Commits:
-
afd58309
by Makoto Kato at 2026-09-14T12:12:31+02:00
Bug 2027336 - Always call forget. a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D322230
Differential Revision: https://phabricator.services.mozilla.com/D322280
-
0497d2bb
by Andreas Farre at 2026-09-14T12:29:41+02:00
Bug 2029482 - Don't make ORB exemptions for DevTools. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D319804
Differential Revision: https://phabricator.services.mozilla.com/D322302
-
532762bf
by Chun-Min Chang at 2026-09-14T16:20:39+02:00
[ESR 153] Bug 2050150 - Require an NV12 destination stride that can hold a chroma row. a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D320550
-
372a6a1a
by David Parks at 2026-09-14T16:20:43+02:00
Bug 2058018 - Check the payload length in DragEnter before using r=win-reviewers,gstoll
Differential Revision: https://phabricator.services.mozilla.com/D318224
-
c14b8231
by Alexandre Poirot at 2026-09-14T16:20:48+02:00
Bug 2062551 - Allow heapsnapshot records when DevTools are active. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D318392
Differential Revision: https://phabricator.services.mozilla.com/D321173
-
732385f9
by Maurice Dauer at 2026-09-14T16:20:52+02:00
Bug 2063539 - Always resolve special target names, a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D318844
Differential Revision: https://phabricator.services.mozilla.com/D319952
-
0e2df94d
by Valentin Gosu at 2026-09-14T16:20:57+02:00
Bug 2063814 - Handle \ correctly in SplitMimetype a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D319097
Differential Revision: https://phabricator.services.mozilla.com/D320017
-
206afe8c
by Valentin Gosu at 2026-09-14T16:21:02+02:00
Bug 2064026 - Check if iterator has reached the end of the string a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D319073
Differential Revision: https://phabricator.services.mozilla.com/D320016
-
05459251
by Dominik Bay at 2026-09-14T16:21:06+02:00
Bug 2066736 - Validate filter array lengths in FilePickerParent::RecvOpen. a=dmeehan
The loop in RecvOpen counts with aFilters.Length() but reads
aFilterNames[i]. If a content process sends the message with more filters
than filterNames, the read goes out of bounds and the parent process
crashes. So I added a check that both arrays have the same length.
Original Revision: https://phabricator.services.mozilla.com/D321511
Differential Revision: https://phabricator.services.mozilla.com/D321697
-
ca2da456
by Sotaro Ikeda at 2026-09-14T16:21:11+02:00
Bug 2068438 a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D323156
Differential Revision: https://phabricator.services.mozilla.com/D323435
13 changed files:
Changes:
devtools/shared/heapsnapshot/HeapSnapshotTempFileHelperParent.cpp
| ... |
... |
@@ -6,6 +6,7 @@ |
|
6
|
6
|
|
|
7
|
7
|
#include "mozilla/devtools/HeapSnapshot.h"
|
|
8
|
8
|
#include "mozilla/devtools/HeapSnapshotTempFileHelperParent.h"
|
|
|
9
|
+#include "mozilla/dom/ChromeUtils.h"
|
|
9
|
10
|
#include "mozilla/ErrorResult.h"
|
|
10
|
11
|
#include "private/pprio.h"
|
|
11
|
12
|
|
| ... |
... |
@@ -23,6 +24,9 @@ static bool openFileFailure(ErrorResult& rv, |
|
23
|
24
|
mozilla::ipc::IPCResult
|
|
24
|
25
|
HeapSnapshotTempFileHelperParent::RecvOpenHeapSnapshotTempFile(
|
|
25
|
26
|
OpenHeapSnapshotTempFileResponse* outResponse) {
|
|
|
27
|
+ if (!dom::ChromeUtils::IsDevToolsOpened()) {
|
|
|
28
|
+ return IPC_FAIL_NO_REASON(this);
|
|
|
29
|
+ }
|
|
26
|
30
|
auto start = TimeStamp::Now();
|
|
27
|
31
|
ErrorResult rv;
|
|
28
|
32
|
nsAutoString filePath;
|
devtools/shared/heapsnapshot/tests/xpcshell/test_saveHeapSnapshot_e10s_01.js
| ... |
... |
@@ -5,5 +5,6 @@ |
|
5
|
5
|
// Test saving a heap snapshot in the sandboxed e10s child process.
|
|
6
|
6
|
|
|
7
|
7
|
function run_test() {
|
|
|
8
|
+ ChromeUtils.notifyDevToolsOpened();
|
|
8
|
9
|
run_test_in_child("test_SaveHeapSnapshot.js");
|
|
9
|
10
|
} |
dom/base/MimeType.cpp
| ... |
... |
@@ -111,8 +111,10 @@ template <typename char_type> |
|
111
|
111
|
++pos;
|
|
112
|
112
|
}
|
|
113
|
113
|
|
|
114
|
|
- // Might as well check for base64 now
|
|
115
|
|
- if (*pos != '=') {
|
|
|
114
|
+ // Might as well check for base64 now. Note that the loop above may have
|
|
|
115
|
+ // stopped because it reached the end of the input, in which case there is
|
|
|
116
|
+ // no code point to look at.
|
|
|
117
|
+ if (pos == end || *pos != '=') {
|
|
116
|
118
|
// trim leading and trailing spaces
|
|
117
|
119
|
while (namePos < pos && NS_IsHTTPWhitespace(*namePos)) {
|
|
118
|
120
|
++namePos;
|
| ... |
... |
@@ -253,7 +255,13 @@ TMimeType<char_type>::SplitMimetype(const nsTSubstring<char_type>& aMimeType) { |
|
253
|
255
|
for (size_t i = 0; i < aMimeType.Length(); i++) {
|
|
254
|
256
|
char_type c = aMimeType[i];
|
|
255
|
257
|
|
|
256
|
|
- if (c == '\"' && (i == 0 || aMimeType[i - 1] != '\\')) {
|
|
|
258
|
+ // https://fetch.spec.whatwg.org/#collect-an-http-quoted-string : a
|
|
|
259
|
+ // backslash only escapes inside a quoted string, and it consumes the code
|
|
|
260
|
+ // point that follows it, so an escaped backslash does not escape the next
|
|
|
261
|
+ // character.
|
|
|
262
|
+ if (inQuotes && c == '\\') {
|
|
|
263
|
+ ++i;
|
|
|
264
|
+ } else if (c == '"') {
|
|
257
|
265
|
inQuotes = !inQuotes;
|
|
258
|
266
|
} else if (c == ',' && !inQuotes) {
|
|
259
|
267
|
mimeTypeParts.AppendElement(Substring(aMimeType, start, i - start));
|
dom/base/nsGlobalWindowOuter.cpp
| ... |
... |
@@ -3842,10 +3842,8 @@ bool nsGlobalWindowOuter::WindowExists(const nsAString& aName, |
|
3842
|
3842
|
bool aLookForCallerOnJSStack) {
|
|
3843
|
3843
|
MOZ_ASSERT(mDocShell, "Must have docshell");
|
|
3844
|
3844
|
|
|
3845
|
|
- if (aForceNoOpener) {
|
|
3846
|
|
- return aName.LowerCaseEqualsLiteral("_self") ||
|
|
3847
|
|
- aName.LowerCaseEqualsLiteral("_top") ||
|
|
3848
|
|
- aName.LowerCaseEqualsLiteral("_parent");
|
|
|
3845
|
+ if (aForceNoOpener && !nsContentUtils::IsSpecialName(aName)) {
|
|
|
3846
|
+ return false;
|
|
3849
|
3847
|
}
|
|
3850
|
3848
|
|
|
3851
|
3849
|
if (WindowGlobalChild* wgc = mInnerWindow->GetWindowGlobalChild()) {
|
dom/ipc/FilePickerParent.cpp
| ... |
... |
@@ -282,6 +282,10 @@ mozilla::ipc::IPCResult FilePickerParent::RecvOpen( |
|
282
|
282
|
return IPC_OK();
|
|
283
|
283
|
}
|
|
284
|
284
|
|
|
|
285
|
+ if (aFilters.Length() != aFilterNames.Length()) {
|
|
|
286
|
+ return IPC_FAIL(this, "PFilePicker::Open filter arrays lengths mismatch");
|
|
|
287
|
+ }
|
|
|
288
|
+
|
|
285
|
289
|
mFilePicker->SetAddToRecentDocs(aAddToRecentDocs);
|
|
286
|
290
|
|
|
287
|
291
|
for (uint32_t i = 0; i < aFilters.Length(); ++i) {
|
dom/media/ImageConversion.cpp
| ... |
... |
@@ -486,6 +486,13 @@ nsresult ConvertToNV12(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY, |
|
486
|
486
|
return NS_ERROR_INVALID_ARG;
|
|
487
|
487
|
}
|
|
488
|
488
|
|
|
|
489
|
+ // An interleaved chroma row is 2 * ceil(width / 2) bytes wide.
