Closed
Bug 1465108
Opened 6 years ago
Closed 6 years ago
Uplift some compacting GC changes which landed in bug 1457703
Categories
(Core :: JavaScript: GC, defect)
Core
JavaScript: GC
Tracking
()
People
(Reporter: jonco, Assigned: jonco)
References
Details
(Keywords: sec-high, Whiteboard: [adv-main61+][adv-esr52.9+][adv-esr60.1+][post-critsmash-triage])
Attachments
(6 files)
(deleted),
patch
|
RyanVM
:
approval-mozilla-beta+
|
Details | Diff | Splinter Review |
(deleted),
patch
|
RyanVM
:
approval-mozilla-beta+
|
Details | Diff | Splinter Review |
(deleted),
patch
|
RyanVM
:
approval-mozilla-esr60+
|
Details | Diff | Splinter Review |
(deleted),
patch
|
RyanVM
:
approval-mozilla-esr60+
|
Details | Diff | Splinter Review |
(deleted),
patch
|
RyanVM
:
approval-mozilla-esr52+
|
Details | Diff | Splinter Review |
(deleted),
patch
|
RyanVM
:
approval-mozilla-esr52+
|
Details | Diff | Splinter Review |
I think we want to uplift two out of three patches that landed in bug 1457703. Moving those patches to this bug for the sake of simplicity.
Assignee | ||
Comment 1•6 years ago
|
||
Approval Request Comment
[Feature/Bug causing the regression]: Bug 1257186.
[User impact if declined]: Possible crash / security vulnerability.
[Is this code covered by automated tests?]: Yes.
[Has the fix been verified in Nightly?]: Yes.
[Needs manual test from QE? If yes, steps to reproduce]: No.
[List of other uplifts needed for the feature/fix]: None.
[Is the change risky?]: No.
[Why is the change risky/not risky?]: This is a very simple change and is covered by assertions in the patch.
[String changes made/needed]: None.
Attachment #8981527 -
Flags: approval-mozilla-beta?
Assignee | ||
Comment 2•6 years ago
|
||
Approval Request Comment
[Feature/Bug causing the regression]: Bug 1064578.
[User impact if declined]: Possible crash / security vulnerability.
[Is this code covered by automated tests?]: Yes.
[Has the fix been verified in Nightly?]: Yes.
[Needs manual test from QE? If yes, steps to reproduce]: No.
[List of other uplifts needed for the feature/fix]: None.
[Is the change risky?]: Low risk.
[Why is the change risky/not risky?]: This is a fairly mechanical change that only affects the GC.
[String changes made/needed]: None.
Attachment #8981528 -
Flags: approval-mozilla-beta?
Assignee | ||
Comment 3•6 years ago
|
||
[Approval Request Comment]
If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-high bug.
User impact if declined: Possible crash / security vulnerability.
Fix Landed on Version: FF 62.
Risk to taking this patch (and alternatives if risky): Low.
String or UUID changes made by this patch: None
Attachment #8981529 -
Flags: approval-mozilla-esr60?
Assignee | ||
Comment 4•6 years ago
|
||
[Approval Request Comment]
If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-high bug.
User impact if declined: Possible crash / security vulnerability.
Fix Landed on Version: FF 62.
Risk to taking this patch (and alternatives if risky): Low.
String or UUID changes made by this patch: None
Attachment #8981530 -
Flags: approval-mozilla-esr60?
Assignee | ||
Updated•6 years ago
|
Keywords: sec-high
Summary: Uplift some compacting GC changes in bug 1457703 → Uplift some compacting GC changes which landed in bug 1457703
Assignee | ||
Comment 5•6 years ago
|
||
[Approval Request Comment]
If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-high bug.
User impact if declined: Possible crash / security vulnerability.
Fix Landed on Version: FF 62.
Risk to taking this patch (and alternatives if risky): Low.
