BUGS: 1.9.4.x Dev
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: BUGS: 1.9.4.1 Dev
latest development build is out:
v 1.9.4.2
=====================================================================
x Fixed mixed content SSL false positives when ABE enabled
x Fixed file:// entry added to whitelist everytime a 2nd level
domain gets allowed on Gecko >= 1.9 (thanks GµårÐïåñ for reporting)
@therube: the "broken icon" was just a cosmetic artifact, security of the page was not broken.
@dhown: that bug is fixed as well, even though not reported in the changelog, because of the SSL mixed content fix.
@GµårÐïåñ:
the file:// issue has been quite hard to track, because it was actually not a bug freshly introduced NoScript, but a behavior change in Gecko's nsFileProtocol class: file URLs don't seem to support hostPort anymore (it was used to address Samba shares), and this caused any 2nd level domain to collapse into file:// as soon as it was added to the whitelist.
v 1.9.4.2
=====================================================================
x Fixed mixed content SSL false positives when ABE enabled
x Fixed file:// entry added to whitelist everytime a 2nd level
domain gets allowed on Gecko >= 1.9 (thanks GµårÐïåñ for reporting)
@therube: the "broken icon" was just a cosmetic artifact, security of the page was not broken.
@dhown: that bug is fixed as well, even though not reported in the changelog, because of the SSL mixed content fix.
@GµårÐïåñ:
the file:// issue has been quite hard to track, because it was actually not a bug freshly introduced NoScript, but a behavior change in Gecko's nsFileProtocol class: file URLs don't seem to support hostPort anymore (it was used to address Samba shares), and this caused any 2nd level domain to collapse into file:// as soon as it was added to the whitelist.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3370
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: BUGS: 1.9.4.1 Dev
Thank you sir, figured that but thanks for confirming.Giorgio Maone wrote:Code: Select all
Site googleapis.com *.googleapis.com Accept from site1.com site2.com Deny
I will try to make it in XUL but at the moment its VB.NET but once I get it working, I can easily port it and you are most welcome to ANY useful portion of it. Definitely.Yes, a rule builder is definitely in the ABE roadmap, but if you build your wizard in XUL (or XHTML) + JavaScript, maybe we can reuse something in ABE's core
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3370
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: BUGS: 1.9.4.2 Dev
I have discovered an issue with the latest dev build that many sites that I have gone to have had trouble logging in (loops back to login screen like the data is not kept) and logouts that just hang or come back with :neterror message (connection just drops and won't acknowledge again, must restart Fx). I observed that the sites that it was happening on, were operating ASP.net with javascript:dopostback methods on everything. These tend to be the ones failing to log on to or log out from. Why is this happening? If I disable NS AND reboot Fx, then I can go with no problems on any of them. If I disable NS WITHOUT rebooting Fx, it will not work either BUT rebooting Fx fixes it in disabled mode.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: BUGS: 1.9.4.2 Dev
Can you pinpoint a reproducible case for me?GµårÐïåñ wrote:I have discovered an issue with the latest dev build that many sites that I have gone to have had trouble logging in (loops back to login screen like the data is not kept) and logouts that just hang or come back with :neterror message (connection just drops and won't acknowledge again, must restart Fx).
That's not suprising, since disabling an extension from the Add-ons Manager require restarting Firefox for being effective.GµårÐïåñ wrote:If I disable NS WITHOUT rebooting Fx, it will not work either BUT rebooting Fx fixes it in disabled mode.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
1.9.4.3 Dev
1.9.4.3 Dev
(Which is very difficult to quantify, though suffice to say it appears that I've been running into higher Mem Usage <&VM Size> numbers then I would be expecting when running the last number of builds. Matter of fact, first thing I did this morning was to open Task Manager.)
And that could be contributing to "high memory usage".x Optimized garbage collection in DNS 2nd level cache
(Which is very difficult to quantify, though suffice to say it appears that I've been running into higher Mem Usage <&VM Size> numbers then I would be expecting when running the last number of builds. Matter of fact, first thing I did this morning was to open Task Manager.)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.22) Gecko/20090605 SeaMonkey/1.1.17
1.9.4.3 Dev
Ah, who knows.
Unresponsive Script Warning (with high CPU usage during the time).
At some point after the fact:
And while we're here:
Don't know if any of this relates or will be meaningful?
Anyhow, Mem Usage seem much more controlled.
Unresponsive Script Warning (with high CPU usage during the time).
Code: Select all
Security Error: Content at https://www.bankofamerica.com/www/en_US/js/search/search-lite.js may not load data from https://onlineeast3.bankofamerica.com/eas-docs/html/en_US/searchTextbox_prod.html.
Code: Select all
Error: jQuery is not defined
Source File: https://www.bankofamerica.com/www/en_US/js/search/search-lite.js
Line: 8
Code: Select all
[NoScript] nsBrowserAccess not found?!
Code: Select all
Error: this.log is not a function
Source File: chrome://flashgot/content/flashgotOverlay.js
Line: 15
Anyhow, Mem Usage seem much more controlled.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.22) Gecko/20090605 SeaMonkey/1.1.17
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: BUGS: 1.9.4.1 Dev
Where exactly, and which message (those warnings have a file and line number, usually)?therube wrote: Unresponsive Script Warning (with high CPU usage during the time).
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
1.9.4.3 Dev
I'm not really sure.
What I posted looked to be the most "useful" & what I posted is all that was shown (for those particular messages).
What I posted looked to be the most "useful" & what I posted is all that was shown (for those particular messages).
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.22) Gecko/20090605 SeaMonkey/1.1.17
-
- Ambassador
- Posts: 1586
- Joined: Fri Mar 20, 2009 4:47 am
- Location: Colorado, USA
Re: 1.9.4.3 Dev
I installed 1.9.4.3 a couple of hours ago. Mem Usage and VM size still relatively low, although I haven't browsed much since the restart.therube wrote:And that could be contributing to "high memory usage".x Optimized garbage collection in DNS 2nd level cache
(Which is very difficult to quantify, though suffice to say it appears that I've been running into higher Mem Usage <&VM Size> numbers then I would be expecting when running the last number of builds.
Mine's in my Startup folder.Matter of fact, first thing I did this morning was to open Task Manager.)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
Re: BUGS: 1.9.4.1 Dev
Maybe. Maybe not.Anyhow, Mem Usage seem much more controlled.
Real difficult to determine. Really hard to pin it on NoScript (or anything in particular).
Seemed to start out better. Right now I'm sitting at 300 MB Mem, 376 MB VM? I would have expected (whatever that means) less.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.22) Gecko/20090605 SeaMonkey/1.1.17
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3370
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: BUGS: 1.9.4.2 Dev
Nothing that you would be able to log into, I will see if I can find something that will reproduce this for you.Giorgio Maone wrote:Can you pinpoint a reproducible case for me?
Of course but in the case of NoScript, if you disable it via (allow globally) then it should relinquish but it doesn't until you reboot. That's what I mean by disable, not actually disabled the addon. If I tell NS to allow globally it will not work until I reboot Fx which is totally and should be unnecessary.That's not suprising, since disabling an extension from the Add-ons Manager require restarting Firefox for being effective.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: BUGS: 1.9.4.2 Dev
This might have been true long time ago, when all NoScript did was "allowing" and "forbidding".GµårÐïåñ wrote:Of course but in the case of NoScript, if you disable it via (allow globally) then it should relinquish but it doesn't until you reboot. That's what I mean by disable, not actually disabled the addon. If I tell NS to allow globally it will not work until I reboot Fx which is totally and should be unnecessary.
Now you got many stuff like XSS protection, HTTPS enhancements, Clearclick or ABE which are still active even if you "Allow scripts globally", and have their own preferences to be disabled.
