for next release.

 -- Tails developers <tails@boum.org>  Wed, 09 Aug 2017 15:24:41 +0200

bertagaz's avatar
bertagaz committed
166
tails (3.1) unstable; urgency=medium
intrigeri's avatar
intrigeri committed
167

bertagaz's avatar
bertagaz committed
168 169
  * Security fixes
    - Upgrade Tor Browser to 7.0.4-build1 (Closes: #13577).
bertagaz's avatar
bertagaz committed
170
    - Upgrade Linux to 4.9.30-2+deb9u3.
bertagaz's avatar
bertagaz committed
171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201
    - Upgrade libtiff to 4.0.8-2+deb9u1.
    - Upgrade bind9 to 1:9.10.3.dfsg.P4-12.3+deb9u2.
    - Upgrate evince to 3.22.1-3+deb9u1.
    - Upgrade imagemagick 8:6.9.7.4+dfsg-11+deb9u1.
    - Ensure Thunderbird cleans its temporary directory. (Closes: #13340).

  * Minor improvements
    - Patch gconf to produce reproducible XML output (refs: #12738). This is
      the temporary solution for #12738 in Tails 3.1 which will be reverted
      (and fixed permanently by removing gconf) in Tails 3.2.
    - Apply Debian bts patch to cracklib to produce reproducible dictionnaries
      (Closes: #12909).
    - Upgrade to Debian 9.1 (Closes: #13178).

  * Bugfixes
    - Replace faulty URL in htpdate neutral pool (Closes: #13472).
    - Keep installing a version of Enigmail compatible with Thunderbird 45.x
      (Closes: #13530).
    - Fix the time syncing and Tor notifications translations (Closes: #13437).

  * Build system
    - Upgrade the Vagrant basebox for building ISO images to Stretch
      (Closes: #11738).
    - Fix on-disk build by bumping Vagrant build VM memory to 768M
      (Closes: #13480).
    - Fix rescue build option by exporting TAILS_BUILD_FAILURE_RESCUE
      (Closes: #13476).

  * Test suite
    - mark gnome screenshot scenario as fragile (refs: #13458)
    - mark UEFI scenario as fragile (refs: #13459).
intrigeri's avatar
intrigeri committed
202

203
 -- Tails developers <tails@boum.org>  Sat, 05 Aug 2017 15:25:51 +0200
intrigeri's avatar
intrigeri committed
204

anonym's avatar
anonym committed
205
tails (3.0.1) unstable; urgency=medium
intrigeri's avatar
intrigeri committed
206

anonym's avatar
anonym committed
207 208 209 210 211 212 213
  * Security fixes
    - Upgrade tor to 0.3.0.9-1~d90.stretch+1 (Closes: #13253).
    - Upgrade Linux to 4.9.30-2+deb9u2.
    - Upgrade libc to 2.24-11+deb9u1.
    - Upgrade libexpat1 to 2.2.0-2+deb9u1.
    - Upgrade libgcrypt20 to 1.7.6-2+deb9u1.
    - Upgrade libgnutls30 to 3.5.8-5+deb9u1.
intrigeri's avatar
intrigeri committed
214
    - Enable Debian security APT sources (Closes: #12309).
intrigeri's avatar
intrigeri committed
215

anonym's avatar
anonym committed
216 217 218 219 220
  * Minor improvements
    - Use a higher resolution image in Tails persistence setup
      (Closes: #12510).

  * Bugfixes
221
    - Forcibly set $SSH_AUTH_SOCK before starting GNOME
anonym's avatar
anonym committed
222 223 224 225 226 227 228
      Shell. Apparently, due to a race condition, GNOME keyring
      sometimes fails to tell the session manager about the correct
      SSH_AUTH_SOCK, and thus GNOME Terminal hasn't this variable set
      and any ssh process started in there won't use the (perfectly
      working) SSH agent (Closes: #12481).
    - Fix issue that made Tails Installer rejects working USB drives,
      pretending they're not "removable" (Closes: #12696).
229
    - Make behavior of the power button and lid close actions in the Greeter
anonym's avatar
anonym committed
230 231 232 233 234 235 236 237 238
      consistent with the regular GNOME session (Closes: #13000).

  * Build system
    - Track the latest debian-security archive for the corresponding
      APT sources, and not for the unrelated jessie-updates (Closes:
      #12829).
    - Print APT sources used in the build VM, to help debugging issues
      such as #12829.

anonym's avatar
anonym committed
239
 -- Tails developers <tails@boum.org>  Tue, 04 Jul 2017 15:59:18 +0200
intrigeri's avatar
intrigeri committed
240

intrigeri's avatar
intrigeri committed
241
tails (3.0) unstable; urgency=medium
242

intrigeri's avatar
intrigeri committed
243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332
  * Major changes
    - Upgrade Tor Browser to 7.0.1 (Closes: #12635, #12657).
    - Upgrade to a new snapshot of the Debian and Torproject
      APT repositories: respectively 2017060904 and 2017060903
      (Closes: #12609).

  * Minor improvements
    - Tor Browser: enable Electrolysis (e10s), i.e. render content in a separate
      child process, which will allow to improve performance and security
      further along the road. This required us to drop our branding add-on
      and re-implement its functionality in our Tor Browser wrapper
      (Closes: #12569).
    - Clean obsolete cached packages when using the Additional Software Packages
      feature (Closes: #12400).
    - Improve KeePassX database migration handling (Closes: #12375).
    - Upgrade OnionShare to 0.9.2, from Debian sid as it has been removed
      from Stretch (Closes: #12610).
    - Upgrade Tor to 0.3.0.8 (Closes: #12656).
    - Drop obsolete bilibop patch, that was applied in 0.5.2.1.
    - Include disk space usage information in the WhisperBack bug reports.
    - Reorder technical details in WhisperBack bug reports in way that makes
      more sense when reading them.
    - Convert lc.py to Python 3.
    - Simplify some Python code thanks to subprocess.check_ouput.
    - Set the initial keyboard focus on the "Start Tails" button
      in Tails Greeter (Closes: #12509).
    - Convert Tails Greeter's Debian packaging to current best practices.

  * Bugfixes
    - Fix persistent Thunderbird configuration migration when there is
      a mimeTypes.rdf, that doesn't contain any associations to "icedove"
      or "/usr/bin/iceweasel" (Closes: #12580).
    - Fix persistent browser bookmarks, by generating them from an sqlite dump
      (Closes: #12568).
    - Use the "intel" X.Org driver for Intel Atom/Celeron/Pentium Processor
      x5-E8000/J3xxx/N3xxx Integrated Graphics Controller.
    - `exec' from our Thunderbird wrapper so it doesn't remain running.
    - Tails Installer: don't allow installing on non-removable drives
      (Closes: #10731).
    - Fetch the torbrowser-launcher sources from Debian sid:
      it's been removed from Debian testing.
      Refresh torbrowser-AppArmor-profile.patch accordingly.
    - Unsafe Browser: remove the search bar, that's currently buggy
      and its presence only encourages unsupported usage (Closes: #12573).
    - Unsafe Browser: disable searching in the address bar. It can result
      in leaking hostnames and credentials to the default search
      engine operator (Closes: #12540).
    - Make our omni.ja modifications reproducible (Closes: #12620).
    - Generate the fontconfig cache in a reproducible manner (Closes: #12567).
    - Don't include torrents/rss.html in the ISO. It's not generated
      in a deterministic manner and is worthless in the ISO (Closes: #12619).
    - Improve the language → default keyboard layout mapping
      in Tails Greeter (Closes: #12547).
    - Don't close Tails Greeter's main window when Alt-F4 is pressed
      (Closes: #12462).

  * Test suite
    - Run emergency_shutdown.feature after usb_*.feature, to reduce disk
      space requirements (Closes: #12565).
    - Deal with server messages in Pidgin.
    - Improve Pidgin connectivity check robustness.
    - Flag the Synaptic test as fragile (i.e. #12586).
    - Optimization: only test once that Tails, booted on DVD, eventually
      shuts down after wiping memory.
    - Move tests about the shutdown applet to a dedicated feature,
      as they have nothing to do with Tails' "emergency" shutdown feature.
    - Adapt the network connectivity check to Stretch, and improve it to check
      both link and IP connectivity (Closes: #12602).
    - Apply a fix from upstream Git to mutter, to fix some of its interactions
      with dogtail (Closes: #11718).
    - Mark "Scenario: Watching a WebM video" as fragile (i.e. #10442).

  * Build system
    - Set create_box -e, to make the vagrant box generation a bit more robust.
      (Closes: #12578).
    - Install kernel from backports and Tails build deps before performing
      APT upgrade, to avoid useless bandwidth usage (Closes: #12529).
    - Update submodules after merging the base branch (Closes: #12556).
    - Rakefile: fix date comparison in basebox:clean_old (Closes: #12575).
    - Rakefile: have basebox:clean_old delete baseboxes more than 4 months old
      (refs: #12576).
    - Also check for fuzzy patches' .orig files at the end of our build hooks,
      so we detect any fuzzy patches applied by hooks (Closes: #12617).
    - Remove .orig files for patches we allow to be fuzzy.
    - Don't pre-build the wiki when mergebasebranch is enabled.
      When pre-building the wiki, we modify the PO files which results in a
      conflict from the base branch merge in case it modifies the same
      files, which breaks the build (Closes: #12611).
    - Rakefile: add a task that removes all tails-builder-* libvirt volumes
      (Closes: #12599).
333

intrigeri's avatar
intrigeri committed
334
 -- Tails developers <tails@boum.org>  Sat, 10 Jun 2017 14:39:10 +0000
335

anonym's avatar
anonym committed
336
tails (3.0~rc1) unstable; urgency=medium
337

338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353
  * Major changes
    - Install Thunderbird 1:45.8.0-3+tails2 and handle the Icedove  Thunderbird
      migration, including wrt. persistent data (Closes: #11712, #12242).
      This package also has the patch from
      https://bugzilla.mozilla.org/show_bug.cgi?id=1281959 applied,
      to ease future integration of the Thunderbird AppArmor profile.
      Also, drop the Claws  Icedove migration path.
    - Upgrade to a new snapshot of the Debian and Torproject
      APT repositories: 2017051803 (Closes: #12554).
    - Upgrade Linux packages to the Debian kernel 4.9.0-3, based on
      mainline Linux 4.9.25.
    - Replace the kexec-based memory erasure feature with the Linux kernel's
      memory poisoning (Closes: #12354, #12428). The kexec-based implementation
      was not reliable enough and provided a poor UX. Instead, we now return
      to the initramfs on shutdown and unmount all filesystems there, so their
      content and corresponding caches are erased.
354 355 356 357 358 359
    - Upgrade Tor Browser to 7.0a4 based on Firefox 52.1.1esr (Closes:
      #12115, #12464):
      * Unfortunately e10s (multi-process Firefox) is disabled (#12569).
      * Unfortunately persistent bookmarks created for the first time
        in Tails 3.0~rc1 is broken (#12568).
      * Adds exceptions for the extensions Tails installs on top of
360
        the vanilla Tor Browser (Closes: #11419).
361 362 363 364 365
    - Upgrade tor to 0.3.0.7-1 (Closes: #12485) and log both to the
      usual file and the journal (Closes: #12412).
    - Merge the code that makes Tails almost build reproducibly (Refs:
      #5630); we still have issues with the fontconfig cache (Refs:
      #12567).
366 367

  * Minor improvements
368 369 370 371 372
    - Add a HACKING document for new code contributors (Closes:
      #12164).
    - Rename tor-controlport-filter to onion-grater (Closes: #12394)
      and import patches killing the delta against Whonix version
      (Closes: #12173).
373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400
    - Improve onion-grater; thanks to Joy SN <joysn1980@yahoo.com>
      for the original patches (Closes: #12173):
      · add --listen-interface
      · make stdout/stderr unbuffered to ensure Python exceptions are logged
      · use yaml.safe_load()
    - Improve KeePassX database migration handling (refs: #12375).
    - Electrum: set coin selection strategy to 'Privacy' (Closes: #12177).
    - Allow Onion Circuits to access /proc/pid/status.
    - Make gdm-shell-tails.desktop more similar to the one shipped
      in gnome-shell 3.22.3-3 (refs: #12364).
    - Greeter: have the help window point to updated documentation,
      use WebKit2 instead of the deprecated WebKit, and hide the sidebar
      and banner.
    - Use exec to start KeePassX, i.e. avoid leaving the wrapper running.

  * Bugfixes
    - Install xserver-xorg-legacy, to fix support for various graphics
      adapters that still don't work with rootless X.Org (Closes: #12542).
    - Use the "intel" X.Org driver for Intel Q35 and Intel Atom
      D4xx/D5xx/N4xx/N5xx graphics controllers (refs: #12219).
    - Give UEFI bootloaders upper-case filenames (Closes: #12511).
      Some UEFI firmware, such as the one in the ThinkPad X220, only recognize
      them if they have an upper-case name.
    - KeePassX: enable "Automatically save after each change" again,
      like we did in Tails 2.x (fixes a regression introduced
      in 3.0~beta3).
    - Install packages needed by the "Test speakers" functionality
      (Closes: #12549).
401 402
    - Fix automatic upgrades when one is already applied (Closed:
      #12501).
403
    - When generating the network device blacklist, also blacklist
intrigeri's avatar
intrigeri committed
404
      network drivers from the staging directory (Closes: #12362).
405 406 407
    - htpdate pool: replace www.sarava.org with leap.se. The former
      has been down for a while and it's not clear when it's going to
      be stable again. The latter should be reliable.
408 409 410 411 412 413 414 415 416 417 418 419 420 421 422

  * Test suite
    - Check that dirmngr used the configured keyserver (Closes: #12371).
    - Sanity check that Chutney starts all nodes in the network.
    - Disable the Sandbox option for all nodes, until Tor#21943
      is fixed (Closes: #12512).
    - Wait for the desktop icons to be displayed in the "Tails desktop is ready"
      step. Let's not try interacting with the desktop earlier.
    - Add tests for memory erasure on "normal" shutdown (refs: #12428).
    - Add tests for memory erasure on "emergency" shutdown, and run some
      with network enabled (refs: #12354).
    - Have eject_cdrom run eject(1) like it used to do in the past.
      Otherwise the machine is immediately halted and we cannot test
      whether memory has been erased.
    - Pass mount_USB_drive structured data instead of free-form text.
423 424
    - Test that MAC spoofing and "Disable network" works for
      hotplugged networking devices (Refs: #12362).
425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460

  * Build system
    - Generate the Vagrant base box locally as part of the build process,
      instead of downloading it: one less binary blob as input in the build
      process (refs: #12409).
    - Use Vagrant for builds on Jenkins too (Closes: #11972).
    - Tell build script to be more verbose.
    - Respect the 'ARTIFACTS' environment variable if set.
    - Add a second disk to handle the apt-cacher-ng cache, and store
      the corresponding logs in there (Closes: #11979).
    - Use APT snapshots in Vagrant build VMs, create/use a basebox that matches
      the branch/tag/commit being tested, and provision a new VM for each build
      (Closes: #11980, #11981).
    - Ship all build dependencies in the Vagrant basebox, to save some
      time when building ISOs.
    - Make basebox generation compatible with both GnuPG 1.x and 2.x.
    - Set LC_ALL=C, mostly to suppress some warnings.
    - Support forcing VM cleanup before/after build.
    - Add tasks for cleaning up old or all base boxes (refs: #12409).
    - Add build option useful for debugging build failures.
    - Remove obsolete build options.
    - Make auto/scripts/utils.sh more reusable, use it in Rakefile,
      auto/build and setup-tails-builder.
    - Add an option controlling whether to merge the base branch.
    - Add "rake test" target and import logics from puppet-tails'
      wrap_test_suite script.
    - Build Tails as a release simply when HEAD is tagged, i.e. we do not
      require building from a detached head any more.
    - Sanity check compression choice when building a release.
    - Use the host's resolv.conf when building the Vagrant base box.
      Since systemd-networkd is used to manage resolv.conf inside the base box,
      and it hasn't been initialized yet (we are not booting it, just chrooting
      into it) DNS is broken otherwise.
    - Release process: "release" a new base box when freezing.
    - Chown/scp artifacts with a single command to limit overhead and warnings
      noise caused by repeated SSH calls.
461 462 463
    - Add a build options to use a custom CPU model, and custom
      machine type, for reproducibility testing (refs: #12345).
    - Add support for installing Tor Browser nightly builds.
464

anonym's avatar
anonym committed
465
 -- Tails developers <tails@boum.org>  Sat, 20 May 2017 16:48:45 +0200
466

intrigeri's avatar
intrigeri committed
467
tails (3.0~beta4) unstable; urgency=medium
anonym's avatar
anonym committed
468

intrigeri's avatar
intrigeri committed
469 470 471 472
  * Major changes
    - All changes brought by Tails 2.12.
    - Upgrade to a new snapshot of the Debian and Torproject
      APT repositories (2017041704).
intrigeri's avatar
intrigeri committed
473 474 475 476

