Skip to content
This repository was archived by the owner on Nov 6, 2023. It is now read-only.

Conversation

@cschanaj
Copy link
Collaborator

PR #18760 introduced a regression which breaks whitelisting and de-whitelisting for URLs contain a port number.

List related PRs if any

List related issues if any

PR #18760 introduced a regression which breaks whitelisting and
de-whitelisting for URLs contain a port number.
@zoracon
Copy link
Contributor

zoracon commented Mar 17, 2020

Considering we are limited in movement right now I won't be able to do an emergency release until April :(

@pipboy96 pipboy96 added the bug label Mar 17, 2020
@jmgurney
Copy link

Please pull the release and provide a way for people to downgrade if you can't release till 2 weeks. If you don't, there will be plenty of people that will uninstall the plugin and might not ever reinstall it.

@pipboy96
Copy link
Contributor

@jmgurney It may be an option (if it will indeed cause uninstalls), but that means other important things will get rolled back. Also it would need to be approved by EFF staff.

@zoracon
Copy link
Contributor

zoracon commented Mar 18, 2020

Please pull the release and provide a way for people to downgrade if you can't release till 2 weeks. If you don't, there will be plenty of people that will uninstall the plugin and might not ever reinstall it.

@jmgurney We have previous extensions releases on our page to download: https://www.eff.org/https-everywhere. Also, we are in the middle of a very serious pandemic. In normal circumstances, I'd be able to do this today. So I hope patience and grace would be considered.

@jmgurney
Copy link

Please pull the release and provide a way for people to downgrade if you can't release till 2 weeks. If you don't, there will be plenty of people that will uninstall the plugin and might not ever reinstall it.

@jmgurney We have previous extensions releases on our page to download: https://www.eff.org/https-everywhere. Also, we are in the middle of a very serious pandemic. In normal circumstances, I'd be able to do this today. So I hope patience and grace would be considered.

Thank you for the link to the past releases to make things functional. Installing 2019.11.7 makes things functional again. You might want to advertise this and figure out how to stop having people automatically upgraded to 2020.3.16. If the original bug has this work around, I would have used it sooner.

I will be attaching this work around to the bug as well.

There are lots of government websites, like large parts of Alameda County's website that do not have https functional, so blocking people from those websites is not a good outcome, especially in the middle of a crisis like this.

@zoracon
Copy link
Contributor

zoracon commented Mar 18, 2020

There are lots of government websites, like large parts of Alameda County's website that do not have https functional, so blocking people from those websites is not a good outcome, especially in the middle of a crisis like this.

@jmgurney Right now the more immediate work-around would be to turn EASE mode off for these sites. I understand that this is an urgent issue, but this crisis also affects the real people on this project as well. Hence mistakes and issues occurring due to the added stress on everyone. I could not predict that city actions would happen so quickly I could not come in to do secure patch releases.

To shed some transparency, we have to do this release securely on site. Not remotely. Which should answer why I can not do a release at the moment.

@zoracon zoracon merged commit 16c65b2 into EFForg:master Mar 18, 2020
@pipboy96
Copy link
Contributor

@zoracon Can William (Hainish) do that?

@zoracon
Copy link
Contributor

zoracon commented Mar 18, 2020

@zoracon Can William (Hainish) do that?

@pipboy96 Due to the Shelter-in-place order by the area, none of us can.

@cooperq
Copy link
Contributor

cooperq commented Mar 18, 2020

@pipboy96 @jmgurney the entire bay area is under a shelter in place order right now. No one at EFF is available to make a release since it requires coming to the office. You two could help us best by commenting on the bug report instructing people on how to downgrade if they are concerned about the issues in this PR. We currently don't know when we will be able to make a new release of any of our projects. Thank you for your patience with us.

@jmgurney
Copy link

I understand that things take time, but you do have to realize that you said:

Considering we are limited in movement right now I won't be able to do an emergency release until April :(

and there were no workarounds documented, nor statements about any other possible actions to be taken in the near future. Two weeks is a LONG time to leave something broken w/o action or a documented work around. If you had communicated a time line, or simply said we are exploring options, give me a day or two, that would have been helpful.

@zoracon
Copy link
Contributor

zoracon commented Mar 18, 2020

I understand that things take time, but you do have to realize that you said:

Considering we are limited in movement right now I won't be able to do an emergency release until April :(

and there were no workarounds documented, nor statements about any other possible actions to be taken in the near future. Two weeks is a LONG time to leave something broken w/o action or a documented work around. If you had communicated a time line, or simply said we are exploring options, give me a day or two, that would have been helpful.

@jmgurney It's not just about things taking time, unprecedented events occurred. Where I truly thought we could handle issues that arose from this release. You're right, two weeks is a long time. This was not planned.

We can post and pin an issue. I also planned to communicate this on our social and email channels. Either way, we can't do a release. I am not sure how many ways we can convey this. This is merged in now and that is all that can be done.

@EFForg EFForg locked as too heated and limited conversation to collaborators Mar 18, 2020
@pipboy96
Copy link
Contributor

pipboy96 commented Mar 18, 2020

@jmgurney The problem is releasing updates is not as simple as pushing a .crx file to a server, there are protections against pushing malicious updates, it's physically impossible to do that outside EFF's office, so until quarantine is lifted we are stuck with a broken release. I hope this explains things better.

@zoracon
Copy link
Contributor

zoracon commented Mar 18, 2020

And to clarify why the conversation is locked, the issue has a patch in master, I have pinned the issue to the repo involved, and we have discussed in depth with as much calm as possible why a release can't occur.

It should be somewhat obvious that a shelter-in-place order means these are trying and extreme constraints we normally don't have. So this was locked so that we can discuss, resolve, and move forward with the energy I have to give towards this project. There's just not many options for locked conversation categories. So "too heated" was the only one that made the most sense.

@pipboy96
Copy link
Contributor

pipboy96 commented Mar 19, 2020

@zoracon I thought "Resolved" would be a better reason, but I don't think it matters much. Also, for some reason I don't get this update on Firefox. Was it pulled?

@zoracon
Copy link
Contributor

zoracon commented Mar 19, 2020

@pipboy96 No it was not pulled, maybe it didn't auto update?

@cschanaj cschanaj deleted the fix-whitelist-host-with-port-number branch May 22, 2020 23:44
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Known issue: Release 2020.3.16 breaks whitelisting of some URLS and "open insecure page" button for them.

5 participants