Skip to content

arti: 2.4.0 -> 2.5.0#537280

Open
whispersofthedawn wants to merge 1 commit into
NixOS:masterfrom
whispersofthedawn:p/arti
Open

arti: 2.4.0 -> 2.5.0#537280
whispersofthedawn wants to merge 1 commit into
NixOS:masterfrom
whispersofthedawn:p/arti

Conversation

@whispersofthedawn

@whispersofthedawn whispersofthedawn commented Jul 1, 2026

Copy link
Copy Markdown
Contributor

blog: https://blog.torproject.org/arti_2_5_0_released/
changelog: https://gitlab.torproject.org/tpo/core/arti/-/blob/arti-v2.5.0/CHANGELOG.md
diff: https://gitlab.torproject.org/tpo/core/arti/-/compare/arti-v2.4.0...arti-v2.5.0
trove: https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE

this release is non-breaking for users of the binary, but should provide various transparent improvements (CGO, congestion control). additionally, the upstream tag contains fixes for two medium severity DoS issues: TROVE-2026-024 and TROVE-2026-027. we already had (and now drop) the patch for the former, but this does fix the latter for us.

Fixes: TROVE-2026-027

tested:

  • with tor-browser as a standalone proxy
  • with curl as a socks5 proxy to connect to clearnet sites and onion services
  • running a regular onion service
  • running an onion service with restricted discovery/client authorization
  • as a client in a test network as part of nixosTests.tor

Things done

blog: https://blog.torproject.org/arti_2_5_0_released/
changelog: https://gitlab.torproject.org/tpo/core/arti/-/blob/arti-v2.5.0/CHANGELOG.md
diff: https://gitlab.torproject.org/tpo/core/arti/-/compare/arti-v2.4.0...arti-v2.5.0
trove: https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/TROVE

this release is non-breaking for users of the binary, but should provide
various transparent improvements (CGO, congestion control).
additionally, the upstream tag contains fixes for two medium severity
DoS issues: TROVE-2026-024 and TROVE-2026-027. we already had (and now
drop) the patch for the former, but this does fix the latter for us.

Fixes: TROVE-2026-027
@whispersofthedawn whispersofthedawn added the backport release-26.05 Backport PR automatically label Jul 1, 2026
@nixpkgs-ci nixpkgs-ci Bot requested a review from Steinhagen July 1, 2026 04:09
@nixpkgs-ci nixpkgs-ci Bot added 8.has: package (update) This PR updates a package to a newer version 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 11.by: package-maintainer This PR was created by a maintainer of all the package it changes. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. 10.rebuild-linux: 1 This PR causes 1 package to rebuild on Linux. labels Jul 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

8.has: package (update) This PR updates a package to a newer version 10.rebuild-darwin: 1-10 This PR causes between 1 and 10 packages to rebuild on Darwin. 10.rebuild-darwin: 1 This PR causes 1 package to rebuild on Darwin. 10.rebuild-linux: 1-10 This PR causes between 1 and 10 packages to rebuild on Linux. 10.rebuild-linux: 1 This PR causes 1 package to rebuild on Linux. 11.by: package-maintainer This PR was created by a maintainer of all the package it changes. backport release-26.05 Backport PR automatically

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant