Opened 8 years ago

Closed 7 years ago

#2844 closed defect (fixed)

Remove Polipo from all Tor Project bundles

Reported by: rransom Owned by: erinn
Priority: High Milestone:
Component: Applications/Tor bundles/installation Version:
Severity: Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description (last modified by mikeperry)

We have been shipping Polipo with several known security holes for which both exploit code and patches have been available for well over a year. We can apply the patches we have, but Polipo is too much of a mess for us to keep fixing.

Removing Polipo will require a lot of work from a lot of people; this is a parent ticket for all tickets related to Polipo removal.

Ticket Component Owner Summary Priority
#2845 Applications/Tor bundles/installation erinn Start building Firefox from source on Windows Very High
#5546 Applications/Tor bundles/installation erinn Stop producing Vidalia bundles High
#2848 Applications/Tor bundles/installation erinn Ship TBB-Firefox as a separately downloadable package Medium
#3648 Applications/Tor bundles/installation erinn move Vidalia bundles to server-only style package Medium
#6039 Applications/Tor bundles/installation erinn When we no longer include Polipo, update the download page Medium


Child Tickets

TicketStatusOwnerSummaryComponent
#2845closederinnStart building Firefox from source on WindowsApplications/Tor bundles/installation
#2848closederinnShip TBB-Firefox as a separately downloadable packageApplications/Tor bundles/installation
#3648closederinnmove Vidalia bundles to server-only style packageApplications/Tor bundles/installation
#5546closederinnStop producing Vidalia bundlesApplications/Tor bundles/installation
#6039closederinnWhen we no longer include Polipo, update the download pageApplications/Tor bundles/installation

Change History (15)

comment:1 Changed 8 years ago by mikeperry

Description: modified (diff)

comment:2 Changed 8 years ago by erinn

Polipo is removed from all current experimental TBBs, but is present in the Vidalia bundles. In theory we are going to move the Vidalia bundles to a strict relay/bridge/server configuration and stop shipping polipo and Torbutton in them, but we haven't done that yet.

comment:3 Changed 8 years ago by erinn

Update: all experimental TBBs have gone 'stable', and I have made relay and exit by default bundles for Windows. This week I will announce those packages properly on the blog and also articulate our move towards client & server packages, and my plan is to discontinue the Vidalia bundles on September 24th.

comment:4 Changed 8 years ago by erinn

Well, that was poorly worded. What I mean to say is that I will discontinue the Vidalia bundles that have polipo in them. I will keep making Vidalia bundles. :)

comment:5 Changed 8 years ago by Sebastian

What's the status here?

comment:6 Changed 7 years ago by phobos

I believe this is done, yes?

comment:7 Changed 7 years ago by Sebastian

No, the Vidalia bundles still have polipo

comment:8 Changed 7 years ago by phobos

Umm, what vidalia bundles? Weren't those killed in January per https://blog.torproject.org/blog/plain-vidalia-bundles-be-discontinued-dont-panic

comment:9 in reply to:  8 Changed 7 years ago by runa

Replying to phobos:

Umm, what vidalia bundles? Weren't those killed in January per https://blog.torproject.org/blog/plain-vidalia-bundles-be-discontinued-dont-panic

Apparently not, we still have Vidalia Bundles available for download.

comment:10 Changed 7 years ago by phobos

Right. This is my point. We're wasting resources maintaining them when we could be focusing on making TBB better, making TIMBB return, and producing the '(bridge|non-exit relay|exit relay)-by default' bundles.

comment:11 Changed 7 years ago by rransom

Are we there yet?

comment:12 Changed 7 years ago by arma

Still no word from erinn?

comment:13 Changed 7 years ago by phobos

As seen in the child tickets, I removed the client vidalia-bundle from the download page.

comment:14 Changed 7 years ago by phobos

I think this means the ticket is done. We need to stop producing the client vidalia-bundles in the build environment and we're really done.

comment:15 Changed 7 years ago by phobos

Resolution: fixed
Status: newclosed

done.

Note: See TracTickets for help on using tickets.