mirror of
https://github.com/daijro/camoufox.git
synced 2026-10-04 16:00:21 +00:00
e425dddcfdd764957dee5e2f58d95ceedbcd257d
8
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
6daae88dbc |
Stock-Firefox parity for native identities: input, fonts, locale, WebGL, WebRTC, media, timing, launcher (#779)
* feat(humanize): replay recorded human mouse movements (Cursory) humanize=True used to walk a Bezier curve through two random knots and emit a point every 10 ms. Both halves are tells: an analytic curve sampled at a fixed rate has velocity and jerk profiles that separate cleanly from a hand's, and every movement accelerated through the same easing function. Juggler now picks one of Cursory's 2357 recorded human movements whose direction, distance and wander suit the move, morphs it onto the requested endpoints and replays it with the recording's own timing. The generator is cursory-js (a bit-exact TypeScript port of Vinyzu/cursory) vendored under additions/juggler/input/cursory/; it is LGPLv3-or-later, not MPL-2.0, and ships its LICENSE and NOTICE inside juggler.jar. MouseTrajectories.hpp and ChromeUtils.camouGetMouseTrajectory are removed. sendTrajectoryAcked takes per-step pauses, drops points on the pixel the last dispatch left the cursor on (a zero-displacement move is never acked), and the humanize guards are updated for the new path shape. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): shared helpers for binary resolution, a private Xvfb and Marionette resolve_binary() honours the runner's CAMOUFOX_EXECUTABLE_PATH before falling back to a Linux objdir (search-service-init and touchscreen-digitizer ignored it and ran the newest objdir, which after a macOS cross build is an arm64 Mach-O), hidden_display() gives a guard its own Xvfb so nothing ever opens on the user's display, and a minimal chrome-context Marionette client lets guards inspect browser UI state. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): synthesized input carries what real mouse and keyboard input carries - pointerType was "" for every Playwright mouse event: juggler dispatched with MOZ_SOURCE_UNKNOWN. It now passes MOZ_SOURCE_MOUSE (#776). - keyboard.type() never pressed Shift: a shifted character now arrives bracketed by ShiftLeft keydown/keyup (location 1) with shiftKey set. - After the pointer was parked off content, pointerover/enter re-entered with buttons=1 and pressure 0.5; the tracked position is now forgotten on park. - A Windows identity gets contextmenu after mouseup with buttons=0, as Windows does; GTK/macOS keep it on press. - Wheel events are sent as line deltas (DOMMouseScroll.detail 3 per notch instead of the pixel count). - The browser rect is measured after the APZ flush await, so a chrome height change during the wait cannot put a y==0 dispatch one row above content. - ci/run_sundial.py moves and clicks the mouse so input vectors have data. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): evaluate() no longer grants user activation Upstream Playwright runs every evaluate() as handling user input and notifies a user-gesture activation. Init scripts go through that path at load, so every page started with navigator.userActivation.hasBeenActive === true, autoplay allowed and popups permitted before any input. Activation now only comes from juggler's trusted input events, as in a stock browser. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): stop hiding scrollbars in headless The headless agent sheet set scrollbar-width: none !important, which a page reads back from getComputedStyle and from overflow:scroll gutters. Scrollbar appearance is left to the platform look-and-feel (the launcher sets ui.useOverlayScrollbars per claimed OS). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(ui): no visible automation cues in the browser window - Every Playwright context was a public container, so the URL bar showed a "JUGGLER <id>" label and a container colour. Contexts are now non-public identities (tabbrowser renders public identities only); startup cleanup still removes persisted leftovers. - showcursor defaulted to true, drawing a red dot that followed the mouse. It is now opt-in. tests/patches/visible-automation-cues.py checks both on a private Xvfb. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): web fonts, local(), per-character fallback and native bundles - FontFace / @font-face were answered from the font allowlist by the FontFace's own family name, so every url() web font failed with NS_ERROR_FAILURE and never rendered, local() of an allowed font failed, and a miss rejected with an XPCOM code instead of NetworkError (#759). Stock FontFace/FontFaceImpl are restored; local() is filtered by the RESOLVED family in gfxUserFontSet. - GlobalFontFallback forced the cmap scan, which skips families whose charmap is not loaded yet, so any character outside Gecko's script-based common-fallback table rendered as the primary family's .notdef (U+1E9E on macOS). The platform fallback chooses again, and its choice is held to the mask. - For a native macOS/Windows identity the bundled font sets are not activated: a bundled face of a family the system also has (Papyrus, Helvetica) won the lookup with different metrics. On Windows the enumerator still keeps Twemoji Mozilla, the emoji font stock Firefox ships (flag emoji drew nothing). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): CSS2 system fonts and system-ui follow the claimed OS - The host's own OS gets no system-ui override (macOS resolved system-ui to Helvetica instead of -apple-system). - CSS2 system font keywords use per-keyword faces and sizes; a Linux identity reports the Ubuntu desktop font; Windows form controls (-moz-button/field/list) answer "MS Shell Dlg 2" as Windows does, not Segoe UI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * feat(fonts): per-OS font model and fontconfig parity fonts.json is now generated from the bundle by scripts/gen-fonts-json.py (fc-scan + aliases + scan-time families, intersected with the per-OS manifest in scripts/data/font-manifests.json) so every reportable family is renderable; scripts/verify-fonts.py checks that invariant, the generics and the reject globs. font-groups.json lets the draw keep co-shipped families together. Linux fontconfig: stock metric aliases (Arial -> Liberation Sans, ...), 49-sansserif, urw-base35 and the non-Latin rule files in stock conf.d order, generics resolving like a stock Ubuntu (Noto Sans / Noto Serif / DejaVu Sans Mono / Z003), hintslight so advances are not pinned to whole pixels, and weak <prefer> lists instead of strongly-bound generic pins so lang can promote a script face. Windows fontconfig: GDI substitution aliases, MS Shell Dlg 2, cursive/fantasy generics, duplicate-face rejects and Sitka / Segoe UI Variable optical-size families. NOTE: generated against a ~3.9 GB target font bundle that is not part of this change (one file is over GitHub's 100 MB limit); see docs/FONTS.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(locale): localize browser strings with the spoofed locale; stop rewriting explicit locales - With locale="fr-FR", Intl/number/date went French but input.validationMessage and XML parse errors stayed English, a mix no real Firefox produces. Official language packs are now baked in as packaged locales (scripts/fetch-langpacks.py, scripts/inject-locales.py, called by package.py, fetched on demand) and the launcher selects the UI locale through intl.locale.requested. A langpack add-on cannot do this: the parent pre-creates those string bundles first. - locale-spoofing.patch overrode Language/Script/Region on every intl::Locale, so new Intl.DisplayNames(['en'],{type:'region'}).of('DE') returned the spoofed region's name and Intl.Locale('ja-Jpan-JP').minimize() returned the spoofed tag. Only the OS/default locale is spoofed now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): enumerate, capture and label the identity's media devices coherently The fake media engine now enumerates the identity's microphones, cameras and speakers (labels and group ids from new mediaDevices:*Labels/*Groups config keys), MediaManager uses it whenever mediaDevices:enabled, and stock exposure rules apply: before a grant one device per input kind, no outputs, no labels; after a grant OS-style labels, distinct deviceIds, shared groupIds. So enumerateDevices(), getUserMedia() tracks and getSettings() ids agree, and a claimed camera captures instead of throwing NotFoundError. Fixes the content-process crash on an identity with a camera and no microphone (InsertElementAt on an empty array). docs/MEDIA-DEVICES.md; guard tests/patches/media-devices-coherence.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(navigator): globalPrivacyControl agrees between window and workers (#760) The main-thread Navigator getter ignored the config key that WorkerNavigator::GlobalPrivacyControl honours, so a page read false in the window and true in a worker. Both read the key the same way now; the launcher also mirrors it into privacy.globalprivacycontrol.enabled so the Sec-GPC header agrees. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): apply the launch-level timezone from the first read (#773) The timezone config key was only applied lazily from a navigator getter, so Intl and Date reported the host zone until a page happened to touch navigator. It is now applied eagerly in every process (nsJSContext::EnsureStatics) and per realm when a new inner window is created, entering that window's realm rather than whichever one triggered the navigation. window.setTimezone() still takes precedence per context. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(screen): the CSS color media feature follows the spoofed colorDepth screen.colorDepth was spoofed at the WebIDL level only, so on a 10-bit panel a 24-bit identity reported 24 with (color: 10), a pair Gecko cannot produce. Gecko_MediaFeatures_GetColorDepth now resolves the depth in the same order as nsScreen::PixelDepth. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): pass live state through instead of answering it from the table getParameter answered everything from the sampled table, so state a page had just set read back wrong (lineWidth(5) read 1, VIEWPORT/SCISSOR_BOX stayed 300x150 on a 64x64 canvas), extension parameters were null (anisotropy, draw buffers), COMPRESSED_TEXTURE_FORMATS was null instead of [], and getContextAttributes() ignored the attributes requested ({antialias:false} still reported 4 samples). Identity and limits still come from the table; live state and context attributes are real. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): ICE gathering completes behind a proxy (#774) With Playwright's per-context proxy and media.peerconnection.ice.proxy_only_if_behind_proxy, ICE failed before gathering started and iceGatheringState stayed "new" forever, where stock Firefox completes with host candidates. When that happens around the fabricated candidates the new -> gathering -> complete state walk is replayed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * chore(patches): refresh window-setter-seal.patch offsets Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(windows): embed Firefox's application manifest in camoufox.exe config/rules.mk embeds <program>.manifest and browser/app only ships firefox.exe.manifest, so --with-app-name=camoufox produced an exe with no manifest. Without the Windows 10 supportedOS GUID the process and its children run as a pre-Windows-10 application and Gecko's Windows-10-gated paths switch off (MediaCapabilities.decodingInfo powerEfficient false for H.264/VP9 where stock is true). The new patch adds a byte-for-byte copy as camoufox.exe.manifest; the old rename hunk in windows-theming-bug-modified.patch is dropped. Guard: tests/patches/windows-exe-manifest.py. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock values for page-observable prefs; launcher prefs at startup Page-observable defaults that no stock Firefox has, restored: - the forced built-in dark theme (it also removed the 1 px nav-bar separator, and was applied ~1 s after startup, resizing the viewport) and ui.systemUsesDarkTheme (prefers-color-scheme disagreed with the desktop); - focus rings off, autoplay allowed, popup blocker off; - gfx.color_management.mode=0 (Playwright's test pref: ICC-tagged images were drawn unconverted, readable from a canvas pixel); - ui.use_standins_for_native_colors (non-native system colours); - GMP updates off (Widevine/OpenH264 never available); - storage.estimate() quota derived from the raw disk instead of the stock cap. The HardwareAcceleration:false enterprise policy is removed: it locked software WebRender with no hardware video decoding on every OS (guard tests/patches/hardware-acceleration-policy.py). The minimal-theme chrome.css is emptied: its ~55 px chrome made outerHeight - innerHeight impossible. Playwright's non-persistent launch writes no user.js, so launcher prefs only arrived through juggler after startup and anything Gecko reads while starting raced (on Windows the UI locale lost 3 of 4 launches). camoufox.cfg now applies the launcher's CAMOU_PREFS_1..N env chunks as default prefs at startup (guard tests/patches/startup-prefs.py). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(branding): chrome://branding assets match stock Firefox chrome://branding/content/ is content-accessible. The wordmark SVGs had different intrinsic sizes (336x48 / 172x48 vs 300x67) and document.ico, document_pdf.svg and the private-browsing about logos were missing, all measurable from a page with an <img>. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): identity draws that match real machines and stay stable Launcher-side fixes found by comparing camoufox against stock Firefox 152.0.4 on Linux, Windows 11 and macOS hosts: - DNT / GPC: BrowserForge draws doNotTrack "1" on most Firefox samples, but a stock Firefox 152 reports "unspecified" and globalPrivacyControl false; the stock defaults are used unless the caller sets them, and both are applied as prefs so the API, the worker and the DNT / Sec-GPC headers agree (#760). - Timezone and geolocation: the timezone is passed to the browser, and a configured position sets permissions.default.geo so permissions.query agrees with the auto-grant (#769, #773). - hardwareConcurrency: the reported count is the fingerprint's and the browser is pinned to that many cores (cpu_affinity.py, Linux/Windows), so worker timing agrees with it; otherwise the host count snapped into the core counts real machines ship with (never 2, Firefox's resistFingerprinting value). - Fonts: the OS base is always present in full, OS-version variants are drawn all-or-nothing, co-shipped groups stay together, Cascadia is never claimed off Windows, a native macOS/Windows identity claims only the real OS base, and gfx.font_rendering.fallback.async is off on Linux so per-character fallback does not depend on cmap-load timing. - Speech voices: a per-OS installed-voice model (voice-manifests.json) with the voiceURI formats each backend really produces (voice-uris.json); no default voice where stock has none. - WebGL: extensions a release Firefox never exposes are filtered, but OVR_multiview2 stays for Windows D3D11 renderers, which expose it. - Media devices: a seeded draw of common per-OS devices with OS-style labels. - Windows scrollbars follow the drawn Windows version (overlay on 11). - Glyph-advance perturbation (fonts:spacing_seed) defaults to off: it moved every measureText width off the value the same font gives on a real machine. - Launcher prefs are also exported as CAMOU_PREFS_1..N so camoufox.cfg applies them at startup, and the browser UI locale follows the spoofed locale. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): per-identity salt for seeded draws; core pinning under concurrency Found in review of the previous commits: - identity_seed() hashed only the UA, platform, screen size and core count. Those take a handful of values per OS, so over 500 launches the seed took 12-30 distinct values and every install drew its fonts, voices, GPU, media devices and canvas/audio noise seeds from that same short list. The seed now mixes in identity_salt(): derived from what the caller pinned the identity with (a Fingerprint, a preset dict, a config naming the UA) so relaunching that identity reproduces every draw, and random otherwise. A pinned preset now reproduces its noise seeds too; seeds the caller sets are kept. - Concurrent AsyncNewBrowser launches on one driver interleaved pin/restore: one browser inherited the other's mask and the driver could stay pinned. pin -> launch -> restore is serialized per driver. - Every pinned browser landed on cores 0..N-1; pins now take N adjacent cores from a random start. - A pinnable host with 1-3 cores reported 1, 2 or 3 (2 is the resistFingerprinting value); the table floor of 4 applies as on other hosts. - launch_options() callers that launch the browser themselves (launch_server, direct use) kept the drawn core count although nothing pins the browser; only Camoufox/AsyncCamoufox pass pin_cpu_cores=True now, everyone else reports the host's snapped count. - PLAUSIBLE_CORE_COUNTS gains 18, 22, 28 and 32, all recorded in the -v150 corpus. - The Windows voice list was drawn before the locale was resolved, so an fr-FR identity got en-US voices; it is drawn after locale/geoip now. - macOS "Alex" gets its com.apple.speech.synthesis.voice identifier. - CAMOU_PREFS env chunks are ASCII-only JSON (Windows getenv goes through the ANSI code page). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(fonts): canvas accepts CSS2 system-font keywords; local() works on macOS - GetSpoofedSystemFontForRFP's per-OS branches returned before marking the result a system font. ComputeSystemFont copies that flag into FontFamilyList::is_system_font, and without it the canvas font setter could not serialize the value: ctx.font = 'caption' (or icon, menu, message-box, small-caption, status-bar) was silently ignored and read back '10px sans-serif' where stock reads back the keyword. - CoreTextFontList::LookupLocalFont builds a CTFontEntry with no family name, and local() sources are held to the spoofed font list by the resolved family, so on macOS every local() face (Helvetica, Menlo, Arial...) failed with NetworkError, installed and allowed or not. The entry now carries the family CoreText resolved. A blocked lookup's entry is released instead of leaked. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webgl): only device limits come from the spoofed table getParameter still answered ~100 state pnames from the table, so state the page had just changed read back wrong: UNPACK_FLIP_Y_WEBGL / PREMULTIPLY_ALPHA / COLORSPACE_CONVERSION after pixelStorei, FRAGMENT_SHADER_DERIVATIVE_HINT after hint(), DRAW_BUFFERi after drawBuffers(), RED/ALPHA/DEPTH/STENCIL_BITS and IMPLEMENTATION_COLOR_READ_* for the bound framebuffer, and COMPRESSED_TEXTURE_ FORMATS after enabling an extension. UNMASKED_VENDOR/RENDERER_WEBGL came back without the extension enabled, where stock returns null with INVALID_ENUM. The table now answers only the MAX_*/ALIASED_*/SUBPIXEL_BITS limits, WebGL 2 limits on WebGL 2 contexts only, and extension limits (anisotropy, draw buffers, OVR multiview) only once that extension is enabled; everything else is the real context's answer. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(webrtc): fabricate candidates only where a real gather would have them With webrtc:ipv4/ipv6 set (every geoip launch), new RTCPeerConnection() with no iceServers produced a srflx carrying the spoofed IP, and after end-of-candidates a second host set with a different mDNS name. getStats() exposed that srflx as id 'camou-srflx' and rewrote every candidate address, including .local host names and the remote peer's candidates. A srflx is now fabricated only when the page configured an ICE server, host candidates only when none reached the page (sharing the real UDP host's port otherwise), the synthetic stats id has the shape real candidate ids have (8 hex digits, fixed per connection), and only this side's non-mDNS addresses are rewritten. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(media): honour mediaDevices:enabled=false; page fake:true behaves as stock - MaskConfig::GetBool returns std::optional<bool>, and the checks tested its presence: "mediaDevices:enabled": false still enabled the fake devices. - media.navigator.permission.fake=true was page-readable: a page's own getUserMedia({video: true, fake: true}) prompted and never resolved, where stock resolves at once with its generic fake device. The pref is off again; the identity's devices count as real hardware in the capturing checks instead (prompt, sharing indicator, post-grant labels), and a page's fake:true request gets stock's generic devices rather than the identity's. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(storage): per-context values are session state, and misses are cached - Values lived on the user pref branch, which a persistent profile writes to prefs.js: relaunching with a different timezone (or navigator values) kept reporting the previous session's in the page, iframes and workers. They now live on the default branch, which is never saved, and reads ignore user values an older build left behind. - A read of an unset key did a synchronous IPC to the parent every time, and in a launch without per-context values every read is unset: navigator.hardwareConcurrency, screen.