Your message dated Fri, 06 Dec 2019 13:00:49 +0000
with message-id <[email protected]>
and subject line Bug#931656: fixed in libtorrent 0.13.8-1
has caused the Debian Bug report #931656,
regarding libtorrent20: sends private IP address to trackers
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
931656: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931656
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libtorrent20
Version: 0.13.7-1
Severity: normal
Tags: patch

Dear Maintainer,

I just upgraded to buster and found that rtorrent now sends my private
IP address to trackers unless manually configured (to send a bogus
address or the public address, via scripting if dynamic).  For details,
see <https://github.com/rakshasa/rtorrent/issues/731>.

Leaking the private IP can be a security and privacy issue which is not
obvious to users, unless trackers report a warning or error (most do
not).

The issue is fixed by a 2-line patch to libtorrent that has been merged,
but not released: https://github.com/rakshasa/libtorrent/pull/176

Is there any chance you would consider applying this patch, ideally in
both sid and stable?

Thanks,
Kevin


-- System Information:
Debian Release: 10.0
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (101, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 5.1.11 (SMP w/4 CPU cores)
Kernel taint flags: TAINT_OOT_MODULE
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8), 
LANGUAGE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages libtorrent20 depends on:
ii  libc6              2.28-10
ii  libcppunit-1.14-0  1.14.0-3
ii  libgcc1            1:8.3.0-6
ii  libssl1.1          1.1.1c-1
ii  libstdc++6         8.3.0-6
ii  zlib1g             1:1.2.11.dfsg-1

libtorrent20 recommends no packages.

libtorrent20 suggests no packages.

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: libtorrent
Source-Version: 0.13.8-1

