classilla / tenfourfox

Mozilla for Power Macintosh.
http://www.tenfourfox.com/
Other
273 stars 41 forks source link

Security and patch rollup for FPR17 from ESR68 #578

Closed classilla closed 3 years ago

classilla commented 4 years ago

Through 40604532805a07a5a30be8a1cdef0f48975de71e Build system, test and Mozilla-internal bugs omitted

Not relevant: M1499093 (Android) M1578907 (Catacrapalina) M1554805 (WX) M1570559 (no APZ) M1592502 (GTK) M1573753 (we don't have this regression) M1580288 (not in code) M1592371 (Windows) M1591334 (not in code) M1564127 (not IPC, we don't support VR)

Not taking: M1560667 (compiler specific and likely to have more regression than benefit) M1590845 (don't care) M1426865 (don't care) M1581084 (larger class of fingerprint bugs; we have no sensor data of interest here)

Deferred: M1218456 moved to #579

Candidates: M1580320 https://hg.mozilla.org/releases/mozilla-esr68/rev/9dced159051d M1584170 https://hg.mozilla.org/releases/mozilla-esr68/rev/1bcfb098011f https://hg.mozilla.org/releases/mozilla-esr68/rev/4b95348b577e (as nsAutoTArray) M1578143 https://hg.mozilla.org/releases/mozilla-esr68/rev/f83089aed736 (needs minimal changes such as EvictionThreshold() to mEvictionThreshold and possibly track->GetTrackBuffer() to GetTrackBuffer(track)???)

classilla commented 4 years ago

I should have read M1578143 more thoroughly. It was actually caused by M1531201, which we don't have, so we don't need it.

classilla commented 4 years ago

Interdiff

M1579612 (unaffected) M1576374 (unaffected, and SafeBrowsing is dead against 45) M1580156 (Windows) M1594136 (unaffected) M1546331 (we don't have M1211903, so I don't think we're susceptible) M1583957 moved to #580 M1582215 (unaffected) M1584986 (unaffected) M1591077 (Android) M1587962 (Catacrapalina) M1593041 (don't care) M1586496 (don't care) M1591691 (we don't implement this) M1588975 (Windows)

Current to 1cc2971e671a0816c122cbef798a53e577398ad6

classilla commented 4 years ago

Still need to figure out what to do with M1501152 ("this is a somewhat scary fix, so land first and see if there is any bustage"). https://hg.mozilla.org/releases/mozilla-esr60/rev/2ce17180fd4dd8828caa964ba55205a51c313355 https://hg.mozilla.org/releases/mozilla-esr60/rev/d8dd10ac54302e4bd9cf6c537f790933b149099d

classilla commented 4 years ago

Interdiff

M1322864 https://hg.mozilla.org/releases/mozilla-esr68/rev/30006ca3a1e1ce3419cc4360cb70d703bc14a40c (first half) M1449736 (no plugins, no IPC) M1585106 unlikely to be a problem, but won't hurt. https://hg.mozilla.org/releases/mozilla-esr68/rev/02a75a0b91b8e6c55a6489146432373c9c7e0e0f M1597043 https://hg.mozilla.org/releases/mozilla-esr68/rev/d36df7bc9977 M1597543 (not in code) M1579127 (unaffected) M1580695 (unaffected) M1589900 (unaffected) M1575934 (unaffected) M1585760 (unaffected, not enabled) M1597273 (not implemented) M1590453 (Android) M1596078 (Android)

Current to 78ab5e054eb0a2a71f3d1f1875de5fc4c575ac91

NSS updates M1579060 can't hurt https://hg.mozilla.org/projects/nss/rev/64e55c9f658e2a75f0835d00a8a1cdc2f25c74d6 (both files in security/pkix/lib) M1586176 https://hg.mozilla.org/projects/nss/rev/1e22a0c93afe9f46545560c86caedef9dab6cfda

classilla commented 3 years ago

Wontfixing.