|
|
|
490
|
+ if (aDestStrideY < aDestSize.width ||
|
|
|
491
|
+ aDestStrideUV < 2 * CeilingOfHalf(aDestSize.width)) {
|
|
|
492
|
+ NS_WARNING("ConvertToNV12: destination strides too small for NV12");
|
|
|
493
|
+ return NS_ERROR_INVALID_ARG;
|
|
|
494
|
+ }
|
|
|
495
|
+
|
|
489
|
496
|
if (const PlanarYCbCrData* data = GetPlanarYCbCrData(aImage)) {
|
|
490
|
497
|
const ImageUtils imageUtils(aImage);
|
|
491
|
498
|
Maybe<dom::ImageBitmapFormat> format = imageUtils.GetFormat();
|
dom/media/ImageConversion.h
| ... |
... |
@@ -45,6 +45,9 @@ nsresult ConvertToI420(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY, |
|
45
|
45
|
|
|
46
|
46
|
/**
|
|
47
|
47
|
* Converts aImage to an NV12 image and writes it to the given buffers.
|
|
|
48
|
+ *
|
|
|
49
|
+ * aDestStrideUV must be at least 2 * ceil(aDestSize.width / 2), since U and V
|
|
|
50
|
+ * are interleaved. Returns NS_ERROR_INVALID_ARG if either stride is too small.
|
|
48
|
51
|
*/
|
|
49
|
52
|
nsresult ConvertToNV12(layers::Image* aImage, uint8_t* aDestY, int aDestStrideY,
|
|
50
|
53
|
uint8_t* aDestUV, int aDestStrideUV,
|
gfx/layers/ImageContainer.cpp
| ... |
... |
@@ -254,10 +254,8 @@ Maybe<SurfaceDescriptor> Image::GetDescFromTexClient( |
|
254
|
254
|
return {};
|
|
255
|
255
|
}
|
|
256
|
256
|
|
|
257
|
|
- const auto& tcd = tc->GetInternalData();
|
|
258
|
|
-
|
|
259
|
257
|
SurfaceDescriptor ret;
|
|
260
|
|
- if (!tcd->Serialize(ret)) {
|
|
|
258
|
+ if (!tc->ToSurfaceDescriptor(ret)) {
|
|
261
|
259
|
return {};
|
|
262
|
260
|
}
|
|
263
|
261
|
return Some(ret);
|
gfx/layers/client/TextureClient.cpp
| ... |
... |
@@ -558,8 +558,12 @@ void TextureClient::Destroy() { |
|
558
|
558
|
actor = nullptr;
|
|
559
|
559
|
}
|
|
560
|
560
|
|
|
561
|
|
- TextureData* data = mData;
|
|
562
|
|
- mData = nullptr;
|
|
|
561
|
+ TextureData* data;
|
|
|
562
|
+ {
|
|
|
563
|
+ MutexAutoLock lock(mMutex);
|
|
|
564
|
+ data = mData;
|
|
|
565
|
+ mData = nullptr;
|
|
|
566
|
+ }
|
|
563
|
567
|
|
|
564
|
568
|
if (data || actor || readLock) {
|
|
565
|
569
|
TextureDeallocParams params;
|
| ... |
... |
@@ -1050,8 +1054,7 @@ bool TextureClient::BorrowMappedYCbCrData(MappedYCbCrTextureData& aMap) { |
|
1050
|
1054
|
}
|
|
1051
|
1055
|
|
|
1052
|
1056
|
bool TextureClient::ToSurfaceDescriptor(SurfaceDescriptor& aOutDescriptor) {
|
|
1053
|
|
- MOZ_ASSERT(IsValid());
|
|
1054
|
|
-
|
|
|
1057
|
+ MutexAutoLock lock(mMutex);
|
|
1055
|
1058
|
return mData ? mData->Serialize(aOutDescriptor) : false;
|
|
1056
|
1059
|
}
|
|
1057
|
1060
|
|
gfx/layers/client/TextureClient.h
| ... |
... |
@@ -621,6 +621,13 @@ class TextureClient : public AtomicRefCountedWithFinalize<TextureClient> { |
|
621
|
621
|
TextureData* GetInternalData() { return mData; }
|
|
622
|
622
|
const TextureData* GetInternalData() const { return mData; }
|
|
623
|
623
|
|
|
|
624
|
+ /**
|
|
|
625
|
+ * Serializes the underlying TextureData into aDescriptor. Returns false if
|
|
|
626
|
+ * the TextureData has already been destroyed. Safe to call from any thread
|
|
|
627
|
+ * concurrently with Destroy().
|
|
|
628
|
+ */
|
|
|
629
|
+ bool ToSurfaceDescriptor(SurfaceDescriptor& aDescriptor);
|
|
|
630
|
+
|
|
624
|
631
|
uint64_t GetSerial() const { return mSerial; }
|
|
625
|
632
|
void GetSurfaceDescriptorRemoteDecoder(
|
|
626
|
633
|
SurfaceDescriptorRemoteDecoder* aOutDesc);
|
| ... |
... |
@@ -719,16 +726,6 @@ class TextureClient : public AtomicRefCountedWithFinalize<TextureClient> { |
|
719
|
726
|
friend class AtomicRefCountedWithFinalize<TextureClient>;
|
|
720
|
727
|
|
|
721
|
728
|
protected:
|
|
722
|
|
- /**
|
|
723
|
|
- * Should only be called *once* per texture, in TextureClient::InitIPDLActor.
