Ukukhishwa kweFirefox 73

Isiphequluli sewebhu sikhululiwe I-Firefox 73Futhi inguqulo yeselula IFirefox 68.5 yesikhulumi se-Android. Ngaphezu kwalokho, isibuyekezo senziwe amagatsha ukwesekwa kwesikhathi eside 68.5.0. Uyeza maduze esiteji ukuhlolwa kwe-beta igatsha leFirefox 74 lizohamba, ukukhululwa kwalo kuhlelelwe uMashi 10 (iphrojekthi ethuthile amaviki angu-4 umjikelezo wokuthuthukisa).

main emisha:

  • Kumodi yokufinyelela i-DNS nge-HTTPS (i-DoH, i-DNS nge-HTTPS), usekelo lwesevisi lwengeziwe. Okulandelayo, ngaphezu kweseva ye-CloudFlare DNS enikeziwe ngaphambilini (“https://1.1.1.1/dns-query”). Vula i-DoH bese ukhetha umhlinzeki can kumasethingi okuxhumana kwenethiwekhi.
    Ukukhishwa kweFirefox 73

  • Isigaba sokuqala senziwe ukuqedwa ukwesekwa kwezengezo ezifakwe yi-workaround. Ushintsho luthinta kuphela ukufakwa kwezengezo kunkhombandlela okwabelwana ngayo (/usr/lib/mozilla/extensions/, /usr/share/mozilla/extensions/ noma ~/.mozilla/extensions/) ezicutshungulwe yizo zonke izimo zeFirefox ohlelweni ( ayihlobene nomsebenzisi) . Le ndlela ivamise ukusetshenziselwa ukufaka izengezo ngaphambilini ekusabalaliseni, ukufaka esikhundleni okungacelwanga nezinhlelo zokusebenza zezinkampani zangaphandle, ukuhlanganisa izengezo ezinonya, noma ukuletha isengezo ngokuhlukana nesifaki saso. KuFirefox 73, izengezo ezinjalo zizoqhubeka nokusebenza, kodwa zizosuswa kuhla lwemibhalo ziye kumaphrofayili womsebenzisi ngamunye, i.e. izoguqulelwa kufomethi esetshenziswa uma ifakwa ngomphathi wesengezo.
  • Kwengezwe amandla okusetha izinga lokukala lesisekelo lomhlaba jikelele elisebenza kuwo wonke amakhasi kunokuboshelwa kumasayithi ngamanye. Ungashintsha sonke isikali kuzilungiselelo (mayelana:okuncanyelwayo) kusigaba "solimi nokubukeka". Kukhona futhi inketho kuzilungiselelo ekuvumela ukuthi usebenzise ukukala kumbhalo kuphela, ngaphandle kokuthinta izithombe.

    Ukukhishwa kweFirefox 73

  • Ingxoxo ekucela ukuthi ulondoloze ukungena ngemvume manje isiboniswa kuphela uma inani lokungena endaweni yokufaka lishintshiwe.
  • Kumasistimu anamashayeli e-NVIDIA okuphathelene amasha kunokukhululwa kwe-432 nezinqumo zesikrini ezingaphansi kuka-1920x1200, isistimu yokuhlanganisa inikwe amandla. I-WebRender. Ngaphambilini, iWebRender ibinikwe amandla kuphela ama-NVIDIA GPU anomshayeli we-Nouveau, kanye ne-AMD ne-Intel GPU. Isistimu yokuhlanganisa ye-WebRender ibhalwe ku-Rust futhi ikhipha okuqukethwe kwekhasi okuhlinzeka ngemisebenzi ku-GPU.
  • Kwengeziwe ithuba usebenzisa umqondo weSiphequluli Esicacisiwe Sesayithi (SSB) ukuze
    sebenza ngohlelo lwewebhu njengohlelo olujwayelekile lwedeskithophu. Ikwimodi
    I-SSB ifihla imenyu, ibha yamakheli nezinye izici zesixhumi esibonakalayo sesiphequluli, futhi efasiteleni lamanje ungakwazi kuphela ukuvula izixhumanisi zamakhasi esayithi lamanje (izixhumanisi zangaphandle zivuleka ewindini lesiphequluli elihlukile). Ngokungafani nemodi ye-kiosk ekhona, umsebenzi awenziwa ngemodi yesikrini esigcwele, kodwa efasiteleni elivamile, kodwa ngaphandle kwama-interface e-Firefox-specific interface. Ukuze uvule isixhumanisi kumodi ye-SSB, kuhlongozwa ifulegi lomugqa womyalo elithi “-ssb”, elingasetshenziswa lapho kwakhiwa izinqamuleli zezinhlelo zokusebenza zewebhu. Imodi ingaphinda ibizwe kusetshenziswa inkinobho ethi “Yethula Isiphequluli Esiqondile Sesayithi” etholakala kumenyu yezenzo zekhasi (ama-ellipses kwesokudla sebha yekheli). Ngokuzenzakalelayo, imodi ayisebenzi futhi kufanele ivulwe ngokucacisa “browser.ssb.enabled = true” kokuthi about:config.
    Ukukhishwa kweFirefox 73

