Commit graph

255 commits

Author SHA1 Message Date
adeshkp
f7b02cecab Issue #1280 - Remove hostname parameter to trust domain.
Host name was purely being used for HPKP and since HPKP is killed,
this can also go. Currently it doesn't do anything other than
generating build warnings.
2020-09-16 21:11:01 +08:00
Roy Tam
8015bb7004 update NSS as-of pm27 rev 7606140ee 2020-09-04 22:55:34 +08:00
Roy Tam
eeb44de4a1 Merge remote-tracking branch 'origin/master' into custom 2020-09-04 22:34:20 +08:00
Moonchild
38470e4fe9 [NSS] Version and build bump 2020-09-04 22:30:57 +08:00
J.C. Jones
0e23c7cc48 [NSS] Prevent slotLock race in NSC_GetTokenInfo
Basically, NSC_GetTokenInfo doesn't lock slot->slotLock before accessing slot
after obtaining it, even though slotLock is defined as its lock.
2020-09-04 22:30:55 +08:00
Roy Tam
3d5ac98e9d Merge remote-tracking branch 'origin/master' into custom 2020-07-10 22:22:14 +08:00
Moonchild
9890572c8e [NSS] Version and build bump 2020-07-10 22:18:56 +08:00
Sohaib ul Hassan
62467c473d [NSS] Implement constant-time GCD and modular inversion
The implementation is based on the work by Bernstein and Yang
(https://eprint.iacr.org/2019/266)
"Fast constant-time gcd computation and modular inversion".

It fixes the old mp_gcd and s_mp_invmod_odd_m functions. The patch also fixes
mpl_significant_bits s_mp_div_2d and s_mp_mul_2d by having less control flow to
reduce side-channel leaks.

Co-authored by : Billy Bob Brumley
2020-07-10 22:18:52 +08:00
Roy Tam
6ef287a52e Merge remote-tracking branch 'origin/master' into custom 2020-06-10 21:03:13 +08:00
Moonchild
594c930eca Issue #439 - Remove, fix and clean up automated tests
With the big amount of code churn around DOM a lot of tests
broke severely enough that they caused build bustage.
This commit cleans up, removes or otherwise fixes tests
that are broken, no longer relevant or obsolete.
2020-06-10 21:00:09 +08:00
Roy Tam
5c4cee240f Merge remote-tracking branch 'origin/master' into custom 2020-06-06 07:27:53 +08:00
Moonchild
ca3ce88bd1 [NSS] Bump NSS version 2020-06-06 07:21:18 +08:00
Moonchild
4789fee7cf [NSS] Force a fixed length for DSA exponentiation 2020-06-06 07:21:15 +08:00
Roy Tam
4ecaa49dd0 Merge remote-tracking branch 'origin/master' into custom 2020-04-03 09:57:28 +08:00
athenian200
768fad9864 Issue #1501 - Un-bust building of NSS after update to 3.48 on Solaris. 2020-04-03 09:30:25 +08:00
wolfbeast
052b2e70a3 Issue #1280 - Un-bust certerror pages and ForgetAboutSite 2020-04-03 09:30:07 +08:00
wolfbeast
593ea86a68 Issue #1280 - Part 2: Remove HPKP tests. 2020-04-03 09:27:13 +08:00
wolfbeast
cf5f069080 Issue #1280 - Part 1: Remove HPKP components.
This also removes leftover plumbing for storing preload information
in SiteSecurityService since no service still uses it.
2020-04-03 09:27:11 +08:00
wolfbeast
ff8c58e8db Issue #1498 - Part 6: Remove STS preloadlist pref. 2020-04-03 09:22:00 +08:00
wolfbeast
be0246f8e4 Issue #1498 - Part 5: Update SSService CID and correct mismatch. 2020-04-03 09:21:57 +08:00
wolfbeast
6fe7731e5e Issue #1498 - Part 4: Remove clearPreloads.
Also tag #1280
2020-04-03 09:21:53 +08:00
wolfbeast
bcfc5b3a88 Issue #1498 - Part 3: Remove support for storing "knockout" values. 2020-04-03 09:21:49 +08:00
wolfbeast
786480c19c Issue #1498 - Part 1: Stop persisting preload states.
Since we don't use preloading anymore for either HPKP or HSTS, we no
longer need persistent storage in the profile for preload states.
Tag #1280 also
2020-04-03 09:17:35 +08:00
wolfbeast
7d012bfdc0 Issue #1498 - Part 1: Stop using HSTS preload lists. 2020-04-03 09:17:28 +08:00
Matt A. Tobin
5010fed2fd Take nsSiteSecurityService out of UNIFIED_SOURCES
It exceeded the obj file sections limit because of the HSTS preload list so it cannot be built in UNIFIED mode.
2020-04-03 09:16:53 +08:00
wolfbeast
2c18f6df31 Issue #447 - Update HSTS preload list 2020-04-03 09:16:50 +08:00
wolfbeast
8778ddfc52 Issue #1467 - Part 4: Rename NSS_SQLSTORE to MOZ_SECURITY_SQLSTORE.
Rename the build config option accordingly.
2020-04-03 09:14:07 +08:00
wolfbeast
ff29b77edc Issue #1467 - Part 3: Use UTF-8 file paths for NSS-SQL database. 2020-04-03 09:14:04 +08:00
wolfbeast
5efa1a9e43 Issue #1467 - Part 1: Set up conditional NSS-SQL builds.
- Adds buildconfig option --enable-nss-sqlstore
- Prefixes NSS dbinit with either sql: or dbm: depending on config
- Pre-initializes mozStorage when NSS-SQL storage is used to prevent
  an sqlite3_config race in NSS Init
2020-04-03 09:12:04 +08:00
Roy Tam
bd46990741 Merge remote-tracking branch 'origin/master' into custom 2020-03-05 09:48:44 +08:00
Matt A. Tobin
56f64bd775 Issue #1053 - Remove android support from nsNSSComponent.cpp 2020-03-05 09:38:27 +08:00
Roy Tam
c9f0b81b06 Merge remote-tracking branch 'origin/master' into custom 2020-02-07 08:01:35 +08:00
wolfbeast
ed6f10f477 Issue #447 - Update HSTS preload list & reduce debug spew
Commented out spewing dump() statements in loops. With the ever growing
HSTS list it takes too much time and is pointless to display.
2020-02-07 07:52:21 +08:00
Roy Tam
678ad26488 Merge remote-tracking branch 'origin/master' into custom 2020-01-24 09:39:16 +08:00
Kai Engert
a8daf97de0 Issue #1338 - Follow-up: Also cache the most recent PBKDF1 hash
This rewrites the caching mechanism to apply to both PBKDF1 and PBKDF2
2020-01-24 09:36:33 +08:00
wolfbeast
abb2afe2a7 Issue #1338 - Bump NSS version
Our NSS version is closer to the currently-released .1, so bump version
to that.
Note: we still have some additional patches to the in-tree version in
place so this isn't a 100% match to the RTM one.
2020-01-24 09:28:39 +08:00
Roy Tam
969d239b65 Merge remote-tracking branch 'origin/master' into custom 2020-01-17 09:24:31 +08:00
Kai Engert
3d75257e8d Issue #1338: Follow-up: Cache the most recent PBKDF2 password hash,
to speed up repeated SDR operations.

Landed on NSS-3.48 for Bug 1606992
2020-01-17 09:15:04 +08:00
Roy Tam
f9aa123602 Merge remote-tracking branch 'origin/master' into custom 2020-01-11 06:48:56 +08:00
Daiki Ueno
75fdf9c3b0 Issue #1338 - Followup: certdb: propagate trust information if trust
module is loaded afterwards,

Summary: When the builtin trust module is loaded after some temp certs
being created, these temp certs are usually not accompanied by trust
information. This causes a problem in UXP as it loads the module from a
separate thread while accessing the network cache which populates temp
certs.

This change makes it properly roll up the trust information, if a temp
cert doesn't have trust information.
2020-01-11 06:47:38 +08:00
wolfbeast
b299b34492 Issue #1338 - Un-bust building of NSS after update to 3.48 on Linux. 2020-01-11 06:47:34 +08:00
Roy Tam
239002b5c9 Merge remote-tracking branch 'origin/master' into custom 2020-01-10 17:07:32 +08:00
wolfbeast
d12d260c6a Be more consistent about decoding IP addresses in PSM. 2020-01-10 17:06:58 +08:00
wolfbeast
c57cac24e8 Issue #1338 - Part 2: Update NSS to 3.48-RTM 2020-01-05 11:42:29 +08:00
Roy Tam
9778f15c7d import NSS tip revs: bug1594965, bug1593167, bug1603027, bug1600144, bug1590001, bug1603257, bug1605545, bug1513586 2020-01-03 22:08:56 +08:00
Roy Tam
171849c8e5 Update NSS to 3.48 while keeping vc2013 hackfix and no-sslkeylogfile intact. 2020-01-03 13:36:26 +08:00
Roy Tam
b74770e3f1 Merge remote-tracking branch 'origin/master' into custom 2019-12-28 21:20:53 +08:00
wolfbeast
b753aec164 Issue #1118 - Part 6: Fix various tests that are no longer correct.
The behavior change of document.open() requires these tests to be
changed to account for the new spec behavior.
2019-12-28 21:20:04 +08:00
Roy Tam
91821d6b92 partly imported from tenfourfox: #578: M1579060 M1586176 2019-12-10 10:53:09 +08:00
Roy Tam
8c7f5dcc57 Merge remote-tracking branch 'origin/master' into custom 2019-12-07 06:55:51 +08:00