brizental pushed to branch tor-browser-153.4.0esr-16.0-1 at The Tor Project / Applications / Tor Browser Commits: bf38c314 by Beatriz Rizental at 2026-09-30T18:02:26+02:00 fixup! BB 45120: Add tests for Base Browser Bug 44820: Disable HTTPS-only mode when running mochitests - - - - - 8d3f622b by Beatriz Rizental at 2026-09-30T18:02:26+02:00 fixup! TB 43817: Add tests for Tor Browser Bug 44820: Modify mochi runtests scripts to work in Tor Browser. - - - - - 88ee7239 by Beatriz Rizental at 2026-09-30T18:02:26+02:00 fixup! TB3: Tor Browser's official .mozconfigs. Bug 44820: Make TOR_BROWSER config is available to gradle - - - - - 97193106 by Beatriz Rizental at 2026-09-30T18:02:26+02:00 fixup! BB 45120: Add tests for Base Browser Bug 44820: Upstream geckoiew's own manifest requests ACCESS_NETWORK_STATE. Tor Browser comments that line out so geckoview doesn't ask for network-state access, but the test app needs it. So we add it back. - - - - - b06b7fca by Beatriz Rizental at 2026-09-30T18:02:26+02:00 fixup! Firefox preference overrides. Bug 44820: Add note about prefs modified for mochitests - - - - - 6 changed files: - browser/app/profile/001-base-profile.js - mobile/android/test_runner/src/main/AndroidManifest.xml - moz.configure - testing/mochitest/mochitest_options.py - testing/mochitest/runtests.py - testing/mochitest/runtestsremote.py Changes: ===================================== browser/app/profile/001-base-profile.js ===================================== @@ -57,6 +57,7 @@ pref("browser.disableResetPrompt", true); pref("browser.privatebrowsing.autostart", true); pref("browser.cache.disk.enable", false); pref("permissions.memory_only", true); +// Note: toggled for mochitests (see testing/mochitest/runtests.py). pref("security.nocertdb", true); // tor-browser#42094: do not collect stats about WebRTC. @@ -171,9 +172,13 @@ pref("clipboard.imageAsFile.enabled", false); pref("clipboard.copyPrivateDataToClipboardCloudOrHistory", false); // Enable HTTPS-Only mode (tor-browser#19850) +// +// Note: toggled for mochitests (see testing/mochitest/runtests.py). pref("dom.security.https_only_mode", true); // The previous pref automatically sets this to true (see StaticPrefList.yaml), // but set it anyway only as a defense-in-depth. +// +// Note: toggled for mochitests (see testing/mochitest/runtests.py). pref("dom.security.https_only_mode_pbm", true); // tor-browser#43197, defense in depth if ever https-only got disabled pref("dom.security.https_first_add_exception_on_failure", false); ===================================== mobile/android/test_runner/src/main/AndroidManifest.xml ===================================== @@ -11,6 +11,7 @@ <uses-permission android:name="android.permission.CAMERA"/> <uses-permission android:name="android.permission.FOREGROUND_SERVICE"/> <uses-permission android:name="android.permission.ACCESS_WIFI_STATE"/> + <uses-permission android:name="android.permission.ACCESS_NETWORK_STATE"/> <application android:allowBackup="true" ===================================== moz.configure ===================================== @@ -1019,6 +1019,7 @@ set_define("BASE_BROWSER_VERSION_QUOTED", base_browser_version_quoted) # We always want Tor Browser to be defined. Since we do not need any # value for it, just always set it to True. set_define("TOR_BROWSER", True) +set_config("TOR_BROWSER", True) # Please do not add configure checks from here on. ===================================== testing/mochitest/mochitest_options.py ===================================== @@ -7,7 +7,7 @@ import os import sys import tempfile from abc import ABCMeta, abstractmethod, abstractproperty -from argparse import SUPPRESS, ArgumentParser +from argparse import SUPPRESS, ArgumentParser, BooleanOptionalAction from itertools import chain from shutil import which from urllib.parse import urlparse @@ -163,6 +163,20 @@ class MochitestArguments(ArgumentContainer): "help": "Only run tests of this flavor.", }, ], + [ + ["--tor-bootstrap"], + { + "action": BooleanOptionalAction, + "dest": "torBootstrap", + "default": True, + "help": "Wait for the Tor connection to finish bootstrapping " + "before loading the first test. The prefs/env needed for " + "mochitest content to load at all in Tor Browser (disabling " + "HTTPS-Only, TorDomainIsolator's non-Tor-proxy exemption, " + "and the mock TorProvider) are applied regardless of this " + "flag. Pass --no-tor-bootstrap to skip the wait.", + }, + ], [ ["--keep-open"], { ===================================== testing/mochitest/runtests.py ===================================== @@ -2136,6 +2136,11 @@ toolbar#nav-bar { # via the commandline at your own risk. browserEnv["XPCOM_DEBUG_BREAK"] = "stack" + # Default to the mock Tor provider so mochitest runs + # don't depend on a real tor daemon/network. + # --setenv TOR_PROVIDER=... below can still override this. + browserEnv.setdefault("TOR_PROVIDER", "mock") + # interpolate environment passed with options try: browserEnv.update( @@ -2604,6 +2609,23 @@ toolbar#nav-bar { if getattr(self, "testRootAbs", None): prefs["mochitest.testRoot"] = self.testRootAbs + # 001-base-profile.js forces HTTPS-Only mode on, which upgrades + # requests to the (plain http) mochitest web server and breaks test + # content loading. Unlike a real Tor Browser install, that hardening + # has nothing to do with what these tests exercise, and it applies + # regardless of whether --tor-bootstrap is used. + prefs["dom.security.https_only_mode"] = False + prefs["dom.security.https_only_mode_pbm"] = False + + # 001-base-profile.js sets security.nocertdb, so NSS never loads the + # on-disk cert DB that fillCertificateDB() populates with mochitest's + # test CA, and any HTTPS test content would fail with an + # untrusted-issuer error. Persisting a cert DB is exactly what + # nocertdb exists to prevent in a real Tor Browser profile for + # privacy, but that doesn't apply here: this profile is thrown away + # after the run, so there's nothing to leak. + prefs["security.nocertdb"] = False + # See if we should use fake media devices. if options.useTestMediaDevices: prefs["media.audio_loopback_dev"] = self.mediaDevices["audio"]["name"] ===================================== testing/mochitest/runtestsremote.py ===================================== @@ -352,11 +352,16 @@ class MochiRemote(MochitestDesktop): runFailures=False, crashAsPass=False, currentManifest=None, + torBootstrap=False, ): """ Run the app, log the duration it took to execute, return the status code. Kill the app if it outputs nothing for |timeout| seconds. """ + # torBootstrap is accepted for signature compatibility with the + # shared doTests() call site, but not implemented here: unlike + # MochitestDesktop.runApp, this launches the app via adb/activity + # rather than a Marionette session, so there's nothing to wait on. if timeout == -1: timeout = self.DEFAULT_TIMEOUT View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/efe05ef... -- View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/efe05ef... You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
participants (1)
-
brizental (@brizental)