  * Security improvements
    - Enable the buddy page allocator free poisoning (Closes: #12089).
    - Enable slub/slab allocator free poisoning (Closes: #12090).
intrigeri's avatar
intrigeri committed
477 478
    - Create IUKs (automatic upgrades) in a reproducible manner
      (Closes: #11974).
intrigeri's avatar
intrigeri committed
479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527

  * Minor improvements
    - Firewall: forbid the _apt user to talk to DNS ports. APT works very well
      without DNS access since we only have Onion APT sources, so let's silence
      the logs.
    - Replace Pidgin's "systray" icon with the guifications plugin
      (Closes: #11741). We're trying to remove as much as we can from
      the set of icons managed by TopIcons extension flavours, in the hope
      it's enough to cancel the problems we've seen with them (#10576, #11737).
    - Disable apt-daily.timer, that can only cause problems in our context
      (Closes: #12390).
    - Do not let pppd-dns manage /etc/resolv.conf (Closes: #12401).
    - Ensure rootless X.Org can access /dev/fb0 when started by GDM.
    - Include the amdgpu module in the initramfs (refs: #12218).
    - Tails Greeter: don't mention 'firewall' anymore (#12382).
    - Tails Greeter: avoid the popover menu for Formats being cut,
      in most cases (Closes: #12249).
    - Tails Greeter: disable the screensaver (Closes: #12370).
    - Tails Greeter: fix behavior when pressing Enter in the language selection
      menu (Closes: #12359).

  * Bugfixes
    - Install speech-dispatcher-espeak-ng to fix the Orca screen reader
      (Closes: #12389).
    - Install xserver-xorg-video-intel and use it on a few graphics adapters
      that are not supported correctly by the modesetting driver (refs: #12219).
      More PCI IDs will be added as new affected hardware is reported.

  * Test suite
    - Run on a Q35 2.8 machine (Closes: #11605).
    - Deprecate xtightvncviewer in favor of tigervnc-viewer.
    - Test the Unsafe Browser in 3 random supported languages, not all.
      This should be enough to identify most future regressions in this area,
      and will be much faster than testing them all.
    - Pidgin tests: switch to an image that doesn't depend on the
      topic of tails@conference.riseup.net.
    - Fix a problematic use of try_for.
    - Fix VM.select_virtual_desktop() and VM.do_focus().
    - Random Gherkin improvements.
    - Fix a focus issue for GNOME Terminal vs. Tails Installer.
    - Adjust to kernel memory poisoning being enabled, which breaks the way
      we used to test memory erasure (refs: #12354):
      · Drop "no memory erasure" and "memory erasure" tests, that can't work
        anymore.
      · Test erasure of memory freed by a killed userspace process.
      · Test that memory poisoning applies to unmounted tmpfs.
      · Test that memory poisoning applies to read and write cache
        for unmounted vfat and LUKS-encrypted ext4.
      · Run erase_memory a bit later, it requires less disk space nowadays.
anonym's avatar
anonym committed
528

intrigeri's avatar
intrigeri committed
529
 -- Tails developers <tails@boum.org>  Tue, 18 Apr 2017 13:01:25 +0000
anonym's avatar
anonym committed
530

anonym's avatar
anonym committed
531
tails (2.12) unstable; urgency=medium
anonym's avatar
anonym committed
532

anonym's avatar
anonym committed
533 534 535 536
  * Major changes
    - Completely remove I2P. :( We have decided to remove I2P (see
      #11276) due to our failure of finding someone interested in
      maintaining it in Tails (Closes: #12263).
537
    - Upgrade the Linux kernel to 4.9.13-1~bpo8+1 (Closes: #12122).
anonym's avatar
anonym committed
538

anonym's avatar
anonym committed
539
  * Security fixes
anonym's avatar
anonym committed
540 541
    - Upgrade Tor Browser to 6.5.2 based on Firefox 45.9. (Closes:
      #12444)
anonym's avatar
anonym committed
542 543 544 545 546 547 548 549 550 551 552 553
    - Mount a dedicated filesystem on /var/tmp, to mitigate the
      hardlinks permissions open by the user-tmp abstraction. See
      https://labs.riseup.net/code/issues/9949#note-23 for details
      (Closes: #12125).
    - Protect against CVE-2017-2636 by disabling the n-hdlc kernel
      module (Closes: #12315).
    - Ensure /etc/resolv.conf is owned by root:root in the SquashFS.
      lb_chroot_resolv will "cp -a" it from the source tree, so it
      inherits its ownership from the whoever cloned the Git
      repository. This has two problems. First, this results in unsafe
      permissions on this file (e.g. a Vagrant build results in the
      'amnesia' user having write access to it).
anonym's avatar
anonym committed
554 555 556 557 558 559 560
    - Upgrade libjasper1 to 1.900.1-debian1-2.4+deb8u3
    - Upgrade gstreamer and its plugins to 1.4.4-2+deb8u1.
    - Upgrade eject to 2.1.5+deb1+cvs20081104-13.1+deb8u1.
    - Upgrade imagemagick to 8:6.8.9.9-5+deb8u8.
    - Upgrade pidgin to 2.11.0-0+deb8u2.
    - Upgrade samba to 2:4.2.14+dfsg-0+deb8u5.

anonym's avatar
anonym committed
561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589

  * Minor improvements
    - Don't add the live user to the "audio" group. This should not be
      needed on a modern Linux desktop system anymore (Closes:
      #12209).
    - Install virtualbox-* 5.1.14-dfsg-3~bpo8+1 from our custom APT
      repository (Closes: #12307).
    - Install virtualbox-guest-* from sid. The version currently in
      jessie-backports is not compatible with Linux 4.9, and there's
      basically no chance that it gets updated (the maintainer asked
      for them to be *removed* from jessie-backports) (Closes:
      #12298).
    - Pull ttdnsd from our custom APT repository. It's gone from the
      TorProject one. We removed ttdnsd on feature/stretch already, so
      we'll need to pull it from our custom APT repository only for
      the next 3 months.
    - Clean up libdvd-pkg build files, again.  This cleanup operation
      was mistakenly removed in commit c4e8744 (Closes: #11273).
    - Install gnome-sound-recorder (Closes #10950). Thanks to Austin
      English <austinenglish@gmail.com> for the patch!
    - Stop restarting tor if bootstrapping stalls. It seems tor might
      have fixed the issues we used (see: #10238, #9516) to experience
      with the bootstrap process stalling and requiring a restart to
      kickstart it (Closes: #12411).
    - tor.sh: communicate via the UNIX socket instead of TCP port.
      This makes the library usable when run inside systemd units that
      have `PrivateNetwork=yes` set.
    - Get tor's bootstrap progress via GETINFO instead of log
      grep:ing.
anonym's avatar
anonym committed
590
    - Upgrade tor to 0.2.9.10-1~d80.jessie+1
anonym's avatar
anonym committed
591 592 593 594 595 596

