Chromecast does not use OFFICIAL_BUILD at all |
||||||||||||
Issue descriptionChromecast builds that are given to users should be built with OFFICIAL_BUILD #defined, but currently they aren't.
,
Mar 15 2016
,
Apr 5 2016
slan@: Uh oh! This issue is still open and hasn't been updated in the last 21 days. Since this is a serious security vulnerability, we want to make sure progress is happening. Can you update the bug with current status, and what, if anything, is blocking? If you are not the right Owner for this bug, please find someone else to own it as soon as possible and remove yourself as Owner. If the issue is already fixed or you are to unable to reproduce it, please close the bug. (And thanks for fixing the bug!). These nags can be disabled by adding a 'WIP' label and an optional codereview link. - Your friendly ClusterFuzz
,
Apr 21 2016
slan: Uh oh! This issue still open and hasn't been updated in the last 37 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 6 2016
slan: Uh oh! This issue still open and hasn't been updated in the last 52 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 24 2016
This doesn't seem like a it should be a Type=Bug-Security, since there is no concrete vulnerability here. Flipping labels.
,
May 24 2016
,
Jun 30 2016
@ochang: see comment 1, there are extra holes we open up.
,
Jul 26 2016
Currently, static key pinning is enabled when OFFICIAL_BUILD is set. https://cs.chromium.org/chromium/src/net/http/transport_security_state.cc?q=transportsecuritystate&sq=package:chromium&dr=CSs&l=724 We cannot enable OFFICIAL_BUILD until static key pinning no longer relies on this flag. rsleevi@ is looking at fixing this.
,
Mar 6 2017
To clarify: rsleevi@ is not working on this. I highlighted the risk of setting it.
,
Mar 6 2017
,
Mar 6 2017
jasonkliu is talking to the cast team about other issues.
,
Mar 13 2017
,
May 15 2017
,
Jun 6 2017
,
Jun 6 2017
The static key pinning part was fixed a while back: https://codereview.chromium.org/2737583002 Seems like we could attempt to use is_official_build now.
,
Jun 12 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/8777982503bdf20d27992ded417d64b8a2be081e commit 8777982503bdf20d27992ded417d64b8a2be081e Author: Luke Halliwell <halliwell@chromium.org> Date: Mon Jun 12 15:59:06 2017 [Chromecast] Fix death test failures in official builds CHECK macro strings are dropped in official builds to save space. BUG= 594632 Change-Id: Ic53faaa7480fa3c72a75e9af9c4a658cf05b4cc4 Reviewed-on: https://chromium-review.googlesource.com/530103 Reviewed-by: Stephen Lanham <slan@chromium.org> Commit-Queue: Luke Halliwell <halliwell@chromium.org> Cr-Commit-Position: refs/heads/master@{#478642} [modify] https://crrev.com/8777982503bdf20d27992ded417d64b8a2be081e/chromecast/media/cma/backend/alsa/slew_volume_unittests.cc [modify] https://crrev.com/8777982503bdf20d27992ded417d64b8a2be081e/chromecast/media/cma/backend/alsa/stream_mixer_alsa_unittest.cc
,
Jul 31 2017
1.26 release enabled is_official_build |
||||||||||||
►
Sign in to add a comment |
||||||||||||
Comment 1 by jam@chromium.org
, Mar 14 2016