Flash plugin can not save settings
Categories
(Core :: Security: Process Sandboxing, defect, P2)
Tracking
()
People
(Reporter: Matti, Assigned: handyman)
References
Details
(Keywords: regression)
Attachments
(1 file)
(deleted),
text/x-phabricator-request
|
lizzard
:
approval-mozilla-beta+
|
Details |
Reporter | ||
Updated•6 years ago
|
Assignee | ||
Comment 1•6 years ago
|
||
Updated•6 years ago
|
Updated•6 years ago
|
Comment 2•6 years ago
|
||
[Tracking Requested - why for this release]:
We're not going to get a fix for 66, so 67 is the new target.
Updated•6 years ago
|
Assignee | ||
Comment 5•6 years ago
|
||
I duped bug 1513966 to this issue. This fix for this (coming soon) also fixes that issue. STR that demo the case in bug 1513966:
- Go to https://www.permadi.com/tutorial/flashSharedObject/index.html
- Scroll down to the applets and select one to click-to-play. Permit Flash to run.
- Example 3 shows : "Number of times you have visited this page: 1". Reload the page.
Expected results:
Example 3 shows : "Number of times you have visited this page: 2"
Actual results:
Example 3 shows : "Number of times you have visited this page: 1" again.
Assignee | ||
Comment 6•6 years ago
|
||
The sandbox already permits the process to create/delete the folder and access files in it. This patch gives is access to the folder itself, namely it allows NtQueryAttributesFile to evaluate it. For complex reasons, this fixes Flash's ability to store local objects (see AS3's SharedObject API).
Assignee | ||
Comment 7•6 years ago
|
||
Comment 9•6 years ago
|
||
The fix here is pretty minimal and safe, so an uplift to 66 is possible.
Comment 10•6 years ago
|
||
bugherder |
jimm, can you request uplift since it looks like David is on PTO?
Andrei, can your team verify the fix? Thanks!
Comment 12•6 years ago
|
||
I can confirm that the issue isn't reproducible any more on Windows 10 x64 and on Ubuntu 16.04 x64 on the latest Firefox Nightly 67.0a1 (2019-02-05).
But on Mac OS X 10.14 I faced the same issues mentioned in the user story and in comment 5.
Is this expected?
Thanks.
Updated•6 years ago
|
Updated•6 years ago
|
Comment 13•6 years ago
|
||
Haik, maybe we need a similar fix on OSX?
Comment 14•6 years ago
|
||
Comment on attachment 9040600 [details]
Bug 1514073: Allow Windows plugin process to access Macromedia roaming folder (r?bobowen)
Beta/Release Uplift Approval Request
Feature/Bug causing the regression
sandbox work
User impact if declined
flash settings not saved
Is this code covered by automated tests?
No
Has the fix been verified in Nightly?
Yes
Needs manual test from QE?
No
If yes, steps to reproduce
List of other uplifts needed
Risk to taking this patch
Low
Why is the change risky/not risky? (and alternatives if risky)
adding a directory access exclusion, low risk change.
String changes made/needed
Comment 15•6 years ago
|
||
(In reply to Jim Mathies [:jimm] from comment #13)
Haik, maybe we need a similar fix on OSX?
I've filed bug 1525625 to address this.
Updated•6 years ago
|
Comment on attachment 9040600 [details]
Bug 1514073: Allow Windows plugin process to access Macromedia roaming folder (r?bobowen)
Fix for sandboxing Flash settings on Windows, OK to uplift for beta 6.
[Triage Comment]
Comment 17•6 years ago
|
||
bugherder uplift |
Comment 19•6 years ago
|
||
Since bug 1525625 was logged for the issue on Mac, I'll mark this as verified as fixed on Windows 10 x64 and on Ubuntu 16.04 x64.
Updated•6 years ago
|
Comment 20•6 years ago
|
||
Jim, this looks like a pretty safe patch. Is this something we might want to include as a ride-along for 65.0.1?
Comment 21•6 years ago
|
||
(In reply to Ryan VanderMeulen [:RyanVM] from comment #20)
Jim, this looks like a pretty safe patch. Is this something we might want to include as a ride-along for 65.0.1?
@Ryan, we have the same problem on Mac (bug 1525625) and the fix will probably also be low risk. I think the Mac fix will land within the next few days. If the timing lines up, it would be nice to fix this on both platforms.
Comment 22•6 years ago
|
||
Verified as fixed on Firefox 66.0b6 on Windows 10 x64 and on Ubuntu 16.04 x64.
Comment 23•6 years ago
|
||
(In reply to Ryan VanderMeulen [:RyanVM] from comment #20)
Jim, this looks like a pretty safe patch. Is this something we might want to
include as a ride-along for 65.0.1?
Sure, that seems ok.
Updated•6 years ago
|
Description
•