changelog 19 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548
  1. tor (0.1.1.6-alpha-2) experimental; urgency=low
  2. * Merge 0.1.0.14+XXXX changes.
  3. -- Peter Palfrader <weasel@debian.org> Wed, 14 Sep 2005 15:05:16 +0200
  4. tor (0.1.1.6-alpha-1) experimental; urgency=low
  5. * Experimental upstream version.
  6. -- Peter Palfrader <weasel@debian.org> Sat, 10 Sep 2005 10:17:43 +0200
  7. tor (0.1.1.5-alpha-cvs-1) UNRELEASED; urgency=low
  8. * Even more experimental cvs snapshot.
  9. * Testsuite is mandatory again.
  10. * Forward port 03_tor_manpage_in_section_8.dpatch
  11. * Forward port 06_add_compile_time_defaults.dpatch
  12. -- Peter Palfrader <weasel@debian.org> Fri, 9 Sep 2005 23:22:38 +0200
  13. tor (0.1.1.5-alpha-1) UNRELEASED; urgency=low
  14. * Experimental upstream version.
  15. * Allow test suite to fail, it's broken in this version.
  16. * Update list of files from doc/ that should be installed.
  17. * Forward port debian/ patches.
  18. -- Peter Palfrader <weasel@debian.org> Fri, 12 Aug 2005 17:02:23 +0200
  19. tor (0.1.0.14+XXXX) UNRELEASED; urgency=low
  20. * Ship debugging information in a separate package now, instead
  21. of simply not stripping tor. This is still useful while tor is
  22. young. Ideally it would go away some time.
  23. * Add LSB comments to init script as suggested by Petter Reinholdtsen
  24. on the debian-devel list:
  25. - http://lists.debian.org/debian-devel/2005/08/msg01172.html
  26. - http://wiki.debian.net/?LSBInitScripts
  27. * Work around broken chroots that do not resolve localhost or resolve
  28. it to the wrong IP. We now catch such cases in debian/rules, shout
  29. at the buildd maintainer, and ignore the result of our test suite.
  30. -- Peter Palfrader <weasel@debian.org> Tue, 13 Sep 2005 19:18:39 +0200
  31. tor (0.1.0.14-1) unstable; urgency=high
  32. * New upstream version - changes, among others:
  33. - Fixes the other half of the bug with crypto handshakes.
  34. * Since gs-gpl on s390 is broken (#321435) and unable to
  35. build PDFs of our images for the design paper this version
  36. ships them in the source and uses them on s390, should building
  37. them from source really fail.
  38. * Increase standards-version from 3.6.1 to 3.6.2. No changes
  39. necessary.
  40. -- Peter Palfrader <weasel@debian.org> Mon, 8 Aug 2005 23:55:05 +0200
  41. tor (0.1.0.13-1) unstable; urgency=high
  42. * New upstream version:
  43. - Explicitly set no-unaligned-access for sparc in configure.in.
  44. it turns out the new gcc's let you compile broken code, but
  45. that doesn't make it not-broken (closes: #320140).
  46. - Fix a critical bug in the security of our crypto handshakes.
  47. (Therefore set urgency to high).
  48. and more (see upstream changelog).
  49. * Slightly improve init script to give you proper error messages when
  50. you do not run it as root.
  51. -- Peter Palfrader <weasel@debian.org> Fri, 5 Aug 2005 01:27:49 +0200
  52. tor (0.1.0.12-1) unstable; urgency=medium
  53. * New upstream version:
  54. - New IP for tor26 directory server,
  55. - fix a possible double-free in tor_gzip_uncompress,
  56. - and more (see upstream changelog).
  57. -- Peter Palfrader <weasel@debian.org> Tue, 19 Jul 2005 17:36:24 +0200
  58. tor (0.1.0.11-1) unstable; urgency=high
  59. * New upstream version (closes: #316753):
  60. - Fixes a serious bug: servers now honor their exit policies -
  61. In 0.1.0.x only clients enforced them so far. 0.0.9.x is
  62. not affected.
