lists.torproject.org
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

tbb-commits

Thread Start a new thread
Threads by month
  • ----- 2026 -----
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2018 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2017 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2016 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2015 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2014 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
tbb-commits@lists.torproject.org

September 2026

  • 1 participants
  • 218 discussions
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! MB 538: Mullvad DoH discontinued notification.
by morgan (@morgan) 22 Sep '26

22 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 7b871b64 by Morgan at 2026-09-22T12:56:39+00:00 fixup! MB 538: Mullvad DoH discontinued notification. MB 581: change Review settings button to move user to about:preferences#dnsOverHttps rather than about:preferences#privacy - - - - - 1 changed file: - browser/base/content/mullvadDoHNotification.js Changes: ===================================== browser/base/content/mullvadDoHNotification.js ===================================== @@ -47,7 +47,7 @@ window.addEventListener("load", () => { "l10n-id": "mullvad-doh-notification-settings-button", primary: true, callback: () => { - window.openPreferences("privacy-doh"); + window.openPreferences("dnsOverHttps"); Services.prefs.clearUserPref(this.showPref); // Keep the notification open in case the user wants to click // "Learn more". View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/7b8… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/7b8… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! TB 23247: Communicating security expectations for .onion
by Pier Angelo Vendrame (@pierov) 22 Sep '26

22 Sep '26
Pier Angelo Vendrame pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: a33d5f55 by Pier Angelo Vendrame at 2026-09-22T09:05:26+02:00 fixup! TB 23247: Communicating security expectations for .onion TB 45343: Hide the custom roots warning for onion sites. At the moment, we allow self-signed certificates for onion services. However, tghere are several warnings we need to hide, as they would be misleading of the actual situation. Also, hide any field we get from the certificate, to avoid phishing. In the future, we may re-evaluate accepting self-certificates from onion services. - - - - - 1 changed file: - browser/base/content/browser-siteIdentity.js Changes: ===================================== browser/base/content/browser-siteIdentity.js ===================================== @@ -1192,7 +1192,11 @@ var gIdentityHandler = { this._updateAttribute(element, "ciphers", ciphers); this._updateAttribute(element, "mixedcontent", mixedcontent); this._updateAttribute(element, "isbroken", this._isBrokenConnection); - element.toggleAttribute("customroot", this._hasCustomRoot()); + // tor-browser#45343: hide the custom root warning for Onion sites. + element.toggleAttribute( + "customroot", + this._hasCustomRoot() && !this._uriIsOnionHost + ); this._updateAttribute(element, "httpsonlystatus", httpsOnlyStatus); } @@ -1237,6 +1241,14 @@ var gIdentityHandler = { } } + // tor-browser#45343: hide the custom root warning for Onion sites, but also + // empty the verifier, since it might be a lie. + if (this._uriIsOnionHost && this._hasCustomRoot()) { + owner = ""; + supplemental = ""; + verifier = ""; + } + // Push the appropriate strings out to the UI. document.l10n.setAttributes( this._identityPopupMainViewHeaderLabel, View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/a33d5f5… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/a33d5f5… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! [android] Bug 45217: Implement YEC 2026 Takeover for Android Stable
by Dan Ballard (@dan) 22 Sep '26

22 Sep '26
Dan Ballard pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: 95a61b47 by clairehurst at 2026-09-21T18:37:12-06:00 fixup! [android] Bug 45217: Implement YEC 2026 Takeover for Android Stable Add lightning bolt illustration description - - - - - 2 changed files: - mobile/android/fenix/app/src/main/java/org/mozilla/fenix/tor/CampaignCompose.kt - mobile/android/fenix/app/src/main/res/values/torbrowser_strings.xml Changes: ===================================== mobile/android/fenix/app/src/main/java/org/mozilla/fenix/tor/CampaignCompose.kt ===================================== @@ -174,7 +174,7 @@ private fun DynamicCampaignContent( Icon(shouldShow = !alternateLayout, R.drawable.bulb_illo_yec, contentDescription = stringResource(R.string.bulb_illo_yec_description)) Spacer(Modifier.size (if (alternateLayout) 0.dp else 16.dp)) Row(verticalAlignment = Alignment.CenterVertically) { - Icon(shouldShow = alternateLayout, R.drawable.circled_lighning_yec) + Icon(shouldShow = alternateLayout, R.drawable.circled_lighning_yec, contentDescription = stringResource(R.string.lightning_bolt_yec_description) ) Spacer(Modifier.size(if (alternateLayout) 8.dp else 0.dp)) TitleText() } ===================================== mobile/android/fenix/app/src/main/res/values/torbrowser_strings.xml ===================================== @@ -196,5 +196,7 @@ <string name="yec26_call_to_action">Unlike Big Tech, Tor doesn’t sell your data to make money. Instead, 6,490 donors every year keep Tor strong. Join the movement with a donation today!</string> <!-- Year End Campaign 2026. Main image description. --> <string name="bulb_illo_yec_description">Illustration of a pink hand reaching to turn on a pink light bulb on a violet background. The light bulb vaguely resembles an onion with greens coming out of the top. There are playful bolts coming out of the bulb, and a green heart on the sleeve of the shirt.</string> + <!-- Year End Campaign 2026. Alt image description. --> + <string name="lightning_bolt_yec_description">An icon of a yellow lightning bolt over a dark purple circle</string> </resources> View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/95a61b4… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/95a61b4… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! [android] Bug 45217: Implement YEC 2026 Takeover for Android Stable
by Dan Ballard (@dan) 21 Sep '26

21 Sep '26
Dan Ballard pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: 73d0d638 by clairehurst at 2026-09-21T16:46:24-06:00 fixup! [android] Bug 45217: Implement YEC 2026 Takeover for Android Stable Add illustration description - - - - - 2 changed files: - mobile/android/fenix/app/src/main/java/org/mozilla/fenix/tor/CampaignCompose.kt - mobile/android/fenix/app/src/main/res/values/torbrowser_strings.xml Changes: ===================================== mobile/android/fenix/app/src/main/java/org/mozilla/fenix/tor/CampaignCompose.kt ===================================== @@ -152,11 +152,11 @@ private fun DynamicCampaignContent( onDonateButtonClicked: () -> Unit, ) { @Composable - fun Icon(shouldShow: Boolean, @DrawableRes drawable: Int) { + fun Icon(shouldShow: Boolean, @DrawableRes drawable: Int, contentDescription: String? = null) { if (shouldShow) { Image( painterResource(drawable), - contentDescription = null, + contentDescription = contentDescription, alignment = Alignment.Center, ) } @@ -171,7 +171,7 @@ private fun DynamicCampaignContent( modifier = Modifier.fillMaxWidth(), horizontalAlignment = if (alternateLayout) Alignment.Start else Alignment.CenterHorizontally, ) { - Icon(shouldShow = !alternateLayout, R.drawable.bulb_illo_yec) + Icon(shouldShow = !alternateLayout, R.drawable.bulb_illo_yec, contentDescription = stringResource(R.string.bulb_illo_yec_description)) Spacer(Modifier.size (if (alternateLayout) 0.dp else 16.dp)) Row(verticalAlignment = Alignment.CenterVertically) { Icon(shouldShow = alternateLayout, R.drawable.circled_lighning_yec) ===================================== mobile/android/fenix/app/src/main/res/values/torbrowser_strings.xml ===================================== @@ -194,5 +194,7 @@ <string name="yec26_tor_powered_by_you">Tor: powered by you</string> <!-- Year End Campaign 2026. Main body text. --> <string name="yec26_call_to_action">Unlike Big Tech, Tor doesn’t sell your data to make money. Instead, 6,490 donors every year keep Tor strong. Join the movement with a donation today!</string> + <!-- Year End Campaign 2026. Main image description. --> + <string name="bulb_illo_yec_description">Illustration of a pink hand reaching to turn on a pink light bulb on a violet background. The light bulb vaguely resembles an onion with greens coming out of the top. There are playful bolts coming out of the bulb, and a green heart on the sleeve of the shirt.</string> </resources> View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/73d0d63… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/73d0d63… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser-update-responses][main] 6 commits: alpha: new version, 16.0a12 (linux-aarch64)
