Bug 26018 - Our cryfs is old, new version brings more security, integrity, usability and performance.
Summary: Our cryfs is old, new version brings more security, integrity, usability and ...
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: David GEIGER
QA Contact:
URL:
Whiteboard:
Keywords: Backport
Depends on:
Blocks:
 
Reported: 2020-01-04 23:18 CET by Morgan Leijström
Modified: 2020-06-16 18:53 CEST (History)
0 users

See Also:
Source RPM: cryfs-0.9.10-1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description Morgan Leijström 2020-01-04 23:18:22 CET
Description of problem:
Our cryfs 0.9.10 is a year old, while development have progressed, improving performance, security, integrity, easier use etc, and also adding windows client ( = more useful on Mageia too) 

The 0.10.x versions have a different filesystem but thankfully can migrate from 0.9.10 - which is the one we have :)

Reading the changelog https://github.com/cryfs/cryfs/releases i can not see a problem, and if packaged in mga7-64 testing i can do real life testing of filesystem migration and syncing the encrypted folder by means of our NextCloud client.
Comment 1 David Walser 2020-01-05 05:17:12 CET
It sounds like 0.10.x wouldn't be an appropriate stable update per our policies, but 0.9.11 would have all of the same fixes.

Assignee: bugsquad => geiger.david68210

Comment 2 Morgan Leijström 2020-01-19 15:31:59 CET
I find 0.9.11 only have one fix over 0.9.10, regarding a race condition:
https://github.com/cryfs/cryfs/compare/0.9.10...0.9.11

0.10.x have a plenty of fixes and improvements regarding speed and security.
https://github.com/cryfs/cryfs/compare/0.9.10...0.10.2
I guess the file system change (though automatic) is the culprit for not putting in updates? (downgrading after filesystem change wont work with old data!)

But we definately want 0.10.x in mga8.
And backport to mga7 would be nice :)

Keywords: (none) => Backport
Version: 7 => Cauldron

Comment 3 David GEIGER 2020-06-16 15:19:51 CEST
Latest 0.10.2 release now in Cauldron!

I can't update for mga7 as we need libcryptopp >= 8.0.

So let's close this bug.

Resolution: (none) => FIXED
Status: NEW => RESOLVED

Comment 4 Morgan Leijström 2020-06-16 18:53:19 CEST
Nice, thanks :)

Note You need to log in before you can comment on or make changes to this bug.