mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-04 00:00:26 +00:00
0bbd15246fb73c595f152b60ecc65b2109a2a437
64
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
c7dbca3926 |
docs: show the cursor paths humanize=True actually produces
The README's cursor video showed the Bezier generator Camoufox replaced with Cursory's recorded trajectories. scripts/cursor-demo.py drives a real build with humanize=True and records every mousemove event the page receives. It writes assets/humanize-cursor.svg, an animated replay at the recorded speed, so what the figure shows is what a site sees. The script cannot change the binary, so ci/browser_inputs.py lists it as non-native and editing it does not invalidate the cached browser. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|
|
be9f38b08e |
chore: remove build tooling nothing uses
- The developer UI (scripts/developer.py, `make edits`). It depended on easygui, which no requirements file declares, and every action it offered is a Makefile target: patch, unpatch, workspace, revert, diff. Its two helpers in scripts/_mixin.py (is_bootstrap_patch, patch) had no other callers. - legacy/, the Go launcher deprecated in 2024-11. Nothing built or shipped it. Its Makefile targets and scripts/run-pw.py go with it, and so does Go from every dependency list and workflow. - jsonvv/ and settings/camoucfg.jvv. Nothing read the .jvv schema: config is validated against settings/properties.json, and the two had already drifted. The jsonvv package stays on PyPI. - Scripts with no caller: bootstrap.py, moztree, setup-wasi-linux.sh, package-helper.sh, install-local-build.sh, mozfetch.sh (copied into lw/ but never packaged), examples/. - The pre-ESM Juggler copies JugglerFrameParent.jsm and JugglerFrameChild.jsm, and hidden-scrollbars.css. Juggler loads the .sys.mjs actors and deliberately no stylesheet, but jar.mn still packaged all three. - patches/librewolf/*.opt, which list_patches() never picks up; the roverfox second pass in patch.py, whose directory no longer exists; the unread --no-settings-pane option. - The CAMOUFOX_PASSWD secret passed to `make fetch` and closedsrc_rev in upstream.sh, which nothing reads. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
||
|
|
6daae88dbc |
Stock-Firefox parity for native identities: input, fonts, locale, WebGL, WebRTC, media, timing, launcher (#779)
* feat(humanize): replay recorded human mouse movements (Cursory) humanize=True used to walk a Bezier curve through two random knots and emit a point every 10 ms. Both halves are tells: an analytic curve sampled at a fixed rate has velocity and jerk profiles that separate cleanly from a hand's, and every movement accelerated through the same easing function. Juggler now picks one of Cursory's 2357 recorded human movements whose direction, distance and wander suit the move, morphs it onto the requested endpoints and replays it with the recording's own timing. The generator is cursory-js (a bit-exact TypeScript port of Vinyzu/cursory) vendored under additions/juggler/input/cursory/; it is LGPLv3-or-later, not MPL-2.0, and ships its LICENSE and NOTICE inside juggler.jar. MouseTrajectories.hpp and ChromeUtils.camouGetMouseTrajectory are removed. sendTrajectoryAcked takes per-step pauses, drops points on the pixel the last dispatch left the cursor on (a zero-displacement move is never acked), and the humanize guards are updated for the new path shape. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): shared helpers for binary resolution, a private Xvfb and Marionette resolve_binary() honours the runner's CAMOUFOX_EXECUTABLE_PATH before falling back to a Linux objdir (search-service-init and touchscreen-digitizer ignored it and ran the newest objdir, which after a macOS cross build is an arm64 Mach-O), hidden_display() gives a guard its own Xvfb so nothing ever opens on the user's display, and a minimal chrome-context Marionette client lets guards inspect browser UI state. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): synthesized input carries what real mouse and keyboard input carries - pointerType was "" for every Playwright mouse event: juggler dispatched with MOZ_SOURCE_UNKNOWN. It now passes MOZ_SOURCE_MOUSE (#776). - keyboard.type() never pressed Shift: a shifted character now arrives bracketed by ShiftLeft keydown/keyup (location 1) with shiftKey set. - After the pointer was parked off content, pointerover/enter re-entered with buttons=1 and pressure 0.5; the tracked position is now forgotten on park. - A Windows identity gets contextmenu after mouseup with buttons=0, as Windows does; GTK/macOS keep it on press. - Wheel events are sent as line deltas (DOMMouseScroll.detail 3 per notch instead of the pixel count). - The browser rect is measured after the APZ flush await, so a chrome height change during the wait cannot put a y==0 dispatch one row above content. - ci/run_sundial.py moves and clicks the mouse so input vectors have data. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): evaluate() no longer grants user activation Upstream Playwright runs every evaluate() as handling user input and notifies a user-gesture activation. Init scripts go through that path at load, so every page started with navigator.userActivation.hasBeenActive === true, autoplay allowed and popups permitted before any input. Activation now only comes from juggler's trusted input events, as in a stock browser. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): stop hiding scrollbars in headless The headless agent sheet set scrollbar-width: none !important, which a page reads back from getComputedStyle and from overflow:scroll gutters. Scrollbar appearance is left to the platform look-and-feel (the launcher sets ui.useOverlayScrollbars per claimed OS). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ui): no visible automation cues in the browser window - Every Playwright context was a public container, so the URL bar showed a "JUGGLER <id>" label and a container colour. Contexts are now non-public identities (tabbrowser renders public identities only); startup cleanup still removes persisted leftovers. - showcursor defaulted to true, drawing a red dot that followed the mouse. It is now opt-in. tests/patches/visible-automation-cues.py checks both on a private Xvfb. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): web fonts, local(), per-character fallback and native bundles - FontFace / @font-face were answered from the font allowlist by the FontFace's own family name, so every url() web font failed with NS_ERROR_FAILURE and never rendered, local() of an allowed font failed, and a miss rejected with an XPCOM code instead of NetworkError (#759). Stock FontFace/FontFaceImpl are restored; local() is filtered by the RESOLVED family in gfxUserFontSet. - GlobalFontFallback forced the cmap scan, which skips families whose charmap is not loaded yet, so any character outside Gecko's script-based common-fallback table rendered as the primary family's .notdef (U+1E9E on macOS). The platform fallback chooses again, and its choice is held to the mask. - For a native macOS/Windows identity the bundled font sets are not activated: a bundled face of a family the system also has (Papyrus, Helvetica) won the lookup with different metrics. On Windows the enumerator still keeps Twemoji Mozilla, the emoji font stock Firefox ships (flag emoji drew nothing). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): CSS2 system fonts and system-ui follow the claimed OS - The host's own OS gets no system-ui override (macOS resolved system-ui to Helvetica instead of -apple-system). - CSS2 system font keywords use per-keyword faces and sizes; a Linux identity reports the Ubuntu desktop font; Windows form controls (-moz-button/field/list) answer "MS Shell Dlg 2" as Windows does, not Segoe UI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(fonts): per-OS font model and fontconfig parity fonts.json is now generated from the bundle by scripts/gen-fonts-json.py (fc-scan + aliases + scan-time families, intersected with the per-OS manifest in scripts/data/font-manifests.json) so every reportable family is renderable; scripts/verify-fonts.py checks that invariant, the generics and the reject globs. font-groups.json lets the draw keep co-shipped families together. Linux fontconfig: stock metric aliases (Arial -> Liberation Sans, ...), 49-sansserif, urw-base35 and the non-Latin rule files in stock conf.d order, generics resolving like a stock Ubuntu (Noto Sans / Noto Serif / DejaVu Sans Mono / Z003), hintslight so advances are not pinned to whole pixels, and weak <prefer> lists instead of strongly-bound generic pins so lang can promote a script face. Windows fontconfig: GDI substitution aliases, MS Shell Dlg 2, cursive/fantasy generics, duplicate-face rejects and Sitka / Segoe UI Variable optical-size families. NOTE: generated against a ~3.9 GB target font bundle that is not part of this change (one file is over GitHub's 100 MB limit); see docs/FONTS.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(locale): localize browser strings with the spoofed locale; stop rewriting explicit locales - With locale="fr-FR", Intl/number/date went French but input.validationMessage and XML parse errors stayed English, a mix no real Firefox produces. Official language packs are now baked in as packaged locales (scripts/fetch-langpacks.py, scripts/inject-locales.py, called by package.py, fetched on demand) and the launcher selects the UI locale through intl.locale.requested. A langpack add-on cannot do this: the parent pre-creates those string bundles first. - locale-spoofing.patch overrode Language/Script/Region on every intl::Locale, so new Intl.DisplayNames(['en'],{type:'region'}).of('DE') returned the spoofed region's name and Intl.Locale('ja-Jpan-JP').minimize() returned the spoofed tag. Only the OS/default locale is spoofed now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): enumerate, capture and label the identity's media devices coherently The fake media engine now enumerates the identity's microphones, cameras and speakers (labels and group ids from new mediaDevices:*Labels/*Groups config keys), MediaManager uses it whenever mediaDevices:enabled, and stock exposure rules apply: before a grant one device per input kind, no outputs, no labels; after a grant OS-style labels, distinct deviceIds, shared groupIds. So enumerateDevices(), getUserMedia() tracks and getSettings() ids agree, and a claimed camera captures instead of throwing NotFoundError. Fixes the content-process crash on an identity with a camera and no microphone (InsertElementAt on an empty array). docs/MEDIA-DEVICES.md; guard tests/patches/media-devices-coherence.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(navigator): globalPrivacyControl agrees between window and workers (#760) The main-thread Navigator getter ignored the config key that WorkerNavigator::GlobalPrivacyControl honours, so a page read false in the window and true in a worker. Both read the key the same way now; the launcher also mirrors it into privacy.globalprivacycontrol.enabled so the Sec-GPC header agrees. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): apply the launch-level timezone from the first read (#773) The timezone config key was only applied lazily from a navigator getter, so Intl and Date reported the host zone until a page happened to touch navigator. It is now applied eagerly in every process (nsJSContext::EnsureStatics) and per realm when a new inner window is created, entering that window's realm rather than whichever one triggered the navigation. window.setTimezone() still takes precedence per context. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(screen): the CSS color media feature follows the spoofed colorDepth screen.colorDepth was spoofed at the WebIDL level only, so on a 10-bit panel a 24-bit identity reported 24 with (color: 10), a pair Gecko cannot produce. Gecko_MediaFeatures_GetColorDepth now resolves the depth in the same order as nsScreen::PixelDepth. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): pass live state through instead of answering it from the table getParameter answered everything from the sampled table, so state a page had just set read back wrong (lineWidth(5) read 1, VIEWPORT/SCISSOR_BOX stayed 300x150 on a 64x64 canvas), extension parameters were null (anisotropy, draw buffers), COMPRESSED_TEXTURE_FORMATS was null instead of [], and getContextAttributes() ignored the attributes requested ({antialias:false} still reported 4 samples). Identity and limits still come from the table; live state and context attributes are real. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): ICE gathering completes behind a proxy (#774) With Playwright's per-context proxy and media.peerconnection.ice.proxy_only_if_behind_proxy, ICE failed before gathering started and iceGatheringState stayed "new" forever, where stock Firefox completes with host candidates. When that happens around the fabricated candidates the new -> gathering -> complete state walk is replayed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(patches): refresh window-setter-seal.patch offsets Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(windows): embed Firefox's application manifest in camoufox.exe config/rules.mk embeds <program>.manifest and browser/app only ships firefox.exe.manifest, so --with-app-name=camoufox produced an exe with no manifest. Without the Windows 10 supportedOS GUID the process and its children run as a pre-Windows-10 application and Gecko's Windows-10-gated paths switch off (MediaCapabilities.decodingInfo powerEfficient false for H.264/VP9 where stock is true). The new patch adds a byte-for-byte copy as camoufox.exe.manifest; the old rename hunk in windows-theming-bug-modified.patch is dropped. Guard: tests/patches/windows-exe-manifest.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock values for page-observable prefs; launcher prefs at startup Page-observable defaults that no stock Firefox has, restored: - the forced built-in dark theme (it also removed the 1 px nav-bar separator, and was applied ~1 s after startup, resizing the viewport) and ui.systemUsesDarkTheme (prefers-color-scheme disagreed with the desktop); - focus rings off, autoplay allowed, popup blocker off; - gfx.color_management.mode=0 (Playwright's test pref: ICC-tagged images were drawn unconverted, readable from a canvas pixel); - ui.use_standins_for_native_colors (non-native system colours); - GMP updates off (Widevine/OpenH264 never available); - storage.estimate() quota derived from the raw disk instead of the stock cap. The HardwareAcceleration:false enterprise policy is removed: it locked software WebRender with no hardware video decoding on every OS (guard tests/patches/hardware-acceleration-policy.py). The minimal-theme chrome.css is emptied: its ~55 px chrome made outerHeight - innerHeight impossible. Playwright's non-persistent launch writes no user.js, so launcher prefs only arrived through juggler after startup and anything Gecko reads while starting raced (on Windows the UI locale lost 3 of 4 launches). camoufox.cfg now applies the launcher's CAMOU_PREFS_1..N env chunks as default prefs at startup (guard tests/patches/startup-prefs.py). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(branding): chrome://branding assets match stock Firefox chrome://branding/content/ is content-accessible. The wordmark SVGs had different intrinsic sizes (336x48 / 172x48 vs 300x67) and document.ico, document_pdf.svg and the private-browsing about logos were missing, all measurable from a page with an <img>. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): identity draws that match real machines and stay stable Launcher-side fixes found by comparing camoufox against stock Firefox 152.0.4 on Linux, Windows 11 and macOS hosts: - DNT / GPC: BrowserForge draws doNotTrack "1" on most Firefox samples, but a stock Firefox 152 reports "unspecified" and globalPrivacyControl false; the stock defaults are used unless the caller sets them, and both are applied as prefs so the API, the worker and the DNT / Sec-GPC headers agree (#760). - Timezone and geolocation: the timezone is passed to the browser, and a configured position sets permissions.default.geo so permissions.query agrees with the auto-grant (#769, #773). - hardwareConcurrency: the reported count is the fingerprint's and the browser is pinned to that many cores (cpu_affinity.py, Linux/Windows), so worker timing agrees with it; otherwise the host count snapped into the core counts real machines ship with (never 2, Firefox's resistFingerprinting value). - Fonts: the OS base is always present in full, OS-version variants are drawn all-or-nothing, co-shipped groups stay together, Cascadia is never claimed off Windows, a native macOS/Windows identity claims only the real OS base, and gfx.font_rendering.fallback.async is off on Linux so per-character fallback does not depend on cmap-load timing. - Speech voices: a per-OS installed-voice model (voice-manifests.json) with the voiceURI formats each backend really produces (voice-uris.json); no default voice where stock has none. - WebGL: extensions a release Firefox never exposes are filtered, but OVR_multiview2 stays for Windows D3D11 renderers, which expose it. - Media devices: a seeded draw of common per-OS devices with OS-style labels. - Windows scrollbars follow the drawn Windows version (overlay on 11). - Glyph-advance perturbation (fonts:spacing_seed) defaults to off: it moved every measureText width off the value the same font gives on a real machine. - Launcher prefs are also exported as CAMOU_PREFS_1..N so camoufox.cfg applies them at startup, and the browser UI locale follows the spoofed locale. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): per-identity salt for seeded draws; core pinning under concurrency Found in review of the previous commits: - identity_seed() hashed only the UA, platform, screen size and core count. Those take a handful of values per OS, so over 500 launches the seed took 12-30 distinct values and every install drew its fonts, voices, GPU, media devices and canvas/audio noise seeds from that same short list. The seed now mixes in identity_salt(): derived from what the caller pinned the identity with (a Fingerprint, a preset dict, a config naming the UA) so relaunching that identity reproduces every draw, and random otherwise. A pinned preset now reproduces its noise seeds too; seeds the caller sets are kept. - Concurrent AsyncNewBrowser launches on one driver interleaved pin/restore: one browser inherited the other's mask and the driver could stay pinned. pin -> launch -> restore is serialized per driver. - Every pinned browser landed on cores 0..N-1; pins now take N adjacent cores from a random start. - A pinnable host with 1-3 cores reported 1, 2 or 3 (2 is the resistFingerprinting value); the table floor of 4 applies as on other hosts. - launch_options() callers that launch the browser themselves (launch_server, direct use) kept the drawn core count although nothing pins the browser; only Camoufox/AsyncCamoufox pass pin_cpu_cores=True now, everyone else reports the host's snapped count. - PLAUSIBLE_CORE_COUNTS gains 18, 22, 28 and 32, all recorded in the -v150 corpus. - The Windows voice list was drawn before the locale was resolved, so an fr-FR identity got en-US voices; it is drawn after locale/geoip now. - macOS "Alex" gets its com.apple.speech.synthesis.voice identifier. - CAMOU_PREFS env chunks are ASCII-only JSON (Windows getenv goes through the ANSI code page). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): canvas accepts CSS2 system-font keywords; local() works on macOS - GetSpoofedSystemFontForRFP's per-OS branches returned before marking the result a system font. ComputeSystemFont copies that flag into FontFamilyList::is_system_font, and without it the canvas font setter could not serialize the value: ctx.font = 'caption' (or icon, menu, message-box, small-caption, status-bar) was silently ignored and read back '10px sans-serif' where stock reads back the keyword. - CoreTextFontList::LookupLocalFont builds a CTFontEntry with no family name, and local() sources are held to the spoofed font list by the resolved family, so on macOS every local() face (Helvetica, Menlo, Arial...) failed with NetworkError, installed and allowed or not. The entry now carries the family CoreText resolved. A blocked lookup's entry is released instead of leaked. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): only device limits come from the spoofed table getParameter still answered ~100 state pnames from the table, so state the page had just changed read back wrong: UNPACK_FLIP_Y_WEBGL / PREMULTIPLY_ALPHA / COLORSPACE_CONVERSION after pixelStorei, FRAGMENT_SHADER_DERIVATIVE_HINT after hint(), DRAW_BUFFERi after drawBuffers(), RED/ALPHA/DEPTH/STENCIL_BITS and IMPLEMENTATION_COLOR_READ_* for the bound framebuffer, and COMPRESSED_TEXTURE_ FORMATS after enabling an extension. UNMASKED_VENDOR/RENDERER_WEBGL came back without the extension enabled, where stock returns null with INVALID_ENUM. The table now answers only the MAX_*/ALIASED_*/SUBPIXEL_BITS limits, WebGL 2 limits on WebGL 2 contexts only, and extension limits (anisotropy, draw buffers, OVR multiview) only once that extension is enabled; everything else is the real context's answer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): fabricate candidates only where a real gather would have them With webrtc:ipv4/ipv6 set (every geoip launch), new RTCPeerConnection() with no iceServers produced a srflx carrying the spoofed IP, and after end-of-candidates a second host set with a different mDNS name. getStats() exposed that srflx as id 'camou-srflx' and rewrote every candidate address, including .local host names and the remote peer's candidates. A srflx is now fabricated only when the page configured an ICE server, host candidates only when none reached the page (sharing the real UDP host's port otherwise), the synthetic stats id has the shape real candidate ids have (8 hex digits, fixed per connection), and only this side's non-mDNS addresses are rewritten. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): honour mediaDevices:enabled=false; page fake:true behaves as stock - MaskConfig::GetBool returns std::optional<bool>, and the checks tested its presence: "mediaDevices:enabled": false still enabled the fake devices. - media.navigator.permission.fake=true was page-readable: a page's own getUserMedia({video: true, fake: true}) prompted and never resolved, where stock resolves at once with its generic fake device. The pref is off again; the identity's devices count as real hardware in the capturing checks instead (prompt, sharing indicator, post-grant labels), and a page's fake:true request gets stock's generic devices rather than the identity's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(storage): per-context values are session state, and misses are cached - Values lived on the user pref branch, which a persistent profile writes to prefs.js: relaunching with a different timezone (or navigator values) kept reporting the previous session's in the page, iframes and workers. They now live on the default branch, which is never saved, and reads ignore user values an older build left behind. - A read of an unset key did a synchronous IPC to the parent every time, and in a launch without per-context values every read is unset: navigator.hardwareConcurrency, screen.* and (color) media queries measured ~20x slower than stock. A miss is now cached per key until a pref change or a local put clears it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): no per-realm override for the process-wide zone; cache DateTimeInfo With a launch-level timezone every new document and worker got a per-realm override of the zone the process already reported. Setting one releases all JIT code in the runtime (hot code after adding an iframe ran ~4x slower), and the realm rebuilt its DateTimeInfo on every call (getHours() ~40x slower than stock). The override is applied only when the zone differs from the one JS::SetTimeZoneOverride applied process-wide, and a realm keeps its DateTimeInfo until its override changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): wheel scrolls in native notches; Shift leads the key it modifies - A wheel notch now reaches the page as its own 3-line event carrying one native tick (new WHEEL_EVENT_NATIVE_NOTCHES option in patches/wheel-native-ticks.patch), so wheelDelta is -120 per notch as with a physical wheel; it was -396, and a multi-notch scroll arrived as one event. Several notches are spaced a few tens of ms apart. - Auto-Shift pressed Shift 0 ms before the character's keydown and released it 0 ms after its keyup; it now leads and trails by a drawn human-scale delay, and a failing keydown no longer leaves Shift latched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock cookie partitioning, preconnect, popup notification; about dialog CSS - network.cookie.cookieBehavior 4 (Playwright's) -> Firefox's default 5. With 4 a cross-site iframe (captcha and anti-bot widgets are exactly that) sees document.hasStorageAccess() true and its first-party cookies and localStorage, where stock partitions them. Playwright set 4 so storageState need not carry thirdPartyCookie^ permissions. - network.http.speculative-parallel-limit 0 turned <link rel=preconnect> into a no-op, visible in Resource Timing. - privacy.popups.showBrowserMessage false: stock shows a notification bar for a blocked popup, which shrinks the viewport and fires resize. - chrome://branding/content/aboutDialog.css is page-loadable and was empty; it is the official branding's now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): stock-parity probes for the leaks found in review One launch (plus two persistent relaunches) checks page-observable invariants stock Firefox 152 holds: canvas CSS2 system-font keywords, WebGL state readback and UNMASKED_RENDERER without the extension, no srflx without ICE servers and no 'camou' stats id, getUserMedia({fake: true}), cross-site storage partitioning, wheel notches, per-read cost of (color)/hardwareConcurrency and of local Date getters under a launch timezone, and a persistent profile's timezone after relaunch (page and worker). Run against the build before these fixes it fails on every one of them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(humanize): judge cadence by distinct values and spread, not a share of the gap count The page clock is clamped to 1 ms and Cursory's recorded steps mostly sit between 12 and 20 ms, so the number of distinct gap values cannot grow with the number of gaps. Requiring len(gaps) // 4 made the guard fail on visibly uneven runs whenever event delivery was steady (3 of 4 runs once the per-read sync IPC jitter was gone). A fixed 10 ms cadence yields about three values within a few ms of each other, which the new rule (>= 6 values, >= 20 ms spread) still fails. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): restore the popup, wheel and history contracts The Playwright suite went red on this branch, and five of its six shards ran out their 40-minute budget before reporting, so ~470 sync tests were never run at all. Three causes, all ours: - window.open() from page.evaluate() returned null. The popup blocker being ON (Firefox's default) and evaluate() no longer granting user activation are each defensible alone; together they block every gesture-less popup. ~35 tests, each burning 30s x 4 attempts x 2 worlds, which is what exhausted the shards. The blocker goes back to Playwright's and geckodriver's value. Reading it costs a detector a popup window the user sees, so it is not a check an anti-bot script in the page runs -- unlike navigator.userActivation.hasBeenActive, which is one property read, and which is why the activation half stays. - mouse.wheel(0, 100) delivered deltaY 114 (or 132, depending on the host's font metrics) in deltaMode 1. Quantising into native wheel notches is what a physical wheel does, but it changes the number the caller asked for, so it now rides behind humanize= with the rest of the humanized input. Default is the exact requested delta in deltaMode 0. - page.go_back() did nothing after history.pushState(). canGoBack is the BACK BUTTON's answer: under browser.navigation.requireUserInteraction it reports false when every entry behind this one was pushed without the user touching the page, which is now every entry, because evaluate() grants no activation. goBack() itself does not skip those entries and neither does history.back(), so ask canGoBackIgnoringUserInteraction, as Marionette does. Two keyboard tests are skiplisted rather than fixed: auto-Shift means typing "!" emits the Shift a US keyboard requires, and upstream asserts the character's three events with shiftKey false throughout. The character's own key/code/keyCode are unchanged; what upstream asserts is the absence of a Shift no real typist could omit. Full suite against the fixed build: 2223 passed, 6 failed -- the two keyboard tests above, and four client-certificate tests that fail only on this machine (Node/OpenSSL rejects the fixture server) and pass in CI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): stop overriding the corpus on core counts; pinning is opt-in Two findings from auditing the sweep's fixes against one bar: a difference is a leak only if a page's JavaScript can actually read it. hardwareConcurrency 2 was excluded from PLAUSIBLE_CORE_COUNTS because "2 is what Firefox reports under resistFingerprinting". That has not been true for years: RuntimeService::ClampedHardwareConcurrency hardcodes 4, and 8 on macOS, both of which are already in the table. The exclusion protected against nothing and cost every genuinely dual-core machine -- 20% of the macOS presets in the recorded corpus, 4.2% of Linux draws. It also made the small-host tail worse: a 3-core host reported 4, which cannot be pinned, so a page measured 3 while being told 4. At 2 the pin succeeds. pin_cpu_cores now defaults to False. What it buys is defence against a page timing N parallel workers; what it costs is a browser-wide CPU cap, a per-driver launch lock, and nothing at all on macOS. Unpinned, the host's own snapped count is reported, so reported and measurable still agree -- the identity just loses one drawn value. Callers who want the draw kept can still ask for it. The WebGL sampler keeps rejecting software rasterisers, and its docstring now says so: it described the opposite of what the code does. llvmpipe as the presented GPU is a live check on a string every fingerprint script reads, which is worth ~1.5% of corpus fidelity. 251 pythonlib tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): keep 2 out of the core table -- an Apple M1 is never dual-core Reverts the PLAUSIBLE_CORE_COUNTS half of |
||
|
|
4132dd50a6 |
refactor(juggler): make the input-dispatch deadlock structurally unreachable
Four deadlocks shipped between 2026-04 and 2026-09 -- exact-edge coordinates (9270618), humanized trajectory points that bypassed the endpoint's guard ( |
||
|
|
41ba997799 |
build: stage bundled fonts into unpackaged builds
`mach build` leaves dist/bin/fonts holding only TwemojiMozilla.ttf -- the font bundles and fontconfig are staged by scripts/package.py, so they exist only in packaged builds. Anything launching the objdir binary through the Python wrapper therefore starts a browser with no usable content font, because the wrapper sets FONTCONFIG_FILE to a file that is not there. It fails confusingly: the browser chrome still has system fonts, so the only symptom is tofu boxes in page content, and through AsyncCamoufox it surfaces as a TargetClosedError with no indication of the cause. That cost real time while writing the tests/patches scripts, hence the note in their docstrings. `make stage-fonts` copies them in. Idempotent, and a no-op when nothing is built yet. Not needed by `make run` or `make tests`, which launch the binary directly and fall back to the system fontconfig. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> |
||
|
|
c4716d2ec1 |
fix(build): stop dropping the MSVC CRT from Windows packages (#650)
package-windows pulls VCRUNTIME140/VCRUNTIME140_1/MSVCP140 out of the mozbuild Visual Studio tree through a shell glob that pins one redist version (14.38.33135) and one toolset (VC143). Windows builds cross-compile on Linux and get their toolchain from mozbootstrap, so a different version there leaves the glob unexpanded -- and add_includes_to_package() skipped anything that did not exist, with no warning. The package then ships without the CRT. camoufox.exe imports those DLLs, so on any machine without the Visual C++ Redistributable installed the process dies immediately and Playwright surfaces only "spawn UNKNOWN". - glob the redist and toolset versions instead of pinning them - treat a missing --includes entry as fatal, so an unexpanded glob fails the build instead of silently shipping a broken package |
||
|
|
fb6d475fd3 |
Drop Linux i686 support for future releases
Firefox 32-bit Linux Support ended in 2026. This change removes it from the workflow https://blog.mozilla.org/futurereleases/2025/09/05/firefox-32-bit-linux-support-to-end-in-2026/ |
||
|
|
34760a639b | Fix patcher attempting to use git after setup-minimal | ||
|
|
26b94797c3 |
fix(stealth): consolidated stealth/juggler/build fixes (rebased onto FF152)
Consolidates the following individual fixes into one changeset, all rebased onto the current Firefox 152 base and validated together via a full build: - webrtc: stop real-IP leak under a proxy; sanitize getStats IP + fabricate a synthetic srflx when ICE produces none (TCP-proxy case). - proxy: re-enable launch-arg proxy by disabling https_first. - screen: make MaskConfig the single source for screen + CSS device dims so matchMedia(device-width) agrees with screen.width. - stealth: spoof CSS2 system-font keyword resolution (font-system-fonts-css2). - juggler: filepicker reliability + skip mouse-move coalescing for synthetic (juggler) events so input dispatch can't stall under parallel load. - juggler: emit a single input event for insertText on form fields. - juggler: reload about:blank via browsingContext.reload. - locale: propagate launch-arg locale to BrowsingContext. - build: create v150-removed dirs before copy-additions. - stealth: BrowserForge headless / impossible-geometry tell corrections and speech-voice spoofing (host-voice leak fix). Supersedes daijro/camoufox #637-#647. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|
|
f342c20dd2 |
Version 152.0.2 Upgrade (#658)
* 152 upgrade patches * remove unused patch * fix juggler * add rust cross compile to required deps |
||
|
|
4f5e4484d1 | add install deps script | ||
|
|
0ac611c4ad |
v150 with Windows Support - Python Package Being Merged Separately (#611)
* fix v150 patches * screen related patch fixes * fix juggler issues with 150 * Update grading.py improved build tester scoring * fix windows build for v150 - scripts/_mixin.py: switch moz_target from x86_64-pc-mingw32 (no longer supported in FF150) to x86_64-pc-windows-msvc - additions/juggler/screencast/HeadlessWindowCapturer.h: typedef pid_t on XP_WIN; libwebrtc headers (video_capture.h, desktop_capturer.h) reference pid_t which is POSIX-only - patches/anti-font-fingerprinting.patch: include mozilla/dom/Document.h in gfxTextRun.cpp; on Windows it is not transitively included so doc->GetInnerWindow() failed with "incomplete type 'Document'" Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * make service test use local binary * updated ff fingerprint versions * Update README.md --------- Co-authored-by: Ubuntu <ubuntu@ip-172-31-15-96.us-east-2.compute.internal> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
5219a40849 |
build test fixes (#586)
* build test fixes * fix wrong references * Update PULL_REQUEST_TEMPLATE.md |
||
|
|
5f3c1f2c64 |
Allow disabling font spacing perturbation (seed=0 no-op, matching audio) (#548)
* Allow disabling font spacing perturbation (seed=0 no-op, matching audio) The audio fingerprint manager treats seed==0 as "no perturbation", but font spacing had a hardcoded fallback (0x6D2B79F5u) that made it always active — even when no seed was explicitly set. C++ change: remove the hardcoded fallback and add `if (seed != 0)` guard around the LCG + glyph offset loop (mirrors AudioFingerprintManager). Also removes the debug printf that fired on every ShapeText() call. To disable font spacing from the Python API, set fonts:spacing_seed to 0 in the config/preset — same convention as audio:seed and canvas:seed. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com> * Add local channel install script for custom builds Installs build artifacts to browsers/local/ instead of overwriting official slots. Survives camoufox fetch. Handles permissions and version.json automatically. --------- Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com> |
||
|
|
d6540b52ce |
Service Test and Contributing Guides (#521)
* example files * contributing guides * simple service test * run tests in sync * update pr template * pip updates * Update README.md * typo fixes * undo pip package update lol * upgraded service test * undo injections * test with proxies * auto set timezone and proxy url * delete checks bundle * split up service tests * split up build tests * rename service tests to service tester * Update CONTRIBUTING.md * fix entry vs exit ip * allow alpha versions * fix patch issues on macos * bidirectional patch * Add note on experimental pip package |
||
|
|
33b0e0ebcc |
Build improvements (#3)
* fix asets.car issue * dist folder issue bruh |
||
|
|
dfa62f7070 |
Juggler fixes (#2)
* fix: migrate Services import to lazy loading pattern and disable dark theme to prevent XPIProvider crash - Changed Services from ChromeUtils.defineLazyGetter to ChromeUtils.defineESModuleGetters with lazy object - Updated all Services references to lazy.Services throughout Juggler.js - Added re-copying of additions and settings after git reset in patch.py - Removed juggler components.conf copy logic from patch.py (now handled by copy-additions.sh) - Disabled dark theme preference in camoufox.cfg to * fix: revert Services import to direct ESM import and re-enable dark theme preference - Changed Services from lazy loading pattern back to direct ChromeUtils.importESModule() - Removed lazy object wrapper and ChromeUtils.defineESModuleGetters usage - Updated all lazy.Services references to Services throughout Juggler.js - Re-enabled dark theme preference in camoufox.cfg (extensions.activeThemeID) - Removed XPIProvider crash prevention comment as issue is resolved * fix: remove redundant Services import as it's available globally in XPCOM component context - Removed ChromeUtils.importESModule imports for XPCOMUtils, ComponentUtils, and Services - Added comment explaining Services is available as a global in XPCOM component context - Services.scriptloader.loadSubScript call continues to work with global Services reference * fix: correct JugglerFrameChild.sys.mjs path by removing duplicate content directory - Changed esModuleURI from 'chrome://juggler/content/content/JugglerFrameChild.sys.mjs' to 'chrome://juggler/content/JugglerFrameChild.sys.mjs' - Removes erroneous duplicate 'content' directory in the child actor module path * fix: add ESM module entries and correct JugglerFrameChild.jsm path in jar.mn - Added JugglerFrameParent.sys.mjs entry to juggler.jar manifest - Added JugglerFrameChild.sys.mjs entry to juggler.jar manifest - Fixed JugglerFrameChild.jsm path from 'content/content/JugglerFrameChild.jsm' to 'content/JugglerFrameChild.jsm' removing duplicate content directory * fix: remove redundant Services lazy getter as it's available globally in content process context - Removed ChromeUtils.defineLazyGetter for Services in main.js - Added comment explaining Services is available as a global - Services reference continues to work with global availability in content process --------- Co-authored-by: Nirupam Bhowmick <48842933+heydryft@users.noreply.github.com> |
||
|
|
3cceb0f4f5 |
Revert "bring back camoufox branding"
This reverts commit
|
||
|
|
3258fca5b2 | bring back camoufox branding | ||
|
|
7106903bb0 |
fix: add binary flag to patch command for line ending preservation
- Added --binary flag to preserve line endings (CRLF vs LF) - Removed -F3 (fuzz factor) flag - Helps with cross-platform patching where line endings may differ |
||
|
|
acba61d7aa |
fix: improve patch command flexibility with whitespace and fuzz tolerance
- Changed --fuzz=3 to -F3 for consistent short option format - Added -l flag to ignore whitespace differences when applying patches - Maintains --forward flag to skip already applied patches |
||
|
|
ee997d1518 | make patching more lenient | ||
|
|
f7a9bf7fbd |
refactor: move MOZ_APP_VENDOR and MOZ_APP_PROFILE to moz.configure and fix juggler component registration
- Removed MOZ_APP_VENDOR and MOZ_APP_PROFILE from configure.sh branding file - Added note that these must be set via imply_option() in browser/moz.configure - Updated disable-data-reporting-at-compile-time.patch to set MOZ_APP_VENDOR="Camoufox" and MOZ_APP_PROFILE="camoufox" - Changed juggler components.conf to use "type" instead of "constructor" for Firefox 146+ compatibility - Added automatic |
||
|
|
32122430be | fix: every patch patches except 0, 1 playwright and roverfox context | ||
|
|
75fb8d2f78 | fix: auto-update 6 line numbers in 0-playwright.patch | ||
|
|
08ecd86746 |
feat: add Firefox v147 patch update task list and tracking document
Add comprehensive task list documenting the Firefox upgrade from v135.0.1 to v147.0b3 (12 major versions). Includes status tracking for all 45 patches after syncing with upstream LibreWolf (Firefox 146) and Playwright repositories. Key changes: - 25 broken patches identified (56% failure rate) - 20 patches applying cleanly (44% success rate) - LibreWolf patches updated from upstream: 17 patches synced, 5 deleted, 2 auto-fixed - |
||
|
|
cd77ea7bd5 | feat: remove webrtc ipv6 func and update diff command in developer script | ||
|
|
e1a28778db | feat: add WebRTC IP spoofing with per-context isolation support | ||
|
|
15719fe9b1 | feat: implement user context-based font spacing | ||
|
|
cc852b424a | Minor dev UI improvements: add patch statuses directly to lists for improved usability | ||
|
|
8dc1f6b039 | fix broken f-string formatting and broken python make edits call | ||
|
|
9f6d55f39b | Extract inner tar in packager | ||
|
|
2f2af937a1 | Update packager to search for tar.xz | ||
|
|
33085c90f3 |
Merge with Playwright a121f85
Merges patches with the latest commit: https://github.com/microsoft/playwright/commit/a121f85ce91b67aeb1191e2fcca0939ad5b38671 |
||
|
|
bbe1cbe2b2 | Memory benchmark scripts via podman #87 | ||
|
|
4f15447e04 | Deprecate old launcher & locales | ||
|
|
85eb40aee4 | Leak fixes #90 | ||
|
|
e126cf379c | Update uBlock Origin assets & updater | ||
|
|
ad3b3f04fe |
Add extra parameters to test site
Added the following parameters to the WebGL testing site: TIMESTAMP_EXT, GPU_DISJOINT_EXT, MAX_VIEWS_OVR |
||
|
|
5bfc3ee026 |
Further improved WebGL spoofing beta.12
- Added ability to spoof webgl2 supported extensions - Added ability to block parameters that aren't defined in config - Passing null in config will block the value - Added more parameters to the demo site |
||
|
|
02bc15161a |
feat: WebGL fingerprint spoofing
Experimental WebGL fingerprint injection. - Allows the ability to set all WebGL parameters, supported extension list, shader precision formats, & context attributes. - Added a demo website under scripts/examples/webgl.html that can be used to generate Camoufox config data |
||
|
|
8a9b062d05 | Update test script to output debug.log | ||
|
|
ea84f792df | Developer UI: Keep clean build files on reset | ||
|
|
a2cb02df8a |
Add config type validator
- Validates property types passed in --config. - Types are stored in properties.json. |
||
|
|
a766940363 |
Makefile: Fix build resetting workspace when editing patch
|
||
|
|
1d31bad14e |
Merge gh-actions branch into main
main..gh-actions: - CI/CD: Fix release permissions - Fix macos packaging on debian - CI/CD: Remove unwanted tools - CI/CD: Attempt to fix OOM killing GH runner during LTO - CI/CD: Fix glibc errors - CI/CD: Downgrade to ubuntu-20.04 - CI/CD: Use target os matrix & fix release - CI/CD: Remove Windows (temporarily) - CI/CD: Move to AdityaGarg8/remove-unwanted-software@v4.1 - CI/CD: Limit CPU as well - CI/CD: Create cgroup with 80% mem limit - CI/CD: Revert "Remove .mozbuild caching" - CI/CD: Expand root & swap build space - CI/CD: Remove .mozbuild caching - CI/CD: Check disk space after checkout - CI/CD: Use easimon/maximize-build-space - CI/CD: Add workflow dispatch trigger - CI/CD: Experimental fix for clang, add swap space - CI/CD: Save .mozbuid cache after Build |
||
|
|
80a657268e |
Packaging & macos exec fixes
- Use "open -a" to launch Camoufox.app - Fix fonts not copying correctly - Find & move asset files to dist/ correctly |
||
|
|
a891914b9a |
Makefile: Remove revert from dir command
Removes git reset when running `make dir`. This avoids errors when using `make setup-minimal`. |
||
|
|
2ac5351fd5 | Fix developer UI not finding source folder | ||
|
|
ad87cec317 |
Makefile: run-pw with launcher
Build and copy the launcher when testing Playwright |