ChangeLog.txt 190 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693269426952696269726982699270027012702270327042705270627072708270927102711271227132714271527162717271827192720272127222723272427252726272727282729273027312732273327342735273627372738273927402741274227432744274527462747274827492750275127522753275427552756275727582759276027612762276327642765276627672768276927702771277227732774277527762777277827792780278127822783278427852786278727882789279027912792279327942795279627972798279928002801280228032804280528062807280828092810281128122813281428152816281728182819282028212822282328242825282628272828282928302831283228332834283528362837283828392840284128422843284428452846284728482849285028512852285328542855285628572858285928602861286228632864286528662867286828692870287128722873287428752876287728782879288028812882288328842885288628872888288928902891289228932894289528962897289828992900290129022903290429052906290729082909291029112912291329142915291629172918291929202921292229232924292529262927292829292930293129322933293429352936293729382939294029412942294329442945294629472948294929502951295229532954295529562957295829592960296129622963296429652966296729682969297029712972297329742975297629772978297929802981298229832984298529862987298829892990299129922993299429952996299729982999300030013002300330043005300630073008300930103011301230133014301530163017301830193020302130223023302430253026302730283029303030313032303330343035303630373038303930403041304230433044304530463047304830493050305130523053305430553056305730583059306030613062306330643065306630673068306930703071307230733074307530763077307830793080308130823083308430853086308730883089309030913092309330943095309630973098309931003101310231033104310531063107310831093110311131123113311431153116311731183119312031213122312331243125312631273128312931303131313231333134313531363137313831393140314131423143314431453146314731483149315031513152315331543155315631573158315931603161316231633164316531663167316831693170317131723173317431753176317731783179318031813182318331843185318631873188318931903191319231933194319531963197319831993200320132023203320432053206320732083209321032113212321332143215321632173218321932203221322232233224322532263227322832293230323132323233323432353236323732383239324032413242324332443245324632473248324932503251325232533254325532563257325832593260326132623263326432653266326732683269327032713272327332743275327632773278327932803281328232833284328532863287328832893290329132923293329432953296329732983299330033013302330333043305330633073308330933103311331233133314331533163317331833193320332133223323332433253326332733283329333033313332333333343335333633373338333933403341334233433344334533463347334833493350335133523353335433553356335733583359336033613362336333643365336633673368336933703371337233733374337533763377337833793380338133823383338433853386338733883389339033913392339333943395339633973398339934003401340234033404340534063407340834093410341134123413341434153416341734183419342034213422342334243425342634273428342934303431343234333434343534363437343834393440344134423443344434453446344734483449345034513452345334543455345634573458345934603461346234633464346534663467346834693470347134723473347434753476347734783479348034813482348334843485348634873488348934903491349234933494349534963497349834993500350135023503350435053506350735083509351035113512351335143515351635173518351935203521352235233524352535263527352835293530353135323533353435353536353735383539354035413542354335443545354635473548354935503551355235533554355535563557355835593560356135623563356435653566356735683569357035713572357335743575357635773578357935803581358235833584358535863587358835893590359135923593359435953596359735983599360036013602360336043605360636073608360936103611361236133614361536163617361836193620362136223623362436253626362736283629363036313632363336343635363636373638363936403641364236433644364536463647364836493650365136523653365436553656365736583659366036613662366336643665366636673668366936703671367236733674367536763677367836793680368136823683368436853686368736883689369036913692369336943695369636973698369937003701370237033704370537063707370837093710371137123713371437153716371737183719372037213722372337243725372637273728372937303731373237333734373537363737373837393740374137423743374437453746374737483749375037513752375337543755375637573758375937603761376237633764376537663767376837693770377137723773377437753776377737783779378037813782378337843785378637873788378937903791379237933794379537963797379837993800380138023803380438053806380738083809381038113812381338143815381638173818381938203821382238233824382538263827382838293830383138323833383438353836383738383839384038413842384338443845384638473848384938503851385238533854385538563857385838593860386138623863386438653866386738683869387038713872387338743875387638773878387938803881388238833884388538863887388838893890389138923893389438953896389738983899390039013902390339043905390639073908390939103911391239133914391539163917391839193920392139223923392439253926392739283929393039313932393339343935393639373938393939403941394239433944394539463947394839493950395139523953395439553956395739583959396039613962396339643965396639673968396939703971397239733974397539763977397839793980398139823983398439853986398739883989399039913992399339943995399639973998399940004001400240034004400540064007400840094010401140124013401440154016401740184019402040214022402340244025402640274028402940304031403240334034403540364037403840394040404140424043404440454046404740484049405040514052405340544055405640574058405940604061406240634064406540664067406840694070407140724073407440754076407740784079408040814082408340844085408640874088408940904091409240934094409540964097409840994100410141024103410441054106410741084109411041114112411341144115411641174118411941204121412241234124412541264127412841294130413141324133413441354136413741384139
  1. Tor Browser 8.5a10 -- March 24 2019
  2. * All platforms
  3. * Update Firefox to 60.6.1esr
  4. * Update NoScript to 10.2.4
  5. * Bug 29733: Work around Mozilla's bug 1532530
  6. Tor Browser 8.0.8 -- March 22 2019
  7. * All platforms
  8. * Update Firefox to 60.6.1esr
  9. * Update NoScript to 10.2.4
  10. * Bug 29733: Work around Mozilla's bug 1532530
  11. Tor Browser 8.5a9 -- March 20 2019
  12. * All platforms
  13. * Update Firefox to 60.6.0esr
  14. * Update Torbutton to 2.1.5
  15. * Bug 25658: Replace security slider with security level UI
  16. * Bug 28628: Change onboarding Security panel to open new Security Level panel
  17. * Bug 29440: Update about:tor when Tor Browser is updated
  18. * Bug 27478: Improved Torbutton icons for dark theme
  19. * Bug 29021: Tell NoScript it is running within Tor Browser
  20. * Bug 29239: Don't ship the Torbutton .xpi on mobile
  21. * Translations update
  22. * Bug 29120: Enable media cache in memory
  23. * Bug 29445: Enable support for enterprise policies
  24. * Windows + OS X + Linux
  25. * Update Tor to 0.4.0.2-alpha
  26. * Bug 29660: XMPP can not connect to SOCKS5 anymore
  27. * Update OpenSSL to 1.0.2r
  28. * Update Tor Launcher to 0.2.18.1
  29. * Bug 29328: Account for Tor 0.4.0.x's revised bootstrap status reporting
  30. * Bug 22402: Improve "For assistance" link
  31. * Translations update
  32. * Bug 25658+29554: Replace security slider with security level UI
  33. * Bug 28885: notify users that update is downloading
  34. * Bug 29180: MAR download stalls when about dialog is opened
  35. * Bug 27485: Users are not taught how to open security-slider dialog
  36. * Bug 27486: Avoid about:blank tabs when opening onboarding pages
  37. * Bug 29440: Update about:tor when Tor Browser is updated
  38. * Bug 23359: WebExtensions icons are not shown on first start
  39. * Bug 28628: Change onboarding Security panel to open new Security Level panel
  40. * Android
  41. * Bug 28329: Design Tor Browser for Android configuration UI
  42. * Bug 28802: Support PTs in Tor Browser for Android
  43. * Bug 29794: Update TBA built-in bridges
  44. * Bug 27210: Add support for x86 on Android
  45. * Bug 29809: Only ship tor binary for .apk architecture
  46. * Bug 29633: Don't ship pdnsd anymore
  47. * Bug 28708: about:tor is not the default homepage after upgrade
  48. * Bug 29626: Application name is now "Always-On Notifications"
  49. * Bug 29467: Backport fix for arc4random_buf bustage
  50. * Build System
  51. * All platforms
  52. * Bug 25876: Generate source tarballs during build
  53. * Bug 28685: Set Build ID based on Tor Browser version
  54. * Bug 29194: Set DEBIAN_FRONTEND=noninteractive
  55. * Linux
  56. * Bug 26323+29812: Build 32bit Linux bundles on 64bit Debian Wheezy
  57. * Bug 29758: Build firefox debug symbols for linux-i686
  58. * Android
  59. * Bug 29632: Use HTTPS for downloading Gradle
  60. Tor Browser 8.0.7 -- March 19 2019
  61. * All platforms
  62. * Update Firefox to 60.6.0esr
  63. * Update Tor to 0.3.5.8
  64. * Bug 29660: XMPP can not connect to SOCKS5 anymore
  65. * Update Torbutton to 2.0.11
  66. * Bug 29021: Tell NoScript it is running within Tor Browser
  67. * Windows
  68. * Bug 29081: Harden libwinpthread
  69. * Linux
  70. * Bug 27531: Add separate LD_LIBRARY_PATH for fteproxy
  71. Tor Browser 8.5a8 -- February 13 2019
  72. * All platforms
  73. * Update Firefox to 60.5.1esr
  74. * Update HTTPS Everywhere to 2019.1.31
  75. * Bug 29378: Remove 83.212.101.3 from default bridges
  76. * Bug 29349: Remove network.http.spdy.* overrides from meek helper user.js
  77. * Bug 29327: TypeError: hostName is null on about:tor page
  78. * Build System
  79. * All Platforms
  80. * Bug 29235: Build our own version of python3.6 for HTTPS Everywhere
  81. * Bug 29167: Upgrade go to 1.11.5
  82. * Linux
  83. * Bug 29183: Use linux-x86_64 langpacks on linux-x86_64
  84. Tor Browser 8.0.6 -- February 12 2019
  85. * All platforms
  86. * Update Firefox to 60.5.1esr
  87. * Update HTTPS Everywhere to 2019.1.31
  88. * Bug 29378: Remove 83.212.101.3 from default bridges
  89. * Build System
  90. * All Platforms
  91. * Bug 29235: Build our own version of python3.6 for HTTPS Everywhere
  92. Tor Browser 8.5a7 -- January 29 2019
  93. * All Platforms
  94. * Update Firefox to 60.5.0esr
  95. * Update Torbutton to 2.1.4
  96. * Bug 25702: Update Tor Browser icon to follow design guidelines
  97. * Bug 21805: Add click-to-play button for WebGL
  98. * Bug 28836: Links on about:tor are not clickable
  99. * Bug 29035: Clean up our donation campaign and add newsletter sign-up link
  100. * Translations update
  101. * Code clean-up
  102. * Update HTTPS Everywhere to 2019.1.7
  103. * Update NoScript to 10.2.1
  104. * Bug 28873: Cascading of permissions is broken
  105. * Bug 28720: Some videos are blocked outright on higher security levels
  106. * Bug 29082: Backport patches for bug 1469916
  107. * Bug 28711: Backport patches for bug 1474659
  108. * Bug 27828: "Check for Tor Browser update" doesn't seem to do anything
  109. * Bug 29028: Auto-decline most canvas warning prompts again
  110. * Bug 27597: Fix our debug builds
  111. * Windows
  112. * Update Tor to 0.4.0.1-alpha
  113. * Bug 25702: Activity 1.1 Update Tor Browser icon to follow design guidelines
  114. * Bug 28111: Use Tor Browser icon in identity box
  115. * Bug 22654: Firefox icon is shown for Tor Browser on Windows 10 start menu
  116. * Bug 27503: Compile with accessibility support
  117. * Bug 28874: Bump mingw-w64 commit to fix WebGL crash
  118. * Bug 12885: Windows Jump Lists fail for Tor Browser
  119. * Bug 28618: Set MOZILLA_OFFICIAL for Windows build
  120. * OS X
  121. * Update Tor to 0.4.0.1-alpha
  122. * Bug 25702: Activity 1.1 Update Tor Browser icon to follow design guidelines
  123. * Bug 28111: Use Tor Browser icon in identity box
  124. * Linux
  125. * Update Tor to 0.4.0.1-alpha
  126. * Bug 25702: Activity 1.1 Update Tor Browser icon to follow design guidelines
  127. * Bug 28111: Use Tor Browser icon in identity box
  128. * Bug 27531: Fix crashing print dialog
  129. * Android
  130. * Bug 28705: Fix download crash on newer Android devices
  131. * Bug 28814: Backport 1480079 to allow installing downloaded apps
  132. * Build System
  133. * All Platforms
  134. * Bug 29158: Install updated apt packages (CVE-2019-3462)
  135. * Bug 29097: Don't try to install python3.6-lxml for HTTPS Everywhere
  136. * Windows
  137. * Bug 26148: Update binutils to 2.31.1
  138. * Bug 29081: Harden libwinpthread
  139. * Linux
  140. * Bug 26148: Update binutils to 2.31.1
  141. * Android
  142. * Bug 28752: Don't download tor-android-binary resources during build
  143. Tor Browser 8.0.5 -- January 29 2019
  144. * All platforms
  145. * Update Firefox to 60.5.0esr
  146. * Update Tor to 0.3.5.7
  147. * Update Torbutton to 2.0.10
  148. * Bug 29035: Clean up our donation campaign and add newsletter sign-up link
  149. * Bug 27175: Add pref to allow users to persist custom noscript settings
  150. * Update HTTPS Everywhere to 2019.1.7
  151. * Update NoScript to 10.2.1
  152. * Bug 28873: Cascading of permissions is broken
  153. * Bug 28720: Some videos are blocked outright on higher security levels
  154. * Bug 26540: Enabling pdfjs disableRange option prevents pdfs from loading
  155. * Bug 28740: Adapt Windows navigator.platform value on 64-bit systems
  156. * Bug 28695: Set default security.pki.name_matching_mode to enforce (3)
  157. Tor Browser 8.5a6 -- December 11 2018
  158. * All Platforms
  159. * Update Firefox to 60.4.0esr
  160. * Update Torbutton to 2.1.3
  161. * Bug 28540: Use new text for 2018 donation banner
  162. * Bug 27290: Remove WebGL pref for min capability mode
  163. * Bug 28075: Tone down missing SOCKS credential warning
  164. * Bug 28747: Remove NoScript (XPCOM) related unused code
  165. * Translations update
  166. * Bug 28608: Disable background HTTP response throttling
  167. * Bug 28695: Set default security.pki.name_matching_mode to enforce (3)
  168. * Bug 27290: Remove WebGL pref for min capability mode
  169. * Bug 27919: Backport SSL status API
  170. * Bug 25794: Disable pointer events
  171. * Windows
  172. * Update OpenSSL to 1.0.2q
  173. * Bug 28740: Adapt Windows navigator.platform value on 64-bit systems
  174. * OS X
  175. * Update OpenSSL to 1.0.2q
  176. * Linux
  177. * Update OpenSSL to 1.0.2q
  178. * Android
  179. * Bug 26843: Multi-locale support for Tor Browser on Android
  180. * Build System
  181. * Android
  182. * Bug 25164: Add .apk to our sha256sums unsigned build file
  183. * Bug 28696: Make path to Gradle dependencies reproducible
  184. * Bug 28697: Use pregenerated keystore and fix timestamp issues
  185. Tor Browser 8.0.4 -- December 11 2018
  186. * All platforms
  187. * Update Firefox to 60.4.0esr
  188. * Update Tor to 0.3.4.9
  189. * Update OpenSSL to 1.0.2q
  190. * Update Torbutton to 2.0.9
  191. * Bug 28540: Use new text for 2018 donation banner
  192. * Bug 28515: Use en-US for english Torbutton strings
  193. * Translations update
  194. * Update HTTPS Everywhere to 2018.10.31
  195. * Update NoScript to 10.2.0
  196. * Bug 1623: Block protocol handler enumeration (backport of fix for #680300)
  197. * Bug 25794: Disable pointer events
  198. * Bug 28608: Disable background HTTP response throttling
  199. * Bug 28185: Add smallerRichard to Tor Browser
  200. * Windows
  201. * Bug 26381: about:tor page does not load on first start on Windows
  202. * Bug 28657: Remove broken FTE bridge from Tor Browser
  203. * OS X
  204. * Bug 26263: App icon positioned incorrectly in macOS DMG installer window
  205. * Bug 26475: Fix Stylo related reproducibility issue
  206. * Linux
  207. * Bug 26475: Fix Stylo related reproducibility issue
  208. * Bug 28657: Remove broken FTE bridge from Tor Browser
  209. * Build System
  210. * All Platforms
  211. * Bug 27218: Generate multiple Tor Browser bundles in parallel
  212. Tor Browser 8.5a5 -- December 3 2018
  213. * All Platforms
  214. * Update Torbutton to 2.1.2
  215. * Bug 25013: Integrate Torbutton into tor-browser for Android
  216. * Bug 27111: Update about:tor desktop version to work on mobile
  217. * Bug 28093: Update donation banner style to make it fit in small screens
  218. * Bug 28543: about:tor has scroll bar between widths 900px and 1000px
  219. * Bug 28039: Enable dump() if log method is 0
  220. * Bug 27701: Don't show App Blocker dialog on Android
  221. * Bug 28187: Change tor circuit icon to torbutton.svg
  222. * Bug 28515: Use en-US for english Torbutton strings
  223. * Translations update
  224. * Update Tor Launcher to 0.2.18
  225. * Bug 28039: Enable dump() if log method is 0
  226. * Translations update
  227. * Update HTTPS Everywhere to 2018.10.31
  228. * Update NoScript to 10.2.0
  229. * Bug 22343: Make 'Save Page As' obey first-party isolation
  230. * Bug 26540: Enabling pdfjs disableRange option prevents pdfs from loading
  231. * Windows
  232. * Update Tor to 0.3.5.5-alpha
  233. * Bug 28310: Don't build obfs4 with module versioning support
  234. * Bug 27827: Update Go to 1.11.1
  235. * Bug 28185: Add smallerRichard to Tor Browser
  236. * Bug 28657: Remove broken FTE bridge from Tor Browser
  237. * OS X
  238. * Update Tor to 0.3.5.5-alpha
  239. * Bug 28310: Don't build obfs4 with module versioning support
  240. * Bug 27827: Update Go to 1.11.1
  241. * Bug 27827: Build snowflake reproducibly
  242. * Bug 28258: Don't look for webrtc headers under talk/
  243. * Bug 28185: Add smallerRichard to Tor Browser
  244. * Linux
  245. * Update Tor to 0.3.5.5-alpha
  246. * Bug 28310: Don't build obfs4 with module versioning support
  247. * Bug 27827: Update Go to 1.11.1
  248. * Bug 27827: Build snowflake reproducibly
  249. * Bug 28258: Don't look for webrtc headers under talk/
  250. * Bug 28185: Add smallerRichard to Tor Browser
  251. * Bug 28657: Remove broken FTE bridge from Tor Browser
  252. * Android
  253. * Bug 28051: Fix up Orbot for inclusion into Tor Browser
  254. * Bug 26690+25765: Port padlock states for .onion services to mobile
  255. * Bug 28507: Delete private data in the browser startup
  256. * Bug 27111+25013: Configure Tor Browser for mobile to load about:tor
  257. * Bug 27256: Enable TouchEvents on Android
  258. * Bug 28640: Use system add-on and distributed preferences
  259. * Build System
  260. * Bug 27977: Build Orbot inside tor-browser-build
  261. * Bug 27443: Update Firefox RBM config and build for Android
  262. * Bug 27439: Add android target for rust compiler
  263. * Bug 28469: Fix unsupported libbacktrace in Rust 1.26
  264. * Bug 28468: Modify Android toolchain to support Orbot
  265. * Bug 28483: Modify Android Toolchain API Version
  266. * Bug 28472: Add Android Makefile Rules
  267. * Bug 28470: Add fetch gradle dependency script to common project
  268. * Bug 28144: Update projects/tor-browser for Android
  269. Tor Browser 8.5a4 -- October 23 2018
  270. * All Platforms
  271. * Update Firefox to 60.3.0esr
  272. * Update Tor to 0.3.5.3-alpha
  273. * Update Torbutton to 2.1.1
  274. * Bug 23925+27959: Donation banner for year end 2018 campaign
  275. * Bug 24172: Donation banner clobbers Tor Browser version string
  276. * Bug 28082: Add locales cs, el, hu, ka
  277. * Translations update
  278. * Update Tor Launcher to 0.2.17
  279. * Bug 27994+25151: Use the new Tor Browser logo
  280. * Bug 28082: Add locales cs, el, hu, ka
  281. * Translations update
  282. * Update HTTPS Everywhere to 2018.9.19
  283. * Update NoScript to 10.1.9.9
  284. * Bug 1623: Block protocol handler enumeration (backport of fix for #680300)
  285. * Bug 27905: Fix many occurrences of "Firefox" in about:preferences
  286. * Bug 28082: Add locales cs, el, hu, ka
  287. * Windows
  288. * Bug 21704: Abort install if CPU is missing SSE2 support
  289. * Bug 28002: Fix the precomplete file in the en-US installer
  290. * OS X
  291. * Bug 26263: App icon positioned incorrectly in macOS DMG installer window
  292. * Bug 26475: Fix Stylo related reproducibility issue
  293. * Linux
  294. * Bug 26475: Fix Stylo related reproducibility issue
  295. * Bug 28022: Use `/usr/bin/env bash` for bash invocation
  296. * Android
  297. * Backport of fixes for bug 1448014, 1458905, 1441345, and 1448305
  298. * Build System
  299. * All Platforms
  300. * Bug 27218: Generate multiple Tor Browser bundles in parallel
  301. * Windows
  302. * Bug 27320: Build certutil for Windows
  303. * OS X
  304. * Bug 27320: Build certutil for macOS
  305. Tor Browser 8.0.3 -- October 23 2018
  306. * All platforms
  307. * Update Firefox to 60.3.0esr
  308. * Update Torbutton to 2.0.8
  309. * Bug 23925+27959: Donation banner for year end 2018 campaign
  310. * Bug 24172: Donation banner clobbers Tor Browser version string
  311. * Bug 27760: Use new NoScript API for IPC and fix about:blank issue
  312. * Translations update
  313. * Update HTTPS Everywhere to 2018.9.19
  314. * Update NoScript to 10.1.9.9
  315. * Linux
  316. * Bug 27546: Fix vertical scrollbar behavior in Tor Browser 8 with Gtk3
  317. * Bug 27552: Use bundled dir on CentOS/RHEL 6
  318. Tor Browser 8.5a3 -- October 4 2018
  319. * All platforms
  320. * Update Firefox to 60.2.1esr
  321. * Backport fix for Mozilla bug 1493900 and 1493903
  322. * Windows
  323. * Bug 27865: Tor Browser 8.5a2 is crashing on Windows
  324. * OS X
  325. * Backport fix for Mozilla bug 1489785 for macOS 10.14 compatibility
  326. Tor Browser 8.0.2 -- October 2 2018
  327. * All platforms
  328. * Update Firefox to 60.2.1esr
  329. * Backport fix for Mozilla bug 1493900 and 1493903
  330. * OS X
  331. * Backport fix for Mozilla bug 1489785 for macOS 10.14 compatibility
  332. Tor Browser 8.5a2 -- September 24 2018
  333. * All platforms
  334. * Update Tor to 0.3.5.2-alpha
  335. * Update Torbutton to 2.1
  336. * Bug 27097: Tor News signup banner
  337. * Bug 27663: Add New Identity menuitem again
  338. * Bug 27175: Add pref to allow users to persist custom noscript settings
  339. * Bug 27760: Use new NoScript API for IPC and fix about:blank issue
  340. * Bug 26624: Only block OBJECT on highest slider level
  341. * Bug 26555: Don't show IP address for meek or snowflake
  342. * Bug 27478: Torbutton icons for dark theme
  343. * Bug 27506+14520: Move status version to upper left corner for RTL locales
  344. * Bug 27558: Update the link to "Your Guard note may not change" text
  345. * Bug 21263: Remove outdated information from the README
  346. * Translations update
  347. * Update Tor Launcher to 0.2.16.5
  348. * Bug 27469: Adapt Moat URLs
  349. * Translations update
  350. * Clean-up
  351. * Update NoScript to 10.1.9.6
  352. * Bug 27763: Restrict Torbutton signing exemption to mobile
  353. * Bug 26146: Spoof HTTP User-Agent header for desktop platforms
  354. * Bug 27543: QR code is broken on web.whatsapp.com
  355. * Bug 27264: Bookmark items are not visible on the boomark toolbar
  356. * Bug 27535: Enable TLS 1.3 draft version
  357. * Bug 27623: Use MOZILLA_OFFICIAL for our builds
  358. * Backport of Mozilla bug 1490585, 1475775, and 1489744
  359. * Windows:
  360. * Bug 26381: about:tor page does not load on first start on Windows
  361. * Linux:
  362. * Bug 27546: Fix vertical scrollbar behavior in Tor Browser 8 with Gtk3
  363. * Bug 27552: Use bundled dir on CentOS/RHEL 6
  364. * Bug 26556: Fix broken Tor Browser icon path on Linux
  365. Tor Browser 8.0.1 -- September 24 2018
  366. * All platforms
  367. * Update Tor to 0.3.4.8
  368. * Update Torbutton to 2.0.7
  369. * Bug 27097: Tor News signup banner
  370. * Bug 27663: Add New Identity menuitem again
  371. * Bug 26624: Only block OBJECT on highest slider level
  372. * Bug 26555: Don't show IP address for meek or snowflake
  373. * Bug 27478: Torbutton icons for dark theme
  374. * Bug 27506+14520: Move status version to upper left corner for RTL locales
  375. * Bug 27427: Fix NoScript IPC for about:blank by whitelisting messages
  376. * Bug 27558: Update the link to "Your Guard note may not change" text
  377. * Translations update
  378. * Update Tor Launcher to 0.2.16.6
  379. * Bug 27469: Adapt Moat URLs
  380. * Translations update
  381. * Clean-up
  382. * Update NoScript to 10.1.9.6
  383. * Bug 27763: Restrict Torbutton signing exemption to mobile
  384. * Bug 26146: Spoof HTTP User-Agent header for desktop platforms
  385. * Bug 27543: QR code is broken on web.whatsapp.com
  386. * Bug 27264: Bookmark items are not visible on the boomark toolbar
  387. * Bug 27535: Enable TLS 1.3 draft version
  388. * Backport of Mozilla bug 1490585, 1475775, and 1489744
  389. * OS X
  390. * Bug 27482: Fix crash during start-up on macOS 10.9.x systems
  391. * Linux
  392. * Bug 26556: Fix broken Tor Browser icon path on Linux
  393. Tor Browser 8.5a1 -- September 5 2018
  394. * All platforms
  395. * Update Firefox to 60.2.0esr
  396. * Update Tor to 0.3.4.7-rc
  397. * Update OpenSSL to 1.0.2p
  398. * Update Torbutton to 2.0.6
  399. * Bug 27401: Start listening for NoScript before it loads
  400. * Bug 27276: Adapt to new NoScript messaging protocol
  401. * Bug 26884: Use Torbutton to provide security slider on mobile
  402. * Bug 26962: Circuit display onboarding
  403. * Bug 26520: Fix sec slider/NoScript for TOR_SKIP_LAUNCH=1
  404. * Bug 26490: Remove the security slider notification
  405. * Bug 27301: Improve about:tor behavior and appearance
  406. * Bug 27097: Add text for Tor News signup widget
  407. * Bug 27214: Improve the onboarding text
  408. * Translations update
  409. * Update Tor Launcher to 0.2.16.4
  410. * Bug 25405: Cannot use Moat if a meek bridge is configured
  411. * Bug 27392: Update Moat URLs
  412. * Translations update
  413. * Update HTTPS Everywhere to 2018.8.22
  414. * Update NoScript to 10.1.9.1
  415. * Bug 26962: New feature onboarding
  416. * Bug 27403: The onboarding bubble is not always displayed
  417. * Bug 27283: Fix first-party isolation for UI tour
  418. * Bug 27213: Update about:tbupdate to new (about:tor) layout
  419. * Bug 26670: Make canvas permission prompt respect first-party isolation
  420. * Bug 26561: .onion images are not displayed
  421. * Bug 21787: Spoof en-US for date picker
  422. * Bug 21607: Disable WebVR for now until it is properly audited
  423. * Bug 21549: Disable wasm for now until it is properly audited
  424. * Bug 26614: Disable Web Authentication API until it is properly audited
  425. * Bug 27281: Enable Reader View mode again
  426. * Bug 26114: Don't expose navigator.mozAddonManager to websites
  427. * Bug 26048: Fix potentially confusing "restart to update" message
  428. * Bug 27221: Purge startup cache if Tor Browser version changed
  429. * Bug 26049: Reduce delay for showing update prompt to 1 hour
  430. * Bug 25405: Cannot use Moat if a meek bridge is configured
  431. * Bug 27268+27257+27262+26603: Preferences clean-up
  432. * Windows
  433. * Bug 26381: Work around endless loop during page load and about:tor not loading
  434. * Bug 27411: Fix broken security slider and NoScript interaction on Windows
  435. * Build System
  436. * All Platforms
  437. * Bug 27061: Enable verification of langpacks checksums
  438. * Bug 27178+27179: Add support for xz compression in mar files
  439. Tor Browser 8.0 -- September 5 2018
  440. * All platforms
  441. * Update Firefox to 60.2.0esr
  442. * Update Tor to 0.3.3.9
  443. * Update OpenSSL to 1.0.2p
  444. * Update Libevent to 2.1.8
  445. * Update Torbutton to 2.0.6
  446. * Bug 26960: Implement new about:tor start page
  447. * Bug 26961: Implement new user onboarding
  448. * Bug 26962: Circuit display onboarding
  449. * Bug 27301: Improve about:tor behavior and appearance
  450. * Bug 27214: Improve the onboarding text
  451. * Bug 26321: Move 'New Identity', 'New Circuit' to File, hamburger menus
  452. * Bug 26100: Adapt Torbutton to Firefox 60 ESR
  453. * Bug 26520: Fix sec slider/NoScript for TOR_SKIP_LAUNCH=1
  454. * Bug 27401: Start listening for NoScript before it loads
  455. * Bug 26430: New Torbutton icon
  456. * Bug 24309: Move circuit display to the identity popup
  457. * Bug 26884: Use Torbutton to provide security slider on mobile
  458. * Bug 26128: Adapt security slider to the WebExtensions version of NoScript
  459. * Bug 27276: Adapt to new NoScript messaging protocol
  460. * Bug 23247: Show security state of .onions
  461. * Bug 26129: Show our about:tor page on startup
  462. * Bug 26235: Hide new unusable items from help menu
  463. * Bug 26058: Remove workaround for hiding 'sign in to sync' button
  464. * Bug 26590: Use new svg.disabled pref in security slider
  465. * Bug 26655: Adjust color and size of onion button
  466. * Bug 26500: Reposition circuit display relay icon for RTL locales
  467. * Bug 26409: Remove spoofed locale implementation
  468. * Bug 26189: Remove content-policy.js
  469. * Bug 26544: Images are not centered anymore
  470. * Bug 26490: Remove the security slider notification
  471. * Bug 25126: Make about:tor layout responsive
  472. * Bug 27097: Add text for Tor News signup widget
  473. * Bug 21245: Add da translation to Torbutton and keep track of it
  474. * Bug 27129+20628: Add locales ca, ga, id, is, nb, da, he, sv, and zh-TW
  475. * Translations update
  476. * Update Tor Launcher to 0.2.16.3
  477. * Bug 23136: Moat integration (fetch bridges for the user)
  478. * Bug 25750: Update Tor Launcher to make it compatible with Firefox 60 ESR
  479. * Bug 26985: Help button icons missing
  480. * Bug 25509: Improve the proxy help text
  481. * Bug 26466: Remove sv-SE from tracking for releases
  482. * Bug 27129+20628: Add locales ca, ga, id, is, nb, da, he, sv, and zh-TW
  483. * Translations update
  484. * Update HTTPS Everywhere to 2018.8.22
  485. * Update NoScript to 10.1.9.1
  486. * Update meek to 0.31
  487. * Bug 26477: Make meek extension compatible with ESR 60
  488. * Update obfs4proxy to v0.0.7 (bug 25356)
  489. * Bug 27082: Enable a limited UITour for user onboarding
  490. * Bug 26961: New user onboarding
  491. * Bug 26962: New feature onboarding
  492. * Bug 27403: The onboarding bubble is not always displayed
  493. * Bug 27283: Fix first-party isolation for UI tour
  494. * Bug 27213: Update about:tbupdate to new (about:tor) layout
  495. * Bug 14952+24553: Enable HTTP2 and AltSvc
  496. * Bug 25735: Tor Browser stalls while loading Facebook login page
  497. * Bug 17252: Enable TLS session identifiers with first-party isolation
  498. * Bug 26353: Prevent speculative connects that violate first-party isolation
  499. * Bug 26670: Make canvas permission prompt respect first-party isolation
  500. * Bug 24056: Use en-US strings in HTML forms if locale is spoofed to english
  501. * Bug 26456: HTTP .onion sites inherit previous page's certificate information
  502. * Bug 26561: .onion images are not displayed
  503. * Bug 26321: Move 'New Identity', 'New Circuit' to File, hamburger menus
  504. * Bug 26833: Backport Mozilla's bug 1473247
  505. * Bug 26628: Backport Mozilla's bug 1470156
  506. * Bug 26237: Clean up toolbar for ESR60-based Tor Browser
  507. * Bug 26519: Avoid Firefox icons in ESR60
  508. * Bug 26039: Load our preferences that modify extensions (fixup)
  509. * Bug 26515: Update Tor Browser blog post URLs
  510. * Bug 26216: Fix broken MAR file generation
  511. * Bug 26409: Remove spoofed locale implementation
  512. * Bug 25543: Rebase Tor Browser patches for ESR60
  513. * Bug 23247: Show security state of .onions
  514. * Bug 26039: Load our preferences that modify extensions
  515. * Bug 17965: Isolate HPKP and HSTS to URL bar domain
  516. * Bug 21787: Spoof en-US for date picker
  517. * Bug 21607: Disable WebVR for now until it is properly audited
  518. * Bug 21549: Disable wasm for now until it is properly audited
  519. * Bug 26614: Disable Web Authentication API until it is properly audited
  520. * Bug 27281: Enable Reader View mode again
  521. * Bug 26114: Don't expose navigator.mozAddonManager to websites
  522. * Bug 21850: Update about:tbupdate handling for e10s
  523. * Bug 26048: Fix potentially confusing "restart to update" message
  524. * Bug 27221: Purge startup cache if Tor Browser version changed
  525. * Bug 26049: Reduce delay for showing update prompt to 1 hour
  526. * Bug 26365: Add potential AltSvc support
  527. * Bug 9145: Fix broken hardware acceleration on Windows and enable it
  528. * Bug 26045: Add new MAR signing keys
  529. * Bug 25215: Revert bug 18619 (we are not disabling IndexedDB any longer)
  530. * Bug 19910: Rip out optimistic data socks handshake variant (#3875)
  531. * Bug 22564: Hide Firefox Sync
  532. * Bug 25090: Disable updater telemetry
  533. * Bug 26127: Make sure Torbutton and Tor Launcher are not treated as legacy extensions
  534. * Bug 13575: Disable randomised Firefox HTTP cache decay user tests
  535. * Bug 22548: Firefox downgrades VP9 videos to VP8 for some users
  536. * Bug 24995: Include git hash in tor --version
  537. * Bug 27268+27257+27262+26603 : Preferences clean-up
  538. * Bug 26073: Migrate general.useragent.locale to intl.locale.requested
  539. * Bug 27129+20628: Make Tor Browser available in ca, ga, id, is, nb, da, he, sv, and zh-TW
  540. * Bug 12927: Include Hebrew translation into Tor Browser
  541. * Bug 21245: Add danish (da) translation
  542. * Windows
  543. * Bug 20636+10026: Create 64bit Tor Browser for Windows
  544. * Bug 26239+24197: Enable content sandboxing for 64bit Windows builds
  545. * Bug 26514: Fix intermittent updater failures on Win64 (Error 19)
  546. * Bug 26874: Fix UNC path restrictions failure in Tor Browser 8.0a9
  547. * Bug 12968: Enable HEASLR in Windows x86_64 builds
  548. * Bug 26381: Work around endless loop during page load and about:tor not loading
  549. * Bug 27411: Fix broken security slider and NoScript interaction on Windows
  550. * Bug 22581: Fix shutdown crash
  551. * Bug 25266: PT config should include full names of executable files
  552. * Bug 26304: Update zlib to version 1.2.11
  553. * Update tbb-windows-installer to 0.4
  554. * Bug 26355: Update tbb-windows-installer to check for Windows7+
  555. * Bug 26355: Require Windows7+ for updates to Tor Browser 8
  556. * OS X
  557. * Bug 24136: After loading file:// URLs clicking on links is broken on OS X
  558. * Bug 24243: Tor Browser only renders HTML for local pages via file://
  559. * Bug 24263: Tor Browser does not run extension scripts if loaded via about:debugging
  560. * Bug 22794: Don't open AF_INET/AF_INET6 sockets when AF_LOCAL is configured
  561. * Linux
  562. * Bug 22794: Don't open AF_INET/AF_INET6 sockets when AF_LOCAL is configured
  563. * Bug 25485: Unbreak Tor Browser on systems with newer libstdc++
  564. * Bug 20866: Fix OpenGL software rendering on systems with newer libstdc++
  565. * Bug 26951+18022: Fix execdesktop argument passing
  566. * Bug 24136: After loading file:// URLs clicking on links is broken on Linux
  567. * Bug 24243: Tor Browser only renders HTML for local pages via file://
  568. * Bug 24263: Tor Browser does not run extension scripts if loaded via about:debugging
  569. * Bug 20283: Tor Browser should run without a `/proc` filesystem.
