Closed Bug 1569889 Opened 6 months ago Closed 6 months ago

nsDocShellLoadState(DocShellLoadStateInit&) doesn't set mIsFormSubmission

Categories

(Core :: DOM: Security, defect, P1)

defect

Tracking

()

RESOLVED FIXED
mozilla70
Tracking Status
firefox70 --- fixed

People

(Reporter: peterv, Assigned: beriksson)

References

(Regression)

Details

(Whiteboard: [domsecurity-active])

Attachments

(1 file)

This can cause us to read uninitialized memory.

It might also need to be serialized in nsDocShellLoadState::Serialize.

Flags: needinfo?(beriksson)

Note that this is causing a lot of crashes on ASAN builds on the ash branch: https://treeherder.mozilla.org/#/jobs?repo=ash&revision=b653fb57c4b5db336f508ca46d8e298d8fce7dea&searchStr=asan

Thanks Peter, we'll fix that.

Assignee: nobody → beriksson
Status: NEW → ASSIGNED
Priority: -- → P1
Whiteboard: [domsecurity-active]

Ensure that IsFormSubmission is set in all constructors and can be serialized

Flags: needinfo?(beriksson)

Pushed by nerli@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/2c8875e6dff7
Fix Bug 1569889 by setting mIsFormSubmission in nsDocShellLoadState r=ckerschb

Keywords: checkin-needed
Status: ASSIGNED → RESOLVED
Closed: 6 months ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla70
You need to log in before you can comment on or make changes to this bug.