Version in base suite: 140.12.0esr-1~deb13u1
Version in overlay suite: 140.13.0esr-1~deb13u1
Base version: firefox-esr_140.13.0esr-1~deb13u1
Target version: firefox-esr_140.15.0esr-1~deb13u1
Base file: /srv/ftp-master.debian.org/ftp/pool/main/f/firefox-esr/firefox-esr_140.13.0esr-1~deb13u1.dsc
Target file: /srv/ftp-master.debian.org/policy/pool/main/f/firefox-esr/firefox-esr_140.15.0esr-1~deb13u1.dsc
/srv/release.debian.org/tmp/3owaAOKck2/firefox-esr-140.15.0esr/services/settings/dumps/blocklists/addons-bloomfilters/addons-mlbf.bin |binary
/srv/release.debian.org/tmp/3owaAOKck2/firefox-esr-140.15.0esr/services/settings/dumps/blocklists/addons-bloomfilters/softblocks-addons-mlbf.bin |binary
firefox-esr-140.15.0esr/.lando.ini | 8
firefox-esr-140.15.0esr/CLOBBER | 2
firefox-esr-140.15.0esr/accessible/ipc/DocAccessibleParent.cpp | 2
firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/SharedSection.cpp | 20
firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/moz.build | 1
firefox-esr-140.15.0esr/browser/app/winlauncher/test/TestCrossProcessWin.cpp | 13
firefox-esr-140.15.0esr/browser/app/winlauncher/test/moz.build | 1
firefox-esr-140.15.0esr/browser/base/content/nsContextMenu.sys.mjs | 21
firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser.toml | 3
firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser_contextmenu_blocked_image_protocols.js | 63
firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/file_blocked_image_protocols.html | 9
firefox-esr-140.15.0esr/browser/base/content/test/siteIdentity/browser_secure_transport_insecure_scheme.js | 2
firefox-esr-140.15.0esr/browser/base/content/test/static/browser_all_files_referenced.js | 5
firefox-esr-140.15.0esr/browser/base/content/test/static/browser_parsable_css.js | 8
firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_experimentsAPILoader.js | 2
firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_targeting.js | 1
firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_trigger_messagesLoaded.js | 2
firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/head.js | 6
firefox-esr-140.15.0esr/browser/components/preferences/tests/head.js | 4
firefox-esr-140.15.0esr/browser/components/shell/nsWindowsShellService.cpp | 18
firefox-esr-140.15.0esr/browser/components/tabbrowser/test/browser/tabs/browser_new_tab_in_privilegedabout_process_pref.js | 7
firefox-esr-140.15.0esr/browser/config/version.txt | 2
firefox-esr-140.15.0esr/browser/config/version_display.txt | 2
firefox-esr-140.15.0esr/browser/extensions/webcompat/injections/js/bug1831007-nintendo-window-OnetrustActiveGroups.js | 4
firefox-esr-140.15.0esr/browser/extensions/webcompat/manifest.json | 2
firefox-esr-140.15.0esr/browser/modules/WindowsJumpLists.sys.mjs | 8
firefox-esr-140.15.0esr/config/milestone.txt | 2
firefox-esr-140.15.0esr/debian/changelog | 38
firefox-esr-140.15.0esr/debian/patches/debian-hacks/Set-DPI-to-system-settings.patch | 4
firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch | 77
firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch | 27
firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch | 43
firefox-esr-140.15.0esr/debian/patches/fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch | 21
firefox-esr-140.15.0esr/debian/patches/fixes/Fix-conficting-types-for-once_flag-and-call_once.patch | 56
firefox-esr-140.15.0esr/debian/patches/series | 5
firefox-esr-140.15.0esr/docshell/base/BrowsingContext.cpp | 11
firefox-esr-140.15.0esr/docshell/base/nsDocShell.cpp | 52
firefox-esr-140.15.0esr/docshell/base/nsDocShellLoadState.cpp | 122
firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.cpp | 11
firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.h | 4
firefox-esr-140.15.0esr/dom/base/Document.cpp | 11
firefox-esr-140.15.0esr/dom/base/nsContentUtils.cpp | 60
firefox-esr-140.15.0esr/dom/base/nsContentUtils.h | 7
firefox-esr-140.15.0esr/dom/base/nsFocusManager.cpp | 5
firefox-esr-140.15.0esr/dom/base/nsFrameLoader.cpp | 6
firefox-esr-140.15.0esr/dom/base/nsObjectLoadingContent.cpp | 11
firefox-esr-140.15.0esr/dom/broadcastchannel/BroadcastChannel.cpp | 16
firefox-esr-140.15.0esr/dom/cache/CacheStorage.cpp | 8
firefox-esr-140.15.0esr/dom/cache/DBSchema.cpp | 122
firefox-esr-140.15.0esr/dom/cache/PrincipalVerifier.cpp | 7
firefox-esr-140.15.0esr/dom/cache/TypeUtils.cpp | 3
firefox-esr-140.15.0esr/dom/cache/test/mochitest/test_chrome_constructor.html | 9
firefox-esr-140.15.0esr/dom/canvas/TexUnpackBlob.cpp | 12
firefox-esr-140.15.0esr/dom/canvas/WebGLBuffer.cpp | 21
firefox-esr-140.15.0esr/dom/canvas/WebGLContext.cpp | 18
firefox-esr-140.15.0esr/dom/canvas/WebGLContext.h | 2
firefox-esr-140.15.0esr/dom/canvas/WebGLContextDraw.cpp | 8
firefox-esr-140.15.0esr/dom/canvas/WebGLFramebuffer.cpp | 6
firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.cpp | 12
firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.h | 88
firefox-esr-140.15.0esr/dom/canvas/WebGLTransformFeedback.cpp | 9
firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/generated-mochitest.toml | 1
firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/mochitest-errata.toml | 19
firefox-esr-140.15.0esr/dom/chrome-webidl/WindowsJumpListShortcutDescription.webidl | 2
firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerParent.cpp | 11
firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.cpp | 4
firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.h | 3
firefox-esr-140.15.0esr/dom/clients/manager/ClientNavigateOpChild.cpp | 10
firefox-esr-140.15.0esr/dom/clients/manager/ClientSource.cpp | 4
firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.cpp | 9
firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.h | 13
firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.cpp | 22
firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.h | 3
firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreNotifier.cpp | 5
firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreParent.cpp | 25
firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreSubscriptionService.cpp | 17
firefox-esr-140.15.0esr/dom/events/EventStateManager.cpp | 11
firefox-esr-140.15.0esr/dom/events/IMEStateManager.cpp | 42
firefox-esr-140.15.0esr/dom/filesystem/FileSystemSecurity.cpp | 5
firefox-esr-140.15.0esr/dom/fs/child/FileSystemBackgroundRequestHandler.cpp | 13
firefox-esr-140.15.0esr/dom/gamepad/linux/LinuxGamepad.cpp | 20
firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.cpp | 30
firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.h | 6
firefox-esr-140.15.0esr/dom/html/HTMLOptionElement.h | 10
firefox-esr-140.15.0esr/dom/html/HTMLSelectElement.cpp | 7
firefox-esr-140.15.0esr/dom/html/nsGenericHTMLElement.cpp | 3
firefox-esr-140.15.0esr/dom/html/test/browser.toml | 3
firefox-esr-140.15.0esr/dom/html/test/browser_input_file_untrusted_drop.js | 174
firefox-esr-140.15.0esr/dom/html/test/file_input_file_untrusted_drop.html | 77
firefox-esr-140.15.0esr/dom/indexedDB/ActorsParent.cpp | 25
firefox-esr-140.15.0esr/dom/indexedDB/IDBFactory.cpp | 16
firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.cpp | 10
firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.h | 3
firefox-esr-140.15.0esr/dom/indexedDB/test/test_message_manager_ipc.html | 4
firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-head-child-process.js | 3
firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-parent-process.toml | 1
firefox-esr-140.15.0esr/dom/ipc/BrowserParent.cpp | 61
firefox-esr-140.15.0esr/dom/ipc/ContentChild.cpp | 30
firefox-esr-140.15.0esr/dom/ipc/ContentChild.h | 3
firefox-esr-140.15.0esr/dom/ipc/ContentParent.cpp | 27
firefox-esr-140.15.0esr/dom/ipc/ContentParent.h | 2
firefox-esr-140.15.0esr/dom/ipc/PContent.ipdl | 4
firefox-esr-140.15.0esr/dom/ipc/ProcessIsolation.cpp | 110
firefox-esr-140.15.0esr/dom/ipc/WindowGlobalParent.cpp | 38
firefox-esr-140.15.0esr/dom/ipc/gtest/ProcessIsolationTest.cpp | 109
firefox-esr-140.15.0esr/dom/localstorage/ActorsParent.cpp | 199
firefox-esr-140.15.0esr/dom/media/AudioPacketizer.h | 60
firefox-esr-140.15.0esr/dom/media/AudioSegment.cpp | 51
firefox-esr-140.15.0esr/dom/media/AudioSegment.h | 14
firefox-esr-140.15.0esr/dom/media/GraphDriver.cpp | 43
firefox-esr-140.15.0esr/dom/media/GraphDriver.h | 8
firefox-esr-140.15.0esr/dom/media/ImageConversion.cpp | 27
firefox-esr-140.15.0esr/dom/media/ImageConversion.h | 10
firefox-esr-140.15.0esr/dom/media/MediaData.cpp | 8
firefox-esr-140.15.0esr/dom/media/MediaInfo.h | 10
firefox-esr-140.15.0esr/dom/media/MediaTrackGraph.cpp | 8
firefox-esr-140.15.0esr/dom/media/TimedPacketizer.h | 4
firefox-esr-140.15.0esr/dom/media/gmp/GMPChild.cpp | 6
firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.cpp | 66
firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.h | 12
firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoDecoderChild.cpp | 2
firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoEncoderChild.cpp | 2
firefox-esr-140.15.0esr/dom/media/gtest/TestAudioPacketizer.cpp | 16
firefox-esr-140.15.0esr/dom/media/ipc/MFCDMChild.cpp | 4
firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.cpp | 18
firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.h | 4
firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineParent.cpp | 25
firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineParent.h | 6
firefox-esr-140.15.0esr/dom/media/ipc/RemoteDecoderParent.cpp | 6
firefox-esr-140.15.0esr/dom/media/ipc/RemoteDecoderParent.h | 1
firefox-esr-140.15.0esr/dom/media/mediasink/AudioDecoderInputTrack.cpp | 10
firefox-esr-140.15.0esr/dom/media/platforms/apple/AppleVTDecoder.cpp | 18
firefox-esr-140.15.0esr/dom/media/platforms/apple/AppleVTEncoder.cpp | 148
firefox-esr-140.15.0esr/dom/media/platforms/ffmpeg/FFmpegAudioEncoder.cpp | 6
firefox-esr-140.15.0esr/dom/media/platforms/wmf/MFCDMProxy.cpp | 13
firefox-esr-140.15.0esr/dom/media/platforms/wmf/MFCDMProxy.h | 12
firefox-esr-140.15.0esr/dom/media/platforms/wmf/MFMediaEngineStream.cpp | 45
firefox-esr-140.15.0esr/dom/media/platforms/wmf/MFMediaEngineStream.h | 12
firefox-esr-140.15.0esr/dom/media/platforms/wmf/WMFVideoMFTManager.cpp | 18
firefox-esr-140.15.0esr/dom/media/platforms/wrappers/MediaChangeMonitor.cpp | 7
firefox-esr-140.15.0esr/dom/media/webm/WebMDemuxer.cpp | 26
firefox-esr-140.15.0esr/dom/media/webrtc/MediaEngineWebRTCAudio.cpp | 7
firefox-esr-140.15.0esr/dom/media/webrtc/transportbridge/MediaPipeline.cpp | 5
firefox-esr-140.15.0esr/dom/push/PushManager.cpp | 17
firefox-esr-140.15.0esr/dom/push/test/mochitest.toml | 7
firefox-esr-140.15.0esr/dom/quota/ActorsParent.cpp | 6
firefox-esr-140.15.0esr/dom/quota/PrincipalUtils.cpp | 4
firefox-esr-140.15.0esr/dom/quota/RemoteQuotaObjectParent.cpp | 5
firefox-esr-140.15.0esr/dom/quota/StorageManager.cpp | 6
firefox-esr-140.15.0esr/dom/quota/test/xpcshell/test_estimateOrigin.js | 17
firefox-esr-140.15.0esr/dom/security/nsContentSecurityManager.cpp | 29
firefox-esr-140.15.0esr/dom/security/nsContentSecurityUtils.cpp | 1
firefox-esr-140.15.0esr/dom/security/test/crashtests/1583044.html | 11
firefox-esr-140.15.0esr/dom/security/test/crashtests/crashtests.list | 1
firefox-esr-140.15.0esr/dom/security/test/general/chrome.toml | 3
firefox-esr-140.15.0esr/dom/security/test/general/test_image_protocol_document_context.html | 78
firefox-esr-140.15.0esr/dom/serviceworkers/ServiceWorkerPrivate.cpp | 36
firefox-esr-140.15.0esr/dom/simpledb/SDBConnection.cpp | 6
firefox-esr-140.15.0esr/dom/storage/LocalStorageManager.cpp | 7
firefox-esr-140.15.0esr/dom/storage/StorageActivityService.cpp | 5
firefox-esr-140.15.0esr/dom/storage/components.conf | 1
firefox-esr-140.15.0esr/dom/svg/DOMSVGLengthList.cpp | 22
firefox-esr-140.15.0esr/dom/svg/DOMSVGLengthList.h | 10
firefox-esr-140.15.0esr/dom/svg/DOMSVGNumber.cpp | 17
firefox-esr-140.15.0esr/dom/svg/DOMSVGNumber.h | 16
firefox-esr-140.15.0esr/dom/svg/DOMSVGNumberList.cpp | 22
firefox-esr-140.15.0esr/dom/svg/DOMSVGNumberList.h | 10
firefox-esr-140.15.0esr/dom/svg/DOMSVGPointList.cpp | 22
firefox-esr-140.15.0esr/dom/svg/DOMSVGPointList.h | 12
firefox-esr-140.15.0esr/dom/svg/DOMSVGTransform.cpp | 18
firefox-esr-140.15.0esr/dom/svg/DOMSVGTransform.h | 7
firefox-esr-140.15.0esr/dom/svg/DOMSVGTransformList.cpp | 22
firefox-esr-140.15.0esr/dom/svg/DOMSVGTransformList.h | 7
firefox-esr-140.15.0esr/dom/webbrowserpersist/PWebBrowserPersistDocument.ipdl | 6
firefox-esr-140.15.0esr/dom/webbrowserpersist/WebBrowserPersistDocumentChild.cpp | 10
firefox-esr-140.15.0esr/dom/webbrowserpersist/WebBrowserPersistDocumentParent.cpp | 17
firefox-esr-140.15.0esr/dom/webbrowserpersist/WebBrowserPersistDocumentParent.h | 6
firefox-esr-140.15.0esr/dom/webbrowserpersist/WebBrowserPersistRemoteDocument.cpp | 16
firefox-esr-140.15.0esr/dom/webbrowserpersist/WebBrowserPersistRemoteDocument.h | 4
firefox-esr-140.15.0esr/dom/workers/RuntimeService.cpp | 133
firefox-esr-140.15.0esr/dom/workers/RuntimeService.h | 11
firefox-esr-140.15.0esr/dom/workers/WorkerPrivate.cpp | 2
firefox-esr-140.15.0esr/dom/workers/WorkerPrivate.h | 5
firefox-esr-140.15.0esr/dom/workers/sharedworkers/SharedWorker.cpp | 10
firefox-esr-140.15.0esr/dom/workers/sharedworkers/SharedWorkerService.cpp | 85
firefox-esr-140.15.0esr/dom/workers/sharedworkers/SharedWorkerService.h | 4
firefox-esr-140.15.0esr/dom/workers/test/browser.toml | 6
firefox-esr-140.15.0esr/dom/workers/test/browser_privilegedmozilla_remoteworker.js | 116
firefox-esr-140.15.0esr/dom/workers/test/browser_serviceworker_fetch_new_process.js | 43
firefox-esr-140.15.0esr/dom/workers/test/file_service_worker.js | 3
firefox-esr-140.15.0esr/dom/workers/test/file_service_worker_container.html | 15
firefox-esr-140.15.0esr/dom/xml/nsXMLContentSink.cpp | 9
firefox-esr-140.15.0esr/dom/xml/nsXMLContentSink.h | 1
firefox-esr-140.15.0esr/dom/xslt/tests/mochitest/test_bug1769155.html | 2
firefox-esr-140.15.0esr/editor/libeditor/EditorBase.cpp | 2
firefox-esr-140.15.0esr/editor/libeditor/HTMLEditor.cpp | 2
firefox-esr-140.15.0esr/editor/libeditor/HTMLEditorDataTransfer.cpp | 8
firefox-esr-140.15.0esr/editor/libeditor/HTMLEditorDeleteHandler.cpp | 2
firefox-esr-140.15.0esr/editor/libeditor/HTMLTableEditor.cpp | 2
firefox-esr-140.15.0esr/extensions/auth/nsAuthSSPI.cpp | 291
firefox-esr-140.15.0esr/extensions/auth/nsAuthSSPI.h | 6
firefox-esr-140.15.0esr/extensions/auth/nsHttpNegotiateAuth.cpp | 111
firefox-esr-140.15.0esr/gfx/2d/DataSurfaceHelpers.cpp | 7
firefox-esr-140.15.0esr/gfx/2d/DrawTargetCairo.cpp | 3
firefox-esr-140.15.0esr/gfx/2d/DrawTargetSkia.cpp | 1
firefox-esr-140.15.0esr/gfx/2d/Factory.cpp | 18
firefox-esr-140.15.0esr/gfx/2d/NativeFontResourceGDI.cpp | 52
firefox-esr-140.15.0esr/gfx/2d/NativeFontResourceGDI.h | 51
firefox-esr-140.15.0esr/gfx/2d/RecordedEventImpl.h | 5
firefox-esr-140.15.0esr/gfx/2d/ScaledFontWin.cpp | 121
firefox-esr-140.15.0esr/gfx/2d/ScaledFontWin.h | 46
firefox-esr-140.15.0esr/gfx/2d/Types.h | 1
firefox-esr-140.15.0esr/gfx/2d/UnscaledFontGDI.h | 46
firefox-esr-140.15.0esr/gfx/2d/moz.build | 3
firefox-esr-140.15.0esr/gfx/cairo/cairo/src/cairo-cff-subset.c | 35
firefox-esr-140.15.0esr/gfx/cairo/cairo/src/cairo-truetype-subset.c | 6
firefox-esr-140.15.0esr/gfx/cairo/cairo/src/cairo-type1-subset.c | 24
firefox-esr-140.15.0esr/gfx/cairo/cairo/src/win32/cairo-win32-printing-surface.c | 42
firefox-esr-140.15.0esr/gfx/cairo/patches/0042-win32-printing-linear-pattern.patch | 87
firefox-esr-140.15.0esr/gfx/cairo/patches/0044-Bug-2053599-glyph-index-bounds.patch | 60
firefox-esr-140.15.0esr/gfx/cairo/patches/0047-Bug-2050228-win32-print-tiny-dash.patch | 21
firefox-esr-140.15.0esr/gfx/cairo/patches/0047-Bug-2054626-type2-decode-integer.patch | 86
firefox-esr-140.15.0esr/gfx/cairo/patches/0048-Bug-2054627-skip-token-check.patch | 101
firefox-esr-140.15.0esr/gfx/gl/GLBlitHelper.cpp | 5
firefox-esr-140.15.0esr/gfx/gl/SharedSurfaceD3D11Interop.cpp | 22
firefox-esr-140.15.0esr/gfx/layers/GPUVideoImage.h | 13
firefox-esr-140.15.0esr/gfx/layers/ImageContainer.cpp | 7
firefox-esr-140.15.0esr/gfx/layers/d3d11/TextureD3D11.cpp | 7
firefox-esr-140.15.0esr/gfx/layers/ipc/CanvasChild.cpp | 9
firefox-esr-140.15.0esr/gfx/layers/ipc/SharedRGBImage.cpp | 23
firefox-esr-140.15.0esr/gfx/layers/ipc/SharedRGBImage.h | 3
firefox-esr-140.15.0esr/gfx/layers/wr/AsyncImagePipelineManager.cpp | 10
firefox-esr-140.15.0esr/gfx/layers/wr/WebRenderBridgeParent.cpp | 27
firefox-esr-140.15.0esr/gfx/layers/wr/WebRenderBridgeParent.h | 9
firefox-esr-140.15.0esr/gfx/metrics.yaml | 17
firefox-esr-140.15.0esr/gfx/skia/skia/src/core/SkBlitBWMaskTemplate.h | 2
firefox-esr-140.15.0esr/gfx/skia/skia/src/ports/SkFontHost_cairo.cpp | 11
firefox-esr-140.15.0esr/gfx/thebes/CoreTextFontList.cpp | 7
firefox-esr-140.15.0esr/gfx/thebes/gfxDWriteFontList.cpp | 9
firefox-esr-140.15.0esr/gfx/thebes/gfxDWriteFonts.cpp | 38
firefox-esr-140.15.0esr/gfx/thebes/gfxDWriteFonts.h | 8
firefox-esr-140.15.0esr/gfx/thebes/gfxFT2FontList.cpp | 7
firefox-esr-140.15.0esr/gfx/thebes/gfxFont.cpp | 17
firefox-esr-140.15.0esr/gfx/thebes/gfxFont.h | 64
firefox-esr-140.15.0esr/gfx/thebes/gfxFontUtils.cpp | 6
firefox-esr-140.15.0esr/gfx/thebes/gfxGDIFont.cpp | 553
firefox-esr-140.15.0esr/gfx/thebes/gfxGDIFont.h | 91
firefox-esr-140.15.0esr/gfx/thebes/gfxGDIFontList.cpp | 1162 -
firefox-esr-140.15.0esr/gfx/thebes/gfxGDIFontList.h | 366
firefox-esr-140.15.0esr/gfx/thebes/gfxGraphiteShaper.cpp | 8
firefox-esr-140.15.0esr/gfx/thebes/gfxOTSUtils.h | 4
firefox-esr-140.15.0esr/gfx/thebes/gfxTextRun.cpp | 33
firefox-esr-140.15.0esr/gfx/thebes/gfxTextRun.h | 2
firefox-esr-140.15.0esr/gfx/thebes/gfxWindowsPlatform.cpp | 36
firefox-esr-140.15.0esr/gfx/thebes/gfxWindowsPlatform.h | 3
firefox-esr-140.15.0esr/gfx/thebes/moz.build | 4
firefox-esr-140.15.0esr/gfx/webrender_bindings/RenderTextureHost.h | 2
firefox-esr-140.15.0esr/gfx/webrender_bindings/RenderTextureHostSWGL.cpp | 21
firefox-esr-140.15.0esr/gfx/webrender_bindings/RenderTextureHostSWGL.h | 10
firefox-esr-140.15.0esr/gfx/webrender_bindings/RenderTextureHostWrapper.cpp | 6
firefox-esr-140.15.0esr/gfx/webrender_bindings/RenderTextureHostWrapper.h | 1
firefox-esr-140.15.0esr/gfx/webrender_bindings/WebRenderAPI.cpp | 10
firefox-esr-140.15.0esr/gfx/webrender_bindings/WebRenderAPI.h | 9
firefox-esr-140.15.0esr/gfx/webrender_bindings/src/bindings.rs | 6
firefox-esr-140.15.0esr/gfx/wr/example-compositor/compositor/src/main.rs | 4
firefox-esr-140.15.0esr/gfx/wr/examples/common/boilerplate.rs | 2
firefox-esr-140.15.0esr/gfx/wr/examples/document.rs | 1
firefox-esr-140.15.0esr/gfx/wr/examples/iframe.rs | 1
firefox-esr-140.15.0esr/gfx/wr/examples/multiwindow.rs | 1
firefox-esr-140.15.0esr/gfx/wr/swgl/src/swgl_ext.h | 3
firefox-esr-140.15.0esr/gfx/wr/webrender/src/render_api.rs | 9
firefox-esr-140.15.0esr/gfx/wr/webrender/src/scene.rs | 7
firefox-esr-140.15.0esr/gfx/wr/webrender/src/scene_builder_thread.rs | 2
firefox-esr-140.15.0esr/gfx/wr/webrender/src/scene_building.rs | 132
firefox-esr-140.15.0esr/gfx/wr/wrench/src/rawtest.rs | 4
firefox-esr-140.15.0esr/gfx/wr/wrench/src/wrench.rs | 29
firefox-esr-140.15.0esr/image/ImageBlocker.cpp | 4
firefox-esr-140.15.0esr/image/RasterImage.cpp | 20
firefox-esr-140.15.0esr/image/RasterImage.h | 3
firefox-esr-140.15.0esr/image/decoders/icon/components.conf | 1
firefox-esr-140.15.0esr/image/decoders/icon/nsIconProtocolHandler.cpp | 10
firefox-esr-140.15.0esr/ipc/chromium/src/base/pickle.cc | 29
firefox-esr-140.15.0esr/ipc/chromium/src/base/pickle.h | 12
firefox-esr-140.15.0esr/ipc/chromium/src/chrome/common/ipc_channel_posix.cc | 96
firefox-esr-140.15.0esr/ipc/chromium/src/chrome/common/ipc_channel_posix.h | 5
firefox-esr-140.15.0esr/ipc/chromium/src/chrome/common/ipc_message_utils.h | 3
firefox-esr-140.15.0esr/ipc/glue/BackgroundChild.h | 13
firefox-esr-140.15.0esr/ipc/glue/BackgroundImpl.cpp | 48
firefox-esr-140.15.0esr/ipc/glue/BackgroundParent.h | 12
firefox-esr-140.15.0esr/ipc/glue/BackgroundParentImpl.cpp | 57
firefox-esr-140.15.0esr/ipc/glue/BackgroundParentImpl.h | 3
firefox-esr-140.15.0esr/ipc/glue/GeckoChildProcessHost.h | 1
firefox-esr-140.15.0esr/js/src/gc/Nursery.cpp | 9
firefox-esr-140.15.0esr/js/src/irregexp/RegExpNativeMacroAssembler.cpp | 9
firefox-esr-140.15.0esr/js/src/jit/CodeGenerator.cpp | 3
firefox-esr-140.15.0esr/js/src/jit/Lowering.cpp | 60
firefox-esr-140.15.0esr/js/src/jit/MIR.h | 6
firefox-esr-140.15.0esr/js/src/proxy/Proxy.cpp | 9
firefox-esr-140.15.0esr/js/src/vm/JitActivation.cpp | 11
firefox-esr-140.15.0esr/js/src/vm/JitActivation.h | 7
firefox-esr-140.15.0esr/js/src/wasm/WasmBCFrame.cpp | 2
firefox-esr-140.15.0esr/js/src/wasm/WasmBaselineCompile.cpp | 28
firefox-esr-140.15.0esr/js/src/wasm/WasmJS.cpp | 25
firefox-esr-140.15.0esr/layout/base/PresShell.cpp | 7
firefox-esr-140.15.0esr/layout/build/components.conf | 10
firefox-esr-140.15.0esr/layout/forms/nsFileControlFrame.cpp | 5
firefox-esr-140.15.0esr/layout/generic/nsBlockFrame.cpp | 3
firefox-esr-140.15.0esr/layout/generic/nsTextFrame.cpp | 2
firefox-esr-140.15.0esr/layout/generic/nsTextRunTransformations.cpp | 4
firefox-esr-140.15.0esr/layout/mathml/nsMathMLChar.cpp | 2
firefox-esr-140.15.0esr/layout/painting/nsCSSRendering.cpp | 3
firefox-esr-140.15.0esr/media/ffvpx/README_MOZILLA | 2
firefox-esr-140.15.0esr/media/ffvpx/cbs_decoder_sync.patch | 18
firefox-esr-140.15.0esr/media/ffvpx/libavcodec/cbs_av1_syntax_template.c | 3
firefox-esr-140.15.0esr/media/libcubeb/0006-fix-loopback-separate-streams-flakiness-windows.patch | 88
firefox-esr-140.15.0esr/media/libcubeb/moz.yaml | 4
firefox-esr-140.15.0esr/media/libcubeb/src/cubeb.c | 11
firefox-esr-140.15.0esr/media/libcubeb/src/cubeb_wasapi.cpp | 32
firefox-esr-140.15.0esr/media/libcubeb/src/cubeb_winmm.c | 76
firefox-esr-140.15.0esr/media/libcubeb/test/test_loopback.cpp | 50
firefox-esr-140.15.0esr/media/libcubeb/test/test_sanity.cpp | 23
firefox-esr-140.15.0esr/media/libcubeb/wasapi-async-reconfigure-on-start.patch | 41
firefox-esr-140.15.0esr/media/libcubeb/wasapi-output-mix-channel-count.patch | 84
firefox-esr-140.15.0esr/media/libcubeb/winmm-destroy-work-item-uaf.patch | 187
firefox-esr-140.15.0esr/mfbt/BufferList.h | 3
firefox-esr-140.15.0esr/modules/libjar/components.conf | 2
firefox-esr-140.15.0esr/modules/libpref/Preferences.cpp | 5
firefox-esr-140.15.0esr/modules/libpref/init/StaticPrefList.yaml | 14
firefox-esr-140.15.0esr/mozglue/misc/NativeNt.h | 101
firefox-esr-140.15.0esr/mozglue/tests/TestNativeNt.cpp | 167
firefox-esr-140.15.0esr/netwerk/base/SimpleChannelParent.cpp | 1
firefox-esr-140.15.0esr/netwerk/base/nsSimpleNestedURI.cpp | 22
firefox-esr-140.15.0esr/netwerk/base/nsSimpleNestedURI.h | 4
firefox-esr-140.15.0esr/netwerk/base/nsStandardURL.cpp | 90
firefox-esr-140.15.0esr/netwerk/base/nsStandardURL.h | 2
firefox-esr-140.15.0esr/netwerk/build/components.conf | 13
firefox-esr-140.15.0esr/netwerk/cookie/CookieServiceParent.cpp | 42
firefox-esr-140.15.0esr/netwerk/cookie/CookieServiceParent.h | 2
firefox-esr-140.15.0esr/netwerk/dns/effective_tld_names.dat | 127
firefox-esr-140.15.0esr/netwerk/ipc/DocumentLoadListener.cpp | 27
firefox-esr-140.15.0esr/netwerk/ipc/NeckoParent.cpp | 26
firefox-esr-140.15.0esr/netwerk/ipc/NeckoParent.h | 3
firefox-esr-140.15.0esr/netwerk/protocol/about/nsAboutProtocolHandler.cpp | 23
firefox-esr-140.15.0esr/netwerk/protocol/about/nsAboutProtocolHandler.h | 1
firefox-esr-140.15.0esr/netwerk/protocol/http/InterceptedHttpChannel.cpp | 4
firefox-esr-140.15.0esr/netwerk/protocol/http/SpeculativeTransaction.cpp | 13
firefox-esr-140.15.0esr/netwerk/protocol/res/PageThumbProtocolHandler.cpp | 11
firefox-esr-140.15.0esr/netwerk/protocol/res/PageThumbProtocolHandler.h | 2
firefox-esr-140.15.0esr/netwerk/protocol/websocket/WebSocketChannelChild.cpp | 31
firefox-esr-140.15.0esr/netwerk/protocol/webtransport/WebTransportSessionProxy.cpp | 61
firefox-esr-140.15.0esr/python/mozbuild/mozbuild/mach_commands.py | 8
firefox-esr-140.15.0esr/python/mozbuild/mozbuild/repackaging/deb.py | 3
firefox-esr-140.15.0esr/security/ct/CTKnownLogs.h | 12
firefox-esr-140.15.0esr/security/manager/ssl/StaticHPKPins.h | 20
firefox-esr-140.15.0esr/security/manager/ssl/components.conf | 1
firefox-esr-140.15.0esr/security/manager/ssl/nsSTSPreloadList.inc | 5894 ++----
firefox-esr-140.15.0esr/security/manager/tools/log_list.json | 20
firefox-esr-140.15.0esr/security/sandbox/chromium-shim/patches/55_dont_broker_dir_creation_or_write.patch | 56
firefox-esr-140.15.0esr/security/sandbox/chromium/sandbox/win/src/filesystem_dispatcher.cc | 29
firefox-esr-140.15.0esr/security/sandbox/chromium/sandbox/win/src/registry_dispatcher.cc | 12
firefox-esr-140.15.0esr/security/sandbox/chromium/sandbox/win/src/registry_policy.cc | 67
firefox-esr-140.15.0esr/security/sandbox/chromium/sandbox/win/src/registry_policy.h | 14
firefox-esr-140.15.0esr/security/sandbox/linux/broker/SandboxBrokerRealpath.cpp | 34
firefox-esr-140.15.0esr/security/sandbox/win/src/sandboxbroker/sandboxBroker.cpp | 24
firefox-esr-140.15.0esr/services/settings/RemoteSettingsClient.sys.mjs | 9
firefox-esr-140.15.0esr/services/settings/dumps/blocklists/addons-bloomfilters.json | 9738 ----------
firefox-esr-140.15.0esr/services/settings/dumps/blocklists/addons-bloomfilters/addons-mlbf.bin.meta.json | 2
firefox-esr-140.15.0esr/services/settings/dumps/blocklists/addons-bloomfilters/softblocks-addons-mlbf.bin.meta.json | 2
firefox-esr-140.15.0esr/services/settings/dumps/blocklists/gfx.json | 26
firefox-esr-140.15.0esr/services/settings/dumps/main/devtools-compatibility-browsers.json | 454
firefox-esr-140.15.0esr/services/settings/dumps/main/search-config-icons.json | 53
firefox-esr-140.15.0esr/services/settings/dumps/main/search-config-v2.json | 26
firefox-esr-140.15.0esr/services/settings/dumps/main/search-telemetry-v2.json | 321
firefox-esr-140.15.0esr/services/settings/dumps/main/translations-models.json | 116
firefox-esr-140.15.0esr/services/settings/dumps/security-state/intermediates.json | 1416 +
firefox-esr-140.15.0esr/sourcestamp.txt | 4
firefox-esr-140.15.0esr/taskcluster/gecko_taskgraph/transforms/repackage.py | 9
firefox-esr-140.15.0esr/taskcluster/gecko_taskgraph/transforms/repackage_routes.py | 5
firefox-esr-140.15.0esr/taskcluster/kinds/release-update-verify-config/kind.yml | 6
firefox-esr-140.15.0esr/testing/mochitest/runtests.py | 2
firefox-esr-140.15.0esr/testing/mozharness/configs/releases/bouncer_firefox_esr.py | 54
firefox-esr-140.15.0esr/testing/mozharness/configs/repackage/base.py | 1
firefox-esr-140.15.0esr/testing/mozharness/scripts/repackage.py | 1
firefox-esr-140.15.0esr/testing/web-platform/meta/push-api/worker-subscribe.https.window.js.ini | 4
firefox-esr-140.15.0esr/testing/web-platform/meta/service-workers/service-worker/windowclient-navigate.https.html.ini | 3
firefox-esr-140.15.0esr/testing/web-platform/tests/editing/crashtests/set-documentElement-innerHTML-when-embed-in-designMode-has-focus.html | 18
firefox-esr-140.15.0esr/testing/web-platform/tests/html/browsers/browsing-the-web/navigating-across-documents/javascript-url-security-check-failure.sub.html | 3
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/cross-origin-nested.tentative.https.sub.window.js | 56
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/cross-origin-same-site-request.tentative.https.sub.window.js | 32
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/cross-origin-serviceworker.tentative.https.sub.window.js | 29
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/cross-origin-nested-child.sub.html | 13
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/cross-origin-nested-parent.sub.html | 28
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/cross-origin-serviceworker-iframe.sub.html | 24
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/permission-helper.js | 26
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/permission-sw.js | 19
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/resources/permission-worker.js | 5
firefox-esr-140.15.0esr/testing/web-platform/tests/push-api/worker-subscribe.https.window.js | 22
firefox-esr-140.15.0esr/testing/web-platform/tests/selection/crashtests/find-whole-word-crash.html | 9
firefox-esr-140.15.0esr/third_party/libwebrtc/api/video/rtp_video_frame_assembler.cc | 27
firefox-esr-140.15.0esr/third_party/libwebrtc/modules/video_coding/packet_buffer.cc | 89
firefox-esr-140.15.0esr/third_party/libwebrtc/modules/video_coding/packet_buffer.h | 32
firefox-esr-140.15.0esr/third_party/libwebrtc/modules/video_coding/packet_buffer_unittest.cc | 10
firefox-esr-140.15.0esr/third_party/libwebrtc/video/rtp_video_stream_receiver2.cc | 31
firefox-esr-140.15.0esr/third_party/libwebrtc/video/rtp_video_stream_receiver2.h | 2
firefox-esr-140.15.0esr/toolkit/components/contentanalysis/tests/browser/browser_download_content_analysis.js | 99
firefox-esr-140.15.0esr/toolkit/components/contentanalysis/tests/browser/browser_download_save_link_as_content_analysis.js | 63
firefox-esr-140.15.0esr/toolkit/components/contentanalysis/tests/browser/head.js | 6
firefox-esr-140.15.0esr/toolkit/components/downloads/DownloadIntegration.sys.mjs | 4
firefox-esr-140.15.0esr/toolkit/components/extensions/ConduitsParent.sys.mjs | 79
firefox-esr-140.15.0esr/toolkit/components/extensions/ExtensionParent.sys.mjs | 80
firefox-esr-140.15.0esr/toolkit/components/extensions/test/xpcshell/test_ext_runtime_ports_membership.js | 110
firefox-esr-140.15.0esr/toolkit/components/extensions/test/xpcshell/xpcshell-common.toml | 2
firefox-esr-140.15.0esr/toolkit/components/find/nsFind.cpp | 2
firefox-esr-140.15.0esr/toolkit/components/gfx/SanityTest.sys.mjs | 2
firefox-esr-140.15.0esr/toolkit/components/gfx/content/gfxFrameScript.js | 2
firefox-esr-140.15.0esr/toolkit/components/gfx/content/sanitytest.html | 2
firefox-esr-140.15.0esr/toolkit/components/gfx/jar.mn | 7
firefox-esr-140.15.0esr/toolkit/components/nimbus/lib/RemoteSettingsExperimentLoader.sys.mjs | 1
firefox-esr-140.15.0esr/toolkit/components/nimbus/test/NimbusTestUtils.sys.mjs | 30
firefox-esr-140.15.0esr/toolkit/components/nimbus/test/browser/head.js | 2
firefox-esr-140.15.0esr/toolkit/components/places/PageIconProtocolHandler.cpp | 10
firefox-esr-140.15.0esr/toolkit/components/places/nsCachedFaviconProtocolHandler.cpp | 4
firefox-esr-140.15.0esr/toolkit/components/reputationservice/ApplicationReputation.cpp | 62
firefox-esr-140.15.0esr/toolkit/components/telemetry/Histograms.json | 9
firefox-esr-140.15.0esr/toolkit/components/telemetry/histogram-allowlists.json | 2
firefox-esr-140.15.0esr/toolkit/content/tests/chrome/findbar_entireword_window.xhtml | 2
firefox-esr-140.15.0esr/toolkit/library/rust/shared/lib.rs | 2
firefox-esr-140.15.0esr/toolkit/mozapps/handling/ContentDispatchChooser.sys.mjs | 2
firefox-esr-140.15.0esr/toolkit/xre/dllservices/mozglue/Authenticode.cpp | 3
firefox-esr-140.15.0esr/tools/tryselect/push.py | 4
firefox-esr-140.15.0esr/tools/tryselect/selectors/perf.py | 6
firefox-esr-140.15.0esr/tools/tryselect/test/test_perf.py | 1
firefox-esr-140.15.0esr/uriloader/exthandler/nsExternalHelperAppService.cpp | 8
firefox-esr-140.15.0esr/widget/ClipboardWriteRequestParent.cpp | 4
firefox-esr-140.15.0esr/widget/gtk/DMABufSurface.cpp | 28
firefox-esr-140.15.0esr/widget/nsBaseDragService.cpp | 4
firefox-esr-140.15.0esr/widget/nsDragServiceProxy.cpp | 1
firefox-esr-140.15.0esr/widget/windows/DirectManipulationOwner.cpp | 141
firefox-esr-140.15.0esr/widget/windows/DirectManipulationOwner.h | 2
firefox-esr-140.15.0esr/widget/windows/JumpListBuilder.cpp | 19
firefox-esr-140.15.0esr/widget/windows/TSFEmptyTextStore.cpp | 13
firefox-esr-140.15.0esr/widget/windows/TSFTextStore.cpp | 8
firefox-esr-140.15.0esr/widget/windows/TSFTextStoreBase.cpp | 95
firefox-esr-140.15.0esr/widget/windows/TSFTextStoreBase.h | 59
firefox-esr-140.15.0esr/widget/windows/TSFUtils.cpp | 40
firefox-esr-140.15.0esr/widget/windows/TSFUtils.h | 37
firefox-esr-140.15.0esr/widget/windows/WinUtils.h | 34
firefox-esr-140.15.0esr/widget/windows/tests/gtest/TestJumpListBuilder.cpp | 18
firefox-esr-140.15.0esr/xpcom/components/StaticComponents.h | 3
firefox-esr-140.15.0esr/xpcom/components/gen_static_components.py | 2
firefox-esr-140.15.0esr/xpcom/io/moz.build | 2
firefox-esr-140.15.0esr/xpcom/io/nsBinaryStream.cpp | 29
454 files changed, 12218 insertions(+), 17860 deletions(-)
dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpwxj_se87/firefox-esr_140.13.0esr-1~deb13u1.dsc: no acceptable signature found
dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmpwxj_se87/firefox-esr_140.15.0esr-1~deb13u1.dsc: no acceptable signature found
diff -Nru firefox-esr-140.13.0esr/.lando.ini firefox-esr-140.15.0esr/.lando.ini
--- firefox-esr-140.13.0esr/.lando.ini 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/.lando.ini 2026-08-26 17:03:40.000000000 +0000
@@ -6,14 +6,14 @@
# Lando production Auth0 configuration.
auth0_domain = auth.mozilla.auth0.com
auth0_client_id = ccpmWbDAMz1pxHIWF4vqkdr0ScdgDyyM
-auth0_audience = https://api.lando.services.mozilla.com
+auth0_audience = https://lando.moz.tools
auth0_scope = openid email profile lando https://sso.mozilla.com/claim/groups
-api_domain = api.lando.services.mozilla.com
+api_domain = lando.moz.tools
[lando-dev]
# Lando dev server Auth0 configuration.
auth0_domain = auth.mozilla.auth0.com
auth0_client_id = TAtuZwbJd4SRtWg0YznfS1YYCatOvvnX
-auth0_audience = https://api.lando.devsvcdev.mozaws.net
+auth0_audience = https://lando-dev.allizom.org
auth0_scope = openid email profile lando https://sso.mozilla.com/claim/groups
-api_domain = api.dev.lando.nonprod.cloudops.mozgcp.net
+api_domain = lando-dev.allizom.org
diff -Nru firefox-esr-140.13.0esr/CLOBBER firefox-esr-140.15.0esr/CLOBBER
--- firefox-esr-140.13.0esr/CLOBBER 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/CLOBBER 2026-08-26 17:03:40.000000000 +0000
@@ -22,4 +22,4 @@
# changes to stick? As of bug 928195, this shouldn't be necessary! Please
# don't change CLOBBER for WebIDL changes any more.
-Merge day clobber 2026-06-15
\ No newline at end of file
+Merge day clobber 2026-08-13
\ No newline at end of file
diff -Nru firefox-esr-140.13.0esr/accessible/ipc/DocAccessibleParent.cpp firefox-esr-140.15.0esr/accessible/ipc/DocAccessibleParent.cpp
--- firefox-esr-140.13.0esr/accessible/ipc/DocAccessibleParent.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/accessible/ipc/DocAccessibleParent.cpp 2026-08-26 17:03:39.000000000 +0000
@@ -1118,7 +1118,7 @@
// XXX This indirection through the hash map of live documents shouldn't be
// needed, but be paranoid for now.
- int32_t actorID = mActorID;
+ uint64_t actorID = mActorID;
for (uint32_t i = childDocCount - 1; i < childDocCount; i--) {
DocAccessibleParent* thisDoc = LiveDocs().Get(actorID);
MOZ_ASSERT(thisDoc);
diff -Nru firefox-esr-140.13.0esr/browser/app/winlauncher/freestanding/SharedSection.cpp firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/SharedSection.cpp
--- firefox-esr-140.13.0esr/browser/app/winlauncher/freestanding/SharedSection.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/SharedSection.cpp 2026-08-26 17:03:39.000000000 +0000
@@ -151,9 +151,23 @@
kSharedViewSize >= sizeof(Layout),
"kSharedViewSize is too small to represent SharedSection::Layout.");
- HANDLE section =
- ::CreateFileMappingW(INVALID_HANDLE_VALUE, nullptr, PAGE_READWRITE, 0,
- kSharedViewSize, nullptr);
+ // Create with an empty DACL to limit the duplicated handle's access rights.
+ // See shared_memory::CreateImpl for details.
+ SECURITY_DESCRIPTOR sd;
+ ACL dacl;
+ if (!::InitializeAcl(&dacl, sizeof(dacl), ACL_REVISION) ||
+ !::InitializeSecurityDescriptor(&sd, SECURITY_DESCRIPTOR_REVISION) ||
+ !::SetSecurityDescriptorDacl(&sd, TRUE, &dacl, FALSE)) {
+ return LAUNCHER_ERROR_FROM_LAST();
+ }
+
+ SECURITY_ATTRIBUTES sa;
+ sa.nLength = sizeof(sa);
+ sa.lpSecurityDescriptor = &sd;
+ sa.bInheritHandle = FALSE;
+
+ HANDLE section = ::CreateFileMappingW(
+ INVALID_HANDLE_VALUE, &sa, PAGE_READWRITE, 0, kSharedViewSize, nullptr);
if (!section) {
return LAUNCHER_ERROR_FROM_LAST();
}
diff -Nru firefox-esr-140.13.0esr/browser/app/winlauncher/freestanding/moz.build firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/moz.build
--- firefox-esr-140.13.0esr/browser/app/winlauncher/freestanding/moz.build 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/app/winlauncher/freestanding/moz.build 2026-08-26 17:03:40.000000000 +0000
@@ -38,6 +38,7 @@
CXXFLAGS += [SRCDIR + "/Freestanding.h"]
OS_LIBS += [
+ "advapi32",
"ntdll",
"ntdll_freestanding",
]
diff -Nru firefox-esr-140.13.0esr/browser/app/winlauncher/test/TestCrossProcessWin.cpp firefox-esr-140.15.0esr/browser/app/winlauncher/test/TestCrossProcessWin.cpp
--- firefox-esr-140.13.0esr/browser/app/winlauncher/test/TestCrossProcessWin.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/app/winlauncher/test/TestCrossProcessWin.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -70,6 +70,7 @@
(offsetof(SharedSection::Layout, mFirstBlockEntry) +
sizeof(DllBlockInfo));
}
+ static HANDLE GetSectionHandle() { return SharedSection::sSectionHandle; }
};
} // namespace mozilla::freestanding
@@ -527,6 +528,18 @@
return 1;
}
+ // The empty DACL should prevent writable handles.
+ HANDLE writableHandle;
+ if (::DuplicateHandle(
+ nt::kCurrentProcess, SharedSectionTestHelper::GetSectionHandle(),
+ nt::kCurrentProcess, &writableHandle, GENERIC_WRITE, FALSE, 0)) {
+ ::CloseHandle(writableHandle);
+ printf(
+ "TEST-FAILED | TestCrossProcessWin | "
+ "The handle was writable.\n");
+ return 1;
+ }
+
if (!VerifySharedSection(gSharedSection)) {
return 1;
}
diff -Nru firefox-esr-140.13.0esr/browser/app/winlauncher/test/moz.build firefox-esr-140.15.0esr/browser/app/winlauncher/test/moz.build
--- firefox-esr-140.13.0esr/browser/app/winlauncher/test/moz.build 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/app/winlauncher/test/moz.build 2026-08-26 17:03:40.000000000 +0000
@@ -20,6 +20,7 @@
]
OS_LIBS += [
+ "advapi32",
"ntdll",
]
diff -Nru firefox-esr-140.13.0esr/browser/base/content/nsContextMenu.sys.mjs firefox-esr-140.15.0esr/browser/base/content/nsContextMenu.sys.mjs
--- firefox-esr-140.13.0esr/browser/base/content/nsContextMenu.sys.mjs 2026-07-15 20:30:27.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/nsContextMenu.sys.mjs 2026-08-26 17:03:39.000000000 +0000
@@ -91,6 +91,13 @@
const PASSWORD_FIELDNAME_HINTS = ["current-password", "new-password"];
const USERNAME_FIELDNAME_HINT = "username";
+const IMAGE_ONLY_PROTOCOLS = [
+ "cached-favicon:",
+ "moz-icon:",
+ "moz-page-thumb:",
+ "page-icon:",
+];
+
export class nsContextMenu {
/**
* A promise to retrieve the translations language pair
@@ -729,6 +736,12 @@
this.onImage && !this.onCompletedImage
);
+ // Some protocols only return images in an image context and can no longer
+ // be loaded otherwise.
+ const mediaURL = URL.parse(this.mediaURL);
+ const isImageOnlyProtocol =
+ mediaURL && IMAGE_ONLY_PROTOCOLS.includes(mediaURL.protocol);
+
// View image depends on having an image that's not standalone
// (or is in a frame), or a canvas. If this isn't an image, check
// if there is a background image.
@@ -748,12 +761,16 @@
!this.onAudio &&
!this.onLink &&
!this.onTextInput;
- this.showItem("context-viewimage", showViewImage || showBGImage);
+ this.showItem(
+ "context-viewimage",
+ (showViewImage || showBGImage) && !isImageOnlyProtocol
+ );
// Save image depends on having loaded its content.
this.showItem(
"context-saveimage",
- (this.onLoadedImage || this.onCanvas) && !this.inPDFEditor
+ ((this.onLoadedImage && !isImageOnlyProtocol) || this.onCanvas) &&
+ !this.inPDFEditor
);
if (Services.policies.status === Services.policies.ACTIVE) {
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/browser.toml firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser.toml
--- firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/browser.toml 2026-07-15 20:30:27.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser.toml 2026-08-26 17:03:39.000000000 +0000
@@ -33,6 +33,9 @@
"os == 'linux' && socketprocess_networking",
]
+["browser_contextmenu_blocked_image_protocols.js"]
+support-files = ["file_blocked_image_protocols.html"]
+
["browser_contextmenu_contenteditable.js"]
["browser_contextmenu_cross_boundary_selection.js"]
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/browser_contextmenu_blocked_image_protocols.js firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser_contextmenu_blocked_image_protocols.js
--- firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/browser_contextmenu_blocked_image_protocols.js 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/browser_contextmenu_blocked_image_protocols.js 2026-08-26 17:03:39.000000000 +0000
@@ -0,0 +1,63 @@
+/* Any copyright is dedicated to the Public Domain.
+ http://creativecommons.org/publicdomain/zero/1.0/ */
+
+"use strict";
+
+Services.scriptloader.loadSubScript(
+ getRootDirectory(gTestPath) + "contextmenu_common.js",
+ this
+);
+
+const IMAGE_PROTOCOLS_IDS = [
+ "cached-favicon",
+ "moz-icon",
+ "moz-page-thumb",
+ "page-icon",
+];
+
+add_task(async function test_blocked() {
+ for (const protocol of IMAGE_PROTOCOLS_IDS) {
+ info(`Testing contextmenu with the ${protocol}: protocol`);
+
+ await BrowserTestUtils.withNewTab(
+ {
+ gBrowser,
+ url: getRootDirectory(gTestPath) + "file_blocked_image_protocols.html",
+ },
+ async browser => {
+ await SpecialPowers.spawn(browser, [`#${protocol}`], async selector => {
+ const img = content.document.querySelector(selector);
+ if (!img.complete) {
+ await ContentTaskUtils.waitForEvent(img, "load");
+ }
+ });
+
+ let contextMenu = document.getElementById("contentAreaContextMenu");
+ let popupShown = BrowserTestUtils.waitForEvent(
+ contextMenu,
+ "popupshown"
+ );
+
+ await BrowserTestUtils.synthesizeMouse(
+ `#${protocol}`,
+ 2,
+ 2,
+ { type: "contextmenu", button: 2 },
+ browser
+ );
+ await popupShown;
+
+ let viewImageItem = document.getElementById("context-viewimage");
+ ok(viewImageItem.hidden, "View Image menu item should be hidden");
+
+ let saveImageItem = document.getElementById("context-saveimage");
+ ok(saveImageItem.hidden, "Save Image menu item should be hidden");
+
+ let sendImageItem = document.getElementById("context-sendimage");
+ ok(!sendImageItem.hidden, "Send Image menu item should be shown");
+
+ contextMenu.hidePopup();
+ }
+ );
+ }
+});
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/file_blocked_image_protocols.html firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/file_blocked_image_protocols.html
--- firefox-esr-140.13.0esr/browser/base/content/test/contextMenu/file_blocked_image_protocols.html 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/contextMenu/file_blocked_image_protocols.html 2026-08-26 17:03:39.000000000 +0000
@@ -0,0 +1,9 @@
+
+
+
+
+
+
+
+
+
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/siteIdentity/browser_secure_transport_insecure_scheme.js firefox-esr-140.15.0esr/browser/base/content/test/siteIdentity/browser_secure_transport_insecure_scheme.js
--- firefox-esr-140.13.0esr/browser/base/content/test/siteIdentity/browser_secure_transport_insecure_scheme.js 2026-07-15 20:30:27.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/siteIdentity/browser_secure_transport_insecure_scheme.js 2026-08-26 17:03:39.000000000 +0000
@@ -56,7 +56,7 @@
let blob = new Blob([JSON.stringify(debug, null, 2)], {
type: "application/json",
});
- let blobUri = URL.createObjectURL(blob);
+ let blobUri = content.URL.createObjectURL(blob);
content.document.location = blobUri;
});
await BrowserTestUtils.browserLoaded(browser);
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/static/browser_all_files_referenced.js firefox-esr-140.15.0esr/browser/base/content/test/static/browser_all_files_referenced.js
--- firefox-esr-140.13.0esr/browser/base/content/test/static/browser_all_files_referenced.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/static/browser_all_files_referenced.js 2026-08-26 17:03:40.000000000 +0000
@@ -121,6 +121,11 @@
"chrome://newtab/",
];
+if (AppConstants.platform == "win") {
+ // Referenced via resource://gfxsanity/
+ gExceptionPaths.push("resource://gre-resources/gfxsanity/");
+}
+
// These are not part of the omni.ja file, so we find them only when running
// the test on a non-packaged build.
if (AppConstants.platform == "macosx") {
diff -Nru firefox-esr-140.13.0esr/browser/base/content/test/static/browser_parsable_css.js firefox-esr-140.15.0esr/browser/base/content/test/static/browser_parsable_css.js
--- firefox-esr-140.13.0esr/browser/base/content/test/static/browser_parsable_css.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/base/content/test/static/browser_parsable_css.js 2026-08-26 17:03:40.000000000 +0000
@@ -416,8 +416,14 @@
function chromeFileExists(aURI) {
let available = 0;
try {
+ let uri = NetUtil.newURI(aURI);
+ // moz-icon: is only loadable as an image, so we pretend to do that.
+ let contentPolicyType = uri.schemeIs("moz-icon")
+ ? Ci.nsIContentPolicy.TYPE_IMAGE
+ : Ci.nsIContentPolicy.TYPE_OTHER;
let channel = NetUtil.newChannel({
- uri: aURI,
+ uri,
+ contentPolicyType,
loadUsingSystemPrincipal: true,
});
let stream = channel.open();
diff -Nru firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_asrouter_experimentsAPILoader.js firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_experimentsAPILoader.js
--- firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_asrouter_experimentsAPILoader.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_experimentsAPILoader.js 2026-08-26 17:03:40.000000000 +0000
@@ -4,7 +4,7 @@
const { ASRouter } = ChromeUtils.importESModule(
"resource:///modules/asrouter/ASRouter.sys.mjs"
);
-const { EnrollmentType, ExperimentAPI } = ChromeUtils.importESModule(
+const { EnrollmentType } = ChromeUtils.importESModule(
"resource://nimbus/ExperimentAPI.sys.mjs"
);
const { NimbusTestUtils } = ChromeUtils.importESModule(
diff -Nru firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_asrouter_targeting.js firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_targeting.js
--- firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_asrouter_targeting.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_asrouter_targeting.js 2026-08-26 17:03:39.000000000 +0000
@@ -9,7 +9,6 @@
BuiltInThemes: "resource:///modules/BuiltInThemes.sys.mjs",
CFRMessageProvider: "resource:///modules/asrouter/CFRMessageProvider.sys.mjs",
ClientID: "resource://gre/modules/ClientID.sys.mjs",
- ExperimentAPI: "resource://nimbus/ExperimentAPI.sys.mjs",
FxAccounts: "resource://gre/modules/FxAccounts.sys.mjs",
HomePage: "resource:///modules/HomePage.sys.mjs",
InfoBar: "resource:///modules/asrouter/InfoBar.sys.mjs",
diff -Nru firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_trigger_messagesLoaded.js firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_trigger_messagesLoaded.js
--- firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/browser_trigger_messagesLoaded.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/browser_trigger_messagesLoaded.js 2026-08-26 17:03:40.000000000 +0000
@@ -8,7 +8,7 @@
const { RemoteSettings } = ChromeUtils.importESModule(
"resource://services-settings/remote-settings.sys.mjs"
);
-const { EnrollmentType, ExperimentAPI } = ChromeUtils.importESModule(
+const { EnrollmentType } = ChromeUtils.importESModule(
"resource://nimbus/ExperimentAPI.sys.mjs"
);
const { NimbusTestUtils } = ChromeUtils.importESModule(
diff -Nru firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/head.js firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/head.js
--- firefox-esr-140.13.0esr/browser/components/asrouter/tests/browser/head.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/asrouter/tests/browser/head.js 2026-08-26 17:03:40.000000000 +0000
@@ -2,6 +2,7 @@
ChromeUtils.defineESModuleGetters(this, {
ASRouter: "resource:///modules/asrouter/ASRouter.sys.mjs",
+ ExperimentAPI: "resource://nimbus/ExperimentAPI.sys.mjs",
FeatureCallout: "resource:///modules/asrouter/FeatureCallout.sys.mjs",
FeatureCalloutBroker:
@@ -10,6 +11,7 @@
FeatureCalloutMessages:
"resource:///modules/asrouter/FeatureCalloutMessages.sys.mjs",
+ NimbusTestUtils: "resource://testing-common/NimbusTestUtils.sys.mjs",
PlacesTestUtils: "resource://testing-common/PlacesTestUtils.sys.mjs",
QueryCache: "resource:///modules/asrouter/ASRouterTargeting.sys.mjs",
AboutWelcomeParent: "resource:///actors/AboutWelcomeParent.sys.mjs",
@@ -29,6 +31,10 @@
const calloutDismissSelector = `#${calloutId} .dismiss-button`;
const CTASelector = `#${calloutId} :is(.primary, .secondary)`;
+add_setup(function setup() {
+ registerCleanupFunction(NimbusTestUtils.disableSignatureVerification());
+});
+
function pushPrefs(...prefs) {
return SpecialPowers.pushPrefEnv({ set: prefs });
}
diff -Nru firefox-esr-140.13.0esr/browser/components/preferences/tests/head.js firefox-esr-140.15.0esr/browser/components/preferences/tests/head.js
--- firefox-esr-140.13.0esr/browser/components/preferences/tests/head.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/preferences/tests/head.js 2026-08-26 17:03:40.000000000 +0000
@@ -486,6 +486,9 @@
];
async function setupLabsTest(recipes) {
+ const restoreSignatureVerification =
+ NimbusTestUtils.disableSignatureVerification();
+
await SpecialPowers.pushPrefEnv({
set: [
["app.normandy.run_interval_seconds", 0],
@@ -517,6 +520,7 @@
return async function cleanup() {
await NimbusTestUtils.removeStore(ExperimentAPI.manager.store);
await SpecialPowers.popPrefEnv();
+ restoreSignatureVerification();
};
}
diff -Nru firefox-esr-140.13.0esr/browser/components/shell/nsWindowsShellService.cpp firefox-esr-140.15.0esr/browser/components/shell/nsWindowsShellService.cpp
--- firefox-esr-140.13.0esr/browser/components/shell/nsWindowsShellService.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/shell/nsWindowsShellService.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -94,24 +94,6 @@
#define REG_FAILED(val) (val != ERROR_SUCCESS)
-#ifdef DEBUG
-# define NS_ENSURE_HRESULT(hres, ret) \
- do { \
- HRESULT result = hres; \
- if (MOZ_UNLIKELY(FAILED(result))) { \
- mozilla::SmprintfPointer msg = mozilla::Smprintf( \
- "NS_ENSURE_HRESULT(%s, %s) failed with " \
- "result 0x%" PRIX32, \
- #hres, #ret, static_cast(result)); \
- NS_WARNING(msg.get()); \
- return ret; \
- } \
- } while (false)
-#else
-# define NS_ENSURE_HRESULT(hres, ret) \
- if (MOZ_UNLIKELY(FAILED(hres))) return ret
-#endif
-
using namespace mozilla;
using mozilla::intl::Localization;
diff -Nru firefox-esr-140.13.0esr/browser/components/tabbrowser/test/browser/tabs/browser_new_tab_in_privilegedabout_process_pref.js firefox-esr-140.15.0esr/browser/components/tabbrowser/test/browser/tabs/browser_new_tab_in_privilegedabout_process_pref.js
--- firefox-esr-140.13.0esr/browser/components/tabbrowser/test/browser/tabs/browser_new_tab_in_privilegedabout_process_pref.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/components/tabbrowser/test/browser/tabs/browser_new_tab_in_privilegedabout_process_pref.js 2026-08-26 17:03:40.000000000 +0000
@@ -216,13 +216,6 @@
BrowserTestUtils.startLoadingURIString(browser, TEST_HTTP);
await BrowserTestUtils.browserLoaded(browser, false, TEST_HTTP);
checkBrowserRemoteType(browser, E10SUtils.WEB_REMOTE_TYPE);
-
- // Check that location change causes a change in process type as well.
- await SpecialPowers.spawn(browser, [ABOUT_NEWTAB], uri => {
- content.location = uri;
- });
- await BrowserTestUtils.browserLoaded(browser, false, ABOUT_NEWTAB);
- assertIsPrivilegedProcess(browser, "about:newtab after location change");
}
);
diff -Nru firefox-esr-140.13.0esr/browser/config/version.txt firefox-esr-140.15.0esr/browser/config/version.txt
--- firefox-esr-140.13.0esr/browser/config/version.txt 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/config/version.txt 2026-08-26 17:03:40.000000000 +0000
@@ -1 +1 @@
-140.13.0
+140.15.0
diff -Nru firefox-esr-140.13.0esr/browser/config/version_display.txt firefox-esr-140.15.0esr/browser/config/version_display.txt
--- firefox-esr-140.13.0esr/browser/config/version_display.txt 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/config/version_display.txt 2026-08-26 17:03:40.000000000 +0000
@@ -1 +1 @@
-140.13.0esr
+140.15.0esr
diff -Nru firefox-esr-140.13.0esr/browser/extensions/webcompat/injections/js/bug1831007-nintendo-window-OnetrustActiveGroups.js firefox-esr-140.15.0esr/browser/extensions/webcompat/injections/js/bug1831007-nintendo-window-OnetrustActiveGroups.js
--- firefox-esr-140.13.0esr/browser/extensions/webcompat/injections/js/bug1831007-nintendo-window-OnetrustActiveGroups.js 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/extensions/webcompat/injections/js/bug1831007-nintendo-window-OnetrustActiveGroups.js 2026-08-26 17:03:40.000000000 +0000
@@ -21,4 +21,6 @@
"The window.OnetrustActiveGroups property has been shimmed for compatibility reasons. See https://bugzilla.mozilla.org/show_bug.cgi?id=1831007 for details."
);
-window.wrappedJSObject.OnetrustActiveGroups = "";
+if (typeof window.wrappedJSObject.OnetrustActiveGroups == "undefined") {
+ window.wrappedJSObject.OnetrustActiveGroups = null;
+}
diff -Nru firefox-esr-140.13.0esr/browser/extensions/webcompat/manifest.json firefox-esr-140.15.0esr/browser/extensions/webcompat/manifest.json
--- firefox-esr-140.13.0esr/browser/extensions/webcompat/manifest.json 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/extensions/webcompat/manifest.json 2026-08-26 17:03:39.000000000 +0000
@@ -2,7 +2,7 @@
"manifest_version": 2,
"name": "Web Compatibility Interventions",
"description": "Urgent post-release fixes for web compatibility.",
- "version": "140.12.0",
+ "version": "140.13.0",
"browser_specific_settings": {
"gecko": {
"id": "webcompat@mozilla.org",
diff -Nru firefox-esr-140.13.0esr/browser/modules/WindowsJumpLists.sys.mjs firefox-esr-140.15.0esr/browser/modules/WindowsJumpLists.sys.mjs
--- firefox-esr-140.13.0esr/browser/modules/WindowsJumpLists.sys.mjs 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/browser/modules/WindowsJumpLists.sys.mjs 2026-08-26 17:03:40.000000000 +0000
@@ -94,7 +94,7 @@
get description() {
return _getString("taskbar.tasks.newTab.description");
},
- args: "-new-tab about:blank",
+ args: ["-new-tab", "about:blank"],
iconIndex: 3, // New window icon
open: true,
close: true, // The jump list already has an app launch icon, but
@@ -110,7 +110,7 @@
get description() {
return _getString("taskbar.tasks.newWindow.description");
},
- args: "-browser",
+ args: ["-browser"],
iconIndex: 2, // New tab icon
open: true,
close: true, // No point, but we don't always update the list on
@@ -126,7 +126,7 @@
get description() {
return _getString("taskbar.tasks.newPrivateWindow.description");
},
- args: "-private-window",
+ args: ["-private-window"],
iconIndex: 4, // Private browsing mode icon
open: true,
close: true, // No point, but we don't always update the list on
@@ -261,7 +261,7 @@
title: row.getResultByName("title"),
description: row.getResultByName("title"),
path: selfPath,
- arguments: row.getResultByName("url"),
+ arguments: ["-osint", "-url", row.getResultByName("url")],
fallbackIconIndex: 1,
iconPath,
});
diff -Nru firefox-esr-140.13.0esr/config/milestone.txt firefox-esr-140.15.0esr/config/milestone.txt
--- firefox-esr-140.13.0esr/config/milestone.txt 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/config/milestone.txt 2026-08-26 17:03:39.000000000 +0000
@@ -10,4 +10,4 @@
# hardcoded milestones in the tree from these two files.
#--------------------------------------------------------
-140.13.0
+140.15.0
diff -Nru firefox-esr-140.13.0esr/debian/changelog firefox-esr-140.15.0esr/debian/changelog
--- firefox-esr-140.13.0esr/debian/changelog 2026-07-21 23:00:36.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/changelog 2026-08-19 00:51:19.000000000 +0000
@@ -1,3 +1,41 @@
+firefox-esr (140.15.0esr-1~deb13u1) trixie-security; urgency=medium
+
+ * New upstream release.
+ * Fixes for mfsa2026-84, also known as:
+ CVE-2026-75874, CVE-2026-16365, CVE-2026-84119, CVE-2026-84120,
+ CVE-2026-84121, CVE-2026-84122, CVE-2026-84124, CVE-2026-16371,
+ CVE-2026-84131, CVE-2026-84143, CVE-2026-84145.
+
+ * third_party/rust/glslopt/.cargo-checksum.json,
+ third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h:
+ Fix conficting types for once_flag and call_once. Fixes: #1128875.
+
+ -- Mike Hommey Wed, 19 Aug 2026 09:51:19 +0900
+
+firefox-esr (140.14.0esr-1~deb13u1) trixie-security; urgency=medium
+
+ * New upstream release.
+ * Fixes for mfsa2026-70, also known as:
+ CVE-2026-74934, CVE-2026-74935, CVE-2026-74936, CVE-2026-74939,
+ CVE-2026-74940, CVE-2026-74941, CVE-2026-74942, CVE-2026-74943,
+ CVE-2026-74944, CVE-2026-74945, CVE-2026-74946, CVE-2026-74948,
+ CVE-2026-74949, CVE-2026-74953, CVE-2026-74957, CVE-2026-74959,
+ CVE-2026-74960, CVE-2026-74962, CVE-2026-74963, CVE-2026-74964,
+ CVE-2026-74965, CVE-2026-74967, CVE-2026-74969, CVE-2026-74971,
+ CVE-2026-74972, CVE-2026-74973, CVE-2026-74974, CVE-2026-74976,
+ CVE-2026-74983, CVE-2026-74987, CVE-2026-74990.
+
+ * python/mach/mach/command_util.py: Fix AST parsing in DecoratorVisitor for
+ Python 3.14. bz#1993797.
+ * python/mozbuild/mozbuild/frontend/reader.py,
+ python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py: Change uses of
+ ast.Str with ast.Constant. bz#1969769.
+ * python/mozbuild/mozbuild/vendor/vendor_python.py,
+ third_party/python/jsonschema/jsonschema/validators.py: Patch jsonschema
+ to work with Python 3.14+. bz#1983736.
+
+ -- Mike Hommey Wed, 22 Jul 2026 09:18:35 +0900
+
firefox-esr (140.13.0esr-1~deb13u1) trixie-security; urgency=medium
* New upstream release.
diff -Nru firefox-esr-140.13.0esr/debian/patches/debian-hacks/Set-DPI-to-system-settings.patch firefox-esr-140.15.0esr/debian/patches/debian-hacks/Set-DPI-to-system-settings.patch
--- firefox-esr-140.13.0esr/debian/patches/debian-hacks/Set-DPI-to-system-settings.patch 2026-07-21 23:00:27.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/debian-hacks/Set-DPI-to-system-settings.patch 2026-08-19 00:51:19.000000000 +0000
@@ -7,10 +7,10 @@
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/modules/libpref/init/StaticPrefList.yaml b/modules/libpref/init/StaticPrefList.yaml
-index 282bb8d..d9b5c52 100644
+index 03cda69..4a7efdc 100644
--- a/modules/libpref/init/StaticPrefList.yaml
+++ b/modules/libpref/init/StaticPrefList.yaml
-@@ -9636,7 +9636,7 @@
+@@ -9642,7 +9642,7 @@
# interpretation of physical units such as "pt".
- name: layout.css.dpi
type: int32_t
diff -Nru firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch
--- firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch 2026-08-19 00:51:19.000000000 +0000
@@ -0,0 +1,77 @@
+From: Mike Hommey
+Date: Tue, 19 Aug 2025 05:09:09 +0000
+Subject: Bug 1969769 - Change uses of ast.Str with ast.Constant.
+ r=firefox-build-system-reviewers,ahochheiden
+
+ast.Str was deprecated in python 3.12 and removed in 3.14. It inherited
+from ast.Constant, `Str.s` was equivalent to `Constant.value`, so we can
+use the latter on both old and newer python versions.
+
+Differential Revision: https://phabricator.services.mozilla.com/D261512
+---
+ python/mozbuild/mozbuild/frontend/reader.py | 14 +++++++-------
+ .../mozbuild/mozbuild/vendor/rewrite_mozbuild.py | 6 ++----
+ 2 files changed, 9 insertions(+), 11 deletions(-)
+
+diff --git a/python/mozbuild/mozbuild/frontend/reader.py b/python/mozbuild/mozbuild/frontend/reader.py
+index 9f6292c..89bf999 100644
+--- a/python/mozbuild/mozbuild/frontend/reader.py
++++ b/python/mozbuild/mozbuild/frontend/reader.py
+@@ -470,7 +470,7 @@ class TemplateFunction:
+ return c(
+ ast.Subscript(
+ value=c(ast.Name(id=self._global_name, ctx=ast.Load())),
+- slice=c(ast.Index(value=c(ast.Str(s=node.id)))),
++ slice=c(ast.Index(value=c(ast.Constant(value=node.id)))),
+ ctx=node.ctx,
+ )
+ )
+@@ -1039,8 +1039,8 @@ class BuildReader:
+ else:
+ # Others
+ assert isinstance(target.slice, ast.Index)
+- assert isinstance(target.slice.value, ast.Str)
+- key = target.slice.value.s
++ assert isinstance(target.slice.value, ast.Constant)
++ key = target.slice.value.value
+ elif isinstance(target, ast.Attribute):
+ assert isinstance(target.attr, str)
+ key = target.attr
+@@ -1051,11 +1051,11 @@ class BuildReader:
+ value = node.value
+ if isinstance(value, ast.List):
+ for v in value.elts:
+- assert isinstance(v, ast.Str)
+- yield v.s
++ assert isinstance(v, ast.Constant)
++ yield v.value
+ else:
+- assert isinstance(value, ast.Str)
+- yield value.s
++ assert isinstance(value, ast.Constant)
++ yield value.value
+
+ assignments = []
+
+diff --git a/python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py b/python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py
+index cfcc0f1..de06b58 100644
+--- a/python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py
++++ b/python/mozbuild/mozbuild/vendor/rewrite_mozbuild.py
+@@ -327,15 +327,13 @@ def assignment_node_to_source_filename_list(code, node):
+ """
+ if isinstance(node.value, ast.List) and "elts" in node.value._fields:
+ for f in node.value.elts:
+- if not isinstance(f, ast.Constant) and not isinstance(f, ast.Str):
++ if not isinstance(f, ast.Constant):
+ log(
+ "Found non-constant source file name in list: ",
+ ast_get_source_segment(code, f),
+ )
+ return []
+- return [
+- f.value if isinstance(f, ast.Constant) else f.s for f in node.value.elts
+- ]
++ return [f.value for f in node.value.elts]
+ elif isinstance(node.value, ast.ListComp):
+ # SOURCES += [f for f in foo if blah]
+ log("Could not find the files for " + ast_get_source_segment(code, node.value))
diff -Nru firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch
--- firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch 2026-08-19 00:51:19.000000000 +0000
@@ -0,0 +1,27 @@
+From: Mike Hommey
+Date: Tue, 19 Aug 2025 05:08:34 +0000
+Subject: Bug 1983713 - Use non-deprecated ast value.
+ r=firefox-build-system-reviewers,nalexander,ahochheiden
+
+ast.Str was deprecated in python 3.12 and removed in 3.14. It inherited
+from ast.Constant, `Str.s` was equivalent to `Constant.value`, so we can
+use the latter on both old and newer python versions.
+
+Differential Revision: https://phabricator.services.mozilla.com/D261511
+---
+ python/mach/mach/command_util.py | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/python/mach/mach/command_util.py b/python/mach/mach/command_util.py
+index 44e13f1..8539bf37 100644
+--- a/python/mach/mach/command_util.py
++++ b/python/mach/mach/command_util.py
+@@ -292,7 +292,7 @@ class DecoratorVisitor(ast.NodeVisitor):
+ kwarg_dict = {}
+
+ for name, arg in zip(["command", "subcommand"], decorator.args):
+- kwarg_dict[name] = arg.s
++ kwarg_dict[name] = arg.value
+
+ for keyword in decorator.keywords:
+ if keyword.arg not in relevant_kwargs:
diff -Nru firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch
--- firefox-esr-140.13.0esr/debian/patches/fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch 2026-08-19 00:51:19.000000000 +0000
@@ -0,0 +1,43 @@
+From: Jan-Erik Rediger
+Date: Wed, 27 Aug 2025 01:09:58 +0000
+Subject: Bug 1983736 - Patch jsonschema to work with Python 3.14+
+ r=mach-reviewers,ahal,ahochheiden
+
+Differential Revision: https://phabricator.services.mozilla.com/D262335
+---
+ python/mozbuild/mozbuild/vendor/vendor_python.py | 4 ++++
+ third_party/python/jsonschema/jsonschema/validators.py | 5 ++++-
+ 2 files changed, 8 insertions(+), 1 deletion(-)
+
+diff --git a/python/mozbuild/mozbuild/vendor/vendor_python.py b/python/mozbuild/mozbuild/vendor/vendor_python.py
+index 9acee94..2801e1b 100644
+--- a/python/mozbuild/mozbuild/vendor/vendor_python.py
++++ b/python/mozbuild/mozbuild/vendor/vendor_python.py
+@@ -40,6 +40,10 @@ EXCLUDED_PACKAGES = {
+ # modified 'dummy' version of it so that the dependency checks still succeed, but
+ # if it ever is attempted to be used, it will fail gracefully.
+ "ansicon",
++ # jsonschema 4.17.3 is incompatible with Python 3.14+,
++ # but later versions use a dependency with Rust components, which we thus can't vendor.
++ # For now we apply the minimal patch to jsonschema to make it work again.
++ "jsonschema",
+ }
+
+
+diff --git a/third_party/python/jsonschema/jsonschema/validators.py b/third_party/python/jsonschema/jsonschema/validators.py
+index 66e803e..88316a8b 100644
+--- a/third_party/python/jsonschema/jsonschema/validators.py
++++ b/third_party/python/jsonschema/jsonschema/validators.py
+@@ -875,8 +875,11 @@ class RefResolver:
+ return None
+ uri, fragment = urldefrag(url)
+ for subschema in subschemas:
++ id = subschema["$id"]
++ if not isinstance(id, str):
++ continue
+ target_uri = self._urljoin_cache(
+- self.resolution_scope, subschema["$id"],
++ self.resolution_scope, id,
+ )
+ if target_uri.rstrip("/") == uri.rstrip("/"):
+ if fragment:
diff -Nru firefox-esr-140.13.0esr/debian/patches/fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch firefox-esr-140.15.0esr/debian/patches/fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch
--- firefox-esr-140.13.0esr/debian/patches/fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch 2026-08-19 00:51:19.000000000 +0000
@@ -0,0 +1,21 @@
+From: Mike Hommey
+Date: Wed, 19 Aug 2026 10:40:13 +0900
+Subject: Bug 2016618 - Fix Linux sandbox build breakage on glibc 2.43
+
+---
+ .../chromium/sandbox/linux/system_headers/linux_seccomp.h | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/security/sandbox/chromium/sandbox/linux/system_headers/linux_seccomp.h b/security/sandbox/chromium/sandbox/linux/system_headers/linux_seccomp.h
+index a60fe2a..d6a8503 100644
+--- a/security/sandbox/chromium/sandbox/linux/system_headers/linux_seccomp.h
++++ b/security/sandbox/chromium/sandbox/linux/system_headers/linux_seccomp.h
+@@ -5,6 +5,8 @@
+ #ifndef SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_
+ #define SANDBOX_LINUX_SYSTEM_HEADERS_LINUX_SECCOMP_H_
+
++#include // for SYS_SECCOMP
++
+ // The Seccomp2 kernel ABI is not part of older versions of glibc.
+ // As we can't break compilation with these versions of the library,
+ // we explicitly define all missing symbols.
diff -Nru firefox-esr-140.13.0esr/debian/patches/fixes/Fix-conficting-types-for-once_flag-and-call_once.patch firefox-esr-140.15.0esr/debian/patches/fixes/Fix-conficting-types-for-once_flag-and-call_once.patch
--- firefox-esr-140.13.0esr/debian/patches/fixes/Fix-conficting-types-for-once_flag-and-call_once.patch 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/fixes/Fix-conficting-types-for-once_flag-and-call_once.patch 2026-08-19 00:51:19.000000000 +0000
@@ -0,0 +1,56 @@
+From: Mike Hommey
+Date: Wed, 19 Aug 2026 09:47:43 +0900
+Subject: Fix conficting types for once_flag and call_once
+
+https://github.com/jamienicol/glsl-optimizer/commit/9913c27419488217cb3e9aa18dcda41c8dee1284
+---
+ third_party/rust/glslopt/.cargo-checksum.json | 2 +-
+ .../rust/glslopt/glsl-optimizer/include/c11/threads_posix.h | 6 ++++++
+ 2 files changed, 7 insertions(+), 1 deletion(-)
+
+diff --git a/third_party/rust/glslopt/.cargo-checksum.json b/third_party/rust/glslopt/.cargo-checksum.json
+index ddd05dac..352aac8 100644
+--- a/third_party/rust/glslopt/.cargo-checksum.json
++++ b/third_party/rust/glslopt/.cargo-checksum.json
+@@ -1 +1 @@
+-{"files":{"Cargo.toml":"010bb96167ff152e0e5ac30f9905dc749a3f038199b70c541c5d8cb97a185ee3","README.md":"4468e08c64c19977707d792bfab0080e35ff927b64990eab77873f8ba056ba1c","build.rs":"6a64610018701781af182c418a4355c9ac5d99d000be9457f0e38a7dadf7542a","glsl-optimizer/CMakeLists.txt":"42ce94744e82ffa000da8b64d81fc140e293b9f5da7dd4cf6b49e7404a2448d9","glsl-optimizer/README.md":"b18eef11a92d267d88a937b1154f7670ee433c730b102fdf7e2da0b02722b146","glsl-optimizer/contrib/glslopt/Main.cpp":"14ba213210c62e234b8d9b0052105fed28eedd83d535ebe85acc10bda7322dd4","glsl-optimizer/contrib/glslopt/Readme":"65d2a6f1aa1dc61e903e090cdade027abad33e02e7c9c81e07dc80508acadec4","glsl-optimizer/generateParsers.sh":"878a97db5d3b69eb3b4c3a95780763b373cfcc0c02e0b28894f162dbbd1b8848","glsl-optimizer/include/GL/gl.h":"1989b51365b6d7d0c48ff6e8b181ef75e2cdf71bfb1626b1cc4362e2f54854a3","glsl-optimizer/include/GL/glext.h":"2ac3681045a35a2194a81a960cad395c04bef1c8a20ef46b799fb24af3ec5f70","glsl-optimizer/include/KHR/khrplatform.h":"1448141a0c054d7f46edfb63f4fe6c203acf9591974049481c32442fb03fd6ed","glsl-optimizer/include/c11/threads.h":"56e9e592b28df19f0db432125223cb3eb5c0c1f960c22db96a15692e14776337","glsl-optimizer/include/c11/threads_posix.h":"f8ad2b69fa472e332b50572c1b2dcc1c8a0fa783a1199aad245398d3df421b4b","glsl-optimizer/include/c11/threads_win32.h":"95bf19d7fc14d328a016889afd583e4c49c050a93bcfb114bd2e9130a4532488","glsl-optimizer/include/c11_compat.h":"103fedb48f658d36cb416c9c9e5ea4d70dff181aab551fcb1028107d098ffa3e","glsl-optimizer/include/c99_compat.h":"aafad02f1ea90a7857636913ea21617a0fcd6197256dcfc6dd97bb3410ba892e","glsl-optimizer/include/no_extern_c.h":"40069dbb6dd2843658d442f926e609c7799b9c296046a90b62b570774fd618f5","glsl-optimizer/license.txt":"e26a745226f4a46b3ca00ffbe8be18507362189a2863d04b4f563ba176a9a836","glsl-optimizer/src/compiler/builtin_type_macros.h":"5b4fc4d4da7b07f997b6eb569e37db79fa0735286575ef1fab08d419e76776ff","glsl-optimizer/src/compiler/glsl/README":"e7d408b621c1b605857c4cab63902f615edb06b530142b91ac040808df6e22f7","glsl-optimizer/src/compiler/glsl/TODO":"dd3b7a098e6f9c85ca8c99ce6dea49d65bb75d4cea243b917f29e4ad2c974603","glsl-optimizer/src/compiler/glsl/ast.h":"3e68ff374350c49211a9931f7f55a485d8d89fc4b21caaffbf6655009ad95bf8","glsl-optimizer/src/compiler/glsl/ast_array_index.cpp":"92b4d501f33e0544c00d14e4f8837753afd916c2b42e076ccc95c9e8fc37ba94","glsl-optimizer/src/compiler/glsl/ast_expr.cpp":"afd712a7b1beb2b633888f4a0911b0a8e4ae5eb5ab9c1e3f247d518cdaaa56d6","glsl-optimizer/src/compiler/glsl/ast_function.cpp":"74f4fbd490e366b37f4715168bb3465ecd9334d4130942f75dcc8e80e8e7f027","glsl-optimizer/src/compiler/glsl/ast_to_hir.cpp":"d0f798eb09271d41d068b9e7b18220d37f1ed0083300ab51eba30989698fe23d","glsl-optimizer/src/compiler/glsl/ast_type.cpp":"8eb790b24b26dfb72bdc333744b566c26d8464c5d47d20eae659461f5c4899f7","glsl-optimizer/src/compiler/glsl/builtin_functions.cpp":"454189d643c220fcb49116ee5c8a34f7b349aa67564040deb8607f6a41a15e70","glsl-optimizer/src/compiler/glsl/builtin_functions.h":"a37cad7ed09b522c5b8bec7b80115a36846e7ba6e0874a2a858e32f7f202c665","glsl-optimizer/src/compiler/glsl/builtin_int64.h":"619def6f3aebf180da3944ef08f159ab12a58b24767e41d8b985ac37ded54d62","glsl-optimizer/src/compiler/glsl/builtin_types.cpp":"afec060b62d6f3b00bfbf94e9fa5f96341ce096c128d1eef322791e6ed9cea4d","glsl-optimizer/src/compiler/glsl/builtin_variables.cpp":"6563bfb1345cbca4c77e00eef09ad152f3e1dc271d246a08c5ce9e1f4ce4250a","glsl-optimizer/src/compiler/glsl/float64.glsl":"1072fd888be48c2a7a5117cd2d92a65f034965a66375f598bb856bff5d7be766","glsl-optimizer/src/compiler/glsl/generate_ir.cpp":"e5f0175370a0d07f93c48d3f0f1b8233d12c64a7b02de02dcc753ef7b398ef0f","glsl-optimizer/src/compiler/glsl/glcpp/README":"a0332a1b221d047e9cce5181a64d4ac4056046fd878360ec8ae3a7b1e062bcff","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-lex.c":"2d179879b1ffe84f58875eee5b0c19b6bae9c973b0c48e6bcd99978f2f501c80","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-lex.l":"e4c5744c837200dafd7c15a912d13f650308ea552454d4fa67271bc0a5bde118","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.c":"03494f9ce1cb82260506e2559e73a3eeb622c4bd51b65eaa0a2c3351862bd4c8","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.h":"264d9a18421cde255ce34a0a62b3d8e73465359f0d167e64aa3973062aae5bdd","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.y":"fafb66e3a8f149d19e085f18a4273ba6d4c11af9e9a01d665cc784dddf97b79f","glsl-optimizer/src/compiler/glsl/glcpp/glcpp.c":"37ed294403c2abfd17fd999d1ae8d11b170e5e9c878979fefac74a31195c96b0","glsl-optimizer/src/compiler/glsl/glcpp/glcpp.h":"85ac8b444bcbd0822b66448a1da407b6ae5467b649f5afaf5c58325bd7569468","glsl-optimizer/src/compiler/glsl/glcpp/pp.c":"a52d94f1bcb3fb2747a95709c4a77c25de7eea8354d2b83bb18efd96976a4473","glsl-optimizer/src/compiler/glsl/glcpp/pp_standalone_scaffolding.c":"d11aeb3acfe966d1b78f1ee49804093f2434214c41391d139ffcb67b69dc9862","glsl-optimizer/src/compiler/glsl/glcpp/pp_standalone_scaffolding.h":"abbf1f36ec5a92d035bfbb841b9452287d147616e56373cdbee1c0e55af46406","glsl-optimizer/src/compiler/glsl/glsl_lexer.cpp":"272b9fc1383d72b81bfc03fa11fdf82270ed91a294e523f9ce2b4554bd3effa9","glsl-optimizer/src/compiler/glsl/glsl_lexer.ll":"2b57d9f9eb830c3d7961d4533048a158ee6f458c8d05c65bea7b7cfbc36e4458","glsl-optimizer/src/compiler/glsl/glsl_optimizer.cpp":"f8095d20629d0af70be930b0612e169edb274551a1d25a3cd1bf9995a11ce2e8","glsl-optimizer/src/compiler/glsl/glsl_optimizer.h":"22e843b4ec53ba5f6cd85ca5f7bad33922dca8061b19fb512d46f1caca8d4757","glsl-optimizer/src/compiler/glsl/glsl_parser.cpp":"126baf368d525aba301854e3d91ba60b5aee32e1102376af71416f32cb95ec48","glsl-optimizer/src/compiler/glsl/glsl_parser.h":"2ea9a50716098a8f7bef782d2a030d757b68da73afb01b4d4940d3e8381d44e8","glsl-optimizer/src/compiler/glsl/glsl_parser.yy":"6b1fd1576b29fce005dff744a6dbd0219e4c695c361d61864e1f3a8d6fa6b764","glsl-optimizer/src/compiler/glsl/glsl_parser_extras.cpp":"aad64b5b66467da650091430681e8c6a820cf3cadc4db3c160bf2f15875390ae","glsl-optimizer/src/compiler/glsl/glsl_parser_extras.h":"71fd0e92bbdb193dfb067d7bfdb1200d77392be2fbd0cbfc9ca89d1bb4c7e741","glsl-optimizer/src/compiler/glsl/glsl_symbol_table.cpp":"6660fb83c0ddddbbd64581d46ccfdb9c84bfaa99d13348c289e6442ab00df046","glsl-optimizer/src/compiler/glsl/glsl_symbol_table.h":"24682b8304e0ea3f6318ddb8c859686bd1faee23cd0511d1760977ae975d41bf","glsl-optimizer/src/compiler/glsl/hir_field_selection.cpp":"72a039b0fcab4161788def9e4bedac7ac06a20d8e13146529c6d246bd5202afd","glsl-optimizer/src/compiler/glsl/int64.glsl":"303dbe95dde44b91aee3e38b115b92028400d6a92f9268975d607471984e13eb","glsl-optimizer/src/compiler/glsl/ir.cpp":"2b4741cce90b5d4abff5d719c7324e2693c67294d4d99736cb241554adb281bc","glsl-optimizer/src/compiler/glsl/ir.h":"990b1c74447c4eb4835353ccb0ed9aea644f97fc1129ef1739cd935075d85d2e","glsl-optimizer/src/compiler/glsl/ir_array_refcount.cpp":"8cdc1cffe01e42e0566fa2193a75f789628e8025ad1b82f0ee6f204451b7f9f7","glsl-optimizer/src/compiler/glsl/ir_array_refcount.h":"75f06ec81342b379096ca52e1dc0fd5f19a11ff8e9b58203c20628179d644c12","glsl-optimizer/src/compiler/glsl/ir_basic_block.cpp":"1e2920b1c0ecb08424c745c558f84d0d7e44b74585cf2cc2265dc4dfede3fa2f","glsl-optimizer/src/compiler/glsl/ir_basic_block.h":"81be7da0fc0ee547cd13ec60c1fcd7d3ce3d70d7e5e988f01a3b43a827acdf05","glsl-optimizer/src/compiler/glsl/ir_builder.cpp":"daba29c5a1efdd5a9754f420eb3e2ebdf73485273497f40d4863dadeddb23c0d","glsl-optimizer/src/compiler/glsl/ir_builder.h":"2822e74dd3f6e3df8b300af27d5b11ea2dd99d0e5e7ca809b7bbcce9833c483c","glsl-optimizer/src/compiler/glsl/ir_builder_print_visitor.cpp":"8c6df5abf2fe313363f285f171c19ca6c8ee4f3bc2ed79d33c0c88cc8be45c48","glsl-optimizer/src/compiler/glsl/ir_builder_print_visitor.h":"799852adc3a0e54d04080655e7cebfa0d3bf5b6ffed5d8414f141380665d4db7","glsl-optimizer/src/compiler/glsl/ir_clone.cpp":"d897a4e1f5bbec4a6a2f15044c1be9a4d13899c73be77335b041049a4589aa5d","glsl-optimizer/src/compiler/glsl/ir_constant_expression.cpp":"78bd87ddb09db67f6c499067728d72aef4f16aa02721a99a4b769d1e0cfa9010","glsl-optimizer/src/compiler/glsl/ir_equals.cpp":"bca28533a6310b0fc152b56d80872368f1510dc62ed6e8ac199b9ffa7fac02e7","glsl-optimizer/src/compiler/glsl/ir_expression_flattening.cpp":"7e918d4e1f237eca01396004015865ce345afe32a876c9dbc6728576a1a7eae4","glsl-optimizer/src/compiler/glsl/ir_expression_flattening.h":"f45b66aa9497520e7e08e612d24b308477c34477fbd963ee9320eac664957f16","glsl-optimizer/src/compiler/glsl/ir_expression_operation.h":"cc9f10727dbd26cac506804f51456302c702650f9eeb59054a7e1575d5cf6687","glsl-optimizer/src/compiler/glsl/ir_expression_operation.py":"7b86c96021b9fbe165957f4ecb0b612fefcde1c2cf3c6d75e3cdb22e369216ba","glsl-optimizer/src/compiler/glsl/ir_expression_operation_constant.h":"9ad3346416392e3efa11e12ecf2feca7453c5253d241eb96c91dfb85d4f2b971","glsl-optimizer/src/compiler/glsl/ir_expression_operation_strings.h":"a6826daf496a8b9e89885bc2a161ac3445d501b23c6e0ac33e2c01b506b273c8","glsl-optimizer/src/compiler/glsl/ir_function.cpp":"7537365fc0fbe4b37a26b9a2146cc64d3e9a774d60eab63b65002ad165ae8fc7","glsl-optimizer/src/compiler/glsl/ir_function_can_inline.cpp":"faddbf112187a048d502716a3fb82570a322299ba2a3abd79388382c82040bfc","glsl-optimizer/src/compiler/glsl/ir_function_detect_recursion.cpp":"9176973eaf5c0a984701f953bb7a80f37dca43d59b5bce50fc69b3f02f2902d7","glsl-optimizer/src/compiler/glsl/ir_function_inlining.h":"9739493f99c489987d650762fccdd3fb3d432f6481d67f6c799176685bd59632","glsl-optimizer/src/compiler/glsl/ir_hierarchical_visitor.cpp":"3725861fbe2b98e0617f52d3b14cf6d3b25fb5ec00f5ef5d308b03642f592767","glsl-optimizer/src/compiler/glsl/ir_hierarchical_visitor.h":"e0560210e966c0c31e4ca843e80ea154e64db5a444b8c2df845b6ba5b3a43fc1","glsl-optimizer/src/compiler/glsl/ir_hv_accept.cpp":"caf7ce2cd9494aadd3c58bcf77f29de58368dc9e347a362bbf37f8bda9509b80","glsl-optimizer/src/compiler/glsl/ir_optimization.h":"8b3dcfc7f9e96b21a8dd47a0040d90be483a9e67a2cdce3a697188fb758d4630","glsl-optimizer/src/compiler/glsl/ir_print_glsl_visitor.cpp":"f8e34a983452be0dcb5a695e9c8e895eead24f9e540992a8afe510ae85da4c4c","glsl-optimizer/src/compiler/glsl/ir_print_glsl_visitor.h":"1ad1bd3efd1ace39051c13f904c05fd80425d329444f9a8d47fd6d948faf46e0","glsl-optimizer/src/compiler/glsl/ir_print_visitor.cpp":"643f5a68aae3fb37267fd793f1216d1cfdeb2c09338c26b1f30e4c6deaef4de5","glsl-optimizer/src/compiler/glsl/ir_print_visitor.h":"4573eb93268a2654c14b505253dd651e2695d43dc745904d824da18305269b95","glsl-optimizer/src/compiler/glsl/ir_reader.cpp":"06bfba802c8354e5a8b2334b6d78d6297de18235bedd3f8fbb382c89870b02f2","glsl-optimizer/src/compiler/glsl/ir_reader.h":"63e3f7f1597936a7011d5b520e171b197bf82bee6c1560d822c3edf5aaa6f9e9","glsl-optimizer/src/compiler/glsl/ir_rvalue_visitor.cpp":"84b5c5d746555adca85759c2912fe48010232b7c1c0bd2cf03bd04067a85e66f","glsl-optimizer/src/compiler/glsl/ir_rvalue_visitor.h":"fd8c561b71085d3211fff85ed514fecb299d8ce19a04bc063419a55b6d840525","glsl-optimizer/src/compiler/glsl/ir_set_program_inouts.cpp":"ab9f115ce9e7f312d9c7978340ced0dc4ae6d13a80e08442ba9709d11d50cae5","glsl-optimizer/src/compiler/glsl/ir_uniform.h":"683ae6896b1a08470c090be5f822fc31cd434eab9216e954b9bba24a46975109","glsl-optimizer/src/compiler/glsl/ir_unused_structs.cpp":"9c1620c45f2fc071fe5ed828472040b14c5f42effe06aa0e3b8352c95ef78786","glsl-optimizer/src/compiler/glsl/ir_unused_structs.h":"13387b49c23093575276b25b9dfd31fedd8f131c5c4f3128ab04cf03e15b5295","glsl-optimizer/src/compiler/glsl/ir_validate.cpp":"6b232be5999a86ea278f4f15b2832d76843246509118d924243055a3b9b0299f","glsl-optimizer/src/compiler/glsl/ir_variable_refcount.cpp":"2764a3cad937d53f36db7447c3a5b98b04bf153acf81074d971857fc5bca460d","glsl-optimizer/src/compiler/glsl/ir_variable_refcount.h":"b0668e3eb1501ef65e38fe12830742ecb3d28e6039f30e366c8924efc29b4a39","glsl-optimizer/src/compiler/glsl/ir_visitor.h":"f21b3534c3d66d5fb707d1581fece7e1eb043523afbaedf89918cfb031c6df94","glsl-optimizer/src/compiler/glsl/link_atomics.cpp":"360f0209e11f367ba358223597b0a118bae095bff16337cf03f1fb89c5b80ca6","glsl-optimizer/src/compiler/glsl/link_functions.cpp":"de7895da8aa33a1e3c2c1eb2fdaf267ab5d1fbfdb79ae2e67f95211e946e294c","glsl-optimizer/src/compiler/glsl/link_interface_blocks.cpp":"1926cfa73810704eb19b916c1b2cdb9321155e2f98b2a0a57c7c3c6e960540cd","glsl-optimizer/src/compiler/glsl/link_uniform_block_active_visitor.cpp":"1e14e06ca3b2c1089cfba2e8eaf0c1f373d9d6374b6082f320962dd71ae09611","glsl-optimizer/src/compiler/glsl/link_uniform_block_active_visitor.h":"fd58c155af645295bb6aec08797889de586f4d919731de2bce57e8dce59bb048","glsl-optimizer/src/compiler/glsl/link_uniform_blocks.cpp":"09589f49776dce32e6c4044937de7e0c839a9754ad31960148f8f9e010658997","glsl-optimizer/src/compiler/glsl/link_uniform_initializers.cpp":"bf98e08c12db466acf9623cbeb8fa8e3b4002512722e7a6521287f558a099f37","glsl-optimizer/src/compiler/glsl/link_uniforms.cpp":"84bad5b1377362cecf259b05124239be5220b03ce1c0c61b59bd9a47e4379af2","glsl-optimizer/src/compiler/glsl/link_varyings.cpp":"a5f1a53e7c80d635515fe808ff223d89fef1767abb0f2b7aa28fa6773dca353f","glsl-optimizer/src/compiler/glsl/link_varyings.h":"b9dbe018f038df69763df2e928742ce81bbc6e3aaba26f50621e30a6d9aa6220","glsl-optimizer/src/compiler/glsl/linker.cpp":"40b1ecd5d4f6c7f13d5a87ce390561a51fdf6f3fcd9b2197b9c88b03a773ba94","glsl-optimizer/src/compiler/glsl/linker.h":"ecf94b4ad75ef461c27c557fda4bd25f34c91930822b8e1d729ec84520d4a049","glsl-optimizer/src/compiler/glsl/linker_util.cpp":"1663ad88e2a369305659aeeffaedb5bd752cf76340a2ba5797fc0bf600633cf9","glsl-optimizer/src/compiler/glsl/linker_util.h":"6db788daf9c8e87ae2764b61a8b37ebe419e69c1b82ddee01986e37c978c6993","glsl-optimizer/src/compiler/glsl/list.h":"b1f46ce0e552fe7c45b2a19408a9d97662e23e4b182ab335491c26f8cf25886f","glsl-optimizer/src/compiler/glsl/loop_analysis.cpp":"57ecd573477c68091c7cc99537faa7139a8f395935e3d4f10144cefdefb5a611","glsl-optimizer/src/compiler/glsl/loop_analysis.h":"a85f045a038ee5b5176063e85d7988865862c44ab0580f771b993a042d0b69cc","glsl-optimizer/src/compiler/glsl/loop_unroll.cpp":"bd4292ea2809f5a669bcb76ceaa1ac365772dcd638c579c3ed10275214901a54","glsl-optimizer/src/compiler/glsl/lower_blend_equation_advanced.cpp":"8cfbef140d9c4b4d2f57bfa05c9c374d31a121d0f87afce94333f049023b654a","glsl-optimizer/src/compiler/glsl/lower_buffer_access.cpp":"1ae221c3c7a95aeb867207e7a742be635f91b406c157747bfd6ddf10274d97fb","glsl-optimizer/src/compiler/glsl/lower_buffer_access.h":"807886953a576a323591798cbca5e2df24295ea893b28affd8ffb5926cebaa04","glsl-optimizer/src/compiler/glsl/lower_builtins.cpp":"4d81afc32cf58e1481fcb5e42888ab93dbe6820310a20ff7a9982b77b2152d9b","glsl-optimizer/src/compiler/glsl/lower_const_arrays_to_uniforms.cpp":"608403f0eeeedf21cfcd3014116e0f44e28cbdf6c4c32aac7e613e64e30205e1","glsl-optimizer/src/compiler/glsl/lower_cs_derived.cpp":"179905cd47a294122adeb5b0abfed6f2f67782dcde21b544d1ee2c1985154e66","glsl-optimizer/src/compiler/glsl/lower_discard.cpp":"3b361b2db0004d544d64611cb50d5a6e364cf6c5f2e60c449085d7d753dd7fb0","glsl-optimizer/src/compiler/glsl/lower_discard_flow.cpp":"f5c29b6a27690bb5c91f196d1a1cf9f6be4f1025292311fe2dac561ce6774dee","glsl-optimizer/src/compiler/glsl/lower_distance.cpp":"a118c85493d5d22b2c059a930c51a5854896d4b1dade76598eaa985e5a3dff8c","glsl-optimizer/src/compiler/glsl/lower_if_to_cond_assign.cpp":"469e617757fd1728709cce021aac5c8da05ee503bf5366977bdc4ef7a6d83950","glsl-optimizer/src/compiler/glsl/lower_instructions.cpp":"6ff5c396abe40d8a2145d571e99e2bbe9143393e15aafc28adc2803a01d821b6","glsl-optimizer/src/compiler/glsl/lower_int64.cpp":"d1ed41196880dd53c7b13e2782f9423f8442bf1d46186e8be92b1b66218a83ee","glsl-optimizer/src/compiler/glsl/lower_jumps.cpp":"34de7b493f281589fb0c2c0f6e885d0a0fabbe7a4e97a73de374dd714777a58c","glsl-optimizer/src/compiler/glsl/lower_mat_op_to_vec.cpp":"dff7a308edc4846c348ed4225c6699a9c75abac68d88f41f85954276552779f4","glsl-optimizer/src/compiler/glsl/lower_named_interface_blocks.cpp":"16063ac127bff75a68272070ab11c21c25101edbff62b4c68f4983b4cd941af0","glsl-optimizer/src/compiler/glsl/lower_offset_array.cpp":"3b00773399135aea85746a5a68b96ef000bc6841be1a2c8e6f25c516628b0949","glsl-optimizer/src/compiler/glsl/lower_output_reads.cpp":"a0fc9975d5aa1617e21fc6c353659a9802da9e83779a3eef4ec584f74b4dadc5","glsl-optimizer/src/compiler/glsl/lower_packed_varyings.cpp":"7550099d4ae123d71541c2fc88bc04fbfe9271ec75d7e210987d1c8cac3cf3ea","glsl-optimizer/src/compiler/glsl/lower_packing_builtins.cpp":"79a13d161fe505a410ab948d92769395708693ec888153630fa240e5b97e356f","glsl-optimizer/src/compiler/glsl/lower_precision.cpp":"f82a185b879872b977a1787d8061b9a80bc4cf8db1b970db6efba2ad9cc20fa2","glsl-optimizer/src/compiler/glsl/lower_shared_reference.cpp":"ea2dccf50a83bc19391bf6b7ab6aa53c0005f427af4066d25140340af9a4beef","glsl-optimizer/src/compiler/glsl/lower_subroutine.cpp":"f69fa53650eeb6f2944fce4d36a6e0a423e6705f3a3bd3389c7fadb83cfc8802","glsl-optimizer/src/compiler/glsl/lower_tess_level.cpp":"b196c9d424c0569f3e85d75c2d125af21566cb113d69036db87c0990703e0fa7","glsl-optimizer/src/compiler/glsl/lower_texture_projection.cpp":"4d247f244272adc8250fd888d8d932a140dd5de4d1efc7a58492c3c2b8291527","glsl-optimizer/src/compiler/glsl/lower_ubo_reference.cpp":"89bdbc6c1669230c644c0857db1ce2781ec61d349ecd08c7914146e1f4750a4a","glsl-optimizer/src/compiler/glsl/lower_variable_index_to_cond_assign.cpp":"fce930f29ac9405b297d1f749d68f59506b89c70b4ee1b1ab8cf49a34cc71ecf","glsl-optimizer/src/compiler/glsl/lower_vec_index_to_cond_assign.cpp":"3c67d851a11a55fad1c49a550f3a0cfe50892d33a3f238ce266cd829eba510a8","glsl-optimizer/src/compiler/glsl/lower_vec_index_to_swizzle.cpp":"f5ec666b73e1415cbab32519a53605ed385f3b03e889560373dbce69dda5000e","glsl-optimizer/src/compiler/glsl/lower_vector.cpp":"f7c13f5572ebe09b6a71553133b2cf003cd4b77b9657600672ee3b21bf890725","glsl-optimizer/src/compiler/glsl/lower_vector_derefs.cpp":"b05793da6dd620a531b43df5af8b2ecbc37b9db0c88910f5724ea10bcd057e19","glsl-optimizer/src/compiler/glsl/lower_vector_insert.cpp":"fee772ec17eea5e86a529bf9c5fa2ee0d29a5982bb75ebc6d68ed36cd19aa299","glsl-optimizer/src/compiler/glsl/lower_vertex_id.cpp":"690e8715182e03fead5cc5a35251fb4f41b357e4c71a1dfbc4bd7be19862b56d","glsl-optimizer/src/compiler/glsl/lower_xfb_varying.cpp":"58c0e8b270e4bbde54250be03cdb2f36966bcafb785372ad2e2b786835df7f9f","glsl-optimizer/src/compiler/glsl/main.cpp":"ae5e88abbbc8a12f769e1296bad938b9d7398cc6da0d3d0caeceeeb876536850","glsl-optimizer/src/compiler/glsl/opt_add_neg_to_sub.h":"f5054944bfd068810629080d0ea11df78b3f57a8f86df75e13ca50157ad1964d","glsl-optimizer/src/compiler/glsl/opt_algebraic.cpp":"25f45b20e1972ee8c789177a1aeda6e4286c25db2eae3a43ff83029ae64969c0","glsl-optimizer/src/compiler/glsl/opt_array_splitting.cpp":"19d3ce0e815438f4df9ab2890e767b03a4f3f191b53bb30c0217cf2ae6a95430","glsl-optimizer/src/compiler/glsl/opt_conditional_discard.cpp":"0e44e0e126711a3725c1f3a2aa65ff03c381fed08680ffc30101aae60f716c4e","glsl-optimizer/src/compiler/glsl/opt_constant_folding.cpp":"a088d04d9b45f9e55e235835648f614c89b7803c03a6d4f6a6d1a6bc1f0228bd","glsl-optimizer/src/compiler/glsl/opt_constant_propagation.cpp":"8a9440d77ecd6dcf13e683cbb99943aab6311c8fd4b5f6a9189a8d4f270746f4","glsl-optimizer/src/compiler/glsl/opt_constant_variable.cpp":"63d3ccd4dd09f19c9cf1a2f51592111bed41284504f29f3c0de4cadebc439a37","glsl-optimizer/src/compiler/glsl/opt_copy_propagation_elements.cpp":"ffa0f50863995e0d2e31f55a52e82319edc71e520987bebd7f7e561ea331c64b","glsl-optimizer/src/compiler/glsl/opt_dead_builtin_variables.cpp":"84e8747b948232f01dd56b428b9315f96f9511f605f240119fc446fae28981a9","glsl-optimizer/src/compiler/glsl/opt_dead_builtin_varyings.cpp":"761523e88f5b3ba785170f4d7205e94fa99acb7e74d29efbe40e1c010e1dbdb3","glsl-optimizer/src/compiler/glsl/opt_dead_code.cpp":"fd1ba2da7337d4e5dad17f5c2d73d9cc8880305f423e85d64cf94553588fa401","glsl-optimizer/src/compiler/glsl/opt_dead_code_local.cpp":"969a598b4df322baf222258a66cd64a326ea20e5b3125be9d8d1771f522c69e0","glsl-optimizer/src/compiler/glsl/opt_dead_functions.cpp":"774cae6536d02edf26e996a2a895e1f62d5098f16dc96b44798b4fc731a9a95f","glsl-optimizer/src/compiler/glsl/opt_flatten_nested_if_blocks.cpp":"3696a5c55f02e20056e085bc2714f73ac992f221b6f3387d655068e86b512046","glsl-optimizer/src/compiler/glsl/opt_flip_matrices.cpp":"44f0fe05b49329667671f88c96dc86ab3fe1459ff7b87f2b2d88de2d49829f9f","glsl-optimizer/src/compiler/glsl/opt_function_inlining.cpp":"fb56a33c90419a01676b57cbd91d0674a54cca40e6defaacc88dd33facebc131","glsl-optimizer/src/compiler/glsl/opt_if_simplification.cpp":"ac406eb35e379c357641d6c5749f50c65961455924d3dc884e2b90046fa92c5c","glsl-optimizer/src/compiler/glsl/opt_minmax.cpp":"8abd59d3b14ef60ff14a9c69660e6945f5cf10b97edb4afebe56be3f81d96316","glsl-optimizer/src/compiler/glsl/opt_rebalance_tree.cpp":"8bb6329dc0f299042368fc81934c2df019b45ab9f7aa0415d4e57b8d1ff98c9f","glsl-optimizer/src/compiler/glsl/opt_redundant_jumps.cpp":"222c73e2ac7a938ebb6428cc6c780c908ff6156d8ff935b04fed93a48fc10496","glsl-optimizer/src/compiler/glsl/opt_structure_splitting.cpp":"2edc79cc13f3177934e0443ad62f5976a1991f01f86ea303a803434849b13a47","glsl-optimizer/src/compiler/glsl/opt_swizzle.cpp":"015d0abddfe507f67c4b96c82988d861d018ededf7bf055e2bcbe9ea92da694e","glsl-optimizer/src/compiler/glsl/opt_tree_grafting.cpp":"46d28ac983ea244a4315bdc0e8892979ec4d1f9b9a96ac8a8a08006d9bc5e878","glsl-optimizer/src/compiler/glsl/opt_vectorize.cpp":"d80ee43bb97d9f016fb9c5e1e06f5b2afa569811f368ba067be794ec11d085fb","glsl-optimizer/src/compiler/glsl/program.h":"2982447e2abd35371e273ad87951722782a8b21c08294f67c39d987da1e1c55f","glsl-optimizer/src/compiler/glsl/propagate_invariance.cpp":"080943e21baa32494723a2eefb185915d2daae1f46d6df420145c5ad6857e119","glsl-optimizer/src/compiler/glsl/s_expression.cpp":"1ced972bc6ecc8eab4116ea71fb0212ab9ae5bcc0be3b47aa5d9d903566b3af1","glsl-optimizer/src/compiler/glsl/s_expression.h":"65b847e30e22a809b57d0bc70243049c99d9c6318803c5b8d0826aba55dc217e","glsl-optimizer/src/compiler/glsl/serialize.cpp":"be0eb4251348a9d921acb839a5c48c6023a2e9d116d602bb0432787ab623655d","glsl-optimizer/src/compiler/glsl/serialize.h":"57425732eba1233d928e5f07f88b623ce65af46b3bb034bf147f0a4b7f94f9a1","glsl-optimizer/src/compiler/glsl/shader_cache.cpp":"e0c5c433f2df3fccdf1d61281bfcb0ee5633433339b97c697d64db99611cbaaf","glsl-optimizer/src/compiler/glsl/shader_cache.h":"9217164d8d7f54aca0fe5922c7187095a6ae0cb703b196b79805aeef07a7e697","glsl-optimizer/src/compiler/glsl/standalone.cpp":"8e6c416a14d631261917a5fe4cc91880c287b22b2dfd70eb22028289a8fa5364","glsl-optimizer/src/compiler/glsl/standalone.h":"a7c397d1dfdd1e7fb2cfe99db35cd9df93251e642059208533202b7f20497f83","glsl-optimizer/src/compiler/glsl/standalone_scaffolding.cpp":"970d14b7a9d58e5270321f97bf5d57795558b1c570a56678e04a65b26c60bf4f","glsl-optimizer/src/compiler/glsl/standalone_scaffolding.h":"d921a617ea82b9e49413314492a645c44356de503581b1be3f1b57de236e480d","glsl-optimizer/src/compiler/glsl/string_to_uint_map.cpp":"d824bf5b839bd39498dc9e457103cdbe3e5289ddf7564107c27b1505948dd31f","glsl-optimizer/src/compiler/glsl/string_to_uint_map.h":"e2f18e66359c9d620e085de7f4a334a47df9c66e65a5bfe8b734c627bec04104","glsl-optimizer/src/compiler/glsl/test_optpass.h":"b27b8f35f5387e7ce4982bb51c7b63ccf14f91757f3108a5d02ed006925bb8a0","glsl-optimizer/src/compiler/glsl/xxd.py":"376484142f27f45090ea8203ae2621abf73f06175cb0ee8d96f44a3b9327f4bd","glsl-optimizer/src/compiler/glsl_types.cpp":"044bb6754f45419a3151e7a25c39202a82009ae3c6bc54ff7f0bb4258a5deefe","glsl-optimizer/src/compiler/glsl_types.h":"fd899a42f34ddeb8601bc3cd6c5e3aed82fc8aef4042dde1b39b3c01e1dcc219","glsl-optimizer/src/compiler/shader_enums.c":"436bff5216b11b0980bdfada5885fc6ac9afa2037a3027fcd6eea2a8635597ac","glsl-optimizer/src/compiler/shader_enums.h":"13220442a5c02e83540cf2c0ad4f8417b2fbda5f2586dec4e92082544c937cdd","glsl-optimizer/src/compiler/shader_info.h":"4c5453e81197ca83593ee4f365074b23530f2ab21c78e1733b63dec6f344c12a","glsl-optimizer/src/gallium/auxiliary/util/u_half.h":"3c2b37bda3ccb64387e44b723d29cf9046decab1a893bf42d842e9603398bdee","glsl-optimizer/src/gallium/include/pipe/p_compiler.h":"c75620096ce8523dae90599e50aa2ef6468d3b0e368a77795edeb20dd1abfc0c","glsl-optimizer/src/gallium/include/pipe/p_config.h":"a27692fc35f9e55df3224b7529e66b3001e911e94e6bc5f8f569e493e1ee3fb7","glsl-optimizer/src/gallium/include/pipe/p_defines.h":"be26d68c0acc67c5e44788c6299716a9eee415fd81d7d747e3738a829e3b6b38","glsl-optimizer/src/gallium/include/pipe/p_format.h":"5674215fc41d27496f037cf837717daefbf23ebb38d40ace7c0c414bc08182b0","glsl-optimizer/src/gallium/include/pipe/p_state.h":"d600593aba5f5a17072a6c38f6baa81e01c7994b0174250f7e433bb41684b702","glsl-optimizer/src/mapi/glapi/glapi.h":"73632a625c0ddabc401205e8b5a81eb8af8506868efe4b170d7979ec3619e9c5","glsl-optimizer/src/mesa/main/config.h":"5800259373099e5405de2eb52619f9de242552a479902a3a642a333c8cb3c1e7","glsl-optimizer/src/mesa/main/context.c":"2f3208473d99c94f734b1137ba91889d4a1babb9e7534bf1dc85d851ee98274e","glsl-optimizer/src/mesa/main/context.h":"cc7e4194797db9d007f01884e23d786c453b3860821f7f2ddcdf0f1bf3f8ffb1","glsl-optimizer/src/mesa/main/dd.h":"6a964acd06b6c2d88700e69fb75fe3c6b3b3d45bbc41db24f3f897a29695fe0c","glsl-optimizer/src/mesa/main/debug_output.h":"7312422e90b8c0e34028ac27280e438139b5cba525c99deb3ac883cd3d87e452","glsl-optimizer/src/mesa/main/draw.h":"7eaef3a9e27a60ea6f7937109bf3a6190b831162fde0479abb12077ce27c353d","glsl-optimizer/src/mesa/main/enums.h":"87d562a6764f51c014a2274fa7c3aca17c04441537ddd56b2554f13c6fffea92","glsl-optimizer/src/mesa/main/errors.h":"c79444b5df289c90fbb22a33b2d0c23917d9fc4510960088f0b79e53bb56b1b2","glsl-optimizer/src/mesa/main/extensions.h":"a38b2f87cc93c513994281350d69e06c84ff8eded5313ec0a1be33f375e0ebbd","glsl-optimizer/src/mesa/main/extensions_table.c":"17642d1a8c9a0bf2bd61060052d33ff14a005d2b962e6cf91465797a50851e85","glsl-optimizer/src/mesa/main/extensions_table.h":"2c879571c238d2e14461031ac740372fd0f9ac3a34c0d5541bb9b7ed4c0376c8","glsl-optimizer/src/mesa/main/formats.h":"02e2f7ec3e39286cf9f27e2641043e6df8ecb1dfde9e643313210e214af2a929","glsl-optimizer/src/mesa/main/glheader.h":"58217b33eead6aa6b23cd4a291cefeaa6cb84e465f4960daffca97c44d6d1c35","glsl-optimizer/src/mesa/main/glthread.h":"51fb2711f77e7eafcfc52d29d5b844978832b24c930d88accd48d143a6eb9c6f","glsl-optimizer/src/mesa/main/hash.h":"7e7f782034c16a8e693de48e00c31d4a90b0129f4029fd074033d7d16ccbe718","glsl-optimizer/src/mesa/main/macros.h":"73d15ddfd64f2b57b9b2ffeeb993b9c2c0899a80563e9d6ff337b11ccbe6eee5","glsl-optimizer/src/mesa/main/menums.h":"5dfac0e2279d60b0cd0c7b9fc2a5021620d0f6282ed2e738c420214e3af152d3","glsl-optimizer/src/mesa/main/mesa_private.h":"edda678b93438944279a551f663b8858ad84814a9fc88ba9672ef195599c24ae","glsl-optimizer/src/mesa/main/mtypes.h":"6efddefa099e4d2e3fdd97f0055644f47aba21711385edfeabc2d9b0676f2eec","glsl-optimizer/src/mesa/main/shaderobj.h":"9f0dfe96d0c2154201adef942bd36053533ac7b2492fb3786acda5bea514c75e","glsl-optimizer/src/mesa/main/uniforms.h":"4e331e6ad6e9cbded978b4082dbe0a57c1f8f01327446bb6892bfc179976c38b","glsl-optimizer/src/mesa/main/version.h":"9d0a13a758099302dc55cf7d045791834a89b0f9d4cf17b2692259b369a8a9a1","glsl-optimizer/src/mesa/math/m_matrix.h":"a37b19f182e070db3df93b0ede43c22fb8be8c2906504133ee6dbd7db1185d8b","glsl-optimizer/src/mesa/program/dummy_errors.c":"1820e305515b4c5e041f5e1623266a48ec8f076a155310be7d60637101f593e4","glsl-optimizer/src/mesa/program/ir_to_mesa.h":"b47f58d22e3ca2ae42d52501ea769d15c4476834944fa97eeccd3a3439211d00","glsl-optimizer/src/mesa/program/prog_instruction.h":"ab3832152a7e144b59e5a2264b2c29db56d93be31e76bbd958527a56771b40eb","glsl-optimizer/src/mesa/program/prog_parameter.h":"ba18c743284eadbc837c2c364c73e5d372321a7637a76e589d8d39fe8b5de225","glsl-optimizer/src/mesa/program/prog_statevars.h":"fc413698f84bc52d45fdeae0471934ee9904bfb7eac1a2b5f70446e54bcbbdca","glsl-optimizer/src/mesa/program/program.h":"1f01026a4eff440a3f122fd9b519d03546fe7f7d8be60dca834e95a2f8fbbfd2","glsl-optimizer/src/mesa/program/symbol_table.c":"6611cb9f078035bf5ff8c9112093a6c7d99f8af99a3931d0c07f227cc72283ea","glsl-optimizer/src/mesa/program/symbol_table.h":"631dc35ac48d5e87962d45507461920f6575610960ffcc42a08cefeb43300cda","glsl-optimizer/src/mesa/vbo/vbo.h":"6eb1dcd9a08c92f276c5fe08da184ff9d455d1be421913b8ad732a7b65e858fb","glsl-optimizer/src/util/bitscan.h":"9e49e694e6b34fe035bc685f32588827eb8cbe7d82878963c7ab52843e1c16aa","glsl-optimizer/src/util/bitset.h":"c40f78515c6230fed18345c6751ce33833a49da7a27901c7e6d7340cbdcbc5e7","glsl-optimizer/src/util/blob.c":"8f729846f66efc9c15485cc5fc24c6ec861fc1fecb2f652573f2a237d481b791","glsl-optimizer/src/util/blob.h":"93e1eaac866b9a7cd6fc03b533c18fb2edf0e97f03395eff4f3a605c4fc14d0c","glsl-optimizer/src/util/compiler.h":"79e3bf40a5bab704e6c949f23a1352759607bb57d80e5d8df2ef159755f10b68","glsl-optimizer/src/util/crc32.c":"2f3467a046b3a76784ecb9aa55d527698c8607fd0b12c622f6691aaa77b58505","glsl-optimizer/src/util/crc32.h":"59bd81865e51042b73a86f8fb117c312418df095fed2d828c5c1d1c8b6fc6cd4","glsl-optimizer/src/util/debug.c":"c3d68e9752ccc19e66c669562cd113cf1d0ac83cbb30174789e7fb8d1df58f9c","glsl-optimizer/src/util/debug.h":"50068d745c4199ccbd33d68dd4c8a36d2b5179c7869a21e75906ddd0718ca456","glsl-optimizer/src/util/detect_os.h":"343a8790d17a3710c6dd015ee367f84e3902ff3f2e36faca2bf93f9d725d3574","glsl-optimizer/src/util/disk_cache.c":"f533937e5a4fffe76e2739ef4b6b1e1da097d96d63eb808e68ebbc7027641c23","glsl-optimizer/src/util/disk_cache.h":"e83314fb14134a8e079b15e470a6376ba5a8253701f048c890a62b7e55d64bc8","glsl-optimizer/src/util/fast_urem_by_const.h":"e108fce804616c47d071dfe4a04163eec1126e448ed1aa89abb6b3a6d772bd5b","glsl-optimizer/src/util/fnv1a.h":"ab2596f19c6adf431ae27618f62c5743e24ad23ef83bb359a4c4c218245ab459","glsl-optimizer/src/util/format/u_format.h":"4cdfc0c59cbc99a092e5ec5a396910f2d93b9643e5d8141050b011e66f11e45b","glsl-optimizer/src/util/futex.h":"26f7c9d86e9ffef4c0fa2761f1aaa1918337302e20bd6ca10e61dc3c47356deb","glsl-optimizer/src/util/half_float.c":"11bc2584493d5d9d46e8c8a619a0307cf150bf5ab5d0f96bb764b061dc37a00e","glsl-optimizer/src/util/half_float.h":"7f7c380f126da1400a91758cc0392f24bf967bce1672890b62be26fe9fbd922b","glsl-optimizer/src/util/hash_table.c":"0ca40352e35dedab0a84c64c903f1b16d47e950bb5f43b4d22bb57d499bfea6e","glsl-optimizer/src/util/hash_table.h":"217191bb360592e2232f187473c10287d2cda8ae6fa5c53d0ef74c8c206118b4","glsl-optimizer/src/util/list.h":"9fab03c6a78186bb5f173269f825f6ce976b409d931852e3d93bac632e07989a","glsl-optimizer/src/util/macros.h":"63faf65b51058c483b17f1f77da51d1c53c8beab52678cb6bd01f1228a63b6b0","glsl-optimizer/src/util/mesa-sha1.c":"00c692ec353ebc02c06c57c5a71de0ab7a119f86a4146f452e65ec87e4944417","glsl-optimizer/src/util/mesa-sha1.h":"bff4c29f4bf7cdbcefb30fa0c996a7604a380eba8976467c2a60e7cd328f7e26","glsl-optimizer/src/util/mesa-sha1_test.c":"25da89a59d51469f77b4c468ca23ffdce0a7a1166a70b6cc23026a6800b0143c","glsl-optimizer/src/util/os_memory.h":"64555faf1760ae6954f42c83727c38dfc4c278e9152115779ffaad58b42adacf","glsl-optimizer/src/util/os_memory_aligned.h":"12d86fa94be38c13f7eeebdf313795e1267dd5a7187d2f0072e0e896f41702f6","glsl-optimizer/src/util/os_memory_stdc.h":"07360363b88c927065e10df71bebf6c8a0cc3b9167c9dfce55f2d65f11e6f787","glsl-optimizer/src/util/os_misc.c":"a9936e613ec84803abd59ad47c192c8e3939993c950ac91973fdc4cec1801bb8","glsl-optimizer/src/util/os_misc.h":"cc68eb12e05b5e749c54298cb4a6f4cd20cc5af7db3403e70b3c27b56090c740","glsl-optimizer/src/util/os_time.h":"73e775f7335244ff5964c678c27eedf1aea6abea44c4169d327ea8c7ce4a3a88","glsl-optimizer/src/util/ralloc.c":"4b51189595ef67bcef52c40cbf654d969041dbd15e15d4a893ad494ac060aeca","glsl-optimizer/src/util/ralloc.h":"e573c45875ff1530f0dbee9a93ae55535fdac8d5cc88a79ebc327c688824bde5","glsl-optimizer/src/util/rounding.h":"0450722353caf83de07e67f335949dbe95fe53b534052d4ee9d28d2781387614","glsl-optimizer/src/util/set.c":"86f8c9a830bead5a5a79bc970b0ff97809312af07b3beb39ef9d90af04d40a1b","glsl-optimizer/src/util/set.h":"3e39ca161e7ed4ec7c436cc9c7919ed9a55ed1b71edbf2caf6f9bcfd9bc578ed","glsl-optimizer/src/util/sha1/README":"00af7419af05247081858acb2902efd99fcda2ce16e331079f701645bb3729c0","glsl-optimizer/src/util/sha1/sha1.c":"1403bbe0aad42ba3e6be7e09f7cad87a6a8c4ad5b63962f7b92b9f37d8133b04","glsl-optimizer/src/util/sha1/sha1.h":"68d9f240eab2918026ecdf22be36811abbd4f1389f6c36e31258041aeaedd247","glsl-optimizer/src/util/simple_mtx.h":"12c6c3c4b7db9168bc656d5b3c65912075084d2b388c415d5c3d3f5953a9d6c7","glsl-optimizer/src/util/softfloat.c":"a97e51a96fe5e6a052c02aa6bbec683fe73fb88a8c087d9c930503e2120d8a2e","glsl-optimizer/src/util/softfloat.h":"66664b0250e83bf5dd4cc743acd119d076efcea624a0eab3d6b60718e6ee8811","glsl-optimizer/src/util/string_buffer.c":"63a1d1b1e34926c88ea00159cafbcd56568b805c4f64d1e8c97169fe313921fc","glsl-optimizer/src/util/string_buffer.h":"7b88d1b1d9c6cfb8e93331813535c127289437c75f822029e9a3bca8ea6b52ee","glsl-optimizer/src/util/strndup.h":"0273c4fdb7482cd7746881a63d3998648c6d63415ba85af1d1860f0e0dc504c6","glsl-optimizer/src/util/strtod.c":"5cf610d8a37373cf37cfb7aae903525d943b2674b1f32594c70b0eb19a8c9697","glsl-optimizer/src/util/strtod.h":"237396def4e264d35ed4bedea00ef9a4ceab6d7a11a18c770d9747d22c69ed2d","glsl-optimizer/src/util/u_atomic.h":"c02e809526c6c09ba8fe51f50b2490d1b6c8e5c7f3c4031ae958250d098fc3bb","glsl-optimizer/src/util/u_debug.c":"8c060e379b816618f3dd22c9ea523c68b9425c76c36a7dfe5d6d375b337f5f4a","glsl-optimizer/src/util/u_debug.h":"e11e26edd9b9e4e6f8e6a435e69f4d9edda27e9a379f68f4c82ea2525aaaea68","glsl-optimizer/src/util/u_dynarray.h":"853d0fa6ff2261614488be624deb8a2b01e57c2c8eabc28578cbeed4ccc95694","glsl-optimizer/src/util/u_endian.h":"3ccea7e529740318d8a4b05c00db3adc9d1e292a52bdc56a05c9fae99209720f","glsl-optimizer/src/util/u_math.c":"c868a8c0886dc78f1b06b13404ba8b253090449045774dd56893ac9d75795184","glsl-optimizer/src/util/u_math.h":"a04e32e126db016413f9de0a2028a3e71737137463b1289eae576f884b06fcf1","glsl-optimizer/src/util/u_memory.h":"c5db17c724c70283ddbe04165722f6988d4e0eb9aa3602ae472feff016649af9","glsl-optimizer/src/util/u_queue.h":"92930ce236c0528a98b695f5cea8c5c6aa9683beaf71a2227bdc5d33d1b21506","glsl-optimizer/src/util/u_string.h":"c5a2f4ef576d1547bda12c4ea219179fefa54414977743ac094abcaf696ef6ca","glsl-optimizer/src/util/u_thread.h":"00b708459b27f9910d18db92c18cc65cfc618ac2b3cd144e45f8640057b10d58","glsl-optimizer/src/util/xxhash.h":"2f2aff2fc6c0c929f52cf6ae7314122124c5be026d41ad1c357608383c4a37ad","src/bindings.rs":"79993db2058bde39f99ef483d02560d33b1cb882f6a552319e8b86eb6f9021e1","src/lib.rs":"04be1554cd829eb40864b06d80b491dd48117a4e3a601c7d482117f7a0391e67","wrapper.hpp":"f3ea34cc496f7d90b9bfcada3250b37b314c3524dac693b2ece9517bc7d274ac"},"package":"913662ae8335df058d56e00f11340b20fa82e03e0276587797ef325ab01e50d4"}
+\ No newline at end of file
++{"files":{"Cargo.toml":"010bb96167ff152e0e5ac30f9905dc749a3f038199b70c541c5d8cb97a185ee3","README.md":"4468e08c64c19977707d792bfab0080e35ff927b64990eab77873f8ba056ba1c","build.rs":"6a64610018701781af182c418a4355c9ac5d99d000be9457f0e38a7dadf7542a","glsl-optimizer/CMakeLists.txt":"42ce94744e82ffa000da8b64d81fc140e293b9f5da7dd4cf6b49e7404a2448d9","glsl-optimizer/README.md":"b18eef11a92d267d88a937b1154f7670ee433c730b102fdf7e2da0b02722b146","glsl-optimizer/contrib/glslopt/Main.cpp":"14ba213210c62e234b8d9b0052105fed28eedd83d535ebe85acc10bda7322dd4","glsl-optimizer/contrib/glslopt/Readme":"65d2a6f1aa1dc61e903e090cdade027abad33e02e7c9c81e07dc80508acadec4","glsl-optimizer/generateParsers.sh":"878a97db5d3b69eb3b4c3a95780763b373cfcc0c02e0b28894f162dbbd1b8848","glsl-optimizer/include/GL/gl.h":"1989b51365b6d7d0c48ff6e8b181ef75e2cdf71bfb1626b1cc4362e2f54854a3","glsl-optimizer/include/GL/glext.h":"2ac3681045a35a2194a81a960cad395c04bef1c8a20ef46b799fb24af3ec5f70","glsl-optimizer/include/KHR/khrplatform.h":"1448141a0c054d7f46edfb63f4fe6c203acf9591974049481c32442fb03fd6ed","glsl-optimizer/include/c11/threads.h":"56e9e592b28df19f0db432125223cb3eb5c0c1f960c22db96a15692e14776337","glsl-optimizer/include/c11/threads_posix.h":"5fa592653213459e2cce70b430715246d53fd1a10c1866acf427874530a69f92","glsl-optimizer/include/c11/threads_win32.h":"95bf19d7fc14d328a016889afd583e4c49c050a93bcfb114bd2e9130a4532488","glsl-optimizer/include/c11_compat.h":"103fedb48f658d36cb416c9c9e5ea4d70dff181aab551fcb1028107d098ffa3e","glsl-optimizer/include/c99_compat.h":"aafad02f1ea90a7857636913ea21617a0fcd6197256dcfc6dd97bb3410ba892e","glsl-optimizer/include/no_extern_c.h":"40069dbb6dd2843658d442f926e609c7799b9c296046a90b62b570774fd618f5","glsl-optimizer/license.txt":"e26a745226f4a46b3ca00ffbe8be18507362189a2863d04b4f563ba176a9a836","glsl-optimizer/src/compiler/builtin_type_macros.h":"5b4fc4d4da7b07f997b6eb569e37db79fa0735286575ef1fab08d419e76776ff","glsl-optimizer/src/compiler/glsl/README":"e7d408b621c1b605857c4cab63902f615edb06b530142b91ac040808df6e22f7","glsl-optimizer/src/compiler/glsl/TODO":"dd3b7a098e6f9c85ca8c99ce6dea49d65bb75d4cea243b917f29e4ad2c974603","glsl-optimizer/src/compiler/glsl/ast.h":"3e68ff374350c49211a9931f7f55a485d8d89fc4b21caaffbf6655009ad95bf8","glsl-optimizer/src/compiler/glsl/ast_array_index.cpp":"92b4d501f33e0544c00d14e4f8837753afd916c2b42e076ccc95c9e8fc37ba94","glsl-optimizer/src/compiler/glsl/ast_expr.cpp":"afd712a7b1beb2b633888f4a0911b0a8e4ae5eb5ab9c1e3f247d518cdaaa56d6","glsl-optimizer/src/compiler/glsl/ast_function.cpp":"74f4fbd490e366b37f4715168bb3465ecd9334d4130942f75dcc8e80e8e7f027","glsl-optimizer/src/compiler/glsl/ast_to_hir.cpp":"d0f798eb09271d41d068b9e7b18220d37f1ed0083300ab51eba30989698fe23d","glsl-optimizer/src/compiler/glsl/ast_type.cpp":"8eb790b24b26dfb72bdc333744b566c26d8464c5d47d20eae659461f5c4899f7","glsl-optimizer/src/compiler/glsl/builtin_functions.cpp":"454189d643c220fcb49116ee5c8a34f7b349aa67564040deb8607f6a41a15e70","glsl-optimizer/src/compiler/glsl/builtin_functions.h":"a37cad7ed09b522c5b8bec7b80115a36846e7ba6e0874a2a858e32f7f202c665","glsl-optimizer/src/compiler/glsl/builtin_int64.h":"619def6f3aebf180da3944ef08f159ab12a58b24767e41d8b985ac37ded54d62","glsl-optimizer/src/compiler/glsl/builtin_types.cpp":"afec060b62d6f3b00bfbf94e9fa5f96341ce096c128d1eef322791e6ed9cea4d","glsl-optimizer/src/compiler/glsl/builtin_variables.cpp":"6563bfb1345cbca4c77e00eef09ad152f3e1dc271d246a08c5ce9e1f4ce4250a","glsl-optimizer/src/compiler/glsl/float64.glsl":"1072fd888be48c2a7a5117cd2d92a65f034965a66375f598bb856bff5d7be766","glsl-optimizer/src/compiler/glsl/generate_ir.cpp":"e5f0175370a0d07f93c48d3f0f1b8233d12c64a7b02de02dcc753ef7b398ef0f","glsl-optimizer/src/compiler/glsl/glcpp/README":"a0332a1b221d047e9cce5181a64d4ac4056046fd878360ec8ae3a7b1e062bcff","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-lex.c":"2d179879b1ffe84f58875eee5b0c19b6bae9c973b0c48e6bcd99978f2f501c80","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-lex.l":"e4c5744c837200dafd7c15a912d13f650308ea552454d4fa67271bc0a5bde118","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.c":"03494f9ce1cb82260506e2559e73a3eeb622c4bd51b65eaa0a2c3351862bd4c8","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.h":"264d9a18421cde255ce34a0a62b3d8e73465359f0d167e64aa3973062aae5bdd","glsl-optimizer/src/compiler/glsl/glcpp/glcpp-parse.y":"fafb66e3a8f149d19e085f18a4273ba6d4c11af9e9a01d665cc784dddf97b79f","glsl-optimizer/src/compiler/glsl/glcpp/glcpp.c":"37ed294403c2abfd17fd999d1ae8d11b170e5e9c878979fefac74a31195c96b0","glsl-optimizer/src/compiler/glsl/glcpp/glcpp.h":"85ac8b444bcbd0822b66448a1da407b6ae5467b649f5afaf5c58325bd7569468","glsl-optimizer/src/compiler/glsl/glcpp/pp.c":"a52d94f1bcb3fb2747a95709c4a77c25de7eea8354d2b83bb18efd96976a4473","glsl-optimizer/src/compiler/glsl/glcpp/pp_standalone_scaffolding.c":"d11aeb3acfe966d1b78f1ee49804093f2434214c41391d139ffcb67b69dc9862","glsl-optimizer/src/compiler/glsl/glcpp/pp_standalone_scaffolding.h":"abbf1f36ec5a92d035bfbb841b9452287d147616e56373cdbee1c0e55af46406","glsl-optimizer/src/compiler/glsl/glsl_lexer.cpp":"272b9fc1383d72b81bfc03fa11fdf82270ed91a294e523f9ce2b4554bd3effa9","glsl-optimizer/src/compiler/glsl/glsl_lexer.ll":"2b57d9f9eb830c3d7961d4533048a158ee6f458c8d05c65bea7b7cfbc36e4458","glsl-optimizer/src/compiler/glsl/glsl_optimizer.cpp":"f8095d20629d0af70be930b0612e169edb274551a1d25a3cd1bf9995a11ce2e8","glsl-optimizer/src/compiler/glsl/glsl_optimizer.h":"22e843b4ec53ba5f6cd85ca5f7bad33922dca8061b19fb512d46f1caca8d4757","glsl-optimizer/src/compiler/glsl/glsl_parser.cpp":"126baf368d525aba301854e3d91ba60b5aee32e1102376af71416f32cb95ec48","glsl-optimizer/src/compiler/glsl/glsl_parser.h":"2ea9a50716098a8f7bef782d2a030d757b68da73afb01b4d4940d3e8381d44e8","glsl-optimizer/src/compiler/glsl/glsl_parser.yy":"6b1fd1576b29fce005dff744a6dbd0219e4c695c361d61864e1f3a8d6fa6b764","glsl-optimizer/src/compiler/glsl/glsl_parser_extras.cpp":"aad64b5b66467da650091430681e8c6a820cf3cadc4db3c160bf2f15875390ae","glsl-optimizer/src/compiler/glsl/glsl_parser_extras.h":"71fd0e92bbdb193dfb067d7bfdb1200d77392be2fbd0cbfc9ca89d1bb4c7e741","glsl-optimizer/src/compiler/glsl/glsl_symbol_table.cpp":"6660fb83c0ddddbbd64581d46ccfdb9c84bfaa99d13348c289e6442ab00df046","glsl-optimizer/src/compiler/glsl/glsl_symbol_table.h":"24682b8304e0ea3f6318ddb8c859686bd1faee23cd0511d1760977ae975d41bf","glsl-optimizer/src/compiler/glsl/hir_field_selection.cpp":"72a039b0fcab4161788def9e4bedac7ac06a20d8e13146529c6d246bd5202afd","glsl-optimizer/src/compiler/glsl/int64.glsl":"303dbe95dde44b91aee3e38b115b92028400d6a92f9268975d607471984e13eb","glsl-optimizer/src/compiler/glsl/ir.cpp":"2b4741cce90b5d4abff5d719c7324e2693c67294d4d99736cb241554adb281bc","glsl-optimizer/src/compiler/glsl/ir.h":"990b1c74447c4eb4835353ccb0ed9aea644f97fc1129ef1739cd935075d85d2e","glsl-optimizer/src/compiler/glsl/ir_array_refcount.cpp":"8cdc1cffe01e42e0566fa2193a75f789628e8025ad1b82f0ee6f204451b7f9f7","glsl-optimizer/src/compiler/glsl/ir_array_refcount.h":"75f06ec81342b379096ca52e1dc0fd5f19a11ff8e9b58203c20628179d644c12","glsl-optimizer/src/compiler/glsl/ir_basic_block.cpp":"1e2920b1c0ecb08424c745c558f84d0d7e44b74585cf2cc2265dc4dfede3fa2f","glsl-optimizer/src/compiler/glsl/ir_basic_block.h":"81be7da0fc0ee547cd13ec60c1fcd7d3ce3d70d7e5e988f01a3b43a827acdf05","glsl-optimizer/src/compiler/glsl/ir_builder.cpp":"daba29c5a1efdd5a9754f420eb3e2ebdf73485273497f40d4863dadeddb23c0d","glsl-optimizer/src/compiler/glsl/ir_builder.h":"2822e74dd3f6e3df8b300af27d5b11ea2dd99d0e5e7ca809b7bbcce9833c483c","glsl-optimizer/src/compiler/glsl/ir_builder_print_visitor.cpp":"8c6df5abf2fe313363f285f171c19ca6c8ee4f3bc2ed79d33c0c88cc8be45c48","glsl-optimizer/src/compiler/glsl/ir_builder_print_visitor.h":"799852adc3a0e54d04080655e7cebfa0d3bf5b6ffed5d8414f141380665d4db7","glsl-optimizer/src/compiler/glsl/ir_clone.cpp":"d897a4e1f5bbec4a6a2f15044c1be9a4d13899c73be77335b041049a4589aa5d","glsl-optimizer/src/compiler/glsl/ir_constant_expression.cpp":"78bd87ddb09db67f6c499067728d72aef4f16aa02721a99a4b769d1e0cfa9010","glsl-optimizer/src/compiler/glsl/ir_equals.cpp":"bca28533a6310b0fc152b56d80872368f1510dc62ed6e8ac199b9ffa7fac02e7","glsl-optimizer/src/compiler/glsl/ir_expression_flattening.cpp":"7e918d4e1f237eca01396004015865ce345afe32a876c9dbc6728576a1a7eae4","glsl-optimizer/src/compiler/glsl/ir_expression_flattening.h":"f45b66aa9497520e7e08e612d24b308477c34477fbd963ee9320eac664957f16","glsl-optimizer/src/compiler/glsl/ir_expression_operation.h":"cc9f10727dbd26cac506804f51456302c702650f9eeb59054a7e1575d5cf6687","glsl-optimizer/src/compiler/glsl/ir_expression_operation.py":"7b86c96021b9fbe165957f4ecb0b612fefcde1c2cf3c6d75e3cdb22e369216ba","glsl-optimizer/src/compiler/glsl/ir_expression_operation_constant.h":"9ad3346416392e3efa11e12ecf2feca7453c5253d241eb96c91dfb85d4f2b971","glsl-optimizer/src/compiler/glsl/ir_expression_operation_strings.h":"a6826daf496a8b9e89885bc2a161ac3445d501b23c6e0ac33e2c01b506b273c8","glsl-optimizer/src/compiler/glsl/ir_function.cpp":"7537365fc0fbe4b37a26b9a2146cc64d3e9a774d60eab63b65002ad165ae8fc7","glsl-optimizer/src/compiler/glsl/ir_function_can_inline.cpp":"faddbf112187a048d502716a3fb82570a322299ba2a3abd79388382c82040bfc","glsl-optimizer/src/compiler/glsl/ir_function_detect_recursion.cpp":"9176973eaf5c0a984701f953bb7a80f37dca43d59b5bce50fc69b3f02f2902d7","glsl-optimizer/src/compiler/glsl/ir_function_inlining.h":"9739493f99c489987d650762fccdd3fb3d432f6481d67f6c799176685bd59632","glsl-optimizer/src/compiler/glsl/ir_hierarchical_visitor.cpp":"3725861fbe2b98e0617f52d3b14cf6d3b25fb5ec00f5ef5d308b03642f592767","glsl-optimizer/src/compiler/glsl/ir_hierarchical_visitor.h":"e0560210e966c0c31e4ca843e80ea154e64db5a444b8c2df845b6ba5b3a43fc1","glsl-optimizer/src/compiler/glsl/ir_hv_accept.cpp":"caf7ce2cd9494aadd3c58bcf77f29de58368dc9e347a362bbf37f8bda9509b80","glsl-optimizer/src/compiler/glsl/ir_optimization.h":"8b3dcfc7f9e96b21a8dd47a0040d90be483a9e67a2cdce3a697188fb758d4630","glsl-optimizer/src/compiler/glsl/ir_print_glsl_visitor.cpp":"f8e34a983452be0dcb5a695e9c8e895eead24f9e540992a8afe510ae85da4c4c","glsl-optimizer/src/compiler/glsl/ir_print_glsl_visitor.h":"1ad1bd3efd1ace39051c13f904c05fd80425d329444f9a8d47fd6d948faf46e0","glsl-optimizer/src/compiler/glsl/ir_print_visitor.cpp":"643f5a68aae3fb37267fd793f1216d1cfdeb2c09338c26b1f30e4c6deaef4de5","glsl-optimizer/src/compiler/glsl/ir_print_visitor.h":"4573eb93268a2654c14b505253dd651e2695d43dc745904d824da18305269b95","glsl-optimizer/src/compiler/glsl/ir_reader.cpp":"06bfba802c8354e5a8b2334b6d78d6297de18235bedd3f8fbb382c89870b02f2","glsl-optimizer/src/compiler/glsl/ir_reader.h":"63e3f7f1597936a7011d5b520e171b197bf82bee6c1560d822c3edf5aaa6f9e9","glsl-optimizer/src/compiler/glsl/ir_rvalue_visitor.cpp":"84b5c5d746555adca85759c2912fe48010232b7c1c0bd2cf03bd04067a85e66f","glsl-optimizer/src/compiler/glsl/ir_rvalue_visitor.h":"fd8c561b71085d3211fff85ed514fecb299d8ce19a04bc063419a55b6d840525","glsl-optimizer/src/compiler/glsl/ir_set_program_inouts.cpp":"ab9f115ce9e7f312d9c7978340ced0dc4ae6d13a80e08442ba9709d11d50cae5","glsl-optimizer/src/compiler/glsl/ir_uniform.h":"683ae6896b1a08470c090be5f822fc31cd434eab9216e954b9bba24a46975109","glsl-optimizer/src/compiler/glsl/ir_unused_structs.cpp":"9c1620c45f2fc071fe5ed828472040b14c5f42effe06aa0e3b8352c95ef78786","glsl-optimizer/src/compiler/glsl/ir_unused_structs.h":"13387b49c23093575276b25b9dfd31fedd8f131c5c4f3128ab04cf03e15b5295","glsl-optimizer/src/compiler/glsl/ir_validate.cpp":"6b232be5999a86ea278f4f15b2832d76843246509118d924243055a3b9b0299f","glsl-optimizer/src/compiler/glsl/ir_variable_refcount.cpp":"2764a3cad937d53f36db7447c3a5b98b04bf153acf81074d971857fc5bca460d","glsl-optimizer/src/compiler/glsl/ir_variable_refcount.h":"b0668e3eb1501ef65e38fe12830742ecb3d28e6039f30e366c8924efc29b4a39","glsl-optimizer/src/compiler/glsl/ir_visitor.h":"f21b3534c3d66d5fb707d1581fece7e1eb043523afbaedf89918cfb031c6df94","glsl-optimizer/src/compiler/glsl/link_atomics.cpp":"360f0209e11f367ba358223597b0a118bae095bff16337cf03f1fb89c5b80ca6","glsl-optimizer/src/compiler/glsl/link_functions.cpp":"de7895da8aa33a1e3c2c1eb2fdaf267ab5d1fbfdb79ae2e67f95211e946e294c","glsl-optimizer/src/compiler/glsl/link_interface_blocks.cpp":"1926cfa73810704eb19b916c1b2cdb9321155e2f98b2a0a57c7c3c6e960540cd","glsl-optimizer/src/compiler/glsl/link_uniform_block_active_visitor.cpp":"1e14e06ca3b2c1089cfba2e8eaf0c1f373d9d6374b6082f320962dd71ae09611","glsl-optimizer/src/compiler/glsl/link_uniform_block_active_visitor.h":"fd58c155af645295bb6aec08797889de586f4d919731de2bce57e8dce59bb048","glsl-optimizer/src/compiler/glsl/link_uniform_blocks.cpp":"09589f49776dce32e6c4044937de7e0c839a9754ad31960148f8f9e010658997","glsl-optimizer/src/compiler/glsl/link_uniform_initializers.cpp":"bf98e08c12db466acf9623cbeb8fa8e3b4002512722e7a6521287f558a099f37","glsl-optimizer/src/compiler/glsl/link_uniforms.cpp":"84bad5b1377362cecf259b05124239be5220b03ce1c0c61b59bd9a47e4379af2","glsl-optimizer/src/compiler/glsl/link_varyings.cpp":"a5f1a53e7c80d635515fe808ff223d89fef1767abb0f2b7aa28fa6773dca353f","glsl-optimizer/src/compiler/glsl/link_varyings.h":"b9dbe018f038df69763df2e928742ce81bbc6e3aaba26f50621e30a6d9aa6220","glsl-optimizer/src/compiler/glsl/linker.cpp":"40b1ecd5d4f6c7f13d5a87ce390561a51fdf6f3fcd9b2197b9c88b03a773ba94","glsl-optimizer/src/compiler/glsl/linker.h":"ecf94b4ad75ef461c27c557fda4bd25f34c91930822b8e1d729ec84520d4a049","glsl-optimizer/src/compiler/glsl/linker_util.cpp":"1663ad88e2a369305659aeeffaedb5bd752cf76340a2ba5797fc0bf600633cf9","glsl-optimizer/src/compiler/glsl/linker_util.h":"6db788daf9c8e87ae2764b61a8b37ebe419e69c1b82ddee01986e37c978c6993","glsl-optimizer/src/compiler/glsl/list.h":"b1f46ce0e552fe7c45b2a19408a9d97662e23e4b182ab335491c26f8cf25886f","glsl-optimizer/src/compiler/glsl/loop_analysis.cpp":"57ecd573477c68091c7cc99537faa7139a8f395935e3d4f10144cefdefb5a611","glsl-optimizer/src/compiler/glsl/loop_analysis.h":"a85f045a038ee5b5176063e85d7988865862c44ab0580f771b993a042d0b69cc","glsl-optimizer/src/compiler/glsl/loop_unroll.cpp":"bd4292ea2809f5a669bcb76ceaa1ac365772dcd638c579c3ed10275214901a54","glsl-optimizer/src/compiler/glsl/lower_blend_equation_advanced.cpp":"8cfbef140d9c4b4d2f57bfa05c9c374d31a121d0f87afce94333f049023b654a","glsl-optimizer/src/compiler/glsl/lower_buffer_access.cpp":"1ae221c3c7a95aeb867207e7a742be635f91b406c157747bfd6ddf10274d97fb","glsl-optimizer/src/compiler/glsl/lower_buffer_access.h":"807886953a576a323591798cbca5e2df24295ea893b28affd8ffb5926cebaa04","glsl-optimizer/src/compiler/glsl/lower_builtins.cpp":"4d81afc32cf58e1481fcb5e42888ab93dbe6820310a20ff7a9982b77b2152d9b","glsl-optimizer/src/compiler/glsl/lower_const_arrays_to_uniforms.cpp":"608403f0eeeedf21cfcd3014116e0f44e28cbdf6c4c32aac7e613e64e30205e1","glsl-optimizer/src/compiler/glsl/lower_cs_derived.cpp":"179905cd47a294122adeb5b0abfed6f2f67782dcde21b544d1ee2c1985154e66","glsl-optimizer/src/compiler/glsl/lower_discard.cpp":"3b361b2db0004d544d64611cb50d5a6e364cf6c5f2e60c449085d7d753dd7fb0","glsl-optimizer/src/compiler/glsl/lower_discard_flow.cpp":"f5c29b6a27690bb5c91f196d1a1cf9f6be4f1025292311fe2dac561ce6774dee","glsl-optimizer/src/compiler/glsl/lower_distance.cpp":"a118c85493d5d22b2c059a930c51a5854896d4b1dade76598eaa985e5a3dff8c","glsl-optimizer/src/compiler/glsl/lower_if_to_cond_assign.cpp":"469e617757fd1728709cce021aac5c8da05ee503bf5366977bdc4ef7a6d83950","glsl-optimizer/src/compiler/glsl/lower_instructions.cpp":"6ff5c396abe40d8a2145d571e99e2bbe9143393e15aafc28adc2803a01d821b6","glsl-optimizer/src/compiler/glsl/lower_int64.cpp":"d1ed41196880dd53c7b13e2782f9423f8442bf1d46186e8be92b1b66218a83ee","glsl-optimizer/src/compiler/glsl/lower_jumps.cpp":"34de7b493f281589fb0c2c0f6e885d0a0fabbe7a4e97a73de374dd714777a58c","glsl-optimizer/src/compiler/glsl/lower_mat_op_to_vec.cpp":"dff7a308edc4846c348ed4225c6699a9c75abac68d88f41f85954276552779f4","glsl-optimizer/src/compiler/glsl/lower_named_interface_blocks.cpp":"16063ac127bff75a68272070ab11c21c25101edbff62b4c68f4983b4cd941af0","glsl-optimizer/src/compiler/glsl/lower_offset_array.cpp":"3b00773399135aea85746a5a68b96ef000bc6841be1a2c8e6f25c516628b0949","glsl-optimizer/src/compiler/glsl/lower_output_reads.cpp":"a0fc9975d5aa1617e21fc6c353659a9802da9e83779a3eef4ec584f74b4dadc5","glsl-optimizer/src/compiler/glsl/lower_packed_varyings.cpp":"7550099d4ae123d71541c2fc88bc04fbfe9271ec75d7e210987d1c8cac3cf3ea","glsl-optimizer/src/compiler/glsl/lower_packing_builtins.cpp":"79a13d161fe505a410ab948d92769395708693ec888153630fa240e5b97e356f","glsl-optimizer/src/compiler/glsl/lower_precision.cpp":"f82a185b879872b977a1787d8061b9a80bc4cf8db1b970db6efba2ad9cc20fa2","glsl-optimizer/src/compiler/glsl/lower_shared_reference.cpp":"ea2dccf50a83bc19391bf6b7ab6aa53c0005f427af4066d25140340af9a4beef","glsl-optimizer/src/compiler/glsl/lower_subroutine.cpp":"f69fa53650eeb6f2944fce4d36a6e0a423e6705f3a3bd3389c7fadb83cfc8802","glsl-optimizer/src/compiler/glsl/lower_tess_level.cpp":"b196c9d424c0569f3e85d75c2d125af21566cb113d69036db87c0990703e0fa7","glsl-optimizer/src/compiler/glsl/lower_texture_projection.cpp":"4d247f244272adc8250fd888d8d932a140dd5de4d1efc7a58492c3c2b8291527","glsl-optimizer/src/compiler/glsl/lower_ubo_reference.cpp":"89bdbc6c1669230c644c0857db1ce2781ec61d349ecd08c7914146e1f4750a4a","glsl-optimizer/src/compiler/glsl/lower_variable_index_to_cond_assign.cpp":"fce930f29ac9405b297d1f749d68f59506b89c70b4ee1b1ab8cf49a34cc71ecf","glsl-optimizer/src/compiler/glsl/lower_vec_index_to_cond_assign.cpp":"3c67d851a11a55fad1c49a550f3a0cfe50892d33a3f238ce266cd829eba510a8","glsl-optimizer/src/compiler/glsl/lower_vec_index_to_swizzle.cpp":"f5ec666b73e1415cbab32519a53605ed385f3b03e889560373dbce69dda5000e","glsl-optimizer/src/compiler/glsl/lower_vector.cpp":"f7c13f5572ebe09b6a71553133b2cf003cd4b77b9657600672ee3b21bf890725","glsl-optimizer/src/compiler/glsl/lower_vector_derefs.cpp":"b05793da6dd620a531b43df5af8b2ecbc37b9db0c88910f5724ea10bcd057e19","glsl-optimizer/src/compiler/glsl/lower_vector_insert.cpp":"fee772ec17eea5e86a529bf9c5fa2ee0d29a5982bb75ebc6d68ed36cd19aa299","glsl-optimizer/src/compiler/glsl/lower_vertex_id.cpp":"690e8715182e03fead5cc5a35251fb4f41b357e4c71a1dfbc4bd7be19862b56d","glsl-optimizer/src/compiler/glsl/lower_xfb_varying.cpp":"58c0e8b270e4bbde54250be03cdb2f36966bcafb785372ad2e2b786835df7f9f","glsl-optimizer/src/compiler/glsl/main.cpp":"ae5e88abbbc8a12f769e1296bad938b9d7398cc6da0d3d0caeceeeb876536850","glsl-optimizer/src/compiler/glsl/opt_add_neg_to_sub.h":"f5054944bfd068810629080d0ea11df78b3f57a8f86df75e13ca50157ad1964d","glsl-optimizer/src/compiler/glsl/opt_algebraic.cpp":"25f45b20e1972ee8c789177a1aeda6e4286c25db2eae3a43ff83029ae64969c0","glsl-optimizer/src/compiler/glsl/opt_array_splitting.cpp":"19d3ce0e815438f4df9ab2890e767b03a4f3f191b53bb30c0217cf2ae6a95430","glsl-optimizer/src/compiler/glsl/opt_conditional_discard.cpp":"0e44e0e126711a3725c1f3a2aa65ff03c381fed08680ffc30101aae60f716c4e","glsl-optimizer/src/compiler/glsl/opt_constant_folding.cpp":"a088d04d9b45f9e55e235835648f614c89b7803c03a6d4f6a6d1a6bc1f0228bd","glsl-optimizer/src/compiler/glsl/opt_constant_propagation.cpp":"8a9440d77ecd6dcf13e683cbb99943aab6311c8fd4b5f6a9189a8d4f270746f4","glsl-optimizer/src/compiler/glsl/opt_constant_variable.cpp":"63d3ccd4dd09f19c9cf1a2f51592111bed41284504f29f3c0de4cadebc439a37","glsl-optimizer/src/compiler/glsl/opt_copy_propagation_elements.cpp":"ffa0f50863995e0d2e31f55a52e82319edc71e520987bebd7f7e561ea331c64b","glsl-optimizer/src/compiler/glsl/opt_dead_builtin_variables.cpp":"84e8747b948232f01dd56b428b9315f96f9511f605f240119fc446fae28981a9","glsl-optimizer/src/compiler/glsl/opt_dead_builtin_varyings.cpp":"761523e88f5b3ba785170f4d7205e94fa99acb7e74d29efbe40e1c010e1dbdb3","glsl-optimizer/src/compiler/glsl/opt_dead_code.cpp":"fd1ba2da7337d4e5dad17f5c2d73d9cc8880305f423e85d64cf94553588fa401","glsl-optimizer/src/compiler/glsl/opt_dead_code_local.cpp":"969a598b4df322baf222258a66cd64a326ea20e5b3125be9d8d1771f522c69e0","glsl-optimizer/src/compiler/glsl/opt_dead_functions.cpp":"774cae6536d02edf26e996a2a895e1f62d5098f16dc96b44798b4fc731a9a95f","glsl-optimizer/src/compiler/glsl/opt_flatten_nested_if_blocks.cpp":"3696a5c55f02e20056e085bc2714f73ac992f221b6f3387d655068e86b512046","glsl-optimizer/src/compiler/glsl/opt_flip_matrices.cpp":"44f0fe05b49329667671f88c96dc86ab3fe1459ff7b87f2b2d88de2d49829f9f","glsl-optimizer/src/compiler/glsl/opt_function_inlining.cpp":"fb56a33c90419a01676b57cbd91d0674a54cca40e6defaacc88dd33facebc131","glsl-optimizer/src/compiler/glsl/opt_if_simplification.cpp":"ac406eb35e379c357641d6c5749f50c65961455924d3dc884e2b90046fa92c5c","glsl-optimizer/src/compiler/glsl/opt_minmax.cpp":"8abd59d3b14ef60ff14a9c69660e6945f5cf10b97edb4afebe56be3f81d96316","glsl-optimizer/src/compiler/glsl/opt_rebalance_tree.cpp":"8bb6329dc0f299042368fc81934c2df019b45ab9f7aa0415d4e57b8d1ff98c9f","glsl-optimizer/src/compiler/glsl/opt_redundant_jumps.cpp":"222c73e2ac7a938ebb6428cc6c780c908ff6156d8ff935b04fed93a48fc10496","glsl-optimizer/src/compiler/glsl/opt_structure_splitting.cpp":"2edc79cc13f3177934e0443ad62f5976a1991f01f86ea303a803434849b13a47","glsl-optimizer/src/compiler/glsl/opt_swizzle.cpp":"015d0abddfe507f67c4b96c82988d861d018ededf7bf055e2bcbe9ea92da694e","glsl-optimizer/src/compiler/glsl/opt_tree_grafting.cpp":"46d28ac983ea244a4315bdc0e8892979ec4d1f9b9a96ac8a8a08006d9bc5e878","glsl-optimizer/src/compiler/glsl/opt_vectorize.cpp":"d80ee43bb97d9f016fb9c5e1e06f5b2afa569811f368ba067be794ec11d085fb","glsl-optimizer/src/compiler/glsl/program.h":"2982447e2abd35371e273ad87951722782a8b21c08294f67c39d987da1e1c55f","glsl-optimizer/src/compiler/glsl/propagate_invariance.cpp":"080943e21baa32494723a2eefb185915d2daae1f46d6df420145c5ad6857e119","glsl-optimizer/src/compiler/glsl/s_expression.cpp":"1ced972bc6ecc8eab4116ea71fb0212ab9ae5bcc0be3b47aa5d9d903566b3af1","glsl-optimizer/src/compiler/glsl/s_expression.h":"65b847e30e22a809b57d0bc70243049c99d9c6318803c5b8d0826aba55dc217e","glsl-optimizer/src/compiler/glsl/serialize.cpp":"be0eb4251348a9d921acb839a5c48c6023a2e9d116d602bb0432787ab623655d","glsl-optimizer/src/compiler/glsl/serialize.h":"57425732eba1233d928e5f07f88b623ce65af46b3bb034bf147f0a4b7f94f9a1","glsl-optimizer/src/compiler/glsl/shader_cache.cpp":"e0c5c433f2df3fccdf1d61281bfcb0ee5633433339b97c697d64db99611cbaaf","glsl-optimizer/src/compiler/glsl/shader_cache.h":"9217164d8d7f54aca0fe5922c7187095a6ae0cb703b196b79805aeef07a7e697","glsl-optimizer/src/compiler/glsl/standalone.cpp":"8e6c416a14d631261917a5fe4cc91880c287b22b2dfd70eb22028289a8fa5364","glsl-optimizer/src/compiler/glsl/standalone.h":"a7c397d1dfdd1e7fb2cfe99db35cd9df93251e642059208533202b7f20497f83","glsl-optimizer/src/compiler/glsl/standalone_scaffolding.cpp":"970d14b7a9d58e5270321f97bf5d57795558b1c570a56678e04a65b26c60bf4f","glsl-optimizer/src/compiler/glsl/standalone_scaffolding.h":"d921a617ea82b9e49413314492a645c44356de503581b1be3f1b57de236e480d","glsl-optimizer/src/compiler/glsl/string_to_uint_map.cpp":"d824bf5b839bd39498dc9e457103cdbe3e5289ddf7564107c27b1505948dd31f","glsl-optimizer/src/compiler/glsl/string_to_uint_map.h":"e2f18e66359c9d620e085de7f4a334a47df9c66e65a5bfe8b734c627bec04104","glsl-optimizer/src/compiler/glsl/test_optpass.h":"b27b8f35f5387e7ce4982bb51c7b63ccf14f91757f3108a5d02ed006925bb8a0","glsl-optimizer/src/compiler/glsl/xxd.py":"376484142f27f45090ea8203ae2621abf73f06175cb0ee8d96f44a3b9327f4bd","glsl-optimizer/src/compiler/glsl_types.cpp":"044bb6754f45419a3151e7a25c39202a82009ae3c6bc54ff7f0bb4258a5deefe","glsl-optimizer/src/compiler/glsl_types.h":"fd899a42f34ddeb8601bc3cd6c5e3aed82fc8aef4042dde1b39b3c01e1dcc219","glsl-optimizer/src/compiler/shader_enums.c":"436bff5216b11b0980bdfada5885fc6ac9afa2037a3027fcd6eea2a8635597ac","glsl-optimizer/src/compiler/shader_enums.h":"13220442a5c02e83540cf2c0ad4f8417b2fbda5f2586dec4e92082544c937cdd","glsl-optimizer/src/compiler/shader_info.h":"4c5453e81197ca83593ee4f365074b23530f2ab21c78e1733b63dec6f344c12a","glsl-optimizer/src/gallium/auxiliary/util/u_half.h":"3c2b37bda3ccb64387e44b723d29cf9046decab1a893bf42d842e9603398bdee","glsl-optimizer/src/gallium/include/pipe/p_compiler.h":"c75620096ce8523dae90599e50aa2ef6468d3b0e368a77795edeb20dd1abfc0c","glsl-optimizer/src/gallium/include/pipe/p_config.h":"a27692fc35f9e55df3224b7529e66b3001e911e94e6bc5f8f569e493e1ee3fb7","glsl-optimizer/src/gallium/include/pipe/p_defines.h":"be26d68c0acc67c5e44788c6299716a9eee415fd81d7d747e3738a829e3b6b38","glsl-optimizer/src/gallium/include/pipe/p_format.h":"5674215fc41d27496f037cf837717daefbf23ebb38d40ace7c0c414bc08182b0","glsl-optimizer/src/gallium/include/pipe/p_state.h":"d600593aba5f5a17072a6c38f6baa81e01c7994b0174250f7e433bb41684b702","glsl-optimizer/src/mapi/glapi/glapi.h":"73632a625c0ddabc401205e8b5a81eb8af8506868efe4b170d7979ec3619e9c5","glsl-optimizer/src/mesa/main/config.h":"5800259373099e5405de2eb52619f9de242552a479902a3a642a333c8cb3c1e7","glsl-optimizer/src/mesa/main/context.c":"2f3208473d99c94f734b1137ba91889d4a1babb9e7534bf1dc85d851ee98274e","glsl-optimizer/src/mesa/main/context.h":"cc7e4194797db9d007f01884e23d786c453b3860821f7f2ddcdf0f1bf3f8ffb1","glsl-optimizer/src/mesa/main/dd.h":"6a964acd06b6c2d88700e69fb75fe3c6b3b3d45bbc41db24f3f897a29695fe0c","glsl-optimizer/src/mesa/main/debug_output.h":"7312422e90b8c0e34028ac27280e438139b5cba525c99deb3ac883cd3d87e452","glsl-optimizer/src/mesa/main/draw.h":"7eaef3a9e27a60ea6f7937109bf3a6190b831162fde0479abb12077ce27c353d","glsl-optimizer/src/mesa/main/enums.h":"87d562a6764f51c014a2274fa7c3aca17c04441537ddd56b2554f13c6fffea92","glsl-optimizer/src/mesa/main/errors.h":"c79444b5df289c90fbb22a33b2d0c23917d9fc4510960088f0b79e53bb56b1b2","glsl-optimizer/src/mesa/main/extensions.h":"a38b2f87cc93c513994281350d69e06c84ff8eded5313ec0a1be33f375e0ebbd","glsl-optimizer/src/mesa/main/extensions_table.c":"17642d1a8c9a0bf2bd61060052d33ff14a005d2b962e6cf91465797a50851e85","glsl-optimizer/src/mesa/main/extensions_table.h":"2c879571c238d2e14461031ac740372fd0f9ac3a34c0d5541bb9b7ed4c0376c8","glsl-optimizer/src/mesa/main/formats.h":"02e2f7ec3e39286cf9f27e2641043e6df8ecb1dfde9e643313210e214af2a929","glsl-optimizer/src/mesa/main/glheader.h":"58217b33eead6aa6b23cd4a291cefeaa6cb84e465f4960daffca97c44d6d1c35","glsl-optimizer/src/mesa/main/glthread.h":"51fb2711f77e7eafcfc52d29d5b844978832b24c930d88accd48d143a6eb9c6f","glsl-optimizer/src/mesa/main/hash.h":"7e7f782034c16a8e693de48e00c31d4a90b0129f4029fd074033d7d16ccbe718","glsl-optimizer/src/mesa/main/macros.h":"73d15ddfd64f2b57b9b2ffeeb993b9c2c0899a80563e9d6ff337b11ccbe6eee5","glsl-optimizer/src/mesa/main/menums.h":"5dfac0e2279d60b0cd0c7b9fc2a5021620d0f6282ed2e738c420214e3af152d3","glsl-optimizer/src/mesa/main/mesa_private.h":"edda678b93438944279a551f663b8858ad84814a9fc88ba9672ef195599c24ae","glsl-optimizer/src/mesa/main/mtypes.h":"6efddefa099e4d2e3fdd97f0055644f47aba21711385edfeabc2d9b0676f2eec","glsl-optimizer/src/mesa/main/shaderobj.h":"9f0dfe96d0c2154201adef942bd36053533ac7b2492fb3786acda5bea514c75e","glsl-optimizer/src/mesa/main/uniforms.h":"4e331e6ad6e9cbded978b4082dbe0a57c1f8f01327446bb6892bfc179976c38b","glsl-optimizer/src/mesa/main/version.h":"9d0a13a758099302dc55cf7d045791834a89b0f9d4cf17b2692259b369a8a9a1","glsl-optimizer/src/mesa/math/m_matrix.h":"a37b19f182e070db3df93b0ede43c22fb8be8c2906504133ee6dbd7db1185d8b","glsl-optimizer/src/mesa/program/dummy_errors.c":"1820e305515b4c5e041f5e1623266a48ec8f076a155310be7d60637101f593e4","glsl-optimizer/src/mesa/program/ir_to_mesa.h":"b47f58d22e3ca2ae42d52501ea769d15c4476834944fa97eeccd3a3439211d00","glsl-optimizer/src/mesa/program/prog_instruction.h":"ab3832152a7e144b59e5a2264b2c29db56d93be31e76bbd958527a56771b40eb","glsl-optimizer/src/mesa/program/prog_parameter.h":"ba18c743284eadbc837c2c364c73e5d372321a7637a76e589d8d39fe8b5de225","glsl-optimizer/src/mesa/program/prog_statevars.h":"fc413698f84bc52d45fdeae0471934ee9904bfb7eac1a2b5f70446e54bcbbdca","glsl-optimizer/src/mesa/program/program.h":"1f01026a4eff440a3f122fd9b519d03546fe7f7d8be60dca834e95a2f8fbbfd2","glsl-optimizer/src/mesa/program/symbol_table.c":"6611cb9f078035bf5ff8c9112093a6c7d99f8af99a3931d0c07f227cc72283ea","glsl-optimizer/src/mesa/program/symbol_table.h":"631dc35ac48d5e87962d45507461920f6575610960ffcc42a08cefeb43300cda","glsl-optimizer/src/mesa/vbo/vbo.h":"6eb1dcd9a08c92f276c5fe08da184ff9d455d1be421913b8ad732a7b65e858fb","glsl-optimizer/src/util/bitscan.h":"9e49e694e6b34fe035bc685f32588827eb8cbe7d82878963c7ab52843e1c16aa","glsl-optimizer/src/util/bitset.h":"c40f78515c6230fed18345c6751ce33833a49da7a27901c7e6d7340cbdcbc5e7","glsl-optimizer/src/util/blob.c":"8f729846f66efc9c15485cc5fc24c6ec861fc1fecb2f652573f2a237d481b791","glsl-optimizer/src/util/blob.h":"93e1eaac866b9a7cd6fc03b533c18fb2edf0e97f03395eff4f3a605c4fc14d0c","glsl-optimizer/src/util/compiler.h":"79e3bf40a5bab704e6c949f23a1352759607bb57d80e5d8df2ef159755f10b68","glsl-optimizer/src/util/crc32.c":"2f3467a046b3a76784ecb9aa55d527698c8607fd0b12c622f6691aaa77b58505","glsl-optimizer/src/util/crc32.h":"59bd81865e51042b73a86f8fb117c312418df095fed2d828c5c1d1c8b6fc6cd4","glsl-optimizer/src/util/debug.c":"c3d68e9752ccc19e66c669562cd113cf1d0ac83cbb30174789e7fb8d1df58f9c","glsl-optimizer/src/util/debug.h":"50068d745c4199ccbd33d68dd4c8a36d2b5179c7869a21e75906ddd0718ca456","glsl-optimizer/src/util/detect_os.h":"343a8790d17a3710c6dd015ee367f84e3902ff3f2e36faca2bf93f9d725d3574","glsl-optimizer/src/util/disk_cache.c":"f533937e5a4fffe76e2739ef4b6b1e1da097d96d63eb808e68ebbc7027641c23","glsl-optimizer/src/util/disk_cache.h":"e83314fb14134a8e079b15e470a6376ba5a8253701f048c890a62b7e55d64bc8","glsl-optimizer/src/util/fast_urem_by_const.h":"e108fce804616c47d071dfe4a04163eec1126e448ed1aa89abb6b3a6d772bd5b","glsl-optimizer/src/util/fnv1a.h":"ab2596f19c6adf431ae27618f62c5743e24ad23ef83bb359a4c4c218245ab459","glsl-optimizer/src/util/format/u_format.h":"4cdfc0c59cbc99a092e5ec5a396910f2d93b9643e5d8141050b011e66f11e45b","glsl-optimizer/src/util/futex.h":"26f7c9d86e9ffef4c0fa2761f1aaa1918337302e20bd6ca10e61dc3c47356deb","glsl-optimizer/src/util/half_float.c":"11bc2584493d5d9d46e8c8a619a0307cf150bf5ab5d0f96bb764b061dc37a00e","glsl-optimizer/src/util/half_float.h":"7f7c380f126da1400a91758cc0392f24bf967bce1672890b62be26fe9fbd922b","glsl-optimizer/src/util/hash_table.c":"0ca40352e35dedab0a84c64c903f1b16d47e950bb5f43b4d22bb57d499bfea6e","glsl-optimizer/src/util/hash_table.h":"217191bb360592e2232f187473c10287d2cda8ae6fa5c53d0ef74c8c206118b4","glsl-optimizer/src/util/list.h":"9fab03c6a78186bb5f173269f825f6ce976b409d931852e3d93bac632e07989a","glsl-optimizer/src/util/macros.h":"63faf65b51058c483b17f1f77da51d1c53c8beab52678cb6bd01f1228a63b6b0","glsl-optimizer/src/util/mesa-sha1.c":"00c692ec353ebc02c06c57c5a71de0ab7a119f86a4146f452e65ec87e4944417","glsl-optimizer/src/util/mesa-sha1.h":"bff4c29f4bf7cdbcefb30fa0c996a7604a380eba8976467c2a60e7cd328f7e26","glsl-optimizer/src/util/mesa-sha1_test.c":"25da89a59d51469f77b4c468ca23ffdce0a7a1166a70b6cc23026a6800b0143c","glsl-optimizer/src/util/os_memory.h":"64555faf1760ae6954f42c83727c38dfc4c278e9152115779ffaad58b42adacf","glsl-optimizer/src/util/os_memory_aligned.h":"12d86fa94be38c13f7eeebdf313795e1267dd5a7187d2f0072e0e896f41702f6","glsl-optimizer/src/util/os_memory_stdc.h":"07360363b88c927065e10df71bebf6c8a0cc3b9167c9dfce55f2d65f11e6f787","glsl-optimizer/src/util/os_misc.c":"a9936e613ec84803abd59ad47c192c8e3939993c950ac91973fdc4cec1801bb8","glsl-optimizer/src/util/os_misc.h":"cc68eb12e05b5e749c54298cb4a6f4cd20cc5af7db3403e70b3c27b56090c740","glsl-optimizer/src/util/os_time.h":"73e775f7335244ff5964c678c27eedf1aea6abea44c4169d327ea8c7ce4a3a88","glsl-optimizer/src/util/ralloc.c":"4b51189595ef67bcef52c40cbf654d969041dbd15e15d4a893ad494ac060aeca","glsl-optimizer/src/util/ralloc.h":"e573c45875ff1530f0dbee9a93ae55535fdac8d5cc88a79ebc327c688824bde5","glsl-optimizer/src/util/rounding.h":"0450722353caf83de07e67f335949dbe95fe53b534052d4ee9d28d2781387614","glsl-optimizer/src/util/set.c":"86f8c9a830bead5a5a79bc970b0ff97809312af07b3beb39ef9d90af04d40a1b","glsl-optimizer/src/util/set.h":"3e39ca161e7ed4ec7c436cc9c7919ed9a55ed1b71edbf2caf6f9bcfd9bc578ed","glsl-optimizer/src/util/sha1/README":"00af7419af05247081858acb2902efd99fcda2ce16e331079f701645bb3729c0","glsl-optimizer/src/util/sha1/sha1.c":"1403bbe0aad42ba3e6be7e09f7cad87a6a8c4ad5b63962f7b92b9f37d8133b04","glsl-optimizer/src/util/sha1/sha1.h":"68d9f240eab2918026ecdf22be36811abbd4f1389f6c36e31258041aeaedd247","glsl-optimizer/src/util/simple_mtx.h":"12c6c3c4b7db9168bc656d5b3c65912075084d2b388c415d5c3d3f5953a9d6c7","glsl-optimizer/src/util/softfloat.c":"a97e51a96fe5e6a052c02aa6bbec683fe73fb88a8c087d9c930503e2120d8a2e","glsl-optimizer/src/util/softfloat.h":"66664b0250e83bf5dd4cc743acd119d076efcea624a0eab3d6b60718e6ee8811","glsl-optimizer/src/util/string_buffer.c":"63a1d1b1e34926c88ea00159cafbcd56568b805c4f64d1e8c97169fe313921fc","glsl-optimizer/src/util/string_buffer.h":"7b88d1b1d9c6cfb8e93331813535c127289437c75f822029e9a3bca8ea6b52ee","glsl-optimizer/src/util/strndup.h":"0273c4fdb7482cd7746881a63d3998648c6d63415ba85af1d1860f0e0dc504c6","glsl-optimizer/src/util/strtod.c":"5cf610d8a37373cf37cfb7aae903525d943b2674b1f32594c70b0eb19a8c9697","glsl-optimizer/src/util/strtod.h":"237396def4e264d35ed4bedea00ef9a4ceab6d7a11a18c770d9747d22c69ed2d","glsl-optimizer/src/util/u_atomic.h":"c02e809526c6c09ba8fe51f50b2490d1b6c8e5c7f3c4031ae958250d098fc3bb","glsl-optimizer/src/util/u_debug.c":"8c060e379b816618f3dd22c9ea523c68b9425c76c36a7dfe5d6d375b337f5f4a","glsl-optimizer/src/util/u_debug.h":"e11e26edd9b9e4e6f8e6a435e69f4d9edda27e9a379f68f4c82ea2525aaaea68","glsl-optimizer/src/util/u_dynarray.h":"853d0fa6ff2261614488be624deb8a2b01e57c2c8eabc28578cbeed4ccc95694","glsl-optimizer/src/util/u_endian.h":"3ccea7e529740318d8a4b05c00db3adc9d1e292a52bdc56a05c9fae99209720f","glsl-optimizer/src/util/u_math.c":"c868a8c0886dc78f1b06b13404ba8b253090449045774dd56893ac9d75795184","glsl-optimizer/src/util/u_math.h":"a04e32e126db016413f9de0a2028a3e71737137463b1289eae576f884b06fcf1","glsl-optimizer/src/util/u_memory.h":"c5db17c724c70283ddbe04165722f6988d4e0eb9aa3602ae472feff016649af9","glsl-optimizer/src/util/u_queue.h":"92930ce236c0528a98b695f5cea8c5c6aa9683beaf71a2227bdc5d33d1b21506","glsl-optimizer/src/util/u_string.h":"c5a2f4ef576d1547bda12c4ea219179fefa54414977743ac094abcaf696ef6ca","glsl-optimizer/src/util/u_thread.h":"00b708459b27f9910d18db92c18cc65cfc618ac2b3cd144e45f8640057b10d58","glsl-optimizer/src/util/xxhash.h":"2f2aff2fc6c0c929f52cf6ae7314122124c5be026d41ad1c357608383c4a37ad","src/bindings.rs":"79993db2058bde39f99ef483d02560d33b1cb882f6a552319e8b86eb6f9021e1","src/lib.rs":"04be1554cd829eb40864b06d80b491dd48117a4e3a601c7d482117f7a0391e67","wrapper.hpp":"f3ea34cc496f7d90b9bfcada3250b37b314c3524dac693b2ece9517bc7d274ac"},"package":"913662ae8335df058d56e00f11340b20fa82e03e0276587797ef325ab01e50d4"}
+diff --git a/third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h b/third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h
+index 45cb6075..5f22aca 100644
+--- a/third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h
++++ b/third_party/rust/glslopt/glsl-optimizer/include/c11/threads_posix.h
+@@ -51,7 +51,9 @@ Configuration macro:
+ #include
+
+ /*---------------------------- macros ----------------------------*/
++#ifndef __once_flag_defined
+ #define ONCE_FLAG_INIT PTHREAD_ONCE_INIT
++#endif
+ #ifdef INIT_ONCE_STATIC_INIT
+ #define TSS_DTOR_ITERATIONS PTHREAD_DESTRUCTOR_ITERATIONS
+ #else
+@@ -66,7 +68,9 @@ typedef pthread_cond_t cnd_t;
+ typedef pthread_t thrd_t;
+ typedef pthread_key_t tss_t;
+ typedef pthread_mutex_t mtx_t;
++#ifndef __once_flag_defined
+ typedef pthread_once_t once_flag;
++#endif
+
+
+ /*
+@@ -90,11 +94,13 @@ impl_thrd_routine(void *p)
+
+ /*--------------- 7.25.2 Initialization functions ---------------*/
+ // 7.25.2.1
++#ifndef __once_flag_defined
+ static inline void
+ call_once(once_flag *flag, void (*func)(void))
+ {
+ pthread_once(flag, func);
+ }
++#endif
+
+
+ /*------------- 7.25.3 Condition variable functions -------------*/
diff -Nru firefox-esr-140.13.0esr/debian/patches/series firefox-esr-140.15.0esr/debian/patches/series
--- firefox-esr-140.13.0esr/debian/patches/series 2026-07-21 23:00:27.000000000 +0000
+++ firefox-esr-140.15.0esr/debian/patches/series 2026-08-19 00:51:19.000000000 +0000
@@ -1,3 +1,8 @@
+fixes/Bug-1983713-Use-non-deprecated-ast-value.-r-firefox-.patch
+fixes/Bug-1969769-Change-uses-of-ast.Str-with-ast.Constant.patch
+fixes/Bug-1983736-Patch-jsonschema-to-work-with-Python-3.1.patch
+fixes/Fix-conficting-types-for-once_flag-and-call_once.patch
+fixes/Bug-2016618-Fix-Linux-sandbox-build-breakage-on-glib.patch
debian-hacks/Avoid-wrong-sessionstore-data-to-keep-windows-out-of.patch
debian-hacks/Add-another-preferences-directory-for-applications-p.patch
debian-hacks/Add-a-2-minutes-timeout-on-xpcshell-tests.patch
diff -Nru firefox-esr-140.13.0esr/docshell/base/BrowsingContext.cpp firefox-esr-140.15.0esr/docshell/base/BrowsingContext.cpp
--- firefox-esr-140.13.0esr/docshell/base/BrowsingContext.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/docshell/base/BrowsingContext.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -865,6 +865,17 @@
parent->mOriginAttributes.EqualsIgnoringFPD(mOriginAttributes));
}
+ if (aOriginProcess) {
+ if (GetBrowserId() == 0) {
+ return "Content BC must have a nonzero BrowserId";
+ }
+ if (!GetParent()) {
+ uint64_t browserProc =
+ std::get<0>(nsContentUtils::SplitProcessSpecificId(GetBrowserId()));
+ COHERENCY_ASSERT(browserProc == aOriginProcess->ChildID());
+ }
+ }
+
// UseRemoteSubframes and UseRemoteTabs must match.
if (mUseRemoteSubframes && !mUseRemoteTabs) {
return "Cannot set useRemoteSubframes without also setting useRemoteTabs";
diff -Nru firefox-esr-140.13.0esr/docshell/base/nsDocShell.cpp firefox-esr-140.15.0esr/docshell/base/nsDocShell.cpp
--- firefox-esr-140.13.0esr/docshell/base/nsDocShell.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/docshell/base/nsDocShell.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -4293,6 +4293,11 @@
if (!aOtherDocShell) {
return NS_ERROR_INVALID_POINTER;
}
+ auto* otherDocShell = nsDocShell::Cast(aOtherDocShell);
+
+ Document* otherDoc = otherDocShell->GetDocument();
+ NS_ENSURE_TRUE(otherDoc, NS_ERROR_UNEXPECTED);
+
nsCOMPtr newURI;
nsresult rv = NS_NewURI(getter_AddRefs(newURI), aURI);
if (NS_FAILED(rv)) {
@@ -4301,7 +4306,6 @@
RefPtr loadState;
uint32_t cacheKey;
- auto* otherDocShell = nsDocShell::Cast(aOtherDocShell);
if (mozilla::SessionHistoryInParent()) {
loadState = new nsDocShellLoadState(newURI);
if (!otherDocShell->FillLoadStateFromCurrentEntry(*loadState)) {
@@ -4326,8 +4330,10 @@
// is only exposed to system code. The triggering principal for this load
// should be the system principal.
loadState->SetTriggeringPrincipal(nsContentUtils::GetSystemPrincipal());
- loadState->SetPrincipalToInherit(nullptr);
- loadState->SetPartitionedPrincipalToInherit(nullptr);
+ RefPtr nullPrincipal =
+ NullPrincipal::CreateWithInheritedAttributes(otherDoc->NodePrincipal());
+ loadState->SetPrincipalToInherit(nullPrincipal);
+ loadState->SetPartitionedPrincipalToInherit(nullPrincipal);
loadState->SetOriginalURI(nullptr);
loadState->SetResultPrincipalURI(nullptr);
@@ -12220,48 +12226,24 @@
return NS_OK;
}
+ // https://html.spec.whatwg.org/#navigate-to-a-javascript:-url
+ // Step 13: historyEntry should store entryToReplace's URL.
+ if (aLoadState->URI()->SchemeIs("javascript")) {
+ MOZ_ASSERT_UNREACHABLE("javascript: URIs should not enter session history");
+ return NS_ERROR_FAILURE;
+ }
+
// We are setting load type afterwards so we don't have to
// send it in an IPC message
aLoadState->SetLoadType(aLoadType);
- nsresult rv;
- if (aLoadState->URI()->SchemeIs("javascript")) {
- // We're loading a URL that will execute script from inside asyncOpen.
- // Replace the current document with about:blank now to prevent
- // anything from the current document from leaking into any JavaScript
- // code in the URL.
- // Don't cache the presentation if we're going to just reload the
- // current entry. Caching would lead to trying to save the different
- // content viewers in the same nsISHEntry object.
- rv = CreateAboutBlankDocumentViewer(
- aLoadState->PrincipalToInherit(),
- aLoadState->PartitionedPrincipalToInherit(), nullptr, nullptr,
- /* aIsInitialDocument */ false, Nothing(), !aLoadingCurrentEntry);
-
- if (NS_FAILED(rv)) {
- // The creation of the intermittent about:blank content
- // viewer failed for some reason (potentially because the
- // user prevented it). Interrupt the history load.
- return NS_OK;
- }
-
- if (!aLoadState->TriggeringPrincipal()) {
- // Ensure that we have a triggeringPrincipal. Otherwise javascript:
- // URIs will pick it up from the about:blank page we just loaded,
- // and we don't really want even that in this case.
- nsCOMPtr principal =
- NullPrincipal::Create(GetOriginAttributes());
- aLoadState->SetTriggeringPrincipal(principal);
- }
- }
-
/* If there is a valid postdata *and* the user pressed
* reload or shift-reload, take user's permission before we
* repost the data to the server.
*/
if ((aLoadType & LOAD_CMD_RELOAD) && aLoadState->PostDataStream()) {
bool repost;
- rv = ConfirmRepost(&repost);
+ nsresult rv = ConfirmRepost(&repost);
if (NS_FAILED(rv)) {
return rv;
}
diff -Nru firefox-esr-140.13.0esr/docshell/base/nsDocShellLoadState.cpp firefox-esr-140.15.0esr/docshell/base/nsDocShellLoadState.cpp
--- firefox-esr-140.13.0esr/docshell/base/nsDocShellLoadState.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/docshell/base/nsDocShellLoadState.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -9,15 +9,18 @@
#include "nsDocShell.h"
#include "nsILoadInfo.h"
#include "nsIProtocolHandler.h"
+#include "nsIScriptSecurityManager.h"
#include "nsISHEntry.h"
#include "nsIURIFixup.h"
#include "nsIWebNavigation.h"
#include "nsIChannel.h"
#include "nsIURLQueryStringStripper.h"
#include "nsIXULRuntime.h"
+#include "nsAboutProtocolUtils.h"
#include "nsNetUtil.h"
#include "nsQueryObject.h"
#include "ReferrerInfo.h"
+#include "xpcpublic.h"
#include "mozilla/BasePrincipal.h"
#include "mozilla/ClearOnShutdown.h"
#include "mozilla/Components.h"
@@ -26,6 +29,7 @@
#include "mozilla/dom/ContentParent.h"
#include "mozilla/dom/FormData.h"
#include "mozilla/dom/LoadURIOptionsBinding.h"
+#include "mozilla/dom/ProcessIsolation.h"
#include "mozilla/dom/nsHTTPSOnlyUtils.h"
#include "mozilla/StaticPrefs_browser.h"
#include "mozilla/StaticPrefs_fission.h"
@@ -43,6 +47,65 @@
// Global reference to the URI fixup service.
static mozilla::StaticRefPtr sURIFixup;
+static bool ContentTriggeredURILoadIsAllowed(
+ nsIURI* aURI, const nsACString& aEffectiveRemoteType) {
+ MOZ_ASSERT(aEffectiveRemoteType != NOT_REMOTE_TYPE);
+ MOZ_ASSERT(!aURI->SchemeIs("javascript"), "Should have been blocked already");
+
+ // view-source: URIs are not linkable from web content, but the "View Page
+ // Source" context menu has the content process itself load them,
+ // so decide based on the inner URI instead.
+ if (aURI->SchemeIs("view-source")) {
+ nsCOMPtr nestedURI = do_QueryInterface(aURI);
+ MOZ_ASSERT(nestedURI);
+
+ nsCOMPtr innerURI;
+ return NS_SUCCEEDED(nestedURI->GetInnerURI(getter_AddRefs(innerURI))) &&
+ ContentTriggeredURILoadIsAllowed(innerURI, aEffectiveRemoteType);
+ }
+
+ // A null principal is the least privileged principal there is, so any URI it
+ // is allowed to link to may be loaded from any content process.
+ nsCOMPtr genericNullPrincipal = NullPrincipal::Create({});
+
+ nsCOMPtr secMan =
+ do_GetService(NS_SCRIPTSECURITYMANAGER_CONTRACTID);
+
+ if (NS_SUCCEEDED(secMan->CheckLoadURIWithPrincipal(
+ genericNullPrincipal, aURI,
+ nsIScriptSecurityManager::DISALLOW_SCRIPT |
+ nsIScriptSecurityManager::DONT_REPORT_ERRORS,
+ 0))) {
+ return true;
+ }
+
+ nsCOMPtr principal =
+ BasePrincipal::CreateContentPrincipal(aURI, {});
+ if (principal->GetIsNullPrincipal()) {
+ // Only allow null principals from URIs that have the
+ // URI_LOADABLE_BY_SUBSUMERS (i.e. blob:) flag. Other null principals likely
+ // correspond to internal, unsafe-to-load in content, resources.
+ bool loadableBySubsumers = false;
+ if (NS_FAILED(NS_URIChainHasFlags(
+ aURI, nsIProtocolHandler::URI_LOADABLE_BY_SUBSUMERS,
+ &loadableBySubsumers))) {
+ return false;
+ }
+ return loadableBySubsumers;
+ }
+
+ // Automation-Only: Allow loading of chrome://reftest/* URLs.
+ if (aURI->SchemeIs("chrome") && xpc::IsInAutomation()) {
+ nsAutoCString host;
+ if (NS_SUCCEEDED(aURI->GetHost(host)) && host.EqualsLiteral("reftest")) {
+ return true;
+ }
+ }
+
+ return ValidatePrincipalCouldPotentiallyBeLoadedBy(principal,
+ aEffectiveRemoteType, {});
+}
+
nsDocShellLoadState::nsDocShellLoadState(nsIURI* aURI)
: nsDocShellLoadState(aURI, nsContentUtils::GenerateLoadIdentifier()) {}
@@ -146,9 +209,55 @@
return;
}
- if (mURI->SchemeIs("javascript") &&
- mTriggeringRemoteType != NOT_REMOTE_TYPE) {
- aActor->FatalError("Illegal cross-process javascript: load attempt");
+ if (mTriggeringRemoteType != NOT_REMOTE_TYPE) {
+ if (mURI->SchemeIs("javascript")) {
+ aActor->FatalError("Illegal cross-process javascript: load attempt");
+ return;
+ }
+
+ if (mRemoteTypeOverride.isSome()) {
+ aActor->FatalError("RemoteTypeOverride can only be set by parent");
+ return;
+ }
+ }
+
+ if (!ValidatePrincipalCouldPotentiallyBeLoadedBy(
+ mTriggeringPrincipal, GetEffectiveTriggeringRemoteType(),
+ {ValidatePrincipalOptions::AllowExpanded,
+ ValidatePrincipalOptions::AllowSystem})) {
+ aActor->FatalError(
+ "nsDocShellLoadState with invalid triggering principal");
+ return;
+ }
+ EnumSet principalToInheritOptions = {
+ ValidatePrincipalOptions::AllowNullPtr};
+ if (xpc::IsInAutomation()) {
+ // Bug 2011307, chrome reftests run in content.
+ principalToInheritOptions += ValidatePrincipalOptions::AllowSystem;
+ }
+ if (!ValidatePrincipalCouldPotentiallyBeLoadedBy(
+ mPrincipalToInherit, GetEffectiveTriggeringRemoteType(),
+ principalToInheritOptions)) {
+ aActor->FatalError("nsDocShellLoadState with invalid principalToInherit");
+ return;
+ }
+
+ const nsCString& effectiveRemoteType = GetEffectiveTriggeringRemoteType();
+ if (effectiveRemoteType != NOT_REMOTE_TYPE &&
+ !ContentTriggeredURILoadIsAllowed(mURI, effectiveRemoteType)) {
+ nsAutoCString aboutModuleOrScheme;
+ if (mURI->SchemeIs("about")) {
+ (void)NS_GetAboutModuleName(mURI, aboutModuleOrScheme);
+ aboutModuleOrScheme.InsertLiteral("about:", 0);
+ } else {
+ mURI->GetScheme(aboutModuleOrScheme);
+ aboutModuleOrScheme.AppendLiteral(":");
+ }
+ nsCString remotePrefix(RemoteTypePrefix(effectiveRemoteType));
+ aActor->FatalError(
+ nsPrintfCString("Illegal load attempt of %s URL from %s",
+ aboutModuleOrScheme.get(), remotePrefix.get())
+ .get());
return;
}
}
@@ -1302,10 +1411,17 @@
if (!uriEq(mOriginalURI, aOriginalState->mOriginalURI)) {
return "OriginalURI";
}
+ if (!uriEq(mResultPrincipalURI, aOriginalState->mResultPrincipalURI)) {
+ return "mResultPrincipalURI";
+ }
if (!uriEq(mBaseURI, aOriginalState->mBaseURI)) {
return "BaseURI";
}
+ if (mSrcdocData != aOriginalState->mSrcdocData) {
+ return "SrcdocData";
+ }
+
if (!mTriggeringPrincipal->Equals(aOriginalState->mTriggeringPrincipal)) {
return "TriggeringPrincipal";
}
diff -Nru firefox-esr-140.13.0esr/docshell/shistory/SessionHistoryEntry.cpp firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.cpp
--- firefox-esr-140.13.0esr/docshell/shistory/SessionHistoryEntry.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -59,6 +59,8 @@
aLoadState->PartitionedPrincipalToInherit(), aLoadState->Csp(),
/* FIXME Is this correct? */
aLoadState->TypeHint())) {
+ MOZ_DIAGNOSTIC_ASSERT(!mURI->SchemeIs("javascript"));
+
// Pull the upload stream off of the channel instead of the load state, as
// ownership has already been transferred from the load state to the channel.
if (nsCOMPtr postChannel = do_QueryInterface(aChannel)) {
@@ -78,6 +80,7 @@
SessionHistoryInfo::SessionHistoryInfo(
const SessionHistoryInfo& aSharedStateFrom, nsIURI* aURI)
: mURI(aURI), mSharedState(aSharedStateFrom.mSharedState) {
+ MOZ_DIAGNOSTIC_ASSERT(!mURI || !mURI->SchemeIs("javascript"));
MaybeUpdateTitleFromURI();
mHasUserInteraction = aSharedStateFrom.mHasUserInteraction;
}
@@ -91,6 +94,7 @@
mSharedState(SharedState::Create(
aTriggeringPrincipal, aPrincipalToInherit,
aPartitionedPrincipalToInherit, aCsp, aContentType)) {
+ MOZ_DIAGNOSTIC_ASSERT(!mURI || !mURI->SchemeIs("javascript"));
MaybeUpdateTitleFromURI();
}
@@ -102,6 +106,7 @@
NS_WARNING("NS_GetFinalChannelURI somehow failed in SessionHistoryInfo?");
aChannel->GetURI(getter_AddRefs(mURI));
}
+ MOZ_DIAGNOSTIC_ASSERT(!mURI->SchemeIs("javascript"));
mLoadType = aLoadType;
nsCOMPtr loadInfo;
@@ -519,6 +524,7 @@
NS_IMETHODIMP
SessionHistoryEntry::SetURI(nsIURI* aURI) {
+ MOZ_DIAGNOSTIC_ASSERT(!aURI->SchemeIs("javascript"));
mInfo->mURI = aURI;
return NS_OK;
}
@@ -1622,6 +1628,11 @@
return false;
}
+ if (aResult->mURI && aResult->mURI->SchemeIs("javascript")) {
+ aReader->FatalError("javascript: URIs should not enter session history");
+ return false;
+ }
+
nsCOMPtr triggeringPrincipal;
nsCOMPtr principalToInherit;
nsCOMPtr partitionedPrincipalToInherit;
diff -Nru firefox-esr-140.13.0esr/docshell/shistory/SessionHistoryEntry.h firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.h
--- firefox-esr-140.13.0esr/docshell/shistory/SessionHistoryEntry.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/docshell/shistory/SessionHistoryEntry.h 2026-08-26 17:03:40.000000000 +0000
@@ -119,6 +119,10 @@
mStateData = aStateData;
}
+ const Maybe& GetSrcdocData() const { return mSrcdocData; }
+
+ nsIURI* GetBaseURI() const { return mBaseURI; }
+
void SetLoadReplace(bool aLoadReplace) { mLoadReplace = aLoadReplace; }
void SetURIWasModified(bool aURIWasModified) {
diff -Nru firefox-esr-140.13.0esr/dom/base/Document.cpp firefox-esr-140.15.0esr/dom/base/Document.cpp
--- firefox-esr-140.13.0esr/dom/base/Document.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/Document.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -15244,6 +15244,12 @@
// we would actually do nothing below except crashing ourselves via
// dispatching the "MozDOMFullscreen:Exited" event to an nonexistent
// document.
+ //
+ // We still reset this document, otherwise it could keep a stale element
+ // in its top layer with the fullscreen flag set.
+ if (aMaybeNotARootDoc->GetUnretargetedFullscreenElement()) {
+ aMaybeNotARootDoc->CleanupFullscreenState();
+ }
return;
}
@@ -15729,6 +15735,7 @@
nsTArray elements;
for (const nsWeakPtr& ptr : mTopLayer) {
if (nsCOMPtr elem = do_QueryReferent(ptr)) {
+ MOZ_DIAGNOSTIC_ASSERT(elem->GetComposedDoc() == this);
elements.AppendElement(elem);
}
}
@@ -16349,6 +16356,10 @@
RefPtr doc = aRequest->Document();
doc->HideAllPopoversUntil(*hideUntil, false, true);
+ if (!FullscreenElementReadyCheck(*aRequest)) {
+ return false;
+ }
+
// Stash a reference to any existing fullscreen doc, we'll use this later
// to detect if the origin which is fullscreen has changed.
nsCOMPtr previousFullscreenDoc = GetFullscreenLeaf(this);
diff -Nru firefox-esr-140.13.0esr/dom/base/nsContentUtils.cpp firefox-esr-140.15.0esr/dom/base/nsContentUtils.cpp
--- firefox-esr-140.13.0esr/dom/base/nsContentUtils.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/nsContentUtils.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -117,6 +117,7 @@
#include "mozilla/Span.h"
#include "mozilla/StaticAnalysisFunctions.h"
#include "mozilla/StaticPrefs_browser.h"
+#include "mozilla/StaticPrefs_clipboard.h"
#include "mozilla/StaticPrefs_dom.h"
#ifdef FUZZING
# include "mozilla/StaticPrefs_fuzzing.h"
@@ -8837,11 +8838,33 @@
nsresult rv;
const nsTArray& items = aTransferableData.items();
for (const auto& item : items) {
- if (aFilterUnknownFlavors && !IPCTransferableDataItemHasKnownFlavor(item)) {
- NS_WARNING(
- "Ignoring unknown flavor in "
- "nsContentUtils::IPCTransferableDataToTransferable");
- continue;
+ if (aFilterUnknownFlavors) {
+ if (item.flavor().EqualsLiteral(kFilePromiseDirectoryMime)) {
+ NS_WARNING(
+ "Ignoring unknown flavor in "
+ "nsContentUtils::IPCTransferableDataToTransferable");
+ continue;
+ }
+
+ if ((item.flavor().EqualsLiteral(kFilePromiseMime) ||
+ item.flavor().EqualsLiteral(kFilePromiseURLMime) ||
+ item.flavor().EqualsLiteral(kFilePromiseDestFilename))
+#ifdef XP_WIN
+ && !StaticPrefs::clipboard_imageAsFile_enabled()
+#endif
+ ) {
+ NS_WARNING(
+ "Ignoring unknown flavor in "
+ "nsContentUtils::IPCTransferableDataToTransferable");
+ continue;
+ }
+
+ if (!IPCTransferableDataItemHasKnownFlavor(item)) {
+ NS_WARNING(
+ "Ignoring unknown flavor in "
+ "nsContentUtils::IPCTransferableDataToTransferable");
+ continue;
+ }
}
if (aAddDataFlavor) {
@@ -9003,17 +9026,24 @@
const uint32_t& aStride, const IntSize& aImageSize,
const SurfaceFormat& aFormat, size_t* aMaxBufferSize,
size_t* aUsedBufferSize) {
- CheckedInt32 requiredBytes =
- CheckedInt32(aStride) * CheckedInt32(aImageSize.height);
+ if (aImageSize.width <= 0 || aImageSize.height <= 0) {
+ return NS_ERROR_FAILURE;
+ }
- CheckedInt32 usedBytes =
- requiredBytes - aStride +
- (CheckedInt32(aImageSize.width) * BytesPerPixel(aFormat));
- if (!usedBytes.isValid()) {
+ CheckedInt32 rowBytes =
+ CheckedInt32(aImageSize.width) * BytesPerPixel(aFormat);
+ CheckedInt32 stride(aStride);
+ if (!rowBytes.isValid() || !stride.isValid() ||
+ stride.value() < rowBytes.value()) {
+ return NS_ERROR_FAILURE;
+ }
+
+ CheckedInt32 requiredBytes = stride * CheckedInt32(aImageSize.height);
+ CheckedInt32 usedBytes = requiredBytes - stride + rowBytes;
+ if (!requiredBytes.isValid() || !usedBytes.isValid()) {
return NS_ERROR_FAILURE;
}
- MOZ_ASSERT(requiredBytes.isValid(), "usedBytes valid but not required?");
*aMaxBufferSize = requiredBytes.value();
*aUsedBufferSize = usedBytes.value();
return NS_OK;
@@ -9652,6 +9682,12 @@
}
// static
+bool nsContentUtils::IsImageType(ExtContentPolicy aType) {
+ return aType == ExtContentPolicy::TYPE_IMAGE ||
+ aType == ExtContentPolicy::TYPE_IMAGESET;
+}
+
+// static
ReferrerPolicy nsContentUtils::GetReferrerPolicyFromChannel(
nsIChannel* aChannel) {
nsCOMPtr httpChannel = do_QueryInterface(aChannel);
diff -Nru firefox-esr-140.13.0esr/dom/base/nsContentUtils.h firefox-esr-140.15.0esr/dom/base/nsContentUtils.h
--- firefox-esr-140.13.0esr/dom/base/nsContentUtils.h 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/nsContentUtils.h 2026-08-26 17:03:40.000000000 +0000
@@ -1504,6 +1504,13 @@
static bool IsPreloadType(nsContentPolicyType aType);
/**
+ * Returns true if the content policy type is any of:
+ * * ExtContentPolicy::TYPE_IMAGE
+ * * ExtContentPolicy::TYPE_IMAGESET
+ */
+ static bool IsImageType(ExtContentPolicy aType);
+
+ /**
* Quick helper to determine whether mutation events are enabled and there are
* any mutation listeners of a given type that apply to this content or any of
* its ancestors.
diff -Nru firefox-esr-140.13.0esr/dom/base/nsFocusManager.cpp firefox-esr-140.15.0esr/dom/base/nsFocusManager.cpp
--- firefox-esr-140.13.0esr/dom/base/nsFocusManager.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/nsFocusManager.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -2449,8 +2449,9 @@
window->UpdateCommands(u"focus"_ns);
}
- SendFocusOrBlurEvent(eBlur, presShell, element->GetComposedDoc(), element,
- false, false, aElementToFocus);
+ RefPtr doc = element->GetComposedDoc();
+ SendFocusOrBlurEvent(eBlur, presShell, doc, element, false, false,
+ aElementToFocus);
}
// if we are leaving the document or the window was lowered, make the caret
diff -Nru firefox-esr-140.13.0esr/dom/base/nsFrameLoader.cpp firefox-esr-140.15.0esr/dom/base/nsFrameLoader.cpp
--- firefox-esr-140.13.0esr/dom/base/nsFrameLoader.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/nsFrameLoader.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -729,6 +729,12 @@
}
if (IsRemoteFrame()) {
+ if (!XRE_IsParentProcess() && mURIToLoad &&
+ mURIToLoad->SchemeIs("javascript")) {
+ // Web content should only be able to load javascript URIs same origin.
+ return NS_ERROR_DOM_BAD_CROSS_ORIGIN_URI;
+ }
+
if (!EnsureRemoteBrowser()) {
NS_WARNING("Couldn't create child process for iframe.");
return NS_ERROR_FAILURE;
diff -Nru firefox-esr-140.13.0esr/dom/base/nsObjectLoadingContent.cpp firefox-esr-140.15.0esr/dom/base/nsObjectLoadingContent.cpp
--- firefox-esr-140.13.0esr/dom/base/nsObjectLoadingContent.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/base/nsObjectLoadingContent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -1428,6 +1428,17 @@
return NS_ERROR_NOT_AVAILABLE;
}
+ // The channel's own security check happens in the parent process, which for
+ // a document load is only reached after the nsDocShellLoadState has already
+ // crossed IPC. Check here as well so that a load which content is not
+ // allowed to trigger never gets that far.
+ rv = nsContentUtils::GetSecurityManager()->CheckLoadURIWithPrincipal(
+ el->NodePrincipal(), mURI, nsIScriptSecurityManager::STANDARD,
+ doc->InnerWindowID());
+ if (NS_FAILED(rv)) {
+ return rv;
+ }
+
nsCOMPtr group = doc->GetDocumentLoadGroup();
nsCOMPtr chan;
RefPtr shim =
diff -Nru firefox-esr-140.13.0esr/dom/broadcastchannel/BroadcastChannel.cpp firefox-esr-140.15.0esr/dom/broadcastchannel/BroadcastChannel.cpp
--- firefox-esr-140.13.0esr/dom/broadcastchannel/BroadcastChannel.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/broadcastchannel/BroadcastChannel.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -211,6 +211,14 @@
bc->mWorkerRef = workerRef;
}
+ // Throw if this process wouldn't be allowed to access storage.
+ if (!BackgroundChild::ValidatePrincipal(unpartitionedPrincipal, {})) {
+ MOZ_ASSERT_UNREACHABLE(
+ "ValidatePrincipal failure in UnpartitionedTestingChannel");
+ aRv.Throw(NS_ERROR_UNEXPECTED);
+ return nullptr;
+ }
+
// Register this component to PBackground.
PBackgroundChild* actorChild = BackgroundChild::GetOrCreateForCurrentThread();
if (NS_WARN_IF(!actorChild)) {
@@ -334,6 +342,14 @@
return nullptr;
}
+ // Throw if this process wouldn't be allowed to access storage.
+ if (!BackgroundChild::ValidatePrincipal(storagePrincipal, {})) {
+ MOZ_ASSERT_UNREACHABLE(
+ "ValidatePrincipal failure in UnpartitionedTestingChannel");
+ aRv.Throw(NS_ERROR_UNEXPECTED);
+ return nullptr;
+ }
+
// Register this component to PBackground.
PBackgroundChild* actorChild = BackgroundChild::GetOrCreateForCurrentThread();
if (NS_WARN_IF(!actorChild)) {
diff -Nru firefox-esr-140.13.0esr/dom/cache/CacheStorage.cpp firefox-esr-140.15.0esr/dom/cache/CacheStorage.cpp
--- firefox-esr-140.13.0esr/dom/cache/CacheStorage.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cache/CacheStorage.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -272,6 +272,14 @@
mStatus(NS_OK) {
MOZ_DIAGNOSTIC_ASSERT(mGlobal);
+ // Throw if this process wouldn't be allowed to access storage.
+ if (!BackgroundChild::ValidatePrincipalInfo(*mPrincipalInfo, {})) {
+ MOZ_ASSERT_UNREACHABLE(
+ "ValidatePrincipalInfo failed in CacheStorage constructor");
+ mStatus = NS_ERROR_UNEXPECTED;
+ return;
+ }
+
// If the PBackground actor is already initialized then we can
// immediately use it
PBackgroundChild* actor = BackgroundChild::GetOrCreateForCurrentThread();
diff -Nru firefox-esr-140.13.0esr/dom/cache/DBSchema.cpp firefox-esr-140.15.0esr/dom/cache/DBSchema.cpp
--- firefox-esr-140.13.0esr/dom/cache/DBSchema.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cache/DBSchema.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -79,7 +79,7 @@
const int32_t kHackyPaddingSizePresentVersion = 27;
//
// Update this whenever the DB schema is changed.
-const int32_t kLatestSchemaVersion = 29;
+const int32_t kLatestSchemaVersion = 31;
// ---------
// The following constants define the SQL schema. These are defined in the
// same order the SQL should be executed in CreateOrMigrateSchema(). They are
@@ -148,7 +148,8 @@
"request_url_fragment TEXT NOT NULL, "
"response_padding_size INTEGER NULL, "
"request_body_disk_size INTEGER NULL, "
- "response_body_disk_size INTEGER NULL "
+ "response_body_disk_size INTEGER NULL, "
+ "response_credentials INTEGER NOT NULL "
// New columns must be added at the end of table to migrate and
// validate properly.
")";
@@ -185,6 +186,11 @@
"CREATE INDEX response_headers_name_index "
"ON response_headers (name)";
+// Index for fast lookup of headers by entry_id, particularly for vary checks
+const char kIndexResponseHeadersEntryId[] =
+ "CREATE INDEX response_headers_entry_id_index "
+ "ON response_headers (entry_id, name)";
+
const char kTableResponseUrlList[] =
"CREATE TABLE response_url_list ("
"url TEXT NOT NULL, "
@@ -544,6 +550,8 @@
aConn.ExecuteSimpleSQL(nsLiteralCString(kTableResponseHeaders))));
QM_TRY(MOZ_TO_RESULT(
aConn.ExecuteSimpleSQL(nsLiteralCString(kIndexResponseHeadersName))));
+ QM_TRY(MOZ_TO_RESULT(aConn.ExecuteSimpleSQL(
+ nsLiteralCString(kIndexResponseHeadersEntryId))));
QM_TRY(MOZ_TO_RESULT(
aConn.ExecuteSimpleSQL(nsLiteralCString(kTableResponseUrlList))));
QM_TRY(
@@ -1062,12 +1070,18 @@
return Result{std::in_place};
}
+ // We use truncated SHA-1 hashes (64 bits) in the WHERE clause for O(log n)
+ // index lookup performance. The full URL strings are retrieved in the SELECT
+ // and verified post-query to handle the extremely rare case of hash
+ // collisions. This approach avoids O(n) string comparisons in the SQL query
+ // while maintaining correctness.
+ //
+ // We use a simplified query that avoids the expensive LEFT JOIN, GROUP BY,
+ // and COUNT() operations. The vary count check is done separately only when
+ // needed, avoiding ~300μs overhead per query.
nsAutoCString query(
- "SELECT id, COUNT(response_headers.name) AS vary_count, response_type "
+ "SELECT id, response_type, request_url_no_query, request_url_query "
"FROM entries "
- "LEFT OUTER JOIN response_headers ON "
- "entries.id=response_headers.entry_id "
- "AND response_headers.name='vary' COLLATE NOCASE "
"WHERE entries.cache_id=:cache_id "
"AND entries.request_url_no_query_hash=:url_no_query_hash ");
@@ -1075,13 +1089,7 @@
query.AppendLiteral("AND entries.request_url_query_hash=:url_query_hash ");
}
- query.AppendLiteral("AND entries.request_url_no_query=:url_no_query ");
-
- if (!aParams.ignoreSearch()) {
- query.AppendLiteral("AND entries.request_url_query=:url_query ");
- }
-
- query.AppendLiteral("GROUP BY entries.id ORDER BY entries.id;");
+ query.AppendLiteral("ORDER BY entries.id;");
QM_TRY_INSPECT(const auto& state, MOZ_TO_RESULT_INVOKE_MEMBER_TYPED(
nsCOMPtr, aConn,
@@ -1108,14 +1116,6 @@
state->BindUTF8StringAsBlobByName("url_query_hash"_ns, urlQueryHash)));
}
- QM_TRY(MOZ_TO_RESULT(state->BindUTF8StringByName(
- "url_no_query"_ns, aRequest.urlWithoutQuery())));
-
- if (!aParams.ignoreSearch()) {
- QM_TRY(MOZ_TO_RESULT(
- state->BindUTF8StringByName("url_query"_ns, aRequest.urlQuery())));
- }
-
EntryIds entryIdList;
QM_TRY(CollectWhile(
@@ -1130,17 +1130,35 @@
QM_TRY_INSPECT(const EntryId& entryId,
MOZ_TO_RESULT_INVOKE_MEMBER(state, GetInt32, 0));
- QM_TRY_INSPECT(const int32_t& varyCount,
+ QM_TRY_INSPECT(const int32_t& responseType,
MOZ_TO_RESULT_INVOKE_MEMBER(state, GetInt32, 1));
- QM_TRY_INSPECT(const int32_t& responseType,
- MOZ_TO_RESULT_INVOKE_MEMBER(state, GetInt32, 2));
+ QM_TRY_INSPECT(const auto& cachedUrlNoQuery,
+ MOZ_TO_RESULT_INVOKE_MEMBER_TYPED(nsAutoCString, state,
+ GetUTF8String, 2));
+
+ QM_TRY_INSPECT(const auto& cachedUrlQuery,
+ MOZ_TO_RESULT_INVOKE_MEMBER_TYPED(nsAutoCString, state,
+ GetUTF8String, 3));
+
+ // Verify URLs match to handle potential hash collisions. We use
+ // truncated SHA-1 (64 bits) for indexing performance, but verify the
+ // full URL post-query to ensure correctness. Hash collisions are
+ // extremely rare (~1 in 92 million for 20k entries) but possible.
+ if (!aRequest.urlWithoutQuery().Equals(cachedUrlNoQuery)) {
+ return Ok{};
+ }
+
+ if (!aParams.ignoreSearch() &&
+ !aRequest.urlQuery().Equals(cachedUrlQuery)) {
+ return Ok{};
+ }
auto ignoreVary =
aParams.ignoreVary() ||
responseType == static_cast(ResponseType::Opaque);
- if (!ignoreVary && varyCount > 0) {
+ if (!ignoreVary) {
QM_TRY_INSPECT(const bool& matchedByVary,
MatchByVaryHeader(aConn, aRequest, entryId));
if (!matchedByVary) {
@@ -1182,8 +1200,10 @@
})));
}()));
- // Should not have called this function if this was not the case
- MOZ_DIAGNOSTIC_ASSERT(!varyValues.IsEmpty());
+ // If there are no vary headers, the request matches
+ if (varyValues.IsEmpty()) {
+ return true;
+ }
QM_TRY_INSPECT(const auto& state,
MOZ_TO_RESULT_INVOKE_MEMBER_TYPED(
@@ -1726,6 +1746,7 @@
"response_security_info_id, "
"response_principal_info, "
"response_padding_size, "
+ "response_credentials, "
"cache_id "
") VALUES ("
":request_method, "
@@ -1754,6 +1775,7 @@
":response_security_info_id, "
":response_principal_info, "
":response_padding_size, "
+ ":response_credentials, "
":cache_id "
");"_ns));
@@ -1876,6 +1898,10 @@
aResponse.paddingSize())));
}
+ QM_TRY(MOZ_TO_RESULT(
+ state->BindInt32ByName("response_credentials"_ns,
+ static_cast(aResponse.credentials()))));
+
QM_TRY(MOZ_TO_RESULT(state->BindInt64ByName("cache_id"_ns, aCacheId)));
QM_TRY(MOZ_TO_RESULT(state->Execute()));
@@ -1987,7 +2013,7 @@
"entries.response_principal_info, "
"entries.response_padding_size, "
"security_info.data, "
- "entries.request_credentials "
+ "entries.response_credentials "
"FROM entries "
"LEFT OUTER JOIN security_info "
"ON entries.response_security_info_id=security_info.id "
@@ -2467,6 +2493,8 @@
Expect("request_headers", "table", kTableRequestHeaders),
Expect("response_headers", "table", kTableResponseHeaders),
Expect("response_headers_name_index", "index", kIndexResponseHeadersName),
+ Expect("response_headers_entry_id_index", "index",
+ kIndexResponseHeadersEntryId),
Expect("response_url_list", "table", kTableResponseUrlList),
Expect("storage", "table", kTableStorage),
Expect("sqlite_autoindex_storage_1", "index"), // auto-gen by sqlite
@@ -2573,6 +2601,10 @@
bool& aRewriteSchema);
nsresult MigrateFrom28To29(nsIFile& aDBDir, mozIStorageConnection& aConn,
bool& aRewriteSchema);
+nsresult MigrateFrom29To30(nsIFile& aDBDir, mozIStorageConnection& aConn,
+ bool& aRewriteSchema);
+nsresult MigrateFrom30To31(nsIFile& aDBDir, mozIStorageConnection& aConn,
+ bool& aRewriteSchema);
// Configure migration functions to run for the given starting version.
constexpr Migration sMigrationList[] = {
Migration{15, MigrateFrom15To16}, Migration{16, MigrateFrom16To17},
@@ -2582,6 +2614,7 @@
Migration{23, MigrateFrom23To24}, Migration{24, MigrateFrom24To25},
Migration{25, MigrateFrom25To26}, Migration{26, MigrateFrom26To27},
Migration{27, MigrateFrom27To28}, Migration{28, MigrateFrom28To29},
+ Migration{29, MigrateFrom29To30}, Migration{30, MigrateFrom30To31},
};
nsresult RewriteEntriesSchema(mozIStorageConnection& aConn) {
@@ -3225,6 +3258,39 @@
aRewriteSchema = true;
+ return NS_OK;
+}
+
+nsresult MigrateFrom29To30(nsIFile& aDBDir, mozIStorageConnection& aConn,
+ bool& aRewriteSchema) {
+ MOZ_ASSERT(!NS_IsMainThread());
+
+ // Add an index on response_headers(entry_id, name) to dramatically speed up
+ // vary header lookups during cache matching operations.
+ QM_TRY(MOZ_TO_RESULT(
+ aConn.ExecuteSimpleSQL(nsLiteralCString(kIndexResponseHeadersEntryId))));
+
+ QM_TRY(MOZ_TO_RESULT(aConn.SetSchemaVersion(30)));
+
+ return NS_OK;
+}
+
+nsresult MigrateFrom30To31(nsIFile& aDBDir, mozIStorageConnection& aConn,
+ bool& aRewriteSchema) {
+ MOZ_ASSERT(!NS_IsMainThread());
+
+ // Existing response objects would be getting credential type set to 2,
+ // which means that these response objects can no longer be loaded by
+ // credentialless cross-origin embedders which is fine; a network fetch
+ // would need to be performed for such objects.
+ QM_TRY(MOZ_TO_RESULT(aConn.ExecuteSimpleSQL(
+ "ALTER TABLE entries "
+ "ADD COLUMN response_credentials INTEGER NOT NULL DEFAULT 2;"_ns)));
+
+ QM_TRY(MOZ_TO_RESULT(aConn.SetSchemaVersion(31)));
+
+ aRewriteSchema = true;
+
return NS_OK;
}
diff -Nru firefox-esr-140.13.0esr/dom/cache/PrincipalVerifier.cpp firefox-esr-140.15.0esr/dom/cache/PrincipalVerifier.cpp
--- firefox-esr-140.13.0esr/dom/cache/PrincipalVerifier.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cache/PrincipalVerifier.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -8,6 +8,7 @@
#include "ErrorList.h"
#include "mozilla/dom/ContentParent.h"
+#include "mozilla/dom/ProcessIsolation.h"
#include "mozilla/dom/QMResult.h"
#include "mozilla/dom/cache/ManagerId.h"
#include "mozilla/dom/quota/ResultExtensions.h"
@@ -99,6 +100,12 @@
const auto& principal, PrincipalInfoToPrincipal(mPrincipalInfo), QM_VOID,
[this](const nsresult result) { DispatchToInitiatingThread(result); });
+ if (NS_WARN_IF(mHandle && !ValidatePrincipalCouldPotentiallyBeLoadedBy(
+ principal, mHandle->GetRemoteType(), {}))) {
+ DispatchToInitiatingThread(NS_ERROR_FAILURE);
+ return;
+ }
+
// We disallow null principal on the client side, but double-check here.
if (NS_WARN_IF(principal->GetIsNullPrincipal())) {
DispatchToInitiatingThread(NS_ERROR_FAILURE);
diff -Nru firefox-esr-140.13.0esr/dom/cache/TypeUtils.cpp firefox-esr-140.15.0esr/dom/cache/TypeUtils.cpp
--- firefox-esr-140.13.0esr/dom/cache/TypeUtils.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cache/TypeUtils.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -199,6 +199,9 @@
aOut.paddingInfo() = aIn.GetPaddingInfo();
aOut.paddingSize() = aIn.GetPaddingSize();
+
+ // Record the credentials mode of the fetch that produced this response.
+ aOut.credentials() = aIn.GetCredentialsMode();
}
void TypeUtils::ToCacheResponse(JSContext* aCx, CacheResponse& aOut,
diff -Nru firefox-esr-140.13.0esr/dom/cache/test/mochitest/test_chrome_constructor.html firefox-esr-140.15.0esr/dom/cache/test/mochitest/test_chrome_constructor.html
--- firefox-esr-140.13.0esr/dom/cache/test/mochitest/test_chrome_constructor.html 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cache/test/mochitest/test_chrome_constructor.html 2026-08-26 17:03:41.000000000 +0000
@@ -14,12 +14,11 @@
SpecialPowers.pushPrefEnv({
"set": [[ "dom.caches.testing.enabled", true ]],
}, function() {
- // attach to a different origin's CacheStorage
- var url = "https://example.com/";
- var storage = SpecialPowers.createChromeCache("content", url);
+ // attach to our origin's CacheStorage.
+ var storage = SpecialPowers.createChromeCache("content", window.location.origin);
- // verify we can use the other origin's CacheStorage as normal
- var req = new Request("https://example.com/index.html");
+ // verify we can our origin's CacheStorage as normal
+ var req = new Request(`${window.location.origin}/index.html`);
var res = new Response("hello world");
var cache;
storage.open("foo").then(function(c) {
diff -Nru firefox-esr-140.13.0esr/dom/canvas/TexUnpackBlob.cpp firefox-esr-140.15.0esr/dom/canvas/TexUnpackBlob.cpp
--- firefox-esr-140.13.0esr/dom/canvas/TexUnpackBlob.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/TexUnpackBlob.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -397,11 +397,17 @@
WebGLTexelFormat dstFormat, const ptrdiff_t dstStride,
const uint8_t** const out_begin,
UniqueBuffer* const out_anchoredBuffer) const {
- MOZ_ASSERT(srcFormat != WebGLTexelFormat::FormatNotSupportingAnyConversion);
- MOZ_ASSERT(dstFormat != WebGLTexelFormat::FormatNotSupportingAnyConversion);
-
*out_begin = srcBegin;
+ // TexelBytesForFormat() has no size for these, so the stride validation below
+ // would be vacuous. Bail before it rather than relying on ConvertImage() to
+ // reject them.
+ if (srcFormat == WebGLTexelFormat::FormatNotSupportingAnyConversion ||
+ dstFormat == WebGLTexelFormat::FormatNotSupportingAnyConversion) {
+ webgl->ErrorImplementationBug("Unconvertible texel format.");
+ return false;
+ }
+
const auto& unpacking = mDesc.unpacking;
if (!rowLength || !rowCount) return true;
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLBuffer.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLBuffer.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLBuffer.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLBuffer.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -77,22 +77,9 @@
void WebGLBuffer::BufferData(const GLenum target, const uint64_t size,
const void* const maybeData, const GLenum usage,
bool allowUninitialized) {
- // The driver knows only GLsizeiptr, which is int32_t on 32bit!
- bool sizeValid = CheckedInt(size).isValid();
-
- if (mContext->gl->WorkAroundDriverBugs()) {
- // Bug 790879
-#if defined(XP_MACOSX) || defined(MOZ_WIDGET_GTK)
- sizeValid &= CheckedInt(size).isValid();
-#endif
-
- // Bug 1610383
- if (mContext->gl->IsANGLE()) {
- // While ANGLE seems to support up to `unsigned int`, UINT32_MAX-4 causes
- // GL_OUT_OF_MEMORY in glFlush??
- sizeValid &= CheckedInt(size).isValid();
- }
- }
+ // Bug 790879
+ // Bug 1610383
+ bool sizeValid = CheckedInt(size).isValid();
if (!sizeValid) {
mContext->ErrorOutOfMemory("Size not valid for platform: %" PRIu64, size);
@@ -276,7 +263,7 @@
for (const auto& cur : mIndexRanges) {
const auto& range = cur.first;
const auto& indexByteSize = IndexByteSizeByType(range.type);
- const auto rangeBegin = range.byteOffset * indexByteSize;
+ const auto rangeBegin = range.byteOffset;
const auto rangeEnd =
rangeBegin + uint64_t(range.indexCount) * indexByteSize;
if (rangeBegin >= updateEnd || rangeEnd <= updateBegin) continue;
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLContext.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLContext.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLContext.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLContext.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -2108,21 +2108,21 @@
// --
-uint64_t AvailGroups(const uint64_t totalAvailItems,
+uint64_t AvailGroups(const uint64_t totalAvailItemBytes,
const uint64_t firstItemOffset, const uint32_t groupSize,
const uint32_t groupStride) {
MOZ_ASSERT(groupSize && groupStride);
- MOZ_ASSERT(groupSize <= groupStride);
- if (totalAvailItems <= firstItemOffset) return 0;
- const size_t availItems = totalAvailItems - firstItemOffset;
+ if (totalAvailItemBytes <= firstItemOffset) {
+ return 0;
+ }
- size_t availGroups = availItems / groupStride;
- const size_t tailItems = availItems % groupStride;
- if (tailItems >= groupSize) {
- availGroups += 1;
+ const size_t availItemBytes = totalAvailItemBytes - firstItemOffset;
+ if (availItemBytes < groupSize) {
+ return 0;
}
- return availGroups;
+
+ return (availItemBytes - groupSize) / groupStride + 1;
}
////////////////////////////////////////////////////////////////////////////////
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLContext.h firefox-esr-140.15.0esr/dom/canvas/WebGLContext.h
--- firefox-esr-140.13.0esr/dom/canvas/WebGLContext.h 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLContext.h 2026-08-26 17:03:40.000000000 +0000
@@ -1451,7 +1451,7 @@
int32_t* out_intRead0, int32_t* out_intWrite0,
int32_t* out_intSize);
-uint64_t AvailGroups(uint64_t totalAvailItems, uint64_t firstItemOffset,
+uint64_t AvailGroups(uint64_t totalAvailItemBytes, uint64_t firstItemOffset,
uint32_t groupSize, uint32_t groupStride);
////
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLContextDraw.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLContextDraw.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLContextDraw.cpp 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLContextDraw.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -639,8 +639,12 @@
const auto usedVerts =
CheckedInt(usedVertsPerInstance) * instanceCount;
- const auto remainingCapacity =
- mTFO->mActive_VertCapacity - mTFO->mActive_VertPosition;
+ // The position can exceed the capacity if a bound buffer was shrunk while
+ // the TF was paused.
+ const size_t remainingCapacity =
+ mTFO->mActive_VertCapacity > mTFO->mActive_VertPosition
+ ? mTFO->mActive_VertCapacity - mTFO->mActive_VertPosition
+ : 0;
if (!usedVerts.isValid() || usedVerts.value() > remainingCapacity) {
mWebGL->ErrorInvalidOperation(
"Insufficient buffer capacity remaining for"
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLFramebuffer.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLFramebuffer.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLFramebuffer.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLFramebuffer.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -893,6 +893,11 @@
const uint32_t drawBuffer =
cur->mAttachmentPoint - LOCAL_GL_COLOR_ATTACHMENT0;
MOZ_ASSERT(drawBuffer <= 100);
+ std::vector drawBuffersForClear(drawBuffer + 1,
+ LOCAL_GL_NONE);
+ drawBuffersForClear[drawBuffer] = cur->mAttachmentPoint;
+ gl->fDrawBuffers(drawBuffersForClear.size(),
+ drawBuffersForClear.data());
switch (format->componentType) {
case webgl::ComponentType::Int:
gl->fClearBufferiv(LOCAL_GL_COLOR, drawBuffer, iZeros);
@@ -924,6 +929,7 @@
}
imageInfo->mUninitializedSlices.reset();
}
+ RefreshDrawBuffers();
return;
}
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLTexelConversions.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLTexelConversions.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -65,12 +65,15 @@
case WebGLTexelFormat::RGBA8:
case WebGLTexelFormat::RGBA16F:
case WebGLTexelFormat::RGBA32F:
+ case WebGLTexelFormat::RGBX8:
case WebGLTexelFormat::BGRX8:
case WebGLTexelFormat::BGRA8:
return 4;
default:
- MOZ_ASSERT(false, "Unknown texel format. Coding mistake?");
- return 0;
+ // Returning 0 here would make the conversion loop below a no-op that
+ // still reports success, leaving the destination uninitialized; crash
+ // in all build types instead.
+ MOZ_CRASH("GFX: Unknown texel format. Coding mistake?");
}
}
@@ -107,13 +110,14 @@
}
// Only textures uploaded from DOM elements or ImageData can allow DstFormat
- // != SrcFormat. DOM elements can only give BGRA8, BGRX8, A8, RGB565
- // formats. See DOMElementToImageSurface. ImageData is always RGBA8. So all
+ // != SrcFormat. DOM elements can only give BGRA8, BGRX8, RGBX8, A8, RGB565
+ // formats. See GetFormatForSurf. ImageData is always RGBA8. So all
// other SrcFormat will always satisfy DstFormat==SrcFormat, so we can avoid
// compiling the code for all the unreachable paths.
const bool CanSrcFormatComeFromDOMElementOrImageData =
SrcFormat == WebGLTexelFormat::BGRA8 ||
SrcFormat == WebGLTexelFormat::BGRX8 ||
+ SrcFormat == WebGLTexelFormat::RGBX8 ||
SrcFormat == WebGLTexelFormat::A8 ||
SrcFormat == WebGLTexelFormat::RGB565 ||
SrcFormat == WebGLTexelFormat::RGBA8;
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLTexelConversions.h firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.h
--- firefox-esr-140.13.0esr/dom/canvas/WebGLTexelConversions.h 2026-07-15 20:30:28.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLTexelConversions.h 2026-08-26 17:03:40.000000000 +0000
@@ -280,6 +280,38 @@
}
}
+MOZ_ALWAYS_INLINE float unpackFromFloat11(uint16_t fp11) {
+ const uint32_t exponent = (fp11 >> 6) & 0x1F;
+ const uint32_t mantissa = fp11 & 0x3F;
+
+ if (exponent == 0x1F) {
+ // INF or NaN
+ return BitwiseCast(0x7F800000 | (mantissa << 17));
+ }
+ if (exponent == 0) {
+ // Zero or denormalized: mantissa * 2^-20.
+ return float(mantissa) / float(1 << 20);
+ }
+ // Normalized: rebias the exponent for float32 (127 - 15 = 112).
+ return BitwiseCast(((exponent + 112) << 23) | (mantissa << 17));
+}
+
+MOZ_ALWAYS_INLINE float unpackFromFloat10(uint16_t fp10) {
+ const uint32_t exponent = (fp10 >> 5) & 0x1F;
+ const uint32_t mantissa = fp10 & 0x1F;
+
+ if (exponent == 0x1F) {
+ // INF or NaN
+ return BitwiseCast(0x7F800000 | (mantissa << 18));
+ }
+ if (exponent == 0) {
+ // Zero or denormalized: mantissa * 2^-19.
+ return float(mantissa) / float(1 << 19);
+ }
+ // Normalized: rebias the exponent for float32 (127 - 15 = 112).
+ return BitwiseCast(((exponent + 112) << 23) | (mantissa << 18));
+}
+
enum class WebGLTexelPremultiplicationOp : int {
None,
Premultiply,
@@ -368,6 +400,7 @@
case WebGLTexelFormat::RG16F:
case WebGLTexelFormat::RGB11F11F10F:
case WebGLTexelFormat::RGBA8:
+ case WebGLTexelFormat::RGBX8:
case WebGLTexelFormat::BGRX8:
case WebGLTexelFormat::BGRA8:
return 4;
@@ -415,7 +448,8 @@
format == WebGLTexelFormat::RGBA8 ||
format == WebGLTexelFormat::RGBA16F ||
format == WebGLTexelFormat::RGBA32F ||
- format == WebGLTexelFormat::BGRX8 || format == WebGLTexelFormat::BGRA8);
+ format == WebGLTexelFormat::RGBX8 || format == WebGLTexelFormat::BGRX8 ||
+ format == WebGLTexelFormat::BGRA8);
}
/****** BEGIN CODE SHARED WITH WEBKIT ******/
@@ -429,7 +463,11 @@
template
MOZ_ALWAYS_INLINE void unpack(const SrcType* __restrict src,
DstType* __restrict dst) {
- MOZ_ASSERT(false, "Unimplemented texture format conversion");
+ // Every source format dispatched by WebGLImageConverter::run() must have an
+ // unpack specialization; a silent fallthrough here would leave the
+ // intermediate texel uninitialized and leak host memory into textures, so
+ // crash in all build types instead.
+ MOZ_CRASH("GFX: Unimplemented texture format unpacking");
}
////////////////////////////////////////////////////////////////////////////////
@@ -517,6 +555,33 @@
dst[3] = src[1];
}
+template <>
+MOZ_ALWAYS_INLINE void unpack(
+ const uint8_t* __restrict src, uint8_t* __restrict dst) {
+ dst[0] = src[0];
+ dst[1] = src[1];
+ dst[2] = 0;
+ dst[3] = 0xFF;
+}
+
+template <>
+MOZ_ALWAYS_INLINE void unpack(
+ const uint16_t* __restrict src, uint16_t* __restrict dst) {
+ dst[0] = src[0];
+ dst[1] = src[1];
+ dst[2] = kFloat16Value_Zero;
+ dst[3] = kFloat16Value_One;
+}
+
+template <>
+MOZ_ALWAYS_INLINE void unpack(
+ const float* __restrict src, float* __restrict dst) {
+ dst[0] = src[0];
+ dst[1] = src[1];
+ dst[2] = 0.0f;
+ dst[3] = 1.0f;
+}
+
////////////////////////////////////////////////////////////////////////////////
// 3-channel formats
template <>
@@ -559,6 +624,16 @@
dst[3] = 1.0f;
}
+template <>
+MOZ_ALWAYS_INLINE void unpack(
+ const uint32_t* __restrict src, float* __restrict dst) {
+ const uint32_t packedValue = src[0];
+ dst[0] = unpackFromFloat11(uint16_t(packedValue & 0x7FF));
+ dst[1] = unpackFromFloat11(uint16_t((packedValue >> 11) & 0x7FF));
+ dst[2] = unpackFromFloat10(uint16_t((packedValue >> 22) & 0x3FF));
+ dst[3] = 1.0f;
+}
+
////////////////////////////////////////////////////////////////////////////////
// 4-channel formats
template <>
@@ -618,6 +693,15 @@
////////////////////////////////////////////////////////////////////////////////
// DOM element formats
template <>
+MOZ_ALWAYS_INLINE void unpack(
+ const uint8_t* __restrict src, uint8_t* __restrict dst) {
+ dst[0] = src[0];
+ dst[1] = src[1];
+ dst[2] = src[2];
+ dst[3] = 0xFF;
+}
+
+template <>
MOZ_ALWAYS_INLINE void unpack(
const uint8_t* __restrict src, uint8_t* __restrict dst) {
dst[0] = src[2];
diff -Nru firefox-esr-140.13.0esr/dom/canvas/WebGLTransformFeedback.cpp firefox-esr-140.15.0esr/dom/canvas/WebGLTransformFeedback.cpp
--- firefox-esr-140.13.0esr/dom/canvas/WebGLTransformFeedback.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/WebGLTransformFeedback.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -72,10 +72,17 @@
}
}
- const size_t vertCapacity = buffer->ByteLength() / 4 / componentsPerVert;
+ // Use the bound range rather than the whole buffer, since
+ // bindBufferRange may expose only part of it.
