Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug.


https://bugzilla.redhat.com/show_bug.cgi?id=459211


Michel Alexandre Salim <[email protected]> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
    External Bug ID|                            |Mozilla Foundation 315288




--- Comment #15 from Michel Alexandre Salim <[email protected]>  
2009-09-28 16:22:27 EDT ---
(In reply to comment #13)
> However, Oolite depends on SpiderMonkey being built with the
> JS_C_STRINGS_ARE_UTF8 feature macro enabled, while Firefox currently depends 
> on
> it not being enabled. (There’s a runtime check in Oolite for this.) Switching
> to JS_C_STRINGS_ARE_UTF8 is a to-do for Mozilla 2.0, as attempting to do it 
> for
> 1.9 broke stuff. (Specifically, bits of Mozilla incorrectly use strings as a
> binary blob, and fixing this requires API changes.) This is Mozilla bug 
> 315288,
> https://bugzilla.mozilla.org/show_bug.cgi?id=315288
> 
Jens, thanks for the official comment! I've linked to the Mozilla tracker. I
agree with Manuel -- we'd need the packaging committee's approval to get an
exemption for this.

What would be really helpful is if we get official word from Oolite (you,
basically) clarifying how libjs is used, and thus what the security risk in
using a local copy (that is not patched automatically) would be.

-- 
Configure bugmail: https://bugzilla.redhat.com/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.

_______________________________________________
Fedora-package-review mailing list
[email protected]
http://www.redhat.com/mailman/listinfo/fedora-package-review

Reply via email to