lists.torproject.org
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

tbb-commits

Thread Start a new thread
Threads by month
  • ----- 2026 -----
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2018 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2017 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2016 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2015 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2014 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
tbb-commits@lists.torproject.org

  • 1 participants
  • 21170 discussions
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by Pier Angelo Vendrame (@pierov) 21 Sep '26

21 Sep '26
Pier Angelo Vendrame pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: fdc6efc1 by Pier Angelo Vendrame at 2026-09-21T21:26:59+02:00 fixup! Firefox preference overrides. BB 45073: 140-153 preference review. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -1,7 +1,7 @@ // Preferences to harden Firefox's security and privacy // Do not edit this file. -// Use the OS locale by default (tor-browser#17400) +// tor-browser#17400: use the OS locale by default. pref("intl.locale.requested", ""); // Home page is blank rather than Firefox Home (Activity Stream). @@ -21,11 +21,6 @@ pref("startup.homepage_welcome_url.additional", ""); // Disable Firefox Welcome Dialog pref("browser.aboutwelcome.enabled", false); -#if MOZ_UPDATE_CHANNEL == release -// tor-browser#42640: Disable Firefox Flame button due to unknown interactions with New Identity -pref("browser.privatebrowsing.resetPBM.enabled", false, locked); -#endif - #ifndef ANDROID // Bug 41668: allow users to apply updates. This is set also in firefox.js for // all platforms, except for Windows. As explained on firefox.js, Firefox uses a @@ -53,6 +48,9 @@ pref("app.update.staging.enabled", false); pref("browser.startup.homepage_override.buildID", "20100101"); // Disable the "Refresh" prompt that is displayed for stale profiles. +// TODO: Re-evaluate (tor-browser#45341): this was needed because the new +// profile it created did not contain NoScript. Now profiles work, so the main +// technical reason for this preference does not hold anymore. pref("browser.disableResetPrompt", true); // Disk activity: Disable Browsing History Storage @@ -60,15 +58,18 @@ pref("browser.privatebrowsing.autostart", true); pref("browser.cache.disk.enable", false); pref("permissions.memory_only", true); pref("security.nocertdb", true); + +// tor-browser#42094: do not collect stats about WebRTC. +// Defense-in-depth: this is already false in upstream release builds. pref("media.aboutwebrtc.hist.enabled", false); -// tor-browser#45214: Disable the megalist (contextual password manager). +// tor-browser#45214: disable the megalist (contextual password manager). pref("browser.contextual-password-manager.enabled", false); // Disk Activity -// Disable auto-downloading to ~/Downloads and other download tweaks to minimize -// disk leaks (tor-browser#42050). +// tor-browser#42050: disable auto-downloading to ~/Downloads and other download +// tweaks to minimize disk leaks. pref("browser.download.useDownloadDir", false); pref("browser.download.always_ask_before_handling_new_types", true); pref("browser.download.manager.addToRecentDocs", false); @@ -139,16 +140,29 @@ pref("browser.pagethumbnails.capturing_disabled", true); // pref("privacy.exposeContentTitleInWindow", false); // pref("privacy.exposeContentTitleInWindow.pbm", false); -// tor-browser#42054: Opt-out from any built-in backup system, even though +// tor-browser#42630: Disable LaterRun. +// +// This preference is set in a few places in code, so we lock it to keep this +// feature off. +// Even though it's locked, setting it will still change the value in +// `prefs.js`, but it will be ignored. +// If this is ever unlocked, the value in prefs.js will be used. +pref("browser.laterrun.enabled", false, locked); + +// tor-browser#42054: opt-out from any built-in backup system, even though // local, as it might be a violation of our standalone mode. // Users can still opt-in if they wish. pref("browser.backup.enabled", false); pref("browser.backup.scheduled.enabled", false); -// tor-browser#45123: Disable the profile automated backup and restore service. +// tor-browser#45123: disable the profile automated backup and restore service. pref("browser.backup.archive.enabled", false); pref("browser.backup.restore.enabled", false); -// Empty clipboard content from private windows on exit (tor-browser#42154) +// tor-browser#45073 (153.0 preference review): do not send media metadata to +// the OS when in PBM (defense-in-depth). +pref("media.privatebrowsing.metadata.enabled", false); + +// tor-browser#42154: empty clipboard content from private windows on exit pref("browser.privatebrowsing.preserveClipboard", false); // tor-browser#42611: Do not include the URL of the image, when copying it. @@ -164,6 +178,9 @@ pref("dom.security.https_only_mode_pbm", true); // tor-browser#43197, defense in depth if ever https-only got disabled pref("dom.security.https_first_add_exception_on_failure", false); +// tor-browser#44123: never trim the protocol off of URLs. +pref("browser.urlbar.trimURLs", false); + // tor-browser#22320: Hide referer when coming from a .onion address // We enable this here (rather than in Tor Browser) in case users of other // base-browser derived browsers configure it to use a system Tor daemon @@ -182,12 +199,8 @@ pref("network.http.referer.hideOnionSource", true); // [4] https://www.ssllabs.com/ssl-pulse/ pref("security.ssl.require_safe_negotiation", true); -// lock those disabled by https://bugzilla.mozilla.org/show_bug.cgi?id=1036765 -pref("security.ssl3.dhe_rsa_aes_128_sha", false, locked); -pref("security.ssl3.dhe_rsa_aes_256_sha", false, locked); - -// Wrapping a static pref to lock it and prevent changing. -// See tor-browser#40565. +// tor-browser#40565: lock as the UI offered to enable TLS 1.0 and 1.1 without +// explaining the actual reasons. pref("security.tls.version.enable-deprecated", false, locked); // tor-browser#44187: Disable session identifiers to make PBM and normal mode @@ -227,15 +240,12 @@ pref("browser.urlbar.maxCharsForSearchSuggestions", 0); // Misc privacy: Remote pref("browser.send_pings", false); -// Space separated list of URLs that are allowed to send objects (instead of -// only strings) through webchannels. The default for Firefox is some Mozilla -// domains. -pref("webchannel.allowObject.urlWhitelist", ""); + +// Geolocation preferences. pref("geo.enabled", false); pref("geo.provider.network.url", ""); pref("geo.provider.ms-windows-location", false); pref("geo.provider.use_corelocation", false); -pref("geo.provider.use_gpsd", false); pref("geo.provider.use_geoclue", false); pref("browser.safebrowsing.malware.enabled", false); @@ -248,6 +258,9 @@ pref("browser.safebrowsing.provider.google.updateURL", ""); pref("browser.safebrowsing.provider.google.gethashURL", ""); pref("browser.safebrowsing.provider.google4.updateURL", ""); pref("browser.safebrowsing.provider.google4.gethashURL", ""); +pref("browser.safebrowsing.provider.google5.enabled", false); +pref("browser.safebrowsing.provider.google5.updateURL", ""); +pref("browser.safebrowsing.provider.google5.gethashURL", ""); pref("browser.safebrowsing.provider.mozilla.updateURL", ""); pref("browser.safebrowsing.provider.mozilla.gethashURL", ""); @@ -267,26 +280,29 @@ pref("toolkit.telemetry.shutdownPingSender.enabled", false); // Added in tor-bro pref("toolkit.telemetry.firstShutdownPing.enabled", false); // Added