These NSPR and NSS upgrades are driven by the bugs listed in the dependency list, which are under embargo. We intend to land these patches into public NSS repository on October 15, and immediately afterwards into mozilla-inbound/central, for initial testing using the Firefox test automation. We should be ready to land release candidates of NSPR/NSS into the Firefox branch on October 16, and if it works fine, declare the final NSPR/NSS releases and land them into the Firefox branch by October 19. We're trying to land these patches as late as possible, but because you'll need time for Firefox release preparation, and testing of final Firefox builds, we're planning to do so two weeks prior to the scheduled November 3rd release date. Please let me know if this plan doesn't work for you.
Created attachment 8669837 [details] placeholder-1211587 [Approval Request Comment] fix critical security issues in NSPR and NSS Could you please approve by to October 15? Thank you.
Attachment #8669837 - Flags: approval-mozilla-aurora?
Tracked for 43.
status-firefox43: --- → affected
tracking-firefox43: --- → +
Group: crypto-core-security → core-security-release
Keywords: meta, sec-other
Attachment #8669837 - Flags: approval-mozilla-aurora? → approval-mozilla-aurora+
https://hg.mozilla.org/releases/mozilla-aurora/rev/c02736eb4d23 Note these are release candidates. The final tags (plus the change to bump configure.in) are expected to land on Monday, hopefully without any code changes.
Status: NEW → RESOLVED
Last Resolved: 3 years ago
status-firefox43: affected → fixed
Resolution: --- → FIXED
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main43-]
You need to log in before you can comment on or make changes to this bug.