  570. * Bug 26354: Set SSE2 support as minimal requirement for Tor Browser 8
  571. * Build System
  572. * All Platforms
  573. * Bug 26362+26410: Use old MAR format for first ESR60-based stable
  574. * Bug 27020: RBM build fails with runc version 1.0.1
  575. * Bug 26949: Use GitHub repository for STIX
  576. * Bug 26773: Add --verbose to the ./mach build flag for firefox
  577. * Bug 26319: Don't package up Tor Browser in the `mach package` step
  578. * Bug 27178: Add support for xz compression in mar files
  579. * Clean up
  580. * Windows
  581. * Bug 26203: Adapt tor-browser-build/tor-browser for Windows
  582. * Bug 26204: Bundle d3dcompiler_47.dll for Tor Browser 8
  583. * Bug 26205: Don't build the uninstaller for Windows during Firefox compilation
  584. * Bug 26206: Ship pthread related dll where needed
  585. * Bug 26396: Build libwinpthread reproducible
  586. * Bug 25837: Integrate fxc2 into our build setup for Windows builds
  587. * Bug 27152: Use mozilla/fxc2.git for the fxc2 repository
  588. * Bug 25894: Get a rust cross-compiler for Windows
  589. * Bug 25554: Bump mingw-w64 version for ESR 60
  590. * Bug 23561: Fix nsis builds for Windows 64
  591. * Bug 13469: Windows installer is missing many languages from NSIS file
  592. * Bug 23231: Remove our STL Wrappers workaround for Windows 64bit
  593. * Bug 26370: Don't copy msvcr100.dll and libssp-0.dll twice
  594. * Bug 26476: Work around Tor Browser crashes due to fix for bug 1467041
  595. * Bug 18287: Use SHA-2 signature for Tor Browser setup executables
  596. * Bug 25420: Update GCC to 6.4.0
  597. * Bug 16472: Update Binutils to 2.26.1
  598. * Bug 20302: Fix FTE compilation for Windows with GCC 6.4.0
  599. * Bug 25111: Don't compile Yasm on our own anymore for Windows Tor Browser
  600. * Bug 18691: Switch Windows builds from precise to jessie
  601. * OS X
  602. * Bug 24632: Update macOS toolchain for ESR 60
  603. * Bug 9711: Build our own cctools for macOS cross-compilation
  604. * Bug 25548: Update macOS SDK for Tor Browser builds to 10.11
  605. * Bug 26003: Clean up our mozconfig-osx-x86_64 file
  606. * Bug 26195: Use new cctools in our macosx-toolchain project
  607. * Bug 25975: Get a rust cross-compiler for macOS
  608. * Bug 26475: Disable Stylo to make macOS build reproducible
  609. * Bug 26489: Fix .app directory name in tools/dmg2mar
  610. * Linux
  611. * Bug 26073: Patch tor-browser-build for transition to ESR 60
  612. * Bug 25481: Rust support for tor-browser and tor
  613. * Bug 25304: Update GCC to 6.4.0
  614. * Bug 16472: Update Binutils to 2.26.1
  615. Tor Browser 8.0a10 -- August 20 2018
  616. * All platforms
  617. * Update Tor to 0.3.4.6-rc
  618. * Update Torbutton to 2.0.2
  619. * Bug 26960: Implement new about:tor start page
  620. * Bug 26961: Implement new user onboarding
  621. * Bug 26321: Move 'New Identity', 'New Circuit' to File, hamburger menus
  622. * Bug 26590: Use new svg.disabled pref in security slider
  623. * Bug 26655: Adjust color and size of onion button
  624. * Bug 26500: Reposition circuit display relay icon for RTL locales
  625. * Bug 26409: Remove spoofed locale implementation
  626. * Bug 26189: Remove content-policy.js
  627. * Bug 26544: Images are not centered anymore
  628. * Bug 27129: Add locales ca, ga, id, is, nb
  629. * Translations update
  630. * Update Tor Launcher to 0.2.16.2
  631. * Bug 26985: Help button icons missing
  632. * Bug 25509: Improve the proxy help text
  633. * Bug 27129: Add locales ca, ga, id, is, nb
  634. * Translations update
  635. * Update NoScript to 10.1.8.16
  636. * Update meek to 0.31
  637. * Bug 26477: Make meek extension compatible with ESR 60
  638. * Bug 27082: Enable a limited UITour for user onboarding
  639. * Bug 26961: New user onboarding
  640. * Bug 14952+24553: Enable HTTP2 and AltSvc
  641. * Bug 25735: Tor Browser stalls while loading Facebook login page
  642. * Bug 17252: Enable TLS session identifiers with first-party isolation
  643. * Bug 26353: Prevent speculative connects that violate first-party isolation
  644. * Bug 24056: Use en-US strings in HTML forms if locale is spoofed to english
  645. * Bug 26456: HTTP .onion sites inherit previous page's certificate information
  646. * Bug 26321: Move 'New Identity', 'New Circuit' to File, hamburger menus
  647. * Bug 26833: Backport Mozilla's bug 1473247
  648. * Bug 26628: Backport Mozilla's bug 1470156
  649. * Bug 26237: Clean up toolbar for ESR60-based Tor Browser
  650. * Bug 26519: Avoid Firefox icons in ESR60
  651. * Bug 26039: Load our preferences that modify extensions (fixup)
  652. * Bug 26515: Update Tor Browser blog post URLs
  653. * Bug 27129: Add locales ca, ga, id, is, nb
  654. * Bug 26216: Fix broken MAR file generation
  655. * Bug 26409: Remove spoofed locale implementation
  656. * Bug 26603: Remove obsolete HTTP pipelining preferences
  657. * Windows
  658. * Bug 26514: Fix intermittent updater failures on Win64 (Error 19)
  659. * Bug 26874: Fix UNC path restrictions failure in Tor Browser 8.0a9
  660. * Bug 12968: Enable HEASLR in Windows x86_64 builds
  661. * Update tbb-windows-installer to 0.4
  662. * Bug 26355: Update tbb-windows-installer to check for Windows7+
  663. * Bug 26355: Require Windows7+ for updates to Tor Browser 8
  664. * OS X
  665. * Bug 26795: Bump snowflake to 6077141f4a for bug 25600
  666. * Linux
  667. * Bug 25485: Unbreak Tor Browser on systems with newer libstdc++
  668. * Bug 20866: Fix OpenGL software rendering on systems with newer libstdc++
  669. * Bug 26951+18022: Fix execdesktop argument passing
  670. * Bug 26795: Bump snowflake to 6077141f4a for bug 25600
  671. * Build System
  672. * All Platforms
  673. * Bug 26410: Stop using old MAR format in the alpha series
  674. * Bug 27020: RBM build fails with runc version 1.0.1
  675. * Bug 26949: Use GitHub repository for STIX
  676. * Bug 26773: Add --verbose to the ./mach build flag for firefox
  677. * Bug 26569: Redirect pre-8.0a9 alpha users to a separate update directory
  678. * Bug 26319: Don't package up Tor Browser in the `mach package` step
  679. * OS X
  680. * Bug 26489: Fix .app directory name in tools/dmg2mar
  681. * Windows
  682. * Bug 27152: Use mozilla/fxc2.git for the fxc2 repository
  683. Tor Browser 8.0a9 -- June 27 2018
  684. * All platforms
  685. * Update Firefox to 60.1.0esr
  686. * Update Tor to 0.3.4.2-alpha
  687. * Update Libevent to 2.1.8
  688. * Update Torbutton to 2.0.1
  689. * Bug 26100: Adapt Torbutton to Firefox 60 ESR
  690. * Bug 26430: New Torbutton icon
  691. * Bug 24309: Move circuit display to the identity popup
  692. * Bug 26128: Adapt security slider to the WebExtensions version of NoScript
  693. * Bug 23247: Show security state of .onions
  694. * Bug 26129: Show our about:tor page on startup
  695. * Bug 26235: Hide new unusable items from help menu
  696. * Bug 26058: Remove workaround for hiding 'sign in to sync' button
  697. * Bug 20628: Add locales da, he, sv, and zh-TW
  698. * Translations update
  699. * Update Tor Launcher to 0.2.16.1
  700. * Bug 25750: Update Tor Launcher to make it compatible with Firefox 60 ESR
  701. * Bug 20890: Increase control port connection timeout
  702. * Bug 26466: Remove sv-SE from tracking for releases
  703. * Bug 20628: Add more locales to Tor Browser
  704. * Translations update
  705. * Update HTTPS Everywhere to 2018.6.21
  706. * Update NoScript to 10.1.8.2
  707. * Bug 25543: Rebase Tor Browser patches for ESR60
  708. * Bug 23247: Show security state of .onions
  709. * Bug 26039: Load our preferences that modify extensions
  710. * Bug 17965: Isolate HPKP and HSTS to URL bar domain
  711. * Bug 26365: Add potential AltSvc support
  712. * Bug 9145: Fix broken hardware acceleration on Windows and enable it
  713. * Bug 26045: Add new MAR signing keys
  714. * Bug 22564: Hide Firefox Sync
  715. * Bug 25090: Disable updater telemetry
  716. * Bug 26127: Make sure Torbutton and Tor Launcher are not treated as legacy extensions
  717. * Bug 26073: Migrate general.useragent.locale to intl.locale.requested
  718. * Bug 20628: Make Tor Browser available in da, he, sv-SE, and zh-TW
  719. * Bug 12927: Include Hebrew translation into Tor Browser
  720. * Bug 21245: Add danish (da) translation
  721. * Windows
  722. * Bug 26239+24197: Enable content sandboxing for 64bit Windows builds
  723. * Bug 22581: Fix shutdown crash
  724. * Bug 26424: Disable UNC paths to prevent possible proxy bypasses
  725. * Bug 26304: Update zlib to version 1.2.11
  726. * OS X
  727. * Bug 24052: Backport fix for bug 1412081 for better file:// handling
  728. * Bug 24136: After loading file:// URLs clicking on links is broken on OS X
  729. * Bug 24243: Tor Browser only renders HTML for local pages via file://
  730. * Bug 24263: Tor Browser does not run extension scripts if loaded via about:debugging
  731. * Bug 24632: Disable snowflake for now until its build is fixed
  732. * Bug 26438: Remove broken seatbelt profiles
  733. * Linux
  734. * Bug 24052: Backport fix for bug 1412081 for better file:// handling
  735. * Bug 24136: After loading file:// URLs clicking on links is broken on Linux
  736. * Bug 24243: Tor Browser only renders HTML for local pages via file://
  737. * Bug 24263: Tor Browser does not run extension scripts if loaded via about:debugging
  738. * Bug 26153: Update selfrando to be compatible with Firefox 60 ESR
  739. * Bug 22242: Remove RUNPATH in Linux binaries embedded by selfrando
  740. * Bug 26354: Set SSE2 support as minimal requirement for Tor Browser 8
  741. * Build System
  742. * All Platforms
  743. * Bug 26362: Use old MAR format for first ESR60-based alpha
  744. * Clean up
  745. * Windows
  746. * Bug 26203: Adapt tor-browser-build/tor-browser for Windows
  747. * Bug 26204: Bundle d3dcompiler_47.dll for Tor Browser 8
  748. * Bug 26205: Don't build the uninstaller for Windows during Firefox compilation
  749. * Bug 26206: Ship pthread related dll where needed
  750. * Bug 26396: Build libwinpthread reproducible
  751. * Bug 25837: Integrate fxc2 into our build setup for Windows builds
  752. * Bug 25894: Get a rust cross-compiler for Windows
  753. * Bug 25554: Bump mingw-w64 version for ESR 60
  754. * Bug 23561: Fix nsis builds for Windows 64
  755. * Bug 13469: Windows installer is missing many languages from NSIS file
  756. * Bug 23231: Remove our STL Wrappers workaround for Windows 64bit
  757. * Bug 26370: Don't copy msvcr100.dll and libssp-0.dll twice
  758. * Bug 26476: Work around Tor Browser crashes due to fix for bug 1467041
  759. * Bug 18287: Use SHA-2 signature for Tor Browser setup executables
  760. * Bug 16472: Update Binutils to 2.26.1
  761. * OS X
  762. * Bug 24632: Update macOS toolchain for ESR 60
  763. * Bug 9711: Build our own cctools for macOS cross-compilation
  764. * Bug 25548: Update macOS SDK for Tor Browser builds to 10.11
  765. * Bug 26003: Clean up our mozconfig-osx-x86_64 file
  766. * Bug 26195: Use new cctools in our macosx-toolchain project
  767. * Bug 25975: Get a rust cross-compiler for macOS
  768. * Bug 26475: Disable Stylo to make macOS build reproducible
  769. * Linux
  770. * Bug 26073: Patch tor-browser-build for transition to ESR 60
  771. * Bug 25540: Stop building and distributing sandboxed tor browser
  772. * Bug 25481: Rust support for tor-browser and tor
  773. * Bug 16472: Update Binutils to 2.26.1
  774. Tor Browser 7.5.6 -- June 26 2018
  775. * All platforms
  776. * Update Firefox to 52.9.0esr
  777. * Update Tor to 0.3.3.7
  778. * Update Tor Launcher to 0.2.14.5
  779. * Bug 20890: Increase control port connection timeout
  780. * Update HTTPS Everywhere to 2018.6.21
  781. * Bug 26451: Prevent HTTPS Everywhere from freezing the browser
  782. * Update NoScript to 5.1.8.6
  783. * Bug 21537: Mark .onion cookies as secure
  784. * Bug 25938: Backport fix for cross-origin header leak (bug 1334776)
  785. * Bug 25721: Backport patches from Mozilla's bug 1448771
  786. * Bug 25147+25458: Sanitize HTML fragments for chrome documents
  787. * Bug 26221: Backport fix for leak in SHA256 in nsHttpConnectionInfo.cpp
  788. * Windows
  789. * Bug 26424: Disable UNC paths to prevent possible proxy bypasses
  790. Tor Browser 8.0a8 -- June 10 2018
  791. * All platforms
  792. * Update Firefox to 52.8.1esr
  793. * Bug 26098: Remove amazon-meek
  794. Tor Browser 7.5.5 -- June 10 2018
  795. * All platforms
  796. * Update Firefox to 52.8.1esr
  797. * Bug 26098: Remove amazon-meek
  798. Tor Browser 8.0a7 -- May 9 2018
  799. * All platforms
  800. * Update Firefox to 52.8.0esr
  801. * Update Tor Launcher to 0.2.15.2
  802. * Bug 25807: Change front domain to unbreak Moat
  803. * Translations update
  804. * Bug 25973: Backport off-by-one fix (bug 1352073)
  805. * Bug 25938: Backport fix for cross-origin header leak (bug 1334776)
  806. * Bug 25458: Fix broken UI customization
  807. * Bug 25898: Make Youtube videos play automatically again
  808. * Bug 25980: Improve backport of bug 1448771 (fixes broken Orfox build)
  809. * OS X
  810. * Bug 26010: Change Snowflake rendezvous to use the Azure domain front
  811. * Linux
  812. * Bug 26010: Change Snowflake rendezvous to use the Azure domain front
  813. Tor Browser 7.5.4 -- May 9 2018
  814. * All platforms
  815. * Update Firefox to 52.8.0esr
  816. * Update HTTPS Everywhere to 2018.4.11
  817. * Update NoScript to 5.1.8.5
  818. * Bug 23439: Exempt .onion domains from mixed content warnings
  819. * Bug 22614: Make e10s/non-e10s Tor Browsers indistinguishable
  820. * Bug 22659: Changes to `intl.accept.languages` get overwritten after restart
  821. * Bug 25973: Backport off-by-one fix (bug 1352073)
  822. * Bug 25020: Add a tbb_version.json file
  823. Tor Browser 8.0a6 -- April 19 2018
  824. * All platforms
  825. * Update Tor to 0.3.3.5-rc
  826. * Update OpenSSL to 1.0.2o
  827. * Update Torbutton to 1.9.9.1
  828. * Bug 25126: Make about:tor layout responsive
  829. * Translations update
  830. * Update HTTPS Everywhere to 2018.4.11
  831. * Update NoScript to 5.1.8.5
  832. * Bug 21537: Mark .onion cookies as secure
  833. * Bug 21850: Update about:tbupdate handling for e10s
  834. * Bug 25721: Backport patches from Mozilla's bug 1448771
  835. * Linux
  836. * Bug 20283: Tor Browser should run without a `/proc` filesystem.
  837. * Windows
  838. * Bug 13893: Make EMET compatible with Tor Browser
  839. * Build System
  840. * Windows
  841. * Bug 25420: Update GCC to 6.4.0
  842. * Bug 20302: Fix FTE compilation for Windows with GCC 6.4.0
  843. * Linux
  844. * Bug 25304: Update GCC to 6.4.0
  845. Tor Browser 8.0a5 -- March 27 2018
  846. * All platforms
  847. * Update Firefox to 52.7.3esr
  848. * Update HTTPS Everywhere to 2018.3.13
  849. * Bug 23439: Exempt .onion domains from mixed content warnings
  850. * OS X
  851. * Update Snowflake
  852. * Bug 21312+25579+25449: Fix crashes and memory/file descriptor leaks in go-webrtc
  853. * Linux
  854. * Update Snowflake
  855. * Bug 21312+25579+25449: Fix crashes and memory/file descriptor leaks in go-webrtc
  856. Tor Browser 7.5.3 -- March 26 2018
  857. * All platforms
  858. * Update Firefox to 52.7.3esr
  859. * Update HTTPS Everywhere to 2018.3.13
  860. * Bug 25339: Adapt build system for Python 3.6 based build procedure
  861. Tor Browser 8.0a4 -- March 17 2018
  862. * All platforms
  863. * Update Firefox to 52.7.2esr
  864. Tor Browser 7.5.2 -- March 17 2018
  865. * All platforms
  866. * Update Firefox to 52.7.2esr
  867. Tor Browser 8.0a3 -- March 13 2018
  868. * All platforms
  869. * Update Firefox to 52.7.0esr
  870. * Update Tor to 0.3.3.3-alpha
  871. * Update Tor Launcher to 0.2.15.1
  872. * Bug 23136: Moat integration (fetch bridges for the user)
  873. * Translations update
  874. * Update HTTPS Everywhere to 2018.2.26
  875. * Bug 25339: Adapt build system for Python 3.6 based build procedure
  876. * Bug 25356: Update obfs4proxy to v0.0.7
  877. * Bug 25147: Sanitize HTML fragments created for chrome-privileged documents
  878. * Windows
  879. * Bug 25112: No sandboxing on 64-bit Windows <= Vista
  880. Tor Browser 7.5.1 -- March 13 2018
  881. * All platforms
  882. * Update Firefox to 52.7.0esr
  883. * Update Tor to 0.3.2.10
  884. * Update Torbutton to 1.9.8.6
  885. * Bug 24159: Version check does not deal with platform specific checks
  886. * Bug 25016: Remove 2017 donation banner
  887. * Translations update
  888. * Update Tor Launcher to 0.2.14.4
  889. * Bug 25089: Special characters are not escaped in proxy password
  890. * Translations update
  891. * Update NoScript to 5.1.8.4
  892. * Bug 25356: Update obfs4proxy to v0.0.7
  893. * Bug 25000: Add [System+Principal] to the NoScript whitelist
  894. * Windows
  895. * Bug 25112: Disable sandboxing on 64-bit Windows <= Vista
  896. Tor Browser 8.0a2 -- February 23 2018
  897. * All Platforms
  898. * Update Tor to 0.3.3.2-alpha
  899. * Update Torbutton to 1.9.9
  900. * Bug 24159: Version check does not deal with platform specific checks
  901. * Bug 25016: Remove 2017 donation banner
  902. * Translations update
  903. * Update Tor Launcher to 0.2.15
  904. * Bug 25089: Special characters are not escaped in proxy password
  905. * Translations update
  906. * Update HTTPS Everywhere to 2018.1.29
  907. * Update NoScript to 5.1.8.4
  908. * Update meek to 0.29
  909. * Bug 25215: Revert bug 18619 (we are not disabling IndexedDB any longer)
  910. * Bug 19910: Rip out optimistic data socks handshake variant (#3875)
  911. * Bug 22659: Changes to `intl.accept.languages` get overwritten after restart
  912. * Bug 25000: Add [System+Principal] to the NoScript whitelist
  913. * Bug 15599: Disable Range requests used by pdfjs as they are not isolated
  914. * Bug 22614: Make e10s/non-e10s Tor Browsers indistinguishable
  915. * Bug 13575: Disable randomised Firefox HTTP cache decay user tests
  916. * Bug 25020: Add a tbb_version.json file
  917. * Bug 24995: Include git hash in tor --version
  918. * OS X
  919. * Bug 22794: Don't open AF_INET/AF_INET6 sockets when AF_LOCAL is configured
  920. * Linux
  921. * Bug 22794: Don't open AF_INET/AF_INET6 sockets when AF_LOCAL is configured
  922. * Windows:
  923. * Bug 25266: PT config should include full names of executable files
  924. * Build System
  925. * Windows
  926. * Bug 25111: Don't compile Yasm on our own anymore for Windows Tor Browser
  927. Tor Browser 8.0a1 -- January 23 2018
  928. * All Platforms
  929. * Update Firefox to 52.6.0esr
  930. * Update Tor to 0.3.2.9
  931. * Update Torbutton to 1.9.8.5
  932. * Bug 21245: Add da translation to Torbutton and keep track of it
  933. * Bug 24702: Remove Mozilla text from banner
  934. * Translations update
  935. * Update Tor Launcher to 0.2.14.3
  936. * Translations update
  937. * Update HTTPS Everywhere to 2018.1.11
  938. * Bug 24756: Add noisebridge01 obfs4 bridge configuration
  939. * Bug 23916: Add new MAR signing key
  940. * Bug 22548: Firefox downgrades VP9 videos to VP8 for some users
  941. * Windows
  942. * Bug 24197: Fix win64 sandbox compile issues
  943. * Build System
  944. * Windows
  945. * Bug 18691: switch Windows builds from precise to jessie
  946. * Linux
  947. * Bug 23892: Include Firefox and Tor debug files in final build directory
  948. * Bug 24842: include libasan.so.2 and libubsan.so.0 in debug builds
  949. Tor Browser 7.5 -- January 23 2018
  950. * All Platforms
  951. * Update Firefox to 52.6.0esr
  952. * Update Tor to 0.3.2.9
  953. * Update OpenSSL to 1.0.2n
  954. * Update Torbutton to 1.9.8.5
  955. * Bug 21847: Update copy for security slider
  956. * Bug 21245: Add da translation to Torbutton and keep track of it
  957. * Bug 24702: Remove Mozilla text from banner
  958. * Bug 10573: Replace deprecated nsILocalFile with nsIFile (code clean-up)
  959. * Translations update
  960. * Update Tor Launcher to 0.2.14.3
  961. * Bug 23262: Implement integrated progress bar
  962. * Bug 23261: implement configuration portion of new Tor Launcher UI
  963. * Bug 24623: Revise "country that censors Tor" text
  964. * Bug 24624: tbb-logo.svg may cause network access
  965. * Bug 23240: Retrieve current bootstrap progress before showing progress bar
  966. * Bug 24428: Bootstrap error message sometimes lost
  967. * Bug 22232: Add README on use of bootstrap status messages
  968. * Bug 10573: Replace deprecated nsILocalFile with nsIFile (code clean-up)
  969. * Translations update
  970. * Update HTTPS Everywhere to 2018.1.11
  971. * Update NoScript to 5.1.8.3
  972. * Bug 23104: CSS line-height reveals the platform Tor Browser is running on
  973. * Bug 24398: Plugin-container process exhausts memory
  974. * Bug 22501: Requests via javascript: violate FPI
  975. * Bug 24756: Add noisebridge01 obfs4 bridge configuration
  976. * Windows
  977. * Bug 16010: Enable content sandboxing on Windows
  978. * Bug 23230: Fix build error on Windows 64
  979. * OS X
  980. * Bug 24566: Avoid white flashes when opening dialogs in Tor Browser
  981. * Bug 23025: Add some hardening flags to macOS build
  982. * Linux
  983. * Bug 23970: Make "Print to File" work with sandboxing enabled
  984. * Bug 23016: "Print to File" is broken on some non-english Linux systems
  985. * Bug 10089: Set middlemouse.contentLoadURL to false by default
  986. * Bug 18101: Suppress upload file dialog proxy bypass (linux part)
  987. * Android
  988. * Bug 22084: Spoof network information API
  989. * Build System
  990. * All Platforms
  991. * Switch from gitian/tor-browser-bundle to rbm/tor-browser-build
  992. * Windows
  993. * Bug 22563: Update mingw-w64 to fix W^X violations
  994. * Bug 20929: Bump GCC version to 5.4.0
  995. * Linux
  996. * Bug 20929: Bump GCC version to 5.4.0
  997. * Bug 23892: Include Firefox and Tor debug files in final build directory
  998. * Bug 24842: include libasan.so.2 and libubsan.so.0 in debug builds
  999. Tor Browser 7.5a10 -- December 19 2017
  1000. * All Platforms
  1001. * Update Tor to 0.3.2.7-rc
  1002. * Update OpenSSL to 1.0.2n
  1003. * Update Torbutton to 1.9.8.4
  1004. * Bug 21847: Update copy for security slider
  1005. * Bug 10573: Replace deprecated nsILocalFile with nsIFile (code clean-up)
  1006. * Translations update
  1007. * Update Tor Launcher to 0.2.14.2
  1008. * Bug 24623: Revise "country that censors Tor" text
  1009. * Bug 24428: Bootstrap error message sometimes lost
  1010. * Bug 24624: tbb-logo.svg may cause network access
  1011. * Bug 10573: Replace deprecated nsILocalFile with nsIFile (code clean-up)
  1012. * Translations update
  1013. * Update NoScript to 5.1.8.3
  1014. * Bug 23104: CSS line-height reveals the platform Tor Browser is running on
  1015. * Bug 24398: Plugin-container process exhausts memory
  1016. * OS X
  1017. * Bug 24566: Avoid white flashes when opening dialogs in Tor Browser
  1018. * Linux
  1019. * Bug 23970: Make "Print to File" work with sandboxing enabled
  1020. * Bug 23016: "Print to File" is broken on some non-english Linux systems
  1021. * Android
  1022. * Bug 22084: Spoof network information API
  1023. Tor Browser 7.5a9 -- December 09 2017
  1024. * All Platforms
  1025. * Update Firefox to 52.5.2esr
  1026. * Update Tor to 0.3.2.6-alpha
  1027. * Update HTTPS-Everywhere to 2017.12.6
  1028. * Update NoScript to 5.1.8.1
  1029. * Update sandboxed-tor-browser to 0.0.16
  1030. Tor Browser 7.0.11 -- December 09 2017
  1031. * All Platforms
  1032. * Update Firefox to 52.5.2esr
  1033. * Update Tor to 0.3.1.9
  1034. * Update HTTPS-Everywhere to 2017.12.6
  1035. * Update NoScript to 5.1.8.1
  1036. Tor Browser 7.5a8 -- November 15 2017
  1037. * All Platforms
  1038. * Update Firefox to 52.5.0esr
  1039. * Update Tor to 0.3.2.4-alpha
  1040. * Update Torbutton to 1.9.8.3
  1041. * Bug 23997: Add link to Tor Browser manual for de, nl, tr, vi
  1042. * Bug 23949: Fix donation banner display
  1043. * Update locales with translated banner
  1044. * Translations update
  1045. * Update Tor Launcher to 0.2.14.1
  1046. * Bug 23262: Implement integrated progress bar
  1047. * Bug 23261: implement configuration portion of new Tor Launcher UI
  1048. * Translations update
  1049. * Update HTTPS-Everywhere to 2017.10.30
  1050. * Update NoScript to 5.1.5
  1051. * Bug 23968: NoScript icon jumps to the right after update
  1052. * Update sandboxed-tor-browser to 0.0.15
  1053. * Windows
  1054. * Bug 20636+10026: Create 64bit Tor Browser for Windows
  1055. * Bug 24052: Block file:// redirects early
  1056. Tor Browser 7.0.10 -- November 14 2017
  1057. * All Platforms
  1058. * Update Firefox to 52.5.0esr
  1059. * Update Tor to 0.3.1.8
  1060. * Update Torbutton to 1.9.7.10
  1061. * Bug 23997: Add link to Tor Browser manual for de, nl, tr, vi
  1062. * Translations update
  1063. * Update HTTPS-Everywhere to 2017.10.30
  1064. * Bug 24178: Use make.sh for building HTTPS-Everywhere
  1065. * Update NoScript to 5.1.5
  1066. * Bug 23968: NoScript icon jumps to the right after update
  1067. * Windows
  1068. * Bug 23582: Enable the Windows DLL blocklist for mingw-w64 builds
  1069. * Bug 23396: Update the msvcr100.dll we ship
  1070. * Bug 24052: Block file:// redirects early
  1071. Tor Browser 7.5a7 -- November 4 2017
  1072. * OS X
  1073. * Bug 24052: Streamline handling of file:// resources
  1074. * Linux
  1075. * Bug 24052: Streamline handling of file:// resources
  1076. Tor Browser 7.0.9 -- November 3 2017
  1077. * OS X
  1078. * Bug 24052: Streamline handling of file:// resources
  1079. * Linux
  1080. * Bug 24052: Streamline handling of file:// resources
  1081. Tor Browser 7.0.8 -- October 25 2017
  1082. * All Platforms
  1083. * Update Torbutton to 1.9.7.9
  1084. * Bug 23949: Fix donation banner display
  1085. * Update locales with translated banner
  1086. * Translations update
  1087. Tor Browser 7.5a6 -- October 19 2017
  1088. * All Platforms
  1089. * Update Firefox to 52.4.1esr
  1090. * Update Tor to 0.3.2.2-alpha
  1091. * Update Torbutton to 1.9.8.2
  1092. * Bug 23887: Update banner locales and Mozilla text
  1093. * Translations update
  1094. * Update HTTPS-Everywhere to 2017.10.4
  1095. * Update NoScript to 5.1.2
  1096. * Bug 23723: Loading entities from NoScript .dtd files is blocked
  1097. * Bug 23724: NoScript update breaks Security Slider and its icon disappears
  1098. * Update sandboxed-tor-browser to 0.0.14
  1099. * Bug 23745: Tab crashes when using Tor Browser to access Google Drive
  1100. * Bug 23694: Update the detailsURL in update responses
  1101. * Bug 22501: Requests via javascript: violate FPI
  1102. * OS X
  1103. * Bug 23807: Tab crashes when playing video on High Sierra
  1104. * Bug 23025: Add some hardening flags to macOS build
  1105. Tor Browser 7.0.7 -- October 19 2017
  1106. * All Platforms
  1107. * Update Firefox to 52.4.1esr
  1108. * Update Torbutton to 1.9.7.8
  1109. * Bug 23887: Update banner locales and Mozilla text
  1110. * Bug 23526: Add 2017 Donation banner text
  1111. * Bug 23483: Donation banner on about:tor for 2017 (testing mode)
  1112. * Bug 22610: Avoid crashes when canceling external helper app related downloads
  1113. * Bug 22472: Fix FTP downloads when external helper app dialog is shown
  1114. * Bug 22471: Downloading pdf files via the PDF viewer download button is broken
  1115. * Bug 22618: Downloading pdf file via file:/// is stalling
  1116. * Translations update
  1117. * Update HTTPS-Everywhere to 2017.10.4
  1118. * Update NoScript to 5.1.2
  1119. * Bug 23723: Loading entities from NoScript .dtd files is blocked
  1120. * Bug 23724: NoScript update breaks Security Slider and its icon disappears
  1121. * Bug 23745: Tab crashes when using Tor Browser to access Google Drive
  1122. * Bug 22610: Avoid crashes when canceling external helper app related downloads
  1123. * Bug 22472: Fix FTP downloads when external helper app dialog is shown
  1124. * Bug 22471: Downloading pdf files via the PDF viewer download button is broken
  1125. * Bug 22618: Downloading pdf file via file:/// is stalling
  1126. * Bug 23694: Update the detailsURL in update responses
  1127. * OS X
  1128. * Bug 23807: Tab crashes when playing video on High Sierra
  1129. * Linux
  1130. * Bug 22692: Enable content sandboxing on Linux
  1131. Tor Browser 7.5a5 -- September 28 2017
  1132. * All Platforms
  1133. * Update Firefox to 52.4.0esr
  1134. * Update Tor to 0.3.2.1-alpha
  1135. * Update Torbutton to 1.9.8.1
  1136. * Bug 20375: Warn users after entering fullscreen mode
  1137. * Bug 22989: Fix dimensions of new windows on macOS
  1138. * Bug 23526: Add 2017 Donation banner text
  1139. * Bug 23483: Donation banner on about:tor for 2017 (testing mode)
  1140. * Translations update
  1141. * Update Tor Launcher to 0.2.13
  1142. * Bug 23240: Retrieve current bootstrap progress before showing progress bar
  1143. * Bug 22232: Add README on use of bootstrap status messages
  1144. * Translations update
  1145. * Update HTTPS-Everywhere to 2017.9.12
  1146. * Update NoScript to 5.0.10
  1147. * Update sandboxed-tor-browser to 0.0.13
  1148. * Bug 23393: Don't crash all tabs when closing one tab
  1149. * Bug 23166: Add new obfs4 bridge to the built-in ones
  1150. * Bug 23258: Fix broken HTTPS-Everywhere on higher security levels
  1151. * Bug 21270: NoScript settings break WebExtensions add-ons
  1152. * Bug 23104: CSS line-height reveals the platform Tor Browser is running on
  1153. * Windows
  1154. * Bug 16010: Enable content sandboxing on Windows
  1155. * Bug 23582: Enable the Windows DLL blocklist for mingw-w64 builds
  1156. * Bug 23396: Update the msvcr100.dll we ship
  1157. * Bug 23230: Fix build error on Windows 64
  1158. * OS X
  1159. * Bug 23404: Add missing Noto Sans Buginese font to the macOS whitelist
  1160. * Linux
  1161. * Bug 10089: Set middlemouse.contentLoadURL to false by default
  1162. * Bug 22692: Enable content sandboxing on Linux
  1163. * Bug 18101: Suppress upload file dialog proxy bypass (linux part)
  1164. * Build System
  1165. * All Platforms
  1166. * Switch from gitian/tor-browser-bundle to rbm/tor-browser-build
  1167. Tor Browser 7.0.6 -- September 28 2017
  1168. * All Platforms
  1169. * Update Firefox to 52.4.0esr
  1170. * Update Tor to 0.3.1.7
  1171. * Update Torbutton to 1.9.7.7
  1172. * Bug 22542: Security Settings window too small on macOS 10.12 (fixup)
  1173. * Bug 20375: Warn users after entering fullscreen mode
  1174. * Update HTTPS-Everywhere to 2017.9.12
  1175. * Update NoScript to 5.0.10
  1176. * Bug 21830: Copying large text from web console leaks to /tmp
  1177. * Bug 23393: Don't crash all tabs when closing one tab
  1178. * OS X
  1179. * Bug 23404: Add missing Noto Sans Buginese font to the macOS whitelist
  1180. Tor Browser 7.0.5 -- September 4 2017
  1181. * All Platforms
  1182. * Update Torbutton to 1.9.7.6
  1183. * Bug 22989: Fix dimensions of new windows on macOS
  1184. * Translations update
  1185. * Update HTTPS-Everywhere to 2017.8.31
  1186. * Update NoScript to 5.0.9
  1187. * Bug 23166: Add new obfs4 bridge to the built-in ones
  1188. * Bug 23258: Fix broken HTTPS-Everywhere on higher security levels
  1189. * Bug 21270: NoScript settings break WebExtensions add-ons
  1190. Tor Browser 7.5a4 -- August 9 2017
  1191. * All Platforms
  1192. * Update Firefox to 52.3.0esr
  1193. * Update Tor to 0.3.1.5-alpha
  1194. * Update OpenSSL to 1.0.2l
  1195. * Update Torbutton to 1.9.8
  1196. * Bug 22610: Avoid crashes when canceling external helper app related downloads
  1197. * Bug 22472: Fix FTP downloads when external helper app dialog is shown
  1198. * Bug 22471: Downloading pdf files via the PDF viewer download button is broken
  1199. * Bug 22618: Downloading pdf file via file:/// is stalling
  1200. * Bug 22542: Resize slider window to work without scrollbars
  1201. * Bug 21999: Fix display of language prompt in non-en-US locales
  1202. * Bug 18913: Don't let about:tor have chrome privileges
  1203. * Bug 22535: Search on about:tor discards search query
  1204. * Bug 21948: Going back to about:tor page gives "Address isn't valid" error
  1205. * Code clean-up
  1206. * Translations update
  1207. * Update Tor Launcher to 0.2.12.3
  1208. * Bug 22592: Default bridge settings are not removed
  1209. * Translations update
  1210. * Update HTTPS-Everywhere to 5.2.21
  1211. * Update NoScript to 5.0.8.1
  1212. * Bug 22362: Remove workaround for XSS related browser freezing
  1213. * Bug 22067: NoScript Click-to-Play bypass with embedded videos and audio
  1214. * Update sandboxed-tor-browser to 0.0.12
  1215. * Bug 22610: Avoid crashes when canceling external helper app related downloads
  1216. * Bug 22472: Fix FTP downloads when external helper app dialog is shown
  1217. * Bug 22471: Downloading pdf files via the PDF viewer download button is broken
  1218. * Bug 22618: Downloading pdf file via file:/// is stalling
  1219. * Bug 21321: Exempt .onions from HTTP related security warnings
  1220. * Bug 21830: Copying large text from web console leaks to /tmp
  1221. * Bug 22073: Disable GetAddons option on addons page
  1222. * Bug 22884: Fix broken about:tor page on higher security levels
  1223. * Bug 22829: Remove default obfs4 bridge riemann.
  1224. * Windows
  1225. * Bug 21617: Fix single RWX page on Windows (included in 52.3.0esr)
  1226. * OS X
  1227. * Bug 22831: Enable Snowflake for mac
  1228. * Linux
  1229. * Bug 22832: Don't include monthly timestamp in libwebrtc build output
  1230. * Bug 20848: Deploy Selfrando in 32bit Linux builds
  1231. * Build system
  1232. * Windows
  1233. * Bug 22563: Update mingw-w64 to fix W^X violations
  1234. * Bug 20929: Bump GCC version to 5.4.0
  1235. * Linux
  1236. * Bug 20929: Bump GCC version to 5.4.0
  1237. Tor Browser 7.0.4 -- August 8 2017
  1238. * All Platforms
  1239. * Update Firefox to 52.3.0esr
  1240. * Update Tor to 0.3.0.10
  1241. * Update Torbutton to 1.9.7.5
  1242. * Bug 21999: Fix display of language prompt in non-en-US locales
  1243. * Bug 18913: Don't let about:tor have chrome privileges
  1244. * Bug 22535: Search on about:tor discards search query
  1245. * Bug 21948: Going back to about:tor page gives "Address isn't valid" error
  1246. * Code clean-up
  1247. * Translations update
  1248. * Update Tor Launcher to 0.2.12.3
  1249. * Bug 22592: Default bridge settings are not removed
  1250. * Translations update
  1251. * Update HTTPS-Everywhere to 5.2.21
  1252. * Update NoScript to 5.0.8.1
  1253. * Bug 22362: Remove workaround for XSS related browser freezing
  1254. * Bug 22067: NoScript Click-to-Play bypass with embedded videos and audio
  1255. * Bug 21321: Exempt .onions from HTTP related security warnings
  1256. * Bug 22073: Disable GetAddons option on addons page
  1257. * Bug 22884: Fix broken about:tor page on higher security levels
  1258. * Windows
  1259. * Bug 22829: Remove default obfs4 bridge riemann.
  1260. * Bug 21617: Fix single RWX page on Windows (included in 52.3.0esr)
  1261. * OS X
  1262. * Bug 22829: Remove default obfs4 bridge riemann.
  1263. Tor Browser 7.5a3 -- July 28 2017
  1264. * Linux
  1265. * Bug 23044: Don't allow GIO supported protocols by default
  1266. Tor Browser 7.0.3 -- July 27 2017
  1267. * Linux
  1268. * Bug 23044: Don't allow GIO supported protocols by default
  1269. * Bug 22829: Remove default obfs4 bridge riemann.
  1270. Tor Browser 7.5a2 -- July 6 2017
  1271. * All Platforms
  1272. * Update Tor to 0.3.1.4-alpha
  1273. * Update HTTPS-Everywhere to 5.2.19
  1274. * Linux
  1275. * Update sandboxed-tor-browser to 0.0.9
  1276. Tor Browser 7.0.2 -- July 3 2017
  1277. * All Platforms
  1278. * Update Tor to 0.3.0.9, fixing bug #22753
  1279. * Update HTTPS-Everywhere to 5.2.19
  1280. Tor Browser 7.5a1 -- June 14 2017
  1281. * All Platforms
  1282. * Update Firefox to 52.2.0esr
  1283. * Update Tor to 0.3.1.3-alpha
  1284. * Update Torbutton to 1.9.7.4
  1285. * Bug 22542: Security Settings window too small on macOS 10.12
  1286. * Bug 22104: Adjust our content policy whitelist for ff52-esr
  1287. * Bug 22457: Allow resources loaded by view-source://
  1288. * Bug 21627: Ignore HTTP 304 responses when checking redirects
  1289. * Bug 22459: Adapt our use of the nsIContentPolicy to e10s mode
  1290. * Translations update
  1291. * Update Tor Launcher to 0.2.12.2
  1292. * Bug 22283: Linux 7.0a4 is broken after update due to unix: lines in torrc
  1293. * Translations update
  1294. * Update HTTPS-Everywhere to 5.2.18
  1295. * Update NoScript to 5.0.5
  1296. * Update sandboxed-tor-browser to 0.0.7
  1297. * Bug 22362: NoScript's XSS filter freezes the browser
  1298. * Bug 21766: Fix crash when the external application helper dialog is invoked
  1299. * Bug 21886: Download is stalled in non-e10s mode
  1300. * Bug 22333: Disable WebGL2 API for now
  1301. * Bug 21861: Disable additional mDNS code to avoid proxy bypasses
  1302. * Bug 21684: Don't expose navigator.AddonManager to content
  1303. * Bug 21431: Clean-up system extensions shipped in Firefox 52
  1304. * Bug 22320: Use preference name 'referer.hideOnionSource' everywhere
  1305. * Bug 16285: Don't ship ClearKey EME system and update EME preferences
  1306. * Bug 21972: about:support is partially broken
  1307. * Bug 21323: Enable Mixed Content Blocking
  1308. * Bug 22415: Fix format error in our pipeline patch
  1309. * Bug 21862: Rip out potentially unsafe Rust code
  1310. * Bug 16485: Improve about:cache page
  1311. * Bug 22462: Backport of patch for bug 1329521 to fix assertion failure
  1312. * Bug 22458: Fix broken `about:cache` page on higher security levels
  1313. * Bug 18531: Uncaught exception when opening ip-check.info
  1314. * Bug 18574: Uncaught exception when clicking items in Library
  1315. * Bug 22327: Isolate Page Info media previews to first party domain
  1316. * Bug 22452: Isolate tab list menuitem favicons to first party domain
  1317. * Bug 15555: View-source requests are not isolated by first party domain
  1318. * Bug 5293: Neuter fingerprinting with Battery API
  1319. * Bug 22429: Add IPv6 address for Lisbeth:443 obfs4 bridge
  1320. * Bug 22468: Add default obfs4 bridges frosty and dragon
  1321. * Windows
  1322. * Bug 22419: Prevent access to file://
  1323. * Bug 21617: Fix single RWX page on Windows
  1324. * OS X
  1325. * Bug 22558: Don't update OS X 10.7.x and 10.8.x users to Tor Browser 7.0
  1326. * Linux
  1327. * Bug 16285: Remove ClearKey related library stripping
  1328. * Bug 21852: Don't use jemalloc4 anymore
  1329. * Android
  1330. * Bug 19078: Disable RtspMediaResource stuff in Orfox
  1331. Tor Browser 7.0.1 -- June 13 2017
  1332. * All Platforms
  1333. * Update Firefox to 52.2.0esr
  1334. * Update Tor to 0.3.0.8
  1335. * Update Torbutton to 1.9.7.4
  1336. * Bug 22542: Security Settings window too small on macOS 10.12
  1337. * Update HTTPS-Everywhere to 5.2.18
  1338. * Bug 22362: NoScript's XSS filter freezes the browser
  1339. * OS X
  1340. * Bug 22558: Don't update OS X 10.7.x and 10.8.x users to Tor Browser 7.0
  1341. Tor Browser 7.0 -- June 7 2017
  1342. * All Platforms
  1343. * Update Firefox to 52.1.2esr
  1344. * Update Tor to 0.3.0.7
  1345. * Update Torbutton to 1.9.7.3
  1346. * Bug 22104: Adjust our content policy whitelist for ff52-esr
  1347. * Bug 22457: Allow resources loaded by view-source://
  1348. * Bug 21627: Ignore HTTP 304 responses when checking redirects
  1349. * Bug 22459: Adapt our use of the nsIContentPolicy to e10s mode
  1350. * Bug 21865: Update our JIT preferences in the security slider
  1351. * Bug 21747: Make 'New Tor Circuit for this Site' work in ESR52
  1352. * Bug 21745: Fix handling of catch-all circuit
  1353. * Bug 21547: Fix circuit display under e10s
  1354. * Bug 21268: e10s compatibility for New Identity
  1355. * Bug 21267: Remove window resize implementation for now
  1356. * Bug 21201: Make Torbutton multiprocess compatible
  1357. * Translations update
  1358. * Update Tor Launcher to 0.2.12.2
  1359. * Bug 22283: Linux 7.0a4 broken after update due to unix: lines in torrc
  1360. * Bug 20761: Don't ignore additional SocksPorts
  1361. * Bug 21920: Don't show locale selection dialog
  1362. * Bug 21546: Mark Tor Launcher as multiprocess compatible
  1363. * Bug 21264: Add a README file
  1364. * Translations update
  1365. * Update HTTPS-Everywhere to 5.2.17
  1366. * Update NoScript to 5.0.5
  1367. * Update Go to 1.8.3 (bug 22398)
  1368. * Bug 21962: Fix crash on about:addons page
  1369. * Bug 21766: Fix crash when the external application helper dialog is invoked
  1370. * Bug 21886: Download is stalled in non-e10s mode
  1371. * Bug 21778: Canvas prompt is not shown in Tor Browser based on ESR52
  1372. * Bug 21569: Add first-party domain to Permissions key
  1373. * Bug 22165: Don't allow collection of local IP addresses
  1374. * Bug 13017: Work around audio fingerprinting by disabling the Web Audio API
  1375. * Bug 10286: Disable Touch API and add fingerprinting resistance as fallback
  1376. * Bug 13612: Disable Social API
  1377. * Bug 10283: Disable SpeechSynthesis API
  1378. * Bug 22333: Disable WebGL2 API for now
  1379. * Bug 21861: Disable additional mDNS code to avoid proxy bypasses
  1380. * Bug 21684: Don't expose navigator.AddonManager to content
  1381. * Bug 21431: Clean-up system extensions shipped in Firefox 52
  1382. * Bug 22320: Use preference name 'referer.hideOnionSource' everywhere
  1383. * Bug 16285: Don't ship ClearKey EME system and update EME preferences
  1384. * Bug 21675: Spoof window.navigator.hardwareConcurrency
  1385. * Bug 21792: Suppress MediaError.message
  1386. * Bug 16337: Round times exposed by Animation API to nearest 100ms
  1387. * Bug 21972: about:support is partially broken
  1388. * Bug 21726: Keep Graphite support disabled
  1389. * Bug 21323: Enable Mixed Content Blocking
  1390. * Bug 21685: Disable remote new tab pages
  1391. * Bug 21790: Disable captive portal detection
  1392. * Bug 21686: Disable Microsoft Family Safety support
  1393. * Bug 22073: Make sure Mozilla's experiments are disabled
  1394. * Bug 21683: Disable newly added Safebrowsing capabilities
  1395. * Bug 22071: Disable Kinto-based blocklist update mechanism
  1396. * Bug 22415: Fix format error in our pipeline patch
  1397. * Bug 22072: Hide TLS error reporting checkbox
  1398. * Bug 20761: Don't ignore additional SocksPorts
  1399. * Bug 21862: Rip out potentially unsafe Rust code
  1400. * Bug 16485: Improve about:cache page
  1401. * Bug 22462: Backport of patch for bug 1329521 to fix assertion failure
  1402. * Bug 21340: Identify and backport new patches from Firefox
  1403. * Bug 22153: Fix broken feeds on higher security levels
  1404. * Bug 22025: Fix broken certificate error pages on higher security levels
  1405. * Bug 21887: Fix broken error pages on higher security levels
  1406. * Bug 22458: Fix broken `about:cache` page on higher security levels
  1407. * Bug 21876: Enable e10s by default on all supported platforms
  1408. * Bug 21876: Always use esr policies for e10s
  1409. * Bug 20905: Fix resizing issues after moving to a direct Firefox patch
