Your message dated Wed, 28 Aug 2013 12:32:11 +0900
with message-id <[email protected]>
and subject line Re: Bug#720289: history, analysis, and a recommendation
has caused the Debian Bug report #720289,
regarding iceweasel: Possible regression in WebGL Renderer: Blocked, looking
for "Not Mesa"
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
720289: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=720289
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: iceweasel
Version: 17.0.8esr-1~deb7u1
Severity: normal
Dear Maintainer,
Upgrading stock wheezy from iceweasel 10.0.12esr-1 (on the CD)
to 17.0.8esr-1~deb7u1 (current security patch as of 2013-08-19)
breaks WebGL renderer detection, at least on my test machine with
Adapter Description: X.Org -- Gallium 0.4 on AMD ARUBA
Vendor ID: X.Org
Device ID: Gallium 0.4 on AMD ARUBA
Driver Version: 2.1 Mesa 8.0.5
I am aware of bugzilla@mozillabug 734297
https://bugzilla.mozilla.org/show_bug.cgi?id=734297
and hope that didn't confuse me.
I checked the WebGL Renderer status (on the about:support page)
immediately before and after the upgrade. The "after" message is:
Blocked for your graphics driver version. Try updating your graphics driver to
version Not Mesa or newer.
-- Package-specific info:
-- Extensions information
Name: Default theme
Location: /usr/lib/iceweasel/extensions/{972ce4c6-7e08-4474-a285-3208198ce6fd}
Package: iceweasel
Status: enabled
Name: Download YouTube Videos as MP4 user-script
Status: enabled
Name: Greasemonkey
Location:
/usr/share/mozilla/extensions/{ec8030f7-c20a-464f-9b0e-13a3a9e97384}/{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
Package: xul-ext-greasemonkey
Status: enabled
-- Plugins information
Name: Gnome Shell Integration
Location: /usr/lib/mozilla/plugins/libgnome-shell-browser-plugin.so
Package: gnome-shell
Status: enabled
-- Addons package information
ii gnome-shell 3.4.2-7 amd64 graphical shell for the GNOME des
ii iceweasel 17.0.8esr-1~ amd64 Web browser based on Firefox
ii xul-ext-grease 0.9.20-1 all extension that enables customizat
-- System Information:
Debian Release: 7.1
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 3.2.0-4-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Versions of packages iceweasel depends on:
ii debianutils 4.3.2
ii fontconfig 2.9.0-7.1
ii libc6 2.13-38
ii libgdk-pixbuf2.0-0 2.26.1-1
ii libglib2.0-0 2.33.12+really2.32.4-5
ii libgtk2.0-0 2.24.10-2
ii libnspr4 2:4.9.2-1
ii libnspr4-0d 2:4.9.2-1
ii libsqlite3-0 3.7.13-1+deb7u1
ii libstdc++6 4.7.2-5
ii procps 1:3.3.3-3
ii xulrunner-17.0 17.0.8esr-1~deb7u1
iceweasel recommends no packages.
Versions of packages iceweasel suggests:
ii fonts-stix [otf-stix] 1.1.0-1
ii libgssapi-krb5-2 1.10.1+dfsg-5+deb7u1
pn mozplugger <none>
Versions of packages xulrunner-17.0 depends on:
ii libasound2 1.0.25-4
ii libatk1.0-0 2.4.0-2
ii libbz2-1.0 1.0.6-4
ii libc6 2.13-38
ii libcairo2 1.12.2-3
ii libdbus-1-3 1.6.8-1+deb7u1
ii libdbus-glib-1-2 0.100.2-1
ii libevent-2.0-5 2.0.19-stable-3
ii libfontconfig1 2.9.0-7.1
ii libfreetype6 2.4.9-1.1
ii libgcc1 1:4.7.2-5
ii libgdk-pixbuf2.0-0 2.26.1-1
ii libglib2.0-0 2.33.12+really2.32.4-5
ii libgtk2.0-0 2.24.10-2
ii libhunspell-1.3-0 1.3.2-4
ii libjpeg8 8d-1
ii libmozjs17d 17.0.8esr-1~deb7u1
ii libnspr4 2:4.9.2-1
ii libnss3 2:3.14.3-1
ii libnss3-1d 2:3.14.3-1
ii libpango1.0-0 1.30.0-1
ii libpixman-1-0 0.26.0-4
ii libsqlite3-0 3.7.13-1+deb7u1
ii libstartup-notification0 0.12-1
ii libstdc++6 4.7.2-5
ii libvpx1 1.1.0-1
ii libx11-6 2:1.5.0-1+deb7u1
ii libxext6 2:1.3.1-2+deb7u1
ii libxrender1 1:0.9.7-1+deb7u1
ii libxt6 1:1.1.3-1+deb7u1
ii zlib1g 1:1.2.7.dfsg-13
Versions of packages xulrunner-17.0 suggests:
ii libcanberra0 0.28-6
pn libgnomeui-0 <none>
-- no debconf information
--- End Message ---
--- Begin Message ---
On Tue, Aug 27, 2013 at 07:59:24PM -0700, Larry Doolittle wrote:
> Dear iceweasel maintainers and lurkers,
>
> Here's some history, analysis, and a recommendation.
>
> Firefox 10-ESR disabled WebGL/Mesa based on
> https://bugzilla.mozilla.org/show_bug.cgi?id=777028
> in which the rationale comes out clearly:
> 1. the Firefox team can't control the quality of the Mesa version installed
> 2. ESR releases are meant for ultra-conservative users who probably are
> not interested in glitzy frills like WebGL
> Neither of these assumptions is completely true for a Debian stable release.
> Also, blacklisting WebGL/Mesa indirectly endorses proprietary drivers; a
> position
> that probably doesn't bother Mozilla much, but is at odds with Debian
> principles.
>
> iceweasel_10.0.12esr-1 shipped with
> patches/fixes/Allow-webGL-with-mesa-assuming-users-will-have-updat.patch
> which removes the disabling stanza. Its meta-information reads:
> From: Mike Hommey <redacted>
> Date: Fri, 31 Aug 2012 09:01:08 +0200
> Subject: Allow webGL with mesa, assuming users will have updated to 8.0.4-2
> on wheezy
> The version in squeeze-backports is not affected by CVE-2012-2864, and the
> version in squeeze is blacklisted.
>
> Firefox 17-ESR disabled WebGL/Mesa based on
> https://bugzilla.mozilla.org/show_bug.cgi?id=838413
> which has much less detail than the Firefox 10 discussion.
> The starting comment from Benoit Jacob is:
> In ESR10 Mesa was blacklisted and we've had many occasions to be thankful
> for that.
> We should do the same for ESR17.
>
> iceweasel_17.0.8esr-1~deb7u1 shipped _without_ any patch changing the
> WebGL/Mesa blacklisting. If there was any internal discussion leading to that
> decision, I'm not aware of it. And of course there's no commit message to
> read.
>
> I don't want to second-guess the decision to leave WebGL/Mesa disabled in
> Wheezy's
> iceweasel. But if that is in fact the intended behavior, there are two bugs:
> 1. Not documenting the regression
> 2. Not providing a bypass
> I have been taught that software "should not set policy, but provide
> capabilities."
> (That phrasing is from 2008 by John Kacur, but the idea is much older.)
>
> I'm no Firefox source code expert, so I don't really want to write the patch
> putting in a bypass switch to ignore the blacklist. If I did it, it would
> probably be based on a magic environment variable. Maybe there's a more GUI
> way to do it. Whatever. But it should not require a 75+ MB download and 2
> hours
> of CPU time to bypass a blacklist that may or may not have any basis.
WebGL on Mesa is a security hazard. It was blacklisted for that reason
in ESR17. Newer Firefox versions have mitigations that haven't been
backported, and that I'm not willing to backport myself.
I do agree the blacklist message is really not clear.
Note you can disable the blacklist by setting the webgl.force-enabled
preference in about:config.
https://wiki.mozilla.org/Blocklisting/Blocked_Graphics_Drivers#How_to_force-enable_blocked_graphics_features
Mike
--- End Message ---