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3370
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: BUGS: 1.9.4.3 Dev
Understood, of course but as I said restarting with NS in globally allow makes it work fine, so although it might be faulty logic on my part, I am assuming the issue is not the with the remaining components that remain active. UNLESS, whatever issue exists IS indeed caused by the XSS and other still active components, just exasperated by the regular NS functionality. So there is that too but no way to know I guess. I was hoping you would work your magic and see what's up. I updated to the 1.9.4.3 dev as well and agree with therube that on certain occasions, there is a huge performance drag, which I actually reported in my initial post but everyone told me they couldn't reproduce it, so I let it go.Giorgio Maone wrote:This might have been true long time ago, when all NoScript did was "allowing" and "forbidding".
Now you got many stuff like XSS protection, HTTPS enhancements, Clearclick or ABE which are still active even if you "Allow scripts globally", and have their own preferences to be disabled.
EDIT: So far the easiest and quickest site that can reproduce the login issue is Netflix. 1) Log in here: https://www.netflix.com/Login and 2) It will refresh to this page: http://www.netflix.com/ consistently each and every time. Effectively no access with NS and coincidentally now NS needs to be disabled on the addon level, no longer will globally with reboot fix the issue. Bummer.
~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: BUGS: 1.9.4.3 Dev
I've just signed up for the 2 weeks free trial, giving fake generalities (I don't live in US but they want a valid address wich they validate up to the suite numberGµårÐïåñ wrote:So far the easiest and quickest site that can reproduce the login issue is Netflix.


I know it may sound lame to you, but could you try Alan's standard troubleshooting (starting with an export/reset)?
Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11 (.NET CLR 3.5.30729)
- GµårÐïåñ
- Lieutenant Colonel
- Posts: 3370
- Joined: Fri Mar 20, 2009 5:19 am
- Location: PST - USA
- Contact:
Re: BUGS: 1.9.4.3 Dev
I am sorry you had to go through that, I am sorry. If you want you can give me the account and I will change the credit card on it and take over until it expires. I don't think its lame and I have done that 3 times alreadyGiorgio Maone wrote:I've just signed up for the 2 weeks free trial, giving fake generalities (I don't live in US but they want a valid address wich they validate up to the suite number) but real credit card details
, however I couldn't reproduce this issue: I can login just fine on Netflix (ABE enabled, automatic secure cookies enabled, XSS enabled, scripts disabled but on netflix.com, all the usual suspects invited...)
I know it may sound lame to you, but could you try Alan's standard troubleshooting (starting with an export/reset)?



Update: I noticed the only difference between your conditions and mine was that you had scripts disabled. So I figured, maybe something to that. I logged on with scripts disabled and it comes up with the url: https://www.netflix.com/redirect.jsp?ta ... lix.com%2F and a meta-redirect message with this info: <meta http-equiv="refresh" content="0; URL=http://www.netflix.com/"> and goes to the main page. Frustrated, I tried logging in again and HOLLY SHIT, it logs into the MemberHome this time around; HOWEVER, the path in the url is the same as above and the meta forward is listed same as above but it lands on the http://www.netflix.com/MemberHome so what the hell? In addition, notice that login page is HTTPS but when it forwards or lands on member home, its HTTP. Is there something screwy going on with cookie management? Now enable scripts for Netflix and sure as shit, it will keep looping into the login, home, login, home and never lands on the memberhome, this is becoming a real perpetual pain in my *BLEEP*
Update2: Now as if that wasn't bizarre enough already, allowed the site to see if I could reproduce the issue I had earlier and I get this lovely looking thing on reload after allowing script:

~.:[ Lï£ê ï§ å Lêmðñ åñÐ Ì Wåñ† M¥ Mðñê¥ ßå¢k ]:.~
________________ .: [ Major Mike's ] :. ________________
________________ .: [ Major Mike's ] :. ________________
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.0.11) Gecko/2009060215 Firefox/3.0.11