Closed Bug 1886157 Opened 1 year ago Closed 1 year ago

Enable new AOM restrictions on new weak signatures xpi installs on Nightly

Categories

(Toolkit :: Add-ons Manager, task, P2)

task

Tracking

()

VERIFIED FIXED
127 Branch
Tracking Status
firefox127 --- verified

People

(Reporter: rpl, Assigned: willdurand)

References

Details

Attachments

(1 file)

This bugzilla issue is tracking enabling the new AOM restrictions applied on install new xpi files signed only with weak algorithms in nigthly builds.

Group: mozilla-employee-confidential
Depends on: 1890843
Group: mozilla-employee-confidential
Assignee: nobody → wdurand
Status: NEW → ASSIGNED
Pushed by wdurand@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/405f315bce3e Disable xpinstall.signatures.weakSignaturesTemporarilyAllowed by default on Nightly. r=rpl
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 127 Branch

For QA: https://addons.mozilla.org/en-US/firefox/addon/colorzilla/ shouldn't be installable on Nightly between now and April 25.

Flags: qe-verify+

Verified as Fixed. Tested on the latest Nightly (127.0a1/20240423214125) under Windows 10 x64, Ubuntu 22.04 LTS and macOS 11.3.1.

Attempting to install https://addons.mozilla.org/en-US/firefox/addon/colorzilla/ fails, confirming the fix.

addons.xpi WARN Download of https://addons.mozilla.org/firefox/downloads/file/595546/colorzilla-3.3.xpi failed: install rejected due to the package not including a strong cryptographic signature is logged to the browser console and AMO shows a banner stating Installation aborted because the add-on appears to be corrupt.

Status: RESOLVED → VERIFIED
Flags: qe-verify+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: