Mozilla Data YouTube Channel
Mozilla Data YouTube Channel
Last Lecture: Writing the Data Docs
The Rust Programming Language Blog
Demoting i686 Windows targets to std-only
With Rust 1.100.0, the following changes to 32-bit Windows targets will happen:
i686-pc-windows-msvcTier 1 with host tools target will be demoted to Tier 1 without host tools.i686-pc-windows-gnuTier 2 with host tools target will be demoted to Tier 2 without host tools.
Builds of the standard library will continue to be distributed, but host tools such as the compiler will be no longer available. i686-pc-windows-msvc as a Tier 1 target still undergoes CI testing.
To build 32-bit Windows binaries, cross-compiling from a still-supported host toolchain (such as a 64-bit Windows ones) will be required from now on.
Background
Desktop and Server 32-bit only x86 CPUs are no longer sold for over 15 years, and general 32-bit Windows support has ended in October 2025. This means that the development platforms these targets are meant for hardly exist these days, and even if they do exist they typically aren't capable enough for development.
Even on the modern x86_64 hardware, building i686 Windows toolchains has proven to be problematic. We have encountered compiler binaries crashing when built with the i686 MSVC target, and the GNU C++ toolchain failing with OOMs during LLVM build.
Considering all these things, cross-compiling these targets from a better supported one is what we have found to be the best solution forward. As part of that, we stopped producing host tools for these targets. For the time being, the prebuilt standard library is still available, and in case of i686-pc-windows-msvc still tested on CI.
What Changes?
After Rust 1.100, it will no longer be possible to install toolchains on 32-bit Windows hosts. We recommend cross-compiling from a still-supported host (such as a 64-bit Windows toolchain) instead. Other 32-bit platforms are not impacted by this change.
For more details about these demotions, see RFC 3999 for i686-pc-windows-msvc demotion, and MCP 1020 for i686-pc-windows-gnu demotion.
Mozilla Data YouTube Channel
Monitoring Sensitive Data: How do we monitor data we don't store?
Thunderbird Blog
Thunderbird for iOS: A First Look at the Native iPhone Email App in Development
The team has been working hard behind the scenes laying a strong foundation for the Thunderbird iOS app. Rather than leveraging existing code, we are building natively from scratch. This fresh start allows us to take everything we’ve learned from Thunderbird Desktop and Android to ensure a fast, reliable, and modern experience on your iPhone right from the start.
Our ultimate goal is seamless cross-device experience. Whether you’re sitting at your desktop computer, checking messages on the go, your workflow should feel effortless and unified.
Right now, we are focused heavily on getting the core foundations right. We are excited about the momentum because having clean architecture today means we can layer on exciting new features much faster in the future.
Below we’ve captured some of our work in progress. Nothing is final, but we wanted to share what we are cooking up so far. If you have feedback, keep reading on. At the bottom of the post we have a link to a user research study where we want to hear from you and what you want to see from Thunderbird for iOS.
Hassle-free setup
We know people are really busy, often doing more than one thing at a time. We’re making login fast, secure, and fully automatic, so whether you’re signing in with a single click or setting up multiple accounts, you can get to your inbox quickly.
Solid reliable connections
An email app is only as good as its connection. Behind the scenes, we’re building a background sync that maintains a steady connection with your provider that keeps your inbox up to date while respecting your battery life.
Core daily tools
Your daily email routine should feel effortless. We’re polishing the essentials: a clutter-free, easy-to-read inbox layout paired with a clean, modern editor that lets you format messages smoothly without getting in your way.
Designed for growth
Thunderbird has always belonged to its community. We’re structuring the app with clean code and an experimental feature flag system so it’s easy for community developers to contribute. This means power users will be able to test out new experimental features early, and external contributors can easily help us extend what the app can do.
When can you try it?
Our goal is to have a first version ready for community testing in the next few months.
Building with our community, not just for people, is core to what we are trying to do. To help us decide what to build next after our first release, we’d love your input. If you had to pick the top three things that matter most to your daily email routine, what would they be?
A note to the community
Lastly, we know how long many of you have been asking for and waiting for Thunderbird on iOS. Whether you’ve dropped a comment on our forums, tagged us on social media, or simply kept an eye on our progress, thank you for your patience!
Bringing Thunderbird to iPhone and iPad isn’t just about building an app; it’s about doing it right so it serves you reliably for years to come. Today, we want to pop open the hood, share where we are, and work with everyone to design the best possible experience.
The post Thunderbird for iOS: A First Look at the Native iPhone Email App in Development appeared first on The Thunderbird Blog.
Mozilla Data YouTube Channel
Glean Dictionary Looker Demo
The Mozilla Blog
Under the Hood: Prompt tuning Shake to Summarize for recipes
Following the rollout of Firefox’s Shake to Summarize feature to Android devices this May, we wanted to take a closer look at the modeling work behind the feature. In a previous blog post, we discussed our model selection process. Now that Shake to Summarize has been available on both iOS and Android for a few months, we wanted to take it a step further and outline our approach to prompt development.
This is the story of a Shake to Summarize use case that required a little extra prompt tuning: online recipes.
Framing the Problem
The first step in developing a useful prompt is clearly describing what you want the LLM to do. LLMs thrive on specificity, so the more sharply you can define your task, the better your results are likely to be.
This is especially important when using smaller LLMs (like we are here), since these little models are not as good at reading between the lines and intuiting unstated intentions as their more powerful cousins are.
For this application, we were looking to create summaries. On the face of it, this seems pretty straightforward. However, as we iterated on prompts, we quickly discovered that what constitutes a “good” summary depends largely on what one is summarizing.
For example, a useful summary of a novel should provide us with a quick overview of the plot without getting into too many specific details; we wouldn’t expect the summary to contain anything from the text verbatim.
In contrast, a summary of a recipe website should include the recipe essentially as written. If the recipe says “cook lovingly” we might be OK with shortening it to “cook,” but if it calls for 4 cups of vegetable broth, a Tbsp of oregano and a tsp of thyme, we want these details relayed to us exactly. Merely stating, “this recipe calls for some broth and some spices” would not be adequate.
Forming the Prompt
From here, it became clear that we wanted not just one “summarize” instruction, but a whole set of instructions — one for each category of webpage that we wished to summarize. We worked with the product team to compile a list of article types that we were targeting for this feature. For each article type, we then gave a brief description of what a good summary would look like:
Recipe – Ingredients as written, along with the key steps, time required, and any tips given by the author or commenters
News – Only the important details: what happened, when, and what would be the likely consequences to the reader
How-to – Start with the required materials, skills, tools, etc., along with the main steps and any specific warnings called out by the author
Review – Highlight the bottom line rating. If it is a product review, include the pros and cons, the price, and who the target audience is.
Research – Key finding and level of confidence the researchers have in their results as well as the projected real-world impact.
Opinion – The main argument, along with any key evidence cited in support
We then wrapped this list in some general instructions to ground the model in the task and came up with our initial prompt (formatted for readability) [source]:
You are a Content Summarizer. You create mobile-optimized summaries by first understanding what users actually need from each type of content.
Process:
Step 1: Identify and Adapt.
Step 2: Based on content type, prioritize:
Recipe – Servings, Total time, Ingredients list, Key steps, Tips.
News – What happened, when, where.
How-to – Total time, Materials, Key steps, Warnings.
Review – Bottom line rating, price.
Opinion – Main arguments, Key evidence.
Personal Blog – Author, main points.
Fiction – Author, summary of plot.
All other content types – Provide a brief summary of no more than 6 sentences.
Step 3: Format for mobile using concise language and paragraphs with 3 sentences maximum.
Bold critical details (numbers, warnings, key terms).
We Foxfooded the above prompt and found that it mostly worked pretty well. The summaries the model produced were concise, accurate, and informative.
The only exception was recipes.
We found that, when the prompt above was used for recipes, the model tended to summarize too much — often leaving out key ingredients, or in some cases, leaving out the recipe entirely.
For example, when asked to summarize a lentil soup recipe the model returned:
The webpage provides a detailed recipe for a vegan lentil soup, which the author claims is the best they’ve ever made. The soup is made with pantry staples like lentils, diced tomatoes, vegetable broth, and spices (cumin, curry powder, thyme), along with fresh vegetables (onion, carrots, garlic) and greens (kale or collard greens). A key step is blending a portion of the soup to create a creamy texture without dairy.
The summary is accurate, so far as it goes, but it isn’t exactly useful. If our goal is to have the summary be a quick way to access the recipe itself, without having to read through the narrative preamble, this wouldn’t cut it.