  63. * Build depend on libevent-dev >= 1.1.
  64. * Urgency high because 0.0.9.10-1 did not make it into testing after
  65. like 3 weeks because of an impending ftp-master move. So I might
  66. just as well upload this one.
  67. -- Peter Palfrader <weasel@debian.org> Mon, 4 Jul 2005 17:53:48 +0200
  68. tor (0.1.0.10-0.pre.1) UNRELEASED; urgency=low
  69. * New upstream version.
  70. * Add a watch file.
  71. * Forward port 03_tor_manpage_in_section_8.
  72. * Forward port 06_add_compile_time_defaults.
  73. * Add libevent-dev to build-depends.
  74. * Update URL to tor in debian/control and debian/copyright.
  75. * Add a snippet to disable epoll in etc/default/tor, commented out.
  76. * Add a snippet to set nice level in etc/default/tor.
  77. * Wait for 60 seconds in init stop. 35 is too little.
  78. * Don't depend on python anymore - tor-resolve is C now.
  79. * If "with-dmalloc" is in DEB_BUILD_OPTIONS we build against libdmalloc4.
  80. Of course the -dev package needs to be installed.
  81. * Update README.Debian to say that upstream now does have a default
  82. for DataDirectory.
  83. * Don't fail in the init script when we cannot raise the ulimit.
  84. Instead just warn a bit (closes: #312882).
  85. -- Peter Palfrader <weasel@debian.org> Wed, 15 Jun 2005 16:38:06 +0200
  86. tor (0.0.9.10-1) unstable; urgency=high
  87. * While we're waiting for a newer libevent to enter sid, make another
  88. upload of the 0.0.9.x tree:
  89. - Refuse relay cells that claim to have a length larger than the
  90. maximum allowed. This prevents a potential attack that could read
  91. arbitrary memory (e.g. keys) from an exit server's process.
  92. -- Peter Palfrader <weasel@debian.org> Thu, 16 Jun 2005 22:56:11 +0200
  93. tor (0.0.9.9-1) unstable; urgency=low
  94. * New upstream version.
  95. -- Peter Palfrader <weasel@debian.org> Sat, 23 Apr 2005 23:58:47 +0200
  96. tor (0.0.9.8-1) unstable; urgency=low
  97. * New upstream version.
  98. -- Peter Palfrader <weasel@debian.org> Fri, 8 Apr 2005 09:11:34 +0200
  99. tor (0.0.9.7-1) unstable; urgency=low
  100. * New upstream version.
  101. -- Peter Palfrader <weasel@debian.org> Fri, 1 Apr 2005 09:52:12 +0200
  102. tor (0.0.9.6-1) unstable; urgency=low
  103. * New upstream version.
  104. * Upstream used newer auto* tools, so hopefully the new config.sub
  105. and config.guess files (2003-08-18) are good enough to build
  106. tor on ppc64 (closes: #300376: FTBFS on ppc64).
  107. -- Peter Palfrader <weasel@debian.org> Fri, 25 Mar 2005 01:34:28 +0100
  108. tor (0.0.9.5-1) unstable; urgency=low
  109. * New upstream version.
  110. -- Peter Palfrader <weasel@debian.org> Thu, 24 Feb 2005 09:45:52 +0100
  111. tor (0.0.9.4-1) unstable; urgency=low
  112. * New upstream version.
  113. * Set ulimit for file descriptors to 4096 in our init
  114. script.
  115. * Use SIGINT to shutdown tor. That way - if you are a server -
  116. tor will stop accepting new connections immediately, and
  117. give existing connections a grace period of 30 seconds in
  118. which they might complete their task. If you just run a
  119. client it should make no difference.
  120. -- Peter Palfrader <weasel@debian.org> Fri, 4 Feb 2005 00:20:25 +0100
  121. tor (0.0.9.3-1) unstable; urgency=low
  122. * New upstream version.
  123. * Forward port 07_log_to_file_by_default.
  124. -- Peter Palfrader <weasel@debian.org> Sun, 23 Jan 2005 16:01:58 +0100
  125. tor (0.0.9.2-1) unstable; urgency=low
  126. * New upstream version.
  127. * Update debian/copyright (it's 2005).
  128. * Add sharedscripts tor logrotate.d/tor.
  129. -- Peter Palfrader <weasel@debian.org> Tue, 4 Jan 2005 11:14:03 +0100
  130. tor (0.0.9.1-1) unstable; urgency=low
  131. * New upstream version.
  132. -- Peter Palfrader <weasel@debian.org> Thu, 16 Dec 2004 00:16:47 +0100
  133. tor (0.0.8+0.0.9rc7-1) unstable; urgency=medium
  134. * New upstream release (candidate).
  135. For real this time. Looks like our rc6 orig.tar.gz
  136. was in fact the rc5 one.
  137. * forward port patches/07_log_to_file_by_default
  138. -- Peter Palfrader <weasel@debian.org> Wed, 8 Dec 2004 15:22:44 +0100
  139. tor (0.0.8+0.0.9rc6-1) unstable; urgency=medium
  140. * New upstream release (candidate).
  141. - cleans up more integer underflows that don't look exploitable.
  142. But one never knows (-> medium).
  143. * Remove those 'date' calls in debian/rules again that were
  144. added in rc5-1.
  145. -- Peter Palfrader <weasel@debian.org> Mon, 6 Dec 2004 11:11:23 +0100
  146. tor (0.0.8+0.0.9rc5-1) unstable; urgency=medium
  147. * New upstream release (candidate).
  148. - medium because it fixes an integer overflow that might
  149. be exploitable, but doesn't seem to be currently.
  150. * Add a few 'date' calls in debian/rules, so I can see how long
  151. building the docs take on autobuilders.
  152. -- Peter Palfrader <weasel@debian.org> Wed, 1 Dec 2004 10:02:08 +0100
  153. tor (0.0.8+0.0.9rc3-1) unstable; urgency=low
  154. * New upstream release (candidate).
  155. -- Peter Palfrader <weasel@debian.org> Thu, 25 Nov 2004 10:33:42 +0100
  156. tor (0.0.8+0.0.9rc2-1) unstable; urgency=low
  157. * New upstream release (candidate).
  158. * Nick's patch is now part of upstream, remove it from
  159. the debian diff.
  160. -- Peter Palfrader <weasel@debian.org> Wed, 24 Nov 2004 09:03:13 +0100
  161. tor (0.0.8+0.0.9rc1-1) unstable; urgency=low
  162. * New upstream release (candidate).
  163. * Apply nick's patch against config.c (1.267) to handle
  164. absense of units in BandwidthRate.
  165. -- Peter Palfrader <weasel@debian.org> Tue, 23 Nov 2004 11:57:49 +0100
  166. tor (0.0.8+0.0.9pre6-1) unstable; urgency=low
  167. * New upstream (pre)release.
  168. * Install control-spec.txt into usr/share/doc/tor/.
  169. -- Peter Palfrader <weasel@debian.org> Tue, 16 Nov 2004 04:49:32 +0100
  170. tor (0.0.8+0.0.9pre5-2) unstable; urgency=low
  171. * Symlink tor(8) manpage to torrc(5).
  172. * Make logs readable by the system administrators (group adm).
  173. * Point to /var/log/tor (the directory) instead of a single
  174. file (/var/log/tor/log) in the debian patch of the manpage.
  175. * Do not patch the default torrc to include settings we really want.
  176. Instead modify the compiled in default options. Those settings are
  177. - RunAsDaemon is enabled by default.
  178. - PidFile is set to /var/run/tor/tor.pid. No default upstream.
  179. - default logging goes to /var/log/tor/log instead of stdout.
  180. - DataDirectory is set to /var/lib/tor by default. No default upstream.
  181. This is also documented in the new debian/README.Debian.
  182. * Remove /usr/bin/tor-control.py from the binary package, it is
  183. not really useful yet, and wasn't meant to be installed by
  184. default.
  185. * Change init startup script to properly deal with tor
  186. printing stuff on startup.
  187. -- Peter Palfrader <weasel@debian.org> Fri, 12 Nov 2004 18:30:50 +0100
  188. tor (0.0.8+0.0.9pre5-1) unstable; urgency=low
  189. * New upstream (pre)release.
  190. * 04_fix_test can be backed out again.
  191. * Make sure all patches apply cleanly.
  192. * No longer use --pidfile, --logfile, and --runasdaemon
  193. command line options. Set them in the configfile instead.
  194. * Change the description slightly, to say "don't rely on the current Tor
  195. network if you really need strong anonymity", instead of "Tor will not
  196. provide anonymity currently".
  197. -- Peter Palfrader <weasel@debian.org> Wed, 10 Nov 2004 04:43:10 +0100
  198. tor (0.0.8+0.0.9pre4-1) unstable; urgency=low
  199. * New upstream (pre)release.
  200. * Apply patch from cvs to fix a segfault in src/or/test
  201. (test.c, 1.131).
  202. -- Peter Palfrader <weasel@debian.org> Sun, 17 Oct 2004 19:04:31 +0200
  203. tor (0.0.8+0.0.9pre3-1) unstable; urgency=high
  204. * New upstream (pre)release.
  205. * Fixes at least one segfault that can be triggered remotely,
  206. a format string vulnerability which probably is not exploitable,
  207. and several assert bugs.
  208. -- Peter Palfrader <weasel@debian.org> Thu, 14 Oct 2004 13:36:45 +0200
  209. tor (0.0.8+0.0.9pre2-1) unstable; urgency=low
  210. * New upstream (pre)release.
  211. -- Peter Palfrader <weasel@debian.org> Sun, 3 Oct 2004 01:29:13 +0200
  212. tor (0.0.8+0.0.9pre1-1) unstable; urgency=low
  213. * New upstream (pre)release.
  214. * Built depend on zlib1g-dev.
  215. -- Peter Palfrader <weasel@debian.org> Fri, 1 Oct 2004 21:28:49 +0200
  216. tor (0.0.8-1) unstable; urgency=low
  217. * New upstream release.
  218. -- Peter Palfrader <weasel@debian.org> Fri, 27 Aug 2004 14:08:10 +0200
  219. tor (0.0.7.2+0.0.8rc1-1) unstable; urgency=low
  220. * New upstream release candidate.
  221. * Install design paper in usr/share/doc/tor, not usr/share/doc. Ooops.
  222. -- Peter Palfrader <weasel@debian.org> Wed, 18 Aug 2004 09:59:13 +0200
  223. tor (0.0.7.2+0.0.8pre3-1) unstable; urgency=low
  224. * New upstream (pre)release.
  225. * Ship AUTHORS, doc/CLIENTS, doc/FAQ, doc/HACKING, doc/TODO,
  226. doc/tor-doc.{css,html}, doc/{rend,tor}-spec.txt with the binary package.
  227. * Build tor-design.{pdf,ps}, wich adds new build-dependencies:
  228. tetex-{bin,extra}, transfig, and gs.
  229. * Support DEB_BUILD_OPTIONS option 'nodoc' to skip building tor-design.
  230. With nodoc the build will not need tetex-{bin,extra}, transfig, and gs.
  231. * Support DEB_BUILD_OPTIONS option 'nocheck' to skip unittests
  232. ('notest' is an alias')
  233. * Enable coredumps by default, this is still development code.
  234. * Modify 02_add_debian_files_in_manpage to still apply.
  235. -- Peter Palfrader <weasel@debian.org> Sun, 8 Aug 2004 15:03:32 +0200
  236. tor (0.0.7.2+0.0.8pre2-1) unstable; urgency=low
  237. * New upstream (pre)release.
  238. * Depend on python as we now have a python script: tor_resolve
  239. -- Peter Palfrader <weasel@debian.org> Wed, 4 Aug 2004 20:09:26 +0200
  240. tor (0.0.7.2-1) unstable; urgency=medium
  241. * New upstream release.
  242. Fixes another instance of that remote crash bug.
  243. * Mention another reason why stop/reload may fail in the init script.