  * Bugfixes
    - mirror-pool-dispatcher: bump maximum expected mirrors.json size
      to 32 KiB. This fixes an error where Tails Upgrader would
      complain with "cannot choose a download server" (Closes:
      #11735).
anonym's avatar
anonym committed
597

anonym's avatar
anonym committed
598 599 600 601 602 603 604 605 606 607 608
  * Build system
    - Retry curl and APT operations up to 20 times to make the ISO
      build more robust wrt. unreliable Internet connectivity. Thanks
      to Arnaud <arnaud@preev.io> for the patch!
    - Install ikiwiki from jessie-backports, instead of our patched
      one. Our changes were merged in 3.20161219, and jessie-backports
      now has 3.20170111~bpo8+1 (Closes: #12051).
    - Fix FTBFS when installing a .deb via config/chroot_local-packages
      by being more flexible when matching local packages in the apt
      list file (Closes: #12374). Thanks to Arnaud <arnaud@preev.io>
      for the patch!
anonym's avatar
anonym committed
609
    - auto/build: support Stretch's GnuPG v2 keyring filename.
anonym's avatar
anonym committed
610

anonym's avatar
anonym committed
611 612 613 614 615 616 617 618 619 620 621 622 623 624
  * Test suite
    - Try possible fix for #11508. IPv6Packet:s' source is accessed by
      `.ipv6_saddr`, not `ip_saddr` (that's for IPv4Packet). So, let's
      just try and see which one of the two each packet has, because
      one of them must be there! Also, given that UDPPacket can be
      either IPv4 or IPv6 it seems safest to try to parse each packet
      as IPv6Packet first -- that way we keep looking at transport
      layer protocols for IPv4 only, and treat everything IPv6 as the
      same, which makes sense, since we should block all IPv6, so
      everything should be treated the same at all times.
    - Changes due to #12411:
      * Raise special exception for Tor bootstrap failures.
      * Remove obsolete debug logging now that we don't log anything
        interesting for `restart-tor` any more.
anonym's avatar
anonym committed
625

anonym's avatar
anonym committed
626
 -- Tails developers <tails@boum.org>  Tue, 18 Apr 2017 17:41:46 +0200
anonym's avatar
anonym committed
627

anonym's avatar
anonym committed
628
tails (3.0~beta3) unstable; urgency=medium
629

intrigeri's avatar
intrigeri committed
630 631 632 633 634 635 636 637 638 639 640
  * Major new features and changes
    - Make the "Formats" settings in Tails Greeter take effect (Closes: #12079,
      new feature that was broken since it was introduced in 3.0~alpha1).
    - Upgrade to a new snapshot of the Debian and Torproject
      APT repositories (2017031702).

  * Removed features
    - Stop including I2P: we decided (#11276) to remove I2P, due to our failure
      at finding someone to maintain it in Tails (Closes: #12263).

  * Security fixes
intrigeri's avatar
intrigeri committed
641 642
    - Upgrade MAT to 0.6.1-4: fixes silent failure of the Nautilus
      contextual menu extension.
intrigeri's avatar
intrigeri committed
643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700
    - Ensure /etc/resolv.conf is owned by root:root in the SquashFS
      (Closes: #12343).
    - Protect against CVE-2017-2636 by disabling the n-hdlc kernel module
      (Closes: #12315).

  * Minor improvements
    - Reintroduce the X11 guest utilities for VirtualBox (regression
      introduced in 3.0~beta2).
    - Upgrade X.Org server and the modesetting driver (hopefully helps
      fixing #12219).
    - Automate the migration from KeePassX databases generated on Tails 2.x
      to the format required by KeePassX 2.0.x (Closes: #10956, #12369).
    - Add keyboard shortcuts in Tails Greeter (Closes: #12186, #12063).
    - Install dbus-user-session (regression introduced in 3.0~beta2).
    - Manage temporary directories in a declarative way (tmpfiles.d).
    - Replace references to the /var/run compatibility symlink
      with the canonical /run.
    - Update our Torbirdy patchset to the latest one sent upstream.
    - Install mesa-utils, so that Qt 5 can detect whether software based
      rendering is needed.
    - Have Tails Greeter honor the "debug" kernel command-line option,
      for easier debugging (Closes: #12373).
    - Refactor Tails Greeter to reduce code duplication (Closes: #12247).

  * Bugfixes
    - Fix sizing of zenity dialogs (Closes: #12313, regression introduced
      in 3.0~alpha1).
    - Fix confusing, spurious error messages in command-line applications
      wrapped with torsocks:
      · Ship a /etc/mailname file with content "localhost".
        Otherwise something (Git? libc6?) tries to resolve the "amnesia" host
        name, which fails, and a confusing error message is displayed
        (Closes: #12205, regression introduced in 3.0~alpha1).
      · Have torsocks allow UDP connections to the loopback interface,
        with AllowOutboundLocalhost 2 (Closes: #11736).

  * Test suite
    - Improve debugging info logging for PacketFu parsing issues,
      and implement a plausible fix (refs: #11508).
    - Try to make "double-click on desktop launcher" more reliable.
    - Fix selection of ISO in Tails Installer.
    - Re-enable the GnuPG tests that require a keyserver, pointing them
      to an Onion service we run on Chutney, that redirects all TCP traffic
      to a real, clearnet keyserver (Closes: #12211).
    - Implement a workaround for checking the configured keyserver in GnuPG,
      until a better fix is implemented (refs: #12371).
    - Fix the "Report an Error launcher" scenario in German.

  * Build system
    - Retry curl and APT operations up to 20 times to make the ISO build
      more robust wrt. unreliable Internet connectivity.
      Thanks to Arnaud <arnaud@preev.io> for the patch!
    - Install ikiwiki from jessie-backports, instead of our patched one
      (Closes: #12051).
    - Clean up libdvd-pkg build files, again (Closes: #11273).
    - Rakefile: fix TAILS_OFFLINE_BUILD exported variable name.
    - Adjust apt-mirror to support branches based on feature/stretch
      that don't use frozen APT snapshots.
701

anonym's avatar
anonym committed
702
 -- Tails developers <tails@boum.org>  Sun, 19 Mar 2017 15:10:28 +0100
703

intrigeri's avatar
intrigeri committed
704
tails (3.0~beta2) unstable; urgency=medium
705

intrigeri's avatar
intrigeri committed
706 707 708 709 710
  * All changes brought by Tails 2.11, except:
    - the test suite changes, that are not all compatible with this branch;
    - the "Tails 3.0 will require a 64-bit processor" notification:
      this advance warning is not useful on a release series
      that's 64-bit only.
711

intrigeri's avatar
intrigeri committed
712 713 714 715 716
  * Major new features and changes
    - Upgrade to a new snapshot of the Debian APT repositories (2017030802),
      and of the Torproject ones (2017030801).
    - Upgrade Linux to 4.9.0-2 (version 4.9.13-1).

intrigeri's avatar
intrigeri committed
717 718 719 720 721 722 723 724 725 726 727 728 729 730 731
  * Minor improvements
    - Improve GNOME Shell Window List styling. (Closes: #12233)

  * Bugfixes
    - Make it possible to start graphical applications in the Root Terminal.
      (part of #12000)

  * Test suite
    - Improve robustness when dealing with notifications. (Closes: #11464)
    - Bump timeout when waiting for 'Tor is ready' notification.
    - Fix the incremental upgrade test.
    - Drop a few obsolete test cases, update a number of images.
    - Adapt firewall leak test to new DHCP source IP address.
    - Adjust Seahorse and Enigmail tests to the keyserver that is now used.