  1410. * Bug 21875: Modal dialogs are maximized in ESR52 nightly builds
  1411. * Bug 21885: SVG is not disabled in Tor Browser based on ESR52
  1412. * Bug 17334: Hide Referer when leaving a .onion domain (improved patch)
  1413. * Bug 18531: Uncaught exception when opening ip-check.info
  1414. * Bug 18574: Uncaught exception when clicking items in Library
  1415. * Bug 22327: Isolate Page Info media previews to first party domain
  1416. * Bug 22452: Isolate tab list menuitem favicons to first party domain
  1417. * Bug 15555: View-source requests are not isolated by first party domain
  1418. * Bug 3246: Double-key cookies
  1419. * Bug 8842: Fix XML parsing error
  1420. * Bug 5293: Neuter fingerprinting with Battery API
  1421. * Bug 16886: 16886: "Add-on compatibility check dialog" contains Firefox logo
  1422. * Bug 19645: TBB zooms text when resizing browser window
  1423. * Bug 19192: Untrust Blue Coat CA
  1424. * Bug 19955: Avoid confusing warning that favicon load request got cancelled
  1425. * Bug 20005: Backport fixes for memory leaks investigation
  1426. * Bug 20755: ltn.com.tw is broken in Tor Browser
  1427. * Bug 21896: Commenting on website is broken due to CAPTCHA not being displayed
  1428. * Bug 20680: Rebase Tor Browser patches to 52 ESR
  1429. * Bug 22429: Add IPv6 address for Lisbeth:443 obfs4 bridge
  1430. * Bug 22468: Add default obfs4 bridges frosty and dragon
  1431. * Windows
  1432. * Bug 22419: Prevent access to file://
  1433. * Bug 12426: Make use of HeapEnableTerminationOnCorruption
  1434. * Bug 19316: Make sure our Windows updates can deal with the SSE2 requirement
  1435. * Bug 21868: Fix build bustage with FIREFOX_52_0_2esr_RELEASE for Windows
  1436. * OS X
  1437. * Bug 21940: Don't allow privilege escalation during update
  1438. * Bug 22044: Fix broken default search engine on macOS
  1439. * Bug 21879: Use our default bookmarks on OSX
  1440. * Bug 21779: Non-admin users can't access Tor Browser on macOS
  1441. * Bug 21723: Fix inconsistent generation of MOZ_MACBUNDLE_ID
  1442. * Bug 21724: Make Firefox and Tor Browser distinct macOS apps
  1443. * Bug 21931: Backport OSX SetupMacCommandLine updater fixes
  1444. * Bug 15910: Don't download GMPs via the local fallback
  1445. * Linux
  1446. * Bug 16285: Remove ClearKey related library stripping
  1447. * Bug 22041: Fix update error during update to 7.0a3
  1448. * Bug 22238: Fix use of hardened wrapper for Firefox build
  1449. * Bug 21907: Fix runtime error on CentOS 6
  1450. * Bug 15910: Don't download GMPs via the local fallback
  1451. * Android
  1452. * Bug 19078: Disable RtspMediaResource stuff in Orfox
  1453. * Build system
  1454. * Windows
  1455. * Bug 21837: Fix reproducibility of accessibility code for Windows
  1456. * Bug 21240: Create patches to fix mingw-w64 compilation of Firefox ESR 52
  1457. * Bug 21904: Bump mingw-w64 commit to help with sandbox compilation
  1458. * Bug 18831: Use own Yasm for Firefox cross-compilation
  1459. * OS X
  1460. * Bug 21328: Updating to clang 3.8.0
  1461. * Bug 21754: Remove old GCC toolchain and macOS SDK
  1462. * Bug 19783: Remove unused macOS helper scripts
  1463. * Bug 10369: Don't use old GCC toolchain anymore for utils
  1464. * Bug 21753: Replace our old GCC toolchain in PT descriptor
  1465. * Bug 18530: ESR52 based Tor Browser only runs on macOS 10.9+
  1466. * Bug 22328: Remove clang PIE wrappers
  1467. * Linux
  1468. * Bug 21930: NSS libraries are missing from mar-tools archive
  1469. * Bug 21239: Adapt Linux Firefox descriptor to ESR52 (use GTK2)
  1470. * Bug 21960: Linux bundles based on ESR 52 are not reproducible anymore
  1471. * Bug 21629: Fix broken ASan builds when switching to ESR 52
  1472. * Bug 22444: Use hardening-wrapper when building GCC
  1473. * Bug 22361: Fix hardening of libraries built in linux/gitian-utils.yml
  1474. Tor Browser 7.0a4 -- May 15 2017
  1475. * All Platforms
  1476. * Update Firefox to 52.1.1esr
  1477. * Update Tor to 0.3.0.6
  1478. * Update Tor Launcher to 0.2.12.1
  1479. * Bug 20761: Don't ignore additional SocksPorts
  1480. * Translation update
  1481. * Update HTTPS-Everywhere to 5.2.16
  1482. * Update NoScript to 5.0.4
  1483. * Bug 21962: Fix crash on about:addons page
  1484. * Bug 21778: Canvas prompt is not shown in Tor Browser based on ESR52
  1485. * Bug 21569: Add first-party domain to Permissions key
  1486. * Bug 22165: Don't allow collection of local IP addresses
  1487. * Bug 13017: Work around audio fingerprinting by disabling the Web Audio API
  1488. * Bug 10286: Disable Touch API and add fingerprinting resistance as fallback
  1489. * Bug 13612: Disable Social API
  1490. * Bug 10283: Disable SpeechSynthesis API
  1491. * Bug 21675: Spoof window.navigator.hardwareConcurrency
  1492. * Bug 21792: Suppress MediaError.message
  1493. * Bug 16337: Round times exposed by Animation API to nearest 100ms
  1494. * Bug 21726: Keep Graphite support disabled
  1495. * Bug 21685: Disable remote new tab pages
  1496. * Bug 21790: Disable captive portal detection
  1497. * Bug 21686: Disable Microsoft Family Safety support
  1498. * Bug 22073: Make sure Mozilla's experiments are disabled
  1499. * Bug 21683: Disable newly added Safebrowsing capabilities
  1500. * Bug 22071: Disable Kinto-based blocklist update mechanism
  1501. * Bug 22072: Hide TLS error reporting checkbox
  1502. * Bug 20761: Don't ignore additional SocksPorts
  1503. * Bug 21340: Identify and backport new patches from Firefox
  1504. * Bug 22153: Fix broken feeds on higher security levels
  1505. * Bug 22025: Fix broken certificate error pages on higher security levels
  1506. * Bug 21710: Upgrade Go to 1.8.1
  1507. * Mac
  1508. * Bug 21940: Don't allow privilege escalation during update
  1509. * Bug 22044: Fix broken default search engine on macOS
  1510. * Bug 21879: Use our default bookmarks on OSX
  1511. * Bug 21779: Non-admin users can't access Tor Browser on macOS
  1512. * Linux
  1513. * Bug 22041: Fix update error during update to 7.0a3
  1514. * Bug 22238: Fix use of hardened wrapper for Firefox build
  1515. * Bug 20683: Selfrando support for 64-bit Linux systems
  1516. Tor Browser 7.0a3 -- April 20 2017
  1517. * All Platforms
  1518. * Update Firefox to 52.1.0esr
  1519. * Tor to 0.3.0.5-rc
  1520. * Update Torbutton to 1.9.7.2
  1521. * Bug 21865: Update our JIT preferences in the security slider
  1522. * Bug 21747: Make 'New Tor Circuit for this Site' work in ESR52
  1523. * Bug 21745: Fix handling of catch-all circuit
  1524. * Bug 21547: Fix circuit display under e10s
  1525. * Bug 21268: e10s compatibility for New Identity
  1526. * Bug 21267: Remove window resize implementation for now
  1527. * Bug 21201: Make Torbutton multiprocess compatible
  1528. * Translations update
  1529. * Update Tor Launcher to 0.2.12
  1530. * Bug 21920: Don't show locale selection dialog
  1531. * Bug 21546: Mark Tor Launcher as multiprocess compatible
  1532. * Bug 21264: Add a README file
  1533. * Translations update
  1534. * Update HTTPS-Everywhere to 5.2.14
  1535. * Update NoScript to 5.0.2
  1536. * Update sandboxed-tor-browser to 0.0.6
  1537. * Bug 21764: Use bubblewrap's `--die-with-parent` when supported
  1538. * Fix e10s Web Content crash on systems with grsec kernels
  1539. * Bug 21928: Force a reinstall if an existing hardened bundle is present
  1540. * Bug 21929: Remove hardened/ASAN related code
  1541. * Bug 21927: Remove the ability to install/update the hardened bundle
  1542. * Bug 21244: Update the MAR signing key for 7.0
  1543. * Bug 21536: Remove asn's scramblesuit bridge from Tor Browser
  1544. * Add back the old release MAR signing key
  1545. * Add `prlimit64` to the firefox system call whitelist
  1546. * Fix compilation with Go 1.8
  1547. * Use Config.Clone() to clone TLS configs when available
  1548. * Update Go to 1.7.5 (bug 21709)
  1549. * Bug 21555+16450: Don't remove Authorization header on subdomains (e.g. Twitter)
  1550. * Bug 21887: Fix broken error pages on higher security levels
  1551. * Bug 21876: Enable e10s by default on all supported platforms
  1552. * Bug 21876: Always use esr policies for e10s
  1553. * Bug 20905: Fix resizing issues after moving to a direct Firefox patch
  1554. * Bug 21875: Modal dialogs are maximized in ESR52 nightly builds
  1555. * Bug 21885: SVG is not disabled in Tor Browser based on ESR52
  1556. * Bug 17334: Hide Referer when leaving a .onion domain (improved patch)
  1557. * Bug 3246: Double-key cookies
  1558. * Bug 8842: Fix XML parsing error
  1559. * Bug 16886: "Add-on compatibility check dialog" contains Firefox logo
  1560. * Bug 19192: Untrust Blue Coat CA
  1561. * Bug 19955: Avoid confusing warning that favicon load request got cancelled
  1562. * Bug 20005: Backport fixes for memory leaks investigation
  1563. * Bug 20755: ltn.com.tw is broken in Tor Browser
  1564. * Bug 21896: Commenting on website is broken due to CAPTCHA not being displayed
  1565. * Bug 20680: Rebase Tor Browser patches to 52 ESR
  1566. * Bug 21917: Add new obfs4 bridges
  1567. * Bug 21918: Move meek-amazon to d2cly7j4zqgua7.cloudfront.net backend
  1568. * Windows
  1569. * Bug 21795: Fix Tor Browser crashing on github.com
  1570. * Bug 12426: Make use of HeapEnableTerminationOnCorruption
  1571. * Bug 19316: Make sure our Windows updates can deal with the SSE2 requirement
  1572. * Bug 21868: Fix build bustage with FIREFOX_52_0_2esr_RELEASE for Windows
  1573. * OS X
  1574. * Bug 21723: Fix inconsistent generation of MOZ_MACBUNDLE_ID
  1575. * Bug 21724: Make Firefox and Tor Browser distinct macOS apps
  1576. * Bug 21931: Backport OSX SetupMacCommandLine updater fixes
  1577. * Bug 15910: Don't download GMPs via the local fallback
  1578. * Linux
  1579. * Bug 21907: Fix runtime error on CentOS 6
  1580. * Bug 21748: Fix broken Snowflake build and update bridge details
  1581. * Bug 21954: Snowflake breaks the 7.0a3 build
  1582. * Bug 15910: Don't download GMPs via the local fallback
  1583. * Build system
  1584. * Windows
  1585. * Bug 21837: Fix reproducibility of accessibility code for Windows
  1586. * Bug 21240: Create patches to fix mingw-w64 compilation of Firefox ESR 52
  1587. * Bug 21904: Bump mingw-w64 commit to help with sandbox compilation
  1588. * Bug 18831: Use own Yasm for Firefox cross-compilation
  1589. * OS X
  1590. * Bug 21328: Updating to clang 3.8.0
  1591. * Bug 21754: Remove old GCC toolchain and macOS SDK
  1592. * Bug 19783: Remove unused macOS helper scripts
  1593. * Bug 10369: Don't use old GCC toolchain anymore for utils
  1594. * Bug 21753: Replace our old GCC toolchain in PT descriptor
  1595. * Bug 18530: ESR52 based Tor Browser only runs on macOS 10.9+
  1596. * Linux
  1597. * Bug 21930: NSS libraries are missing from mar-tools archive
  1598. * Bug 21239: Adapt Linux Firefox descriptor to ESR52 (use GTK2)
  1599. * Bug 21960: Linux bundles based on ESR 52 are not reproducible anymore
  1600. * Bug 21629: Fix broken ASan builds when switching to ESR 52
  1601. Tor Browser 6.5.2 -- April 19 2017
  1602. * All Platforms
  1603. * Update Firefox to 45.9.0esr
  1604. * Update HTTPS-Everywhere to 5.2.14
  1605. * Update NoScript to 5.0.2
  1606. * Bug 21555+16450: Don't remove Authorization header on subdomains (e.g. Twitter)
  1607. * Bug 19316: Make sure our Windows updates can deal with the SSE2 requirement
  1608. * Bug 21917: Add new obfs4 bridges
  1609. * Bug 21918: Move meek-amazon to d2cly7j4zqgua7.cloudfront.net backend
  1610. * Windows
  1611. * Bug 21795: Fix Tor Browser crashing on github.com
  1612. Tor Browser 7.0a2-hardened -- March 7 2017
  1613. * All Platforms
  1614. * Update Firefox to 45.8.0esr
  1615. * Tor to 0.3.0.4-rc
  1616. * OpenSSL to 1.0.2k
  1617. * Update Torbutton to 1.9.7.1
  1618. * Bug 21396: Allow leaking of resource/chrome URIs (off by default)
  1619. * Bug 21574: Add link for zh manual and create manual links dynamically
  1620. * Bug 21330: Non-usable scrollbar appears in tor browser security settings
  1621. * Bug 21324: Don't update NoScript button with timer update
  1622. * Translation updates
  1623. * Update HTTPS-Everywhere to 5.2.11
  1624. * Bug 21514: Restore W^X JIT implementation removed from ESR45
  1625. * Bug 21536: Remove scramblesuit bridge
  1626. * Bug 21342: Move meek-azure to the meek.azureedge.net backend and cymrubridge02 bridge
  1627. * Bug 21326: Update the "Using a system-installed Tor" section in start script
  1628. * Build system
  1629. * Bug 17034: Use our built binutils and GCC for building tor
  1630. * Code clean-up
  1631. Tor Browser 7.0a2 -- March 7 2017
  1632. * All Platforms
  1633. * Update Firefox to 45.8.0esr
  1634. * Tor to 0.3.0.4-rc
  1635. * OpenSSL to 1.0.2k
  1636. * Update Torbutton to 1.9.7.1
  1637. * Bug 21396: Allow leaking of resource/chrome URIs (off by default)
  1638. * Bug 21574: Add link for zh manual and create manual links dynamically
  1639. * Bug 21330: Non-usable scrollbar appears in tor browser security settings
  1640. * Bug 21324: Don't update NoScript button with timer update
  1641. * Translation updates
  1642. * Update HTTPS-Everywhere to 5.2.11
  1643. * Bug 21514: Restore W^X JIT implementation removed from ESR45
  1644. * Bug 21536: Remove scramblesuit bridge
  1645. * Bug 21342: Move meek-azure to the meek.azureedge.net backend and cymrubridge02 bridge
  1646. * Bug 21348: Make snowflake only available on Linux for now
  1647. * Linux
  1648. * Bug 21326: Update the "Using a system-installed Tor" section in start script
  1649. * Build system
  1650. * OS X
  1651. * Bug 21343: Remove unused FTE related parts for macOS
  1652. * Linux
  1653. * Bug 17034: Use our built binutils and GCC for building tor
  1654. * Clean-up
  1655. Tor Browser 6.5.1 -- March 7 2017
  1656. * All Platforms
  1657. * Update Firefox to 45.8.0esr
  1658. * Tor to 0.2.9.10
  1659. * OpenSSL to 1.0.2k
  1660. * Update Torbutton to 1.9.6.14
  1661. * Bug 21396: Allow leaking of resource/chrome URIs (off by default)
  1662. * Bug 21574: Add link for zh manual and create manual links dynamically
  1663. * Bug 21330: Non-usable scrollbar appears in tor browser security settings
  1664. * Translation updates
  1665. * Update HTTPS-Everywhere to 5.2.11
  1666. * Bug 21514: Restore W^X JIT implementation removed from ESR45
  1667. * Bug 21536: Remove scramblesuit bridge
  1668. * Bug 21342: Move meek-azure to the meek.azureedge.net backend and cymrubridge02 bridge
  1669. * Linux
  1670. * Bug 21326: Update the "Using a system-installed Tor" section in start script
  1671. Tor Browser 7.0a1-hardened -- January 25 2017
  1672. * All Platforms
  1673. * Update Firefox to 45.7.0esr
  1674. * Tor to 0.3.0.2-alpha
  1675. * Update Torbutton to 1.9.7
  1676. * Bug 19898: Use DuckDuckGo on about:tor
  1677. * Bug 21091: Hide the update check menu entry when running under the sandbox
  1678. * Bug 21243: Add links to es, fr, and pt Tor Browser manual
  1679. * Bug 21194: Show snowflake in the circuit display
  1680. * Bug 21131: Remove 2016 donation banner
  1681. * Translation updates
  1682. * Update HTTPS-Everywhere to 5.2.9
  1683. * Update NoScript to 2.9.5.3
  1684. * Bug 20471: Allow javascript: links from HTTPS first party pages
  1685. * Bug 20651: DuckDuckGo does not work with JavaScript disabled
  1686. * Bug 20589: Add new MAR signing key
  1687. * Bug 20735: Add snowflake pluggable transport to alpha Linux builds
  1688. * Build system
  1689. * All platforms
  1690. * Bug 20927: Upgrade Go to 1.7.4
  1691. Tor Browser 7.0a1 -- January 25 2017
  1692. * All Platforms
  1693. * Update Firefox to 45.7.0esr
  1694. * Tor to 0.3.0.2-alpha
  1695. * Update Torbutton to 1.9.7
  1696. * Bug 19898: Use DuckDuckGo on about:tor
  1697. * Bug 21091: Hide the update check menu entry when running under the sandbox
  1698. * Bug 21243: Add links to es, fr, and pt Tor Browser manual
  1699. * Bug 21194: Show snowflake in the circuit display
  1700. * Bug 21131: Remove 2016 donation banner
  1701. * Translation updates
  1702. * Update HTTPS-Everywhere to 5.2.9
  1703. * Update NoScript to 2.9.5.3
  1704. * Bug 20471: Allow javascript: links from HTTPS first party pages
  1705. * Bug 20651: DuckDuckGo does not work with JavaScript disabled
  1706. * Bug 20589: Add new MAR signing key
  1707. * Windows
  1708. * Bug 20981: On Windows, check TZ for timezone first
  1709. * OS X
  1710. * Bug 20989: Browser sandbox profile is too restrictive on OSX 10.12.2
  1711. * Linux
  1712. * Update sandboxed-tor-browser to 0.0.3
  1713. * Bug 20735: Add snowflake pluggable transport to alpha Linux builds
  1714. * Build system
  1715. * All platforms
  1716. * Bug 20927: Upgrade Go to 1.7.4
  1717. * Linux
  1718. * Bug 21103: Update descriptors for sandboxed-tor-browser 0.0.3
  1719. Tor Browser 6.5 -- January 24 2017
  1720. * All Platforms
  1721. * Update Firefox to 45.7.0esr
  1722. * Tor to 0.2.9.9
  1723. * OpenSSL to 1.0.2j
  1724. * Update Torbutton to 1.9.6.12
  1725. * Bug 16622: Timezone spoofing moved to tor-browser.git
  1726. * Bug 17334: Move referrer spoofing for .onion domains into tor-browser.git
  1727. * Bug 8725: Block addon resource and url fingerprinting with nsIContentPolicy
  1728. * Bug 20701: Allow the directory listing stylesheet in the content policy
  1729. * Bug 19837: Whitelist internal URLs that Firefox requires for media
  1730. * Bug 19206: Avoid SOCKS auth and NEWNYM collisions when sharing a tor client
  1731. * Bug 19273: Improve external app launch handling and associated warnings
  1732. * Bug 15852: Remove/synchronize Torbutton SOCKS pref logic
  1733. * Bug 19733: GETINFO response parser doesn't handle AF_UNIX entries + IPv6
  1734. * Bug 17767: Make "JavaScript disabled" more visible in Security Slider
  1735. * Bug 20556: Use pt-BR strings from now on
  1736. * Bug 20614: Add links to Tor Browser User Manual
  1737. * Bug 20414: Fix non-rendering arrow on OS X
  1738. * Bug 20728: Fix bad preferences.xul dimensions
  1739. * Bug 19898: Use DuckDuckGo on about:tor
  1740. * Bug 21091: Hide the update check menu entry when running under the sandbox
  1741. * Bug 19459: Move resizing code to tor-browser.git
  1742. * Bug 20264: Change security slider to 3 options
  1743. * Bug 20347: Enhance security slider's custom mode
  1744. * Bug 20123: Disable remote jar on all security levels
  1745. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1746. * Bug 17546: Add tooltips to explain our privacy checkboxes
  1747. * Bug 17904: Allow security settings dialog to resize
  1748. * Bug 18093: Remove 'Restore Defaults' button
  1749. * Bug 20373: Prevent redundant dialogs opening
  1750. * Bug 20318: Remove helpdesk link from about:tor
  1751. * Bug 21243: Add links for pt, es, and fr Tor Browser manuals
  1752. * Bug 20753: Remove obsolete StartPage locale strings
  1753. * Bug 21131: Remove 2016 donation banner
  1754. * Bug 18980: Remove obsolete toolbar button code
  1755. * Bug 18238: Remove unused Torbutton code and strings
  1756. * Bug 20388+20399+20394: Code clean-up
  1757. * Translation updates
  1758. * Update Tor Launcher to 0.2.10.3
  1759. * Bug 19568: Set CurProcD for Thunderbird/Instantbird
  1760. * Bug 19432: Remove special handling for Instantbird/Thunderbird
  1761. * Translation updates
  1762. * Update HTTPS-Everywhere to 5.2.9
  1763. * Update NoScript to 2.9.5.3
  1764. * Bug 16622: Spoof timezone with Firefox patch
  1765. * Bug 17334: Spoof referrer when leaving a .onion domain
  1766. * Bug 19273: Write C++ patch for external app launch handling
  1767. * Bug 19459: Size new windows to 1000x1000 or nearest 200x100 (Firefox patch)
  1768. * Bug 12523: Mark JIT pages as non-writable
  1769. * Bug 20123: Always block remote jar files
  1770. * Bug 19193: Reduce timing precision for AudioContext, HTMLMediaElement, and MediaStream
  1771. * Bug 19164: Remove support for SHA-1 HPKP pins
  1772. * Bug 19186: KeyboardEvents are only rounding to 100ms
  1773. * Bug 16998: Isolate preconnect requests to URL bar domain
  1774. * Bug 19478: Prevent millisecond resolution leaks in File API
  1775. * Bug 20471: Allow javascript: links from HTTPS first party pages
  1776. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1777. * Bug 20707: Fix broken preferences tab in non-en-US alpha bundles
  1778. * Bug 20709: Fix wrong update URL in alpha bundles
  1779. * Bug 19481: Point the update URL to aus1.torproject.org
  1780. * Bug 20556: Start using pt-BR instead of pt-PT for Portuguese
  1781. * Bug 20442: Backport fix for local path disclosure after drag and drop
  1782. * Bug 20160: Backport fix for broken MP3-playback
  1783. * Bug 20043: Isolate SharedWorker script requests to first party
  1784. * Bug 18923: Add script to run all Tor Browser regression tests
  1785. * Bug 20651: DuckDuckGo does not work with JavaScript disabled
  1786. * Bug 19336+19835: Enhance about:tbupdate page
  1787. * Bug 20399+15852: Code clean-up
  1788. * Windows
  1789. * Bug 20981: On Windows, check TZ for timezone first
  1790. * Bug 18175: Maximizing window and restarting leads to non-rounded window size
  1791. * Bug 13437: Rounded inner window accidentally grows to non-rounded size
  1792. * OS X
  1793. * Bug 20590: Badly resized window due to security slider notification bar on OS X
  1794. * Bug 20439: Make the build PIE on OSX
  1795. * Linux
  1796. * Bug 20691: Updater breaks if unix domain sockets are used
  1797. * Bug 15953: Weird resizing dance on Tor Browser startup
  1798. * Build system
  1799. * All platforms
  1800. * Bug 20927: Upgrade Go to 1.7.4
  1801. * Bug 20583: Make the downloads.json file reproducible
  1802. * Bug 20133: Don't apply OpenSSL patch anymore
  1803. * Bug 19528: Set MOZ_BUILD_DATE based on Firefox version
  1804. * Bug 18291: Remove some uses of libfaketime
  1805. * Bug 18845: Make zip and tar helpers generate reproducible archives
  1806. * OS X
  1807. * Bug 20258: Make OS X Tor archive reproducible again
  1808. * Bug 20184: Make OS X builds reproducible (use clang for compiling tor)
  1809. * Bug 19856: Make OS X builds reproducible (getting libfaketime back)
  1810. * Bug 19410: Fix incremental updates by taking signatures into account
  1811. * Bug 20210: In dmg2mar, extract old mar file to copy permissions to the new one
  1812. Tor Browser 6.5a6-hardened -- December 14 2016
  1813. * All Platforms
  1814. * Update Firefox to 45.6.0esr
  1815. * Tor to 0.2.9.7-rc
  1816. * Update Torbutton to 1.9.6.9
  1817. * Bug 16622: Timezone spoofing moved to tor-browser.git
  1818. * Bug 20701: Allow the directory listing stylesheet in the content policy
  1819. * Bug 20556: Use pt-BR strings from now on
  1820. * Bug 20614: Add links to Tor Browser User Manual
  1821. * Bug 20414: Fix non-rendering arrow on OS X
  1822. * Bug 20728: Fix bad preferences.xul dimensions
  1823. * Bug 20318: Remove helpdesk link from about:tor
  1824. * Bug 20753: Remove obsolete StartPage locale strings
  1825. * Bug 20947: Donation banner improvements
  1826. * Translation updates
  1827. * Update HTTPS-Everywhere to 5.2.8
  1828. * Bug 16622: Spoof timezone with Firefox patch
  1829. * Bug 20707: Fix broken preferences tab in non-en-US alpha bundles
  1830. * Bug 20709: Fix wrong update URL in alpha bundles
  1831. * Bug 20556: Start using pt-BR instead of pt-PT for Portuguese
  1832. * Bug 20809: Use non-/html search engine URL for DuckDuckGo search plugins
  1833. * Bug 20837: Activate iat-mode for certain obfs4 bridges
  1834. * Bug 20838: Uncomment NX01 default obfs4 bridge
  1835. * Bug 20840: Rotate ports a third time for default obfs4 bridges
  1836. Tor Browser 6.5a6 -- December 14 2016
  1837. * All Platforms
  1838. * Update Firefox to 45.6.0esr
  1839. * Tor to 0.2.9.6-rc
  1840. * Update Torbutton to 1.9.6.8
  1841. * Bug 16622: Timezone spoofing moved to tor-browser.git
  1842. * Bug 20701: Allow the directory listing stylesheet in the content policy
  1843. * Bug 20556: Use pt-BR strings from now on
  1844. * Bug 20614: Add links to Tor Browser User Manual
  1845. * Bug 20414: Fix non-rendering arrow on OS X
  1846. * Bug 20728: Fix bad preferences.xul dimensions
  1847. * Bug 20318: Remove helpdesk link from about:tor
  1848. * Bug 20753: Remove obsolete StartPage locale strings
  1849. * Translation updates
  1850. * Update HTTPS-Everywhere to 5.2.8
  1851. * Bug 16622: Spoof timezone with Firefox patch
  1852. * Bug 20707: Fix broken preferences tab in non-en-US alpha bundles
  1853. * Bug 20709: Fix wrong update URL in alpha bundles
  1854. * Bug 20556: Start using pt-BR instead of pt-PT for Portuguese
  1855. * Bug 20809: Use non-/html search engine URL for DuckDuckGo search plugins
  1856. * Bug 20837: Activate iat-mode for certain obfs4 bridges
  1857. * Bug 20838: Uncomment NX01 default obfs4 bridge
  1858. * Bug 20840: Rotate ports a third time for default obfs4 bridges
  1859. * Linux
  1860. * Bug 20352: Integrate sandboxed-tor-browser into our Gitian build
  1861. * Bug 20758: Make Linux sandbox build deterministic
  1862. * Bug 10281: Use jemalloc4 and abort on redzone corruption
  1863. * OS X
  1864. * Bug 20121: Create Seatbelt profile(s) for Tor Browser
  1865. Tor Browser 6.0.8 -- December 13 2016
  1866. * All Platforms
  1867. * Update Firefox to 45.6.0esr
  1868. * Tor to 0.2.8.11
  1869. * Update Torbutton to 1.9.5.13
  1870. * Bug 20947: Donation banner improvements
  1871. * Update HTTPS-Everywhere to 5.2.8
  1872. * Bug 20809: Use non-/html search engine URL for DuckDuckGo search plugins
  1873. * Bug 20837: Activate iat-mode for certain obfs4 bridges
  1874. * Bug 20838: Uncomment NX01 default obfs4 bridge
  1875. * Bug 20840: Rotate ports a third time for default obfs4 bridges
  1876. Tor Browser 6.5a5-hardened -- December 1 2016
  1877. * All Platforms
  1878. * Update Firefox to 45.5.1esr
  1879. * Update NoScript to 2.9.5.2
  1880. * Linux
  1881. * Bug 20691: Updater breaks if unix domain sockets are used
  1882. Tor Browser 6.5a5 -- December 1 2016
  1883. * All Platforms
  1884. * Update Firefox to 45.5.1esr
  1885. * Update NoScript to 2.9.5.2
  1886. * Linux
  1887. * Bug 20691: Updater breaks if unix domain sockets are used
  1888. Tor Browser 6.0.7 -- November 30 2016
  1889. * All Platforms
  1890. * Update Firefox to 45.5.1esr
  1891. * Update NoScript to 2.9.5.2
  1892. Tor Browser 6.5a4-hardened -- November 16 2016
  1893. * All Platforms
  1894. * Update Firefox to 45.5.0esr
  1895. * Update Tor to 0.2.9.5-alpha
  1896. * Update OpenSSL to 1.0.2j
  1897. * Update Torbutton to 1.9.6.7
  1898. * Bug 20414: Add donation banner on about:tor for 2016 campaign
  1899. * Bug 20111: use Unix domain sockets for SOCKS port by default
  1900. * Bug 19459: Move resizing code to tor-browser.git
  1901. * Bug 20264: Change security slider to 3 options
  1902. * Bug 20347: Enhance security slider's custom mode
  1903. * Bug 20123: Disable remote jar on all security levels
  1904. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1905. * Bug 17546: Add tooltips to explain our privacy checkboxes
  1906. * Bug 17904: Allow security settings dialog to resize
  1907. * Bug 18093: Remove 'Restore Defaults' button
  1908. * Bug 20373: Prevent redundant dialogs opening
  1909. * Bug 20388+20399+20394: Code clean-up
  1910. * Translation updates
  1911. * Update Tor Launcher to 0.2.11.1
  1912. * Bug 20111: use Unix domain sockets for SOCKS port by default
  1913. * Bug 20185: Avoid using Unix domain socket paths that are too long
  1914. * Bug 20429: Do not open progress window if tor doesn't get started
  1915. * Bug 19646: Wrong location for meek browser profile on OS X
  1916. * Translation updates
  1917. * Update HTTPS-Everywhere to 5.2.7
  1918. * Update meek to 0.25
  1919. * Bug 19646: Wrong location for meek browser profile on OS X
  1920. * Bug 20030: Shut down meek-http-helper cleanly if built with Go > 1.5.4
  1921. * Bug 20304: Support spaces and other special characters for SOCKS socket
  1922. * Bug 20490: Fix assertion failure due to fix for #20304
  1923. * Bug 19459: Size new windows to 1000x1000 or nearest 200x100 (Firefox patch)
  1924. * Bug 20442: Backport fix for local path disclosure after drag and drop
  1925. * Bug 20160: Backport fix for broken MP3-playback
  1926. * Bug 20043: Isolate SharedWorker script requests to first party
  1927. * Bug 20123: Always block remote jar files
  1928. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1929. * Bug 19838: Add dgoulet's bridge and add another one commented out
  1930. * Bug 19481: Point the update URL to aus1.torproject.org
  1931. * Bug 20296: Rotate ports again for default obfs4 bridges
  1932. * Bug 20651: DuckDuckGo does not work with JavaScript disabled
  1933. * Bug 20399+15852: Code clean-up
