Files
sousa-gecko/toolkit/profile/test/xpcshell/xpcshell.toml
T
Benjamin Beurdouche f158cf08b8 Bug 1996558 - Address review feedback for SQLite encryption (excluding keystore). r=gcp,places-reviewers,mconley,mak,mossop
Follow-up to D270165 addressing reviewer comments outside security/keystore/
and adding a profile-encryption launch guard:

- Add a database-at-rest launch guard. nsAppRunner reads an
  EncryptedDatabases marker from compatibility.ini early in
  XRE_mainStartup and refuses to launch (alert + clean exit) rather than
  corrupt data when the profile's on-disk state and the
  security.storage.encryption.sqlite.enabled pref disagree: an encrypted
  profile opened by a pref-off build, or plaintext databases under a
  pref-on build (the latter detected by reading the SQLite header's
  8192-byte-page / 32-reserved-byte obfsvfs signature, no mozStorage).
  The gate is skipped in backgroundtask mode. The EncryptedDatabases flag
  is read in CheckCompatibility (which already parses compatibility.ini)
  and written by a new nsIXULRuntime.markProfileEncryptedDatabases
  (append-only, modeled on invalidateCachesOnRestart), with an xpcshell
  test; the storage layer wires the marker write on profile-after-change
  in the lockstore commit.
- Drop duplicate hasKey/mDatabaseEncrypted assignment and clarify the
  "outside profile" fallback comments in Connection::initialize.
- Restore explicit `return rv` at the three sqlite3_open failure sites
  that the original patch had switched to NS_ENSURE_SUCCESS.
- Strengthen the security.storage.encryption.sqlite.enabled pref
  description to flag it INTERNAL / DO NOT ENABLE pending the
  enterprise-policy gate in the rest of the stack.
- Replace the mozilla_net_percent_encode Rust addition in
  netwerk/base/idna_glue with a call to NS_EscapeURLSpan(esc_FilePath |
  esc_Forced) inside a new shared helper, storage::PreparePathForURI,
  exported via storage/StoragePathUtil.h. NS_EscapeURLSpan covers '?',
  '#', '&', space, etc. -- not just '%'.
- Expose obfsvfs::kObfsPageSize from ObfuscatingVFS.h so that
  Connection::GetDefaultPageSize and ObfuscatingVFS.cpp share the same
  8192 constant instead of duplicating literals.
- Use storage::PreparePathForURI in toolkit/components/places/
  Database.cpp::AttachDatabase before building the file: URI, so paths
  containing URI-significant bytes don't produce malformed URIs.
- Make ExtractURIPathAndQuery tolerant of bare filesystem paths. PRAGMA
  database_list returns normalized filenames (no file: prefix), so the
  encrypted-clone branch was previously returning NS_ERROR_FAILURE and
  breaking Connection::initializeClone for encrypted DBs with attached
  databases.
- Track the pending mozIStoragePendingStatement returned by
  attachDatabase in Sqlite.sys.mjs's _pendingStatements map, matching
  the _executeStatement pattern, so shutdown can cancel in-flight
  ATTACH operations instead of leaking them.
- Parameterize test_page_size_is_32k.js on the encryption pref (8 KiB
  when on, 32 KiB when off) and drop its pref override in xpcshell.toml.
- Strengthen the comment in dom/indexedDB/test/marionette/
  manifest.toml about the PBM x obfsvfs interaction gap and reference a
  pending follow-up bug.

Differential Revision: https://phabricator.services.mozilla.com/D301054
2026-06-16 13:00:19 +00:00

150 lines
2.4 KiB
TOML

[DEFAULT]
head = "head.js"
skip-if = [
"os == 'android'",
]
["test_appgroup_profile.js"]
run-if = ["os == 'mac'"]
["test_async_flush.js"]
["test_async_flush_cp_path.js"]
["test_async_flush_cp_storeID.js"]
["test_async_flush_current_profile.js"]
["test_bad_ini.js"]
["test_check_backup.js"]
["test_claim_locked.js"]
["test_clean.js"]
["test_conflict_installs.js"]
["test_conflict_profiles.js"]
["test_create_default.js"]
["test_delete_dirs.js"]
["test_encrypted_databases_marker.js"]
["test_find_currentProfile.js"]
["test_fix_directory_case.js"]
["test_ignore_legacy_directory.js"]
["test_ignore_storeID_pref.js"]
["test_invalid_descriptor.js"]
["test_legacy_empty.js"]
["test_legacy_select.js"]
["test_lock.js"]
["test_missing_profilesini.js"]
["test_new_default.js"]
["test_new_profile_ping_sent.js"]
skip-if = [
"artifact", # Bug 2012613 - known limitation of FOG ping testing APIs
]
["test_new_profile_ping_skipped.js"]
["test_previous_dedicated.js"]
["test_profile_descriptor_and_localdir.js"]
["test_profile_reset.js"]
["test_remove.js"]
["test_remove_default.js"]
["test_restore_storeID.js"]
["test_select_backgroundtasks_ephemeral.js"]
["test_select_backgroundtasks_not_ephemeral_create.js"]
["test_select_backgroundtasks_not_ephemeral_exists.js"]
["test_select_default.js"]
["test_select_environment.js"]
["test_select_environment_named.js"]
["test_select_missing.js"]
["test_select_named.js"]
["test_select_noname.js"]
["test_select_profile_argument.js"]
["test_select_profile_argument_new.js"]
["test_select_profilemanager.js"]
["test_showselector.js"]
["test_single_profile_selected.js"]
skip-if = [
"devedition",
]
["test_single_profile_unselected.js"]
skip-if = [
"devedition",
]
["test_skip_locked_environment.js"]
["test_snap.js"]
environment = ["SNAP_NAME=firefox", "SNAP_INSTANCE_NAME=firefox"]
run-if = [
"os == 'linux'",
]
skip-if = [
"appname == 'thunderbird'",
]
["test_snap_empty.js"]
environment = ["SNAP_NAME=firefox", "SNAP_INSTANCE_NAME=firefox"]
run-if = [
"os == 'linux' && os_version == '24.04' && arch == 'x86_64' && display == 'x11'",
]
skip-if = [
"appname == 'thunderbird'",
]
["test_snatch_environment.js"]
["test_snatch_environment_default.js"]
["test_startswithlast.js"]
["test_steal_inuse.js"]
["test_storeid.js"]
["test_update_paths.js"]
["test_update_selected_dedicated.js"]
["test_update_unknown_dedicated.js"]
["test_update_unselected_dedicated.js"]
["test_use_dedicated.js"]