Status of module from perspective of update_status

snorkers - October 14, 2009 - 20:54
Project:OG Vocabulary
Version:6.x-1.0
Component:Miscellaneous
Category:support request
Priority:normal
Assigned:Unassigned
Status:closed
Description

There was a security alert for 6.x-1.0rc1 (604514 - SA-CONTRIB-2009-071 - Organic Groups Vocabulary Access Bypass) recommending an immediate upgrade to 1.0. 6.x-1.0 took several hours to appear on d.o for download... and having downloaded, it's almost immediately been revoked (in /admin/reports/updates) stating it's no longer available for download.

Should this module be completely disabled, or is there a solution on the horizon?

#1

Amitaibu - October 14, 2009 - 21:06
Priority:critical» normal
Status:active» postponed (maintainer needs more info)

This module is very much alive, you should use this version -- http://drupal.org/node/604354

> it's almost immediately been revoked

What do you mean by that?

#2

snorkers - October 14, 2009 - 21:18

Downloaded and updated the module, and this is what I have in /admin/reports/status is attached as screen shot.

Worried that if it had taken a while to be released via d.o, then revoked *within minutes* that there was a problem you'd uncovered after the commit

AttachmentSize
Screen shot of 'Available updates' 51.76 KB

#3

greggles - October 14, 2009 - 21:19
Title:Status of Module? Revoked?» Status of module from perspective of update_status
Status:postponed (maintainer needs more info)» needs review

I must apologize for this. I didn't publish the release quickly.

There is another potential problem, though. The og_vocab.info file has packaging information in it that should not be there. This could be confusing the sites about which version is installed.

AttachmentSize
og_vocab_info_fixup.patch 572 bytes

#4

snorkers - October 14, 2009 - 21:20
Title:Status of module from perspective of update_status» Status of Module? Revoked?
Status:needs review» postponed (maintainer needs more info)

Sorry file didn't seem to upload

AttachmentSize
screen-shot-avail-updates.png 51.76 KB

#5

snorkers - October 14, 2009 - 21:34
Title:Status of Module? Revoked?» Status of module from perspective of update_status
Status:postponed (maintainer needs more info)» needs review

Applied the patch (stripping out the DEV references) and I still have revoked as the status of the module in 'Available Updates'. Judging from the comments above, all is well with the module and it has not been revoked by the maintainers.

Also changing back status and title changes (sorry @greggles, we must have hit submit at the same time).

#6

greggles - October 14, 2009 - 22:25

No problem. Also, note that there is a ~6 hour delay between publishing a release and the update status module knowing about it. So, let's also wait for tomorrow to see if that fixes it.

#7

snorkers - October 15, 2009 - 17:06
Status:needs review» closed

The problem seems to have gone away... Also tried in a separate D6 install and the 'Revoked' message has gone too.

Closing issue as nobody else seems to have encountered the problem on the same day as the update was released.

 
 

Drupal is a registered trademark of Dries Buytaert.