Closed Bug 1952926 Opened 15 days ago Closed 14 days ago

Enable MITIGATION_WIN32K_DISABLE and MITIGATION_DYNAMIC_CODE_DISABLE flags for compatible GMP processes for release.

Categories

(Core :: Security: Process Sandboxing, enhancement, P1)

enhancement

Tracking

()

RESOLVED FIXED
138 Branch
Tracking Status
firefox137 --- fixed
firefox138 --- fixed

People

(Reporter: bobowen, Assigned: bobowen)

References

Details

Attachments

(2 files)

In bug 1950112 these two mitigations were enabled for compatible GMPs, this is to enable for other branches and uplift.

Summary: Enable MITIGATION_WIN32K_DISABLE and MITIGATION_DYNAMIC_CODE_DISABLE flags for compatible GMP process for release. → Enable MITIGATION_WIN32K_DISABLE and MITIGATION_DYNAMIC_CODE_DISABLE flags for compatible GMP processes for release.
Pushed by bobowencode@gmail.com: https://hg.mozilla.org/integration/autoland/rev/47ecf5b4ba03 Enable win32k lockdown and ACG for compatible GMP processes for release. r=gcp
Status: ASSIGNED → RESOLVED
Closed: 14 days ago
Resolution: --- → FIXED
Target Milestone: --- → 138 Branch
Attachment #9470983 - Flags: approval-mozilla-beta?

beta Uplift Approval Request

  • User impact if declined: They won't get the process sandbox improvements for some GMP types.
  • Code covered by automated testing: yes
  • Fix verified in Nightly: yes
  • Needs manual QE test: no
  • Steps to reproduce for manual QE testing: n/a
  • Risk associated with taking this patch: Low
  • Explanation of risk level: openh264 doesn't have automated tests, but has been manually in Nightly with improved sandbox.
  • String changes made/needed: None
  • Is Android affected?: no
Attachment #9470983 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: