zerotracepen (6.4)

  • Upgrade Thunderbird to 115.12

    • Resolve "Upgrade to Tor Browser 13.0.16 based on 115.12" (zerotracepen/zerotracepen!1574)

      Closes issues:

      • Upgrade to Tor Browser 13.0.16 based on 115.12 (zerotracepen/zerotracepen#20417)

      Commits:

      • Fetch Tor Browser from our own archive
      • Upgrade Tor Browser to 13.0.16 (refs: zerotracepen#20417)
    • Resolve "Upgrade tor to 0.4.8.12" (zerotracepen/zerotracepen!1569)

      Closes issues:

      • Upgrade tor to 0.4.8.12 (zerotracepen/zerotracepen#20416)

      Commits:

      • upgrade tor to 0.4.8.12
    • Fix Plymouth messages not being hidden (zerotracepen/zerotracepen!1549)

      Closes issues:

      • "Preparing Zero Trace Pen for first use..." Plymouth message remains displayed until GDM
        starts (zerotracepen/zerotracepen#20401)

      Commits:

      • Fix Plymouth messages not being hidden
    • Allow NetworkManager to load kernel modules (zerotracepen/zerotracepen!1566)

      Commits:

      • Allow NetworkManager to explicitly load kernel modules
    • Complete the switch to non-Onion APT repositories (zerotracepen/zerotracepen!1564)

      Closes issues:

      • Complete the switch to non-Onion APT repositories: Onion services are less
        reliable than a direct connection (zerotracepen/zerotracepen#20365)

      Commits:

      • Test suite: relax timeout
      • Complete the switch to non-Onion APT repositories
    • Fix "no merge base" failures in ruff tests (zerotracepen/zerotracepen!1563)

      Commits:

      • Fix "no merge base" failures in ruff tests
    • Use custom container image to build the website (zerotracepen/zerotracepen!1562)

      Commits:

      • Do not store all untracked files as artifacts
      • Cache website underlays when building the website
      • Use custom container image to build the website
    • GitLab CI: fix missing diff merge base for branches that have diverged from the
      target (zerotracepen/zerotracepen!1560)

      Closes issues:

      • ruff-*-changed-files fail on some branches: no merge base (zerotracepen/zerotracepen#20408)

      Commits:

      • GitLab CI: fix missing diff merge base for branches that have diverged from the
        target
    • Draft: GitLab CI: fix missing diff merge base for branches that have diverged
      sufficiently from the target branch (zerotracepen/zerotracepen!1559)

      Closes issues:

      • ruff-*-changed-files fail on some branches: no merge base (zerotracepen/zerotracepen#20408)

      Commits:

      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Translated using Weblate (Catalan)
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Translated using Weblate (French)
      • Weblate commit
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Weblate commit
      • Translated using Weblate (French)
      • Weblate commit
      • Translated using Weblate (French)
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Translated using Weblate (French)
      • Weblate commit
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (French)
      • Translated using Weblate (Chinese (Taiwan) (zh_TW))
      • Translated using Weblate (Chinese (zh))
      • Translated using Weblate (Russian)
      • Translated using Weblate (Catalan)
      • Translated using Weblate (Portuguese)
      • Translated using Weblate (Italian)
      • Translated using Weblate (French)
      • Translated using Weblate (Spanish)
      • Translated using Weblate (German)
      • updated PO files
      • Use automatic anchors
      • updated PO files
      • Ditch website artifacts in GitLab CI after 1 day
      • Make website deployment more robust
      • Add monthly report for April 2024
      • updated PO files
      • Downplay the importance of manual upgrades
      • Remove note for nerds only
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Weblate commit
      • Shorten
      • updated PO files
      • Update release frequency
      • updated PO files
      • Delete Bootstrap (#18142)
      • Rewrite without Bootstrap (#18142)
      • Factorize
      • Improve layout
      • Remove hidden setup for dual currency donations
    • Test suite: fix keyboard input in interactive debugging shell when --capture is
      enabled (zerotracepen/zerotracepen!1552)

      Closes issues:

      • Test suite: pry run by --interactive-debugging is broken when --capture is
        used (zerotracepen/zerotracepen#20403)

      Commits:

      • Test suite: reformat code
      • Test suite: redirect stdin when spawning ffmpeg through --capture
    • Remote shell server: add SIGIO handler earlier (zerotracepen/zerotracepen!1551)

      Closes issues:

      • Test suite: the remote shell is sometimes killed by SIGIO during startup
        (zerotracepen/zerotracepen#20404)

      Commits:

      • Remote shell server: add SIGIO handler earlier
    • Drop obsolete references to HTTPS Everywhere and fix deleting uBlock from the
      Unsafe Browser (zerotracepen/zerotracepen!1548)

      Commits:

      • Remove another trace of HTTPS Everywhere
      • Revert "Unsafe Browser: disable uBlock Origin"
      • Unsafe Browser: actually delete uBlock add-on
      • Drop obsolete references to HTTPS Everywhere
    • Avoid homepage blocked on new identity (zerotracepen/zerotracepen!1547)

      Closes issues:

      • "Tor Browser blocked your homepage (zerotracepen.net) from loading because it might
        recognize your previous session." (see screenshot) (zerotracepen/zerotracepen#20381)

      Commits:

      • Avoid homepage being blocked on new identity
    • Use time.monotonic for timeouts (zerotracepen/zerotracepen!1543)

      Closes issues:

      • Use time.monotonic for timeouts (zerotracepen/zerotracepen#20400)

      Commits:

      • Use time.monotonic for timeouts
    • Make boot log artifact accessible in Jenkins (zerotracepen/zerotracepen!1542)

      Closes issues:

      • boot log artifact is not accessible in Jenkins (zerotracepen/zerotracepen#20396)

      Commits:

      • Test suite: Fix file extension of failure artifacts
      • Make boot log artifact accessible in Jenkins
    • Fix GNOME's OOM notification module (zerotracepen/zerotracepen!1541)

      Commits:

      • Enable the 7782-warn-on-oom APT overlay (refs: #7782).
    • Update deb.torproject.org's APT key (zerotracepen/zerotracepen!1540)

      Closes issues:

      • Included deb.torproject.org APT key will not be valid in 3 months
        (zerotracepen/zerotracepen#20340)

      Commits:

      • Update deb.torproject.org's APT key
    • Thunderbird: re-enable pdf.js that was temporarily disabled in Zero Trace Pen 6.3 due to
      CVE-2024-4367 (zerotracepen/zerotracepen!1539)

      Closes issues:

      • Thunderbird: re-enable pdf.js (zerotracepen/zerotracepen#20385)

      Commits:

      • Revert "Thunderbird: temporarily disable pdf.js in Zero Trace Pen 6.3 to fix
        CVE-2024-4367"
    • Fix build of zerotracepen:gitlab-triage-stable container image (zerotracepen/zerotracepen!1538)

      Closes issues:

      • Cannot update zerotracepen:gitlab-triage-stable container image (zerotracepen/zerotracepen#20387)

      Commits:

      • Fix build of zerotracepen:gitlab-triage-stable container image
    • Test suite: Bump timeout of waiting for Persistent Storage to be unlocked,
      again (zerotracepen/zerotracepen!1533)

      Closes issues:

      • Step "I enable persistence" is fragile (zerotracepen/zerotracepen#20390)

      Commits:

      • Test suite: Bump timeout again
    • Test suite: Enter language via Dogtail (zerotracepen/zerotracepen!1532)

      Closes issues:

      • Step "I log in to a new session $LANG" is fragile (zerotracepen/zerotracepen#20388)

      Commits:

      • Test suite: Make opening language popover more robust
      • Test suite: Enter language via Dogtail
    • tps-frontend: Fix journalctl command in error message (zerotracepen/zerotracepen!1530)

      Commits:

      • tps-frontend: Fix journalctl command in error message
    • tps: Only trigger udev events for the tps partition (zerotracepen/zerotracepen!1516)

      Closes issues:

      • Unexpected pipewire error in the journal (zerotracepen/zerotracepen#20344)
      • tpsd: don't use full-blown "udevadm trigger" and "udevadm settle" when it's not
        necessary (zerotracepen/zerotracepen#20020)

      Commits:

      • tps: Call udevadm trigger --settle with a timeout
      • Fix Ruff RUF005
      • Fix Ruff F541
      • Suppress Ruff PLW1510
      • Fix Ruff UP035
      • tps: Remove stacklevel of "Executing hook" log message
      • tps: Fix stacklevel of log functions
      • tps: Remove unused function
      • tps: Print the triggered udev events
      • tps: Wait for triggered udev events to finish
      • tps: Only trigger udev events for the tps partition
      • Ruff format
      • Fix type annotation
    • zerotracepen-detect-disk-ioerrors: Minor improvements to formatting and code comments
      (zerotracepen/zerotracepen!1511)

      Commits:

      • Remove empty lines
      • Inline _add_pattern_boot_device
      • Improve comments
      • Fix formatting
      • Fix typo
      • Fix spelling of SquashFS
      • Fix indentation
      • Remove copyright notice
    • Test suite: stream the journal from the guest over a virtio channel
      (zerotracepen/zerotracepen!1506)

      Closes issues:

      • Test suite: continuously stream the journal from the guest to the host
        (zerotracepen/zerotracepen#20366)

      Commits:

      • Appease ruff
      • Test suite: make JournalDumper#start always restart
      • Test suite: ensure we clean up for the next scenario in the After hook
      • Test suite: stop Tor later in After hook
      • Test suite: fix typo
      • Test suite: also restart JournalDumper after saving an internal snapshot
      • Appease ruff
      • Test suite: try to make the journal dumper not miss the last few entries
      • Test suite: make code more readable
      • Test suite: consistently check that the remote shell is up before using it in
        After hook
      • Remote shell server: log when opening files
      • Test suite: reorder stuff in After hook so all remote shell interaction's are
        caught in the journal
      • Appease rubocop
      • Test suite: stream the journal from the guest over a virtio channel
      • Test suite: refactor
    • Cloner: improve error message when target device has filesystems in use that
      cannot be unmounted (zerotracepen/zerotracepen!1504)