Focusing the Prompt
To address this problem, we needed to be more explicit with the instructions we gave the model when summarizing recipes: we needed to tell it which information we were interested in and which it could safely discard.
Although we could have added this extra guidance directly to the prompt above, doing so risked causing the model to over-index on the recipe formatting and ignore the other article types. Instead, we developed a separate prompt which contained only the recipe instructions and directed recipe summarization requests to use it, rather than the general one [source].
To perform this routing, we used the structured data embedded in each webpage. While this categorization could have been handled by another model pass, metadata from the webpage itself allowed us to quickly and deterministically identify the page categories without additional inference overhead. To capture cases where this data is either missing or inaccurate, we also maintain some lightweight recipe guidance in the general prompt.
After this change, the summary returned by the model for the above recipe became much more usable (shortened for brevity):
Servings: 6
Total Time: 50 minutes
Prep Time: 10 minutes
Cook Time: 40 minutes
Ingredients
- ¼ cup extra virgin olive oil
- 1 medium yellow or white onion, chopped
- 2 carrots, peeled and chopped
- …
Instructions
- Warm the olive oil in a large Dutch oven or pot over medium heat.
- Add the chopped onion and carrot, cooking until the onion softens and turns translucent, about 5 minutes.
- …
Tips
- Use an immersion blender for easier blending without transferring soup.
- …
Nutrition
- Calories: 320
- …
With this change in place, we ran a quick test over a curated set of recipe sites and found that the new system was more than twice as likely to return a complete and accurate summary than our previous one. Success!
The system was now working as expected: summaries were useful and recipes were complete.
Reflections
From this experience we learned that the model produced the best results when it was told explicitly what we wanted it to do. When the instructions were vague or left too much up to the model, performance suffered.
To this end, we found that framing this problem as a routing problem — where the specific kinds of articles are routed to specific prompts — worked well. Since the task of summarization is not monolithic, our summarization pipeline should not be either.
Even though our current approach has only a single category-specific prompt, we hypothesize that the system would see further gains by using dedicated prompts for other page types as well.
More broadly, this experience reinforced an important lesson for us: improving AI systems is not solely about building larger or more capable models. Some of the biggest gains come from reducing ambiguity, narrowing the task, and designing systems that help the model succeed. Within the right harness, smaller, open source models can deliver great value.
While building more capable models continues to advance the field, our experience shows that thoughtful system design and solid engineering still matter.
The post Under the Hood: Prompt tuning Shake to Summarize for recipes appeared first on The Mozilla Blog.
Mozilla Data YouTube Channel
An opinionated intro to NLP (text analytics)
Mozilla Data YouTube Channel
Data Incident Process
The Rust Programming Language Blog
Announcing Rust 1.99.0
The Rust team is happy to announce a new version of Rust, 1.99.0. Rust is a programming language empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, you can get 1.99.0 with:
$ rustup update stable
If you don't have it already, you can get rustup from the appropriate page on our website, and check out the detailed release notes for 1.99.0.
If you'd like to help us out by testing future releases, you might consider updating locally to use the beta channel (rustup default beta) or the nightly channel (rustup default nightly). Please report any bugs you might come across!
What's in 1.99.0 stable
extern "C" variadics
Rust 1.99.0 stabilizes defining C-ABI variadic functions with "C" and
"C-unwind" ABIs. Variadic functions defined this way use a variable argument
list (...) and accept an arbitrary number of arguments. Rust could already
call externally-defined variadic functions (e.g., libc::printf). With Rust
1.99, these functions can now be written in Rust itself:
/// SAFETY: must be called with (at least) 2 i32 arguments.
unsafe extern "C" fn sum(mut args: ...) -> i32 {
// SAFETY: guaranteed by the caller.
let a = unsafe { args.next_arg::<i32>() };
let b = unsafe { args.next_arg::<i32>() };
a + b
}
fn foo() -> i32 {
unsafe { sum(0i32, 2i32) }
}
The type of ... is VaList,
which is ABI-compatible with the C va_list type across targets. What types can be read from a VaList is guarded by the
VaArgSafe trait.
For more details on c-variadic functions, see the Reference. This release also stabilizes support for defining naked variadic functions with non-"C" ABIs, which must be written via inline assembly.
