Bug 2870

Summary: update candidate: Firefox 7
Product: Mageia Reporter: Manuel Hiebel <manuel.mageia>
Component: SecurityAssignee: Mageia Bug Squad <bugsquad>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Normal CC: alien, davidwhodgins, dmorganec, geiger.david68210, mageia, qa-bugs, sysadmin-bugs
Version: 1Keywords: validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: CVE:
Status comment:
Attachments: Screenshot showing disabled extensions.
Screen shot showing three extensions still disabled.

Description Manuel Hiebel 2011-09-29 13:37:19 CEST
Description of problem:

Update security of firefox:

firefox-7.0-0.2.mga1.src.rpm
firefox-ext-bugzilla-tweaks-1.11-0.1.mga1.src.rpm
firefox-ext-foxyproxy-3.2-0.1.mga1.src.rpm
firefox-ext-greasemonkey-0.9.11-0.1.mga1.src.rpm
firefox-ext-noscript-2.1.3-0.1.mga1.src.rpm
firefox-ext-xmarks-4.0.2-0.1.mga1.src.rpm
firefox-l10n-7.0-0.1.mga1.src.rpm
xulrunner-7.0-0.1.mga1.src.rpm

(I hope I have nothing forgotten)
Comment 1 Manuel Hiebel 2011-09-29 13:44:33 CEST
another one:
mozilla-esteid-3.4.0-1.3.mga1.src.rpm

Dmorgan, alien, according to http://www.mageia.org/wiki/doku.php?id=firefox
these extentions needs an update, I don't know where to check if that is right)
firefox-ext-firebug 
firefox-ext-download-statusbar
beid-middleware

CC: (none) => alien, dmorganec
Hardware: i586 => All

Comment 2 David GEIGER 2011-09-29 19:33:55 CEST
Hello,

Tested firefox-7.0-0.2.mga1 on Mageia release 1 (Official) for x86_64 
and for me it's Ok. Nothing to report.

->For the StartupNotify ,still Ok.
->And for the French dictionary,nothing to report, still OK.
->Also,I test  the flash-player-plugin11 in cauldron deposit and it's Ok:
flash-player-plugin11-11.0.1.129-0.rc1.090611.2.mga2.nonfree
flash-player-plugin11-kde-11.0.1.129-0.rc1.090611.2.mga2.nonfree
->For extension "ext" I don't know because I use "xpi" extension and it works
perfectly.

CC: (none) => geiger.david68210

Comment 3 AL13N 2011-09-29 19:49:12 CEST
(In reply to comment #1)
> another one:
> mozilla-esteid-3.4.0-1.3.mga1.src.rpm
> 
> Dmorgan, alien, according to http://www.mageia.org/wiki/doku.php?id=firefox
> these extentions needs an update, I don't know where to check if that is right)
> firefox-ext-firebug 
> firefox-ext-download-statusbar
> beid-middleware

currently i don't have the time to test beid-middleware yet, i'll try and find some time this weekend... sorry.

but shouldn't we wait updating? i heard that there was an issue with FF7 with regards to extensions disappearing...?
Comment 4 Sander Lepik 2011-09-29 20:46:03 CEST
(In reply to comment #3)
> but shouldn't we wait updating? i heard that there was an issue with FF7 with
> regards to extensions disappearing...?

Hearing is one thing.. do you have a link to prove it? I'm using fx7 beta since it was released and haven't detected any problems with it.

There is also a lot of critical security issues: http://www.mozilla.org/security/known-vulnerabilities/firefox.html#firefox7

CC: (none) => sander.lepik

Comment 6 Dave Hodgins 2011-09-30 02:23:07 CEST
Still waiting for the updates to the Finnish spell checker,
the Estonian ID Card PKCS11 module, and the Firebug extension.

If they have been submitted, they are not on the i586 mirrors.
 
Also, I've noticed that greasemonkey is generating an error
when starting firefox from the console ...
 
$ firefox
[Exception... "Component returned failure code: 0x80004002 (NS_NOINTERFACE) [nsISupports.QueryInterface]"  nsresult: "0x80004002 (NS_NOINTERFACE)"  location: "JS frame :: jar:file:///usr/share/mozilla/extensions/%7Bec8030f7-c20a-464f-9b0e-13a3a9e97384%7D/%7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D.xpi!/components/greasemonkey.js :: <TOP_LEVEL> :: line 20"  data: no]
({})

CC: (none) => davidwhodgins

Comment 7 Sander Lepik 2011-09-30 10:15:11 CEST
(In reply to comment #6)
> Still waiting for the updates to the Finnish spell checker,
> the Estonian ID Card PKCS11 module, and the Firebug extension.
> 
> If they have been submitted, they are not on the i586 mirrors.

http://ftp.belnet.be/mirror/mageia/distrib/1/i586/media/core/updates_testing/mozilla-esteid-3.4.0-1.3.mga1.noarch.rpm
Comment 8 Sander Lepik 2011-10-01 15:35:18 CEST
7.0.1 is uploaded into updates_testing.
Comment 9 Dave Hodgins 2011-10-01 17:30:24 CEST
Still need an update for 
firefox-ext-mozvoikko (the Finnish spell checker)
esteid-browser-plugin (Estonian ID card extension for Mozilla)
firefox-ext-firebug (Web development tool)

The estonian id card is confusing, as to which package is involved, as
the description shown by firefox in the tools/addons is similar to the
mozilla-esteid package description, but actually comes from the browser
plugin.

Still getting the greasmonkey error on startup, but haven't determined
if it's cosmetic, or causes problems.
Comment 10 Sander Lepik 2011-10-01 17:39:39 CEST
(In reply to comment #9)
> The estonian id card is confusing, as to which package is involved, as
> the description shown by firefox in the tools/addons is similar to the
> mozilla-esteid package description, but actually comes from the browser
> plugin.

esteid-browser-plugin is a plugin that should have no compatibility issues, mozilla-esteid is an extension and is updated to be compatible with fx7.*
Comment 11 Dave Hodgins 2011-10-02 02:21:55 CEST
Created attachment 880 [details]
Screenshot showing disabled extensions.
Comment 12 Sander Lepik 2011-10-02 09:57:34 CEST
(In reply to comment #11)
> Created attachment 880 [details]
> Screenshot showing disabled extensions.

Is this old profile or new profile. There seems to be some problem with such extensions that have only max version updated. Firefox doesn't check them always. With new profile this should not happen.

I do not know how to solve that. Maybe next time i should change extension's version as well.
Comment 13 Manuel Hiebel 2011-10-02 10:13:09 CEST
(In reply to comment #12)
> (In reply to comment #11)
> > Created attachment 880 [details]
> > Screenshot showing disabled extensions.
> 
> Is this old profile or new profile. There seems to be some problem with such
> extensions that have only max version updated. Firefox doesn't check them
> always. With new profile this should not happen.
I see something similar, the localisation don't work with my current, and it's work with a new profile.
Comment 14 AL13N 2011-10-02 11:08:57 CEST
it is my personal opinion that we hold of this update until mozilla fixes this issue... as an update this will give alot of issues...
Comment 15 Sander Lepik 2011-10-02 11:24:19 CEST
(In reply to comment #14)
> it is my personal opinion that we hold of this update until mozilla fixes this
> issue... as an update this will give alot of issues...

The problem you are referring to is already solved in fx7.0.1. Problem with old profiles has been there for quite some time now.

One more reason not to have amo addons in our repos.
Comment 16 AL13N 2011-10-02 11:36:11 CEST
i had not seen the disappearing extension issues when migrating to 4, 5 or 6...

since upstream is apparently seeing this as a problem, i think we should wait for their solution? no?
Comment 17 Sander Lepik 2011-10-02 11:42:48 CEST
Disappearing extensions issue is solved, can't you read?

Compatibility issues were there already earlier. I know and i noticed them. And still have no idea how to overcome them. It seems to be some problem with system wide extensions. If they are installed from amo there is no problems. And sometimes system wide extensions are working fine too. For me mozilla-esteid was compatible on old profile too. I don't know how to debug it.

But for sure it's a different problem that Mozilla had with 7.0 (and fixed in 7.0.1, read release notes if you still don't trust me).
Comment 18 Sander Lepik 2011-10-02 12:21:59 CEST
https://bugzilla.mozilla.org/show_bug.cgi?id=638314 seems to be something that i have noticed, but not the same problem.
Comment 19 AL13N 2011-10-02 13:36:41 CEST
(In reply to comment #17)
> Disappearing extensions issue is solved, can't you read?
> 
> Compatibility issues were there already earlier. I know and i noticed them. And
> still have no idea how to overcome them. It seems to be some problem with
> system wide extensions. If they are installed from amo there is no problems.
> And sometimes system wide extensions are working fine too. For me
> mozilla-esteid was compatible on old profile too. I don't know how to debug it.
> 
> But for sure it's a different problem that Mozilla had with 7.0 (and fixed in
> 7.0.1, read release notes if you still don't trust me).

so, it's not the same issue? "If they are installed from amo there is no problems." What if it isn't? I think we should be able to have amo addons in our repos.

It's not 100% clear to me anymore, but IF that's the issue and it's _FIXED_ only if you have addons from amo, then it's not completely fixed imho.
Comment 20 Sander Lepik 2011-10-02 13:52:27 CEST
Disappearing != not compatible. Mozilla worked on another problem.

Who knows, mybe it's very old bug and didn't appear because we didn't update Firefox major version so often before.

