Thanks Thomas for reviewing this SRU. I have updated the regression
potential, please let me know if it is ok now.

** Description changed:

  [Impact]
  The torbrowser-launcher package in Ubuntu 20.04 does not work *at all* on new 
installations (see bug #1856895), because of a Tor Browser Developers public 
key change (old key is not valid anymore) that causes Tor Browser archive 
downloaded by torbrowser-launcher when being launched for a first time to fail 
verification. The included debdiff contains patch with a new key from latest 
package version (that is in Debian Testing and Ubuntu Groovy) and makes the 
torbrowser-launcher work again.
  
  [Test Case]
  1. Use a clean, fully updated Ubuntu 20.04 system where torbrowser-launcher 
was not previously installed/configured.
  2. Install the "torbrowser-launcher" package.
  3. Run "Tor Browser" from a desktop menu (or "torbrowser-launcher" from 
terminal).
  4. Wait for the Tor Browser archive to finish downloading, verifying and 
unpacking.
  
  [Regression Potential]
- There should be none. This debdiff adds just the one patch mentioned above. 
As mentioned, the developer key is used only when torbrowser-launcher is 
launched for a first time - to verify Tor Browser archive that is downloaded 
and unpacked (into user's home) by torbrowser-launcher. torbrowser updates are 
then handled by torbrowser itself, not by torbrowser-launcher. Subsequent Tor 
Browser updates are handled by Tor Browser itself, not by torbrowser-launcher 
and work fine even if the developer key shipped with torbrowser-launcher is 
incorrect.
+ This debdiff adds just the one patch mentioned above. As mentioned, the 
developer key is used only when torbrowser-launcher is launched for a first 
time - to verify Tor Browser archive that is downloaded and unpacked (into 
user's home) by torbrowser-launcher. torbrowser updates are then handled by 
torbrowser itself, not by torbrowser-launcher. Subsequent Tor Browser updates 
are handled by Tor Browser itself, not by torbrowser-launcher and work fine 
even if the developer key shipped with torbrowser-launcher is incorrect. I am 
not aware of any regression this change could cause.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1896085

Title:
  [SRU] Backport patch to update Tor Browser Developers public key into
  Ubuntu 20.04

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/torbrowser-launcher/+bug/1896085/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to