New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 868463 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Aug 1
Cc:
Components:
EstimatedDays: ----
NextAction: 2018-07-30
OS: Linux , Windows , Chrome , Mac
Pri: 1
Type: Bug-Security

Blocked on:
issue 868651
issue 868695



Sign in to add a comment

Security: libaom build default values

Project Member Reported by jaikk@chromium.org, Jul 27

Issue description

Change default values for the three security changes with libaom:
1. Set profile > 0 to OFF by default
2. Set large scale tile to OFF by default
3. Set AV1 decode flag to ON by default
 
Components: Internals>Media>Codecs
Labels: Security_Severity-High Security_Impact-Beta OS-Chrome OS-Linux OS-Mac OS-Windows
Status: Assigned (was: Unconfirmed)
I took care of the first two as part of this roll on M69
https://chromium-review.googlesource.com/c/chromium/src/+/1151961

and earlier, same was done for master branch:
https://chromium-review.googlesource.com/c/chromium/src/+/1150903

I'm not sure about #3
Owner: johannkoenig@chromium.org
Owner: johannko...@google.com
Cc: mlamouri@chromium.org
Cc: -mlamouri@chromium.org beccahughes@chromium.org
Blocking: -866103
Cc: dalecur...@chromium.org
Last CL for this bug cl/1153578
https://chromium-review.googlesource.com/c/chromium/src/+/1153578

And once this lands I was going to use this to request M69 merge approval.
Cc: -beccahughes@chromium.org
Project Member

Comment 12 by bugdroid1@chromium.org, Jul 27

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/f2813ce352ac65a2d4259ae7aba9fa739d3903aa

commit f2813ce352ac65a2d4259ae7aba9fa739d3903aa
Author: Johann <johannkoenig@google.com>
Date: Fri Jul 27 21:23:55 2018

enable av1 playback by default

Bug:  868463 
Change-Id: I6183b008ba749dcde3b317fbccc0636053e8a667
Reviewed-on: https://chromium-review.googlesource.com/1153578
Reviewed-by: Dale Curtis <dalecurtis@chromium.org>
Commit-Queue: Johann Koenig <johannkoenig@google.com>
Cr-Commit-Position: refs/heads/master@{#578803}
[modify] https://crrev.com/f2813ce352ac65a2d4259ae7aba9fa739d3903aa/content/browser/media/media_canplaytype_browsertest.cc
[modify] https://crrev.com/f2813ce352ac65a2d4259ae7aba9fa739d3903aa/media/base/media_switches.cc

NextAction: 2018-07-30
Pls request a merge to M69 on Monday morning if change listed at #12 looks good in canary. Thank you.
Project Member

Comment 14 by sheriffbot@chromium.org, Jul 28

Labels: ReleaseBlock-Stable
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it.

If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Blockedon: 868651
Project Member

Comment 16 by sheriffbot@chromium.org, Jul 28

Labels: Pri-1
Not sure what the ReleaseBlock-Stable label is referring to. The bug I linked is in ToT, not the M69 branch (which is going to Beta, not Stable) and comment 14 was added before I set the blocking bug.
The NextAction date has arrived: 2018-07-30
Blockedon: 868695
Is this need a merge to M69? If yes, pls request a merge to M69.
There were two clusterfuzz issues filed over the weekend:
https://bugs.chromium.org/p/chromium/issues/detail?id=868651
https://bugs.chromium.org/p/chromium/issues/detail?id=868695

Both had patches land yesterday but may need to be merged to M69 before I can request a merge for this issue.
awhalley@, could you ptal comment #21 and let us know whether you're ok with above merges? Thank you.
govind@ should be good once they've been made it into Canary, they've not yet from what I can see.
Owner: gov...@chromium.org
govind@ can we check again? I believe both patches should be ready for merging.
Owner: jaikk@chromium.org
Merge is approved here - https://bugs.chromium.org/p/chromium/issues/detail?id=868651#c16. Pls let me know if any other merge needs approval.

Pls close this bug after the merge if nothing else is pending for M69. Thank you.

Cc: johannkoenig@chromium.org
Cc: -johannkoenig@chromium.org johannko...@google.com
Labels: Merge-Request-69
Since the blocking bugs are resolved, requesting merge permission for "enable av1 playback by default"

https://chromium-review.googlesource.com/1153578
Do we need to complete any cross functional reviews (Legal, Privacy, Test, Security...etc) before "enable av1 playback by default" for M69?
Labels: -Merge-Request-69 Merge-Approved-69
Approving merge to M69 branch 3497 for Cl listed at #28 based on comments #28, #29 and per group discussion. Please merge ASAP. Thank you.
Project Member

Comment 32 by bugdroid1@chromium.org, Aug 1

Labels: -merge-approved-69 merge-merged-3497
The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/5482868466da68aa15e8c5705fd297b50a2170a8

commit 5482868466da68aa15e8c5705fd297b50a2170a8
Author: Johann <johannkoenig@google.com>
Date: Wed Aug 01 23:08:34 2018

enable av1 playback by default

Bug:  868463 
Change-Id: I6183b008ba749dcde3b317fbccc0636053e8a667
Reviewed-on: https://chromium-review.googlesource.com/1153578
Reviewed-by: Dale Curtis <dalecurtis@chromium.org>
Commit-Queue: Johann Koenig <johannkoenig@google.com>
Cr-Original-Commit-Position: refs/heads/master@{#578803}(cherry picked from commit f2813ce352ac65a2d4259ae7aba9fa739d3903aa)
Reviewed-on: https://chromium-review.googlesource.com/1159501
Reviewed-by: Johann Koenig <johannkoenig@google.com>
Cr-Commit-Position: refs/branch-heads/3497@{#323}
Cr-Branched-From: 271eaf50594eb818c9295dc78d364aea18c82ea8-refs/heads/master@{#576753}
[modify] https://crrev.com/5482868466da68aa15e8c5705fd297b50a2170a8/content/browser/media/media_canplaytype_browsertest.cc
[modify] https://crrev.com/5482868466da68aa15e8c5705fd297b50a2170a8/media/base/media_switches.cc

Status: Fixed (was: Assigned)
Project Member

Comment 34 by sheriffbot@chromium.org, Aug 2

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: -ReleaseBlock-Stable
Project Member

Comment 36 by sheriffbot@chromium.org, Nov 8

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment