Permanent comm/mail/test/browser/content-policy/browser_jsContentPolicy.js | JS should be turned on in content. - "undefined" == true | noscript display should be 'none' - "inline" == "none"
Categories
(Thunderbird :: Security, defect, P5)
Tracking
(thunderbird_esr91 fixed, thunderbird98 fixed)
People
(Reporter: intermittent-bug-filer, Assigned: mkmelin)
References
Details
(Keywords: intermittent-failure)
Attachments
(1 file)
48 bytes,
text/x-phabricator-request
|
rjl
:
approval-comm-beta+
wsmwk
:
approval-comm-esr91+
|
Details | Review |
Filed by: geoff [at] darktrojan.net
Parsed log: https://treeherder.mozilla.org/logviewer?job_id=367345716&repo=comm-central
Full log: https://firefox-ci-tc.services.mozilla.com/api/queue/v1/task/Orj9lLrJT3uLBkvrYvNg0Q/runs/0/artifacts/public/logs/live_backing.log
Comment 1•3 years ago
|
||
It's not failing on debug because the content policy tests don't run on debug.
Assignee | ||
Comment 2•3 years ago
•
|
||
Assignee | ||
Comment 3•3 years ago
|
||
Something we need to change around here? https://searchfox.org/comm-central/rev/fd6043fc9c553cd603b9044cbfb9bcc051db040f/mailnews/base/src/nsMsgContentPolicy.cpp#873
Comment 4•3 years ago
|
||
I'm not super familiar with the thunderbird code, so I'll be guessing a bit here. It appears that in bug 1643986 you made thunderbird set sandboxing flags on the BrowsingContext from the nsMsgContentPolicy.cpp
code whenever a message is loaded. This will, in turn, cause all loads in that BrowsingContext to be sandboxed. Before the changes I landed last week, we were incorrectly dropping those sandboxing flags after some types of navigations, so it didn't come up in testing that after the flags were set, they were never cleared.
You probably need to make the else
branch in that function also configure the sandbox flags on the BrowsingContext
to be more relaxed in order to get things working more consistently.
Assignee | ||
Comment 5•3 years ago
|
||
I did try rv = browsingContext->SetSandboxFlags(SANDBOXED_NONE);
in the else. But the test still fails.
Comment 6•3 years ago
|
||
The flags are things to enable, so it should be SANDBOX_ALL_FLAGS
, not SANDBOXED_NONE
. I think. I'll see what the Try server thinks.
Comment hidden (Intermittent Failures Robot) |
Assignee | ||
Comment 9•3 years ago
|
||
Tried also clearing explicitly the SANDBOXED_SCRIPTS, but no changes to the flags take effect.
It's this line causing it - https://hg.mozilla.org/mozilla-central/rev/b3a8f99f0044f5a4c7c44878d67c3de880b68340#l2.15
Would setting the initial sandboxflags (on the next line) be enough?
Comment hidden (Intermittent Failures Robot) |
Assignee | ||
Comment 11•3 years ago
|
||
Before the changes in bug 1754785, sandboxing flags were dropped after some types of navigations => we started off from unsandboxed here.
This patch sets that unsandboxed state explicitely on the browsing context so when the code bails out early (for data: url) the we do not get the sandboxing of what used to be loaded in the context.
Updated•3 years ago
|
Comment 12•3 years ago
|
||
Pushed by mkmelin@iki.fi:
https://hg.mozilla.org/comm-central/rev/e9cce01454a0
fix browser_jsContentPolicy.js after bug 1754785. r=benc
Comment hidden (Intermittent Failures Robot) |
Updated•3 years ago
|
Comment 14•3 years ago
|
||
Comment on attachment 9263732 [details]
Bug 1754672 - fix browser_jsContentPolicy.js after bug 1754785. r=benc
[Triage Comment]
Fix for browser_jsContentPolicy.js failures caused by uplift of bug 1744352 to m-beta. Not sure why bug 1754785 is mentioned; it doesn't seem to affect the outcome of the tests.
Comment 15•3 years ago
|
||
bugherder uplift |
Thunderbird 98.0b3:
https://hg.mozilla.org/releases/comm-beta/rev/ca168ac5a203
Assignee | ||
Comment 16•3 years ago
|
||
The commit comment should have said "after bug 1744352".
Bug 1754785 is also caused by that bug.
Comment 17•3 years ago
|
||
Comment on attachment 9263732 [details]
Bug 1754672 - fix browser_jsContentPolicy.js after bug 1754785. r=benc
[Approval Request Comment]
Per comment 16, bug 1744352 caused this bug. Bug 1744352 was uplifted to m-esr91 necessitating uplift.
Comment 18•3 years ago
|
||
Comment on attachment 9263732 [details]
Bug 1754672 - fix browser_jsContentPolicy.js after bug 1754785. r=benc
[Triage Comment]
approved for esr91
Comment 19•3 years ago
|
||
bugherder uplift |
Thunderbird 91.7.0:
https://hg.mozilla.org/releases/comm-esr91/rev/37ce5243da5f
Description
•