29 Sep 2026
Planet Mozilla
Mozilla Addons Blog: Nova is here: what changes for your Firefox theme
On September 29, Firefox 157 shipped Nova, the biggest refresh of the Firefox interface since Proton back in 2021. The browser frame is cleaner, the sidebar plays a bigger role, and vertical tabs are a first-class layout. Your theme continues to load, and most color and image properties work as they did before.
What does change is where those colors and images display, how some of them look next to each other, and a handful of properties that no longer have a visible effect. Most themes will look fine. Some, especially themes built around a background image, look different enough that you will want to take a look.
This post walks through what changed compared with the Proton interface, what to check in your theme, and what is still being worked on. If you only have five minutes, jump to the checklist.
What changed in the browser frame
The toolbar and sidebar now sit flush with the window edges, with no gaps between them.
For your theme, this means your frame color and background image have less empty space around them, and the edges where the toolbar, sidebar, and page meet are more visible.
| Area | Proton | Nova (Firefox 157) |
|---|---|---|
| Toolbar and sidebar | Flush with the window, no gaps or floating borders | Same as before |
| Horizontal tabs | Theme background applied to the tab strip | Same as before |
| Vertical tabs | Tab bar color on the tab strip | Tab bar color also shows on the toolbar |
| Sidebar | Separate panel | Shares the theme background with the toolbar area |
colors, accents and tabs
Accent color. The default Firefox theme uses Nova's purple accent. Every other theme, including yours, uses the operating system's accent color for buttons and other accented controls. Themes cannot set the accent color through the manifest, and is why your theme cannot show the purple you see in the default theme.
Focus and link colors. Firefox still applies its own blue and cyan to focus rings and some links when a theme other than the default is active.
The selected tab. Proton always drew a shadow under the selected tab, which helped it stand out even when a theme did not style it. Nova removes that shadow. If your theme relies on it, the selected tab can blend into the tab strip. Set the selected tab colors, with tab_selected and tab_line, so the selected tab stands out.
Button hover colors. Your button_background_hover and button_background_active colors also apply to buttons on the tab strip, and for buttons that sit on your frame background with vertical tabs. A solid color picked to match the toolbar can almost disappear there. Semi-transparent colors, for example rgba(0, 0, 0, 0.15) for hover and rgba(0, 0, 0, 0.3) for pressed, work on both backgrounds.
Sidebar and vertical tabs
- The sidebar shares your background. The theme background now continues under the sidebar, so the sidebar and the toolbar area appear as one surface.
- Set sidebar colors explicitly. Use
sidebarandsidebar_textfor sidebar panels. If you leave them out, Firefox picks colors for you, relevant to your theme's color. sidebar_borderis now a separator. The sidebar splitter is gone; the property now colors the line between the sidebar and the page.- Sidebar buttons follow your text color. Buttons and icons in the sidebar are derived from your text color rather than your toolbar button colors, so they can look slightly different from the toolbar.
- Vertical tabs and the toolbar. With vertical tabs, your tab bar color is also applied to the toolbar. If those two colors were chosen to contrast, check how they look together.
- Expand on hover. In Firefox 157, a sidebar that expands on hover may not show your theme's background. This is fixed in Firefox 158.
Properties that changed or no longer work
Some theme properties behave differently in Nova. Your theme still loads if it uses them; they just have no visible effect, or style something different.
| Property | In Nova |
|---|---|
ntp_text |
No longer styles the new tab page search box |
popup_text |
No longer styles the address bar dropdown; other popups still use it |
sidebar_highlight |
No visible effect; the default highlight color is used |
sidebar_highlight_text |
No visible effect |
toolbar_bottom_separator |
Acts as a separator next to or below the toolbar and around the page |
The theme manifest reference on MDN is being updated with these changes.
Themes with background images
Themes using images are where you are most likely to see a difference. Your image can now show behind the sidebar and vertical tabs, and an image designed for a wide, short toolbar rarely looks good stretched or tiled down a vertical panel. In our testing of popular themes, the image themes that look off in the sidebar mostly did before Nova too. We did test a number of themes but we invite you to do your own testing. Nova makes the sidebar more visible, so the issues are easier to notice.
You can now choose where your images go with the backgrounds_area property, available from Firefox 156:
- "auto" (the default): Firefox decides from
additional_backgrounds_alignment. If any image is aligned to the vertical center or bottom, images stay in the top toolbars; otherwise they cover the whole window. - "window": images cover the whole window, including behind the sidebar and vertical tabs.
- "top_toolbars": images stay in the toolbars at the top of the window, and the sidebar uses your frame color.
If your image was made for the toolbar only, "top_toolbars" with a frame color that suits the image is usually the quickest fix.
Also set a toolbar color, even a semi-transparent one. Without it, notification bars that appear above the page sit directly on your image and can be hard to read.
New Gradient Support
Nova's color themes use gradients, and you can too. The Nova theme manifests are the best working example; look at how they set colors for each surface, including the sidebar. backgrounds_area applies to gradients the same way it applies to images. Older versions of Firefox ignore color properties they don't recognize, so your theme still loads there; if you use a feature older versions reject, set strict_min_version in your manifest.
Checklist: what to check in your theme
Install your theme in Firefox 157 and look at it in each of these states:
- Horizontal tabs and vertical tabs.
- Sidebar closed, open, and expanded on hover. Also toggle "Customize sidebar" while the sidebar is open or expanded.
- Compact density, if your users are likely to use it (under settings -> appearance density(.
- A private window.
- Light and dark system settings, since the accent follows the operating system.
- Hover over the buttons on the tab strip.
Then, if something looks off:
- Set
tab_selectedandtab_lineso the selected tab stands out without Firefox's old shadow. - Set
sidebarandsidebar_textto colors that match your theme. - Use semi-transparent
button_background_hoverandbutton_background_activecolors. - Check that your tab bar and toolbar colors work together with vertical tabs enabled.
- For image themes, choose a
backgrounds_areaand set a toolbar color. - Remove or ignore properties that no longer have an effect.
- Publish an update on AMO so your users get the changes.
What we are still working on
Nova will evolve after launch. Firefox 158 ships on October 13 with the expand-on-hover sidebar fix. We are also working on these, with no release date yet:
- Focus and link colors that fit your theme instead of the fixed blue and cyan.
- A
popup_iconscolor for icons in menus and panels, separate from toolbar icons. - Theme colors for hover and selected states inside sidebar panels.
- Better hover states for tab strip buttons.
We will post again when these land.
For users who prefer the old look
Some of your users may miss Proton. From September 29, Mozilla is featuring a Firefox Proton theme in the Add-ons Manager for anyone who wants the previous look. It is a normal theme, so users can switch between it and yours at any time.
Resources
- Theme manifest reference on MDN: every color, image, and property, including
backgrounds_area. - Static themes on Extension Workshop : updated for Nova.
- Nova theme manifests: worked examples for gradients and sidebar colors; the themes themselves are on AMO, for example Nova Sun.
Questions?
We want your theme to look its best in Nova. If something looks wrong and the checklist does not fix it, tell us on Discourse and include a link to your theme and a screenshot. Those reports help us find the cases that need a Firefox fix rather than a theme change.
Thank you for making Firefox look like you and like your users.
The post Nova is here: what changes for your Firefox theme appeared first on Mozilla Add-ons Community Blog.
29 Sep 2026 3:34pm GMT
The Mozilla Blog: More modern. More flexible. Still Firefox.
What comes to mind when you think of Firefox? Is it our best-in-class privacy features and ad blocking capabilities? Our partnerships with Wrexham, NVIDIA or Mistral? Or maybe our adorable mascot Kit?
If you've been following Firefox this year, you've seen us add new ways to get things done while giving you more choice over how you browse. That includes browsing two pages side by side, adding an extra layer of privacy with built-in VPN, blocking trackers for smoother scrolling and faster load times, and deciding how AI shows up in Firefox.
For the past few months, many of you have also been trying out our new Firefox design in Nightly and sharing your thoughts with us as we continued to refine the experience.
Today, we're rolling out that design with FX 157 to everyone using Firefox across desktop and mobile devices. Firefox has done a lot of growing over the last year; now it looks the part.
A more modern Firefox
When we first shared our plans to design Firefox for the future, we said we wanted Firefox to feel "current, but not generic. Warm, but still precise."
That design ethos now carries across all of Firefox. We've refreshed the colors, icons and themes throughout the browser, from the tabs and toolbars you use every day to your New Tab page, Private Browsing experience and more, with no cost to your browser performance.
This shared design language across desktop and mobile gives Firefox a consistent foundation for new features and experiences, while keeping the personality that makes Firefox unique.
Make Firefox yours
We've added more choices for how Firefox looks and works, including the return of a feature many of you asked for:
Compact Mode is back. As people started trying the new design, we heard from many of you who wanted to fit more into your browser window. Compact Mode reduces the size of your tabs and toolbar to give more of your screen to the web, with an auto-compact option for smaller screens.

Find your look. A new theme picker makes it easier to explore different looks for Firefox, with new themes and wallpapers to choose from.

Set up New Tab your way. Choose what you want to see on your homepage. Now, you have a dedicated space to pin and organize shortcuts so sites you use all the time stay put.

Refined, not reinvented
Themes and wallpapers may change over time, but the things that made people choose Firefox in the first place are still the same. We're still independent and open source, with privacy protections built into the browser and controls that put you in charge of how Firefox works for you.
This carries through everything we build, from the height of your toolbars and what belongs on your New Tab page to which AI features show up in your browser, which model you choose and what context you want it to have.
Today's Firefox is a renewal, grounded in the same principles that have shaped it from the beginning, with a new design built to carry Firefox forward.
For those who have come with us on this journey, thank you for helping us shape the future of Firefox.
If you've been away on hiatus, welcome back. Try the latest Firefox and let us know what you think.
The post More modern. More flexible. Still Firefox. appeared first on The Mozilla Blog.
29 Sep 2026 1:00pm GMT
28 Sep 2026
Planet Mozilla
Firefox Nightly: Shoutout to More Layouts – These Weeks in Firefox: Issue 210
Highlights
- Rév O'Conner added a settings popup to control the layout of the Inspector. "Auto" automatically switches the layout at a given toolbox width.
- The new sidebar (sidebar.revamp) and switcher setting will be enabled by default for users along with Nova in DevEdition, Beta and Release channels. To ease the transition for old sidebar users, the "Open tools from sidebar" option will be unchecked for those users to more closely resemble the old sidebar experience. The migration won't apply to users who had already tried the new sidebar and reverted back.
- The custom wallpaper library for the New Tab page is coming along! This allows you to save multiple images to your wallpaper folder, rather than replacing one image at a time. While it's still in development, you can test it by setting
browser.newtabpage.activity-stream.newtabWallpapers.customWallpaper.library.enabledto true, starting in Firefox 157. - Mark added an MDN search engine for Nightly and Developer Edition. Select it from the menus, or type @mdn <search term>.
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- :Benjamin Peterson
- Amadi
- any1here
- Caleb Pickard
- Chris Vander Linden
- Gopalarathnam Venkatesan
- Igor [:ExplodingJoysticks]
- Khalid AlHaddad
- Lukáš Lipinský
- Mayank Bansal
- Nazeer Ahmed Shaikh
- Noah Varghese
- Sameem [:sameembaba]
- Sebastian Zartner [:sebo]
- sfshah
- Xiaosen Zhuang
New contributors (🌟 = first patch)
- Amadi:
- Caleb Pickard
- dchen705: Remove unnecessary module import in browser/components/urlbar/tests/browser/head.js
- Ekerin Agboola: Remove old documentation related to the removed SEARCH_SUGGESTIONS_LATENCY_MS histogram
- Igor [:ExplodingJoysticks]:
- Gopalarathnam Venkatesan:
- 🌟 Jieke Jiang: Remove unused AboutReaderParent._getArticle
- 🌟 Andrew: White flash on startup caused by abouthome_cache storing incompatible startup frame
- 🌟 Rév O'Conner: Inspector does not respect panel layout
- 🌟 Kana: browser_privatebrowsing_resetPBM.js awaits an array instead of Promise.all, so the tab-close wait does nothing
- Raúl: L10nCache.add() throws on an unknown Fluent ID instead of reporting it
- 🌟 Samuel Mbabhazi: Use new color syntax throughout the DevTools
- K: "Go to line" sets a cursor line which does not exist in footer location indicator
- sfshah:
- Nazeer Ahmed Shaikh
- Noah Varghese:
- Valerie Racine (:v-racine): Fix incorrect assertion message in browser_adoptTab_failure.js
- 🌟 Xiaosen Zhuang:
Project Updates
Add-ons / Web Extensions
Addon Manager & about:addons
- As part of Project Nova related work:
- Fixed responsive layout issues that caused horizontal scrolling in about:addons at high zoom levels - Bug 2059864
- Fixed the "Discover extensions" button appearing multiple times in about:addons - Bug 2070281
- Added telemetry for theme-picker shown events and for appearance/native-theme changes in about:addons - Bug 2069417 / Bug 2070341
- Added an accessible name to the themes mode control in about:addons, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel - Bug 2064563
- Thanks to Mark Kennedy for the help on fixing this accessibility gap
- Updated the built-in dark and light theme previews to use the nova style - Bug 2070274
- Thanks to Emilio Cobos Álvarez for the fix to the default light and dark theme previews.
- Fixed the Nova default and AMO curated theme previews to follow the OS light/dark mode while ignoring the Website appearance setting, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel - Bug 2070562
- Stopped setting unused taarId session cookies for AMO on startup - Bug 1871561
- Thanks to Manuel Bucher for helping us to clean up these unused internals.
WebExtension APIs
- Fixed webRequest requestBody parsing so POST form fields named __proto__ are no longer dropped - Bug 2061470
- Changed alarms.clearAll() to resolve with undefined instead of a boolean, starting in Firefox 157 - Bug 2067229
- Thanks to Ollie Hensman-Crook for the fix to the alarms API.
- Implemented native messaging support via xdg-native-messaging-proxy for Flatpak and Snap builds - Bug 1955255
- Thanks to Jan Horak for the native messaging work on Linux packaging.
- As part of Florian Quèze effort to investigate and fix intermittent failures:
- Made windows.update() wait for the window to actually resize or move before resolving, fixing an intermittent Linux test failure - Bug 1307759
- Fixed a pageAction popup incorrectly opening via a commands API shortcut while the extension was already shutting down - Bug 2039637
- Fixed action.openPopup() rejecting when a tab hover preview was showing, a regression from Bug 2022281 in Firefox 150, with the fix shipping in Firefox 157 and no uplift planned - Bug 2062229
DevTools
- The team has a few sizable ongoing projects.
- Bomsy is working on moving Stylesheets to the Debugger so we can retire the (XUL-based) Style Editor, and turn the Debugger into a "Sources" panel (keeping all the existing functionality of course). (pref: devtools.debugger.features.stylesheets-in-debugger)
- Alex is investigating ways to better handle CSS authored text and CSSOM changes in the Inspector, building information directly from the Rust CSS engine, with the hope it will bring performance improvement editing styles in the Rules view.
- Nicolas is implementing a way to show to the user how the engine goes from a CSS declaration value to the computed value so it's easier to follow what's the result of the different call sites, or how the different units (em, %, vmin, …) are computed to their final (e.g. px) values. (pref: devtools.inspector.css-explainers)
External contributions
- Chris Vander Linden finalized a multi-months project to add a search toolbar in the Netmonitor Raw Response panel, adapting and reusing the component we are using in the Debugger (#1941575)
- Amadi made the "Open in new tab" context menu entry to open tab next to the selected tab, not at the very end of the tab list (#2059979)
- Mayank Bansal optimized the performance of console.clear() (#2068156, #2068157, #2067000)
- Benoit added JSON Lines (JSONL/NDJSON) support in the Netmonitor Response panel (#2059673)
- Gopalarathnam Venkatesan made the "Add class" button (.cls) to be disabled when a class can't be added to the selected node (e.g. it's a text node, or a comment, or the doctype node) (#2000150)
- K fixed an issue with the "Go to line" action in the Debugger (#2064575)
- Samuel Mbabhazi refactored our CSS codebase to use new color syntax (e.g. rgb(255 0 0) instead of rgb(255, 0, 0)) (#2054228)
- sfshah turned devtools/client/jsonview/converter-child.js into an ES class (#2004273)
Team/Project Update
- Florian Quèze [:florian] is working on fixing test flakiness in devtools/client/debugger and already landed an impressive stack of patches (#2001947, #2070917, #2070920, #2070932, #2070970, #2027953, #1932082, #2070923, #2070933, #1814093, #1868969, #2071238)
- that also includes fixing various accessibility issues that were spotted by a11y_checks #2070911, #2070955, #2071227, #2071231)
- Note that Julian Descottes [:jdescottes] also has an ongoing quest to reduce intermittent failures in our codebase and fixed a few those last 2 weeks (#1767707, 2069100, #2009386)
- [florian] 24 patches landed on Friday, you can see the impact on https://tests.firefox.dev/tests.html?path=devtools%2Fclient%2Fdebugger
- Nicolas Chevobbe [:nchevobbe] fixed a few issues spotted by Jake in the Inspector for the new-ish attr()CSS function (#2068479, #2068480, #2068483)
- Alexandre Poirot [:ochameau] fixed an OOM crash when viewing source mapped file for a large wasm module with many workers (#2058286)
- Julian Descottes [:jdescottes] improved performance of the Inspector when Devtools was opened on a page with many grid elements (#1988868)
- Hubert Boma Manilla (:bomsy) fixed an infinite loop in the Debugger search if you were searching for $ on a big JS file (#2068517)
WebDriver
- Sameem merged two internal helpers (remote/shared/Sync.sys.mjs and remote/marionette/sync.sys.mjs) which removed some code duplication.
