Closed Bug 1341088 Opened 3 years ago Closed 2 years ago

Support validation of OpenType Variation font tables


(Core :: Graphics: Text, defect, P3)




Tracking Status
firefox61 --- fixed


(Reporter: jfkthame, Assigned: jfkthame)


(Depends on 1 open bug, Blocks 1 open bug)


(Whiteboard: [gfx-noted])


(2 files)

Currently, the version of OTS we're using doesn't know about OpenType Variations tables.[1]

We should fix that, so that we don't risk passing corrupt/malicious tables to the font rasterizers.

Whiteboard: [gfx-noted]
Priority: -- → P3
I've submitted a PR to upstream OTS with an initial effort at validation of the Variations tables:
Presumably once this lands, the keep_variation_tables preference being flipped in bug 1447163 would need to be... removed?
Right, that will be redundant once OTS handles them.
Support for validating these tables has now landed upstream, so let's pull it into gecko as well.
Attachment #8964121 - Flags: review?(jmuizelaar)
Assignee: nobody → jfkthame
Rather than just removing the pref, I've replaced it with one that can be used to bypass validation for these tables (just like we can for the OpenType Layout tables), which may be useful for testing purposes (particularly if we run into flaws in the validator). But my assumption is that validation will stay turned on by default, so that we have some protection against exposing the various rasterizers to random bad data in these font tables.
Note that as the variation-font support only just landed upstream, there are likely to be minor fixes over the next few days as it gets a fuzzing workout, etc. At this point there are three small fixes pending in, and I fully expect there will be a few more of a similar nature.

So I intend to update the patch here with these fixes in the new code, as and when they get found/fixed/tested upstream.
Attachment #8964121 - Flags: review?(jmuizelaar) → review+
Attachment #8964122 - Flags: review?(jmuizelaar) → review+
Pushed by
Update OTS to upstream rev. 63ff19f4a8, which includes support for variation tables. r=jrmuizel
Enable validation of opentype variation tables in downloadable fonts, and replace the keep_variation_tables pref with validate_variation_tables (default=true). r=jrmuizel
Closed: 2 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla61
Duplicate of this bug: 1446024
You need to log in before you can comment on or make changes to this bug.