file not found in Preloader's nsZipArchive Likely/mostly omni jar corruption
Categories
(Core :: XPConnect, defect, P3)
Tracking
()
| Tracking | Status | |
|---|---|---|
| thunderbird_esr78 | --- | wontfix |
| thunderbird_esr91 | --- | affected |
| firefox-esr52 | --- | wontfix |
| firefox-esr60 | --- | wontfix |
| firefox-esr68 | --- | affected |
| firefox57 | + | wontfix |
| firefox58 | --- | wontfix |
| firefox59 | --- | wontfix |
| firefox60 | --- | wontfix |
| firefox61 | --- | wontfix |
| firefox62 | --- | wontfix |
| firefox63 | --- | wontfix |
| firefox64 | --- | wontfix |
| firefox65 | --- | wontfix |
| firefox66 | --- | wontfix |
| firefox67 | --- | wontfix |
| firefox68 | --- | wontfix |
| firefox69 | --- | wontfix |
| firefox70 | --- | fix-optional |
| firefox71 | --- | fix-optional |
People
(Reporter: philipp, Unassigned)
References
Details
(Keywords: crash, leave-open, regression, Whiteboard: [tbird crash])
Crash Data
Attachments
(1 file)
|
59 bytes,
text/x-review-board-request
|
mccr8
:
review+
rweiss
:
review+
rweiss
:
feedback+
ritu
:
approval-mozilla-beta+
|
Details |
Comment 1•8 years ago
|
||
| Reporter | ||
Comment 2•8 years ago
|
||
Updated•8 years ago
|
Comment 4•8 years ago
|
||
Updated•8 years ago
|
Comment 5•8 years ago
|
||
Comment 7•8 years ago
|
||
Comment 8•8 years ago
|
||
Comment 9•8 years ago
|
||
Comment 10•8 years ago
|
||
Updated•8 years ago
|
Comment 13•7 years ago
|
||
Comment 14•7 years ago
|
||
| Comment hidden (mozreview-request) |
Comment 16•7 years ago
|
||
Comment 17•7 years ago
|
||
| mozreview-review | ||
Comment 18•7 years ago
|
||
| mozreview-review | ||
Updated•7 years ago
|
Comment 19•7 years ago
|
||
Updated•7 years ago
|
Comment 20•7 years ago
|
||
Comment 21•7 years ago
|
||
| bugherder | ||
Updated•7 years ago
|
Comment 23•7 years ago
|
||
| uplift | ||
| Reporter | ||
Updated•7 years ago
|
| Reporter | ||
Comment 24•7 years ago
|
||
Comment 25•7 years ago
|
||
Updated•7 years ago
|
Comment 26•7 years ago
|
||
Comment 27•7 years ago
|
||
Comment 28•7 years ago
|
||
Updated•7 years ago
|
Comment 29•7 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Updated•6 years ago
|
Comment 30•6 years ago
|
||
Updated•6 years ago
|
Comment 31•6 years ago
|
||
Updating flags based on the fact there are still crashes happening in 68 nightly and 67 beta.
Updated•6 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Comment 32•5 years ago
|
||
The leave-open keyword is there and there is no activity for 6 months.
:peterv, maybe it's time to close this bug?
Comment 33•5 years ago
|
||
bp-dfe24d0d-d7e2-428b-98f9-a75bf0200404 mozilla::URLPreloader::BackgroundReadFiles
crash rate not substantially changed
Comment 34•5 years ago
|
||
The leave-open keyword is there and there is no activity for 6 months.
:peterv, maybe it's time to close this bug?
Comment 36•5 years ago
|
||
The most likely cause if this is still omni jar corruption. We still have a lot of other crashes that suggest that's a common cause of crashes, and we still unfortunately don't have a way to reliably detect it in crash reports.
In any case, if that is the cause, there really isn't anything we can do here but crash (we obviously can't run without the app omnijar), and this isn't really a security issue.
Comment 37•5 years ago
|
||
(In reply to Kris Maglione [:kmag] from comment #36)
The most likely cause if this is still omni jar corruption. We still have a lot of other crashes that suggest that's a common cause of crashes, and we still unfortunately don't have a way to reliably detect it in crash reports.
In any case, if that is the cause, there really isn't anything we can do here but crash (we obviously can't run without the app omnijar), and this isn't really a security issue.
Dan, are you still of the opinion this is sec-moderate?
Comment 38•5 years ago
|
||
The vast majority of crashes (211 in the last week) are startup crashes that moved to the breakpoint at mozilla::URLPreloader::BackgroundReadFiles -- I'm not worried about those particularly.
There are still a handful (6-8) of crashes in nsZipArchive::GetItem() that are non-startup and worry me. You're right that a corrupt omnijar is not a reasonable attack vector, but a corrupt WebExtension served from a website would be. For those we open and read the archive as part of the signature-checking process.
Until yesterday this bug's summary didn't include "Startup Crash in". If you want to clone a new bug about the non-startup crash in nsZipArchive::GetItem and make that one the sec-moderate, then this startup crash in mozilla::URLPreloader::BackgroundReadFiles doesn't need to be a security bug. There is still a potential security problem one way or another.
Comment 39•4 years ago
|
||
The leave-open keyword is there and there is no activity for 6 months.
:peterv, maybe it's time to close this bug?
Comment 40•4 years ago
|
||
This is still happening. Still not clear if it is actionable.
Updated•4 years ago
|
Comment 41•4 years ago
|
||
The leave-open keyword is there and there is no activity for 6 months.
:peterv, maybe it's time to close this bug?
Updated•4 years ago
|
Comment 43•3 years ago
|
||
The startup crash and JAR stuff isn't a use after free, so I think we can unhide this. Maybe there's some occasional crash somewhere with a signature that has some corruption but eh.
Comment 44•3 years ago
|
||
The leave-open keyword is there and there is no activity for 6 months.
:peterv, maybe it's time to close this bug?
For more information, please visit auto_nag documentation.
Updated•3 years ago
|
Updated•3 years ago
|
Comment 45•2 years ago
•
|
||
All non-breakpoint crashes in Preload (except for a few random sigill's on 91esr) are actually MOZ_CRASH_UNSAFE_PRINTF()'s, which appear on mac and linux as nullptrs
Updated•2 years ago
|
Comment 46•2 years ago
|
||
Splitting from GetItem, which seems to be a different crash - no crashes in GetItem have preloader in the stack
Updated•2 years ago
|
Comment 47•2 years ago
|
||
The bug is linked to a topcrash signature, which matches the following criterion:
- Top 20 desktop browser crashes on beta (startup)
For more information, please visit auto_nag documentation.
Comment 48•2 years ago
|
||
Based on the topcrash criteria, the crash signature linked to this bug is not a topcrash signature anymore.
For more information, please visit auto_nag documentation.
Updated•2 years ago
|
Description
•