by ma1 (@ma1) 21 Sep '26

21 Sep '26
ma1 pushed to branch main at The Tor Project / Applications / Tor Browser update responses Commits: 044630de by hackademix at 2026-09-22T00:56:23+02:00 alpha: new version, 16.0a12 (linux-aarch64) - - - - - a335e2a3 by hackademix at 2026-09-22T00:56:23+02:00 alpha: new version, 16.0a12 (linux-x86_64) - - - - - 2878e9d8 by hackademix at 2026-09-22T00:56:23+02:00 alpha: new version, 16.0a12 (macos) - - - - - 1073d0af by hackademix at 2026-09-22T00:56:23+02:00 alpha: new version, 16.0a12 (windows-i686) - - - - - 2f638d5f by hackademix at 2026-09-22T00:56:23+02:00 alpha: new version, 16.0a12 (windows-x86_64) - - - - - 10baa648 by hackademix at 2026-09-22T00:56:24+02:00 alpha: new version, 16.0a12 - - - - - 38 changed files: - update_3/alpha/download-android-aarch64.json - update_3/alpha/download-android-armv7.json - update_3/alpha/download-android-x86_64.json - update_3/alpha/download-linux-aarch64.json - update_3/alpha/download-linux-x86_64.json - update_3/alpha/download-macos.json - update_3/alpha/download-windows-i686.json - update_3/alpha/download-windows-x86_64.json - update_3/alpha/downloads.json - update_3/alpha/linux-aarch64/.htaccess - − update_3/alpha/linux-aarch64/update-16.0a10-16.0a11-linux-aarch64.xml - + update_3/alpha/linux-aarch64/update-16.0a10-16.0a12-linux-aarch64.xml - + update_3/alpha/linux-aarch64/update-16.0a11-16.0a12-linux-aarch64.xml - update_3/alpha/linux-aarch64/update-16.0a11-linux-aarch64.xml → update_3/alpha/linux-aarch64/update-16.0a12-linux-aarch64.xml - − update_3/alpha/linux-aarch64/update-16.0a8-16.0a11-linux-aarch64.xml - − update_3/alpha/linux-aarch64/update-16.0a9-16.0a11-linux-aarch64.xml - + update_3/alpha/linux-aarch64/update-16.0a9-16.0a12-linux-aarch64.xml - update_3/alpha/linux-x86_64/.htaccess - update_3/alpha/linux-x86_64/update-16.0a10-16.0a11-linux-x86_64.xml → update_3/alpha/linux-x86_64/update-16.0a10-16.0a12-linux-x86_64.xml - update_3/alpha/linux-x86_64/update-16.0a8-16.0a11-linux-x86_64.xml → update_3/alpha/linux-x86_64/update-16.0a11-16.0a12-linux-x86_64.xml - update_3/alpha/linux-x86_64/update-16.0a11-linux-x86_64.xml → update_3/alpha/linux-x86_64/update-16.0a12-linux-x86_64.xml - update_3/alpha/linux-x86_64/update-16.0a9-16.0a11-linux-x86_64.xml → update_3/alpha/linux-x86_64/update-16.0a9-16.0a12-linux-x86_64.xml - update_3/alpha/macos/.htaccess - update_3/alpha/macos/update-16.0a10-16.0a11-macos.xml → update_3/alpha/macos/update-16.0a10-16.0a12-macos.xml - update_3/alpha/macos/update-16.0a9-16.0a11-macos.xml → update_3/alpha/macos/update-16.0a11-16.0a12-macos.xml - update_3/alpha/macos/update-16.0a11-macos.xml → update_3/alpha/macos/update-16.0a12-macos.xml - update_3/alpha/macos/update-16.0a8-16.0a11-macos.xml → update_3/alpha/macos/update-16.0a9-16.0a12-macos.xml - update_3/alpha/windows-i686/.htaccess - update_3/alpha/windows-i686/update-16.0a10-16.0a11-windows-i686.xml → update_3/alpha/windows-i686/update-16.0a10-16.0a12-windows-i686.xml - update_3/alpha/windows-i686/update-16.0a9-16.0a11-windows-i686.xml → update_3/alpha/windows-i686/update-16.0a11-16.0a12-windows-i686.xml - update_3/alpha/windows-i686/update-16.0a11-windows-i686.xml → update_3/alpha/windows-i686/update-16.0a12-windows-i686.xml - update_3/alpha/windows-i686/update-16.0a8-16.0a11-windows-i686.xml → update_3/alpha/windows-i686/update-16.0a9-16.0a12-windows-i686.xml - update_3/alpha/windows-x86_64/.htaccess - update_3/alpha/windows-x86_64/update-16.0a10-16.0a11-windows-x86_64.xml → update_3/alpha/windows-x86_64/update-16.0a10-16.0a12-windows-x86_64.xml - + update_3/alpha/windows-x86_64/update-16.0a11-16.0a12-windows-x86_64.xml - update_3/alpha/windows-x86_64/update-16.0a11-windows-x86_64.xml → update_3/alpha/windows-x86_64/update-16.0a12-windows-x86_64.xml - − update_3/alpha/windows-x86_64/update-16.0a9-16.0a11-windows-x86_64.xml - update_3/alpha/windows-x86_64/update-16.0a8-16.0a11-windows-x86_64.xml → update_3/alpha/windows-x86_64/update-16.0a9-16.0a12-windows-x86_64.xml The diff was not included because it is too large. View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-update-responses… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-update-responses… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser-update-responses][main] 5 commits: alpha: new version, 16.0a12 (linux-aarch64)
by ma1 (@ma1) 21 Sep '26

21 Sep '26
ma1 pushed to branch main at The Tor Project / Applications / mullvad-browser-update-responses Commits: e35894a9 by hackademix at 2026-09-21T23:25:17+02:00 alpha: new version, 16.0a12 (linux-aarch64) - - - - - fe2c5848 by hackademix at 2026-09-21T23:25:17+02:00 alpha: new version, 16.0a12 (linux-x86_64) - - - - - c7c2877a by hackademix at 2026-09-21T23:25:17+02:00 alpha: new version, 16.0a12 (macos) - - - - - 7f17db2a by hackademix at 2026-09-21T23:25:17+02:00 alpha: new version, 16.0a12 (windows-x86_64) - - - - - a89430d9 by hackademix at 2026-09-21T23:25:17+02:00 alpha: new version, 16.0a12 - - - - - 41 changed files: - update_1/alpha/download-linux-aarch64.json - update_1/alpha/download-linux-x86_64.json - update_1/alpha/download-macos.json - update_1/alpha/download-windows-x86_64.json - update_1/alpha/downloads.json - update_1/alpha/linux-aarch64/.htaccess - − update_1/alpha/linux-aarch64/update-16.0a10-16.0a11-linux-aarch64.xml - + update_1/alpha/linux-aarch64/update-16.0a10-16.0a12-linux-aarch64.xml - + update_1/alpha/linux-aarch64/update-16.0a11-16.0a12-linux-aarch64.xml - − update_1/alpha/linux-aarch64/update-16.0a11-linux-aarch64.xml - + update_1/alpha/linux-aarch64/update-16.0a12-linux-aarch64.xml - − update_1/alpha/linux-aarch64/update-16.0a8-16.0a11-linux-aarch64.xml - − update_1/alpha/linux-aarch64/update-16.0a9-16.0a11-linux-aarch64.xml - + update_1/alpha/linux-aarch64/update-16.0a9-16.0a12-linux-aarch64.xml - update_1/alpha/linux-x86_64/.htaccess - − update_1/alpha/linux-x86_64/update-16.0a10-16.0a11-linux-x86_64.xml - + update_1/alpha/linux-x86_64/update-16.0a10-16.0a12-linux-x86_64.xml - + update_1/alpha/linux-x86_64/update-16.0a11-16.0a12-linux-x86_64.xml - − update_1/alpha/linux-x86_64/update-16.0a11-linux-x86_64.xml - + update_1/alpha/linux-x86_64/update-16.0a12-linux-x86_64.xml - − update_1/alpha/linux-x86_64/update-16.0a8-16.0a11-linux-x86_64.xml - − update_1/alpha/linux-x86_64/update-16.0a9-16.0a11-linux-x86_64.xml - + update_1/alpha/linux-x86_64/update-16.0a9-16.0a12-linux-x86_64.xml - update_1/alpha/macos/.htaccess - − update_1/alpha/macos/update-16.0a10-16.0a11-macos.xml - + update_1/alpha/macos/update-16.0a10-16.0a12-macos.xml - + update_1/alpha/macos/update-16.0a11-16.0a12-macos.xml - − update_1/alpha/macos/update-16.0a11-macos.xml - + update_1/alpha/macos/update-16.0a12-macos.xml - − update_1/alpha/macos/update-16.0a8-16.0a11-macos.xml - − update_1/alpha/macos/update-16.0a9-16.0a11-macos.xml - + update_1/alpha/macos/update-16.0a9-16.0a12-macos.xml - update_1/alpha/windows-x86_64/.htaccess - − update_1/alpha/windows-x86_64/update-16.0a10-16.0a11-windows-x86_64.xml - + update_1/alpha/windows-x86_64/update-16.0a10-16.0a12-windows-x86_64.xml - + update_1/alpha/windows-x86_64/update-16.0a11-16.0a12-windows-x86_64.xml - − update_1/alpha/windows-x86_64/update-16.0a11-windows-x86_64.xml - + update_1/alpha/windows-x86_64/update-16.0a12-windows-x86_64.xml - − update_1/alpha/windows-x86_64/update-16.0a8-16.0a11-windows-x86_64.xml - − update_1/alpha/windows-x86_64/update-16.0a9-16.0a11-windows-x86_64.xml - + update_1/alpha/windows-x86_64/update-16.0a9-16.0a12-windows-x86_64.xml The diff was not included because it is too large. View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser-update-respo… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser-update-respo… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by Pier Angelo Vendrame (@pierov) 21 Sep '26

21 Sep '26
