From MozillaWiki
Jump to: navigation, search

« previous week | index | next week »

Platform Meeting Details

  • Tuesdays - 11:00 am Pacific
  • Dial-in: Audio-only conference# 95312
    • People with Mozilla phones or softphones please dial x4000 Conf# 95312
    • US/Toll-free: +1 800 707 2533, (pin 4000) Conf# 95312
    • US/California/Mountain View: +1 650 903 0800, x4000 Conf# 95312
    • US/California/San Francisco: +1 415 762 5700, x4000 Conf# 95312
    • US/Oregon/Portland: +1 971 544 8000, x4000 Conf# 95312
    • CA/British Columbia/Vancouver: +1 778 785 1540, x4000 Conf# 95312
    • CA/Ontario/Toronto: +1 416 848 3114, x4000 Conf# 95312
    • UK/London: +44 (0)207 855 3000, x4000 Conf# 95312
    • FR/Paris: +33 1 84 88 37 37, x4000 Conf# 95312
    • Gmail Chat (requires Flash and the Google Talk plugin): paste +1 650 903 0800 into the Gmail Chat box that doesn't look like it accepts phone numbers
    • SkypeOut is free if you use the 800 number
  • Warp Core Vidyo Room
  • join #planning for back channel

Notices / Schedule

  • We're already building FF12 beta 3 today - please take a look at the 12+ tracking list for bugs assigned to you or in modules/components you watch
    • Email if you need any support in your investigation
    • Now is the time in the cycle to nominate speculative crash fixes

Firefox Development

  • pdf.js landed on trunk, thanks to efforts by Dave Townsend, Yury Delendik and the rest of the pdf.js team (bug 714712)
    • A bunch of followup bugs have been filed, including needing to sort out the problems with it being caught by our drop-in add-on install detection (bug 738674).
  • Upcoming work:
    • Web Apps system installation (bug 731054): Felipe, Tim Abraldes, Myk Melez and others have been working hard to get installable web apps support landed
    • In-content prefs, a project by a group of MSU Students (bug 718011), is getting closer to being able to land. Parts of it have landed in "UX" builds, so if you want an early preview you can check those out

Firefox Developer Tools

  • Work week last week
  • Chrome debugging demoed.
  • Fennec debugging demoed.
  • Magnifier feature written in scratchpad. To run scratchpads in browser context:
    • go to about:config, set to true
    • Restart the browser
    • Start scratchpad
    • Select Environment->Browser menu item.
  • More hacks, see the writeups.
  • Some writeups:

Add-on SDK

  • Nothing to add this week


  • New, easier to remember Telemetry URL -
  • This week's Snappy summary
  • Vlad landed a new Telemetry probe for slow dynamic SQL queries and updated about:telemetry to show the data.
  • Profiler
    • Ehsan landed Android stackwalking support.
    • Markus Stange (mstange) has been rocking the entire UI. See the new front end screenshot. (bug 719530)
    • Front-end now using chrome and web worker. Improved the performance of operations in the UI to support a larger profile.
  • Vlad blogged about chromehang work. Read it.
  • Vlad updated the about:telemetry add-on to show chromehang reports locally - will be released once the Symbolication Server is deployed publicly.
  • Avi has been working on fixing scrolling for OSX and Linux.
  • Peptest is enabled on try. Submit your test cases (mcote can review) for changes for which you want to measure the effect on responsiveness.
  • mccr8 has been looking to speed up CCs with two tabs open (Gmail+mozilla Wiki) by removing more stuff from the CC graph. Landed bug 735342, bug 736763, bug 735550, bug 737060.
    • Next will investigate CCs with 6 or so tabs open and reported slowdowns from add-ons.
  • Rafael identified new issues related to shutdown and has some further paths to check. bug 735697, bug 711076, bug 732173, bug 731741



  • Jim Blandy and Jason Orendorff were in London for the devtools work week
    • Working together with devtools, they got chrome debugging demo'd with the built-in debugger (see also devtools update)
  • GC still blocked on Tinderbox memory leaks.



  • Zzzzzz





work week last week, khuey and ddahl in attendance. Worked out components needed for native implementation. Diagram and bugs to follow.




Tree Management

  • b2g builds starting on m-c today, project branches and try
    • checks that people don't break the b2g build and packaging
    • uploads build logs
    • does not currently upload packages
    • run as an extra job on each push and as part of the nightly
    • will show up on tbpl once new tbpl code is pushed out (bug 738891)
  • Infrastructure load for january and february
    • 4th month in a row of record # of checkins. 4,027 checkins in february!
    • new record of 223 checkins per day on feb 23
  • tcheckerboard and trobopan tests enabled for m-c/m-i today for native fennec builds


Security Reviews & Threat Modeling Sessions Scheduled for this week

Date / Time Item
Mon Mar 25 / 13:00 PST None
Wed Mar 28 / 13:00 PST Geolocation WebAPI
Thu Mar 29 / 10:00 PST AVAILABLE
Fri Mar 30 / 10:00 AM PST AVAILABLE

Calendar and Meeting details

General Meeting Details 
* IRC Channel: #security 
* Etherpad: 
* Vidyo: (Room 9058)
* Dial-in Info (phone): 
** In office or soft phone: extension 92 
** US/INTL: 650-903-0800 or 650-215-1282 then extension 92 
** Toronto: 416-848-3114 then extension 92 
** Toll-free: 800-707-2533 then password 369 
** Conference num 99058

For updates to meetings please see the Security Review Calendar

Security Review Needed but Unscheduled

Review Needed

  • Feature pages triaged to need review, review unscheduled
Feature Feature List Target Rel Prod Mgr Lead Engr Security lead Security status Security notes Last Modified
Client-side XPI construction Jetpack Add-on Builder 2 Daniel Buchner Piotr Zalewa/Sean McArthur `sec-review-needed `2012-04-12T20:05:12
Add-On Tab API ` Add-on SDK 1.5 David Mason ` Dan Veditzsec-review-needed bug 7449132012-04-12T20:10:51
B2G App Security and Privacy Model ` B2G 1.0 Lucas Adamski Jonas Sicking, Chris Jones Paul Theriaultsec-review-needed bug 7449152013-11-22T18:35:41
Style Editor Desktop Firefox 11 Kevin Dangoor Cedric Vivier `sec-review-needed bug 7449212012-08-30T13:42:53
Migrate Chrome settings and data Desktop Firefox 11 Asa Dotzler Makoto Kato, Marco Bonardo `sec-review-needed bug 7449192012-04-12T20:17:13
Generic Thumbnail Service Platform Firefox 12 ` Tim Taubert `sec-review-needed 2012-05-16T23:15:03
Easy UI Feature Testing and "Success Evaluation" (integrate TestPilot like features) ` Firefox 13 ` ` `sec-review-needed Please schedule with curtisk2012-03-02T23:41:56
Hang Detector and Reporter Desktop Firefox 14 Asa Dotzler Vladan Djeric `sec-review-needed bug 7449262012-04-18T19:50:16
Install and Uninstall Web Apps in Firefox ` Firefox 15 Ragavan Srinivasan ` `sec-review-needed 2012-06-05T21:53:38
Responsive View Desktop Firefox 15 Kevin Dangoor Paul Rouget `sec-review-needed 2012-08-30T13:40:32
In-content preferences Desktop Firefox 15 Asa Dotzler Jon Rietveld `sec-review-needed bug 7449362012-05-07T14:15:25
Camera API Phase 2 - based on getUserMedia Mobile Firefox 15 - Mobile only, still image support only Maire Reavy Anant Narayanan Lucas Adamski (currently) Curtis Koenig (soon)sec-review-needed bug 7492212012-10-16T07:15:46
Media Plugin API (MPAPI) Mobile Firefox 15 or 16 (TBD) - Mobile only, by the end of Q2 Maire Reavy Rob O'Callahan (formerly Andreas Gal) TBDsec-review-needed bug 7492212012-06-06T02:40:33
Feature name here ` Firefox 16 Karen Rudnitski Brad Lassey `sec-review-needed 2012-08-31T17:39:44
Firefox Social Integration Desktop Firefox 17 Asa Dotzler Shane Caraveo Michael Coatessec-review-needed bug 7334142014-04-11T05:29:17
HTML Tree Editor Desktop Firefox 17 Kevin Dangoor Dave Camp `sec-review-needed 2012-09-17T17:04:20
Per-Site Third-Party Cookie Setting Platform Firefox 18 ` ` Curtis Koenigsec-review-needed 2013-02-08T17:31:48
Show PDF inline Platform Firefox 18 Asa Dotzler Bill Walker `sec-review-needed 2012-10-04T13:16:57
Windows Plugin Hang UI Desktop Firefox 19 asa Aaron Klotz `sec-review-needed 2012-10-29T15:51:21
Tools In Windows Desktop Firefox 20 Kevin Dangoor Paul Rouget `sec-review-needed 2013-08-01T20:30:23
JavaScript Profiling Desktop Firefox 20 Kevin Dangoor Anton Kovalyov `sec-review-needed 2013-08-01T20:31:39
Network View Desktop Firefox 23 Kevin Dangoor ` `sec-review-needed assigned to mgoodwin2013-08-14T21:07:34
Downloads API Desktop Firefox 26 ` Paolo Amadini `sec-review-needed assigned to mgoodwin to look at via sec-review? in bug 8255882013-10-25T09:40:01
Panel Menu Desktop Firefox 29 Asa Dotzler Blair McBride `sec-review-needed sec review work to be done by freddyb2014-05-15T03:04:34
FlightDeck as a Client-side App Jetpack FlightDeck 1.0 Daniel Buchner Sean McArthur `sec-review-needed when ready sched w/ curtisk2012-01-25T22:43:38
IndexedDB Support for Multi-Process Firefox Platform Future, distant future. Chris Blizzard ` `sec-review-needed 2011.10.17: sid recommends we wait on this one but likely needs a review. bug 7449402012-04-12T20:52:20
Simplify signing XPIs in Jetpack Jetpack Jetpack Future Dave Mason ` `sec-review-needed 2012-06-05T22:46:09
Purchase PIN Marketplace Marketplace July Justin Scott Unassigned Raymond Forbessec-review-needed 2016-04-01T02:19:58
Notifications Other Q3 None Assigned, One has been requested JR Colin David Chansec-review-needed bug 7498062012-05-09T17:00:36
Sharing textures cross-process for Electrolysis Platform Q4 of 2011. Chris Blizzard Chris Jones `sec-review-needed bug 7449442013-07-22T07:19:02
SDK Support for Firefox for Mobile Addons Jetpack SDK 1.5 David Mason Matteo Ferretti `sec-review-needed bug 7449462012-04-12T21:04:55
Apps Management App ` TBD ` ` `sec-review-needed 2012-08-31T17:38:35
Modern MIME Parser Thunderbird Thunderbird 16 ` Joshua Cranmer `sec-review-needed bug 7449522012-05-31T14:31:02
Thunderbird Metro Thunderbird Thunderbird 17 ` ` `sec-review-needed 2012-07-22T02:29:05
SMS support in Thunderbird Thunderbird Thunderbird 19 ` ` `sec-review-needed
Modern Address Book - V1 Thunderbird Under revision ` Mike Conley `sec-review-needed bug 7449552012-05-16T17:16:47
Speedy Session Restore Desktop ` Asa Dotzler Dietrich Ayala `sec-review-needed bug 7449342012-07-23T20:43:45
Enhancements to help mitigate search hijacking Desktop ` Asa Dotzler Gavin Sharp Al Billingssec-review-needed bug 7449572012-07-18T01:36:50
Blocklist UX enhancements [Plug-ins] Desktop ` Kev Needham ` `sec-review-needed bug 7449622012-04-12T21:40:01
Sign into the browser Other ` Dan Mills Ben Adida `sec-review-needed bug 7449482012-07-26T22:36:15
Add plugincheck functionality to Add-on Manager Desktop ` Kev Needham ` `sec-review-needed bug 7449672012-04-12T21:46:41
DOMCryptAPI (a Crypto API in the DOM) Platform ` Chris Blizzard David Dahl Brian Smithsec-review-needed bug 7449382013-11-22T19:02:09
Native Sign In to Website Desktop ` ` Austin King (ozten) `sec-review-needed `2013-10-18T23:50:02

Bugs marked sec-review-needed that need to be scheduled

No results.

0 Total; 0 Open (0%); 0 Resolved (0%); 0 Verified (0%);

Stability Report

  • Planning a stability work week in MV - either June 11th or June 18th.


  • Another incremental release landing on Wednesday
    • A lot of skiplist additions, mostly concerning desktop, e.g. MOZ_Crash signature which is #1 on Nightly right now.
    • Visual indicator for startup crashes coming to topcrash lists.
  • A lot of ongoing work focused on getting ElasticSearch working.
  • Proposal for user-facing priorities for Socorro in Q2 is up for discussion, but needs some more work and input.



  • Release - FF11
    • Crash rate looks pretty good
    • Some increase in hangs related to Flash Version 11.1.x: bug 739445
  • Beta - FF12
    • bug 725503 - still a concern. Something new that appeared in FF12 but haven't been able to isolate a clear regression range or STR.
    • Tracking Firefox 12
  • Aurora - FF13
  • Nightly - FF14
    • Spike up in crashes yesterday
    • bug 739027 - crash in nsXPConnect::Push
    • bug 739024 - crash in nsHttpPipeline::WriteSegments
    • bug 739023 - crash in nsHttpChannel::OnDataAvailable
    • bug 739147 - crash in nsHttpConnectionMgr::PostEvent
    • bug 739400 - crash in mozglue@0x79be


Fennec Native - Nightly

Other Channels

  • Fennec Native - Aurora
    • 13.48% bug 738977 java.lang.RuntimeException: An error occured while executing doInBackground() at
    • 6.19% bug 730890
    • 5.36% bug 730688 java.lang.RuntimeException: Unable to resume activity {org.mozilla.fennec_aurora
  • XUL - Beta
  • Note: Beta numbers has been fixed; bug 737069
  • ESR
    • 33.03% Java_org_mozilla_gecko_GeckoAppShell_reportJavaCrash
      • Needs to be pushed to XUL : bug 701002 - Put Java stacks into a separate field (not AppNotes)
    • 26.05% bug 694964 gfxSharedImageSurface::Open
    • 7.15% bug 715831 js::RegExpPrivate::executeInternal