* and (color) media queries measured ~20x slower than stock. A miss is now cached per key until a pref change or a local put clears it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(timezone): no per-realm override for the process-wide zone; cache DateTimeInfo With a launch-level timezone every new document and worker got a per-realm override of the zone the process already reported. Setting one releases all JIT code in the runtime (hot code after adding an iframe ran ~4x slower), and the realm rebuilt its DateTimeInfo on every call (getHours() ~40x slower than stock). The override is applied only when the zone differs from the one JS::SetTimeZoneOverride applied process-wide, and a realm keeps its DateTimeInfo until its override changes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): wheel scrolls in native notches; Shift leads the key it modifies - A wheel notch now reaches the page as its own 3-line event carrying one native tick (new WHEEL_EVENT_NATIVE_NOTCHES option in patches/wheel-native-ticks.patch), so wheelDelta is -120 per notch as with a physical wheel; it was -396, and a multi-notch scroll arrived as one event. Several notches are spaced a few tens of ms apart. - Auto-Shift pressed Shift 0 ms before the character's keydown and released it 0 ms after its keyup; it now leads and trails by a drawn human-scale delay, and a failing keydown no longer leaves Shift latched. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(settings): stock cookie partitioning, preconnect, popup notification; about dialog CSS - network.cookie.cookieBehavior 4 (Playwright's) -> Firefox's default 5. With 4 a cross-site iframe (captcha and anti-bot widgets are exactly that) sees document.hasStorageAccess() true and its first-party cookies and localStorage, where stock partitions them. Playwright set 4 so storageState need not carry thirdPartyCookie^ permissions. - network.http.speculative-parallel-limit 0 turned <link rel=preconnect> into a no-op, visible in Resource Timing. - privacy.popups.showBrowserMessage false: stock shows a notification bar for a blocked popup, which shrinks the viewport and fires resize. - chrome://branding/content/aboutDialog.css is page-loadable and was empty; it is the official branding's now. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(patches): stock-parity probes for the leaks found in review One launch (plus two persistent relaunches) checks page-observable invariants stock Firefox 152 holds: canvas CSS2 system-font keywords, WebGL state readback and UNMASKED_RENDERER without the extension, no srflx without ICE servers and no 'camou' stats id, getUserMedia({fake: true}), cross-site storage partitioning, wheel notches, per-read cost of (color)/hardwareConcurrency and of local Date getters under a launch timezone, and a persistent profile's timezone after relaunch (page and worker). Run against the build before these fixes it fails on every one of them. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * test(humanize): judge cadence by distinct values and spread, not a share of the gap count The page clock is clamped to 1 ms and Cursory's recorded steps mostly sit between 12 and 20 ms, so the number of distinct gap values cannot grow with the number of gaps. Requiring len(gaps) // 4 made the guard fail on visibly uneven runs whenever event delivery was steady (3 of 4 runs once the per-read sync IPC jitter was gone). A fixed 10 ms cadence yields about three values within a few ms of each other, which the new rule (>= 6 values, >= 20 ms spread) still fails. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(juggler): restore the popup, wheel and history contracts The Playwright suite went red on this branch, and five of its six shards ran out their 40-minute budget before reporting, so ~470 sync tests were never run at all. Three causes, all ours: - window.open() from page.evaluate() returned null. The popup blocker being ON (Firefox's default) and evaluate() no longer granting user activation are each defensible alone; together they block every gesture-less popup. ~35 tests, each burning 30s x 4 attempts x 2 worlds, which is what exhausted the shards. The blocker goes back to Playwright's and geckodriver's value. Reading it costs a detector a popup window the user sees, so it is not a check an anti-bot script in the page runs -- unlike navigator.userActivation.hasBeenActive, which is one property read, and which is why the activation half stays. - mouse.wheel(0, 100) delivered deltaY 114 (or 132, depending on the host's font metrics) in deltaMode 1. Quantising into native wheel notches is what a physical wheel does, but it changes the number the caller asked for, so it now rides behind humanize= with the rest of the humanized input. Default is the exact requested delta in deltaMode 0. - page.go_back() did nothing after history.pushState(). canGoBack is the BACK BUTTON's answer: under browser.navigation.requireUserInteraction it reports false when every entry behind this one was pushed without the user touching the page, which is now every entry, because evaluate() grants no activation. goBack() itself does not skip those entries and neither does history.back(), so ask canGoBackIgnoringUserInteraction, as Marionette does. Two keyboard tests are skiplisted rather than fixed: auto-Shift means typing "!" emits the Shift a US keyboard requires, and upstream asserts the character's three events with shiftKey false throughout. The character's own key/code/keyCode are unchanged; what upstream asserts is the absence of a Shift no real typist could omit. Full suite against the fixed build: 2223 passed, 6 failed -- the two keyboard tests above, and four client-certificate tests that fail only on this machine (Node/OpenSSL rejects the fixture server) and pass in CI. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): stop overriding the corpus on core counts; pinning is opt-in Two findings from auditing the sweep's fixes against one bar: a difference is a leak only if a page's JavaScript can actually read it. hardwareConcurrency 2 was excluded from PLAUSIBLE_CORE_COUNTS because "2 is what Firefox reports under resistFingerprinting". That has not been true for years: RuntimeService::ClampedHardwareConcurrency hardcodes 4, and 8 on macOS, both of which are already in the table. The exclusion protected against nothing and cost every genuinely dual-core machine -- 20% of the macOS presets in the recorded corpus, 4.2% of Linux draws. It also made the small-host tail worse: a 3-core host reported 4, which cannot be pinned, so a page measured 3 while being told 4. At 2 the pin succeeds. pin_cpu_cores now defaults to False. What it buys is defence against a page timing N parallel workers; what it costs is a browser-wide CPU cap, a per-driver launch lock, and nothing at all on macOS. Unpinned, the host's own snapped count is reported, so reported and measurable still agree -- the identity just loses one drawn value. Callers who want the draw kept can still ask for it. The WebGL sampler keeps rejecting software rasterisers, and its docstring now says so: it described the opposite of what the code does. llvmpipe as the presented GPU is a live check on a string every fingerprint script reads, which is worth ~1.5% of corpus fidelity. 251 pythonlib tests pass. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> * fix(pythonlib): keep 2 out of the core table -- an Apple M1 is never dual-core Reverts the PLAUSIBLE_CORE_COUNTS half of |
||
|
|
4132dd50a6 |
refactor(juggler): make the input-dispatch deadlock structurally unreachable
Four deadlocks shipped between 2026-04 and 2026-09 -- exact-edge coordinates (9270618), humanized trajectory points that bypassed the endpoint's guard ( |
||
|
|
0ac611c4ad |
v150 with Windows Support - Python Package Being Merged Separately (#611)
* fix v150 patches * screen related patch fixes * fix juggler issues with 150 * Update grading.py improved build tester scoring * fix windows build for v150 - scripts/_mixin.py: switch moz_target from x86_64-pc-mingw32 (no longer supported in FF150) to x86_64-pc-windows-msvc - additions/juggler/screencast/HeadlessWindowCapturer.h: typedef pid_t on XP_WIN; libwebrtc headers (video_capture.h, desktop_capturer.h) reference pid_t which is POSIX-only - patches/anti-font-fingerprinting.patch: include mozilla/dom/Document.h in gfxTextRun.cpp; on Windows it is not transitively included so doc->GetInnerWindow() failed with "incomplete type 'Document'" Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * make service test use local binary * updated ff fingerprint versions * Update README.md --------- Co-authored-by: Ubuntu <ubuntu@ip-172-31-15-96.us-east-2.compute.internal> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
c6a6c20670 |
Camoufox 2.0: Hardware Spoofing + Python Package Updates (#519)
* feat: update timezone, geolocation, and locale spoofing patches - timezone-spoofing.patch: per-context timezone via per-realm DateTimeInfo - geolocation-spoofing.patch: CAMOU_CONFIG backwards compatibility for geolocation - locale-spoofing.patch: add camoucfg LOCAL_INCLUDES - anti-font-fingerprinting.patch: add RoverfoxStorageManager exports to moz.build * feat: per-context audio fingerprinting and screen spoofing patches - audio-fingerprint-manager.patch: per-context audio fingerprinting (all 6 API methods) - screen-spoofing.patch: per-context screen dimensions with global MaskConfig fallback - Disable webrtc-ip-spoofing.patch (will re-enable after fixing) - Remove screen-hijacker.patch (superseded by screen-spoofing.patch) * fix: add global MaskConfig hooks for navigator.platform, hardwareConcurrency, and timezone (#443) Fixes issue where global CAMOU_CONFIG settings for navigator.platform, navigator.hardwareConcurrency, and timezone were not applied in the main window Navigator (only WorkerNavigator was patched via fingerprint-injection.patch). * fix: run nsJSUtils::SetTimeZoneOverride() after SpiderMonkey has Initialized to prevent SIGSEGV * Add fingerprint improvements for PR #3 - navigator-spoofing.patch: Global config fixes for platform/hardwareConcurrency/timezone - timezone-spoofing.patch: Persistence across page navigation via SetNewDocument hook - audio-fingerprint-manager.patch: Full 6-method coverage with self-destruct pattern - screen-spoofing.patch: Per-context dimensions with self-destruct pattern - webrtc-ip-spoofing.patch: Re-enabled with getStats() sanitization + comprehensive IPv6 regex * fix: simplify userContextId to BrowsingContext + add per-context docs * feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update. * fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager * fix(navigator): header line count build error * fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error * fix(navigator): more line count build errors * fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager * feat(webgl): per-context spoofing patch * fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version * fix(webgl): remove coupled self-destruct * feat(canvas): per-context spoofing * feat(font-list): per-context spoofing * fix(font-list): use GetOwnerWindow() instead of GetOwner() * feat(speech): per-context spoofing * fix(speech): add /dom/base inside local_includes * fix(speech): changed context to avoid conflicts * feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers * feat(timezone): add per-context timezone override to workers * fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise * fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height * fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId * fix(canvas): make canvas noise use proper format for BGRA toDataURL path * fix(canvas): line count fixes * docs: updated hardware per-context documentation * Final Per-Context Hardware Fingerprint Spoofing (#9) * feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update. * fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager * fix(navigator): header line count build error * fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error * fix(navigator): more line count build errors * fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager * feat(webgl): per-context spoofing patch * fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version * fix(webgl): remove coupled self-destruct * feat(canvas): per-context spoofing * feat(font-list): per-context spoofing * fix(font-list): use GetOwnerWindow() instead of GetOwner() * feat(speech): per-context spoofing * fix(speech): add /dom/base inside local_includes * fix(speech): changed context to avoid conflicts * feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers * feat(timezone): add per-context timezone override to workers * fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise * fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height * fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId * fix(canvas): make canvas noise use proper format for BGRA toDataURL path * fix(canvas): line count fixes * docs: updated hardware per-context documentation * feat(screen): screen avail per context * fix(font): align userContextId resolution to BrowsingContext * fix(audio): align userContextId resolution to BrowsingContext * Avoid macos caching (#11) * the property to undefined before deleting * undo webrtc undefined * feat: userContextId added to WordCacheKey * fix: hunk line counts for macos cache changes * fix: add WorkerPrivate fallback in OffscreenCanvas * fix(audio): transformation added to mSharedChannels path to ensure consistency * fix(webgl): added WorkerPrivate to ucid * fix(timezone): add ucid=0 fallback for worker timezone resolution * fix(audio): move seed lookup outside window guard for all 6 hooks * fix(canvas): add ucid=0 fallback and WorkerPrivate resolution for workers * fix(navigator): add setNavigatorUserAgent and ucid=0 fallback and WorkerNavigator for UA spoofing fix * fix(webgl): add ucid=0 fallback and WorkerPrivate resolution * fix(webgl): decouple vendor/renderer self-destruct * fix(navigator): add main-thread navigator.userAgent getter hook * fix(navigator): add MaskConfig hook for navigator.appVersion in main window * feat: Add Chakra Petch font for macOS to solidify detection on CreepJS * fix(fontconfig): rename to match Go launcher, add TTC aliases and update .gitignore * fix(navigator): oscpu missing MaskConfig global fallback * feat: add real fingerprint presets (65 firefox profiles) - mainly to test with, more will come when tested. * feat: use real fingerprint presets as default with BrowserForge as fallback * feat: add audio:seed and canvas:seed to property schema and validation * feat: add MaskConfig fallback to seed managers for cross-process worker consistency - don't need to disable fission * fix(font): moved mUserContextId declaration before mRounding in WordCacheKey so init order matches * fix(audio): line count correction * fix(canvas): line count fix * feat: add per-context fingerprinting API (NewContext/AsyncNewContext) + merge upstream - fix seed range - add oscpu derivation from platform, and timezone mapping in from_preset() - new real fingerprints preset support * feat: new presets + en-US only, stripped fonts/language, clamp DPR * feat: random 30-78% font subset generation for NewBrowser and NewContext * fix: add fission.autostart=true to camoufox.cfg - will be changing this soon with new update so processCount is not 1, so it will be undetectable * fix: update macos fonts.conf rendering settings * feat: cross-process fingerprint storage via Firefox Preferences API Replace RoverfoxStorageManager's per-process static HashMap with Firefox's built-in Preferences system. Values stored as CString prefs under "roverfox.s." namespace, auto-synced to all content processes by Firefox. Content processes can't set prefs directly (ENSURE_PARENT_PROCESS), so a single IPDL message (RoverfoxStoragePut) routes writes through the parent. Same public API — all 10 dependent patches require zero changes. Removes dom.ipc.processCount=1 from camoufox.cfg. Firefox now uses Playwright's default multi-process model (fresh process per page) with fission enabled, while fingerprint values remain accessible everywhere. * fix(cross-process): hunk headers and build fixes * fix(storage): add local write-through cache to RoverfoxStorageManager * fix(storage): add sync IPC read fallback for cross-process fingerprint propagation * fix(storage): add NS_IsMainThread guard to sync IPC fallback - prevent crashes * fix(storage): sync IPC + pref whitelist for cross-process fingerprint sync * feat: full documentation update, speech voices generated per context and BrowserForge primary fingerprint generation method for global and per context. * fix: Direct3D NVIDIA GTX 980 renderers incorrectly appearing on mac because of duplicates * Update .gitignore --------- Co-authored-by: PopcornDev1 <e.coiley@icloud.com> Co-authored-by: Build <build@local> Co-authored-by: Elliot Coiley <153072396+PopcornDev1@users.noreply.github.com> |