in tor-browser#41496 pref("toolkit.telemetry.updatePing.enabled", false); // Make sure updater telemetry is disabled; see #25909. pref("toolkit.telemetry.bhrPing.enabled", false); -pref("toolkit.telemetry.coverage.opt-out", true); pref("datareporting.healthreport.uploadEnabled", false); pref("datareporting.policy.dataSubmissionEnabled", false); -// Force all telemtry identifier to their canary values tor-browser#43750 +// tor-browser#43750: force all telemtry identifier to their canary values. +// Locked to prevent the browser from changing them. pref("toolkit.telemetry.cachedClientID", "c0ffeec0-ffee-c0ff-eec0-ffeec0ffeec0", locked); pref("toolkit.telemetry.cachedProfileGroupID", "decafdec-afde-cafd-ecaf-decafdecafde", locked); pref("datareporting.dau.cachedUsageProfileID", "beefbeef-beef-beef-beef-beeefbeefbee", locked); pref("datareporting.dau.cachedUsageProfileGroupID", "b0bacafe-b0ba-cafe-b0ba-cafeb0bacafe", locked); +pref("datareporting.usage.uploadEnabled", false); pref("toolkit.coverage.opt-out", true); pref("toolkit.coverage.endpoint.base", ""); pref("browser.tabs.crashReporting.sendReport", false); pref("browser.crashReports.unsubmittedCheck.autoSubmit2", false); -// Added in tor-browser#41496 even though false by default +// tor-browser#41496: do not offer to send unsubmitted crash reports. +// (Defense in detph: we do not have the crash reporter and this is false on the +// release channel also in Firefox). pref("browser.crashReports.unsubmittedCheck.enabled", false); +// tor-browser#45073 (153.0 preference review): add also this pref not to send +// unsubmitted crash reports. +pref("browser.crashReports.onDemand", false); // tor-browser#44026: Disable the modal that shows upstream terms of usage, // since we opt out of their telemetry and data collection. pref("browser.preonboarding.enabled", false); -// Disable checkbox in about:neterror that controls -// security.xfocsp.errorReporting.automatic. See tor-browser#42653. -pref("security.xfocsp.errorReporting.enabled", false); // tor-browser#45080: disable the reporting API. pref("dom.reporting.enabled", false); pref("dom.reporting.header.enabled", false); @@ -317,9 +333,11 @@ pref("services.sync.engine.prefs", false); pref("services.sync.engine.tabs", false); pref("extensions.getAddons.cache.enabled", false); // https://blog.mozilla.org/addons/how-to-opt-out-of-add-on-metadata-updates/ pref("privacy.donottrackheader.enabled", false); // (mullvad-browser#17) -// Make sure there is no Tracking Protection active in Tor Browser, see: #17898. +// tor-browser#17898: disable Tracking Protection in Tor Browser because of +// doubts about the blocklist-based approach and the breakage. pref("privacy.trackingprotection.enabled", false); pref("privacy.trackingprotection.pbmode.enabled", false); +pref("privacy.trackingprotection.emailtracking.enabled", false); pref("privacy.trackingprotection.emailtracking.pbmode.enabled", false); pref("privacy.trackingprotection.annotate_channels", false); pref("privacy.trackingprotection.cryptomining.enabled", false); @@ -329,9 +347,9 @@ pref("privacy.trackingprotection.socialtracking.enabled", false); // This is mostly for consistency, since we disable the safe browsing lists, // which are needed for this feature to work properly. pref("privacy.trackingprotection.harmfuladdon.enabled", false); -// Hide the Unified Trust Panel until we have new designs. tor-browser#44814. +// tor-browser#44814: hide the Unified Trust Panel until we have new designs. pref("browser.urlbar.trustPanel.featureGate", false); -// tor-browser#43986: Explicitly disable bounce tracking protection +// tor-browser#43986: explicitly disable bounce tracking protection pref("privacy.bounceTrackingProtection.mode", 0); pref("privacy.socialtracking.block_cookies.enabled", false); pref("privacy.annotate_channels.strict_list.enabled", false); @@ -339,14 +357,11 @@ pref("privacy.annotate_channels.strict_list.enabled", false); // Notice that it should not apply to RFP anyway... pref("privacy.fingerprintingProtection.remoteOverrides.enabled", false); -// Disable Privacy-Preserving-Attribution (Bug #42687) -pref("dom.private-attribution.submission.enabled", false); - // Custom extensions preferences tor-browser#41581 pref("extensions.hideNoScript", true); pref("extensions.hideUnifiedWhenEmpty", true); -// Disable activity stream in about:home (Bug #41029) +// tor-browser#41029: disable activity stream in about:home pref("browser.newtabpage.activity-stream.discoverystream.enabled", false); pref("browser.newtabpage.activity-stream.feeds.section.topstories", false); pref("browser.newtabpage.activity-stream.showSponsored", false); @@ -369,37 +384,34 @@ pref("browser.newtabpage.activity-stream.asrouter.useRemoteL10n", false); // tor-browser#42054: make sure search result telemetry is disabled. pref("browser.search.serpEventTelemetryCategorization.enabled", false); - - // ML components that we want to hide from the user. See tor-browser#44045. -// Many of these preferences are locked because the component is entirely -// removed, so they could not be functionally enabled. - +// The component is entirely removed, so many functionalities will not work even +// if flipped. // tor-browser#42872, #42555, #44045: Disable ML translations. // Maybe re-enable after auditing and fixing the UX (tor-browser#41837). // NOTE: whilst the "translations" component is still included in the build, we // lock the preference because the engine is excluded and the // "translations-models" RemoteSettings needed for the engine is empty. -pref("browser.translations.enable", false, locked); +pref("browser.translations.enable", false); // Hide some AI settings outside the "ai" setting pane. See tor-browser#44764. // NOTE: This preference tracks whether the *user* opted out of all AI features // in about:preferences. By itself, it does not provide global blocking of the // AI features, which are often controlled by separate preferences below. // However, some parts of the UI will react to this preference. See // tor-browser#44541. -pref("browser.ai.control.default", "blocked", locked); +pref("browser.ai.control.default", "blocked"); // Disables many (but not all) ML engines. Note, this does not have overall // control over exposure to ML features. tor-browser#44045. -pref("browser.ml.enable", false, locked); +pref("browser.ml.enable", false); // Disable third party AI chatbot. tor-browser#43989. -pref("browser.ml.chat.enabled", false, locked); +pref("browser.ml.chat.enabled", false); // Disable LinkPreview. tor-browser#44045 and tor-browser#43867. -pref("browser.ml.linkPreview.enabled", false, locked); -// Disable Smart Tab Groups. tor-browser#44045. -pref("browser.tabs.groups.smart.enabled", false, locked); -pref("browser.tabs.groups.smart.userEnabled", false, locked); +pref("browser.ml.linkPreview.enabled", false); +// tor-browser#44045: disable Smart Tab Groups. +pref("browser.tabs.groups.smart.enabled", false); +pref("browser.tabs.groups.smart.userEnabled", false); // Don't expose ModelHub API for extensions. tor-browser#44045. -pref("extensions.ml.enabled", false, locked); +pref("extensions.ml.enabled", false); // Don't enable ML generated alt text. tor-browser#44045. // pdfjs.enableAltText controls whether MLManager is created, // pdfjs.enableGuessAltText controls whether the MLManager can create an ML @@ -407,25 +419,26 @@ pref("extensions.ml.enabled", false, locked); // changed by the user in the UI, but also has the side effect of hiding the // UI controls for the non-ML preference pdfjs.enableNewAltTextWhenAddingImage. // See bugzilla bug 1943456 comment 12. -pref("pdfjs.enableAltText", false, locked); -pref("pdfjs.enableAltTextForEnglish", false, locked); -pref("pdfjs.enableGuessAltText", false, locked); -pref("pdfjs.enableAltTextModelDownload", false, locked); +pref("pdfjs.enableAltText", false); +pref("pdfjs.enableAltTextForEnglish", false); +pref("pdfjs.enableGuessAltText", false); +pref("pdfjs.enableAltTextModelDownload", false); // Disable SuggestBackendMl. tor-browser#44045. -pref("browser.urlbar.quicksuggest.mlEnabled", false, locked); +pref("browser.urlbar.quicksuggest.mlEnabled", false); // Disable SemanticHistory search. tor-browser#44045. -pref("places.semanticHistory.featureGate", false, locked); -// tor-browser#45120: Disable AIWindow. -// tor-browser#45338: Locked as a precaution against entry points that try to -// flip this value. +pref("places.semanticHistory.featureGate", false); +// tor-browser#45120: disable AIWindow. +// tor-browser#45338: locked as a precaution against entry points that try to +// flip this value. Also, policies also lock it. pref("browser.smartwindow.enabled", false, locked); - +// tor-browser#45073 (153 preference review): lock to pretend we have disabled +// AI through policies (see AIWindow.isManagedByPolicy). +pref("browser.ai.control.smartWindow", "blocked", locked); // tor-browser#41945 - disable automatic cookie banners dismissal until // we're sure it does not causes fingerprinting risks or other issues. pref("cookiebanners.service.mode", 0); pref("cookiebanners.service.mode.privateBrowsing", 0); -pref("cookiebanners.ui.desktop.enabled", false); // Disable moreFromMozilla pane in the preferences/settings (tor-browser#41292). pref("browser.preferences.moreFromMozilla", false); @@ -457,12 +470,9 @@ pref("browser.tabs.remote.separatedMozillaDomains", ""); // Avoid DNS lookups on search terms pref("browser.urlbar.dnsResolveSingleWordsAfterSearch", 0); -// Disable about:newtab and "first run" experiments -pref("messaging-system.rsexperimentloader.enabled", false); // true means that you are *not* opting out. See its usage in various file. pref("app.shield.optoutstudies.enabled", false); -// Disable nimbus rollouts. -// See bugzilla bug 2003350. See tor-browser#44520. +// tor-browser#44520: disable nimbus rollouts (see bugzilla bug 2003350). pref("nimbus.rollouts.enabled", false); // Disable Normandy/Shield pref("app.normandy.enabled", false); @@ -520,11 +530,6 @@ pref("dom.xslt.enabled", false); #if MOZ_UPDATE_CHANNEL == release pref("privacy.resistFingerprinting", true, locked); pref("privacy.resistFingerprinting.exemptedDomains", "", locked); -// tor-browser#42125: Some misleading guides suggest to set this to false, but -// the result would be that the canvas is completely white -// (see StaticPrefList.yaml), so lock it to true. -// Might be removed (MozBug 1670447). -pref("privacy.resistFingerprinting.randomDataOnCanvasExtract", true, locked); #else pref("privacy.resistFingerprinting", true); pref("privacy.resistFingerprinting.exemptedDomains", ""); @@ -542,8 +547,6 @@ pref("webgl.enable-webgl2", false); // tor-browser#44763: disable WebGPU until audited. pref("dom.webgpu.enabled", false); pref("browser.link.open_newwindow.restriction", 0); // Bug 9881: Open popups in new tabs (to avoid fullscreen popups) -// tor-browser#42767: Disable offscreen canvas until verified it is not fingerprintable -pref("gfx.offscreencanvas.enabled", false); // Prevent scripts from moving and resizing open windows pref("dom.disable_window_move_resize", true); // Set video VP9 to 0 for everyone (bug 22548) @@ -596,9 +599,8 @@ pref("dom.netinfo.enabled", false); pref("network.http.referer.defaultPolicy", 2); // Bug 32948: Make referer behavior consistent regardless of private browing mode status pref("network.http.referer.defaultPolicy.pbmode", 2); pref("network.http.referer.XOriginTrimmingPolicy", 2); // Bug 17228: Force trim referer to scheme+host+port in cross-origin requests -// Bug 40463: Disable Windows SSO -pref("network.http.windows-sso.enabled", false, locked); -// Bug 43165: Disable Microsoft SSO on macOS +// tor-browser#40463 (91 preference review): disable Windows SSO +pref("network.http.windows-sso.enabled", false); pref("network.http.microsoft-entra-sso.enabled", false); pref("network.microsoft-sso-authority-list", ""); // tor-browser#40424 @@ -620,6 +622,9 @@ pref("security.restrict_to_adults.respect_platform", false); // Xwayland as the default. pref("widget.wayland.fractional-scale.enabled", false); +// tor-browser#45171: Disabled split view which is janky. +pref("browser.tabs.splitView.enabled", false); + // tor-browser#41943: defense-in-depth, but do not lock anymore (enabled in Firefox 119, http://bugzil.la/1851162) pref("javascript.options.spectre.disable_for_isolated_content", false); @@ -628,13 +633,11 @@ pref("privacy.firstparty.isolate", true); // Always enforce first party isolatio // Only accept cookies from the originating site (block third party cookies) pref("network.cookie.cookieBehavior", 1); pref("network.cookie.cookieBehavior.pbmode", 1); -pref("network.predictor.enabled", false); // Temporarily disabled. See https://bugs.torproject.org/16633 -pref("network.predictor.enable-prefetch", false); pref("network.http.speculative-parallel-limit", 0); pref("browser.places.speculativeConnect.enabled", false); pref("network.prefetch-next", false); pref("browser.urlbar.speculativeConnect.enabled", false); -// Bug 40220: Make sure tracker cookie purging is disabled. +// tor-browser#40220: make sure tracker cookie purging is disabled. // It depends on Firefox's tracking protection, which we currently do not enable // See also tor-browser#30939. pref("privacy.purge_trackers.enabled", false); @@ -648,6 +651,8 @@ pref("network.dns.disablePrefetchFromHTTPS", true); pref("dom.prefetch_dns_for_anchor_http_document", false); pref("dom.prefetch_dns_for_anchor_https_document", false); +// Notice: some of these values are already false on Firefox, but we still +// define them as defense-in-depth. pref("network.protocol-handler.external-default", false); pref("network.protocol-handler.external.mailto", false); pref("network.protocol-handler.external.news", false); @@ -661,25 +666,22 @@ pref("network.protocol-handler.warn-external.snews", true); pref("network.protocol-handler.external.ms-windows-store", false); pref("network.protocol-handler.warn-external.ms-windows-store", true); #endif -pref("network.proxy.allow_bypass", false, locked); // #40682 -// Bug 40548: Disable proxy-bypass + +// tor-browser#40682: some API (e.g., telemetry) might try to bypass the proxy +// if this is true. At the moment, the browser will not try to set this +// anywhere, but it makes sense to lock it as a defense-in-depth in case of +// future changes. +pref("network.proxy.allow_bypass", false, locked); +// tor-browser#40548: disable another proxy-bypass for system requests. +// This is also disabled at build time (tor-browser#45336). pref("network.proxy.failover_direct", false, locked); -// Lock to 'true', which is already the firefox default, to prevent users -// from making themselves fingerprintable by disabling. This pref -// alters content load order in a page. See tor-browser#24686 -pref("network.http.tailing.enabled", true, locked); -// Block 0.0.0.0 +// tor-browser#43811: block 0.0.0.0 // https://bugzilla.mozilla.org/show_bug.cgi?id=1889130 -// tor-browser#43811 pref("network.socket.ip_addr_any.disabled", true); -// tor-browser#23044: Make sure we don't have any GIO supported protocols -// (defense in depth measure). -// As of Firefox 118 (Bug 1843763), upstream does not add any protocol by -// default, but setting it to blank seems a good idea (tor-browser#42054). -pref("network.gio.supported-protocols", ""); -pref("media.peerconnection.enabled", false); // Disable WebRTC interfaces +// Disable WebRTC interfaces +pref("media.peerconnection.enabled", false); // Mullvad Browser enables WebRTC by default, meaning that there the following prefs // are first-line defense, rather than "in depth" (mullvad-browser#40) // tor-browser#41667 - Defense in depth: use mDNS to avoid local IP leaks on Android too if user enables WebRTC @@ -733,7 +735,7 @@ pref("network.file.path_blacklist", "/net"); pref("svg.disabled", false); pref("mathml.disabled", false); -// Bug 40408 +// tor-browser#40408 pref("svg.context-properties.content.allowed-domains", ""); // Network and performance @@ -798,7 +800,9 @@ pref("security.certerrors.mitm.priming.enabled", false); // Don't automatically enable enterprise roots, see bug 40166 pref("security.certerrors.mitm.auto_enable_enterprise_roots", false); -// Disable share menus on Mac and Windows tor-browser#41117 +// tor-browser#41117: disable share menus on Mac and Windows. +// Locked as user might not realize sharing might result in proxy bypasses or +// general linkability. pref("browser.menu.share_url.allow", false, locked); // tor-browser#45133: Disable share button @@ -848,6 +852,10 @@ pref("toolkit.winRegisterApplicationRestart", false); // tor-browser#43051: Hide the checkbox to open the browser automatically on // Windows startup. pref("browser.startup.windowsLaunchOnLogin.enabled", false); + +// tor-browser#45293: force devices to be detected as not capable of tablet mode +// on Windows 11+ (defense-in-depth for fingerprinting). +pref("widget.windows.tablet_detection_override", -1); #endif #ifdef ANDROID @@ -1158,16 +1166,3 @@ pref("font.name-list.monospace.x-unicode", "Cousine, Noto Sans Balinese, Noto Sa // The rest are not customized, because they are covered only by one font #endif #endif - -// tor-browser#42630: Disable LaterRun. -// -// This preference is set in a few places in code. Even though it's locked, -// setting it will still change the value in `prefs.js`, but it will be ignored. -// If this is ever unlocked, the value in prefs.js will be used. -pref("browser.laterrun.enabled", false, locked); - -// tor-browser#44123: Never trim the protocol off of URLs. -pref("browser.urlbar.trimURLs", false); - -// tor-browser#45171: Disabled split view which is janky. -pref("browser.tabs.splitView.enabled", false); View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/fdc6efc… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/fdc6efc… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] 2 commits: fixup! TB 34378: [android] Port external helper app prompting
by Dan Ballard (@dan) 21 Sep '26

21 Sep '26
Dan Ballard pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: c589157b by Dan Ballard at 2026-09-21T12:23:30-07:00 fixup! TB 34378: [android] Port external helper app prompting TB40627: Fix android share by making new intents with new request codes and not caching the dialog - - - - - c73add30 by Dan Ballard at 2026-09-21T12:23:30-07:00 fixup! [android] Disable features and functionality TB 40627: Remove Share function from selected text context menu - - - - - 3 changed files: - mobile/android/android-components/components/feature/contextmenu/src/main/java/mozilla/components/feature/contextmenu/DefaultSelectionActionDelegate.kt - mobile/android/android-components/components/support/utils/src/main/java/mozilla/components/support/utils/TorUtils.kt - mobile/android/fenix/app/src/main/java/org/mozilla/fenix/HomeActivity.kt Changes: ===================================== mobile/android/android-components/components/feature/contextmenu/src/main/java/mozilla/components/feature/contextmenu/DefaultSelectionActionDelegate.kt ===================================== @@ -26,7 +26,7 @@ internal const val EMAIL = "CUSTOM_CONTEXT_MENU_EMAIL" @VisibleForTesting(otherwise = VisibleForTesting.PRIVATE) internal const val CALL = "CUSTOM_CONTEXT_MENU_CALL" -private val customActions = arrayOf(CALL, EMAIL, SEARCH, SEARCH_PRIVATELY, SHARE) +private val customActions = arrayOf(SEARCH_PRIVATELY) /** * Adds normal and private search buttons to text selection context menus. ===================================== mobile/android/android-components/components/support/utils/src/main/java/mozilla/components/support/utils/TorUtils.kt ===================================== @@ -10,6 +10,7 @@ import android.content.Intent object TorUtils { const val TORBROWSER_START_ACTIVITY_PROMPT = "torbrowser_start_activity_prompt" + var requestCode = 0 // Delegates showing prompt and possibly starting the activity to the main app activity. // Highly dependant on Fenix/Tor Browser for Android. @@ -19,7 +20,8 @@ object TorUtils { fun startActivityPrompt(context: Context, intent: Intent) { val intentContainer = Intent() intentContainer.setPackage(context.applicationContext.packageName) - intentContainer.putExtra(TORBROWSER_START_ACTIVITY_PROMPT, PendingIntent.getActivity(context, 0, intent, PendingIntent.FLAG_IMMUTABLE)) + intentContainer.putExtra(TORBROWSER_START_ACTIVITY_PROMPT, PendingIntent.getActivity(context, requestCode, intent, PendingIntent.FLAG_IMMUTABLE)) + requestCode++ intentContainer.flags = Intent.FLAG_ACTIVITY_NEW_TASK context.startActivity(intentContainer) } ===================================== mobile/android/fenix/app/src/main/java/org/mozilla/fenix/HomeActivity.kt ===================================== @@ -438,8 +438,6 @@ open class HomeActivity : LocaleAwareAppCompatActivity(), NavHostActivity, Crash } } - private var dialog: RedirectDialogFragment? = null - private val providerStoppedViewModel: ProviderStoppedViewModel by viewModels() private val urlQuickLoadViewModel: UrlQuickLoadViewModel by viewModels() @@ -991,15 +989,9 @@ open class HomeActivity : LocaleAwareAppCompatActivity(), NavHostActivity, Crash // Copied from mozac AppLinksFeature.kt internal fun getOrCreateDialog(): RedirectDialogFragment { - val existingDialog = dialog - if (existingDialog != null) { - return existingDialog - } - SimpleRedirectDialogFragment.newInstance( getString(appLinksR.string.mozac_feature_applinks_normal_confirm_dialog_title), ).also { - dialog = it return it } } View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/738620… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/738620… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 2a398e47 by Pier Angelo Vendrame at 2026-09-21T18:14:54+00:00 fixup! Firefox preference overrides. BB 45080: Disable the reporting API. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -287,6 +287,10 @@ pref("browser.preonboarding.enabled", false); // Disable checkbox in about:neterror that controls // security.xfocsp.errorReporting.automatic. See tor-browser#42653. pref("security.xfocsp.errorReporting.enabled", false); +// tor-browser#45080: disable the reporting API. +pref("dom.reporting.enabled", false); +pref("dom.reporting.header.enabled", false); +pref("dom.reporting.crash.enabled", false); // Added in tor-browser#41496 even though it shuld be already always disabled // since we disable MOZ_CRASHREPORTER. pref("breakpad.reportURL", "data:"); View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/2a3… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/2a3… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! Firefox preference overrides.
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: 73862028 by Pier Angelo Vendrame at 2026-09-21T18:10:47+00:00 fixup! Firefox preference overrides. BB 45080: Disable the reporting API. - - - - - 1 changed file: - browser/app/profile/001-base-profile.js Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -287,6 +287,10 @@ pref("browser.preonboarding.enabled", false); // Disable checkbox in about:neterror that controls // security.xfocsp.errorReporting.automatic. See tor-browser#42653. pref("security.xfocsp.errorReporting.enabled", false); +// tor-browser#45080: disable the reporting API. +pref("dom.reporting.enabled", false); +pref("dom.reporting.header.enabled", false); +pref("dom.reporting.crash.enabled", false); // Added in tor-browser#41496 even though it shuld be already always disabled // since we disable MOZ_CRASHREPORTER. pref("breakpad.reportURL", "data:"); View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/7386202… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/7386202… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] 3 commits: fixup! MB 1: Mullvad Browser branding
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: c48f130d by Beatriz Rizental at 2026-09-21T16:16:09+00:00 fixup! MB 1: Mullvad Browser branding Bug 569: Drop kitty image from default browser dialog - - - - - 75fd6427 by Beatriz Rizental at 2026-09-21T16:16:09+00:00 fixup! MB 1: Mullvad Browser branding Bug 569: Use mullvad Browser logo in sidebar - - - - - 34f8283e by Morgan at 2026-09-21T17:56:32+00:00 fixup! MB 1: Mullvad Browser branding switch hard-coded fill to 'context-fill' so firefox can colour the icon based on theme - - - - - 4 changed files: - browser/components/preferences/main.js - browser/themes/shared/sidebar/firefox.svg - toolkit/content/widgets/moz-promo/moz-promo.css - toolkit/content/widgets/moz-promo/moz-promo.tokens.css Changes: ===================================== browser/components/preferences/main.js ===================================== @@ -620,10 +620,6 @@ function createDefaultBrowserConfig({ id: "isDefaultPane", l10nId: "is-default-browser-2", control: "moz-promo", - controlAttrs: { - imagesrc: "chrome://global/skin/illustrations/kit-happy.svg", - imagedisplay: "cover", - }, }; const isNotDefaultPane = { @@ -642,10 +638,6 @@ function createDefaultBrowserConfig({ }, }, ], - controlAttrs: { - imagesrc: "chrome://global/skin/illustrations/kit-concerned.svg", - imagedisplay: "cover", - }, }; const items = includeIsDefaultPane ===================================== browser/themes/shared/sidebar/firefox.svg ===================================== @@ -1,6 +1,6 @@ <!-- This Source Code Form is subject to the terms of the Mozilla Public - License, v. 2.0. If a copy of the MPL was not distributed with this - file, You can obtain one at http://mozilla.org/MPL/2.0/. --> -<svg width="26" height="26" viewBox="0 0 26 26" fill="context-fill" xmlns="http://www.w3.org/2000/svg"> - <path d="M24.3095 8.8538C23.7791 7.57797 22.7049 6.20058 21.8613 5.76523C22.5478 7.11119 22.9452 8.46136 23.097 9.46901C23.097 9.47099 23.0978 9.47592 23.0994 9.48932C21.7194 6.04976 19.3795 4.66282 17.4687 1.64296C17.3723 1.49026 17.2755 1.33716 17.1813 1.17577C17.1333 1.09335 17.0885 1.00913 17.0469 0.923289C16.9675 0.770024 16.9063 0.60802 16.8645 0.440563C16.8647 0.432635 16.8621 0.424884 16.8569 0.418833C16.8518 0.412782 16.8446 0.408868 16.8367 0.40786C16.8292 0.405713 16.8213 0.405713 16.8138 0.40786C16.8121 0.408469 16.8096 0.410449 16.8077 0.41116C16.805 0.412227 16.8016 0.414664 16.7988 0.416238C16.8002 0.41441 16.803 0.410297 16.8039 0.409332C13.7382 2.20475 12.6982 5.5261 12.6026 7.18782C12.7448 7.17797 12.8866 7.16603 13.0313 7.16603C15.3192 7.16603 17.3117 8.42388 18.3786 10.2883C17.727 9.83052 16.5601 9.37842 15.436 9.57393C19.8256 11.7684 18.6471 19.3252 12.5646 19.04C12.0229 19.0179 11.4876 18.9146 10.9766 18.7337C10.8557 18.6882 10.7362 18.6394 10.6181 18.5871C10.5492 18.5558 10.4804 18.524 10.4124 18.4889C10.4149 18.4906 10.4182 18.4924 10.4207 18.494C10.3611 18.4653 10.3018 18.4358 10.243 18.4054C10.3001 18.4327 10.3537 18.4625 10.4123 18.4887C8.92186 17.7184 7.69123 16.2628 7.53751 14.4951C7.53751 14.4951 8.10083 12.396 11.5712 12.396C11.9463 12.396 13.0189 11.3492 13.0387 11.0456C13.0342 10.9465 10.9101 10.1016 10.0821 9.28574C9.63965 8.84984 9.42957 8.63965 9.24351 8.48198C9.14257 8.39672 9.03704 8.31704 8.92739 8.2433C8.64923 7.27013 8.63741 6.24012 8.89317 5.26082C7.63948 5.83165 6.66438 6.73398 5.95547 7.53074H5.94984C5.46604 6.91796 5.50017 4.89657 5.52774 4.47452C5.52195 4.44837 5.16684 4.65886 5.12032 4.6906C4.69341 4.99532 4.29431 5.33723 3.92768 5.71232C3.51059 6.13547 3.12951 6.59266 2.7884 7.07915C2.7884 7.07975 2.78804 7.08047 2.78784 7.08107C2.78784 7.08041 2.7882 7.07975 2.7884 7.07915C2.00364 8.19123 1.44707 9.44781 1.15086 10.7763C1.14502 10.8027 1.14009 10.8302 1.1344 10.8568C1.11145 10.9643 1.00816 11.5095 0.993738 11.6265C0.992621 11.6354 0.994805 11.6175 0.993738 11.6265C0.899547 12.1899 0.839448 12.7585 0.81377 13.3291C0.81377 13.35 0.8125 13.3706 0.8125 13.3915C0.8125 20.1305 6.27656 25.5937 13.0165 25.5937C19.0526 25.5937 24.0644 21.2119 25.0456 15.4562C25.0663 15.3 25.0828 15.143 25.1011 14.9854C25.3437 12.8927 25.0742 10.6931 24.3095 8.8538ZM23.0989 9.48049C23.0995 9.48481 23.1002 9.48932 23.1009 9.49364L23.1005 9.49232L23.0989 9.48049Z"/> +<svg width="26" height="26" viewBox="0 0 80 80" fill="context-fill" xmlns="http://www.w3.org/2000/svg" > + <path fill-rule="evenodd" clip-rule="evenodd" d="M13.125 8.125C10.3636 8.125 8.125 10.3636 8.125 13.125V66.875C8.125 69.6364 10.3636 71.875 13.125 71.875H66.875C69.6364 71.875 71.875 69.6364 71.875 66.875V13.125C71.875 10.3636 69.6364 8.125 66.875 8.125H13.125ZM17.5 16.875H27L40 41.5L53 16.875H62.5V63.75H53V39.25L46.5 51.625H33.5L27 39.25V63.75H17.5V16.875Z" /> </svg> ===================================== toolkit/content/widgets/moz-promo/moz-promo.css ===================================== @@ -135,6 +135,7 @@ word-break: break-word; margin: 0; align-items: center; + justify-content: space-between; &:has(slot:has-slotted) { gap: var(--space-small); ===================================== toolkit/content/widgets/moz-promo/moz-promo.tokens.css ===================================== @@ -23,7 +23,7 @@ --promo-image-size-large: calc(2 * var(--size-image-xlarge)); --promo-message-text-color: var(--text-color); --promo-message-text-color-vibrant: light-dark(var(--color-violet-80), var(--color-violet-0)); - --promo-padding: var(--space-medium); + --promo-padding: var(--space-medium) var(--space-xlarge); } } View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/38… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/38… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser-bundle-testsuite][main] 2 commits: Bug 40107: Execute xpcshell tests on CI
by brizental (@brizental) 21 Sep '26

21 Sep '26
brizental pushed to branch main at The Tor Project / Applications / tor-browser-bundle-testsuite Commits: ce7fa79b by Beatriz Rizental at 2026-09-16T14:32:16-03:00 Bug 40107: Execute xpcshell tests on CI - - - - - 03eca1fb by Beatriz Rizental at 2026-09-16T16:09:52-03:00 Bug 40107: Pass base-browser as a test tag for all browsers - - - - - 8 changed files: - .gitlab-ci.yml - .gitlab/_base.yml - .gitlab/_inputs.yml - .gitlab/scripts/before_script.py - .gitlab/test_marionette.yml - + .gitlab/test_xpcshell.yml - config/tb-build-06.torproject.org - tools/trigger-test-pipeline.py Changes: ===================================== .gitlab-ci.yml ===================================== @@ -3,6 +3,7 @@ spec: - local: '.gitlab/_inputs.yml' --- stages: + - test-xpcshell - test-marionette default: @@ -17,7 +18,7 @@ include: - local: '.gitlab/_base.yml' inputs: mozharness_url: $[[ inputs.mozharness_url ]] - tag: $[[ inputs.tag ]] + tags: $[[ inputs.tags ]] android_x86_64_installer_url: $[[ inputs.android_x86_64_installer_url ]] android_x86_64_package_name: $[[ inputs.android_x86_64_package_name ]] android_x86_64_artifacts_url: $[[ inputs.android_x86_64_artifacts_url ]] @@ -31,4 +32,5 @@ include: windows_x86_64_installer_url: $[[ inputs.windows_x86_64_installer_url ]] windows_x86_64_artifacts_url: $[[ inputs.windows_x86_64_artifacts_url ]] windows_x86_64_sha256sums_url: $[[ inputs.windows_x86_64_sha256sums_url ]] + - local: '.gitlab/test_xpcshell.yml' - local: '.gitlab/test_marionette.yml' ===================================== .gitlab/_base.yml ===================================== @@ -4,9 +4,10 @@ spec: --- variables: MOZHARNESS_URL: "$[[ inputs.mozharness_url ]]" - TAG: "$[[ inputs.tag ]]" + TAGS: "$[[ inputs.tags ]]" .common: + allow_failure: true before_script: - python3 .gitlab/scripts/before_script.py @@ -16,6 +17,10 @@ variables: .debian-x86_64: extends: .common + before_script: + - Xvfb :99 -screen 0 1280x1024x24 >/dev/null 2>&1 & + - !reference [.common, before_script] + tags: - debian-trixie-x86_64 @@ -25,9 +30,11 @@ variables: - when: never variables: + DISPLAY: ":99" MOZ_FETCHES_DIR: "/home/gitlab-runner/fetches" MINIDUMP_STACKWALK_URL: "https://github.com/rust-minidump/rust-minidump/releases/download/v0.26.1/mi…" MINIDUMP_STACKWALK_SHA256: "f789997f086dab6e46c46ab4560fc28676124613770ddac3b89a6e2e0e4963d8" + NODEJS_PATH: "/home/gitlab-runner/.nvm/versions/node/v22.16.0/bin/node" INSTALLER_URL: "$[[ inputs.debian_x86_64_installer_url ]]" ARTIFACTS_URL: "$[[ inputs.debian_x86_64_artifacts_url ]]" SHA256SUMS_URL: "$[[ inputs.debian_x86_64_sha256sums_url ]]" @@ -35,6 +42,11 @@ variables: .macos-x86_64: extends: .common + # Overwrite just so we can change $PATH + before_script: + - export PATH="/usr/local/bin:$PATH" + - !reference [.common, before_script] + tags: - macos-sonoma-x86_64 @@ -47,6 +59,7 @@ variables: MOZ_FETCHES_DIR: "/Users/gitlab-runner/fetches" MINIDUMP_STACKWALK_URL: "https://github.com/rust-minidump/rust-minidump/releases/download/v0.26.1/mi…" MINIDUMP_STACKWALK_SHA256: "7a3e274a09bc35ccc35e9d3dcd60e738ab14e54ea3306be94a4a8dedaf7a468d" + NODEJS_PATH: "/Users/gitlab-runner/.nvm/versions/node/v22.16.0/bin/node" INSTALLER_URL: "$[[ inputs.macos_x86_64_installer_url ]]" ARTIFACTS_URL: "$[[ inputs.macos_x86_64_artifacts_url ]]" SHA256SUMS_URL: "$[[ inputs.macos_x86_64_sha256sums_url ]]" @@ -66,6 +79,7 @@ variables: MOZ_FETCHES_DIR: 'C:\windoes\fetches' MINIDUMP_STACKWALK_URL: 'https://github.com/rust-minidump/rust-minidump/releases/download/v0.26.1/mi…' MINIDUMP_STACKWALK_SHA256: "dc6da411047ef15b784bffe0f9bf7ecb9221186c4c8fd655e3d8a3fbba0a9c61" + NODEJS_PATH: 'C:\Program Files\nodejs\node.exe' INSTALLER_URL: "$[[ inputs.windows_x86_64_installer_url ]]" ARTIFACTS_URL: "$[[ inputs.windows_x86_64_artifacts_url ]]" SHA256SUMS_URL: "$[[ inputs.windows_x86_64_sha256sums_url ]]" ===================================== .gitlab/_inputs.yml ===================================== @@ -3,10 +3,10 @@ inputs: type: string default: "" description: "Location of the mozharness.zip archive" - tag: + tags: type: string default: "" - description: "Tag used to filter tests" + description: "Space-separated --tag flags (e.g. '--tag foo --tag bar'). Will run all tests if not provided" android_x86_64_installer_url: type: string ===================================== .gitlab/scripts/before_script.py ===================================== @@ -1,5 +1,6 @@ import hashlib import os +import platform import shutil import subprocess import time @@ -32,12 +33,17 @@ def download_file(url: str, dest: Path, sha256: str = "") -> None: def extract_tar(tar_path: Path, dest_dir: Path) -> None: - subprocess.run( + result = subprocess.run( # --strip-components=1: all the archives we fetch have contents nested inside a # top-level directory rather than at the root, so we strip it on extraction. - ["tar", "-xf", str(tar_path), "-C", str(dest_dir), "--strip-components=1"], - check=True, + # + # NOTE: The `v` flag is _required_ for tar to work on MacOS ¯\_(ツ)_/¯ + ["tar", f"-x{'v' if platform.system() == 'Darwin' else ''}f", str(tar_path), "-C", str(dest_dir), "--strip-components=1"], + stderr=subprocess.PIPE, + text=True, ) + if result.returncode != 0: + raise RuntimeError(f"tar failed (exit {result.returncode}):\n{result.stderr}") def check_sha256sums_url(sha256sums_url: str) -> None: @@ -159,6 +165,22 @@ def setup_android_sdk(moz_fetches_dir: str) -> None: print(f"Moved AVD -> {android_device_dir / 'avd'}") + +def download_hostutils(moz_fetches_dir: str) -> None: + # Stable mirror of https://firefox-ci-tc.services.mozilla.com/api/index/v1/task/gecko.cache.le… + HOSTUTILS_URL = "https://build-sources.tbb.torproject.org/hostutils.tar.zst" + HOSTUTILS_SHA256 = ( + "90ff9390181d7dc015c882f11e11800ef03be39f003c29b22bda01ad21c04a9e" + ) + + hostutils_dir = Path(moz_fetches_dir) / "hostutils" + hostutils_dir.mkdir(parents=True, exist_ok=True) + + tar_zst_path = Path("hostutils.tar.zst") + download_file(HOSTUTILS_URL, tar_zst_path, HOSTUTILS_SHA256) + extract_tar(tar_zst_path, hostutils_dir) + + def before_script( mozharness_url: str, minidump_stackwalk_url: str, @@ -175,6 +197,7 @@ def before_script( if setup_android: setup_android_sdk(moz_fetches_dir) + download_hostutils(moz_fetches_dir) if __name__ == "__main__": ===================================== .gitlab/test_marionette.yml ===================================== @@ -1,4 +1,5 @@ -.marionette-desktop: +debian-x86_64_marionette: + extends: .debian-x86_64 stage: test-marionette script: - > @@ -6,23 +7,32 @@ --config-file "$(pwd)/mozharness/configs/marionette/prod_config.py" --installer-url "$INSTALLER_URL" --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" - --tag "$TAG" --headless - -debian-x86_64_marionette: - extends: - - .debian-x86_64 - - .marionette-desktop + $TAGS macos-x86_64_marionette: - extends: - - .macos-x86_64 - - .marionette-desktop + extends: .macos-x86_64 + stage: test-marionette + script: + - > + python3 "$(pwd)/mozharness/scripts/marionette.py" + --config-file "$(pwd)/mozharness/configs/marionette/prod_config.py" + --installer-url "$INSTALLER_URL" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + --headless + $TAGS windows-x86_64_marionette: - extends: - - .windows-x86_64 - - .marionette-desktop + extends: .windows-x86_64 + stage: test-marionette + script: + - > + python3 "$(pwd)/mozharness/scripts/marionette.py" + --config-file "$(pwd)/mozharness/configs/marionette/prod_config.py" + --installer-url "$INSTALLER_URL" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + --headless + ($env:TAGS -split ' ') android-x86_64_marionette: extends: .android-x86_64 @@ -36,4 +46,4 @@ android-x86_64_marionette: --installer-url "$INSTALLER_URL" --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" --package-name "$PACKAGE_NAME" - --tag "$TAG" + $TAGS ===================================== .gitlab/test_xpcshell.yml ===================================== @@ -0,0 +1,50 @@ +debian-x86_64_xpcshell: + extends: .debian-x86_64 + stage: test-xpcshell + script: + - > + python3 "$(pwd)/mozharness/scripts/desktop_unittest.py" + --config-file "$(pwd)/mozharness/configs/unittests/linux_unittest.py" + --xpcshell-suite xpcshell + --installer-url "$INSTALLER_URL" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + $TAGS + +macos-x86_64_xpcshell: + extends: .macos-x86_64 + stage: test-xpcshell + script: + - > + python3 "$(pwd)/mozharness/scripts/desktop_unittest.py" + --config-file "$(pwd)/mozharness/configs/unittests/mac_unittest.py" + --xpcshell-suite xpcshell + --installer-url "$INSTALLER_URL" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + $TAGS + +windows-x86_64_xpcshell: + extends: .windows-x86_64 + stage: test-xpcshell + script: + - > + python3 "$(pwd)/mozharness/scripts/desktop_unittest.py" + --config-file "$(pwd)/mozharness/configs/unittests/win_unittest.py" + --xpcshell-suite xpcshell + --installer-url "$INSTALLER_URL" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + --pip-index + ($env:TAGS -split ' ') + +android-x86_64_xpcshell: + extends: .android-x86_64 + stage: test-xpcshell + script: + - > + python3 "$(pwd)/mozharness/scripts/android_emulator_unittest.py" + --config-file "$(pwd)/mozharness/configs/android/android_common.py" + --config-file "$(pwd)/mozharness/configs/android/android14-x86_64.py" + --test-suite=xpcshell + --installer-url "$ARTIFACTS_URL/test_runner.apk" + --test-packages-url "$ARTIFACTS_URL/target.test_packages.json" + --package-name "$PACKAGE_NAME" + $TAGS ===================================== config/tb-build-06.torproject.org ===================================== @@ -37,13 +37,13 @@ my $test_post = sub { return unless $test->{results} && $test->{results}{success}; return unless $test->{publish_dir}; - my $tag = $test->{name} =~ /^torbrowser/ ? 'tor' : 'mullvad-browser'; + my $browser_tag = $test->{name} =~ /^torbrowser/ ? 'tor' : 'mullvad-browser'; my ($stdout, $stderr, $success) = capture_exec( 'python3', "$FindBin::Bin/tools/trigger-test-pipeline.py", '--step-name', $test->{name}, '--publish-url', $publish_url, '--publish-dir', $test->{publish_dir}, - '--tag', $tag, + '--tags', "$browser_tag,base-browser", ); write_file( "$tbbinfos->{'results-dir'}/$test->{name}.trigger-test-pipeline.stderr.txt", ===================================== tools/trigger-test-pipeline.py ===================================== @@ -35,6 +35,13 @@ def setup_logging() -> None: ) +def comma_separated_list(value): + items = [item.strip() for item in value.split(",") if item.strip()] + if not items: + raise argparse.ArgumentTypeError("must provide at least one tag") + return items + + def parse_args() -> argparse.Namespace: parser = argparse.ArgumentParser( description="Post-build trigger hook for triggering GitLab CI pipelines." @@ -59,9 +66,10 @@ def parse_args() -> argparse.Namespace: help="Subdirectory within the publish URL where build artifacts are located.", ) parser.add_argument( - "--tag", + "--tags", required=False, - help="Tag used to filter tests.", + type=comma_separated_list, + help="Comma separated list of tags used to filter tests. Will run all tests if not provided", ) parser.add_argument( "--dry-run", @@ -71,7 +79,7 @@ def parse_args() -> argparse.Namespace: return parser.parse_args() -def build_inputs(step_name: str, publish_url: str, publish_dir: str, tag: str) -> dict[str, str] | None: +def build_inputs(step_name: str, publish_url: str, publish_dir: str, tags: list[str] | None) -> dict[str, str] | None: # Add the architecture as padding, to address the macos case which doesn't # have architecture in the step name since it is a universal build. browser, channel, platform, architecture = (step_name.split("-") + ["x86_64"])[:4] @@ -116,8 +124,8 @@ def build_inputs(step_name: str, publish_url: str, publish_dir: str, tag: str) - if platform == "android": inputs[f"{input_prefix}_package_name"] = f"org.torproject.