Bug#1006616: firefox: new upstream version

2022-03-08 Thread Christoph Anton Mitterer
Seems that rustc 1.57 is now even in sid and FF 98, with further
"high" rated fixes, is out.

Mike, any estimates on whether this could be upgraded? :)

Thanks,
Chris.



Bug#1006616: firefox: new upstream version

2022-03-08 Thread jim_p
Package: firefox
Version: 96.0.3-1
Followup-For: Bug #1006616
X-Debbugs-Cc: pitsior...@outlook.com

Dear Maintainer,

First of all, I know that firefox 97 requires rustc, cargo and nss to build.
How about updating those 3 and building firefox 97+ for the experimental repo?
It is not just to get "the latest and greatest" but to close critical security
issues like the ones discovered here
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/

Like the user that opened this report, I am on debian testing and I use
unstable for firefox and a few other packages.


-- Package-specific info:

-- Extensions information
Name: Add-ons Search Detection
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Amazon.co.uk
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Amazon.com
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Bing
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Dark theme
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: user-disabled

Name: DoH Roll-Out
Location: /usr/lib/firefox/browser/features/doh-roll...@mozilla.org.xpi
Package: firefox
Status: enabled

Name: DuckDuckGo
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: eBay
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Firefox Alpenglow theme
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: user-disabled

Name: Firefox Screenshots
Location: /usr/lib/firefox/browser/features/screensh...@mozilla.org.xpi
Package: firefox
Status: enabled

Name: Form Autofill
Location: /usr/lib/firefox/browser/features/formautof...@mozilla.org.xpi
Package: firefox
Status: enabled

Name: Google
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled

Name: Light theme
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: user-disabled

Name: Picture-In-Picture
Location: /usr/lib/firefox/browser/features/pictureinpict...@mozilla.org.xpi
Package: firefox
Status: enabled

Name: Privacy Redirect
Location: ${PROFILE_EXTENSIONS}/{b7f9d2cd-d772-4302-8c3f-eb941af36f76}.xpi
Status: enabled

Name: Proxy Failover
Location: /usr/lib/firefox/browser/features/proxy-failo...@mozilla.com.xpi
Package: firefox
Status: enabled

Name: System theme — auto theme
Location: /usr/lib/firefox/omni.ja
Package: firefox
Status: enabled

Name: uBlock Origin
Location: ${PROFILE_EXTENSIONS}/ublo...@raymondhill.net.xpi
Status: enabled

Name: Video DownloadHelper
Location: ${PROFILE_EXTENSIONS}/{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Status: enabled

Name: Web Compatibility Interventions
Location: /usr/lib/firefox/browser/features/webcom...@mozilla.org.xpi
Package: firefox
Status: enabled

Name: WebCompat Reporter
Location: /usr/lib/firefox/browser/features/webcompat-repor...@mozilla.org.xpi
Package: firefox
Status: user-disabled

Name: Wikipedia (en)
Location: /usr/lib/firefox/browser/omni.ja
Package: firefox
Status: enabled


-- Addons package information
ii  firefox96.0.3-1 amd64Mozilla Firefox web browser

-- System Information:
Debian Release: bookworm/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.16.0-3-amd64 (SMP w/2 CPU threads; PREEMPT)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages firefox depends on:
ii  debianutils  5.7-0.1
ii  fontconfig   2.13.1-4.4
ii  libatk1.0-0  2.36.0-3
ii  libc62.33-7
ii  libcairo-gobject21.16.0-5
ii  libcairo21.16.0-5
ii  libdbus-1-3  1.14.0-1
ii  libdbus-glib-1-2 0.112-2
ii  libevent-2.1-7   2.1.12-stable-1
ii  libffi8  3.4.2-4
ii  libfontconfig1   2.13.1-4.4
ii  libfreetype6 2.11.1+dfsg-1
ii  libgcc-s112-20220302-1
ii  libgdk-pixbuf-2.0-0  2.42.6+dfsg-2
ii  libglib2.0-0 2.70.4-1
ii  libgtk-3-0   3.24.31-1
ii  libnspr4 2:4.32-3
ii  libnss3  2:3.75-1
ii  libpango-1.0-0   1.50.4+ds-1
ii  libstdc++6   12-20220302-1
ii  libvpx7  1.11.0-2
ii  libx11-6 2:1.7.2-2+b1
ii  libx11-xcb1  2:1.7.2-2+b1
ii  libxcb-shm0  1.14-3
ii  libxcb1  1.14-3
ii  libxcomposite1   1:0.4.5-1
ii  libxdamage1  1:1.1.5-2
ii  libxext6 2:1.3.4-1
ii  libxfixes3   1:6.0.0-1
ii  libxrandr2   2:1.5.2-1
ii  libxtst6 2:1.2.3-1
ii  procps   2:3.3.17-6
ii  zlib1g   1:1.2.11.dfsg-2

Versions of packages firefox recommends:
ii  libavcodec58  10:4.4.1-dmo4

Versions of packages firefox suggests:
pn  fonts-lmodern  

Bug#1006616: firefox: new upstream version

2022-03-08 Thread Vincent Lefevre
On 2022-03-07 19:28:19 +0100, Christoph Anton Mitterer wrote:
> On Wed, 2022-03-02 at 03:13 -0300, Leandro Cunha wrote:
> > It's having a problem and logs can be accessed through the link
> > below.
> > https://buildd.debian.org/status/package.php?p=firefox=sid
> 
> Isn't it "just" the current rust version that's missing?

It seems that's the only missing build dependency for the common
architectures.

rust 1.57 is now available in experimental (I wonder why it hasn't
been uploaded directly to unstable, so that dependencies could be
fulfilled). So, how about a new firefox version in experimental?

-- 
Vincent Lefèvre  - Web: 
100% accessible validated (X)HTML - Blog: 
Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)



Bug#1006616: firefox: new upstream version

2022-03-07 Thread Christoph Anton Mitterer
On Wed, 2022-03-02 at 03:13 -0300, Leandro Cunha wrote:
> Firefox in bookworm/testing is ESR version only.

Well sure... but I guess not few people (probably including DDs/DMs)
are using FF non-ESR on their systems.

The recent minor release contains further critical issues, which are
apparently already actively attacked.


> It's having a problem and logs can be accessed through the link
> below.
> https://buildd.debian.org/status/package.php?p=firefox=sid

Isn't it "just" the current rust version that's missing?

Would it be feasible to backport the fixes for the most grave holes?


Thanks,
Chris.



Bug#1006616: firefox: new upstream version

2022-03-01 Thread Leandro Cunha
Hi,

On Mon, Feb 28, 2022 at 3:21 PM Christoph Anton Mitterer
 wrote:
>
> Package: firefox
> Version: 96.0.3-1
> Severity: wishlist
>
>
> Hey.
>
> Numerous security holes have been fixed in FF 97... would it be possible to 
> get that
> packaged for unstable/testing?
>
> Thanks,
> Chris.
>

Firefox in bookworm/testing is ESR version only.
It's having a problem and logs can be accessed through the link below.
https://buildd.debian.org/status/package.php?p=firefox=sid

-- 
Cheers,
Leandro Cunha
Software Engineer and Debian Contributor

⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄



Bug#1006616: firefox: new upstream version

2022-02-28 Thread Christoph Anton Mitterer
Package: firefox
Version: 96.0.3-1
Severity: wishlist


Hey.

Numerous security holes have been fixed in FF 97... would it be possible to get 
that
packaged for unstable/testing?

Thanks,
Chris.