Anyway, it's not a new problem and was there at least for fx5 and 6 and probably for 4 as well. So it's not stopping us from updating Firefox.
Comment 21 AL13N 2011-10-02 14:34:07 CEST
well, i can only speak for myself, but with beid-middleware, the plugin wasn't compatible, but disappearing != incompatible... i have no problem it being extensions being incompatible; but i do have an issue if they just disappear...

in any case, perhaps someone should test if beid-middleware is compatible or dissappears.

because, i also think that FF new version needs to be blocked until at least the plugins are "working" or at the very least considered compatible.
Comment 22 Sander Lepik 2011-10-02 14:42:33 CEST
(In reply to comment #21)
> because, i also think that FF new version needs to be blocked until at least
> the plugins are "working" or at the very least considered compatible.

Are you talking about plugins or about extensions? Those are different things. Plugins should work anyway. AFAIK there is no compatibility check for plugins.
Comment 23 Manuel Hiebel 2011-10-02 16:46:37 CEST
firefox-ext-adblock-plus needs also a update :( (I have not check the other

If we keep this extensions, maybe we can add a update check at http://check.mageia.org/updates.html ,and at all firefox release, update also all firefox-ext-* to the last version ?
Comment 24 AL13N 2011-10-02 18:26:11 CEST
(In reply to comment #22)
> (In reply to comment #21)
> > because, i also think that FF new version needs to be blocked until at least
> > the plugins are "working" or at the very least considered compatible.
> 
> Are you talking about plugins or about extensions? Those are different things.
> Plugins should work anyway. AFAIK there is no compatibility check for plugins.

i'm pretty sure beid-middleware is an extension since i had to adapt for it to work with FF6
Comment 25 Dave Hodgins 2011-10-03 01:52:25 CEST
Created attachment 886 [details]
Screen shot showing three extensions still disabled.

After deleting ~/.mozilla, tools/addons/extensions is still showing
three disabled extensions.  In addition, the Finnish spell checker
can not be re-installed.
# urpmi firefox-ext-mozvoikko
The following package cannot be installed because it depends on packages
that are older than the installed ones:
firefox-ext-mozvoikko-1.10.0-1.2.mga1

Attachment 880 is obsolete: 0 => 1

Comment 26 Manuel Hiebel 2011-10-03 15:58:55 CEST
(assign to the maintainer of the firefox-ext-*)

CC: (none) => qa-bugs
Assignee: qa-bugs => dmorganec

Comment 27 Dave Hodgins 2011-10-05 10:38:00 CEST
Validating the update.  The extensions that are not being maintained should
not be blocking security updates.

Can someone from the sysadmin team push the srpm packages
firefox-l10n-7.0-0.1.mga1.src.rpm
firefox-ext-xmarks-4.0.2-0.1.mga1.src.rpm
firefox-ext-greasemonkey-0.9.11-0.1.mga1.src.rpm
firefox-ext-bugzilla-tweaks-1.11-0.1.mga1.src.rpm
firefox-ext-foxyproxy-3.2-0.1.mga1.src.rpm
firefox-ext-noscript-2.1.3-0.1.mga1.src.rpm
mozilla-esteid-3.4.0-1.3.mga1.src.rpm
firefox-7.0-0.2.mga1.src.rpm
xulrunner-7.0-0.1.mga1.src.rpm
from Core Updates Testing to Core Updates.

Advisory:
This security and bug fix updates for firefox.  See
http://www.mozilla.org/en-US/firefox/7.0/releasenotes/
for details.

Please note, some extensions will be disabled, until they
too have been updated.

https://bugs.mageia.org/show_bug.cgi?id=2870

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 28 David GEIGER 2011-10-06 19:26:31 CEST
Hello,

Tested firefox-7.0.1-0.1.mga1 on Mageia release 1 (Official) for x86_64 
and for me it's Ok. Nothing to report.

->For the StartupNotify ,still Ok.
->And for the French dictionary,nothing to report, still OK.
->Also,I test  the flash-player-plugin11 in Nonfree_Updates_Testing deposit and it's Ok:
flash-player-plugin-11.0.1.152-1.mga1.nonfree
flash-player-plugin-kde-11.0.1.152-1.mga1.nonfree
->For extension "ext" I don't know because I use "xpi" extension and it works
perfectly.
Comment 29 D Morgan 2011-10-07 14:41:00 CEST
update pushed.

Status: NEW => RESOLVED
Resolution: (none) => FIXED

Comment 30 Manuel Hiebel 2011-10-07 14:47:58 CEST
with no firefox-ext-adblock updated, so please remove all package of addon for the future...
Nicolas Vigier 2011-10-25 11:19:52 CEST

CC: (none) => boklm
Component: RPM Packages => Security
Assignee: dmorganec => bugsquad

Nicolas Vigier 2014-05-08 18:06:34 CEST

CC: boklm => (none)