||
|
|
76c30acc4c |
Timezone, geolocation, font, locale and more spoofing (#504)
* feat: update timezone, geolocation, and locale spoofing patches - timezone-spoofing.patch: per-context timezone via per-realm DateTimeInfo - geolocation-spoofing.patch: CAMOU_CONFIG backwards compatibility for geolocation - locale-spoofing.patch: add camoucfg LOCAL_INCLUDES - anti-font-fingerprinting.patch: add RoverfoxStorageManager exports to moz.build * feat: per-context audio fingerprinting and screen spoofing patches - audio-fingerprint-manager.patch: per-context audio fingerprinting (all 6 API methods) - screen-spoofing.patch: per-context screen dimensions with global MaskConfig fallback - Disable webrtc-ip-spoofing.patch (will re-enable after fixing) - Remove screen-hijacker.patch (superseded by screen-spoofing.patch) * fix: add global MaskConfig hooks for navigator.platform, hardwareConcurrency, and timezone (#443) Fixes issue where global CAMOU_CONFIG settings for navigator.platform, navigator.hardwareConcurrency, and timezone were not applied in the main window Navigator (only WorkerNavigator was patched via fingerprint-injection.patch). * fix: run nsJSUtils::SetTimeZoneOverride() after SpiderMonkey has Initialized to prevent SIGSEGV * Add fingerprint improvements for PR #3 - navigator-spoofing.patch: Global config fixes for platform/hardwareConcurrency/timezone - timezone-spoofing.patch: Persistence across page navigation via SetNewDocument hook - audio-fingerprint-manager.patch: Full 6-method coverage with self-destruct pattern - screen-spoofing.patch: Per-context dimensions with self-destruct pattern - webrtc-ip-spoofing.patch: Re-enabled with getStats() sanitization + comprehensive IPv6 regex * fix: simplify userContextId to BrowsingContext + add per-context docs * Final Per-Context Hardware Fingerprint Spoofing (#9) * feat(navigator): Add per-context spoofing (platform, oscpu, hardwareConcurrency) with global fallback + docs update. * fix(navigator): use 2-arg GetUint(key, value) for RoverfoxStorageManager * fix(navigator): header line count build error * fix(navigator): move NavigatorManager.cpp into SOURCES for leakage error * fix(navigator): more line count build errors * fix(navigator): include nsTHashMap and nsHashKeys.h before RoverfoxStorageManager * feat(webgl): per-context spoofing patch * fix(webgl): changed GetCanvasElement() to mCanvasElement() for firefox version * fix(webgl): remove coupled self-destruct * feat(canvas): per-context spoofing * feat(font-list): per-context spoofing * fix(font-list): use GetOwnerWindow() instead of GetOwner() * feat(speech): per-context spoofing * fix(speech): add /dom/base inside local_includes * fix(speech): changed context to avoid conflicts * feat(navigator): add WorkerNavigator hooks for per-context platform and hardwareConcurrency in workers * feat(timezone): add per-context timezone override to workers * fix(canvas): add OffscreenCanvas userContextId support and skip zero pixels in canvas noise * fix(screen): hook nsMediaFeatures GetDeviceSize for per-context matchMedia device-width/height * fix(webgl): add OffscreenCanvas userContextId fallback in WebGL GetUserContextId * fix(canvas): make canvas noise use proper format for BGRA toDataURL path * fix(canvas): line count fixes * docs: updated hardware per-context documentation * Avoid macos caching (#11) * the property to undefined before deleting * undo webrtc undefined --------- Co-authored-by: PopcornDev1 <e.coiley@icloud.com> Co-authored-by: Build <build@local> Co-authored-by: Elliot Coiley <153072396+PopcornDev1@users.noreply.github.com> |
||
|
|
11e02fdfea |
beta testing guide (#444)
* beta install guide * Update README.md |
||
|
|
03c12302b0 |
fix: migrate Juggler modules from JSM to ESM for Firefox 146 compatibility
- Converted ChannelEventSink from JSM to ESM (.sys.mjs) - Changed ChromeUtils.import() to ChromeUtils.importESModule() across all modules - Updated .jsm file extensions to .sys.mjs for system module imports - Replaced EXPORTED_SYMBOLS with export keyword in Helper.js, NetworkObserver.js, SimpleChannel.js, TargetRegistry.js, and JugglerFrameParent.jsm - Updated EventEmitter import from resource://gre/modules/EventEmitter.jsm to . |
||
|
|
a1b7e4c033 |
docs: add comprehensive patch upgrading guide for LLMs
- Created patch-upgrading-guide.md with step-by-step instructions for updating patches across Firefox versions - Covers understanding patch system, preparation, general workflow, and common reject types - Includes historical context patch merging section (no longer applicable after Firefox 146) - Documents testing, validation, best practices, and complete example session - Provides troubleshooting section for common issues and API changes - Details |