  244. -- Peter Palfrader <weasel@debian.org> Thu, 8 Jul 2004 03:21:32 +0200
  245. tor (0.0.7.1-1) unstable; urgency=medium
  246. * New upstream release.
  247. Fixes a bug that allows a remote crash on exit nodes.
  248. * Logrotate var/log/tor/*log instead of just var/log/tor/log, in
  249. case the admin wants several logs.
  250. -- Peter Palfrader <weasel@debian.org> Mon, 5 Jul 2004 19:18:12 +0200
  251. tor (0.0.7-1) unstable; urgency=low
  252. * New upstream version
  253. closes: #249893: FTBFS on ia64
  254. -- Peter Palfrader <weasel@debian.org> Mon, 7 Jun 2004 21:46:08 +0200
  255. tor (0.0.6.2-1) unstable; urgency=medium
  256. * New upstream release (breaks backwards compatibility yet again).
  257. * Recommend socat.
  258. * Since tor is in /usr/sbin, the manpage should be in section 8, not
  259. in section 1. Move it there, including updating the section in
  260. the manpage itself and the reference in torify(1).
  261. * Update debian/copyright file.
  262. -- Peter Palfrader <weasel@debian.org> Sun, 16 May 2004 10:47:20 +0200
  263. tor (0.0.6.1-1) unstable; urgency=medium
  264. * New upstream release (breaks backwards compatibility).
  265. -- Peter Palfrader <weasel@debian.org> Fri, 7 May 2004 00:24:49 +0200
  266. tor (0.0.6-1) unstable; urgency=low
  267. * New upstream release (breaks backwards compatibility).
  268. -- Peter Palfrader <weasel@debian.org> Sun, 2 May 2004 23:58:36 +0200
  269. tor (0.0.5+0.0.6rc4-1) unstable; urgency=low
  270. * New upstream release candidate.
  271. -- Peter Palfrader <weasel@debian.org> Sun, 2 May 2004 14:36:59 +0200
  272. tor (0.0.5+0.0.6rc3-1) unstable; urgency=low
  273. * New upstream release candidate.
  274. -- Peter Palfrader <weasel@debian.org> Thu, 29 Apr 2004 11:52:07 +0200
  275. tor (0.0.5+0.0.6rc2-1) unstable; urgency=low
  276. * New upstream release candidate.
  277. * Mention upstream website and mailinglist archives in long
  278. description.
  279. -- Peter Palfrader <weasel@debian.org> Mon, 26 Apr 2004 12:23:20 +0200
  280. tor (0.0.5-1) unstable; urgency=low
  281. * New upstream release.
  282. * Upstream installs a torrc.sample file now, rather than torrc.
  283. Keep using torrc as dpkg handles conffile upgrades.
  284. -- Peter Palfrader <weasel@debian.org> Tue, 30 Mar 2004 20:54:00 +0200
  285. tor (0.0.4-1) unstable; urgency=low
  286. * New upstream release (how the version numbers fly by :).
  287. -- Peter Palfrader <weasel@debian.org> Fri, 26 Mar 2004 23:46:09 +0100
  288. tor (0.0.3-1) unstable; urgency=low
  289. * New upstream release.
  290. * Also mention that tree.h is by Niels Provos in debian/copyright.
  291. -- Peter Palfrader <weasel@debian.org> Fri, 26 Mar 2004 20:36:08 +0100
  292. tor (0.0.2-1) unstable; urgency=low
  293. * New upstream release.
  294. * Uses strlcpy and strlcat by Todd C. Miller, mention him in
  295. debian/copyright.
  296. -- Peter Palfrader <weasel@debian.org> Fri, 19 Mar 2004 12:37:17 +0100
  297. tor (0.0.1+0.0.2pre27-1) unstable; urgency=low
  298. * New upstream release.
  299. -- Peter Palfrader <weasel@debian.org> Mon, 15 Mar 2004 05:19:16 +0100
  300. tor (0.0.1+0.0.2pre26-1) unstable; urgency=low
  301. * New upstream release.
  302. * Mention log and pidfile location in tor.1.
  303. -- Peter Palfrader <weasel@debian.org> Mon, 15 Mar 2004 02:21:29 +0100
  304. tor (0.0.1+0.0.2pre25-1) unstable; urgency=low
  305. * New upstream release.
  306. -- Peter Palfrader <weasel@debian.org> Thu, 4 Mar 2004 23:05:38 +0100
  307. tor (0.0.1+0.0.2pre24-1) unstable; urgency=low
  308. * New upstream release.
  309. * Do not strip binaries for now.
  310. * Add "# ulimit -c unlimited" to tor.default
  311. * Always enable DataDirectory.
  312. * Actually use dpatch now (to modify upstream torrc.in)
  313. * Wait for tor to die in init stop. Let the user know if it doesn't.
  314. -- Peter Palfrader <weasel@debian.org> Wed, 3 Mar 2004 14:10:25 +0100
  315. tor (0.0.1+0.0.2pre23-1) unstable; urgency=low
  316. * New upstream release.
  317. * The one test that always failed has been fixed: removed comment from
  318. rules file.
  319. -- Peter Palfrader <weasel@debian.org> Sun, 29 Feb 2004 12:36:33 +0100
  320. tor (0.0.1+0.0.2pre22-1) unstable; urgency=low
  321. * New upstream release.
  322. * Upstream has moved tor back to usr/bin, but we will keep it in
  323. usr/sbin. That's the right place and it doesn't break my tab
  324. completion there.
  325. -- Peter Palfrader <weasel@debian.org> Fri, 27 Feb 2004 01:59:09 +0100
  326. tor (0.0.1+0.0.2pre21-1) unstable; urgency=low
  327. * New upstream release.
  328. * 0.0.2pre20-2 removed the Recommends: on privoxy rather
  329. than tsocks (which is now required) by mistake. Fix that.
  330. * package description: Mention that the package starts the OP by default and
  331. that OR can be enabled in the config.
  332. * tor moved to sbin, updating init script.
  333. -- Peter Palfrader <weasel@debian.org> Wed, 18 Feb 2004 10:08:12 +0100
  334. tor (0.0.1+0.0.2pre20-2) unstable; urgency=low
  335. * Add torify script, documentation, and config file. Means we also
  336. depend on tsocks now rather than just recommending it. Right now
  337. we install it in debian/rules, but upcoming versions might install
  338. it in upstream's make install target.
  339. * There's an upstream ChangeLog file now. Enjoy!
  340. * Add a README.privoxy file that explains how to setup privoxy to
  341. go over tor.
  342. * As is the case too often, the INSTALL file not only covers
  343. installation, but also basic usage and configuration. Therefore
  344. include it in the docs dir.
  345. * Add a lintian override for the INSTALL file.
  346. -- Peter Palfrader <weasel@debian.org> Tue, 17 Feb 2004 02:32:00 +0100
  347. tor (0.0.1+0.0.2pre20-1) unstable; urgency=low
  348. * New upstream version.
  349. - various design paper updates
  350. - resolve cygwin warnings
  351. - split the token bucket into "rate" and "burst" params
  352. - try to resolve discrepency between bytes transmitted over TLS and actual
  353. bandwidth use
  354. - setuid to user _before_ complaining about running as root
  355. - fix several memleaks and double frees
  356. - minor logging fixes
  357. - add more debugging for logs.
  358. - various documentation fixes and improvements
  359. - for perforcmance testing, paths are always 3 hops, not "3 or more"
  360. (this will go away at a later date again)
  361. * Add dependency on adduser which was previously missing.
  362. * Change short description to a nicer one.
  363. -- Peter Palfrader <weasel@debian.org> Sat, 31 Jan 2004 10:10:45 +0100
  364. tor (0.0.1+0.0.2pre19-1) unstable; urgency=low
  365. * Initial Release (closes: #216611).
  366. -- Peter Palfrader <weasel@debian.org> Sat, 10 Jan 2004 11:20:06 +0100