<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?status=closed&amp;milestone=Maintenance&amp;group=resolution&amp;order=summary</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?status=closed&amp;milestone=Maintenance&amp;group=resolution&amp;order=summary</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/774</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/774</guid>
        <title>#774: * Advisory ID: DRUPAL-SA-CORE-2014-004</title>
        <pubDate>Wed, 06 Aug 2014 19:52:54 GMT</pubDate>
        
        <dc:creator>paul</dc:creator>

        <description>&lt;p&gt;
View online: &lt;a class="ext-link" href="https://www.drupal.org/SA-CORE-2014-004"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/SA-CORE-2014-004&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Advisory ID: DRUPAL-SA-CORE-2014-004
&lt;/li&gt;&lt;li&gt;Project: Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Version: 6.x, 7.x
&lt;/li&gt;&lt;li&gt;Date: 2014-August-06
&lt;/li&gt;&lt;li&gt;Security risk: 13/25 ( Moderately Critical)
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
AC:None/A:None/CI:None/II:None/E:Proof/TD:100 &lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt;
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Exploitable from: Remote
&lt;/li&gt;&lt;li&gt;Vulnerability: Denial of service
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Drupal 6 and Drupal 7 include an XML-RPC endpoint which is publicly available
(xmlrpc.php). The PHP XML parser used by this XML-RPC endpoint is vulnerable
to an XML entity expansion attack and other related XML payload attacks which
can cause CPU and memory exhaustion and the site's database to reach the
maximum number of open connections. Any of these may lead to the site
becoming unavailable or unresponsive (denial of service).
&lt;/p&gt;
&lt;p&gt;
All Drupal sites are vulnerable to this attack whether XML-RPC is used or
not.
&lt;/p&gt;
&lt;p&gt;
In addition, a similar vulnerability exists in the core OpenID module (for
sites that have this module enabled).
&lt;/p&gt;
&lt;p&gt;
This is a joint release as the XML-RPC vulnerability also affects &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt;
(see the announcement &lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt;).
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;/A CVE identifier &lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; will be requested, and added upon issuance, in
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
accordance
with Drupal Security Team processes./
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Drupal core 7.x versions prior to 7.31.
&lt;/li&gt;&lt;li&gt;Drupal core 6.x versions prior to 6.33.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
Install the latest version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;If you use Drupal 7.x, upgrade to Drupal core 7.31 &lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt;.
&lt;/li&gt;&lt;li&gt;If you use Drupal 6.x, upgrade to Drupal core 6.33 &lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt;.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
If you are unable to install the latest version of Drupal immediately, you
can alternatively remove the xmlrpc.php file from the root of Drupal core (or
add a rule to .htaccess to prevent access to xmlrpc.php) and disable the
OpenID module. These steps are sufficient to mitigate the vulnerability in
Drupal core if your site does not require the use of XML-RPC or OpenID
functionality. However, this mitigation will not be effective if you are
using a contributed module that exposes Drupal's XML-RPC API at a different
URL (for example, the Services module); updating Drupal core is therefore
strongly recommended.
&lt;/p&gt;
&lt;p&gt;
Also see the Drupal core &lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; project page.
&lt;/p&gt;
&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Willis Vandevanter &lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Nir Goldshlager &lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;Andrew Nacin &lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; Security Team
&lt;/li&gt;&lt;li&gt;Michael Adams &lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; Security Team
&lt;/li&gt;&lt;li&gt;Frédéric Marand &lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;David Rothstein &lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Damien Tournoud &lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Greg Knaddison &lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Stéphane Corlosquet &lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;li&gt;Dave Reid &lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; of the Drupal Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;ul&gt;&lt;li&gt;The Drupal Security Team &lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; and the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; Security Team
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;hr /&gt;
&lt;p&gt;
The Drupal security team can be reached at security at drupal.org or via the
contact form at &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt; &lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
Learn more about the Drupal Security team and their policies &lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt;, writing
secure code for Drupal &lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt;, and securing your site &lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[1]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[2]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team/risk-levels"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team/risk-levels&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[3]&lt;/a&gt; &lt;a class="ext-link" href="https://wordpress.org/news/2014/08/wordpress-3-9-2/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/news/2014/08/wordpress-3-9-2/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[4]&lt;/a&gt; &lt;a class="ext-link" href="http://cve.mitre.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://cve.mitre.org/&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[5]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/drupal-7.31-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/drupal-7.31-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[6]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/drupal-6.33-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/drupal-6.33-release-notes&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[7]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/project/drupal"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/project/drupal&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[8]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/1867894"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/1867894&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[9]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/2891345"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/2891345&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[10]&lt;/a&gt; &lt;a class="ext-link" href="http://profiles.wordpress.org/nacin"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://profiles.wordpress.org/nacin&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[11]&lt;/a&gt; &lt;a class="ext-link" href="http://profiles.wordpress.org/mdawaffe"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://profiles.wordpress.org/mdawaffe&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[12]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/27985"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/27985&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[13]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/124982"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/124982&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[14]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/22211"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/22211&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[15]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/u/greggles"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/u/greggles&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[16]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/52142"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/52142&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[17]&lt;/a&gt; &lt;a class="ext-link" href="https://www.drupal.org/user/53892"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.drupal.org/user/53892&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[18]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[19]&lt;/a&gt; &lt;a class="ext-link" href="http://wordpress.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://wordpress.org&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[20]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/contact&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[21]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security-team"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security-team&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[22]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/writing-secure-code"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/writing-secure-code&lt;/a&gt;
&lt;a class="missing changeset" title="No default repository defined"&gt;[23]&lt;/a&gt; &lt;a class="ext-link" href="http://drupal.org/security/secure-configuration"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://drupal.org/security/secure-configuration&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;&lt;/span&gt;&lt;span class="underline"&gt;_
Security-news mailing list
Security-news@…
Unsubscribe at &lt;a class="ext-link" href="https://lists.drupal.org/mailman/listinfo/security-news"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.drupal.org/mailman/listinfo/security-news&lt;/a&gt;
&lt;/span&gt;&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/774#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/820</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/820</guid>
        <title>#820: *.transitionnetwork.org 2015 security certificate</title>
        <pubDate>Fri, 26 Dec 2014 09:47:49 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The current wild-card &lt;tt&gt;*.transitionnetwork.org&lt;/tt&gt; cert will run out on 24th Jan, this is a ticket to track the time spent renewing it.
&lt;/p&gt;
&lt;p&gt;
See also &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/795" title="maintenance: SHA1 Deprecation: Regenerate all certs using SHA256 (closed: fixed)"&gt;ticket:795&lt;/a&gt;, SHA1 Deprecation: Regenerate all certs using SHA256.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/820#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/569</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/569</guid>
        <title>#569: 403s served to editors, admin very slow</title>
        <pubDate>Tue, 09 Jul 2013 07:52:32 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;ol&gt;&lt;li&gt;Rob is getting 403s when trying to submit his work. Report from 07:12am this morning (Tuesday)
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;Ed tried to add a blog post at node add:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/node/add/blog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/add/blog&lt;/a&gt;
It took nearly 15 seconds to get this published
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/ed-mitchell/2013-07/eds-test-blog-item-check-403"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/ed-mitchell/2013-07/eds-test-blog-item-check-403&lt;/a&gt;
&lt;/p&gt;
&lt;ol start="3"&gt;&lt;li&gt;Running admin functions takes ages.This request took well over 30 seconds:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/node/overview"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/node/overview&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Please advise?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/569#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/563</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/563</guid>
        <title>#563: 503 Errors</title>
        <pubDate>Wed, 19 Jun 2013 10:59:54 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The BOA &lt;tt&gt;/var/xdrago/second.sh&lt;/tt&gt; script is run every minute via the root crontab and if it detects a certain load level it changes the nginx config to a "high load" config which results in bots being served 503 errors when they spider the site. When the load goes higher and hits another threshold the &lt;tt&gt;second.sh&lt;/tt&gt; script stops the site, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555&lt;/a&gt;.
&lt;/p&gt;
&lt;h2 id="OriginalDescription"&gt;Original Description&lt;/h2&gt;
&lt;p&gt;
The site is generating a lot of 503 errors, 83 since 6:30am today and there were around 750 yesterday.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/563#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/843</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/843</guid>
        <title>#843: 8.8.8.8 (US/United States/google-public-dns-a.google.com) blocked for port scanning</title>
        <pubDate>Tue, 07 Apr 2015 23:05:33 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Never seen this before:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Date: Tue,  7 Apr 2015 23:46:09 +0100 (BST)
From: root@puffin.webarch.net
To: chris@webarchitects.co.uk
Subject: lfd on puffin.webarch.net: 8.8.8.8 (US/United States/google-public-dns-a.google.com) blocked for port scanning
Time:    Tue Apr  7 23:46:09 2015 +0000
IP:      8.8.8.8 (US/United States/google-public-dns-a.google.com)
Hits:    20
Blocked: Temporary Block
Sample of block hits:
Apr  7 23:45:36 puffin kernel: [19823338.636822] Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:16:3e:19:68:02:00:12:1e:13:6c:db:08:00 SRC=8.8.8.8 DST=81.95.52.103 LEN=162 TOS=0x00 PREC=0x00 TTL=45 ID=65064 PROTO=UDP SPT=53 DPT=48825 LEN=142
&lt;/pre&gt;&lt;p&gt;
I thought set the Google DNS servers for the machine via   /etc/resolv.conf but that contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;# Dynamic resolv.conf(5) file for glibc resolver(3) generated by resolvconf(8)
#     DO NOT EDIT THIS FILE BY HAND -- YOUR CHANGES WILL BE OVERWRITTEN
nameserver 127.0.0.1
&lt;/pre&gt;&lt;p&gt;
There is /etc/resolvconf/resolv.conf.d/original containing:
&lt;/p&gt;
&lt;pre class="wiki"&gt;nameserver 8.8.8.8
nameserver 8.8.4.4
&lt;/pre&gt;&lt;p&gt;
But I don't know what DNS resolver BOA has installed and the server is using.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/843#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/744</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/744</guid>
        <title>#744: Add CSS Injector module to the D6 mix</title>
        <pubDate>Thu, 19 Jun 2014 10:50:03 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
CSS Injector module allows admin dynamic adding of CSS in to a live production server without code updates. this is to respond quickly to client needs whilst implementing the requests in the correct place in the themes on the next promotion from dev.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/744#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/534</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/534</guid>
        <title>#534: Add accounts for Ben</title>
        <pubDate>Fri, 26 Apr 2013 17:16:23 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ben is a new member of the TTech team and accounts need setting up for him, this is a ticket to track the time taken to do this.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/534#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/632</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/632</guid>
        <title>#632: Add accounts for Sam</title>
        <pubDate>Mon, 25 Nov 2013 14:41:25 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Following &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/534" title="maintenance: Add accounts for Ben (closed: fixed)"&gt;ticket:534&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/632#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/649</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/649</guid>
        <title>#649: Add commenting to /films/ content type in January</title>
        <pubDate>Thu, 12 Dec 2013 10:53:16 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
seen here:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/node-type/films"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/node-type/films&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/films"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/films&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/films/occupy-love"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/films/occupy-love&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/649#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/643</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/643</guid>
        <title>#643: Add paginator for /films view</title>
        <pubDate>Mon, 09 Dec 2013 11:40:08 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please add pages links for this view:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/Films?destination=films#views-tab-page_1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/Films?destination=films#views-tab-page_1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
10 per page should do it
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/643#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/684</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/684</guid>
        <title>#684: Adding Paul and Nick to Transition Network on github.org</title>
        <pubDate>Thu, 23 Jan 2014 10:42:23 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
It looks like Ed and Jim are the only one with permissions to add members to &lt;a class="ext-link" href="https://github.com/orgs/transitionnetwork/members"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Transition Network on GitHub&lt;/a&gt; as they are listed as owners and the rest of us are members.
&lt;/p&gt;
&lt;p&gt;
Paul and Nick can you post you account names to this ticket so you can be added?
&lt;/p&gt;
&lt;p&gt;
Jim could you make me and/or Ben owners as well so we can add people?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/684#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/611</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/611</guid>
        <title>#611: Adding Trac Account for Alan</title>
        <pubDate>Thu, 17 Oct 2013 12:55:21 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Alan, the other sysadmin at Webarchitects is in a  better position than me to help with some of the more complex sysadmin issues so I hope it's OK that I have added an account for him here following the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/TracUserAdmin"&gt;wiki:TracUserAdmin&lt;/a&gt; notes.
&lt;/p&gt;
&lt;p&gt;
He is looking at helping with these tickets:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/599" title="maintenance: Server time drift (closed: fixed)"&gt;ticket:599&lt;/a&gt; Server time drift
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/555" title="maintenance: Load spikes causing the TN site to be stopped for 15 min at a time (closed: fixed)"&gt;ticket:555&lt;/a&gt; Load spikes causing the TN site to be stopped for 15 min at a time
&lt;/li&gt;&lt;li&gt;&lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/593" title="maintenance: Migrating Puffin to a ZFS file server (closed: fixed)"&gt;ticket:593&lt;/a&gt; Migrating Puffin to a ZFS file server
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
I don't expect he will be recording much time, I hope that is OK, he already has sudo access to all the servers.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/611#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/888</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/888</guid>
        <title>#888: Adverts on Transition Network Front Page loaded via flickrit.com embedded content</title>
        <pubDate>Sun, 06 Dec 2015 12:25:49 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
It it intentional or accidental that adverts from &lt;a class="ext-link" href="https://secureads.bitbillions.com/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://secureads.bitbillions.com/&lt;/a&gt; are being loaded on the front page of &lt;a class="ext-link" href="https://www.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/&lt;/a&gt; via the embedded content from flickrit.com?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/888#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/610</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/610</guid>
        <title>#610: Aegir database intensive (migrate, clone, restore) tasks hang for larger sites</title>
        <pubDate>Tue, 15 Oct 2013 10:18:59 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
Large sites (TN.org and variants) will simply not complete their migrate, clone or restore tasks in Aegir.
&lt;/p&gt;
&lt;p&gt;
However, smaller sites are fine, and all tasks work for them.
&lt;/p&gt;
&lt;p&gt;
The process largely completes -- codebase installs, database is cloned, symlinks for sites aliases and files created... BUT the process never completes in Aegir, so the final steps of switching a site's served location never occurs.
&lt;/p&gt;
&lt;p&gt;
Useful links/comments in this issue:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://tech.transitionnetwork.org/trac/ticket/610#comment:30"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Tests of Aegir commands&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://drupal.org/node/984256"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/984256&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://omega8.cc/aegir-task-fails-or-spins-forever-126"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;How to fix: Aegir task fails or spins forever&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/610#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/548</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/548</guid>
        <title>#548: All Admin functions broken on TN.org</title>
        <pubDate>Tue, 14 May 2013 07:50:15 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Admins, editors, social reporters cannot create content on TN.org. Choosing to create content leads to homepage. Can't do anything on the admin menu.
&lt;/p&gt;
&lt;p&gt;
Emergency.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/548#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/779</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/779</guid>
        <title>#779: Annesley locked out of puffin?</title>
        <pubDate>Wed, 27 Aug 2014 14:28:12 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Looks like Annesley's IP has been blocked on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/779#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/630</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/630</guid>
        <title>#630: Archiving Transition Town Totnes site</title>
        <pubDate>Mon, 25 Nov 2013 11:54:35 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please estimate to archive TTT site as per conversation with Ed:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;convert to html
&lt;/li&gt;&lt;li&gt;host on Penguin (incl. any likely issues for Penguin doing this)
&lt;/li&gt;&lt;li&gt;any ongoing maintenance
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
Then Ed will discuss with Frances at TTT as per agreement with Chris
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/630#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/702</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/702</guid>
        <title>#702: Attachments not being deleted from Trustees page</title>
        <pubDate>Fri, 21 Mar 2014 17:11:14 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
I can't remove the attachments from the Trustees page:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/about/people/trustees"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/about/people/trustees&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
please investigate and sort if you can. We need to remove all the attachments apart from those in 2013.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/702#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/798</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/798</guid>
        <title>#798: BOA-2.3.5</title>
        <pubDate>Thu, 16 Oct 2014 12:40:58 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://raw.githubusercontent.com/omega8cc/boa/master/CHANGELOG.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;changelog&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.3.5 Release - Full Edition
### Date: Wed Oct 15 16:28:25 PDT 2014
### Includes Aegir 2.1 with improvements
### Latest hotfix added on: Wed Oct 15 20:09:52 PDT 2014
# Release Notes:
  This new BOA release includes important updates and bug fixes.
  * All new Drupal 7 platforms received Drupal core security upgrade.
    For details please read: https://www.drupal.org/SA-CORE-2014-005
  * All existing Drupal 7 built-in platforms will receive a hot-fix for
    this known vulnerability: https://www.drupal.org/SA-CORE-2014-005
    once you will run 'barracuda up-stable' command on your server.
    This procedure is automated on hosted and managed Aegir at Omega8.cc
  * Your custom D7 platforms created in the ~/static directory tree
    will be checked in the next 12 hours after the upgrade, and if you
    have not applied this patch yet, it will be applied automatically
    for you - but only if there is at least one active site present
    in the given custom D7 platform. Note that while this procedure is
    automated on hosted and managed Aegir at Omega8.cc, on self-hosted
    BOA systems it will work only if you will set _PERMISSIONS_FIX=YES
    in /root/.barracuda.cnf (default is NO)
  We recommend that you upgrade your D7 sites using safe workflow:
    https://omega8.cc/your-drupal-site-upgrade-safe-workflow-298
# Updated Octopus platforms:
  aGov 1.5 --------------------- https://drupal.org/project/agov
  Commerce 1.31 ---------------- https://drupal.org/project/commerce_kickstart
  Commerce 2.19 ---------------- https://drupal.org/project/commerce_kickstart
  Guardr 1.14 ------------------ https://drupal.org/project/guardr
  Open Atrium 2.22 ------------- https://drupal.org/project/openatrium
  Open Outreach 1.12 ----------- https://drupal.org/project/openoutreach
  OpenPublic 1.2 --------------- https://drupal.org/project/openpublic
  Panopoly 1.12 ---------------- https://drupal.org/project/panopoly
# New features and enhancements in this release:
  * Explain that Solr self-provisioning works only if _MODULES_FIX=YES is set.
  * Reverify all sites daily if /root/.force.sites.verify.cnf ctrl file exists
    and _PERMISSIONS_FIX=YES is set in /root/.barracuda.cnf (default is NO)
# Changes in this release:
  * Security: Remove support for SSLv3 due to POODLE vulnerability.
  * Disable Redis in Hostmaster until we will fix the Views based pages/blocks.
  * Disable site_readonly for non-dev sites by default.
  * Drush: Upgrade command line version 6 to mini-6-04-10-2014
  * Enable AllowUserFXP in Pure-FTPd config by default.
  * Remove support for already deprecated non-LTS Ubuntu versions.
  * Run manage_ip_auth_access only once per minute.
  * The INI variable redis_flush_forced_mode is enabled by default (again).
  * Use sysklogd instead of rsyslog on Ubuntu.
# System upgrades in this release:
  * MariaDB 5.5.40
  * Nginx 1.7.6
  * OpenSSH 6.7p1 (if installed from sources)
  * OpenSSL 1.0.1j (if installed from sources) - security upgrade.
  * PHPRedis: master-03-10-2014
# Fixes in this release:
  * Add auto-detection of Legacy Ruby patch level update on old systems.
  * Add cleanup for ghost/broken sites dirs leftovers.
  * Add missing cleanup for backup_migrate leftovers.
  * Always cleanup pid files on exit/abort.
  * Apply patch for SA-CORE-2014-005 in all shared D7 cores/built-in platforms.
  * Compass Tools: Install 1.9.3 ffi expected by older themes.
  * Fix db_port entry in all vhosts hourly.
  * Fix for broken erpal-7.x-2.0-7.31.1
  * Fix for broken site level drushrc.php file.
  * Fix for false alarm caused by ghost sites leftovers.
  * Fix for incorrect hash filtering on systems with OpenSSL built from sources.
  * Fix locales: Numerous fixes and improvements -- thanks ar-jan!
  * Fix typo in REVISIONS.
  * Force site Verify via frontend if drushrc.php has been fixed.
  * Issue #435 - SQL: Remove deprecated table_cache +update table_open_cache
  * Issue #440 - Improve innodb_buffer_pool_size calculation and add 10%
  * Issue #441 - New Relic is not disabled after removing newrelic.info file.
  * Issue #442 - Skip locked/fpmcheck if /root/.high_traffic.cnf exists.
  * Issue #444 - PHP: Remove useless sed replacement in pool.d/www{*}.conf
  * Issue #445 - Remote Import: update 6.x-2.x branch for Aegir 2.x and Drush 6
  * Issue #447 - Export LANG, LANGUAGE and all LC_ environment variables.
  * Issue #447 - Improve locales consistency.
  * Issue #447 - Set default LC_CTYPE and LC_COLLATE environment variables.
  * Issue #447 - Simplify locales configuration on Ubuntu.
  * Issue #448 - Enforce locale settings by configuring defaults.
  * Issue #452 - PHP build is broken with latest MariaDB 5.5.40
  * Make sure that db_port is never empty and defaults to 3306.
  * Make sure that firewall monitoring scripts never run simultaneously.
  * Make sure that standard caching is enabled in hostmaster.
  * Pause hostmaster tasks when RVM install for any user is running.
  * PHP: Do not run rebuilds if not needed.
  * PHP: Fix for broken upgrade logic on libcurl or libssl packages upgrade.
  * Remove acquia_connector from latest Commons to avoid broken installs.
  * Remove all legacy gems and re-install RVM/Ruby for root from scratch.
  * Remove legacy replacement to avoid converting symlinked includes into files.
  * SQL: Use correct defaults if MySQLTuner test failed.
  * Workaround for Drupal flood using 127.0.0.1 for all requests behind proxy.
### Stable BOA-2.3.4 Release - Full Edition
### Date: Wed Oct 15 09:51:08 PDT 2014
### Includes Aegir 2.1 with improvements
  Release Notes and changelog for BOA-2.3.4 has been merged into BOA-2.3.5
  above after security upgrades related to OpenSSL and SSLv3 have been added
  shortly after 2.3.4 release.
&lt;/pre&gt;&lt;p&gt;
I'm going to run this update tonight.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/798#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/589</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/589</guid>
        <title>#589: Blocking spammers at a firewall level</title>
        <pubDate>Fri, 06 Sep 2013 09:48:59 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
At the meeting on 5th September &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/585" title="maintenance: TTech Meeting 5th September 2013 (closed: fixed)"&gt;ticket:585&lt;/a&gt; one thing we discussed was that for August 2013:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;blockquote&gt;
&lt;p&gt;
More data is transferred for /user/register than the front page, 5.1GB compared to 3.6GB.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Most of this will be spam bots trying to register to post spam. Jim suggested that we could look at blocking some of these spam bots at a firewall level to save on resources. This ticket is to follow up on this suggestion.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/589#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/565</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/565</guid>
        <title>#565: Blogs breadcrumbs incorrect on listings views</title>
        <pubDate>Tue, 25 Jun 2013 13:21:56 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Blogs breadcrumbs are wrong at main all blogs view and one author's full list view:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blog&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/ed-mitchell"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/ed-mitchell&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Jim can you sort this in under 15 minutes (which is what you have left)
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/565#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/544</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/544</guid>
        <title>#544: CSF / LDF false positive blocks on Puffin</title>
        <pubDate>Sat, 04 May 2013 11:02:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ticket to keep track of CSF /LDF issues on Puffin, see &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#CSFLDF"&gt;wiki:PuffinServer#CSFLDF&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/544#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/628</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/628</guid>
        <title>#628: Change space notifications email from IJK.co.uk to TN.org</title>
        <pubDate>Thu, 21 Nov 2013 16:50:37 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
The space notifications are coming from "space.transitionnetwork.org" &amp;lt;jim@…&amp;gt;
&lt;/p&gt;
&lt;p&gt;
can you make them from
"space.transitionnetwork.org" and a suitable TN address?
&lt;/p&gt;
&lt;p&gt;
Do I need to set up a suitable TN address? Perhaps
&lt;/p&gt;
&lt;p&gt;
space@…?
&lt;/p&gt;
&lt;p&gt;
Or is there a standard drupal system one in place already?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/628#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/621</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/621</guid>
        <title>#621: Check and speed up updates to homepage sections: TC and slideshow</title>
        <pubDate>Mon, 18 Nov 2013 09:22:59 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Two bits of the homepage are taking ages to update once Rob has made the changes and it's driving him spare. He's waiting up to 30 mins for them to update.
&lt;/p&gt;
&lt;p&gt;
Please speed up the times that it takes the system to update these two parts of the homepage to *instant* if possible:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Slideshow on homepage (AKA: &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/slideshows?destination=newhome#views-tab-panel_pane_1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/slideshows?destination=newhome#views-tab-panel_pane_1&lt;/a&gt;).
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;Latest Transition Culture Blog pane on Homepage (AKA &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/tc_latest_blog?destination=newhome#views-tab-block_1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/tc_latest_blog?destination=newhome#views-tab-block_1&lt;/a&gt;)
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/621#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/658</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/658</guid>
        <title>#658: Check caching on Social Reporters views</title>
        <pubDate>Mon, 16 Dec 2013 14:59:38 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
The SRs are reporting very slow site updates - is this to do with not switching them over to the new views content caching? please check:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/blogs?destination=stories#views-tab-panel_pane_2"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/blogs?destination=stories#views-tab-panel_pane_2&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/block/configure/views/blogs-block_1?destination=newhome"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/block/configure/views/blogs-block_1?destination=newhome&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
And elsewhere there may be SR latest views?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/658#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/896</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/896</guid>
        <title>#896: Chive access to TN Drupal DB</title>
        <pubDate>Mon, 18 Jan 2016 17:56:44 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ade would like to give the developers of the new Transition Network  &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; site access to the live database via Chive.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/896#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/624</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/624</guid>
        <title>#624: Comment handling on pages: particularly Austerity one</title>
        <pubDate>Tue, 19 Nov 2013 11:16:02 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Rob is doing an austerity special over 8 days, with a different clip from an interview with NEF every day. I've set up a page here:
/austerity-basics
&lt;/p&gt;
&lt;p&gt;
Question:
&lt;/p&gt;
&lt;p&gt;
I know we can handle comments on pages, and I know that I don't get notifications of them. Can we arrange comment notifications for a page - asap - so that commenters get updates?
&lt;/p&gt;
&lt;p&gt;
If not, no problem. I heard about this plan *today* so am not expecting any massive tech leaps.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/624#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/777</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/777</guid>
        <title>#777: Comments to blog post only showing up when logged in</title>
        <pubDate>Mon, 25 Aug 2014 09:18:39 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Most of the comments to this blog post are only showing up when you are logged in:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/blogs/rob-hopkins/2014-07/fiona-ward-learning-celebrate-10000-failure#comment-17492"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/blogs/rob-hopkins/2014-07/fiona-ward-learning-celebrate-10000-failure#comment-17492&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Logged in: 5 comments
Not logged in: 1 comment
&lt;/p&gt;
&lt;p&gt;
Handing this to Sam but happy for it to escalate. Presumably this issue won't be on this one post only - and it is important.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/777#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/683</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/683</guid>
        <title>#683: Create Aegir account for Paul</title>
        <pubDate>Wed, 22 Jan 2014 12:42:48 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Jim
&lt;/p&gt;
&lt;p&gt;
It looks like i@… will be joining us to pick up some of your work.
&lt;/p&gt;
&lt;p&gt;
Could you create an Aegir account for him please?
&lt;/p&gt;
&lt;p&gt;
I was also wondering about the Transition Network Github repo, do we need to do anything to hand that over?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/683#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/822</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/822</guid>
        <title>#822: Create TRAC id for Ade</title>
        <pubDate>Wed, 07 Jan 2015 09:54:13 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
name: ade
email: adestuart@…
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/822#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/682</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/682</guid>
        <title>#682: Create Trac &amp; Wiki account for Paul</title>
        <pubDate>Wed, 22 Jan 2014 12:39:18 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi it looks like i@… will be joining us to pick up some of Jim's role as he moves on.
&lt;/p&gt;
&lt;p&gt;
Chris could you create a trac &amp;amp; Wiki account for him please?
&lt;/p&gt;
&lt;p&gt;
His email is; i@…
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/682#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/705</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/705</guid>
        <title>#705: Create a contents page on TransitionCulture.org Wordpress site</title>
        <pubDate>Wed, 26 Mar 2014 15:33:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Create a contents page on TC.org to see a listing of all the blog posts. Mike suggests:
"use category post list widget to pull in the titles and then use widgetise pages to add widget to a standard page.:
&lt;/p&gt;
&lt;p&gt;
Sam to follow up. MAX time: 1 hour.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/705#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/829</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/829</guid>
        <title>#829: Creation of web space request</title>
        <pubDate>Mon, 02 Feb 2015 10:11:03 GMT</pubDate>
        
        <dc:creator>ade</dc:creator>

        <description>&lt;p&gt;
Hi Chris,
As discussed, can you please set up some webspace on Penguin?
If you could also set up a sub-domain of 'projects' and confirm the FTP access details?
&lt;/p&gt;
&lt;p&gt;
Many thanks
Ade
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/829#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/208</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/208</guid>
        <title>#208: Dblog Issues</title>
        <pubDate>Fri, 17 Dec 2010 14:53:29 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;blockquote&gt;
&lt;p&gt;
"The dblog module monitors your website, capturing system events in a log to be reviewed by an authorized individual at a later time. The dblog log is simply a list of recorded events containing usage data, performance data, errors, warnings and operational information. It is vital to check the dblog report on a regular basis as it is often the only way to tell what is going on."
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/dblog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/dblog&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This is a ticket to be used to flag up issues that are not going to take up enough time that they justify their own ticket -- if an issue is raised in a comment on this ticket that does look like it's going to take some significant time then best start a new ticket for it.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/208#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/663</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/663</guid>
        <title>#663: De-commission the PSE</title>
        <pubDate>Wed, 18 Dec 2013 17:44:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
We are wrapping up the PSE to simplify our web traffic, codebase and support requirements before we move to TNv3.
&lt;/p&gt;
&lt;p&gt;
Ed has informed all the PSE alpha triallists twice and asked them to remove their widgets. About half have. Others say they will. So we can remove the service any time from now on.
&lt;/p&gt;
&lt;p&gt;
Ed has UNpublished the following pages:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;/pse/create
&lt;/li&gt;&lt;li&gt;/pse/about
&lt;/li&gt;&lt;li&gt;/pse/faq
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Jim - time to de-commission the service in a suitable way. Wrap this puppy up and turn it off. Please outline what you are going to do on this ticket and then do it.
&lt;/p&gt;
&lt;p&gt;
Ed suggests this is work for January 2014.
&lt;/p&gt;
&lt;p&gt;
Sam, Chris, fyi and any other changes needed?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/663#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/218</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/218</guid>
        <title>#218: Debian upgrades and updates</title>
        <pubDate>Thu, 06 Jan 2011 13:34:16 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is a ticket to track debian upgrades to the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; the time they take.
&lt;/p&gt;
&lt;p&gt;
See:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://lists.debian.org/debian-security-announce/recent"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Recent Debian security announcements&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://lists.askmonty.org/pipermail/announce/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MariaDB Announce List archives&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
These updates are generally done using the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/AptitudeUpdateScript"&gt;wiki:AptitudeUpdateScript&lt;/a&gt; and this records all the changes in the &lt;tt&gt;/root/Changelog&lt;/tt&gt; and then the contents of the Changelog are pasted into the ticket to document the upgrade.
&lt;/p&gt;
&lt;p&gt;
This ticket was was originally used for the &lt;del&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/DevelopmentServer"&gt;wiki:DevelopmentServer&lt;/a&gt;&lt;/del&gt; and the &lt;del&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/NewLiveServer"&gt;wiki:NewLiveServer&lt;/a&gt;&lt;/del&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/218#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/597</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/597</guid>
        <title>#597: Default owner for tickets</title>
        <pubDate>Tue, 17 Sep 2013 08:04:58 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Ben reported that the default owner for tickets is laura and that this should be changed.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/597#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/572</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/572</guid>
        <title>#572: Design changes for homepage and TC section</title>
        <pubDate>Wed, 17 Jul 2013 14:17:25 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Design changes for TN homepage and TC section done by Ben to be part of maintenance budget.
&lt;/p&gt;
&lt;p&gt;
list here:
&lt;a class="ext-link" href="https://docs.google.com/spreadsheet/ccc?key=0An7ZaZdq6UfJdDhxS0JxbXZLYnhLRkN4X3h5aVV3R1E#gid=0"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://docs.google.com/spreadsheet/ccc?key=0An7ZaZdq6UfJdDhxS0JxbXZLYnhLRkN4X3h5aVV3R1E#gid=0&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/572#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/667</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/667</guid>
        <title>#667: Development handover process</title>
        <pubDate>Wed, 08 Jan 2014 16:40:47 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Work by the Ttech team to share Jim's knowledge and tasks around the team before he leaves in early February 2014. Please use this ticket to log your time spent on this.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/667#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/696</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/696</guid>
        <title>#696: Disk space error on parrot for TTT site</title>
        <pubDate>Mon, 03 Mar 2014 10:51:46 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Message appearing at top of ttt website when I just took a look-
&lt;/p&gt;
&lt;pre class="wiki"&gt;Warning: session_start():
open(/home/ttt/tmp/sess_mnme76d2k5s6vopk5u1it126p5, O_RDWR) failed: No
space left on device (28) in
/home/ttt/sites/default/wp-content/plugins/tt-resource-database/participants-database.php
on line 2534
&lt;/pre&gt;&lt;p&gt;
and something in the sidebar -
&lt;/p&gt;
&lt;pre class="wiki"&gt;Warning: call_user_func_array() expects parameter 1 to be a valid
callback, array must have exactly two members in
/home/ttt/sites/default/wp-includes/plugin.php on line 199
&lt;/pre&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/696#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/911</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/911</guid>
        <title>#911: Disk space for /home on Parrot is running out</title>
        <pubDate>Mon, 30 May 2016 20:58:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Getting this alert from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; every 5 mins:
&lt;/p&gt;
&lt;pre class="wiki"&gt;transitionnetwork.org :: parrot.transitionnetwork.org :: Disk usage in percent
        WARNINGs: /home is 96.06 (outside range [:96]).
        OKs: /run/shm is 0.00, /run is 0.09, /dev is 0.00, / is 95.94, / is 95.94, /run/lock is 0.00.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/911#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/531</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/531</guid>
        <title>#531: Disk usage on puffin</title>
        <pubDate>Wed, 10 Apr 2013 13:12:24 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The disk usage on puffing is currently at 85% and it's been going up at around 5% a week, see:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/df.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://penguin.transitionnetwork.org/munin/transitionnetwork.org/puffin.transitionnetwork.org/df.html&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This will become a critical issue in a couple of weeks, it would be good to find and address the cause before then.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/531#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/648</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/648</guid>
        <title>#648: Edit the contact form reply in January</title>
        <pubDate>Thu, 12 Dec 2013 10:49:39 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Ed has edited the contact form replies for webproject@… on the contact form for TN.org which will now reply to users saying this:
&lt;/p&gt;
&lt;p&gt;
"Thank you for getting in touch. Please note that the website support is part time; and between mid-December 2013 and mid-January 2014 we are handing over the website support work as Ed goes on Paternity leave and Sam comes onboard, so please be patient - your replies are likely to take more time than usual. "
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/contact"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/contact&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
SAM - when you are ready - probably mid-Jan - you will want to edit this back to something more suitable like:
&lt;/p&gt;
&lt;p&gt;
Thank you for getting in touch. Please note that the website support is part time, so while we will get back to you as soon as we can, that may be a few days
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/648#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/494</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/494</guid>
        <title>#494: Email account for TRAC</title>
        <pubDate>Thu, 21 Feb 2013 10:16:37 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Set up: 'trac@…'
Password: going to Chris separately
Secure SSL/TLS Settings
Username: trac@…
Password: Use the email account’s password.
Incoming Server: mail.xssl.net
IMAP: Port 993
POP3: Port 995
Outgoing Server: mail.xssl.net
SMTP: Port 465
Authentication is required for IMAP, POP3, and SMTP.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/494#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/751</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/751</guid>
        <title>#751: Email alert changes</title>
        <pubDate>Tue, 01 Jul 2014 11:14:42 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;ol&gt;&lt;li&gt;Change the email alert template for news items to include the term 'news item' so it is:
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
"New news item: [title]"
&lt;/p&gt;
&lt;ol start="2"&gt;&lt;li&gt;When users click on the subs links at the bottom of their email alerts, and they are not logged in they get the ‘access denied’ screen. This is not good. Please investigate
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
(a) can this be changed (with small time investment)
(b) can we change the access denied blurb to include something human encouraging the user to login to continue the journey:
&lt;/p&gt;
&lt;p&gt;
"We are sorry for the inconvenience, but if you are seeing this screen having followed a link, you will probably need to login to continue with your request" (NB if they are coming from an email link with their id in it, how do we keep that journey so they get to the destinateion they wanted?)
&lt;/p&gt;
&lt;ol start="3"&gt;&lt;li&gt;When user clicks on the general subs link at the bottom of an email alert (and is not logged in), they get a 403 forbidden page. Not good - pls investigage
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/751#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/641</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/641</guid>
        <title>#641: Enable dynamic Munin graphs</title>
        <pubDate>Mon, 02 Dec 2013 15:25:45 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
If we only generate munin graphs on the fly we will also get the zoom function working, this example config looks good: &lt;a class="ext-link" href="http://uname.pingveno.net/blog/index.php/post/2013/08/25/Configure-Munin-graphs-with-Nginx-and-Debian-7"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://uname.pingveno.net/blog/index.php/post/2013/08/25/Configure-Munin-graphs-with-Nginx-and-Debian-7&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/641#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/659</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/659</guid>
        <title>#659: Featured story on homepage not updating</title>
        <pubDate>Mon, 16 Dec 2013 17:03:41 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Rob cleared the nodequeue for the featured story on the homepage about three hours ago, removed all but one story. No change has been observed. Please investigate:
&lt;/p&gt;
&lt;p&gt;
Nodequeue:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/nodequeue/6/view/5"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/nodequeue/6/view/5&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This view:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/build/views/edit/featured_content?destination=newhome#views-tab-panel_pane_1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/build/views/edit/featured_content?destination=newhome#views-tab-panel_pane_1&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This is using content cache
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/659#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/695</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/695</guid>
        <title>#695: File upload problem with TTT WordPress site</title>
        <pubDate>Sun, 02 Mar 2014 19:46:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Laura has reported:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Had a report this evening that the TTT website isn't letting any uploads happen (adding of a new plugin by another admin, and also media/image uploads not being able to uploaded - no real error message as such just doesn't upload).
&lt;/p&gt;
&lt;p&gt;
I just logged in quickly to see if I could upload a pic to test and wouldn't upload.
Just wanted to check if anything had changed server side re permissions.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/695#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/679</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/679</guid>
        <title>#679: Filter Initiative by Country not working</title>
        <pubDate>Fri, 17 Jan 2014 17:15:58 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Filtering the initiatives by country is not working
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/initiatives?themes=All&amp;amp;community_type=All&amp;amp;status_value=All&amp;amp;country=at&amp;amp;field_title_search="&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/initiatives?themes=All&amp;amp;community_type=All&amp;amp;status_value=All&amp;amp;country=at&amp;amp;field_title_search=&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I had a play with the view on stg2.transitionnetwork.org but I couldn't get it working.
&lt;/p&gt;
&lt;p&gt;
It should display only initiatives from the country selected in the filter. It is displaying initiatives from all countries &amp;amp; not respecting the filter.
&lt;/p&gt;
&lt;p&gt;
This view is used a lot by international initiatives.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/679#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/571</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/571</guid>
        <title>#571: Force HTTP for anonymous, HTTPS for logged in users</title>
        <pubDate>Tue, 16 Jul 2013 11:59:54 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
To further reduce load and leverage the caching I've changed the Session 443 settings to force anon users to HTTP and logged in to HTTPS. The benefit of allowing a handful of users to choose is tiny compared the downsides of outages, 503s and higher load.
&lt;/p&gt;
&lt;p&gt;
The &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/settings/session443"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;"User state" setting on the config page&lt;/a&gt; is now " Redirect authenticated users to HTTPS and redirect anonymous users to HTTP (with the exception of login/registration pages).", was "Redirect authenticated users to HTTPS and redirect anonymous users on login/registration pages to HTTPS. Anonymous users visiting other pages may use HTTP or HTTPS."
&lt;/p&gt;
&lt;p&gt;
I've also set user and site-wide contact forms, plus the mailchimp subs page force secure-only per the "Additional pages to make secure" setting.
&lt;/p&gt;
&lt;p&gt;
We can see if this makes a difference, and this ticket is to track comments and see if it results in any improvement in performance/stability.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/571#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/786</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/786</guid>
        <title>#786: GitHub Transition: Annesley needs permission to create repositories</title>
        <pubDate>Mon, 15 Sep 2014 07:17:03 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
is Paul the owner of Transition &lt;a class="missing wiki"&gt;GitHub?&lt;/a&gt;?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/786#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/895</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/895</guid>
        <title>#895: HTTPS wildcard *.transitionnnetwork.org expires on 22nd January 2016</title>
        <pubDate>Mon, 11 Jan 2016 09:56:17 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Unless I hear otherwise I'll renew the &lt;tt&gt;*.transitionnnetwork.org&lt;/tt&gt; cert which is used by &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt;, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; at a cost of &lt;a class="ext-link" href="https://www.webarch.net/certs"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;£130.50&lt;/a&gt; on or before the 22nd January 2016 when the &lt;a class="ext-link" href="https://www.ssllabs.com/ssltest/analyze.html?d=transitionnetwork.org&amp;amp;latest"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;current one expires&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
An alternative would be to use &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/875" title="maintenance: Free HTTPS certificates from Let's Encrypt (new)"&gt;Free HTTPS certificates from Let's Encrypt&lt;/a&gt; but this would take some time to set up as &lt;a class="ext-link" href="https://www.letsencrypt.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Let's Encrypt&lt;/a&gt; don't provide wild card certs.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/895#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/921</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/921</guid>
        <title>#921: HTTP_PROXY env var vulnerability</title>
        <pubDate>Tue, 19 Jul 2016 12:34:30 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
See &lt;a class="ext-link" href="https://httpoxy.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://httpoxy.org/&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/921#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/617</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/617</guid>
        <title>#617: Help adding text to account creation email</title>
        <pubDate>Mon, 11 Nov 2013 17:16:37 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
I want to add a link to the email a user receives following their creation of an account.
&lt;/p&gt;
&lt;p&gt;
this one: Subject: Account details for [user] at Transition Network
&lt;/p&gt;
&lt;p&gt;
Can I do this myself? I've looked in subs, notifications, logintoboggan etc. and can't find the place
&lt;/p&gt;
&lt;p&gt;
is it do-able?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/617#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/650</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/650</guid>
        <title>#650: Helping TN strategy consultation with online publishing</title>
        <pubDate>Thu, 12 Dec 2013 11:00:08 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Sarah will be working on the TN strategy and this is about the content and comms tactics therein. The guiding principle is to use TN.org as the most suitable place for this material and conversations, and social media and direct mailshots for marketing and communicating it (because Sarah/TN cannot manage multiple conversations in multiple locations atm).
&lt;/p&gt;
&lt;p&gt;
This is work for Sam to do from January onwards
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;set up a landing page ".../TN-strategy-consultation" with its own RHS block with manual links to different documents and interviews
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
SAM this can be a normal page with anchor links etc.
&lt;/p&gt;
&lt;ol start="2"&gt;&lt;li&gt;Use of blogs
&lt;/li&gt;&lt;li&gt;Rob's for outreach - it's got the momentum - for updates/alerts/subscriptions
&lt;/li&gt;&lt;li&gt;Sarah's for continuity (and looking back at it) - using tag "fn-strategy-consultation"
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="3"&gt;&lt;li&gt;other places for comms/engagement
&lt;/li&gt;&lt;li&gt;Forums not good; too open to trolls and spam; better in blog comments
&lt;/li&gt;&lt;li&gt;webinar? Possibly if suitable
&lt;/li&gt;&lt;li&gt;FB, twitter, other marketing channels - for marketing only
&lt;/li&gt;&lt;li&gt;online meeting with national hubs - quite possibly
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="4"&gt;&lt;li&gt;Direct Mail shot to PPOCs
&lt;/li&gt;&lt;li&gt;Sarah Let Sam know if this is happening; Sam you'll need to do an export of PPOCs (&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/initiatives/primary-contacts"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/initiatives/primary-contacts&lt;/a&gt;), tidy and dump into mail chimp using the standard template
&lt;/li&gt;&lt;/ol&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/650#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/657</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/657</guid>
        <title>#657: Homepage slideshow: can't order the images</title>
        <pubDate>Mon, 16 Dec 2013 14:30:49 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Big picture slideshow on TN homepage: Rob can't get it to go in the order he wants - please investigate:
&lt;/p&gt;
&lt;p&gt;
It is this nodequeue:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/nodequeue/9/view/8"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/nodequeue/9/view/8&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Made up with these CTs:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/content/node-type/slide"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/content/node-type/slide&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/657#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/906</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/906</guid>
        <title>#906: I borked it</title>
        <pubDate>Tue, 01 Mar 2016 22:27:10 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
I recklessly tried to enable a module on the site that enabled sending articles to friends by email, this seems to have been one of my less-good ideas.
&lt;/p&gt;
&lt;p&gt;
It tried to enable a print-friendly page and this seems to have brought the whole crumbling edifice down
&lt;/p&gt;
&lt;p&gt;
Sorry about that. Can you fix it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/906#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/837</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/837</guid>
        <title>#837: Iframe in a panel page</title>
        <pubDate>Thu, 12 Mar 2015 11:55:21 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Ben
&lt;/p&gt;
&lt;p&gt;
I'm trying to embed a Eventbrite form into the 'tickets' block on this page: &lt;a class="ext-link" href="https://www.transitionnetwork.org/conference-2015"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/conference-2015&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
It looks like it's going to appear in the preview here: &lt;a class="ext-link" href="https://www.transitionnetwork.org/node/39195/panel_content"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/39195/panel_content&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
But when I view the actual page it's just a big white space.
&lt;/p&gt;
&lt;p&gt;
Could you estimate how long it would take to get it working?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/837#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/703</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/703</guid>
        <title>#703: Image not scaling on project</title>
        <pubDate>Wed, 26 Mar 2014 13:06:15 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
The REconomy logo is not scaling and being re-presented well on the project page:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/projects/reconomy"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/projects/reconomy&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Is this a theme/design issue or a problem with image re-sizing?
&lt;/p&gt;
&lt;p&gt;
What can we do about it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/703#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/704</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/704</guid>
        <title>#704: Image not scaling on project</title>
        <pubDate>Wed, 26 Mar 2014 13:51:48 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
The REconomy logo is not scaling and being re-presented well on the project page:
&lt;a class="ext-link" href="https://www.transitionnetwork.org/projects/reconomy"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/projects/reconomy&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Is this a theme/design issue or a problem with image re-sizing?
&lt;/p&gt;
&lt;p&gt;
What can we do about it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/704#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/710</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/710</guid>
        <title>#710: Incorrect email address for Sam on Transition Culture</title>
        <pubDate>Tue, 01 Apr 2014 12:01:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I'm seeing quite a few emails like this:
&lt;/p&gt;
&lt;pre class="wiki"&gt;From: Mail Delivery System &amp;lt;Mailer-Daemon@parrot.webarch.net&amp;gt;
Date: Tue, 01 Apr 2014 08:04:28 +0100
To: tc@parrot.webarch.net
Subject: Mail delivery failed: returning message to sender
This message was created automatically by mail delivery software.
A message that you sent could not be delivered to one or more of its
recipients. This is a permanent error. The following address(es) failed:
  samrossiter@transitionentwork.org
    Unrouteable address
------ This is a copy of the message, including all the headers. ------
Return-path: &amp;lt;tc@parrot.webarch.net&amp;gt;
Received: from tc (uid=1011)
        by parrot.webarch.net with local (Exim 4.80)
        (envelope-from &amp;lt;tc@parrot.webarch.net&amp;gt;)
        id 1WUskG-0005Rv-Sa
        for samrossiter@transitionentwork.org; Tue, 01 Apr 2014 08:04:28 +0100
To: samrossiter@transitionentwork.org
Subject: [Wordfence Alert] Problems found on Transition Culture
X-PHP-Originating-Script: 1011:class-phpmailer.php
Date: Tue, 1 Apr 2014 07:04:28 +0000
From: WordPress &amp;lt;wordpress@transitionculture.org&amp;gt;
Message-ID: &amp;lt;11e64e1b3cdb24f69d0069ecdc224524@transitionculture.org&amp;gt;
X-Priority: 3
X-Mailer: PHPMailer 5.2.4 (http://code.google.com/a/apache-extras.org/p/phpmailer/)
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset=UTF-8
Wordfence found the following new issues on "Transition Culture".
NOTE: Upgrading to the paid version of Wordfence gives you two factor authentication (sign-in via cellphone)
and country blocking which are both effective methods to block attacks.
You can also schedule when your scans occur with Wordfence Premium.
Click here to sign-up for the Premium version of Wordfence now.
https://www.wordfence.com/wordfence-signup/
Alert generated at Tuesday 1st of April 2014 at 08:04:28 AM
Critical Problems:
* The Plugin "Spam Destroyer" needs an upgrade.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/710#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/560</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/560</guid>
        <title>#560: Install drupal-based project management system onto our servers</title>
        <pubDate>Tue, 11 Jun 2013 17:00:28 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Please can you install a suitable project management drupal-based tool onto the suitable server? I am thinking of Open Atrium. It's for staff and partners to use for management stuff (ie not a ticketing system or mediawiki).
&lt;/p&gt;
&lt;p&gt;
Open Atrium?
&lt;/p&gt;
&lt;p&gt;
Can you let me know how long it would take to install to a point where I can manage it and get a pilot project up and running?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/560#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/673</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/673</guid>
        <title>#673: Install mosh - the mobile shell</title>
        <pubDate>Mon, 13 Jan 2014 11:27:40 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The mobile shell enables terminal connections to stay up when using really bad connections, for example on a train, see:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://mosh.mit.edu/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://mosh.mit.edu/&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/673#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/553</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/553</guid>
        <title>#553: Invalid response from server ERROR message</title>
        <pubDate>Tue, 28 May 2013 15:13:43 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
Trying to add a user. Get error message: "Received an Invalid response from the server" then served a blank screen. Same with project profile:
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/user/user/create"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/user/user/create&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/node/add/project-profile"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/node/add/project-profile&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
This has also happened for a user trying to add a project.
&lt;/p&gt;
&lt;p&gt;
Ed can add an event and blog post, ingredient, panel page.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/553#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/891</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/891</guid>
        <title>#891: Issue with TTT and REconomy websites after upgrade to WP 4.4</title>
        <pubDate>Thu, 17 Dec 2015 11:18:38 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Laura:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Just to let you know there's a bit of an oddity going on with both the TTT and
Reconomy websites.
&lt;/p&gt;
&lt;p&gt;
I upgraded to WP 4.4 after running full tests on my local copies here, and for
some odd reason images aren't showing on the site.  If you try to open an
image in the browser eg
&lt;a class="ext-link" href="https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.reconomy.org/wp-content/uploads/2015/10/hubs-logos-landscape.jpg&lt;/a&gt;
takes you to the -
"Server error!
The server encountered an internal error and was unable to complete your
request
Either the server is overloaded or there was an error in a CGI script.
Please return to the front page of the site."
&lt;/p&gt;
&lt;p&gt;
I've updated over 20 sites over the past few days (!) and these are the only
two this has happened on.
There are a few discussions here, (and have tried the temp fix of various
functions.php tweaks in the theme files to see if that helps, but it
doesn't)...
&lt;a class="ext-link" href="https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wordpress.org/support/topic/after-upgrade-to-44-media-files-are-not-showing&lt;/a&gt;
and even though sites are not appearing to use SSL wondering if related
somehow to that or other? Has this happened to any other WP 4.4 sites on your
servers?
&lt;/p&gt;
&lt;p&gt;
I'll let TTT and REconomy know their site has been updated, but there is a
glitch at present.
&lt;/p&gt;
&lt;p&gt;
I've also added Wordfence to the sites too as there are swathes of brute force
attacks happening on lots of WP sites everywhere currently and this plugin
seems to help somewhat currently.  I don't think it's the Wordfence plugin, as
disabled it to test the missing images issue.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/891#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/846</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/846</guid>
        <title>#846: Load Spikes on BOA PuffinServer</title>
        <pubDate>Thu, 16 Apr 2015 11:16:00 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Creating this as a ticket to record load spikes and related site outages.
&lt;/p&gt;
&lt;p&gt;
See &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#LoadSpikes"&gt;wiki:PuffinServer#LoadSpikes&lt;/a&gt; for links to historic issues of this nature.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/846#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/555</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/555</guid>
        <title>#555: Load spikes causing the TN site to be stopped for 15 min at a time</title>
        <pubDate>Wed, 29 May 2013 09:53:52 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The BOA &lt;tt&gt;/var/xdrago/second.sh&lt;/tt&gt; script is run every minute via the root crontab and if it detects a certain load level it changes the nginx config to a "high load" config which results in bots being served 503 errors when they spider the site, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/563" title="maintenance: 503 Errors (closed: fixed)"&gt;ticket:563&lt;/a&gt;. When the load goes higher and hits another threshold the &lt;tt&gt;second.sh&lt;/tt&gt; script kills the webserver applications, nginx and php-fpm, and waits till the load has dropped before starting them up again. This was happening once or twice a day following the increase in traffic around the launch of &lt;a class="ext-link" href="https://www.transitionnetwork.org/power-just-doing-stuff"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;The Power of Just Doing Stuff&lt;/a&gt;. This has been addressed by multiplying the thresholds by 5 in &lt;tt&gt;second.sh&lt;/tt&gt;.
&lt;/p&gt;
&lt;h2 id="OriginalDescription"&gt;Original Description&lt;/h2&gt;
&lt;p&gt;
This morning at 10:19:24 I received the following alert from puffin:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Subject: lfd on puffin.webarch.net: High 5 minute load average alert - 6.59
Time:                    Wed May 29 10:17:02 2013 +0100
1 Min Load Avg:          23.39
5 Min Load Avg:          6.59
15 Min Load Avg:         2.57
Running/Total Processes: 44/326
&lt;/pre&gt;&lt;p&gt;
At 10:21:57 I got an alert regarding ssh:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Service: SSH
Host: puffin
Address: puffin.webarch.net
State: CRITICAL
Date/Time: Wed May 29 10:21:57 BST 2013
Additional Info:
CRITICAL - Socket timeout after 10 seconds
&lt;/pre&gt;&lt;p&gt;
Then at 10:26:47 ssh appeared to have recovered:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Service: SSH
Host: puffin
Address: puffin.webarch.net
State: OK
Date/Time: Wed May 29 10:26:47 BST 2013
Additional Info:
SSH OK - OpenSSH_5.5p1 Debian-6+squeeze3 (protocol 2.0)
&lt;/pre&gt;&lt;p&gt;
But then pingdom reported at 10:29:07:
&lt;/p&gt;
&lt;pre class="wiki"&gt;www.transitionnetwork.org is down since 29/05/2013  10:24:57.
&lt;/pre&gt;&lt;p&gt;
There was then a report regarding Nginx at 10:32:07:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Notification Type: PROBLEM
Service: HTTP
Host: puffin
Address: puffin.webarch.net
State: CRITICAL
Date/Time: Wed May 29 10:32:07 BST 2013
Additional Info:
Connection refused
&lt;/pre&gt;&lt;p&gt;
So at 10:33:47 I ssh'd in and found that php53-fpm and nginx were not running and it took several attempts to get them running again.
&lt;/p&gt;
&lt;p&gt;
The up email from pingdom reported:
&lt;/p&gt;
&lt;pre class="wiki"&gt;www.transitionnetwork.org is UP again at 29/05/2013  10:36:57, after 12m of downtime.
&lt;/pre&gt;&lt;p&gt;
I can't find anything in the logs to indicate what caused the load spike and php-fpm and nginx to stopp running.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/555#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/769</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/769</guid>
        <title>#769: Locked myself out of puffin again</title>
        <pubDate>Mon, 04 Aug 2014 08:40:53 GMT</pubDate>
        
        <dc:creator>annesley</dc:creator>

        <description>&lt;p&gt;
really sorry. locked my IP out of puffin again. please could you clear it?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/769#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/207</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/207</guid>
        <title>#207: Logwatch Issues</title>
        <pubDate>Fri, 17 Dec 2010 14:19:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This is a ticket to track items that show up in the logwatch emails to root and often just take a few mins of reading time and response.
&lt;/p&gt;
&lt;p&gt;
Any issues that look like they might take longer than a few mins should have their own tickets opened.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/207#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/592</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/592</guid>
        <title>#592: Many panes on homepage are in italics</title>
        <pubDate>Wed, 11 Sep 2013 07:29:50 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
they shouldn't be, but they are:
ingredient of the day
latest tc post
featured training
why do transition
featured resrouce
featured project
social reporters
all automated listings at bottom
&lt;/p&gt;
&lt;p&gt;
please resolve - ben are you around to do this or is it more suitable to ask jim atm?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/592#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/708</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/708</guid>
        <title>#708: Map not showing Indian initiative</title>
        <pubDate>Thu, 27 Mar 2014 13:44:29 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/initiatives/heal-soil-csa-community-supported-agriculture"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/initiatives/heal-soil-csa-community-supported-agriculture&lt;/a&gt;
Address is correct, but doesn’t appear. The person who put it there doesn’t appear on the people map either, so wondering what’s afoot.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/708#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/622</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/622</guid>
        <title>#622: Maps not working on TN.org</title>
        <pubDate>Mon, 18 Nov 2013 17:06:59 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/initiatives/map"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/initiatives/map&lt;/a&gt;
&lt;a class="ext-link" href="https://www.transitionnetwork.org/initiatives/exeter-nh-transition-town"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/initiatives/exeter-nh-transition-town&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
please attend
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/622#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/573</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/573</guid>
        <title>#573: MariaDB 5.5.32 is available for Puffin</title>
        <pubDate>Thu, 18 Jul 2013 19:11:24 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
I could either update this via aptitude and it would be quick and have little down time or I could update it via BOA and it'll take 3 or 4 times as long and involved extra downtime.
&lt;/p&gt;
&lt;p&gt;
Jim -- which way would you like it done?
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
The MariaDB project is pleased to announce the immediate availability
of MariaDB 5.5.32.
&lt;/p&gt;
&lt;p&gt;
This is a bug-fix release. See the Release Notes and Changelog for
details.
&lt;/p&gt;
&lt;p&gt;
MariaDB 5.5.32 Stable (GA)
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Release Notes: &lt;a class="ext-link" href="https://kb.askmonty.org/en/mariadb-5532-release-notes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kb.askmonty.org/en/mariadb-5532-release-notes&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Changelog: &lt;a class="ext-link" href="https://kb.askmonty.org/en/mariadb-5532-changelog"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://kb.askmonty.org/en/mariadb-5532-changelog&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;a class="ext-link" href="http://lists.askmonty.org/pipermail/announce/2013-July/000048.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://lists.askmonty.org/pipermail/announce/2013-July/000048.html&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/573#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/382</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/382</guid>
        <title>#382: Measurement and tracking requirements for TN and PSE</title>
        <pubDate>Tue, 13 Dec 2011 04:57:12 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
to list the measurement and tracking requirements for TN and PSE so that we can assess piwik vs google and decide which way to go.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/382#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/686</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/686</guid>
        <title>#686: MediaWiki 1.19.11 Update</title>
        <pubDate>Wed, 29 Jan 2014 09:53:13 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
On the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-January/000140.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of MediaWiki 1.22.2, 1.21.5 and 1.19.11.
&lt;/p&gt;
&lt;p&gt;
Your MediaWiki installation is affected by a remote code execution vulnerability if you have enabled file upload support for DjVu (natively supported by MediaWiki) or PDF files (in combination with the PdfHandlerxtension). Neither file type is enabled by default in MediaWiki installations. If you are affected, we strongly urge you to update immediately.
&lt;/p&gt;
&lt;p&gt;
Affected supported versions: All
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;Netanel Rubin from Check Point discovered a remote code execution
vulnerability in MediaWiki's thumbnail generation for DjVu files. Internal
review also discovered similar logic in the PdfHandler extension, which
could be exploited in a similar way. (CVE-2014-1610)
&lt;a class="ext-link" href="https://bugzilla.wikimedia.org/show_bug.cgi?id=60339"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://bugzilla.wikimedia.org/show_bug.cgi?id=60339&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="BugFixesin1.22.2"&gt;Bug Fixes in 1.22.2&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 58253) Check for very old PCRE versions in installer and updater
&lt;/li&gt;&lt;li&gt;(bug 60054) Make WikiPage::$mPreparedEdit public
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.19.9:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.19&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/686#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/813</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/813</guid>
        <title>#813: MediaWiki 1.23.7</title>
        <pubDate>Thu, 27 Nov 2014 14:38:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-November/000170.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23.7, 1.22.14 and 1.19.22. This is a regular security and maintenance release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bugs 66776, 71478) SECURITY:  User PleaseStand reported a way to inject code into API clients that used format=php to process pages that underwent flash policy mangling. This was fixed along with improving how the mangling was done for format=json, and allowing sites to disable the mangling using $wgMangleFlashPolicy.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T68776"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T68776&lt;/a&gt; &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73478"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73478&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 70901) SECURITY: User Jackmcbarn reported that the ability to update the content model for a page could allow an unprivileged attacker to edit another user's common.js under certain circumstances. The user right "editcontentmodel" was added, and is needed to change a revision's content model.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T72901"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T72901&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 71111) SECURITY: User PleaseStand reported that on wikis that allow raw HTML, it is not safe to preview wikitext coming from an untrusted source such as a cross-site request. Thus add an edit token to the form, and when raw HTML is allowed, ensure the token is provided before showing the preview.  This check is not performed on wikis that both allow raw HTML and anonymous editing, since there are easier ways to exploit that scenario.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73111"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73111&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 72222) SECURITY: Do not show log action when the entry is revdeleted with DELETED_ACTION. NOTICE: this may be reverted in a future release pending a public RFC about the desired functionality. This issue was reported by user Bawolff.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T74222"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T74222&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 71621) Make allowing site-wide styles on restricted special pages a config option. &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73621"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73621&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;(bug 42723) Added updated version history from 1.19.2 to 1.22.13 &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T44723"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T44723&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;$wgMangleFlashPolicy was added to make &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s mangling of anything that might be a flash policy directive configurable.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.7:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/813#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/816</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/816</guid>
        <title>#816: MediaWiki 1.23.8</title>
        <pubDate>Thu, 18 Dec 2014 11:20:43 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-December/000173.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement email&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.24.1, 1.23.8, 1.22.15 and 1.19.23. This is a regular security and maintenance release. Download links are given at the end of this email. Please note this release marks the end of lifetime for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22 branch.
&lt;/p&gt;
&lt;h2 id="Securityfixesin1.24.11.23.81.22.15and1.19.23"&gt;Security fixes in 1.24.1, 1.23.8, 1.22.15 and 1.19.23&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T76686) [SECURITY] thumb.php outputs wikitext message as raw HTML,
which could lead to xss. Permission to edit &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; namespace is required
to exploit this.
&lt;/li&gt;&lt;li&gt;(bug T77028) [SECURITY] Malicious site can bypass CORS restrictions in
$wgCrossSiteAJAXdomains in API calls if it only included an allowed domain as
part of its name.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bugfixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T74222) The original patch for T74222 was reverted as unnecessary.
&lt;/li&gt;&lt;li&gt;Fixed a couple of entries in RELEASE-NOTES-1.24.
&lt;/li&gt;&lt;li&gt;(bug T76168) OutputPage: Add accessors for some protected properties.
&lt;/li&gt;&lt;li&gt;(bug T74834) Make 1.24 branch directly installable under PostgreSQL.
&lt;/li&gt;&lt;li&gt;Add missing $ in front of variable in OutputPage.php
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Securityfixesinextensions"&gt;Security fixes in extensions&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug T77624) [SECURITY] Extension:Listings: missing validation in the
'name' and 'url' parameters.
&lt;/li&gt;&lt;li&gt;(bug T73111) [SECURITY] Extension:ExpandTemplates: parses user input
as wikitext and shows a preview, yet it fails to add an edit token to
the form and check it. This can be exploited as an XSS when
$wgRawHtml = true. Note this only affects the 1.19/1.22 branches.
&lt;/li&gt;&lt;li&gt;(bug T76195) [SECURITY] Extension:TemplateSandbox:
Special:TemplateSandbox needs edit token when raw HTML is allowed
&lt;/li&gt;&lt;li&gt;(bug T69180) [SECURITY] Extension:Hovercards: XSS in text extracts.
