FYI - First SRU template added to the bug description , waiting on
upstreams answers to my mail to finalize it

** Changed in: tor (Ubuntu)
     Assignee: (unassigned) => Christian Ehrhardt (paelzer)

** Description changed:

+ [ Impact ]
+ 
+  * Upstream announced a need to actively disable older versions
+    of Tor as we they begin the process of upgrading the Tor
+    network to support a number of more modern features that are
+    not supported by older versions of the Tor application.
+    => https://blog.torproject.org/sunsetting-tor-048/
+ 
+  * Without such an update and due to the nature of the network
+    this needs to interact with otherwise
+     - Tor Clients will stop working.
+     - Tor Onion Services, that people may use to reach their
+       SSH daemons with behind NAT/CG-NAT, will stop working.
+ 
+ [ Test Plan ]
+ 
+  * TBD - waiting on upstreams input to that
+ 
+ [ Where problems could occur ]
+ 
+  * TBD - waiting on upstreams input to that
+ 
+  * Think about what the upload changes in the software. Imagine the
+    change is wrong or breaks something else: how would this show up?
+ 
+  * It is assumed that any SRU candidate patch is well-tested before
+    upload and has a low overall risk of regression, but it's important
+    to make the effort to think about what ''could'' happen in the event
+    of a regression.
+ 
+  * This must never be "None" or "Low", or entirely an argument as to why
+    your upload is low risk.
+ 
+  * This both shows the SRU team that the risks have been considered,
+    and provides guidance to testers in regression-testing the SRU.
+ 
+ [ Other Info ]
+ 
+  * Debian does the very same minor release updates, so we would
+    not be the outlier.
+    tor        | 0.4.9.11-0+deb12u1 | oldstable                        | source
+    tor        | 0.4.9.11-0+deb13u1 | stable                           | source
+    tor        | 0.4.9.11-1         | testing                          | source
+    I'll check these Debian uploads to decide if I go tarball-only or
+    also some packaging changes
+ 
+ --- original report ---
+ 
+ 
  Tor[28740]: Please upgrade! This version of Tor (0.4.8.10) is obsolete, 
according to the directory authorities. Recommended versions are: 
0.4.9.4-rc,0.4.9.5,0.4.9.6,0.4.9.7,0.4.9.8,0.4.9.9,0.4.9.
  10,0.4.9.11
  
  [it's that time again.]
  
  Ubuntu: 26.10
- tor: 
+ tor:
  
  # apt-cache policy tor
  tor:
-   Installed: 0.4.8.10-1build2
-   Candidate: 0.4.8.10-1build2
-   Version table:
-  *** 0.4.8.10-1build2 500
-         500 https://ubuntu.hysing.is/ubuntu noble/universe amd64 Packages
-         100 /var/lib/dpkg/status
+   Installed: 0.4.8.10-1build2
+   Candidate: 0.4.8.10-1build2
+   Version table:
+  *** 0.4.8.10-1build2 500
+         500 https://ubuntu.hysing.is/ubuntu noble/universe amd64 Packages
+         100 /var/lib/dpkg/status
  
  ProblemType: Bug
  DistroRelease: Ubuntu 24.04
  Package: tor 0.4.8.10-1build2
  Uname: Linux 6.13.0-gnmlibre x86_64
  ApportVersion: 2.28.1-0ubuntu3.8
  Architecture: amd64
  CasperMD5CheckResult: unknown
  Date: Tue Aug 11 16:04:29 2026
  ProcEnviron:
-  LANG=en_US.UTF-8
-  PATH=(custom, no user)
-  SHELL=/bin/bash
-  TERM=screen.xterm-256color
-  XDG_RUNTIME_DIR=<set>
+  LANG=en_US.UTF-8
+  PATH=(custom, no user)
+  SHELL=/bin/bash
+  TERM=screen.xterm-256color
+  XDG_RUNTIME_DIR=<set>
  RebootRequiredPkgs: Error: path contained symlinks.
  SourcePackage: tor
  UpgradeStatus: Upgraded to noble on 2024-04-26 (838 days ago)
  modified.conffile..etc.tor.torrc: [modified]
  mtime.conffile..etc.tor.torrc: 2026-08-11T15:45:52.916988

** Summary changed:

- This version of Tor is obsolete
+ Tor sunsets <=4.8 - update to 4.9.11

** Description changed:

  [ Impact ]
  
-  * Upstream announced a need to actively disable older versions
-    of Tor as we they begin the process of upgrading the Tor
-    network to support a number of more modern features that are
-    not supported by older versions of the Tor application.
-    => https://blog.torproject.org/sunsetting-tor-048/
+  * Upstream announced a need to actively disable older versions
+    of Tor as we they begin the process of upgrading the Tor
+    network to support a number of more modern features that are
+    not supported by older versions of the Tor application.
+    => https://blog.torproject.org/sunsetting-tor-048/
  
-  * Without such an update and due to the nature of the network
-    this needs to interact with otherwise
-     - Tor Clients will stop working.
-     - Tor Onion Services, that people may use to reach their
-       SSH daemons with behind NAT/CG-NAT, will stop working.
+  * Without such an update and due to the nature of the network
+    this needs to interact with otherwise
+     - Tor Clients will stop working.
+     - Tor Onion Services, that people may use to reach their
+       SSH daemons with behind NAT/CG-NAT, will stop working.
  
  [ Test Plan ]
  
-  * TBD - waiting on upstreams input to that
+  * TBD - waiting on upstreams input to that
  
  [ Where problems could occur ]
  
-  * TBD - waiting on upstreams input to that
+  * TBD - waiting on upstreams input to that
  
-  * Think about what the upload changes in the software. Imagine the
-    change is wrong or breaks something else: how would this show up?
+  * Think about what the upload changes in the software. Imagine the
+    change is wrong or breaks something else: how would this show up?
  
-  * It is assumed that any SRU candidate patch is well-tested before
-    upload and has a low overall risk of regression, but it's important
-    to make the effort to think about what ''could'' happen in the event
-    of a regression.
+  * It is assumed that any SRU candidate patch is well-tested before
+    upload and has a low overall risk of regression, but it's important
+    to make the effort to think about what ''could'' happen in the event
+    of a regression.
  
-  * This must never be "None" or "Low", or entirely an argument as to why
-    your upload is low risk.
+  * This must never be "None" or "Low", or entirely an argument as to why
+    your upload is low risk.
  
-  * This both shows the SRU team that the risks have been considered,
-    and provides guidance to testers in regression-testing the SRU.
+  * This both shows the SRU team that the risks have been considered,
+    and provides guidance to testers in regression-testing the SRU.
  
  [ Other Info ]
  
-  * Debian does the very same minor release updates, so we would
-    not be the outlier.
-    tor        | 0.4.9.11-0+deb12u1 | oldstable                        | source
-    tor        | 0.4.9.11-0+deb13u1 | stable                           | source
-    tor        | 0.4.9.11-1         | testing                          | source
-    I'll check these Debian uploads to decide if I go tarball-only or
-    also some packaging changes
+  * Debian does the very same minor release updates, so we would
+    not be the outlier.
+    tor        | 0.4.9.11-0+deb12u1 | oldstable                        | source
+    tor        | 0.4.9.11-0+deb13u1 | stable                           | source
+    tor        | 0.4.9.11-1         | testing                          | source
+    I'll check these Debian uploads to decide if I go tarball-only or
+    also some packaging changes
  
- --- original report ---
+  * Strictly speaking, the 4.9.6 in Resolute would be ok in regard to the
+    discontinuation in the network, but it has security bugs and
+    therefore the best would be to bump all active releases to the latest.
+ 
+  * Time is scarce, which is why I'm helping to get this out fast for now (but
+    guided them how to get upload rights and otherwise use patch pilots and 
+    such). The sunset of <4.9 is planned for 1st September, hence it would
+    be nice to have that done before that.
+ 
+ 
+ ----- original report -----
  
  
  Tor[28740]: Please upgrade! This version of Tor (0.4.8.10) is obsolete, 
according to the directory authorities. Recommended versions are: 
0.4.9.4-rc,0.4.9.5,0.4.9.6,0.4.9.7,0.4.9.8,0.4.9.9,0.4.9.
  10,0.4.9.11
  
  [it's that time again.]
  
  Ubuntu: 26.10
  tor:
  
  # apt-cache policy tor
  tor:
    Installed: 0.4.8.10-1build2
    Candidate: 0.4.8.10-1build2
    Version table:
   *** 0.4.8.10-1build2 500
          500 https://ubuntu.hysing.is/ubuntu noble/universe amd64 Packages
          100 /var/lib/dpkg/status
  
  ProblemType: Bug
  DistroRelease: Ubuntu 24.04
  Package: tor 0.4.8.10-1build2
  Uname: Linux 6.13.0-gnmlibre x86_64
  ApportVersion: 2.28.1-0ubuntu3.8
  Architecture: amd64
  CasperMD5CheckResult: unknown
  Date: Tue Aug 11 16:04:29 2026
  ProcEnviron:
   LANG=en_US.UTF-8
   PATH=(custom, no user)
   SHELL=/bin/bash
   TERM=screen.xterm-256color
   XDG_RUNTIME_DIR=<set>
  RebootRequiredPkgs: Error: path contained symlinks.
  SourcePackage: tor
  UpgradeStatus: Upgraded to noble on 2024-04-26 (838 days ago)
  modified.conffile..etc.tor.torrc: [modified]
  mtime.conffile..etc.tor.torrc: 2026-08-11T15:45:52.916988

** Also affects: tor (Ubuntu Resolute)
   Importance: Undecided
       Status: New

** Also affects: tor (Ubuntu Noble)
   Importance: Undecided
       Status: New

** Also affects: tor (Ubuntu Jammy)
   Importance: Undecided
       Status: New

** Changed in: tor (Ubuntu Jammy)
     Assignee: (unassigned) => Christian Ehrhardt (paelzer)

** Changed in: tor (Ubuntu Noble)
     Assignee: (unassigned) => Christian Ehrhardt (paelzer)

** Changed in: tor (Ubuntu)
       Status: Confirmed => Fix Released

** Changed in: tor (Ubuntu Resolute)
     Assignee: (unassigned) => Christian Ehrhardt (paelzer)

** Changed in: tor (Ubuntu Noble)
       Status: New => Triaged

** Changed in: tor (Ubuntu Resolute)
       Status: New => Triaged

** Changed in: tor (Ubuntu Jammy)
       Status: New => Triaged

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2163259

Title:
  Tor sunsets <=4.8 - update to 4.9.11

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/tor/+bug/2163259/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to