We believe that the bug you reported is fixed in the latest version of
libtorrent, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jonathan McDowell <[email protected]> (supplier of updated libtorrent package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 01 Dec 2019 11:15:05 +0000
Source: libtorrent
Binary: libtorrent-dev libtorrent21 libtorrent21-dbgsym
Architecture: source amd64
Version: 0.13.8-1
Distribution: experimental
Urgency: medium
Maintainer: Jose Luis Rivas <[email protected]>
Changed-By: Jonathan McDowell <[email protected]>
Description:
 libtorrent-dev - C++ BitTorrent library by Rakshasa (development files)
 libtorrent21 - C++ BitTorrent library by Rakshasa
Closes: 931656
Changes:
 libtorrent (0.13.8-1) experimental; urgency=medium
 .
   [ Ondřej Nový ]
   * d/copyright: Use https protocol in Format field
   * d/changelog: Remove trailing whitespaces
 .
   [ Jonathan McDowell ]
   * New upstream release
     + Remove no longer necessary OpenSSL 1.1 patch
     + No longer sends private IP to trackers (closes: #931656)
   * Remove unnecessary build-dep on dh-autoreconf
   * Bumped package to match the soname change.
Checksums-Sha1:
 ce09e962df9456b1aa2e3573a9844c9269107d79 2101 libtorrent_0.13.8-1.dsc
 db9330ac07d65d5fc9c1562997054f4b45458e4a 357802 libtorrent_0.13.8.orig.tar.gz
 603858661f4a332c2b37eefa56edfe950db32ff9 21844 
libtorrent_0.13.8-1.debian.tar.xz
 872bd59eba9adf4fcd3324fecc88073e4cab6ce4 67108 
libtorrent-dev_0.13.8-1_amd64.deb
 307dc2be900b256d6ce81d20c6eb58c039ed6d9c 11414640 
libtorrent21-dbgsym_0.13.8-1_amd64.deb
 98c044971aaecdd8bb75d15b275269079c9e948c 426300 libtorrent21_0.13.8-1_amd64.deb
 c50033b9bb4d7bc9562da8ed865bdd3f20ce1ce1 7010 
libtorrent_0.13.8-1_amd64.buildinfo
Checksums-Sha256:
 c8027b3a407502539b3ddde2c626b5ff6e45f0cc0b33767972342066cf9b14b8 2101 
libtorrent_0.13.8-1.dsc
 0f6c2e7ffd3a1723ab47fdac785ec40f85c0a5b5a42c1d002272205b988be722 357802 
libtorrent_0.13.8.orig.tar.gz
 40245af43a6b7f6e639fe8cab8a8aba6e4564e489150ad1985663f1e5bfa5a88 21844 
libtorrent_0.13.8-1.debian.tar.xz
 87db9ed5f58541a2ee3cbbc5888c96cecc991d60753dc9c3cbb4d19402d8a0dc 67108 
libtorrent-dev_0.13.8-1_amd64.deb
 abb842518ff6fc3fe9a0643e1e5ff76435b463d53686d388e0e58595ebfdc06f 11414640 
libtorrent21-dbgsym_0.13.8-1_amd64.deb
 00b0a769757f481ba49e4dd2183504e69a3bf4c16834549318dffba221a6fa35 426300 
libtorrent21_0.13.8-1_amd64.deb
 36ed2a245f881b9f9d11deecf3337c043a6dfa40890cc77a642ae21165c1d821 7010 
libtorrent_0.13.8-1_amd64.buildinfo
Files:
 1015991c90f5eac6d6c2b8833daa4db8 2101 libs optional libtorrent_0.13.8-1.dsc
 dd184eadb8b449ddc6c3498a93ddd568 357802 libs optional 
libtorrent_0.13.8.orig.tar.gz
 3480510a2037fb0cdc9a6c037fa1d14c 21844 libs optional 
libtorrent_0.13.8-1.debian.tar.xz
 0a21d31586945900720d62cca6ec999e 67108 libdevel optional 
libtorrent-dev_0.13.8-1_amd64.deb
 ff0368c2c10bc90117e1407817d67871 11414640 debug optional 
libtorrent21-dbgsym_0.13.8-1_amd64.deb
 78df3b6ce2f19a8c184b2b2e2988114a 426300 libs optional 
libtorrent21_0.13.8-1_amd64.deb
 74ae71f455270262c76870bf1718c712 7010 libs optional 
libtorrent_0.13.8-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE/S8txYRw4wP3eXWjSgDzSK903QIFAl3jqrsACgkQSgDzSK90
3QKNfBAApagXvEubyxalxa2WgS9v0fnjw5a5v0epuzJb3NZVOvT7jlnYPmKH8DWC
LvkDOTwG+xiKVnvy5sYTzMxAe2aTeR/P2dPDE//ncPIZX87EJNIZiShwnb2VeUa+
kTOjdx5Orl+CQHmDjllfwm3evN9WdA+pijK/NJAHi9Q4zAQ5cdfn+uQ8zeiKtTOT
KZDX7baJ3+x4HIGLRQL40mYyMxSaWsvlqcnW96fVG2LkN5EOSVU5I62N3bLdCPNd
mHF42LDnNGEyvr4amxEfWnMizHh7ntWbwwkTi5Ny9GMDKg4hI17pbMxVmu+ZxniA
rx42nc0xrWCt3HzLTd0Or5RfKKFNLxPNyDsw/c+sOHsD76sFQtPeUCDLPOQwVGgb
utzOKY/90fzMYmxlkB9CAbNcxmjjC5314iwNWX2Y3G4no5+mTkOvC0SBfbYs1h0g
Y+/J48cYwrYE11ewZ5bgboCu5gO5xc8cgbxDdPvxvUgLKDYScy/aMmGpaXH7Kpqs
Kb3jbr/Oq03F8KRc/K5lwr3TsRTSBYb8BCeTNEC0t+EC9HVxu4HkloNjk9gyvFu5
IfP7l19Bk2IH3c17wtP6vTiKUvOzoL/RnuZrMXXT+unTYwWSCgYP8ui+beUcdFrv
KuGbiDEfFqKhmEStRzBWSqJB1iv44q3Hs07OIJxinWSckGoYkZU=
=PJgb
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to