  • Imodi yokubonisa enokugqama okuphezulu, eyenzelwe abantu abangaboni kahle noma abangaboni kahle ngombala, manje isekela izithombe ezingemuva. Ukuze kugcinwe ukufundeka nokunikeza izinga elifanele lokuqhathanisa, umbhalo obonakalayo uhlukaniswa ingemuva elihlukile esebenzisa umbala wetimu esebenzayo.
  • Ikhwalithi yomsindo ethuthukisiwe lapho ukhuphuka noma wehla isivinini sokudlala;
  • Ukutholwa okuzenzakalelayo okuthuthukisiwe kombhalo wekhodi omdala emakhasini anganikezi ngokusobala ulwazi lombhalo wekhodi.
  • Kubha yokusesha kukhonsoli yewebhu, manje usuyakwazi ukuhlunga ngokhiye ongekho ngokucacisa uphawu "-" ngaphambi kwemaski noma isisho esivamile. Isibonelo, umbuzo wosesho othi "-img" uzobuyisela zonke izici ezingenayo iyunithi yezinhlamvu ethi "img", kuyilapho "-/(cool|rad)/" izobuyisela izici ezingahambisani nenkulumo evamile "/(cool|rad )/".
  • Kwengezwe izici ezintsha ze-CSS overscroll-behaviour-inline и overscroll-behavior-block ukulawula ukuziphatha kokuskrola lapho umngcele onengqondo wendawo yokuskrola ufinyelelwa.
  • I-SVG manje isekela izakhiwo ukuhlukanisa izinhlamvu и ukuhlukanisa amagama.
  • Kwengezwe indlela ku-HTMLFormElement isiceloThumela(), eqala ukuhanjiswa okuhleliwe kwedatha yefomu ngendlela efanayo nokuchofoza inkinobho yokuhambisa. Umsebenzi ungasetshenziswa lapho uthuthukisa ifomu lakho thumela izinkinobho lapho ifomu lokushaya ucingo.submit() linganele ngenxa yokuthi aliwaqinisekisi amapharamitha ngokuhlanganyela, likhiqize umcimbi 'wokuhambisa', futhi lidlulise idatha eboshelwe enkinobho yokuhambisa.
  • Свойства InnerWidth и innerHeight Izinto zewindi manje zihlala zibuyisela ububanzi nobude bangempela bendawo (Isakhiwo sembobo yokubuka), hhayi usayizi wengxenye ebonakalayo (Imbobo yokubuka ebonakalayo).
  • Kwenziwe ukuthuthukisa ukusebenza kwamathuluzi wabathuthukisi bewebhu. Umthwalo wokuqoqa izibalo zephaneli yokuqapha umsebenzi wenethiwekhi wehlisiwe. Ku-JavaScript debugger naku-web console, ukulayishwa kwemibhalo emikhulu ngokubhekiselwa emibhalweni yomthombo wangempela (imephu yomthombo) kusheshisiwe.
  • Kukhonsoli yewebhu kunezinkinga ngokuya ngale kobubanzi besizinda samanje (AMAKORI, I-Cross-Origin Resource Sharing) manje isiboniswa njengamaphutha kunezixwayiso. Okuguquguqukayo okuchazwe kuzinkulumo manje sekuyatholakala ukuze kuqedelwe ngokuzenzakalela kukhonsoli.
  • Kumathuluzi kanjiniyela wewebhu esigabeni sokuhlola inethiwekhi, ukuqoshwa kwemilayezo (JSON, MsgPack kanye ne-CBOR) ngefomethi ye-WAMP (WebSocket Web Application Messaging Protocol) edluliselwa ngoxhumo lwe-WebSocket kunikezwa.

    Ukukhishwa kweFirefox 73

Ngaphezu kwezinto ezintsha nokulungiswa kweziphazamisi kuFirefox 73, 15 ubuthakathaka, okungu-11 kwakho (okuqoqwe ngaphansi kwe-CVE-2020-6800 ne-CVE-2020-6801) amakwe njenganamandla okuholela ekwenzeni ikhodi yomhlaseli lapho kuvulwa amakhasi aklanywe ngokukhethekile. Ake sikukhumbuze ukuthi izinkinga zememori, ezifana nokuchichima kwe-buffer nokufinyelela ezindaweni zememori esezivele zikhululiwe, kamuva nje zimakwa njengeziyingozi, kodwa ezingabalulekile.

Source: opennet.ru

Engeza amazwana