head 1.2; access; symbols pkgsrc-2026Q3:1.1.0.2 pkgsrc-2026Q3-base:1.1; locks; strict; comment @# @; 1.2 date 2026.09.23.08.39.50; author ryoon; state Exp; branches; next 1.1; commitid phfaM19ZhqLpTIWG; 1.1 date 2026.08.24.12.51.47; author ryoon; state Exp; branches; next ; commitid MFLCFv64IvfDfTSG; desc @@ 1.2 log @www/firefox: Update to 156.0.1 Changelog: 156.0.1: Fixed * Fixed the NVDA screen reader not announcing address bar buttons when the mouse pointer moves over them. (Bug 2069276) * Fixed elements inside a link not showing their CSS :active styles while being clicked. (Bug 2067272) * Fixed Firefox becoming unresponsive on some pages that use CSS anchor positioning. (Bug 2070171) * Fixed Firefox windows on macOS 27 immediately returning to maximized after being restored by double-clicking the title bar. (Bug 2066632) * Fixed Firefox leaking system handles on Windows as content processes were started and stopped. (Bug 2069644) 156.0: New * Firefox on macOS can now be set to open automatically when the computer starts up, from the Startup section of Settings. * Localized Wikipedia and occasional sponsored suggestions in the address bar are now available in France, Germany, and Italy. These suggestions can be turned off in Firefox Suggest settings. Fixed * Fixed an issue where dragging an image to a new position in a rich-text editor could replace it with a long line of text instead of moving it. * Fixed high-sample-rate FLAC audio in MP4 failing to play on sites such as Bilibili. * Fixed subtitles not appearing in the Picture-in-Picture window when they are turned on in the video player after the window has already opened. * Fixed bookmarks moving out of their folder when the folder and the bookmarks inside it were selected and dragged together in the Bookmarks sidebar. * Fixed the find bar becoming permanently unavailable in a tab after reversing the panes in Split View. * Fixed some sites failing to load when DNS over HTTPS is enabled and the site does not support HTTPS. * Fixed Firefox losing all network connectivity for some users with the built-in VPN enabled. * Fixed an issue on Windows where Firefox could block an auto-hiding taskbar from showing. * Various security fixes. Changed * Firefox's built-in PDF viewer now starts up to 45% faster. * Improved memory and CPU usage when Firefox displays large JPEG images scaled down to fit a page. * On Windows devices with ARM64 processors, WebRTC video calls may now use hardware H264 decoding instead of falling back to software. Security fixes: Mozilla Foundation Security Advisory 2026-90 #CVE-2026-92033: Privilege escalation in Firefox for Android #CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component #CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component #CVE-2026-92015: Privilege escalation in the WebExtensions component #CVE-2026-92034: Site isolation issue in the Graphics component #CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component #CVE-2026-92016: Use-after-free in the Disability Access APIs component #CVE-2026-92017: Privilege escalation in the DOM: Service Workers component #CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component #CVE-2026-92019: Mitigation bypass in the Remote Settings Client component #CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component #CVE-2026-92022: Use-after-free in the DOM: HTML Parser component #CVE-2026-92023: Use-after-free in the XML component #CVE-2026-92024: Use-after-free in the SVG component #CVE-2026-92025: Use-after-free in the DOM: Navigation component #CVE-2026-92026: Use-after-free in the Networking component #CVE-2026-92036: Incorrect boundary conditions in the Networking: HTTP component #CVE-2026-92027: Use-after-free in the DOM: Streams component #CVE-2026-92028: Use-after-free in the DOM: Core & HTML component #CVE-2026-92029: Use-after-free in the SVG component #CVE-2026-92037: Incorrect boundary conditions in the DOM: Animation component #CVE-2026-92038: Mitigation bypass in the Remote Settings Client component #CVE-2026-92039: Mitigation bypass in the DOM: Notifications component #CVE-2026-92040: Use-after-free in the JavaScript: WebAssembly component #CVE-2026-92041: Mitigation bypass in the DOM: Networking component #CVE-2026-92042: Race condition in the DOM: Content Processes component #CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component #CVE-2026-92044: Information disclosure in the Networking: HTTP component #CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component #CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component #CVE-2026-92046: Use-after-free in the Graphics component #CVE-2026-92047: Privilege escalation in the Crash Reporting component #CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92049: Use-after-free in the Widget: Win32 component #CVE-2026-92050: Sandbox escape due to race condition in the XPConnect component #CVE-2026-92051: Spoofing issue due to invalid pointer in the Graphics component #CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component #CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component #CVE-2026-92054: Privilege escalation in the Memory component #CVE-2026-92055: Privilege escalation in the DevTools component #CVE-2026-92056: Use-after-free in the Graphics: Text component #CVE-2026-92057: Mitigation bypass in the Enterprise Policies component #CVE-2026-92031: Information disclosure in the Graphics: ImageLib component #CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component #CVE-2026-92058: Use-after-free in the Graphics component #CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component #CVE-2026-92060: Use-after-free in the Internationalization component #CVE-2026-92061: Incorrect boundary conditions in the Security: Process Sandboxing component #CVE-2026-92062: Privilege escalation in the Session Restore component #CVE-2026-92063: Denial-of-service in the Audio/Video component #CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92066: Sandbox escape in the Profile Backup component #CVE-2026-92067: Use-after-free in the Widget: Gtk component #CVE-2026-92068: Site isolation issue in the Reader Mode component #CVE-2026-92069: Spoofing issue in the DOM: Navigation component #CVE-2026-92070: Information disclosure in the Networking component #CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component #CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component #CVE-2026-92073: Privilege escalation in the Enterprise Policies component #CVE-2026-92074: Mitigation bypass in the Popup Blocker component #CVE-2026-92075: Mitigation bypass in the Networking component #CVE-2026-92076: Incorrect boundary conditions in the Networking component #CVE-2026-92077: Denial-of-service in the SVG component #CVE-2026-92078: Denial-of-service in the Security component #CVE-2026-92079: Mitigation bypass in the Widget: Win32 component @ text @$NetBSD$ --- third_party/angle/angle_common_gn/moz.build.orig 2026-09-09 20:41:52.000000000 +0000 +++ third_party/angle/angle_common_gn/moz.build @@@@ -136,7 +136,7 @@@@ if CONFIG["OS_TARGET"] == "Linux": "/third_party/angle/src/common/system_utils_posix.cpp" ] -if CONFIG["OS_TARGET"] == "OpenBSD": +if CONFIG["OS_TARGET"] == "OpenBSD" or CONFIG["OS_TARGET"] == "FreeBSD" or CONFIG["OS_TARGET"] == "NetBSD": DEFINES["EGL_NO_X11"] = True DEFINES["USE_GLIB"] = "1" @@@@ -147,6 +147,17 @@@@ if CONFIG["OS_TARGET"] == "OpenBSD": DEFINES["__STDC_CONSTANT_MACROS"] = True DEFINES["__STDC_FORMAT_MACROS"] = True + if CONFIG["OS_TARGET"] == "FreeBSD": + OS_LIBS += { + "dl" + } + + UNIFIED_SOURCES += [ + "/third_party/angle/src/common/system_utils_linux.cpp", + "/third_party/angle/src/common/system_utils_posix.cpp" + ] + + if CONFIG["OS_TARGET"] == "WINNT": DEFINES["ANGLE_IS_WIN"] = True @@@@ -212,7 +223,7 @@@@ if CONFIG["MOZ_DEBUG"] == "1" and CONFIG["OS_TARGET"] DEFINES["_DEBUG"] = True -if CONFIG["MOZ_DEBUG"] == "1" and CONFIG["OS_TARGET"] == "OpenBSD": +if CONFIG["MOZ_DEBUG"] == "1" and (CONFIG["OS_TARGET"] == "OpenBSD" or CONFIG["OS_TARGET"] == "FreeBSD" or CONFIG["OS_TARGET"] == "NetBSD"): DEFINES["_DEBUG"] = True @ 1.1 log @www/firefox: Update to 154.0 * Generate and use more generic PLIST. Changelog: 154.0: New * Firefox's Local Network Access protections now extend to WebSocket connections. Websites that try to open a WebSocket to a device on the local network will now ask for permission first. * In Smart Window, Firefox can now suggest groups of related tabs and propose a name for each group. * Firefox on Windows is now a supported browser for NVIDIA GeForce NOW, letting users stream supported PC games directly in the browser. * Local Firefox profile backups are now available on macOS in addition to Windows and Linux, and backups can be restored across all three platforms. * Sites can now be exempted from having their cookies and site data cleared on shutdown without also being exempted from tracking protection and other cookie restrictions. * The full-page Translations feature now translates