Re-enable Win32k Lockdown by Default
Categories
(Core :: Security: Process Sandboxing, enhancement, P1)
Tracking
()
People
(Reporter: bobowen, Assigned: bobowen)
References
Details
Attachments
(1 file)
48 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-beta+
diannaS
:
approval-mozilla-release+
|
Details | Review |
This was set to early beta and earlier in bug 1766033 for a staged roll-out.
We now need to flip it back to be on by default.
Assignee | ||
Comment 1•3 years ago
|
||
Updated•3 years ago
|
Assignee | ||
Comment 3•3 years ago
|
||
Comment on attachment 9275252 [details]
Bug 1767999: Re-enable Win32k Lockdown by default. r=gcp!
Beta/Release Uplift Approval Request
- User impact if declined: Win32k lockdown enablement will rely on Normandy roll out instead of just being enabled by default.
- Is this code covered by automated tests?: No
- Has the fix been verified in Nightly?: No
- Needs manual test from QE?: No
- If yes, steps to reproduce:
- List of other uplifts needed: None
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): Simple pref flip.
- String changes made/needed: None
- Is Android affected?: No
Comment 4•3 years ago
|
||
bugherder |
Comment 5•3 years ago
|
||
Release Note Request (optional, but appreciated)
[Why is this notable]: Major improvement to sandbox strength
[Affects Firefox for Android]: No
[Suggested wording]: Firefox's security sandbox now blocks access to the Win32k APIs for Content Processes on Windows.
[Links (documentation, blog post, etc)]: To be announced on Hacks
Comment 6•3 years ago
|
||
Comment on attachment 9275252 [details]
Bug 1767999: Re-enable Win32k Lockdown by default. r=gcp!
Approved for 100.0.1
Comment 7•3 years ago
|
||
bugherder uplift |
Comment 8•3 years ago
|
||
Comment on attachment 9275252 [details]
Bug 1767999: Re-enable Win32k Lockdown by default. r=gcp!
Approved for 101.0b7.
Comment 9•3 years ago
|
||
bugherder uplift |
Updated•3 years ago
|
Updated•3 years ago
|
Comment 10•3 years ago
|
||
Verified as enabled on Fx 100.0.1 and Fx 100.0b7 Windows 10 and Windows 11.
Updated•3 years ago
|
Comment 11•3 years ago
|
||
Verified as enabled with Fx 102.0a1 Windows 11 and Windows 10 x64.
Updated•3 years ago
|
Updated•3 years ago
|
Description
•