+ const size_t vertCapacity =
+ indexedBinding.ByteCount() / 4 / componentsPerVert;
minVertCapacity = std::min(minVertCapacity, vertCapacity);
}
+ // Don't clamp mActive_VertPosition to the capacity here: it mirrors the
+ // driver's write offset, which persists across buffer re-specification, so
+ // clamping would lose track of the capacity already consumed if the buffer is
+ // grown again. Draw-time validation saturates instead.
mActive_VertCapacity = minVertCapacity;
return true;
diff -Nru firefox-esr-140.13.0esr/dom/canvas/test/webgl-conf/generated-mochitest.toml firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/generated-mochitest.toml
--- firefox-esr-140.13.0esr/dom/canvas/test/webgl-conf/generated-mochitest.toml 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/generated-mochitest.toml 2026-08-26 17:03:41.000000000 +0000
@@ -5384,7 +5384,6 @@
["generated/test_2_conformance2__extensions__ovr_multiview2_draw_buffers.html"]
subsuite = "webgl2-core"
skip-if = ["os == 'android'"]
-fail-if = ["os == 'win' && debug"]
["generated/test_2_conformance2__extensions__ovr_multiview2_flat_varying.html"]
subsuite = "webgl2-core"
diff -Nru firefox-esr-140.13.0esr/dom/canvas/test/webgl-conf/mochitest-errata.toml firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/mochitest-errata.toml
--- firefox-esr-140.13.0esr/dom/canvas/test/webgl-conf/mochitest-errata.toml 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/canvas/test/webgl-conf/mochitest-errata.toml 2026-08-26 17:03:41.000000000 +0000
@@ -1265,25 +1265,6 @@
["generated/test_2_conformance2__extensions__ovr_multiview2_draw_buffers.html"]
skip-if = ["os == 'android'"]
-# https://bugzilla.mozilla.org/show_bug.cgi?id=1810021
-#
-# Currently getting failures like the following:
-#
-# > ```
-# > the right edge of view 0 of color attachment 1 should be untouched
-# > the left edge of view 1 of color attachment 1 should be untouched
-# > the right edge of view 1 of color attachment 1 should be untouched
-# > the left edge of view 2 of color attachment 1 should be untouched
-# > the right edge of view 2 of color attachment 1 should be untouched
-# > the left edge of view 3 of color attachment 1 should be untouched
-# > the right edge of view 0 of color attachment 2 should be untouched
-# > the left edge of view 1 of color attachment 2 should be untouched
-# > the right edge of view 1 of color attachment 2 should be untouched
-# > the left edge of view 2 of color attachment 2 should be untouched
-# > the right edge of view 2 of color attachment 2 should be untouched
-# > the left edge of view 3 of color attachment 2 should be untouched
-# > ```
-fail-if = ["os == 'win' && debug"]
["generated/test_2_conformance2__extensions__ovr_multiview2_instanced_draw.html"]
skip-if = ["os == 'android'"]
diff -Nru firefox-esr-140.13.0esr/dom/chrome-webidl/WindowsJumpListShortcutDescription.webidl firefox-esr-140.15.0esr/dom/chrome-webidl/WindowsJumpListShortcutDescription.webidl
--- firefox-esr-140.13.0esr/dom/chrome-webidl/WindowsJumpListShortcutDescription.webidl 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/chrome-webidl/WindowsJumpListShortcutDescription.webidl 2026-08-26 17:03:41.000000000 +0000
@@ -28,7 +28,7 @@
* Arguments to be supplied to the executable when the item is selected in
* the Jump List.
*/
- DOMString arguments;
+ sequence arguments;
/**
* A description of the item that is displayed as a tooltip.
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerParent.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerParent.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerParent.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -12,6 +12,7 @@
#include "ClientManagerService.h"
#include "ClientSourceParent.h"
#include "ClientValidation.h"
+#include "mozilla/dom/ContentParent.h"
#include "mozilla/dom/PClientNavigateOpParent.h"
#include "mozilla/Unused.h"
@@ -75,14 +76,10 @@
already_AddRefed
ClientManagerParent::AllocPClientSourceParent(
const ClientSourceConstructorArgs& aArgs) {
- Maybe contentParentId;
+ RefPtr contentParentHandle =
+ ::mozilla::ipc::BackgroundParent::GetContentParentHandle(Manager());
- uint64_t childID = ::mozilla::ipc::BackgroundParent::GetChildID(Manager());
- if (childID) {
- contentParentId = Some(ContentParentId(childID));
- }
-
- return MakeAndAddRef(aArgs, contentParentId);
+ return MakeAndAddRef(aArgs, contentParentHandle);
}
IPCResult ClientManagerParent::RecvPClientSourceConstructor(
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerService.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerService.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -716,7 +716,7 @@
}
bool ClientManagerService::HasWindow(
- const Maybe& aContentParentId,
+ ThreadsafeContentParentHandle* aContentParentHandle,
const PrincipalInfo& aPrincipalInfo, const nsID& aClientId) {
AssertIsOnBackgroundThread();
@@ -733,7 +733,7 @@
return false;
}
- if (aContentParentId && !source->IsOwnedByProcess(aContentParentId.value())) {
+ if (!source->IsOwnedByProcess(aContentParentHandle)) {
return false;
}
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerService.h firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.h
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientManagerService.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientManagerService.h 2026-08-26 17:03:41.000000000 +0000
@@ -10,7 +10,6 @@
#include "ClientOpPromise.h"
#include "mozilla/AlreadyAddRefed.h"
#include "mozilla/Assertions.h"
-#include "mozilla/Maybe.h"
#include "mozilla/MozPromise.h"
#include "mozilla/RefPtr.h"
#include "mozilla/Variant.h"
@@ -153,7 +152,7 @@
ThreadsafeContentParentHandle* aOriginContent,
const ClientOpenWindowArgs& aArgs);
- bool HasWindow(const Maybe& aContentParentId,
+ bool HasWindow(ThreadsafeContentParentHandle* aContentParentHandle,
const mozilla::ipc::PrincipalInfo& aPrincipalInfo,
const nsID& aClientId);
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientNavigateOpChild.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientNavigateOpChild.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientNavigateOpChild.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientNavigateOpChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -240,6 +240,16 @@
nsCOMPtr principal = doc->NodePrincipal();
+ rv = nsContentUtils::GetSecurityManager()->CheckLoadURIWithPrincipal(
+ principal, url, nsIScriptSecurityManager::STANDARD, doc->InnerWindowID());
+ if (NS_FAILED(rv)) {
+ nsPrintfCString err("Navigation to \"%s\" is not allowed",
+ aArgs.url().get());
+ CopyableErrorResult result;
+ result.ThrowTypeError(err);
+ return ClientOpPromise::CreateAndReject(result, __func__);
+ }
+
nsCOMPtr docShell = window->GetDocShell();
nsCOMPtr webProgress = do_GetInterface(docShell);
if (!docShell || !webProgress) {
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientSource.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientSource.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientSource.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientSource.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -15,6 +15,7 @@
#include "mozilla/Try.h"
#include "mozilla/dom/BlobURLProtocolHandler.h"
#include "mozilla/dom/ClientIPCTypes.h"
+#include "mozilla/dom/ContentChild.h"
#include "mozilla/dom/DOMMozPromiseRequestHolder.h"
#include "mozilla/dom/ipc/StructuredCloneData.h"
#include "mozilla/dom/JSExecutionManager.h"
@@ -183,7 +184,8 @@
// This can happen since we use MozURL for validation which does not handle
// some of the more obscure internal principal/url combinations. Normal
// content pages will pass this check.
- if (NS_WARN_IF(!ClientIsValidPrincipalInfo(mClientInfo.PrincipalInfo()))) {
+ if (NS_WARN_IF(!ClientIsValidPrincipalInfo(mClientInfo.PrincipalInfo(),
+ CurrentRemoteType()))) {
Shutdown();
return;
}
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientSourceParent.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientSourceParent.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -147,11 +147,11 @@
ClientSourceParent::ClientSourceParent(
const ClientSourceConstructorArgs& aArgs,
- const Maybe& aContentParentId)
+ ThreadsafeContentParentHandle* aContentParentHandle)
: mClientInfo(aArgs.id(), aArgs.agentClusterId(), aArgs.type(),
aArgs.principalInfo(), aArgs.creationTime(), aArgs.url(),
aArgs.frameType()),
- mContentParentId(aContentParentId),
+ mContentParentHandle(aContentParentHandle),
mService(ClientManagerService::GetOrCreateInstance()),
mExecutionReady(false),
mFrozen(false) {}
@@ -166,7 +166,10 @@
// Ensure the principal is reasonable before adding ourself to the service.
// Since we validate the principal on the child side as well, any failure
// here is treated as fatal.
- if (NS_WARN_IF(!ClientIsValidPrincipalInfo(mClientInfo.PrincipalInfo()))) {
+ if (NS_WARN_IF(!ClientIsValidPrincipalInfo(
+ mClientInfo.PrincipalInfo(),
+ mContentParentHandle ? mContentParentHandle->GetRemoteType()
+ : NOT_REMOTE_TYPE))) {
mService->ForgetFutureSource(mClientInfo.ToIPC());
return IPC_FAIL(Manager(), "Invalid PrincipalInfo!");
}
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientSourceParent.h firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.h
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientSourceParent.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientSourceParent.h 2026-08-26 17:03:41.000000000 +0000
@@ -17,11 +17,12 @@
class ClientHandleParent;
class ClientManagerService;
+class ThreadsafeContentParentHandle;
class ClientSourceParent final : public PClientSourceParent {
ClientInfo mClientInfo;
Maybe mController;
- const Maybe mContentParentId;
+ const RefPtr mContentParentHandle;
RefPtr mService;
nsTArray mHandleList;
MozPromiseHolder mExecutionReadyPromise;
@@ -57,8 +58,9 @@
public:
NS_INLINE_DECL_REFCOUNTING(ClientSourceParent, override)
- explicit ClientSourceParent(const ClientSourceConstructorArgs& aArgs,
- const Maybe& aContentParentId);
+ explicit ClientSourceParent(
+ const ClientSourceConstructorArgs& aArgs,
+ ThreadsafeContentParentHandle* aContentParentHandle);
mozilla::ipc::IPCResult Init();
@@ -74,8 +76,9 @@
void ClearController();
- bool IsOwnedByProcess(ContentParentId aContentParentId) const {
- return mContentParentId && mContentParentId.value() == aContentParentId;
+ bool IsOwnedByProcess(
+ ThreadsafeContentParentHandle* aContentParentHandle) const {
+ return mContentParentHandle == aContentParentHandle;
}
void AttachHandle(ClientHandleParent* aClientSource);
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientValidation.cpp firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.cpp
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientValidation.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -6,6 +6,7 @@
#include "ClientValidation.h"
+#include "mozilla/dom/ProcessIsolation.h"
#include "mozilla/ipc/PBackgroundSharedTypes.h"
#include "mozilla/StaticPrefs_security.h"
#include "mozilla/net/MozURL.h"
@@ -16,11 +17,22 @@
using mozilla::ipc::PrincipalInfo;
using mozilla::net::MozURL;
-bool ClientIsValidPrincipalInfo(const PrincipalInfo& aPrincipalInfo) {
- // Ideally we would verify that the source process has permission to
- // create a window or worker with the given principal, but we don't
- // currently have any such restriction in place. Instead, at least
- // verify the PrincipalInfo is an expected type and has a parsable
+bool ClientIsValidPrincipalInfo(const PrincipalInfo& aPrincipalInfo,
+ const nsACString& aRemoteType) {
+ auto result = mozilla::ipc::PrincipalInfoToPrincipal(aPrincipalInfo);
+ if (NS_WARN_IF(result.isErr())) {
+ return false;
+ }
+
+ // FIXME: Remove the system allowance once for non-inference processes once we
+ // can load documents with the system principal into content.
+ if (NS_WARN_IF(!ValidatePrincipalCouldPotentiallyBeLoadedBy(
+ result.inspect(), aRemoteType,
+ {ValidatePrincipalOptions::AllowSystem}))) {
+ return false;
+ }
+
+ // Verify the PrincipalInfo is an expected type and has a parsable
// origin/spec.
switch (aPrincipalInfo.type()) {
// Any system and null principal is acceptable.
diff -Nru firefox-esr-140.13.0esr/dom/clients/manager/ClientValidation.h firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.h
--- firefox-esr-140.13.0esr/dom/clients/manager/ClientValidation.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/clients/manager/ClientValidation.h 2026-08-26 17:03:41.000000000 +0000
@@ -17,7 +17,8 @@
namespace dom {
bool ClientIsValidPrincipalInfo(
- const mozilla::ipc::PrincipalInfo& aPrincipalInfo);
+ const mozilla::ipc::PrincipalInfo& aPrincipalInfo,
+ const nsACString& aRemoteType);
bool ClientIsValidCreationURL(const mozilla::ipc::PrincipalInfo& aPrincipalInfo,
const nsACString& aURL);
diff -Nru firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreNotifier.cpp firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreNotifier.cpp
--- firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreNotifier.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreNotifier.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -12,6 +12,7 @@
#include "mozilla/dom/Document.h"
#include "mozilla/dom/WorkerPrivate.h"
#include "mozilla/Unused.h"
+#include "nsContentUtils.h"
#include "nsICookie.h"
#include "nsICookieNotification.h"
#include "nsISerialEventTarget.h"
@@ -49,7 +50,9 @@
}
nsCString host;
- if (NS_WARN_IF(NS_FAILED(principal->GetAsciiHost(host))) || host.IsEmpty()) {
+ if (NS_WARN_IF(NS_FAILED(
+ nsContentUtils::GetHostOrIPv6WithBrackets(principal, host))) ||
+ host.IsEmpty()) {
return nullptr;
}
diff -Nru firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreParent.cpp firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreParent.cpp
--- firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreParent.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreParent.cpp 2026-08-26 17:03:40.000000000 +0000
@@ -21,6 +21,7 @@
#include "mozilla/Unused.h"
#include "nsICookieManager.h"
#include "nsICookieService.h"
+#include "nsNetUtil.h"
#include "nsProxyRelease.h"
#include "mozilla/ipc/URIUtils.h" // for IPDLParamTraits
#include "nsIEffectiveTLDService.h"
@@ -44,19 +45,19 @@
RefPtr contentParent = aParent->GetContentParent();
if (!contentParent) {
- return true;
+ return false;
}
PNeckoParent* neckoParent =
LoneManagedOrNullAsserts(contentParent->ManagedPNeckoParent());
if (!neckoParent) {
- return true;
+ return false;
}
PCookieServiceParent* csParent =
LoneManagedOrNullAsserts(neckoParent->ManagedPCookieServiceParent());
if (!csParent) {
- return true;
+ return false;
}
auto* cs = static_cast(csParent);
@@ -64,6 +65,16 @@
return cs->ContentProcessHasCookie(aDomain, aOriginAttributes);
}
+bool SubscriptionPrincipalMatchesScope(nsIPrincipal* aPrincipal,
+ const nsACString& aScopeURL) {
+ nsCOMPtr scopeURI;
+ if (NS_WARN_IF(NS_FAILED(NS_NewURI(getter_AddRefs(scopeURI), aScopeURL)))) {
+ return false;
+ }
+
+ return aPrincipal->IsSameOrigin(scopeURI);
+}
+
} // namespace
CookieStoreParent::CookieStoreParent() { AssertIsOnBackgroundThread(); }
@@ -196,6 +207,10 @@
return IPC_FAIL(this, "principal not allowed for remote type");
}
+ if (!SubscriptionPrincipalMatchesScope(principal, aScopeURL)) {
+ return IPC_FAIL(this, "principal not same-origin with scope");
+ }
+
InvokeAsync(GetMainThreadSerialEventTarget(), __func__,
[self = RefPtr(this), aPrincipalInfo, aScopeURL]() {
CookieStoreSubscriptionService* service =
@@ -246,6 +261,10 @@
return IPC_FAIL(this, "principal not allowed for remote type");
}
+ if (!SubscriptionPrincipalMatchesScope(principal, aScopeURL)) {
+ return IPC_FAIL(this, "principal not same-origin with scope");
+ }
+
InvokeAsync(GetMainThreadSerialEventTarget(), __func__,
[self = RefPtr(this), aPrincipalInfo, aScopeURL, aSubscriptions,
aSubscription]() {
diff -Nru firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreSubscriptionService.cpp firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreSubscriptionService.cpp
--- firefox-esr-140.13.0esr/dom/cookiestore/CookieStoreSubscriptionService.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/cookiestore/CookieStoreSubscriptionService.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -13,6 +13,7 @@
#include "mozilla/net/Cookie.h"
#include "mozilla/net/CookieCommons.h"
#include "nsAppDirectoryServiceDefs.h"
+#include "nsContentUtils.h"
#include "nsICookieNotification.h"
using namespace mozilla::dom;
@@ -322,6 +323,22 @@
continue;
}
+ nsCOMPtr principalURI;
+ rv = NS_NewURI(getter_AddRefs(principalURI), principalInfo.spec());
+ if (NS_WARN_IF(NS_FAILED(rv))) {
+ continue;
+ }
+
+ nsAutoCString host;
+ rv = nsContentUtils::GetHostOrIPv6WithBrackets(principalURI, host);
+ if (NS_WARN_IF(NS_FAILED(rv)) || host.IsEmpty()) {
+ continue;
+ }
+
+ if (!CookieCommons::DomainMatches(Cookie::Cast(cookie), host)) {
+ continue;
+ }
+
for (const CookieSubscription& subscription : data.mSubscriptions) {
if (subscription.name().isSome() && subscription.name().value() != name) {
continue;
diff -Nru firefox-esr-140.13.0esr/dom/events/EventStateManager.cpp firefox-esr-140.15.0esr/dom/events/EventStateManager.cpp
--- firefox-esr-140.13.0esr/dom/events/EventStateManager.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/events/EventStateManager.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -2909,6 +2909,8 @@
nsIContent* editingElement = aSelectionTarget->IsEditable()
? aSelectionTarget->GetEditingHost()
: nullptr;
+ nsCOMPtr principal;
+ bool fromChildProcess = false;
// In chrome, only allow dragging inside editable areas.
bool isChromeContext = !aWindow->GetBrowsingContext()->IsContent();
@@ -2916,8 +2918,9 @@
if (mGestureDownDragStartData) {
// A child process started a drag so use any data it assigned for the dnd
// session.
- mGestureDownDragStartData->AddInitialDnDDataTo(aDataTransfer, aPrincipal,
- aCsp, aCookieJarSettings);
+ mGestureDownDragStartData->AddInitialDnDDataTo(
+ aDataTransfer, getter_AddRefs(principal), aCsp, aCookieJarSettings);
+ fromChildProcess = true;
mGestureDownDragStartData.forget(aRemoteDragStartData);
*aAllowEmptyDataTransfer = true;
}
@@ -2994,6 +2997,10 @@
if (dragContent != originalDragContent) aDataTransfer->ClearAll();
*aTargetNode = dragContent;
NS_ADDREF(*aTargetNode);
+ if (!fromChildProcess) {
+ principal = dragContent->NodePrincipal();
+ }
+ principal.forget(aPrincipal);
}
}
diff -Nru firefox-esr-140.13.0esr/dom/events/IMEStateManager.cpp firefox-esr-140.15.0esr/dom/events/IMEStateManager.cpp
--- firefox-esr-140.13.0esr/dom/events/IMEStateManager.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/events/IMEStateManager.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -479,12 +479,44 @@
nsContentUtils::AddScriptRunner(NS_NewRunnableFunction(
"IMEStateManager::RecreateIMEContentObserverWhenContentRemoved",
[presContext = OwningNonNull{aPresContext}]() {
- MOZ_ASSERT(sFocusedPresContext == presContext);
- MOZ_ASSERT(!sFocusedElement);
- if (RefPtr htmlEditor =
- nsContentUtils::GetHTMLEditor(presContext)) {
- CreateIMEContentObserver(*htmlEditor, nullptr);
+ // If focus has been changed, we need to do nothing.
+ if (MOZ_UNLIKELY(sFocusedPresContext != presContext ||
+ sFocusedElement)) {
+ return;
}
+ // Otherwise, we need to recreate IMEContentObserver if there is no
+ // proper IMEContentObserver has not been created.
+ const RefPtr htmlEditor =
+ nsContentUtils::GetHTMLEditor(presContext);
+ if (MOZ_UNLIKELY(!htmlEditor)) {
+ return;
+ }
+ if (sActiveIMEContentObserver) {
+ // If we've already created IMEContentObserver and it is observing
+ // for the HTMLEditor, we need to do nothing.
+ if (sActiveIMEContentObserver->IsObserving(presContext, nullptr)) {
+ return;
+ }
+ NS_WARNING(
+ "There is unexpected IMEContentObserver, we'll recreate it...");
+ // Then, destroy the unnecessary observer.
+ DestroyIMEContentObserver();
+ // NOTIFY_IME_OF_BLUR **might** cause changing the DOM focus because
+ // if we're in the parent process, the widget may call native IME
+ // synchronously.
+ if (MOZ_UNLIKELY(sFocusedPresContext != presContext ||
+ sFocusedElement)) {
+ MOZ_ASSERT(XRE_IsParentProcess());
+ return;
+ }
+ if (sActiveIMEContentObserver) {
+ MOZ_ASSERT(XRE_IsParentProcess());
+ MOZ_ASSERT(
+ sActiveIMEContentObserver->IsObserving(presContext, nullptr));
+ return;
+ }
+ }
+ CreateIMEContentObserver(*htmlEditor, nullptr);
}));
}
diff -Nru firefox-esr-140.13.0esr/dom/filesystem/FileSystemSecurity.cpp firefox-esr-140.15.0esr/dom/filesystem/FileSystemSecurity.cpp
--- firefox-esr-140.13.0esr/dom/filesystem/FileSystemSecurity.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/filesystem/FileSystemSecurity.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -112,6 +112,11 @@
MOZ_ASSERT(NS_IsMainThread());
mozilla::ipc::AssertIsInMainProcess();
+ // POSIX APIs accept all other characters than NUL
+ if (aPath.FindChar(char16_t(0)) != kNotFound) {
+ return false;
+ }
+
#if defined(XP_WIN)
if (StringBeginsWith(aPath, u"..\\"_ns) ||
FindInReadable(u"\\..\\"_ns, aPath) ||
diff -Nru firefox-esr-140.13.0esr/dom/fs/child/FileSystemBackgroundRequestHandler.cpp firefox-esr-140.15.0esr/dom/fs/child/FileSystemBackgroundRequestHandler.cpp
--- firefox-esr-140.13.0esr/dom/fs/child/FileSystemBackgroundRequestHandler.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/fs/child/FileSystemBackgroundRequestHandler.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -7,6 +7,7 @@
#include "FileSystemBackgroundRequestHandler.h"
#include "fs/FileSystemChildFactory.h"
+#include "mozilla/dom/ContentChild.h"
#include "mozilla/dom/FileSystemManagerChild.h"
#include "mozilla/dom/PFileSystemManager.h"
#include "mozilla/ipc/BackgroundChild.h"
@@ -78,6 +79,18 @@
using mozilla::ipc::Endpoint;
using mozilla::ipc::PBackgroundChild;
+ // Throw if this process wouldn't be allowed to access storage.
+ EnumSet options;
+ if (CurrentRemoteType() == INFERENCE_REMOTE_TYPE) {
+ options += ValidatePrincipalOptions::AllowSystem;
+ }
+ if (!BackgroundChild::ValidatePrincipalInfo(aPrincipalInfo, options)) {
+ MOZ_ASSERT_UNREACHABLE(
+ "ValidatePrincipalInfo failure in CreateFileSystemManagerChild");
+ return FileSystemManagerChild::ActorPromise::CreateAndReject(
+ NS_ERROR_FAILURE, __func__);
+ }
+
if (!mCreatingFileSystemManagerChild) {
PBackgroundChild* backgroundChild =
BackgroundChild::GetOrCreateForCurrentThread();
diff -Nru firefox-esr-140.13.0esr/dom/gamepad/linux/LinuxGamepad.cpp firefox-esr-140.15.0esr/dom/gamepad/linux/LinuxGamepad.cpp
--- firefox-esr-140.13.0esr/dom/gamepad/linux/LinuxGamepad.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/gamepad/linux/LinuxGamepad.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -62,11 +62,18 @@
guint source_id = UINT_MAX;
char idstring[256] = {0};
char devpath[PATH_MAX] = {0};
- uint8_t key_map[KEY_MAX] = {0};
- uint8_t abs_map[ABS_MAX] = {0};
+ uint8_t key_map[KEY_CNT] = {0};
+ uint8_t abs_map[ABS_CNT] = {0};
std::unordered_map abs_info;
};
+// evdev admits key/abs codes up to KEY_MAX/ABS_MAX inclusive, so the maps must
+// have KEY_CNT/ABS_CNT (== *_MAX + 1) entries to index every valid code.
+static_assert(sizeof(Gamepad::key_map) > KEY_MAX,
+ "key_map must hold every valid EV_KEY code (0..KEY_MAX)");
+static_assert(sizeof(Gamepad::abs_map) > ABS_MAX,
+ "abs_map must hold every valid EV_ABS code (0..ABS_MAX)");
+
static inline bool LoadAbsInfo(int fd, Gamepad* gamepad, uint16_t code) {
input_absinfo info{0};
if (ioctl(fd, EVIOCGABS(code), &info) < 0) {
@@ -211,7 +218,7 @@
}
// Now, go through the non-semantic buttons and handle them as extras
- for (uint16_t key = 0; key < KEY_MAX; key++) {
+ for (uint16_t key = 0; key < KEY_CNT; key++) {
// Skip standard buttons
if (gamepad->isStandardGamepad &&
std::find(kStandardButtons.begin(), kStandardButtons.end(), key) !=
@@ -237,7 +244,7 @@
LoadAbsInfo(fd, gamepad.get(), ABS_HAT0Y);
}
- for (uint16_t i = 0; i < ABS_MAX; ++i) {
+ for (uint16_t i = 0; i < ABS_CNT; ++i) {
if (gamepad->isStandardGamepad &&
(std::find(kStandardAxes.begin(), kStandardAxes.end(), i) !=
kStandardAxes.end() ||
@@ -440,6 +447,11 @@
switch (event.type) {
case EV_KEY:
+ // event.code comes from the device and is untrusted; bound it before
+ // indexing key_map.
+ if (event.code >= KEY_CNT) {
+ continue;
+ }
if (gamepad->isStandardGamepad) {
service->NewButtonEvent(gamepad->handle, gamepad->key_map[event.code],
!!event.value);
diff -Nru firefox-esr-140.13.0esr/dom/html/HTMLMediaElement.cpp firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.cpp
--- firefox-esr-140.13.0esr/dom/html/HTMLMediaElement.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -2407,6 +2407,18 @@
nsIChannel* aNewChannel,
uint32_t aFlags) {
MOZ_ASSERT(mChannelLoader);
+ if (aNewChannel) {
+ nsCOMPtr oldURI;
+ if (aChannel) {
+ aChannel->GetURI(getter_AddRefs(oldURI));
+ }
+ aNewChannel->GetURI(getter_AddRefs(mLoadingSrcFinalURI));
+ LOG(LogLevel::Debug,
+ ("%p OnChannelRedirect: from %s to %s", this,
+ oldURI ? oldURI->GetSpecOrDefault().get() : "null",
+ mLoadingSrcFinalURI ? mLoadingSrcFinalURI->GetSpecOrDefault().get()
+ : "null"));
+ }
return mChannelLoader->Redirect(aChannel, aNewChannel, aFlags);
}
@@ -2445,6 +2457,8 @@
mChannelLoader = nullptr;
}
+ mLoadingSrcFinalURI = nullptr;
+
bool fireTimeUpdate = false;
if (mDecoder) {
@@ -2461,6 +2475,8 @@
RemoveMediaElementFromURITable();
mLoadingSrcTriggeringPrincipal = nullptr;
+ // The CORS mode is scoped to the current load.
+ mCORSMode = CORS_NONE;
DDLOG(DDLogCategory::Property, "loading_src", "");
DDUNLINKCHILD(mMediaSource.get());
mMediaSource = nullptr;
@@ -2553,12 +2569,12 @@
bool isSameOriginLoad = false;
nsresult rv = NS_ERROR_NOT_AVAILABLE;
- if (mSrcAttrTriggeringPrincipal && mLoadingSrc) {
- rv = mSrcAttrTriggeringPrincipal->IsSameOrigin(mLoadingSrc,
- &isSameOriginLoad);
+ if (mLoadingSrcTriggeringPrincipal && mLoadingSrcFinalURI) {
+ rv = mLoadingSrcTriggeringPrincipal->IsSameOrigin(mLoadingSrcFinalURI,
+ &isSameOriginLoad);
}
- if (NS_SUCCEEDED(rv) && !isSameOriginLoad) {
+ if (NS_FAILED(rv) || !isSameOriginLoad) {
// aErrorDetails can include sensitive details like MimeType or HTTP Status
// Code. In case we're loading a 3rd party resource we should not leak this
// and pass a Generic Error Message
@@ -2761,6 +2777,9 @@
// If we have a 'src' attribute, use that exclusively.
nsAutoString src;
if (mSrcAttrStream) {
+ // Media provider objects use local mode, so a previous URL load's CORS
+ // mode does not apply.
+ mCORSMode = CORS_NONE;
SetupSrcMediaStreamPlayback(mSrcAttrStream);
} else if (GetAttr(nsGkAtoms::src, src)) {
nsCOMPtr uri;
@@ -2784,6 +2803,7 @@
} else {
mLoadingSrc = nullptr;
}
+ mLoadingSrcFinalURI = mLoadingSrc;
mLoadingSrcTriggeringPrincipal = mSrcAttrTriggeringPrincipal;
DDLOG(DDLogCategory::Property, "loading_src",
nsCString(NS_ConvertUTF16toUTF8(src)));
@@ -3074,6 +3094,7 @@
RemoveMediaElementFromURITable();
mLoadingSrc = uri;
+ mLoadingSrcFinalURI = mLoadingSrc;
mLoadingSrcTriggeringPrincipal = child->GetSrcTriggeringPrincipal();
DDLOG(DDLogCategory::Property, "loading_src",
nsCString(NS_ConvertUTF16toUTF8(src)));
@@ -5437,6 +5458,7 @@
void HTMLMediaElement::SetupSrcMediaStreamPlayback(DOMMediaStream* aStream) {
NS_ASSERTION(!mSrcStream, "Should have been ended already");
+ MOZ_ASSERT(mCORSMode == CORS_NONE);
mLoadingSrc = nullptr;
mSrcStream = aStream;
diff -Nru firefox-esr-140.13.0esr/dom/html/HTMLMediaElement.h firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.h
--- firefox-esr-140.13.0esr/dom/html/HTMLMediaElement.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/HTMLMediaElement.h 2026-08-26 17:03:41.000000000 +0000
@@ -1577,6 +1577,12 @@
// redirects etc.
nsCOMPtr mLoadingSrc;
+ // The URI of the resource actually loaded. Starts equal to mLoadingSrc and
+ // is updated to the post-redirect URI on each redirect. Used to decide
+ // cross-origin load-error redaction; null means we have no captured URI, and
+ // is treated as cross-origin.
+ nsCOMPtr mLoadingSrcFinalURI;
+
// The triggering principal for the current source.
nsCOMPtr mLoadingSrcTriggeringPrincipal;
diff -Nru firefox-esr-140.13.0esr/dom/html/HTMLOptionElement.h firefox-esr-140.15.0esr/dom/html/HTMLOptionElement.h
--- firefox-esr-140.13.0esr/dom/html/HTMLOptionElement.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/HTMLOptionElement.h 2026-08-26 17:03:42.000000000 +0000
@@ -110,11 +110,6 @@
int32_t Index();
- protected:
- virtual ~HTMLOptionElement();
-
- JSObject* WrapNode(JSContext*, JS::Handle aGivenProto) override;
-
/**
* Get the select content element that contains this option, this
* intentionally does not return nsresult, all we care about is if
@@ -122,6 +117,11 @@
*/
HTMLSelectElement* GetSelect();
+protected:
+ virtual ~HTMLOptionElement();
+
+ JSObject* WrapNode(JSContext*, JS::Handle aGivenProto) override;
+
bool mSelectedChanged = false;
// True only while we're under the SetOptionsSelectedByIndex call when our
diff -Nru firefox-esr-140.13.0esr/dom/html/HTMLSelectElement.cpp firefox-esr-140.15.0esr/dom/html/HTMLSelectElement.cpp
--- firefox-esr-140.13.0esr/dom/html/HTMLSelectElement.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/HTMLSelectElement.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -665,15 +665,16 @@
bool HTMLSelectElement::MatchSelectedOptions(Element* aElement,
int32_t /* unused */,
nsAtom* /* unused */,
- void* /* unused*/) {
+ void* aData) {
HTMLOptionElement* option = HTMLOptionElement::FromNode(aElement);
- return option && option->Selected();
+ return option && option->Selected() &&
+ option->GetSelect() == static_cast(aData);
}
nsIHTMLCollection* HTMLSelectElement::SelectedOptions() {
if (!mSelectedOptions) {
mSelectedOptions = new nsContentList(this, MatchSelectedOptions, nullptr,
- nullptr, /* deep */ true);
+ this, /* deep */ true);
}
return mSelectedOptions;
}
diff -Nru firefox-esr-140.13.0esr/dom/html/nsGenericHTMLElement.cpp firefox-esr-140.15.0esr/dom/html/nsGenericHTMLElement.cpp
--- firefox-esr-140.13.0esr/dom/html/nsGenericHTMLElement.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/nsGenericHTMLElement.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -3704,7 +3704,8 @@
void nsGenericHTMLElement::HidePopoverInternal(bool aFocusPreviousElement,
bool aFireEvents,
ErrorResult& aRv) {
- OwnerDoc()->HidePopover(*this, aFocusPreviousElement, aFireEvents, aRv);
+ RefPtr document = OwnerDoc();
+ document->HidePopover(*this, aFocusPreviousElement, aFireEvents, aRv);
}
void nsGenericHTMLElement::ForgetPreviouslyFocusedElementAfterHidingPopover() {
diff -Nru firefox-esr-140.13.0esr/dom/html/test/browser.toml firefox-esr-140.15.0esr/dom/html/test/browser.toml
--- firefox-esr-140.13.0esr/dom/html/test/browser.toml 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/test/browser.toml 2026-08-26 17:03:41.000000000 +0000
@@ -34,6 +34,9 @@
["browser_form_post_from_file_to_http.js"]
+["browser_input_file_untrusted_drop.js"]
+support-files = ["file_input_file_untrusted_drop.html"]
+
["browser_refresh_after_document_write.js"]
support-files = ["file_refresh_after_document_write.html"]
diff -Nru firefox-esr-140.13.0esr/dom/html/test/browser_input_file_untrusted_drop.js firefox-esr-140.15.0esr/dom/html/test/browser_input_file_untrusted_drop.js
--- firefox-esr-140.13.0esr/dom/html/test/browser_input_file_untrusted_drop.js 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/test/browser_input_file_untrusted_drop.js 2026-08-26 17:03:42.000000000 +0000
@@ -0,0 +1,174 @@
+/* Any copyright is dedicated to the Public Domain.
+ http://creativecommons.org/publicdomain/zero/1.0/ */
+
+"use strict";
+
+const TEST_PATH = getRootDirectory(gTestPath).replace(
+ "chrome://mochitests/content",
+ "https://example.com"
+);
+const PAGE = TEST_PATH + "file_input_file_untrusted_drop.html";
+
+const FILE_CONTENTS = "not for the page to see";
+
+async function createDraggedFile() {
+ const path = PathUtils.join(
+ PathUtils.tempDir,
+ "browser_input_file_untrusted_drop.txt"
+ );
+ await IOUtils.writeUTF8(path, FILE_CONTENTS);
+ registerCleanupFunction(() => IOUtils.remove(path, { ignoreAbsent: true }));
+ return File.createFromFileName(path);
+}
+
+function dragFileOverInput(browser, file) {
+ return SpecialPowers.spawn(browser, [file], async draggedFile => {
+ const doc = content.document;
+ const input = doc.getElementById("fileinput");
+
+ content.wrappedJSObject.installDragEnterStealer();
+
+ const dragData = [[{ type: "application/x-moz-file", data: draggedFile }]];
+
+ // EventUtils.startDragSession() is not available on this branch, so use
+ // the drag service to start the session for a drag from another
+ // application.
+ const dragService = SpecialPowers.Cc[
+ "@mozilla.org/widget/dragservice;1"
+ ].getService(SpecialPowers.Ci.nsIDragService);
+ dragService.startDragSessionForTests(
+ content,
+ SpecialPowers.Ci.nsIDragService.DRAGDROP_ACTION_COPY
+ );
+ try {
+ // Fires dragstart on #dragsource, then dragenter and dragover on the
+ // file input. No drop.
+ EventUtils.synthesizeDragOver(
+ doc.getElementById("dragsource"),
+ input,
+ dragData,
+ "copy",
+ content
+ );
+ } finally {
+ content.windowUtils.dragSession?.endDragSession(true);
+ }
+
+ const stolen = content.wrappedJSObject.stealResult;
+ return {
+ fileCountAfterDrag: input.files.length,
+ stolen: stolen
+ ? {
+ types: Array.from(stolen.types),
+ itemCount: stolen.itemCount,
+ fileCountDuringDragEnter: stolen.fileCountDuringDragEnter,
+ anyItemReadableAsFile: stolen.anyItemReadableAsFile,
+ dropEventCancelled: stolen.dropEventCancelled,
+ fileCountAfterUntrustedDrop: stolen.fileCountAfterUntrustedDrop,
+ }
+ : null,
+ };
+ });
+}
+
+add_task(async function test_stolen_datatransfer_in_untrusted_drop() {
+ const file = await createDraggedFile();
+
+ await BrowserTestUtils.withNewTab(PAGE, async browser => {
+ const result = await dragFileOverInput(browser, file);
+
+ ok(result.stolen, "The page saw a dragenter event");
+ if (!result.stolen) {
+ return;
+ }
+
+ ok(
+ result.stolen.types.includes("Files"),
+ "The page can see that the drag carries a file"
+ );
+ is(result.stolen.itemCount, 1, "The page can see one item");
+ is(
+ result.stolen.fileCountDuringDragEnter,
+ 0,
+ "DataTransfer.files is empty during dragenter"
+ );
+ ok(
+ !result.stolen.anyItemReadableAsFile,
+ "getAsFile() returns null during dragenter"
+ );
+
+ ok(
+ !result.stolen.dropEventCancelled,
+ "The untrusted drop event was not handled by the file control"
+ );
+ is(
+ result.stolen.fileCountAfterUntrustedDrop,
+ 0,
+ "The untrusted drop did not set input.files"
+ );
+ is(result.fileCountAfterDrag, 0, "input.files is still empty");
+ });
+});
+
+add_task(async function test_untrusted_events_with_page_made_datatransfer() {
+ await BrowserTestUtils.withNewTab(PAGE, async browser => {
+ const [dragOverAllowed, fileCount] = await SpecialPowers.spawn(
+ browser,
+ [],
+ () => [
+ content.wrappedJSObject.spoofUntrustedDragOver(),
+ content.wrappedJSObject.spoofUntrustedDrop(),
+ ]
+ );
+
+ ok(
+ dragOverAllowed,
+ "The file control did not preventDefault() an untrusted dragover"
+ );
+ is(fileCount, 0, "An untrusted drop did not set input.files");
+ });
+});
+
+// Make sure the above isn't passing because dropping files stopped working.
+add_task(async function test_trusted_drop_still_works() {
+ const file = await createDraggedFile();
+
+ await BrowserTestUtils.withNewTab(PAGE, async browser => {
+ const result = await SpecialPowers.spawn(
+ browser,
+ [file],
+ async draggedFile => {
+ const doc = content.document;
+ const input = doc.getElementById("fileinput");
+
+ const changed = new Promise(resolve =>
+ input.addEventListener("change", resolve, { once: true })
+ );
+
+ EventUtils.synthesizeDrop(
+ doc.getElementById("dragsource"),
+ input,
+ [[{ type: "application/x-moz-file", data: draggedFile }]],
+ "copy",
+ content
+ );
+
+ // Only wait for the change event if the drop actually did something,
+ // otherwise a regression here would hang until the test times out
+ // instead of failing with a useful message.
+ const fileCount = input.files.length;
+ if (fileCount) {
+ await changed;
+ }
+
+ return {
+ fileCount,
+ text: fileCount ? await input.files[0].text() : null,
+ };
+ }
+ );
+
+ is(result.fileCount, 1, "A trusted drop set input.files");
+ is(result.text, FILE_CONTENTS, "The dropped file is readable");
+ });
+});
diff -Nru firefox-esr-140.13.0esr/dom/html/test/file_input_file_untrusted_drop.html firefox-esr-140.15.0esr/dom/html/test/file_input_file_untrusted_drop.html
--- firefox-esr-140.13.0esr/dom/html/test/file_input_file_untrusted_drop.html 1970-01-01 00:00:00.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/html/test/file_input_file_untrusted_drop.html 2026-08-26 17:03:41.000000000 +0000
@@ -0,0 +1,77 @@
+
+
+
+
+ Untrusted drop events on input type=file
+
+
+drag me
+
+
+
+
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/ActorsParent.cpp firefox-esr-140.15.0esr/dom/indexedDB/ActorsParent.cpp
--- firefox-esr-140.13.0esr/dom/indexedDB/ActorsParent.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/ActorsParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -9088,17 +9088,22 @@
MOZ_ASSERT(principalInfo.type() == PrincipalInfo::TSystemPrincipalInfo ||
principalInfo.type() == PrincipalInfo::TContentPrincipalInfo);
- if (NS_AUUF_OR_WARN_IF(
- principalInfo.type() == PrincipalInfo::TSystemPrincipalInfo &&
- metadata.persistenceType() != PERSISTENCE_TYPE_PERSISTENT)) {
+ if (!BackgroundParent::ValidatePrincipalInfo(Manager(), principalInfo,
+ PrincipalValidationOptions())) {
+ IPC_FAIL(this, "Invalid principal!");
return nullptr;
}
- if (NS_AUUF_OR_WARN_IF(
- principalInfo.type() == PrincipalInfo::TContentPrincipalInfo &&
- QuotaManager::IsOriginInternal(
- principalInfo.get_ContentPrincipalInfo().originNoSuffix()) &&
- metadata.persistenceType() != PERSISTENCE_TYPE_PERSISTENT)) {
+ /* GetPersistenceType returns PERSISTENT for system principals and internal
+ content principals, PRIVATE for private-browsing content principals, and
+ DEFAULT for everything else. The sent value is technically redundant and
+ always deducible from the principal but we validate it here so that an
+ incorrect metadata value cannot reach other parts of the code.
+ TODO: Stop sending persistenceType from the content process and just derive it
+ on the parent side. */
+ if (metadata.persistenceType() !=
+ IDBFactory::GetPersistenceType(principalInfo)) {
+ IPC_FAIL(this, "Persistence type does not match principal!");
return nullptr;
}
@@ -9170,6 +9175,10 @@
MOZ_ASSERT(aPrincipalInfo.type() == PrincipalInfo::TSystemPrincipalInfo ||
aPrincipalInfo.type() == PrincipalInfo::TContentPrincipalInfo);
+ QM_TRY(MOZ_TO_RESULT(BackgroundParent::ValidatePrincipalInfo(
+ Manager(), aPrincipalInfo, PrincipalValidationOptions())),
+ QM_IPC_FAIL(this));
+
PersistenceType persistenceType =
IDBFactory::GetPersistenceType(aPrincipalInfo);
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/IDBFactory.cpp firefox-esr-140.15.0esr/dom/indexedDB/IDBFactory.cpp
--- firefox-esr-140.13.0esr/dom/indexedDB/IDBFactory.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/IDBFactory.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -7,7 +7,9 @@
#include "IDBFactory.h"
#include "BackgroundChildImpl.h"
+#include "ErrorList.h"
#include "IDBRequest.h"
+#include "IndexedDBCommon.h"
#include "IndexedDatabaseManager.h"
#include "mozilla/BasePrincipal.h"
#include "mozilla/ErrorResult.h"
@@ -468,6 +470,13 @@
return promise.forget();
}
+ // If this request would fail in the parent process, fail early in content.
+ if (!BackgroundChild::ValidatePrincipalInfo(
+ *mPrincipalInfo, indexedDB::PrincipalValidationOptions())) {
+ promise->MaybeRejectWithSecurityError(kAccessError);
+ return promise.forget();
+ }
+
PersistenceType persistenceType = GetPersistenceType(*mPrincipalInfo);
QM_TRY(MOZ_TO_RESULT(EnsureBackgroundActor()), [&promise](const nsresult rv) {
@@ -729,6 +738,13 @@
principalInfo = *mPrincipalInfo;
}
+ // If this request would fail in the parent process, fail early in content.
+ if (!BackgroundChild::ValidatePrincipalInfo(
+ principalInfo, indexedDB::PrincipalValidationOptions())) {
+ aRv.ThrowSecurityError(kAccessError);
+ return nullptr;
+ }
+
uint64_t version = 0;
if (!aDeleting && aVersion.WasPassed()) {
if (aVersion.Value() < 1) {
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/IndexedDBCommon.cpp firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.cpp
--- firefox-esr-140.13.0esr/dom/indexedDB/IndexedDBCommon.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -8,9 +8,19 @@
#include "js/StructuredClone.h"
#include "mozilla/SnappyUncompressInputStream.h"
+#include "mozilla/StaticPrefs_dom.h"
namespace mozilla::dom::indexedDB {
+EnumSet PrincipalValidationOptions() {
+ EnumSet options;
+ if (StaticPrefs::dom_indexedDB_testing_allowContentSystem() &&
+ xpc::IsInAutomation()) {
+ options += ValidatePrincipalOptions::AllowSystem;
+ }
+ return options;
+}
+
// aStructuredCloneData is a parameter rather than a return value because one
// caller preallocates it on the heap not immediately before calling for some
// reason. Maybe this could be changed.
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/IndexedDBCommon.h firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.h
--- firefox-esr-140.13.0esr/dom/indexedDB/IndexedDBCommon.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/IndexedDBCommon.h 2026-08-26 17:03:42.000000000 +0000
@@ -7,6 +7,7 @@
#ifndef mozilla_dom_indexeddb_IndexedDBCommon_h
#define mozilla_dom_indexeddb_IndexedDBCommon_h
+#include "mozilla/dom/ProcessIsolation.h"
#include "mozilla/dom/quota/QuotaCommon.h"
class JSStructuredCloneData;
@@ -16,6 +17,8 @@
static constexpr uint32_t kFileCopyBufferSize = 32768;
+EnumSet PrincipalValidationOptions();
+
nsresult SnappyUncompressStructuredCloneData(
nsIInputStream& aInputStream, JSStructuredCloneData& aStructuredCloneData);
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/test/test_message_manager_ipc.html firefox-esr-140.15.0esr/dom/indexedDB/test/test_message_manager_ipc.html
--- firefox-esr-140.13.0esr/dom/indexedDB/test/test_message_manager_ipc.html 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/test/test_message_manager_ipc.html 2026-08-26 17:03:41.000000000 +0000
@@ -312,6 +312,10 @@
}
add_task(async function() {
+ await SpecialPowers.pushPrefEnv({
+ set: [["dom.indexedDB.testing.allowContentSystem", true]],
+ });
+
let chromeScript = SpecialPowers.loadChromeScript(chromeScriptFunc);
await chromeScript.promiseOneMessage("done");
await chromeScript.destroy();
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/test/unit/xpcshell-head-child-process.js firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-head-child-process.js
--- firefox-esr-140.13.0esr/dom/indexedDB/test/unit/xpcshell-head-child-process.js 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-head-child-process.js 2026-08-26 17:03:42.000000000 +0000
@@ -6,6 +6,8 @@
function run_test() {
const INDEXEDDB_HEAD_FILE = "xpcshell-head-parent-process.js";
const INDEXEDDB_PREF_EXPERIMENTAL = "dom.indexedDB.experimental";
+ const INDEXEDDB_PREF_TESTING_ALLOW_CONTENT_SYSTEM =
+ "dom.indexedDB.testing.allowContentSystem";
// IndexedDB needs a profile.
do_get_profile();
@@ -18,6 +20,7 @@
_HEAD_FILES.push(do_get_file(INDEXEDDB_HEAD_FILE).path.replace(/\\/g, "/"));
Services.prefs.setBoolPref(INDEXEDDB_PREF_EXPERIMENTAL, true);
+ Services.prefs.setBoolPref(INDEXEDDB_PREF_TESTING_ALLOW_CONTENT_SYSTEM, true);
run_test_in_child(thisTest);
}
diff -Nru firefox-esr-140.13.0esr/dom/indexedDB/test/unit/xpcshell-parent-process.toml firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-parent-process.toml
--- firefox-esr-140.13.0esr/dom/indexedDB/test/unit/xpcshell-parent-process.toml 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/indexedDB/test/unit/xpcshell-parent-process.toml 2026-08-26 17:03:41.000000000 +0000
@@ -64,6 +64,7 @@
["test_file_copy_failure.js"]
["test_globalObjects_ipc.js"]
+prefs = ["dom.indexedDB.testing.allowContentSystem=true"]
["test_idbSubdirUpgrade.js"]
diff -Nru firefox-esr-140.13.0esr/dom/ipc/BrowserParent.cpp firefox-esr-140.15.0esr/dom/ipc/BrowserParent.cpp
--- firefox-esr-140.13.0esr/dom/ipc/BrowserParent.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/BrowserParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -64,6 +64,7 @@
#include "mozilla/TouchEvents.h"
#include "mozilla/UniquePtr.h"
#include "mozilla/Unused.h"
+#include "nsBaseDragService.h"
#include "nsCOMPtr.h"
#include "nsContentPermissionHelper.h"
#include "nsContentUtils.h"
@@ -120,6 +121,7 @@
#include "nsPIWindowRoot.h"
#include "nsReadableUtils.h"
#include "nsIAuthPrompt2.h"
+#include "nsIScriptSecurityManager.h"
#include "gfxDrawable.h"
#include "ImageOps.h"
#include "UnitTransforms.h"
@@ -930,17 +932,18 @@
// not been modified then it's safe to load those links using the
// SystemPrincipal. If they have been modified by web content, then
// we use a NullPrincipal which still allows to load web links.
- bool loadUsingSystemPrincipal = true;
- if (aLinks.Length() != mVerifyDropLinks.Length()) {
- loadUsingSystemPrincipal = false;
- }
- for (uint32_t i = 0; i < aLinks.Length(); i++) {
- if (loadUsingSystemPrincipal) {
+ const bool loadUsingSystemPrincipal = [&]() {
+ if (aLinks.Length() != mVerifyDropLinks.Length()) {
+ return false;
+ }
+ for (uint32_t i = 0; i < aLinks.Length(); i++) {
if (!aLinks[i].Equals(mVerifyDropLinks[i])) {
- loadUsingSystemPrincipal = false;
+ return false;
}
}
- }
+ return true;
+ }();
+
mVerifyDropLinks.Clear();
nsCOMPtr triggeringPrincipal;
if (loadUsingSystemPrincipal) {
@@ -1615,6 +1618,27 @@
return false;
}
+ nsCOMPtr triggeringPrincipal;
+ dragSession->GetTriggeringPrincipal(getter_AddRefs(triggeringPrincipal));
+
+ nsIScriptSecurityManager* secMan = nullptr;
+ if (triggeringPrincipal) {
+ if (!(secMan = nsContentUtils::GetSecurityManager())) {
+ NS_WARNING("No ScriptSecurityManager for links verification");
+ return false;
+ }
+ } else {
+ RefPtr sourceWC = dragSession->GetSourceWindowContext();
+ RefPtr sourceTopWC =
+ dragSession->GetSourceTopWindowContext();
+ if (sourceWC || sourceTopWC) {
+ NS_WARNING(
+ "How can we have a source window context while no triggering "
+ "principal?");
+ return false;
+ }
+ }
+
// No more than one drop event can happen simultaneously; reset the link
// verification array and store all links that are being dragged.
mVerifyDropLinks.Clear();
@@ -1633,6 +1657,22 @@
NS_WARNING("Failed to query url for verification");
break;
}
+
+ if (triggeringPrincipal) {
+ MOZ_ASSERT(secMan);
+ if (NS_FAILED(secMan->CheckLoadURIStrWithPrincipal(
+ triggeringPrincipal, NS_ConvertUTF16toUTF8(tmp),
+ nsIScriptSecurityManager::STANDARD |
+ nsIScriptSecurityManager::DISALLOW_INHERIT_PRINCIPAL))) {
+ MOZ_DRAGSERVICE_LOG("[%p] %s | dragSession: %p | Bad URI %s from %p",
+ this, __FUNCTION__, dragSession.get(),
+ NS_ConvertUTF16toUTF8(tmp).get(),
+ triggeringPrincipal.get());
+ mVerifyDropLinks.Clear();
+ return true;
+ }
+ }
+
mVerifyDropLinks.AppendElement(tmp);
rv = item->GetName(tmp);
@@ -3904,6 +3944,11 @@
return IPC_OK();
}
+ if (!Manager()->ValidatePrincipal(aPrincipal, {})) {
+ return ContentParent::PrincipalValidationIpcFail(aPrincipal, this,
+ __func__);
+ }
+
nsCOMPtr cookieJarSettings;
net::CookieJarSettings::Deserialize(aCookieJarSettingsArgs,
getter_AddRefs(cookieJarSettings));
diff -Nru firefox-esr-140.13.0esr/dom/ipc/ContentChild.cpp firefox-esr-140.15.0esr/dom/ipc/ContentChild.cpp
--- firefox-esr-140.13.0esr/dom/ipc/ContentChild.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/ContentChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -23,6 +23,7 @@
#include "imgLoader.h"
#include "ScrollingMetrics.h"
#include "mozilla/BasePrincipal.h"
+#include "mozilla/ClearOnShutdown.h"
#include "mozilla/ClipboardContentAnalysisChild.h"
#include "mozilla/ClipboardReadRequestChild.h"
#include "mozilla/Components.h"
@@ -43,6 +44,7 @@
#include "mozilla/dom/SharedScriptCache.h"
#include "mozilla/SimpleEnumerator.h"
#include "mozilla/SpinEventLoopUntil.h"
+#include "mozilla/StaticMutex.h"
#include "mozilla/StaticPrefs_browser.h"
#include "mozilla/StaticPrefs_dom.h"
#include "mozilla/StaticPrefs_fission.h"
@@ -2501,6 +2503,22 @@
return IPC_OK();
}
+static StaticMutex sCurrentRemoteTypeMutex;
+static StaticAutoPtr sCurrentRemoteType
+ MOZ_GUARDED_BY(sCurrentRemoteTypeMutex);
+
+nsCString CurrentRemoteType() {
+ if (XRE_IsContentProcess()) {
+ StaticMutexAutoLock lock(sCurrentRemoteTypeMutex);
+ if (sCurrentRemoteType) {
+ return *sCurrentRemoteType;
+ }
+ return PREALLOC_REMOTE_TYPE;
+ }
+
+ return NOT_REMOTE_TYPE;
+}
+
mozilla::ipc::IPCResult ContentChild::RecvRemoteType(
const nsCString& aRemoteType, const nsCString& aProfile) {
if (aRemoteType == mRemoteType) {
@@ -2536,6 +2554,18 @@
// Must do before SetProcessName
mRemoteType.Assign(aRemoteType);
+ {
+ StaticMutexAutoLock lock(sCurrentRemoteTypeMutex);
+ if (!sCurrentRemoteType) {
+ sCurrentRemoteType = new nsCString();
+ RunOnShutdown([] {
+ StaticMutexAutoLock lock(sCurrentRemoteTypeMutex);
+ sCurrentRemoteType = nullptr;
+ });
+ }
+ sCurrentRemoteType->Assign(mRemoteType);
+ }
+
// Update the process name so about:memory's process names are more obvious.
if (aRemoteType == FILE_REMOTE_TYPE) {
SetProcessName("file:// Content"_ns, nullptr, &aProfile);
diff -Nru firefox-esr-140.13.0esr/dom/ipc/ContentChild.h firefox-esr-140.15.0esr/dom/ipc/ContentChild.h
--- firefox-esr-140.13.0esr/dom/ipc/ContentChild.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/ContentChild.h 2026-08-26 17:03:41.000000000 +0000
@@ -904,6 +904,9 @@
return static_cast(aContentChild);
}
+// Threadsafe getter for the current process's RemoteType.
+nsCString CurrentRemoteType();
+
} // namespace dom
} // namespace mozilla
diff -Nru firefox-esr-140.13.0esr/dom/ipc/ContentParent.cpp firefox-esr-140.15.0esr/dom/ipc/ContentParent.cpp
--- firefox-esr-140.13.0esr/dom/ipc/ContentParent.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/ContentParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -3198,9 +3198,7 @@
// aRequestingPrincipal is allowed to be nullptr here.
if (!ValidatePrincipal(aTransferable.dataPrincipal(),
- {ValidatePrincipalOptions::AllowNullPtr,
- ValidatePrincipalOptions::AllowExpanded,
- ValidatePrincipalOptions::AllowSystem})) {
+ {ValidatePrincipalOptions::AllowNullPtr})) {
return PrincipalValidationIpcFail(aTransferable.dataPrincipal(), this,
__func__);
}
@@ -4669,7 +4667,7 @@
}
mozilla::ipc::IPCResult ContentParent::RecvLoadURIExternal(
- nsIURI* uri, nsIPrincipal* aTriggeringPrincipal,
+ NotNull uri, NotNull aTriggeringPrincipal,
nsIPrincipal* aRedirectPrincipal,
const MaybeDiscarded& aContext,
bool aWasExternallyTriggered, bool aHasValidUserGestureActivation,
@@ -4678,16 +4676,23 @@
return IPC_OK();
}
+ if (!ValidatePrincipal(aTriggeringPrincipal)) {
+ LogAndAssertFailedPrincipalValidationInfo(aTriggeringPrincipal, __func__);
+ return IPC_FAIL(this, "aTriggeringPrincipal invalid");
+ }
+
+ if (!ValidatePrincipal(aRedirectPrincipal,
+ {ValidatePrincipalOptions::AllowNullPtr})) {
+ LogAndAssertFailedPrincipalValidationInfo(aRedirectPrincipal, __func__);
+ return IPC_FAIL(this, "aRedirectPrincipal invalid");
+ }
+
nsCOMPtr extProtService(
do_GetService(NS_EXTERNALPROTOCOLSERVICE_CONTRACTID));
if (!extProtService) {
return IPC_OK();
}
- if (!uri) {
- return IPC_FAIL(this, "uri must not be null.");
- }
-
BrowsingContext* bc = aContext.get();
extProtService->LoadURI(uri, aTriggeringPrincipal, aRedirectPrincipal, bc,
aWasExternallyTriggered,
@@ -7524,7 +7529,7 @@
}
BrowsingContext* bc = aContext.GetMaybeDiscarded();
- if (!bc) {
+ if (!bc || !bc->Canonical()->IsOwnedByProcess(ChildID())) {
return IPC_OK();
}
SessionHistoryEntry* entry = bc->Canonical()->GetActiveSessionHistoryEntry();
@@ -7643,6 +7648,10 @@
return IPC_OK();
}
+ if (!aContext.get_canonical()->IsOwnedByProcess(ChildID())) {
+ return IPC_OK();
+ }
+
Maybe info;
aContext.get_canonical()->GetLoadingSessionHistoryInfoFromParent(info);
aResolver(info);
diff -Nru firefox-esr-140.13.0esr/dom/ipc/ContentParent.h firefox-esr-140.15.0esr/dom/ipc/ContentParent.h
--- firefox-esr-140.13.0esr/dom/ipc/ContentParent.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/ContentParent.h 2026-08-26 17:03:41.000000000 +0000
@@ -1006,7 +1006,7 @@
mozilla::ipc::IPCResult RecvSetURITitle(nsIURI* uri, const nsAString& title);
mozilla::ipc::IPCResult RecvLoadURIExternal(
- nsIURI* uri, nsIPrincipal* triggeringPrincipal,
+ NotNull uri, NotNull triggeringPrincipal,
nsIPrincipal* redirectPrincipal,
const MaybeDiscarded& aContext,
bool aWasExternallyTriggered, bool aHasValidUserGestureActivation,
diff -Nru firefox-esr-140.13.0esr/dom/ipc/PContent.ipdl firefox-esr-140.15.0esr/dom/ipc/PContent.ipdl
--- firefox-esr-140.13.0esr/dom/ipc/PContent.ipdl 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/PContent.ipdl 2026-08-26 17:03:41.000000000 +0000
@@ -1158,8 +1158,8 @@
async StartVisitedQueries(nullable nsIURI[] uri);
async SetURITitle(nullable nsIURI uri, nsString title);
- async LoadURIExternal(nullable nsIURI uri,
- nullable nsIPrincipal triggeringPrincipal,
+ async LoadURIExternal(nsIURI uri,
+ nsIPrincipal triggeringPrincipal,
nullable nsIPrincipal redirectPrincipal,
MaybeDiscardedBrowsingContext browsingContext,
bool wasExternallyTriggered,
diff -Nru firefox-esr-140.13.0esr/dom/ipc/ProcessIsolation.cpp firefox-esr-140.15.0esr/dom/ipc/ProcessIsolation.cpp
--- firefox-esr-140.13.0esr/dom/ipc/ProcessIsolation.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/ProcessIsolation.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -210,9 +210,14 @@
* When handling a navigation, this method will be called twice: first with the
* channel's creation URI, and then it will be called with a result principal's
* URI.
+ *
+ * `aIsWorker` selects process isolation for a remote worker rather than for a
+ * document; see the file:// URI allowlist handling below for why the two
+ * differ.
*/
static IsolationBehavior IsolationBehaviorForURI(nsIURI* aURI, bool aIsSubframe,
- bool aForChannelCreationURI) {
+ bool aForChannelCreationURI,
+ bool aIsWorker) {
MOZ_ASSERT(NS_IsMainThread());
nsAutoCString scheme;
@@ -308,7 +313,8 @@
nsCOMPtr inner;
if (nsCOMPtr nested = do_QueryInterface(aURI);
nested && NS_SUCCEEDED(nested->GetInnerURI(getter_AddRefs(inner)))) {
- return IsolationBehaviorForURI(inner, aIsSubframe, aForChannelCreationURI);
+ return IsolationBehaviorForURI(inner, aIsSubframe, aForChannelCreationURI,
+ aIsWorker);
}
// If we're doing the initial check based on the channel creation URI, stop
@@ -360,12 +366,22 @@
}
}
- nsCOMPtr secMan =
- nsContentUtils::GetSecurityManager();
- bool inFileURIAllowList = false;
- if (NS_SUCCEEDED(secMan->InFileURIAllowlist(aURI, &inFileURIAllowList)) &&
- inFileURIAllowList) {
- return IsolationBehavior::File;
+ // If the domain is allowlisted to allow it to use file:// URIs, then we have
+ // to run it in a file content process, in case it uses file:// sub-resources.
+ //
+ // This only applies to documents. A worker has no sub-resources of its own to
+ // render, and forcing it into the file process would additionally mean
+ // rejecting it outright whenever the requesting process isn't the file
+ // process (see ValidateBehaviorForWorker). Workers were likewise excluded
+ // from this rule back when it lived in E10SUtils; see bug 2064648.
+ if (!aIsWorker) {
+ nsCOMPtr secMan =
+ nsContentUtils::GetSecurityManager();
+ bool inFileURIAllowList = false;
+ if (NS_SUCCEEDED(secMan->InFileURIAllowlist(aURI, &inFileURIAllowList)) &&
+ inFileURIAllowList) {
+ return IsolationBehavior::File;
+ }
}
return IsolationBehavior::WebContent;
@@ -626,7 +642,8 @@
// First, check for any special cases which should be handled using the
// channel creation URI, and handle them.
auto behavior = IsolationBehaviorForURI(aChannelCreationURI, aParentWindow,
- /* aForChannelCreationURI */ true);
+ /* aForChannelCreationURI */ true,
+ /* aIsWorker */ false);
MOZ_LOG(gProcessIsolationLog, LogLevel::Verbose,
("Channel Creation Isolation Behavior: %s",
IsolationBehaviorName(behavior)));
@@ -731,7 +748,8 @@
}
} else if (nsCOMPtr principalURI = resultOrPrecursor->GetURI()) {
behavior = IsolationBehaviorForURI(principalURI, aParentWindow,
- /* aForChannelCreationURI */ false);
+ /* aForChannelCreationURI */ false,
+ /* aIsWorker */ false);
}
}
@@ -926,6 +944,48 @@
return options;
}
+static bool ValidateBehaviorForWorker(IsolationBehavior aBehavior,
+ const nsACString& aCurrentRemoteType) {
+ if (aCurrentRemoteType == NOT_REMOTE_TYPE) {
+ return true;
+ }
+
+ switch (aBehavior) {
+ case IsolationBehavior::Parent:
+ // Can't load in a parent process from any other process.
+ return false;
+
+ case IsolationBehavior::AboutReader:
+ case IsolationBehavior::Inherit:
+ // Not relevant for Workers.
+ return false;
+
+ case IsolationBehavior::WebContent:
+ case IsolationBehavior::ForceWebRemoteType:
+ case IsolationBehavior::Anywhere:
+ return true;
+
+ case IsolationBehavior::Extension:
+ // Extension iframes could be loaded in any process.
+ return true;
+
+ case IsolationBehavior::PrivilegedAbout:
+ return aCurrentRemoteType == PRIVILEGEDABOUT_REMOTE_TYPE;
+
+ case IsolationBehavior::File:
+ return !StaticPrefs::browser_tabs_remote_separateFileUriProcess() ||
+ aCurrentRemoteType == FILE_REMOTE_TYPE;
+
+ case IsolationBehavior::PrivilegedMozilla:
+ return aCurrentRemoteType == PRIVILEGEDMOZILLA_REMOTE_TYPE;
+
+ case IsolationBehavior::Error:
+ break;
+ }
+
+ return false;
+}
+
Result IsolationOptionsForWorker(
nsIPrincipal* aPrincipal, WorkerKind aWorkerKind,
const nsACString& aCurrentRemoteType, bool aUseRemoteSubframes) {
@@ -989,7 +1049,8 @@
if (resultOrPrecursor->GetIsContentPrincipal()) {
nsCOMPtr uri = resultOrPrecursor->GetURI();
behavior = IsolationBehaviorForURI(uri, /* aIsSubframe */ false,
- /* aForChannelCreationURI */ false);
+ /* aForChannelCreationURI */ false,
+ /* aIsWorker */ true);
} else if (resultOrPrecursor->IsSystemPrincipal()) {
MOZ_ASSERT(aWorkerKind == WorkerKindShared);
@@ -1036,6 +1097,15 @@
behavior = IsolationBehavior::ForceWebRemoteType;
}
+ if (!ValidateBehaviorForWorker(behavior, aCurrentRemoteType)) {
+ MOZ_LOG(
+ gProcessIsolationLog, LogLevel::Warning,
+ ("Rejecting invalid worker isolation behavior %s for remote type %s",
+ IsolationBehaviorName(behavior),
+ PromiseFlatCString(aCurrentRemoteType).get()));
+ return Err(NS_ERROR_FAILURE);
+ }
+
if (behavior != IsolationBehavior::WebContent) {
MOZ_TRY_VAR(
options.mRemoteType,
@@ -1252,7 +1322,8 @@
// NOTE: The logic for about URIs is somewhat complex, so we lean on
// IsolationBehaviorForURI to ensure it matches.
switch (IsolationBehaviorForURI(aboutURI, /* aIsSubframe */ false,
- /* aForChannelCreationURI */ true)) {
+ /* aForChannelCreationURI */ true,
+ /* aIsWorker */ false)) {
case IsolationBehavior::Parent:
return false;
case IsolationBehavior::Anywhere:
@@ -1299,13 +1370,24 @@
nsDependentCSubstring typePrefix(aRemoteType, 0, equalIdx);
nsDependentCSubstring typeOrigin(aRemoteType, equalIdx + 1);
- // Only validate webIsolated and webServiceWorker remote types for now. This
- // should be expanded in the future.
+ // Only validate webIsolated, webCOOP+COEP and webServiceWorker remote types
+ // for now. This should be expanded in the future.
if (typePrefix != FISSION_WEB_REMOTE_TYPE &&
+ typePrefix != WITH_COOP_COEP_REMOTE_TYPE &&
typePrefix != SERVICEWORKER_REMOTE_TYPE) {
return true;
}
+ // COOP+COEP processes might have cross-site iframes without remote subframes.
+ //
+ // HACK: Unfortunately, we can't easily check useRemoteSubframes here, but we
+ // shouldn't be loading any webCOOP+COEP windows without useRemoteSubframes if
+ // Fission is enabled.
+ if (typePrefix == WITH_COOP_COEP_REMOTE_TYPE &&
+ !mozilla::FissionAutostart()) {
+ return true;
+ }
+
// Trim any OriginAttributes from the origin, as those will not be validated.
int32_t suffixIdx = typeOrigin.RFindChar('^');
nsDependentCSubstring typeOriginNoSuffix(typeOrigin, 0, suffixIdx);
diff -Nru firefox-esr-140.13.0esr/dom/ipc/WindowGlobalParent.cpp firefox-esr-140.15.0esr/dom/ipc/WindowGlobalParent.cpp
--- firefox-esr-140.13.0esr/dom/ipc/WindowGlobalParent.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/WindowGlobalParent.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -10,6 +10,7 @@
#include "mozilla/AntiTrackingUtils.h"
#include "mozilla/AsyncEventDispatcher.h"
+#include "mozilla/BasePrincipal.h"
#include "mozilla/BounceTrackingStorageObserver.h"
#include "mozilla/BounceTrackingProtection.h"
#include "mozilla/ClearOnShutdown.h"
@@ -80,6 +81,7 @@
#include "mozilla/dom/JSWindowActorBinding.h"
#include "mozilla/dom/JSWindowActorParent.h"
+#include "mozilla/net/CookieCommons.h"
#include "mozilla/net/NeckoParent.h"
#include "mozilla/net/PCookieServiceParent.h"
#include "mozilla/net/CookieServiceParent.h"
@@ -1781,6 +1783,27 @@
const nsCString& aBaseDomain, const OriginAttributes& aOriginAttributes,
nsIURI* aHost, bool aFromHttp, bool aIsThirdParty,
const nsTArray& aCookies) {
+ // Only content principals should be setting cookies via this path.
+ // Reject non-content principals (system, null, expanded) to prevent a
+ // compromised content process from bypassing the baseDomain check below.
+ nsIPrincipal* documentPrincipal = DocumentPrincipal();
+ if (!documentPrincipal || !documentPrincipal->GetIsContentPrincipal()) {
+ return IPC_FAIL(this,
+ "SetCookies requires a content principal on the window");
+ }
+
+ // file:// principals have no meaningful baseDomain for cookie validation,
+ // skip the domain check.
+ if (!documentPrincipal->SchemeIs("file")) {
+ nsAutoCString principalBaseDomain;
+ if (NS_FAILED(net::CookieCommons::GetBaseDomain(documentPrincipal,
+ principalBaseDomain)) ||
+ !principalBaseDomain.Equals(aBaseDomain)) {
+ return IPC_FAIL(
+ this, "SetCookies baseDomain does not match document principal");
+ }
+ }
+
// Get CookieServiceParent via
// ContentParent->NeckoParent->CookieServiceParent.
ContentParent* contentParent = GetContentParent();
@@ -1794,6 +1817,21 @@
NS_ENSURE_TRUE(csParent, IPC_OK());
auto* cs = static_cast(csParent);
+ if (!aHost) {
+ return IPC_FAIL(this, "aHost must not be null");
+ }
+
+ // Authorize the write if the process has already loaded this cookie key, or
+ // could legitimately load this principal. The latter covers documents with no
+ // channel registration (e.g. file://), which never populate the key set.
+ nsCOMPtr principal =
+ BasePrincipal::CreateContentPrincipal(aHost, aOriginAttributes);
+ if (!cs->ContentProcessHasCookie(aBaseDomain, aOriginAttributes) &&
+ !contentParent->ValidatePrincipal(principal)) {
+ return IPC_FAIL(this,
+ "Content process not authorized for this cookie domain");
+ }
+
return cs->SetCookies(aBaseDomain, aOriginAttributes, aHost, aFromHttp,
aIsThirdParty, aCookies, GetBrowsingContext());
}
diff -Nru firefox-esr-140.13.0esr/dom/ipc/gtest/ProcessIsolationTest.cpp firefox-esr-140.15.0esr/dom/ipc/gtest/ProcessIsolationTest.cpp
--- firefox-esr-140.13.0esr/dom/ipc/gtest/ProcessIsolationTest.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/ipc/gtest/ProcessIsolationTest.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -82,6 +82,17 @@
return SERVICEWORKER_REMOTE_TYPE + "="_ns + origin;
}
+// When file URI process separation is disabled (as is the default on
+// Android), a file: shared worker is allowed to load in any remote type,
+// rather than being rejected when it isn't already in a file: process.
+static Result FileWorkerOutsideFileProcessExpected(
+ const nsCString& aFileRemoteType) {
+ if (StaticPrefs::browser_tabs_remote_separateFileUriProcess()) {
+ return Err(NS_ERROR_UNEXPECTED);
+ }
+ return RemoteTypes{aFileRemoteType, aFileRemoteType};
+}
+
TEST(ProcessIsolationTest, WorkerOptions)
{
// Forcibly enable the privileged mozilla content process for the duration of
@@ -159,11 +170,16 @@
WEB_REMOTE_TYPE}},
{.mPrincipal = extensionPrincipal,
.mWorkerKind = WorkerKindService,
- .mExpected = RemoteTypes{extensionRemoteType, extensionRemoteType}},
+ .mExpected = RemoteTypes{extensionRemoteType, extensionRemoteType},
+ .mCurrentRemoteType = EXTENSION_REMOTE_TYPE},
+ {.mPrincipal = privilegedMozillaPrincipal,
+ .mWorkerKind = WorkerKindService,
+ .mExpected = Err(NS_ERROR_UNEXPECTED)},
{.mPrincipal = privilegedMozillaPrincipal,
.mWorkerKind = WorkerKindService,
.mExpected = RemoteTypes{PRIVILEGEDMOZILLA_REMOTE_TYPE,
- PRIVILEGEDMOZILLA_REMOTE_TYPE}},
+ PRIVILEGEDMOZILLA_REMOTE_TYPE},
+ .mCurrentRemoteType = PRIVILEGEDMOZILLA_REMOTE_TYPE},
// Shared Worker loaded from within a webCOOP+COEP remote type process,
// should load elsewhere.
@@ -197,8 +213,7 @@
.mWorkerKind = WorkerKindShared,
.mExpected = Err(NS_ERROR_UNEXPECTED)},
- // Content principals should load in the appropriate remote types,
- // ignoring the current remote type.
+ // Content principals should load in the appropriate remote types.
{.mPrincipal = secureComPrincipal,
.mWorkerKind = WorkerKindShared,
.mExpected = RemoteTypes{WebIsolatedRemoteType(secureComPrincipal),
@@ -213,14 +228,23 @@
WEB_REMOTE_TYPE}},
{.mPrincipal = filePrincipal,
.mWorkerKind = WorkerKindShared,
- .mExpected = RemoteTypes{fileRemoteType, fileRemoteType}},
+ .mExpected = FileWorkerOutsideFileProcessExpected(fileRemoteType)},
+ {.mPrincipal = filePrincipal,
+ .mWorkerKind = WorkerKindShared,
+ .mExpected = RemoteTypes{fileRemoteType, fileRemoteType},
+ .mCurrentRemoteType = FILE_REMOTE_TYPE},
{.mPrincipal = extensionPrincipal,
.mWorkerKind = WorkerKindShared,
- .mExpected = RemoteTypes{extensionRemoteType, extensionRemoteType}},
+ .mExpected = RemoteTypes{extensionRemoteType, extensionRemoteType},
+ .mCurrentRemoteType = EXTENSION_REMOTE_TYPE},
+ {.mPrincipal = privilegedMozillaPrincipal,
+ .mWorkerKind = WorkerKindShared,
+ .mExpected = Err(NS_ERROR_UNEXPECTED)},
{.mPrincipal = privilegedMozillaPrincipal,
.mWorkerKind = WorkerKindShared,
.mExpected = RemoteTypes{PRIVILEGEDMOZILLA_REMOTE_TYPE,
- PRIVILEGEDMOZILLA_REMOTE_TYPE}},
+ PRIVILEGEDMOZILLA_REMOTE_TYPE},
+ .mCurrentRemoteType = PRIVILEGEDMOZILLA_REMOTE_TYPE},
{.mPrincipal = nullSecureComPrecursorPrincipal,
.mWorkerKind = WorkerKindShared,
.mExpected = RemoteTypes{WebIsolatedRemoteType(secureComPrincipal),
@@ -228,6 +252,77 @@
};
for (auto& expectation : expectations) {
+ expectation.Check(true);
+ expectation.Check(false);
+ }
+}
+
+// The file:// URI allowlist is populated from the `capability.policy.*` prefs,
+// which in practice are written by the LocalFileLinks enterprise policy so that
+// an intranet origin may link to files on a network share. Historically that
+// allowlist only made documents load in the file: content process; workers were
+// explicitly excluded (see the `!aIsWorker` guard that used to live in
+// E10SUtils). Since bug 1850589 dropped that exclusion, a service worker on an
+// allowlisted origin resolves to IsolationBehavior::File and is then rejected
+// outright by ValidateBehaviorForWorker, because ServiceWorkerPrivate passes
+// the shared "web" remote type rather than the file remote type.
+TEST(ProcessIsolationTest, FileURIAllowlistedWorkerOptions)
+{
+ MOZ_ALWAYS_SUCCEEDS(Preferences::SetCString("capability.policy.policynames",
+ "localfilelinks_policy"));
+ MOZ_ALWAYS_SUCCEEDS(Preferences::SetCString(
+ "capability.policy.localfilelinks_policy.checkloaduri.enabled",
+ "allAccess"));
+ MOZ_ALWAYS_SUCCEEDS(Preferences::SetCString(
+ "capability.policy.localfilelinks_policy.sites", "https://example.com"));
+ auto cleanup = MakeScopeExit([&] {
+ MOZ_ALWAYS_SUCCEEDS(
+ Preferences::ClearUser("capability.policy.policynames"));
+ MOZ_ALWAYS_SUCCEEDS(Preferences::ClearUser(
+ "capability.policy.localfilelinks_policy.checkloaduri.enabled"));
+ MOZ_ALWAYS_SUCCEEDS(Preferences::ClearUser(
+ "capability.policy.localfilelinks_policy.sites"));
+ });
+
+ nsCOMPtr allowlistedPrincipal =
+ MakeTestPrincipal("https://example.com");
+ nsCOMPtr filePrincipal =
+ MakeTestPrincipal("file:///path/to/dir");
+
+ nsCString fileRemoteType =
+ StaticPrefs::browser_tabs_remote_separateFileUriProcess()
+ ? FILE_REMOTE_TYPE
+ : WEB_REMOTE_TYPE;
+
+ WorkerExpectation expectations[] = {
+ // Being in the file:// URI allowlist must not change worker process
+ // selection: these are the same expectations as for a principal which
+ // isn't allowlisted at all. The current remote type mirrors what
+ // ServiceWorkerPrivate::Initialize() passes for a service worker.
+ {.mPrincipal = allowlistedPrincipal,
+ .mWorkerKind = WorkerKindService,
+ .mExpected =
+ RemoteTypes{ServiceWorkerIsolatedRemoteType(allowlistedPrincipal),
+ WEB_REMOTE_TYPE},
+ .mCurrentRemoteType = WEB_REMOTE_TYPE},
+ {.mPrincipal = allowlistedPrincipal,
+ .mWorkerKind = WorkerKindShared,
+ .mExpected = RemoteTypes{WebIsolatedRemoteType(allowlistedPrincipal),
+ WEB_REMOTE_TYPE},
+ .mCurrentRemoteType = WEB_REMOTE_TYPE},
+
+ // An actual file: principal is still confined to the file process,
+ // regardless of the allowlist.
+ {.mPrincipal = filePrincipal,
+ .mWorkerKind = WorkerKindShared,
+ .mExpected = FileWorkerOutsideFileProcessExpected(fileRemoteType)},
+ {.mPrincipal = filePrincipal,
+ .mWorkerKind = WorkerKindShared,
+ .mExpected = RemoteTypes{fileRemoteType, fileRemoteType},
+ .mCurrentRemoteType = FILE_REMOTE_TYPE},
+ };
+
+ for (auto& expectation : expectations) {
expectation.Check(true);
expectation.Check(false);
}
diff -Nru firefox-esr-140.13.0esr/dom/localstorage/ActorsParent.cpp firefox-esr-140.15.0esr/dom/localstorage/ActorsParent.cpp
--- firefox-esr-140.13.0esr/dom/localstorage/ActorsParent.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/localstorage/ActorsParent.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -68,6 +68,7 @@
#include "mozilla/dom/PBackgroundLSSharedTypes.h"
#include "mozilla/dom/PBackgroundLSSimpleRequestParent.h"
#include "mozilla/dom/PBackgroundLSSnapshotParent.h"
+#include "mozilla/dom/ProcessIsolation.h"
#include "mozilla/dom/SnappyUtils.h"
#include "mozilla/dom/StorageDBUpdater.h"
#include "mozilla/dom/StorageUtils.h"
@@ -1676,7 +1677,7 @@
class PreparedDatastore {
RefPtr mDatastore;
nsCOMPtr mTimer;
- const Maybe mContentParentId;
+ const RefPtr mContentParentHandle;
// Strings share buffers if possible, so it's not a problem to duplicate the
// origin here.
const nsCString mOrigin;
@@ -1686,12 +1687,12 @@
public:
PreparedDatastore(Datastore* aDatastore,
- const Maybe& aContentParentId,
+ ThreadsafeContentParentHandle* aContentParentHandle,
const nsACString& aOrigin, uint64_t aDatastoreId,
bool aForPreload)
: mDatastore(aDatastore),
mTimer(NS_NewTimer()),
- mContentParentId(aContentParentId),
+ mContentParentHandle(aContentParentHandle),
mOrigin(aOrigin),
mDatastoreId(aDatastoreId),
mForPreload(aForPreload),
@@ -1730,8 +1731,8 @@
return *mDatastore;
}
- const Maybe& GetContentParentId() const {
- return mContentParentId;
+ ThreadsafeContentParentHandle* GetContentParentHandle() const {
+ return mContentParentHandle;
}
const nsCString& Origin() const { return mOrigin; }
@@ -1772,7 +1773,7 @@
RefPtr mDatastore;
Snapshot* mSnapshot;
const PrincipalInfo mPrincipalInfo;
- const Maybe mContentParentId;
+ const RefPtr mContentParentHandle;
// Strings share buffers if possible, so it's not a problem to duplicate the
// origin here.
nsCString mOrigin;
@@ -1788,7 +1789,7 @@
public:
// Created in AllocPBackgroundLSDatabaseParent.
Database(const PrincipalInfo& aPrincipalInfo,
- const Maybe& aContentParentId,
+ ThreadsafeContentParentHandle* aContentParentHandle,
const nsACString& aOrigin, uint32_t aPrivateBrowsingId);
void AssertIsOnOwningThread() const {
@@ -1809,8 +1810,8 @@
const PrincipalInfo& GetPrincipalInfo() const { return mPrincipalInfo; }
- const Maybe& ContentParentIdRef() const {
- return mContentParentId;
+ ThreadsafeContentParentHandle* ContentParentHandle() const {
+ return mContentParentHandle;
}
uint32_t PrivateBrowsingId() const { return mPrivateBrowsingId; }
@@ -2088,17 +2089,17 @@
};
class Observer final : public PBackgroundLSObserverParent {
- const Maybe mContentParentId;
+ const RefPtr mContentParentHandle;
nsCString mOrigin;
bool mActorDestroyed;
public:
// Created in AllocPBackgroundLSObserverParent.
- Observer(const Maybe& aContentParentId,
+ Observer(ThreadsafeContentParentHandle* aContentParentHandle,
const nsACString& aOrigin);
- const Maybe& ContentParentIdRef() const {
- return mContentParentId;
+ ThreadsafeContentParentHandle* ContentParentHandle() const {
+ return mContentParentHandle;
}
const nsCString& Origin() const { return mOrigin; }
@@ -2151,13 +2152,13 @@
};
const LSRequestParams mParams;
- Maybe mContentParentId;
+ RefPtr mContentParentHandle;
State mState;
bool mWaitingForFinish;
public:
LSRequestBase(const LSRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
void Dispatch();
@@ -2170,6 +2171,10 @@
protected:
~LSRequestBase() override;
+ ThreadsafeContentParentHandle* ContentParentHandle() const {
+ return mContentParentHandle;
+ }
+
virtual nsresult Start() = 0;
virtual nsresult NestedRun();
@@ -2319,7 +2324,7 @@
public:
PrepareDatastoreOp(const LSRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
Maybe MaybeDirectoryLockRef() const {
AssertIsOnBackgroundThread();
@@ -2460,7 +2465,7 @@
public:
PrepareObserverOp(const LSRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
private:
nsresult Start() override;
@@ -2488,12 +2493,12 @@
};
const LSSimpleRequestParams mParams;
- Maybe mContentParentId;
+ RefPtr mContentParentHandle;
State mState;
public:
LSSimpleRequestBase(const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
void Dispatch();
@@ -2524,7 +2529,7 @@
public:
PreloadedOp(const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
private:
nsresult Start() override;
@@ -2537,7 +2542,7 @@
public:
GetStateOp(const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId);
+ ThreadsafeContentParentHandle* aContentParentHandle);
private:
nsresult Start() override;
@@ -3118,7 +3123,8 @@
}
}
-bool VerifyPrincipalInfo(const PrincipalInfo& aPrincipalInfo,
+bool VerifyPrincipalInfo(ThreadsafeContentParentHandle* aContentParentHandle,
+ const PrincipalInfo& aPrincipalInfo,
const PrincipalInfo& aStoragePrincipalInfo,
bool aCheckClientPrincipal) {
AssertIsOnBackgroundThread();
@@ -3127,6 +3133,17 @@
return false;
}
+ auto prinResult = PrincipalInfoToPrincipal(aPrincipalInfo);
+ if (NS_WARN_IF(prinResult.isErr())) {
+ return false;
+ }
+
+ if (aContentParentHandle &&
+ NS_WARN_IF(!ValidatePrincipalCouldPotentiallyBeLoadedBy(
+ prinResult.inspect(), aContentParentHandle->GetRemoteType(), {}))) {
+ return false;
+ }
+
// Note that the client prinicpal could have a different spec than the node
// principal but they should have the same origin. It's because the client
// could be initialized when opening the initial about:blank document and pass
@@ -3150,7 +3167,7 @@
return true;
}
-bool VerifyClientId(const Maybe& aContentParentId,
+bool VerifyClientId(ThreadsafeContentParentHandle* aContentParentHandle,
const Maybe& aPrincipalInfo,
const Maybe& aClientId) {
AssertIsOnBackgroundThread();
@@ -3165,8 +3182,9 @@
}
RefPtr svc = ClientManagerService::GetInstance();
- if (svc && NS_WARN_IF(!svc->HasWindow(
- aContentParentId, aPrincipalInfo.ref(), aClientId.ref()))) {
+ if (svc &&
+ NS_WARN_IF(!svc->HasWindow(aContentParentHandle, aPrincipalInfo.ref(),
+ aClientId.ref()))) {
return false;
}
}
@@ -3280,7 +3298,7 @@
// method.
RefPtr database =
- new Database(aPrincipalInfo, preparedDatastore->GetContentParentId(),
+ new Database(aPrincipalInfo, preparedDatastore->GetContentParentHandle(),
preparedDatastore->Origin(), aPrivateBrowsingId);
return database.forget();
@@ -3416,12 +3434,8 @@
return nullptr;
}
- Maybe contentParentId;
-
- uint64_t childID = BackgroundParent::GetChildID(aBackgroundActor);
- if (childID) {
- contentParentId = Some(ContentParentId(childID));
- }
+ RefPtr contentParentHandle =
+ BackgroundParent::GetContentParentHandle(aBackgroundActor);
RefPtr actor;
@@ -3429,7 +3443,7 @@
case LSRequestParams::TLSRequestPreloadDatastoreParams:
case LSRequestParams::TLSRequestPrepareDatastoreParams: {
RefPtr prepareDatastoreOp =
- new PrepareDatastoreOp(aParams, contentParentId);
+ new PrepareDatastoreOp(aParams, contentParentHandle);
if (!gPrepareDatastoreOps) {
gPrepareDatastoreOps = new PrepareDatastoreOpArray();
@@ -3444,7 +3458,7 @@
case LSRequestParams::TLSRequestPrepareObserverParams: {
RefPtr prepareObserverOp =
- new PrepareObserverOp(aParams, contentParentId);
+ new PrepareObserverOp(aParams, contentParentHandle);
actor = std::move(prepareObserverOp);
@@ -3499,19 +3513,15 @@
return nullptr;
}
- Maybe contentParentId;
-
- uint64_t childID = BackgroundParent::GetChildID(aBackgroundActor);
- if (childID) {
- contentParentId = Some(ContentParentId(childID));
- }
+ RefPtr contentParentHandle =
+ BackgroundParent::GetContentParentHandle(aBackgroundActor);
RefPtr actor;
switch (aParams.type()) {
case LSSimpleRequestParams::TLSSimpleRequestPreloadedParams: {
RefPtr preloadedOp =
- new PreloadedOp(aParams, contentParentId);
+ new PreloadedOp(aParams, contentParentHandle);
actor = std::move(preloadedOp);
@@ -3519,7 +3529,8 @@
}
case LSSimpleRequestParams::TLSSimpleRequestGetStateParams: {
- RefPtr getStateOp = new GetStateOp(aParams, contentParentId);
+ RefPtr getStateOp =
+ new GetStateOp(aParams, contentParentHandle);
actor = std::move(getStateOp);
@@ -4595,7 +4606,7 @@
AssertIsOnBackgroundThread();
for (Database* database : mDatabases) {
- if (database->ContentParentIdRef() != aDatabase->ContentParentIdRef()) {
+ if (database->ContentParentHandle() != aDatabase->ContentParentHandle()) {
return true;
}
}
@@ -5103,7 +5114,7 @@
MOZ_ASSERT(array);
for (Observer* observer : *array) {
- if (observer->ContentParentIdRef() != aDatabase->ContentParentIdRef()) {
+ if (observer->ContentParentHandle() != aDatabase->ContentParentHandle()) {
return true;
}
}
@@ -5134,7 +5145,7 @@
// that caused the change.
for (Observer* observer : *array) {
- if (observer->ContentParentIdRef() != aDatabase->ContentParentIdRef()) {
+ if (observer->ContentParentHandle() != aDatabase->ContentParentHandle()) {
observer->Observe(aDatabase, aDocumentURI, aKey, aOldValue, aNewValue);
}
}
@@ -5155,7 +5166,7 @@
bool hasOtherProcessObservers = false;
for (Observer* observer : aObservers) {
- if (observer->ContentParentIdRef() != database->ContentParentIdRef()) {
+ if (observer->ContentParentHandle() != database->ContentParentHandle()) {
hasOtherProcessObservers = true;
break;
}
@@ -5363,11 +5374,11 @@
******************************************************************************/
Database::Database(const PrincipalInfo& aPrincipalInfo,
- const Maybe& aContentParentId,
+ ThreadsafeContentParentHandle* aContentParentHandle,
const nsACString& aOrigin, uint32_t aPrivateBrowsingId)
: mSnapshot(nullptr),
mPrincipalInfo(aPrincipalInfo),
- mContentParentId(aContentParentId),
+ mContentParentHandle(aContentParentHandle),
mOrigin(aOrigin),
mRequestAllowToCloseTimerId(0),
mPrivateBrowsingId(aPrivateBrowsingId),
@@ -5492,7 +5503,7 @@
aResult.Append(kQuotaGenericDelimiter);
aResult.AppendLiteral("OtherProcessActor:");
- aResult.AppendInt(mContentParentId.isSome());
+ aResult.AppendInt(!!mContentParentHandle);
aResult.Append(kQuotaGenericDelimiter);
aResult.AppendLiteral("Origin:");
@@ -6153,9 +6164,9 @@
* Observer
******************************************************************************/
-Observer::Observer(const Maybe& aContentParentId,
+Observer::Observer(ThreadsafeContentParentHandle* aContentParentHandle,
const nsACString& aOrigin)
- : mContentParentId(aContentParentId),
+ : mContentParentHandle(aContentParentHandle),
mOrigin(aOrigin),
mActorDestroyed(false) {
AssertIsOnBackgroundThread();
@@ -6216,10 +6227,11 @@
* LSRequestBase
******************************************************************************/
-LSRequestBase::LSRequestBase(const LSRequestParams& aParams,
- const Maybe& aContentParentId)
+LSRequestBase::LSRequestBase(
+ const LSRequestParams& aParams,
+ ThreadsafeContentParentHandle* aContentParentHandle)
: mParams(aParams),
- mContentParentId(aContentParentId),
+ mContentParentHandle(aContentParentHandle),
mState(State::Initial),
mWaitingForFinish(false) {}
@@ -6308,7 +6320,8 @@
mParams.get_LSRequestPreloadDatastoreParams().commonParams();
if (NS_WARN_IF(!VerifyPrincipalInfo(
- params.principalInfo(), params.storagePrincipalInfo(), false))) {
+ ContentParentHandle(), params.principalInfo(),
+ params.storagePrincipalInfo(), false))) {
return false;
}
@@ -6326,20 +6339,20 @@
const LSRequestCommonParams& commonParams = params.commonParams();
- if (NS_WARN_IF(!VerifyPrincipalInfo(commonParams.principalInfo(),
- commonParams.storagePrincipalInfo(),
- false))) {
+ if (NS_WARN_IF(!VerifyPrincipalInfo(
+ ContentParentHandle(), commonParams.principalInfo(),
+ commonParams.storagePrincipalInfo(), false))) {
return false;
}
if (params.clientPrincipalInfo() &&
- NS_WARN_IF(!VerifyPrincipalInfo(commonParams.principalInfo(),
- params.clientPrincipalInfo().ref(),
- true))) {
+ NS_WARN_IF(!VerifyPrincipalInfo(
+ ContentParentHandle(), commonParams.principalInfo(),
+ params.clientPrincipalInfo().ref(), true))) {
return false;
}
- if (NS_WARN_IF(!VerifyClientId(mContentParentId,
+ if (NS_WARN_IF(!VerifyClientId(ContentParentHandle(),
params.clientPrincipalInfo(),
params.clientId()))) {
return false;
@@ -6358,18 +6371,19 @@
mParams.get_LSRequestPrepareObserverParams();
if (NS_WARN_IF(!VerifyPrincipalInfo(
- params.principalInfo(), params.storagePrincipalInfo(), false))) {
+ ContentParentHandle(), params.principalInfo(),
+ params.storagePrincipalInfo(), false))) {
return false;
}
if (params.clientPrincipalInfo() &&
- NS_WARN_IF(!VerifyPrincipalInfo(params.principalInfo(),
- params.clientPrincipalInfo().ref(),
- true))) {
+ NS_WARN_IF(!VerifyPrincipalInfo(
+ ContentParentHandle(), params.principalInfo(),
+ params.clientPrincipalInfo().ref(), true))) {
return false;
}
- if (NS_WARN_IF(!VerifyClientId(mContentParentId,
+ if (NS_WARN_IF(!VerifyClientId(ContentParentHandle(),
params.clientPrincipalInfo(),
params.clientId()))) {
return false;
@@ -6612,8 +6626,8 @@
PrepareDatastoreOp::PrepareDatastoreOp(
const LSRequestParams& aParams,
- const Maybe& aContentParentId)
- : LSRequestBase(aParams, aContentParentId),
+ ThreadsafeContentParentHandle* aContentParentHandle)
+ : LSRequestBase(aParams, aContentParentHandle),
mProcessingTimerId(
glean::localstorage_request::prepare_datastore_processing_time
.Start()),
@@ -7592,8 +7606,8 @@
}
const auto& preparedDatastore = gPreparedDatastores->InsertOrUpdate(
mDatastoreId, MakeUnique(
- mDatastore, mContentParentId, Origin(), mDatastoreId,
- /* aForPreload */ mForPreload));
+ mDatastore, ContentParentHandle(), Origin(),
+ mDatastoreId, /* aForPreload */ mForPreload));
if (mInvalidated) {
preparedDatastore->Invalidate();
@@ -7972,8 +7986,8 @@
PrepareObserverOp::PrepareObserverOp(
const LSRequestParams& aParams,
- const Maybe& aContentParentId)
- : LSRequestBase(aParams, aContentParentId) {
+ ThreadsafeContentParentHandle* aContentParentHandle)
+ : LSRequestBase(aParams, aContentParentHandle) {
MOZ_ASSERT(aParams.type() ==
LSRequestParams::TLSRequestPrepareObserverParams);
}
@@ -8013,7 +8027,7 @@
uint64_t observerId = ++gLastObserverId;
- RefPtr observer = new Observer(mContentParentId, mOrigin);
+ RefPtr observer = new Observer(ContentParentHandle(), mOrigin);
if (!gPreparedObsevers) {
gPreparedObsevers = new PreparedObserverHashtable();
@@ -8033,9 +8047,9 @@
LSSimpleRequestBase::LSSimpleRequestBase(
const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId)
+ ThreadsafeContentParentHandle* aContentParentHandle)
: mParams(aParams),
- mContentParentId(aContentParentId),
+ mContentParentHandle(aContentParentHandle),
mState(State::Initial) {}
LSSimpleRequestBase::~LSSimpleRequestBase() {
@@ -8061,8 +8075,9 @@
const LSSimpleRequestPreloadedParams& params =
mParams.get_LSSimpleRequestPreloadedParams();
- if (NS_WARN_IF(!VerifyPrincipalInfo(
- params.principalInfo(), params.storagePrincipalInfo(), false))) {
+ if (NS_WARN_IF(
+ !VerifyPrincipalInfo(mContentParentHandle, params.principalInfo(),
+ params.storagePrincipalInfo(), false))) {
return false;
}
@@ -8073,8 +8088,9 @@
const LSSimpleRequestGetStateParams& params =
mParams.get_LSSimpleRequestGetStateParams();
- if (NS_WARN_IF(!VerifyPrincipalInfo(
- params.principalInfo(), params.storagePrincipalInfo(), false))) {
+ if (NS_WARN_IF(
+ !VerifyPrincipalInfo(mContentParentHandle, params.principalInfo(),
+ params.storagePrincipalInfo(), false))) {
return false;
}
@@ -8183,8 +8199,8 @@
******************************************************************************/
PreloadedOp::PreloadedOp(const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId)
- : LSSimpleRequestBase(aParams, aContentParentId) {
+ ThreadsafeContentParentHandle* aContentParentHandle)
+ : LSSimpleRequestBase(aParams, aContentParentHandle) {
MOZ_ASSERT(aParams.type() ==
LSSimpleRequestParams::TLSSimpleRequestPreloadedParams);
}
@@ -8240,8 +8256,8 @@
******************************************************************************/
GetStateOp::GetStateOp(const LSSimpleRequestParams& aParams,
- const Maybe& aContentParentId)
- : LSSimpleRequestBase(aParams, aContentParentId) {
+ ThreadsafeContentParentHandle* aContentParentHandle)
+ : LSSimpleRequestBase(aParams, aContentParentHandle) {
MOZ_ASSERT(aParams.type() ==
LSSimpleRequestParams::TLSSimpleRequestGetStateParams);
}
@@ -8894,18 +8910,15 @@
void QuotaClient::AbortOperationsForProcess(ContentParentId aContentParentId) {
AssertIsOnBackgroundThread();
- // XXX Quota Manager should do the wrapping.
