Closed Bug 1184065 Opened 9 years ago Closed 9 years ago

DestinationInsertionPointList doesn't QI to nsWrapperCache, nor trace the wrapper

Categories

(Core :: DOM: Core & HTML, defect)

36 Branch
defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla42
Tracking Status
firefox39 --- wontfix
firefox40 --- wontfix
firefox41 --- disabled
firefox42 + fixed
firefox-esr31 --- disabled
firefox-esr38 --- disabled
b2g-v2.0 --- wontfix
b2g-v2.0M --- wontfix
b2g-v2.1 --- wontfix
b2g-v2.1S --- fixed
b2g-v2.2 --- fixed
b2g-v2.2r --- fixed
b2g-master --- fixed

People

(Reporter: smaug, Assigned: smaug)

References

Details

(Keywords: sec-high, Whiteboard: [post-critsmash-triage])

Attachments

(1 file)

Attached patch patch (deleted) — Splinter Review
No description provided.
Attachment #8634026 - Flags: review?(wchen)
Comment on attachment 8634026 [details] [diff] [review] patch [Security approval request comment] This is similar to https://bugzilla.mozilla.org/show_bug.cgi?id=1183901#c3
Attachment #8634026 - Flags: sec-approval?
Attachment #8634026 - Flags: review?(wchen) → review+
Keywords: sec-high
sec-approval+. We should take this on affected branches as well.
Attachment #8634026 - Flags: sec-approval? → sec-approval+
Comment on attachment 8634026 [details] [diff] [review] patch [Approval Request Comment] https://bugzilla.mozilla.org/show_bug.cgi?id=1183901#c3 The patch seems to apply cleanly to esr38 too.
Attachment #8634026 - Flags: approval-mozilla-esr38?
Attachment #8634026 - Flags: approval-mozilla-beta?
Attachment #8634026 - Flags: approval-mozilla-aurora?
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla42
I have the same question here as in https://bugzilla.mozilla.org/show_bug.cgi?id=1183901#c8. If the browser is not affected in the default configuration, do we need to uplift the fix?
abillings - Can we let this fix ride the trains like bug 1183901?
Flags: needinfo?(abillings)
Comment on attachment 8634026 [details] [diff] [review] patch As per comment 8, we're going to let this ride the trains.
Attachment #8634026 - Flags: approval-mozilla-esr38?
Attachment #8634026 - Flags: approval-mozilla-esr38-
Attachment #8634026 - Flags: approval-mozilla-beta?
Attachment #8634026 - Flags: approval-mozilla-beta-
Attachment #8634026 - Flags: approval-mozilla-aurora?
Attachment #8634026 - Flags: approval-mozilla-aurora-
Comment on attachment 8634026 [details] [diff] [review] patch NOTE: Please see https://wiki.mozilla.org/Release_Management/B2G_Landing to better understand the B2G approval process and landings. [Approval Request Comment] Bug caused by (feature/regressing bug #): bug 854736 User impact if declined: crashes in certified apps that use WebComponents Testing completed: just tree herder Risk to taking this patch (and alternatives if risky): low, this is pretty standard stuff String or UUID changes made by this patch: none (This is similar to bug 1183901.)
Attachment #8634026 - Flags: approval‑mozilla‑b2g37_v2_2r?
Attachment #8634026 - Flags: approval-mozilla-b2g37?
Attachment #8634026 - Flags: approval-mozilla-b2g34?
Attachment #8634026 - Flags: approval-mozilla-b2g32?
Comment on attachment 8634026 [details] [diff] [review] patch This is sec-high, so it has auto-approval for uplift to affected active B2G branches.
Attachment #8634026 - Flags: approval‑mozilla‑b2g37_v2_2r?
Attachment #8634026 - Flags: approval-mozilla-b2g37?
Attachment #8634026 - Flags: approval-mozilla-b2g34?
Attachment #8634026 - Flags: approval-mozilla-b2g32?
Group: dom-core-security → release-core-security
Olli, would this benefit from a test?
Flags: needinfo?(bugs)
bug 1183604 made us assert hard on debug builds if this kind of mistake happens in the future.
Flags: needinfo?(bugs)
Was this disabled in 41, like bug 1183901?
Flags: needinfo?(bugs)
Whiteboard: [post-critsmash-triage]
yeah, this is web components stuff too, so, not enabled by default.
Flags: needinfo?(bugs)
Group: core-security-release
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: