tails (1.5~rc1) UNRELEASED; urgency=medium
* Major new features and changes
- Move LAN web browsing from Tor Browser to the Unsafe Browser,
and forbid access to the LAN from the former. (Closes: #7976)
-- Tails developers <> Mon, 04 May 2015 14:48:25 +0200
* Security fixes
- XXX: Tor Browser 5.0
- XXX: update list of Debian packages that were upgraded for security
- Fix panic mode on MAC spoofing failure, bis repetita. (Closes: #9531)
- Deny Tor Browser access to global tmp directories with AppArmor,
and give it its own $TMPDIR. (Closes: #9558)
- Tails Installer: don't use a predictable file name for the subprocess
error log. (Closes: #9349)
- Upgrade Linux to 3.16.7-ckt11-1+deb8u2.
- Upgrade bind9-host, dnsutils and friends to 1:9.8.4.dfsg.P1-6+nmu2+deb7u6.
- Upgrade cups-filters to 1.0.18-2.1+deb7u2.
- Upgrade ghostscript to 9.05~dfsg-6.3+deb7u2.
- Upgrade libexpat1 to 2.1.0-1+deb7u2.
- Upgrade libicu48 to
- Upgrade libwmf0.2-7 to
- Upgrade openjdk-7 to 7u79-2.5.6-1~deb7u1.
* Bugfixes
- XXX: Tor
* Minor improvements
- Tails Installer: let the user know when it has rejected a candidate
destination device because it is too small. (Closes: #9130)
- Tails Installer: prevent users from trying to "upgrade" a device
that contains no Tails, or that was not installed with Tails Installer.
(Closes: #5623)
- Install libotr5 and pidgin-otr 4.x from wheezy-backports. This adds
support for the OTRv3 protocol and for multiple concurrent connections
to the same account. (Closes: #9513)
- Skip warning dialog when starting Tor Browser while being offline,
in case it is already running. Thanks to Austin English for the patch!
(Closes: #7525)
* Build system
- Add our jenkins-tools repository as a Git submodule, and replace with a symlink pointing to the same script in that submodule.
Adjust the automated test suite accordingly. (Closes: #9567)
* Test suite
- Test that the Tor Browser cannot access LAN resources.
- Test that the Unsafe Browser can access the LAN.
- Installer: test new behavior when trying to upgrade an empty device, and
when attempting to upgrade a non-Tails FAT partition on GPT; also, take
into account that all unsupported upgrade scenarios now trigger
the same behavior.
- Request a new Tor circuit and re-run the Seahorse and GnuPG CLI tests
on failure. (Closes: #9518, #9709)
- run_test_suite: remove control chars from log file even when cucumber
exits with non-zero. (Closes: #9376)
- Add compatibility with cucumber 2.0 and Debian Stretch. (Closes: #9667)
- Use custom exception when 'execute_successfully' fails.
- Retry looking up whois info on transient failure. (Closes: #9668)
- Retry wget on transient failure. (Closes: #9715)
- Test that Tor Browser cannot access files in /tmp.
- Allow running the test suite without ntp installed. There are other means
to have an accurate host system clock, e.g. systemd-timesyncd and tlsdate.
(Closes: #9651)
- Bump timeout in the Totem feature.
- Grep memory dump using the --text option. This is necessary with recent
versions of grep, such as the one in current Debian sid, otherwise it
will count only one occurrence of the pattern we're looking for.
(Closes: #9759)
- Include execute_successfully's error in the exception, instead
of writing it to stdout via puts. (Closes: #9795)
- Test that udev-watchdog is actually monitoring the correct device.
(Closes: #5560)
- IUK: workaround weird Archive::Tar behaviour on current sid.
-- Tails developers <> Tue, 04 Aug 2015 17:51:56 +0200
tails (1.4.1) unstable; urgency=medium
