Cover both failure modes from #656 and pin the driver entrypoint
contract, so a future Playwright reshuffle fails in CI rather than in a
user's terminal. No browser download or launch, so they run anywhere.
Refs #656
When the node server exits early, writing its config to the dead stdin
raised BrokenPipeError (EINVAL on Windows), burying the real cause.
communicate() ignores both, so the underlying failure stays visible.
Refs #656
Playwright 1.60 bundled its internals and removed the private
lib/browserServerImpl.js that launchServer.js required, so
`python -m camoufox server` died with MODULE_NOT_FOUND. Load the
driver's package entrypoint instead, which is a bundled playwright-core
and exposes launchServer as public API.
The driver path is now passed explicitly rather than inferred from
process.cwd().
Fixes#656
Fix for JWriter20 repo having several releases with the same version and build name, which broke the manager
- Installs browsers as version-build-sha256/ rather than version-build/ since assets can share a version-build combo
- Doesn't break existing downloads
- Show date column in gui and selector tui
Replace the terminate→wait→kill fallback in VirtualDisplay.kill() with a
direct SIGKILL to prevent zombie Xvfb processes. After the process exits,
remove the stale /tmp/.X{n}-lock and /tmp/.X11-unix/X{n} files so future
display allocations are not blocked. Also set self.proc = None to mark the
display as fully cleaned up.
* fix v150 patches
* screen related patch fixes
* fix juggler issues with 150
* Update grading.py
improved build tester scoring
* fix windows build for v150
- scripts/_mixin.py: switch moz_target from x86_64-pc-mingw32 (no longer
supported in FF150) to x86_64-pc-windows-msvc
- additions/juggler/screencast/HeadlessWindowCapturer.h: typedef pid_t
on XP_WIN; libwebrtc headers (video_capture.h, desktop_capturer.h)
reference pid_t which is POSIX-only
- patches/anti-font-fingerprinting.patch: include mozilla/dom/Document.h
in gfxTextRun.cpp; on Windows it is not transitively included so
doc->GetInnerWindow() failed with "incomplete type 'Document'"
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* make service test use local binary
* updated ff fingerprint versions
* Update README.md
---------
Co-authored-by: Ubuntu <ubuntu@ip-172-31-15-96.us-east-2.compute.internal>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Replace the userspace lock-file scan + random-jitter retry loop with
Xvfb's own -displayfd mechanism. Xvfb scans up from :0 and atomically
binds the first free X11 socket (kernel-mediated, no userspace race),
then writes the chosen display number back through an inherited pipe.
This eliminates the duplicate-display race that occurred when many
camoufox processes started concurrently and all observed the same set
of free display numbers before any of them bound.
Adds a 10s read timeout on the displayfd pipe so a hung Xvfb fails
fast instead of blocking forever, and adds tests covering single
launch, idempotent get(), 50 concurrent reservations with uniqueness,
and post-kill display reuse.
* Add system-ui font spoofing patch
GetSystemUIFontFamilies() now reads navigator.platform from MaskConfig
and returns the appropriate system font (Helvetica for macOS, Segoe UI
for Windows) before falling through to LookAndFeel::GetFont. Fixes the
CreepJS headless.systemFonts "Sans:Linux" leak when spoofing macOS from
Linux.
* Add patch verification test for system-ui font spoofing
Tests macOS and Windows presets: launches Camoufox with a fingerprint,
measures canvas text width with unquoted system-ui, asserts it matches
the expected system font (Helvetica / Segoe UI).
* Rename test to match patch naming convention
tests/patches/ files should mirror patch names, not use dated prefixes.
* Add config_overrides param to generate_context_fingerprint()
There was no clean way to override config values (like disabling font
spacing perturbation with fonts:spacing_seed=0) because init_script is
rendered inside generate_context_fingerprint() — by the time the caller
gets the config dict back, the init_script string is already baked.
config_overrides is applied after all config building (preset/seeds/
timezone/locale) but before init_script rendering, giving callers a
clean override point without touching the preset (which represents
real device data, not perturbation config).
The longer-term fix is separating config building from init_script
rendering so callers can modify config and re-render. config_overrides
is the minimal API addition that unblocks the use case without that
refactor.
* Rename test to match patch naming convention
When using Xvfb-backed virtual display, override Wayland env vars
(GDK_BACKEND, WAYLAND_DISPLAY, MOZ_ENABLE_WAYLAND) so Firefox/GTK
honors DISPLAY and reliably uses the X11 virtual screen.
closes#575
Without FONTCONFIG_FILE, fontconfig loads the system's /etc/fonts/fonts.conf
which includes system font directories. This means system fonts leak into the
rendering pipeline for fallback glyphs (emoji, CJK, etc.), even though the
font enumeration whitelist hides them from JavaScript. The result is
environment-dependent font metrics that differ between machines with different
system font packages installed.
