Files
Jake WriterandClaude Opus 5.5 ec37d722b7 Update to Firefox 156.0.1 (#806)
* Pin Firefox 156.0.1

Camoufox beta.32 is built on Firefox 156.0.1 (was 152.0.4).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port playwright patch to Firefox 156

- nsGeolocationService became mozilla::GeolocationService in
  toolkit/components/geolocation/GeolocationService.{h,cpp}; the override
  (Init(isOverride), IsOverride, the UpdateAccuracy early return) moves there.
- OnLinkClick now dispatches through OnLinkClickWithLoadState, so the
  juggler-link-click notification is sent just before that call.
- nsWindowWatcher::CalculateChromeFlagsForContent was restructured around
  ShouldOpenPopup; the explicit-size flag is added on the popup branch.
- JUGGLER_WINDOW_EXPLICIT_SIZE was 1<<22, which Firefox 156 assigns to
  CHROME_DOCUMENT_PIP. The hunk applied cleanly and would have flagged every
  sized popup as a document PiP window; it moves to the free bit 1<<26, as
  upstream Playwright did.
- EnterprisePolicies _chooseProvider became _buildProvider and the remote
  settings getter shouldSkipRemoteActivityDueToTests became
  shouldSkipRemoteActivity.
- Port upstream's WorkerScriptLoader fix (microsoft/playwright#42565): from
  Firefox 153 a reload while a large worker script is still compiling crashes
  the content process (Bugzilla 2044428).
- Drop the GetAcceptLanguages argument swap. Firefox 156 adds callers that use
  the native signature (worker language override), and the swap changed no
  behaviour: every caller passes null for an empty override.
- The HeadlessCompositorWidget and nsFilePicker include hunks are rebased; the
  file picker already includes gfxPlatform.h.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port playwright leak fixes to Firefox 156

Navigator::Webdriver() now asks Marionette and the remote agent for
GetIsBrowserAutomationRunning; the body is still replaced with 'return false'.
The policy provider hunk applied cleanly but restored _chooseProvider(), which
Firefox 156 renamed to _buildProvider() -- policy loading would have thrown.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* juggler: follow Firefox 156 API changes

- Firefox 156 enforces dom.jsipc.check_safeForUntrustedWebProcess: a
  JSWindowActor without safeForUntrustedWebProcess is never instantiated in a
  web content process, so JugglerFrame would not load in any page.
- ContextualIdentityService moved to a moz-src:/// URL.
- Debugger.onPromiseSettled was removed (bug 2044167). Pending promises are
  settled the way upstream Juggler does now: reactions in the debuggee hit a
  debugger statement, and onDebuggerStatement sweeps the pending set.
  Without this every evaluate returning a pending promise never resolves.
- The worker debugger manager is a singleton service; createInstance now
  fails in the content process, so FrameTree uses getService like upstream.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port anti-font-fingerprinting to Firefox 156

gfxTextRun.cpp's include block was re-sorted, and nsPIDOMWindow.h no longer
pulls in nsPIDOMWindowInlines.h, so the per-context font group lookup needs it
explicitly to link. A whitespace-only hunk that no longer applied is dropped.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port contentaccessible-parity to Firefox 156

Firefox 156 moved DevelopmentHelpers.init() out of browser-init.js into a
browser-window-delayed-startup category entry in BrowserComponents.manifest,
so that entry goes with the file. The stock file-set manifest is re-recorded
from the official Firefox 156.0.1 linux-x86_64 build (sha256 7405c048...);
the guard refuses to compare across versions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port cross-process-storage to Firefox 156

RecvCreateGMPService's tail changed; the Roverfox storage IPC handlers are
added after it unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port librewolf dbus_name to Firefox 156

The D-Bus fallback bus and object path names moved; the same strings are
renamed at their new locations.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port debugger-invisible-to-content to Firefox 156

Firefox 156 removed asm.js compilation and with it Debugger
allowUnobservedAsmJS and the DebuggerObservesAsmJS realm bit. The wasm side
is unchanged, so invisibleToContent now keeps wasm unobserved, and the realm
flag moves down to the freed bit. The set of content-observable isDebuggee()
checks is the same as in 152 (Promise, async stack capture, throw stacks).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port fingerprint-injection to Firefox 156

nsGlobalWindowInner::GetInnerWidth/GetInnerHeight gained a CallerType
parameter; the MaskConfig override is applied at the top of the new
signatures.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port librewolf firefox-view to Firefox 156

Firefox 156 already made firefox-view-button a CustomizableWidget that is not
in the default tab strip, and removes it from existing profiles. What still
applies is dropping the old version-18 migration that would re-add it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port font-hijacker to Firefox 156

Include blocks were re-sorted. LookupLocalFont now returns
already_AddRefed<gfxFontEntry> and the user font set holds a RefPtr, so the
macOS family-name fix builds the entry with MakeRefPtr and the local() mask
check just drops the RefPtr.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port librewolf hide-default-browser to Firefox 156

The isDefaultPane/isNotDefaultPane visibility conditions gained policy and
lock checks; both are still forced false.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port media-codec-spoofing to Firefox 156