Pier Angelo Vendrame pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: def7c9a9 by Pier Angelo Vendrame at 2026-09-21T21:44:19+02:00 fixup! Firefox preference overrides. BB 45073: 140-153 preference review. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -1,7 +1,7 @@ // Preferences to harden Firefox's security and privacy // Do not edit this file. -// Use the OS locale by default (tor-browser#17400) +// tor-browser#17400: use the OS locale by default. pref("intl.locale.requested", ""); // Home page is blank rather than Firefox Home (Activity Stream). @@ -21,11 +21,6 @@ pref("startup.homepage_welcome_url.additional", ""); // Disable Firefox Welcome Dialog pref("browser.aboutwelcome.enabled", false); -#if MOZ_UPDATE_CHANNEL == release -// tor-browser#42640: Disable Firefox Flame button due to unknown interactions with New Identity -pref("browser.privatebrowsing.resetPBM.enabled", false, locked); -#endif - #ifndef ANDROID // Bug 41668: allow users to apply updates. This is set also in firefox.js for // all platforms, except for Windows. As explained on firefox.js, Firefox uses a @@ -53,6 +48,9 @@ pref("app.update.staging.enabled", false); pref("browser.startup.homepage_override.buildID", "20100101"); // Disable the "Refresh" prompt that is displayed for stale profiles. +// TODO: Re-evaluate (tor-browser#45341): this was needed because the new +// profile it created did not contain NoScript. Now profiles work, so the main +// technical reason for this preference does not hold anymore. pref("browser.disableResetPrompt", true); // Disk activity: Disable Browsing History Storage @@ -60,15 +58,18 @@ pref("browser.privatebrowsing.autostart", true); pref("browser.cache.disk.enable", false); pref("permissions.memory_only", true); pref("security.nocertdb", true); + +// tor-browser#42094: do not collect stats about WebRTC. +// Defense-in-depth: this is already false in upstream release builds. pref("media.aboutwebrtc.hist.enabled", false); -// tor-browser#45214: Disable the megalist (contextual password manager). +// tor-browser#45214: disable the megalist (contextual password manager). pref("browser.contextual-password-manager.enabled", false); // Disk Activity -// Disable auto-downloading to ~/Downloads and other download tweaks to minimize -// disk leaks (tor-browser#42050). +// tor-browser#42050: disable auto-downloading to ~/Downloads and other download +// tweaks to minimize disk leaks. pref("browser.download.useDownloadDir", false); pref("browser.download.always_ask_before_handling_new_types", true); pref("browser.download.manager.addToRecentDocs", false); @@ -139,16 +140,29 @@ pref("browser.pagethumbnails.capturing_disabled", true); // pref("privacy.exposeContentTitleInWindow", false); // pref("privacy.exposeContentTitleInWindow.pbm", false); -// tor-browser#42054: Opt-out from any built-in backup system, even though +// tor-browser#42630: Disable LaterRun. +// +// This preference is set in a few places in code, so we lock it to keep this +// feature off. +// Even though it's locked, setting it will still change the value in +// `prefs.js`, but it will be ignored. +// If this is ever unlocked, the value in prefs.js will be used. +pref("browser.laterrun.enabled", false, locked); + +// tor-browser#42054: opt-out from any built-in backup system, even though // local, as it might be a violation of our standalone mode. // Users can still opt-in if they wish. pref("browser.backup.enabled", false); pref("browser.backup.scheduled.enabled", false); -// tor-browser#45123: Disable the profile automated backup and restore service. +// tor-browser#45123: disable the profile automated backup and restore service. pref("browser.backup.archive.enabled", false); pref("browser.backup.restore.enabled", false); -// Empty clipboard content from private windows on exit (tor-browser#42154) +// tor-browser#45073 (153.0 preference review): do not send media metadata to +// the OS when in PBM (defense-in-depth). +pref("media.privatebrowsing.metadata.enabled", false); + +// tor-browser#42154: empty clipboard content from private windows on exit pref("browser.privatebrowsing.preserveClipboard", false); // tor-browser#42611: Do not include the URL of the image, when copying it. @@ -164,6 +178,9 @@ pref("dom.security.https_only_mode_pbm", true); // tor-browser#43197, defense in depth if ever https-only got disabled pref("dom.security.https_first_add_exception_on_failure", false); +// tor-browser#44123: never trim the protocol off of URLs. +pref("browser.urlbar.trimURLs", false); + // tor-browser#22320: Hide referer when coming from a .onion address // We enable this here (rather than in Tor Browser) in case users of other // base-browser derived browsers configure it to use a system Tor daemon @@ -182,12 +199,8 @@ pref("network.http.referer.hideOnionSource", true); // [4] https://www.ssllabs.com/ssl-pulse/ pref("security.ssl.require_safe_negotiation", true); -// lock those disabled by https://bugzilla.mozilla.org/show_bug.cgi?id=1036765 -pref("security.ssl3.dhe_rsa_aes_128_sha", false, locked); -pref("security.ssl3.dhe_rsa_aes_256_sha", false, locked); - -// Wrapping a static pref to lock it and prevent changing. -// See tor-browser#40565. +// tor-browser#40565: lock as the UI offered to enable TLS 1.0 and 1.1 without +// explaining the actual reasons. pref("security.tls.version.enable-deprecated", false, locked); // tor-browser#44187: Disable session identifiers to make PBM and normal mode @@ -227,15 +240,12 @@ pref("browser.urlbar.maxCharsForSearchSuggestions", 0); // Misc privacy: Remote pref("browser.send_pings", false); -// Space separated list of URLs that are allowed to send objects (instead of -// only strings) through webchannels. The default for Firefox is some Mozilla -// domains. -pref("webchannel.allowObject.urlWhitelist", ""); + +// Geolocation preferences. pref("geo.enabled", false); pref("geo.provider.network.url", ""); pref("geo.provider.ms-windows-location", false); pref("geo.provider.use_corelocation", false); -pref("geo.provider.use_gpsd", false); pref("geo.provider.use_geoclue", false); pref("browser.safebrowsing.malware.enabled", false); @@ -248,6 +258,9 @@ pref("browser.safebrowsing.provider.google.updateURL", ""); pref("browser.safebrowsing.provider.google.gethashURL", ""); pref("browser.safebrowsing.provider.google4.updateURL", ""); pref("browser.safebrowsing.provider.google4.gethashURL", ""); +pref("browser.safebrowsing.provider.google5.enabled", false); +pref("browser.safebrowsing.provider.google5.updateURL", ""); +pref("browser.safebrowsing.provider.google5.gethashURL", ""); pref("browser.safebrowsing.provider.mozilla.updateURL", ""); pref("browser.safebrowsing.provider.mozilla.gethashURL", ""); @@ -267,26 +280,29 @@ pref("toolkit.telemetry.shutdownPingSender.enabled", false); // Added in tor-bro pref("toolkit.telemetry.firstShutdownPing.enabled", false); // Added in tor-browser#41496 pref("toolkit.telemetry.updatePing.enabled", false); // Make sure updater telemetry is disabled; see #25909. pref("toolkit.telemetry.bhrPing.enabled", false); -pref("toolkit.telemetry.coverage.opt-out", true); pref("datareporting.healthreport.uploadEnabled", false); pref("datareporting.policy.dataSubmissionEnabled", false); -// Force all telemtry identifier to their canary values tor-browser#43750 +// tor-browser#43750: force all telemtry identifier to their canary values. +// Locked to prevent the browser from changing them. pref("toolkit.telemetry.cachedClientID", "c0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0", locked); pref("toolkit.telemetry.cachedProfileGroupID", "decafdec-afde-cafd-ecaf-decafdecafde", locked); pref("datareporting.dau.cachedUsageProfileID", "beefbeef-beef-beef-beef-beeefbeefbee", locked); pref("datareporting.dau.cachedUsageProfileGroupID", "b0bacafe-b0ba-cafe-b0ba-cafeb0bacafe", locked); +pref("datareporting.usage.uploadEnabled", false); pref("toolkit.coverage.opt-out", true); pref("toolkit.coverage.endpoint.base", ""); pref("browser.tabs.crashReporting.sendReport", false); pref("browser.crashReports.unsubmittedCheck.autoSubmit2", false); -// Added in tor-browser#41496 even though false by default +// tor-browser#41496: do not offer to send unsubmitted crash reports. +// (Defense in detph: we do not have the crash reporter and this is false on the +// release channel also in Firefox). pref("browser.crashReports.unsubmittedCheck.enabled", false); +// tor-browser#45073 (153.0 preference review): add also this pref not to send +// unsubmitted crash reports. +pref("browser.crashReports.onDemand", false); // tor-browser#44026: Disable the modal that shows upstream terms of usage, // since we opt out of their telemetry and data collection. pref("browser.preonboarding.enabled", false); -// Disable checkbox in about:neterror that controls -// security.xfocsp.errorReporting.automatic. See tor-browser#42653. -pref("security.xfocsp.errorReporting.enabled", false); // tor-browser#45080: disable the reporting API. pref("dom.reporting.enabled", false); pref("dom.reporting.header.enabled", false); @@ -317,9 +333,11 @@ pref("services.sync.engine.prefs", false); pref("services.sync.engine.tabs", false); pref("extensions.getAddons.cache.enabled", false); // https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/ pref("privacy.donottrackheader.enabled", false); // (mullvad-browser#17) -// Make sure there is no Tracking Protection active in Tor Browser, see: #17898. +// tor-browser#17898: disable Tracking Protection in Tor Browser because of +// doubts about the blocklist-based approach and the breakage. pref("privacy.trackingprotection.enabled", false); pref("privacy.trackingprotection.pbmode.enabled", false); +pref("privacy.trackingprotection.emailtracking.enabled", false); pref("privacy.trackingprotection.emailtracking.pbmode.enabled", false); pref("privacy.trackingprotection.annotate_channels", false); pref("privacy.trackingprotection.cryptomining.enabled", false); @@ -329,9 +347,9 @@ pref("privacy.trackingprotection.socialtracking.enabled", false); // This is mostly for consistency, since we disable the safe browsing lists, // which are needed for this feature to work properly. pref("privacy.trackingprotection.harmfuladdon.enabled", false); -// Hide the Unified Trust Panel until we have new designs. tor-browser#44814. +// tor-browser#44814: hide the Unified Trust Panel until we have new designs. pref("browser.urlbar.trustPanel.featureGate", false); -// tor-browser#43986: Explicitly disable bounce tracking protection +// tor-browser#43986: explicitly disable bounce tracking protection pref("privacy.bounceTrackingProtection.mode", 0); pref("privacy.socialtracking.block_cookies.enabled", false); pref("privacy.annotate_channels.strict_list.enabled", false); @@ -339,14 +357,11 @@ pref("privacy.annotate_channels.strict_list.enabled", false); // Notice that it should not apply to RFP anyway... pref("privacy.fingerprintingProtection.remoteOverrides.enabled", false); -// Disable Privacy-Preserving-Attribution (Bug #42687) -pref("dom.private-attribution.submission.enabled", false); - // Custom extensions preferences tor-browser#41581 pref("extensions.hideNoScript", true); pref("extensions.hideUnifiedWhenEmpty", true); -// Disable activity stream in about:home (Bug #41029) +// tor-browser#41029: disable activity stream in about:home pref("browser.newtabpage.activity-stream.discoverystream.enabled", false); pref("browser.newtabpage.activity-stream.feeds.section.topstories", false); pref("browser.newtabpage.activity-stream.showSponsored", false); @@ -369,37 +384,34 @@ pref("browser.newtabpage.activity-stream.asrouter.useRemoteL10n", false); // tor-browser#42054: make sure search result telemetry is disabled. pref("browser.search.serpEventTelemetryCategorization.enabled", false); - - // ML components that we want to hide from the user. See tor-browser#44045. -// Many of these preferences are locked because the component is entirely -// removed, so they could not be functionally enabled. - +// The component is entirely removed, so many functionalities will not work even +// if flipped. // tor-browser#42872, #42555, #44045: Disable ML translations. // Maybe re-enable after auditing and fixing the UX (tor-browser#41837). // NOTE: whilst the "translations" component is still included in the build, we // lock the preference because the engine is excluded and the // "translations-models" RemoteSettings needed for the engine is empty. -pref("browser.translations.enable", false, locked); +pref("browser.translations.enable", false); // Hide some AI settings outside the "ai" setting pane. See tor-browser#44764. // NOTE: This preference tracks whether the *user* opted out of all AI features // in about:preferences. By itself, it does not provide global blocking of the // AI features, which are often controlled by separate preferences below. // However, some parts of the UI will react to this preference. See // tor-browser#44541. -pref("browser.ai.control.default", "blocked", locked); +pref("browser.ai.control.default", "blocked"); // Disables many (but not all) ML engines. Note, this does not have overall // control over exposure to ML features. tor-browser#44045. -pref("browser.ml.enable", false, locked); +pref("browser.ml.enable", false); // Disable third party AI chatbot. tor-browser#43989. -pref("browser.ml.chat.enabled", false, locked); +pref("browser.ml.chat.enabled", false); // Disable LinkPreview. tor-browser#44045 and tor-browser#43867. -pref("browser.ml.linkPreview.enabled", false, locked); -// Disable Smart Tab Groups. tor-browser#44045. -pref("browser.tabs.groups.smart.enabled", false, locked); -pref("browser.tabs.groups.smart.userEnabled", false, locked); +pref("browser.ml.linkPreview.enabled", false); +// tor-browser#44045: disable Smart Tab Groups. +pref("browser.tabs.groups.smart.enabled", false); +pref("browser.tabs.groups.smart.userEnabled", false); // Don't expose ModelHub API for extensions. tor-browser#44045. -pref("extensions.ml.enabled", false, locked); +pref("extensions.ml.enabled", false); // Don't enable ML generated alt text. tor-browser#44045. // pdfjs.enableAltText controls whether MLManager is created, // pdfjs.enableGuessAltText controls whether the MLManager can create an ML @@ -407,25 +419,26 @@ pref("extensions.ml.enabled", false, locked); // changed by the user in the UI, but also has the side effect of hiding the // UI controls for the non-ML preference pdfjs.enableNewAltTextWhenAddingImage. // See bugzilla bug 1943456 comment 12. -pref("pdfjs.enableAltText", false, locked); -pref("pdfjs.enableAltTextForEnglish", false, locked); -pref("pdfjs.enableGuessAltText", false, locked); -pref("pdfjs.enableAltTextModelDownload", false, locked); +pref("pdfjs.enableAltText", false); +pref("pdfjs.enableAltTextForEnglish", false); +pref("pdfjs.enableGuessAltText", false); +pref("pdfjs.enableAltTextModelDownload", false); // Disable SuggestBackendMl. tor-browser#44045. -pref("browser.urlbar.quicksuggest.mlEnabled", false, locked); +pref("browser.urlbar.quicksuggest.mlEnabled", false); // Disable SemanticHistory search. tor-browser#44045. -pref("places.semanticHistory.featureGate", false, locked); -// tor-browser#45120: Disable AIWindow. -// tor-browser#45338: Locked as a precaution against entry points that try to -// flip this value. +pref("places.semanticHistory.featureGate", false); +// tor-browser#45120: disable AIWindow. +// tor-browser#45338: locked as a precaution against entry points that try to +// flip this value. Also, policies also lock it. pref("browser.smartwindow.enabled", false, locked); - +// tor-browser#45073 (153 preference review): lock to pretend we have disabled +// AI through policies (see AIWindow.isManagedByPolicy). +pref("browser.ai.control.smartWindow", "blocked", locked); // tor-browser#41945 - disable automatic cookie banners dismissal until // we're sure it does not causes fingerprinting risks or other issues. pref("cookiebanners.service.mode", 0); pref("cookiebanners.service.mode.privateBrowsing", 0); -pref("cookiebanners.ui.desktop.enabled", false); // Disable moreFromMozilla pane in the preferences/settings (tor-browser#41292). pref("browser.preferences.moreFromMozilla", false); @@ -457,12 +470,9 @@ pref("browser.tabs.remote.separatedMozillaDomains", ""); // Avoid DNS lookups on search terms pref("browser.urlbar.dnsResolveSingleWordsAfterSearch", 0); -// Disable about:newtab and "first run" experiments -pref("messaging-system.rsexperimentloader.enabled", false); // true means that you are *not* opting out. See its usage in various file. pref("app.shield.optoutstudies.enabled", false); -// Disable nimbus rollouts. -// See bugzilla bug 2003350. See tor-browser#44520. +// tor-browser#44520: disable nimbus rollouts (see bugzilla bug 2003350). pref("nimbus.rollouts.enabled", false); // Disable Normandy/Shield pref("app.normandy.enabled", false); @@ -520,11 +530,6 @@ pref("dom.xslt.enabled", false); #if MOZ_UPDATE_CHANNEL == release pref("privacy.resistFingerprinting", true, locked); pref("privacy.resistFingerprinting.exemptedDomains", "", locked); -// tor-browser#42125: Some misleading guides suggest to set this to false, but -// the result would be that the canvas is completely white -// (see StaticPrefList.yaml), so lock it to true. -// Might be removed (MozBug 1670447). -pref("privacy.resistFingerprinting.randomDataOnCanvasExtract", true, locked); #else pref("privacy.resistFingerprinting", true); pref("privacy.resistFingerprinting.exemptedDomains", ""); @@ -542,8 +547,6 @@ pref("webgl.enable-webgl2", false); // tor-browser#44763: disable WebGPU until audited. pref("dom.webgpu.enabled", false); pref("browser.link.open_newwindow.restriction", 0); // Bug 9881: Open popups in new tabs (to avoid fullscreen popups) -// tor-browser#42767: Disable offscreen canvas until verified it is not fingerprintable -pref("gfx.offscreencanvas.enabled", false); // Prevent scripts from moving and resizing open windows pref("dom.disable_window_move_resize", true); // Set video VP9 to 0 for everyone (bug 22548) @@ -596,9 +599,8 @@ pref("dom.netinfo.enabled", false); pref("network.http.referer.defaultPolicy", 2); // Bug 32948: Make referer behavior consistent regardless of private browing mode status pref("network.http.referer.defaultPolicy.pbmode", 2); pref("network.http.referer.XOriginTrimmingPolicy", 2); // Bug 17228: Force trim referer to scheme+host+port in cross-origin requests -// Bug 40463: Disable Windows SSO -pref("network.http.windows-sso.enabled", false, locked); -// Bug 43165: Disable Microsoft SSO on macOS +// tor-browser#40463 (91 preference review): disable Windows SSO +pref("network.http.windows-sso.enabled", false); pref("network.http.microsoft-entra-sso.enabled", false); pref("network.microsoft-sso-authority-list", ""); // tor-browser#40424 @@ -620,6 +622,9 @@ pref("security.restrict_to_adults.respect_platform", false); // Xwayland as the default. pref("widget.wayland.fractional-scale.enabled", false); +// tor-browser#45171: Disabled split view which is janky. +pref("browser.tabs.splitView.enabled", false); + // tor-browser#41943: defense-in-depth, but do not lock anymore (enabled in Firefox 119, http://bugzil.la/1851162) pref("javascript.options.spectre.disable_for_isolated_content", false); @@ -628,13 +633,11 @@ pref("privacy.firstparty.isolate", true); // Always enforce first party isolatio // Only accept cookies from the originating site (block third party cookies) pref("network.cookie.cookieBehavior", 1); pref("network.cookie.cookieBehavior.pbmode", 1); -pref("network.predictor.enabled", false); // Temporarily disabled. See https://bugs.torproject.org/16633 -pref("network.predictor.enable-prefetch", false); pref("network.http.speculative-parallel-limit", 0); pref("browser.places.speculativeConnect.enabled", false); pref("network.prefetch-next", false); pref("browser.urlbar.speculativeConnect.enabled", false); -// Bug 40220: Make sure tracker cookie purging is disabled. +// tor-browser#40220: make sure tracker cookie purging is disabled. // It depends on Firefox's tracking protection, which we currently do not enable // See also tor-browser#30939. pref("privacy.purge_trackers.enabled", false); @@ -648,6 +651,8 @@ pref("network.dns.disablePrefetchFromHTTPS", true); pref("dom.prefetch_dns_for_anchor_http_document", false); pref("dom.prefetch_dns_for_anchor_https_document", false); +// Notice: some of these values are already false on Firefox, but we still +// define them as defense-in-depth. pref("network.protocol-handler.external-default", false); pref("network.protocol-handler.external.mailto", false); pref("network.protocol-handler.external.news", false); @@ -661,24 +666,20 @@ pref("network.protocol-handler.warn-external.snews", true); pref("network.protocol-handler.external.ms-windows-store", false); pref("network.protocol-handler.warn-external.ms-windows-store", true); #endif -pref("network.proxy.allow_bypass", false, locked); // #40682 -// Bug 40548: Disable proxy-bypass + +// tor-browser#40682: some API (e.g., telemetry) might try to bypass the proxy +// if this is true. At the moment, the browser will not try to set this +// anywhere, but it makes sense to lock it as a defense-in-depth in case of +// future changes. +pref("network.proxy.allow_bypass", false, locked); +// tor-browser#40548: disable another proxy-bypass for system requests. +// This is also disabled at build time (tor-browser#45336). pref("network.proxy.failover_direct", false, locked); -// Lock to 'true', which is already the firefox default, to prevent users -// from making themselves fingerprintable by disabling. This pref -// alters content load order in a page. See tor-browser#24686 -pref("network.http.tailing.enabled", true, locked); -// Block 0.0.0.0 +// tor-browser#43811: block 0.0.0.0 // https://bugzilla.mozilla.org/show_bug.cgi?id=1889130 -// tor-browser#43811 pref("network.socket.ip_addr_any.disabled", true); -// tor-browser#23044: Make sure we don't have any GIO supported protocols -// (defense in depth measure). -// As of Firefox 118 (Bug 1843763), upstream does not add any protocol by -// default, but setting it to blank seems a good idea (tor-browser#42054). -pref("network.gio.supported-protocols", ""); // Mullvad Browser enables WebRTC by default, meaning that there the following prefs // are first-line defense, rather than "in depth" (mullvad-browser#40) // tor-browser#41667 - Defense in depth: use mDNS to avoid local IP leaks on Android too if user enables WebRTC @@ -729,7 +730,7 @@ pref("network.file.path_blacklist", "/net"); pref("svg.disabled", false); pref("mathml.disabled", false); -// Bug 40408 +// tor-browser#40408 pref("svg.context-properties.content.allowed-domains", ""); // Network and performance @@ -794,7 +795,9 @@ pref("security.certerrors.mitm.priming.enabled", false); // Don't automatically enable enterprise roots, see bug 40166 pref("security.certerrors.mitm.auto_enable_enterprise_roots", false); -// Disable share menus on Mac and Windows tor-browser#41117 +// tor-browser#41117: disable share menus on Mac and Windows. +// Locked as user might not realize sharing might result in proxy bypasses or +// general linkability. pref("browser.menu.share_url.allow", false, locked); // tor-browser#45133: Disable share button @@ -844,6 +847,10 @@ pref("toolkit.winRegisterApplicationRestart", false); // tor-browser#43051: Hide the checkbox to open the browser automatically on // Windows startup. pref("browser.startup.windowsLaunchOnLogin.enabled", false); + +// tor-browser#45293: force devices to be detected as not capable of tablet mode +// on Windows 11+ (defense-in-depth for fingerprinting). +pref("widget.windows.tablet_detection_override", -1); #endif #ifdef ANDROID @@ -1154,16 +1161,3 @@ pref("font.name-list.monospace.x-unicode", "Cousine, Noto Sans Balinese, Noto Sa // The rest are not customized, because they are covered only by one font #endif #endif - -// tor-browser#42630: Disable LaterRun. -// -// This preference is set in a few places in code. Even though it's locked, -// setting it will still change the value in `prefs.js`, but it will be ignored. -// If this is ever unlocked, the value in prefs.js will be used. -pref("browser.laterrun.enabled", false, locked); - -// tor-browser#44123: Never trim the protocol off of URLs. -pref("browser.urlbar.trimURLs", false); - -// tor-browser#45171: Disabled split view which is janky. -pref("browser.tabs.splitView.enabled", false); View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/def… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/def… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by Pier Angelo Vendrame (@pierov) 21 Sep '26

21 Sep '26
Pier Angelo Vendrame pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: fdc6efc1 by Pier Angelo Vendrame at 2026-09-21T21:26:59+02:00 fixup! Firefox preference overrides. BB 45073: 140-153 preference review. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -1,7 +1,7 @@ // Preferences to harden Firefox's security and privacy // Do not edit this file. -// Use the OS locale by default (tor-browser#17400) +// tor-browser#17400: use the OS locale by default. pref("intl.locale.requested", ""); // Home page is blank rather than Firefox Home (Activity Stream). @@ -21,11 +21,6 @@ pref("startup.homepage_welcome_url.additional", ""); // Disable Firefox Welcome Dialog pref("browser.aboutwelcome.enabled", false); -#if MOZ_UPDATE_CHANNEL == release -// tor-browser#42640: Disable Firefox Flame button due to unknown interactions with New Identity -pref("browser.privatebrowsing.resetPBM.enabled", false, locked); -#endif - #ifndef ANDROID // Bug 41668: allow users to apply updates. This is set also in firefox.js for // all platforms, except for Windows. As explained on firefox.js, Firefox uses a @@ -53,6 +48,9 @@ pref("app.update.staging.enabled", false); pref("browser.startup.homepage_override.buildID", "20100101"); // Disable the "Refresh" prompt that is displayed for stale profiles. +// TODO: Re-evaluate (tor-browser#45341): this was needed because the new +// profile it created did not contain NoScript. Now profiles work, so the main +// technical reason for this preference does not hold anymore. pref("browser.disableResetPrompt", true); // Disk activity: Disable Browsing History Storage @@ -60,15 +58,18 @@ pref("browser.privatebrowsing.autostart", true); pref("browser.cache.disk.enable", false); pref("permissions.memory_only", true); pref("security.nocertdb", true); + +// tor-browser#42094: do not collect stats about WebRTC. +// Defense-in-depth: this is already false in upstream release builds. pref("media.aboutwebrtc.hist.enabled", false); -// tor-browser#45214: Disable the megalist (contextual password manager). +// tor-browser#45214: disable the megalist (contextual password manager). pref("browser.contextual-password-manager.enabled", false); // Disk Activity -// Disable auto-downloading to ~/Downloads and other download tweaks to minimize -// disk leaks (tor-browser#42050). +// tor-browser#42050: disable auto-downloading to ~/Downloads and other download +// tweaks to minimize disk leaks. pref("browser.download.useDownloadDir", false); pref("browser.download.always_ask_before_handling_new_types", true); pref("browser.download.manager.addToRecentDocs", false); @@ -139,16 +140,29 @@ pref("browser.pagethumbnails.capturing_disabled", true); // pref("privacy.exposeContentTitleInWindow", false); // pref("privacy.exposeContentTitleInWindow.pbm", false); -// tor-browser#42054: Opt-out from any built-in backup system, even though +// tor-browser#42630: Disable LaterRun. +// +// This preference is set in a few places in code, so we lock it to keep this +// feature off. +// Even though it's locked, setting it will still change the value in +// `prefs.js`, but it will be ignored. +// If this is ever unlocked, the value in prefs.js will be used. +pref("browser.laterrun.enabled", false, locked); + +// tor-browser#42054: opt-out from any built-in backup system, even though // local, as it might be a violation of our standalone mode. // Users can still opt-in if they wish. pref("browser.backup.enabled", false); pref("browser.backup.scheduled.enabled", false); -// tor-browser#45123: Disable the profile automated backup and restore service. +// tor-browser#45123: disable the profile automated backup and restore service. pref("browser.backup.archive.enabled", false); pref("browser.backup.restore.enabled", false); -// Empty clipboard content from private windows on exit (tor-browser#42154) +// tor-browser#45073 (153.0 preference review): do not send media metadata to +// the OS when in PBM (defense-in-depth). +pref("media.privatebrowsing.metadata.enabled", false); + +// tor-browser#42154: empty clipboard content from private windows on exit pref("browser.privatebrowsing.preserveClipboard", false); // tor-browser#42611: Do not include the URL of the image, when copying it. @@ -164,6 +178,9 @@ pref("dom.security.https_only_mode_pbm", true); // tor-browser#43197, defense in depth if ever https-only got disabled pref("dom.security.https_first_add_exception_on_failure", false); +// tor-browser#44123: never trim the protocol off of URLs. +pref("browser.urlbar.trimURLs", false); + // tor-browser#22320: Hide referer when coming from a .onion address // We enable this here (rather than in Tor Browser) in case users of other // base-browser derived browsers configure it to use a system Tor daemon @@ -182,12 +199,8 @@ pref("network.http.referer.hideOnionSource", true); // [4] https://www.ssllabs.com/ssl-pulse/ pref("security.ssl.require_safe_negotiation", true); -// lock those disabled by https://bugzilla.mozilla.org/show_bug.cgi?id=1036765 -pref("security.ssl3.dhe_rsa_aes_128_sha", false, locked); -pref("security.ssl3.dhe_rsa_aes_256_sha", false, locked); - -// Wrapping a static pref to lock it and prevent changing. -// See tor-browser#40565. +// tor-browser#40565: lock as the UI offered to enable TLS 1.0 and 1.1 without +// explaining the actual reasons. pref("security.tls.version.enable-deprecated", false, locked); // tor-browser#44187: Disable session identifiers to make PBM and normal mode @@ -227,15 +240,12 @@ pref("browser.urlbar.maxCharsForSearchSuggestions", 0); // Misc privacy: Remote pref("browser.send_pings", false); -// Space separated list of URLs that are allowed to send objects (instead of -// only strings) through webchannels. The default for Firefox is some Mozilla -// domains. -pref("webchannel.allowObject.urlWhitelist", ""); + +// Geolocation preferences. pref("geo.enabled", false); pref("geo.provider.network.url", ""); pref("geo.provider.ms-windows-location", false); pref("geo.provider.use_corelocation", false); -pref("geo.provider.use_gpsd", false); pref("geo.provider.use_geoclue", false); pref("browser.safebrowsing.malware.enabled", false); @@ -248,6 +258,9 @@ pref("browser.safebrowsing.provider.google.updateURL", ""); pref("browser.safebrowsing.provider.google.gethashURL", ""); pref("browser.safebrowsing.provider.google4.updateURL", ""); pref("browser.safebrowsing.provider.google4.gethashURL", ""); +pref("browser.safebrowsing.provider.google5.enabled", false); +pref("browser.safebrowsing.provider.google5.updateURL", ""); +pref("browser.safebrowsing.provider.google5.gethashURL", ""); pref("browser.safebrowsing.provider.mozilla.updateURL", ""); pref("browser.safebrowsing.provider.mozilla.gethashURL", ""); @@ -267,26 +280,29 @@ pref("toolkit.telemetry.shutdownPingSender.enabled", false); // Added in tor-bro pref("toolkit.telemetry.firstShutdownPing.enabled", false); // Added in tor-browser#41496 pref("toolkit.telemetry.updatePing.enabled", false); // Make sure updater telemetry is disabled; see #25909. pref("toolkit.telemetry.bhrPing.enabled", false); -pref("toolkit.telemetry.coverage.opt-out", true); pref("datareporting.healthreport.uploadEnabled", false); pref("datareporting.policy.dataSubmissionEnabled", false); -// Force all telemtry identifier to their canary values tor-browser#43750 +// tor-browser#43750: force all telemtry identifier to their canary values. +// Locked to prevent the browser from changing them. pref("toolkit.telemetry.cachedClientID", "c0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0", locked); pref("toolkit.telemetry.cachedProfileGroupID", "decafdec-afde-cafd-ecaf-decafdecafde", locked); pref("datareporting.dau.cachedUsageProfileID", "beefbeef-beef-beef-beef-beeefbeefbee", locked); pref("datareporting.dau.cachedUsageProfileGroupID", "b0bacafe-b0ba-cafe-b0ba-cafeb0bacafe", locked); +pref("datareporting.usage.uploadEnabled", false); pref("toolkit.coverage.opt-out", true); pref("toolkit.coverage.endpoint.base", ""); pref("browser.tabs.crashReporting.sendReport", false); pref("browser.crashReports.unsubmittedCheck.autoSubmit2", false); -// Added in tor-browser#41496 even though false by default +// tor-browser#41496: do not offer to send unsubmitted crash reports. +// (Defense in detph: we do not have the crash reporter and this is false on the +// release channel also in Firefox). pref("browser.crashReports.unsubmittedCheck.enabled", false); +// tor-browser#45073 (153.0 preference review): add also this pref not to send +// unsubmitted crash reports. +pref("browser.crashReports.onDemand", false); // tor-browser#44026: Disable the modal that shows upstream terms of usage, // since we opt out of their telemetry and data collection. pref("browser.preonboarding.enabled", false); -// Disable checkbox in about:neterror that controls -// security.xfocsp.errorReporting.automatic. See tor-browser#42653. -pref("security.xfocsp.errorReporting.enabled", false); // tor-browser#45080: disable the reporting API. pref("dom.reporting.enabled", false); pref("dom.reporting.header.enabled", false); @@ -317,9 +333,11 @@ pref("services.sync.engine.prefs", false); pref("services.sync.engine.tabs", false); pref("extensions.getAddons.cache.enabled", false); // https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/ pref("privacy.donottrackheader.enabled", false); // (mullvad-browser#17) -// Make sure there is no Tracking Protection active in Tor Browser, see: #17898. +// tor-browser#17898: disable Tracking Protection in Tor Browser because of +// doubts about the blocklist-based approach and the breakage. pref("privacy.trackingprotection.enabled", false); pref("privacy.trackingprotection.pbmode.enabled", false); +pref("privacy.trackingprotection.emailtracking.enabled", false); pref("privacy.trackingprotection.emailtracking.pbmode.enabled", false); pref("privacy.trackingprotection.annotate_channels", false); pref("privacy.trackingprotection.cryptomining.enabled", false); @@ -329,9 +347,9 @@ pref("privacy.trackingprotection.socialtracking.enabled", false); // This is mostly for consistency, since we disable the safe browsing lists, // which are needed for this feature to work properly. pref("privacy.trackingprotection.harmfuladdon.enabled", false); -// Hide the Unified Trust Panel until we have new designs. tor-browser#44814. +// tor-browser#44814: hide the Unified Trust Panel until we have new designs. pref("browser.urlbar.trustPanel.featureGate", false); -// tor-browser#43986: Explicitly disable bounce tracking protection +// tor-browser#43986: explicitly disable bounce tracking protection pref("privacy.bounceTrackingProtection.mode", 0); pref("privacy.socialtracking.block_cookies.enabled", false); pref("privacy.annotate_channels.strict_list.enabled", false); @@ -339,14 +357,11 @@ pref("privacy.annotate_channels.strict_list.enabled", false); // Notice that it should not apply to RFP anyway... pref("privacy.fingerprintingProtection.remoteOverrides.enabled", false); -// Disable Privacy-Preserving-Attribution (Bug #42687) -pref("dom.private-attribution.submission.enabled", false); - // Custom extensions preferences tor-browser#41581 pref("extensions.hideNoScript", true); pref("extensions.hideUnifiedWhenEmpty", true); -// Disable activity stream in about:home (Bug #41029) +// tor-browser#41029: disable activity stream in about:home pref("browser.newtabpage.activity-stream.discoverystream.enabled", false); pref("browser.newtabpage.activity-stream.feeds.section.topstories", false); pref("browser.newtabpage.activity-stream.showSponsored", false); @@ -369,37 +384,34 @@ pref("browser.newtabpage.activity-stream.asrouter.useRemoteL10n", false); // tor-browser#42054: make sure search result telemetry is disabled. pref("browser.search.serpEventTelemetryCategorization.enabled", false); - - // ML components that we want to hide from the user. See tor-browser#44045. -// Many