      Closes issues:

      • Cloner: follow up on !1504, consider improvements to phrasings
        (zerotracepen/zerotracepen#20383)
      • Improve error message when Zero Trace Pen Cloner can't format the destination USB stick
        because it's already mounted (zerotracepen/zerotracepen#19253)

      Commits:

      • Reformat with black and appease ruff
      • Appease ruff
      • Reformat with black
      • Cloner: improve phrasing based on reviewers comments
      • Cloner: raise TargetDeviceBusy with message as required
      • Cloner: make cases more explicit
      • Cloner: improve error message when target device has filesystems in use that
        cannot be unmounted
    • Test suite: make --interactive-debugging run pry in the failure's context
      (zerotracepen/zerotracepen!1481)

      Commits:

      • Test suite: improve filename
      • Add example of stack navigation in the automated test suite's debugging REPL
      • Drop unnecessary part of path
      • Test suite: drop unnecessary newline
      • Appease rubocop
      • Test suite: group stack commands under "Stack navigation"
      • Test suite: print stack neighborhood after moving down/up in the stack
      • Test suite: refactor
      • Appease rubocop
      • Test suite: add commands to Pry to navigate and show the stack
      • Test suite: log any of our methods we skip when injecting a pause() breakpoint
      • Test suite: replace crazy monkeypatch with bindex and binding_of_caller
      • Test suite: move pause() into its own file
      • Test suite: reorder cases so the special ones that need explanation are in the
        top
      • Test suite: refactor comment
      • Test suite: exempt a few more helpers from --interactive-debugging
      • Test suite: simplify
      • Test suite: adapt to new libvirt error message
      • Revert "Tests suite: temporarily add tests that were useful when developing the
        interactive debugging monkeypatch"
      • Tests suite: temporarily add tests that were useful when developing the
        interactive debugging monkeypatch
      • Appease rubocop
      • Test suite: make --interactive-debugging run pry in the failure's context
      • Test suite: freeze constants
      • Test suite: make sure we only apply monkeypatch once
      • Test suite: split code for improved organization
    • Unlock VeraCrypt Volumes: Fix second unlock dialog being opened
      (zerotracepen/zerotracepen!1457)

      Closes issues:

      • Test suite: Scenario "Use Unlock VeraCrypt Volumes to unlock a basic VeraCrypt
        file container with a PIM" is flaky (zerotracepen/zerotracepen#20281)
      • unlock-veracrypt-volumes opens second unlock dialog (zerotracepen/zerotracepen#20280)

      Commits:

      • Fix Ruff INT002
      • Fix Ruff A003
      • Suppress Ruff E402
      • Fix Ruff UP035
      • Fix Ruff INT002
      • Suppress Ruff RUF001
      • Fix Ruff UP031
      • Fix Ruff UP018
      • Fix Ruff UP004
      • Suppress Ruff E402
      • Unlock VeraCrypt Volumes: Fix "An operation is already pending"
      • Unlock VeraCrypt Volumes: Fix lock button doing nothing if volume is not
        mounted
      • Fix Ruff UP004
      • Fix Ruff UP035
      • Unlock VeraCrypt Volumes: Fix second unlock dialog being opened
    • Store a random seed (zerotracepen/zerotracepen!1431)

      Closes issues:

      • Persist a random seed across boots (zerotracepen/zerotracepen#11897)

      Commits:

      • Remove "Waiting for the Zero Trace Pen system partition..." plymough message
      • Update plymouth messages
      • Update design doc on entropy pool initialization
      • Also use unbuffered I/O when updating random seed during shutdown
      • Suppress Ruff S103
      • Fix Ruff ISC001
      • Fix Ruff UP008
      • Fix Ruff UP009
      • Add comment to zerotracepen-start-system-gnome-session-target.service
      • Use unbuffered I/O when updating random seed
      • Update random seed after the GNOME session has started
      • Test suite: Wait for the random seed to be updated
      • Test suite: Simplify random seed check
      • Add quotes in variable assignment as requested by reviewer
      • Suppress shellcheck SC2034
      • Update the random seed late during boot
      • Avoid plymouth error message
      • Show Plymouth messages
      • read-and-update-random-seed-sector: Move to earlier init-top stage
      • Test suite: Test the random seed feature
      • early_patch: Add note to comment that panic doesn't work with set -e
      • read-and-update-random-seed-sector: Print messages
      • read-and-update-random-seed-sector: Silence dd
      • Try to obfuscate how many times Zero Trace Pen was booted
      • Update design section on entropy pool initialization
      • Zero Trace Pen Cloner: Write random seed
      • partitioning: Check if parent device is actually accessible
      • Add design section for entropy pool initialization
      • Disable systemd-random-seed.service
      • Improve how the random seed is stored (refs: #11897)
      • Relate to Feature #11897: improve the storage of the random seed
      • Relate to Feature #11897: store a random seed file after the GPT.
      • According to the systemd random seed service source
      • Improve random seed installation by a initramfs script on boot time. Implements
      • Create random seed at installation time with Zero Trace Pen Installer,