- Maybe contentParentId;
-
- if (aContentParentId) {
- contentParentId = Some(aContentParentId);
- }
-
// XXX We could try to invalidate other objects here.
RequestAllowToCloseDatabasesMatching(
- [&contentParentId](const auto& database) {
- return database.ContentParentIdRef() == contentParentId;
+ [aContentParentId](const auto& database) {
+ ThreadsafeContentParentHandle* contentParentHandle =
+ database.ContentParentHandle();
+ return contentParentHandle
+ ? contentParentHandle->ChildID() == aContentParentId
+ : !aContentParentId;
});
}
diff -Nru firefox-esr-140.13.0esr/dom/media/AudioPacketizer.h firefox-esr-140.15.0esr/dom/media/AudioPacketizer.h
--- firefox-esr-140.13.0esr/dom/media/AudioPacketizer.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/AudioPacketizer.h 2026-08-26 17:03:41.000000000 +0000
@@ -8,9 +8,15 @@
#include
#include
+#include
+#include
#include
+#include
#include
+#include "nsDebug.h"
+#include "nsError.h"
+
// Enable this to warn when `Output` has been called but not enough data was
// buffered.
// #define LOG_PACKETIZER_UNDERRUN
@@ -49,46 +55,60 @@
"positive");
}
- void Input(const InputType* aFrames, uint32_t aFrameCount) {
- uint32_t inputSamples = aFrameCount * mChannels;
+ [[nodiscard]] nsresult Input(const InputType* aFrames, uint32_t aFrameCount) {
+ CheckedUint32 inputSamples = CheckedUint32(aFrameCount) * mChannels;
+ if (!inputSamples.isValid()) {
+ NS_WARNING("AudioPacketizer::Input: frame count too large to buffer");
+ return NS_ERROR_DOM_MEDIA_OVERFLOW_ERR;
+ }
// Need to grow the storage. This should rarely happen, if at all, once the
// array has the right size.
- if (inputSamples > EmptySlots()) {
+ if (inputSamples.value() > EmptySlots()) {
// Calls to Input and Output are roughtly interleaved
// (Input,Output,Input,Output, etc.), or balanced
// (Input,Input,Input,Output,Output,Output), so we update the buffer to
// the exact right size in order to not waste space.
- uint32_t newLength = AvailableSamples() + inputSamples;
- uint32_t toCopy = AvailableSamples();
- UniquePtr oldStorage = std::move(mStorage);
- mStorage = mozilla::MakeUnique(newLength);
+ CheckedUint32 newLength =
+ CheckedUint32(AvailableSamples()) + inputSamples;
+ if (!newLength.isValid()) {
+ NS_WARNING("AudioPacketizer::Input: buffer size too large to grow");
+ return NS_ERROR_DOM_MEDIA_OVERFLOW_ERR;
+ }
+ UniquePtr newStorage =
+ mozilla::MakeUniqueFallible(newLength.value());
+ if (!newStorage) {
+ NS_WARNING("AudioPacketizer::Input: buffer allocation failed");
+ return NS_ERROR_OUT_OF_MEMORY;
+ }
// Copy the old data at the beginning of the new storage.
if (WriteIndex() >= ReadIndex()) {
- PodCopy(mStorage.get(), oldStorage.get() + ReadIndex(),
+ PodCopy(newStorage.get(), mStorage.get() + ReadIndex(),
AvailableSamples());
} else {
uint32_t firstPartLength = mLength - ReadIndex();
uint32_t secondPartLength = AvailableSamples() - firstPartLength;
- PodCopy(mStorage.get(), oldStorage.get() + ReadIndex(),
+ PodCopy(newStorage.get(), mStorage.get() + ReadIndex(),
firstPartLength);
- PodCopy(mStorage.get() + firstPartLength, oldStorage.get(),
+ PodCopy(newStorage.get() + firstPartLength, mStorage.get(),
secondPartLength);
}
- mWriteIndex = toCopy;
+ mStorage = std::move(newStorage);
+ mWriteIndex -= mReadIndex;
mReadIndex = 0;
- mLength = newLength;
+ mLength = newLength.value();
}
- if (WriteIndex() + inputSamples <= mLength) {
- PodCopy(mStorage.get() + WriteIndex(), aFrames, aFrameCount * mChannels);
+ if (WriteIndex() + inputSamples.value() <= mLength) {
+ PodCopy(mStorage.get() + WriteIndex(), aFrames, inputSamples.value());
} else {
uint32_t firstPartLength = mLength - WriteIndex();
- uint32_t secondPartLength = inputSamples - firstPartLength;
+ uint32_t secondPartLength = inputSamples.value() - firstPartLength;
PodCopy(mStorage.get() + WriteIndex(), aFrames, firstPartLength);
PodCopy(mStorage.get(), aFrames + firstPartLength, secondPartLength);
}
- mWriteIndex += inputSamples;
+ mWriteIndex += inputSamples.value();
+ return NS_OK;
}
OutputType* Output() {
@@ -162,7 +182,13 @@
uint32_t WriteIndex() const { return mWriteIndex % mLength; }
- uint32_t AvailableSamples() const { return mWriteIndex - mReadIndex; }
+ uint32_t AvailableSamples() const {
+ // Output never advances mReadIndex past mWriteIndex (it clamps to the
+ // available count on under-run), so the difference is never negative.
+ // The live count is bounded by mLength (a uint32), so the cast is in range.
+ MOZ_DIAGNOSTIC_ASSERT(mWriteIndex >= mReadIndex);
+ return AssertedCast(mWriteIndex - mReadIndex);
+ }
uint32_t EmptySlots() const { return mLength - AvailableSamples(); }
diff -Nru firefox-esr-140.13.0esr/dom/media/AudioSegment.cpp firefox-esr-140.15.0esr/dom/media/AudioSegment.cpp
--- firefox-esr-140.13.0esr/dom/media/AudioSegment.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/AudioSegment.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -32,9 +32,11 @@
}
template
-void AudioSegment::Resample(nsAutoRef& aResampler,
- uint32_t* aResamplerChannelCount, uint32_t aInRate,
- uint32_t aOutRate) {
+nsresult AudioSegment::Resample(nsAutoRef& aResampler,
+ uint32_t* aResamplerChannelCount,
+ uint32_t aInRate, uint32_t aOutRate) {
+ MOZ_ASSERT(aInRate > 0);
+ MOZ_ASSERT(aOutRate > 0);
mDuration = 0;
for (ChunkIterator ci(*this); !ci.IsEnded(); ci.Next()) {
@@ -47,6 +49,7 @@
mDuration += c.mDuration;
continue;
}
+ MOZ_ASSERT(c.mDuration > 0);
uint32_t channels = c.mChannelData.Length();
// This might introduce a discontinuity, but a channel count change in the
// middle of a stream is not that common. This also initializes the
@@ -61,16 +64,26 @@
}
output.SetLength(channels);
bufferPtrs.SetLength(channels);
- uint32_t inFrames = c.mDuration;
- // Round up to allocate; the last frame may not be used.
- NS_ASSERTION((UINT64_MAX - aInRate + 1) / c.mDuration >= aOutRate,
- "Dropping samples");
- uint32_t outSize =
- (static_cast(c.mDuration) * aOutRate + aInRate - 1) / aInRate;
+ // Round up in 64 bits, and reject a size that will not fit in uint32_t,
+ // which would otherwise silently drop part of the chunk. Clearing keeps
+ // mDuration the sum of the chunk durations.
+ CheckedUint32 outSizeChecked =
+ ((CheckedInt(c.mDuration) * aOutRate + (aInRate - 1)) /
+ aInRate)
+ .toChecked();
+ if (!outSizeChecked.isValid()) {
+ Clear();
+ return NS_ERROR_DOM_MEDIA_OVERFLOW_ERR;
+ }
+ uint32_t outSize = outSizeChecked.value();
for (uint32_t i = 0; i < channels; i++) {
T* out = output[i].AppendElements(outSize);
uint32_t outFrames = outSize;
+ // Speex overwrites this count, so reset it for each channel: sharing one
+ // variable would resample later channels from fewer frames and leave
+ // their buffers short of the duration the chunk advertises.
+ uint32_t inFrames = c.mDuration;
const T* in = static_cast(c.mChannelData[i]);
dom::WebAudioUtils::SpeexResamplerProcess(aResampler.get(), i, in,
&inFrames, out, &outFrames);
@@ -78,6 +91,7 @@
bufferPtrs[i] = out;
output[i].SetLength(outFrames);
+ MOZ_ASSERT(output[i].Length() == output[0].Length());
}
MOZ_ASSERT(channels > 0);
c.mDuration = output[0].Length();
@@ -87,13 +101,14 @@
}
mDuration += c.mDuration;
}
+ return NS_OK;
}
-void AudioSegment::ResampleChunks(nsAutoRef& aResampler,
- uint32_t* aResamplerChannelCount,
- uint32_t aInRate, uint32_t aOutRate) {
+nsresult AudioSegment::ResampleChunks(
+ nsAutoRef& aResampler,
+ uint32_t* aResamplerChannelCount, uint32_t aInRate, uint32_t aOutRate) {
if (mChunks.IsEmpty()) {
- return;
+ return NS_OK;
}
AudioSampleFormat format = AUDIO_FORMAT_SILENCE;
@@ -109,14 +124,14 @@
// the chunks duration.
case AUDIO_FORMAT_SILENCE:
case AUDIO_FORMAT_FLOAT32:
- Resample(aResampler, aResamplerChannelCount, aInRate, aOutRate);
- break;
+ return Resample(aResampler, aResamplerChannelCount, aInRate,
+ aOutRate);
case AUDIO_FORMAT_S16:
- Resample(aResampler, aResamplerChannelCount, aInRate, aOutRate);
- break;
+ return Resample(aResampler, aResamplerChannelCount, aInRate,
+ aOutRate);
default:
MOZ_ASSERT(false);
- break;
+ return NS_ERROR_UNEXPECTED;
}
}
diff -Nru firefox-esr-140.13.0esr/dom/media/AudioSegment.h firefox-esr-140.15.0esr/dom/media/AudioSegment.h
--- firefox-esr-140.13.0esr/dom/media/AudioSegment.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/AudioSegment.h 2026-08-26 17:03:41.000000000 +0000
@@ -354,9 +354,11 @@
// function finds a chunk with more channels, `aResampler` is destroyed and a
// new resampler is created, and `aResamplerChannelCount` is updated with the
// new channel count value.
- void ResampleChunks(nsAutoRef& aResampler,
- uint32_t* aResamplerChannelCount, uint32_t aInRate,
- uint32_t aOutRate);
+ // Rates must be non-zero. Clears the segment and returns an error if the
+ // output size is not representable.
+ [[nodiscard]] nsresult ResampleChunks(
+ nsAutoRef& aResampler,
+ uint32_t* aResamplerChannelCount, uint32_t aInRate, uint32_t aOutRate);
template
void AppendFrames(already_AddRefed aBuffer,
@@ -465,9 +467,9 @@
private:
template
- void Resample(nsAutoRef& aResampler,
- uint32_t* aResamplerChannelCount, uint32_t aInRate,
- uint32_t aOutRate);
+ [[nodiscard]] nsresult Resample(nsAutoRef& aResampler,
+ uint32_t* aResamplerChannelCount,
+ uint32_t aInRate, uint32_t aOutRate);
};
template
diff -Nru firefox-esr-140.13.0esr/dom/media/GraphDriver.cpp firefox-esr-140.15.0esr/dom/media/GraphDriver.cpp
--- firefox-esr-140.13.0esr/dom/media/GraphDriver.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/GraphDriver.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -655,9 +655,10 @@
forcedOutputDeviceId ? forcedOutputDeviceId : outputId, &output,
latencyFrames, DataCallback_s, StateCallback_s, this) == CUBEB_OK) {
mCubeb = handle;
- mAudioStream.own(stream);
- DebugOnly rv =
- cubeb_stream_set_volume(mAudioStream, CubebUtils::GetVolumeScale());
+ auto streamLocked = mAudioStream.Lock();
+ streamLocked->own(stream);
+ DebugOnly rv = cubeb_stream_set_volume(streamLocked.ref(),
+ CubebUtils::GetVolumeScale());
NS_WARNING_ASSERTION(
rv == CUBEB_OK,
"Could not set the audio stream volume in GraphDriver.cpp");
@@ -684,8 +685,11 @@
SetInputProcessingParams(mInputProcessingRequest);
}
- cubeb_stream_register_device_changed_callback(
- mAudioStream, AudioCallbackDriver::DeviceChangedCallback_s);
+ {
+ auto streamLocked = mAudioStream.Lock();
+ cubeb_stream_register_device_changed_callback(
+ streamLocked.ref(), AudioCallbackDriver::DeviceChangedCallback_s);
+ }
// No-op if MOZ_DUMP_AUDIO is not defined as an environment variable. This
// is intended for diagnosing issues, and only works if the content sandbox is
@@ -704,8 +708,9 @@
void AudioCallbackDriver::SetCubebStreamName(const nsCString& aStreamName) {
MOZ_ASSERT(OnCubebOperationThread());
- MOZ_ASSERT(mAudioStream);
- cubeb_stream_set_name(mAudioStream, aStreamName.get());
+ auto streamLocked = mAudioStream.Lock();
+ MOZ_ASSERT(streamLocked.ref());
+ cubeb_stream_set_name(streamLocked.ref(), aStreamName.get());
}
void AudioCallbackDriver::Start() {
@@ -767,7 +772,8 @@
// can result in a callback (that may read mAudioStreamState) before
// mAudioStreamState would otherwise be set.
mAudioStreamState = AudioStreamState::Starting;
- if (cubeb_stream_start(mAudioStream) != CUBEB_OK) {
+ auto streamLocked = mAudioStream.Lock();
+ if (cubeb_stream_start(streamLocked.ref()) != CUBEB_OK) {
NS_WARNING("Could not start cubeb stream for MTG.");
return false;
}
@@ -780,8 +786,9 @@
("%p: AudioCallbackDriver::Stop driver=%p", Graph(), this));
TRACE("AudioCallbackDriver::Stop");
MOZ_ASSERT(OnCubebOperationThread());
- cubeb_stream_register_device_changed_callback(mAudioStream, nullptr);
- if (cubeb_stream_stop(mAudioStream) != CUBEB_OK) {
+ auto streamLocked = mAudioStream.Lock();
+ cubeb_stream_register_device_changed_callback(streamLocked.ref(), nullptr);
+ if (cubeb_stream_stop(streamLocked.ref()) != CUBEB_OK) {
NS_WARNING("Could not stop cubeb stream for MTG.");
} else {
mAudioStreamState = AudioStreamState::None;
@@ -1193,7 +1200,8 @@
// For macbook pro before 2016 model (change of chassis), hard pan the audio
// to the right if the speakers are in use to avoid feedback.
if (model == MacBookPro && major <= 12) {
- if (cubeb_stream_get_current_device(mAudioStream, &out) == CUBEB_OK) {
+ auto streamLocked = mAudioStream.Lock();
+ if (cubeb_stream_get_current_device(streamLocked.ref(), &out) == CUBEB_OK) {
MOZ_ASSERT(out);
// Check if we are currently outputing sound on external speakers.
if (out->output_name && !strcmp(out->output_name, "ispk")) {
@@ -1205,7 +1213,7 @@
LOG(LogLevel::Debug, ("Using an external output device"));
mNeedsPanning = false;
}
- cubeb_stream_device_destroy(mAudioStream, out);
+ cubeb_stream_device_destroy(streamLocked.ref(), out);
}
}
#endif
@@ -1277,8 +1285,12 @@
TimeDuration AudioCallbackDriver::AudioOutputLatency() {
TRACE("AudioCallbackDriver::AudioOutputLatency");
+ // Called from the main thread, unlike virtually everything else touching
+ // mAudioStream, hence the lock: latency can change over the life of the
+ // stream, so it must be queried live rather than cached at Init() time.
uint32_t latencyFrames;
- int rv = cubeb_stream_get_latency(mAudioStream, &latencyFrames);
+ auto streamLocked = mAudioStream.Lock();
+ int rv = cubeb_stream_get_latency(streamLocked.ref(), &latencyFrames);
if (rv || mSampleRate == 0) {
return TimeDuration::FromSeconds(0.0);
}
@@ -1435,6 +1447,7 @@
const auto requested = aRequest.mParams;
auto params = aRequest.mParams;
const auto generation = aRequest.mGeneration;
+ auto streamLocked = mAudioStream.Lock();
auto result = ([&]() -> Maybe> {
// This function decides how to handle the request.
// Returning Nothing() does nothing, because either
@@ -1443,7 +1456,7 @@
// Returning Some() result will forward that result to
// AudioDataListener::OnInputProcessingParamsResult on the callback
// thread.
- if (!mAudioStream) {
+ if (!streamLocked.ref()) {
// No Init yet.
LOG(LogLevel::Debug, ("AudioCallbackDriver %p, has no cubeb stream to "
"set processing params on!",
@@ -1478,7 +1491,7 @@
return Some(params);
}
mConfiguredInputProcessingParams = params;
- r = cubeb_stream_set_input_processing_params(mAudioStream, params);
+ r = cubeb_stream_set_input_processing_params(streamLocked.ref(), params);
if (r == CUBEB_OK) {
LOG(LogLevel::Info,
("AudioCallbackDriver %p, input processing params set to %s", this,
diff -Nru firefox-esr-140.13.0esr/dom/media/GraphDriver.h firefox-esr-140.15.0esr/dom/media/GraphDriver.h
--- firefox-esr-140.13.0esr/dom/media/GraphDriver.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/GraphDriver.h 2026-08-26 17:03:41.000000000 +0000
@@ -719,8 +719,12 @@
// we hold a strong reference on its behalf.
RefPtr mCubeb;
/* cubeb stream for this graph. This is non-null after a successful
- * cubeb_stream_init(). CubebOperation thread only. */
- nsAutoRef mAudioStream;
+ * cubeb_stream_init(). Written and read on the CubebOperation thread only,
+ * except for AudioOutputLatency(), which reads it from the main thread.
+ * Behind a lock because of that cross-thread read; never touched by the
+ * real-time audio callback thread. */
+ DataMutex> mAudioStream{
+ "AudioCallbackDriver::mAudioStream"};
/* The number of input channels from cubeb. Set before opening cubeb. If it is
* zero then the driver is output-only. */
const uint32_t mInputChannelCount;
diff -Nru firefox-esr-140.13.0esr/dom/media/ImageConversion.cpp firefox-esr-140.15.0esr/dom/media/ImageConversion.cpp
--- firefox-esr-140.13.0esr/dom/media/ImageConversion.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/ImageConversion.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -59,6 +59,12 @@
}
}
+static bool DataSurfaceCoversSize(DataSourceSurface* aSurface,
+ const IntSize& aSize) {
+ const IntSize surfaceSize = aSurface->GetSize();
+ return surfaceSize.width >= aSize.width && surfaceSize.height >= aSize.height;
+}
+
namespace mozilla {
already_AddRefed GetSourceSurface(Image* aImage) {
@@ -86,6 +92,10 @@
}
const IntSize imageSize = aImage->GetSize();
+ if (!IsImageDimensionSupportedForConversion(imageSize)) {
+ return NS_ERROR_INVALID_ARG;
+ }
+
auto srcPixelCount = CheckedInt(imageSize.width) * imageSize.height;
auto dstPixelCount = CheckedInt(aDestSize.width) * aDestSize.height;
if (!srcPixelCount.isValid() || !dstPixelCount.isValid()) {
@@ -180,6 +190,11 @@
return NS_ERROR_FAILURE;
}
+ if (!DataSurfaceCoversSize(dataSurface, imageSize)) {
+ NS_WARNING("ConvertToI420: Source surface smaller than image size");
+ return NS_ERROR_INVALID_ARG;
+ }
+
surfaceMap.emplace(dataSurface, DataSourceSurface::READ);
if (!surfaceMap->IsMapped()) {
return NS_ERROR_FAILURE;
@@ -466,6 +481,11 @@
return NS_ERROR_INVALID_ARG;
}
+ const gfx::IntSize imageSize = aImage->GetSize();
+ if (!IsImageDimensionSupportedForConversion(imageSize)) {
+ return NS_ERROR_INVALID_ARG;
+ }
+
if (const PlanarYCbCrData* data = GetPlanarYCbCrData(aImage)) {
const ImageUtils imageUtils(aImage);
Maybe format = imageUtils.GetFormat();
@@ -482,7 +502,7 @@
PlanarYCbCrData i420Source = *data;
gfx::AlignedArray scaledI420Buffer;
- if (aDestSize != aImage->GetSize()) {
+ if (aDestSize != imageSize) {
const int32_t halfWidth = CeilingOfHalf(aDestSize.width);
const uint32_t halfHeight = CeilingOfHalf(aDestSize.height);
@@ -555,6 +575,11 @@
return NS_ERROR_FAILURE;
}
+ if (!DataSurfaceCoversSize(data, aImage->GetSize())) {
+ NS_WARNING("ConvertToNV12: Source surface smaller than image size");
+ return NS_ERROR_INVALID_ARG;
+ }
+
DataSourceSurface::ScopedMap map(data, DataSourceSurface::READ);
if (!map.IsMapped()) {
return NS_ERROR_FAILURE;
diff -Nru firefox-esr-140.13.0esr/dom/media/ImageConversion.h firefox-esr-140.15.0esr/dom/media/ImageConversion.h
--- firefox-esr-140.13.0esr/dom/media/ImageConversion.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/ImageConversion.h 2026-08-26 17:03:41.000000000 +0000
@@ -21,6 +21,16 @@
class Image;
} // namespace layers
+// The conversion routines below scale with libyuv's box filter, which is
+// defined for image dimensions below this value.
+static constexpr int32_t kMaxConvertImageDimension = 32768;
+
+// Whether an image of aSize can be passed to the conversion routines below.
+inline bool IsImageDimensionSupportedForConversion(const gfx::IntSize& aSize) {
+ return aSize.width < kMaxConvertImageDimension &&
+ aSize.height < kMaxConvertImageDimension;
+}
+
/**
* Gets a SourceSurface from given image.
*/
diff -Nru firefox-esr-140.13.0esr/dom/media/MediaData.cpp firefox-esr-140.15.0esr/dom/media/MediaData.cpp
--- firefox-esr-140.13.0esr/dom/media/MediaData.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/MediaData.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -230,9 +230,10 @@
}
// Ensure the picture size specified in the headers can be extracted out of
// the frame we've been supplied without indexing out of bounds.
+ // The picture extent and the plane width are both measured in samples.
CheckedUint32 xLimit = aPicture.x + CheckedUint32(aPicture.width);
CheckedUint32 yLimit = aPicture.y + CheckedUint32(aPicture.height);
- if (!xLimit.isValid() || xLimit.value() > aBuffer.mPlanes[0].mStride ||
+ if (!xLimit.isValid() || xLimit.value() > aBuffer.mPlanes[0].mWidth ||
!yLimit.isValid() || yLimit.value() > aBuffer.mPlanes[0].mHeight) {
// The specified picture dimensions can't be contained inside the video
// frame, we'll stomp memory if we try to copy it. Fail.
@@ -340,6 +341,11 @@
bool aCopyData) {
MOZ_ASSERT(aVideoImage);
+ if (MediaResult r = ValidateBufferAndPicture(aBuffer, aPicture);
+ NS_FAILED(r)) {
+ return r;
+ }
+
PlanarYCbCrData data = ConstructPlanarYCbCrData(aInfo, aBuffer, aPicture);
if (aCopyData) {
diff -Nru firefox-esr-140.13.0esr/dom/media/MediaInfo.h firefox-esr-140.15.0esr/dom/media/MediaInfo.h
--- firefox-esr-140.13.0esr/dom/media/MediaInfo.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/MediaInfo.h 2026-08-26 17:03:41.000000000 +0000
@@ -404,6 +404,16 @@
void SetImageRect(const gfx::IntRect& aRect) { mImageRect = Some(aRect); }
void ResetImageRect() { mImageRect.reset(); }
+ // Adopts an image size decoded from the bitstream. The picture rectangle is
+ // expressed relative to the image size, so a change in size invalidates it
+ // and it is discarded; an unchanged size keeps the existing rectangle.
+ void AdoptImageSize(const gfx::IntSize& aImage) {
+ if (mImage != aImage) {
+ ResetImageRect();
+ }
+ mImage = aImage;
+ }
+
// Returned the crop rectangle scaled to aWidth/aHeight size relative to
// mImage size.
// If aWidth and aHeight are identical to the original
diff -Nru firefox-esr-140.13.0esr/dom/media/MediaTrackGraph.cpp firefox-esr-140.15.0esr/dom/media/MediaTrackGraph.cpp
--- firefox-esr-140.13.0esr/dom/media/MediaTrackGraph.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/MediaTrackGraph.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -3015,9 +3015,11 @@
return;
}
AudioSegment* segment = static_cast(aSegment);
- segment->ResampleChunks(mUpdateTrack->mResampler,
- &mUpdateTrack->mResamplerChannelCount,
- mUpdateTrack->mInputRate, GraphImpl()->GraphRate());
+ // 10 ms of 48 kHz audio always yields a representable size at GraphRate().
+ DebugOnly rv = segment->ResampleChunks(
+ mUpdateTrack->mResampler, &mUpdateTrack->mResamplerChannelCount,
+ mUpdateTrack->mInputRate, GraphImpl()->GraphRate());
+ MOZ_ASSERT(NS_SUCCEEDED(rv));
}
void SourceMediaTrack::AdvanceTimeVaryingValuesToCurrentTime(
diff -Nru firefox-esr-140.13.0esr/dom/media/TimedPacketizer.h firefox-esr-140.15.0esr/dom/media/TimedPacketizer.h
--- firefox-esr-140.13.0esr/dom/media/TimedPacketizer.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/TimedPacketizer.h 2026-08-26 17:03:41.000000000 +0000
@@ -23,8 +23,8 @@
mTimeStamp(media::TimeUnit(aInitialTick, aBase)),
mBase(aBase) {}
- void Input(const InputType* aFrames, uint32_t aFrameCount) {
- mPacketizer.Input(aFrames, aFrameCount);
+ [[nodiscard]] nsresult Input(const InputType* aFrames, uint32_t aFrameCount) {
+ return mPacketizer.Input(aFrames, aFrameCount);
}
media::TimeUnit Output(OutputType* aOutputBuffer) {
diff -Nru firefox-esr-140.13.0esr/dom/media/gmp/GMPChild.cpp firefox-esr-140.15.0esr/dom/media/gmp/GMPChild.cpp
--- firefox-esr-140.13.0esr/dom/media/gmp/GMPChild.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gmp/GMPChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -581,6 +581,12 @@
mGMPContentChildren[i - 1]->Close();
}
+ if (ShutdownPlatformAPI() ==
+ PlatformShutdownResult::PluginExecutionOutstanding) {
+ ProcessChild::QuickExit();
+ return;
+ }
+
if (mGMPLoader) {
mGMPLoader->Shutdown();
}
diff -Nru firefox-esr-140.13.0esr/dom/media/gmp/GMPPlatform.cpp firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.cpp
--- firefox-esr-140.13.0esr/dom/media/gmp/GMPPlatform.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -6,10 +6,12 @@
#include "GMPPlatform.h"
#include "GMPStorageChild.h"
#include "GMPTimerChild.h"
+#include "mozilla/Atomics.h"
#include "mozilla/Monitor.h"
#include "GMPChild.h"
#include "mozilla/Mutex.h"
#include "mozilla/ReentrantMonitor.h"
+#include "mozilla/StaticMutex.h"
#include "nsThreadUtils.h"
#include "base/task.h"
#include "base/thread.h"
@@ -25,23 +27,37 @@
static GMPChild* sChild = nullptr;
+// sShutdown is atomic so GMPRunnable::Run() can check it lock-free. The
+// counters and the shutdown snapshot are serialized by sPlatformStateMutex so
+// that closing admission and reading whether any plugin execution remains is a
+// single transaction.
+static Atomic sShutdown{false};
+static StaticMutex sPlatformStateMutex;
+static uint32_t sLiveThreads MOZ_GUARDED_BY(sPlatformStateMutex) = 0;
+static uint32_t sLivePluginObjects MOZ_GUARDED_BY(sPlatformStateMutex) = 0;
+
// We just need a refcounted wrapper for GMPTask objects.
class GMPRunnable final : public Runnable {
public:
- explicit GMPRunnable(GMPTask* aTask)
- : Runnable("mozilla::gmp::GMPRunnable"), mTask(aTask) {
+ GMPRunnable(GMPTask* aTask, bool aCancelOnShutdown)
+ : Runnable("mozilla::gmp::GMPRunnable"),
+ mTask(aTask),
+ mCancelOnShutdown(aCancelOnShutdown) {
MOZ_ASSERT(mTask);
}
NS_IMETHOD Run() override {
- mTask->Run();
- mTask->Destroy();
+ if (!(mCancelOnShutdown && sShutdown)) {
+ mTask->Run();
+ mTask->Destroy();
+ }
mTask = nullptr;
return NS_OK;
}
private:
GMPTask* mTask;
+ const bool mCancelOnShutdown;
};
class GMPSyncRunnable final : public Runnable {
@@ -99,17 +115,24 @@
return GMPGenericErr;
}
+ StaticMutexAutoLock lock(sPlatformStateMutex);
+ if (sShutdown) {
+ return GMPGenericErr;
+ }
+
*aThread = new GMPThreadImpl();
+ ++sLiveThreads;
return GMPNoErr;
}
GMPErr RunOnMainThread(GMPTask* aTask) {
- if (!aTask) {
+ if (!aTask || sShutdown) {
return GMPGenericErr;
}
- if (NS_FAILED(NS_DispatchToMainThread(MakeAndAddRef(aTask)))) {
+ if (NS_FAILED(NS_DispatchToMainThread(
+ MakeAndAddRef(aTask, /* aCancelOnShutdown */ true)))) {
return GMPGenericErr;
}
@@ -117,7 +140,7 @@
}
GMPErr SyncRunOnMainThread(GMPTask* aTask) {
- if (!aTask || NS_IsMainThread()) {
+ if (!aTask || sShutdown || NS_IsMainThread()) {
return GMPGenericErr;
}
@@ -170,7 +193,7 @@
}
GMPErr SetTimerOnMainThread(GMPTask* aTask, int64_t aTimeoutMS) {
- if (!aTask || !NS_IsMainThread()) {
+ if (!aTask || sShutdown || !NS_IsMainThread()) {
return GMPGenericErr;
}
GMPTimerChild* timers = sChild->GetGMPTimers();
@@ -201,6 +224,25 @@
aPlatformAPI.getcurrenttime = &GetClock;
}
+void AddPluginObject() {
+ StaticMutexAutoLock lock(sPlatformStateMutex);
+ ++sLivePluginObjects;
+}
+
+void RemovePluginObject() {
+ StaticMutexAutoLock lock(sPlatformStateMutex);
+ --sLivePluginObjects;
+}
+
+PlatformShutdownResult ShutdownPlatformAPI() {
+ MOZ_ASSERT(NS_IsMainThread());
+ StaticMutexAutoLock lock(sPlatformStateMutex);
+ sShutdown = true;
+ return sLiveThreads == 0 && sLivePluginObjects == 0
+ ? PlatformShutdownResult::ReadyToUnload
+ : PlatformShutdownResult::PluginExecutionOutstanding;
+}
+
void SendFOGData(ipc::ByteBuf&& buf) {
if (sChild) {
sChild->SendFOGData(std::move(buf));
@@ -220,7 +262,11 @@
GMPThreadImpl::GMPThreadImpl() { MOZ_COUNT_CTOR(GMPThread); }
-GMPThreadImpl::~GMPThreadImpl() { MOZ_COUNT_DTOR(GMPThread); }
+GMPThreadImpl::~GMPThreadImpl() {
+ MOZ_COUNT_DTOR(GMPThread);
+ StaticMutexAutoLock lock(sPlatformStateMutex);
+ --sLiveThreads;
+}
void GMPThreadImpl::Post(GMPTask* aTask) {
MutexAutoLock lock(mMutex);
@@ -233,7 +279,7 @@
}
}
- RefPtr r = new GMPRunnable(aTask);
+ RefPtr r = new GMPRunnable(aTask, /* aCancelOnShutdown */ false);
mThread.message_loop()->PostTask(
NewRunnableMethod("gmp::GMPRunnable::Run", r.get(), &GMPRunnable::Run));
}
diff -Nru firefox-esr-140.13.0esr/dom/media/gmp/GMPPlatform.h firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.h
--- firefox-esr-140.13.0esr/dom/media/gmp/GMPPlatform.h 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gmp/GMPPlatform.h 2026-08-26 17:03:41.000000000 +0000
@@ -25,6 +25,18 @@
void InitPlatformAPI(GMPPlatformAPI& aPlatformAPI, GMPChild* aChild);
+enum class PlatformShutdownResult {
+ ReadyToUnload,
+ PluginExecutionOutstanding,
+};
+
+PlatformShutdownResult ShutdownPlatformAPI();
+
+// Count of live plugin-implemented objects (e.g. codec instances) held by GMP
+// child actors.
+void AddPluginObject();
+void RemovePluginObject();
+
GMPErr RunOnMainThread(GMPTask* aTask);
GMPTask* NewGMPTask(std::function&& aFunction);
diff -Nru firefox-esr-140.13.0esr/dom/media/gmp/GMPVideoDecoderChild.cpp firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoDecoderChild.cpp
--- firefox-esr-140.13.0esr/dom/media/gmp/GMPVideoDecoderChild.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoDecoderChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -30,6 +30,7 @@
// the worker thread.
if (mVideoDecoder) {
mVideoDecoder->DecodingComplete();
+ RemovePluginObject();
}
}
@@ -41,6 +42,7 @@
MOZ_ASSERT(aDecoder,
"Cannot initialize video decoder child without a video decoder!");
mVideoDecoder = aDecoder;
+ AddPluginObject();
}
void GMPVideoDecoderChild::Decoded(GMPVideoi420Frame* aDecodedFrame) {
diff -Nru firefox-esr-140.13.0esr/dom/media/gmp/GMPVideoEncoderChild.cpp firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoEncoderChild.cpp
--- firefox-esr-140.13.0esr/dom/media/gmp/GMPVideoEncoderChild.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gmp/GMPVideoEncoderChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -26,6 +26,7 @@
// the worker thread.
if (mVideoEncoder) {
mVideoEncoder->EncodingComplete();
+ RemovePluginObject();
}
}
@@ -37,6 +38,7 @@
MOZ_ASSERT(aEncoder,
"Cannot initialize video encoder child without a video encoder!");
mVideoEncoder = aEncoder;
+ AddPluginObject();
}
void GMPVideoEncoderChild::Encoded(GMPVideoEncodedFrame* aEncodedFrame,
diff -Nru firefox-esr-140.13.0esr/dom/media/gtest/TestAudioPacketizer.cpp firefox-esr-140.15.0esr/dom/media/gtest/TestAudioPacketizer.cpp
--- firefox-esr-140.13.0esr/dom/media/gtest/TestAudioPacketizer.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/gtest/TestAudioPacketizer.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -68,7 +68,7 @@
AutoBuffer b(441 * channels);
int16_t prevEnd = seqEnd;
seqEnd = Sequence(b.Get(), channels * 441, prevEnd);
- ap.Input(b.Get(), 441);
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b.Get(), 441)));
std::unique_ptr out(ap.Output());
IsSequence(out.get(), 441 * channels, prevEnd);
}
@@ -85,8 +85,8 @@
seqEnd = Sequence(b.Get(), 441 * channels, prevEnd0);
int16_t prevEnd1 = seqEnd;
seqEnd = Sequence(b1.Get(), 441 * channels, seqEnd);
- ap.Input(b.Get(), 441);
- ap.Input(b1.Get(), 441);
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b.Get(), 441)));
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b1.Get(), 441)));
std::unique_ptr out(ap.Output());
std::unique_ptr out2(ap.Output());
IsSequence(out.get(), 441 * channels, prevEnd0);
@@ -104,8 +104,8 @@
AutoBuffer b1(480 * channels);
prevSeq = Sequence(b.Get(), 480 * channels, prevSeq);
prevSeq = Sequence(b1.Get(), 480 * channels, prevSeq);
- ap.Input(b.Get(), 480);
- ap.Input(b1.Get(), 480);
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b.Get(), 480)));
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b1.Get(), 480)));
std::unique_ptr out(ap.Output());
std::unique_ptr out2(ap.Output());
IsSequence(out.get(), 441 * channels, prevEnd);
@@ -133,7 +133,7 @@
}
phase++;
}
- ap.Input(b.Get(), 128);
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b.Get(), 128)));
while (ap.PacketsAvailable()) {
std::unique_ptr packet(ap.Output());
for (uint32_t k = 0; k < ap.mPacketSize; k++) {
@@ -151,7 +151,7 @@
AudioPacketizer ap(441, channels);
AutoBuffer b(440 * channels);
Sequence(b.Get(), 440 * channels);
- ap.Input(b.Get(), 440);
+ EXPECT_TRUE(NS_SUCCEEDED(ap.Input(b.Get(), 440)));
EXPECT_EQ(ap.FramesAvailable(), 440U);
ap.Clear();
EXPECT_EQ(ap.FramesAvailable(), 0U);
@@ -177,7 +177,7 @@
for (int16_t i = 0; i < 10; i++) {
AutoBuffer b(inputPacketSize * channels);
prevSeq = Sequence(b.Get(), inputPacketSize * channels, prevSeq);
- tp.Input(b.Get(), inputPacketSize);
+ EXPECT_TRUE(NS_SUCCEEDED(tp.Input(b.Get(), inputPacketSize)));
while (tp.PacketsAvailable()) {
media::TimeUnit ts = tp.Output(packet.Elements());
IsSequence(packet.Elements(), packetSize * channels, prevEnd);
diff -Nru firefox-esr-140.13.0esr/dom/media/ipc/MFCDMChild.cpp firefox-esr-140.15.0esr/dom/media/ipc/MFCDMChild.cpp
--- firefox-esr-140.13.0esr/dom/media/ipc/MFCDMChild.cpp 2026-07-15 20:30:29.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/ipc/MFCDMChild.cpp 2026-08-26 17:03:41.000000000 +0000
@@ -200,6 +200,8 @@
MozPromiseHolder& aPromise) {
AssertSendable();
+ RefPtr promise = aPromise.Ensure(aCallerName);
+
if (mState == NS_OK) {
// mRemotePromise is resolved, send on manager thread.
mManagerThread->Dispatch(
@@ -215,7 +217,7 @@
});
}
- return aPromise.Ensure(aCallerName);
+ return promise.forget();
}
RefPtr MFCDMChild::Init(
diff -Nru firefox-esr-140.13.0esr/dom/media/ipc/MFMediaEngineChild.cpp firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.cpp
--- firefox-esr-140.13.0esr/dom/media/ipc/MFMediaEngineChild.cpp 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.cpp 2026-08-26 17:03:42.000000000 +0000
@@ -59,11 +59,19 @@
MOZ_ASSERT(mMediaEngineId == 0);
RefPtr self = this;
+ RefPtr initPromise =
+ mInitPromiseHolder.Ensure(__func__);
RemoteDecoderManagerChild::LaunchUtilityProcessIfNeeded(
RemoteDecodeIn::UtilityProcess_MFMediaEngineCDM)
->Then(
mManagerThread, __func__,
[self, this, flag = aFlags, info = aInfo](bool) {
+ mLaunchProcessRequest.Complete();
+ if (mShutdown || !mOwner) {
+ CLOG("Already shut down or no owner, won't bind the actor");
+ mInitPromiseHolder.RejectIfExists(NS_ERROR_FAILURE, __func__);
+ return;
+ }
RefPtr manager =
RemoteDecoderManagerChild::GetSingleton(
RemoteDecodeIn::UtilityProcess_MFMediaEngineCDM);
@@ -113,10 +121,12 @@
->Track(mInitEngineRequest);
},
[self, this](nsresult aResult) {
+ mLaunchProcessRequest.Complete();
CLOG("SendInitMediaEngine Failed");
self->mInitPromiseHolder.RejectIfExists(NS_ERROR_FAILURE, __func__);
- });
- return mInitPromiseHolder.Ensure(__func__);
+ })
+ ->Track(mLaunchProcessRequest);
+ return initPromise;
}
mozilla::ipc::IPCResult MFMediaEngineChild::RecvRequestSample(TrackType aType,
@@ -200,6 +210,9 @@
mozilla::ipc::IPCResult MFMediaEngineChild::RecvUpdateStatisticData(
const StatisticData& aData) {
AssertOnManagerThread();
+ if (mShutdown || !mOwner) {
+ return IPC_OK();
+ }
const uint64_t currentRenderedFrames = mFrameStats->GetPresentedFrames();
const uint64_t newRenderedFrames = GetUpdatedRenderedFrames(aData);
// Media engine won't tell us that which stage those dropped frames happened,
@@ -278,6 +291,7 @@
}
SendShutdown();
mInitPromiseHolder.RejectIfExists(NS_ERROR_FAILURE, __func__);
+ mLaunchProcessRequest.DisconnectIfExists();
mInitEngineRequest.DisconnectIfExists();
mShutdown = true;
}
diff -Nru firefox-esr-140.13.0esr/dom/media/ipc/MFMediaEngineChild.h firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.h
--- firefox-esr-140.13.0esr/dom/media/ipc/MFMediaEngineChild.h 2026-07-15 20:30:30.000000000 +0000
+++ firefox-esr-140.15.0esr/dom/media/ipc/MFMediaEngineChild.h 2026-08-26 17:03:42.000000000 +0000
@@ -74,8 +74,10 @@
MozPromiseHolder mInitPromiseHolder;
MozPromiseRequestHolder mInitEngineRequest;
+ MozPromiseRequestHolder mLaunchProcessRequest;
- // This is guaranteed always being alive in our lifetime.
+ // Owned by the state machine which also owns `mOwner`, so this is only
+ // guaranteed to be alive while `mOwner` is non-null.
NotNull