tor-commits
Threads by month
- ----- 2026 -----
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- 1 participants
- 215539 discussions
[Git][tpo/applications/mullvad-browser-update-responses][main] 4 commits: release: new version, 15.0.18 (linux-x86_64)
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed to branch main at The Tor Project / Applications / mullvad-browser-update-responses
Commits:
45c15b48 by hackademix at 2026-07-14T12:49:05+02:00
release: new version, 15.0.18 (linux-x86_64)
- - - - -
99b7f99c by hackademix at 2026-07-14T12:49:05+02:00
release: new version, 15.0.18 (macos)
- - - - -
c5facc60 by hackademix at 2026-07-14T12:49:05+02:00
release: new version, 15.0.18 (windows-x86_64)
- - - - -
4d041152 by hackademix at 2026-07-14T12:49:05+02:00
release: new version, 15.0.18
- - - - -
31 changed files:
- update_1/release/download-linux-x86_64.json
- update_1/release/download-macos.json
- update_1/release/download-windows-x86_64.json
- update_1/release/downloads.json
- update_1/release/linux-x86_64/.htaccess
- − update_1/release/linux-x86_64/update-15.0.11-15.0.16-linux-x86_64.xml
- − update_1/release/linux-x86_64/update-15.0.12-15.0.16-linux-x86_64.xml
- + update_1/release/linux-x86_64/update-15.0.12-15.0.18-linux-x86_64.xml
- − update_1/release/linux-x86_64/update-15.0.14-15.0.16-linux-x86_64.xml
- + update_1/release/linux-x86_64/update-15.0.14-15.0.18-linux-x86_64.xml
- + update_1/release/linux-x86_64/update-15.0.16-15.0.18-linux-x86_64.xml
- − update_1/release/linux-x86_64/update-15.0.16-linux-x86_64.xml
- + update_1/release/linux-x86_64/update-15.0.18-linux-x86_64.xml
- update_1/release/macos/.htaccess
- − update_1/release/macos/update-15.0.11-15.0.16-macos.xml
- − update_1/release/macos/update-15.0.12-15.0.16-macos.xml
- + update_1/release/macos/update-15.0.12-15.0.18-macos.xml
- − update_1/release/macos/update-15.0.14-15.0.16-macos.xml
- + update_1/release/macos/update-15.0.14-15.0.18-macos.xml
- + update_1/release/macos/update-15.0.16-15.0.18-macos.xml
- − update_1/release/macos/update-15.0.16-macos.xml
- + update_1/release/macos/update-15.0.18-macos.xml
- update_1/release/windows-x86_64/.htaccess
- − update_1/release/windows-x86_64/update-15.0.11-15.0.16-windows-x86_64.xml
- − update_1/release/windows-x86_64/update-15.0.12-15.0.16-windows-x86_64.xml
- + update_1/release/windows-x86_64/update-15.0.12-15.0.18-windows-x86_64.xml
- − update_1/release/windows-x86_64/update-15.0.14-15.0.16-windows-x86_64.xml
- + update_1/release/windows-x86_64/update-15.0.14-15.0.18-windows-x86_64.xml
- + update_1/release/windows-x86_64/update-15.0.16-15.0.18-windows-x86_64.xml
- − update_1/release/windows-x86_64/update-15.0.16-windows-x86_64.xml
- + update_1/release/windows-x86_64/update-15.0.18-windows-x86_64.xml
The diff was not included because it is too large.
View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser-update-respo…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser-update-respo…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser-build][maint-15.0] Bug 41819: Update windows-rs URL
by boklm (@boklm) 14 Jul '26
by boklm (@boklm) 14 Jul '26
14 Jul '26
boklm pushed to branch maint-15.0 at The Tor Project / Applications / tor-browser-build
Commits:
c2817c90 by Nicolas Vigier at 2026-07-14T11:39:59+02:00
Bug 41819: Update windows-rs URL
The URL we had now returns this error:
We are unable to process your request at this time. This usually means
that you are in violation of our API data access policy
(https://crates.io/data-access)
According to https://crates.io/data-access we can use
https://static.crates.io/ instead.
We also update the filename to use the correct extension.
- - - - -
1 changed file:
- projects/firefox/config
Changes:
=====================================
projects/firefox/config
=====================================
@@ -223,9 +223,9 @@ input_files:
enable: '[% c("var/windows") %]'
target_prepend:
- torbrowser-windows-x86_64
- - URL: 'https://crates.io/api/v1/crates/windows/[% c("var/windows_rs_version") %]/download'
+ - URL: 'https://static.crates.io/crates/windows/windows-[% c("var/windows_rs_version") %].crate'
name: windows-rs
- filename: 'windows-rs-[% c("var/windows_rs_version") %].tar.zst'
+ filename: 'windows-rs-[% c("var/windows_rs_version") %].tar.gz'
sha256sum: '[% c("var/windows_rs_sha256sum") %]'
enable: '[% c("var/windows") %]'
- filename: abicheck.cc
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/c…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/c…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser-build][main] Bug 41819: Update windows-rs URL
by boklm (@boklm) 14 Jul '26
by boklm (@boklm) 14 Jul '26
14 Jul '26
boklm pushed to branch main at The Tor Project / Applications / tor-browser-build
Commits:
d67e930f by Nicolas Vigier at 2026-07-14T11:12:24+02:00
Bug 41819: Update windows-rs URL
The URL we had now returns this error:
We are unable to process your request at this time. This usually means
that you are in violation of our API data access policy
(https://crates.io/data-access)
According to https://crates.io/data-access we can use
https://static.crates.io/ instead.
We also update the filename to use the correct extension.
- - - - -
1 changed file:
- projects/firefox/config
Changes:
=====================================
projects/firefox/config
=====================================
@@ -207,9 +207,9 @@ input_files:
enable: '[% c("var/windows") %]'
target_prepend:
- torbrowser-windows-x86_64
- - URL: 'https://crates.io/api/v1/crates/windows/[% c("var/windows_rs_version") %]/download'
+ - URL: 'https://static.crates.io/crates/windows/windows-[% c("var/windows_rs_version") %].crate'
name: windows-rs
- filename: 'windows-rs-[% c("var/windows_rs_version") %].tar.zst'
+ filename: 'windows-rs-[% c("var/windows_rs_version") %].tar.gz'
sha256sum: '[% c("var/windows_rs_sha256sum") %]'
enable: '[% c("var/windows") %]'
- project: windows-app-sdk
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/d…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/d…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
14 Jul '26
ma1 pushed new tag mb-15.0.18-build1 at The Tor Project / Applications / tor-browser-build
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/tree/mb-…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser-build] Pushed new tag tbb-15.0.18-build1
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed new tag tbb-15.0.18-build1 at The Tor Project / Applications / tor-browser-build
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/tree/tbb…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser-build][maint-15.0] ug 41825,41826: Prepare Tor, Mullvad Browser 15.0.18
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed to branch maint-15.0 at The Tor Project / Applications / tor-browser-build
Commits:
80e47919 by hackademix at 2026-07-14T09:03:06+02:00
ug 41825,41826: Prepare Tor, Mullvad Browser 15.0.18
- - - - -
8 changed files:
- projects/browser/Bundle-Data/Docs-MB/ChangeLog.txt
- projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt
- projects/browser/config
- projects/firefox/config
- projects/geckoview/config
- projects/go/config
- projects/translation/config
- rbm.conf
Changes:
=====================================
projects/browser/Bundle-Data/Docs-MB/ChangeLog.txt
=====================================
@@ -1,3 +1,13 @@
+Mullvad Browser 15.0.18 - July 14 2026
+ * All Platforms
+ * Updated NoScript to 13.6.30.1984
+ * Updated uBlock Origin to 1.72.2
+ * Bug 45111: Cherry-pick latest firefox/esr140 commits on 140.12.0esr [tor-browser]
+ * Build System
+ * All Platforms
+ * Bug 41821: Update gpg subkeys for boklm [tor-browser-build]
+ * Bug 41827: Update morgan's keychain with renewed key [tor-browser-build]
+
Mullvad Browser 15.0.16 - June 16 2026
* All Platforms
* Updated Firefox to 140.12.0esr
=====================================
projects/browser/Bundle-Data/Docs-TBB/ChangeLog.txt
=====================================
@@ -1,3 +1,13 @@
+Tor Browser 15.0.18 - July 14 2026
+ * All Platforms
+ * Updated NoScript to 13.6.30.1984
+ * Bug 45111: Cherry-pick latest firefox/esr140 commits on 140.12.0esr [tor-browser]
+ * Build System
+ * All Platforms
+ * Bug 41821: Update gpg subkeys for boklm [tor-browser-build]
+ * Windows + Linux + Android
+ * Updated Go to 1.25.12
+
Tor Browser 15.0.17 - June 29 2026
* All Platforms
* Updated Tor to 0.4.9.11
=====================================
projects/browser/config
=====================================
@@ -114,15 +114,15 @@ input_files:
- filename: dmg-root
enable: '[% ! c("var/android") %]'
- name: fenix-nightly-apk
- URL: https://ftp.mozilla.org/pub/fenix/nightly/2026/06/2026-06-27-20-33-48-fenix…
+ URL: https://ftp.mozilla.org/pub/fenix/nightly/2026/07/2026-07-13-20-26-34-fenix…
enable: '[% c("var/android") %]'
- sha256sum: 0f320103ec68bc9b648fd2c5fe3928a600a4a3c3b6eddc7138d2adb22d0c54be
- - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.25.1984.xpi
+ sha256sum: 1a0ca51024fa7624c407cfa9c0ca6571878d8558fe80c5e37fbba2f687219c7e
+ - URL: https://dist.torproject.org/torbrowser/noscript/noscript-13.6.30.1984.xpi
name: noscript
- sha256sum: e6329c6a9a6e4e9d2b56606e34a5eca53b9dda8204a185d562a53885df0b0afc
- - URL: https://addons.mozilla.org/firefox/downloads/file/4814095/ublock_origin-1.7…
+ sha256sum: c93285f97d9c2755d4778eb190f3f9263270554cd762f420eca5a7ff67633d0a
+ - URL: https://addons.mozilla.org/firefox/downloads/file/4888680/ublock_origin-1.7…
name: ublock-origin
- sha256sum: 47f788a1fc2c014830b30bb0ef9588615701b98c5265fb19b8cf4ba779849feb
+ sha256sum: 40c315b0da7871868155ecfae7a50a58dfa0920aebd865e008214986f1b7c578
enable: '[% c("var/mullvad-browser") %]'
- URL: https://cdn.mullvad.net/browser-extension/0.9.10/mullvad-browser-extension-…
name: mullvad-extension
=====================================
projects/firefox/config
=====================================
@@ -23,7 +23,7 @@ var:
browser_series: '15.0'
browser_rebase: 1
browser_branch: '[% c("var/browser_series") %]-[% c("var/browser_rebase") %]'
- browser_build: 2
+ browser_build: 3
copyright_year: '[% exec("git show -s --format=%ci " _ c("git_hash") _ "^{commit}", { exec_noco => 1 }).remove("-.*") %]'
nightly_updates_publish_dir: '[% c("var/nightly_updates_publish_dir_prefix") %]nightly-[% c("var/osname") %]'
gitlab_project: https://gitlab.torproject.org/tpo/applications/tor-browser
=====================================
projects/geckoview/config
=====================================
@@ -25,7 +25,7 @@ var:
browser_series: '15.0'
browser_rebase: 1
browser_branch: '[% c("var/browser_series") %]-[% c("var/browser_rebase") %]'
- browser_build: 2
+ browser_build: 3
gitlab_project: https://gitlab.torproject.org/tpo/applications/tor-browser
git_commit: '[% exec("git rev-parse " _ c("git_hash") _ "^{commit}", { exec_noco => 1 }) %]'
deps:
=====================================
projects/go/config
=====================================
@@ -1,11 +1,11 @@
# vim: filetype=yaml sw=2
-version: '1.25.11'
+version: '1.25.12'
filename: '[% project %]-[% c("version") %]-[% c("var/osname") %]-[% c("var/build_id") %].tar.[% c("compress_tar") %]'
container:
use_container: 1
var:
- source_sha256: 7b4e5b079b3c9bc420373ca68621a296b4d13c10735d4acac4171928d70f5480
+ source_sha256: f90dcee4bd023fa376374ea0a5a6ebe553537b39c426ffd8c689469b45519932
no_crosscompile: 1
setup: |
mkdir -p /var/tmp/dist
=====================================
projects/translation/config
=====================================
@@ -12,13 +12,13 @@ compress_tar: 'gz'
steps:
base-browser:
base-browser: '[% INCLUDE build %]'
- git_hash: 4432a9ab5c10ba53dc1d3ec9329a73a44446ac4c
+ git_hash: 38c3b4e6b3b71f9dbf84ed31c0552b2461e506c5
targets:
nightly:
git_hash: 'base-browser'
tor-browser:
tor-browser: '[% INCLUDE build %]'
- git_hash: f1579ea805d3d1af56d394893d26561a2945824c
+ git_hash: ca0d23d9a380a2bce5a677952789738a57d8f715
targets:
nightly:
git_hash: 'tor-browser'
@@ -32,7 +32,7 @@ steps:
fenix: '[% INCLUDE build %]'
# We need to bump the commit before releasing but just pointing to a branch
# might cause too much rebuidling of the Firefox part.
- git_hash: 925fa40ece33f0c66b11c41b856fc71a1f8bf25c
+ git_hash: ef9b8c76e315678f5c1841ad63f35870106492e4
compress_tar: 'zst'
targets:
nightly:
=====================================
rbm.conf
=====================================
@@ -74,11 +74,11 @@ buildconf:
git_signtag_opt: '-s'
var:
- torbrowser_version: '15.0.17'
+ torbrowser_version: '15.0.18'
torbrowser_build: 'build1'
# This should be the date of when the build is started. For the build
# to be reproducible, browser_release_date should always be in the past.
- browser_release_date: '2026/06/28 12:30:00'
+ browser_release_date: '2026/07/14 06:29:51'
browser_release_date_timestamp: '[% USE date; date.format(c("var/browser_release_date"), "%s") %]'
browser_default_channel: release
browser_platforms:
@@ -128,9 +128,10 @@ var:
updater_enabled: 1
build_mar: 1
torbrowser_incremental_from:
+ - '[% IF c("var/tor-browser") %]15.0.17[% END %]'
- 15.0.16
- '[% IF c("var/tor-browser") %]15.0.15[% END %]'
- - 15.0.14
+ - '[% IF c("var/mullvad-browser") %]15.0.14[% END %]'
- '[% IF c("var/mullvad-browser") %]15.0.12[% END %]'
mar_channel_id: '[% c("var/projectname") %]-torproject-[% c("var/channel") %]'
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/8…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser-build/-/commit/8…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/mullvad-browser] Pushed new tag mullvad-browser-140.12.0esr-15.0-1-build3
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed new tag mullvad-browser-140.12.0esr-15.0-1-build3 at The Tor Project / Applications / Mullvad Browser
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/tree/mullv…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser][tor-browser-140.12.0esr-15.0-1] 179 commits: Bug 2046256 - extend web-platform-tests test certificates until 2027-05-11....
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed to branch tor-browser-140.12.0esr-15.0-1 at The Tor Project / Applications / Tor Browser
Commits:
9ff8a03c by Sebastian Hengst at 2026-07-14T07:40:40+02:00
Bug 2046256 - extend web-platform-tests test certificates until 2027-05-11. r=Sasha,jgraham a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D305756
- - - - -
8b50b981 by Release Engineering Landoscript at 2026-07-14T07:40:45+02:00
Automatic version bump NO BUG a=release CLOSED TREE
- - - - -
ef5a3a9e by Release Engineering Landoscript at 2026-07-14T07:40:47+02:00
No Bug - Update configs after merge day operations a=release
IGNORE BROKEN CHANGESETS
CLOSED TREE
- - - - -
fea82c0d by Nicholas Rishel at 2026-07-14T07:40:48+02:00
Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D277134
Differential Revision: https://phabricator.services.mozilla.com/D305398
- - - - -
46c5c619 by rperta at 2026-07-14T07:40:49+02:00
Revert "Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM" for causing build bustages DONTBUILD
This reverts commit 7fb19cd315c5b13d32fda38234fa1fd0efa06df6.
- - - - -
698df278 by Andrea Marchesini at 2026-07-14T07:40:50+02:00
Bug 2027788 - Ignore the distribution ini file if its global.id is mozillaonline, a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D305913
- - - - -
4d6acd89 by Emilio Cobos Álvarez at 2026-07-14T07:40:52+02:00
Bug 2046162 - Remove some redundant pub qualifiers. a=RyanVM DONTBUILD
The enum is not public so this doesn't change behavior but a patch I'm
working on in cbindgen gets a bit confused with this.
Original Revision: https://phabricator.services.mozilla.com/D305678
Differential Revision: https://phabricator.services.mozilla.com/D305831
- - - - -
dc80e72b by Andrew Osmond at 2026-07-14T07:40:53+02:00
Bug 2045730. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305642
Differential Revision: https://phabricator.services.mozilla.com/D305722
- - - - -
54969f84 by Alastor Wu at 2026-07-14T07:40:54+02:00
Bug 2043739 - (esr140) Adjust CDM lifetime handling in the Media Foundation CDM IPC path. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306517
- - - - -
3ac27d2d by Alastor Wu at 2026-07-14T07:40:55+02:00
Bug 2045281 - Use the decoded frame format for ffmpeg video chroma plane geometry. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305741
Differential Revision: https://phabricator.services.mozilla.com/D306247
- - - - -
bec43ad4 by Leo Tenenbaum at 2026-07-14T07:40:56+02:00
Bug 2045732 - a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305347
Differential Revision: https://phabricator.services.mozilla.com/D306136
- - - - -
fd126b78 by Brad Werth at 2026-07-14T07:40:57+02:00
Bug 2040119: Enforce ownership of external image in WebRenderBridgeParent::UpdateSharedExternalImage. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304923
Differential Revision: https://phabricator.services.mozilla.com/D306193
- - - - -
29082b2d by Valentin Gosu at 2026-07-14T07:40:58+02:00
Bug 2036591 - Use origin attributes in FailDelayManager a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304395
Differential Revision: https://phabricator.services.mozilla.com/D306416
- - - - -
69e8bb62 by ffxbld at 2026-07-14T07:40:59+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D306766
- - - - -
bea5df97 by Tim Huang at 2026-07-14T07:41:00+02:00
Bug 2038587 - Introduce "wsb" to the application reputation check. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D301066
Differential Revision: https://phabricator.services.mozilla.com/D306933
- - - - -
c28b2c3d by Emilio Cobos Álvarez at 2026-07-14T07:41:01+02:00
Bug 2045616 - Fix CharacterDataBuffer OOM handling. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305165
Differential Revision: https://phabricator.services.mozilla.com/D306945
- - - - -
49cda768 by Emilio Cobos Álvarez at 2026-07-14T07:41:02+02:00
Bug 2045413 - Deal correctly with <area> element removals. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305124
Differential Revision: https://phabricator.services.mozilla.com/D306939
- - - - -
78769f56 by Bob Owen at 2026-07-14T07:41:03+02:00
Bug 2045769 - Check required snapshot shmem size against actual size. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305707
Differential Revision: https://phabricator.services.mozilla.com/D306972
- - - - -
7d10c341 by Tooru Fujisawa at 2026-07-14T07:41:04+02:00
Bug 2013415 - Use b-linux-docker-large-amd for searchfox jobs. r=ahal a=NPOTB DONTBUILD
This reduces the time taken by the linux64-searchfox job from 113min to 53min.
Differential Revision: https://phabricator.services.mozilla.com/D283000
- - - - -
03d03ebe by Ryan VanderMeulen at 2026-07-14T07:41:05+02:00
Bug 2013415 - Add b-linux-docker-large-amd worker alias to esr140 config. a=bustage DONTBUILD
- - - - -
c4e2ebe4 by Ryan VanderMeulen at 2026-07-14T07:41:06+02:00
Bug 2013415 - Use docker-worker implementation for b-linux-docker-large-amd alias. a=bustage DONTBUILD
- - - - -
7863fb5a by Nicholas Rishel at 2026-07-14T07:41:07+02:00
Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D277134
Differential Revision: https://phabricator.services.mozilla.com/D305398
- - - - -
bbc716d6 by Tom Schuster at 2026-07-14T07:41:08+02:00
Bug 2044612 - Use ClientInfo for font loading in Worker. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305486
Differential Revision: https://phabricator.services.mozilla.com/D307286
- - - - -
0b5660f5 by Tom Schuster at 2026-07-14T07:41:09+02:00
Bug 2041902 - For WebTransport require a ClientInfo. . a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305171
Differential Revision: https://phabricator.services.mozilla.com/D307271
- - - - -
b8db7029 by Alastor Wu at 2026-07-14T07:41:10+02:00
Bug 2045756 - Skip a renderer-referenced surface when matching by FFmpeg id in FFmpegVideoFramePool a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305429
Differential Revision: https://phabricator.services.mozilla.com/D307086
- - - - -
81ad8910 by Timothy Nikkel at 2026-07-14T07:41:11+02:00
Bug 2045624. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306891
- - - - -
9103d7f8 by Masayuki Nakano at 2026-07-14T07:41:12+02:00
Bug 2045405 - Improve the error handling in `PresShell::CompleteMove` a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305544
Differential Revision: https://phabricator.services.mozilla.com/D307163
- - - - -
9e14fc50 by Timothy Nikkel at 2026-07-14T07:41:13+02:00
Bug 2045614. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306900
- - - - -
4ceae3b0 by Lee Salzman at 2026-07-14T07:41:14+02:00
Bug 2045625. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305785
Differential Revision: https://phabricator.services.mozilla.com/D307126
- - - - -
54e2a23a by Lee Salzman at 2026-07-14T07:41:15+02:00
Bug 2045185. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307130
- - - - -
825e17b1 by Edgar Chen at 2026-07-14T07:41:16+02:00
Bug 2045513 - Make parser update form owner properly; a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305669
Differential Revision: https://phabricator.services.mozilla.com/D307295
- - - - -
54ff5613 by az at 2026-07-14T07:41:17+02:00
Bug 2045742 - a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305387
Differential Revision: https://phabricator.services.mozilla.com/D307110
- - - - -
10efbdd3 by Andrew McCreight at 2026-07-14T07:41:18+02:00
Bug 2048110 - Add remoteTypes to AboutTabCrashed, LightweightTheme, Megalist. a=RyanVM DONTBUILD
These are only used in a few specific processes.
Original Revision: https://phabricator.services.mozilla.com/D307152
Differential Revision: https://phabricator.services.mozilla.com/D307574
- - - - -
0f7666a9 by Leo Tenenbaum at 2026-07-14T07:41:19+02:00
Bug 2047718 - Check for unexpected DOM changes in more places in EnsureNoInvisibleWhiteSpaces. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306863
Differential Revision: https://phabricator.services.mozilla.com/D307559
- - - - -
81f45631 by Brad Werth at 2026-07-14T07:41:20+02:00
Bug 2045184: Make SharedContextWebgl destructor prevent resurrection. a=RyanVM
Detaching the WeakPtr early prevents the object from being AddRef'ed by
anything later in the destructor.
Original Revision: https://phabricator.services.mozilla.com/D305720
Differential Revision: https://phabricator.services.mozilla.com/D307604
- - - - -
732e7f65 by Ryan VanderMeulen at 2026-07-14T07:41:21+02:00
Bug 2045185 - Fix bustage from stride type mismatch. a=bustage
stride is a plain size_t on esr140 (GetAlignedStride's Maybe<> return type was
never backported), so the .value() call from the backport fails to compile.
- - - - -
f7c818b1 by Eden Chuang at 2026-07-14T07:41:22+02:00
Bug 2005113 - Bind FetchBodyBase::mReadableStream to the body stream and rebind it on clone(). . a=RyanVM DONTBUILD
Create the body ReadableStream from the underlying body input stream directly.
When clone() is called before the stream has been read and the underlying body
is not cloneable, clone() replaces the original input stream; repoint the
existing unread native ReadableStream at the replacement so the original stream
is not read from two places. This keeps native bodies native (cancellation of
an unread stream still tears down the channel, and the consume path keeps
reading the body input stream directly) without teeing native byte streams.
This no longer clones the body when creating the ReadableStream, so it does not
buffer the whole body; restore the huge-fetch crashtest expectations that were
disabled to avoid OOMing the 32-bit process.
Original Revision: https://phabricator.services.mozilla.com/D280568
(cherry picked from commit 38e360c0d435c4bd9b0e45b207877610506433f3)
Differential Revision: https://phabricator.services.mozilla.com/D307754
- - - - -
bde78cad by Alastor Wu at 2026-07-14T07:41:23+02:00
Bug 2045424 - (esr140) Constrain the per-sample IV size in the CENC parser and ClearKey decryptor. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307384
- - - - -
0d5cda16 by Alastor Wu at 2026-07-14T07:41:24+02:00
Bug 2045395 - (esr140) Use checked arithmetic for the interleave buffer length in AudioDecoderInputTrack a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307385
- - - - -
f07e254d by Shravan Narayan at 2026-07-14T07:41:25+02:00
Bug 2045149 - Fix rlbox's unnecessary rejection of unaligned transfer buffers a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D307194
Differential Revision: https://phabricator.services.mozilla.com/D307859
- - - - -
40a38de4 by ffxbld at 2026-07-14T07:41:26+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D308004
- - - - -
2ae11c90 by Jonathan Kew at 2026-07-14T07:41:28+02:00
Bug 2045378 - Validate font descriptor in UnscaledFontFontconfig::CreateFromFontDescriptor. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305662
Differential Revision: https://phabricator.services.mozilla.com/D308002
- - - - -
ee07db4d by Jonathan Kew at 2026-07-14T07:41:29+02:00
Bug 2045771 - Validate kern subtable length. a=pascalc DONTBUILD
As suggested by clauditor.
Original Revision: https://phabricator.services.mozilla.com/D306160
Differential Revision: https://phabricator.services.mozilla.com/D307998
- - - - -
8bfb3ee8 by Jan-Niklas Jaeschke at 2026-07-14T07:41:29+02:00
Bug 2045402 - Refactor CrossShadowBoundaryRange::DoSetRange. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305276
Differential Revision: https://phabricator.services.mozilla.com/D308085
- - - - -
9930ca0c by Ben Visness at 2026-07-14T07:41:31+02:00
Bug 2043271. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306329
Differential Revision: https://phabricator.services.mozilla.com/D308069
- - - - -
ba76e147 by Henri Sivonen at 2026-07-14T07:41:31+02:00
Bug 2045417. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D305108
Differential Revision: https://phabricator.services.mozilla.com/D307995
- - - - -
046b2007 by Timothy Nikkel at 2026-07-14T07:41:33+02:00
Bug 2045775. a=pascalc DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307939
- - - - -
9e8a90ef by Jonathan Kew at 2026-07-14T07:41:34+02:00
Bug 2045612 - Take ownership of the state in RestoreFormControlState. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307613
Differential Revision: https://phabricator.services.mozilla.com/D307827
- - - - -
d172f7de by David Shin at 2026-07-14T07:41:35+02:00
Bug 2045611: a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307076
Differential Revision: https://phabricator.services.mozilla.com/D307776
- - - - -
3e7ee821 by Tomislav Jovanovic at 2026-07-14T07:41:36+02:00
Bug 2048267 - Enable WebExtensions WPT tests on ESR140 a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D307614
Differential Revision: https://phabricator.services.mozilla.com/D307920
- - - - -
b8fc453c by Matthew Gregan at 2026-07-14T07:41:37+02:00
Bug 2042033 - Update audioipc to 3f0d4aef7a2c06b0146384592b312a7f47ab7cea. a=pascalc DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307454
- - - - -
ab647faa by Jan de Mooij at 2026-07-14T07:41:38+02:00
Bug 2045957 - Initialize BaselineFrame return value slot in OnLeaveBaselineFrame. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305464
Differential Revision: https://phabricator.services.mozilla.com/D307470
- - - - -
146910a7 by Andrew Osmond at 2026-07-14T07:41:39+02:00
Bug 2045187. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305653
Differential Revision: https://phabricator.services.mozilla.com/D305719
- - - - -
876d8492 by Justin Link at 2026-07-14T07:41:40+02:00
Bug 2028663: Fixed error-checking in WinRegistry a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D291621
Differential Revision: https://phabricator.services.mozilla.com/D308307
- - - - -
c85fb073 by Julien Cristau at 2026-07-14T07:41:41+02:00
Bug 2048897 - fix update-verify-config failures on esr for win64-aarch64 DONTBUILD a=RyanVM
That platform was discontinued on esr115 which confuses our scripts.
Set last-watershed to 140.0esr to bypass the issue.
Original Revision: https://phabricator.services.mozilla.com/D307745
Differential Revision: https://phabricator.services.mozilla.com/D307844
- - - - -
e34c5c9a by Randell Jesup at 2026-07-14T07:41:42+02:00
Bug 2031768: Validate Principals in CookieStore a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D294473
Differential Revision: https://phabricator.services.mozilla.com/D308285
- - - - -
f4a4901a by Kai Engert at 2026-07-14T07:41:43+02:00
Bug 2013230 - Use strnlen in mozilla::PrintfTarget::cvt_s. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D280910
Differential Revision: https://phabricator.services.mozilla.com/D308438
- - - - -
6d7ef56b by Masayuki Nakano at 2026-07-14T07:41:44+02:00
Bug 2045619 - Make `CompositionTransaction::DoTransaction` scan the replace start position as far as possible a=RyanVM DONTBUILD
The replace start may be in the following `Text`. Therefore, we should
scan the following `Text` before inserting the new composition string.
Original Revision: https://phabricator.services.mozilla.com/D305783
Differential Revision: https://phabricator.services.mozilla.com/D307458
- - - - -
8e407fb3 by Emilio Cobos Álvarez at 2026-07-14T07:41:45+02:00
Bug 2045406 - Validate end of cff dict. a=RyanVM DONTBUILD
Sent upstream in https://gitlab.freedesktop.org/cairo/cairo/-/work_items/967
Original Revision: https://phabricator.services.mozilla.com/D305850
Differential Revision: https://phabricator.services.mozilla.com/D307732
- - - - -
14d9f416 by Emilio Cobos Álvarez at 2026-07-14T07:41:46+02:00
Bug 2045406 - Check cff dict operator / operand sizes. a=RyanVM DONTBUILD
Missed this one from the AI report. Also submitted upstream.
Original Revision: https://phabricator.services.mozilla.com/D306885
Differential Revision: https://phabricator.services.mozilla.com/D307733
- - - - -
05fc875f by Jonathan Kew at 2026-07-14T07:41:47+02:00
Bug 2045518 - Ensure gfxFontEntry's mFamilyName field is guarded by mLock. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305176
Differential Revision: https://phabricator.services.mozilla.com/D307514
- - - - -
1f7385e0 by Andreas Farre at 2026-07-14T07:41:48+02:00
Bug 2045618 - Make sure to consider idle timeouts when getting id. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305582
Differential Revision: https://phabricator.services.mozilla.com/D308000
- - - - -
9599e496 by Jon Coppeard at 2026-07-14T07:41:49+02:00
Bug 2045451 - Prevent allocation of object elemets abutting the end of a nursery chunk a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305804
Differential Revision: https://phabricator.services.mozilla.com/D307781
- - - - -
5376770a by Jan de Mooij at 2026-07-14T07:41:50+02:00
Bug 2045454 - Clamp length of regexp captures array for dollar substitution. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305181
Differential Revision: https://phabricator.services.mozilla.com/D307473
- - - - -
9c204e29 by Ryan VanderMeulen at 2026-07-14T07:41:51+02:00
Bug 2045518 - Use FamilyName() accessor in CacheFont's assertion to fix thread-safety bustage. a=bustage
The backport missed converting one direct mFamilyName access in the NS_ASSERTION at the top of
UserFontCache::CacheFont, breaking debug builds under -Wthread-safety-analysis.
- - - - -
50758141 by Emilio Cobos Álvarez at 2026-07-14T07:41:52+02:00
Bug 2045604 - Don't leak the static doc via the relevant global of the context. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306772
Differential Revision: https://phabricator.services.mozilla.com/D307727
- - - - -
04ded981 by Julian Descottes at 2026-07-14T07:41:53+02:00
Bug 2027519 - [devtools] Use the real source url for sourcemap resolution a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304524
Differential Revision: https://phabricator.services.mozilla.com/D308464
- - - - -
81d1572b by Calixte Denizet at 2026-07-14T07:41:54+02:00
Bug 2037770 - Honor iframe sandbox flags when handling pdf.js downloads a=RyanVM DONTBUILD
Cherry pick pdf.js changes from https://github.com/mozilla/pdf.js/commit/ece1e2ed0c58eb9641da33259d958fa912….
Differential Revision: https://phabricator.services.mozilla.com/D308475
- - - - -
8c8d8c90 by Lee Salzman at 2026-07-14T07:41:55+02:00
Bug 2047729. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307935
Differential Revision: https://phabricator.services.mozilla.com/D308335
- - - - -
10a802fa by Lee Salzman at 2026-07-14T07:41:56+02:00
Bug 2045741. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306315
Differential Revision: https://phabricator.services.mozilla.com/D308338
- - - - -
97899148 by James Teh at 2026-07-14T07:41:57+02:00
Bug 2047957: Ensure cached line start offsets are valid. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307467
Differential Revision: https://phabricator.services.mozilla.com/D308429
- - - - -
1c6274b0 by Valentin Gosu at 2026-07-14T07:41:59+02:00
Bug 2048934 - Make mInVisitHeaders checks reentrant a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308013
Differential Revision: https://phabricator.services.mozilla.com/D308471
- - - - -
907647ec by André Bargull at 2026-07-14T07:42:00+02:00
Bug 2045482: Align with hasSpaceForInsts to simplify test case. r=jandem a=RyanVM DONTBUILD
Align with `hasSpaceForInsts` so the test case doesn't need to emit
thirty additional nop instructions.
Differential Revision: https://phabricator.services.mozilla.com/D306374
- - - - -
15aca0de by Julian Seward at 2026-07-14T07:42:01+02:00
Bug 2043035. . a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D303979
Differential Revision: https://phabricator.services.mozilla.com/D308724
- - - - -
7e1c0edf by Jonathan Kew at 2026-07-14T07:42:02+02:00
Bug 2045607 - Hold a strong ref during GetFontAt lookup. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307564
Differential Revision: https://phabricator.services.mozilla.com/D308506
- - - - -
f194a890 by Olli Pettay at 2026-07-14T07:42:03+02:00
Bug 2045515, avoid leaking a slot, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305076
Differential Revision: https://phabricator.services.mozilla.com/D308743
- - - - -
44108423 by Julian Seward at 2026-07-14T07:42:04+02:00
Bug 2045443. . a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305869
Differential Revision: https://phabricator.services.mozilla.com/D308729
- - - - -
e0586f98 by Olli Pettay at 2026-07-14T07:42:05+02:00
Bug 2045414, be consistent with the promise resolve/reject handling, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306588
Differential Revision: https://phabricator.services.mozilla.com/D308735
- - - - -
59a449f0 by Jan-Niklas Jaeschke at 2026-07-14T07:42:06+02:00
Bug 2049404 - Remove unused method from nsINode, add mainthread checks. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308201
Differential Revision: https://phabricator.services.mozilla.com/D308748
- - - - -
d5135616 by James Teh at 2026-07-14T07:42:07+02:00
Bug 2047716: Ensure cache is valid. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307466
Differential Revision: https://phabricator.services.mozilla.com/D308698
- - - - -
43ccbf85 by longsonr at 2026-07-14T07:42:08+02:00
Bug 2049407 Part 1 - Detach observers on canvas destruction a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308288
Differential Revision: https://phabricator.services.mozilla.com/D308731
- - - - -
bac95fcc by Daniel Darnell at 2026-07-14T07:42:09+02:00
Bug 2005200 - Make Thunderbird langpacks depend on correct Thunderbird epoch. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305463
Differential Revision: https://phabricator.services.mozilla.com/D309200
- - - - -
4d412f5c by Mike Hommey at 2026-07-14T07:42:10+02:00
Bug 2029761 - Handle large values returned by strnlen as an error. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D303290
Differential Revision: https://phabricator.services.mozilla.com/D308936
- - - - -
700cd4fd by Ryan VanderMeulen at 2026-07-14T07:42:11+02:00
Bug 2048062 - Run apt-get update before installing build deps in the debian-packages image. a=diannaS
The ubuntu2404 raw image pins an apt snapshot for reproducibility, and the
package lists from the parent image aren't usable in the debian-packages child,
so apt-get install fails to locate any package. Refresh the lists first. The
snapshot pin is inherited by the child image, so the resolved package versions
are unchanged.
Original Revision: https://phabricator.services.mozilla.com/D307183
Differential Revision: https://phabricator.services.mozilla.com/D308925
- - - - -
ed967fe1 by Edgar Chen at 2026-07-14T07:42:12+02:00
Bug 2046215 - Associate image elements with form only if the form and the intended parent are in the same tree; a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305733
Differential Revision: https://phabricator.services.mozilla.com/D309120
- - - - -
bde0ab88 by Alastor Wu at 2026-07-14T07:42:13+02:00
Bug 2045508 - Reset the create-promise id once the create promise settles in MediaKeys. a=RyanVM (esr140) DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D308879
- - - - -
e4b3238b by Brad Werth at 2026-07-14T07:42:14+02:00
Bug 2045626: Compute range of convolve filter in integer domain. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308096
Differential Revision: https://phabricator.services.mozilla.com/D309197
- - - - -
3dfca483 by Artur Iunusov at 2026-07-14T07:42:15+02:00
Bug 2045397 - Cancel the network channel when failing a cached worker script load a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307328
Differential Revision: https://phabricator.services.mozilla.com/D308528
- - - - -
2c22e70c by Andrew McCreight at 2026-07-14T07:42:15+02:00
Bug 2049523 - Make ToJSValue for float consistent with double. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308323
Differential Revision: https://phabricator.services.mozilla.com/D308559
- - - - -
2cc56156 by Lee Salzman at 2026-07-14T07:42:17+02:00
Bug 2049822. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308391
Differential Revision: https://phabricator.services.mozilla.com/D308818
- - - - -
b934ab2f by Lee Salzman at 2026-07-14T07:42:18+02:00
Bug 2025369. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308172
Differential Revision: https://phabricator.services.mozilla.com/D309240
- - - - -
86792242 by Lee Salzman at 2026-07-14T07:42:19+02:00
Bug 2050151. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308694
Differential Revision: https://phabricator.services.mozilla.com/D309242
- - - - -
71d1a84f by Chun-Min Chang at 2026-07-14T07:42:20+02:00
Bug 2045415 - Harden buffer sizing in Web Audio decoding a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D309159
- - - - -
fc3a13e0 by Lee Salzman at 2026-07-14T07:42:21+02:00
Bug 2049805. a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D308859
- - - - -
ba3108fa by ffxbld at 2026-07-14T07:42:23+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D309303
- - - - -
07d0b96a by Sotaro Ikeda at 2026-07-14T07:42:24+02:00
Bug 2049818 a=pascalc
Signed-off-by: Pascal Chevrel <pascal(a)mozilla.com>
- - - - -
cf8169e5 by Ryan VanderMeulen at 2026-07-14T07:42:25+02:00
Bug 2051165 - Move ub18 package sources off launchpad.net URLs r=firefox-build-system-reviewers,sergesanspaille a=diannaS
Differential Revision: https://phabricator.services.mozilla.com/D309272
- - - - -
e479b581 by Simon Farre at 2026-07-14T07:42:26+02:00
Bug 2045396 - Abort parser that otherwise could trigger the running of script when it shouldn't a=RyanVM DONTBUILD
Only <embed> and <object> teardown seem to finalize parsing, and circumvent script-safety-aware checks which can trigger script running like the bug displays.
nsParser::Terminate is eventually called via nsDocShell::Destroy() also, but this way we ensure the above doesn't happen, provided that NS_BINDING_ABORTED is passed in.
Original Revision: https://phabricator.services.mozilla.com/D305221
Differential Revision: https://phabricator.services.mozilla.com/D309304
- - - - -
379ba586 by Valentin Gosu at 2026-07-14T07:42:27+02:00
Bug 2041001 - Drop intermediary HTTPS result when following alias a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308991
Differential Revision: https://phabricator.services.mozilla.com/D309322
- - - - -
a0b67044 by Vincent Hilla at 2026-07-14T07:42:28+02:00
Bug 2043820 - Reject javascript URI in nsDocShellLoadState. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305829
Differential Revision: https://phabricator.services.mozilla.com/D309583
- - - - -
6175a8b0 by Karl Tomlinson at 2026-07-14T07:42:29+02:00
Bug 2042242 Start fallback driver after queuing cubeb stream init a=RyanVM
This keeps cubeb operations in order and means that no other thread runs the
graph while mStreamName is passed to the cubeb operation thread.
MaybeStartAudioStream() no longer uses Start() to queue the stream init,
because it does not need to and removing this caller allows Start() to more
simply handle its remaining use cases. MaybeStartAudioStream() never starts a
fallback driver nor stops a previous driver because it is called from the
fallback driver loop.
Original Revision: https://phabricator.services.mozilla.com/D305794
Differential Revision: https://phabricator.services.mozilla.com/D309475
- - - - -
b9b7ac11 by Andrew McCreight at 2026-07-14T07:42:30+02:00
Bug 2050990 - Call JS_NumberValue in ClientWebGLContext.cpp. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D309205
Differential Revision: https://phabricator.services.mozilla.com/D309810
- - - - -
ab90d413 by Chun-Min Chang at 2026-07-14T07:42:31+02:00
Bug 2047723 - Cherry-pick commit f738b1132ec1fd56efc90367898244cf52d9e6a5 for libsoundtouch a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D309945
- - - - -
9cb9334d by Lee Salzman at 2026-07-14T07:42:32+02:00
Bug 2051666. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309674
Differential Revision: https://phabricator.services.mozilla.com/D309983
- - - - -
722bf627 by Lee Salzman at 2026-07-14T07:42:33+02:00
Bug 2049405. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308437
Differential Revision: https://phabricator.services.mozilla.com/D309967
- - - - -
b006bf36 by Valentin Gosu at 2026-07-14T07:42:34+02:00
Bug 2050668 - WS: set mDataStarted before dispatching runnable a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308990
Differential Revision: https://phabricator.services.mozilla.com/D309771
- - - - -
0847a453 by Andrew McCreight at 2026-07-14T07:42:35+02:00
Bug 2050657 - Fix more floating point setNumber calls. a=RyanVM
Plus a DoubleValue because we might as well fix both EventDispatcher issues
in one patch.
Original Revision: https://phabricator.services.mozilla.com/D308928
Differential Revision: https://phabricator.services.mozilla.com/D309823
- - - - -
58ec3e09 by Andrew McCreight at 2026-07-14T07:42:36+02:00
Bug 2050657 - Fixes for setDouble, Float32Value and JS::NumberValue. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D309191
Differential Revision: https://phabricator.services.mozilla.com/D309824
- - - - -
87fe7365 by Andrew McCreight at 2026-07-14T07:42:37+02:00
Bug 2050657 - Ensure UbiNode Node::identifier() is representable. a=RyanVM
Node::identifier() gets used as a JS value in a few places, so we should make
sure that it is a nice happy non-NaN value representable as a double. It looks
like all of the callers are passing in pointers, so it should be fine.
Original Revision: https://phabricator.services.mozilla.com/D309192
Differential Revision: https://phabricator.services.mozilla.com/D309825
- - - - -
01d31953 by Arnaud Bienner at 2026-07-14T07:42:38+02:00
Bug 2051285 - Useless reinterpret_cast in EncryptingOutputStream_impl.h a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309361
Differential Revision: https://phabricator.services.mozilla.com/D310141
- - - - -
044da35c by Arnaud Bienner at 2026-07-14T07:42:39+02:00
Bug 2044536 - Quota: make EncryptedBlock::RoundedUpToBasicBlockSize public and use it in EncryptingOutputStream, and propertly clear buffer a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309603
Differential Revision: https://phabricator.services.mozilla.com/D310142
- - - - -
0cc7dcbc by Jens Stutte at 2026-07-14T07:42:40+02:00
Bug 2045510 - Reject snappy CompressedData chunks shorter than the CRC field. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305218
Differential Revision: https://phabricator.services.mozilla.com/D309799
- - - - -
50272d3a by Jens Stutte at 2026-07-14T07:42:41+02:00
Bug 2048795 - Guard access to the GamepadPlatformService singleton by a StaticMutex. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308034
Differential Revision: https://phabricator.services.mozilla.com/D309819
- - - - -
e26e8e3e by Valentin Gosu at 2026-07-14T07:42:42+02:00
Bug 2045833 - Clean up nsUnknownDecoder::OnDataAvailable check a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305526
Differential Revision: https://phabricator.services.mozilla.com/D309891
- - - - -
c886993c by Lee Salzman at 2026-07-14T07:42:43+02:00
Bug 2047719. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307948
Differential Revision: https://phabricator.services.mozilla.com/D310173
- - - - -
30b753cb by Jonathan Kew at 2026-07-14T07:42:44+02:00
Bug 2045865 - Use row_bytes rather than bitmap->pitch when copying glyph. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307593
Differential Revision: https://phabricator.services.mozilla.com/D310192
- - - - -
bd391cb3 by Matthew Gregan at 2026-07-14T07:42:45+02:00
Bug 2045763. r=cubeb-reviewers,padenot a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D310249
- - - - -
3f39be32 by smayya at 2026-07-14T07:42:46+02:00
Bug 2049392 - improve nsStandardURL parsing. n=#necko a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309007
Differential Revision: https://phabricator.services.mozilla.com/D310086
- - - - -
32f4f5f9 by Valentin Gosu at 2026-07-14T07:42:47+02:00
Bug 2045875 - Empty authority is not compatible with port a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D306755
Differential Revision: https://phabricator.services.mozilla.com/D310087
- - - - -
09f5c12c by Bob Owen at 2026-07-14T07:42:48+02:00
Bug 2045767 - a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305931
Differential Revision: https://phabricator.services.mozilla.com/D310114
- - - - -
4b6b8860 by Randell Jesup at 2026-07-14T07:42:49+02:00
Bug 2045783: Clean up TRRQuery::CompleteLookup a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305279
Differential Revision: https://phabricator.services.mozilla.com/D310241
- - - - -
d95e8f5e by Randell Jesup at 2026-07-14T07:42:50+02:00
Bug 2045783: Add thread-safety checks to TRRQuery a=dmeehan DONTBUILD
Belt-and-suspenders; allows static analyisis
Original Revision: https://phabricator.services.mozilla.com/D305601
Differential Revision: https://phabricator.services.mozilla.com/D310242
- - - - -
09073f2c by Yannis Juglaret at 2026-07-14T07:42:51+02:00
Bug 2045770 - Cap constant-fold allocations. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305921
Differential Revision: https://phabricator.services.mozilla.com/D310264
- - - - -
4c008373 by DonalMe at 2026-07-14T07:42:52+02:00
Bug 2051658 a=dmeehan
- - - - -
1073dd73 by DonalMe at 2026-07-14T07:42:53+02:00
Revert "Bug 2051658 a=dmeehan" for causing build failures
This reverts commit e44a92232c4f71f420ce59f22e15f5c962f794f2.
- - - - -
19111068 by Arnaud Bienner at 2026-07-14T07:42:54+02:00
Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308534
Differential Revision: https://phabricator.services.mozilla.com/D310354
- - - - -
887a5625 by Michael Kaply at 2026-07-14T07:42:55+02:00
Bug 2044527 - Normalize the host when matching WebsiteFilter patterns. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305900
Differential Revision: https://phabricator.services.mozilla.com/D310652
- - - - -
e0e61a48 by Tom Schuster at 2026-07-14T07:42:56+02:00
Bug 2008369 - Validate principal in PContent::LoadURIExternal. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309362
Differential Revision: https://phabricator.services.mozilla.com/D310359
- - - - -
d72f21f0 by Jonathan Kew at 2026-07-14T07:42:57+02:00
Bug 2048801 - Validate fdselect entries before use. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308373
Differential Revision: https://phabricator.services.mozilla.com/D310395
- - - - -
fcbb61b8 by Jonathan Kew at 2026-07-14T07:42:58+02:00
Bug 2049398 - Range-check glyph ID. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308374
Differential Revision: https://phabricator.services.mozilla.com/D310396
- - - - -
e151ed6c by Jonathan Kew at 2026-07-14T07:42:59+02:00
Bug 2049399 - Check type1 stack size. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308375
Differential Revision: https://phabricator.services.mozilla.com/D310397
- - - - -
497935fb by ffxbld at 2026-07-14T07:43:00+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310675
- - - - -
e005a313 by Mark Banner at 2026-07-14T07:43:01+02:00
Bug 1874712 - Add a keyword for Ecosia. a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310293
- - - - -
297993de by DonalMe at 2026-07-14T07:43:02+02:00
Bug 2044527 - Fix build failure on ESR140 a=bustage
- - - - -
ec7aa1b0 by DonalMe at 2026-07-14T07:43:03+02:00
Revert "Bug 2008369 - Validate principal in PContent::LoadURIExternal. a=dmeehan" for causing CI failures on ESR140
This reverts commit 418229151ed0e8261397c2bbcde6112814b14947.
- - - - -
2908e88d by DonalMe at 2026-07-14T07:43:04+02:00
Revert "Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan" for causing CI errors on ESR140
This reverts commit acff26261e5c0c60cb66c290d02ff199ea637cf5.
- - - - -
9a4de08f by Arnaud Bienner at 2026-07-14T07:43:05+02:00
Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308534
Differential Revision: https://phabricator.services.mozilla.com/D310354
- - - - -
1075a9f1 by smayya at 2026-07-14T07:43:06+02:00
Bug 2045511 - update nsHttpTransaction::Close() handling of NS_BINDING_RETARGETED. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307751
Differential Revision: https://phabricator.services.mozilla.com/D310586
- - - - -
ed81fda3 by James Teh at 2026-07-14T07:43:07+02:00
Bug 2046416: Ensure a hide event never occurs during a split show event. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306672
Differential Revision: https://phabricator.services.mozilla.com/D310548
- - - - -
615146d9 by Sotaro Ikeda at 2026-07-14T07:43:08+02:00
Bug 2051653 a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309978
Differential Revision: https://phabricator.services.mozilla.com/D310545
- - - - -
5f67890f by Emilio Cobos Álvarez at 2026-07-14T07:43:09+02:00
Bug 2045617 - Add some bounds checks to cairo_cff_font_read_fdselect. a=dmeehan
Attached to https://gitlab.freedesktop.org/cairo/cairo/-/work_items/967
as well.
Original Revision: https://phabricator.services.mozilla.com/D306604
Differential Revision: https://phabricator.services.mozilla.com/D310349
- - - - -
7b20e3e8 by Eden Chuang at 2026-07-14T07:43:10+02:00
Bug 2026301 - Synchronize ThreadSafeRequestHandle::mRunnable to fix cross-thread use-after-free a=dmeehan DONTBUILD
mRunnable was a plain RefPtr read on the main thread (GetCacheCreator and the
other accessors) and cleared on the worker thread by ReleaseRequest() with no
synchronization. When the worker's store dropped the last reference to the
shared ScriptLoaderRunnable, the main thread could dereference the already-freed
pointer, producing a heap-use-after-free.
Guard mRunnable with a Mutex (enforced via MOZ_GUARDED_BY). ReleaseRequest() and
the new SetRunnable() mutate it under the lock, releasing the runnable outside
the lock so it is never destroyed while the mutex is held. Each main-thread
accessor copies mRunnable into a local strong reference under the lock and bails
if it was already released. GetCacheCreator() now returns a strong CacheCreator
reference taken under the lock, so the caller keeps it alive across DeleteCache()
even if the runnable is released on the worker thread afterwards.
Original Revision: https://phabricator.services.mozilla.com/D307211
Differential Revision: https://phabricator.services.mozilla.com/D310969
- - - - -
bec05ff1 by Emilio Cobos Álvarez at 2026-07-14T07:43:11+02:00
Bug 2045198 - Don't bother checking ancestors for constructed check. a=dmeehan DONTBUILD
Since we don't allow @import, we can't get there with a constructed
ancestor.
Original Revision: https://phabricator.services.mozilla.com/D309844
Differential Revision: https://phabricator.services.mozilla.com/D310859
- - - - -
4dd5a131 by Jonathan Kew at 2026-07-14T07:43:12+02:00
Bug 2050368 - Check for end of charstring. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308768
Differential Revision: https://phabricator.services.mozilla.com/D310831
- - - - -
7a51ebdf by Randell Jesup at 2026-07-14T07:43:13+02:00
Bug 2045772: Clean up nsStandardURL::Deserialize a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305274
Differential Revision: https://phabricator.services.mozilla.com/D310198
- - - - -
1ed75d9f by Daniel Holbert at 2026-07-14T07:43:14+02:00
Bug 2048799: Flip polarity of a bounds check in cairo code. a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D307892
Differential Revision: https://phabricator.services.mozilla.com/D310180
- - - - -
1d329b4b by Eitan Isaacson at 2026-07-14T07:43:15+02:00
Bug 2045392 - Don't allow attaching children to outerdoc. a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D305621
- - - - -
0fbd3682 by Sotaro Ikeda at 2026-07-14T07:43:16+02:00
Bug 2051658 - for esr140 a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D310958
- - - - -
b92df16f by Valentin Gosu at 2026-07-14T07:43:17+02:00
Bug 2032140 - Verify content process identity when linking background channels a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309038
Differential Revision: https://phabricator.services.mozilla.com/D311187
- - - - -
8bc39ef1 by Valentin Gosu at 2026-07-14T07:43:18+02:00
Bug 2043200 - Bind RedirectChannelRegistrar ids to their destination content process a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309039
Differential Revision: https://phabricator.services.mozilla.com/D311188
- - - - -
fa458fcf by Atila Butkovits at 2026-07-14T07:43:19+02:00
Revert "Bug 2051658 - for esr140 a=dmeehan DONTBUILD" for causing reftest failures.
This reverts commit 58bbb58a4b533f267000b555474fa3f5f2122c61.
- - - - -
8ad8ffda by Nika Layzell at 2026-07-14T07:43:20+02:00
Bug 2027207 - Part 1: Align validation in TriggerRedirectToRealChannel and RecvNewWindowGlobal better, a=pascalc
This should make TriggerRedirectToRealChannel tighter, to hopefully
match the check in RecvNewWindowGlobal better. While this doesn't add
much in terms of security, it should reduce the risk of us encountering
surprising errors.
Original Revision: https://phabricator.services.mozilla.com/D291061
Differential Revision: https://phabricator.services.mozilla.com/D311158
- - - - -
deab802f by Nika Layzell at 2026-07-14T07:43:21+02:00
Bug 2027207 - Part 2: Handle schemes better in ValidatePrincipalCouldPotentiallyBeLoadedBy, a=pascalc
Previously this logic used `nsIPrincipal::GetScheme`, which returns the
scheme of the URI used to create the principal. This could have
unexpected behaviour for nested URIs like view-source URIs, which have a
view-source: URI scheme, but a non-view-source (e.g. https://) origin.
This patch reworks the logic to instead base the checks off of the
origin's scheme, parsing it out of the origin string.
In addition, the about: URI handling was improved somewhat to have a
better understanding of how process selection for about: URIs happens in
practice by relying on a component of the process isolation logic.
Original Revision: https://phabricator.services.mozilla.com/D291062
Differential Revision: https://phabricator.services.mozilla.com/D311159
- - - - -
585c60c4 by Nika Layzell at 2026-07-14T07:43:23+02:00
Bug 2027207 - Part 3: Return IPC_FAIL when principal validation fails, a=pascalc
This entry actually changes the callers to perform principal validation.
This turns the code which previously would only send a telemetry ping to
a crash. I am hopeful that the rate of failures is low enough that this
won't cause an issue, and if it does, I'm hopeful that we'll be able to
figure out the cause of the mismatch.
Original Revision: https://phabricator.services.mozilla.com/D291063
Differential Revision: https://phabricator.services.mozilla.com/D311160
- - - - -
f0376f95 by Timothy Nikkel at 2026-07-14T07:43:24+02:00
Bug 2036518. r=gfx-reviewers,lsalzman a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311035
- - - - -
b4a89257 by Byron Campen at 2026-07-14T07:43:25+02:00
Bug 2043188: Simplify the buffer handling in RTCEncodedFrameBase. r=sfink a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D310880
- - - - -
a8146042 by Timothy Nikkel at 2026-07-14T07:43:26+02:00
Bug 2028004. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D310743
- - - - -
f8bb7186 by Randell Jesup at 2026-07-14T07:43:27+02:00
Bug 2029734: Flush before calling sctp_process_init() a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D295148
Differential Revision: https://phabricator.services.mozilla.com/D311133
- - - - -
2d6da74b by Randell Jesup at 2026-07-14T07:43:28+02:00
Bug 2045773: Add usrsctp TSN gap check a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309815
Differential Revision: https://phabricator.services.mozilla.com/D311396
- - - - -
e17a56a1 by Timothy Nikkel at 2026-07-14T07:43:29+02:00
Bug 2022635. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311246
- - - - -
c0d41848 by Vincent Hilla at 2026-07-14T07:43:30+02:00
Bug 2035756 - Verify srcdoc and data result principal. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309545
Differential Revision: https://phabricator.services.mozilla.com/D311257
- - - - -
d35af1a8 by Sotaro Ikeda at 2026-07-14T07:43:31+02:00
Bug 2051658 - for esr140 with D265934 a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310958
- - - - -
9022c51d by James Teh at 2026-07-14T07:43:32+02:00
Bug 2052562: Don't allow moves into a detached subtree. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D310457
Differential Revision: https://phabricator.services.mozilla.com/D311752
- - - - -
53fecf21 by Jan de Mooij at 2026-07-14T07:43:33+02:00
Bug 2052207 - Disable OptimizeIteratorIndices optimization. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D310355
Differential Revision: https://phabricator.services.mozilla.com/D311774
- - - - -
8cea04be by Jonathan Kew at 2026-07-14T07:43:34+02:00
Bug 2053576 - Clamp number of components assigned by SetDetailedGlyphs. a=pascalc
(Based on clauditor-suggested patch)
Original Revision: https://phabricator.services.mozilla.com/D311412
Differential Revision: https://phabricator.services.mozilla.com/D311780
- - - - -
b93ab09b by Randell Jesup at 2026-07-14T07:43:34+02:00
Bug 2045848: Avoid avoid re-initting usrsctp a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311578
- - - - -
ca735d05 by ffxbld at 2026-07-14T07:43:36+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311783
- - - - -
6d554987 by Timothy Nikkel at 2026-07-14T07:43:37+02:00
Bug 2052841. Don't taint a same-origin response that a service worker substitutes for a cross-origin request. a=pascalc
When a service worker answers a cross-origin request with a same-origin
resource (respondWith(fetch(<same-origin URL>))), the response is delivered as
an internal redirect from the cross-origin request URL to the same-origin
response URL. nsITimedChannel's allRedirectsSameOrigin counts that internal
redirect as a cross-origin hop, so consumers that use it to decide tainting
(image loads, stylesheets, media) treat the resource as cross-origin and taint
it -- even though the bytes are same-origin and should be readable.
Add nsITimedChannel::allRedirectsSameOriginIgnoringInternal, computed like
allRedirectsSameOrigin but ignoring internal (e.g. service-worker response-URL)
redirects, and switch the tainting consumers (imgRequestProxy, the CSS Loader,
and the media resources) to it. Real cross-origin redirects still flip it, so
genuine cross-origin loads (including bounce-backs) still taint. Other users of
allRedirectsSameOrigin (resource timing, Fetch body-access) intentionally keep
the original flag.
Add a service-worker regression test for the same-origin substitution case
(CSS).
Differential Revision: https://phabricator.services.mozilla.com/D311505
- - - - -
8d1a814b by Timothy Nikkel at 2026-07-14T07:43:38+02:00
Bug 2050626. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311507
- - - - -
54ba522a by Vincent Hilla at 2026-07-14T07:43:39+02:00
Bug 2048851 - Clear principalToInherit in LoadPageAsViewSource. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309163
Differential Revision: https://phabricator.services.mozilla.com/D311786
- - - - -
542aa3e4 by Jon Coppeard at 2026-07-14T07:43:40+02:00
Bug 2046917 - Make implicit edge marking state runtime wide (ESR140) a=pascalc
Currently this is tracked per-marker but the effect should be per-runtime.
There may be multiple markers due to parallel marking.
I couldn't get the testcase to reproduce here either.
Original Revision: https://phabricator.services.mozilla.com/D307221
Differential Revision: https://phabricator.services.mozilla.com/D311837
- - - - -
0278ecd0 by Andreas Farre at 2026-07-14T07:43:41+02:00
Bug 2045468 - Make sure to check the correct browsing context. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305611
Differential Revision: https://phabricator.services.mozilla.com/D311833
- - - - -
a8580110 by Emilio Cobos Álvarez at 2026-07-14T07:43:42+02:00
Bug 2045407 - Validate surface format properly. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305381
Differential Revision: https://phabricator.services.mozilla.com/D310858
- - - - -
e7de1788 by Eden Chuang at 2026-07-14T07:43:43+02:00
Bug 2039452 - Validate file:// URIs in PExternalHelperApp against the sending process's remote type. a=RyanVM DONTBUILD
The parent derived the native helper-launch decision from a
content-process supplied aWasFileChannel flag and URI rather than
binding it to the sending process's capabilities.
Stop sending aWasFileChannel over IPC and derive it on the parent from
the actual URI, and reject a file:// URI in PExternalHelperApp from a
process that is not allowed to load local files (mirrors the file://
policy in ValidatePrincipalCouldPotentiallyBeLoadedBy).
Original Revision: https://phabricator.services.mozilla.com/D309577
Differential Revision: https://phabricator.services.mozilla.com/D311929
- - - - -
7acd409a by Matthew Gregan at 2026-07-14T07:43:44+02:00
Bug 2052753 - Update cubeb-pulse-rs to b46defa to reject start() on a draining stream. a=RyanVM DONTBUILD
Backport of upstream cubeb-pulse-rs commit
88194f91c8778fa608a19af7b91306094525595d, carried on the
mozilla/cubeb-pulse-rs esr140 branch.
The backport adapts the error construction to the cubeb-backend version
vendored on this branch (Error::error() rather than Error::Error).
Original Revision: https://phabricator.services.mozilla.com/D310552
Differential Revision: https://phabricator.services.mozilla.com/D311956
- - - - -
975c16db by Nika Layzell at 2026-07-14T07:43:45+02:00
Bug 1800120 - Part 1: Remove CreateWindowInDifferentProcess, a=RyanVM DONTBUILD
This method is now dead code, as we have shipped fission.autostart on
all platforms since bug 1998306, and CreateWindowInDifferentProcess is
disabled when Fission is disabled.
This is intended to be a fairly straightforward change to remove the
unnecessary IPC call, and does not clean up the implementation to remove
the now-dead codepaths from CommonCreateWindow. That is done in part 2.
Original Revision: https://phabricator.services.mozilla.com/D297450
Differential Revision: https://phabricator.services.mozilla.com/D311910
- - - - -
684e4aab by Nika Layzell at 2026-07-14T07:43:46+02:00
Bug 1800120 - Part 2: Remove now-dead parameters in CommonCreateWindow, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D297451
Differential Revision: https://phabricator.services.mozilla.com/D311911
- - - - -
adf45eb8 by Nika Layzell at 2026-07-14T07:43:47+02:00
Bug 1800120 - Part 3: Update test expectations for window-open-popup-behavior.html, a=RyanVM DONTBUILD
This patch updates the expectations for window-open-popup-behavior.html
on Android to reflect the fact that many of these tests appear to have
only been passing due to Android using CreateWindowInDifferentProcess.
Now that codepath has been removed, the test is now failing more
consistently across platforms.
I also removed the pass cases for linux-nofis, though I don't think we
run that configuration in treeherder anymore off the top of my head.
It appears that we fail this test due to a fundamental mismatch between
our implementation and the WPT. Specifically it appears the test expects
that specifying noopener/noreferrer overrides all other window open
options, and always forces the document to open in a tab, not a popup.
We always respect the specified options even if noopener is set.
Original Revision: https://phabricator.services.mozilla.com/D308619
Differential Revision: https://phabricator.services.mozilla.com/D311912
- - - - -
f917afa7 by Ryan Hunt at 2026-07-14T07:43:48+02:00
Bug 2051854 - Clean up StackSlotAllocator. a=RyanVM
Route all height_ increments through a checked incrementHeight() and make
slot allocation fallible.
Original Revision: https://phabricator.services.mozilla.com/D309918
Differential Revision: https://phabricator.services.mozilla.com/D311873
- - - - -
361 changed files:
- .cargo/config.toml.in
- CLOBBER
- Cargo.lock
- accessible/base/CacheConstants.h
- accessible/base/TextLeafRange.cpp
- accessible/ipc/DocAccessibleParent.cpp
- accessible/ipc/RemoteAccessible.cpp
- accessible/ipc/RemoteAccessible.h
- browser/app/profile/firefox.js
- browser/components/DesktopActorRegistry.sys.mjs
- browser/components/build/components.conf
- browser/components/distribution.sys.mjs
- browser/components/enterprisepolicies/helpers/WebsiteFilter.sys.mjs
- + browser/components/enterprisepolicies/tests/xpcshell/test_websitefilter.js
- browser/components/enterprisepolicies/tests/xpcshell/xpcshell.toml
- browser/components/metrics.yaml
- − browser/components/shell/Windows11LimitedAccessFeatures.cpp
- − browser/components/shell/Windows11LimitedAccessFeatures.h
- browser/components/shell/Windows11TaskbarPinning.cpp
- browser/components/shell/moz.build
- + browser/components/shell/nsILimitedAccessFeature.idl
- + browser/components/shell/rust/shell_windows/Cargo.toml
- + browser/components/shell/rust/shell_windows/src/LimitedAccessFeatureService.h
- + browser/components/shell/rust/shell_windows/src/lib.rs
- + browser/components/shell/rust/shell_windows/src/limited_access_features.rs
- browser/components/shell/test/gtest/LimitedAccessFeatureTests.cpp
- + browser/components/tests/unit/test_distribution_mozillaonline.js
- browser/components/tests/unit/xpcshell.toml
- browser/config/version.txt
- browser/config/version_display.txt
- config/create_rc.py
- config/milestone.txt
- devtools/server/actors/source.js
- docshell/base/BrowsingContext.cpp
- docshell/base/BrowsingContext.h
- docshell/base/nsDocShell.cpp
- docshell/base/nsDocShellLoadState.cpp
- dom/base/CrossShadowBoundaryRange.cpp
- dom/base/CrossShadowBoundaryRange.h
- dom/base/StaticRange.cpp
- dom/base/StaticRange.h
- dom/base/TimeoutManager.cpp
- dom/base/nsContentUtils.h
- dom/base/nsINode.cpp
- dom/base/nsINode.h
- dom/base/nsTextFragment.h
- dom/bindings/ToJSValue.h
- dom/cache/CacheOpParent.cpp
- dom/cache/CacheStreamControlParent.cpp
- dom/cache/CacheStreamControlParent.h
- dom/canvas/CanvasRenderingContext2D.cpp
- dom/canvas/ClientWebGLContext.cpp
- dom/canvas/DrawTargetWebgl.cpp
- dom/canvas/WebGLProgram.cpp
- dom/canvas/nsICanvasRenderingContextInternal.cpp
- dom/cookiestore/CookieStoreParent.cpp
- dom/events/IMEStateManager.cpp
- dom/events/TextComposition.h
- dom/fetch/Fetch.cpp
- dom/fetch/Fetch.h
- dom/fetch/Request.cpp
- dom/fetch/Response.cpp
- dom/gamepad/GamepadPlatformService.cpp
- dom/html/HTMLCanvasElement.cpp
- dom/html/HTMLCanvasElement.h
- dom/html/HTMLImageElement.cpp
- dom/html/HTMLImageElement.h
- dom/html/HTMLSlotElement.cpp
- dom/html/nsGenericHTMLElement.cpp
- dom/indexedDB/Key.cpp
- dom/ipc/BrowserParent.cpp
- dom/ipc/ContentChild.cpp
- dom/ipc/ContentParent.cpp
- dom/ipc/ContentParent.h
- dom/ipc/DOMTypes.ipdlh
- dom/ipc/PContent.ipdl
- dom/ipc/ProcessIsolation.cpp
- dom/media/ChannelMediaResource.cpp
- dom/media/CloneableWithRangeMediaResource.cpp
- dom/media/FileMediaResource.cpp
- dom/media/GraphDriver.cpp
- dom/media/GraphDriver.h
- dom/media/MediaQueue.h
- dom/media/eme/MediaKeys.cpp
- dom/media/eme/clearkey/ClearKeyDecryptionManager.cpp
- dom/media/gmp/GMPVideoDecoderChild.cpp
- dom/media/gmp/GMPVideoi420FrameImpl.cpp
- dom/media/ipc/MFCDMParent.cpp
- dom/media/ipc/MFCDMParent.h
- dom/media/ipc/MFMediaEngineParent.cpp
- dom/media/mediasink/AudioDecoderInputTrack.cpp
- dom/media/mediasource/ContainerParser.cpp
- dom/media/mp4/SinfParser.cpp
- dom/media/platforms/ffmpeg/FFmpegVideoDecoder.cpp
- dom/media/platforms/ffmpeg/FFmpegVideoFramePool.cpp
- + dom/media/platforms/ffmpeg/FFmpegVideoUtils.h
- dom/media/platforms/ffmpeg/ffvpx/D3D11TextureWrapper.cpp
- dom/media/platforms/ffmpeg/ffvpx/D3D11TextureWrapper.h
- dom/media/platforms/wmf/DXVA2Manager.cpp
- dom/media/webaudio/MediaBufferDecoder.cpp
- dom/media/webrtc/jsapi/RTCEncodedFrameBase.cpp
- dom/promise/Promise.cpp
- dom/quota/EncryptedBlock.h
- dom/quota/EncryptingOutputStream_impl.h
- dom/security/nsContentSecurityManager.cpp
- dom/streams/ReadableStream.h
- dom/streams/UnderlyingSourceCallbackHelpers.h
- dom/view-transitions/ViewTransition.cpp
- dom/webtransport/api/WebTransport.cpp
- dom/webtransport/parent/WebTransportParent.cpp
- dom/webtransport/parent/WebTransportParent.h
- + dom/webtransport/test/xpcshell/head.js
- dom/webtransport/test/xpcshell/test_close.js
- dom/webtransport/test/xpcshell/test_simple_conn.js
- dom/webtransport/test/xpcshell/test_simple_stream.js
- dom/webtransport/test/xpcshell/xpcshell.toml
- dom/workers/ScriptLoader.cpp
- dom/workers/loader/CacheLoadHandler.cpp
- dom/workers/loader/NetworkLoadHandler.cpp
- dom/workers/loader/WorkerLoadContext.cpp
- dom/workers/loader/WorkerLoadContext.h
- editor/libeditor/CompositionTransaction.cpp
- editor/libeditor/CompositionTransaction.h
- editor/libeditor/EditorBase.cpp
- editor/libeditor/TextEditSubActionHandler.cpp
- editor/libeditor/WhiteSpaceVisibilityKeeper.cpp
- editor/libeditor/tests/mochitest.toml
- + editor/libeditor/tests/test_composition_modified_as_multiple_text_nodes.html
- gfx/2d/DrawTargetSkia.cpp
- gfx/2d/ScaledFontDWrite.cpp
- gfx/2d/ScaledFontFontconfig.cpp
- gfx/2d/SkConvolver.cpp
- gfx/angle/checkout/src/compiler/translator/IntermNode.cpp
- gfx/angle/checkout/src/compiler/translator/OutputHLSL.cpp
- gfx/angle/checkout/src/libANGLE/renderer/d3d/d3d11/StateManager11.h
- gfx/cairo/cairo/src/cairo-cff-subset.c
- gfx/cairo/cairo/src/cairo-ft-font.c
- gfx/cairo/cairo/src/cairo-scaled-font-subsets.c
- gfx/cairo/cairo/src/cairo-type1-subset.c
- gfx/cairo/cairo/src/cairoint.h
- + gfx/cairo/patches/0034-cff-dict-validation.patch
- + gfx/cairo/patches/0035-cff-fdselect-bounds.patch
- + gfx/cairo/patches/0036-cff-operator-bounds.patch
- + gfx/cairo/patches/0037-fdselect-checks.patch
- + gfx/cairo/patches/0037-pcf-row_bytes.patch
- + gfx/cairo/patches/0038-gid-range-check.patch
- + gfx/cairo/patches/0039-type1-stack-check.patch
- + gfx/cairo/patches/0040-type1-decode-integer.patch
- + gfx/cairo/patches/0041-Bug-2048799-flip-polarity-of-a-bounds-check.patch
- gfx/layers/D3D11ZeroCopyTextureImage.cpp
- gfx/layers/D3D11ZeroCopyTextureImage.h
- gfx/layers/DcompSurfaceImage.cpp
- gfx/layers/ImageContainer.cpp
- gfx/layers/ImageContainer.h
- gfx/layers/apz/util/APZCCallbackHelper.cpp
- gfx/layers/composite/TextureHost.cpp
- gfx/layers/d3d11/FenceD3D11.cpp
- gfx/layers/d3d11/FenceD3D11.h
- gfx/layers/d3d11/TextureD3D11.cpp
- gfx/layers/ipc/CanvasChild.cpp
- gfx/layers/opengl/DMABUFTextureHostOGL.cpp
- gfx/layers/opengl/MacIOSurfaceTextureHostOGL.cpp
- gfx/layers/opengl/TextureHostOGL.cpp
- gfx/layers/wr/AsyncImagePipelineManager.cpp
- gfx/layers/wr/WebRenderBridgeParent.cpp
- gfx/layers/wr/WebRenderCommandBuilder.cpp
- gfx/layers/wr/WebRenderMessageUtils.h
- gfx/thebes/gfxDWriteFontList.cpp
- gfx/thebes/gfxFcPlatformFontList.cpp
- gfx/thebes/gfxFcPlatformFontList.h
- gfx/thebes/gfxFont.cpp
- gfx/thebes/gfxFontEntry.cpp
- gfx/thebes/gfxFontEntry.h
- gfx/thebes/gfxHarfBuzzShaper.cpp
- gfx/thebes/gfxTextRun.cpp
- gfx/thebes/gfxUserFontSet.cpp
- gfx/thebes/gfxUserFontSet.h
- gfx/webrender_bindings/DCLayerTree.cpp
- gfx/webrender_bindings/RenderD3D11TextureHost.cpp
- gfx/webrender_bindings/WebRenderTypes.h
- gfx/wr/swgl/src/gl.cc
- gfx/wr/swgl/src/rasterize.h
- gfx/wr/webrender/src/texture_cache.rs
- gfx/ycbcr/ycbcr_to_rgb565.cpp
- image/BlobSurfaceProvider.cpp
- image/RasterImage.cpp
- image/decoders/nsAVIFDecoder.cpp
- image/imgRequest.cpp
- image/imgRequest.h
- image/imgRequestProxy.cpp
- ipc/glue/BackgroundParentImpl.cpp
- ipc/glue/BackgroundParentImpl.h
- ipc/glue/PBackground.ipdl
- ipc/glue/SharedMemoryPlatform_posix.cpp
- js/public/UbiNode.h
- js/src/builtin/RegExp.cpp
- js/src/builtin/RegExp.js
- js/src/builtin/SelfHostingDefines.h
- js/src/ctypes/CTypes.cpp
- js/src/gc/GC.cpp
- js/src/gc/GCMarker.h
- js/src/gc/GCRuntime.h
- js/src/gc/Marking.cpp
- js/src/gc/Nursery.cpp
- js/src/gc/Verifier.cpp
- js/src/jit/BacktrackingAllocator.cpp
- js/src/jit/BacktrackingAllocator.h
- js/src/jit/JitFrames.cpp
- js/src/jit/JitOptions.cpp
- js/src/jit/LIR.h
- js/src/jit/SimpleAllocator.cpp
- js/src/jit/SimpleAllocator.h
- js/src/jit/StackSlotAllocator.h
- js/src/jit/shared/IonAssemblerBufferWithConstantPools.h
- js/src/wasm/WasmBaselineCompile.cpp
- js/src/wasm/WasmInstance.cpp
- js/src/wasm/WasmStubs.cpp
- js/src/wasm/WasmTable.cpp
- js/xpconnect/src/XPCConvert.cpp
- layout/base/PresShell.cpp
- layout/base/nsCSSFrameConstructor.cpp
- layout/base/nsILayoutHistoryState.idl
- layout/base/nsLayoutHistoryState.cpp
- layout/generic/TextDrawTarget.h
- layout/generic/nsImageMap.cpp
- layout/painting/DottedCornerFinder.cpp
- layout/style/FontFaceSetImpl.cpp
- layout/style/FontFaceSetWorkerImpl.cpp
- layout/style/FontFaceSetWorkerImpl.h
- layout/style/FontLoaderUtils.cpp
- layout/style/FontLoaderUtils.h
- layout/style/ServoCSSRuleList.cpp
- layout/style/StyleSheet.cpp
- layout/style/StyleSheet.h
- + media/libcubeb/delay-line-bounds.patch
- media/libcubeb/moz.yaml
- media/libcubeb/src/cubeb_resampler_internal.h
- media/libsoundtouch/moz.yaml
- + media/libsoundtouch/ratetransposer-clamp-dest-size.patch
- media/libsoundtouch/src/RateTransposer.cpp
- mozglue/misc/Printf.cpp
- mozglue/misc/Printf.h
- netwerk/base/RedirectChannelRegistrar.cpp
- netwerk/base/RedirectChannelRegistrar.h
- netwerk/base/SimpleChannelParent.cpp
- netwerk/base/nsIRedirectChannelRegistrar.idl
- netwerk/base/nsITimedChannel.idl
- netwerk/base/nsNetUtil.cpp
- netwerk/base/nsNetUtil.h
- netwerk/base/nsStandardURL.cpp
- netwerk/dns/DNSPacket.cpp
- netwerk/dns/TRRQuery.cpp
- netwerk/dns/TRRQuery.h
- netwerk/dns/effective_tld_names.dat
- netwerk/ipc/DocumentLoadListener.cpp
- netwerk/ipc/ParentChannelWrapper.cpp
- netwerk/ipc/ParentChannelWrapper.h
- netwerk/ipc/ParentProcessDocumentChannel.cpp
- netwerk/protocol/data/DataChannelParent.cpp
- netwerk/protocol/file/FileChannelParent.cpp
- netwerk/protocol/http/BackgroundChannelRegistrar.cpp
- netwerk/protocol/http/HttpBackgroundChannelParent.cpp
- netwerk/protocol/http/HttpBackgroundChannelParent.h
- netwerk/protocol/http/HttpBaseChannel.cpp
- netwerk/protocol/http/HttpBaseChannel.h
- netwerk/protocol/http/HttpChannelChild.cpp
- netwerk/protocol/http/HttpChannelParams.ipdlh
- netwerk/protocol/http/HttpChannelParent.cpp
- netwerk/protocol/http/HttpChannelParent.h
- netwerk/protocol/http/NullHttpChannel.cpp
- netwerk/protocol/http/NullHttpChannel.h
- netwerk/protocol/http/ReplacedHttpResponse.cpp
- netwerk/protocol/http/ReplacedHttpResponse.h
- netwerk/protocol/http/nsHttpRequestHead.cpp
- netwerk/protocol/http/nsHttpRequestHead.h
- netwerk/protocol/http/nsHttpResponseHead.cpp
- netwerk/protocol/http/nsHttpResponseHead.h
- netwerk/protocol/http/nsHttpTransaction.cpp
- netwerk/protocol/websocket/WebSocketChannel.cpp
- netwerk/sctp/datachannel/DataChannel.cpp
- netwerk/sctp/src/netinet/sctp_indata.c
- netwerk/sctp/src/netinet/sctp_input.c
- netwerk/streamconv/converters/nsUnknownDecoder.cpp
- parser/html/nsHtml5TreeOperation.cpp
- parser/htmlparser/nsParser.cpp
- python/mozbuild/mozbuild/repackaging/deb.py
- security/ct/CTKnownLogs.h
- security/manager/ssl/StaticHPKPins.h
- security/manager/ssl/nsSTSPreloadList.inc
- security/manager/tools/log_list.json
- services/settings/dumps/blocklists/addons-bloomfilters.json
- services/settings/dumps/main/devtools-compatibility-browsers.json
- services/settings/dumps/main/search-config-v2.json
- services/settings/dumps/main/translations-models.json
- services/settings/dumps/security-state/intermediates.json
- services/settings/dumps/security-state/onecrl.json
- taskcluster/config.yml
- taskcluster/docker/debian-packages/Dockerfile
- taskcluster/kinds/packages/ubuntu.yml
- taskcluster/kinds/release-update-verify-config/kind.yml
- taskcluster/kinds/searchfox/kind.yml
- − testing/web-platform/meta/fetch/images/canvas-remote-read-remote-image-redirect.html.ini
- testing/web-platform/meta/html/browsers/the-window-object/window-open-popup-behavior.html.ini
- testing/web-platform/tests/html/semantics/forms/form-control-infrastructure/form_owner_and_table_2.html
- + testing/web-platform/tests/service-workers/service-worker/css-sw-same-origin-substitution.https.html
- + testing/web-platform/tests/service-workers/service-worker/resources/css-sw-same-origin-substitution-iframe.sub.html
- + testing/web-platform/tests/service-workers/service-worker/resources/css-sw-same-origin-substitution-worker.js
- testing/web-platform/tests/tools/certs/cacert.key
- testing/web-platform/tests/tools/certs/cacert.pem
- testing/web-platform/tests/tools/certs/web-platform.test.key
- testing/web-platform/tests/tools/certs/web-platform.test.pem
- third_party/rlbox/include/rlbox_stdlib.hpp
- third_party/rust/audioipc2-client/.cargo-checksum.json
- third_party/rust/audioipc2-client/src/context.rs
- third_party/rust/audioipc2-client/src/stream.rs
- third_party/rust/audioipc2-server/.cargo-checksum.json
- third_party/rust/audioipc2-server/src/server.rs
- third_party/rust/audioipc2/.cargo-checksum.json
- third_party/rust/audioipc2/src/messages.rs
- third_party/rust/cubeb-pulse/.cargo-checksum.json
- third_party/rust/cubeb-pulse/src/backend/stream.rs
- toolkit/components/extensions/Extension.sys.mjs
- toolkit/components/extensions/ExtensionParent.sys.mjs
- toolkit/components/extensions/moz.build
- toolkit/components/extensions/test/mochitest/test_ext_test.html
- + toolkit/components/extensions/test/xpcshell/test_wpt_actor_pref.js
- toolkit/components/extensions/test/xpcshell/test_wpt_test_onMessage.js
- toolkit/components/extensions/test/xpcshell/xpcshell-common.toml
- toolkit/components/pdfjs/content/PdfStreamConverter.sys.mjs
- toolkit/components/pdfjs/content/web/viewer-geckoview.mjs
- toolkit/components/pdfjs/content/web/viewer.mjs
- toolkit/components/pdfjs/test/browser.toml
- + toolkit/components/pdfjs/test/browser_pdfjs_sandboxed_iframe.js
- + toolkit/components/pdfjs/test/file_pdfjs_csp.sjs
- + toolkit/components/pdfjs/test/file_pdfjs_csp_sandbox_opener.html
- + toolkit/components/pdfjs/test/file_pdfjs_csp_sandbox_opener.html^headers^
- toolkit/components/reputationservice/ApplicationReputation.cpp
- toolkit/components/reputationservice/ApplicationReputation.h
- toolkit/components/reputationservice/test/gtest/TestExecutableLists.cpp
- toolkit/components/search/tests/xpcshell/searchconfigs/test_ecosia.js
- toolkit/components/telemetry/core/TelemetryEvent.cpp
- toolkit/components/telemetry/other/TelemetryIOInterposeObserver.cpp
- toolkit/components/telemetry/other/UntrustedModulesDataSerializer.cpp
- toolkit/components/viewsource/test/browser/browser.toml
- + toolkit/components/viewsource/test/browser/browser_bug2048851.js
- + toolkit/components/viewsource/test/browser/file_bug2048851.html
- toolkit/library/rust/gkrust-features.mozbuild
- toolkit/library/rust/shared/Cargo.toml
- toolkit/library/rust/shared/lib.rs
- toolkit/mozapps/extensions/AddonManagerStartup.cpp
- tools/lint/clippy.yml
- uriloader/exthandler/ExternalHelperAppParent.cpp
- uriloader/exthandler/ExternalHelperAppParent.h
- uriloader/exthandler/nsExternalHelperAppService.cpp
- widget/ClipboardWriteRequestParent.cpp
- widget/GfxInfoBase.cpp
- widget/android/EventDispatcher.cpp
- widget/windows/WinRegistry.cpp
- widget/windows/WinRegistry.h
- xpcom/base/ErrorList.py
- xpcom/io/SnappyFrameUtils.cpp
The diff was not included because it is too large.
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/57c25f…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/compare/57c25f…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/tor-browser] Pushed new tag base-browser-140.12.0esr-15.0-1-build3
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed new tag base-browser-140.12.0esr-15.0-1-build3 at The Tor Project / Applications / Tor Browser
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/tor-browser/-/tree/base-brow…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0
[Git][tpo/applications/mullvad-browser][mullvad-browser-140.12.0esr-15.0-1] 179 commits: Bug 2046256 - extend web-platform-tests test certificates until 2027-05-11....
by ma1 (@ma1) 14 Jul '26
by ma1 (@ma1) 14 Jul '26
14 Jul '26
ma1 pushed to branch mullvad-browser-140.12.0esr-15.0-1 at The Tor Project / Applications / Mullvad Browser
Commits:
539bba5f by Sebastian Hengst at 2026-07-14T07:58:41+02:00
Bug 2046256 - extend web-platform-tests test certificates until 2027-05-11. r=Sasha,jgraham a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D305756
- - - - -
18436ae0 by Release Engineering Landoscript at 2026-07-14T07:58:43+02:00
Automatic version bump NO BUG a=release CLOSED TREE
- - - - -
919ee8b6 by Release Engineering Landoscript at 2026-07-14T07:58:45+02:00
No Bug - Update configs after merge day operations a=release
IGNORE BROKEN CHANGESETS
CLOSED TREE
- - - - -
96fbfbbe by Nicholas Rishel at 2026-07-14T07:58:46+02:00
Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D277134
Differential Revision: https://phabricator.services.mozilla.com/D305398
- - - - -
6ee9a1d1 by rperta at 2026-07-14T07:58:48+02:00
Revert "Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM" for causing build bustages DONTBUILD
This reverts commit 7fb19cd315c5b13d32fda38234fa1fd0efa06df6.
- - - - -
de6d88c6 by Andrea Marchesini at 2026-07-14T07:58:50+02:00
Bug 2027788 - Ignore the distribution ini file if its global.id is mozillaonline, a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D305913
- - - - -
d1f9d60d by Emilio Cobos Álvarez at 2026-07-14T07:58:52+02:00
Bug 2046162 - Remove some redundant pub qualifiers. a=RyanVM DONTBUILD
The enum is not public so this doesn't change behavior but a patch I'm
working on in cbindgen gets a bit confused with this.
Original Revision: https://phabricator.services.mozilla.com/D305678
Differential Revision: https://phabricator.services.mozilla.com/D305831
- - - - -
539eb828 by Andrew Osmond at 2026-07-14T07:58:54+02:00
Bug 2045730. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305642
Differential Revision: https://phabricator.services.mozilla.com/D305722
- - - - -
ec17aa79 by Alastor Wu at 2026-07-14T07:58:55+02:00
Bug 2043739 - (esr140) Adjust CDM lifetime handling in the Media Foundation CDM IPC path. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306517
- - - - -
112636c6 by Alastor Wu at 2026-07-14T07:58:57+02:00
Bug 2045281 - Use the decoded frame format for ffmpeg video chroma plane geometry. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305741
Differential Revision: https://phabricator.services.mozilla.com/D306247
- - - - -
373a6cd5 by Leo Tenenbaum at 2026-07-14T07:58:59+02:00
Bug 2045732 - a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305347
Differential Revision: https://phabricator.services.mozilla.com/D306136
- - - - -
f6fc626a by Brad Werth at 2026-07-14T07:59:00+02:00
Bug 2040119: Enforce ownership of external image in WebRenderBridgeParent::UpdateSharedExternalImage. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304923
Differential Revision: https://phabricator.services.mozilla.com/D306193
- - - - -
f87496d9 by Valentin Gosu at 2026-07-14T07:59:02+02:00
Bug 2036591 - Use origin attributes in FailDelayManager a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304395
Differential Revision: https://phabricator.services.mozilla.com/D306416
- - - - -
01e0884b by ffxbld at 2026-07-14T07:59:04+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D306766
- - - - -
2794c54e by Tim Huang at 2026-07-14T07:59:06+02:00
Bug 2038587 - Introduce "wsb" to the application reputation check. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D301066
Differential Revision: https://phabricator.services.mozilla.com/D306933
- - - - -
0ec42a7f by Emilio Cobos Álvarez at 2026-07-14T07:59:08+02:00
Bug 2045616 - Fix CharacterDataBuffer OOM handling. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305165
Differential Revision: https://phabricator.services.mozilla.com/D306945
- - - - -
e64f4970 by Emilio Cobos Álvarez at 2026-07-14T07:59:09+02:00
Bug 2045413 - Deal correctly with <area> element removals. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305124
Differential Revision: https://phabricator.services.mozilla.com/D306939
- - - - -
1b0d5d4a by Bob Owen at 2026-07-14T07:59:11+02:00
Bug 2045769 - Check required snapshot shmem size against actual size. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305707
Differential Revision: https://phabricator.services.mozilla.com/D306972
- - - - -
4cb8c8da by Tooru Fujisawa at 2026-07-14T07:59:13+02:00
Bug 2013415 - Use b-linux-docker-large-amd for searchfox jobs. r=ahal a=NPOTB DONTBUILD
This reduces the time taken by the linux64-searchfox job from 113min to 53min.
Differential Revision: https://phabricator.services.mozilla.com/D283000
- - - - -
56b15878 by Ryan VanderMeulen at 2026-07-14T07:59:15+02:00
Bug 2013415 - Add b-linux-docker-large-amd worker alias to esr140 config. a=bustage DONTBUILD
- - - - -
06edc5db by Ryan VanderMeulen at 2026-07-14T07:59:16+02:00
Bug 2013415 - Use docker-worker implementation for b-linux-docker-large-amd alias. a=bustage DONTBUILD
- - - - -
aab1a725 by Nicholas Rishel at 2026-07-14T07:59:18+02:00
Bug 2007035 - Migrate Windows Limited Access Feature code to Rust. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D277134
Differential Revision: https://phabricator.services.mozilla.com/D305398
- - - - -
daf7c58c by Tom Schuster at 2026-07-14T07:59:20+02:00
Bug 2044612 - Use ClientInfo for font loading in Worker. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305486
Differential Revision: https://phabricator.services.mozilla.com/D307286
- - - - -
2852f195 by Tom Schuster at 2026-07-14T07:59:22+02:00
Bug 2041902 - For WebTransport require a ClientInfo. . a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305171
Differential Revision: https://phabricator.services.mozilla.com/D307271
- - - - -
934bec14 by Alastor Wu at 2026-07-14T07:59:23+02:00
Bug 2045756 - Skip a renderer-referenced surface when matching by FFmpeg id in FFmpegVideoFramePool a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305429
Differential Revision: https://phabricator.services.mozilla.com/D307086
- - - - -
621a5716 by Timothy Nikkel at 2026-07-14T07:59:25+02:00
Bug 2045624. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306891
- - - - -
f28dd889 by Masayuki Nakano at 2026-07-14T07:59:26+02:00
Bug 2045405 - Improve the error handling in `PresShell::CompleteMove` a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305544
Differential Revision: https://phabricator.services.mozilla.com/D307163
- - - - -
977b6ade by Timothy Nikkel at 2026-07-14T07:59:28+02:00
Bug 2045614. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D306900
- - - - -
f83036ef by Lee Salzman at 2026-07-14T07:59:29+02:00
Bug 2045625. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305785
Differential Revision: https://phabricator.services.mozilla.com/D307126
- - - - -
d266991d by Lee Salzman at 2026-07-14T07:59:31+02:00
Bug 2045185. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307130
- - - - -
62f08a35 by Edgar Chen at 2026-07-14T07:59:32+02:00
Bug 2045513 - Make parser update form owner properly; a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305669
Differential Revision: https://phabricator.services.mozilla.com/D307295
- - - - -
c14828b2 by az at 2026-07-14T07:59:34+02:00
Bug 2045742 - a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305387
Differential Revision: https://phabricator.services.mozilla.com/D307110
- - - - -
e2eb16e5 by Andrew McCreight at 2026-07-14T07:59:36+02:00
Bug 2048110 - Add remoteTypes to AboutTabCrashed, LightweightTheme, Megalist. a=RyanVM DONTBUILD
These are only used in a few specific processes.
Original Revision: https://phabricator.services.mozilla.com/D307152
Differential Revision: https://phabricator.services.mozilla.com/D307574
- - - - -
a878dff6 by Leo Tenenbaum at 2026-07-14T07:59:37+02:00
Bug 2047718 - Check for unexpected DOM changes in more places in EnsureNoInvisibleWhiteSpaces. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306863
Differential Revision: https://phabricator.services.mozilla.com/D307559
- - - - -
a2ced920 by Brad Werth at 2026-07-14T07:59:39+02:00
Bug 2045184: Make SharedContextWebgl destructor prevent resurrection. a=RyanVM
Detaching the WeakPtr early prevents the object from being AddRef'ed by
anything later in the destructor.
Original Revision: https://phabricator.services.mozilla.com/D305720
Differential Revision: https://phabricator.services.mozilla.com/D307604
- - - - -
6ecc0fb4 by Ryan VanderMeulen at 2026-07-14T07:59:40+02:00
Bug 2045185 - Fix bustage from stride type mismatch. a=bustage
stride is a plain size_t on esr140 (GetAlignedStride's Maybe<> return type was
never backported), so the .value() call from the backport fails to compile.
- - - - -
a56b3b58 by Eden Chuang at 2026-07-14T07:59:42+02:00
Bug 2005113 - Bind FetchBodyBase::mReadableStream to the body stream and rebind it on clone(). . a=RyanVM DONTBUILD
Create the body ReadableStream from the underlying body input stream directly.
When clone() is called before the stream has been read and the underlying body
is not cloneable, clone() replaces the original input stream; repoint the
existing unread native ReadableStream at the replacement so the original stream
is not read from two places. This keeps native bodies native (cancellation of
an unread stream still tears down the channel, and the consume path keeps
reading the body input stream directly) without teeing native byte streams.
This no longer clones the body when creating the ReadableStream, so it does not
buffer the whole body; restore the huge-fetch crashtest expectations that were
disabled to avoid OOMing the 32-bit process.
Original Revision: https://phabricator.services.mozilla.com/D280568
(cherry picked from commit 38e360c0d435c4bd9b0e45b207877610506433f3)
Differential Revision: https://phabricator.services.mozilla.com/D307754
- - - - -
91346671 by Alastor Wu at 2026-07-14T07:59:43+02:00
Bug 2045424 - (esr140) Constrain the per-sample IV size in the CENC parser and ClearKey decryptor. a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307384
- - - - -
b542ca66 by Alastor Wu at 2026-07-14T07:59:45+02:00
Bug 2045395 - (esr140) Use checked arithmetic for the interleave buffer length in AudioDecoderInputTrack a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307385
- - - - -
2132f01f by Shravan Narayan at 2026-07-14T07:59:46+02:00
Bug 2045149 - Fix rlbox's unnecessary rejection of unaligned transfer buffers a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D307194
Differential Revision: https://phabricator.services.mozilla.com/D307859
- - - - -
81ebddf5 by ffxbld at 2026-07-14T07:59:48+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D308004
- - - - -
5d4e2c27 by Jonathan Kew at 2026-07-14T07:59:50+02:00
Bug 2045378 - Validate font descriptor in UnscaledFontFontconfig::CreateFromFontDescriptor. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305662
Differential Revision: https://phabricator.services.mozilla.com/D308002
- - - - -
ea9a57c9 by Jonathan Kew at 2026-07-14T07:59:51+02:00
Bug 2045771 - Validate kern subtable length. a=pascalc DONTBUILD
As suggested by clauditor.
Original Revision: https://phabricator.services.mozilla.com/D306160
Differential Revision: https://phabricator.services.mozilla.com/D307998
- - - - -
5558f5b6 by Jan-Niklas Jaeschke at 2026-07-14T07:59:53+02:00
Bug 2045402 - Refactor CrossShadowBoundaryRange::DoSetRange. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305276
Differential Revision: https://phabricator.services.mozilla.com/D308085
- - - - -
61f558ea by Ben Visness at 2026-07-14T07:59:54+02:00
Bug 2043271. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306329
Differential Revision: https://phabricator.services.mozilla.com/D308069
- - - - -
c6f961a5 by Henri Sivonen at 2026-07-14T07:59:56+02:00
Bug 2045417. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D305108
Differential Revision: https://phabricator.services.mozilla.com/D307995
- - - - -
83d78108 by Timothy Nikkel at 2026-07-14T07:59:57+02:00
Bug 2045775. a=pascalc DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307939
- - - - -
8a2d0e82 by Jonathan Kew at 2026-07-14T07:59:59+02:00
Bug 2045612 - Take ownership of the state in RestoreFormControlState. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307613
Differential Revision: https://phabricator.services.mozilla.com/D307827
- - - - -
cca5581d by David Shin at 2026-07-14T08:00:00+02:00
Bug 2045611: a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307076
Differential Revision: https://phabricator.services.mozilla.com/D307776
- - - - -
a74a07d8 by Tomislav Jovanovic at 2026-07-14T08:00:02+02:00
Bug 2048267 - Enable WebExtensions WPT tests on ESR140 a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D307614
Differential Revision: https://phabricator.services.mozilla.com/D307920
- - - - -
190d775c by Matthew Gregan at 2026-07-14T08:00:03+02:00
Bug 2042033 - Update audioipc to 3f0d4aef7a2c06b0146384592b312a7f47ab7cea. a=pascalc DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D307454
- - - - -
0346d71c by Jan de Mooij at 2026-07-14T08:00:05+02:00
Bug 2045957 - Initialize BaselineFrame return value slot in OnLeaveBaselineFrame. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305464
Differential Revision: https://phabricator.services.mozilla.com/D307470
- - - - -
a3214b92 by Andrew Osmond at 2026-07-14T08:00:06+02:00
Bug 2045187. a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305653
Differential Revision: https://phabricator.services.mozilla.com/D305719
- - - - -
c213399d by Justin Link at 2026-07-14T08:00:08+02:00
Bug 2028663: Fixed error-checking in WinRegistry a=pascalc DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D291621
Differential Revision: https://phabricator.services.mozilla.com/D308307
- - - - -
d5962549 by Julien Cristau at 2026-07-14T08:00:09+02:00
Bug 2048897 - fix update-verify-config failures on esr for win64-aarch64 DONTBUILD a=RyanVM
That platform was discontinued on esr115 which confuses our scripts.
Set last-watershed to 140.0esr to bypass the issue.
Original Revision: https://phabricator.services.mozilla.com/D307745
Differential Revision: https://phabricator.services.mozilla.com/D307844
- - - - -
68568f1e by Randell Jesup at 2026-07-14T08:00:11+02:00
Bug 2031768: Validate Principals in CookieStore a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D294473
Differential Revision: https://phabricator.services.mozilla.com/D308285
- - - - -
2b1c02b8 by Kai Engert at 2026-07-14T08:00:12+02:00
Bug 2013230 - Use strnlen in mozilla::PrintfTarget::cvt_s. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D280910
Differential Revision: https://phabricator.services.mozilla.com/D308438
- - - - -
5015ae65 by Masayuki Nakano at 2026-07-14T08:00:14+02:00
Bug 2045619 - Make `CompositionTransaction::DoTransaction` scan the replace start position as far as possible a=RyanVM DONTBUILD
The replace start may be in the following `Text`. Therefore, we should
scan the following `Text` before inserting the new composition string.
Original Revision: https://phabricator.services.mozilla.com/D305783
Differential Revision: https://phabricator.services.mozilla.com/D307458
- - - - -
aa99b2cc by Emilio Cobos Álvarez at 2026-07-14T08:00:16+02:00
Bug 2045406 - Validate end of cff dict. a=RyanVM DONTBUILD
Sent upstream in https://gitlab.freedesktop.org/cairo/cairo/-/work_items/967
Original Revision: https://phabricator.services.mozilla.com/D305850
Differential Revision: https://phabricator.services.mozilla.com/D307732
- - - - -
b6b3d205 by Emilio Cobos Álvarez at 2026-07-14T08:00:17+02:00
Bug 2045406 - Check cff dict operator / operand sizes. a=RyanVM DONTBUILD
Missed this one from the AI report. Also submitted upstream.
Original Revision: https://phabricator.services.mozilla.com/D306885
Differential Revision: https://phabricator.services.mozilla.com/D307733
- - - - -
b41fb1a0 by Jonathan Kew at 2026-07-14T08:00:19+02:00
Bug 2045518 - Ensure gfxFontEntry's mFamilyName field is guarded by mLock. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305176
Differential Revision: https://phabricator.services.mozilla.com/D307514
- - - - -
535c1b7f by Andreas Farre at 2026-07-14T08:00:21+02:00
Bug 2045618 - Make sure to consider idle timeouts when getting id. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305582
Differential Revision: https://phabricator.services.mozilla.com/D308000
- - - - -
ed369b87 by Jon Coppeard at 2026-07-14T08:00:22+02:00
Bug 2045451 - Prevent allocation of object elemets abutting the end of a nursery chunk a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305804
Differential Revision: https://phabricator.services.mozilla.com/D307781
- - - - -
2bb1ad2a by Jan de Mooij at 2026-07-14T08:00:24+02:00
Bug 2045454 - Clamp length of regexp captures array for dollar substitution. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305181
Differential Revision: https://phabricator.services.mozilla.com/D307473
- - - - -
fa1f97c2 by Ryan VanderMeulen at 2026-07-14T08:00:25+02:00
Bug 2045518 - Use FamilyName() accessor in CacheFont's assertion to fix thread-safety bustage. a=bustage
The backport missed converting one direct mFamilyName access in the NS_ASSERTION at the top of
UserFontCache::CacheFont, breaking debug builds under -Wthread-safety-analysis.
- - - - -
10635970 by Emilio Cobos Álvarez at 2026-07-14T08:00:27+02:00
Bug 2045604 - Don't leak the static doc via the relevant global of the context. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306772
Differential Revision: https://phabricator.services.mozilla.com/D307727
- - - - -
511f1046 by Julian Descottes at 2026-07-14T08:00:28+02:00
Bug 2027519 - [devtools] Use the real source url for sourcemap resolution a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D304524
Differential Revision: https://phabricator.services.mozilla.com/D308464
- - - - -
2234fbe3 by Calixte Denizet at 2026-07-14T08:00:30+02:00
Bug 2037770 - Honor iframe sandbox flags when handling pdf.js downloads a=RyanVM DONTBUILD
Cherry pick pdf.js changes from https://github.com/mozilla/pdf.js/commit/ece1e2ed0c58eb9641da33259d958fa912….
Differential Revision: https://phabricator.services.mozilla.com/D308475
- - - - -
58795e1f by Lee Salzman at 2026-07-14T08:00:31+02:00
Bug 2047729. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307935
Differential Revision: https://phabricator.services.mozilla.com/D308335
- - - - -
bfbe3d3a by Lee Salzman at 2026-07-14T08:00:33+02:00
Bug 2045741. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306315
Differential Revision: https://phabricator.services.mozilla.com/D308338
- - - - -
cdbf2a44 by James Teh at 2026-07-14T08:00:35+02:00
Bug 2047957: Ensure cached line start offsets are valid. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307467
Differential Revision: https://phabricator.services.mozilla.com/D308429
- - - - -
e3494a02 by Valentin Gosu at 2026-07-14T08:00:36+02:00
Bug 2048934 - Make mInVisitHeaders checks reentrant a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308013
Differential Revision: https://phabricator.services.mozilla.com/D308471
- - - - -
463c059d by André Bargull at 2026-07-14T08:00:38+02:00
Bug 2045482: Align with hasSpaceForInsts to simplify test case. r=jandem a=RyanVM DONTBUILD
Align with `hasSpaceForInsts` so the test case doesn't need to emit
thirty additional nop instructions.
Differential Revision: https://phabricator.services.mozilla.com/D306374
- - - - -
c5bb9621 by Julian Seward at 2026-07-14T08:00:39+02:00
Bug 2043035. . a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D303979
Differential Revision: https://phabricator.services.mozilla.com/D308724
- - - - -
379ade02 by Jonathan Kew at 2026-07-14T08:00:41+02:00
Bug 2045607 - Hold a strong ref during GetFontAt lookup. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307564
Differential Revision: https://phabricator.services.mozilla.com/D308506
- - - - -
2eb83aca by Olli Pettay at 2026-07-14T08:00:42+02:00
Bug 2045515, avoid leaking a slot, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305076
Differential Revision: https://phabricator.services.mozilla.com/D308743
- - - - -
c0238e7b by Julian Seward at 2026-07-14T08:00:44+02:00
Bug 2045443. . a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305869
Differential Revision: https://phabricator.services.mozilla.com/D308729
- - - - -
dbb05e5c by Olli Pettay at 2026-07-14T08:00:45+02:00
Bug 2045414, be consistent with the promise resolve/reject handling, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306588
Differential Revision: https://phabricator.services.mozilla.com/D308735
- - - - -
533c7b4f by Jan-Niklas Jaeschke at 2026-07-14T08:00:47+02:00
Bug 2049404 - Remove unused method from nsINode, add mainthread checks. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308201
Differential Revision: https://phabricator.services.mozilla.com/D308748
- - - - -
7eba4187 by James Teh at 2026-07-14T08:00:48+02:00
Bug 2047716: Ensure cache is valid. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307466
Differential Revision: https://phabricator.services.mozilla.com/D308698
- - - - -
069254af by longsonr at 2026-07-14T08:00:50+02:00
Bug 2049407 Part 1 - Detach observers on canvas destruction a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308288
Differential Revision: https://phabricator.services.mozilla.com/D308731
- - - - -
18daaf56 by Daniel Darnell at 2026-07-14T08:00:51+02:00
Bug 2005200 - Make Thunderbird langpacks depend on correct Thunderbird epoch. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305463
Differential Revision: https://phabricator.services.mozilla.com/D309200
- - - - -
df123116 by Mike Hommey at 2026-07-14T08:00:53+02:00
Bug 2029761 - Handle large values returned by strnlen as an error. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D303290
Differential Revision: https://phabricator.services.mozilla.com/D308936
- - - - -
eafa9906 by Ryan VanderMeulen at 2026-07-14T08:00:54+02:00
Bug 2048062 - Run apt-get update before installing build deps in the debian-packages image. a=diannaS
The ubuntu2404 raw image pins an apt snapshot for reproducibility, and the
package lists from the parent image aren't usable in the debian-packages child,
so apt-get install fails to locate any package. Refresh the lists first. The
snapshot pin is inherited by the child image, so the resolved package versions
are unchanged.
Original Revision: https://phabricator.services.mozilla.com/D307183
Differential Revision: https://phabricator.services.mozilla.com/D308925
- - - - -
70c61e27 by Edgar Chen at 2026-07-14T08:00:56+02:00
Bug 2046215 - Associate image elements with form only if the form and the intended parent are in the same tree; a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305733
Differential Revision: https://phabricator.services.mozilla.com/D309120
- - - - -
f88407c7 by Alastor Wu at 2026-07-14T08:00:57+02:00
Bug 2045508 - Reset the create-promise id once the create promise settles in MediaKeys. a=RyanVM (esr140) DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D308879
- - - - -
a2aaa91d by Brad Werth at 2026-07-14T08:00:59+02:00
Bug 2045626: Compute range of convolve filter in integer domain. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308096
Differential Revision: https://phabricator.services.mozilla.com/D309197
- - - - -
9f7e836f by Artur Iunusov at 2026-07-14T08:01:00+02:00
Bug 2045397 - Cancel the network channel when failing a cached worker script load a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307328
Differential Revision: https://phabricator.services.mozilla.com/D308528
- - - - -
1011fc28 by Andrew McCreight at 2026-07-14T08:01:02+02:00
Bug 2049523 - Make ToJSValue for float consistent with double. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D308323
Differential Revision: https://phabricator.services.mozilla.com/D308559
- - - - -
316f1730 by Lee Salzman at 2026-07-14T08:01:03+02:00
Bug 2049822. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308391
Differential Revision: https://phabricator.services.mozilla.com/D308818
- - - - -
b884d1dc by Lee Salzman at 2026-07-14T08:01:05+02:00
Bug 2025369. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308172
Differential Revision: https://phabricator.services.mozilla.com/D309240
- - - - -
cd6b6b1c by Lee Salzman at 2026-07-14T08:01:06+02:00
Bug 2050151. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308694
Differential Revision: https://phabricator.services.mozilla.com/D309242
- - - - -
fa52b069 by Chun-Min Chang at 2026-07-14T08:01:08+02:00
Bug 2045415 - Harden buffer sizing in Web Audio decoding a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D309159
- - - - -
9048e800 by Lee Salzman at 2026-07-14T08:01:09+02:00
Bug 2049805. a=RyanVM
Differential Revision: https://phabricator.services.mozilla.com/D308859
- - - - -
1f224164 by ffxbld at 2026-07-14T08:01:11+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D309303
- - - - -
6775f755 by Sotaro Ikeda at 2026-07-14T08:01:13+02:00
Bug 2049818 a=pascalc
Signed-off-by: Pascal Chevrel <pascal(a)mozilla.com>
- - - - -
8ae7931d by Ryan VanderMeulen at 2026-07-14T08:01:14+02:00
Bug 2051165 - Move ub18 package sources off launchpad.net URLs r=firefox-build-system-reviewers,sergesanspaille a=diannaS
Differential Revision: https://phabricator.services.mozilla.com/D309272
- - - - -
b527cc72 by Simon Farre at 2026-07-14T08:01:16+02:00
Bug 2045396 - Abort parser that otherwise could trigger the running of script when it shouldn't a=RyanVM DONTBUILD
Only <embed> and <object> teardown seem to finalize parsing, and circumvent script-safety-aware checks which can trigger script running like the bug displays.
nsParser::Terminate is eventually called via nsDocShell::Destroy() also, but this way we ensure the above doesn't happen, provided that NS_BINDING_ABORTED is passed in.
Original Revision: https://phabricator.services.mozilla.com/D305221
Differential Revision: https://phabricator.services.mozilla.com/D309304
- - - - -
bbc1b40f by Valentin Gosu at 2026-07-14T08:01:17+02:00
Bug 2041001 - Drop intermediary HTTPS result when following alias a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308991
Differential Revision: https://phabricator.services.mozilla.com/D309322
- - - - -
83d87230 by Vincent Hilla at 2026-07-14T08:01:19+02:00
Bug 2043820 - Reject javascript URI in nsDocShellLoadState. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305829
Differential Revision: https://phabricator.services.mozilla.com/D309583
- - - - -
0e4c6521 by Karl Tomlinson at 2026-07-14T08:01:20+02:00
Bug 2042242 Start fallback driver after queuing cubeb stream init a=RyanVM
This keeps cubeb operations in order and means that no other thread runs the
graph while mStreamName is passed to the cubeb operation thread.
MaybeStartAudioStream() no longer uses Start() to queue the stream init,
because it does not need to and removing this caller allows Start() to more
simply handle its remaining use cases. MaybeStartAudioStream() never starts a
fallback driver nor stops a previous driver because it is called from the
fallback driver loop.
Original Revision: https://phabricator.services.mozilla.com/D305794
Differential Revision: https://phabricator.services.mozilla.com/D309475
- - - - -
fc84c243 by Andrew McCreight at 2026-07-14T08:01:22+02:00
Bug 2050990 - Call JS_NumberValue in ClientWebGLContext.cpp. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D309205
Differential Revision: https://phabricator.services.mozilla.com/D309810
- - - - -
3e4ba2e6 by Chun-Min Chang at 2026-07-14T08:01:24+02:00
Bug 2047723 - Cherry-pick commit f738b1132ec1fd56efc90367898244cf52d9e6a5 for libsoundtouch a=RyanVM DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D309945
- - - - -
073784f9 by Lee Salzman at 2026-07-14T08:01:25+02:00
Bug 2051666. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309674
Differential Revision: https://phabricator.services.mozilla.com/D309983
- - - - -
23aadda4 by Lee Salzman at 2026-07-14T08:01:27+02:00
Bug 2049405. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308437
Differential Revision: https://phabricator.services.mozilla.com/D309967
- - - - -
4316653e by Valentin Gosu at 2026-07-14T08:01:28+02:00
Bug 2050668 - WS: set mDataStarted before dispatching runnable a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308990
Differential Revision: https://phabricator.services.mozilla.com/D309771
- - - - -
ed0010df by Andrew McCreight at 2026-07-14T08:01:30+02:00
Bug 2050657 - Fix more floating point setNumber calls. a=RyanVM
Plus a DoubleValue because we might as well fix both EventDispatcher issues
in one patch.
Original Revision: https://phabricator.services.mozilla.com/D308928
Differential Revision: https://phabricator.services.mozilla.com/D309823
- - - - -
0debeb1f by Andrew McCreight at 2026-07-14T08:01:31+02:00
Bug 2050657 - Fixes for setDouble, Float32Value and JS::NumberValue. a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D309191
Differential Revision: https://phabricator.services.mozilla.com/D309824
- - - - -
9e5c64d6 by Andrew McCreight at 2026-07-14T08:01:32+02:00
Bug 2050657 - Ensure UbiNode Node::identifier() is representable. a=RyanVM
Node::identifier() gets used as a JS value in a few places, so we should make
sure that it is a nice happy non-NaN value representable as a double. It looks
like all of the callers are passing in pointers, so it should be fine.
Original Revision: https://phabricator.services.mozilla.com/D309192
Differential Revision: https://phabricator.services.mozilla.com/D309825
- - - - -
384482bb by Arnaud Bienner at 2026-07-14T08:01:34+02:00
Bug 2051285 - Useless reinterpret_cast in EncryptingOutputStream_impl.h a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309361
Differential Revision: https://phabricator.services.mozilla.com/D310141
- - - - -
bf1fded7 by Arnaud Bienner at 2026-07-14T08:01:35+02:00
Bug 2044536 - Quota: make EncryptedBlock::RoundedUpToBasicBlockSize public and use it in EncryptingOutputStream, and propertly clear buffer a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309603
Differential Revision: https://phabricator.services.mozilla.com/D310142
- - - - -
455196ce by Jens Stutte at 2026-07-14T08:01:37+02:00
Bug 2045510 - Reject snappy CompressedData chunks shorter than the CRC field. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305218
Differential Revision: https://phabricator.services.mozilla.com/D309799
- - - - -
a8fdd5d3 by Jens Stutte at 2026-07-14T08:01:38+02:00
Bug 2048795 - Guard access to the GamepadPlatformService singleton by a StaticMutex. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308034
Differential Revision: https://phabricator.services.mozilla.com/D309819
- - - - -
40f8f3ee by Valentin Gosu at 2026-07-14T08:01:40+02:00
Bug 2045833 - Clean up nsUnknownDecoder::OnDataAvailable check a=RyanVM
Original Revision: https://phabricator.services.mozilla.com/D305526
Differential Revision: https://phabricator.services.mozilla.com/D309891
- - - - -
6177c763 by Lee Salzman at 2026-07-14T08:01:41+02:00
Bug 2047719. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307948
Differential Revision: https://phabricator.services.mozilla.com/D310173
- - - - -
2ea040c9 by Jonathan Kew at 2026-07-14T08:01:43+02:00
Bug 2045865 - Use row_bytes rather than bitmap->pitch when copying glyph. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307593
Differential Revision: https://phabricator.services.mozilla.com/D310192
- - - - -
d0ae38ab by Matthew Gregan at 2026-07-14T08:01:45+02:00
Bug 2045763. r=cubeb-reviewers,padenot a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D310249
- - - - -
fad1bf1e by smayya at 2026-07-14T08:01:46+02:00
Bug 2049392 - improve nsStandardURL parsing. n=#necko a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309007
Differential Revision: https://phabricator.services.mozilla.com/D310086
- - - - -
7386233a by Valentin Gosu at 2026-07-14T08:01:48+02:00
Bug 2045875 - Empty authority is not compatible with port a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D306755
Differential Revision: https://phabricator.services.mozilla.com/D310087
- - - - -
0b96dace by Bob Owen at 2026-07-14T08:01:49+02:00
Bug 2045767 - a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305931
Differential Revision: https://phabricator.services.mozilla.com/D310114
- - - - -
9f92093d by Randell Jesup at 2026-07-14T08:01:51+02:00
Bug 2045783: Clean up TRRQuery::CompleteLookup a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305279
Differential Revision: https://phabricator.services.mozilla.com/D310241
- - - - -
2ab9b966 by Randell Jesup at 2026-07-14T08:01:52+02:00
Bug 2045783: Add thread-safety checks to TRRQuery a=dmeehan DONTBUILD
Belt-and-suspenders; allows static analyisis
Original Revision: https://phabricator.services.mozilla.com/D305601
Differential Revision: https://phabricator.services.mozilla.com/D310242
- - - - -
c67e88d5 by Yannis Juglaret at 2026-07-14T08:01:54+02:00
Bug 2045770 - Cap constant-fold allocations. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305921
Differential Revision: https://phabricator.services.mozilla.com/D310264
- - - - -
12586d10 by DonalMe at 2026-07-14T08:01:55+02:00
Bug 2051658 a=dmeehan
- - - - -
81826c1c by DonalMe at 2026-07-14T08:01:57+02:00
Revert "Bug 2051658 a=dmeehan" for causing build failures
This reverts commit e44a92232c4f71f420ce59f22e15f5c962f794f2.
- - - - -
4499d3f9 by Arnaud Bienner at 2026-07-14T08:01:58+02:00
Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308534
Differential Revision: https://phabricator.services.mozilla.com/D310354
- - - - -
d98efa2b by Michael Kaply at 2026-07-14T08:02:00+02:00
Bug 2044527 - Normalize the host when matching WebsiteFilter patterns. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305900
Differential Revision: https://phabricator.services.mozilla.com/D310652
- - - - -
5e41c40e by Tom Schuster at 2026-07-14T08:02:02+02:00
Bug 2008369 - Validate principal in PContent::LoadURIExternal. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309362
Differential Revision: https://phabricator.services.mozilla.com/D310359
- - - - -
7bbfd405 by Jonathan Kew at 2026-07-14T08:02:03+02:00
Bug 2048801 - Validate fdselect entries before use. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308373
Differential Revision: https://phabricator.services.mozilla.com/D310395
- - - - -
972ee2ab by Jonathan Kew at 2026-07-14T08:02:05+02:00
Bug 2049398 - Range-check glyph ID. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308374
Differential Revision: https://phabricator.services.mozilla.com/D310396
- - - - -
462e9409 by Jonathan Kew at 2026-07-14T08:02:06+02:00
Bug 2049399 - Check type1 stack size. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308375
Differential Revision: https://phabricator.services.mozilla.com/D310397
- - - - -
a9d8e07b by ffxbld at 2026-07-14T08:02:08+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310675
- - - - -
962f032b by Mark Banner at 2026-07-14T08:02:10+02:00
Bug 1874712 - Add a keyword for Ecosia. a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310293
- - - - -
8dadc152 by DonalMe at 2026-07-14T08:02:11+02:00
Bug 2044527 - Fix build failure on ESR140 a=bustage
- - - - -
3c97c7ae by DonalMe at 2026-07-14T08:02:13+02:00
Revert "Bug 2008369 - Validate principal in PContent::LoadURIExternal. a=dmeehan" for causing CI failures on ESR140
This reverts commit 418229151ed0e8261397c2bbcde6112814b14947.
- - - - -
f9768159 by DonalMe at 2026-07-14T08:02:14+02:00
Revert "Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan" for causing CI errors on ESR140
This reverts commit acff26261e5c0c60cb66c290d02ff199ea637cf5.
- - - - -
9278f069 by Arnaud Bienner at 2026-07-14T08:02:16+02:00
Bug 2045729 - Quota manager: check received stream control is coming from the same Manager/origin a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308534
Differential Revision: https://phabricator.services.mozilla.com/D310354
- - - - -
58058152 by smayya at 2026-07-14T08:02:17+02:00
Bug 2045511 - update nsHttpTransaction::Close() handling of NS_BINDING_RETARGETED. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D307751
Differential Revision: https://phabricator.services.mozilla.com/D310586
- - - - -
5fc59300 by James Teh at 2026-07-14T08:02:19+02:00
Bug 2046416: Ensure a hide event never occurs during a split show event. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D306672
Differential Revision: https://phabricator.services.mozilla.com/D310548
- - - - -
8b53626f by Sotaro Ikeda at 2026-07-14T08:02:20+02:00
Bug 2051653 a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D309978
Differential Revision: https://phabricator.services.mozilla.com/D310545
- - - - -
ecb6e58f by Emilio Cobos Álvarez at 2026-07-14T08:02:22+02:00
Bug 2045617 - Add some bounds checks to cairo_cff_font_read_fdselect. a=dmeehan
Attached to https://gitlab.freedesktop.org/cairo/cairo/-/work_items/967
as well.
Original Revision: https://phabricator.services.mozilla.com/D306604
Differential Revision: https://phabricator.services.mozilla.com/D310349
- - - - -
be1ce2ea by Eden Chuang at 2026-07-14T08:02:23+02:00
Bug 2026301 - Synchronize ThreadSafeRequestHandle::mRunnable to fix cross-thread use-after-free a=dmeehan DONTBUILD
mRunnable was a plain RefPtr read on the main thread (GetCacheCreator and the
other accessors) and cleared on the worker thread by ReleaseRequest() with no
synchronization. When the worker's store dropped the last reference to the
shared ScriptLoaderRunnable, the main thread could dereference the already-freed
pointer, producing a heap-use-after-free.
Guard mRunnable with a Mutex (enforced via MOZ_GUARDED_BY). ReleaseRequest() and
the new SetRunnable() mutate it under the lock, releasing the runnable outside
the lock so it is never destroyed while the mutex is held. Each main-thread
accessor copies mRunnable into a local strong reference under the lock and bails
if it was already released. GetCacheCreator() now returns a strong CacheCreator
reference taken under the lock, so the caller keeps it alive across DeleteCache()
even if the runnable is released on the worker thread afterwards.
Original Revision: https://phabricator.services.mozilla.com/D307211
Differential Revision: https://phabricator.services.mozilla.com/D310969
- - - - -
e7cbf2fa by Emilio Cobos Álvarez at 2026-07-14T08:02:25+02:00
Bug 2045198 - Don't bother checking ancestors for constructed check. a=dmeehan DONTBUILD
Since we don't allow @import, we can't get there with a constructed
ancestor.
Original Revision: https://phabricator.services.mozilla.com/D309844
Differential Revision: https://phabricator.services.mozilla.com/D310859
- - - - -
90a850e0 by Jonathan Kew at 2026-07-14T08:02:26+02:00
Bug 2050368 - Check for end of charstring. a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D308768
Differential Revision: https://phabricator.services.mozilla.com/D310831
- - - - -
9983f101 by Randell Jesup at 2026-07-14T08:02:28+02:00
Bug 2045772: Clean up nsStandardURL::Deserialize a=dmeehan DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305274
Differential Revision: https://phabricator.services.mozilla.com/D310198
- - - - -
bd18f217 by Daniel Holbert at 2026-07-14T08:02:29+02:00
Bug 2048799: Flip polarity of a bounds check in cairo code. a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D307892
Differential Revision: https://phabricator.services.mozilla.com/D310180
- - - - -
af2be3c0 by Eitan Isaacson at 2026-07-14T08:02:31+02:00
Bug 2045392 - Don't allow attaching children to outerdoc. a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D305621
- - - - -
46ada433 by Sotaro Ikeda at 2026-07-14T08:02:32+02:00
Bug 2051658 - for esr140 a=dmeehan DONTBUILD
Differential Revision: https://phabricator.services.mozilla.com/D310958
- - - - -
82524591 by Valentin Gosu at 2026-07-14T08:02:34+02:00
Bug 2032140 - Verify content process identity when linking background channels a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309038
Differential Revision: https://phabricator.services.mozilla.com/D311187
- - - - -
db2f4971 by Valentin Gosu at 2026-07-14T08:02:36+02:00
Bug 2043200 - Bind RedirectChannelRegistrar ids to their destination content process a=dmeehan
Original Revision: https://phabricator.services.mozilla.com/D309039
Differential Revision: https://phabricator.services.mozilla.com/D311188
- - - - -
92efa456 by Atila Butkovits at 2026-07-14T08:02:37+02:00
Revert "Bug 2051658 - for esr140 a=dmeehan DONTBUILD" for causing reftest failures.
This reverts commit 58bbb58a4b533f267000b555474fa3f5f2122c61.
- - - - -
ea754fe7 by Nika Layzell at 2026-07-14T08:02:39+02:00
Bug 2027207 - Part 1: Align validation in TriggerRedirectToRealChannel and RecvNewWindowGlobal better, a=pascalc
This should make TriggerRedirectToRealChannel tighter, to hopefully
match the check in RecvNewWindowGlobal better. While this doesn't add
much in terms of security, it should reduce the risk of us encountering
surprising errors.
Original Revision: https://phabricator.services.mozilla.com/D291061
Differential Revision: https://phabricator.services.mozilla.com/D311158
- - - - -
e00e8c6b by Nika Layzell at 2026-07-14T08:02:40+02:00
Bug 2027207 - Part 2: Handle schemes better in ValidatePrincipalCouldPotentiallyBeLoadedBy, a=pascalc
Previously this logic used `nsIPrincipal::GetScheme`, which returns the
scheme of the URI used to create the principal. This could have
unexpected behaviour for nested URIs like view-source URIs, which have a
view-source: URI scheme, but a non-view-source (e.g. https://) origin.
This patch reworks the logic to instead base the checks off of the
origin's scheme, parsing it out of the origin string.
In addition, the about: URI handling was improved somewhat to have a
better understanding of how process selection for about: URIs happens in
practice by relying on a component of the process isolation logic.
Original Revision: https://phabricator.services.mozilla.com/D291062
Differential Revision: https://phabricator.services.mozilla.com/D311159
- - - - -
77df5ce6 by Nika Layzell at 2026-07-14T08:02:42+02:00
Bug 2027207 - Part 3: Return IPC_FAIL when principal validation fails, a=pascalc
This entry actually changes the callers to perform principal validation.
This turns the code which previously would only send a telemetry ping to
a crash. I am hopeful that the rate of failures is low enough that this
won't cause an issue, and if it does, I'm hopeful that we'll be able to
figure out the cause of the mismatch.
Original Revision: https://phabricator.services.mozilla.com/D291063
Differential Revision: https://phabricator.services.mozilla.com/D311160
- - - - -
72b51bea by Timothy Nikkel at 2026-07-14T08:02:43+02:00
Bug 2036518. r=gfx-reviewers,lsalzman a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311035
- - - - -
747f615a by Byron Campen at 2026-07-14T08:02:45+02:00
Bug 2043188: Simplify the buffer handling in RTCEncodedFrameBase. r=sfink a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D310880
- - - - -
96b92991 by Timothy Nikkel at 2026-07-14T08:02:46+02:00
Bug 2028004. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D310743
- - - - -
ebbad998 by Randell Jesup at 2026-07-14T08:02:48+02:00
Bug 2029734: Flush before calling sctp_process_init() a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D295148
Differential Revision: https://phabricator.services.mozilla.com/D311133
- - - - -
a654bd57 by Randell Jesup at 2026-07-14T08:02:50+02:00
Bug 2045773: Add usrsctp TSN gap check a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309815
Differential Revision: https://phabricator.services.mozilla.com/D311396
- - - - -
82ece4cd by Timothy Nikkel at 2026-07-14T08:02:51+02:00
Bug 2022635. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311246
- - - - -
72bde1d3 by Vincent Hilla at 2026-07-14T08:02:53+02:00
Bug 2035756 - Verify srcdoc and data result principal. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309545
Differential Revision: https://phabricator.services.mozilla.com/D311257
- - - - -
ca09a5e1 by Sotaro Ikeda at 2026-07-14T08:02:54+02:00
Bug 2051658 - for esr140 with D265934 a=dmeehan
Differential Revision: https://phabricator.services.mozilla.com/D310958
- - - - -
2605a324 by James Teh at 2026-07-14T08:02:56+02:00
Bug 2052562: Don't allow moves into a detached subtree. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D310457
Differential Revision: https://phabricator.services.mozilla.com/D311752
- - - - -
9999ec1b by Jan de Mooij at 2026-07-14T08:02:57+02:00
Bug 2052207 - Disable OptimizeIteratorIndices optimization. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D310355
Differential Revision: https://phabricator.services.mozilla.com/D311774
- - - - -
c554ee63 by Jonathan Kew at 2026-07-14T08:02:59+02:00
Bug 2053576 - Clamp number of components assigned by SetDetailedGlyphs. a=pascalc
(Based on clauditor-suggested patch)
Original Revision: https://phabricator.services.mozilla.com/D311412
Differential Revision: https://phabricator.services.mozilla.com/D311780
- - - - -
e862ac15 by Randell Jesup at 2026-07-14T08:03:00+02:00
Bug 2045848: Avoid avoid re-initting usrsctp a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311578
- - - - -
795c6651 by ffxbld at 2026-07-14T08:03:02+02:00
No Bug, mozilla-esr140 repo-update HSTS HPKP remote-settings tld-suffixes ct-logs - a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311783
- - - - -
dcd3f8e3 by Timothy Nikkel at 2026-07-14T08:03:03+02:00
Bug 2052841. Don't taint a same-origin response that a service worker substitutes for a cross-origin request. a=pascalc
When a service worker answers a cross-origin request with a same-origin
resource (respondWith(fetch(<same-origin URL>))), the response is delivered as
an internal redirect from the cross-origin request URL to the same-origin
response URL. nsITimedChannel's allRedirectsSameOrigin counts that internal
redirect as a cross-origin hop, so consumers that use it to decide tainting
(image loads, stylesheets, media) treat the resource as cross-origin and taint
it -- even though the bytes are same-origin and should be readable.
Add nsITimedChannel::allRedirectsSameOriginIgnoringInternal, computed like
allRedirectsSameOrigin but ignoring internal (e.g. service-worker response-URL)
redirects, and switch the tainting consumers (imgRequestProxy, the CSS Loader,
and the media resources) to it. Real cross-origin redirects still flip it, so
genuine cross-origin loads (including bounce-backs) still taint. Other users of
allRedirectsSameOrigin (resource timing, Fetch body-access) intentionally keep
the original flag.
Add a service-worker regression test for the same-origin substitution case
(CSS).
Differential Revision: https://phabricator.services.mozilla.com/D311505
- - - - -
c1129d22 by Timothy Nikkel at 2026-07-14T08:03:05+02:00
Bug 2050626. a=pascalc
Differential Revision: https://phabricator.services.mozilla.com/D311507
- - - - -
2d319501 by Vincent Hilla at 2026-07-14T08:03:07+02:00
Bug 2048851 - Clear principalToInherit in LoadPageAsViewSource. a=pascalc
Original Revision: https://phabricator.services.mozilla.com/D309163
Differential Revision: https://phabricator.services.mozilla.com/D311786
- - - - -
d426780d by Jon Coppeard at 2026-07-14T08:03:08+02:00
Bug 2046917 - Make implicit edge marking state runtime wide (ESR140) a=pascalc
Currently this is tracked per-marker but the effect should be per-runtime.
There may be multiple markers due to parallel marking.
I couldn't get the testcase to reproduce here either.
Original Revision: https://phabricator.services.mozilla.com/D307221
Differential Revision: https://phabricator.services.mozilla.com/D311837
- - - - -
f810b5ba by Andreas Farre at 2026-07-14T08:03:10+02:00
Bug 2045468 - Make sure to check the correct browsing context. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305611
Differential Revision: https://phabricator.services.mozilla.com/D311833
- - - - -
25b28896 by Emilio Cobos Álvarez at 2026-07-14T08:03:11+02:00
Bug 2045407 - Validate surface format properly. a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D305381
Differential Revision: https://phabricator.services.mozilla.com/D310858
- - - - -
45acf9ab by Eden Chuang at 2026-07-14T08:03:13+02:00
Bug 2039452 - Validate file:// URIs in PExternalHelperApp against the sending process's remote type. a=RyanVM DONTBUILD
The parent derived the native helper-launch decision from a
content-process supplied aWasFileChannel flag and URI rather than
binding it to the sending process's capabilities.
Stop sending aWasFileChannel over IPC and derive it on the parent from
the actual URI, and reject a file:// URI in PExternalHelperApp from a
process that is not allowed to load local files (mirrors the file://
policy in ValidatePrincipalCouldPotentiallyBeLoadedBy).
Original Revision: https://phabricator.services.mozilla.com/D309577
Differential Revision: https://phabricator.services.mozilla.com/D311929
- - - - -
8f8ed0c1 by Matthew Gregan at 2026-07-14T08:03:14+02:00
Bug 2052753 - Update cubeb-pulse-rs to b46defa to reject start() on a draining stream. a=RyanVM DONTBUILD
Backport of upstream cubeb-pulse-rs commit
88194f91c8778fa608a19af7b91306094525595d, carried on the
mozilla/cubeb-pulse-rs esr140 branch.
The backport adapts the error construction to the cubeb-backend version
vendored on this branch (Error::error() rather than Error::Error).
Original Revision: https://phabricator.services.mozilla.com/D310552
Differential Revision: https://phabricator.services.mozilla.com/D311956
- - - - -
02abcd52 by Nika Layzell at 2026-07-14T08:03:16+02:00
Bug 1800120 - Part 1: Remove CreateWindowInDifferentProcess, a=RyanVM DONTBUILD
This method is now dead code, as we have shipped fission.autostart on
all platforms since bug 1998306, and CreateWindowInDifferentProcess is
disabled when Fission is disabled.
This is intended to be a fairly straightforward change to remove the
unnecessary IPC call, and does not clean up the implementation to remove
the now-dead codepaths from CommonCreateWindow. That is done in part 2.
Original Revision: https://phabricator.services.mozilla.com/D297450
Differential Revision: https://phabricator.services.mozilla.com/D311910
- - - - -
cd03fbe4 by Nika Layzell at 2026-07-14T08:03:17+02:00
Bug 1800120 - Part 2: Remove now-dead parameters in CommonCreateWindow, a=RyanVM DONTBUILD
Original Revision: https://phabricator.services.mozilla.com/D297451
Differential Revision: https://phabricator.services.mozilla.com/D311911
- - - - -
11cc5453 by Nika Layzell at 2026-07-14T08:03:19+02:00
Bug 1800120 - Part 3: Update test expectations for window-open-popup-behavior.html, a=RyanVM DONTBUILD
This patch updates the expectations for window-open-popup-behavior.html
on Android to reflect the fact that many of these tests appear to have
only been passing due to Android using CreateWindowInDifferentProcess.
Now that codepath has been removed, the test is now failing more
consistently across platforms.
I also removed the pass cases for linux-nofis, though I don't think we
run that configuration in treeherder anymore off the top of my head.
It appears that we fail this test due to a fundamental mismatch between
our implementation and the WPT. Specifically it appears the test expects
that specifying noopener/noreferrer overrides all other window open
options, and always forces the document to open in a tab, not a popup.
We always respect the specified options even if noopener is set.
Original Revision: https://phabricator.services.mozilla.com/D308619
Differential Revision: https://phabricator.services.mozilla.com/D311912
- - - - -
7bce603c by Ryan Hunt at 2026-07-14T08:03:20+02:00
Bug 2051854 - Clean up StackSlotAllocator. a=RyanVM
Route all height_ increments through a checked incrementHeight() and make
slot allocation fallible.
Original Revision: https://phabricator.services.mozilla.com/D309918
Differential Revision: https://phabricator.services.mozilla.com/D311873
- - - - -
361 changed files:
- .cargo/config.toml.in
- CLOBBER
- Cargo.lock
- accessible/base/CacheConstants.h
- accessible/base/TextLeafRange.cpp
- accessible/ipc/DocAccessibleParent.cpp
- accessible/ipc/RemoteAccessible.cpp
- accessible/ipc/RemoteAccessible.h
- browser/app/profile/firefox.js
- browser/components/DesktopActorRegistry.sys.mjs
- browser/components/build/components.conf
- browser/components/distribution.sys.mjs
- browser/components/enterprisepolicies/helpers/WebsiteFilter.sys.mjs
- + browser/components/enterprisepolicies/tests/xpcshell/test_websitefilter.js
- browser/components/enterprisepolicies/tests/xpcshell/xpcshell.toml
- browser/components/metrics.yaml
- − browser/components/shell/Windows11LimitedAccessFeatures.cpp
- − browser/components/shell/Windows11LimitedAccessFeatures.h
- browser/components/shell/Windows11TaskbarPinning.cpp
- browser/components/shell/moz.build
- + browser/components/shell/nsILimitedAccessFeature.idl
- + browser/components/shell/rust/shell_windows/Cargo.toml
- + browser/components/shell/rust/shell_windows/src/LimitedAccessFeatureService.h
- + browser/components/shell/rust/shell_windows/src/lib.rs
- + browser/components/shell/rust/shell_windows/src/limited_access_features.rs
- browser/components/shell/test/gtest/LimitedAccessFeatureTests.cpp
- + browser/components/tests/unit/test_distribution_mozillaonline.js
- browser/components/tests/unit/xpcshell.toml
- browser/config/version.txt
- browser/config/version_display.txt
- config/create_rc.py
- config/milestone.txt
- devtools/server/actors/source.js
- docshell/base/BrowsingContext.cpp
- docshell/base/BrowsingContext.h
- docshell/base/nsDocShell.cpp
- docshell/base/nsDocShellLoadState.cpp
- dom/base/CrossShadowBoundaryRange.cpp
- dom/base/CrossShadowBoundaryRange.h
- dom/base/StaticRange.cpp
- dom/base/StaticRange.h
- dom/base/TimeoutManager.cpp
- dom/base/nsContentUtils.h
- dom/base/nsINode.cpp
- dom/base/nsINode.h
- dom/base/nsTextFragment.h
- dom/bindings/ToJSValue.h
- dom/cache/CacheOpParent.cpp
- dom/cache/CacheStreamControlParent.cpp
- dom/cache/CacheStreamControlParent.h
- dom/canvas/CanvasRenderingContext2D.cpp
- dom/canvas/ClientWebGLContext.cpp
- dom/canvas/DrawTargetWebgl.cpp
- dom/canvas/WebGLProgram.cpp
- dom/canvas/nsICanvasRenderingContextInternal.cpp
- dom/cookiestore/CookieStoreParent.cpp
- dom/events/IMEStateManager.cpp
- dom/events/TextComposition.h
- dom/fetch/Fetch.cpp
- dom/fetch/Fetch.h
- dom/fetch/Request.cpp
- dom/fetch/Response.cpp
- dom/gamepad/GamepadPlatformService.cpp
- dom/html/HTMLCanvasElement.cpp
- dom/html/HTMLCanvasElement.h
- dom/html/HTMLImageElement.cpp
- dom/html/HTMLImageElement.h
- dom/html/HTMLSlotElement.cpp
- dom/html/nsGenericHTMLElement.cpp
- dom/indexedDB/Key.cpp
- dom/ipc/BrowserParent.cpp
- dom/ipc/ContentChild.cpp
- dom/ipc/ContentParent.cpp
- dom/ipc/ContentParent.h
- dom/ipc/DOMTypes.ipdlh
- dom/ipc/PContent.ipdl
- dom/ipc/ProcessIsolation.cpp
- dom/media/ChannelMediaResource.cpp
- dom/media/CloneableWithRangeMediaResource.cpp
- dom/media/FileMediaResource.cpp
- dom/media/GraphDriver.cpp
- dom/media/GraphDriver.h
- dom/media/MediaQueue.h
- dom/media/eme/MediaKeys.cpp
- dom/media/eme/clearkey/ClearKeyDecryptionManager.cpp
- dom/media/gmp/GMPVideoDecoderChild.cpp
- dom/media/gmp/GMPVideoi420FrameImpl.cpp
- dom/media/ipc/MFCDMParent.cpp
- dom/media/ipc/MFCDMParent.h
- dom/media/ipc/MFMediaEngineParent.cpp
- dom/media/mediasink/AudioDecoderInputTrack.cpp
- dom/media/mediasource/ContainerParser.cpp
- dom/media/mp4/SinfParser.cpp
- dom/media/platforms/ffmpeg/FFmpegVideoDecoder.cpp
- dom/media/platforms/ffmpeg/FFmpegVideoFramePool.cpp
- + dom/media/platforms/ffmpeg/FFmpegVideoUtils.h
- dom/media/platforms/ffmpeg/ffvpx/D3D11TextureWrapper.cpp
- dom/media/platforms/ffmpeg/ffvpx/D3D11TextureWrapper.h
- dom/media/platforms/wmf/DXVA2Manager.cpp
- dom/media/webaudio/MediaBufferDecoder.cpp
- dom/media/webrtc/jsapi/RTCEncodedFrameBase.cpp
- dom/promise/Promise.cpp
- dom/quota/EncryptedBlock.h
- dom/quota/EncryptingOutputStream_impl.h
- dom/security/nsContentSecurityManager.cpp
- dom/streams/ReadableStream.h
- dom/streams/UnderlyingSourceCallbackHelpers.h
- dom/view-transitions/ViewTransition.cpp
- dom/webtransport/api/WebTransport.cpp
- dom/webtransport/parent/WebTransportParent.cpp
- dom/webtransport/parent/WebTransportParent.h
- + dom/webtransport/test/xpcshell/head.js
- dom/webtransport/test/xpcshell/test_close.js
- dom/webtransport/test/xpcshell/test_simple_conn.js
- dom/webtransport/test/xpcshell/test_simple_stream.js
- dom/webtransport/test/xpcshell/xpcshell.toml
- dom/workers/ScriptLoader.cpp
- dom/workers/loader/CacheLoadHandler.cpp
- dom/workers/loader/NetworkLoadHandler.cpp
- dom/workers/loader/WorkerLoadContext.cpp
- dom/workers/loader/WorkerLoadContext.h
- editor/libeditor/CompositionTransaction.cpp
- editor/libeditor/CompositionTransaction.h
- editor/libeditor/EditorBase.cpp
- editor/libeditor/TextEditSubActionHandler.cpp
- editor/libeditor/WhiteSpaceVisibilityKeeper.cpp
- editor/libeditor/tests/mochitest.toml
- + editor/libeditor/tests/test_composition_modified_as_multiple_text_nodes.html
- gfx/2d/DrawTargetSkia.cpp
- gfx/2d/ScaledFontDWrite.cpp
- gfx/2d/ScaledFontFontconfig.cpp
- gfx/2d/SkConvolver.cpp
- gfx/angle/checkout/src/compiler/translator/IntermNode.cpp
- gfx/angle/checkout/src/compiler/translator/OutputHLSL.cpp
- gfx/angle/checkout/src/libANGLE/renderer/d3d/d3d11/StateManager11.h
- gfx/cairo/cairo/src/cairo-cff-subset.c
- gfx/cairo/cairo/src/cairo-ft-font.c
- gfx/cairo/cairo/src/cairo-scaled-font-subsets.c
- gfx/cairo/cairo/src/cairo-type1-subset.c
- gfx/cairo/cairo/src/cairoint.h
- + gfx/cairo/patches/0034-cff-dict-validation.patch
- + gfx/cairo/patches/0035-cff-fdselect-bounds.patch
- + gfx/cairo/patches/0036-cff-operator-bounds.patch
- + gfx/cairo/patches/0037-fdselect-checks.patch
- + gfx/cairo/patches/0037-pcf-row_bytes.patch
- + gfx/cairo/patches/0038-gid-range-check.patch
- + gfx/cairo/patches/0039-type1-stack-check.patch
- + gfx/cairo/patches/0040-type1-decode-integer.patch
- + gfx/cairo/patches/0041-Bug-2048799-flip-polarity-of-a-bounds-check.patch
- gfx/layers/D3D11ZeroCopyTextureImage.cpp
- gfx/layers/D3D11ZeroCopyTextureImage.h
- gfx/layers/DcompSurfaceImage.cpp
- gfx/layers/ImageContainer.cpp
- gfx/layers/ImageContainer.h
- gfx/layers/apz/util/APZCCallbackHelper.cpp
- gfx/layers/composite/TextureHost.cpp
- gfx/layers/d3d11/FenceD3D11.cpp
- gfx/layers/d3d11/FenceD3D11.h
- gfx/layers/d3d11/TextureD3D11.cpp
- gfx/layers/ipc/CanvasChild.cpp
- gfx/layers/opengl/DMABUFTextureHostOGL.cpp
- gfx/layers/opengl/MacIOSurfaceTextureHostOGL.cpp
- gfx/layers/opengl/TextureHostOGL.cpp
- gfx/layers/wr/AsyncImagePipelineManager.cpp
- gfx/layers/wr/WebRenderBridgeParent.cpp
- gfx/layers/wr/WebRenderCommandBuilder.cpp
- gfx/layers/wr/WebRenderMessageUtils.h
- gfx/thebes/gfxDWriteFontList.cpp
- gfx/thebes/gfxFcPlatformFontList.cpp
- gfx/thebes/gfxFcPlatformFontList.h
- gfx/thebes/gfxFont.cpp
- gfx/thebes/gfxFontEntry.cpp
- gfx/thebes/gfxFontEntry.h
- gfx/thebes/gfxHarfBuzzShaper.cpp
- gfx/thebes/gfxTextRun.cpp
- gfx/thebes/gfxUserFontSet.cpp
- gfx/thebes/gfxUserFontSet.h
- gfx/webrender_bindings/DCLayerTree.cpp
- gfx/webrender_bindings/RenderD3D11TextureHost.cpp
- gfx/webrender_bindings/WebRenderTypes.h
- gfx/wr/swgl/src/gl.cc
- gfx/wr/swgl/src/rasterize.h
- gfx/wr/webrender/src/texture_cache.rs
- gfx/ycbcr/ycbcr_to_rgb565.cpp
- image/BlobSurfaceProvider.cpp
- image/RasterImage.cpp
- image/decoders/nsAVIFDecoder.cpp
- image/imgRequest.cpp
- image/imgRequest.h
- image/imgRequestProxy.cpp
- ipc/glue/BackgroundParentImpl.cpp
- ipc/glue/BackgroundParentImpl.h
- ipc/glue/PBackground.ipdl
- ipc/glue/SharedMemoryPlatform_posix.cpp
- js/public/UbiNode.h
- js/src/builtin/RegExp.cpp
- js/src/builtin/RegExp.js
- js/src/builtin/SelfHostingDefines.h
- js/src/ctypes/CTypes.cpp
- js/src/gc/GC.cpp
- js/src/gc/GCMarker.h
- js/src/gc/GCRuntime.h
- js/src/gc/Marking.cpp
- js/src/gc/Nursery.cpp
- js/src/gc/Verifier.cpp
- js/src/jit/BacktrackingAllocator.cpp
- js/src/jit/BacktrackingAllocator.h
- js/src/jit/JitFrames.cpp
- js/src/jit/JitOptions.cpp
- js/src/jit/LIR.h
- js/src/jit/SimpleAllocator.cpp
- js/src/jit/SimpleAllocator.h
- js/src/jit/StackSlotAllocator.h
- js/src/jit/shared/IonAssemblerBufferWithConstantPools.h
- js/src/wasm/WasmBaselineCompile.cpp
- js/src/wasm/WasmInstance.cpp
- js/src/wasm/WasmStubs.cpp
- js/src/wasm/WasmTable.cpp
- js/xpconnect/src/XPCConvert.cpp
- layout/base/PresShell.cpp
- layout/base/nsCSSFrameConstructor.cpp
- layout/base/nsILayoutHistoryState.idl
- layout/base/nsLayoutHistoryState.cpp
- layout/generic/TextDrawTarget.h
- layout/generic/nsImageMap.cpp
- layout/painting/DottedCornerFinder.cpp
- layout/style/FontFaceSetImpl.cpp
- layout/style/FontFaceSetWorkerImpl.cpp
- layout/style/FontFaceSetWorkerImpl.h
- layout/style/FontLoaderUtils.cpp
- layout/style/FontLoaderUtils.h
- layout/style/ServoCSSRuleList.cpp
- layout/style/StyleSheet.cpp
- layout/style/StyleSheet.h
- + media/libcubeb/delay-line-bounds.patch
- media/libcubeb/moz.yaml
- media/libcubeb/src/cubeb_resampler_internal.h
- media/libsoundtouch/moz.yaml
- + media/libsoundtouch/ratetransposer-clamp-dest-size.patch
- media/libsoundtouch/src/RateTransposer.cpp
- mozglue/misc/Printf.cpp
- mozglue/misc/Printf.h
- netwerk/base/RedirectChannelRegistrar.cpp
- netwerk/base/RedirectChannelRegistrar.h
- netwerk/base/SimpleChannelParent.cpp
- netwerk/base/nsIRedirectChannelRegistrar.idl
- netwerk/base/nsITimedChannel.idl
- netwerk/base/nsNetUtil.cpp
- netwerk/base/nsNetUtil.h
- netwerk/base/nsStandardURL.cpp
- netwerk/dns/DNSPacket.cpp
- netwerk/dns/TRRQuery.cpp
- netwerk/dns/TRRQuery.h
- netwerk/dns/effective_tld_names.dat
- netwerk/ipc/DocumentLoadListener.cpp
- netwerk/ipc/ParentChannelWrapper.cpp
- netwerk/ipc/ParentChannelWrapper.h
- netwerk/ipc/ParentProcessDocumentChannel.cpp
- netwerk/protocol/data/DataChannelParent.cpp
- netwerk/protocol/file/FileChannelParent.cpp
- netwerk/protocol/http/BackgroundChannelRegistrar.cpp
- netwerk/protocol/http/HttpBackgroundChannelParent.cpp
- netwerk/protocol/http/HttpBackgroundChannelParent.h
- netwerk/protocol/http/HttpBaseChannel.cpp
- netwerk/protocol/http/HttpBaseChannel.h
- netwerk/protocol/http/HttpChannelChild.cpp
- netwerk/protocol/http/HttpChannelParams.ipdlh
- netwerk/protocol/http/HttpChannelParent.cpp
- netwerk/protocol/http/HttpChannelParent.h
- netwerk/protocol/http/NullHttpChannel.cpp
- netwerk/protocol/http/NullHttpChannel.h
- netwerk/protocol/http/ReplacedHttpResponse.cpp
- netwerk/protocol/http/ReplacedHttpResponse.h
- netwerk/protocol/http/nsHttpRequestHead.cpp
- netwerk/protocol/http/nsHttpRequestHead.h
- netwerk/protocol/http/nsHttpResponseHead.cpp
- netwerk/protocol/http/nsHttpResponseHead.h
- netwerk/protocol/http/nsHttpTransaction.cpp
- netwerk/protocol/websocket/WebSocketChannel.cpp
- netwerk/sctp/datachannel/DataChannel.cpp
- netwerk/sctp/src/netinet/sctp_indata.c
- netwerk/sctp/src/netinet/sctp_input.c
- netwerk/streamconv/converters/nsUnknownDecoder.cpp
- parser/html/nsHtml5TreeOperation.cpp
- parser/htmlparser/nsParser.cpp
- python/mozbuild/mozbuild/repackaging/deb.py
- security/ct/CTKnownLogs.h
- security/manager/ssl/StaticHPKPins.h
- security/manager/ssl/nsSTSPreloadList.inc
- security/manager/tools/log_list.json
- services/settings/dumps/blocklists/addons-bloomfilters.json
- services/settings/dumps/main/devtools-compatibility-browsers.json
- services/settings/dumps/main/search-config-v2.json
- services/settings/dumps/main/translations-models.json
- services/settings/dumps/security-state/intermediates.json
- services/settings/dumps/security-state/onecrl.json
- taskcluster/config.yml
- taskcluster/docker/debian-packages/Dockerfile
- taskcluster/kinds/packages/ubuntu.yml
- taskcluster/kinds/release-update-verify-config/kind.yml
- taskcluster/kinds/searchfox/kind.yml
- − testing/web-platform/meta/fetch/images/canvas-remote-read-remote-image-redirect.html.ini
- testing/web-platform/meta/html/browsers/the-window-object/window-open-popup-behavior.html.ini
- testing/web-platform/tests/html/semantics/forms/form-control-infrastructure/form_owner_and_table_2.html
- + testing/web-platform/tests/service-workers/service-worker/css-sw-same-origin-substitution.https.html
- + testing/web-platform/tests/service-workers/service-worker/resources/css-sw-same-origin-substitution-iframe.sub.html
- + testing/web-platform/tests/service-workers/service-worker/resources/css-sw-same-origin-substitution-worker.js
- testing/web-platform/tests/tools/certs/cacert.key
- testing/web-platform/tests/tools/certs/cacert.pem
- testing/web-platform/tests/tools/certs/web-platform.test.key
- testing/web-platform/tests/tools/certs/web-platform.test.pem
- third_party/rlbox/include/rlbox_stdlib.hpp
- third_party/rust/audioipc2-client/.cargo-checksum.json
- third_party/rust/audioipc2-client/src/context.rs
- third_party/rust/audioipc2-client/src/stream.rs
- third_party/rust/audioipc2-server/.cargo-checksum.json
- third_party/rust/audioipc2-server/src/server.rs
- third_party/rust/audioipc2/.cargo-checksum.json
- third_party/rust/audioipc2/src/messages.rs
- third_party/rust/cubeb-pulse/.cargo-checksum.json
- third_party/rust/cubeb-pulse/src/backend/stream.rs
- toolkit/components/extensions/Extension.sys.mjs
- toolkit/components/extensions/ExtensionParent.sys.mjs
- toolkit/components/extensions/moz.build
- toolkit/components/extensions/test/mochitest/test_ext_test.html
- + toolkit/components/extensions/test/xpcshell/test_wpt_actor_pref.js
- toolkit/components/extensions/test/xpcshell/test_wpt_test_onMessage.js
- toolkit/components/extensions/test/xpcshell/xpcshell-common.toml
- toolkit/components/pdfjs/content/PdfStreamConverter.sys.mjs
- toolkit/components/pdfjs/content/web/viewer-geckoview.mjs
- toolkit/components/pdfjs/content/web/viewer.mjs
- toolkit/components/pdfjs/test/browser.toml
- + toolkit/components/pdfjs/test/browser_pdfjs_sandboxed_iframe.js
- + toolkit/components/pdfjs/test/file_pdfjs_csp.sjs
- + toolkit/components/pdfjs/test/file_pdfjs_csp_sandbox_opener.html
- + toolkit/components/pdfjs/test/file_pdfjs_csp_sandbox_opener.html^headers^
- toolkit/components/reputationservice/ApplicationReputation.cpp
- toolkit/components/reputationservice/ApplicationReputation.h
- toolkit/components/reputationservice/test/gtest/TestExecutableLists.cpp
- toolkit/components/search/tests/xpcshell/searchconfigs/test_ecosia.js
- toolkit/components/telemetry/core/TelemetryEvent.cpp
- toolkit/components/telemetry/other/TelemetryIOInterposeObserver.cpp
- toolkit/components/telemetry/other/UntrustedModulesDataSerializer.cpp
- toolkit/components/viewsource/test/browser/browser.toml
- + toolkit/components/viewsource/test/browser/browser_bug2048851.js
- + toolkit/components/viewsource/test/browser/file_bug2048851.html
- toolkit/library/rust/gkrust-features.mozbuild
- toolkit/library/rust/shared/Cargo.toml
- toolkit/library/rust/shared/lib.rs
- toolkit/mozapps/extensions/AddonManagerStartup.cpp
- tools/lint/clippy.yml
- uriloader/exthandler/ExternalHelperAppParent.cpp
- uriloader/exthandler/ExternalHelperAppParent.h
- uriloader/exthandler/nsExternalHelperAppService.cpp
- widget/ClipboardWriteRequestParent.cpp
- widget/GfxInfoBase.cpp
- widget/android/EventDispatcher.cpp
- widget/windows/WinRegistry.cpp
- widget/windows/WinRegistry.h
- xpcom/base/ErrorList.py
- xpcom/io/SnappyFrameUtils.cpp
The diff was not included because it is too large.
View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/ba…
--
View it on GitLab: https://gitlab.torproject.org/tpo/applications/mullvad-browser/-/compare/ba…
You're receiving this email because of your account on gitlab.torproject.org. Manage all notifications: https://gitlab.torproject.org/-/profile/notifications | Help: https://gitlab.torproject.org/help
1
0