morgan pushed to branch main at The Tor Project / Applications / tor-browser-build Commits: 55e25c58 by Morgan at 2026-08-26T15:07:52+00:00 Bug 41840,41841: Prepare Tor, Mullvad Browser 16.0a10 - - - - - 10 changed files: - projects/browser/Bundle-Data/Docs-MB/ChangeLog.txt - projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt - projects/browser/config - projects/firefox/config - projects/geckoview/config - projects/go/config - projects/manual/config - projects/openssl/config - projects/translation/config - rbm.conf Changes: ===================================== projects/browser/Bundle-Data/Docs-MB/ChangeLog.txt ===================================== @@ -1,3 +1,53 @@ +Mullvad Browser 16.0a10 - August 27 2026 + * All Platforms + * Updated Firefox to 153.1.0esr + * Updated NoScript to 13.6.31.90301984 + * Updated uBlock Origin to 1.74.0 + * Bug 446: Implement persistent-mode backend [mullvad-browser] + * Bug 535: Use config to hide settings in mullvad browser [mullvad-browser] + * Bug 565: Update the selector to hide the help button in about:addons [mullvad-browser] + * Bug 566: The security level learn mode link is wrong in Mullvad Browser [mullvad-browser] + * Bug 571: Rebase Mullvad Browser alpha onto 153.1.0esr [mullvad-browser] + * Bug 572: Websites can initiate a WebSocket connection to a lan/localhost port [mullvad-browser] + * Bug 43640: Poor screen reader experience when opening preferences and scrolling to element [tor-browser] + * Bug 44257: Disable locale-based font rules as a defense-in-depth [tor-browser] + * Bug 44511: Make sure new search suggest features are disabled for 16.0 [tor-browser] + * Bug 44629: Add a search suggestion warning in the settings [tor-browser] + * Bug 44699: Amend commit message for "BB 43322: Customize the font visibility lists" [tor-browser] + * Bug 44802: Hide the "safe browsing" settings [tor-browser] + * Bug 44830: Migrate our home page adjustments to the settings config [tor-browser] + * Bug 45039: Make it easier to test ProfileDataUpgrader customization [tor-browser] + * Bug 45079: Move letterboxing to the appearance setting pane [tor-browser] + * Bug 45123: Disable profile backup for 16.0 [tor-browser] + * Bug 45157: Grant "access local files" permission to NoScript (Firefox 153 and above) [tor-browser] + * Bug 45168: Hide the history search option, again [tor-browser] + * Bug 45169: Cannot open history sidebar in private browsing window [tor-browser] + * Bug 45171: Disable split view for 16.0 [tor-browser] + * Bug 45176: Add "Request English" to the website language config [tor-browser] + * Bug 45185: Disable network also in the Rust implementation of the remote settings client [tor-browser] + * Bug 45186: Remove duplicate alert roles in moz-message-bar [tor-browser] + * Bug 45187: Disable private browsing "delete downloaded files" feature [tor-browser] + * Bug 45195: Modify our calls to openPreferences to work with the new settings [tor-browser] + * Bug 45201: Convert security level settings to the new config [tor-browser] + * Bug 45208: Switch on the setting redesign [tor-browser] + * Bug 45209: Remove mention of "sync" from new settings [tor-browser] + * Bug 45211: Add settings for protections from third party applications [tor-browser] + * Bug 45219: Backport Security Fixes from Firefox 154 [tor-browser] + * Bug 45228: Drop browser.urlbar.update2.engineAliasRefresh [tor-browser] + * Bug 45232: Spoof picture-in-picture sizes under RFP [tor-browser] + * Bug 45245: Fix a ML file inclusion that creates an error [tor-browser] + * Windows + * Bug 563: Hide the fox icon in about:pdf [mullvad-browser] + * Bug 44513: Backport Bugzilla 2059471: Do not spoof screen orientation when it is locked [tor-browser] + * Bug 45144: Do not offer to make the browser a PDF viewer when in portable mode [tor-browser] + * Bug 45243: Disable taskbar tabs [tor-browser] + * Build System + * All Platforms + * Bug 45224: Enable Rust linter in CI [tor-browser] + * Bug 45231: Backport Bugzilla 2053518: Rust target detection fails to translate the host triple with rustc nightly >= 2026-07-02 (new *-oe-linux-* targets) [tor-browser] + * Bug 41844: Add scripts to backup/deploy signing keys on signing machines [tor-browser-build] + * Bug 41850: Update keyring/torbrowser.gpg for new subkey and updated expiration date of the main key [tor-browser-build] + Mullvad Browser 16.0a9 - July 23 2026 * All Platforms * Updated Firefox to 153.0esr ===================================== projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt ===================================== @@ -1,3 +1,105 @@ +Tor Browser 16.0a10 - August 27 2026 + * All Platforms + * Updated NoScript to 13.6.31.90301984 + * Updated OpenSSL to 3.5.8 + * Bug 44257: Disable locale-based font rules as a defense-in-depth [tor-browser] + * Bug 45161: Drop TorProviderBuilder.firstWindowLoaded [tor-browser] + * Bug 45205: Rebase Tor Browser onto 153.1.0esr [tor-browser] + * Bug 45219: Backport Security Fixes from Firefox 154 [tor-browser] + * Windows + macOS + Linux + * Updated Firefox to 153.1.0esr + * Bug 43570: Report errors in about:torconnect when tor daemon crashes (Desktop) [tor-browser] + * Bug 43640: Poor screen reader experience when opening preferences and scrolling to element [tor-browser] + * Bug 43939: Update Bridge settings when connection failed [tor-browser] + * Bug 44247: Adapt Tor Browser manual to use the new support pages [tor-browser] + * Bug 44511: Make sure new search suggest features are disabled for 16.0 [tor-browser] + * Bug 44629: Add a search suggestion warning in the settings [tor-browser] + * Bug 44699: Amend commit message for "BB 43322: Customize the font visibility lists" [tor-browser] + * Bug 44802: Hide the "safe browsing" settings [tor-browser] + * Bug 44830: Migrate our home page adjustments to the settings config [tor-browser] + * Bug 44831: Misleading banner in "Search engine suggestions" settings [tor-browser] + * Bug 44855: Use `ariaNotify` for bridge updates [tor-browser] + * Bug 44959: Integrate the new Tor Browser manual into Tor Browser [tor-browser] + * Bug 44998: Remove Firefox branding from about:preferences [tor-browser] + * Bug 45039: Make it easier to test ProfileDataUpgrader customization [tor-browser] + * Bug 45051: Show a separate Tor error prompt for users who do not see about:torconnect (desktop) [tor-browser] + * Bug 45058: Convert bridge settings to new design and config approach [tor-browser] + * Bug 45059: Convert advanced connection settings to new design and config approach [tor-browser] + * Bug 45079: Move letterboxing to the appearance setting pane [tor-browser] + * Bug 45123: Disable profile backup for 16.0 [tor-browser] + * Bug 45125: Tidy up bridge emoji widget [tor-browser] + * Bug 45143: Modify moz-fieldset to allow focusing the heading [tor-browser] + * Bug 45156: Remove "Firefox Home" from the appearance settings [tor-browser] + * Bug 45157: Grant "access local files" permission to NoScript (Firefox 153 and above) [tor-browser] + * Bug 45168: Hide the history search option, again [tor-browser] + * Bug 45169: Cannot open history sidebar in private browsing window [tor-browser] + * Bug 45171: Disable split view for 16.0 [tor-browser] + * Bug 45176: Add "Request English" to the website language config [tor-browser] + * Bug 45178: Change support URLs in new settings [tor-browser] + * Bug 45179: Update the feedback URL to point to the new support page. [tor-browser] + * Bug 45180: Also show download warning in download settings [tor-browser] + * Bug 45185: Disable network also in the Rust implementation of the remote settings client [tor-browser] + * Bug 45186: Remove duplicate alert roles in moz-message-bar [tor-browser] + * Bug 45187: Disable private browsing "delete downloaded files" feature [tor-browser] + * Bug 45190: New circuit urlbar icon button is squished [tor-browser] + * Bug 45192: Some URLs trigger `The proxy server is refusing connections` rather than about:torconnect prior to bootstrap [tor-browser] + * Bug 45194: "Your bridges" background color [tor-browser] + * Bug 45195: Modify our calls to openPreferences to work with the new settings [tor-browser] + * Bug 45196: Replace old connection settings with setting-group widgets [tor-browser] + * Bug 45197: Hide password settings by default [tor-browser] + * Bug 45200: Include onion authentication in the new password settings [tor-browser] + * Bug 45201: Convert security level settings to the new config [tor-browser] + * Bug 45208: Switch on the setting redesign [tor-browser] + * Bug 45209: Remove mention of "sync" from new settings [tor-browser] + * Bug 45211: Add settings for protections from third party applications [tor-browser] + * Bug 45214: Keep megalist (contextual password manager) disabled for 16.0 [tor-browser] + * Bug 45220: about:torconnect doesn't show when launching the browser in non-PBM [tor-browser] + * Bug 45226: Stylelint issues on browser/components/torpreferences/content/torPreferences.css [tor-browser] + * Bug 45228: Drop browser.urlbar.update2.engineAliasRefresh [tor-browser] + * Bug 45232: Spoof picture-in-picture sizes under RFP [tor-browser] + * Bug 45236: Resolve miscellaneus accessibility issues in about:torconnect [tor-browser] + * Bug 45245: Fix a ML file inclusion that creates an error [tor-browser] + * Windows + Android + * Bug 44513: Backport Bugzilla 2059471: Do not spoof screen orientation when it is locked [tor-browser] + * Windows + * Bug 45144: Do not offer to make the browser a PDF viewer when in portable mode [tor-browser] + * Bug 45243: Disable taskbar tabs [tor-browser] + * macOS + * Bug 45163: Consistently do not disable app group container support [tor-browser] + * Android + * Updated GeckoView to 153.1.0esr + * Bug 41758: Don't allow PDFs to be opened by 3rd party apps [tor-browser] + * Bug 43571: Implement improved error handling and tor restart flow (Android) [tor-browser] + * Bug 44054: Review Mozilla 1970806: [Download v2] Implement new UI for External Download Manager dialog [tor-browser] + * Bug 44210: Consider dropping shouldDisableNormalMode setting [tor-browser] + * Bug 44448: Trivialise assets rather than delete them in "[android] Delete unused media" [tor-browser] + * Bug 44758: Disable email mask feature [tor-browser] + * Bug 44881: Remove link sharing setting on android [tor-browser] + * Bug 44921: Disable Google Lens feature [tor-browser] + * Bug 45049: Opening a pdf from outside TBA crashes TBA after bootstrapping it not already bootstrapped [tor-browser] + * Bug 45085: Disable GooglePlay Integrity [tor-browser] + * Bug 45098: Share link button shows in landscape mode on android despite being removed elsewhere [tor-browser] + * Bug 45115: Padlock always shows insecure even for HTTPS and Onion sites [tor-browser] + * Bug 45159: Fix Android Padlock security pane colors [tor-browser] + * Bug 45170: Tab Switcher shows Firefox's private browsing mask badge on tab switcher icon [tor-browser] + * Bug 45173: Disable Search Optimizations for android [tor-browser] + * Bug 45203: Rebase error with: TB 40041: [android] Implement Tor Network Settings [tor-browser] + * Bug 45221: Remove "Manage downloads with another app" setting from TBA download settings [tor-browser] + * Bug 45227: Remove "Default search engine for Standard Mode" [tor-browser] + * Bug 45234: Do not spoof secondary screen orientations if they were requested by a lock [tor-browser] + * Build System + * All Platforms + * Bug 45224: Enable Rust linter in CI [tor-browser] + * Bug 45231: Backport Bugzilla 2053518: Rust target detection fails to translate the host triple with rustc nightly >= 2026-07-02 (new *-oe-linux-* targets) [tor-browser] + * Bug 41844: Add scripts to backup/deploy signing keys on signing machines [tor-browser-build] + * Bug 41850: Update keyring/torbrowser.gpg for new subkey and updated expiration date of the main key [tor-browser-build] + * Windows + macOS + Linux + * Bug 41711: Update our manual machinery for its new home [tor-browser-build] + * Windows + Linux + Android + * Updated Go to 1.26.7 + * Android + * Bug 41843: Remove unused universal apk from geckoview [tor-browser-build] + Tor Browser 16.0a9 - July 23 2026 * All Platforms * Updated NoScript to 13.6.30.90201984 ===================================== projects/browser/config ===================================== @@ -87,12 +87,12 @@ input_files: enable: '[% !c("var/android") %]' - filename: dmg-root enable: '[% c("var/macos") %]' - - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.30.90201984.xp... + - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.31.90301984.xp... name: noscript - sha256sum: ef7b48702916f86d44f0578fcc18dcd4ed4a013481abafca96891e10af1bcf85 - - URL: https://addons.mozilla.org/firefox/downloads/file/4888680/ublock_origin-1.72... + sha256sum: 37026b2449ed18e4f85dea3d870e43c5813db144334f98fd61220f698a351163 + - URL: https://addons.mozilla.org/firefox/downloads/file/4981431/ublock_origin-1.74... name: ublock-origin - sha256sum: 40c315b0da7871868155ecfae7a50a58dfa0920aebd865e008214986f1b7c578 + sha256sum: 175756d74468c9ba45863f7fc333d3be670f82d5b066314e915814dd547d1652 enable: '[% c("var/mullvad-browser") %]' - URL: https://cdn.mullvad.net/browser-extension/0.9.10/mullvad-browser-extension-0... name: mullvad-extension ===================================== projects/firefox/config ===================================== @@ -23,7 +23,7 @@ var: browser_series: '16.0' browser_rebase: 1 browser_branch: '[% c("var/browser_series") %]-[% c("var/browser_rebase") %]' - browser_build: 1 + browser_build: 4 upstream_firefox_commit: FIREFOX_NIGHTLY_153_END copyright_year: '[% exec("git show -s --format=%ci " _ c("git_hash") _ "^{commit}", { exec_noco => 1 }).remove("-.*") %]' nightly_updates_publish_dir: '[% c("var/nightly_updates_publish_dir_prefix") %]nightly-[% c("var/osname") %]' @@ -114,6 +114,7 @@ targets: updater_url: 'https://cdn.mullvad.net/browser/update_responses/update_1/' mar_id_prefix: 'mullvadbrowser-mullvad' nightly_updates_publish_dir_prefix: mullvadbrowser- + browser_build: 3 linux-x86_64: var: arch_deps: ===================================== projects/geckoview/config ===================================== @@ -26,7 +26,7 @@ var: browser_series: '16.0' browser_rebase: 1 browser_branch: '[% c("var/browser_series") %]-[% c("var/browser_rebase") %]' - browser_build: 1 + browser_build: 4 gitlab_project: https://gitlab.torproject.org/tpo/applications/tor-browser git_commit: '[% exec("git rev-parse " _ c("git_hash") _ "^{commit}", { exec_noco => 1 }) %]' deps: ===================================== projects/go/config ===================================== @@ -1,11 +1,11 @@ # vim: filetype=yaml sw=2 -version: '1.26.5' +version: '1.26.7' filename: '[% project %]-[% c("version") %]-[% c("var/osname") %]-[% c("var/build_id") %].tar.