MatroskaDecoder now asks PDMFactorySupport::IsSupported instead of a
PDMFactory instance; the media:spoof_codecs bypass sits before that loop as
before.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port network-patches to Firefox 156

nsHttpHandler.cpp's includes were re-sorted.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port screen-spoofing to Firefox 156

nsDeviceContext.cpp's includes were re-sorted, and ScreenDimensionManager.cpp
includes nsPIDOMWindowInlines.h, which nsPIDOMWindow.h no longer pulls in.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port sessionstore-popup-close-crash to Firefox 156

SessionStore moved to a class with private #windows, and
maybeDontRestoreTabs is now a method; the untracked-window guard is the same.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port trusted-automation-events to Firefox 156

HTMLSelectElement::HandleMouseDown now opens the picker through
TogglePickerInternal, which also handles the in-content base-select popover
(where the release stays in content and pointerup does fire).
TogglePickerInternal now reports whether it opened the parent-process
dropdown, and only then is the following pointerup suppressed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* include nsPIDOMWindowInlines.h in the per-context managers

Firefox 156 stopped including nsPIDOMWindowInlines.h from nsPIDOMWindow.h, so
the managers' IsFunctionEnabledForWebIDL checks, which call
nsPIDOMWindowInner::GetBrowsingContext(), no longer link. Each manager now
includes it itself; the rest of these patches applied unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port webrtc-ip-spoofing to Firefox 156

- The getStats() resolve lambda changed (MakeRefPtr report); the IP
  sanitisation is rebased onto it.
- RTCIceCandidateStats.transportId is now a required member, and Firefox 156
  exposes foundation and usernameFragment on candidate stats to content. The
  fabricated srflx entry now carries the same foundation (1) and ufrag as its
  SDP line, so it is not the only local candidate without them.
- WebRTCIPManager.cpp includes nsPIDOMWindowInlines.h (see the managers).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* port windows-theming-bug-modified to Firefox 156

Firefox 156 removed the macOS repackage recipe from browser/app/Makefile.in;
the bundle is declared with MacOSBundle() in browser/app/moz.build and every
extra file becomes a make prerequisite. The optional Assets.car copy is ported
to where those prerequisites are generated, still for that one file only.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* package.py: name Firefox 156's gfxtest probe

Firefox 156 replaced the glxtest and vaapitest helpers with a single gfxtest
program. The packaging list never named any of them, so gfxtest ships; the
comment explaining why now names the probe that exists.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* playwright: announce form-submit navigations on Firefox 156

Firefox 153 made form submission asynchronous (dom.forms.submit_async_navigation,
on by default): nsDocShell::OnFormSubmit plans the navigation instead of
going through OnLinkClick, so Juggler never heard juggler-link-click for a
form and click() returned before the submit's request existed. Upstream
Playwright notifies from OnFormSubmit for the same reason; this ports that
hunk. Caught by test_should_parse_the_data_if_content_type_is_form_urlencoded.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* gfx-probes guard: check for Firefox 156's gfxtest probe

Firefox 156 folded the glxtest and vaapitest helper programs into a single
gfxtest binary that runs both probes as modes. The guard still requires the
probe to ship beside the binary, still requires the packaging list not to
drop it, and still requires a bare launch to get a WebGL context; only the
file name it looks for follows the rename.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Gate-Change: Firefox 156 replaced the glxtest and vaapitest programs with one gfxtest (toolkit/xre/gfxtest/moz.build Program("gfxtest"), widget/gtk/GfxInfo.cpp GFX_PROBE_BINARY u"gfxtest"); the official 156.0.1 linux-x86_64 tarball ships gfxtest and neither old name.

* juggler: let grantPermissions cover Firefox 156's local network access

Firefox 156 enables Local Network Access blocking in release builds
(network.lna.blocking), gated by the new local-network and loopback-network
permissions. Playwright 1.62 maps its local-network-access permission to
those two names, but Juggler only applies what is listed in ALL_PERMISSIONS,
so the grant was silently dropped and a public page reaching localhost stayed
parked on a prompt no one can answer. Upstream Juggler lists them too.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* run_sundial: exempt sundial's origin from Firefox 156's local network access

Sundial posts its score from its public origin to the harness's collector on
127.0.0.1. Firefox 156 turns Local Network Access blocking on in release
builds, so that POST now waits for a permission prompt no one can answer and
the job times out with nothing measured (CI round 1). The browser is right to
block it -- stock 156 does the same -- so the harness exempts only sundial's
host with Firefox's own network.lna.skip-domains pref. That leaves the
Permissions API reading the stock 'prompt' for the page, unlike a
local-network-access grant, which would also mark geolocation and
notifications denied for the origin. Nothing the job measures or asserts
changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Gate-Change: Firefox 156 made network.lna.blocking true in release builds (modules/libpref/init/StaticPrefList.yaml; @IS_NIGHTLY_BUILD@ in 152.0.4), so a public page's POST to the 127.0.0.1 collector is held for an LNA prompt; reproduced locally (156: collector gets nothing, 152.0.4: delivered; with skip-domains for the page's host: delivered, permission state still 'prompt').

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-28 20:14:47 +00:00
..
2026-09-28 20:14:47 +00:00
2026-04-25 23:47:31 -04:00
2026-09-28 20:14:47 +00:00