- Khalid AlHaddad unified the navigation commands in Marionette and WebDriver BiDi to always initiate navigations via browsingContext.loadURI().
- Khalid AlHaddad updated the WebDriver BiDi client used by WebDriver tests so that browsing_context.locate_nodes returns the nodes array directly instead of the enclosing result object, matching the updated command response.
- Julian Descottes made the destinationFolder mandatory when calling the browser.setDownloadBehavior command with type="allowed" - which aligns us with the specification. In order to restore the default behavior without having to specify a folder, clients should call setDownloadBehavior with null instead.
- Henrik Skupin fixed a bug in geckodriver where specifying androidIntentArguments in the capabilities caused the default intent arguments to be omitted.
Fluent
- According to arewefluentyet.com, ~74.77% of our strings are now using Fluent!
Lint, Docs and Workflow
- According to arewemozsrcyet.com, ~59% of our modules are now using moz-src.
- eslint-plugin-mozilla has switched from using Mocha to Jest for tests.
- Planning on future updates to investigate getting devtools & newtab to use the jest installed at the top-level, rather than separately installed copies.
Information Management/Sidebar
- We're working away on bug fixes for sidebar, vertical tabs, split-view, and Nova
- Thanks Florian (:fqueze) for landing a set of patches that have markedly reduced test flakiness in the Sidebar component
New Tab Page
- Custom wallpaper library
- Dre added a "Your images" folder to the wallpaper picker on the New Tab Page, letting users save and switch between multiple custom wallpapers directly from the picker UI (desktop channels), which reduces friction for users who frequently change backgrounds.
- Dre implemented storage and migration for multiple custom wallpapers so users keep their existing wallpaper during upgrade while gaining the ability to save and switch multiple wallpapers - migration moves old single-wallpaper prefs into the new multi-wallpaper storage and the NTP now reads the wallpaper array at load/sync points.
- Dre updated New Tab Page strings to support multiple custom wallpapers so users now see accurate, localized labels and accessibility text when managing or switching between multiple custom backgrounds, reducing confusion in the UI during wallpaper selection.
- Dre added a delete affordance for saved custom wallpapers inside the New Tab Page picker so users can remove unwanted images from their saved set without going to profile files or prefs, improving manageability of user-provided wallpapers.
- We've completed a mass migration of our unit tests from Mocha (not mochi) / Karma to Jest/RTL, which is more modern and actively maintained.
- Sections is now enabled globally for all regions that show the content feed!
- Reem Hamoui fixed Lists widget so that keyboard users can now tab to completed items on the New Tab Page and see a visible selection/focus state
- Reem Hamoui fixed the Timer widget so that keyboard users can toggle focus vs break modes with standard keys (Enter/Space/arrow keys) thanks to restored keyboard handlers and tabindex semantics.
- Reem Hamoui made it so that screenreaders now announce wallpaper names via added aria-labels/alt text and role improvements in the Customize UI.
- Maxx Crawford made it so that the Customize UI now filters wallpapers by their metadata and no longer surfaces images marked hidden or in specific visibility groups.
- Irene Ni added Section Layout Name (String) telemetry to newtab content impression & click events so impressions/clicks now carry layout identifiers for more granular UX and A/B analysis
- Reem Hamoui added accessible names (aria-label/aria-labelledby) to the HNT Customize panel back buttons to fix screen-reader discoverability and keyboard/AT announcement when navigating the New Tab Customize flow.
- Nina Pypchenko [:nina-py] preserved iframe rendering for New Tab Page widgets during drag operations to prevent iframe-backed widgets from going blank while being moved.
- Nina Pypchenko [:nina-py] restored the Stocks widget dropdown and menu visibility under High Contrast Mode by adjusting contrast-aware CSS and ARIA roles so users relying on HCM can access stock controls again.
- Nina Pypchenko [:nina-py] fixed a results text overflow for long search queries in the Stocks widget by adding word-wrap/clamping to result lines, preventing layout breakage and truncated controls when users enter long symbols or queries.
- Nina Pypchenko [:nina-py] added telemetry for theme selection in the New Tab customization panel by emitting a selection ping on change, enabling measurement of user theme choices without changing UX.
- Irene Ni restored the Lists widget switcher checkmark for the selected list by fixing menu item selection-state rendering so users can again see which list is active in the switcher.
- Reem Hamoui updated the Privacy widget CTA and spacing on the New Tab Page, adjusting CSS/layout and CTA copy so the action is more discoverable and has a clearer tap/click target across responsive breakpoints.
- Reem Hamoui updated the zero-state copy for the New Tab Privacy widget to clarify what the widget does and the next steps for users when no privacy events or trackers are present, reducing confusion for first-time or cleared-state users.
- Maxx Crawford landed Fluent strings for the Nova launch New Tab customization callout, enabling localized text in the New Tab customization callout so users in supported locales see translated UI instead of missing-string fallbacks.
- Nina Pypchenko made the customization panel reset when closed, ensuring about:newtab customization state (temporary tile/layout previews) is cleared on close so users no longer see stale previews when reopening the panel.
- Dão Gottwald fixed New Tab to pick up system High Contrast Mode on Linux and macOS, restoring correct high-contrast colors/contrast on those platforms for users who rely on OS-level accessibility settings.
- Irene Ni restored theme matching for New Tab context menus by reapplying theme-aware CSS variables in the New Tab Page contextmenu styles, fixing mismatched colors for users with custom/light/dark themes.
- Dustin Whisman fixed New Tab section context menu button color regression by adjusting the section-contextmenu button style rules (button color variables and state selectors) so section actions now respect theme contrast.
- Irene Ni restored transparency to New Tab card backgrounds by removing opaque background rules so cards correctly display background images/themes and improve visual consistency across DPI/compositing setups.
Picture-in-Picture
- Thanks to Sebastian Zartner [:sebo] for fixing broken Dailymotion captions on the PiP player.
- kpatenio fixed YouTube's displayed playback speed settings being out of sync with PiP.
- Thanks to Sylvestre Ledru [:Sylvestre] for helping fix a broken link in our PiP docs as a part of Bug 2071683.
Search and Urlbar
Address Bar
- Dao and Moritz are working on bringing the full urlbar experience into the newtab page, now enabled on nightly and going through polish and improvements.. (Bug 2068104, Bug 2068633, Bug 2069260, Bug 2064747)
- Drew enabled AMP and Wikipedia by default in AT, BE, CH, ES, IE, LU, NL, PL, PT and SE. (Bug 2066294)
- James gated adaptive autofill page results behind a minimum score threshold. (Bug 2066171)
- any1here stopped disabled Manage AI and Labs quick actions being displayed when disabled. (Bug 2070378)
Search
- Dale landed the Recent Searches widget which will be be used launched as an experiment (Bug 2063718)
- Caleb fixed the search box eating the first character typed into it. (Bug 1953361)
- Mark configured Wikipedia search for Sardinian (sc) to use the Sardinian Wikipedia rather than the Italian one. (Bug 2057690)
Places
- Marco fixed bookmarked Google Maps using Google's default favicon. (Bug 1575809)
- Marco fixed the Downloads and History windows going full-screen instead of floating on macOS. (Bug 2058062)
Tests
- Dashboards:
- Most frequent oranges: https://tests.firefox.dev/intermittent.html#date=21days
- Folders with the most flaky tests: https://tests.firefox.dev/flaky.html?kind=mochitest#date=21days&view=list
- Issues of tests in a given folder: https://tests.firefox.dev/tests.html
- Eg devtools debugger tests shows progress of the recent effort to fix these tests recently
- Flakiness burn down
- Multi-agent Claude sessions running for hours investigating and fixing tests of a given set provided in the prompt. Still iterating on the process. Did this 3 times so far:
- Bug 2062142 - [meta] Fix the flakiness in browser/components/extensions/test/browser
- Top 20 intermittent mochitest bugs annotated by sheriffs.
- Probably what made the mochitest line go down for the first time on https://tests.firefox.dev/
- And what helped with the sidebar component, even though sidebar wasn't my target.
- Bug 2070797 - [meta] Fix the flakiness in devtools/client/debugger/test/mochitest
- Multi-agent Claude sessions running for hours investigating and fixing tests of a given set provided in the prompt. Still iterating on the process. Did this 3 times so far:
- Profile your claude session for cost and context size: https://github.com/fqueze/claude-profiler
- To monitor cost during your sessions, try https://github.com/padenot/foxtail
28 Sep 2026 7:31pm GMT
25 Sep 2026
Planet Mozilla
Firefox Tooling Announcements: MozPhab 2.21.0 Released
Bugs resolved in Moz-Phab 2.21.0:
- bug 2068637 code review bot fails to apply patches when the parent is not known
- bug 2073291
moz-phab submitcould load reviewers and review groups in parallel with revisions and diffs - bug 2075401 "Phabricator Error: Validation errors" from
moz-phab submitshould display the revision
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
25 Sep 2026 6:18pm GMT
24 Sep 2026
Planet Mozilla
The Mozilla Blog: Classic, Private, or Smart? Choose the right Firefox window for every task
We spend a lot of time browsing online. Whether you are researching for work, planning a trip, paying your bills, or scrolling through social media, your browser is there for it all.
While all these tasks are very different in nature, a lot of people still tend to stick to the same window type for all their use cases. But what if there was a different way to browse?
You may have noticed Firefox now has three window options for desktop. On top of the Classic and Private windows you've known for years, a third choice has been rolling out in beta: Smart Window. This optional AI-powered browsing experience is built to move your work forward and help finish what you started online.
Following the recent addition of several new Smart Window capabilities, we thought now would be the perfect time for a breakdown of what each of our three window options actually does, and when to use them.
Classic: Timeless and tailored to you
Classic Window is still the most customizable option of the three. While Private and Smart windows share many of the same features and capabilities as Classic, a Classic Window offers the widest range of Firefox's standard personalization options. It gives you the broadest canvas for tailoring Firefox to the way you browse.
What makes it Classic:
- Full oversight over controls, buttons, and toolbars.
- Access to the entire Firefox add-ons library.
- Advanced customization and configuration options.
- The ability to sync your history, bookmarks, and open tabs across your signed-in devices.
When to use it:
Classic is your home base. It's the best place to start customizing around your browsing needs, whether that means an extension setup specifically tailored to your workflow, a special theme that matches your style, or just the familiar Firefox experience you created over years of tweaking to your personal taste. While many customizations are also available on Private and Smart window, Classic offers the most extensive line-up of optional browser features, extensions, and aesthetics to personalize your setup.
Classic is the right move for general browsing like scrolling through social media, conducting a quick Google search, or reading online articles. It's also the best place to start if you are looking to build your browser around you.
Private Window: Browse with greater peace of mind
Private Window stays true to its name and number one priority: it's designed to limit the information associated with your browser session. When a Private Window is closed, Firefox doesn't retain session information, such as what you searched for, the sites you visited, or the cookies they set.
What makes it Private:
- Pages visited from a Private Window will not be added to the list of sites in Firefox's History menu, the Library window's history list, nor the address bar drop-down list.
- Nothing entered into text boxes on web pages and Search bar will be saved for Form autocomplete.
- Cookies set in a Private Window are kept only temporarily in memory, separate from your regular cookies, and are discarded after your last Private Window is closed.
- Extensions are off by default in a Private Window, unless you explicitly grant them permission.
When to use it:
A Private Window is recommended when you don't want activity from a browsing session sitting in your history, such as shopping for a gift. It's also helpful when browsing on a shared device, ensuring your history, logins, and cookies will not be saved for the next person.
You may not need a Private Window every time you open your browser, but it's always there for you when you do.
Smart Window: Firefox's privacy-first, AI-powered browsing experience to help get stuff done

Smart Window is Firefox's newest window type, currently rolling out in Beta to users in the U.S., Canada, and France. Think of it as a Classic Firefox window with a built-in AI assistant layered on top - one that you can choose to have utilize your open tabs, recent browsing, and the page in front of you, so it can help you do more without switching contexts - all with the privacy and security you expect from Firefox.
What makes it Smart:
- A built-in assistant that can summarize pages, generate recommendations, compare information, and plan tasks using your open tabs.
- The ability to retrieve current web information and display the sources behind its response without taking you to a separate search results page, supported by Firefox's new partnership with Exa.
- Suggested groups for related tabs.
- Visual previews of pages from your browsing history, so you can surface the page you're looking for more easily among similar results without opening each one.
- The choice of three AI models to power the assistant, as well as the option to bring your own model.
- Optional "memories," built from either your Smart Window chats or your browsing activity in both Smart and Classic windows, or both. Memories help the assistant give you more helpful, personalized answers over time. They are stored locally on your device and can be deleted at any time.
When to use it:
Smart Window shines when you need a little extra help finishing what you started. Its ability to work with the context you choose to share can help you make progress on ongoing tasks that may require more than one session, like trip or event planning, comparison price shopping, or conducting research for work or personal reasons.
And with Smart Window's optional memories, which learn your patterns and preferences over time (with your permission), Smart Window gets more useful the more you use it, keeping you from having to spell everything out from scratch each time.
Selecting the right window for the job
None of these windows is "better" than the others, they're built for different moments.
The good news is you are never locked into one. Firefox lets you move between all three depending on what you're doing, so you can choose the window that fits each task.
You can access Classic and Private windows at any time from the Firefox menu. As for Smart Window, it remains in beta, with current availability to people in the U.S., Canada, and France.
To try Smart Window, visit https://www.firefox.com/smart-window. Or, if it's not available in your region yet, you can sign up to be notified when it is.
The post Classic, Private, or Smart? Choose the right Firefox window for every task appeared first on The Mozilla Blog.
24 Sep 2026 5:00pm GMT
23 Sep 2026
Planet Mozilla
Thunderbird Blog: Thunderbird Monthly Development Digest: September 2026

Greetings once more from the Thunderbird development team!
As the Northern hemisphere summer comes to an end and a slew of PTO, company holidays and projects have wrapped up, what better time to share progress and next steps on the work the Thunderbird Desktop Engineering team has on their plates!?
Exchange support moving well
The powerhouse Exchange engineering team had some great momentum over the summer and completed their work on implementation of the Graph protocol to support email accounts - well in advance of their deadline. They have since moved on to start work to support Exchange calendars using the Graph protocol which is a significant milestone given that our calendar code hasn't had significant changes for some time.
While some team members are now juggling multiple projects, good progress has been made to wrestle the foundations into place, with calendar discovery and persistence in place, along with display of calendar items. Following a brief hiatus to focus on other priorities, the team is once again back into gear.
Keep track of our Graph API Calendar implementation here.
Account Setup & Authentication
Since I last wrote, many of the account setup and account authentication improvements have landed (mostly in versions 156 & 157), unlocking some important security use cases which are becoming more frequently requested and mandated by organizations and legislation around the world.
While diving into the code is an enjoyable adventure, the newly-minted articles devoted to the topic of Oauth customization might be a better starting point for most:
Knowledge Base - Custom OAuth for Thunderbird
UI overhauls - why just one?!
The front end engineering team has completed the rebuild of our account setup manual configuration flows to include new protocol options and security customizations, so it is time to pick up where we left off on our Calendar UI rebuild.
The majority of the front end team is now either focused on Calendar Event data write operations stemming from the Event Read dialog (delete event, RSVPs, Reminders) - or beginning the largest part of the journey, which is the implementation of a new Calendar Create/Edit dialog, along with REDUX-based state management, a new WYSIWYG editor and more reusable components such as date pickers.
Follow the Calendar Event Create/Edit work here
While that work is underway, why not weave in some more improvements?!
After some extensive user research and testing, our design team has begun work to improve the Settings UI, starting with some updates to humanize and homogenize the various options, headings and guidance provided in that area of the application.
Read more about that journey here
Contributions are on the rise! Some AI guidance…
In the past few months, we've seen a wonderful increase in contributions from community members - partially thanks to our move away from Mercurial to a more familiar Git-based workflow - and partially thanks to many LLMs doing a great job of interpreting our public codebase and making it far more accessible. Or it could be that our team is just such a friendly bunch that we've attracted a great group of people willing to support.
Whatever the reason, we're happy to see new names. faces and ideas in our chats and review queue!!
Having said that…We've reached the point where the velocity of work is beginning to pile up and clog our review queue - so I felt it might be time to share some guidance to make the process easier for both external contributors and the internal review team. Bear in mind that while we use AI workflows in several areas, our goal is to preserve a codebase which can be maintained by humans. We're working on a policy that may word some of these points better, but from the past few months of my experience here's what I see as being helpful:
- Keep patches to a digestible size and understandable complexity - Contributions should save more development time than it takes to review. If the patch contribution creates heavy work for maintainers, it will be deprioritized - so the best approach is to break the work up into pieces that can be understood more easily and discussed together. Bear in mind that many cloud-based models aren't primarily designed to be frugal with token usage so it's easy for patches to grow (much) larger than they actually need to be to solve the problem. Be specific with prompts to minimize the surface area of changes so they are reviewable.
- Humanize or write comments (within code and throughout the code review process) by hand - While we've become accustomed to interacting with a variety of automated systems in our daily lives, a good chunk of the joy involved in our work is to share knowledge with each other and refine the code so that it can be reused and understood by humans.
- Be wary of license infringement - much of our work is under the MPL license and we must all take care not to introduce refactored code that originally came from licensed software which can be rewritten and translated using LLM, then relabelled under our licence.
- Be transparent - it will often help to share prompts and your model when submitting code for review. Refining all aspects of our workflow is important, and we can all benefit from a collective evolution of skills and prompts that improve over time with input from the team and community.
- We encourage contact with a member of the team to discuss approach and architecture in advance of spending time and tokens on a patch. Some areas of the codebase are already slated for redevelopment and it's not always obvious what is underway and planned. Having a quick conversation to say "Hey, I'm thinking about working on this" is a great start to landing something that spends less time in review and uses less tokens, energy & the world's natural resources.
- Of course if none of these guidelines are followed, we'll still be very happy to receive help from the wider community - the process may just take longer and be a bit less pleasant.
Enterprise
As parts of the world turn their infrastructure priorities toward digital sovereignty, we've seen an increase in interest from governments, institutions and organizations around the world who are looking to either improve their existing FOSS-based infrastructure or deploy for the first time. That has resulted in some focused efforts throughout Q3 to improve our Enterprise security and policy framework to bring it in line with the strides that the Firefox engineering team has made, and also roll out more Thunderbird-specific administrative mechanisms that allow granular control over end user configurations. Read more about your options and follow the work below:
Thunderbird Enterprise Policies and Relevant Preferences
Thunderbird Enterprise PoC Work Items
Maintenance, Upstream adaptations, Recent Features and Fixes
Waves of changes from upstream Firefox have continually kept the team on their toes throughout July & August, but the small but mighty gang have kept Daily builds largely intact each day. In addition, the team and contributor community have continued landing a series of reliability, stability, and usability improvements across the application. Recent highlights include:
- Nico has a series of calendar improvements in the works with several now cleared for landing: D319397, D320418, D320419
- Hurtmut has again come to the rescue with a number of patches but most recently solved a widespread filtering problem introduced upstream which will need to be uplifted as a matter of urgency.
- Richard pushed many patches since my last update, many related to upstream changes required after the Firefox project "Nova" was unleashed. He's also been on the lookout for other breaking changes such as XUL attribute modifications.
- Max was on fire and in constant comms with the team to deliver a large number of important changes but also helped to refine some of our processes relating to AI-driven workflows. Recently, he led an investigation into growing concerns over instability with connections with Gmail accounts in Bug 2028760.
- and many more which are listed in release notes for beta.
If you would like to see new features as they land, and help us find some early bugs, you can try running daily and check the pushlog to see what has recently landed. This assistance is immensely helpful for catching problems early.
-
Toby Pilling
Senior Manager, Desktop Engineering
The post Thunderbird Monthly Development Digest: September 2026 appeared first on The Thunderbird Blog.
23 Sep 2026 10:35pm GMT
Firefox Tooling Announcements: MozPhab 2.20.0 Released
Bugs resolved in Moz-Phab 2.20.0:
- bug 2066178 Drop support for Python 3.9
- bug 2068605 preserve file logging from moz-phab list --format json and moz-phab patch --raw
- bug 2071586 Review queue reminders should ignore group reviews (at least optionally)
- bug 2073088
moz-phab submitis getting the file size from hg/git even if it could infer it from the blob itself - bug 2074036 List index out of range
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
23 Sep 2026 4:45pm GMT
This Week In Rust: This Week in Rust 670
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Official
- Be alert: targeted attacks on prominent Rustaceans
- GitHub Actions leaking secrets when Miri output is cached
- Maintainer spotlight: Alejandra González (@blyxyas)
- Announcing a Maintainer in Residence: Scott Schafer for the Cargo team
Foundation
Project/Tooling Updates
- Fearless SIMD v1.0 is here
- Syncing Rust GCC backend or how to test Murphy's law
- Benchmarking Wild vs Mold
Observations/Thoughts
Rust Walkthroughs
- [video] Understanding Rust Ownership by Building a Zero-Copy Log Line Parser
- Finding Bugs
- Why datadiff matches arrays by key instead of computing tree edit distance
- [video] RustCurious lesson 10: Three Ways to Fix Any Borrowing Error
- Solving for faster SHA-1 collision detection
- Small and secure Docker images for Rust: Alpine vs Debian vs Scratch
Crate of the Week
This week's crate is fastlogging-rs, a fast logger which supports 8 different programming languages.
Thanks to brmmm3 for the self-suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a call-for-testing label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Cargo, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
RFCs
Rust
Rustup
If you are a feature implementer and would like your RFC to appear on the above list, add the new call-for-testing label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature need testing.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- sysknife - A successful automatic rollback renders to the operator as unknown
- sysknife - sysknife-setup --uninstall deletes .mcp.json whole, taking every other MCP server with it
- sysknife - audit export publishes request_hash, an unsalted hash over unredacted params, with no statement of its sensitivity
- Apache Iggy - Python SDK: expose consumer shutdown and offset drain timeout
- Apache Iggy - Python SDK: expose client disconnect and shutdown lifecycle methods
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
618 pull requests were merged in the last week
Compiler
- A couple polonius constraints perf improvements
- AST lowering cleanups
- an assortment of polonius tweaks
- check
tainted_by_errorin LateLint - even more cleanups for
rustc_builtin_macros - perf: keep the first macro syntax-context mapping inline
- suggest fully qualified path on method name collision
Library
- add
Dir::try_clone - add case mapping fast paths for Latin-1
- complex conjugate, negation and default
- constify comparison traits on sliced types
- implement const Iterator for Range
- stabilize
CommandExt::show_window - stabilize
feature(trim_prefix_suffix)({str,[T],Path}::trim_prefixand {str,[T]}::trim_suffix) - stabilize
windows_process_extensions_main_thread_handle
Cargo
build-rs: makeunstablecompile- account for (uplift) hardlinks when calculating clean file size
- fix: return correct package specs when resolving workspace deps
- remove -Zasymmetric-token / cargo:paseto
- report the number of errors with
build.warnings='deny'
Rustdoc
- Correctly handle
dyntrait methods linking for jump to def feature - Correctly handle intra-doc links on inlined same item with different names
Clippy
- add
must_use_without_reasonlint - fix
const_trait_implrelated infinite loop inneedless_borrows_for_generic_args - generalize
extend_with_draintoVecDequeandBinaryHeap - lint
suboptimal_flopsformul_add,custom_absandradiansin const context - lint nested
format_args!for uninlined args
Rust-Analyzer
- prioritise required items in trait autocomplete
- support completions inside
cfg!() - support hover on cfg predicate
- complete cfg value in string
- correct order deprecated const in builtin ty
- not complete attr args when before exists args
- watch include roots recursively once, not every directory
Rust Compiler Performance Triage
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
- No RFCs were approved this week.
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- Types FCP v2: Supertrait item shadowing stabilization
- declare C and C-unwind as mutually ABI-compatible
- Distinguish
repr(C)ZSTs from others in ABI compatibility rules - Implement Default for NumBuffer
- rustc: Stabilize the WebAssembly
wide-arithmeticfeature - Allow elided ('static) lifetimes in
thread_local! - Stabilize
mem::conjure_zst - Prevent mutating the global environment pointer in
CommandExt::execand opt to use execve and resolve path manually - Stabilize
debug_closure_helpers - Additional NonZero conversions
- Stabilize
funnel_shifts(includingconst) - Stabilize
Result::into_{ok,err} - windows: stabilise inherit_handles
- OUT_DIR is also set when running the program
- feat(config): Add build.profile, install.profile
- fix(git)!: Default to net.git-fetch-with-cli if git is present
- Formulate a
trusted-contributorsmarker team - Participation in Outreachy Dec 2026 (dedication of funds)
No Items entered Final Comment Period this week for Rust RFCs, Language Team, Language Reference or Unsafe Code Guidelines. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
- No New or Updated RFCs were created this week.
