[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-commits] [Git][tpo/applications/tor-browser][tor-browser-153.3.0esr-16.0-1] 2 commits: fixup! TB 40562: Added Tor Browser preferences to 000-tor-browser.js



Title: GitLab

Pier Angelo Vendrame pushed to branch tor-browser-153.3.0esr-16.0-1 at The Tor Project / Applications / Tor Browser

Commits:

  • 67431346
    by Pier Angelo Vendrame at 2026-09-14T16:45:50+02:00
    fixup! TB 40562: Added Tor Browser preferences to 000-tor-browser.js
    
    TB 45073: Pref review, part 1: 000-tor-browser.js.
    
  • 07c94c27
    by Pier Angelo Vendrame at 2026-09-14T16:45:50+02:00
    fixup! Firefox preference overrides.
    
    BB 45073: Pref review, part 1: 000-tor-browser.js.
    

2 changed files:

Changes:

  • browser/app/profile/000-tor-browser.js
    1 1
     #include 001-base-profile.js
    
    2 2
     
    
    3
    -pref("app.update.notifyDuringDownload", true);
    
    4
    -pref("app.update.badgeWaitTime", 0);
    
    5
    -// point to our feedback url rather than Mozilla's
    
    6
    -pref("app.feedback.baseURL", "https://support.torproject.org/%LOCALE/get-in-touch/bug-or-feedback");
    
    7
    -
    
    8
    -pref("browser.shell.checkDefaultBrowser", false);
    
    9
    -
    
    10 3
     // Proxy and proxy security
    
    4
    +pref("network.proxy.type", 1);
    
    11 5
     pref("network.proxy.socks", "127.0.0.1");
    
    12 6
     pref("network.proxy.socks_port", 9150);
    
    13 7
     pref("network.proxy.socks_remote_dns", true);
    
    14
    -pref("network.proxy.no_proxies_on", ""); // For fingerprinting and local service vulns (#10419)
    
    15
    -pref("network.proxy.allow_hijacking_localhost", true); // Allow proxies for localhost (#31065)
    
    16
    -pref("network.proxy.type", 1);
    
    17
    -// localhost is already blocked by setting `network.proxy.allow_hijacking_localhost` to
    
    18
    -// true, allowing users to explicitly block ports makes them fingerprintable; for details, see
    
    19
    -// Bug 41317: Tor Browser leaks banned ports in network.security.ports.banned
    
    20
    -pref("network.security.ports.banned", "", locked);
    
    21
    -pref("network.dns.disabled", true); // This should cover the #5741 patch for DNS leaks
    
    22 8
     pref("network.http.max-persistent-connections-per-proxy", 256);
    
    23
    -// Disable DNS over HTTPS. Set to explicitly off MODE_TRROFF = 5.
    
    24
    -// See tor-browser#41906.
    
    25
    -pref("network.trr.mode", 5, locked);
    
    9
    +// https://gitlab.torproject.org/legacy/trac/-/work_items/10419: prevent
    
    10
    +// fingerprinting and exploiting of local services vulnerabilities.
    
    11
    +pref("network.proxy.no_proxies_on", "");
    
    12
    +// tor-browser#31065: Force proxies also for localhost
    
    13
    +pref("network.proxy.allow_hijacking_localhost", true);
    
    14
    +// tor-browser#41317: banned port can be fingerprinted and is not necessary,
    
    15
    +// since there are multiple protections that prevent localhost access.
    
    16
    +// Lock ratoinale: prevent fingerprinting of old configurations.
    
    17
    +pref("network.security.ports.banned", "", locked);
    
    26 18
     // tor-browser#44155: Block Local Network Access (LNA)
    
    27 19
     pref("network.lna.enabled", true);
    
    28 20
     pref("network.lna.blocking", true);
    
    29 21
     pref("network.lna.block_trackers", true);
    
    22
    +// https://gitlab.torproject.org/legacy/trac/-/work_items/5741 and
    
    23
    +// tor-browser#33962: disable DNS resolution to avoid potential proxy bypasses.
    
    24
    +// In our setup, the proxy is going to do DNS resolution.
    
    25
    +pref("network.dns.disabled", true);
    
    26
    +// tor-browser#41906: disable DNS over HTTPS to prevent linkability thorugh use
    
    27
    +// of a fixed DNS server rather than the exit relay's. 5 is MODE_TRROFF.
    
    28
    +// Also, there are concerns about the interaction with network.dns.disabled
    
    29
    +// (tor-browser#40034).
    
    30
    +pref("network.trr.mode", 5);
    
    30 31
     
    
    31 32
     // Treat .onions as secure
    
    32 33
     pref("dom.securecontext.allowlist_onions", true);
    
    33 34
     
    
    34
    -// Disable HTTPS-Only mode for .onion domains (tor-browser#19850)
    
    35
    +// tor-browser#19850: disable HTTPS-Only mode for .onion domains.
    