intrigeri's avatar
intrigeri committed
732
 -- Tails developers <tails@boum.org>  Wed, 08 Mar 2017 16:29:44 +0000
733

anonym's avatar
anonym committed
734
tails (2.11) unstable; urgency=medium
anonym's avatar
anonym committed
735

anonym's avatar
anonym committed
736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762
  * Security fixes
    - Upgrade Tor Browser to 6.5.1 based on Firefox 45.8. (Closes:
      #12283)
    - Fix CVE-2017-6074 (local root privilege escalation) by disabling
      the 'dccp' module. (Closes: #12280)
    - Disable kernel modules for some uncommon network protocol. These
      are the ones recommended by CIS. (Part of: #6457)
    - Disable modules we blacklist for security reasons. Blacklisted
      (via `blacklist MODULENAME`) modules are only blocked from being
      loaded during the boot process, but are still loadable with an
      explicit `modprobe MODULENAME`, and (worse!) via kernel module
      auto-loading.
    - Upgrade linux-image-4.8.0-0.bpo.2-686-unsigned to 4.8.15-2~bpo8+2.
    - Upgrade bind9 to 1:9.9.5.dfsg-9+deb8u10.
    - Upgrade imagemagick to 8:6.8.9.9-5+deb8u7.
    - Upgrade libevent-2.0-5 to 2.0.21-stable-2+deb8u1.
    - Upgrade libgd3 to 2.1.0-5+deb8u9.
    - Upgrade libjasper1 to 1.900.1-debian1-2.4+deb8u2.
    - Upgrade liblcms2-2 to 2.6-3+deb8u1.
    - Upgrade libxpm4 to 1:3.5.12-0+deb8u1.
    - Upgrade login to 1:4.2-3+deb8u3.
    - Upgrade ntfs-3g to 1:2014.2.15AR.2-1+deb8u3.
    - Upgrade openjdk-7-jre to 7u121-2.6.8-2~deb8u1.
    - Upgrade openssl to 1.0.1t-1+deb8u6.
    - Upgrade tcpdump to 4.9.0-1~deb8u1.
    - Upgrade vim to 2:7.4.488-7+deb8u2.
    - Upgrade libreoffice to 1:4.3.3-2+deb8u6.
anonym's avatar
anonym committed
763

anonym's avatar
anonym committed
764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851
  * Minor improvements
    - import-translations: also import PO files for French from
      Transifex. The translation team for French switched to Transifex
      even for our custom programs:
      https://mailman.boum.org/pipermail/tails-l10n/2016-November/004312.html
    - Notify the user, if running on a 32-bit processor, that it won't
      be supported in Tails 3.0 anymore. (Closes: #12193)
    - Notify I2P users that I2P will be removed in Tails
      2.12. (Closes: #12271)

  * Bugfixes
    - Disable -proposed-updates at boot time. If a Debian point
      release happens right after a freeze but we have decided to
      enable it before the freeze to get (at least most of) it, then
      we get in the situation where -proposed-updates is enabled in
      the final release, which we don't want. We only want it enabled
      at build time. (Closes: #12169)
    - Ferm: Use the variable when referring to the Live user. The
      firewall will fail to start during early boot otherwise since
      the "amnesia" user hasn't been created yet. (Closes: #12208)
    - Tor Browser: Don't show offline warning when opening local
      documentation. (Closes: #12269)
    - tails-virt-notify-user: use the tails-documentation helper to
      improve UX when one is not connected to Tor yet, and display
      localized doc when available.
    - Fix rare issue causing automatic upgrades to not apply properly
      (Closes: #8449, and hopefully #11839 as well):
      * Allow the tails-install-iuk user to run "/usr/bin/nocache
        /bin/cp *" as root.
      * Install tails-iuk 2.8, which will use nocache for various file
        operations, and sync writes to the installation medium.
    - Install Linux 4.8.15 to prevent GNOME from freezing with Intel
      GM965/GL960 Integrated Graphics. (Closes: #12217, but fixes tons
      of other small bugs)

  * Build system
    - Add 'offline' option, making it possible to build Tails offline
      (if all needed resources are present in your cache). (Closes:
      #12272)

  * Test suite
    - Encapsulate exec_helper's class to not "pollute" the global
      namespace with all our helpers. This is an example of how we can
      work towards #9030.
    - Extend remote shell with *safe* file operations. Now we can
      read/write/append *any* characters without worrying that it will
      do crazy things by being passed through the shell, as was the
      case before.  This commit also:
      * adds some better reporting of errors happening on the server
        side by communicating back the exception thrown.
      * removes the `user` parameter from the VM.file_* methods. They
        were not used, any way, and simply do not feel like they
        fit. I think the only reason we had it initially was because
        it was implemented via the command interface, where a user
        concept makes a lot of sense.
    - debug_log() Dogtail script content on failure.
    - Add a very precise timestamp to each debug_log().
    - Make robust_notification_wait() ensure the applet is closed. In
      robust_notification_wait() when we close the notification
      applet, other windows may change position, creating a racy
      situation for any immediately following action aimed at one such
      window. (Closes: #10381)
    - Fix I2P's Pidgin test. The initial conversation (that determines
      the title of the conversation window) is now made by a different
      IRC service than before.
    - Use lossless compression for the VNC viewer with --view.
      Otherwise the VNC viewer is not a good place to extract test
      suite images from, at least with xtigervncviewer.
    - Add optional pause() notification feature to the test suite. It
      will run a user-configurable arbitrary shell command when
      pause() is called, e.g. on failure when --interactive-debugging
      is used. This is pretty useful when multitasking with long test
      suite runs, so you immediately are notified when a test fails
      (or when you reached a temporary pause() breakpoint).  (Closes:
      #12175)
    - Add the possibility to run Python code in a persistent session
      in the remote shell and use this for Dogtail to significantly
      improve its performance by saving state and reusing it between
      commands. This changes the semantics of the creation of Dogtail
      objects. Previously they just created the code that then would
      be run once an actionable method was called (.wait, .click etc),
      but now it works like in Python, that Dogtail will try to find
      the graphical element upon object creation. (Closes: #12059)
    - Test that we don't ship any -proposed-updates APT sources.
      (Closes: #12169)
    - Make force_new_tor_circuit() respect NEWNYM rate limiting.
    - Add retry magic for lost click when opening Tails' documentation
      from the desktop launcher. (Closes: #12131)
anonym's avatar
anonym committed
852

anonym's avatar
anonym committed
853
 -- Tails developers <tails@boum.org>  Mon, 06 Mar 2017 17:14:52 +0100
anonym's avatar
anonym committed
854

intrigeri's avatar
intrigeri committed
855
tails (3.0~beta1) experimental; urgency=medium
intrigeri's avatar
intrigeri committed
856

intrigeri's avatar
intrigeri committed
857
  * All changes brought by Tails 2.7.1, 2.9.1 and 2.10.
intrigeri's avatar
intrigeri committed
858

intrigeri's avatar
intrigeri committed
859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965
  * Major new features and changes
    - Redesigned Tails Greeter.
    - Upgrade to a new snapshot (2017013002) of the Debian and Torproject
      APT repositories.
    - Upgrade Linux to 4.9.0-1.

  * Security fixes
    - Reject packets sent on the LAN to the NetBIOS name service
      (Closes: #11944).
    - Seahorse: use the Tor OnionBalance hidden service pool,
      which provides transport encryption and authentication of the keyserver.

  * Minor improvements
    - Include adwaita-qt* and enable it by default, so that Qt applications
      integrate nicely into a GNOME environment (Closes: #11790).
    - Add support for the TREZOR hardware wallet in Electrum (Closes: #10964).
    - AppArmor: allow all programs to read /etc/tor/torsocks.conf via
      abstractions/base, to ease maintenance.
    - Don't (try to) bind the Power button to the shutdown action
      (Closes: #12004).
    - Enable natural scrolling (Closes: #11969).
    - Update uBlock Origin patterns + settings file.
    - live-persist: remove Squeeze → Wheezy migration code.
    - Update pre-existing persistent GnuPG configuration on login
      (Closes: #12201).
    - Upgrader: use the alpha channel when the next version will be an
      alpha, beta, or RC. This will allow users of 3.0~betaN to upgrade to
      the next beta or RC, without having to type any command-line
      (Closes: #12206).

