Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package tor for openSUSE:Factory checked in 
at 2026-09-28 10:39:07
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/tor (Old)
 and      /work/SRC/openSUSE:Factory/.tor.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "tor"

Mon Sep 28 10:39:07 2026 rev:137 rq:1380293 version:0.4.9.13

Changes:
--------
--- /work/SRC/openSUSE:Factory/tor/tor.changes  2026-08-24 12:16:49.032101165 
+0200
+++ /work/SRC/openSUSE:Factory/.tor.new.383539/tor.changes      2026-09-28 
10:40:25.095783295 +0200
@@ -1,0 +2,94 @@
+Fri Sep 25 03:30:55 UTC 2026 - Bernhard Wiedemann <[email protected]>
+
+- Update to 0.4.9.13
+  * Major bugfixes (security):
+    - Avoid possible memory corruption, double-free, and null
+      pointer dereference bugs that could occur with some reverse DNS
+      virtual address configurations (TROVE-2026-051)
+    - Avoid cacheing DNS PTR responses when DNS caching is disabled
+      (TROVE-2026-050)
+  * Major bugfixes (client stream handling):
+    - Stop trying to reattach BEGIN_DIR directory streams (TROVE-2026-052)
+  * Major bugfixes (client, guard):
+    - Stop blaming guards for circuit, stream, directory-request, and
+      generic channel-close failures, and instead only record guard
+      failure once per unsuccessful outgoing connection establishment.
+      This also covers directory guards, synchronous failures, and proxy
+      or pluggable transport paths.
+      This fixes (TROVE-2026-030, TROVE-2026-038, TROVE-2026-041)
+  * Major bugfixes (connection handling):
+    - Fix a use-after-free when a TCP connection succeeds immediately
+      but starting its TLS handshake fails (TROVE-2026-056)
+  * Major bugfixes (onion service):
+    - A service-side rendezvous circuit that failed before reaching the
+      rendezvous point was relaunched twice (once when marked for close
+      and once more when freed), producing two concurrent circuits that
+      carried the same rendezvous cookie and key material and, with
+      repeated failures, 2^(N+1)-1 circuit builds per INTRODUCE2 instead
+      of N+1. (TROVE-2026-058)
+    - Rotate intro point at the service if the INTRODUCE2 replay cache
+      is at capacity. (TROVE-2026-012)
+  * Major bugfixes (onion service, TROVE):
+    - Reject INTRODUCE2 cells containing a zeroed rendezvous point ntor
+      onion key (TROVE-2026-030)
+  * Major bugfixes (relay):
+    - Remove circuits waiting for a channel from the pending channel
+      list as soon as they are marked for close instead of waiting until
+      they are freed. Fixes bug 41393
+  * Major bugfixes (stream isolation):
+    - When a client establishes a circuit to an onion service, but the
+      original stream had already closed, we were mistakenly clearing
+      the isolation parameters on that circuit, allowing it to be reused
+      by a future stream from a different isolation context. A malicious
+      onion service or HSDir relay could use this technique to break
+      first-party isolation (FPI) in Tor Browser (TROVE-2026-053)
+  * Minor features (HSDirs):
+    - Rate limit "Service descriptor has an invalid signature length"
+      messages at HSDir relays. This step only makes a flooding attack
+      more tolerable; it does not resolve or explain a flooding attack.
+      Improves the situation for ticket 41339. Bugfix on 0.3.0.1-alpha.
+  * Minor bugfixes (client, stream handling):
+    - When an exit or onion service answers a BEGIN with an END cell
+      whose reason byte is 0, report the stream to the application and
+      to controllers as a generic remote failure. Previously reason 0
+      turned into the internal "succeeded" value, so SOCKS clients got a
+      success reply, HTTP CONNECT clients got "200 OK", and controllers
+      got a STREAM SUCCEEDED event for a stream that never connected.
+      Also fix the formatting of unrecognized END reasons in controller
+      STREAM events. Fixes bug 41353
+  * Minor bugfixes (controller):
+    - No longer seg fault if a local authenticated controller connection
+      asks for SETCIRCUITPURPOSE with no arguments. Fixes bug 41332
+  * Minor bugfixes (directory parsing):
+    - When parsing an authority certificate with an explicit length, do
+      not skip trailing whitespace beyond that length. All current
+      callers pass NUL-terminated strings, so no bug was reachable in
+      practice. Fixes bug 41378
+  * Minor bugfixes (metrics):
+    - Fix an off-by-one in metrics_store_hist_entry_get_value() that
+      read one histogram bucket past the end of the array when asked for
+      a bucket boundary that does not exist. No in-tree caller currently
+      passes such a value. Fixes bug 41376
+  * Minor bugfixes (pluggable transports):
+    - Bridge clients or bridge relays no longer mangle memory the second
+      time a pluggable transport or socksproxy configuration is changed,
+      such as by setconf, resetconf, or sighup. Fixes bug 41375
+
+- Update to 0.4.9.12
+  * Major bugfixes (security):
+    + Do not purge memory for OOM from within low-level code.
+      (TROVE-2026-043)
+    + Fix a bug about reusable router descriptor (TROVE-2026-034)
+    + Fix a use-after-free around AutomapHostsOnResolve (TROVE-2026-036)
+    + Negotiate CGO cryptography with every hop that supports it 
(TROVE-2026-033)
+    + Reject certain CC_RESPONSE extensions (boo#1279897, 
CVE-2026-87724,TROVE-2026-032)
+    + Validate DNS names for complience (TROVE-2026-033)
+  * Major bugfixes (conflux, client, stream isolation):
+    + Keep the stream isolation state in sync of a linked conflux set on
+      every leg when attaching new streams (TROVE-2026-040)
+  * Minor features around directory authorities
+  * Removed features:
+    - Tor clients no longer accept consensus instructions to downgrade
+      the congestion control algorithm = defense in depth
+
+-------------------------------------------------------------------