  1934. * Bug 15953: Weird resizing dance on Tor Browser startup
  1935. * Build system
  1936. * All platforms
  1937. * Bug 20023: Upgrade Go to 1.7.3
  1938. * Bug 20583: Make the downloads.json file reproducible
  1939. Tor Browser 6.5a4 -- November 16 2016
  1940. * All Platforms
  1941. * Update Firefox to 45.5.0esr
  1942. * Update Tor to 0.2.9.5-alpha
  1943. * Update OpenSSL to 1.0.2j
  1944. * Update Torbutton to 1.9.6.7
  1945. * Bug 20414: Add donation banner on about:tor for 2016 campaign
  1946. * Bug 20111: use Unix domain sockets for SOCKS port by default
  1947. * Bug 19459: Move resizing code to tor-browser.git
  1948. * Bug 20264: Change security slider to 3 options
  1949. * Bug 20347: Enhance security slider's custom mode
  1950. * Bug 20123: Disable remote jar on all security levels
  1951. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1952. * Bug 17546: Add tooltips to explain our privacy checkboxes
  1953. * Bug 17904: Allow security settings dialog to resize
  1954. * Bug 18093: Remove 'Restore Defaults' button
  1955. * Bug 20373: Prevent redundant dialogs opening
  1956. * Bug 20388+20399+20394: Code clean-up
  1957. * Translation updates
  1958. * Update Tor Launcher to 0.2.10.2
  1959. * Bug 20111: use Unix domain sockets for SOCKS port by default
  1960. * Bug 20185: Avoid using Unix domain socket paths that are too long
  1961. * Bug 20429: Do not open progress window if tor doesn't get started
  1962. * Bug 19646: Wrong location for meek browser profile on OS X
  1963. * Translation updates
  1964. * Update HTTPS-Everywhere to 5.2.7
  1965. * Update meek to 0.25
  1966. * Bug 19646: Wrong location for meek browser profile on OS X
  1967. * Bug 20030: Shut down meek-http-helper cleanly if built with Go > 1.5.4
  1968. * Bug 20304: Support spaces and other special characters for SOCKS socket
  1969. * Bug 20490: Fix assertion failure due to fix for #20304
  1970. * Bug 19459: Size new windows to 1000x1000 or nearest 200x100 (Firefox patch)
  1971. * Bug 20442: Backport fix for local path disclosure after drag and drop
  1972. * Bug 20160: Backport fix for broken MP3-playback
  1973. * Bug 20043: Isolate SharedWorker script requests to first party
  1974. * Bug 20123: Always block remote jar files
  1975. * Bug 20244: Move privacy checkboxes to about:preferences#privacy
  1976. * Bug 19838: Add dgoulet's bridge and add another one commented out
  1977. * Bug 19481: Point the update URL to aus1.torproject.org
  1978. * Bug 20296: Rotate ports again for default obfs4 bridges
  1979. * Bug 20651: DuckDuckGo does not work with JavaScript disabled
  1980. * Bug 20399+15852: Code clean-up
  1981. * Windows
  1982. * Bug 20342: Add tor-gencert.exe to expert bundle
  1983. * Bug 18175: Maximizing window and restarting leads to non-rounded window size
  1984. * Bug 13437: Rounded inner window accidentally grows to non-rounded size
  1985. * OS X
  1986. * Bug 20204: Windows don't drag on macOS Sierra anymore
  1987. * Bug 20250: Meek fails on macOS Sierra if built with Go < 1.7
  1988. * Bug 20590: Badly resized window due to security slider notification bar on OS X
  1989. * Bug 20439: Make the build PIE on OSX
  1990. * Linux
  1991. * Bug 15953: Weird resizing dance on Tor Browser startup
  1992. * Build system
  1993. * All platforms
  1994. * Bug 20023: Upgrade Go to 1.7.3
  1995. * Bug 20583: Make the downloads.json file reproducible
  1996. * OS X
  1997. * Bug 20258: Make OS X Tor archive reproducible again
  1998. * Bug 20184: Make OS X builds reproducible again
  1999. * Bug 20210: In dmg2mar, extract old mar file to copy permissions to the new one
  2000. Tor Browser 6.0.6 -- November 15
  2001. * All Platforms
  2002. * Update Firefox to 45.5.0esr
  2003. * Update Tor to 0.2.8.9
  2004. * Update OpenSSL to 1.0.1u
  2005. * Update Torbutton to 1.9.5.12
  2006. * Bug 20414: Add donation banner on about:tor for 2016 campaign
  2007. * Translation updates
  2008. * Update Tor Launcher to 0.2.9.4
  2009. * Bug 20429: Do not open progress window if tor doesn't get started
  2010. * Bug 19646: Wrong location for meek browser profile on OS X
  2011. * Update HTTPS-Everywhere to 5.2.7
  2012. * Update meek to 0.25
  2013. * Bug 19646: Wrong location for meek browser profile on OS X
  2014. * Bug 20030: Shut down meek-http-helper cleanly if built with Go > 1.5.4
  2015. * Bug 19838: Add dgoulet's bridge and add another one commented out
  2016. * Bug 20296: Rotate ports again for default obfs4 bridges
  2017. * Bug 19735: Switch default search engine to DuckDuckGo
  2018. * Bug 20118: Don't unpack HTTPS Everywhere anymore
  2019. * Windows
  2020. * Bug 20342: Add tor-gencert.exe to expert bundle
  2021. * OS X
  2022. * Bug 20204: Windows don't drag on macOS Sierra anymore
  2023. * Bug 20250: Meek fails on macOS Sierra if built with Go < 1.7
  2024. * Build system
  2025. * All platforms
  2026. * Bug 20023: Upgrade Go to 1.7.3
  2027. Tor Browser 6.5a3-hardened -- September 20 2016
  2028. * All Platforms
  2029. * Update Firefox to 45.4.0esr
  2030. * Update Tor to 0.2.9.2-alpha
  2031. * Update OpenSSL to 1.0.2h (bug 20095)
  2032. * Update Torbutton to 1.9.6.4
  2033. * Bug 17334: Move referrer spoofing for .onion domains into tor-browser.git
  2034. * Bug 17767: Make "JavaScript disabled" more visible in Security Slider
  2035. * Bug 19995: Clear site security settings during New Identity
  2036. * Bug 19906: "Maximizing Tor Browser" Notification can exist multiple times
  2037. * Bug 19837: Whitelist internal URLs that Firefox requires for media
  2038. * Bug 15852: Remove/synchronize Torbutton SOCKS pref logic
  2039. * Bug 19733: GETINFO response parser doesn't handle AF_UNIX entries + IPv6
  2040. * Bug 14271: Make Torbutton work with Unix Domain Socket option
  2041. * Translation updates
  2042. * Update Tor Launcher to 0.2.11
  2043. * Bug 14272: Make Tor Launcher work with Unix Domain Socket option
  2044. * Bug 19568: Set CurProcD for Thunderbird/Instantbird
  2045. * Bug 19432: Remove special handling for Instantbird/Thunderbird
  2046. * Translation updates
  2047. * Update HTTPS-Everywhere to 5.2.4
  2048. * Update NoScript to 2.9.0.14
  2049. * Bug 19851: Fix ASan error by upgrading GCC to 5.4.0
  2050. * Bug 17858: Fix creation of incremental MARs for hardened builds
  2051. * Bug 14273: Backport patches for Unix Domain Socket support
  2052. * Bug 19890: Disable installation of system addons
  2053. * Bug 17334: Spoof referrer when leaving a .onion domain
  2054. * Bug 20092: Rotate ports for default obfs4 bridges
  2055. * Bug 20040: Add update support for unpacked HTTPS Everywhere
  2056. * Bug 20118: Don't unpack HTTPS Everywhere anymore
  2057. * Bug 19336+19835: Enhance about:tbupdate page
  2058. * Build system
  2059. * All platforms
  2060. * Bug 20133: Don't apply OpenSSL patch anymore
  2061. * Bug 19528: Set MOZ_BUILD_DATE based on Firefox version
  2062. Tor Browser 6.5a3 -- September 20 2016
  2063. * All Platforms
  2064. * Update Firefox to 45.4.0esr
  2065. * Update Tor to 0.2.9.2-alpha
  2066. * Update OpenSSL to 1.0.2h (bug 20095)
  2067. * Update Torbutton to 1.9.6.4
  2068. * Bug 17334: Move referrer spoofing for .onion domains into tor-browser.git
  2069. * Bug 17767: Make "JavaScript disabled" more visible in Security Slider
  2070. * Bug 19995: Clear site security settings during New Identity
  2071. * Bug 19906: "Maximizing Tor Browser" Notification can exist multiple times
  2072. * Bug 19837: Whitelist internal URLs that Firefox requires for media
  2073. * Bug 15852: Remove/synchronize Torbutton SOCKS pref logic
  2074. * Bug 19733: GETINFO response parser doesn't handle AF_UNIX entries + IPv6
  2075. * Bug 14271: Make Torbutton work with Unix Domain Socket option
  2076. * Translation updates
  2077. * Update Tor Launcher to 0.2.10.1
  2078. * Bug 14272: Make Tor Launcher work with Unix Domain Socket option
  2079. * Bug 19568: Set CurProcD for Thunderbird/Instantbird
  2080. * Bug 19432: Remove special handling for Instantbird/Thunderbird
  2081. * Translation updates
  2082. * Update HTTPS-Everywhere to 5.2.4
  2083. * Update NoScript to 2.9.0.14
  2084. * Bug 14273: Backport patches for Unix Domain Socket support
  2085. * Bug 19890: Disable installation of system addons
  2086. * Bug 17334: Spoof referrer when leaving a .onion domain
  2087. * Bug 20092: Rotate ports for default obfs4 bridges
  2088. * Bug 20040: Add update support for unpacked HTTPS Everywhere
  2089. * Bug 20118: Don't unpack HTTPS Everywhere anymore
  2090. * Bug 19336+19835: Enhance about:tbupdate page
  2091. * Android
  2092. * Bug 19706: Store browser data in the app home directory
  2093. * Build system
  2094. * All platforms
  2095. * Bug 20133: Don't apply OpenSSL patch anymore
  2096. * Bug 19528: Set MOZ_BUILD_DATE based on Firefox version
  2097. * OS X
  2098. * Bug 19856: Make OS X builds reproducible again
  2099. * Bug 19410: Fix incremental updates by taking signatures into account
  2100. Tor Browser 6.0.5 -- September 16
  2101. * All Platforms
  2102. * Update Firefox to 45.4.0esr
  2103. * Update Tor to 0.2.8.7
  2104. * Update Torbutton to 1.9.5.7
  2105. * Bug 19995: Clear site security settings during New Identity
  2106. * Bug 19906: "Maximizing Tor Browser" Notification can exist multiple times
  2107. * Update HTTPS-Everywhere to 5.2.4
  2108. * Bug 20092: Rotate ports for default obfs4 bridges
  2109. * Bug 20040: Add update support for unpacked HTTPS Everywhere
  2110. * Windows
  2111. * Bug 19725: Remove old updater files left on disk after upgrade to 6.x
  2112. * Linux
  2113. * Bug 19725: Remove old updater files left on disk after upgrade to 6.x
  2114. * Android
  2115. * Bug 19706: Store browser data in the app home directory
  2116. * Build system
  2117. * All platforms
  2118. * Upgrade Go to 1.4.3
  2119. Tor Browser 6.0.4 -- August 16 2016
  2120. * All Platforms
  2121. * Update Tor to 0.2.8.6
  2122. * Update NoScript to 2.9.0.14
  2123. * Bug 19890: Disable installation of system addons
  2124. Tor Browser 6.5a2-hardened -- August 3 2016
  2125. * All Platforms
  2126. * Update Firefox to 45.3.0esr
  2127. * Update Tor to tor-0.2.8.5-rc
  2128. * Update Torbutton to 1.9.6.1
  2129. * Bug 19689: Use proper parent window for plugin prompt
  2130. * Bug 19206: Avoid SOCKS auth and NEWNYM collisions when sharing a tor client
  2131. * Bug 19417: Disable asm.js (but add code to clear on New Identity if enabled)
  2132. * Bug 19273: Improve external app launch handling and associated warnings
  2133. * Bug 8725: Block addon resource and url fingerprinting with nsIContentPolicy
  2134. * Update HTTPS-Everywhere to 5.2.1
  2135. * Update NoScript to 2.9.0.12
  2136. * Bug 17406: Include Selfrando into our hardened builds
  2137. * Bug 19417: Disable asmjs for now
  2138. * Bug 19715: Disable the meek-google pluggable transport option
  2139. * Bug 19714: Remove mercurius4 obfs4 bridge
  2140. * Bug 19585: Fix regression test for keyboard layout fingerprinting
  2141. * Bug 19515: Tor Browser is crashing in graphics code
  2142. * Bug 18513: Favicon requests can bypass New Identity
  2143. * Bug 19273: Write C++ patch for external app launch handling
  2144. * Bug 16998: Isolate preconnect requests to URL bar domain
  2145. * Bug 18923: Add script to run all Tor Browser regression tests
  2146. * Bug 19478: Prevent millisecond resolution leaks in File API
  2147. * Bug 19401: Fix broken PDF download button
  2148. * Bug 19411: Don't show update icon if a partial update failed
  2149. * Bug 19400: Back out GCC bug workaround to avoid asmjs crash
  2150. * Bug 19735: Switch default search engine to DuckDuckGo
  2151. * Bug 19276: Disable Xrender due to possible performance regressions
  2152. * Bug 19725: Remove old updater files left on disk after upgrade to 6.x
  2153. * Build System
  2154. * All Platforms
  2155. * Bug 19703: Upgrade Go to 1.6.3
  2156. Tor Browser 6.5a2 -- August 3 2016
  2157. * All Platforms
  2158. * Update Firefox to 45.3.0esr
  2159. * Update Tor to tor-0.2.8.5-rc
  2160. * Update Torbutton to 1.9.6.1
  2161. * Bug 19689: Use proper parent window for plugin prompt
  2162. * Bug 19206: Avoid SOCKS auth and NEWNYM collisions when sharing a tor client
  2163. * Bug 19417: Disable asm.js (but add code to clear on New Identity if enabled)
  2164. * Bug 19273: Improve external app launch handling and associated warnings
  2165. * Bug 8725: Block addon resource and url fingerprinting with nsIContentPolicy
  2166. * Update HTTPS-Everywhere to 5.2.1
  2167. * Update NoScript to 2.9.0.12
  2168. * Bug 19417: Disable asmjs for now
  2169. * Bug 19715: Disable the meek-google pluggable transport option
  2170. * Bug 19714: Remove mercurius4 obfs4 bridge
  2171. * Bug 19585: Fix regression test for keyboard layout fingerprinting
  2172. * Bug 19515: Tor Browser is crashing in graphics code
  2173. * Bug 18513: Favicon requests can bypass New Identity
  2174. * Bug 19273: Write C++ patch for external app launch handling
  2175. * Bug 16998: Isolate preconnect requests to URL bar domain
  2176. * Bug 18923: Add script to run all Tor Browser regression tests
  2177. * Bug 19478: Prevent millisecond resolution leaks in File API
  2178. * Bug 19401: Fix broken PDF download button
  2179. * Bug 19411: Don't show update icon if a partial update failed
  2180. * Bug 19400: Back out GCC bug workaround to avoid asmjs crash
  2181. * Bug 19735: Switch default search engine to DuckDuckGo
  2182. * Windows
  2183. * Bug 19348: Adapt to more than one build target on Windows (fixes updates)
  2184. * Bug 19725: Remove old updater files left on disk after upgrade to 6.x
  2185. * Linux
  2186. * Bug 19276: Disable Xrender due to possible performance regressions
  2187. * Bug 19725: Remove old updater files left on disk after upgrade to 6.x
  2188. * OS X
  2189. * Bug 19269: Icon doesn't appear in Applications folder or Dock
  2190. * Android
  2191. * Bug 19484: Avoid compilation error when MOZ_UPDATER is not defined
  2192. * Build System
  2193. * All Platforms
  2194. * Bug 19703: Upgrade Go to 1.6.3
  2195. Tor Browser 6.0.3 -- August 2 2016
  2196. * All Platforms
  2197. * Update Firefox to 45.3.0esr
  2198. * Update Torbutton to 1.9.5.6
  2199. * Bug 19417: Disable asmjs for now
  2200. * Bug 19689: Use proper parent window for plugin prompt
  2201. * Update HTTPS-Everywhere to 5.2.1
  2202. * Update NoScript to 2.9.0.12
  2203. * Bug 19417: Disable asmjs for now
  2204. * Bug 19715: Disable the meek-google pluggable transport option
  2205. * Bug 19714: Remove mercurius4 obfs4 bridge
  2206. * Bug 19585: Fix regression test for keyboard layout fingerprinting
  2207. * Bug 19515: Tor Browser is crashing in graphics code
  2208. * Bug 18513: Favicon requests can bypass New Identity
  2209. * OS X
  2210. * Bug 19269: Icon doesn't appear in Applications folder or Dock
  2211. * Android
  2212. * Bug 19484: Avoid compilation error when MOZ_UPDATER is not defined
  2213. Tor Browser 6.0.2 -- June 21 2016
  2214. * All Platforms
  2215. * Update Torbutton to 1.9.5.5
  2216. * Bug 19417: Clear asmjscache
  2217. * Bug 19401: Fix broken PDF download button
  2218. * Bug 19411: Don't show update icon if a partial update failed
  2219. * Bug 19400: Back out GCC bug workaround to avoid asmjs crash
  2220. * Windows
  2221. * Bug 19348: Adapt to more than one build target on Windows (fixes updates)
  2222. * Linux
  2223. * Bug 19276: Disable Xrender due to possible performance regressions
  2224. Tor Browser 6.5a1-hardened -- June 8 2016
  2225. * All Platforms
  2226. * Update Firefox to 45.2.0esr
  2227. * Update Tor to 0.2.8.3-alpha
  2228. * Update Torbutton to 1.9.6
  2229. * Bug 18743: Pref to hide 'Sign in to Sync' button in hamburger menu
  2230. * Bug 18905: Hide unusable items from help menu
  2231. * Bug 17599: Provide shortcuts for New Identity and New Circuit
  2232. * Bug 18980: Remove obsolete toolbar button code
  2233. * Bug 18238: Remove unused Torbutton code and strings
  2234. * Translation updates
  2235. * Code clean-up
  2236. * Update Tor Launcher to 0.2.8.5
  2237. * Bug 18947: Tor Browser is not starting on OS X if put into /Applications
  2238. * Update HTTPS-Everywhere to 5.1.9
  2239. * Update meek to 0.22 (tag 0.22-18371-3)
  2240. * Bug 19121: The update.xml hash should get checked during update
  2241. * Bug 12523: Mark JIT pages as non-writable
  2242. * Bug 19193: Reduce timing precision for AudioContext, HTMLMediaElement, and MediaStream
  2243. * Bug 19164: Remove support for SHA-1 HPKP pins
  2244. * Bug 19186: KeyboardEvents are only rounding to 100ms
  2245. * Bug 18884: Don't build the loop extension
  2246. * Bug 19187: Backport fix for crash related to popup menus
  2247. * Bug 19212: Fix crash related to network panel in developer tools
  2248. * Bug 18703: Fix circuit isolation issues on Page Info dialog
  2249. * bug 19115: Tor Browser should not fall back to Bing as its search engine
  2250. * Bug 18915+19065: Use our search plugins in localized builds
  2251. * Bug 19176: Zip our language packs deterministically
  2252. * Bug 18811: Fix first-party isolation for blobs URLs in Workers
  2253. * Bug 18950: Disable or audit Reader View
  2254. * Bug 18886: Remove Pocket
  2255. * Bug 18619: Tor Browser reports "InvalidStateError" in browser console
  2256. * Bug 18945: Disable monitoring the connected state of Tor Browser users
  2257. * Bug 18855: Don't show error after add-on directory clean-up
  2258. * Bug 18885: Disable the option of logging TLS/SSL key material
  2259. * Bug 18770: SVGs should not show up on Page Info dialog when disabled
  2260. * Bug 18958: Spoof screen.orientation values
  2261. * Bug 19047: Disable Heartbeat prompts
  2262. * Bug 18914: Use English-only label in <isindex/> tags
  2263. * Bug 18996: Investigate server logging in esr45-based Tor Browser
  2264. * Bug 17790: Add unit tests for keyboard fingerprinting defenses
  2265. * Bug 18995: Regression test to ensure CacheStorage is disabled
  2266. * Bug 18912: Add automated tests for updater cert pinning
  2267. * Bug 16728: Add test cases for favicon isolation
  2268. * Bug 18976: Remove some FTE bridges
  2269. * Linux
  2270. * Bug 19189: Backport for working around a linker (gold) bug
  2271. * Build System
  2272. * All PLatforms
  2273. * Bug 18333: Upgrade Go to 1.6.2
  2274. * Bug 18919: Remove unused keys and unused dependencies
  2275. * Bug 18291: Remove some uses of libfaketime
  2276. * Bug 18845: Make zip and tar helpers generate reproducible archives
  2277. Tor Browser 6.5a1 -- June 8 2016
  2278. * All Platforms
  2279. * Update Firefox to 45.2.0esr
  2280. * Update Tor to 0.2.8.3-alpha
  2281. * Update Torbutton to 1.9.6
  2282. * Bug 18743: Pref to hide 'Sign in to Sync' button in hamburger menu
  2283. * Bug 18905: Hide unusable items from help menu
  2284. * Bug 17599: Provide shortcuts for New Identity and New Circuit
  2285. * Bug 18980: Remove obsolete toolbar button code
  2286. * Bug 18238: Remove unused Torbutton code and strings
  2287. * Translation updates
  2288. * Code clean-up
  2289. * Update Tor Launcher to 0.2.9.3
  2290. * Bug 18947: Tor Browser is not starting on OS X if put into /Applications
  2291. * Update HTTPS-Everywhere to 5.1.9
  2292. * Update meek to 0.22 (tag 0.22-18371-3)
  2293. * Bug 18904: Mac OS: meek-http-helper profile not updated
  2294. * Bug 19121: The update.xml hash should get checked during update
  2295. * Bug 12523: Mark JIT pages as non-writable
  2296. * Bug 19193: Reduce timing precision for AudioContext, HTMLMediaElement, and MediaStream
  2297. * Bug 19164: Remove support for SHA-1 HPKP pins
  2298. * Bug 19186: KeyboardEvents are only rounding to 100ms
  2299. * Bug 18884: Don't build the loop extension
  2300. * Bug 19187: Backport fix for crash related to popup menus
  2301. * Bug 19212: Fix crash related to network panel in developer tools
  2302. * Bug 18703: Fix circuit isolation issues on Page Info dialog
  2303. * bug 19115: Tor Browser should not fall back to Bing as its search engine
  2304. * Bug 18915+19065: Use our search plugins in localized builds
  2305. * Bug 19176: Zip our language packs deterministically
  2306. * Bug 18811: Fix first-party isolation for blobs URLs in Workers
  2307. * Bug 18950: Disable or audit Reader View
  2308. * Bug 18886: Remove Pocket
  2309. * Bug 18619: Tor Browser reports "InvalidStateError" in browser console
  2310. * Bug 18945: Disable monitoring the connected state of Tor Browser users
  2311. * Bug 18855: Don't show error after add-on directory clean-up
  2312. * Bug 18885: Disable the option of logging TLS/SSL key material
  2313. * Bug 18770: SVGs should not show up on Page Info dialog when disabled
  2314. * Bug 18958: Spoof screen.orientation values
  2315. * Bug 19047: Disable Heartbeat prompts
  2316. * Bug 18914: Use English-only label in <isindex/> tags
  2317. * Bug 18996: Investigate server logging in esr45-based Tor Browser
  2318. * Bug 17790: Add unit tests for keyboard fingerprinting defenses
  2319. * Bug 18995: Regression test to ensure CacheStorage is disabled
  2320. * Bug 18912: Add automated tests for updater cert pinning
  2321. * Bug 16728: Add test cases for favicon isolation
  2322. * Bug 18976: Remove some FTE bridges
  2323. * OS X
  2324. * Bug 18951: HTTPS-E is missing after update
  2325. * Bug 18904: meek-http-helper profile not updated
  2326. * Bug 18928: Upgrade is not smooth (requires another restart)
  2327. * Linux
  2328. * Bug 19189: Backport for working around a linker (gold) bug
  2329. * Build System
  2330. * All PLatforms
  2331. * Bug 18333: Upgrade Go to 1.6.2
  2332. * Bug 18919: Remove unused keys and unused dependencies
  2333. * Bug 18291: Remove some uses of libfaketime
  2334. * Bug 18845: Make zip and tar helpers generate reproducible archives
  2335. Tor Browser 6.0.1 -- June 7 2016
  2336. * All Platforms
  2337. * Update Firefox to 45.2.0esr
  2338. * Bug 18884: Don't build the loop extension
  2339. * Bug 19187: Backport fix for crash related to popup menus
  2340. * Bug 19212: Fix crash related to network panel in developer tools
  2341. * Linux
  2342. * Bug 19189: Backport for working around a linker (gold) bug
  2343. Tor Browser 6.0 -- May 30 2016
  2344. * All Platforms
  2345. * Update Firefox to 45.1.1esr
  2346. * Update OpenSSL to 1.0.1t
  2347. * Update Torbutton to 1.9.5.4
  2348. * Bug 18466: Make Torbutton compatible with Firefox ESR 45
  2349. * Bug 18743: Pref to hide 'Sign in to Sync' button in hamburger menu
  2350. * Bug 18905: Hide unusable items from help menu
  2351. * Bug 16017: Allow users to more easily set a non-tor SSH proxy
  2352. * Bug 17599: Provide shortcuts for New Identity and New Circuit
  2353. * Translation updates
  2354. * Code clean-up
  2355. * Update Tor Launcher to 0.2.9.3
  2356. * Bug 13252: Do not store data in the application bundle
  2357. * Bug 18947: Tor Browser is not starting on OS X if put into /Applications
  2358. * Bug 11773: Setup wizard UI flow improvements
  2359. * Translation updates
  2360. * Update HTTPS-Everywhere to 5.1.9
  2361. * Update meek to 0.22 (tag 0.22-18371-3)
  2362. * Bug 18371: Symlinks are incompatible with Gatekeeper signing
  2363. * Bug 18904: Mac OS: meek-http-helper profile not updated
  2364. * Bug 15197 and child tickets: Rebase Tor Browser patches to ESR 45
  2365. * Bug 18900: Fix broken updater on Linux
  2366. * Bug 19121: The update.xml hash should get checked during update
  2367. * Bug 18042: Disable SHA1 certificate support
  2368. * Bug 18821: Disable libmdns support for desktop and mobile
  2369. * Bug 18848: Disable additional welcome URL shown on first start
  2370. * Bug 14970: Exempt our extensions from signing requirement
  2371. * Bug 16328: Disable MediaDevices.enumerateDevices
  2372. * Bug 16673: Disable HTTP Alternative-Services
  2373. * Bug 17167: Disable Mozilla's tracking protection
  2374. * Bug 18603: Disable performance-based WebGL fingerprinting option
  2375. * Bug 18738: Disable Selfsupport and Unified Telemetry
  2376. * Bug 18799: Disable Network Tickler
  2377. * Bug 18800: Remove DNS lookup in lockfile code
  2378. * Bug 18801: Disable dom.push preferences
  2379. * Bug 18802: Remove the JS-based Flash VM (Shumway)
  2380. * Bug 18863: Disable MozTCPSocket explicitly
  2381. * Bug 15640: Place Canvas MediaStream behind site permission
  2382. * Bug 16326: Verify cache isolation for Request and Fetch APIs
  2383. * Bug 18741: Fix OCSP and favicon isolation for ESR 45
  2384. * Bug 16998: Disable <link rel="preconnect"> for now
  2385. * Bug 18898: Exempt the meek extension from the signing requirement as well
  2386. * Bug 18899: Don't copy Torbutton, TorLauncher, etc. into meek profile
  2387. * Bug 18890: Test importScripts() for cache and network isolation
  2388. * Bug 18886: Hide pocket menu items when Pocket is disabled
  2389. * Bug 18703: Fix circuit isolation issues on Page Info dialog
  2390. * bug 19115: Tor Browser should not fall back to Bing as its search engine
  2391. * Bug 18915+19065: Use our search plugins in localized builds
  2392. * Bug 19176: Zip our language packs deterministically
  2393. * Bug 18811: Fix first-party isolation for blobs URLs in Workers
  2394. * Bug 18950: Disable or audit Reader View
  2395. * Bug 18886: Remove Pocket
  2396. * Bug 18619: Tor Browser reports "InvalidStateError" in browser console
  2397. * Bug 18945: Disable monitoring the connected state of Tor Browser users
  2398. * Bug 18855: Don't show error after add-on directory clean-up
  2399. * Bug 18885: Disable the option of logging TLS/SSL key material
  2400. * Bug 18770: SVGs should not show up on Page Info dialog when disabled
  2401. * Bug 18958: Spoof screen.orientation values
  2402. * Bug 19047: Disable Heartbeat prompts
  2403. * Bug 18914: Use English-only label in <isindex/> tags
  2404. * Bug 18996: Investigate server logging in esr45-based Tor Browser
  2405. * Bug 17790: Add unit tests for keyboard fingerprinting defenses
  2406. * Bug 18995: Regression test to ensure CacheStorage is disabled
  2407. * Bug 18912: Add automated tests for updater cert pinning
  2408. * Bug 16728: Add test cases for favicon isolation
  2409. * Bug 18976: Remove some FTE bridges
  2410. * Windows
  2411. * Bug 13419: Support ICU in Windows builds
  2412. * Bug 16874: Fix broken https://sports.yahoo.com/dailyfantasy page
  2413. * Bug 18767: Context menu is broken on Windows in ESR 45 based Tor Browser
  2414. * OS X
  2415. * Bug 6540: Support OS X Gatekeeper
  2416. * Bug 13252: Tor Browser should not store data in the application bundle
  2417. * Bug 18951: HTTPS-E is missing after update
  2418. * Bug 18904: meek-http-helper profile not updated
  2419. * Bug 18928: Upgrade is not smooth (requires another restart)
  2420. * Build System
  2421. * All Platforms
  2422. * Bug 18127: Add LXC support for building with Debian guest VMs
  2423. * Bug 16224: Don't use BUILD_HOSTNAME anymore in Firefox builds
  2424. * Bug 18919: Remove unused keys and unused dependencies
  2425. * Windows
  2426. * Bug 17895: Use NSIS 2.51 for installer to avoid DLL hijacking
  2427. * Bug 18290: Bump mingw-w64 commit we use
  2428. * OS X
  2429. * Bug 18331: Update toolchain for Firefox 45 ESR
  2430. * Bug 18690: Switch to Debian Wheezy guest VMs
  2431. * Linux
  2432. * Bug 18699: Stripping fails due to obsolete Browser/components directory
  2433. * Bug 18698: Include libgconf2-dev for our Linux builds
  2434. * Bug 15578: Switch to Debian Wheezy guest VMs (10.04 LTS is EOL)
  2435. Tor Browser 6.0a5-hardened -- April 28 2016
  2436. * All Platforms
  2437. * Update Firefox to 45.1.0esr
  2438. * Update Tor to 0.2.8.2-alpha
  2439. * Update Torbutton to 1.9.5.3
  2440. * Bug 18466: Make Torbutton compatible with Firefox ESR 45
  2441. * Translation updates
  2442. * Update Tor Launcher to 0.2.8.4
  2443. * Bug 13252: Do not store data in the application bundle
  2444. * Bug 10534: Don't advertise the help desk directly anymore
  2445. * Translation updates
  2446. * Update HTTPS-Everywhere to 5.1.6
  2447. * Update NoScript to 2.9.0.11
  2448. * Update meek to 0.22 (tag 0.22-18371-2)
  2449. * Bug 18371: Symlinks are incompatible with Gatekeeper signing
  2450. * Bug 15197 and child tickets: Rebase Tor Browser patches to ESR 45
  2451. * Bug 18900: Fix broken updater on Linux
  2452. * Bug 18042: Disable SHA1 certificate support
  2453. * Bug 18821: Disable libmdns support for desktop and mobile
  2454. * Bug 18848: Disable additional welcome URL shown on first start
  2455. * Bug 14970: Exempt our extensions from signing requirement
  2456. * Bug 16328: Disable MediaDevices.enumerateDevices
  2457. * Bug 16673: Disable HTTP Alternative-Services
  2458. * Bug 17167: Disable Mozilla's tracking protection
  2459. * Bug 18603: Disable performance-based WebGL fingerprinting option
  2460. * Bug 18738: Disable Selfsupport and Unified Telemetry
  2461. * Bug 18799: Disable Network Tickler
  2462. * Bug 18800: Remove DNS lookup in lockfile code
  2463. * Bug 18801: Disable dom.push preferences
  2464. * Bug 18802: Remove the JS-based Flash VM (Shumway)
  2465. * Bug 18863: Disable MozTCPSocket explicitly
  2466. * Bug 15640: Place Canvas MediaStream behind site permission
  2467. * Bug 16326: Verify cache isolation for Request and Fetch APIs
  2468. * Bug 18741: Fix OCSP and favicon isolation for ESR 45
  2469. * Bug 16998: Disable <link rel="preconnect"> for now
  2470. * Bug 17506: Reenable building hardened Tor Browser with startup cache
  2471. * Bug 18898: Exempt the meek extension from the signing requirement as well
  2472. * Bug 18899: Don't copy Torbutton, TorLauncher, etc. into meek profile
  2473. * Bug 18890: Test importScripts() for cache and network isolation
  2474. * Bug 18726: Add new default obfs4 bridge (GreenBelt)
  2475. * Build System
  2476. * Bug 16224: Don't use BUILD_HOSTNAME anymore in Firefox builds
  2477. * Bug 18699: Stripping fails due to obsolete Browser/components directory
  2478. * Bug 18698: Include libgconf2-dev for our Linux builds
  2479. Tor Browser 6.0a5 -- April 28 2016
  2480. * All Platforms
  2481. * Update Firefox to 45.1.0esr
  2482. * Update Tor to 0.2.8.2-alpha
  2483. * Update Torbutton to 1.9.5.3
  2484. * Bug 18466: Make Torbutton compatible with Firefox ESR 45
  2485. * Translation updates
  2486. * Update Tor Launcher to 0.2.9.1
  2487. * Bug 13252: Do not store data in the application bundle
  2488. * Bug 10534: Don't advertise the help desk directly anymore
  2489. * Translation updates
  2490. * Update HTTPS-Everywhere to 5.1.6
  2491. * Update NoScript to 2.9.0.11
  2492. * Update meek to 0.22 (tag 0.22-18371-2)
  2493. * Bug 18371: Symlinks are incompatible with Gatekeeper signing
  2494. * Bug 15197 and child tickets: Rebase Tor Browser patches to ESR 45
  2495. * Bug 18900: Fix broken updater on Linux
  2496. * Bug 18042: Disable SHA1 certificate support
  2497. * Bug 18821: Disable libmdns support for desktop and mobile
  2498. * Bug 18848: Disable additional welcome URL shown on first start
  2499. * Bug 14970: Exempt our extensions from signing requirement
  2500. * Bug 16328: Disable MediaDevices.enumerateDevices
  2501. * Bug 16673: Disable HTTP Alternative-Services
  2502. * Bug 17167: Disable Mozilla's tracking protection
  2503. * Bug 18603: Disable performance-based WebGL fingerprinting option
  2504. * Bug 18738: Disable Selfsupport and Unified Telemetry
  2505. * Bug 18799: Disable Network Tickler
  2506. * Bug 18800: Remove DNS lookup in lockfile code
  2507. * Bug 18801: Disable dom.push preferences
  2508. * Bug 18802: Remove the JS-based Flash VM (Shumway)
  2509. * Bug 18863: Disable MozTCPSocket explicitly
  2510. * Bug 15640: Place Canvas MediaStream behind site permission
  2511. * Bug 16326: Verify cache isolation for Request and Fetch APIs
  2512. * Bug 18741: Fix OCSP and favicon isolation for ESR 45
  2513. * Bug 16998: Disable <link rel="preconnect"> for now
  2514. * Bug 18898: Exempt the meek extension from the signing requirement as well
  2515. * Bug 18899: Don't copy Torbutton, TorLauncher, etc. into meek profile
  2516. * Bug 18890: Test importScripts() for cache and network isolation
  2517. * Bug 18726: Add new default obfs4 bridge (GreenBelt)
  2518. * Windows
  2519. * Bug 13419: Support ICU in Windows builds
  2520. * Bug 16874: Fix broken https://sports.yahoo.com/dailyfantasy page
  2521. * Bug 18767: Context menu is broken on Windows in ESR 45 based Tor Browser
  2522. * OS X
  2523. * Bug 6540: Support OS X Gatekeeper
  2524. * Bug 13252: Tor Browser should not store data in the application bundle
  2525. * Build System
  2526. * All Platforms
  2527. * Bug 18127: Add LXC support for building with Debian guest VMs
  2528. * Bug 16224: Don't use BUILD_HOSTNAME anymore in Firefox builds
  2529. * Windows
  2530. * Bug 17895: Use NSIS 2.51 for installer to avoid DLL hijacking
  2531. * Bug 18290: Bump mingw-w64 commit we use
  2532. * OS X
  2533. * Bug 18331: Update toolchain for Firefox 45 ESR
  2534. * Bug 18690: Switch to Debian Wheezy guest VMs
  2535. * Linux
  2536. * Bug 18699: Stripping fails due to obsolete Browser/components directory
  2537. * Bug 18698: Include libgconf2-dev for our Linux builds
  2538. Tor Browser 5.5.5 -- April 26 2016
  2539. * All Platforms
  2540. * Update Firefox to 38.8.0esr
  2541. * Update Tor Launcher to 0.2.7.9
  2542. * Bug 10534: Don't advertise the help desk directly anymore
  2543. * Translation updates
  2544. * Update HTTPS-Everywhere to 5.1.6
  2545. * Update NoScript to 2.9.0.11
  2546. * Bug 18726: Add new default obfs4 bridge (GreenBelt)
  2547. Tor Browser 6.0a4-hardened -- March 17 2016
  2548. * All Platforms
  2549. * Update Firefox to 38.7.1esr
  2550. * Update Torbutton to 1.9.5.2
  2551. * Bug 18557: Exempt Graphite from the Security Slider
  2552. * Bug 18536: Make Mosaddegh and MaBishomarim available on port 80 and 443
  2553. Tor Browser 6.0a4 -- March 17 2016
  2554. * All Platforms
  2555. * Update Firefox to 38.7.1esr
  2556. * Update Torbutton to 1.9.5.2
  2557. * Bug 18557: Exempt Graphite from the Security Slider
  2558. * Bug 18536: Make Mosaddegh and MaBishomarim available on port 80 and 443
  2559. Tor Browser 5.5.4 -- March 16 2016
  2560. * All Platforms
  2561. * Update Firefox to 38.7.1esr
  2562. * Update Torbutton to 1.9.4.5
  2563. * Bug 18557: Exempt Graphite from the Security Slider
  2564. * Bug 18536: Make Mosaddegh and MaBishomarim available on port 80 and 443
  2565. Tor Browser 6.0a3-hardened -- March 8 2016
  2566. * All Platforms
  2567. * Update Firefox to 38.7.0esr
  2568. * Update Tor to 0.2.8.1-alpha
  2569. * Update OpenSSL to 1.0.1s
  2570. * Update NoScript to 2.9.0.4
  2571. * Update HTTPS Everywhere to 5.1.4
  2572. * Update Torbutton to 1.9.5.1
  2573. * Bug 16990: Don't mishandle multiline commands
  2574. * Bug 18144: about:tor update arrow position is wrong
  2575. * Bug 16725: Allow resizing with non-default homepage
  2576. * Bug 16917: Allow users to more easily set a non-tor SSH proxy
  2577. * Translation updates
  2578. * Bug 18030: Isolate favicon requests on Page Info dialog
  2579. * Bug 18297: Use separate Noto JP,KR,SC,TC fonts
  2580. * Bug 18170: Make sure the homepage is shown after an update as well
  2581. * Bug 16728: Add test cases for favicon isolation
  2582. * Windows
  2583. * Bug 18292: Disable staged updates on Windows
  2584. Tor Browser 6.0a3 -- March 8 2016
  2585. * All Platforms
  2586. * Update Firefox to 38.7.0esr
  2587. * Update Tor to 0.2.8.1-alpha
  2588. * Update OpenSSL to 1.0.1s
  2589. * Update NoScript to 2.9.0.4
  2590. * Update HTTPS Everywhere to 5.1.4
  2591. * Update Torbutton to 1.9.5.1
  2592. * Bug 16990: Don't mishandle multiline commands
  2593. * Bug 18144: about:tor update arrow position is wrong
  2594. * Bug 16725: Allow resizing with non-default homepage
  2595. * Bug 16917: Allow users to more easily set a non-tor SSH proxy
  2596. * Translation updates
  2597. * Bug 18030: Isolate favicon requests on Page Info dialog
  2598. * Bug 18297: Use separate Noto JP,KR,SC,TC fonts
  2599. * Bug 18170: Make sure the homepage is shown after an update as well
  2600. * Bug 16728: Add test cases for favicon isolation
  2601. * Windows
  2602. * Bug 18292: Disable staged updates on Windows
  2603. Tor Browser 5.5.3 -- March 8 2016
  2604. * All Platforms
  2605. * Update Firefox to 38.7.0esr
  2606. * Update OpenSSL to 1.0.1s
  2607. * Update NoScript to 2.9.0.4
  2608. * Update HTTPS Everywhere to 5.1.4
  2609. * Update Torbutton to 1.9.4.4
  2610. * Bug 16990: Don't mishandle multiline commands
  2611. * Bug 18144: about:tor update arrow position is wrong
  2612. * Bug 16725: Allow resizing with non-default homepage
  2613. * Translation updates
  2614. * Bug 18030: Isolate favicon requests on Page Info dialog
  2615. * Bug 18297: Use separate Noto JP,KR,SC,TC fonts
  2616. * Bug 18170: Make sure the homepage is shown after an update as well
  2617. * Windows
  2618. * Bug 18292: Disable staged updates on Windows
  2619. Tor Browser 6.0a2-hardened -- February 15 2016
  2620. * All Platforms
  2621. * Update Firefox to 38.6.1esr
  2622. * Update NoScript to 2.9.0.3
  2623. * Bug 18168: Don't clear an iframe's window.name (fix of #16620)
  2624. * Bug 18137: Add two new obfs4 default bridges
  2625. * Windows
  2626. * Bug 18169: Whitelist zh-CN UI font
  2627. * OSX
  2628. * Bug 18172: Add Emoji support
  2629. * Linux
  2630. * Bug 18172: Add Emoji support
  2631. * Build System
  2632. * Linux
  2633. * Bug 15578: Switch to Debian Wheezy guest VMs (10.04 LTS is EOL)
  2634. * Bug 18198: Building the hardened Tor Browser in a Debian Wheezy VM is broken
  2635. Tor Browser 6.0a2 -- February 15 2016
  2636. * All Platforms
  2637. * Update Firefox to 38.6.1esr
  2638. * Update NoScript to 2.9.0.3
  2639. * Bug 18168: Don't clear an iframe's window.name (fix of #16620)
  2640. * Bug 18137: Add two new obfs4 default bridges
  2641. * Windows
  2642. * Bug 18169: Whitelist zh-CN UI font
  2643. * OSX
  2644. * Bug 18172: Add Emoji support
  2645. * Linux
  2646. * Bug 18172: Add Emoji support
  2647. Tor Browser 5.5.2 -- February 12 2016
  2648. * All Platforms
  2649. * Update Firefox to 38.6.1esr
  2650. * Update NoScript to 2.9.0.3
  2651. Tor Browser 5.5.1 -- February 4 2016
  2652. * All Platforms
  2653. * Bug 18168: Don't clear an iframe's window.name (fix of #16620)
  2654. * Bug 18137: Add two new obfs4 default bridges
  2655. * Windows
  2656. * Bug 18169: Whitelist zh-CN UI font
  2657. * OS X
  2658. * Bug 18172: Add Emoji support
  2659. * Linux
  2660. * Bug 18172: Add Emoji support
  2661. Tor Browser 6.0a1-hardened -- January 27 2016
  2662. * All Platforms
  2663. * Update Firefox to 38.6.0esr
  2664. * Update NoScript to 2.9.0.2
  2665. * Update Torbutton to 1.9.5
  2666. * Bug 16990: Show circuit display for connections using multi-party channels
  2667. * Bug 18019: Avoid empty prompt shown after non-en-US update
  2668. * Bug 18004: Remove Tor fundraising donation banner
  2669. * Code cleanup
  2670. * Translation updates
  2671. * Update Tor Launcher to 0.2.8.3
  2672. * Bug 18113: Randomly permutate available default bridges of chosen type
  2673. * Bug 11773: Setup wizard UI flow improvements
  2674. * Translation updates
  2675. * Bug 17428: Remove Flashproxy
  2676. * Bug 18115+18104+18071+18091: Update/add new obfs4 bridge
  2677. * Bug 18072: Change recommended pluggable transport type to obfs4
  2678. * Bug 18008: Create a new MAR Signing key and bake it into Tor Browser
  2679. * Bug 16322: Use onion address for DuckDuckGo search engine
  2680. * Bug 17917: Changelog after update is empty if JS is disabled
  2681. * Bug 17790: Map the proper SHIFT characters to the digit keys (fix of #15646)
  2682. Tor Browser 6.0a1 -- January 27 2016
  2683. * All Platforms
  2684. * Update Firefox to 38.6.0esr
  2685. * Update NoScript to 2.9.0.2
  2686. * Update Torbutton to 1.9.5
  2687. * Bug 16990: Show circuit display for connections using multi-party channels
  2688. * Bug 18019: Avoid empty prompt shown after non-en-US update
  2689. * Bug 18004: Remove Tor fundraising donation banner
  2690. * Code cleanup
  2691. * Translation updates
  2692. * Update Tor Launcher to 0.2.9
  2693. * Bug 18113: Randomly permutate available default bridges of chosen type
  2694. * Bug 11773: Setup wizard UI flow improvements
  2695. * Translation updates
  2696. * Bug 17428: Remove Flashproxy
  2697. * Bug 18115+18104+18071+18091: Update/add new obfs4 bridge
  2698. * Bug 18072: Change recommended pluggable transport type to obfs4
  2699. * Bug 18008: Create a new MAR Signing key and bake it into Tor Browser
  2700. * Bug 16322: Use onion address for DuckDuckGo search engine
  2701. * Bug 17917: Changelog after update is empty if JS is disabled
  2702. * Bug 17790: Map the proper SHIFT characters to the digit keys (fix of #15646)
  2703. * Build System
  2704. * Linux
  2705. * Bug 15578: Switch to Debian Wheezy guest VMs (10.04 LTS is EOL)
  2706. Tor Browser 5.5 -- January 26 2016
  2707. * All Platforms
  2708. * Update Firefox to 38.6.0esr
  2709. * Update libevent to 2.0.22-stable
  2710. * Update NoScript to 2.9.0.2
  2711. * Update Torbutton to 1.9.4.3
  2712. * Bug 16990: Show circuit display for connections using multi-party channels
  2713. * Bug 18019: Avoid empty prompt shown after non-en-US update
  2714. * Bug 18004: Remove Tor fundraising donation banner
  2715. * Bug 16940: After update, load local change notes
  2716. * Bug 17108: Polish about:tor appearance
  2717. * Bug 17568: Clean up tor-control-port.js
  2718. * Bug 16620: Move window.name handling into a Firefox patch
  2719. * Bug 17351: Code cleanup
  2720. * Translation updates
  2721. * Update Tor Launcher to 0.2.7.8
  2722. * Bug 18113: Randomly permutate available default bridges of chosen type
  2723. * Bug 13313: Bundle a fixed set of fonts to defend against fingerprinting
  2724. * Bug 10140: Add new Tor Browser locale (Japanese)
  2725. * Bug 17428: Remove Flashproxy
  2726. * Bug 13512: Load a static tab with change notes after an update
  2727. * Bug 9659: Avoid loop due to optimistic data SOCKS code (fix of #3875)
  2728. * Bug 15564: Isolate SharedWorkers by first-party domain
  2729. * Bug 16940: After update, load local change notes
  2730. * Bug 17759: Apply whitelist to local fonts in @font-face (fix of #13313)
  2731. * Bug 17009: Shift and Alt keys leak physical keyboard layout (fix of #15646)
  2732. * Bug 17790: Map the proper SHIFT characters to the digit keys (fix of #15646)
  2733. * Bug 17369: Disable RC4 fallback
  2734. * Bug 17442: Remove custom updater certificate pinning
  2735. * Bug 16620: Move window.name handling into a Firefox patch
  2736. * Bug 17220: Support math symbols in font whitelist
  2737. * Bug 10599+17305: Include updater and build patches needed for hardened builds
  2738. * Bug 18115+18104+18071+18091: Update/add new obfs4 bridge
  2739. * Bug 18072: Change recommended pluggable transport type to obfs4
  2740. * Bug 18008: Create a new MAR Signing key and bake it into Tor Browser
  2741. * Bug 16322: Use onion address for DuckDuckGo search engine
  2742. * Bug 17917: Changelog after update is empty if JS is disabled
  2743. * Windows
  2744. * Bug 17250: Add localized font names to font whitelist
  2745. * Bug 16707: Allow more system fonts to get used on Windows
  2746. * Bug 13819: Ship expert bundles with console enabled
  2747. * Bug 17250: Fix broken Japanese fonts
  2748. * Bug 17870: Add intermediate certificate for authenticode signing
  2749. * OS X
  2750. * Bug 17122: Rename Japanese OS X bundle
  2751. * Bug 16707: Allow more system fonts to get used on OS X
  2752. * Bug 17661: Whitelist font .Helvetica Neue DeskInterface
  2753. * Linux
  2754. * Bug 16672: Don't use font whitelisting for Linux users
  2755. Tor Browser 5.5a6-hardened -- January 7 2016
  2756. * All Platforms
  2757. * Update NoScript to 2.9
  2758. * Update HTTPS Everywhere to 5.1.2
  2759. * Bug 17931: Tor Browser crashes in LogMessageToConsole()
  2760. * Bug 17875: Discourage editing of torrc-defaults
  2761. Tor Browser 5.5a6 -- January 7 2016
  2762. * All Platforms
  2763. * Update NoScript to 2.9
  2764. * Update HTTPS Everywhere to 5.1.2
  2765. * Bug 17931: Tor Browser crashes in LogMessageToConsole()
  2766. * Bug 17875: Discourage editing of torrc-defaults
  2767. * Bug 17870: Add intermediate certificate for authenticode signing
  2768. Tor Browser 5.0.7 -- January 7 2016
  2769. * All Platforms
  2770. * Update NoScript to 2.9
  2771. * Update HTTPS Everywhere to 5.1.2
  2772. * Bug 17931: Tor Browser crashes in LogMessageToConsole()
  2773. * Bug 17875: Discourage editing of torrc-defaults
  2774. Tor Browser 5.5a5-hardened -- December 18 2015
  2775. * All Platforms
  2776. * Update Firefox to 38.5.0esr
  2777. * Update Tor to 0.2.7.6
  2778. * Update OpenSSL to 1.0.1q
  2779. * Update NoScript to 2.7
  2780. * Update Torbutton to 1.9.4.2
  2781. * Bug 16940: After update, load local change notes
  2782. * Bug 16990: Avoid matching '250 ' to the end of node name
  2783. * Bug 17565: Tor fundraising campaign donation banner
  2784. * Bug 17770: Fix alignments on donation banner
  2785. * Bug 17792: Include donation banner in some non en-US Tor Browsers
  2786. * Bug 17108: Polish about:tor appearance
  2787. * Bug 17568: Clean up tor-control-port.js
  2788. * Translation updates
  2789. * Update Tor Launcher to 0.2.8.1
  2790. * Bug 17344: Enumerate available language packs for language prompt
  2791. * Code clean-up
  2792. * Translation updates
  2793. * Bug 12516: Compile Tor Browser with -fwrapv
  2794. * Bug 9659: Avoid loop due to optimistic data SOCKS code (fix of #3875)
  2795. * Bug 15564: Isolate SharedWorkers by first-party domain
  2796. * Bug 16940: After update, load local change notes
  2797. * Bug 17759: Apply whitelist to local fonts in @font-face (fix of #13313)
  2798. * Bug 17747: Add ndnop3 as new default obfs4 bridge
  2799. * Bug 17009: Shift and Alt keys leak physical keyboard layout (fix of #15646)
  2800. * Bug 17369: Disable RC4 fallback
  2801. * Bug 17442: Remove custom updater certificate pinning
  2802. * Bug 16863: Avoid confusing error when loop.enabled is false
  2803. * Bug 17502: Add a preference for hiding "Open with" on download dialog
  2804. * Bug 17446: Prevent canvas extraction by third parties (fixup of #6253)
  2805. * Bug 16441: Suppress "Reset Tor Browser" prompt
  2806. Tor Browser 5.5a5 -- December 18 2015
  2807. * All Platforms
  2808. * Update Firefox to 38.5.0esr
  2809. * Update Tor to 0.2.7.6
  2810. * Update OpenSSL to 1.0.1q
  2811. * Update NoScript to 2.7
  2812. * Update Torbutton to 1.9.4.2
  2813. * Bug 16940: After update, load local change notes
  2814. * Bug 16990: Avoid matching '250 ' to the end of node name
  2815. * Bug 17565: Tor fundraising campaign donation banner
  2816. * Bug 17770: Fix alignments on donation banner
  2817. * Bug 17792: Include donation banner in some non en-US Tor Browsers
  2818. * Bug 17108: Polish about:tor appearance
  2819. * Bug 17568: Clean up tor-control-port.js
  2820. * Translation updates
  2821. * Bug 9659: Avoid loop due to optimistic data SOCKS code (fix of #3875)
  2822. * Bug 15564: Isolate SharedWorkers by first-party domain
  2823. * Bug 16940: After update, load local change notes
  2824. * Bug 17759: Apply whitelist to local fonts in @font-face (fix of #13313)
  2825. * Bug 17747: Add ndnop3 as new default obfs4 bridge
  2826. * Bug 17009: Shift and Alt keys leak physical keyboard layout (fix of #15646)
  2827. * Bug 17369: Disable RC4 fallback
  2828. * Bug 17442: Remove custom updater certificate pinning
  2829. * Bug 16863: Avoid confusing error when loop.enabled is false
  2830. * Bug 17502: Add a preference for hiding "Open with" on download dialog
  2831. * Bug 17446: Prevent canvas extraction by third parties (fixup of #6253)
  2832. * Bug 16441: Suppress "Reset Tor Browser" prompt
  2833. * Windows
  2834. * Bug 13819: Ship expert bundles with console enabled
  2835. * Bug 17250: Fix broken Japanese fonts
  2836. * OS X
  2837. * Bug 17661: Whitelist font .Helvetica Neue DeskInterface
  2838. Tor Browser 5.0.6 -- December 18 2015
  2839. * All Platforms
  2840. * Bug 17877: Tor Browser 5.0.5 is using the wrong Mozilla build tag
  2841. Tor Browser 5.0.5 -- December 15 2015
  2842. * All Platforms
  2843. * Update Firefox to 38.5.0esr
  2844. * Update Tor to 0.2.7.6
  2845. * Update OpenSSL to 1.0.1q
  2846. * Update NoScript to 2.7
  2847. * Update HTTPS Everywhere to 5.1.1
  2848. * Update Torbutton to 1.9.3.7
  2849. * Bug 16990: Avoid matching '250 ' to the end of node name
  2850. * Bug 17565: Tor fundraising campaign donation banner
  2851. * Bug 17770: Fix alignments on donation banner
  2852. * Bug 17792: Include donation banner in some non en-US Tor Browsers
  2853. * Translation updates
  2854. * Bug 17207: Hide MIME types and plugins from websites
  2855. * Bug 16909+17383: Adapt to HTTPS-Everywhere build changes
  2856. * Bug 16863: Avoid confusing error when loop.enabled is false
  2857. * Bug 17502: Add a preference for hiding "Open with" on download dialog
  2858. * Bug 17446: Prevent canvas extraction by third parties (fixup of #6253)
  2859. * Bug 16441: Suppress "Reset Tor Browser" prompt
  2860. * Bug 17747: Add ndnop3 as new default obfs4 bridge
  2861. Tor Browser 5.5a4 -- November 3 2015
  2862. * All Platforms
  2863. * Update Firefox to 38.4.0esr
  2864. * Update Tor to 0.2.7.4-rc
  2865. * Update NoScript to 2.6.9.39
  2866. * Update HTTPS-Everywhere to 5.1.1
  2867. * Update Torbutton to 1.9.4.1
  2868. * Bug 9623: Spoof Referer when leaving a .onion domain
  2869. * Bug 16620: Remove old window.name handling code
  2870. * Bug 17164: Don't show text-select cursor on circuit display
  2871. * Bug 17351: Remove unused code
  2872. * Translation updates
  2873. * Bug 17207: Hide MIME types and plugins from websites
  2874. * Bug 16909+17383: Adapt to HTTPS-Everywhere build changes
  2875. * Bug 16620: Move window.name handling into a Firefox patch
  2876. * Bug 17220: Support math symbols in font whitelist
  2877. * Bug 10599+17305: Include updater and build patches needed for hardened builds
  2878. * Bug 17318: Remove dead ScrambleSuit bridge
  2879. * Bug 17428: Remove default Flashproxy bridges
  2880. * Bug 17473: Update meek-amazon fingerprint
  2881. * Windows
  2882. * Bug 17250: Add localized font names to font whitelist
  2883. * OS X
  2884. * Bug 17122: Rename Japanese OS X bundle
  2885. * Linux
  2886. * Bug 17329: Ensure that non-ASCII characters can be typed (fixup of #5926)
  2887. Tor Browser 5.0.4 -- November 3 2015
  2888. * All Platforms
  2889. * Update Firefox to 38.4.0esr
  2890. * Update NoScript to 2.6.9.39
  2891. * Update Torbutton to 1.9.3.5
  2892. * Bug 9623: Spoof Referer when leaving a .onion domain
  2893. * Bug 16735: about:tor should accommodate different fonts/font sizes
  2894. * Bug 16937: Don't translate the homepage/spellchecker dictionary string
  2895. * Bug 17164: Don't show text-select cursor on circuit display
  2896. * Bug 17351: Remove unused code
  2897. * Translation updates
  2898. * Bug 16937: Remove the en-US dictionary from non en-US Tor Browser bundles
  2899. * Bug 17318: Remove dead ScrambleSuit bridge
  2900. * Bug 17473: Update meek-amazon fingerprint
  2901. * Bug 16983: Isolate favicon requests caused by the tab list dropdown
  2902. * Bug 17102: Don't crash while opening a second Tor Browser
  2903. * Windows:
  2904. * Bug 16906: Don't depend on Windows crypto DLLs
  2905. * Linux:
  2906. * Bug 17329: Ensure that non-ASCII characters can be typed (fixup of #5926)
  2907. Tor Browser 5.5a3 -- September 22 2015
  2908. * All Platforms
  2909. * Update Firefox to 38.3.0esr
  2910. * Update libevent to 2.0.22-stable
  2911. * Update Torbutton to 1.9.4
  2912. * Bug 16937: Don't translate the homepage/spellchecker dictionary string
  2913. * Bug 16735: about:tor should accommodate different fonts/font sizes
  2914. * Bug 16887: Update intl.accept_languages value
  2915. * Bug 15493: Update circuit display on new circuit info
  2916. * Bug 16797: brandShorterName is missing from brand.properties
  2917. * Translation updates
  2918. * Bug 10140: Add new Tor Browser locale (Japanese)
  2919. * Bug 17102: Don't crash while opening a second Tor Browser
  2920. * Bug 16983: Isolate favicon requests caused by the tab list dropdown
  2921. * Bug 13512: Load a static tab with change notes after an update
  2922. * Bug 16937: Remove the en-US dictionary from non en-US Tor Browser bundles
  2923. * Bug 7446: Tor Browser should not "fix up" .onion domains (or any domains)
  2924. * Bug 16837: Disable Firefox Hotfix updates
  2925. * Bug 16855: Allow blobs to be downloaded on first-party pages (fixes mega.nz)
  2926. * Bug 16781: Allow saving pdf files in built-in pdf viewer
  2927. * Bug 16842: Restore Media tab on Page information dialog
  2928. * Bug 16727: Disable about:healthreport page
  2929. * Bug 16783: Normalize NoScript default whitelist
  2930. * Bug 16775: Fix preferences dialog with security slider set to "High"
  2931. * Bug 13579: Update download progress bar automatically
  2932. * Bug 15646: Reduce keyboard layout fingerprinting in KeyboardEvent
  2933. * Bug 17046: Event.timeStamp should not reveal startup time
  2934. * Bug 16872: Fix warnings when opening about:downloads
  2935. * Bug 17097: Fix intermittent crashes when using the print dialog
  2936. * Windows
  2937. * Bug 16906: Fix Mingw-w64 compilation/Don't depend on Windows crypto DLLs
  2938. * Bug 16707: Allow more system fonts to get used on Windows
  2939. * OS X
  2940. * Bug 16910: Update copyright year in OS X bundles
  2941. * Bug 16707: Allow more system fonts to get used on OS X
  2942. * Linux
  2943. * Bug 16672: Don't use font whitelisting for Linux users
  2944. Tor Browser 5.0.3 -- September 22 2015
  2945. * All Platforms
  2946. * Update Firefox to 38.3.0esr
  2947. * Update Torbutton to 1.9.3.4
  2948. * Bug 16887: Update intl.accept_languages value
  2949. * Bug 15493: Update circuit display on new circuit info
  2950. * Bug 16797: brandShorterName is missing from brand.properties
  2951. * Bug 14429: Make sure the automatic resizing is disabled
  2952. * Translation updates
  2953. * Bug 7446: Tor Browser should not "fix up" .onion domains (or any domains)
  2954. * Bug 16837: Disable Firefox Hotfix updates
  2955. * Bug 16855: Allow blobs to be downloaded on first-party pages (fixes mega.nz)
  2956. * Bug 16781: Allow saving pdf files in built-in pdf viewer
  2957. * Bug 16842: Restore Media tab on Page information dialog
  2958. * Bug 16727: Disable about:healthreport page
  2959. * Bug 16783: Normalize NoScript default whitelist
  2960. * Bug 16775: Fix preferences dialog with security slider set to "High"
  2961. * Bug 13579: Update download progress bar automatically
  2962. * Bug 15646: Reduce keyboard layout fingerprinting in KeyboardEvent
  2963. * Bug 17046: Event.timeStamp should not reveal startup time
  2964. * Bug 16872: Fix warnings when opening about:downloads
  2965. * Bug 17097: Fix intermittent crashes when using the print dialog
  2966. * Windows
  2967. * Bug 16906: Fix Mingw-w64 compilation breakage
  2968. * OS X
  2969. * Bug 16910: Update copyright year in OS X bundles
  2970. Tor Browser 5.5a2 -- August 28 2015
  2971. * All Platforms:
  2972. * Update Firefox to 38.2.1esr
  2973. * Update NoScript to 2.6.9.36
  2974. * Bug 16771: Fix crash on some websites due to blob URIs
  2975. * Linux
  2976. * Bug 16860: Avoid duplicate desktop icons on Gnome and Unity
  2977. Tor Browser 5.0.2 -- August 27 2015
  2978. * All Platforms
  2979. * Update Firefox to 38.2.1esr
  2980. * Update NoScript to 2.6.9.36
  2981. * Linux
  2982. * Bug 16860: Avoid duplicate icons on Unity and Gnome
  2983. Tor Browser 5.0.1 -- August 18 2015
  2984. * All Platforms
  2985. * Bug 16771: Fix crash on some websites due to blob URIs
  2986. Tor Browser 5.5a1 -- August 11 2015
  2987. * All Platforms
  2988. * Update Firefox to 38.2.0esr
  2989. * Update NoScript to 2.6.9.34
  2990. * Update Torbutton to 1.9.3.3
  2991. * Bug 16731: TBB 5.0 a3/a4 fails to download a file on right click
  2992. * Bug 16730: Reset NoScript whitelist on upgrade
  2993. * Bug 16722: Prevent "Tiles" feature from being enabled after upgrade
  2994. * Bug 16488: Remove "Sign in to Sync" from the browser menu (fixup)
  2995. * Bug 14429: Make sure the automatic resizing is enabled
  2996. * Translation updates
  2997. * Update Tor Launcher to 0.2.7.7
  2998. * Translation updates
  2999. * Bug 16730: Prevent NoScript from updating the default whitelist
  3000. * Bug 16715: Use ThreadsafeIsCallerChrome() instead of IsCallerChrome()
  3001. * Bug 16572: Verify cache isolation for XMLHttpRequests in Web Workers
  3002. * Bug 16311: Fix navigation timing in ESR 38
  3003. * Bug 15646: Prevent keyboard layout fingerprinting in KeyboardEvent (fixup)
  3004. * Bug 16672: Change font whitelists and configs for rendering issues (partial)
  3005. Tor Browser 5.0 -- August 11 2015
  3006. * All Platforms
  3007. * Update Firefox to 38.2.0esr
  3008. * Update OpenSSL to 1.0.1p
  3009. * Update HTTPS-Everywhere to 5.0.7
  3010. * Update NoScript to 2.6.9.34
  3011. * Update meek to 0.20
  3012. * Update Tor to 0.2.6.10 with patches:
  3013. * Bug 16674: Allow FQDNs ending with a single '.' in our SOCKS host name checks.