Layout information from raw pointers
This release settles the safety requirements for retrieving the size and
alignment on raw pointers to both Sized (trivially safe, already possible on
stable) and non-Sized types.
This is done by stabilizing three functions:
Recommend against round-trip unleaking after Box::leak
While there are no changes to the language semantics in Rust 1.99, we have
updated the documentation on Box::leak to recommend against patterns that
later deallocate that memory. This was done because such code was found to have
problematic interactions with current and future potential compiler optimizations,
and is especially problematic with the upcoming stabilization of custom allocators.
Instead, Box::into_non_null or Box::into_raw should be preferred.
This guidance also applies to other leak functions in the standard library.
Stabilized APIs
IntoIteratorforBox<[T; N]>IntoIteratorfor&Box<[T; N]>IntoIteratorfor&mut Box<[T; N]>VecDeque::retain_backcore::ffi::VaListBox::into_non_nullBox::from_non_nullVec::into_partsVec::from_partscore::mem::size_of_val_rawcore::mem::align_of_val_rawcore::alloc::Layout::for_value_rawString::from_utf8_lossy_ownedstring::FromUtf8Error::into_utf8_lossyFusedIterator for StepBy<I>std::fs::set_timesstd::fs::set_times_nofollow
Other changes
Check out everything that changed in Rust, Cargo, and Clippy.
Contributors to 1.99.0
Many people came together to create Rust 1.99.0. We couldn't have done it without all of you. Thanks!
About:Community
A fresh Firefox and MozFest count down
Hi Mozillian,
In this edition, we’re exploring the new Firefox design, Mozilla’s recent partnership with Mistral to expand choice in AI-powered browsing, and several ways to get involved with MozFest. You can join a livestream about the value of bringing open-source communities together in person, volunteer at MozFest in Barcelona, or take part in the latest privacy discussion from the Firefox community on Reddit.
Read on for the latest updates and opportunities to participate!
More modern. More flexible. Still Firefox.
Firefox 157 introduces a new Firefox design with updated colors, icons and themes that make the browser feel more modern while preserving the familiar Firefox experience. The release also brings back Compact Mode and adds easier theme selection, new wallpapers and more ways to customize the New Tab page. Underneath the new look, Firefox remains independent and open source, with built-in privacy protections and controls that let you decide how your browser works, including how AI features appear.
Mozilla and Mistral partner to expand AI choice
Mozilla and Mistral have announced a partnership aimed at increasing competition and preserving user choice in AI-powered browsing. As part of the collaboration, the open-source Mistral Small 4 model is coming to Firefox Smart Window Beta as a new option for users in the US and Canada. Smart Window Beta is also expanding to France with official French-language support, with additional European markets planned. Users can continue choosing from multiple AI models, reinforcing Firefox’s commitment to avoiding lock-in and keeping the web open to different technologies and providers.
Does open source need IRL? The case for MozFest
Is showing up in person important for open source? Join the Owners Not Renters livestream on Tuesday, September 29, to hear the story behind MozFest and explore why gathering in person still matters for open-source communities ahead of MozFest, taking place October 28–30 in Barcelona. Kali Villarosa (MoFo), Seher Shafiq (MoFo) and Brian Behlendorf (co-founded Apache) will join host Marcus Rein for an open conversation, followed by a live Q&A. Bring your questions and your hot takes!
MozFest call for Volunteers
From 28–30 October 2026, the Mozilla Foundation will host the Mozilla Festival in Barcelona, bringing together people from diverse fields to explore how we can work collectively to “re-wild” the web. To help bring the Festival to life, we’re building a team of volunteers. By joining, you’ll help deliver a major event in support of Mozilla’s mission while also having opportunities to participate in sessions throughout the three-day Festival.
From the Reddit Community
Privacy conversations are going mainstream, and Firefox has been at this for 20+ years. In light of a recent video making the rounds about the importance of privacy, the Firefox Team shared a rundown of built-in privacy features (ad blocking, tracking protection, encrypted sync, a free VPN, and more). Jump in at r/firefox and share your own privacy tips and configs!
P.S.
Enjoyed these updates? Subscribe to the Mozilla Community Newsletter and get the latest updates delivered straight to your inbox.
This Week In Rust
This Week in Rust 671
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Newsletters
Observations/Thoughts
- Can safe Rust ever beat Google's C Brotli?
- Building a DMA based driver for the RP2350 I2C (safety not included)
- Advanced soft-bodies for games with the Rapier physics engine
- Supporting native Rust in Workers with the new Emscripten target for wasm-bindgen
- Rusty thoughts on "Parse, don't validate"
- The state of SIMD in Rust in 2026
- How do you stop being a Rust novice?
- We Have Named Arguments at Home: a reply to the blog post Arguing about arguments mentioned in the last issue
- Upstream Rust maintenance report (August-September 2026)
- Rust in the kernel? What about Rust without the kernel!
- Compiling the kernel with gccrs
- Listening to the radio with Rust
- Native support for Rust on the GPU
Rust Walkthroughs
- How to speed up the Rust compiler in September 2026
- Building Real-Time Notifications with SSE and Pub/Sub
- Green Threads from Scratch
- A Type Stronger than the Sum of its Components
- Deser: Rethinking Rust Serialization
- Dropping Swift from our Bevy iOS crates
- Pining for Arc Downcasting in Rust
- Topcoat is pushing the boundary of server applications with Rust
- Rust Reborrowing, Aliasing, and Mutable References
- A very condensed introduction of the basics of Rust
- [video] Making Our GPUI App Interactive with State and Events
- [ES] Domain–Flow–Effects (DFE): an architecture designed for Rust
Miscellaneous
Crate of the Week
This week's crate is ying-profiler, a native Rust sampling memory profiler.
Thanks to Evan Chan for the self-suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a
call-for-testing label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Cargo, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- unsynced - strace frontend fails on pwritev2 with offset -1 (current file offset)
- unsynced - Model hard links (link/linkat) instead of warning
- unsynced - Add an ext4 data=writeback persistence profile
- MemoryWhale - Cover friendly errors for incomplete
mwarguments - MemoryWhale - Lock down
mw --helpoutput - dataprof - Remote Parquet refusal messages should say to download the file when the server ignores Range
- dataprof -
ScoreBounds::dimension_scoresdocs still list estimated key counts as unbounded - dataprof - The progress
finishedevent under-counts rows when a row cap stops the incremental engine
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
546 pull requests were merged in the last week
Compiler
- computing
crate_hashfrom metadata encoding instead of HIR (implements #94878) - detect missing else in let statement
- give noalias back to refs in closures
- implement forced keywords (
k#) - use SmallVec in LocalizedConstraintGraph
Library
- add
DivandMulforComplex<{float}> - alloc: stabilise
Allocator - additional
NonZeroconversions - allow elided (
'static) lifetimes inthread_local! - implement
PartialEq<VecDeque<U>>forVec<T>,&[T],&mut [T],[T; N],&[T; N]and&mut [T; N] - make dropping an empty BTreeMap free
- stabilize SyncView
- stabilize
Box::take - stabilize
Result::into_{ok,err} - stabilize
funnel_shifts(includingconst) - stabilize
mem::conjure_zst - stabilize
vec_try_remove - use wrapping arithmetic in
from_str_radix
Cargo
builtin-deps: add builtin dependencies manifest syntaxconfig: add build.profile, install.profilemetadata: mirror package features infeatures_v2builtin-deps: fix builtin dependencies manifest validationdiag: Don't report unused normal deps when static libs are skippedpackage: preserve feature metadata in normalized manifests
Rustdoc
- correctly check that an item is not
doc(hidden)with--generate-link-to-definition - fix intra doc link resolution when a doc comment is composed of both inner and outer doc comment
- fix invalid jump to def link when
#[rustc_allow_incoherent_impl]is involved - fix quadratic naming of duplicate sidebar links
Clippy
while_let_loop: detect the pattern when the loop has a label- add new
try_from_instead_of_from_strlint - don't suggest
Box::leakinnonnull_unchecked_on_box_ptr - fix
collapsible_matchconsuming/mutation checking - fix
match_str_casematching str inside or patterns - improve doc attr span tracking for proc-macro
Rust-Analyzer
- don't fail extension activation when the server fails to start
- add
type_matchrelevance for type-alias - coercion safe fn to unsafe fn
- complete 'false' in cfg attribute
- complete attr value inside string without quotes
- const eval cast of single-variant
enum - deduplicate 'derive' and 'test' attribute macro
- do not type match unknown type
- don't clear semantic tokens cache on refresh
- hover show impl header when impl with trait
- panic in async closures with higher-ranked trait bounds
- return UB instead of panicking when reading the discriminant of an uninhabited
enum
Rust Compiler Performance Triage
This week was fairly positive. We had no pure regressions, and most of the results came from a few architectural improvements with mixed or mostly positive impact. Some improvements also come from addressing previously triaged regression caused by missing no_alias annotation for references in closures.
The biggest improvement this week is in rustdoc, from tackling quadratic behaviour when generating sidebar links. This was reported by a user, but the effect didn't show up in our benchmarks, so we added a special stress test for it.
Triage done by @panstromek. Revision range: 3670d253..c1070d69
Summary:
| (instructions:u) | mean | range | count |
|---|---|---|---|
| Regressions ❌ (primary) |
0.6% | [0.2%, 0.8%] | 8 |
| Regressions ❌ (secondary) |
1.4% | [0.1%, 5.8%] | 30 |
| Improvements ✅ (primary) |
-0.6% | [-1.7%, -0.2%] | 192 |
| Improvements ✅ (secondary) |
-1.5% | [-82.5%, -0.1%] | 101 |
| All ❌✅ (primary) | -0.6% | [-1.7%, 0.8%] | 200 |
0 Regressions, 2 Improvements, 6 Mixed; 3 of them in rollups 26 artifact comparisons made in total
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
- No RFCs were approved this week.
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- Stop using dlltool for generating import libraries on MinGW
- Stabilize
ptr::try_cast_aligned - [disposition: close] 1.99 beta crater regression: overflow evaluating the requirement
- implement FCW for
rustc_allowed_through_unstable_modulesitems - fix
VisibleForLeakCheckinRegionOutlivesfast path - Stabilize
debug_closure_helpers - Support type-relative assoc item paths in generic param defaults & const param types
- FCW for
#[panic_handler]onunsafe fn. - Stabilize
optimizeattribute - Allow unary operand types to be inferred later
- Feat -
#[inline(always)] + #[target_feature(enable = "....")]#2 - Tracking Issue for
CStr::display - Syntactically reject leading parenthesized precise capturing lists in bare trait object types (
(use<…>)+)
No Items entered Final Comment Period this week for Language Team, Language Reference, Leadership Council or Unsafe Code Guidelines. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
Upcoming Events
Rusty Events between 2026-09-30 - 2026-10-28 🦀
Virtual
- 2026-09-30 | Virtual (Cardiff, UK) | Rust and C++ Cardiff
- 2026-10-01 | Virtual | Rust Foundation & JetBrains
- 2026-10-02 | Virtual | Rust Girona
- 2026-10-03 | Virtual (Amsterdam, NL) | Bevy Game Development
- 2026-10-04 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-06 | Virtual (London, UK) | Women in Rust
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
- 2026-10-08 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-08 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-10-10 | Virtual (Gdansk, PL) | Stacja IT Trójmiasto
- 2026-10-10 | Hybrid (Kuala Lumpur, Malaysia) | Rust Malaysia Meetup
- 2026-10-13 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-18 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-20 | Virtual (Washington, DC, US) | Rust DC
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-10-22 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-27 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-27 | Virtual (London, UK) | Women in Rust
Asia
- 2026-10-09 | Hybrid (Kuala Lumpur, MY) | Rust Malaysia Meetup
Europe
- 2026-09-30 | Basel, CH | Rust Basel
- 2026-09-30 | Berlin, DE | Rust Berlin
- 2026-10-01 | Berlin, DE | Rust Berlin
- 2026-10-01 | Oxford, GB | Oxford ACCU/Rust Meetup.