    36
    +// This is already false in Firefox, but we set it again in case upstream
    
    37
    +// changes default value.
    
    35 38
     pref("dom.security.https_only_mode.upgrade_onion", false);
    
    36 39
     
    
    37
    -// Bug 40423/41137: Disable http/3
    
    38
    -// We should re-enable it as soon as Tor gets UDP support
    
    40
    +// tor-browser#40423, tor-browser#41137: Disable HTTP/3.
    
    41
    +// We should re-enable it if Tor gets UDP support.
    
    39 42
     pref("network.http.http3.enable", false);
    
    40 43
     
    
    41
    -// 0 = do not use a second connection, see all.js and #7656
    
    44
    +// https://gitlab.torproject.org/legacy/trac/-/work_items/7656: rely on tor to
    
    45
    +// rebuild streams rather than on browser's retry mechanisms.
    
    46
    +// 0 means "do not use a second HTTP connection" (see also all.js).
    
    42 47
     pref("network.http.connection-retry-timeout", 0);
    
    43 48
     
    
    44 49
     // Tor Browser used to be compatible with non-Tor proxies. This feature is not
    
    ... ... @@ -49,19 +54,24 @@ pref("network.http.connection-retry-timeout", 0);
    49 54
     // be reduced to the strictly required time).
    
    50 55
     pref("extensions.torbutton.use_nontor_proxy", false);
    
    51 56
     
    
    52
    -// Browser home page:
    
    57
    +// Browser home page
    
    53 58
     pref("browser.startup.homepage", "about:tor");
    
    54 59
     
    
    55
    -// General browser support url. tor-browser#43864 and tor-browser#40899.
    
    60
    +// tor-browser#43864, tor-browser#40899: general browser support url.
    
    56 61
     pref("browser.base-browser-support-url", "https://support.torproject.org/tor-browser");
    
    62
    +// Point to our feedback url rather than Mozilla's
    
    63
    +pref("app.feedback.baseURL", "https://support.torproject.org/%LOCALE%/get-in-touch/bug-or-feedback");
    
    57 64
     
    
    58
    -// tor-browser#40701: Add new download warning
    
    65
    +// tor-browser#40701: add our custom download warning.
    
    59 66
     pref("browser.download.showTorWarning", true);
    
    60 67
     
    
    61
    -// tor-browser#45262: Hide "reset PBM" burn/fire button.
    
    68
    +// tor-browser#45262: hide "reset PBM" burn/fire button.
    
    62 69
     pref("browser.privatebrowsing.resetPBM.enabled", false);
    
    63 70
     
    
    71
    +pref("browser.shell.checkDefaultBrowser", false);
    
    72
    +
    
    64 73
     // Tor connection setting preferences.
    
    74
    +// See TorSettings.sys.mjs for more information.
    
    65 75
     
    
    66 76
     pref("torbrowser.settings.quickstart.enabled", false);
    
    67 77
     pref("torbrowser.settings.bridges.enabled", false);
    
    ... ... @@ -85,9 +95,6 @@ pref("torbrowser.settings.firewall.enabled", false);
    85 95
     pref("torbrowser.settings.firewall.allowed_ports", "");
    
    86 96
     
    
    87 97
     
    
    88
    -// This pref specifies an ad-hoc "version" for various pref update hacks we need to do
    
    89
    -pref("extensions.torbutton.pref_fixup_version", 0);
    
    90
    -
    
    91 98
     // Formerly tor-launcher defaults
    
    92 99
     
    
    93 100
     pref("extensions.torlauncher.start_tor", true);
    

  • browser/app/profile/001-base-profile.js
    ... ... @@ -34,7 +34,12 @@ pref("browser.privatebrowsing.resetPBM.enabled", false, locked);
    34 34
     pref("app.update.auto", true);
    
    35 35
     #endif
    
    36 36
     
    
    37
    -// Try to nag a bit more about updates: Pop up a restart dialog an hour after the initial dialog
    
    37
    +pref("app.update.notifyDuringDownload", true);
    
    38
    +
    
    39
    +// Try to nag a bit more about updates.
    
    40
    +// Show the badge immediately on the hamburger menu...
    
    41
    +pref("app.update.badgeWaitTime", 0);
    
    42
    +// ... and pop up a restart dialog an hour after the initial dialog.
    
    38 43
     pref("app.update.promptWaitTime", 3600);
    
    39 44
     
    
    40 45
     #ifndef XP_MACOSX
    

  • _______________________________________________
    tor-commits mailing list -- tor-commits@xxxxxxxxxxxxxxxxxxxx
    To unsubscribe send an email to tor-commits-leave@xxxxxxxxxxxxxxxxxxxx