&lt;/li&gt;&lt;li&gt;(bug T73167) [SECURITY] Extension:Scribunto allows cross-origin
leakage of data from a wiki through timing
&lt;/li&gt;&lt;li&gt;(bug T71209) [SECURITY] Extension:TimedMediaHandler: Patch getid3
library for CVE-2014-2053.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.8:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/816#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/793</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/793</guid>
        <title>#793: MediaWiki Security and Maintenance Release 1.23.5</title>
        <pubDate>Thu, 02 Oct 2014 08:57:49 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announcement &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-October/000163.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;email&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.19.20, 1.22.12 and 1.23.5. This is a security release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 70672) SECURITY: OutputPage: Remove separation of css and js module allowance.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.5: &amp;lt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;&amp;gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/793#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/781</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/781</guid>
        <title>#781: MediaWiki Security and Maintenance Releases: 1.22.10 and 1.23.3</title>
        <pubDate>Thu, 28 Aug 2014 06:42:16 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announcement email:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-August/000159.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://lists.wikimedia.org/pipermail/mediawiki-announce/2014-August/000159.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Bugfixes only, not a security update so no urgent update required.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/781#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/766</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/766</guid>
        <title>#766: MediaWiki Security and Maintenance Update 1.23.2</title>
        <pubDate>Wed, 30 Jul 2014 20:56:46 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-July/000157.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce&lt;/a&gt; list:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.23.2, 1.22.9 and 1.19.18. This is a regular security and maintenance release. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 68187) SECURITY: Prepend jsonp callback with comment.
&lt;/li&gt;&lt;li&gt;(bug 66608) SECURITY: Fix for XSS issue in bug 66608: Generate the URL used for loading a new page in Javascript,instead of relying on the URL in the link that has been clicked.
&lt;/li&gt;&lt;li&gt;(bug 65778) SECURITY: Copy prevent-clickjacking between OutputPage and ParserOutput.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixesin1.23.2"&gt;Bugfixes in 1.23.2&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 68313) Preferences: Turn stubthreshold back into a combo box.
&lt;/li&gt;&lt;li&gt;(bug 65214) Fix initSiteStats.php maintenance script.
&lt;/li&gt;&lt;li&gt;(bug 67594) Special:ActiveUsers: Fix to work with PostgreSQL.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.23.2:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Public keys:
&amp;lt;&lt;a class="ext-link" href="https://www.mediawiki.org/keys/keys.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/keys/keys.html&lt;/a&gt;&amp;gt;
&lt;/p&gt;
&lt;h2 id="a1.23.2"&gt;1.23.2&lt;/h2&gt;
&lt;p&gt;
Download:
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Patch to previous version (1.23.1):
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
GPG signatures:
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-core-1.23.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-core-1.23.2.tar.gz.sig&lt;/a&gt;
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.tar.gz.sig&lt;/a&gt;
&lt;a class="ext-link" href="https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://releases.wikimedia.org/mediawiki/1.23/mediawiki-1.23.2.patch.gz.sig&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Note:
There is no i18n patch as there are no changes in translation.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/766#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/799</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/799</guid>
        <title>#799: MediaWiki Visual Editor broken from Parsoid update</title>
        <pubDate>Tue, 21 Oct 2014 10:21:54 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
After updating Parasoid on &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/692#comment:102" title="maintenance: Debian Updates (new)"&gt;ticket:692#comment:102&lt;/a&gt; the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; visual editor now generates this error:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
Error loading data from server: parsoidserver-http-bad-status: 500. Would you like to retry?
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/799#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/694</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/694</guid>
        <title>#694: Mediawiki 1.19.12 upgrade</title>
        <pubDate>Fri, 28 Feb 2014 09:03:20 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
On the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-February/000141.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.3, 1.21.6 and 1.19.12.
These releases fix a number of security related bugs that could affect users
of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;. In addition, &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.3 is a maintenance release. It fixes
several bugs. You can consult the RELEASE-NOTES-1.22 file for the full list of
changes in this version. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 60771) SECURITY: Disallow uploading SVG files using non-whitelisted
namespaces. Also disallow iframe elements. User will get an error
including the namespace name if they use a non- whitelisted namespace.
&lt;/li&gt;&lt;li&gt;(bug 61346) SECURITY: Make token comparison use constant time. It seems like
our token comparison would be vulnerable to timing attacks. This will take
constant time.
&lt;/li&gt;&lt;li&gt;(bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/694#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/700</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/700</guid>
        <title>#700: Mediawiki 1.19.13</title>
        <pubDate>Wed, 12 Mar 2014 11:06:44 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From the &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-March/000143.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.4, 1.21.7 and 1.19.13.  Other than the security fix included in 1.19.13, these releases simply fix the bundled version of the tarball. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixbackportedto1.19"&gt;Security fix backported to 1.19&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 61362) SECURITY: API: Don't find links in the middle of api.php links.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Fixesmadeinalltarballs"&gt;Fixes made in all tarballs&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;The correct branch of each extensions git repository (e.g. REL1_19 for 1.19.13) was used.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/700#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/551</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/551</guid>
        <title>#551: Mediawiki 1.19.7 upgrade</title>
        <pubDate>Tue, 21 May 2013 08:25:51 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
From &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2013-May/000130.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;MediaWiki-announce&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Tuesday, May 21st between 20:00-21:00 UTC
(1-2pm PDT) Wikimedia Foundation will release security updates for
current and supported branches of the MediaWiki software. Downloads
and patches will be available at that time, with the git repositories
updated later that afternoon. Although &lt;strong&gt;MediaWiki does not have the&lt;/strong&gt;
&lt;strong&gt;vulnerable feature enabled by default&lt;/strong&gt;, most wiki using common advanced
features will want to patch for this issue.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/551#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/723</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/723</guid>
        <title>#723: Mediawiki 1.22.6 Upgrade</title>
        <pubDate>Mon, 28 Apr 2014 10:10:48 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Announced &lt;a class="ext-link" href="http://lists.wikimedia.org/pipermail/mediawiki-announce/2014-April/000149.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;a few days ago&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.22.6 and 1.21.9. This is a regular security and maintenance release. Download links are given at the end of this email. Please note there is no new release of the 1.19 branch, as it is not affected by the security issue.
&lt;/p&gt;
&lt;h2 id="Security"&gt;Security&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 63251) SECURITY: escape sortKey in pageInfo.
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixesin1.21.9"&gt;Bugfixes in 1.21.9&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 58640) Fixed a compatibility issue with PCRE 8.34 that caused pages
to appear blank or with missing text.
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Full release notes for 1.22.6:
&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.22"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.22&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/723#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/733</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/733</guid>
        <title>#733: Mediawiki 1.22.7 security update</title>
        <pubDate>Sun, 01 Jun 2014 09:20:53 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
See &lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.22#MediaWiki_1.22.6"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.22#MediaWiki_1.22.6&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/733#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/841</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/841</guid>
        <title>#841: Mediawiki 1.23.9</title>
        <pubDate>Wed, 01 Apr 2015 20:26:50 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email on &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-March/000175.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the announcements list&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
I would like to announce the release of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; 1.24.2, 1.23.9 and 1.19.24. These releases fix 10 security issues, in addition to other bug fixes. Download links are given at the end of this email.
&lt;/p&gt;
&lt;h2 id="Securityfixes"&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;iSEC Partners discovered a way to circumvent the SVG MIME blacklist for embedded resources (iSEC-WMF1214-11). This allowed an attacker to embed JavaScript in the SVG. The issue was additionally identified by Mario Heiderich / Cure53. MIME types are now whitelisted.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85850"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85850&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Bawolff pointed out that the SVG filter to prevent injecting JavaScript using animate elements was incorrect.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T86711"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T86711&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Bawolff reported a stored XSS vulnerability due to the way attributes were expanded in &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s Html class, in combination with LanguageConverter substitutions.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T73394"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T73394&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review discovered that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s SVG filtering could be bypassed with entity encoding under the Zend interpreter. This could be used to inject JavaScript. This issue was also discovered by Mario Gomes from Beyond Security.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T88310"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T88310&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered a XSS vulnerability in the way api errors were reflected when running under HHVM versions before 3.6.1 (iSEC-WMF1214-8).  &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; now detects and mitigates this issue on older versions of HHVM.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85851"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85851&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review and iSEC Partners discovered (iSEC-WMF1214-1) that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; versions using PBKDF2 for password hashing (the default since 1.24) are vulnerable to DoS attacks using extremely long passwords.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T64685"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T64685&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt;'s SVG and XMP parsing, running under HHVM, was susceptible to "Billion Laughs" DoS attacks (iSEC-WMF1214-13).  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85848"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85848&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Internal review found that &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; is vulnerable to "Quadratic Blowup" DoS attacks, under both HHVM and Zend PHP.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T71210"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T71210&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners discovered a way to bypass the style filtering for SVG files (iSEC-WMF1214-3). This could violate the anonymity of users viewing the SVG.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85349"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85349&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;iSEC Partners reported that the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; feature allowing a user to preview another user's custom JavaScript could be abused for privilege escalation (iSEC-WMF1214-10). This feature has been removed.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85855"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85855&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Additionally, the following extensions have been updated to fix security issues:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Extension:Scribunto - &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; user Jackmcbarn discovered that function names were not sanitized in Lua error backtraces, which could lead to XSS.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85113"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85113&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;Extension:!CheckUser - iSEC Partners discovered that the CheckUser extension did not prevent CSRF attacks on the form allowing checkusers to look up sensitive information about other users (iSEC-WMF1214-6). Since the use of CheckUser is logged, the CSRF could be abused to defame a trusted user or flood the logs with noise.  &lt;a class="ext-link" href="https://phabricator.wikimedia.org/T85858"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://phabricator.wikimedia.org/T85858&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;h2 id="Bugfixes"&gt;Bug fixes&lt;/h2&gt;
&lt;h3 id="a1.24"&gt;1.24&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;Fix case of SpecialAllPages/SpecialAllMessages in SpecialPageFactory to fix loading these special pages when $wgAutoloadAttemptLowercase is false.
&lt;/li&gt;&lt;li&gt;(bug T76254) Fix deleting of pages with PostgreSQL. Requires a schema change and running update.php to fix.
&lt;/li&gt;&lt;/ul&gt;&lt;h3 id="a1.231.24"&gt;1.23 &amp;amp; 1.24&lt;/h3&gt;
&lt;ul&gt;&lt;li&gt;(bug T70087) Fix Special:ActiveUsers page for installations using PostgreSQL.
&lt;/li&gt;&lt;/ul&gt;&lt;hr /&gt;
&lt;p&gt;
Full release notes:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.24"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.24&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.23"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.23&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/wiki/Release_notes/1.19"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/wiki/Release_notes/1.19&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Download:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Patch to previous version:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
GPG signatures:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.24/mediawiki-1.24.2.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.23/mediawiki-1.23.9.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.tar.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz.sig"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://download.wikimedia.org/mediawiki/1.19/mediawiki-1.19.24.patch.gz.sig&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Extensions:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="http://www.mediawiki.org/wiki/Extension:Scribunto"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.mediawiki.org/wiki/Extension:Scribunto&lt;/a&gt;
&lt;/li&gt;&lt;li&gt;&lt;a class="ext-link" href="http://www.mediawiki.org/wiki/Extension:CheckUser"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.mediawiki.org/wiki/Extension:CheckUser&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Public keys:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;&lt;a class="ext-link" href="https://www.mediawiki.org/keys/keys.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.mediawiki.org/keys/keys.html&lt;/a&gt;
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/841#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/669</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/669</guid>
        <title>#669: Mediawiki upgrade to 1.19.10</title>
        <pubDate>Sat, 11 Jan 2014 09:00:24 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from Mediawiki:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
This is a notice that on Tuesday, January 14th between 00:00-01:00 UTC (*Monday* January 13th, 4-5pm PST) Wikimedia Foundation will release security updates for current and supported branches of the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/MediaWiki"&gt;MediaWiki&lt;/a&gt; software, as well as several extensions. Downloads and patches will be available at that time.
&lt;/p&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/669#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/618</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/618</guid>
        <title>#618: Migrate Penguin and Parrot to the ZFS fileserver</title>
        <pubDate>Fri, 15 Nov 2013 09:37:36 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Since &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt; has been running from the ZFS fileserver, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/593" title="maintenance: Migrating Puffin to a ZFS file server (closed: fixed)"&gt;ticket:593&lt;/a&gt;, it has been performing better -- we should also migrate &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;wiki:PenguinServer&lt;/a&gt; and &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;wiki:ParrotServer&lt;/a&gt; to the ZFS server prior to upgrading them to Debian Wheezy on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/535" title="maintenance: Upgrade Puffin, Penguin and Parrot from Debian Squeeze to Wheezy (closed: fixed)"&gt;ticket:535&lt;/a&gt;.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/618#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/593</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/593</guid>
        <title>#593: Migrating Puffin to a ZFS file server</title>
        <pubDate>Wed, 11 Sep 2013 15:52:47 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
This ticket is for the migration of &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; to a ZFS file server, this will involve some downtime but should result in better IO and easier backups.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/593#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/693</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/693</guid>
        <title>#693: Module security updates: February 2014</title>
        <pubDate>Thu, 27 Feb 2014 16:18:04 GMT</pubDate>
        
        <dc:creator>sam</dc:creator>

        <description>&lt;p&gt;
Hi Paul
&lt;/p&gt;
&lt;p&gt;
You'll see from this ticket; &lt;a class="ext-link" href="https://trac.transitionnetwork.org/trac/ticket/582"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://trac.transitionnetwork.org/trac/ticket/582&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
That the 6.29 &amp;gt; 6.30 core update patches bugs that don't affect us.
&lt;/p&gt;
&lt;p&gt;
However some recent security updates for modules have been released recently; &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/updates"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.transitionnetwork.org/admin/reports/updates&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Affected modules are;
&lt;/p&gt;
&lt;p&gt;
ctools;
&lt;a class="ext-link" href="https://drupal.org/node/2194547"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194547&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
filefield
&lt;a class="ext-link" href="https://drupal.org/node/2194103"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194103&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
image resizer
&lt;a class="ext-link" href="https://drupal.org/node/2194063"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194063&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
mimemail
&lt;a class="ext-link" href="https://drupal.org/node/2205939"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2205939&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
webform
&lt;a class="ext-link" href="https://drupal.org/node/2194181"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/2194181&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
The ctools &amp;amp; webform ones look like ones we should get on top of soonish, the mimemail one looks like it could be a pain.
&lt;/p&gt;
&lt;p&gt;
Are you up for testing the updates on your local box? We can then figure out how to roll them out to the live site.
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/693#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/591</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/591</guid>
        <title>#591: Move MySQL temporary directory to tmpfs</title>
        <pubDate>Mon, 09 Sep 2013 12:47:41 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
Chris, please read: &lt;a class="ext-link" href="http://2bits.com/articles/reduce-your-servers-resource-usage-moving-mysql-temporary-directory-ram-disk.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://2bits.com/articles/reduce-your-servers-resource-usage-moving-mysql-temporary-directory-ram-disk.html&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
I think we could easily drop a little MySQL memory to give it some in-memory disk space to do the temporary table munching Drupal is causing it. I see there are already some mounted tmpfs partitions.
&lt;/p&gt;
&lt;p&gt;
Related to &lt;a class="assigned ticket" href="http://localhost:8080/trac/ticket/590" title="defect: Drupal performance improvements (assigned)"&gt;#590&lt;/a&gt; (proposal L: Review slow query log, explain queries, tweak as necessary/flag poorly behaving modules)
&lt;/p&gt;
&lt;p&gt;
What do you think? Worth doing?
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/591#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/631</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/631</guid>
        <title>#631: Move Transition Culture onto PARROT</title>
        <pubDate>Mon, 25 Nov 2013 11:57:44 GMT</pubDate>
        
        <dc:creator>ed</dc:creator>

        <description>&lt;p&gt;
We are about to move TC onto PARROT. List of likely actions here:
&lt;/p&gt;
&lt;ul&gt;&lt;li&gt;Ed speak to Simon (move the host, keep the developer if poss)
&lt;/li&gt;&lt;li&gt;Chris speak to Simon about TC issues - traffic, size etc.
&lt;/li&gt;&lt;li&gt;analyse TC traffic and DB size
&lt;/li&gt;&lt;li&gt;prepare PARROT
&lt;/li&gt;&lt;li&gt;move TC
&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
Chris thinks we'll need to up PARROT to
VPS2 + 2 GB RAM
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/631#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/615</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/615</guid>
        <title>#615: Move to GMap 6.x-2.x-dev as and get clusterer to work</title>
        <pubDate>Sun, 10 Nov 2013 18:14:51 GMT</pubDate>
        
        <dc:creator>jim</dc:creator>

        <description>&lt;p&gt;
This is largely done, but the only tasks left are:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Make a patch and add to our makefile so our custom markers appear ok.
