Bug 519340 contains an investigation into a topcrash seen with Firefox 3.5. Older versions of the "AVG Safe Search" extension were found to be the cause. We want to blocklist the older versions because it causes Firefox instability.
AVG issues periodic updates to their product automatically, but up until now the Firefox extension's version has remained fixed at "8.5". At the beginning of this week, AVG began pushing an update which included a bump of the extension version number to "188.8.131.523". Future minor updates will also be bumping the version number. So, now have the option to blocklist version "8.5" without impacting users who have upgraded to "8.5.0.*" (which is not causing stability issues).
Bug 457970 contains an older topcrash issue involving AVG 8.0, which should also be resolved by this blocklist addition.
Users who encounter this blocklist are advised to upgrade their AVG installation to the current version, which will re-enable the Safe Search extension.
Note that this blocklist addition will ONLY disable the "AVG Safe Search" extension. The rest of the AVG product is unaffected, and virus scanning on the system will remain unchanged. Firefox's built-in malware / anti-phishing protection provides a similar capability to Safe Search, so users unable to upgrade AVG (for whatever reason) have the option to make sure these Firefox features are active to remain secure.
Also, I should note that we've discussed this plan and timing with AVG, such as to minimize the impact on users.
Update: the newly-released version is actually "184.108.40.2063", and was released yesterday. So, we should want some more for sufficient update before blocklisting.
"220.127.116.114", rather. .423 was the info we had from earlier in the week.
And we should *wait* some more. I clearly can't type today. :(
Ok, AVG update has had time to roll out to users, so let's proceed with blocklisting.
I think morgamic handles the actual addition to the blocklist, so over to him.
For add-ons we need the guid. Justin is pulling that.
We want to blocklist versions equal to or less than 18.104.22.1684 ?
Need to blocklist 8.5 and less.
Yeah, just the plain "8.5" and below, the newer update has a more detailed version number (eg "22.214.171.1244") and is ok.
Also, I verified that my old AVG installer gave me the addon with that GUID, version "8.5"... Updating AVG refreshed the addon; same GUID, now version "126.96.36.1994".
Created attachment 414122 [details]
v1, adding 8.5
Resulting blocklist after changing 8.0 -> 8.5.
Comment on attachment 414122 [details]
v1, adding 8.5
Looks good, I verified that it does not block an up-to-date AVG Safe Search extension, and that the old one is blocked. [Also had the AVG Security Toolbar installed, which didn't seem to have any obvious problems with the other addon being disabled.]
One small change: so that we can close out bug 457970, please drop the targetApplication minVersion to 3.0. There are still a few of those crashes affecting FF3.0 users.
This is going out today. Will resolve when pushed.
This is updated in prod:
Does https://www.mozilla.com/en-US/blocklist/ need updated? It still only mentions AVG 8.0.
Yeah, edited that already on trunk. Should be out shortly on prod.
Please don't mess with the bug flags.