head 1.2; access; symbols pkgsrc-2026Q3:1.1.0.2 pkgsrc-2026Q3-base:1.1; locks; strict; comment @// @; 1.2 date 2026.09.23.08.39.50; author ryoon; state dead; branches; next 1.1; commitid phfaM19ZhqLpTIWG; 1.1 date 2026.09.01.15.55.09; author ryoon; state Exp; branches; next ; commitid D2zFTgYNlEeC0WTG; desc @@ 1.2 log @www/firefox: Update to 156.0.1 Changelog: 156.0.1: Fixed * Fixed the NVDA screen reader not announcing address bar buttons when the mouse pointer moves over them. (Bug 2069276) * Fixed elements inside a link not showing their CSS :active styles while being clicked. (Bug 2067272) * Fixed Firefox becoming unresponsive on some pages that use CSS anchor positioning. (Bug 2070171) * Fixed Firefox windows on macOS 27 immediately returning to maximized after being restored by double-clicking the title bar. (Bug 2066632) * Fixed Firefox leaking system handles on Windows as content processes were started and stopped. (Bug 2069644) 156.0: New * Firefox on macOS can now be set to open automatically when the computer starts up, from the Startup section of Settings. * Localized Wikipedia and occasional sponsored suggestions in the address bar are now available in France, Germany, and Italy. These suggestions can be turned off in Firefox Suggest settings. Fixed * Fixed an issue where dragging an image to a new position in a rich-text editor could replace it with a long line of text instead of moving it. * Fixed high-sample-rate FLAC audio in MP4 failing to play on sites such as Bilibili. * Fixed subtitles not appearing in the Picture-in-Picture window when they are turned on in the video player after the window has already opened. * Fixed bookmarks moving out of their folder when the folder and the bookmarks inside it were selected and dragged together in the Bookmarks sidebar. * Fixed the find bar becoming permanently unavailable in a tab after reversing the panes in Split View. * Fixed some sites failing to load when DNS over HTTPS is enabled and the site does not support HTTPS. * Fixed Firefox losing all network connectivity for some users with the built-in VPN enabled. * Fixed an issue on Windows where Firefox could block an auto-hiding taskbar from showing. * Various security fixes. Changed * Firefox's built-in PDF viewer now starts up to 45% faster. * Improved memory and CPU usage when Firefox displays large JPEG images scaled down to fit a page. * On Windows devices with ARM64 processors, WebRTC video calls may now use hardware H264 decoding instead of falling back to software. Security fixes: Mozilla Foundation Security Advisory 2026-90 #CVE-2026-92033: Privilege escalation in Firefox for Android #CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component #CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92015: Privilege escalation in the WebExtensions component #CVE-2026-92034: Site isolation issue in the Graphics component #CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component #CVE-2026-92016: Use-after-free in the Disability Access APIs component #CVE-2026-92017: Privilege escalation in the DOM: Service Workers component #CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component #CVE-2026-92019: Mitigation bypass in the Remote Settings Client component #CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component #CVE-2026-92022: Use-after-free in the DOM: HTML Parser component #CVE-2026-92023: Use-after-free in the XML component #CVE-2026-92024: Use-after-free in the SVG component #CVE-2026-92025: Use-after-free in the DOM: Navigation component #CVE-2026-92026: Use-after-free in the Networking component #CVE-2026-92036: Incorrect boundary conditions in the Networking: HTTP component #CVE-2026-92027: Use-after-free in the DOM: Streams component #CVE-2026-92028: Use-after-free in the DOM: Core & HTML component #CVE-2026-92029: Use-after-free in the SVG component #CVE-2026-92037: Incorrect boundary conditions in the DOM: Animation component #CVE-2026-92038: Mitigation bypass in the Remote Settings Client component #CVE-2026-92039: Mitigation bypass in the DOM: Notifications component #CVE-2026-92040: Use-after-free in the JavaScript: WebAssembly component #CVE-2026-92041: Mitigation bypass in the DOM: Networking component #CVE-2026-92042: Race condition in the DOM: Content Processes component #CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component #CVE-2026-92044: Information disclosure in the Networking: HTTP component #CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component #CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component #CVE-2026-92046: Use-after-free in the Graphics component #CVE-2026-92047: Privilege escalation in the Crash Reporting component #CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92049: Use-after-free in the Widget: Win32 component #CVE-2026-92050: Sandbox escape due to race condition in the XPConnect component #CVE-2026-92051: Spoofing issue due to invalid pointer in the Graphics component #CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component #CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component #CVE-2026-92054: Privilege escalation in the Memory component #CVE-2026-92055: Privilege escalation in the DevTools component #CVE-2026-92056: Use-after-free in the Graphics: Text component #CVE-2026-92057: Mitigation bypass in the Enterprise Policies component #CVE-2026-92031: Information disclosure in the Graphics: ImageLib component #CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component #CVE-2026-92058: Use-after-free in the Graphics component #CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component #CVE-2026-92060: Use-after-free in the Internationalization component #CVE-2026-92061: Incorrect boundary conditions in the Security: Process Sandboxing component #CVE-2026-92062: Privilege escalation in the Session Restore component #CVE-2026-92063: Denial-of-service in the Audio/Video component #CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92066: Sandbox escape in the Profile Backup component #CVE-2026-92067: Use-after-free in the Widget: Gtk component #CVE-2026-92068: Site isolation issue in the Reader Mode component #CVE-2026-92069: Spoofing issue in the DOM: Navigation component #CVE-2026-92070: Information disclosure in the Networking component #CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component #CVE-2026-92073: Privilege escalation in the Enterprise Policies component #CVE-2026-92074: Mitigation bypass in the Popup Blocker component #CVE-2026-92075: Mitigation bypass in the Networking component #CVE-2026-92076: Incorrect boundary conditions in the Networking component #CVE-2026-92077: Denial-of-service in the SVG component #CVE-2026-92078: Denial-of-service in the Security component #CVE-2026-92079: Mitigation bypass in the Widget: Win32 component @ text @$NetBSD: patch-toolkit_components_remote_nsXRemoteServer.cpp,v 1.1 2026/09/01 15:55:09 ryoon Exp $ * Fix error, Success is not defined, --- toolkit/components/remote/nsXRemoteServer.cpp.orig 2026-09-01 13:28:58.404435470 +0000 +++ toolkit/components/remote/nsXRemoteServer.cpp @@@@ -110,7 +110,7 @@@@ bool nsXRemoteServer::HandleNewProperty(XID aWindowId, // Failed to get property off the window or // got a part only - if (result != Success || bytes_after != 0) { + if (result != X11Success || bytes_after != 0) { return false; } @ 1.1 log @www/firefox: Fix build error, Success is not declared Reported by Thomas Klausner and Marc Baudoin. Thank you. @ text @d1 1 a1 1 $NetBSD$ @