Upcoming Events
Rusty Events between 2026-09-23 - 2026-10-21 🦀
Virtual
- 2026-09-24 | Virtual (Berlin, DE) | Rust Berlin
- 2026-09-24 | Virtual (Charlottesville, VA, US) | Charlottesville Rust Meetup
- 2026-09-29 | Virtual (London, UK) | Women in Rust
- 2026-09-30 | Virtual (Cardiff, UK) | Rust and C++ Cardiff
- 2026-10-02 | Virtual | Rust Girona
- 2026-10-04 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-06 | Virtual (London, UK) | Women in Rust
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
- 2026-10-08 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-08 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-10-10 | Virtual (Gdansk, PL) | Stacja IT Trójmiasto
- 2026-10-13 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-18 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-20 | Virtual (Washington, DC, US) | Rust DC
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
Asia
- 2026-09-23 | Maharashtra, IN | Rust Pune
Europe
- 2026-09-24 | Aarhus, DK | Rust Aarhus
- 2026-09-24 | Amsterdam, NL | Rust Developers Amsterdam Group
- 2026-09-24 | Frankfurt, DE | Rust Rhein-Main
- 2026-09-24 | London, UK | Rust London User Group
- 2026-09-25 | Edinburgh, UK | Rust and Friends
- 2026-09-26 | Stockholm, SE | Stockholm Rust
- 2026-09-28 | Augsburg, DE | Rust Meetup Augsburg
- 2026-09-29 | Manchester, UK | Rust Manchester
- 2026-09-29 | Milano, IT | Rust Language Milan
- 2026-09-30 | Basel, CH | Rust Basel
- 2026-09-30 | Berlin, DE | Rust Berlin
- 2026-10-05 | München, DE | Rust Munich
- 2026-10-08 | Oslo, NO | Rust Oslo
- 2026-10-10 | Geneva, CH | Rust Geneva
- 2026-10-14 | Barcelona, ES | BcnRust
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-20 | Leipzig, DE | Rust - Modern Systems Programming in Leipzig
North America
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-24 | Atlanta, GA, US | Rust Atlanta
- 2026-09-26 | Boston, MA, US | Boston Rust Meetup
- 2026-10-01 | Saint Louis, MO, US | STL Rust
- 2026-10-03 | Boston, MA, US | Boston Rust Meetup
- 2026-10-08 | San Diego, CA, US | San Diego Rust
- 2026-10-10 | Boston, MA, US | Boston Rust Meetup
- 2026-10-14 | Los Angeles, CA, US | Rust Los Angeles
- 2026-10-20 | San Francisco, CA, US | San Francisco Rust Study Group
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
Oceania
- 2026-09-29 | Barton, AU | Canberra Rust User Group
South America
- 2026-10-08 | Buenos Aires, AR | Rust en Español
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
operational pedantics
Thanks to Jules Bertholet for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
23 Sep 2026 4:00am GMT
22 Sep 2026
Planet Mozilla
Firefox Tooling Announcements: Happy BMO Push Day! (20260922.1)
The following changes have been pushed to bugzilla.mozilla.org:
Thanks to Kohei for his work on the newly revised Guided Bug Entry form! If you want to check it out yourself, then click on the Switch to Bugzilla Helper link at the bottom of the enter bug product selection page. Normally users without canconfirm permissions will see the Guided Bug page by default which a large percentage of our Bugzilla users.
- Bug 1995464 - Overhaul guided bug entry form
- Bug 2002553 - BMO rest api search: Failed to fetch key from network storage when an attachment has been deleted
Discuss these changes in the BMO Matrix Room
1 post - 1 participant
22 Sep 2026 10:25pm GMT
Firefox Tooling Announcements: Firefox Profiler Deployment (September 22, 2026)
The latest version of the Firefox Profiler is now live! Check out the full changelog below to see what's changed:
Highlights:
- [fatadel] Show a category breakdown in profiler-cli (#6256)
- [fatadel] Show allocation data in the cli (#6246)
- [Florian Quèze] profiler-cli: add a thread list command (#6273)
- [Florian Quèze] profiler-cli: add a thread list command (#6273)
- [Nazım Can Altınova] Add a permalink command to profiler-cli for already published profiles (#6331)
- [Florian Quèze] profiler-cli: add profile markers for cross-thread marker search (#6276)
- [Nazım Can Altınova] Add
--with-samplyto "profiler-cli load" (#6339)
Other Changes:
- [Florian Quèze] profiler-cli: name the process in the thread banner, and follow the queried thread (#6269)
- [fatadel] Drive PII sanitization from marker schemas (#6291)
- [fatadel] Move FileIO table labels into marker schemas (#6296)
- [Markus Stange] Add missing finishRawMarkerTableBuilder. (#6318)
- [fatadel] Fix the upload error button contrast (#6315)
- [Markus Stange] Allow typed arrays in the nativeSymbols table (#6300)
- [Markus Stange] Remove brittle test. (#6322)
- [Markus Stange] Fix file extension typo. (#6325)
- [Markus Stange] Typed arrays + flags for the FuncTable (#6323)
- [fatadel] Convert extension text markers to structured payloads (#6314)
- [Florian Quèze] profiler-cli: include per-marker fields and data in --list --json (#6275)
- [Markus Stange] Speed up call tree sidebar by sharing work with the activity graph (#6329)
- [Nazım Can Altınova]
Sync: l10n → main (Sept 22, 2026) (#6341) - [Nazım Can Altınova] Bump profiler-cli version to 0.10.0 (#6342)
Big thanks to our amazing localizers for making this release possible:
- el: Jim Spentzos
- ro: robbp
Find out more about the Firefox Profiler on profiler.firefox.com! If you have any questions, join the discussion on our Matrix channel!
1 post - 1 participant
22 Sep 2026 4:42pm GMT
Firefox Tooling Announcements: Firefox DevTools MCP 0.10.4 released
Firefox DevTools MCP (firefox-devtools-mcp) 0.10.4 is out on npm.
Changes
This release only contains additional hooks and configuration files to register Firefox DevTools MCP on various third-party aggregators, as well as a new task to automatically register the mcp on https://registry.modelcontextprotocol.io/ on release.
Full changelog: Release v0.10.4 · mozilla/firefox-devtools-mcp · GitHub
Repository and issues: GitHub - mozilla/firefox-devtools-mcp: Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi · GitHub
Public chatroom: https://chat.mozilla.org/#/room/#firefox-devtools-mcp:mozilla.org
1 post - 1 participant
22 Sep 2026 12:43pm GMT
The Rust Programming Language Blog: Announcing a Maintainer in Residence: Scott Schafer for the Cargo team
At the end of August, we announced our first Maintainers in Residence, Rust Project contributors who are funded for their upstream contributions and maintenance work from the Rust Foundation Maintainers Fund (RFMF). Since then, the Rust Leadership Council has dedicated more funds from its Project Priorities budget to RFMF, and together with AWS also providing additional funds, this allowed us to open a new full-time Maintainer in Residence (MiR) position to support the Cargo team. We would like to thank the Rust Leadership Council, AWS, and also the Rust Foundation for providing us with this opportunity! If you would like to help us hire more maintainers to improve Rust, consider donating to RFMF.
This post explains why we chose to support the Cargo team specifically, and introduces Scott Schafer, the new Cargo Maintainer in Residence.
Why Cargo?
The new MiR full-time position is dedicated to helping with the maintenance of Cargo, our build system and package manager. The Cargo project is deeply involved in many new Rust features, improvements, and Project Goals. Combined with its cross-cutting nature, where it has to support many different use-cases and integrate with several other tools, it takes a lot of work just to keep up with its maintenance needs, let alone support so many feature requests and proposed changes.
Because of that, the Cargo team has sometimes struggled with meeting its maintenance demands. You might remember that for several years, it actually held a feature freeze, to reduce Cargo's internal tech debt, perform necessary refactorings, go through the issue and pull request backlog, and come up with scalable internal development and design processes, so that they could eventually go back to even thinking about adding new features.
Recently, some changes occurred within the team, which made it more difficult for them to meet their maintenance baseline. Some members of the team left, while others lost their dedicated funding for working on Cargo maintenance and had to scale down their involvement. The Funding team thus considered it very important to support this team, given that we had an opportunity to do so. And thus we decided to hire a full-time maintainer to work on Cargo for (at least) the next 12 months.
Even though we know that a single full-time maintainer will not completely solve the maintenance struggles of the Cargo team, we hope that it will improve the situation, and provide a bit of a relief for the team.
Introducing Scott Schafer
We are very happy to welcome Scott Schafer (@muscraft) into the Maintainer in Residence role! Scott has joined the Cargo team three years ago, and apart from working on Cargo, he is also the lead of the Rust Docker team, which prepares official Docker images for every Rust version.
Apart from working on general maintenance of Cargo, Scott has implemented Cargo's Workspace inheritance feature, and has also spearheaded a complex multi-year effort to switch the rendering of diagnostics in the Rust compiler to use the annotate-snippets crate. This effort has been completed in the Rust 1.93.0 release. Thanks to it, the same diagnostics interface can now be shared between the compiler and Cargo (and also other tools), which amongst other things unblocked further development of the Cargo linting system, which has now been stabilized and will ship in the Rust 1.100.0 release.
Everyone we talked about was very excited about Scott becoming a Cargo Maintainer in Residence, and we share that feeling. We wish Scott all the best in his new role, and we are very happy that we can support his maintenance work.
Here is what Scott thinks about it:
I am incredibly excited to work on Cargo full-time! There have been so many things that I wish I could've worked on over the years, that I will now be able to get to. I hope that my efforts will bring Cargo into a more maintainable state.
Conclusion
We are incredibly happy that we keep getting more funds for the Rust Foundation Maintainers Fund, which allows us to support Rust Project contributors. The funding team will be working with the supported maintainers, and also the funders, to ensure that they are all happy with the arrangement, so that we can secure stable funding for Rust maintenance for years to come.
If you would like to help us support more Rust maintainers, consider donating to RFMF!
22 Sep 2026 12:00am GMT
21 Sep 2026
Planet Mozilla
The Mozilla Blog: Stay focused wherever you work with Firefox mobile browsers
When it's Monday morning and you're on the subway, in a coffee shop, or squeezing in a few email replies after your morning workout, your phone becomes your digital office. But every time you open your browser, you risk getting struck with any combination of distracting ads, auto-playing videos, and open tabs from the previous week competing for your attention.
For many remote and on-the-go workers, your mobile browser can become a minefield of interruptions and distractions, slowing you down when you need to focus most.
Luckily, there are multiple Firefox features that can help ensure your mobile browser is a focused, productive workspace.
Reduce distractions and clutter with Ad Blocker for Firefox on iOS

Opening a link shared via text or email can save time and keep things moving when a client or coworker needs a fast response. However, once it's actually opened, there is a lot of opportunity for various pop-ups, overlays, and ads to get in between you and what you came in to do.
Ad Blocker for Firefox on iOS was built to reduce distractions and screen clutter while you browse, so you can stay focused on the task at hand. It's a built-in, optional feature that blocks many intrusive ad formats, third-party ad networks, and ad-related trackers. That means no separate extension required, and you decide if and when to use it.
Because Firefox's strong line-up of ad-blocking and privacy extensions on desktop and Android are not available in the same way on iOS, we built Ad Blocker for Firefox directly into the browser. To decide what gets blocked, Ad Blocker uses the EasyList filter and Apple's WebKit Content Blocker technology. It won't impact every ad or sponsored content on a new tab, as those presented directly by host sites and displayed in search results will still be visible.
To try Ad Blocker on iOS, go to Settings > Browsing > Ad Blocker and turn it on to enjoy a cleaner browsing experience.
Get the gist faster with Shake to Summarize

When you're on a deadline, scanning through heavy text, ads, and filler content can turn a quick scan into an infinite scroll session.
Firefox's Shake to Summarize feature helps people get the gist in seconds on both iOS and Android. To use it, simply shake your phone on any web page under 5,000 words, and a clean summary of the page's content will instantly appear. It can also be activated by tapping the "Summarize Page" option under "More" in the three-dot menu.
Like all Firefox features, we built Shake to Summarize with your privacy and protection in mind. This means using device-specific technology to keep your data secure. You can learn more about the AI powering this feature here.
The feature launched on iOS last September, received a strong response from users, and earned a special mention in TIME's Best Inventions of 2025. It is now available on iOS and Android in English, German, French, Spanish, Portuguese, Italian, and Japanese.
Keep your tabs tidy with Tab Groups on Android

Just like us, our smartphones tend to live multiple lives: work, personal, and everything in between. While it can be incredibly convenient to have everything you need for all parts of your life on one device, things can get cluttered fast.
One minute you are knee-deep in a client proposal and the next you're flicking through the countless Google searches from over the weekend. "How old is Harry Styles?" and "Movie times near me" - while pertinent when you were off the clock 24 hours ago - have absolutely nothing to do with the work you are trying to get done now.
To help make sure your prep for Thursday's client meeting doesn't get lost in your pop music deep dive from the weekend, you can group related tabs in Firefox for Android. Each group can be labeled and assigned a color, appearing as a single, searchable card in the tab tray rather than separate tabs, so it's easy to locate when needed. You can open, rename, recolor, and delete these cards whenever you want.
To use Tab Groups on Android, simply drag one tab onto another, or select a few and tap "Add to group." Label the group, choose a color, and you're all set. To try it out, download the latest version of Firefox for Android. iOS support for this feature is on the way.
Pick up where you left off across devices with Firefox Sync
Sometimes we start a task on one device and finish it on another. Maybe you found an article on your computer that you want to read on the subway on your phone. Or, perhaps you want to pull out your laptop and finish filling out that lease application you started on your tablet.
Enable Firefox Sync and you can resume tasks you paused in your browser when switching across your mobile phone, tablet, and laptop. The feature lets you access your open tabs, bookmarks, and passwords across all the devices you access Firefox on.
The best part? We put your data privacy first. Firefox Sync uses end-to-end encryption so your synced data is encrypted before it reaches Mozilla's servers.
To take your browsing experience with you wherever you go, connect your iOS or Android phone to your Mozilla account and start syncing with your other devices.
Take back control of your focus with Firefox
For remote and on-the-go workers, focus is everything.
With Firefox features like built-in ad blocking on iOS, Shake to Summarize for instant insights, and Tab Groups on Android to keep your work and personal digital spaces organized, you can transform your phone from a distraction hub into a productive workspace.
Download the latest version of Firefox for Android or Firefox for iOS today to test out any of the above features available on your device - and take back control of your attention.
The post Stay focused wherever you work with Firefox mobile browsers appeared first on The Mozilla Blog.
21 Sep 2026 5:00pm GMT
The Rust Programming Language Blog: GitHub Actions leaking secrets when Miri output is cached
The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches.
While not necessary a vulnerability in and of itself, when paired with GitHub Actions caching behavior, it is possible for this to expose secrets to PRs.
Overview
GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing cache poisoning). Rust projects tend to speed up CI by caching binaries built by cargo install and sometimes the contents of target/.
PR CI can be triggered by anyone who can open PRs on your repository. GitHub requires maintainer approval for the first PR, but future PRs will rerun CI on every push. Anyone who has previously landed a change can trigger a CI run extracting information from cached target/ and then cover their tracks by pushing a second commit to the PR.
GitHub sometimes hides overwritten commits in its UI, making this kind of attack harder to detect. CI run logs and overwritten commits are also deleted after a few months.
When cargo miri is invoked, Miri needs to retain build-relevant environment variables between runs1. The current code to do so achieves this by storing all environment variables to target/. This, of course, persists when target/ is cached.
If your environment contained secrets, these can now be accessed by PRs via the cache.
Our fix
Our short term fix for this is to make Miri only preserve CARGO_* environment variables (excepting CARGO_*_TOKEN) and OUT_DIR. In the longer term, Miri and cargo may figure out better ways to inform Miri of the relevant list of environment variables. Note that this patch may not be available on nightly yet.
We also performed an ecosystem scan of GitHub repositories and identified 1 repository with this issue and 7 repositories that do not appear to be vulnerable but should be cautious anyway. We have reached out to those maintainers.
Am I affected?
It is likely that our scan was imperfect, so we recommend you check your own GitHub Actions setups if you run Miri.
You are vulnerable if:
- You run
cargo miriin CI - The step that runs
cargo mirihas access to secrets as an environment variable:- By being passed in to the step itself as an environment variable
- By being set in
envfor the workflow - By being passed in to a previous step that persists it in the environment somehow
- The workflow being used caches the
targetdirectory, usually done viaactions/cacheorswatinem/rust-cache - The cache is accessible to PRs (common and often the intended use case)
Possible quick fixes include:
- Disabling cache for that job.
- Scoping secrets to steps in that job that do not call Miri.
- Temporarily disabling Miri.
Once done, please clear the cache. Consider rotating any secrets that might have leaked.
The Miri release in the upcoming nightly (2026-09-22) will no longer have this problem.
Even if you do not run Miri, ensure jobs that can write to public caches do not have access to secrets. Many tools do not have special handling for secrets, and assume the entire environment can be written to the filesystem.
Threat model
We consider it bad practice to have a cache that can easily be tainted by secrets.
If caching target/, it is worth making sure that the inputs to processes that create target/ (anything invoking cargo) do not have secrets available. It is generally rare for standard cargo build/test subcommands to need any secrets or tokens2, so this is mostly a matter of being careful about having secrets exposed as environment variables to the entire job.
Cargo/Miri/Rust does not guarantee that environment variables will be safe from being copied into target/. While we are treating this as a security issue and patching it out of an abundance of caution, this is not something you should rely on in general. Beyond official Rust tooling, it is possible for build scripts to be doing things that lead to the environment being stored in compilation artifacts.
Acknowledgements
Thanks to Predrag Gruevski of OpenAI for reporting this issue to us. Furthermore, the ecosystem scan was performed using Codex access and credits donated by OpenAI, which we also thank them for.
Issue triage and remediation was performed by Manish Goregaokar, Ralf Jung, Ben Kimock, Weihang Lo, Jacob Finkelman, Walter Pearce, Josh Stone, and Mark Rousskov.
21 Sep 2026 12:00am GMT
18 Sep 2026
Planet Mozilla
Firefox Tooling Announcements: Firefox DevTools MCP 0.10.3 released
Firefox DevTools MCP (firefox-devtools-mcp) 0.10.3 is out on npm.
New features:
- New tool:
close_firefox_session- ends the browser session: it releases the connection when the server is attached to an existing Firefox, and closes the browser when the server started it. - New parameter:
fullPageforscreenshot_page- captures the whole scrollable document instead of the viewport. - New parameter:
downloadFolderforset_download_behavior- only used when setting the "allowed" behavior, it sets the folder where downloads should be stored and defaults to~/.firefox-devtools-mcp/output/downloads.
Bug fixes:
- No longer fails to find the Firefox binary on Linux with Flatpak.
restart_firefoxnow rejects when used against a server started with--connectExisting, whereas it used to restart the WebDriver session without restarting the browser and silently ignored all its configuration parameters.
Other changes:
- Servers started with
--connectExistingnow disconnect after 30 minutes without any tool call. restart_firefoxis now part of the mozilla-internal package, and should only be used in controlled environments, as it allows the agent to restart the browser with a custom configuration. Instead, the new toolclose_firefox_sessioncan be used whenever clients do not need to update the browser configuration, and will have a more consistent behavior.- Path checks for the
saveToparameters have been improved to avoid overlapping with existing profile folders
Install:
claude mcp add firefox-devtools npx @mozillamozilla/firefox-devtools-mcp@latest
codex mcp add firefox-devtools - npx @mozilla/firefox-devtools-mcp@latest
For internal Firefox development, swap firefox-devtools-mcp with firefox-devtools-mcp-moz in order to benefit from additional tools, such as chrome-privileged script execution.
Special thanks to all the contributors who filed issues and submitted patches for this release: f3tch (github), shoemoney and mightykatun.
Full changelog: Release v0.10.3 · mozilla/firefox-devtools-mcp · GitHub
Repository and issues: GitHub - mozilla/firefox-devtools-mcp: Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi · GitHub
Public chatroom: https://chat.mozilla.org/#/room/#firefox-devtools-mcp:mozilla.org
1 post - 1 participant
18 Sep 2026 10:14am GMT
17 Sep 2026
Planet Mozilla
The Mozilla Blog: Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support

Today at ALL IN, Canada's largest AI and technology event, Mozilla and Mila announced a new initiative and fresh investment to build an open source AI foundation layer that enables organizations and institutions to own and operate advanced AI systems locally, ensuring full control over their technology and data.
Doubling down on its commitment to open source AI, the Government of Canada announced its support for the initiative. Mila will lead the technical delivery and coordination of the project, while Mozilla contributes technical expertise. It also provided the initial $5 million investment to kick off the project. Hypertec is committing an additional $1 million in first-year funding to accelerate initial Canadian deployments of the open source AI foundation layer on Hypertec hardware.
"Canada has a choice: depend on technologies developed elsewhere, or build more of what we need here at home," said The Honourable Evan Solomon, Minister of Artificial Intelligence and Digital Innovation and Minister responsible for the Federal Economic Development Agency for Southern Ontario. "Open source AI gives Canadian businesses and institutions greater control over their technology and data, while making powerful tools more affordable, accessible, and easier to adapt. By supporting this work, we are strengthening Canada's capacity to build and adopt AI on our own terms."
Mila and Mozilla will lead the work together: Mila drawing on a world-class community of close to 2,000 researchers and professionals, Mozilla as technical partner from industry, bringing 25 years of experience stewarding open infrastructure others build on. Mila and Mozilla are actively engaging new partners, inviting companies, research institutions, funders, governments, and developers to join and support this work.
What's being built
The goal is simple: make owning your AI as easy as renting it. Using open source models was never the hard part. Turning a raw open source model into something a small business, a hospital, a local charity, or a government can run in production - secure, reliable, plugged into everything else - takes an engineering team most organizations and institutions do not have and months they can't spare.
The goal is to offer businesses and organizations a ready-to-use AI package that they can run privately and keep under their own control, rather than having to build a complex system themselves or rely entirely on expensive, pay-per-use proprietary AI services.
For example, a small manufacturer could use the system as a private AI assistant for its employees. It could search the company's manuals, procedures, and past project files; help staff draft reports or answer technical questions; and help its software team write and improve code. Because the system is designed to be able to run locally, the company could do this while keeping its proprietary information and data within its own environment.
That also means lower costs. For the vast majority of everyday business tasks, companies will be able to use open source AI running on open source tools instead of paying a commercial provider every time an employee makes a request. But this requires reducing the technical work and expense involved in putting open source AI into practice.
This initiative was founded to solve that problem, building the free layer that makes owning open source AI easy - the same kind of layer the web was built on. It has two halves: An open standard, published as interface contracts, so any part of the stack can be swapped for a better one. And a working "reference implementation" any organization can install on its own machines or the ones it chooses, running the models and controls it chooses against its own data, with governance and access control built in from the start. The ambition is that with the standards and foundation in place, open source AI can be built anywhere, by anyone.
"Six months ago, we announced our partnership with Mozilla to advance open source and sovereign AI. Today, we are bringing that work to a whole new level," said Valérie Pisano, President and CEO of Mila. "By delivering an open, secure AI foundation layer, we empower organizations, from small businesses to non-profits to governments, to own their technological future so they can run, control, and maintain AI models themselves. At Mila, our research community has always believed that for AI to be trustworthy and accessible, it must be built on open standards that keep control in local hands."
The work already underway
Over the last six months, Mila and Mozilla have been designing the architecture, deciding which open source components belong at each layer, and testing that the whole system works end to end. This investment builds on that progress.
Working alongside Mila and Mozilla, Hypertec will help move the initiative from research and reference implementation to real-world adoption by Canadian businesses and institutions, providing a practical, private, and cost-effective path to deploy AI while maintaining greater control over their data and technology.
"AI is advancing at an extraordinary pace and has the potential to transform our economy and society for the better. Canada has an important role to play in ensuring that AI is developed and adopted responsibly, said Simon Ahdoot, CEO of Hypertec Group. "Hypertec is proud to help turn open source innovation into AI that Canadian organizations can deploy securely and under their own control. This is exactly the kind of partnership between government, research, and Canadian industry needed to realize the full potential of AI."
Why now
Mozilla's State of Open Source AI report found that while 79% of developers adding AI functionality use open models, only 53% of teams ever reach production, stopped by cost, security, integration, and maintenance. This work aims to change that.
"AI today is at a crossroads, where it could be closed and owned by a few, or open and available to every coder, developer, enterprise, and nation," said Mark Surman, President of Mozilla. That's what we're building - an open source AI ecosystem that fits together as seamlessly as the web, and that anyone, anywhere can build on. We're so grateful to Canada for scaling this work, and call on partners across sectors - from enterprises and governments to coders and startups - to join us in building this future."
Within six months, Mozilla and Mila expect to publish working reference implementations for enterprise, government and public-interest use cases. The two-year ambition is bigger: to have solved this problem outright, so that open source AI can be adopted fully and easily, anywhere, by anyone.
The post Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support appeared first on The Mozilla Blog.
17 Sep 2026 7:30pm GMT