[% c("compress_tar") %]' container: use_container: 1 var: - source_sha256: 495be4bc87176ac567392e5b4116abd98466d33d7b49d41e764ccc6976b2dc42 + source_sha256: 0ed24eac755105085b89fe9cabc2742b91a0ad7b94b59d3ad364918ebc8956ad no_crosscompile: 1 setup: | mkdir -p /var/tmp/dist ===================================== projects/manual/config ===================================== @@ -1,7 +1,7 @@ # vim: filetype=yaml sw=2 # To update, see doc/how-to-update-the-manual.txt # Remember to update also the package's hash, with the version! -version: 402523 +version: 415198 filename: 'manual-[% c("version") %]-[% c("var/build_id") %].tar.[% c("compress_tar") %]' container: use_container: 1 @@ -23,6 +23,6 @@ input_files: - project: container-image - URL: 'https://build-sources.tbb.torproject.org/marble-support_[% c("version") %].zip' name: manual - sha256sum: e0f09c869719bf9dc0ae2761f121cae7cd9b5324f817f2cc0a5861c58442f3ff + sha256sum: c5223af6931d03be5b5e17e9be3d64c4223008a591a3acd3d553f86c6bd8df37 - filename: package_marble_build_artifacts.py name: package_script ===================================== projects/openssl/config ===================================== @@ -1,5 +1,5 @@ # vim: filetype=yaml sw=2 -version: 3.5.7 +version: 3.5.8 filename: '[% project %]-[% c("version") %]-[% c("var/osname") %]-[% c("var/build_id") %].tar.[% c("compress_tar") %]' container: use_container: 1 @@ -41,5 +41,5 @@ input_files: - name: '[% c("var/compiler") %]' project: '[% c("var/compiler") %]' - URL: 'https://github.com/openssl/openssl/releases/download/openssl-[% c("version") %]/openssl-[% c("version") %].tar.gz' - sha256sum: a8c0d28a529ca480f9f36cf5792e2cd21984552a3c8e4aa11a24aa31aeac98e8 + sha256sum: a8f84a39918ec6415ce765d9b429d313ba97b8143169c172e734b9514464f5b2 name: openssl ===================================== projects/translation/config ===================================== @@ -12,13 +12,13 @@ compress_tar: 'gz' steps: base-browser: base-browser: '[% INCLUDE build %]' - git_hash: 7bd0a8e7226bbf29f16d477ff92d0024b1d48a7c + git_hash: 1ebbe4b676d03428a8091e9ce6c64e5f0046b0f9 targets: nightly: git_hash: 'base-browser' tor-browser: tor-browser: '[% INCLUDE build %]' - git_hash: 43635f68f04d7e5645e5b28bbab7cd7f0fc2ffa5 + git_hash: ea6fbf3c7c1e2ded1613285560d927806dd82337 targets: nightly: git_hash: 'tor-browser' @@ -32,7 +32,7 @@ steps: fenix: '[% INCLUDE build %]' # We need to bump the commit before releasing but just pointing to a branch # might cause too much rebuidling of the Firefox part. - git_hash: f3757f734f6d08ff5aecc18f9f4b05e35c9bcbc4 + git_hash: 0a527bd20d6649a5dc6d648aa355e884b80654a9 compress_tar: 'zst' targets: nightly: ===================================== rbm.conf ===================================== @@ -81,11 +81,11 @@ buildconf: git_signtag_opt: '-s' var: - torbrowser_version: '16.0a9' + torbrowser_version: '16.0a10' torbrowser_build: 'build1' # This should be the date of when the build is started. For the build # to be reproducible, browser_release_date should always be in the past. - browser_release_date: '2026/07/22 13:30:00' + browser_release_date: '2026/08/26 14:53:16' browser_release_date_timestamp: '[% USE date; date.format(c("var/browser_release_date"), "%s") %]' browser_default_channel: alpha browser_platforms: @@ -131,9 +131,9 @@ var: updater_enabled: 1 build_mar: 1 torbrowser_incremental_from: + - 16.0a9 - 16.0a8 - 16.0a7 - - 16.0a6 mar_channel_id: '[% c("var/projectname") %]-torproject-[% c("var/channel") %]' # By default, we sort the list of installed packages. This allows sharing View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/55... -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/55... You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
participants (1)
-
morgan (@morgan)