Generate a runtime fontconfig at ~/.cache/camoufox/fontconfig/ that resolves
the bundled font directory absolutely (the bundled fonts.conf uses
prefix="cwd" relative paths which break under Playwright), and point
FONTCONFIG_FILE at it.
The else branch in _build_init_script() reads the system timezone via
Intl.DateTimeFormat().resolvedOptions().timeZone and stores it via
setTimezone(). When geoip resolves a different timezone (set later via
CAMOU_CONFIG/launch_options), the storage value from the init_script
takes precedence — workers read the wrong timezone and the C++ MaskConfig
fallback (PR #546) is never reached.
Fix: only call setTimezone() when an explicit timezone value is provided.
When omitted, timezone propagation is handled entirely by the C++ side
(SetNewDocument + TimezoneManager::GetTimezone MaskConfig fallback).
Companion to #546 (Fix worker timezone leak when using geoip/proxy).
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Allow callers to inject pre-resolved timezone/locale into the
fingerprint before init_script generation. When provided, these
take priority over preset data.
In launch_options(), use setdefault for geoip timezone/locale keys
so that values pre-set via generate_context_fingerprint() aren't
overwritten by geoip resolution.
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
* example files
* contributing guides
* simple service test
* run tests in sync
* update pr template
* pip updates
* Update README.md
* typo fixes
* undo pip package update lol
* upgraded service test
* undo injections
* test with proxies
* auto set timezone and proxy url
* delete checks bundle
* split up service tests
* split up build tests
* rename service tests to service tester
* Update CONTRIBUTING.md
* fix entry vs exit ip
* allow alpha versions
* fix patch issues on macos
* bidirectional patch
* Add note on experimental pip package
* feat: update timezone, geolocation, and locale spoofing patches
- timezone-spoofing.patch: per-context timezone via per-realm DateTimeInfo
- geolocation-spoofing.patch: CAMOU_CONFIG backwards compatibility for geolocation
- locale-spoofing.patch: add camoucfg LOCAL_INCLUDES
- anti-font-fingerprinting.patch: add RoverfoxStorageManager exports to moz.build
* feat: per-context audio fingerprinting and screen spoofing patches
- audio-fingerprint-manager.patch: per-context audio fingerprinting (all 6 API methods)
- screen-spoofing.patch: per-context screen dimensions with global MaskConfig fallback
- Disable webrtc-ip-spoofing.patch (will re-enable after fixing)
- Remove screen-hijacker.patch (superseded by screen-spoofing.patch)
* fix: add global MaskConfig hooks for navigator.platform, hardwareConcurrency, and timezone (#443)
Fixes issue where global CAMOU_CONFIG settings for navigator.platform,
navigator.hardwareConcurrency, and timezone were not applied in the main
window Navigator (only WorkerNavigator was patched via fingerprint-injection.patch).
* fix: run nsJSUtils::SetTimeZoneOverride() after SpiderMonkey has Initialized to prevent SIGSEGV
* Add fingerprint improvements for PR #3
- navigator-spoofing.patch: Global config fixes for platform/hardwareConcurrency/timezone
- timezone-spoofing.patch: Persistence across page navigation via SetNewDocument hook
- audio-fingerprint-manager.patch: Full 6-method coverage with self-destruct pattern
- screen-spoofing.patch: Per-context dimensions with self-destruct pattern
- webrtc-ip-spoofing.patch: Re-enabled with getStats() sanitization + comprehensive IPv6 regex
* fix: simplify userContextId to BrowsingContext + add per-context docs
* feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update.
* fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager
* fix(navigator): header line count build error
* fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error
* fix(navigator): more line count build errors
* fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager
* feat(webgl): per-context spoofing patch
* fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version
* fix(webgl): remove coupled self-destruct
* feat(canvas): per-context spoofing
* feat(font-list): per-context spoofing
* fix(font-list): use GetOwnerWindow() instead of GetOwner()
* feat(speech): per-context spoofing
* fix(speech): add /dom/base inside local_includes
* fix(speech): changed context to avoid conflicts
* feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers
* feat(timezone): add per-context timezone override to workers
* fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise
* fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height
* fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId
* fix(canvas): make canvas noise use proper format for BGRA toDataURL path
* fix(canvas): line count fixes
* docs: updated hardware per-context documentation
* Final Per-Context Hardware Fingerprint Spoofing (#9)
* feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update.
* fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager
* fix(navigator): header line count build error
* fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error
* fix(navigator): more line count build errors
* fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager
* feat(webgl): per-context spoofing patch
* fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version
* fix(webgl): remove coupled self-destruct
* feat(canvas): per-context spoofing
* feat(font-list): per-context spoofing
* fix(font-list): use GetOwnerWindow() instead of GetOwner()
* feat(speech): per-context spoofing
* fix(speech): add /dom/base inside local_includes
* fix(speech): changed context to avoid conflicts
* feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers
* feat(timezone): add per-context timezone override to workers
* fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise
* fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height
* fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId
* fix(canvas): make canvas noise use proper format for BGRA toDataURL path
* fix(canvas): line count fixes
* docs: updated hardware per-context documentation
* feat(screen): screen avail per context
* fix(font): align userContextId resolution to BrowsingContext
* fix(audio): align userContextId resolution to BrowsingContext
* Avoid macos caching (#11)
* the property to undefined before deleting
* undo webrtc undefined
* feat: userContextId added to WordCacheKey
* fix: hunk line counts for macos cache changes
* fix: add WorkerPrivate fallback in OffscreenCanvas
* fix(audio): transformation added to mSharedChannels path to ensure consistency
* fix(webgl): added WorkerPrivate to ucid
* fix(timezone): add ucid=0 fallback for worker timezone resolution
* fix(audio): move seed lookup outside window guard for all 6 hooks
* fix(canvas): add ucid=0 fallback and WorkerPrivate resolution for workers
* fix(navigator): add setNavigatorUserAgent and ucid=0 fallback and WorkerNavigator for UA spoofing fix
* fix(webgl): add ucid=0 fallback and WorkerPrivate resolution
* fix(webgl): decouple vendor/renderer self-destruct
* fix(navigator): add main-thread navigator.userAgent getter hook
* fix(navigator): add MaskConfig hook for navigator.appVersion in main window
* feat: Add Chakra Petch font for macOS to solidify detection on CreepJS
* fix(fontconfig): rename to match Go launcher, add TTC aliases and update .gitignore
* fix(navigator): oscpu missing MaskConfig global fallback
* feat: add real fingerprint presets (65 firefox profiles) - mainly to test with, more will come when tested.
* feat: use real fingerprint presets as default with BrowserForge as fallback
* feat: add audio:seed and canvas:seed to property schema and validation
* feat: add MaskConfig fallback to seed managers for cross-process worker consistency - don't need to disable fission
* fix(font): moved mUserContextId declaration before mRounding in WordCacheKey so init order matches
* fix(audio): line count correction
* fix(canvas): line count fix
* feat: add per-context fingerprinting API (NewContext/AsyncNewContext) + merge upstream
- fix seed range
- add oscpu derivation from platform, and timezone mapping in from_preset()
- new real fingerprints preset support
* feat: new presets + en-US only, stripped fonts/language, clamp DPR
* feat: random 30-78% font subset generation for NewBrowser and NewContext
* fix: add fission.autostart=true to camoufox.cfg - will be changing this soon with new update so processCount is not 1, so it will be undetectable
* fix: update macos fonts.conf rendering settings
* feat: cross-process fingerprint storage via Firefox Preferences API
Replace RoverfoxStorageManager's per-process static HashMap with Firefox's
built-in Preferences system. Values stored as CString prefs under
"roverfox.s." namespace, auto-synced to all content processes by Firefox.
Content processes can't set prefs directly (ENSURE_PARENT_PROCESS), so a
single IPDL message (RoverfoxStoragePut) routes writes through the parent.
Same public API — all 10 dependent patches require zero changes.
Removes dom.ipc.processCount=1 from camoufox.cfg. Firefox now uses
Playwright's default multi-process model (fresh process per page) with
fission enabled, while fingerprint values remain accessible everywhere.
* fix(cross-process): hunk headers and build fixes
* fix(storage): add local write-through cache to RoverfoxStorageManager
* fix(storage): add sync IPC read fallback for cross-process fingerprint propagation
* fix(storage): add NS_IsMainThread guard to sync IPC fallback - prevent crashes
* fix(storage): sync IPC + pref whitelist for cross-process fingerprint sync
* feat: full documentation update, speech voices generated per context and BrowserForge primary fingerprint generation method for global and per context.
* fix: Direct3D NVIDIA GTX 980 renderers incorrectly appearing on mac because of duplicates
* Update .gitignore
---------
Co-authored-by: PopcornDev1 <e.coiley@icloud.com>
Co-authored-by: Build <build@local>
Co-authored-by: Elliot Coiley <153072396+PopcornDev1@users.noreply.github.com>
- Removes the old data directory if Camoufox was installed before 0.5.0
- Fix messy sponsors segment & add repo status info at the top of the README
- Add camoufox/camoufox org as fallback
- Remove (experimental) next to the GeoIP by daijro source
- Format
- Rewrite `camoufox version` to show storage/path info and more python packages
- In camoufox active/set, show active channels. Fall back to original/stable if none is set
- Remove config files in `camoufox remove --all`
- Spoof the camoufox python library version in UI debug mode
- Fix scrollbar always showing on windows
- Other UI cleanup
This allow to pass to Camoufox library the executable-path
from the cli test command allowing to use a camoufox from a different
folder during development.
Example:
python -m camoufox test --executable-path="/tmp/camoufox/camoufox-bin"