of these preferences are locked because the component is entirely -// removed, so they could not be functionally enabled. - +// The component is entirely removed, so many functionalities will not work even +// if flipped. // tor-browser#42872, #42555, #44045: Disable ML translations. // Maybe re-enable after auditing and fixing the UX (tor-browser#41837). // NOTE: whilst the "translations" component is still included in the build, we // lock the preference because the engine is excluded and the // "translations-models" RemoteSettings needed for the engine is empty. -pref("browser.translations.enable", false, locked); +pref("browser.translations.enable", false); // Hide some AI settings outside the "ai" setting pane. See tor-browser#44764. // NOTE: This preference tracks whether the *user* opted out of all AI features // in about:preferences. By itself, it does not provide global blocking of the // AI features, which are often controlled by separate preferences below. // However, some parts of the UI will react to this preference. See // tor-browser#44541. -pref("browser.ai.control.default", "blocked", locked); +pref("browser.ai.control.default", "blocked"); // Disables many (but not all) ML engines. Note, this does not have overall // control over exposure to ML features. tor-browser#44045. -pref("browser.ml.enable", false, locked); +pref("browser.ml.enable", false); // Disable third party AI chatbot. tor-browser#43989. -pref("browser.ml.chat.enabled", false, locked); +pref("browser.ml.chat.enabled", false); // Disable LinkPreview. tor-browser#44045 and tor-browser#43867. -pref("browser.ml.linkPreview.enabled", false, locked); -// Disable Smart Tab Groups. tor-browser#44045. -pref("browser.tabs.groups.smart.enabled", false, locked); -pref("browser.tabs.groups.smart.userEnabled", false, locked); +pref("browser.ml.linkPreview.enabled", false); +// tor-browser#44045: disable Smart Tab Groups. +pref("browser.tabs.groups.smart.enabled", false); +pref("browser.tabs.groups.smart.userEnabled", false); // Don't expose ModelHub API for extensions. tor-browser#44045. -pref("extensions.ml.enabled", false, locked); +pref("extensions.ml.enabled", false); // Don't enable ML generated alt text. tor-browser#44045. // pdfjs.enableAltText controls whether MLManager is created, // pdfjs.enableGuessAltText controls whether the MLManager can create an ML @@ -407,25 +419,26 @@ pref("extensions.ml.enabled", false, locked); // changed by the user in the UI, but also has the side effect of hiding the // UI controls for the non-ML preference pdfjs.enableNewAltTextWhenAddingImage. // See bugzilla bug 1943456 comment 12. -pref("pdfjs.enableAltText", false, locked); -pref("pdfjs.enableAltTextForEnglish", false, locked); -pref("pdfjs.enableGuessAltText", false, locked); -pref("pdfjs.enableAltTextModelDownload", false, locked); +pref("pdfjs.enableAltText", false); +pref("pdfjs.enableAltTextForEnglish", false); +pref("pdfjs.enableGuessAltText", false); +pref("pdfjs.enableAltTextModelDownload", false); // Disable SuggestBackendMl. tor-browser#44045. -pref("browser.urlbar.quicksuggest.mlEnabled", false, locked); +pref("browser.urlbar.quicksuggest.mlEnabled", false); // Disable SemanticHistory search. tor-browser#44045. -pref("places.semanticHistory.featureGate", false, locked); -// tor-browser#45120: Disable AIWindow. -// tor-browser#45338: Locked as a precaution against entry points that try to -// flip this value. +pref("places.semanticHistory.featureGate", false); +// tor-browser#45120: disable AIWindow. +// tor-browser#45338: locked as a precaution against entry points that try to +// flip this value. Also, policies also lock it. pref("browser.smartwindow.enabled", false, locked); - +// tor-browser#45073 (153 preference review): lock to pretend we have disabled +// AI through policies (see AIWindow.isManagedByPolicy). +pref("browser.ai.control.smartWindow", "blocked", locked); // tor-browser#41945 - disable automatic cookie banners dismissal until // we're sure it does not causes fingerprinting risks or other issues. pref("cookiebanners.service.mode", 0); pref("cookiebanners.service.mode.privateBrowsing", 0); -pref("cookiebanners.ui.desktop.enabled", false); // Disable moreFromMozilla pane in the preferences/settings (tor-browser#41292). pref("browser.preferences.moreFromMozilla", false); @@ -457,12 +470,9 @@ pref("browser.tabs.remote.separatedMozillaDomains", ""); // Avoid DNS lookups on search terms pref("browser.urlbar.dnsResolveSingleWordsAfterSearch", 0); -// Disable about:newtab and "first run" experiments -pref("messaging-system.rsexperimentloader.enabled", false); // true means that you are *not* opting out. See its usage in various file. pref("app.shield.optoutstudies.enabled", false); -// Disable nimbus rollouts. -// See bugzilla bug 2003350. See tor-browser#44520. +// tor-browser#44520: disable nimbus rollouts (see bugzilla bug 2003350). pref("nimbus.rollouts.enabled", false); // Disable Normandy/Shield pref("app.normandy.enabled", false); @@ -520,11 +530,6 @@ pref("dom.xslt.enabled", false); #if MOZ_UPDATE_CHANNEL == release pref("privacy.resistFingerprinting", true, locked); pref("privacy.resistFingerprinting.exemptedDomains", "", locked); -// tor-browser#42125: Some misleading guides suggest to set this to false, but -// the result would be that the canvas is completely white -// (see StaticPrefList.yaml), so lock it to true. -// Might be removed (MozBug 1670447). -pref("privacy.resistFingerprinting.randomDataOnCanvasExtract", true, locked); #else pref("privacy.resistFingerprinting", true); pref("privacy.resistFingerprinting.exemptedDomains", ""); @@ -542,8 +547,6 @@ pref("webgl.enable-webgl2", false); // tor-browser#44763: disable WebGPU until audited. pref("dom.webgpu.enabled", false); pref("browser.link.open_newwindow.restriction", 0); // Bug 9881: Open popups in new tabs (to avoid fullscreen popups) -// tor-browser#42767: Disable offscreen canvas until verified it is not fingerprintable -pref("gfx.offscreencanvas.enabled", false); // Prevent scripts from moving and resizing open windows pref("dom.disable_window_move_resize", true); // Set video VP9 to 0 for everyone (bug 22548) @@ -596,9 +599,8 @@ pref("dom.netinfo.enabled", false); pref("network.http.referer.defaultPolicy", 2); // Bug 32948: Make referer behavior consistent regardless of private browing mode status pref("network.http.referer.defaultPolicy.pbmode", 2); pref("network.http.referer.XOriginTrimmingPolicy", 2); // Bug 17228: Force trim referer to scheme+host+port in cross-origin requests -// Bug 40463: Disable Windows SSO -pref("network.http.windows-sso.enabled", false, locked); -// Bug 43165: Disable Microsoft SSO on macOS +// tor-browser#40463 (91 preference review): disable Windows SSO +pref("network.http.windows-sso.enabled", false); pref("network.http.microsoft-entra-sso.enabled", false); pref("network.microsoft-sso-authority-list", ""); // tor-browser#40424 @@ -620,6 +622,9 @@ pref("security.restrict_to_adults.respect_platform", false); // Xwayland as the default. pref("widget.wayland.fractional-scale.enabled", false); +// tor-browser#45171: Disabled split view which is janky. +pref("browser.tabs.splitView.enabled", false); + // tor-browser#41943: defense-in-depth, but do not lock anymore (enabled in Firefox 119, http://bugzil.la/1851162) pref("javascript.options.spectre.disable_for_isolated_content", false); @@ -628,13 +633,11 @@ pref("privacy.firstparty.isolate", true); // Always enforce first party isolatio // Only accept cookies from the originating site (block third party cookies) pref("network.cookie.cookieBehavior", 1); pref("network.cookie.cookieBehavior.pbmode", 1); -pref("network.predictor.enabled", false); // Temporarily disabled. See https://bugs.torproject.org/16633 -pref("network.predictor.enable-prefetch", false); pref("network.http.speculative-parallel-limit", 0); pref("browser.places.speculativeConnect.enabled", false); pref("network.prefetch-next", false); pref("browser.urlbar.speculativeConnect.enabled", false); -// Bug 40220: Make sure tracker cookie purging is disabled. +// tor-browser#40220: make sure tracker cookie purging is disabled. // It depends on Firefox's tracking protection, which we currently do not enable // See also tor-browser#30939. pref("privacy.purge_trackers.enabled", false); @@ -648,6 +651,8 @@ pref("network.dns.disablePrefetchFromHTTPS", true); pref("dom.prefetch_dns_for_anchor_http_document", false); pref("dom.prefetch_dns_for_anchor_https_document", false); +// Notice: some of these values are already false on Firefox, but we still +// define them as defense-in-depth. pref("network.protocol-handler.external-default", false); pref("network.protocol-handler.external.mailto", false); pref("network.protocol-handler.external.news", false); @@ -661,25 +666,22 @@ pref("network.protocol-handler.warn-external.snews", true); pref("network.protocol-handler.external.ms-windows-store", false); pref("network.protocol-handler.warn-external.ms-windows-store", true); #endif -pref("network.proxy.allow_bypass", false, locked); // #40682 -// Bug 40548: Disable proxy-bypass + +// tor-browser#40682: some API (e.g., telemetry) might try to bypass the proxy +// if this is true. At the moment, the browser will not try to set this +// anywhere, but it makes sense to lock it as a defense-in-depth in case of +// future changes. +pref("network.proxy.allow_bypass", false, locked); +// tor-browser#40548: disable another proxy-bypass for system requests. +// This is also disabled at build time (tor-browser#45336). pref("network.proxy.failover_direct", false, locked); -// Lock to 'true', which is already the firefox default, to prevent users -// from making themselves fingerprintable by disabling. This pref -// alters content load order in a page. See tor-browser#24686 -pref("network.http.tailing.enabled", true, locked); -// Block 0.0.0.0 +// tor-browser#43811: block 0.0.0.0 // https://bugzilla.mozilla.org/show_bug.cgi?id=1889130 -// tor-browser#43811 pref("network.socket.ip_addr_any.disabled", true); -// tor-browser#23044: Make sure we don't have any GIO supported protocols -// (defense in depth measure). -// As of Firefox 118 (Bug 1843763), upstream does not add any protocol by -// default, but setting it to blank seems a good idea (tor-browser#42054). -pref("network.gio.supported-protocols", ""); -pref("media.peerconnection.enabled", false); // Disable WebRTC interfaces +// Disable WebRTC interfaces +pref("media.peerconnection.enabled", false); // Mullvad Browser enables WebRTC by default, meaning that there the following prefs // are first-line defense, rather than "in depth" (mullvad-browser#40) // tor-browser#41667 - Defense in depth: use mDNS to avoid local IP leaks on Android too if user enables WebRTC @@ -733,7 +735,7 @@ pref("network.file.path_blacklist", "/net"); pref("svg.disabled", false); pref("mathml.disabled", false); -// Bug 40408 +// tor-browser#40408 pref("svg.context-properties.content.allowed-domains", ""); // Network and performance @@ -798,7 +800,9 @@ pref("security.certerrors.mitm.priming.enabled", false); // Don't automatically enable enterprise roots, see bug 40166 pref("security.certerrors.mitm.auto_enable_enterprise_roots", false); -// Disable share menus on Mac and Windows tor-browser#41117 +// tor-browser#41117: disable share menus on Mac and Windows. +// Locked as user might not realize sharing might result in proxy bypasses or +// general linkability. pref("browser.menu.share_url.allow", false, locked); // tor-browser#45133: Disable share button @@ -848,6 +852,10 @@ pref("toolkit.winRegisterApplicationRestart", false); // tor-browser#43051: Hide the checkbox to open the browser automatically on // Windows startup. pref("browser.startup.windowsLaunchOnLogin.enabled", false); + +// tor-browser#45293: force devices to be detected as not capable of tablet mode +// on Windows 11+ (defense-in-depth for fingerprinting). +pref("widget.windows.tablet_detection_override", -1); #endif #ifdef ANDROID @@ -1158,16 +1166,3 @@ pref("font.name-list.monospace.x-unicode", "Cousine, Noto Sans Balinese, Noto Sa // The rest are not customized, because they are covered only by one font #endif #endif - -// tor-browser#42630: Disable LaterRun. -// -// This preference is set in a few places in code. Even though it's locked, -// setting it will still change the value in `prefs.js`, but it will be ignored. -// If this is ever unlocked, the value in prefs.js will be used. -pref("browser.laterrun.enabled", false, locked); - -// tor-browser#44123: Never trim the protocol off of URLs. -pref("browser.urlbar.trimURLs", false); - -// tor-browser#45171: Disabled split view which is janky. -pref("browser.tabs.splitView.enabled", false); View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/fdc6efc… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/fdc6efc… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] 2 commits: fixup! TB 34378: [android] Port external helper app prompting
by Dan Ballard (@dan) 21 Sep '26

21 Sep '26
Dan Ballard pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: c589157b by Dan Ballard at 2026-09-21T12:23:30-07:00 fixup! TB 34378: [android] Port external helper app prompting TB40627: Fix android share by making new intents with new request codes and not caching the dialog - - - - - c73add30 by Dan Ballard at 2026-09-21T12:23:30-07:00 fixup! [android] Disable features and functionality TB 40627: Remove Share function from selected text context menu - - - - - 3 changed files: - mobile/android/android-components/components/feature/contextmenu/src/main/java/mozilla/components/feature/contextmenu/DefaultSelectionActionDelegate.kt - mobile/android/android-components/components/support/utils/src/main/java/mozilla/components/support/utils/TorUtils.kt - mobile/android/fenix/app/src/main/java/org/mozilla/fenix/HomeActivity.kt Changes: ===================================== mobile/android/android-components/components/feature/contextmenu/src/main/java/mozilla/components/feature/contextmenu/DefaultSelectionActionDelegate.kt ===================================== @@ -26,7 +26,7 @@ internal const val EMAIL = "CUSTOM_CONTEXT_MENU_EMAIL" @VisibleForTesting(otherwise = VisibleForTesting.PRIVATE) internal const val CALL = "CUSTOM_CONTEXT_MENU_CALL" -private val customActions = arrayOf(CALL, EMAIL, SEARCH, SEARCH_PRIVATELY, SHARE) +private val customActions = arrayOf(SEARCH_PRIVATELY) /** * Adds normal and private search buttons to text selection context menus. ===================================== mobile/android/android-components/components/support/utils/src/main/java/mozilla/components/support/utils/TorUtils.kt ===================================== @@ -10,6 +10,7 @@ import android.content.Intent object TorUtils { const val TORBROWSER_START_ACTIVITY_PROMPT = "torbrowser_start_activity_prompt" + var requestCode = 0 // Delegates showing prompt and possibly starting the activity to the main app activity. // Highly dependant on Fenix/Tor Browser for Android. @@ -19,7 +20,8 @@ object TorUtils { fun startActivityPrompt(context: Context, intent: Intent) { val intentContainer = Intent() intentContainer.setPackage(context.applicationContext.packageName) - intentContainer.putExtra(TORBROWSER_START_ACTIVITY_PROMPT, PendingIntent.getActivity(context, 0, intent, PendingIntent.FLAG_IMMUTABLE)) + intentContainer.putExtra(TORBROWSER_START_ACTIVITY_PROMPT, PendingIntent.getActivity(context, requestCode, intent, PendingIntent.FLAG_IMMUTABLE)) + requestCode++ intentContainer.flags = Intent.FLAG_ACTIVITY_NEW_TASK context.startActivity(intentContainer) } ===================================== mobile/android/fenix/app/src/main/java/org/mozilla/fenix/HomeActivity.kt ===================================== @@ -438,8 +438,6 @@ open class HomeActivity : LocaleAwareAppCompatActivity(), NavHostActivity, Crash } } - private var dialog: RedirectDialogFragment? = null - private val providerStoppedViewModel: ProviderStoppedViewModel by viewModels() private val urlQuickLoadViewModel: UrlQuickLoadViewModel by viewModels() @@ -991,15 +989,9 @@ open class HomeActivity : LocaleAwareAppCompatActivity(), NavHostActivity, Crash // Copied from mozac AppLinksFeature.kt internal fun getOrCreateDialog(): RedirectDialogFragment { - val existingDialog = dialog - if (existingDialog != null) { - return existingDialog - } - SimpleRedirectDialogFragment.newInstance( getString(appLinksR.string.mozac_feature_applinks_normal_confirm_dialog_title), ).also { - dialog = it return it } } View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/738620… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/738620… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 2a398e47 by Pier Angelo Vendrame at 2026-09-21T18:14:54+00:00 fixup! Firefox preference overrides. BB 45080: Disable the reporting API. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -287,6 +287,10 @@ pref("browser.preonboarding.enabled", false); // Disable checkbox in about:neterror that controls // security.xfocsp.errorReporting.automatic. See tor-browser#42653. pref("security.xfocsp.errorReporting.enabled", false); +// tor-browser#45080: disable the reporting API. +pref("dom.reporting.enabled", false); +pref("dom.reporting.header.enabled", false); +pref("dom.reporting.crash.enabled", false); // Added in tor-browser#41496 even though it shuld be already always disabled // since we disable MOZ_CRASHREPORTER. pref("breakpad.reportURL", "data:"); View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/2a3… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/2a3… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
  • ← Newer
  • 1
  • ...
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • ...
  • 22
  • Older →

HyperKitty Powered by HyperKitty version 1.3.12.