head 1.3; access; symbols pkgsrc-2026Q2:1.2.0.8 pkgsrc-2026Q2-base:1.2 pkgsrc-2026Q1:1.2.0.6 pkgsrc-2026Q1-base:1.2 pkgsrc-2025Q4:1.2.0.4 pkgsrc-2025Q4-base:1.2 pkgsrc-2025Q3:1.2.0.2 pkgsrc-2025Q3-base:1.2 pkgsrc-2025Q2:1.1.0.8 pkgsrc-2025Q2-base:1.1 pkgsrc-2025Q1:1.1.0.6 pkgsrc-2025Q1-base:1.1 pkgsrc-2024Q4:1.1.0.4 pkgsrc-2024Q4-base:1.1 pkgsrc-2024Q3:1.1.0.2 pkgsrc-2024Q3-base:1.1; locks; strict; comment @# @; 1.3 date 2026.07.21.15.25.01; author ryoon; state Exp; branches; next 1.2; commitid r3OwyFwcwqkSbxOG; 1.2 date 2025.07.15.13.58.05; author ryoon; state Exp; branches; next 1.1; commitid BoegzikoNpQtDQ2G; 1.1 date 2024.08.12.14.03.32; author ryoon; state Exp; branches; next ; commitid 0HnQweQUmvFYuxlF; desc @@ 1.3 log @www/firefox: Update to 153.0 Cnangelog: 153.0: New * High Dynamic Range (HDR) video playback is now available on Windows - this feature needs HDR mode enabled for the display in Windows Settings - Display. Laptop displays that only offer "HDR video streaming" are not supported at this time. Some videos recorded on phones in certain orientations are currently not shown as HDR. * Containers let you keep separate parts of your online life (work, shopping, personal, banking) logged into different accounts in the same browser window, but keep your cookies and ad tracking isolated inside each container. * Share any open page with a QR code. Right-click a tab, select Share > Generate QR Code. Great for posters, invitations, banners, and other printed materials. * It is now possible to merge multiple PDFs by dragging a PDF into the PDF sidebar. * It is now possible to add images as new pages within PDFs using the Firefox PDF editor. * Quickly pick and copy a color from any page by typing "pick color", "color picker", or "eyedropper" in the address bar and selecting the "Pick a color" quick action. * Added support for Apple's system-wide full-screen keyboard command (Globe-F). * Firefox now verifies and displays Qualified Website Authentication Certificates (QWACs) in accordance with eIDAS regulations. * Added improved support for videos with overlays so users can more easily access video actions from context menus. * Firefox now highlights the location permission icon in red whenever a website has access to your location. The permission icon is also now visible on search results pages where it was previously hidden. Screenshot of the red geolocation warning in the address bar when the Geolocation API is being used * Smart Window: + See and choose AI models directly from the Smart Window assistant. + New Tab now includes a familiar address bar for typing websites and searching the web. Firefox Labs * Firefox Labs can now be opened quickly by typing "labs" or "experiment" in the address bar and selecting the Open Firefox Labs quick action. * Firefox now offers experimental support for the new JPEG XL image format, which generally provides better compression than WebP, JPEG, PNG, and GIF and is designed to supersede them. You can enable it from the Firefox Labs panel in Settings. Fixed * Various security fixes. Changed * Extensions can no longer access local files by default. Users can grant or revoke this access via the new "Access local files on your computer" permission, separate from "Access your data for all websites". * Local Network Access restrictions are now enabled by default for all users. Firefox requires websites to request permission before connecting to devices on your local network or to apps and services on your device. * Outdated cookie settings have been removed from the Settings UI. Users still in that mode should switch to default behavior "Isolate cross-site cookies". More information Security fixes: Mozilla Foundation Security Advisory 2026-68 #CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component #CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component #CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component #CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component #CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component #CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component #CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component #CVE-2026-16365: Privilege escalation in the DOM: Workers component #CVE-2026-16366: Privilege escalation in the DOM: Navigation component #CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component #CVE-2026-16354: Information disclosure in the Graphics: ImageLib component #CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component #CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component #CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component #CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component #CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component #CVE-2026-16357: Incorrect boundary conditions in the Graphics component #CVE-2026-16370: Mitigation bypass in the DOM: Networking component #CVE-2026-16371: Privilege escalation in the DOM: Navigation component #CVE-2026-16372: Privilege escalation in the DOM: Content Processes component #CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android #CVE-2026-16374: Information disclosure in the Framework component in DevTools #CVE-2026-16375: Site isolation issue in the Networking: HTTP component #CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component #CVE-2026-16377: Mitigation bypass in the PDF Viewer component #CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component #CVE-2026-16379: Privilege escalation in the DOM: Content Processes component #CVE-2026-16358: Site isolation issue in the Graphics: WebRender component #CVE-2026-16380: Mitigation bypass in the Networking component #CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component #CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component #CVE-2026-16383: Mitigation bypass in the DOM: Networking component #CVE-2026-16384: Information disclosure due to uninitialized memory in the #CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component #CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component #CVE-2026-16387: Site isolation issue in the Networking component #CVE-2026-16388: Sandbox escape in the DOM: Networking component #CVE-2026-16389: Incorrect boundary conditions, integer overflow in the #CVE-2026-16390: Mitigation bypass in the Enterprise Policies component #CVE-2026-16391: Information disclosure in the Storage: IndexedDB component #CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component #CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU #CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP #CVE-2026-16394: Mitigation bypass in the DOM: Security component #CVE-2026-16395: Integer overflow in the Audio/Video component #CVE-2026-16396: Privilege escalation in WebExtensions #CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox #CVE-2026-16398: Site isolation issue in the Graphics component #CVE-2026-16399: Site isolation issue in the DOM: Navigation component #CVE-2026-16400: Information disclosure in the DOM: Security component #CVE-2026-16401: Privilege escalation in the Data Loss Prevention component #CVE-2026-16402: Integer overflow in the Graphics: ImageLib component #CVE-2026-16403: Spoofing issue in the Address Bar component #CVE-2026-16404: Spoofing issue in Firefox for Android #CVE-2026-16405: Information disclosure in the Networking: WebSockets component #CVE-2026-16406: Mitigation bypass in the Networking component #CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component #CVE-2026-16408: Integer overflow in the Audio/Video: Playback component #CVE-2026-16409: Invalid pointer in the Security: PSM component #CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component #CVE-2026-16411: Memory safety bugs fixed in Firefox 153 #CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 #CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 @ text @$NetBSD: patch-third__party_sqlite3_ext_moz.build,v 1.2 2025/07/15 13:58:05 ryoon Exp $ --- third_party/sqlite3/ext/moz.build.orig 2026-07-13 13:09:31.000000000 +0000 +++ third_party/sqlite3/ext/moz.build @@@@ -30,7 +30,7 @@@@ DEFINES["SQLITE_VEC_ENABLE_DISKANN"] = 0 # In this release we're not using DISKANN so remove to save space DEFINES["SQLITE_VEC_ENABLE_DISKANN"] = 0 -if CONFIG["OS_TARGET"] == "Linux" or CONFIG["OS_TARGET"] == "Android": +if CONFIG["OS_TARGET"] == "Linux" or CONFIG["OS_TARGET"] == "Android" or CONFIG["OS_TARGET"] == "FreeBSD" or CONFIG["OS_TARGET"] == "NetBSD" or CONFIG["OS_TARGET"] == "OpenBSD": OS_LIBS += [ "m", ] @ 1.2 log @www/firefox: Update to 139.0.4 * Try to add some NetBSD-specific changes (incompleted). Changelog: 139.0.4: Fixed * Fixed Firefox freezing when switching between apps or opening certain panels within the browser. (Bug 1969253 & Bug 1969346) * Fixed difficult selection of drop-down menu options in the Firefox preferences page when selected via the in-page search. (Bug 1968949) * Fixed various selection issues when triple-clicking text in some situations. (Bug 1969100 & Bug 1969432) * Fixed an incorrect filename being used when setting an image as the desktop wallpaper on Windows. (Bug 1969793) * Various security fixes. Security fixes: Mozilla Foundation Security Advisory 2025-47 #CVE-2025-49709: Memory corruption in canvas surfaces #CVE-2025-49710: Integer overflow in OrderedHashTable 139.0.1: Fixed * Fixed graphics corruption with certain NVIDIA graphics adapters and multiple monitors running at mixed refresh rates after updating to Firefox 139. (Bug 1968876) 139.0: New * By popular request, Full-Page Translations are now available within Firefox extension pages that start with the moz-extension:// URL scheme. * The New Tab custom wallpaper (and colors) option is now available! Your own image can be uploaded as your New Tab wallpaper or any custom color can be selected - from the brightest pink to dark gray. This feature will be rolling out gradually to new users and can also be enabled immediately via Firefox Labs. Additionally, new Wallpaper images and a new Celestial category have also been added. * Link Previews is currently available as an experimental feature which can be enabled via Firefox Labs in the Firefox settings. After enabling, use the Alt+Shift keyboard shortcut when hovering over a link to see the previews in action! * Address autofill has now been enabled for users in Australia and India. Fixed * PNG images with transparency now keep their transparency when pasted into Firefox. * The upload performance of HTTP/3 has been significantly improved, particularly on resumed connections (QUIC 0-RTT) and high-bandwidth and high-delay connections. * Various security fixes. Changed * Due to recent changes in how Chrome encrypts user data on Windows, the Firefox migration wizard can no longer directly import payment methods or passwords from Chrome. However, users can still export passwords from Chrome to a CSV file and then import them into Firefox using the migration wizard or the password manager. * The Review Checker feature is shutting down and will no longer be available after June 10, 2025. Mozilla Foundation Security Advisory 2025-42 #CVE-2025-5283: Double-free in libvpx encoder #CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content #CVE-2025-5264: Potential local code execution in “Copy as cURL” command #CVE-2025-5265: Potential local code execution in “Copy as cURL” command #CVE-2025-5266: Script element events leaked cross-origin resource status #CVE-2025-5271: Devtools' preview ignored CSP headers #CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details #CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 #CVE-2025-5272: Memory safety bugs fixed in Firefox 139 and Thunderbird 139 @ text @d1 1 a1 1 $NetBSD: patch-third__party_sqlite3_ext_moz.build,v 1.1 2024/08/12 14:03:32 ryoon Exp $ d3 1 a3 1 --- third_party/sqlite3/ext/moz.build.orig 2025-05-20 17:57:17.576392093 +0000 d5 3 a7 3 @@@@ -21,7 +21,7 @@@@ SOURCES += [ "sqlite-vec/sqlite-vec.c", ] @ 1.1 log @www/firefox: Update to 129.0 Changelog: 129.0: New * Reader View now has an enhanced Text and Layout menu with new options for character spacing, word spacing, and text alignment. These changes offer a more accessible reading experience. * Reader View now has a Theme menu with additional Contrast and Gray options. You can also select custom colors for text, background, and links from the Custom tab. * A tab preview is now displayed when hovering the mouse over background tabs, making it easier to locate the desired tab without needing to switch tabs. This feature is part of a progressive roll out. * HTTPS is replacing HTTP as the default protocol in the address bar on non-local sites. If a site is not available via HTTPS, Firefox will fall back to HTTP. * HTTPS DNS records can now be resolved with the operating system's DNS resolver on specific platforms (Windows 11, Linux, Android 10+). Previously this required DNS over HTTPS to be enabled. This capability allows the use of HTTP/3 without needing to use the Alt-Svc header, upgrades requests to HTTPS when the DNS record is present, and enables wider use of ECH. * Added support for multiple languages in the same document spoken in macOS VoiceOver. * Address Autofill is now enabled for users in France and Germany. Fixed * Various security fixes. # Enterprise * You can find information about policy updates and enterprise specific bug fixes in the Firefox for Enterprise 129 Release Notes. Security fixes: Mozilla Foundation Security Advisory 2024-33 #CVE-2024-7518: Fullscreen notification dialog can be obscured by document content #CVE-2024-7519: Out of bounds memory access in graphics shared memory handling #CVE-2024-7520: Type confusion in WebAssembly #CVE-2024-7521: Incomplete WebAssembly exception handing #CVE-2024-7522: Out of bounds read in editor component #CVE-2024-7523: Document content could partially obscure security prompts #CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims #CVE-2024-7525: Missing permission check when creating a StreamFilter #CVE-2024-7526: Uninitialized memory used by WebGL #CVE-2024-7527: Use-after-free in JavaScript garbage collection #CVE-2024-7528: Use-after-free in IndexedDB #CVE-2024-7529: Document content could partially obscure security prompts #CVE-2024-7530: Use-after-free in JavaScript code coverage collection #CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel Sandy Bridge machines @ text @d1 1 a1 1 $NetBSD$ d3 1 a3 1 --- third_party/sqlite3/ext/moz.build.orig 2024-08-06 01:06:04.545236415 +0000 d5 2 a6 2 @@@@ -20,7 +20,7 @@@@ SOURCES += [ "fts5.c", @