ma1 pushed to branch mullvad-browser-140.16.0esr-15.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 516c0254 by Makoto Kato at 2026-09-14T17:46:03+02:00 Bug 2027336 - Always call forget. a=dmeehan Original Revision: https://phabricator.services.mozilla.com/D322230 Differential Revision: https://phabricator.services.mozilla.com/D322280 - - - - - 05d8b591 by Andreas Farre at 2026-09-14T17:46:08+02:00 Bug 2029482 - Don't make ORB exemptions for DevTools. a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D319804 Differential Revision: https://phabricator.services.mozilla.com/D322302 - - - - - d1aaab4a by Chun-Min Chang at 2026-09-14T17:46:12+02:00 [ESR 153] Bug 2050150 - Require an NV12 destination stride that can hold a chroma row. a=dmeehan DONTBUILD Differential Revision: https://phabricator.services.mozilla.com/D320550 - - - - - 2eafe752 by David Parks at 2026-09-14T17:46:17+02:00 Bug 2058018 - Check the payload length in DragEnter before using r=win-reviewers,gstoll Differential Revision: https://phabricator.services.mozilla.com/D318224 - - - - - 42739b72 by Alexandre Poirot at 2026-09-14T17:46:22+02:00 Bug 2062551 - Allow heapsnapshot records when DevTools are active. a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D318392 Differential Revision: https://phabricator.services.mozilla.com/D321173 - - - - - 3af06f5c by Maurice Dauer at 2026-09-14T17:46:26+02:00 Bug 2063539 - Always resolve special target names, a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D318844 Differential Revision: https://phabricator.services.mozilla.com/D319952 - - - - - 391cac95 by Valentin Gosu at 2026-09-14T17:46:31+02:00 Bug 2063814 - Handle \ correctly in SplitMimetype a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D319097 Differential Revision: https://phabricator.services.mozilla.com/D320017 - - - - - 9b43e8c3 by Valentin Gosu at 2026-09-14T17:46:36+02:00 Bug 2064026 - Check if iterator has reached the end of the string a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D319073 Differential Revision: https://phabricator.services.mozilla.com/D320016 - - - - - 3e99055f by Dominik Bay at 2026-09-14T17:46:40+02:00 Bug 2066736 - Validate filter array lengths in FilePickerParent::RecvOpen. a=dmeehan The loop in RecvOpen counts with aFilters.Length() but reads aFilterNames[i]. If a content process sends the message with more filters than filterNames, the read goes out of bounds and the parent process crashes. So I added a check that both arrays have the same length. Original Revision: https://phabricator.services.mozilla.com/D321511 Differential Revision: https://phabricator.services.mozilla.com/D321697 - - - - - 6c69f642 by Sotaro Ikeda at 2026-09-14T17:46:45+02:00 Bug 2068438 a=dmeehan DONTBUILD Original Revision: https://phabricator.services.mozilla.com/D323156 Differential Revision: https://phabricator.services.mozilla.com/D323435 - - - - - 13 changed files: - devtools/shared/heapsnapshot/HeapSnapshotTempFileHelperParent.cpp - devtools/shared/heapsnapshot/tests/xpcshell/test_saveHeapSnapshot_e10s_01.js - dom/base/MimeType.cpp - dom/base/nsGlobalWindowOuter.cpp - dom/ipc/FilePickerParent.cpp - dom/media/ImageConversion.cpp - dom/media/ImageConversion.h - gfx/layers/ImageContainer.cpp - gfx/layers/client/TextureClient.cpp - gfx/layers/client/TextureClient.h - intl/components/src/RelativeTimeFormat.cpp - netwerk/protocol/http/HttpBaseChannel.cpp - widget/windows/nsNativeDragTarget.cpp Changes: ===================================== devtools/shared/heapsnapshot/HeapSnapshotTempFileHelperParent.cpp ===================================== @@ -6,6 +6,7 @@ #include "mozilla/devtools/HeapSnapshot.h" #include "mozilla/devtools/HeapSnapshotTempFileHelperParent.h" +#include "mozilla/dom/ChromeUtils.h" #include "mozilla/ErrorResult.h" #include "private/pprio.h" @@ -23,6 +24,9 @@ static bool openFileFailure(ErrorResult& rv, mozilla::ipc::IPCResult HeapSnapshotTempFileHelperParent::RecvOpenHeapSnapshotTempFile( OpenHeapSnapshotTempFileResponse* outResponse) { + if (!dom::ChromeUtils::IsDevToolsOpened()) { + return IPC_FAIL_NO_REASON(this); + } auto start = TimeStamp::Now(); ErrorResult