&lt;/li&gt;&lt;li&gt;Get the clusterer to work per the comments &amp;amp; issues in &lt;a href="http://localhost:8080/trac/ticket/615#comment:1" title="Comment 1 for Ticket #615"&gt;comment:1&lt;/a&gt; below.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
Per an email I got from Google:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
As you may be aware, &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt; Maps API v2 was scheduled for shutdown on May 19, 2013. After listening to feedback from developers we decided to extend the deprecation timeline by six months, to November 19, 2013 to allow more time for migration to v3 of the API.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
On November 19, 2013 we will deploy a &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt; wrapper that attempts to automagically turn remaining v2 maps into v3 maps. Though we expect this wrapper to work for most simple maps, we cannot guarantee that your maps will continue to function. We therefore highly recommend that you migrate to v3 before November 19. The good news is that Google Maps &lt;a class="missing wiki"&gt;JavaScript?&lt;/a&gt; API v3 is more robust and feature rich than v2, and we’ve written a guide to assist the migration.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
So this ticket is to do the update to the GMap module, testing and tweaking.
&lt;/p&gt;
&lt;p&gt;
Critical as we only have until 19 November for this...
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/615#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/760</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/760</guid>
        <title>#760: New BOA-2.2.7 Stable Edition</title>
        <pubDate>Thu, 17 Jul 2014 08:34:22 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is new BOA-2.2.7 Stable Edition available.
&lt;/p&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible
to receive all security updates and new features.
&lt;/p&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The Changelog:
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.2.5 Release - Full Edition
### Date: Thu May  8 11:59:23 PDT 2014
### Includes Aegir 2.x-boa-custom version.
### Latest hotfix added on: Sat May 10 09:05:19 PDT 2014
# Release Notes:
  This release includes no new features, but does include bug fixes plus latest
  Drupal 7.28.1 and Pressflow 6.31.2 core in all built-in Octopus platforms.
  There are also three updated distributions included, as listed below.
  We also list here all hot-fixes applied to previous stable after its release.
# Important - Read This First! (for self-hosted BOA only)
  If you haven't run full barracuda+octopus upgrade to latest BOA Stable
  Edition yet, don't use any partial upgrade modes explained in docs/UPGRADE.txt
  Once new BOA Stable is released, you must run *full* upgrades with commands:
  $ barracuda up-stable
  $ octopus up-stable all both
  For silent, logged mode with e-mail message sent once the upgrade is
  complete, but no progress is displayed in the terminal window, you can run
  alternatively, starting with screen session to avoid incomplete upgrade
  if your SSH session will be closed for any reason before the upgrade
  will complete:
  $ screen
  $ barracuda up-stable log
  $ octopus up-stable all both log
  Note that the silent, non-interactive mode will automatically say Y/Yes
  to all prompts and is thus useful to run auto-upgrades scheduled in cron.
  If you have skipped some recent BOA releases, and you have new default config
  option: _PERMISSIONS_FIX=NO in your /root/.barracuda.cnf configuration file,
  plus, you are not sure if you follow best practices for managing permissions
  as recommended in our docs: https://omega8.cc/node/116 then we recommend
  that you change it to _PERMISSIONS_FIX=YES temporarily, or even permanently
  if your VPS is fast enough, and then run this powerful script as root:
  $ bash /var/xdrago/daily.sh
  Note that BOA 'legacy' mode is still at version 2.1.3
# Updated Octopus platforms:
  Commons 3.12 ----------------- https://drupal.org/project/commons
  Open Atrium 2.18 ------------- https://drupal.org/project/openatrium
  Open Outreach 1.6 ------------ https://drupal.org/project/openoutreach
# Changes in this release:
  * Add rsyslog/sysklogd to auto-healing procedures.
  * Make the aggressive scan_nginx mode optional and use old mode by default.
  * Nginx: Add HiScan to blocked crawlers list.
  * Nginx: Add Riddler to blocked crawlers list.
  * PHP: Use pm.process_idle_timeout = 10s for speed and RAM optimization.
# System upgrades in this release:
  * MySecureShell 1.33
  * PHP 5.4.28
  * PHP 5.5.12
# Fixes in this release:
  * Always define _PHP_CN variable properly.
  * Firewall: Sync CONNLIMIT for web ports with updated limit_conn in Nginx.
  * Fix for _NGINX_DOS_LIMIT logical error in the scan_nginx template.
  * Force Pure-FTPd server re-install if key files are missing for any reason.
  * Issue #2237167 - Improve authorized IPs detection in all protected vhosts.
  * Issue #2262935 - Modules dir must be group writable in custom platforms.
  * Nginx: Do not overwrite custom symlinks to the Under Construction template.
  * Nginx: Update limit_conn in all instances and vhosts on Barracuda upgrade.
  * PHP: Delete pear in legacy paths, if still exists.
  * PHP: Fix for CVE-2014-0185 privilege escalation in FPM (doesn't affect BOA)
  * Postfix: Force re-install if broken permisions detected on upgrade.
  * Pressflow 6: Fix #GH 84 by using drupal_page_is_cacheable().
  * Pressflow 6: Merge pull request #GH 85 from pressflow/SA-CORE-2014-002-fix.
  * Pressflow 6: Remove duplicate openid_update_6001().
  * Revert "Force MariaDB 5.5 re-install".
  * Set the TERM env variable if missing to avoid errors.
  * Skip packages set on hold when running apticron.
  * The ~/static/control must be writeable by lshell user to manage ctrl files.
  * Add extra cron semaphore to prevent concurrent cron invocations via
    multiple running runner.sh instances.
&lt;/pre&gt;&lt;p&gt;
I can't see any issues that have an immediate impact on us, I'll do the upgrade late one evening.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/760#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/765</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/765</guid>
        <title>#765: New BOA-2.2.8 Stable Edition</title>
        <pubDate>Sun, 27 Jul 2014 08:08:55 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is new BOA-2.2.8 Stable Edition available.
&lt;/p&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible to receive all security updates and new features.
&lt;/p&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The Changelog contains:
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.2.5 Release - Full Edition
### Date: Thu May  8 11:59:23 PDT 2014
### Includes Aegir 2.x-boa-custom version.
### Latest hotfix added on: Sat May 10 09:05:19 PDT 2014
# Release Notes:
  This release includes no new features, but does include bug fixes plus latest
  Drupal 7.28.1 and Pressflow 6.31.2 core in all built-in Octopus platforms.
  There are also three updated distributions included, as listed below.
  We also list here all hot-fixes applied to previous stable after its release.
# Important - Read This First! (for self-hosted BOA only)
  If you haven't run full barracuda+octopus upgrade to latest BOA Stable
  Edition yet, don't use any partial upgrade modes explained in docs/UPGRADE.txt
  Once new BOA Stable is released, you must run *full* upgrades with commands:
  $ barracuda up-stable
  $ octopus up-stable all both
  For silent, logged mode with e-mail message sent once the upgrade is
  complete, but no progress is displayed in the terminal window, you can run
  alternatively, starting with screen session to avoid incomplete upgrade
  if your SSH session will be closed for any reason before the upgrade
  will complete:
  $ screen
  $ barracuda up-stable log
  $ octopus up-stable all both log
  Note that the silent, non-interactive mode will automatically say Y/Yes
  to all prompts and is thus useful to run auto-upgrades scheduled in cron.
  If you have skipped some recent BOA releases, and you have new default config
  option: _PERMISSIONS_FIX=NO in your /root/.barracuda.cnf configuration file,
  plus, you are not sure if you follow best practices for managing permissions
  as recommended in our docs: https://omega8.cc/node/116 then we recommend
  that you change it to _PERMISSIONS_FIX=YES temporarily, or even permanently
  if your VPS is fast enough, and then run this powerful script as root:
  $ bash /var/xdrago/daily.sh
  Note that BOA 'legacy' mode is still at version 2.1.3
# Updated Octopus platforms:
  Commons 3.12 ----------------- https://drupal.org/project/commons
  Open Atrium 2.18 ------------- https://drupal.org/project/openatrium
  Open Outreach 1.6 ------------ https://drupal.org/project/openoutreach
# Changes in this release:
  * Add rsyslog/sysklogd to auto-healing procedures.
  * Make the aggressive scan_nginx mode optional and use old mode by default.
  * Nginx: Add HiScan to blocked crawlers list.
  * Nginx: Add Riddler to blocked crawlers list.
  * PHP: Use pm.process_idle_timeout = 10s for speed and RAM optimization.
# System upgrades in this release:
  * MySecureShell 1.33
  * PHP 5.4.28
  * PHP 5.5.12
# Fixes in this release:
  * Always define _PHP_CN variable properly.
  * Firewall: Sync CONNLIMIT for web ports with updated limit_conn in Nginx.
  * Fix for _NGINX_DOS_LIMIT logical error in the scan_nginx template.
  * Force Pure-FTPd server re-install if key files are missing for any reason.
  * Issue #2237167 - Improve authorized IPs detection in all protected vhosts.
  * Issue #2262935 - Modules dir must be group writable in custom platforms.
  * Nginx: Do not overwrite custom symlinks to the Under Construction template.
  * Nginx: Update limit_conn in all instances and vhosts on Barracuda upgrade.
  * PHP: Delete pear in legacy paths, if still exists.
  * PHP: Fix for CVE-2014-0185 privilege escalation in FPM (doesn't affect BOA)
  * Postfix: Force re-install if broken permisions detected on upgrade.
  * Pressflow 6: Fix #GH 84 by using drupal_page_is_cacheable().
  * Pressflow 6: Merge pull request #GH 85 from pressflow/SA-CORE-2014-002-fix.
  * Pressflow 6: Remove duplicate openid_update_6001().
  * Revert "Force MariaDB 5.5 re-install".
  * Set the TERM env variable if missing to avoid errors.
  * Skip packages set on hold when running apticron.
  * The ~/static/control must be writeable by lshell user to manage ctrl files.
  * Add extra cron semaphore to prevent concurrent cron invocations via
    multiple running runner.sh instances.
&lt;/pre&gt;&lt;p&gt;
I'll do this update tonight, following &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer#UpgradingBOA"&gt;wiki:PuffinServer#UpgradingBOA&lt;/a&gt;
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/765#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/775</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/775</guid>
        <title>#775: New BOA-2.2.9 Stable Edition available</title>
        <pubDate>Thu, 07 Aug 2014 08:39:18 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email from &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;wiki:PuffinServer&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is new BOA-2.2.9 Stable Edition available.
&lt;/p&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible to receive all security updates and new features.
&lt;/p&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/boa-changes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/boa-changes&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
The Changelog:
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.2.9 Release - Full Edition
### Date: Wed Aug  6 17:08:10 PDT 2014
### Includes Aegir 2.x-boa-custom version.
# Release Notes:
  This release includes updated versions of all supported Drupal platforms to
  provide latest Drupal 7 and Pressflow 6 core, plus some changes, improvements,
  bug fixes, and five (5) updated Octopus platforms.
  NOTE: Since the first Edition in the BOA-2.3.x series is not ready for release
  yet, and new Drupal core has been released to fix security issues, followed
  by yet another release to fix serious regressions, followed by yet another
  security release, we have decided to make it available to everyone and release
  yet another stable BOA-2.2.x Edition.
  IMPORTANT! This is the last Edition in the 2.2.x series, which marks the end
  of Drupal 5, PHP 5.2 and Drush 4 support. Next Edition will open 2.3.x series,
  which will allow us to provide newer Aegir version with built-in Drush 6
  support, sites in subdirectories, and many Aegir User Interface improvements.
  If you still host any Drupal 5 sites or you are using PHP 5.2 for D6 sites,
  you will not be able to upgrade to the next 2.3.x Edition and you will have to
  stay on the 'legacy' BOA 2.2.x version, which will receive only system
  security upgrades, but no further feature nor bugfix releases.
  This also means that from now on the 'legacy' 2.2.x version will no longer
  receive Drupal core upgrades, even if there will be security core releases.
  It is time to upgrade away from Drupal 5 and away from PHP 5.2, if still used.
# Updated Octopus platforms:
  aGov 1.2 --------------------- https://drupal.org/project/agov
  Guardr 1.10 ------------------ https://drupal.org/project/guardr
  Open Outreach 1.9 ------------ https://drupal.org/project/openoutreach
  OpenPublic 1.0-rc4 ----------- https://drupal.org/project/openpublic
  Panopoly 1.10 ---------------- https://drupal.org/project/panopoly
# New features and enhancements in this release:
  * RVM: Add exceptions for gems which can't be installed in Limited Shell.
  * Shell: Compass Tools: Allow to access guard.
  * Shell: Improve config to better support advanced Drush commands over SSH.
  * Shell: Improve Drush over SSH experience
# Changes in this release:
  * Drush: Upgrade command line version 6 to mini-6-06-08-2014
# System upgrades in this release:
  * MariaDB 5.5.39
  * Nginx 1.7.4
  * OpenSSL 1.0.1i (if installed from sources)
# Fixes in this release:
  * Add cleanup for .tmp in sub-accounts.
  * Add cleanup for drush-backups leftovers.
  * Add cleanup for various /var/backups/* leftovers.
  * Add daily auto-cleanup for ghost vhosts, platforms and drush aliases.
  * Add exception for symlinked /data/all
  * Add hint for HTTPS-only mode forced in local.settings.php
  * Fix -mtime expected values.
  * Fix cleanup for .restore vhost leftovers.
  * Fix Nginx monitor to respect all whitelisted POST requests in both modes.
  * Fix permissions on sites/all/{modules,libraries,themes} globally.
  * Improve RVM cleanup.
  * Make sure that local IPs are never blocked by mistake.
  * Never touch websh wrapper to avoid high load because of redirect loop.
  * Nginx: Fix limreq also for some really old vhosts.
  * Nginx: Modify only vhosts known as included in the protected mode.
  * Remove debugging mode in old codebases cleanup.
  * Restore default websh wrapper symlink as fast as possible.
  * Run manage_ltd_users every 3 minutes instead of every minute.
  * Update regex for exceptions in Nginx monitoring.
&lt;/pre&gt;&lt;p&gt;
I'll do this update after the meeting tonight.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/775#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/784</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/784</guid>
        <title>#784: New BOA-2.3.0</title>
        <pubDate>Tue, 09 Sep 2014 08:52:22 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
These are the updates from the &lt;a class="ext-link" href="https://raw.githubusercontent.com/omega8cc/boa/master/CHANGELOG.txt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Changelog&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.3.0 Release - Full Edition
### Date: Mon Sep  8 08:42:01 PDT 2014
### Includes Aegir 2.1 with improvements
# Release Notes:
  This new BOA Edition introduces latest Aegir 2.1 stable version with newest
  Drush 6 in the backend and with support for Drupal sites in subdirectories
  enabled by default, among many other improvements included in this version,
  like tasks list per site, ability to search in the sites list per domain name
  and/or profile, to schedule tasks in batches, to select any existing domain
  alias as a redirect target, but without the need to rename the site, etc.
  While Barracuda 2.3.0 can continue to run and even upgrade if needed also
  the very old PHP 5.2 version, only Octopus instances running at least PHP 5.3
  or newer in both FPM and CLI mode can be upgraded to Octopus 2.3.0 Edition.
  If you are still using PHP 5.2 in your Octopus instance, you will not
  receive Aegir nor Drupal Platforms upgrade, but the Barracuda part of your
  system will receive upgrade to 2.3.0 anyway, so it will be ready to support
  your outdated Octopus instance upgrade as soon as you will switch it to
  modern and secure PHP version -- which is easy!
  Let's quote the original how-to for reference:
#-### Support for PHP FPM/CLI version safe switch per Octopus instance
  This allows to easily switch PHP version by the instance owner w/o system
  admin (root) help. All you need to do is to create ~/static/control/fpm.info
  and ~/static/control/cli.info file with a single line telling the system
  which available PHP version should be used (if installed): 5.5 or 5.4 or 5.3
  Only one of them can be set, but you can use separate versions for web access
  (fpm.info) and the Aegir backend (cli.info). The system will switch versions
  defined via these control files in 5 minutes or less. We use external control
  files and not any option in the Aegir interface to make sure you will never
  lock yourself by switching to version which may cause unexpected problems.
#-### Legacy mode moves to 2.2.x branch
  From now on, the 'legacy' install and upgrade mode available in all meta-
  installers will utilize branch 2.2.x instead of deprecated 2.1.x series.