  * Bugfixes
    - Fix "upgrade from ISO" when run from a 32-bit system,
      such as Tails 2.x (Closes: #11873).
    - Fix ability to read videos over HTTPS with Totem (Closes: #11963).
    - Re-introduce default directories in $HOME, which fixes
      Spice file transfers (Closes: #11968).
    - Re-enable tap-to-click (Closes: #11993).
    - Lower systemd's DefaultTimeoutStopSec, to get rid of a long delay
      before memory wiping starts. This also prevents shutdown from ever
      being blocked by any buggy service that takes a while to stop
      (Closes: #12061).
    - Drop Jessie APT sources.
    - Re-add VirtualBox DKMS modules.
    - Fix GnuPG communication with keyservers, by using the Tor OnionBalance
      hidden service pool (Closes: #12202).
    - Fix Enigmail communication with keyservers, by teaching Torbirdy
      not to break it (Closes: #11948):
      · Patch Torbirdy to allow not breaking keyserver communication when
        using GnuPG v2.1+, and to use a better default keyserver.
      · Torbirdy: enable the new behaviour made possible by the aforementioned
        patch (extensions.enigmail.already_torified).
      · Torbirdy: drop our custom keyserver configuration, since the
        aforementioned patch makes it the default.

  * Removed features
    - Don't install gnome-system-log anymore (Closes: #12133).
      It's deprecated in GNOME, and mostly useless anyway as it's not
      Journal-aware. It's replacement (gnome-logs) is not usable
      enough in the context of Tails, and most users who can read logs
      should manage to do it with journalctl, so don't install it either.
    - Drop multiarch handling: Tails 3.0 will be amd64-only (Closes: #11961).

  * Build system
    - Disable eatmydata usage and caching: in current Stretch, debootstrap fails
      if we use eatmydata + the operation mode picked by live-build when caching
      is enabled (Closes: #12052).
    - Bump disk space (and memory for in-RAM builds) requirements.
    - Follow replacement of python-reportbug with python3-reportbug.
    - Don't try to deinstall packages that are unknown on Stretch.
    - Move AppArmor aliases to a dedicated file, and include it.
      This will avoid maintaining these settings as a patch.
    - Don't attempt to remove the usr.bin.chromium-browser AppArmor profile:
      it's not shipped in Debian anymore.

  * Test suite
    - Add optional pause() notification (Closes: #12175).
    - Make the remote shell's file operations robust (Closes: #11887).
    - Update a number of test cases for Stretch, sometimes by converting
      them to Dogtail.
    - Drop usage and tests of read-only persistence.
      We won't have this option anymore, and it's not even sure we'll
      reintroduce it (Refs: #12093, Closes: #12055).
    - Adjust CONFIGURED_KEYSERVER_HOSTNAME to match current settings.
    - Test suite: clean up disks between features.

  * Adjustments for Debian 9 (Stretch) with no or very little user-visible impact
    - Adjust dpkg-divert path: it has moved.
    - Replace xfonts-wqy with fonts-wqy-microhei + fonts-wqy-zenhei.
      The former was removed from Debian testing, and the latter are recommended
      by task-chinese-s-desktop and task-chinese-t-desktop.
    - Install virtualbox* from sid.
      It was removed from testing due to https://bugs.debian.org/794466.
    - Drop deprecated settings from org/gnome/settings-daemon/plugins/power.
    - Update settings name in org/gnome/desktop/peripherals/touchpad, and drop
      deprecated ones.
    - Adjust to changed Liferea's .desktop filename.
    - Also torify Liferea when started via its (new) D-Bus service.
    - Install hunspell-pt-br instead of hunspell-pt-pt.
      Tor Browser 6.5 moved from pt-PT to pt-BR, which is fine vs
      spellcheckers in Jessie since its hunspell-pt provides both -pt and
      -br, but in Stretch they are separate packages.
    - AppArmor: adjust usr.sbin.cupsd profile so it loads successfully
      (Closes: #12116).
    - Migrate from netstat to ss.
    - Update extensions.enigmail.configuredVersion.
    - Remove the jessie-proposed-updates APT sources.

intrigeri's avatar
intrigeri committed
966
 -- Tails developers <tails@boum.org>  Wed, 01 Feb 2017 19:23:03 +0000
intrigeri's avatar
intrigeri committed
967

anonym's avatar
anonym committed
968
tails (2.10) unstable; urgency=medium
969

anonym's avatar
anonym committed
970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989
  * Major new features and changes
    - Upgrade the Linux kernel to 4.8.0-0.bpo.2 (Closes: #11886).
    - Install OnionShare from jessie-backports. Also install
      python3-stem from jessie-backports to allow the use of ephemeral
      onion services (Closes: #7870).
    - Completely rewrite tor-controlport-filter. Now we can safely
      support OnionShare, Tor Browser's per-tab circuit view and
      similar.
      * Port to python3.
      * Handle multiple sessions simultaneously.
      * Separate data (filters) from code.
      * Use python3-stem to allow our filter to be a lot more
        oblivious of the control language (Closes: #6788).
      * Allow restricting STREAM events to only those generated by the
        subscribed client application.
      * Allow rewriting commands and responses arbitrarily.
      * Make tor-controlport-filter reusable for others by e.g. making
        it possible to pass the listen port, and Tor control
        cookie/socket paths as arguments (Closes: #6742). We hear
        Whonix plan to use it! :)
anonym's avatar
anonym committed
990
    - Upgrade Tor to 0.2.9.9-1~d80.jessie+1, the new stable series
anonym's avatar
anonym committed
991
      (Closes: #12012).
992

anonym's avatar
anonym committed
993
  * Security fixes
anonym's avatar
anonym committed
994
    - Upgrade Tor Browser to 6.5 based on Firefox 45.7 (Closes: #12159)
995
    - Upgrade Icedove to 1:45.6.0-1~deb8u1+tail1s.
anonym's avatar
anonym committed
996 997 998 999 1000 1001
    - Upgrade bind9-packages to 1:9.9.5.dfsg-9+deb8u9.
    - Upgrade pcscd to 1.8.13-1+deb8u1.
    - Upgrade libgd3 to 2.1.0-5+deb8u8.
    - Upgrade libxml2 to 2.9.1+dfsg1-5+deb8u4.
    - Upgrade tor to 0.2.9.9-1~d80.jessie+1.
    - Upgrade samba-libs to 2:4.2.14+dfsg-0+deb8u2.
anonym's avatar
anonym committed
1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043

  * Minor improvements
    - Enable and use the Debian Jessie proposed-updates APT
      repository, anticipating on the Jessie 8.7 point-release
      (Closes: #12124).
    - Enable the per-tab circuit view in Tor Browser (Closes: #9365).
    - Change syslinux menu entries from "Live" to "Tails" (Closes:
      #11975). Also replace the confusing "failsafe" wording with
      "Troubleshooting Mode" (Closes: #11365).
    - Make OnionCircuits use the filtered control port (Closes:
      #9001).
    - Make  tor-launcher use the filtered control port.
    - Run OnionCircuits directly as the Live user, instead of a
      separate user. This will make it compatible with the Orca screen
      reader (Closes: #11197).
    - Run tor-controlport-filter on port 9051, and the unfiltered one
      on 9052. This simplifies client configurations and assumptions
      made in many applications that use Tor's ControlPort. It's the
      exception that we connect to the unfiltered version, so this
      seems like the more sane approach.
    - Remove tor-arm (Nyx) (Closes: #9811).
    - Remove AddTrust_External_Root.pem from our website CA bundle. We
      now only use Let's Encrypt (Closes: #11811).
    - Configure APT to use Debian's Onion services instead of the
      clearnet ones (Closes: #11556).
    - Replaced AdBlock Plus with uBlock Origin (Closes: #9833). This
      incidentally also makes our filter lists lighter by
      de-duplicating common patterns among the EasyList filters
      (Closes: #6908). Thanks to spriver for this first major code
      contribution!
    - Install OpenPGP Applet 1.0 (and libgtk3-simplelist-perl) from
      Jessie backports (Closes: #11899).
    - Add support for exFAT (Closes: #9659).
    - Disable unprivileged BPF. Since upgrading to kernel 4.6,
      unprivileged users can use the bpf() syscall, which is a
      security concern, even with JIT disabled. So we disable that.
      This feature wasn't available before Linux 4.6, so disabling it
      should not cause any regressions (Closes: #11827).
    - Add and enable AppArmor profiles for OnionCircuits and OnoinShare.
    - Raise the maximum number of loop devices to 32 (Closes: #12065).
    - Drop kernel.dmesg_restrict customization: it's enabled by
      default since 4.8.4-1~exp1 (Closes: #11886).
1044
    - Upgrade Electrum to 2.7.9-1.
anonym's avatar
anonym committed
1045 1046 1047 1048 1049 1050 1051 1052 1053 1054
    - Make the Electrum proxy configuration apply after upgrading to
      2.7.9-1. These changes incidentally makes Electrum behave nicer:
      users will now not be presented the network configuration part
      of the setup wizard -- a server will be picked randomly, and
      Electrum will auto-connect. The automated test suite is adjusted
      accordingly (Closes: #12140).
    - Remove unused Browser profile seed file localstore.rdf which was
      made obsolete in Firefox 34.
    - Tor Browser: switch from pt-PT to pt-BR langpack. The upstream
      Tor Browser did this in version 6.5 (Refs: #12159).
anonym's avatar
anonym committed
1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072