{browser}_{channel}" - if tag: - inputs["tag"] = tag + if tags: + inputs["tags"] = " ".join(f"--tag {tag}" for tag in tags) return inputs @@ -157,7 +165,7 @@ def main() -> int: with open(token_file) as f: trigger_token = f.read().strip() - inputs = build_inputs(args.step_name, args.publish_url, args.publish_dir, args.tag) + inputs = build_inputs(args.step_name, args.publish_url, args.publish_dir, args.tags) if inputs is None: logger.info(f"No CI inputs for step {args.step_name!r}, skipping.") return 0 View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-bundle-testsuite… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-bundle-testsuite… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! BB 43243: Modify mozharness scripts for Base Browser
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 380e6bbd by Beatriz Rizental at 2026-09-21T16:14:44+00:00 fixup! BB 43243: Modify mozharness scripts for Base Browser Bug 45334: Haver marionette harness accept multiple tags - - - - - 1 changed file: - testing/mozharness/scripts/marionette.py Changes: ===================================== testing/mozharness/scripts/marionette.py ===================================== @@ -82,10 +82,11 @@ class MarionetteTest(TestingMixin, MercurialScript, TransferMixin, CodeCoverageM [ ["--tag"], { - "action": "store", - "dest": "test_tag", - "default": "", - "help": "Tag that identifies how to filter which tests to run.", + "action": "append", + "default": [], + "dest": "test_tags", + "help": "Filter out tests that don't have the given tag. Can be used multiple " + "times in which case the test must contain at least one of the given tags.", }, ], [ @@ -345,8 +346,8 @@ class MarionetteTest(TestingMixin, MercurialScript, TransferMixin, CodeCoverageM cmd = [python, "-u", os.path.join(dirs["abs_marionette_dir"], "runtests.py")] - if self.config.get("test_tag", ""): - cmd.extend(["--tag", self.config["test_tag"]]) + if self.config["test_tags"]: + cmd.extend([f"--tag={t}" for t in self.config["test_tags"]]) manifest = os.path.join( dirs["abs_marionette_tests_dir"], self.config["test_manifest"] View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/380… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/380… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] fixup! BB 43243: Modify mozharness scripts for Base Browser
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: 725526ac by Beatriz Rizental at 2026-09-21T16:10:01+00:00 fixup! BB 43243: Modify mozharness scripts for Base Browser Bug 45334: Haver marionette harness accept multiple tags - - - - - 1 changed file: - testing/mozharness/scripts/marionette.py Changes: ===================================== testing/mozharness/scripts/marionette.py ===================================== @@ -82,10 +82,11 @@ class MarionetteTest(TestingMixin, MercurialScript, TransferMixin, CodeCoverageM [ ["--tag"], { - "action": "store", - "dest": "test_tag", - "default": "", - "help": "Tag that identifies how to filter which tests to run.", + "action": "append", + "default": [], + "dest": "test_tags", + "help": "Filter out tests that don't have the given tag. Can be used multiple " + "times in which case the test must contain at least one of the given tags.", }, ], [ @@ -345,8 +346,8 @@ class MarionetteTest(TestingMixin, MercurialScript, TransferMixin, CodeCoverageM cmd = [python, "-u", os.path.join(dirs["abs_marionette_dir"], "runtests.py")] - if self.config.get("test_tag", ""): - cmd.extend(["--tag", self.config["test_tag"]]) + if self.config["test_tags"]: + cmd.extend([f"--tag={t}" for t in self.config["test_tags"]]) manifest = os.path.join( dirs["abs_marionette_tests_dir"], self.config["test_manifest"] View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/725526a… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/commit/725526a… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/tor-browser] Pushed new branch tor-browser-156.0a1-17.0-1
by jwilde (@jwilde) 21 Sep '26

21 Sep '26
jwilde pushed new branch tor-browser-156.0a1-17.0-1 at The Tor Project / Applications / Tor Browser -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/tree/tor-brows… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
[Git][tpo/applications/mullvad-browser][mullvad-browser-153.3.0esr-16.0-1] fixup! MB 1: Mullvad Browser branding
by morgan (@morgan) 21 Sep '26

21 Sep '26
morgan pushed to branch mullvad-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Mullvad Browser Commits: 4a0212ee by Morgan at 2026-09-21T13:53:35+00:00 fixup! MB 1: Mullvad Browser branding MB 580: Migrate hiding feedbackPage menuitem to Mullvad Browser patchset - - - - - 1 changed file: - browser/base/content/browser-menubar.inc.xhtml Changes: ===================================== browser/base/content/browser-menubar.inc.xhtml ===================================== @@ -460,6 +460,7 @@ hidden="true" appmenu-data-l10n-id="appmenuitem-report-broken-site"/> <menuitem id="feedbackPage" + hidden="true" data-l10n-id="menu-help-share-ideas" appmenu-data-l10n-id="appmenu-help-share-ideas"/> <menuitem id="helpSafeMode" View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/4a0… -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/commit/4a0… You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1 0
0 0
  • ← Newer
  • 1
  • ...
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • ...
  • 2117
  • Older →

HyperKitty Powered by HyperKitty version 1.3.12.