|
|
724
|
|
- * Some texture implementations rely on the fact that the descriptor will be
|
|
725
|
|
- * deserialized.
|
|
726
|
|
- * Calling ToSurfaceDescriptor again after it has already returned true,
|
|
727
|
|
- * or never constructing a TextureHost with aDescriptor may result in a memory
|
|
728
|
|
- * leak (see TextureClientD3D9 for example).
|
|
729
|
|
- */
|
|
730
|
|
- bool ToSurfaceDescriptor(SurfaceDescriptor& aDescriptor);
|
|
731
|
|
-
|
|
732
|
729
|
void LockActor() const;
|
|
733
|
730
|
void UnlockActor() const;
|
|
734
|
731
|
|
intl/components/src/RelativeTimeFormat.cpp
| ... |
... |
@@ -57,13 +57,13 @@ RelativeTimeFormat::TryCreate(const char* aLocale, |
|
57
|
57
|
ureldatefmt_open(IcuLocale(aLocale), nf, relDateTimeStyle,
|
|
58
|
58
|
UDISPCTX_CAPITALIZATION_FOR_STANDALONE, &status);
|
|
59
|
59
|
|
|
|
60
|
+ // Ownership was transferred to mFormatter.
|
|
|
61
|
+ closeNumberFormatter.forget();
|
|
|
62
|
+
|
|
60
|
63
|
if (U_FAILURE(status)) {
|
|
61
|
64
|
return Err(ToICUError(status));
|
|
62
|
65
|
}
|
|
63
|
66
|
|
|
64
|
|
- // Ownership was transferred to mFormatter.
|
|
65
|
|
- closeNumberFormatter.forget();
|
|
66
|
|
-
|
|
67
|
67
|
UniquePtr<RelativeTimeFormat> rtf = MakeUnique<RelativeTimeFormat>(
|
|
68
|
68
|
aOptions.numeric, formatter, formattedRelativeDateTime);
|
|
69
|
69
|
|
netwerk/protocol/http/HttpBaseChannel.cpp
| ... |
... |
@@ -3316,13 +3316,6 @@ bool HttpBaseChannel::ShouldBlockOpaqueResponse() const { |
|
3316
|
3316
|
return false;
|
|
3317
|
3317
|
}
|
|
3318
|
3318
|
|
|
3319
|
|
- bool isInDevToolsContext;
|
|
3320
|
|
- mLoadInfo->GetIsInDevToolsContext(&isInDevToolsContext);
|
|
3321
|
|
- if (isInDevToolsContext) {
|
|
3322
|
|
- LOGORB("No block: Request created by devtools");
|
|
3323
|
|
- return false;
|
|
3324
|
|
- }
|
|
3325
|
|
-
|
|
3326
|
3319
|
return true;
|
|
3327
|
3320
|
}
|
|
3328
|
3321
|
|
widget/windows/nsNativeDragTarget.cpp
| ... |
... |
@@ -258,13 +258,13 @@ nsNativeDragTarget::DragEnter(LPDATAOBJECT pIDataSource, DWORD grfKeyState, |
|
258
|
258
|
nsresult loadResult = nsClipboard::GetNativeDataOffClipboard(
|
|
259
|
259
|
pIDataSource, 0, ::RegisterClipboardFormat(CFSTR_PREFERREDDROPEFFECT),
|
|
260
|
260
|
nullptr, &tempOutData, &tempDataLen);
|
|
261
|
|
- if (NS_SUCCEEDED(loadResult) && tempOutData) {
|
|
|
261
|
+ if (NS_SUCCEEDED(loadResult) && tempOutData && tempDataLen >= sizeof(DWORD)) {
|
|
262
|
262
|
mEffectsPreferred = *((DWORD*)tempOutData);
|
|
263
|
|
- free(tempOutData);
|
|
264
|
263
|
} else {
|
|
265
|
264
|
// We have no preference if we can't obtain it
|
|
266
|
265
|
mEffectsPreferred = DROPEFFECT_NONE;
|
|
267
|
266
|
}
|
|
|
267
|
+ free(tempOutData);
|
|
268
|
268
|
|
|
269
|
269
|
// Set the native data object into drag session
|
|
270
|
270
|
session->SetIDataObject(pIDataSource);
|
|