  * Bugfixes
    - Tails Greeter:
      * use gdm-password instead of gdm-autologin, to fix switching to
        the VT where the desktop session lives on Stretch (Closes:
        #11694)
      * Fix more options scrolledwindow size in Stretch (Closes:
        #11919)
    - Tails Installer: remove unused code warning about missing
      extlinux in Tails Installer (Closes: #11196).
    - Update APT pinning to cover all binary packages built from
      src:mesa so we ensure installing mesa from jessie-backports
      (Closes: #11853).
    - Install xserver-xorg-video-amdgpu. This should help supporting
      newer AMD graphics adapters. (Closes #11850)
    - Fix firewall startup during early boot, by referring to the
      "amnesia" user via its UID (Closes: #7018).
    - Include all amd64-microcodes.
anonym's avatar
anonym committed
1073 1074 1075 1076 1077 1078 1079 1080
    - refresh-translations: ignore
      config/chroot_local-includes/usr/share/doc/tails/website/.
      Otherwise, if the website has been built already, PO tools
      complain that there are files with translatable strings in
      there, which are not listed in POTFILES.in.
    - Make uBlock Origin's button appear on first run. Otherwise it
      will only appear on browser runs after the first one. This bug
      also affected Adblock Plus (Closes: #12145).
1081

anonym's avatar
anonym committed
1082 1083 1084 1085 1086 1087 1088
  * Build system
    - Be more careful when unmounting the tmpfs used as workspace
      during builds, fixing an issue that made Jenkins' ISO builders
      prone to failures (Closes: #12009).
    - Upgrade the Vagrant basebox to 20170105. The only big change is
      that we now install the backported kernel in the builder VM, to
      make building possible on Debian Sid (Closes: #12081).
anonym's avatar
anonym committed
1089 1090 1091 1092 1093 1094 1095
    - Ensure the VirtualBox guest DKMS modules are built for the
      kernel we want them for. In some situations, depending on the
      version of the running kernel, the modules would not be built
      for the 686 kernel, which is the one that needs the VirtualBox
      guest modules.  This commit ensures the VirtualBox guest modules
      are built and installed regardless of the how the build
      environment looks like (Closes: #12139).
bertagaz's avatar
bertagaz committed
1096

anonym's avatar
anonym committed
1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110
  * Test suite
    - Replace the filesystem shares support with a helper for easily
      sharing files from the host to the guest using virtual disks
      (Closes: #5571).
    - Do not test sending email when testing POP3. We cannot clean
      that email up (easily) since when we use POP3 deletions won't
      affect the remote inbox, only our local one, resulting in the
      quota being reached eventually (Closes: #12006).
    - Have APT tests configure APT to use non-onion sources. Our test
      suite uses Chutney to create a virtual, private Tor network, and
      thus doesn't support connections to Onion services running in
      the real Tor network (Refs: #11556).
    - Allow connections to Tor's control port during stream isolation
      tests, but only for those applications where we expect that.
anonym's avatar
anonym committed
1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130
    - Fix Electrum tests after upgrading to 2.7.9-1.
    - Make encryption.feature pass for Tails 2.10~rc1.
    - Adapt tests after the Donation campaign was disabled (Refs:
      #12134).
    - Fix 'The "Tails documentation" link on the Desktop works'
      scenario. The TailsOfflineDocHomepage.png image doesn't match
      what we see any more (I have no clue why), so let's use Dogtail
      and solve this once and for all, hopefully.
    - Work around Tails freezing during memory wiping. These
      workarounds should be reverted once #11786 is fixed
      properly. (Refs: #10776, #11786)
    - Support both xtigervncviewer and xtightvncviewer for --view.
      xtightvncviewer is a transitional package in Sid, which depends
      on tigervnc-viewer (which ships xtigervncviewer), so by keeping
      the dep and supporting both binaries, --view will work on both
      Sid and Jessie (Closes: #12129).
    - Test suite: bump image after upgrading to Tor Browser 6.5 (Refs:
      #12159).
    - Add debugging info for when PacketFu misbehaves, and be more
      careful when to save pcap artifacts (Refs: #11508).
anonym's avatar
anonym committed
1131

anonym's avatar
anonym committed
1132
 -- Tails developers <tails@boum.org>  Mon, 23 Jan 2017 11:38:37 +0100
anonym's avatar
anonym committed
1133

anonym's avatar
anonym committed
1134
tails (2.9.1) unstable; urgency=medium
anonym's avatar
anonym committed
1135

anonym's avatar
anonym committed
1136
  * Security fixes
1137 1138 1139 1140 1141
    - Upgrade Tor Browser to 6.0.8 based on Firefox 45.6. If you pay
      close attention you'll see that we import -build1 but there was
      a -build2. The only change is Tor Button 1.9.5.13 which makes
      some changes to the donation campaign banner in `about:tor`,
      which we safely can skip. (Closes: #12028)
anonym's avatar
anonym committed
1142
    - Upgrade Icedove to 45.5.1-1~deb8u1+tails1. (Closes: #12029)
1143
    - Upgrade APT-related packages to 1.0.9.8.4.
anonym's avatar
anonym committed
1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190

  * Minor improvements
    - Switch to DuckDuckGo as the default search engine in the tor
      Browser. This is what Tor Browser has, and Disconnect.me (the
      previous default) has been re-directing to DDG for some time,
      which has been confusing users. In addition, we localize the DDG
      user interface for the locales with availablelangpacks. (Closes:
      #11913)
    - Improve the display name for the Wikipedia search plugin.
    - Enable contrib and non-free for our own APT repos.
    - Upgrade Tor to 0.2.8.10. (Closes: #12015)
    - Upgrade obfs4proxy to 0.0.7-1~tpo1.

  * Bugfixes
    - AppArmor Totem profile: add permissions needed to avoid warning
      on startup. (Closes: #11984)
    - Upgrade the VirtualBox Guest additions and modules to version
      5.1.8. This should prevent Xorg from crashing unless the video
      memory for the VMs are significantly bumped. (Closes: #11965)
      Users will still have to enable I/O APIC due to a bug in Linux.
    - Drop unwanted search plugins from the Tor Browser langpacks.
      Otherwise they are only removed from English locales. Note that
      the langpacks contain copies of the English plugins, not
      localized versions, so we actually lose nothing.

  * Test suite
    - Add support for SikuliX, which recently hit Debian Unstable,
      while still supporting Sikuli for Jessie users. (Closes: #11991)
    - Fix some instances where we were trying to use the mouse outside
      of the Sikuli screen.
    - Use "TorBirdy" instead of "amnesia branding" as the "anchor"
      addon.  I.e. the addon that we use to find the other ones. The
      "amnesia branding" addon has been removed, so we must use
      something else. (Fixup: #11906)
    - Dogtailify "the support documentation page opens in Tor Browser"
      step. We previously relied on Sikuli, and the image was made
      outdated thanks to our donation campaign. No more! (Closes:
      #11911)
    - Resolve dl.amnesia.boum.org instead of picking a static address.
      Just hours after updating the dustri.org IP address, its web
      server went down => test suite failures. Let's make this test as
      robust as actually downloading the Tails ISO image -- if that
      fails, we probably have more serious problems on our hands than
      a failing test suite. (Closes: #11960)
    - Switch MAT scenario from testing PDFs to PNGs. Also add
      anti-test and test using using a tool *different* from MAT, the
      tool being tested here. (Closes: #11901)
anonym's avatar
anonym committed
1191

anonym's avatar
anonym committed
1192
 -- Tails Developers <tails@boum.org>  Wed, 14 Dec 2016 13:19:16 +0100
anonym's avatar
anonym committed
1193

anonym's avatar
anonym committed
1194
tails (2.7.1) unstable; urgency=medium
bertagaz's avatar
bertagaz committed
1195

anonym's avatar
anonym committed
1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240
  * Security fixes
    - Upgrade Tor Browser to 6.0.7 (build3) based on Firefox 45.5.1.
    - Upgrade gstreamer0.10-based packages to 0.10.31-3+nmu4+deb8u2.
    - Upgrade imagemagick-based packages to 8:6.8.9.9-5+deb8u6.
    - Upgrade libicu52 to 52.1-8+deb8u4.
    - Upgrade vim-based packages to 2:7.4.488-7+deb8u1.

  * Minor improvements
    - Reserve 64 MiB for the kernel and 128 MiB for privileged
      processes before the memory is wiped. We hope that this might
      help (but not solve, sadly) some crashes experienced while
      wiping the memory.

  * Build system
    - Make the wiki shipped inside Tails build deterministically
      (Closes: #11966):
      * Enable ikiwiki's "deterministic" option, and require it when
        building.
      * Use our custom backport of discount (2.2.1-1~bpo8+1~0.tails1),
        to fix reproducibility issues (Debian#782315). This can be
        dropped once our ISO builders use Stretch.
      * Install ikiwiki from our builder-jessie APT suite, to make the
        pagestats plugin output deterministic.
    - refresh-translations: don't update PO files unless something
      other than POT-Creation-Date was changed. (Closes: #11967)
    - Fix Vagrant's is_release? check. Per auto/build, we consider it
      a release when we build from detached head, and HEAD is tagged.
    - Enforce `cleanall` when building a release. I.e. don't allow the
      user supplied options to override this behaviour. This is
      important since Vagrant caches wiki builds, and we do not want
      leftovers from a previous builds ending up in a release. Also,
      this is required for making Tails images build reproducibly.
    - Make the build system's `cleanall` option really clean
      everything.  At the moment it doesn't clean the cached wiki
      build (which basically was its only job).
    - import-package: support contrib and non-free sections.

  * Test suite
    - Wait a bit between opening the shutdown applet menu, and
      clicking one of its widgets. (Closes: #11616).
    - Adapt Icedove test after removing the amnesia branding add-on.
      (Closes: #11906)
    - Replace --pause-on-fail with --interactive-debugging. It does
      the same thing, but also offers an interactive Ruby shell, via
      pry, with the Cucumber world context.
bertagaz's avatar
bertagaz committed
1241

anonym's avatar
anonym committed
1242
 -- Tails developers <tails@boum.org>  Wed, 30 Nov 2016 17:27:37 +0100
bertagaz's avatar
bertagaz committed
1243

intrigeri's avatar
intrigeri committed
1244
tails (3.0~alpha1) experimental; urgency=medium
intrigeri's avatar
intrigeri committed
1245

intrigeri's avatar
intrigeri committed
1246 1247 1248 1249 1250 1251 1252 1253
  * Major new features and changes
    - Upgrade to a snapshot of Debian 9 (Stretch) from 2016-11-15.
    - Switch userpace from 32-bit to 64-bit (Closes: #8183), and accordingly:
      · Memory erasure: drop the "one instance of sdmem per 2 GiB of RAM" tweak,
        that is not needed on x86-64.
      · Display a "sorry!" message when trying to boot on a 32-bit BIOS system
        (refs: #11638).
    - Switch GNOME Shell to its default black theme (Closes: #11789).
intrigeri's avatar
intrigeri committed
1254

intrigeri's avatar
intrigeri committed
1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479
  * Minor improvements
    - Install the cirrus and modesetting X.Org drivers (Closes: #10962).
    - Install the 'amdgpu' driver for the AMD Radeon cards (refs: #11850).
    - Stop disabling kernel modesetting for QXL (refs: #11518).
    - Replace TopIcons with gnome-shell-extension-top-icons-plus.
      The former causes plenty of trouble and is apparently abandoned
      upstream. The latter is actively maintained upstream, and packaged
      in Debian. (refs: #10576)
    - Use torsocks to torify Git, and drop tsocks entirely. tsocks has been
      unmaintained for years in Debian, and was removed from testing
      for a while (Closes: #10955).
    - Replace Florence's "systray" icon with the Florence Indicator GNOME Shell
      extension (refs: #8312). And then, don't automatically start Florence:
      the Florence Indicator GNOME Shell extension will start it the first time
      one tries to display it. This should save a tiny bit of RAM.
    - Harden AppArmor Totem profiles.
    - Switch to the Debian-packaged aufs kernel module (Closes: #11829).
    - Configure the firewall to not allow root to connect to Tor at all,
      which is possible now that APT uses a dedicated user for network
      operations.
    - Fix firewall startup during early boot, by referring to the "amnesia"
      user via its UID (refs: #7018).
    - Install hunspell dictionaries instead of myspell ones, for a few more
      languages: Spanish, Italian, Portuguese and Russian. Only Farsi keeps
      using a myspell dictionary for now.

  * Removed features
    - Stop installing BookletImposer PDF imposition toolkit.
      It's unmaintained upstream and thus won't be part of Debian Stretch.
    - Stop installing ekeyd:  it's unmaintained, very rarely used, poorly
      designed (dedicated daemon), and security sensitive (Closes: #7687).
    - Stop shipping ttdnsd. It was only useful for developers and power-users
      who can install it themselves as needed. It's been unmaintained upstream
      for many years. It's very buggy so we had to remove it from the DNS
      resolution loop years ago. It's not in Debian. And it's one of the only
      two bits of Tails that still relied on tsocks, that is RC-buggy,
      unmaintained in Debian, and not in Stretch at the moment. So it has
      become clear that the cost of keeping ttdnsd now outweighs the benefits
      it brought (refs: #10959).

  * Build system
    - Bump disk space (and memory for in-RAM builds) requirements.
    - Support new live-config configuration directory naming, again and again.
    - Use the lowest compression level for the SquashFS when compressing it
      with gzip. This makes our development builds faster, and the resulting
      ISO image only a little bit bigger (Closes: #9788).
    - Configure initramfs compression later, to make the build faster.

  * Test suite
    - Various refactoring while we were at it.
    - Port tests to Dogtail: installation, upgrade, notification detection,
      Synaptic, Gobby, and some of Tor Browser.
    - Workaround GNOME Shell being buggy for Dogtail (refs: #11718).
    - Update a bunch of test suite images for Stretch.
    - Mark created disk as temporary when we don't need to keep it around.
    - Simplify adding NetworkManager connections, and rely more on the defaults.
      Not providing the complete configuration file makes us test something
      closer to what happens when a user adds a Wi-Fi connection themselves.
    - Adjust the minimum allowed memory pattern coverage before wiping.
    - Always sync the time from the host when restoring from a snapshot.
      Previously we wouldn't do it when the network was plugged but Tor wasn't
      running, which can cause issues if we *then* start Tor since the time
      may be off.
    - Adjust to the fact that we now support running as a 64-bit guest
      in VirtualBox, and simplify code since we now include a 64-bit userland.
    - Improve how we restart Tor/I2P after restoring from a snapshot.
    - Adjust PolicyKit tests for Stretch.
    - Work around Tails stopping on shut down due to #11730.
      This should be reverted once #11730 is fixed properly.
    - Update the screenshot scenario.
    - Fix pcap file saving on MAC spoofing failure (Closes: #11698).