# Updated Octopus platforms:
  aGov 1.4 --------------------- https://drupal.org/project/agov
  Guardr 1.12 ------------------ https://drupal.org/project/guardr
  Open Academy 1.1 ------------- https://drupal.org/project/openacademy
  Restaurant 1.0-b9 ------------ https://drupal.org/project/restaurant
# New features and enhancements in this release:
  * It is now possible to add stable Octopus instances w/o forcing Barracuda
    upgrade, plus optionally with no platforms added by default -- usage:
    $ boa {in-octopus} {email} {o2} {mini|max|none}
  * Add default aggressive php-fpm monitoring + /root/.no.fpm.cpu.limit.cnf
  * Allow to define always disabled modules via _MODULES_FORCE variable.
  * Better wait limits on connection testing for slow network / long distance.
  * Issue #362 - Add imageapi_optimize binaries via IMG in _XTRAS_LIST
  * Make firewall management faster with randomized schedule.
  * Procs monitor runs every 3 seconds.
  * Run mysql_proc_control every 5 seconds for better results.
# Changes in this release:
  * Delete default profiles in the hostmaster platform.
  * Disable _DEBUG_MODE if not enabled on the fly.
  * Drush: Upgrade command line version 6 to mini-6-06-09-2014
  * Nginx: Remove deprecated code - _HTTP_WILDCARD is already used by default.
  * Nginx: Use limit_conn protection only for known dynamic requests.
  * Remove dependency on Update Manager globally.
  * Set hosting_default_profile to 'minimal' to improve Ubercart 3 visibility.
  * Use Provision CiviCRM boa-2.3.0-dev
# System upgrades in this release:
  * Git 2.1.0 (if installed from sources)
  * PHP 5.3.29 EOL! Please read: http://php.net/archive/2014.php#id2014-08-14-1
  * PHP 5.4.32
  * PHP 5.5.16
  * Redis 2.8.14
# Fixes in this release:
  * Add cleanup for _GIT_FORCE_REINSTALL if added in .barracuda.cnf
  * Add missing drush cache-clear drush to improve upgrade path.
  * Allow to clear drush cache without directory restrictions.
  * Always set correct TMP path for supported users.
  * Cleanup for cron pid files in user specific .tmp dirs.
  * Count properly also symlinked files directories (improved).
  * D6 colorbox module requires old 1.3.18 library.
  * Delete drush_make leftovers.
  * Delete duplicate menu items on upgrade.
  * Do not allow to install SSH from sources on Trusty to avoid problems.
  * Do not skip daily.sh during barracuda system only update.
  * Eldir theme: Use max width for buttons, if possible.
  * Fix cleanup for drush aliases in sub-accounts.
  * Fix daily cleanup for user specific .tmp directories.
  * Fix docs/HINTS.txt
  * Fix for broken mariadb.list
  * Fix for ghost dirs cleanup.
  * Fix for ghost vhosts cleanup.
  * Fix for missing symlinks to existing platforms.
  * Fix for not working protection from blocking local IPs on multi-IP systems.
  * Fix for subdirs_support universal check.
  * Fix for unreliable _IS_OLD check on Octopus instances upgrade.
  * Fix for warning "Could not create directory ." on Hostmaster site Verify.
  * Fix the fields order in the site edit form.
  * Fix the regex to not whitelist unexpected IP ranges inadvertently.
  * Force cURL rebuild if installed with outdated OpenSSL version.
  * Guard against destructive or insecure tasks run on the hostmaster site.
  * Improve cleanup for empty platforms directories.
  * Improve monitoring to protect against convert trying to overload the system.
  * Issue #2330781 - Use Drush dt() wrapper instead of not always available t()
  * Issue #357 - Fix the logic for Git (re)install from sources.
  * Issue #360 - Exclude special --CDN vhosts from daily cleanup.
  * Issue #361 - Update and improve docs/FAQ.txt
  * Issue #369 - Automatically download and fix /bin/websh if missing.
  * Issue #369 - Restore classic /bin/sh symlink automatically if needed.
  * Issue #373 - Set correct TMP, TEMP, TMPDIR env variables in limited shell.
  * Issue #373 - Too restrictive lshell forbidden list breaks drush sql-sync.
  * Issue #380 - Nameserver / pdnsd problem -- Fixes also Issue #2007990.
  * Issue #381 - Zend OPcache forced adds useless noise in the log.
  * Make it clear that subdomain and subdirectory name must be identical.
  * Make sure that keys subdirectory exists to avoid active platforms cleanup.
  * Nginx: Add config symlinks only on legacy instances.
  * Nginx: Add cron access support for subdir sites.
  * Nginx: Disable monitoring for POST requests related to cart/checkout URI.
  * Nginx: Remove deprecated code and config templates.
  * Nginx: Sanitize aliases in vhost_disabled.tpl.php to avoid warnings.
  * Nginx: Update config includes to match optional BOA features improvements.
  * Nginx: Update unified configuration templates in Provision to unfork BOA.
  * Nginx: Update vhosts templates to match BOA improvements.
  * PHP: Avoid unintended duplicate rebuilds.
  * Protect sites/all/drush
  * Provision: Backport provision_hosting_feature_enabled()
  * Provision: Remove legacy subdir code and update checks.
  * Redis config should sync with PHP-CLI, not PHP-FPM.
  * Remove legacy procs monitoring code.
  * Remove no longer needed limreq global fixes.
  * Remove no longer needed/used contrib updates.
  * Remove redundant file_exists() if is_readable() is also used.
  * Restart pdnsd before running barracuda upgrade.
  * Restore BOA formatting for tasks log to improve readability.
  * Restore BOA naming convention and docs in Hostmaster.
  * Restore BOA naming convention for Installation profiles in Hostmaster.
  * Restore BOA strict _hosting_valid_fqdn* testing procedures in Hostmaster.
  * Restore BOA weight defaults in the form in Hostmaster.
  * Restore punycode in Hostmaster.
  * Restore tasks sort to always show tasks scheduled and running at the top.
  * Sanitize cli.info and fpm.info
  * Set _PLATFORMS_LIST properly.
  * Simplify colorbox-1.3.18 download.
  * Simplify colorbox-1.5.13 download.
  * Switch branch on the fly and add support for Aegir vanilla mode.
  * Sync /tmp access restrictions.
  * Update for the Hostmaster welcome page.
  * Update FPM monitoring settings.
  * Use as short labels on the site node as possible.
  * Use correct paths to platform level drushrc.php file.
  * Use Drush6 with @hostmaster.
  * Use is_dir() instead of file_exists() when checking directory existence.
  * Use is_file() and is_link() instead of file_exists() before trying unlink()
  * Use is_readable() and file_exists() instead of file_exists() for backup.
  * Use is_readable() check instead of insufficient file_exists() for includes.
  * Use is_readable() instead of file_exists() when checking alias existence.
  * Install latest Git even if not specified via _XTRAS_LIST but previous
    version built from sources is detected.
  * Issue #2278847 - Derivatives can't be created on install with Drush and
    Aegir or when no vhost is available yet (Drupal Commons)
&lt;/pre&gt;&lt;p&gt;
I can't see any issues that directly impact on us apart from the new version of PHP, we are running &lt;a class="ext-link" href="https://www.transitionnetwork.org/admin/reports/status/php"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;PHP Version 5.3.28&lt;/a&gt;, the release notes for &lt;a class="ext-link" href="http://php.net/archive/2014.php#id2014-08-14-1"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;PHP 5.3.29&lt;/a&gt;:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
&lt;strong&gt;14 Aug 2014&lt;/strong&gt;
&lt;/p&gt;
&lt;p&gt;
The PHP development team announces the immediate availability of PHP 5.3.29. This release marks the end of life of the PHP 5.3 series. Future releases of this series are not planned. All PHP 5.3 users are encouraged to upgrade to the current stable version of PHP 5.5 or previous stable version of PHP 5.4, which are supported till at least 2016 and 2015 respectively.
&lt;/p&gt;
&lt;p&gt;
PHP 5.3.29 contains about 25 potentially security related fixes backported from PHP 5.4 and 5.5.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
More information in &lt;a class="ext-link" href="http://php.net/ChangeLog-5.php#5.3.29"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the Changelog&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
I'll apply this update one evening soon.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/784#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/788</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/788</guid>
        <title>#788: New BOA-2.3.3 Stable Edition available</title>
        <pubDate>Mon, 15 Sep 2014 09:21:34 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/boa-changes"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/boa-changes&lt;/a&gt;
&lt;/p&gt;
&lt;pre class="wiki"&gt;### Stable BOA-2.3.1 Release - Full Edition
### Date: Sun Sep 14 15:53:25 SGT 2014
### Includes Aegir 2.1 with improvements
### Latest hotfix added on: Mon Sep 15 05:30:37 SGT 2014
# Release Notes:
  This major BOA Edition introduces many new features, changes and fixes.
  You should carefully read about some caveats further below **before** running
  this major upgrade on your system. Please secure a fresh system backup first.
  If you haven't run full barracuda+octopus upgrade to latest BOA Stable
  Edition yet, don't use any partial/system upgrade modes.
  Once new BOA Stable is released, you must run *full* upgrades with commands:
  $ cd;wget -q -U iCab http://files.aegir.cc/BOA.sh.txt;bash BOA.sh.txt
  $ barracuda up-stable
  $ octopus up-stable all both
  @=&amp;gt; Key new features:
  * BOA-2.3.1 comes with shiny Aegir 2.1 stable version, finally!
  * Support for Drupal sites in subdirectories is enabled by default
  * Solr 4 cores can be added/updated/deleted via site level INI settings
  * Super-easy to use New Relic support with per Octopus license key
  * Ability to add new Octopus instances with new, simple command syntax
  @=&amp;gt; Aegir control panel new features:
  * The list of sites is searchable by name or installation profile
  * You can schedule tasks against filtered sites in batches
  * Scheduling tasks in batches is available also on the platform view
  * Scheduling tasks in batches is available also on the profile view
  * Each site has its own tasks list available from the site view tab
  * You can schedule tasks also against platforms in batches
  * You can safely apply db updates via 'Run db updates' task on any site
  * It is now possible to choose any existing alias or the main site name
    as a redirect target, but without the need to rename the site --
    it will just re-verify the site and create new vhost automatically
  @=&amp;gt; Other important changes:
  * Support for PHP 5.2 has been officially deprecated
  * The www53 PHP-FPM pool has been switched from port to default socket mode
  * All existing vhosts must use wildcard in the Nginx 'listen' directive
  * Legacy mode for Install and Upgrade moves to 2.2.x branch
  * DB credentials are no longer in settings.php, only in drushrc.php
  * Latest Drush 6 version is used in the Aegir backend by default
  But what if you are not ready for this major upgrade and you would like
  to have more time for testing, but still be able to run system upgrades,
  thus effectively still using previous version 2.2.9 ?
#-### Legacy mode for Install and Upgrade moves to 2.2.x branch
  From now on, the 'legacy' install and upgrade mode available in all meta-
  installers will utilize branch 2.2.x instead of deprecated 2.1.x series.
  This means that starting with meta installers updated to use BOA-2.3.1
  version you can use commands like shown below to update Barracuda, Octopus
  and also to install more Octopus instances, while still using version 2.2.9:
  $ boa in-legacy public server.mydomain.org my@email o1
  $ barracuda up-legacy system
  $ octopus up-legacy o1
  $ boa in-legacy public server.mydomain.org my@email o2 mini
  etc.
  Remember to update your meta-installers first!
  $ cd;wget -q -U iCab http://files.aegir.cc/BOA.sh.txt;bash BOA.sh.txt
  Note also that if you will upgrade to current 'stable', it is not possible
  to downgrade back to the 'old stable' with 'legacy' mode, so please proceed
  with care!
  Remember also that current legacy version will not receive any further
  updates, even for security issues (besides those provided as packages by
  your OS vendor - Debian or Ubuntu, which will still work), because it is
  already different enough from current 2.3.1 stable, so we can't reliably
  maintain both with working upgrade path.
#-### Caveats: This upgrade will force wildcard in the Nginx 'listen' directive
  If you have old enough BOA system which still uses legacy IP mode and not
  a wildcard in the Nginx 'listen' directive, which is both Aegir and BOA
  standard for a long time already, this upgrade will fix the problem and
  update directives only in vhosts known and controlled by BOA.
  If you have any other vhosts, located in standard or non-standard Nginx/BOA
  directories for vhosts, you have to update them manually after upgrade to
  BOA-2.3.0 or newer, or they will take over all other vhosts on the system
  and cause redirects to /install.php which results with Nginx error 403 or 404,
  depending on the prior configuration.
  It will happen because IP based 'listen' directive in Nginx has higher
  priority, and will mess things horribly if there are vhosts using wildcard
  and some using the main system IP address.
  What and how to replace? Here are commands you need to run as root:
    $ sed -i "s/.*listen.*:80;/  listen  \*:80;/g" /path/to/vhost.file
    $ sed -i "s/.*listen.*:443/  listen  \*:443/g" /path/to/vhost.file
    $ service nginx reload
  Note: this **doesn't** affect special vhosts for SSL enabled sites, if used,
  because they are designed to use IP based 'listen' directives to provide
  separation between SSL enabled IPs and their associated certificates,
  while their associated 'upstream' block may even point to either local or
  remote IP address, so there is no wildcard to use in this case, and it will
  not conflict with all other vhosts managed by Aegir, because all SSL enabled
  vhosts listen on other IP addresses than the main system IP, which is
  by default used by all vhosts with wildcard in the 'listen' directive.
  The problem may happen only when you have vhosts using wildcard and also
  some vhosts using **main** system IP address in the 'listen' directive,
  which may happen also unintentionally during upgrade to BOA-2.3.0 or never,
  if there are either vhosts BOA doesn't control, or there are ghost vhosts
  not yet purged if you didn't upgrade to BOA-2.2.9 before, or there are
  some disabled sites, so their vhosts will not be re-created by Aegir
  during this major upgrade (because only active sites can be re-verified).
  While BOA will fix also any such ghost vhosts anyway, it will not be able
  to detect and fix vhosts outside of the standard directories managed by Aegir.
#-### Ability to add new Octopus instances with new, simple command syntax
  It is now possible to add stable Octopus instances w/o forcing Barracuda
  upgrade, plus optionally with no platforms added by default -- usage:
    $ boa {in-octopus} {email} {o2} {mini|max|none}
#-### The www53 PHP-FPM pool has been switched from port to default socket mode.
  Note that we are breaking backward compatibility here, so it will cause
  downtime on upgrade from any too old BOA version, until you will upgrade also
  Octopus instance(s) and update any other non-standard vhosts or includes
  still using legacy port mode for 'fastcgi_pass' Nginx directive.
  If you have 'fastcgi_pass 127.0.0.1:9090;' in any custom vhost or Nginx
  include file on the Octopus instance, you should replace it with:
    fastcgi_pass unix:/var/run/o1.fpm.socket;
  where 'o1' is your corresponding Octopus system username.
  Note that if you have custom vhosts or includes in the Aegir Master Instance,
  you should instead replace 'fastcgi_pass 127.0.0.1:9090;' with:
    fastcgi_pass unix:/var/run/www53.fpm.socket;
  where '53' is related to PHP version defined via _PHP_FPM_VERSION in your
  /root/.barracuda.cnf file. Note that while variable has a dot, the socket
  name doesn't.
#-### Support for PHP 5.2 has been officially deprecated
  While Barracuda 2.3.1 can continue to run and even upgrade if needed also
  the very old PHP 5.2 version, only Octopus instances running at least PHP 5.3
  or newer in both FPM and CLI mode can be upgraded to Octopus 2.3.1 Edition.
  If you are still using PHP 5.2 in your Octopus instance, you will not
  receive Aegir nor Drupal Platforms upgrade, but the Barracuda part of your
  system will receive upgrade to 2.3.1 anyway, so it will be ready to support
  your outdated Octopus instance upgrade as soon as you will switch it to
  modern and secure PHP version -- which is easy!
  Let's quote the original how-to for reference:
#-### Support for PHP FPM/CLI version safe switch per Octopus instance
  This allows to easily switch PHP version by the instance owner w/o system
  admin (root) help. All you need to do is to create ~/static/control/fpm.info
  and ~/static/control/cli.info file with a single line telling the system
  which available PHP version should be used (if installed): 5.5 or 5.4 or 5.3
  Only one of them can be set, but you can use separate versions for web access
  (fpm.info) and the Aegir backend (cli.info). The system will switch versions
  defined via these control files in 5 minutes or less. We use external control
  files and not any option in the Aegir interface to make sure you will never
  lock yourself by switching to version which may cause unexpected problems.
#-### Support for New Relic monitoring with per Octopus instance license key
  This new feature will disable global New Relic monitoring by deactivating
  server-level license key, so it can safely auto-enable or auto-disable it
  every 5 minutes, but per Octopus instance -- for all sites hosted on
  the given instance -- when a valid license key is present in the special
  new ~/static/control/newrelic.info control file.
  Please note that valid license key is a 40-character hexadecimal string
  that New Relic provides when you sign up for an account.
  To disable New Relic monitoring for the Octopus instance, simply delete
  its ~/static/control/newrelic.info control file and wait a few minutes.
  Please note that on a self-hosted BOA you still need to add your valid
  license key as _NEWRELIC_KEY in the /root/.barracuda.cnf file and run
  system upgrade with at least 'barracuda up-stable' first. This step is
  not required on Omega8.cc hosted service, where New Relic agent is already
  pre-installed for you.
#-### Solr 4 cores can be added/updated/deleted via site level INI settings
;;
;;  This option allows to activate Solr 4 core configuration for the site.
;;
;;  Only Solr 4 powered by Jetty server is available. Supported integration
;;  modules are limited to latest versions of either search_api_solr (D7 only)
;;  or apachesolr (will use Drupal core specific version automatically).
;;
;;  Currently used versions are listed below:
;;
;;    http://ftp.drupal.org/files/projects/search_api_solr-7.x-1.6.tar.gz
;;    http://ftp.drupal.org/files/projects/apachesolr-7.x-1.7.tar.gz
;;    http://ftp.drupal.org/files/projects/apachesolr-6.x-3.0-rc2.tar.gz
;;
;;  Note that you still need to add preferred integration module along with
;;  any its dependencies in your codebase since this feature doesn't modify
;;  your platform or site - it only creates Solr core with configuration
;;  files provided by integration module: schema.xml and solrconfig.xml
;;
;;  This setting affects only the running daily maintenance system behaviour,
;;  so you need to wait until next morning to be able to use new Solr 4 core.
;;
;;  Once the Solr core is ready to use, you will find a special file in your
;;  site directory: sites/foo.com/solr.php with details on how to access
;;  your new Solr core with correct credentials.
;;
;;  The site with enabled Solr core can be safely migrated between platforms,
;;  integration module can be moved within your codebase and even upgraded,
;;  as long as it is using compatible schema.xml and solrconfig.xml files.
;;
;;  Supported values for the solr_integration_module variable:
;;
;;    apachesolr
;;    search_api_solr
;;
;;  To delete existing Solr core simply comment out this line.
;;  The system will cleanly delete existing Solr core next morning.
;;
;solr_integration_module = NO
;;
;;  This option allows to auto-update your Solr 4 core configuration files:
;;
;;    schema.xml
;;    solrconfig.xml
;;
;;  If there is new release for either apachesolr or search_api_solr, your
;;  Solr core will not be automatically upgraded to use newer schema.xml and
;;  solrconfig.xml, unless allowed by switching solr_update_config to YES.
;;
;;  This option will be ignored if you will set solr_custom_config to YES.
;;
;solr_update_config = NO
;;
;;  This option allows to protect custom Solr 4 core configuration files:
;;
;;    schema.xml
;;    solrconfig.xml
;;
;;  To use customized version of either schema.xml or solrconfig.xml, you need
;;  to switch solr_custom_config to YES below and if you are using hosted
;;  Aegir service, submit a support ticket to get these files updated with
;;  your custom versions. On self-hosted BOA simply update these files directly.
;;
;;  Please remember to use Solr 4 compatible config files.
;;
;solr_custom_config = NO
# Updated Octopus platforms:
  aGov 1.4 --------------------- https://drupal.org/project/agov
  Guardr 1.12 ------------------ https://drupal.org/project/guardr
  Open Academy 1.1 ------------- https://drupal.org/project/openacademy
  Restaurant 1.0-b9 ------------ https://drupal.org/project/restaurant
  Ubercart 3.7 ----------------- https://drupal.org/project/ubercart
# New features and enhancements in this release:
  * Ability to add new Octopus instances with new, simple command syntax
  * Add default aggressive php-fpm monitoring + /root/.no.fpm.cpu.limit.cnf
  * Allow to define always disabled modules via _MODULES_FORCE variable.
  * Better wait limits on connection testing for slow network / long distance.
  * Issue #1927522 - Add support for easy Solr cores self-management.
  * Issue #362 - Add imageapi_optimize binaries via IMG in _XTRAS_LIST
  * Issue #376 - Add New Relic support with per Octopus instance license key.
  * Make firewall management faster with randomized schedule.
  * Procs monitor runs every 3 seconds.
  * Run mysql_proc_control every 5 seconds for better results.
  * You can safely apply db updates via 'Run db updates' task on any site.
# Changes in this release:
  * DB credentials are no longer visible in settings.php, only in drushrc.php
  * Delete default profiles in the hostmaster platform.
  * Disable _DEBUG_MODE if not enabled on the fly.
  * Disable newrelic-sysmond unless /root/.enable.newrelic.sysmond.cnf exists.
  * Drush: Upgrade command line version 6 to mini-6-14-09-2014
  * Nginx: Remove deprecated code - _HTTP_WILDCARD is already used by default.
  * Nginx: Use limit_conn protection only for known dynamic requests.
  * Redis Integration Module (cache_backport): Update to version 6.x-1.0-rc2
  * Redis Integration Module: Update to version mod-12-09-2014
  * Remove _ALLOW_UNSUPPORTED legacy and no longer working properly feature.
  * Remove dependency on Update Manager globally.
  * Remove deprecated multi-instance labels in the New Relic configuration.
  * Replace old hosting_civicrm_cron with newer hosting_civicrm module.
  * Set hosting_default_profile to 'minimal' to improve Ubercart 3 visibility.
  * The www53 PHP-FPM pool has been switched from port to default socket mode.
  * Use Provision CiviCRM boa-2.3.1-dev
# System upgrades in this release:
  * cURL 7.38.0 (if installed from sources)
  * Git 2.1.0 (if installed from sources)
  * Jetty 7.6.16.v20140903
  * Jetty 8.1.16.v20140903
  * Jetty 9.2.3.v20140905
  * PHP 5.3.29 EOL! Please read: http://php.net/archive/2014.php#id2014-08-14-1
  * PHP 5.4.32
  * PHP 5.5.16
  * Redis 2.8.14
# Fixes in this release:
  * Add cleanup for _GIT_FORCE_REINSTALL if added in .barracuda.cnf
  * Add missing drush cache-clear drush to improve upgrade path.
  * Add new features in the README.txt
  * Add wheezy to the exceptions list where required.
  * Allow to clear drush cache without directory restrictions.
  * Always set correct TMP path for supported users.
  * Cleanup for cron pid files in user specific .tmp dirs.
  * Count properly also symlinked files directories (improved).
  * D6 colorbox module requires old 1.3.18 library.
  * Delete drush_make leftovers.
  * Delete duplicate menu items on upgrade.
  * Do not allow to install SSH from sources on Trusty to avoid problems.
  * Do not skip daily.sh during barracuda system only update.
  * Eldir theme: Use max width for buttons, if possible.
  * Explain why installing RVM may take longer than expected.
  * Fix cleanup for drush aliases in sub-accounts.
  * Fix daily cleanup for user specific .tmp directories.
  * Fix docs/HINTS.txt
  * Fix for broken mariadb.list
  * Fix for broken, way too aggressive PHP-FPM monitoring.
  * Fix for ghost dirs cleanup.
  * Fix for ghost vhosts cleanup.
  * Fix for missing symlinks to existing platforms.
  * Fix for not working protection from blocking local IPs on multi-IP systems.
  * Fix for subdirs_support universal check.
  * Fix for unreliable _IS_OLD check on Octopus instances upgrade.
  * Fix for warning "Could not create directory ." on Hostmaster site Verify.
  * Fix the fields order in the site edit form.
  * Fix the regex to not whitelist unexpected IP ranges inadvertently.
  * Force cURL rebuild if installed with outdated OpenSSL version.
  * Guard against destructive or insecure tasks run on the hostmaster site.
  * Improve cleanup for empty platforms directories.
  * Improve monitoring to protect against convert trying to overload the system.
  * Issue #2330781 - Use Drush dt() wrapper instead of not always available t()
  * Issue #357 - Fix the logic for Git (re)install from sources.
  * Issue #360 - Exclude special --CDN vhosts from daily cleanup.
  * Issue #361 - Update and improve docs/FAQ.txt
  * Issue #369 - Automatically download and fix /bin/websh if missing.
  * Issue #369 - Restore classic /bin/sh symlink automatically if needed.
  * Issue #373 - Set correct TMP, TEMP, TMPDIR env variables in limited shell.
  * Issue #373 - Too restrictive lshell forbidden list breaks drush sql-sync.
  * Issue #380 - Nameserver / pdnsd problem -- Fixes also Issue #2007990.
  * Issue #381 - Zend OPcache forced adds useless noise in the log.
  * Issue #388 - Version 6.x-2.x of provision_civicrm requires hosting_civicrm
  * Issue #389 - hosting_civicrm breaks site install form with confusing error.
  * Issue #390 - Duplicate platforms nodes are created after upgrade to 2.3.0
  * Issue #395 - Validate username isn't reserved before running install script.
  * Issue #396 - Locale isn't getting set properly.
  * Issue #397 - Not actually prompted for platforms during installation.
  * Issue #398 - Make locales setup/fix for Debian always OS compatible.
  * Issue #399 - The hitimes gem needs to be pre-installed to support Omega4.
  * Issue #400 - CiviCRM is not installed on 2.3.0
  * Issue #401 - Create sites/all/* subdirs in Hostmaster early enough.
  * Issue #402 - Fix for ghost or disabled vhosts which still listen on IP.
  * Issue #405 - Installer hangs due to yes/no dialog - "Untrusted packages"
  * Issue #406 - Force keyring reinstall also upon 'GPG error'.
  * Issue #407 - Fix for 'username is already taken' error on a local VM install
  * Issue #408 - Fix for multiple funny typos. Thanks ar-jan!
  * Make it clear that subdomain and subdirectory name must be identical.
  * Make sure that keys subdirectory exists to avoid active platforms cleanup.
  * Make the PHP-FPM processes monitor less aggressive by default.
  * Nginx: Add config symlinks only on legacy instances.
  * Nginx: Add cron access support for subdir sites.
  * Nginx: Convert all vhosts to wildcard mode on Barracuda upgrade.
  * Nginx: Disable monitoring for POST requests related to cart/checkout URI.
  * Nginx: Do not touch nginx_wild_ssl.conf during this upgrade.
  * Nginx: Improve wildcard conversion procedure on some really old instances.
  * Nginx: Remove deprecated code and config templates.
  * Nginx: Sanitize aliases in vhost_disabled.tpl.php to avoid warnings.
  * Nginx: Update config includes to match optional BOA features improvements.
  * Nginx: Update unified configuration templates in Provision to unfork BOA.
  * Nginx: Update vhosts templates to match BOA improvements.
  * PHP: Avoid unintended duplicate rebuilds.
  * PHP: Sync disable_functions list.
  * Protect sites/all/drush
  * Provision: Backport provision_hosting_feature_enabled()
  * Provision: Remove legacy subdir code and update checks.
  * Redis config should sync with PHP-CLI, not PHP-FPM.
  * Remove legacy procs monitoring code.
  * Remove no longer needed limreq global fixes.
  * Remove no longer needed/used contrib updates.
  * Remove redundant file_exists() if is_readable() is also used.
  * Replace old hosting_civicrm_cron with newer hosting_civicrm module.
  * Restart pdnsd before running barracuda upgrade.
  * Restore BOA formatting for tasks log to improve readability.
  * Restore BOA naming convention and docs in Hostmaster.
  * Restore BOA naming convention for Installation profiles in Hostmaster.
  * Restore BOA strict _hosting_valid_fqdn* testing procedures in Hostmaster.
  * Restore BOA weight defaults in the form in Hostmaster.
  * Restore punycode in Hostmaster.
  * Restore tasks sort to always show tasks scheduled and running at the top.
  * Sanitize cli.info and fpm.info
  * Set _PLATFORMS_LIST properly.
  * Silence early sed replacements to avoid confusion.
  * Simplify colorbox-1.3.18 download.
  * Simplify colorbox-1.5.13 download.
  * Switch branch on the fly and add support for Aegir vanilla mode.
  * Sync /tmp access restrictions.
  * The hosting_civicrm_cron is now a submodule and should be also auto-enabled.
  * The wildcard transition **doesn't** affect vhosts for SSL enabled sites.
  * There is no need to force backend clone from GitHub on initial upgrade.
  * Update for the Hostmaster welcome page.
  * Update FPM monitoring settings.
  * Use as short labels on the site node as possible.
  * Use control files properly to not run redundant Jetty/Solr upgrade.
  * Use correct paths to platform level drushrc.php file.
  * Use correct Provision version on initial upgrade to 2.3.0
  * Use Drush6 with @hostmaster.
  * Use is_dir() instead of file_exists() when checking directory existence.
  * Use is_file() and is_link() instead of file_exists() before trying unlink()
  * Use is_readable() and file_exists() instead of file_exists() for backup.
  * Use is_readable() check instead of insufficient file_exists() for includes.
  * Use is_readable() instead of file_exists() when checking alias existence.
  * Install latest Git even if not specified via _XTRAS_LIST but previous
    version built from sources is detected.
  * Issue #2278847 - Derivatives can't be created on install with Drush and
    Aegir or when no vhost is available yet (Drupal Commons)
&lt;/pre&gt;&lt;p&gt;
Having read through the above it is good to see the switch to use sockets rather than TCP/IP for php-fpm, not sure if there are any other changes that would effect us. I'll do the upgrade one evening this week.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/788#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/529</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/529</guid>
        <title>#529: New Barracuda BOA-2.0.7 Edition available</title>
        <pubDate>Fri, 05 Apr 2013 08:57:09 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;blockquote class="citation"&gt;
&lt;blockquote&gt;
&lt;p&gt;
There is new BOA-2.0.7 Edition of Barracuda and Octopus available.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible
to receive all security updates and new features.
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/529#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/530</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/530</guid>
        <title>#530: New Barracuda BOA-2.0.8 Edition available</title>
        <pubDate>Mon, 08 Apr 2013 07:44:51 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
If I had known this was about to come out I would have waited before doing the BOA-2.0.7 upgrade last night on &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/529" title="maintenance: New Barracuda BOA-2.0.7 Edition available (closed: fixed)"&gt;ticket:529&lt;/a&gt;
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;p&gt;
There is new BOA-2.0.8 Edition of Barracuda and Octopus available.
&lt;/p&gt;
&lt;p&gt;
Please review the changelog and upgrade as soon as possible to receive all security updates and new features.
&lt;/p&gt;
&lt;p&gt;
Changelog: &lt;a class="ext-link" href="http://bit.ly/newboa"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://bit.ly/newboa&lt;/a&gt;
&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;
Is mostly to fix a problem for people using Percona, &lt;a class="ext-link" href="https://drupal.org/node/1962690"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://drupal.org/node/1962690&lt;/a&gt; and as we are using MariaDB this isn't an issue for us.
&lt;/p&gt;
&lt;p&gt;
Other updates in this version:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;ul&gt;&lt;li&gt;Allow to use [a-z0-9] subdomains and not only [www] for IDN domain names.
&lt;/li&gt;&lt;li&gt;Change the interval between platforms builds from 5 to 3 seconds.
&lt;/li&gt;&lt;li&gt;Forced 1s Speed Booster TTL for vhosts behind local proxy is deprecated.
&lt;/li&gt;&lt;li&gt;Move old firewall logs to backups to avoid crazy load after upgrade.
&lt;/li&gt;&lt;li&gt;Nginx: Better exceptions handling in the Abuse Guard for js/shs modules.
&lt;/li&gt;&lt;li&gt;PHP: CLI is at 5.3 since BOA-2.0.4, so symlink old 5.2 binary path to 5.3
&lt;/li&gt;&lt;li&gt;Update _LENNY_TO_SQUEEZE major upgrade procedure.
&lt;/li&gt;&lt;li&gt;Update contrib with login_security-7.x-1.2
&lt;/li&gt;&lt;li&gt;Use static downloads for all distros in stable edition.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
&lt;p&gt;
I'll do this update tonight unless there are any objections, hopefully it should be quite quick.
&lt;/p&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/530#changelog</comments>
    </item>
 </channel>
</rss>