Old:
----
  tor-0.4.9.11.tar.gz
  tor-0.4.9.11.tar.gz.sha256sum
  tor-0.4.9.11.tar.gz.sha256sum.asc

New:
----
  tor-0.4.9.13.tar.gz
  tor-0.4.9.13.tar.gz.sha256sum
  tor-0.4.9.13.tar.gz.sha256sum.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ tor.spec ++++++
--- /var/tmp/diff_new_pack.MYTefu/_old  2026-09-28 10:40:26.550844310 +0200
+++ /var/tmp/diff_new_pack.MYTefu/_new  2026-09-28 10:40:26.552844394 +0200
@@ -20,11 +20,12 @@
 %define toruser %{name}
 %define torgroup %{name}
 Name:           tor
-Version:        0.4.9.11
+Version:        0.4.9.13
 Release:        0
 Summary:        Anonymizing overlay network for TCP (The onion router)
 License:        BSD-3-Clause
 URL:            https://www.torproject.org/
+#Git-Clone:     https://gitlab.com/torproject/tor
 Source0:        https://www.torproject.org/dist/%{name}-%{version}.tar.gz
 # https://support.torproject.org/little-t-tor/verify-little-t-tor/
 Source2:        tor.keyring

++++++ tor-0.4.9.11.tar.gz -> tor-0.4.9.13.tar.gz ++++++
/work/SRC/openSUSE:Factory/tor/tor-0.4.9.11.tar.gz 
/work/SRC/openSUSE:Factory/.tor.new.383539/tor-0.4.9.13.tar.gz differ: char 12, 
line 1

++++++ tor-0.4.9.11.tar.gz.sha256sum -> tor-0.4.9.13.tar.gz.sha256sum ++++++
--- /work/SRC/openSUSE:Factory/tor/tor-0.4.9.11.tar.gz.sha256sum        
2026-08-24 12:16:48.995099847 +0200
+++ /work/SRC/openSUSE:Factory/.tor.new.383539/tor-0.4.9.13.tar.gz.sha256sum    
2026-09-28 10:40:25.033780695 +0200
@@ -1 +1 @@
-2e6c1720118c812acf0079fd47cf91b6bfaba5d766c321c4d3d2a28d6a11a8ed  
tor-0.4.9.11.tar.gz
+5e748d3272cdf44a7d7741173f371c8def3d96eecb77e93c89c50663ce9cc792  
tor-0.4.9.13.tar.gz

Reply via email to