String or UUID changes made by this patch: None
Attachment #8981538 -
Flags: approval-mozilla-esr52?
Assignee | ||
Comment 6•6 years ago
|
||
[Approval Request Comment]
If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-high bug.
User impact if declined: Possible crash / security vulnerability.
Fix Landed on Version: FF 62.
Risk to taking this patch (and alternatives if risky): Low.
String or UUID changes made by this patch: None
Attachment #8981539 -
Flags: approval-mozilla-esr52?
Updated•6 years ago
|
status-firefox60:
--- → wontfix
status-firefox61:
--- → affected
status-firefox62:
--- → fixed
status-firefox-esr52:
--- → affected
status-firefox-esr60:
--- → affected
tracking-firefox61:
--- → +
tracking-firefox62:
--- → +
tracking-firefox-esr52:
--- → 61+
tracking-firefox-esr60:
--- → 61+
Target Milestone: --- → mozilla62
Comment 7•6 years ago
|
||
Comment on attachment 8981527 [details] [diff] [review]
compacting-thread-count-beta
Fixes for various possibly-exploitable race conditions in the GC. Approved for 61.0b10, ESR 60.1, and ESR 52.9.
Attachment #8981527 -
Flags: approval-mozilla-beta? → approval-mozilla-beta+
Updated•6 years ago
|
Attachment #8981528 -
Flags: approval-mozilla-beta? → approval-mozilla-beta+
Updated•6 years ago
|
Attachment #8981529 -
Flags: approval-mozilla-esr60? → approval-mozilla-esr60+
Updated•6 years ago
|
Attachment #8981530 -
Flags: approval-mozilla-esr60? → approval-mozilla-esr60+
Updated•6 years ago
|
Attachment #8981538 -
Flags: approval-mozilla-esr52? → approval-mozilla-esr52+
Updated•6 years ago
|
Attachment #8981539 -
Flags: approval-mozilla-esr52? → approval-mozilla-esr52+
Comment 8•6 years ago
|
||
Jon, I tried to land this on Beta but hit (probably easy to fix) static analysis bustage:
https://treeherder.mozilla.org/logviewer.html#?job_id=180784011&repo=mozilla-beta
Also, please be sure to update the bug number in the commit messages for these patches when pushing.
Status: NEW → ASSIGNED
Flags: needinfo?(jcoppeard)
Assignee | ||
Comment 9•6 years ago
|
||
uplift |
https://hg.mozilla.org/releases/mozilla-beta/rev/8adb9f8f899391c199bdd5841efe2e87260ea595
https://hg.mozilla.org/releases/mozilla-beta/rev/c9632ef7fb170beb9d2217117125c35dc7f7e516
Flags: needinfo?(jcoppeard)
Assignee | ||
Comment 10•6 years ago
|
||
uplift |
Assignee | ||
Comment 11•6 years ago
|
||
uplift |
Assignee | ||
Comment 12•6 years ago
|
||
uplift |
Assignee | ||
Comment 13•6 years ago
|
||
backout |
Backed out for bustage:
https://hg.mozilla.org/releases/mozilla-esr52/rev/2a8f47c78ecc4533fc4317f22bfc9a4442ed3fc5
Updated•6 years ago
|
Assignee | ||
Comment 14•6 years ago
|
||
uplift |
Updated•6 years ago
|
Updated•6 years ago
|
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Updated•6 years ago
|
Group: javascript-core-security → core-security-release
Updated•6 years ago
|
Whiteboard: [adv-main61+][adv-esr52.9+][adv-esr60.1+]
Updated•6 years ago
|
Flags: qe-verify-
Whiteboard: [adv-main61+][adv-esr52.9+][adv-esr60.1+] → [adv-main61+][adv-esr52.9+][adv-esr60.1+][post-critsmash-triage]
Updated•5 years ago
|
Group: core-security-release
You need to log in
before you can comment on or make changes to this bug.
Description
•