Follow-ups Bug in who after installing 1.0.8 Undefined errors uninstalling the 1.0.8 patch ElkArte 1.0.8 - Release announcement July 31, 2016, 10:24:57 am Update: after the release a couple of issues have been discovered:1) the "Who is online" page will not display correctly the IP addresses,2) if using high level of caching, the menu may disappear.The first is a mostly cosmetic bug, the second can be worked around by reducing temporarily the caching level. It's indeed sub-optimal, but better than a security hole I guess.Both are going to be addressed soon, an "unofficial" patch that fixes both is available as attachment to the following message:http://www.elkarte.net/community/index.php?topic=3907.msg27726#msg27726If you really need both fixed you can download the patch and install it, though it will be released "officially" in the next 24 hours with more fixes if needed.Sorry for the trouble.Today, we are pleased to release ElkArte 1.0.8. This release fixes a security issue related to the unserialize php function (related to CVE-2016-5726 and CVE-2016-5727). The release fixes also some bugs that were found or reported since the release of 1.0.7. As this is a security release, it is extremely important to update for everyone running ElkArte.If you are running a version prior to 1.0.7, the recommended procedure is install any update since 1.0.7 and then the 1.0.8 patch.Apart from fixing the security issue, some notable updates in 1.0.8 include: stopped using INET_ATON and INET_NTOA to improve IPv6 handling, fixed YouTube embedding URLs to avoid problems in certain conditions,* fixed editing of polls with expiration date,This release follows our semantic version (MAJOR.MINOR.PATCH), meaning that third-point (x.x.X) releases should contain backwards-compatible bug fixes and enhancements, so for the most part you will not find new features in this release. Major new features will be reserved for second point versions (x.X.x).Refer to the release notes on the forum for a complete list of updates.Patching procedure: go to the page https://github.com/ElkArte/ElkArte/releases/tag/v1.0.8 download the file ElkArte_1-0-8_patch.zip to your computer go to your forum: Admin > Main > Package Manager > Upload Package click the button to upload the package locate and select the file you downloaded at point 2 click the "upload" button follow the instructions on the screen.For any question you may have, feel free to ask on the support forum.Of course you are encouraged to update to this release since it contains a lot of fixes and improvements, thank you for your continued support!
Re: ElkArte 1.0.8 - Release announcement Reply #1 – July 31, 2016, 11:28:58 am Thanks for the release
Re: ElkArte 1.0.8 - Release announcement Reply #2 – July 31, 2016, 01:03:41 pm How's the OpenID bug coming?
Re: ElkArte 1.0.8 - Release announcement Reply #3 – July 31, 2016, 01:49:23 pm Finished updating to 1.0.8. Thank you very much for this release.I can also confirmed what @scripple just said above.
Re: ElkArte 1.0.8 - Release announcement Reply #4 – July 31, 2016, 01:55:42 pm So should i update now or wait till the issue is fixed?
Re: ElkArte 1.0.8 - Release announcement Reply #5 – July 31, 2016, 01:59:28 pm Quote from: Jason – July 31, 2016, 01:55:42 pmSo should i update now or wait till the issue is fixed?Wait a bit @Jason
Re: ElkArte 1.0.8 - Release announcement Reply #6 – July 31, 2016, 02:38:30 pm Quote from: Jason – July 31, 2016, 01:55:42 pmSo should i update now or wait till the issue is fixed?If you value more an IP address than your forum security, wait.If you can live with a couple of issues until they are fixed, install it.I'm going to split the bug reports in their own topics, otherwise it becomes a mess. http://www.elkarte.net/community/index.php?topic=3907.0http://www.elkarte.net/community/index.php?topic=3908.0
Re: ElkArte 1.0.8 - Release announcement Reply #7 – July 31, 2016, 04:35:07 pm Posted an update to the first message, and posting it here as well for redundancy:QuoteUpdate: after the release a couple of issues have been discovered:1) the "Who is online" page will not display correctly the IP addresses,2) if using high level of caching, the menu may disappear.The first is a mostly cosmetic bug, the second can be worked around by reducing temporarily the caching level. It's indeed sub-optimal, but better than a security hole I guess.Both are going to be addressed soon, an "unofficial" patch that fixes both is available as attachment to the following message:http://www.elkarte.net/community/index.php?topic=3907.msg27726#msg27726If you really need both fixed you can download the patch and install it, though it will be released "officially" in the next 24 hours with more fixes if needed.Sorry for the trouble.
Re: ElkArte 1.0.8 - Release announcement Reply #8 – August 02, 2016, 01:16:59 pm Quote from: emanuele – July 31, 2016, 04:35:07 pmPosted an update to the first message, and posting it here as well for redundancy:QuoteUpdate: after the release a couple of issues have been discovered:1) the "Who is online" page will not display correctly the IP addresses,2) if using high level of caching, the menu may disappear.The first is a mostly cosmetic bug, the second can be worked around by reducing temporarily the caching level. It's indeed sub-optimal, but better than a security hole I guess.Both are going to be addressed soon, an "unofficial" patch that fixes both is available as attachment to the following message:http://www.elkarte.net/community/index.php?topic=3907.msg27726#msg27726If you really need both fixed you can download the patch and install it, though it will be released "officially" in the next 24 hours with more fixes if needed.Sorry for the trouble.So has the 'official' fix been released yet?
Re: ElkArte 1.0.8 - Release announcement Reply #9 – August 02, 2016, 03:24:34 pm Considering the original patch was postponed by at least a couple of days I would be surprised if I were able to push it out in 24 hours... That aside, I'm waiting to see if it's possible to fix another issue with the sessions in php 7 while we are at it.
Re: ElkArte 1.0.8 - Release announcement Reply #10 – August 02, 2016, 07:22:00 pm Quote from: emanuele – August 02, 2016, 03:24:34 pmThat aside, I'm waiting to see if it's possible to fix another issue with the sessions in php 7 while we are at it.I am about to ask about this. My EA1.1b1 shows whitepage on php7. EA1.0.8 works fine on php7 (at least I can see no errors so far).
Re: ElkArte 1.0.8 - Release announcement Reply #12 – August 03, 2016, 11:03:08 am When trying to install the patch I get:42.Execute Modification./sources/subs/ScheduledTask.class.phpTest failed1.Replace./sources/subs/ScheduledTask.class.phpTest successful2.Replace./sources/subs/ScheduledTask.class.phpTest failed3.Replace./sources/subs/ScheduledTask.class.phpTest successful4.Replace./sources/subs/ScheduledTask.class.phpTest successfuand...FaceIt-FaceIt100Execute Modification./themes/FaceIt-FaceIt100/scripts/elk_jquery_embed.jsTest failed1.Replace./themes/FaceIt-FaceIt100/scripts/elk_jquery_embed.jsTest failed2.Replace./themes/FaceIt-FaceIt100/scripts/elk_jquery_embed.jsTest successful
Re: ElkArte 1.0.8 - Release announcement Reply #13 – August 03, 2016, 11:18:30 am The one in the theme could be the theme itself is using an older version of the file that changed in the meantime and now is out-of-sync. I should check it.The one about ScheduledTask.class... could you attach it here?
Re: ElkArte 1.0.8 - Release announcement Reply #14 – August 03, 2016, 12:31:36 pm Attached is the file. I think it was modified a while back to fix a bug on the subscriptions task.