Closed
Bug 1966621
Opened 1 year ago
Closed 1 year ago
Use nsContentPolicyType in IPCInternalRequest IPDL
Categories
(Core :: DOM: Networking, task, P2)
Core
DOM: Networking
Tracking
()
RESOLVED
FIXED
140 Branch
People
(Reporter: tschuster, Assigned: tschuster)
References
Details
(Keywords: csectype-undefined, sec-audit, Whiteboard: [necko-triaged][adv-main140-])
Attachments
(1 file)
No description provided.
| Assignee | ||
Comment 1•1 year ago
|
||
Updated•1 year ago
|
Assignee: nobody → tschuster
Status: NEW → ASSIGNED
| Assignee | ||
Updated•1 year ago
|
Keywords: csectype-undefined
| Assignee | ||
Comment 2•1 year ago
|
||
There is a question about how to rate this. Casting an out of range enum value is undefined behavior, so it's impossible to say what the compiler does. bug 1902621 is similar and was rated sec-audit as well. Assuming the compiler doesn't decide to blow up the world, the most likely outcome is a skipped CSP check. I think that shouldn't be too concerning. By faking e.g. nsIContentPolicy::TYPE_CSP_REPORT, which is not handled by CSP, it's always possible to skip CSP completely.
Updated•1 year ago
|
Group: dom-core-security → network-core-security
Updated•1 year ago
|
Keywords: sec-moderate
Comment 3•1 year ago
|
||
Thanks, Tom. I guess I can leave this as audit for consistency but I don't really agree in general with having undefined behavior marked as sec-audit, but I'm not invested enough to figure out why the other bug was marked like that.
Keywords: sec-moderate → sec-audit
Pushed by tschuster@mozilla.com:
https://hg.mozilla.org/integration/autoland/rev/e4e1602504ff
Use nsContentPolicyType in IPCInternalRequest IPDL. r=necko-reviewers,valentin
Comment 5•1 year ago
|
||
Group: network-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
status-firefox140:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → 140 Branch
Updated•1 year ago
|
status-firefox138:
--- → wontfix
status-firefox139:
--- → wontfix
status-firefox-esr115:
--- → wontfix
status-firefox-esr128:
--- → wontfix
tracking-firefox140:
--- → +
Updated•1 year ago
|
QA Whiteboard: [sec] [qa-triage-done-c141/b140]
Flags: qe-verify-
Updated•1 year ago
|
Whiteboard: [necko-triaged] → [necko-triaged][adv-main140-]
Updated•9 months ago
|
Group: core-security-release
You need to log in
before you can comment on or make changes to this bug.
Description
•