  3014. * Bug 16430: Allow DNS names with _ characters in them (fixes nytimes.com)
  3015. * Bug 15482: Don't allow circuits to change while a site is in use
  3016. * Update Torbutton to 1.9.3.2
  3017. * Bug 16731: TBB 5.0 a3/a4 fails to download a file on right click
  3018. * Bug 16730: Reset NoScript whitelist on upgrade
  3019. * Bug 16722: Prevent "Tiles" feature from being enabled after upgrade
  3020. * Bug 16488: Remove "Sign in to Sync" from the browser menu (fixup)
  3021. * Bug 16268: Show Tor Browser logo on About page
  3022. * Bug 16639: Check for Updates menu item can cause update download failure
  3023. * Bug 15781: Remove the sessionstore filter
  3024. * Bug 15656: Sync privacy.resistFingerprinting with Torbutton pref
  3025. * Bug 16427: Use internal update URL to block updates (instead of 127.0.0.1)
  3026. * Bug 16200: Update Cache API usage and prefs for FF38
  3027. * Bug 16357: Use Mozilla API to wipe permissions db
  3028. * Bug 14429: Make sure the automatic resizing is disabled
  3029. * Translation updates
  3030. * Update Tor Launcher to 0.2.7.7
  3031. * Bug 16428: Use internal update URL to block updates (instead of 127.0.0.1)
  3032. * Bug 15145: Visually distinguish "proxy" and "bridge" screens.
  3033. * Translation updates
  3034. * Bug 16730: Prevent NoScript from updating the default whitelist
  3035. * Bug 16715: Use ThreadsafeIsCallerChrome() instead of IsCallerChrome()
  3036. * Bug 16572: Verify cache isolation for XMLHttpRequests in Web Workers
  3037. * Bug 16884: Prefer IPv6 when supported by the current Tor exit
  3038. * Bug 16488: Remove "Sign in to Sync" from the browser menu
  3039. * Bug 16662: Enable network.http.spdy.* prefs in meek-http-helper
  3040. * Bug 15703: Isolate mediasource URIs and media streams to first party
  3041. * Bug 16429+16416: Isolate blob URIs to first party
  3042. * Bug 16632: Turn on the background updater and restart prompting
  3043. * Bug 16528: Prevent indexedDB Modernizr site breakage on Twitter and elsewhere
  3044. * Bug 16523: Fix in-browser JavaScript debugger
  3045. * Bug 16236: Windows updater: avoid writing to the registry
  3046. * Bug 16625: Fully disable network connection prediction
  3047. * Bug 16495: Fix SVG crash when security level is set to "High"
  3048. * Bug 13247: Fix meek profile error after bowser restarts
  3049. * Bug 16005: Relax WebGL minimal mode
  3050. * Bug 16300: Isolate Broadcast Channels to first party
  3051. * Bug 16439: Remove Roku screencasting code
  3052. * Bug 16285: Disabling EME bits
  3053. * Bug 16206: Enforce certificate pinning
  3054. * Bug 15910: Disable Gecko Media Plugins for now
  3055. * Bug 13670: Isolate OCSP requests by first party domain
  3056. * Bug 16448: Isolate favicon requests by first party
  3057. * Bug 7561: Disable FTP request caching
  3058. * Bug 6503: Fix single-word URL bar searching
  3059. * Bug 15526: ES6 page crashes Tor Browser
  3060. * Bug 16254: Disable GeoIP-based search results.
  3061. * Bug 16222: Disable WebIDE to prevent remote debugging and addon downloads.
  3062. * Bug 13024: Disable DOM Resource Timing API
  3063. * Bug 16340: Disable User Timing API
  3064. * Bug 14952: Disable HTTP/2
  3065. * Bug 1517: Reduce precision of time for Javascript
  3066. * Bug 13670: Ensure OCSP & favicons respect URL bar domain isolation
  3067. * Bug 16311: Fix navigation timing in ESR 38
  3068. * Windows
  3069. * Bug 16014: Staged update fails if meek is enabled
  3070. * Bug 16269: repeated add-on compatibility check after update (meek enabled)
  3071. * Mac OS
  3072. * Use OSX 10.7 SDK
  3073. * Bug 16253: Tor Browser menu on OS X is broken with ESR 38
  3074. * Bug 15773: Enable ICU on OS X
  3075. * Build System
  3076. * Bug 16351: Upgrade our toolchain to use GCC 5.1
  3077. * Bug 15772 and child tickets: Update build system for Firefox 38
  3078. * Bugs 15921+15922: Fix build errors during Mozilla Tryserver builds
  3079. * Bug 15864: rename sha256sums.txt to sha256sums-unsigned-build.txt
  3080. Tor Browser 5.0a4 -- August 3 2015
  3081. * All Platforms
  3082. * Update Tor to 0.2.7.2-alpha with patches:
  3083. * Bug 15482: Don't allow circuits to change while a site is in use
  3084. * Update OpenSSL to 1.0.1p
  3085. * Update HTTPS-Everywhere to 5.0.7
  3086. * Update NoScript to 2.6.9.31
  3087. * Update Torbutton to 1.9.3.1
  3088. * Bug 16268: Show Tor Browser logo on About page
  3089. * Bug 16639: Check for Updates menu item can cause update download failure
  3090. * Bug 15781: Remove the sessionstore filter
  3091. * Bug 15656: Sync privacy.resistFingerprinting with Torbutton pref
  3092. * Translation updates
  3093. * Bug 16884: Prefer IPv6 when supported by the current Tor exit
  3094. * Bug 16488: Remove "Sign in to Sync" from the browser menu
  3095. * Bug 13313: Bundle a fixed set of fonts to defend against fingerprinting
  3096. * Bug 16662: Enable network.http.spdy.* prefs in meek-http-helper
  3097. * Bug 15646: Prevent keyboard layout fingerprinting in KeyboardEvent (fixup)
  3098. * Bug 15703: Isolate mediasource URIs and media streams to first party
  3099. * Bug 16429+16416: Isolate blob URIs to first party
  3100. * Bug 16632: Turn on the background updater and restart prompting
  3101. * Bug 16528: Prevent indexedDB Modernizr site breakage on Twitter and elsewhere
  3102. * Bug 16523: Fix in-browser JavaScript debugger
  3103. * Bug 16236: Windows updater: avoid writing to the registry
  3104. * Bug 16005: Restrict WebGL minimal mode a bit (fixup)
  3105. * Bug 16625: Fully disable network connection prediction
  3106. * Bug 16495: Fix SVG crash when security level is set to "High"
  3107. * Build System
  3108. * Bug 15864: rename sha256sums.txt to sha256sums-unsigned-build.txt
  3109. Tor Browser 5.0a3 -- June 30 2015
  3110. * All Platforms
  3111. * Update Firefox to 38.1.0esr
  3112. * Update OpenSSL to 1.0.1o
  3113. * Update NoScript to 2.6.9.27
  3114. * Update meek to 0.20
  3115. * Tor patch backport
  3116. * Bug 16430: Allow DNS names with _ characters in them (fixes nytimes.com)
  3117. * Update Torbutton to 1.9.3.0
  3118. * Bug 16403: Set search parameters for Disconnect
  3119. * Bug 14429: Make sure the automatic resizing is disabled
  3120. * Bug 16427: Use internal update URL to block updates (instead of 127.0.0.1)
  3121. * Bug 16200: Update Cache API usage and prefs for FF38
  3122. * Bug 16357: Use Mozilla API to wipe permissions db
  3123. * Translation updates
  3124. * Update Tor Launcher to 0.2.7.6
  3125. * Bug 16428: Use internal update URL to block updates (instead of 127.0.0.1)
  3126. * Bug 15145: Visually distinguish "proxy" and "bridge" screens.
  3127. * Translation updates
  3128. * Bug 13247: Fix meek profile error after bowser restarts
  3129. * Bug 16397: Fix crash related to disabling SVG
  3130. * Bug 16403: Set search parameters for Disconnect
  3131. * Bug 16446: Update FTE bridge #1 fingerprint
  3132. * Bug 15646: Prevent keyboard layout fingerprinting in KeyboardEvent
  3133. * Bug 16005: Relax WebGL minimal mode
  3134. * Bug 16300: Isolate Broadcast Channels to first party
  3135. * Bug 16439: Remove Roku screencasting code
  3136. * Bug 16285: Disabling EME bits
  3137. * Bug 16206: Enforce certificate pinning
  3138. * Bug 15910: Disable GMPs for now
  3139. * Bug 13670: Isolate OCSP requests by first party domain
  3140. * Bug 16448: Isolate favicon requests by first party
  3141. * Bug 7561: Disable FTP request caching
  3142. * Bug 6503: Fix single-word URL bar searching
  3143. * Bug 15526: ES6 page crashes Tor Browser
  3144. * Bug 16254: Disable GeoIP-based search results.
  3145. * Bug 16222: Disable WebIDE to prevent remote debugging and addon downloads.
  3146. * Bug 13024: Disable DOM Resource Timing API
  3147. * Bug 16340: Disable User Timing API
  3148. * Bug 14952: Disable HTTP/2
  3149. * Mac OS
  3150. * Use OSX 10.7 SDK
  3151. * Bug 16253: Tor Browser menu on OS X is broken with ESR 38
  3152. * Build System
  3153. * Bug 16351: Upgrade our toolchain to use GCC 5.1
  3154. * Bug 15772 and child tickets: Update build system for Firefox 38
  3155. Tor Browser 4.5.3 -- June 30 2015
  3156. * All Platforms
  3157. * Update Firefox to 31.8.0esr
  3158. * Update OpenSSL to 1.0.1o
  3159. * Update NoScript to 2.6.9.27
  3160. * Update Torbutton to 1.9.2.8
  3161. * Bug 16403: Set search parameters for Disconnect
  3162. * Bug 14429: Make sure the automatic resizing is disabled
  3163. * Translation updates
  3164. * Bug 16397: Fix crash related to disabling SVG
  3165. * Bug 16403: Set search parameters for Disconnect
  3166. * Bug 16446: Update FTE bridge #1 fingerprint
  3167. * Tor patch backport
  3168. * Bug 16430: Allow DNS names with _ characters in them (fixes nytimes.com)
  3169. Tor Browser 5.0a2 -- June 15 2015
  3170. * All Platforms
  3171. * Update Tor to 0.2.7.1-alpha
  3172. * Update HTTPS-Everywhere to 5.0.5
  3173. * Update OpenSSL to 1.0.1n
  3174. * Update NoScript to 2.6.9.26
  3175. * Update meek to 0.19
  3176. * Update Torbutton to 1.9.2.7
  3177. * Bug 15984: Disabling Torbutton breaks the Add-ons Manager
  3178. * Bug 14429: Make sure the automatic resizing is enabled
  3179. * Translation updates
  3180. * Bug 16130: Defend against logjam attack
  3181. * Bug 15984: Disabling Torbutton breaks the Add-ons Manager
  3182. * Windows
  3183. * Bug 16014: Staged update fails if meek is enabled
  3184. * Bug 16269: repeated add-on compatibility check after update (meek enabled)
  3185. * Linux
  3186. * Bug 16026: Fix crash in GStreamer
  3187. * Bug 16083: Update comment in start-tor-browser
  3188. Tor Browser 4.5.2 -- June 15 2015
  3189. * All Platforms
  3190. * Update Tor to 0.2.6.9
  3191. * Update HTTPS-Everywhere to 5.0.5
  3192. * Update OpenSSL to 1.0.1n
  3193. * Update NoScript to 2.6.9.26
  3194. * Update Torbutton to 1.9.2.6
  3195. * Bug 15984: Disabling Torbutton breaks the Add-ons Manager
  3196. * Bug 14429: Make sure the automatic resizing is disabled
  3197. * Translation updates
  3198. * Bug 16130: Defend against logjam attack
  3199. * Bug 15984: Disabling Torbutton breaks the Add-ons Manager
  3200. * Linux
  3201. * Bug 16026: Fix crash in GStreamer
  3202. * Bug 16083: Update comment in start-tor-browser
  3203. Tor Browser 5.0a1 -- May 14 2015
  3204. * All Platforms
  3205. * Update Firefox to 31.7.0esr
  3206. * Update meek to 0.18
  3207. * Update Tor Launcher to 0.2.7.5
  3208. * Translation updates only
  3209. * Update Torbutton to 1.9.2.5
  3210. * Bug 15837: Show descriptions if unchecking custom mode
  3211. * Bug 15927: Force update of the NoScript UI when changing security level
  3212. * Bug 15915: Hide circuit display if it is disabled.
  3213. * Bug 14429: Improved automatic window resizing
  3214. * Translation updates
  3215. * Bug 15945: Disable NoScript's ClearClick protection for now
  3216. * Bug 15933: Isolate by base (top-level) domain name instead of FQDN
  3217. * Bug 15857: Fix file descriptor leak in updater that caused update failures
  3218. * Bug 15899: Fix errors with downloading and displaying PDFs
  3219. * Bug 15773: Enable ICU on OS X
  3220. * Bug 1517: Reduce precision of time for Javascript
  3221. * Bug 13670: Ensure OCSP & favicons respect URL bar domain isolation
  3222. * Bug 13875: Improve the spoofing of window.devicePixelRatio
  3223. * Windows
  3224. * Bug 15872: Fix meek pluggable transport startup issue with Windows 7
  3225. * Build System
  3226. * Bug 15947: Support Ubuntu 14.04 LXC hosts via LXC_EXECUTE=lxc-execute env var
  3227. * Bugs 15921+15922: Fix build errors during Mozilla Tryserver builds
  3228. Tor Browser 4.5.1 -- May 12 2015
  3229. * All Platforms
  3230. * Update Firefox to 31.7.0esr
  3231. * Update meek to 0.18
  3232. * Update Tor Launcher to 0.2.7.5
  3233. * Translation updates only
  3234. * Update Torbutton to 1.9.2.3
  3235. * Bug 15837: Show descriptions if unchecking custom mode
  3236. * Bug 15927: Force update of the NoScript UI when changing security level
  3237. * Bug 15915: Hide circuit display if it is disabled.
  3238. * Translation updates
  3239. * Bug 15945: Disable NoScript's ClearClick protection for now
  3240. * Bug 15933: Isolate by base (top-level) domain name instead of FQDN
  3241. * Bug 15857: Fix file descriptor leak in updater that caused update failures
  3242. * Bug 15899: Fix errors with downloading and displaying PDFs
  3243. * Windows
  3244. * Bug 15872: Fix meek pluggable transport startup issue with Windows 7
  3245. * Build System
  3246. * Bug 15947: Support Ubuntu 14.04 LXC hosts via LXC_EXECUTE=lxc-execute env var
  3247. * Bugs 15921+15922: Fix build errors during Mozilla Tryserver builds
  3248. Tor Browser 4.5 -- Apr 28 2015
  3249. * All Platforms
  3250. * Update Tor to 0.2.6.7 with additional patches:
  3251. * Bug 15482: Reset timestamp_dirty each time a SOCKSAuth circuit is used
  3252. * Update NoScript to 2.6.9.22
  3253. * Update HTTPS-Everywhere to 5.0.3
  3254. * Bug 15689: Resume building HTTPS-Everywhere from git tags
  3255. * Update meek to 0.17
  3256. * Update obfs4proxy to 0.0.5
  3257. * Update Tor Launcher to 0.2.7.4
  3258. * Bug 15704: Do not enable network if wizard is opened
  3259. * Bug 11879: Stop bootstrap if Cancel or Open Settings is clicked
  3260. * Bug 13576: Don't strip "bridge" from the middle of bridge lines
  3261. * Bug 15657: Display the host:port of any connection faiures in bootstrap
  3262. * Update Torbutton to 1.9.2.2
  3263. * Bug 15562: Bind SharedWorkers to thirdparty pref
  3264. * Bug 15533: Restore default security level when restoring defaults
  3265. * Bug 15510: Close Tor Circuit UI control port connections on New Identity
  3266. * Bug 15472: Make node text black in circuit status UI
  3267. * Bug 15502: Wipe blob URIs on New Identity
  3268. * Bug 15795: Some security slider prefs do not trigger custom checkbox
  3269. * Bug 14429: Disable automatic window resizing for now
  3270. * Bug 4100: Raise HTTP Keep-Alive back to 115 second default
  3271. * Bug 13875: Spoof window.devicePixelRatio to avoid DPI fingerprinting
  3272. * Bug 15411: Remove old (and unused) cacheDomain cache isolation mechanism
  3273. * Bugs 14716+13254: Fix issues with HTTP Auth usage and TLS connection info display
  3274. * Bug 15502: Isolate blob URI scope to URL domain; block WebWorker access
  3275. * Bug 15794: Crash on some pages with SVG images if SVG is disabled
  3276. * Bug 15562: Disable Javascript SharedWorkers due to third party tracking
  3277. * Bug 15757: Disable Mozilla video statistics API extensions
  3278. * Bug 15758: Disable Device Sensor APIs
  3279. * Linux
  3280. * Bug 15747: Improve start-tor-browser argument handling
  3281. * Bug 15672: Provide desktop app registration+unregistration for Linux
  3282. * Windows
  3283. * Bug 15539: Make installer exe signatures reproducibly removable
  3284. * Bug 10761: Fix instances of shutdown crashes
  3285. Tor Browser 4.5a5 -- Mar 31 2015
  3286. * All Platforms
  3287. * Update Firefox to 31.6.0esr
  3288. * Update OpenSSL to 1.0.1m
  3289. * Update Tor to 0.2.6.6
  3290. * Update NoScript to 2.6.9.19
  3291. * Update HTTPS-Everywhere to 5.0
  3292. * Update meek to 0.16
  3293. * Update Tor Launcher to 0.2.7.3
  3294. * Bug 13983: Directory search path fix for Tor Messanger+TorBirdy
  3295. * Update Torbutton to 1.9.1.0
  3296. * Bug 9387: "Security Slider 1.0"
  3297. * Include descriptions and tooltip hints for security levels
  3298. * Notify users that the security slider exists
  3299. * Flip slider so that "low" is on the bottom
  3300. * Make use of new SVG and MathML prefs
  3301. * Bug 13766: Set a 10 minute circuit lifespan for non-content requests
  3302. * Bug 15460: Ensure FTP urls use content-window circuit isolation
  3303. * Bug 13650: Clip initial window height to 1000px
  3304. * Bug 14429: Ensure windows can only be resized to 200x100px multiples
  3305. * Bug 15334: Display Cookie Protections menu if disk records are enabled
  3306. * Bug 14324: Show HS circuit in Tor circuit display
  3307. * Bug 15086: Handle RTL text in Tor circuit display
  3308. * Bug 15085: Fix about:tor RTL text alignment problems
  3309. * Bug 10216: Add a pref to disable the local tor control port test
  3310. * Bug 14937: Show meek and flashproxy bridges in tor circuit display
  3311. * Bugs 13891+15207: Fix exceptions/errors in circuit display with bridges
  3312. * Bug 13019: Change locale hiding pref to boolean
  3313. * Bug 7255: Warn users about maximizing windows
  3314. * Bug 14631: Improve profile access error msgs (strings).
  3315. * Pluggable Transport Dependency Updates:
  3316. * Bug 15448: Use golang 1.4.2 for meek and obs4proxy
  3317. * Bug 15265: Switch go.net repo to golang.org/x/net
  3318. * Bug 14937: Hard-code meek and flashproxy node fingerprints
  3319. * Bug 13019: Prevent Javascript from leaking system locale
  3320. * Bug 10280: Improved fix to prevent loading plugins into address space
  3321. * Bug 15406: Only include addons in incremental updates if they actually update
  3322. * Bug 15029: Don't prompt to include missing plugins
  3323. * Bug 12827: Create preference to disable SVG images (for security slider)
  3324. * Bug 13548: Create preference to disable MathML (for security slider)
  3325. * Bug 14631: Improve startup error messages for filesystem permissions issues
  3326. * Bug 15482: Don't allow circuits to change while a site is in use
  3327. * Linux
  3328. * Bug 13375: Create a hybrid GUI/desktop/shell launcher wrapper
  3329. * Bug 12468: Only print/write log messages if launched with --debug
  3330. * Windows
  3331. * Bug 3861: Begin signing Tor Browser for Windows the Windows way
  3332. * Bug 15201: Disable 'runas Administrator' codepaths in updater
  3333. * Bug 14688: Create shortcuts to desktop and start menu by default (optional)
  3334. Tor Browser 4.0.6 -- Mar 31 2015
  3335. * All Platforms
  3336. * Update Firefox to 31.6.0esr
  3337. * Update meek to 0.16
  3338. * Update OpenSSL to 1.0.1m
  3339. Tor Browser 4.0.5 -- Mar 23 2015
  3340. * All Platforms
  3341. * Update Firefox to 31.5.3esr
  3342. * Update Tor to 0.2.5.11
  3343. * Update NoScript to 2.6.9.19
  3344. Tor Browser 4.5a4 -- Feb 24 2015
  3345. * All Platforms
  3346. * Update Firefox to 31.5.0esr
  3347. * Update Tor to 0.2.6.3-alpha
  3348. * Update OpenSSL to 1.0.1l
  3349. * Update NoScript to 2.6.9.15
  3350. * Update obfs4proxy to 0.0.4
  3351. * Use obfs4proxy for ScrambleSuit bridges
  3352. * Update Torbutton to 1.9.0.0
  3353. * Bug 13882: Fix display of bridges after bridge settings have been changed
  3354. * Bug 5698: Use "Tor Browser" branding in "About Tor Browser" dialog
  3355. * Bug 10280: Strings and pref for preventing plugin initialization.
  3356. * Bug 14866: Show correct circuit when more than one exists for a given domain
  3357. * Bug 9442: Add New Circuit button to Torbutton menu
  3358. * Bug 9906: Warn users before closing all windows and performing new identity.
  3359. * Bug 8400: Prompt for restart if disk records are enabled/disabled.
  3360. * Bug 14630: Hide Torbutton's proxy settings tab.
  3361. * Bug 14632: Disable Cookie Manager until we get it working.
  3362. * Bug 11175: Remove "About Torbutton" from onion menu.
  3363. * Bug 13900: Remove remaining SafeCache code in favor of C++ patch
  3364. * Bug 14490: Use Disconnect search in about:tor search box
  3365. * Bug 14392: Don't steal input focus in about:tor search box
  3366. * Bug 11236: Don't set omnibox order in Torbutton (to prevent translation)
  3367. * Bug 13406: Stop directing users to download-easy.html.en on update
  3368. * Bug 9387: Handle "custom" mode better in Security Slider
  3369. * Bug 12430: Bind jar: pref to Security Slider
  3370. * Bug 14448: Restore Torbutton menu operation on non-English localizations
  3371. * Translation updates
  3372. * Update Tor Launcher to 0.2.7.2
  3373. * Bug 13271: Display Bridge Configuration wizard pane before Proxy pane
  3374. * Bug 14336: Fix navigation button display issues on some wizard panes
  3375. * Translation updates
  3376. * Bug 14203: Prevent meek from displaying an extra update notification
  3377. * Bug 14849: Remove new NoScript menu option to make permissions permanent
  3378. * Bug 14851: Set NoScript pref to disable permanent permissions
  3379. * Bug 14490: Make Disconnect the default omnibox search engine
  3380. * Bug 11236: Fix omnibox order for non-English builds
  3381. * Also remove Amazon, eBay and bing; add Youtube and Twitter
  3382. * Bug 10280: Don't load any plugins into the address space.
  3383. * Bug 14392: Make about:tor hide itself from the URL bar
  3384. * Bug 12430: Provide a preference to disable remote jar: urls
  3385. * Bug 13900: Remove 3rd party HTTP auth tokens via Firefox patch
  3386. * Bug 5698: Fix branding in "About Torbrowser" window
  3387. * Windows:
  3388. * Bug 13169: Don't use /dev/random on Windows for SSP
  3389. * Linux:
  3390. * Bug 13717: Make sure we use the bash shell on Linux
  3391. Tor Browser 4.0.4 -- Feb 24 2015
  3392. * All Platforms
  3393. * Update Firefox to 31.5.0esr
  3394. * Update OpenSSL to 1.0.1l
  3395. * Update NoScript to 2.6.9.15
  3396. * Update HTTPS-Everywhere to 4.0.3
  3397. * Bug 14203: Prevent meek from displaying an extra update notification
  3398. * Bug 14849: Remove new NoScript menu option to make permissions permanent
  3399. * Bug 14851: Set NoScript pref to disable permanent permissions
  3400. Tor Browser 4.5a3 -- Jan 19 2015
  3401. * All Platforms
  3402. * Update Firefox to 31.4.0esr
  3403. * Update Tor to 0.2.6.2-alpha
  3404. * Update NoScript to 2.6.9.10
  3405. * Update HTTPS Everywhere to 5.0development.2
  3406. * Update meek to 0.15
  3407. * Update Torbutton to 1.8.1.3
  3408. * Bug 13998: Handle changes in NoScript 2.6.9.8+
  3409. * Bug 14100: Option to hide NetworkSettings menuitem
  3410. * Bug 13079: Option to skip control port verification
  3411. * Bug 13835: Option to change default Tor Browser homepage
  3412. * Bug 11449: Fix new identity error if NoScript is not enabled
  3413. * Bug 13881: Localize strings for tor circuit display
  3414. * Bug 9387: Incorporate user feedback
  3415. * Bug 13671: Fixup for circuit display if bridges are used
  3416. * Translation updates
  3417. * Update Tor Launcher to 0.2.7.1
  3418. * Bug 14122: Hide logo if TOR_HIDE_BROWSER_LOGO set
  3419. * Translation updates
  3420. * Bug 13379: Sign our MAR files
  3421. * Bug 13788: Fix broken meek in 4.5-alpha series
  3422. * Bug 13439: No canvas prompt for content callers
  3423. Tor Browser 4.0.3 -- Jan 13 2015
  3424. * All Platforms
  3425. * Update Firefox to 31.4.0esr
  3426. * Update NoScript to 2.6.9.10
  3427. * Update meek to 0.15
  3428. * Update Tor Launcher to 0.2.7.0.2
  3429. * Translation updates only
  3430. Tor Browser 4.5-alpha-2 -- Dec 5 2014
  3431. * All Platforms
  3432. * Update Firefox to 31.3.0esr
  3433. * Update NoScript to 2.6.9.5
  3434. * Update HTTPS Everywhere to 5.0development.1
  3435. * Update Torbutton to 1.8.1.2
  3436. * Bug 13672: Make circuit display optional
  3437. * Bug 13671: Make bridges visible on circuit display
  3438. * Bug 9387: Incorporate user feedback
  3439. * Bug 13784: Remove third party authentication tokens
  3440. * Bug 13435: Remove our custom POODLE fix (fixed by Mozilla in ESR 31.3.0)
  3441. Tor Browser 4.0.2 -- Dec 2 2014
  3442. * All Platforms
  3443. * Update Firefox to 31.3.0esr
  3444. * Update NoScript to 2.6.9.5
  3445. * Update HTTPS Everywhere to 4.0.2
  3446. * Update Torbutton to 1.7.0.2
  3447. * Bug 13019: Synchronize locale spoofing pref with our Firefox patch
  3448. * Bug 13746: Properly link Torbutton UI to thirdparty pref.
  3449. * Bug 13742: Fix domain isolation for content cache and disk-enabled browsing mode
  3450. * Bug 5926: Prevent JS engine locale leaks (by setting the C library locale)
  3451. * Bug 13504: Remove unreliable/unreachable non-public bridges
  3452. * Bug 13435: Remove our custom POODLE fix
  3453. * Windows
  3454. * Bug 13443: Re-enable DirectShow; fix crash with mingw patch.
  3455. * Bug 13558: Fix crash on Windows XP during download folder changing
  3456. * Bug 13594: Fix update failure for Windows XP users
  3457. Tor Browser 4.5-alpha-1 -- Nov 14 2014
  3458. * All Platforms
  3459. * Bug 3455: Patch Firefox SOCKS and proxy filters to allow user+pass isolation
  3460. * Bug 11955: Backport HTTPS Certificate Pinning patches from Firefox 32
  3461. * Bug 13684: Backport Mozilla bug #1066190 (pinning issue fixed in Firefox 33)
  3462. * Bug 13019: Make JS engine use English locale if a pref is set by Torbutton
  3463. * Bug 13301: Prevent extensions incompatibility error after upgrades
  3464. * Bug 13460: Fix MSVC compilation issue
  3465. * Bug 13504: Remove stale bridges from default bridge set
  3466. * Bug 13742: Fix domain isolation for content cache and disk-enabled browsing mode
  3467. * Update Tor to 0.2.6.1-alpha
  3468. * Update NoScript to 2.6.9.3
  3469. * Update Torbutton to 1.8.1.1
  3470. * Bug 9387: Provide a "Security Slider" for vulnerability surface reduction
  3471. * Bug 13019: Synchronize locale spoofing pref with our Firefox patch
  3472. * Bug 3455: Use SOCKS user+pass to isolate all requests from the same url domain
  3473. * Bug 8641: Create browser UI to indicate current tab's Tor circuit IPs
  3474. * Bug 13651: Prevent circuit-status related UI hang.
  3475. * Bug 13666: Various circuit status UI fixes
  3476. * Bugs 13742+13751: Remove cache isolation code in favor of direct C++ patch
  3477. * Bug 13746: Properly update third party isolation pref if disabled from UI
  3478. * Bug 13586: Make meek use TLS session tickets (to look like stock Firefox).
  3479. * Bug 12903: Include obfs4proxy pluggable transport
  3480. * Windows
  3481. * Bug 13443: Re-enable DirectShow; fix crash with mingw patch.
  3482. * Bug 13558: Fix crash on Windows XP during download folder changing
  3483. * Bug 13091: Make app name "Tor Browser" instead of "Tor"
  3484. * Bug 13594: Fix update failure for Windows XP users
  3485. * Mac
  3486. * Bug 10138: Switch to 64bit builds for MacOS
  3487. Tor Browser 4.0.1 -- Oct 30 2014
  3488. * All Platforms
  3489. * Update Tor to 0.2.5.10
  3490. * Update NoScript to 2.6.9.3
  3491. * Bug 13301: Prevent extensions incompatibility error after upgrades
  3492. * Bug 13460: Fix MSVC compilation issue
  3493. * Windows
  3494. * Bug 13443: Disable DirectShow to prevent crashes on many sites
  3495. * Bug 13091: Make app name "Tor Browser" instead of "Tor"
  3496. Tor Browser 4.0 -- Oct 15 2014
  3497. * All Platforms
  3498. * Update Firefox to 31.2.0esr
  3499. * Update Torbutton to 1.7.0.1
  3500. * Bug 13378: Prevent addon reordering in toolbars on first-run.
  3501. * Bug 10751: Adapt Torbutton to ESR31's Australis UI.
  3502. * Bug 13138: ESR31-about:tor shows "Tor is not working"
  3503. * Bug 12947: Adapt session storage blocker to ESR 31.
  3504. * Bug 10716: Take care of drag/drop events in ESR 31.
  3505. * Bug 13366: Fix cert exemption dialog when disk storage is enabled.
  3506. * Update Tor Launcher to 0.2.7.0.1
  3507. * Translation updates only
  3508. * Udate fteproxy to 0.2.19
  3509. * Update NoScript to 2.6.9.1
  3510. * Bug 13416: Defend against new SSLv3 attack (poodle).
  3511. * Bug 13027: Spoof window.navigator useragent values in JS WebWorker threads
  3512. * Bug 13016: Hide CSS -moz-osx-font-smoothing values.
  3513. * Bug 13356: Meek and other symlinks missing after complete update.
  3514. * Bug 13025: Spoof screen orientation to landscape-primary.
  3515. * Bug 13346: Disable Firefox "slow to start" warnings and recordkeeping.
  3516. * Bug 13318: Minimize number of buttons on the browser toolbar.
  3517. * Bug 10715: Enable WebGL on Windows (still click-to-play via NoScript)
  3518. * Bug 13023: Disable the gamepad API.
  3519. * Bug 13021: Prompt before allowing Canvas isPointIn*() calls.
  3520. * Bug 12460: Several cross-compilation and gitian fixes (see child tickets)
  3521. * Bug 13186: Disable DOM Performance timers
  3522. * Bug 13028: Defense-in-depth checks for OCSP/Cert validation proxy usage
  3523. Tor Browser 4.0-alpha-3 -- Sep 24 2014
  3524. * All Platforms
  3525. * Update Tor to 0.2.5.8-rc
  3526. * Update Firefox to 24.8.1esr
  3527. * Update meek to 0.11
  3528. * Update NoScript to 2.6.8.42
  3529. * Update Torbutton to 1.6.12.3
  3530. * Bug 13091: Use "Tor Browser" everywhere
  3531. * Bug 10804: Workaround fix for some cases of startup hang
  3532. * Bug 13091: Use "Tor Browser" everywhere
  3533. * Bug 13049: Browser update failure (self.update is undefined)
  3534. * Bug 13047: Updater should not send Kernel and GTK version
  3535. * Bug 12998: Prevent intermediate certs from being written to disk
  3536. * Bug 13245: Prevent non-english TBBs from upgrading to english version.
  3537. * Linux:
  3538. * Bug 9150: Make RPATH unavailable on Tor binary.
  3539. * Bug 13031: Add full RELRO protection.
  3540. Tor Browser Bundle 3.6.6 -- Sep 24 2014
  3541. * All Platforms
  3542. * Update Tor to tor-0.2.4.24
  3543. * Update Firefox to 24.8.1esr
  3544. * Update NoScript to 2.6.8.42
  3545. * Update HTTPS Everywhere to 4.0.1
  3546. * Bug 12998: Prevent intermediate certs from being written to disk
  3547. * Update Torbutton to 1.6.12.3
  3548. * Bug 13091: Use "Tor Browser" everywhere
  3549. * Bug 10804: Workaround fix for some cases of startup hang
  3550. * Linux
  3551. * Bug 9150: Make RPATH unavailable on Tor binary.
  3552. Tor Browser Bundle 4.0-alpha-2 -- Sep 2 2014
  3553. * All Platforms
  3554. * Update Firefox to 24.8.0esr
  3555. * Update NoScript to 2.6.8.39
  3556. * Update Tor Launcher to 0.2.7.0
  3557. * Bug 11405: Remove firewall prompt from wizard.
  3558. * Bug 12895: Mention @riseup.net as a valid bridge request email address
  3559. * Bug 12444: Provide feedback when “Copy Tor Log” is clicked.
  3560. * Bug 11199: Improve error messages if Tor exits unexpectedly
  3561. * Update Torbutton to 1.6.12.1
  3562. * Bug 12684: New strings for canvas image extraction message
  3563. * Bug 8940: Move RecommendedTBBVersions file to www.torproject.org
  3564. * Bug 12684: Improve Canvas image extraction permissions prompt
  3565. * Bug 7265: Only prompt for first party canvas access. Log all scripts
  3566. that attempt to extract canvas images to Browser console.
  3567. * Bug 12974: Disable NTLM and Negotiate HTTP Auth
  3568. * Bug 2874: Remove Components.* from content access (regression)
  3569. * Bug 4234: Automatic Update support (off by default)
  3570. * Bug 9881: Open popups in new tabs by default
  3571. * Meek Pluggable Transport:
  3572. * Bug 12766: Use TLSv1.0 in meek-http-helper to blend in with Firefox 24
  3573. * Windows:
  3574. * Bug 10065: Enable DEP, ASLR, and SSP hardening options
  3575. * Linux:
  3576. * Bug 12103: Adding RELRO hardening back to browser binaries.
  3577. Tor Browser Bundle 3.6.5 -- Sep 2 2014
  3578. * All Platforms
  3579. * Update Firefox to 24.8.0esr
  3580. * Update NoScript to 2.6.8.39
  3581. * Update HTTPS Everywhere to 4.0.0
  3582. * Update Torbutton to 1.6.12.1
  3583. * Bug 12684: New strings for canvas image extraction message
  3584. * Bug 8940: Move RecommendedTBBVersions file to www.torproject.org
  3585. * Bug 9531: Workaround to avoid rare hangs during New Identity
  3586. * Bug 12684: Improve Canvas image extraction permissions prompt
  3587. * Bug 7265: Only prompt for first party canvas access. Log all scripts
  3588. that attempt to extract canvas images to Browser console.
  3589. * Bug 12974: Disable NTLM and Negotiate HTTP Auth
  3590. * Bug 2874: Remove Components.* from content access (regression)
  3591. * Bug 9881: Open popups in new tabs by default
  3592. * Linux:
  3593. * Bug 12103: Adding RELRO hardening back to browser binaries.
  3594. Tor Browser Bundle 4.0-alpha-1 -- Aug 8 2014
  3595. * All Platforms
  3596. * Ticket 10935: Include the Meek Pluggable Transport (version 0.10)
  3597. * Two modes of Meek are provided: Meek over Google and Meek over Amazon
  3598. * Update Firefox to 24.7.0esr
  3599. * Update Tor to 0.2.5.6-alpha
  3600. * Update OpenSSL to 1.0.1i
  3601. * Update NoScript to 2.6.8.36
  3602. * Script permissions now apply based on URL bar
  3603. * Update HTTPS Everywhere to 5.0development.0
  3604. * Update Torbutton to 1.6.12.0
  3605. * Bug 12221: Remove obsolete Javascript components from the toggle era
  3606. * Bug 10819: Bind new third party isolation pref to Torbutton security UI
  3607. * Bug 9268: Fix some window resizing corner cases with DPI and taskbar size.
  3608. * Bug 12680: Change Torbutton URL in about dialog.
  3609. * Bug 11472: Adjust about:tor font and logo positioning to avoid overlap
  3610. * Bug 9531: Workaround to avoid rare hangs during New Identity
  3611. * Update Tor Launcher to 0.2.6.2
  3612. * Bug 11199: Improve behavior if tor exits
  3613. * Bug 12451: Add option to hide TBB's logo
  3614. * Bug 11193: Change "Tor Browser Bundle" to "Tor Browser"
  3615. * Bug 11471: Ensure text fits the initial configuration dialog
  3616. * Bug 9516: Send Tor Launcher log messages to Browser Console
  3617. * Bug 11641: Reorganize bundle directory structure to mimic Firefox
  3618. * Bug 10819: Create a preference to enable/disable third party isolation
  3619. * Backported Tor Patches:
  3620. * Bug 11200: Fix a hang during bootstrap introduced in the initial
  3621. bug11200 patch.
  3622. * Linux:
  3623. * Bug 10178: Make it easier to set an alternate Tor control port and password
  3624. * Bug 11102: Set Window Class to "Tor Browser" to aid in Desktop navigation
  3625. * Bug 12249: Don't create PT debug files anymore
  3626. Tor Browser Bundle 3.6.4 -- Aug 8 2014
  3627. * All Platforms
  3628. * Update Tor to 0.2.4.23
  3629. * Update Tor launcher to 0.2.5.6
  3630. * Bug 9516: Show Tor log in TorBrowser's Browser Console
  3631. * Update OpenSSL to 1.0.1i
  3632. * Backported Tor Patches:
  3633. * Bug 11654: Properly apply the fix for malformed bug11156 log message
  3634. * Bug 11200: Fix a hang during bootstrap introduced in the initial
  3635. bug11200 patch.
  3636. * Update NoScript to 2.6.8.36
  3637. * Update Torbutton to 1.6.11.1
  3638. * Bug 11472: Adjust about:tor font and logo positioning to avoid overlap
  3639. * Bug 12680: Fix Torbutton about url.
  3640. Tor Browser Bundle 3.6.3 -- Jul 24 2014
  3641. * All Platforms
  3642. * Update Firefox to 24.7.0esr
  3643. * Update obfsproxy to 0.2.12
  3644. * Update FTE to 0.2.17
  3645. * Update NoScript to 2.6.8.33
  3646. * Update HTTPS Everywhere to 3.5.3
  3647. * Bug 12673: Update FTE bridges
  3648. * Update Torbutton to 1.6.11.0
  3649. * Bug 12221: Remove obsolete Javascript components from the toggle era
  3650. * Bug 10819: Bind new third party isolation pref to Torbutton security UI
  3651. * Bug 9268: Fix some window resizing corner cases with DPI and taskbar size.
  3652. * Linux:
  3653. * Bug 11102: Set Window Class to "Tor Browser" to aid in Desktop navigation
  3654. * Bug 12249: Don't create PT debug files anymore
  3655. Tor Browser Bundle 3.6.2 -- Jun 9 2014
  3656. * All Platforms
  3657. * Update Firefox to 24.6.0esr
  3658. * Update OpenSSL to 1.0.1h
  3659. * Update NoScript to 2.6.8.28
  3660. * Update Tor to 0.2.4.22
  3661. * Update Tor Launcher to 0.2.5.5
  3662. * Bug 10425: Provide geoip6 file location to Tor process
  3663. * Bug 11754: Remove untranslated locales that were dropped from Transifex
  3664. * Bug 11772: Set Proxy Type menu correctly after restart
  3665. * Bug 11699: Change &amp;#160 to &#160; in UI elements
  3666. * Update Torbutton to 1.6.10.0
  3667. * Bug 11510: about:tor should not report success if tor proxy is unreachable
  3668. * Bug 11783: Avoid b.webProgress error when double-clicking on New Identity
  3669. * Bug 11722: Add hidden pref to force remote Tor check
  3670. * Bug 11763: Fix pref dialog double-click race that caused settings to be reset
  3671. * Bug 11629: Support proxies with Pluggable Transports
  3672. * Updates FTEProxy to 0.2.15
  3673. * Updates obfsproxy to 0.2.9
  3674. * Backported Tor Patches:
  3675. * Bug 11654: Fix malformed log message in bug11156 patch.
  3676. * Bug 10425: Add in Tor's geoip6 files to the bundle distribution
  3677. * Bugs 11834 and 11835: Include Pluggable Transport documentation
  3678. * Bug 9701: Prevent ClipBoardCache from writing to disk.
  3679. * Bug 12146: Make the CONNECT Host header the same as the Request-URI.
  3680. * Bug 12212: Disable deprecated webaudio API
  3681. * Bug 11253: Turn on TLS 1.1 and 1.2.
  3682. * Bug 11817: Don't send startup time information to Mozilla.
  3683. Tor Browser Bundle 3.6.1 -- May 6 2014
  3684. * All Platforms
  3685. * Update HTTPS-Everywhere to 3.5.1
  3686. * Update NoScript to 2.6.8.22
  3687. * Bug 11658: Fix proxy configuration for non-Pluggable Transports users
  3688. * Backport Pending Tor Patches:
  3689. * Bug 8402: Allow Tor proxy configuration while PTs are present
  3690. * Note: The Pluggable Transports themselves have not been updated to
  3691. support proxy configuration yet.
  3692. Tor Browser Bundle 3.6 -- Apr 29 2014
  3693. * All Platforms
  3694. * Update Firefox to 24.5.0esr
  3695. * Update Tor Launcher to 0.2.5.4
  3696. * Bug #11482: Hide bridge settings prompt if no default bridges.
  3697. * Bug #11484: Show help button even if no default bridges.
  3698. * Update Torbutton to 1.6.9.0
  3699. * Bug 7439: Improve download warning dialog text.
  3700. * Bug 11384: Completely remove hidden toggle menu item.
  3701. * Update NoScript to 2.6.8.20
  3702. * Update fte transport to 0.2.13
  3703. * Backport Pending Tor Patches:
  3704. * Bug 11156: Additional obfsproxy startup error message fixes
  3705. * Bug 11586: Include license files for component software in Docs directory.
  3706. * Windows and Mac:
  3707. * Bug 9308: Prevent install path from leaking in some JS exceptions
  3708. on Mac and Windows builds
  3709. Tor Browser Bundle 3.6-beta-2 -- Apr 8 2014
  3710. * All Platforms
  3711. * Update OpenSSL to 1.0.1g
  3712. * Bug 9010: Add Turkish language support.
  3713. * Bug 9387 testing: Disable JS JIT, type inference, asmjs, and ion.
  3714. * Update fte transport to 0.2.12
  3715. * Update NoScript to 2.6.8.19
  3716. * Update Torbutton to 1.6.8.1
  3717. * Bug 11242: Fix improper "update needed" message after in-place upgrade.
  3718. * Bug 10398: Ease translation of about:tor page elements
  3719. * Update Tor Launcher to 0.2.5.3
  3720. * Bug 9665: Localize Tor's unreachable bridges bootstrap error
  3721. * Backport Pending Tor Patches:
  3722. * Bug 9665: Report a bootstrap error if all bridges are unreachable
  3723. * Bug 11200: Prevent spurious error message prior to enabling network.
  3724. * Linux:
  3725. * Bug 11190: Switch linux PT build process to python2
  3726. * Bug 10383: Enable NIST P224 and P256 accel support for 64bit builds.
  3727. * Windows:
  3728. * Bug 11286: Fix fte transport launch error
  3729. Tor Browser Bundle 3.5.4 -- Apr 7 2014
  3730. * All Platforms
  3731. * Update OpenSSL to 1.0.1g
  3732. Tor Browser Bundle 3.5.3 -- Mar 19 2014
  3733. * All Platforms
  3734. * Update Firefox to 24.4.0esr
  3735. * Update Torbutton to 1.6.7.0:
  3736. * Bug 9901: Fix browser freeze due to content type sniffing
  3737. * Bug 10611: Add Swedish (sv) to extra locales to update
  3738. * Update NoScript to 2.6.8.17
  3739. * Update Tor to 0.2.4.21
  3740. * Bug 10237: Disable the media cache to prevent disk leaks for videos
  3741. * Bug 10703: Force the default charset to avoid locale fingerprinting
  3742. * Bug 10104: Update gitian to fix LXC build issues (for non-KVM/VT builders)
  3743. * Linux:
  3744. * Bug 9353: Fix keyboard input on Ubuntu 13.10
  3745. * Bug 9896: Provide debug symbols for Tor Browser binary
  3746. * Bug 10472: Pass arguments to the browser from Linux startup script
  3747. Tor Browser Bundle 3.6-beta-1 -- Mar 17 2014
  3748. * All Platforms
  3749. * Update Firefox to 24.4.0esr
  3750. * Include Pluggable Transports by default:
  3751. * Obfsproxy3 0.2.4, Flashproxy 1.6, and FTE 0.2.6 are now included
  3752. * Update Tor Launcher to 0.2.5.1
  3753. * Bug 10418: Provide UI configuration for Pluggable Transports
  3754. * Bug 10604: Allow Tor status & error messages to be translated
  3755. * Bug 10894: Make bridge UI clear that helpdesk is a last resort for
  3756. bridges
  3757. * Bug 10610: Clarify wizard UI text describing obstacles/blocking
  3758. * Bug 11074: Support Tails use case (XULRunner and optional
  3759. customizations)
  3760. * Update Torbutton to 1.6.7.0:
  3761. * Bug 9901: Fix browser freeze due to content type sniffing
  3762. * Bug 10611: Add Swedish (sv) to extra locales to update
  3763. * Update NoScript to 2.6.8.17
  3764. * Update Tor to 0.2.4.21
  3765. * Backport Pending Tor Patches:
  3766. * Bug 5018: Don't launch Pluggable Transport helpers if not in use
  3767. * Bug 9229: Eliminate 60 second stall during bootstrap with some PTs
  3768. * Bug 11069: Detect and report Pluggable Transport bootstrap failures
  3769. * Bug 11156: Prevent spurious warning about missing pluggable transports
  3770. * Bug 10237: Disable the media cache to prevent disk leaks for videos
  3771. * Bug 10703: Force the default charset to avoid locale fingerprinting
  3772. * Bug 10104: Update gitian to fix LXC build issues (for non-KVM/VT builders)
  3773. * Mac:
  3774. * Bug 4261: Use DMG instead of ZIP for Mac packages
  3775. * Linux:
  3776. * Bug 9353: Fix keyboard input on Ubuntu 13.10
  3777. * Bug 9896: Provide debug symbols for Tor Browser binary
  3778. * Bug 10472: Pass arguments to the browser from Linux startup script
  3779. Tor Browser Bundle 3.5.2.1 -- Feb 14 2014
  3780. * All Platforms
  3781. * Bug 10895: Fix broken localized bundles
  3782. * Windows:
  3783. * Bug 10323: Remove unneeded gcc/libstdc++ libraries from dist
  3784. Tor Browser Bundle 3.5.2 -- Feb 8 2014
  3785. * All Platforms
  3786. * Rebase Tor Browser to Firefox 24.3.0ESR
  3787. * Bug 10419: Block content window connections to localhost
  3788. * Update Torbutton to 1.6.6.0
  3789. * Bug 10800: Prevent findbox exception and popup in New Identity
  3790. * Bug 10640: Fix about:tor's update pointer position for RTL languages.
  3791. * Bug 10095: Fix some cases where resolution is not a multiple of 200x100
  3792. * Bug 10374: Clear site permissions on New Identity
  3793. * Bug 9738: Fix for auto-maximizing on browser start
  3794. * Bug 10682: Workaround to really disable updates for Torbutton
  3795. * Bug 10419: Don't allow connections to localhost if Torbutton is toggled
  3796. * Bug 10140: Move Japanese to extra locales (not part of TBB dist)
  3797. * Bug 10687: Add Basque (eu) to extra locales (not part of TBB dist)
  3798. * Update Tor Launcher to 0.2.4.4
  3799. * Bug 10682: Workaround to really disable updates for Tor Launcher
  3800. * Update NoScript to 2.6.8.13
  3801. Tor Browser Bundle 3.5.1 -- Jan 22 2014
  3802. * All Platforms
  3803. * Bug 10447: Remove SocksListenAddress to allow multiple socks ports.
  3804. * Bug 10464: Remove addons.mozilla.org from NoScript whitelist
  3805. * Bug 10537: Build an Arabic version of TBB 3.5
  3806. * Update Torbutton to 1.6.5.5
  3807. * Bug 9486: Clear NoScript Temporary Permissions on New Identity
  3808. * Include Arabic translations
  3809. * Update Tor Launcher to 0.2.4.3
  3810. * Include Arabic translations
  3811. * Update Tor to 0.2.4.20
  3812. * Update OpenSSL to 1.0.1f
  3813. * Update NoScript to 2.6.8.12
  3814. * Update HTTPS-Everywhere to 3.4.5
  3815. * Windows
  3816. * Bug 9259: Enable Accessibility (screen reader) support
  3817. * Mac
  3818. * misc: Update bundle version field in Info.plist (for MacUpdates service)
  3819. Tor Browser Bundle 3.5 -- Dec 17 2013
  3820. * All Platforms
  3821. * Update Tor to 0.2.4.19
  3822. * Update Tor Launcher to 0.2.4.2
  3823. * Bug 10382: Fix a Tor Launcher hang on TBB exit
  3824. * Update Torbutton to 1.6.5.2
  3825. * Misc: Switch update download URL back to download-easy
  3826. Tor Browser Bundle 3.5rc1 -- Dec 12 2013
  3827. * All Platforms
  3828. * Update Firefox to 24.2.0esr
  3829. * Update NoScript to 2.6.8.7
  3830. * Update HTTPS-Everywhere to 3.4.4tbb (special TBB tag)
  3831. * Tag includes a patch to handle enabling/disabling Mixed Content Blocking
  3832. * Bug 5060: Disable health report service
  3833. * Bug 10367: Disable prompting about health report and Mozilla Sync
  3834. * Misc Prefs: Disable HTTPS-Everywhere first-run tooltips
  3835. * Misc Prefs: Disable layer acceleration to avoid crashes on Windows
  3836. * Misc Prefs: Disable Mixed Content Blocker pending backport of Mozilla Bug 878890
  3837. * Update Tor Launcher to 0.2.4.1
  3838. * Bug 10147: Adblock Plus interferes w/Tor Launcher dialog
  3839. * Bug 10201: FF ESR 24 hangs during exit on Mac OS
  3840. * Bug 9984: Support running Tor Launcher from InstantBird
  3841. * Misc: Support browser directory location API changes in Firefox 24
  3842. * Update Torbutton to 1.6.5.1
  3843. * Bug 10352: Clear FF24 Private Browsing Mode data during New Identity
  3844. * Bug 8167: Update cache isolation for FF24 API changes
  3845. * Bug 10201: FF ESR 24 hangs during exit on Mac OS
  3846. * Bug 10078: Properly clear crypto tokens during New Identity on FF24
  3847. * Bug 9454: Support changes to Private Browsing Mode and plugin APIs in FF24
  3848. * Linux
  3849. * Bug 10213; Use LD_LIBRARY_PATH (fixes launch issues on old Linux distros)
  3850. Tor Browser Bundle 3.0rc1 -- Nov 21 2013
  3851. * All Platforms:
  3852. * Update Firefox to 17.0.11esr
  3853. * Update Tor to 0.2.4.18-rc
  3854. * Remove unsupported PDF.JS addon from the bundle
  3855. * Bug #7277: TBB's Tor client will now omit its timestamp in the TLS handshake.
  3856. * Update Torbutton to 1.6.4.1
  3857. * Bug #10002: Make the TBB3.0 blog tag our update download URL for now
  3858. * Windows
  3859. * Bug #10102: Patch binutils to remove nondeterministic bytes in compiled binaries
  3860. * Linux
  3861. * Bug #10049: Fix architecture check to work from outside TBB's directory
  3862. * Bug #10126: Remove libz and firefox-bin, and strip unstripped binaries
  3863. * Misc: Disable Firefox updater during compile time (in addition to pref)
  3864. Tor Browser Bundle 3.0beta1 -- Oct 31 2013
  3865. * All Platforms:
  3866. * Update Firefox to 17.0.10esr
  3867. * Update NoScript to 2.6.8.2
  3868. * Update HTTPS-Everywhere to 3.4.2
  3869. * Bug #9114: Reorganize the bundle directory structure to ease future
  3870. autoupdates
  3871. * Bug #9173: Patch Tor Browser to auto-detect profile directory if
  3872. launched without the wrapper script.
  3873. * Bug #9012: Hide Tor Browser infobar for missing plugins.
  3874. * Bug #8364: Change the default entry page for the addons tab to the
  3875. installed addons page.
  3876. * Bug #9867: Make flash objects really be click-to-play if flash is enabled.
  3877. * Bug #8292: Make getFirstPartyURI log+handle errors internally to simplify
  3878. caller usage of the API
  3879. * Bug #3661: Remove polipo and privoxy from the banned ports list.
  3880. * misc: Fix a potential memory leak in the Image Cache isolation
  3881. * misc: Fix a potential crash if OS theme information is ever absent
  3882. * Update Tor-Launcher to 0.2.3.1-beta
  3883. * Bug #9114: Handle new directory structure
  3884. * misc: Tor Launcher now supports Thunderbird
  3885. * Update Torbutton to 1.6.4
  3886. * Bug #9224: Support multiple Tor socks ports for about:tor status check
  3887. * Bug #9587: Add TBB version number to about:tor
  3888. * Bug #9144: Workaround to handle missing translation properties
  3889. * Windows:
  3890. * Bug #9084: Fix startup crash on Windows XP.
  3891. * Linux:
  3892. * Bug #9487: Create detached debuginfo files for Linux Tor and Tor
  3893. Browser binaries.
  3894. Tor Browser Bundle 3.0alpha4 -- Sep 24 2013
  3895. * All Platforms:
  3896. * Bug #8751: Randomize TLS HELLO timestamp in HTTPS connections
  3897. * Bug #9790 (workaround): Temporarily re-enable JS-Ctypes for cache
  3898. isolation and SSL Observatory
  3899. * Update Firefox to 17.0.9esr
  3900. * Update Tor to 0.2.4.17-rc
  3901. * Update NoScript to 2.6.7.1
  3902. * Update Tor-Launcher to 0.2.2-alpha
  3903. * Bug #9675: Provide feedback mechanism for clock-skew and other early
  3904. startup issues
  3905. * Bug #9445: Allow user to enter bridges with or without 'bridge' keyword
  3906. * Bug #9593: Use UTF16 for Tor process launch to handle unicode paths.
  3907. * misc: Detect when Tor exits and display appropriate notification
  3908. * Update Torbutton to 1.6.2.1
  3909. * Bug 9492: Fix Torbutton logo on OSX and Windows (and related
  3910. initialization code)
  3911. * Bug 8839: Disable Google/Startpage search filters using Tor-specific urls
  3912. Tor Browser Bundle 3.0alpha3 -- Aug 01 2013
  3913. * All Platforms:
  3914. * Update Firefox to 17.0.8esr
  3915. * Update Tor to 0.2.4.15-rc
  3916. * Update HTTPS-Everywhere to 3.3.1
  3917. * Update NoScript to 2.6.6.9
  3918. * Improve build input fetching and authentication
  3919. * Bug #9283: Update NoScript prefs for usability.
  3920. * Bug #6152 (partial): Disable JSCtypes support at compile time
  3921. * Update Torbutton to 1.6.1
  3922. * Bug 8478: Change when window resize code fires to avoid rounding errors
  3923. * Bug 9331: Hack an update URL for the next TBB release
  3924. * Bug 9144: Change an aboutTor.dtd string so transifex will accept it
  3925. * Update Tor-Launcher to 0.2.1-alpha
  3926. * Bug #9128: Remove dependency on JSCtypes
  3927. * Windows
  3928. * Bug #9195: Disable download manager AV scanning (to prevent cloud
  3929. reporting+scanning of downloaded files)
  3930. * Mac:
  3931. * Bug #9173 (partial): Launch firefox-bin on MacOS instead of TorBrowser.app
  3932. (improves dock behavior).
  3933. Tor Browser Bundle 3.0alpha2 -- June 27 2013
  3934. * All Platforms:
  3935. * Update Firefox to 17.0.7esr
  3936. * Update Tor to 0.2.4.14-alpha
  3937. * Include Tor's GeoIP file
  3938. * This should fix custom torrc issues with country-based node
  3939. restrictions
  3940. * Fix several build determinism issues
  3941. * Include ChangeLog in bundles.
  3942. * Linux:
  3943. * Use Ubuntu's 'hardening-wrapper' to build our Linux binaries
  3944. * Windows:
  3945. * Fix many crash issues by disabling Direct2D support for now.
  3946. * Mac:
  3947. * Bug 8987: Disable TBB's 'Saved Application State' disk records on OSX 10.7+
  3948. Tor Browser Bundle 3.0alpha1 -- June 17 2013
  3949. * All Platforms:
  3950. * Remove Vidalia; Use the new Tor Launcher Firefox Addon instead
  3951. * Update Torbutton to 1.6.0
  3952. * bug 7494: Create a local home page for TBB as about:tor
  3953. * misc: Perform a control port test of proper Tor configuration by default.
  3954. Only use https://check.torproject.org if the control port is
  3955. unavailable.
  3956. * misc: Add an icon menu option for Tor Launcher's Network Settings
  3957. * misc: Add branding string overrides (primarily controls browser name and
  3958. homepage)
  3959. * Update HTTPS-Everywhere to 3.2.2
  3960. * Update NoScript to 2.6.6.6
  3961. * Update PDF.JS to 0.8.1
  3962. * Windows:
  3963. * Use MinGW-w64 (via Gitian) to cross-compile the bundles from Ubuntu
  3964. * Use TBB-Windows-Installer to guide Windows users through TBB extraction
  3965. * Temporarily disable WebGL and Accessibility support due to minor MinGW
  3966. issues
  3967. * Mac:
  3968. * Use 'Toolchain4' fork by Ray Donnelley to cross-compile the bundles from
  3969. Ubuntu