[tbb-bugs] #19410 [Applications/Tor Browser]: Incremental updates from 6.0 to 6.0.1 are not working on OS X

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jun 21 15:23:17 UTC 2016


#19410: Incremental updates from 6.0 to 6.0.1 are not working on OS X
-------------------------------------------------+-------------------------
 Reporter:  gk                                   |          Owner:  tbb-
     Type:  defect                               |  team
 Priority:  High                                 |         Status:  new
Component:  Applications/Tor Browser             |      Milestone:
 Severity:  Major                                |        Version:
 Keywords:  TorBrowserTeam201606,                |     Resolution:
  tbb-6.0-issues                                 |  Actual Points:
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------

Comment (by mcs):

 Replying to [comment:9 boklm]:
 > Currently the files included in the mar files are not signed. Does this
 cause problems with Gatekeeper, for the users who installed the new
 version using the update?

 I think the Gatekeeper check is not done again unless the files are moved
 to another computer (once an app is opened and the signature is found to
 be valid, it is "blessed" on that Mac OS system).

 > So it looks like we need to update our signature/release process to
 regenerate the OSX mar files after signing the bundles. Maybe we can make
 a script that takes a signed .dmg file and a non-signed mar file as
 inputs, and generate a new mar file containing the signed files from the
 dmg?

 Currently, we run the make_full_update.sh command during the bundling
 phase (mac/gitian-bundle.yml). Can we instead extract the .app from the
 signed .dmg and run make_full_update.sh using the signed .app? I think
 this is basically what you are suggesting....

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/19410#comment:11>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list