From: Steph Burckel Date: Mon, 12 Jul 2021 11:49:31 +0000 (-0400) Subject: Installation package text updates for 3.0.22 release X-Git-Url: http://www.privoxy.org/gitweb/%22https:/developer-manual/faq/user-manual/static/webserver-update.html?a=commitdiff_plain;h=1c011adfcb9ccecf20dfb592bc0ce7e1fda0a94d;p=OSXPackageBuilder.git Installation package text updates for 3.0.22 release --- diff --git a/pkg resources/interface texts/Finish Up.txt b/pkg resources/interface texts/Finish Up.txt old mode 100644 new mode 100755 diff --git a/pkg resources/interface texts/Introduction.txt b/pkg resources/interface texts/Introduction.txt old mode 100644 new mode 100755 diff --git a/pkg resources/interface texts/LICENSE.txt b/pkg resources/interface texts/LICENSE.txt old mode 100644 new mode 100755 diff --git a/pkg resources/interface texts/ReadMe32.txt b/pkg resources/interface texts/ReadMe32.txt old mode 100644 new mode 100755 index a63e72b..d537ae1 --- a/pkg resources/interface texts/ReadMe32.txt +++ b/pkg resources/interface texts/ReadMe32.txt @@ -1,4 +1,4 @@ -January 2016, Privoxy 3.0.24 (stable) OS X installer V1.0 released. +October 2016, Privoxy 3.0.26 (stable) OS X installer V1.1 released. Version Support @@ -6,6 +6,33 @@ This installer supports Macs with Intel 32 bit processors running OS X 10.4 or 1 What's New -This release is (mostly) a bug-fix release; some fixed bugs were security issues. +This release fixes one regression in the 3.0.25 beta and one bug in the V1.0 installer for 3.0.26. As such is recommended for all users. It also adds several minor new features. -Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in Privoxy 3.0.24. \ No newline at end of file +- Bug fixes: + - Add client-tags template to packaged installer + - Fixed crashes with "listen-addr :8118" (SF Bug #902). + The regression was introduced in 3.0.25 beta and reported + by Marvin Renich in Debian bug #834941. + +- General improvements: + - Log when privoxy is toggled on or off via cgi interface. + - Highlight the "Info: Now toggled " on/off log message + in the Windows log viewer. + - Highlight the loading actions/filter file log message + in the Windows log viewer. + - Mention client-specific tags on the toggle page as a + potentionally more appropriate alternative. + +- Documentation improvements: + - Update download section on the homepage. + The downloads are available from the website now. + - Add sponsor FAQ. + - Remove obsolete reference to mailing lists hosted at SourceForge. + - Update the "Before the Release" section of the developer manual. + +- Infrastructure improvements: + - Add perl script to generate an RSS feed for the packages + Submitted by "Unknown". + + +Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in this release. \ No newline at end of file diff --git a/pkg resources/interface texts/ReadMe64.txt b/pkg resources/interface texts/ReadMe64.txt old mode 100644 new mode 100755 index e8f04b4..ddfe4c1 --- a/pkg resources/interface texts/ReadMe64.txt +++ b/pkg resources/interface texts/ReadMe64.txt @@ -1,11 +1,120 @@ -January 2016, Privoxy 3.0.24 (stable) OS X installer V1.0 released. +June 2021, Privoxy 3.0.32 (stable) macOS installer V1.0 released. Version Support -This installer supports Macs with Intel 64 bit processors running OS X 10.6 or higher. +This installer supports Macs with Intel 64 bit processors running OS X 10.11 or higher. What's New -This release is (mostly) a bug-fix release; some fixed bugs were security issues. +Privoxy 3.0.32 fixes multiple DoS issues and a couple of other bugs. The issues also affect earlier Privoxy releases. As such is recommended for all users. It also adds -Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in Privoxy 3.0.24. \ No newline at end of file +Full ChangeLog + +- Security/Reliability: + - ssplit(): Remove an assertion that could be triggered with a + crafted CGI request. + Commit 2256d7b4d67. OVE-20210203-0001. + Reported by: Joshua Rogers (Opera) + - cgi_send_banner(): Overrule invalid image types. Prevents a + crash with a crafted CGI request if Privoxy is toggled off. + Commit e711c505c48. OVE-20210206-0001. + Reported by: Joshua Rogers (Opera) + - socks5_connect(): Don't try to send credentials when none are + configured. Fixes a crash due to a NULL-pointer dereference + when the socks server misbehaves. + Commit 85817cc55b9. OVE-20210207-0001. + Reported by: Joshua Rogers (Opera) + - chunked_body_is_complete(): Prevent an invalid read of size two. + Commit a912ba7bc9c. OVE-20210205-0001. + Reported by: Joshua Rogers (Opera) + - Obsolete pcre: Prevent invalid memory accesses with an invalid + pattern passed to pcre_compile(). Note that the obsolete pcre code + is scheduled to be removed before the 3.0.33 release. There has been + a warning since 2008 already. + Commit 28512e5b624. OVE-20210222-0001. + Reported by: Joshua Rogers (Opera) + +- Bug fixes: + - Properly parse the client-tag-lifetime directive. Previously it was + not accepted as an obsolete hash value was being used. + Reported by: Joshua Rogers (Opera) + - decompress_iob(): Prevent reading of uninitialized data. + Reported by: Joshua Rogers (Opera). + - decompress_iob(): Don't advance cur past eod when looking + for the end of the file name and comment. + - decompress_iob(): Cast value to unsigned char before shifting. + Prevents a left-shift of a negative value which is undefined behaviour. + Reported by: Joshua Rogers (Opera) + - gif_deanimate(): Confirm that that we have enough data before doing + any work. Fixes a crash when fuzzing with an empty document. + Reported by: Joshua Rogers (Opera). + - buf_copy(): Fail if there's no data to write or nothing to do. + Prevents undefined behaviour "applying zero offset to null pointer". + Reported by: Joshua Rogers (Opera) + - log_error(): Treat LOG_LEVEL_FATAL as fatal even when --stfu is + being used while fuzzing. + Reported by: Joshua Rogers (Opera). + - Respect DESTDIR when considering whether or not to install + config files with ".new" extension. + - OpenSSL ssl_store_cert(): Fix two error messages. + - Fix a couple of format specifiers. + - Silence compiler warnings when compiling with NDEBUG. + - fuzz_server_header(): Fix compiler warning. + - fuzz_client_header(): Fix compiler warning. + - cgi_send_user_manual(): Also reject requests if the user-manual + directive specifies a https:// URL. Previously Privoxy would try and + fail to open a local file. + +- General improvements: + - Log the TLS version and the the cipher when debug 2 is enabled. + - ssl_send_certificate_error(): Respect HEAD requests by not sending a body. + - ssl_send_certificate_error(): End the body with a single new line. + - serve(): Increase the chances that the host is logged when closing + a server socket. + - handle_established_connection(): Add parentheses to clarify an expression + Suggested by: David Binderman + - continue_https_chat(): Explicitly unset CSP_FLAG_CLIENT_CONNECTION_KEEP_ALIVE + if process_encrypted_request() fails. This makes it more obvious that the + connection will not be reused. Previously serve() relied on + CSP_FLAG_SERVER_CONTENT_LENGTH_SET and CSP_FLAG_CHUNKED being unset. + Inspired by a patch from Joshua Rogers (Opera). + - decompress_iob(): Add periods to a couple of log messages + - Terminate the body of the HTTP snipplets with a single new line + instead of "\r\n". + - configure: Add --with-assertions option and only enable assertions + when it is used + - windows build: Use --with-brotli and --with-mbedtls by default and + enable dynamic error checking. + - gif_deanimate(): Confirm we've got an image before trying to write it + Saves a pointless buf_copy() call. + - OpenSSL ssl_store_cert(): Remove a superfluous space before the serial number. + +- Action file improvements: + - Disable fast-redirects for .golem.de/ + - Unblock requests to adri*. + - Block requests for trc*.taboola.com/ + - Disable fast-redirects for .linkedin.com/ + +- Filter file improvements: + - Make the second pcrs job of the img-reorder filter greedy again. + The ungreedy version broke the img tags on: + https://bulk.fefe.de/scalability/. + +- Privoxy-Log-Parser: + - Highlight a few more messages. + - Clarify the --statistics output. The shown "Reused connections" + are server connections so name them appropriately. + - Bump version to 0.9.3. + +- Privoxy-Regression-Test: + - Add the --check-bad-ssl option to the --help output. + - Bump version to 0.7.3. + +- Documentation: + - Add pushing the created tag to the release steps in the developer manual. + - Clarify that 'debug 32768' should be used in addition to the other debug + directives when reporting problems. + - Add a 'Third-party licenses and copyrights' section to the user manual. + + +Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in this release. \ No newline at end of file diff --git a/pkg resources/interface texts/ReadMePPC.txt b/pkg resources/interface texts/ReadMePPC.txt old mode 100644 new mode 100755 index 0150691..e7eeb12 --- a/pkg resources/interface texts/ReadMePPC.txt +++ b/pkg resources/interface texts/ReadMePPC.txt @@ -1,11 +1,36 @@ -January 2016, Privoxy 3.0.24 (stable) OS X installer V1.0 released. +May 2016, Privoxy 3.0.26 (stable) OS X installer V1.0 released. Version Support This installer supports Macs with PowerPC processors running OS X 10.4 or 10.5. -What's New -This release is (mostly) a bug-fix release; some fixed bugs were security issues. +This release fixes one regression in the 3.0.25 beta and as such is recommended for all users. It also adds several minor new features. -Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in Privoxy 3.0.24. \ No newline at end of file +- Bug fixes: + - Fixed crashes with "listen-addr :8118" (SF Bug #902). + The regression was introduced in 3.0.25 beta and reported + by Marvin Renich in Debian bug #834941. + +- General improvements: + - Log when privoxy is toggled on or off via cgi interface. + - Highlight the "Info: Now toggled " on/off log message + in the Windows log viewer. + - Highlight the loading actions/filter file log message + in the Windows log viewer. + - Mention client-specific tags on the toggle page as a + potentionally more appropriate alternative. + +- Documentation improvements: + - Update download section on the homepage. + The downloads are available from the website now. + - Add sponsor FAQ. + - Remove obsolete reference to mailing lists hosted at SourceForge. + - Update the "Before the Release" section of the developer manual. + +- Infrastructure improvements: + - Add perl script to generate an RSS feed for the packages + Submitted by "Unknown". + + +Please see the "What's New in this Release" section in the User Manual for details of all new features introduced and bugs fixed in this release. \ No newline at end of file