[tor-bugs] #13252 [Tor Browser]: Tor Browser on OS X should not store data into the application bundle

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Mar 14 11:18:55 UTC 2016


#13252: Tor Browser on OS X should not store data into the application bundle
----------------------------------+--------------------------------
 Reporter:  torosx                |          Owner:  mcs
     Type:  defect                |         Status:  needs_revision
 Priority:  Medium                |      Milestone:
Component:  Tor Browser           |        Version:
 Severity:  Normal                |     Resolution:
 Keywords:  TorBrowserTeam201603  |  Actual Points:
Parent ID:  #6540                 |         Points:
 Reviewer:                        |        Sponsor:
----------------------------------+--------------------------------
Changes (by gk):

 * keywords:  TorBrowserTeam201603R => TorBrowserTeam201603
 * status:  needs_review => needs_revision


Comment:

 Replying to [comment:36 mcs]:
 > Replying to [comment:35 gk]:
 > > Commits 4d8e33f4dca21923f3dfef4e740c3c01f395ec1e,
 4ea6a818614ec50a62e1bf683baed931d33586ff and
 f5f6dd2b7d6358343917dba64f722896aa6b79a3 in your tor-browser branch look
 good to me.
 >
 > Thank you for all the reviews! I think the only remaining patch is
 b03f511d38631243fec0e6c5427d9a50e602a762 (also on our tor-browser branch).

 Yes. I just wanted to indicate to you where I was in my review process and
 that I probably won't get to that commit anymore on Friday. :)

 > After you have a chance to review that one, Kathy and I will create new
 tor-launcher, tor-browser-bundle, and tor-browser patches. We will take
 your feedback into account and probably combine
 4d8e33f4dca21923f3dfef4e740c3c01f395ec1e and
 b03f511d38631243fec0e6c5427d9a50e602a762 into one patch while we are at
 it.

 Sounds good to me. Re the missing commit it looks good to me. I'd like to
 understand better the following, though:

 {{{
 +        // Display an error alert and continue startup. Since XPCOM was
 +        // initialized in a limited way inside ProfileErrorDialog() and
 +        // because it cannot be reinitialized, use LaunchChild() to start
 +        // the browser.
 }}}
 What exactly is happening in this case? What is the user experiencing? I
 assume no IP leakage? But what else?

 arthuredelstein: Could you please have a look at the C++ bits as well
 (especially commit b03f511d38631243fec0e6c5427d9a50e602a762 but commits
 4d8e33f4dca21923f3dfef4e740c3c01f395ec1e,
 4ea6a818614ec50a62e1bf683baed931d33586ff as well)

 mcs, brade: Thanks for all this, nice job. I plan to test the profile
 migration stuff a bit (that's the remaining testing bit I plna to do) this
 week. The `needs_revision` is for the pieces I found so far which are
 mentioned in previous comments.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/13252#comment:37>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list