rv; nsAutoString filePath; ===================================== devtools/shared/heapsnapshot/tests/xpcshell/test_saveHeapSnapshot_e10s_01.js ===================================== @@ -5,5 +5,6 @@ // Test saving a heap snapshot in the sandboxed e10s child process. function run_test() { + ChromeUtils.notifyDevToolsOpened(); run_test_in_child("test_SaveHeapSnapshot.js"); } ===================================== dom/base/MimeType.cpp ===================================== @@ -111,8 +111,10 @@ template <typename char_type> ++pos; } - // Might as well check for base64 now - if (*pos != '=') { + // Might as well check for base64 now. Note that the loop above may have + // stopped because it reached the end of the input, in which case there is + // no code point to look at. + if (pos == end || *pos != '=') { // trim leading and trailing spaces while (namePos < pos && NS_IsHTTPWhitespace(*namePos)) { ++namePos; @@ -253,7 +255,13 @@ TMimeType<char_type>::SplitMimetype(const nsTSubstring<char_type>& aMimeType) { for (size_t i = 0; i < aMimeType.Length(); i++) { char_type c = aMimeType[i]; - if (c == '\"' && (i == 0 || aMimeType[i - 1] != '\\')) { + // https://fetch.spec.whatwg.org/#collect-an-http-quoted-string : a + // backslash only escapes inside a quoted string, and it consumes the code + // point that follows it, so an escaped backslash does not escape the next + // character. + if (inQuotes && c == '\\') { + ++i; + } else if (c == '"') { inQuotes = !inQuotes; } else if (c == ',' && !inQuotes) { mimeTypeParts.AppendElement(Substring(aMimeType, start, i - start)); ===================================== dom/base/nsGlobalWindowOuter.cpp ===================================== @@ -3841,10 +3841,8 @@ bool nsGlobalWindowOuter::WindowExists(const nsAString& aName, bool aLookForCallerOnJSStack) { MOZ_ASSERT(mDocShell, "Must have docshell"); - if (aForceNoOpener) { - return aName.LowerCaseEqualsLiteral("_self") || - aName.LowerCaseEqualsLiteral("_top") || - aName.LowerCaseEqualsLiteral("_parent"); + if (aForceNoOpener && !nsContentUtils::IsSpecialName(aName)) { + return false; } if (WindowGlobalChild* wgc = mInnerWindow->GetWindowGlobalChild()) { ===================================== dom/ipc/FilePickerParent.cpp ===================================== @@ -282,6 +282,10 @@ mozilla::ipc::IPCResult FilePickerParent::RecvOpen( return IPC_OK(); } + if (aFilters.Length() != aFilterNames.Length()) { + return IPC_FAIL(this, "PFilePicker::Open filter arrays lengths mismatch"); + } + mFilePicker->SetAddToRecentDocs(aAddToRecentDocs); for (uint32_t i = 0; i < aFilters.Length(); ++i) { ===================================== dom/media/ImageConversion.cpp ===================================== @@ -486,6 +486,13 @@ nsresult ConvertToNV12(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY, return NS_ERROR_INVALID_ARG; } + // An interleaved chroma row is 2 * ceil(width / 2) bytes wide. + if (aDestStrideY < aDestSize.width || + aDestStrideUV < 2 * CeilingOfHalf(aDestSize.width)) { + NS_WARNING("ConvertToNV12: destination strides too small for NV12"); + return NS_ERROR_INVALID_ARG; + } + if (const PlanarYCbCrData* data = GetPlanarYCbCrData(aImage)) { const ImageUtils imageUtils(aImage); Maybe<dom::ImageBitmapFormat> format = imageUtils.GetFormat(); ===================================== dom/media/ImageConversion.h ===================================== @@ -45,6 +45,9 @@ nsresult ConvertToI420(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY, /** * Converts aImage to an NV12 image and writes it to the given buffers. + * + * aDestStrideUV must be at least 2 * ceil(aDestSize.width / 2), since U and V + * are interleaved. Returns NS_ERROR_INVALID_ARG if either stride is too small. */ nsresult ConvertToNV12(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY, uint8_t* aDestUV, int aDestStrideUV, ===================================== gfx/layers/ImageContainer.cpp ===================================== @@ -254,10 +254,8 @@ Maybe<SurfaceDescriptor> Image::GetDescFromTexClient( return {}; } - const auto& tcd = tc->GetInternalData(); - SurfaceDescriptor ret; - if (!tcd->Serialize(ret)) { + if (!tc->ToSurfaceDescriptor(ret)) { return {}; } return Some(ret); ===================================== gfx/layers/client/TextureClient.cpp ===================================== @@ -558,8 +558,12 @@ void TextureClient::Destroy() { actor = nullptr; } - TextureData* data = mData; - mData = nullptr; + TextureData* data; + { + MutexAutoLock lock(mMutex); + data = mData; + mData = nullptr; + } if (data || actor || readLock) { TextureDeallocParams params; @@ -1050,8 +1054,7 @@ bool TextureClient::BorrowMappedYCbCrData(MappedYCbCrTextureData& aMap) { } bool TextureClient::ToSurfaceDescriptor(SurfaceDescriptor& aOutDescriptor) { - MOZ_ASSERT(IsValid()); - + MutexAutoLock lock(mMutex); return mData ? mData->Serialize(aOutDescriptor) : false; } ===================================== gfx/layers/client/TextureClient.h ===================================== @@ -621,6 +621,13 @@ class TextureClient : public AtomicRefCountedWithFinalize<TextureClient> { TextureData* GetInternalData() { return mData; } const TextureData* GetInternalData() const { return mData; } + /** + * Serializes the underlying TextureData into aDescriptor. Returns false if + * the TextureData has already been destroyed. Safe to call from any thread + * concurrently with Destroy(). + */ + bool ToSurfaceDescriptor(SurfaceDescriptor& aDescriptor); + uint64_t GetSerial() const { return mSerial; } void GetSurfaceDescriptorRemoteDecoder( SurfaceDescriptorRemoteDecoder* aOutDesc); @@ -719,16 +726,6 @@ class TextureClient : public AtomicRefCountedWithFinalize<TextureClient> { friend class AtomicRefCountedWithFinalize<TextureClient>; protected: - /** - * Should only be called *once* per texture, in TextureClient::InitIPDLActor. - * Some texture implementations rely on the fact that the descriptor will be - * deserialized. - * Calling ToSurfaceDescriptor again after it has already returned true, - * or never constructing a TextureHost with aDescriptor may result in a memory - * leak (see TextureClientD3D9 for example). - */ - bool ToSurfaceDescriptor(SurfaceDescriptor& aDescriptor); - void LockActor() const; void UnlockActor() const; ===================================== intl/components/src/RelativeTimeFormat.cpp ===================================== @@ -57,13 +57,13 @@ RelativeTimeFormat::TryCreate(const char* aLocale, ureldatefmt_open(IcuLocale(aLocale), nf, relDateTimeStyle, UDISPCTX_CAPITALIZATION_FOR_STANDALONE, &status); + // Ownership was transferred to mFormatter. + closeNumberFormatter.forget(); + if (U_FAILURE(status)) { return Err(ToICUError(status)); } - // Ownership was transferred to mFormatter. - closeNumberFormatter.forget(); - UniquePtr<RelativeTimeFormat> rtf = MakeUnique<RelativeTimeFormat>( aOptions.numeric, formatter, formattedRelativeDateTime); ===================================== netwerk/protocol/http/HttpBaseChannel.cpp ===================================== @@ -3316,13 +3316,6 @@ bool HttpBaseChannel::ShouldBlockOpaqueResponse() const { return false; } - bool isInDevToolsContext; - mLoadInfo->GetIsInDevToolsContext(&isInDevToolsContext); - if (isInDevToolsContext) { - LOGORB("No block: Request created by devtools"); - return false; - } - return true; } ===================================== widget/windows/nsNativeDragTarget.cpp ===================================== @@ -258,13 +258,13 @@ nsNativeDragTarget::DragEnter(LPDATAOBJECT pIDataSource, DWORD grfKeyState, nsresult loadResult = nsClipboard::GetNativeDataOffClipboard( pIDataSource, 0, ::RegisterClipboardFormat(CFSTR_PREFERREDDROPEFFECT), nullptr, &tempOutData, &tempDataLen); - if (NS_SUCCEEDED(loadResult) && tempOutData) { + if (NS_SUCCEEDED(loadResult) && tempOutData && tempDataLen >= sizeof(DWORD)) { mEffectsPreferred = *((DWORD*)tempOutData); - free(tempOutData); } else { // We have no preference if we can't obtain it mEffectsPreferred = DROPEFFECT_NONE; } + free(tempOutData); // Set the native data object into drag session session->SetIDataObject(pIDataSource); View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/a60... -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/a60... You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
participants (1)
-
ma1 (@ma1)