- 2026-10-05 | München, DE | Rust Munich
- 2026-10-08 | Oslo, NO | Rust Oslo
- 2026-10-08 | Geneva, CH | Rust Geneva
- 2026-10-14 | Barcelona, ES | BcnRust
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-20 | Leipzig, DE | Rust - Modern Systems Programming in Leipzig
North America
- 2026-10-01 | Saint Louis, MO, US | STL Rust
- 2026-10-03 | Boston, MA, US | Boston Rust Meetup
- 2026-10-08 | Lehi, UT, US | Utah Rust
- 2026-10-08 | New York, NY, US | Rust NYC
- 2026-10-08 | San Diego, CA, US | San Diego Rust
- 2026-10-10 | Boston, MA, US | Boston Rust Meetup
- 2026-10-14 | Los Angeles, CA, US | Rust Los Angeles
- 2026-10-20 | San Francisco, CA, US | San Francisco Rust Study Group
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-10-21 | San Francisco, CA, US | Bay Area Rust
- 2026-10-28 | Austin, TX, US | Rust ATX
South America
- 2026-10-08 | Buenos Aires, AR | Rust en Español
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
The community is obnoxiously helpful. I asked a simple question on the Rust community Discord server. What is the best way to read a file in Rust? I expected a straightforward response. Instead, I got back a 2,000-word essay on the inner workings of IO, buffering, error handling, and ownership, plus links to four different blog posts and three different approaches depending on file size, and a working code example.
...
The Rust community has weaponized education against me. I'm now a better engineer than I was yesterday against my will.
Thanks to MusicalNinjaDad for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
Mozilla Addons Blog
Nova is here: what changes for your Firefox theme
On September 29, Firefox 157 shipped Nova, the biggest refresh of the Firefox interface since Proton back in 2021. The browser frame is cleaner, the sidebar plays a bigger role, and vertical tabs are a first-class layout. Your theme continues to load, and most color and image properties work as they did before.
What does change is where those colors and images display, how some of them look next to each other, and a handful of properties that no longer have a visible effect. Most themes will look fine. Some, especially themes built around a background image, look different enough that you will want to take a look.
This post walks through what changed compared with the Proton interface, what to check in your theme, and what is still being worked on. If you only have five minutes, jump to the checklist.
What changed in the browser frame
The toolbar and sidebar now sit flush with the window edges, with no gaps between them.
For your theme, this means your frame color and background image have less empty space around them, and the edges where the toolbar, sidebar, and page meet are more visible.
| Area | Proton | Nova (Firefox 157) |
|---|---|---|
| Toolbar and sidebar | Flush with the window, no gaps or floating borders | Same as before |
| Horizontal tabs | Theme background applied to the tab strip | Same as before |
| Vertical tabs | Tab bar color on the tab strip | Tab bar color also shows on the toolbar |
| Sidebar | Separate panel | Shares the theme background with the toolbar area |
colors, accents and tabs
Accent color. The default Firefox theme uses Nova’s purple accent. Every other theme, including yours, uses the operating system’s accent color for buttons and other accented controls. Themes cannot set the accent color through the manifest, and is why your theme cannot show the purple you see in the default theme.
Focus and link colors. Firefox still applies its own blue and cyan to focus rings and some links when a theme other than the default is active.
The selected tab. Proton always drew a shadow under the selected tab, which helped it stand out even when a theme did not style it. Nova removes that shadow. If your theme relies on it, the selected tab can blend into the tab strip. Set the selected tab colors, with tab_selected and tab_line, so the selected tab stands out.
Button hover colors. Your button_background_hover and button_background_active colors also apply to buttons on the tab strip, and for buttons that sit on your frame background with vertical tabs. A solid color picked to match the toolbar can almost disappear there. Semi-transparent colors, for example rgba(0, 0, 0, 0.15) for hover and rgba(0, 0, 0, 0.3) for pressed, work on both backgrounds.
Sidebar and vertical tabs
- The sidebar shares your background. The theme background now continues under the sidebar, so the sidebar and the toolbar area appear as one surface.
- Set sidebar colors explicitly. Use
sidebarandsidebar_textfor sidebar panels. If you leave them out, Firefox picks colors for you, relevant to your theme’s color. sidebar_borderis now a separator. The sidebar splitter is gone; the property now colors the line between the sidebar and the page.- Sidebar buttons follow your text color. Buttons and icons in the sidebar are derived from your text color rather than your toolbar button colors, so they can look slightly different from the toolbar.
- Vertical tabs and the toolbar. With vertical tabs, your tab bar color is also applied to the toolbar. If those two colors were chosen to contrast, check how they look together.
- Expand on hover. In Firefox 157, a sidebar that expands on hover may not show your theme’s background. This is fixed in Firefox 158.
Properties that changed or no longer work
Some theme properties behave differently in Nova. Your theme still loads if it uses them; they just have no visible effect, or style something different.
| Property | In Nova |
|---|---|
ntp_text |
No longer styles the new tab page search box |
popup_text |
No longer styles the address bar dropdown; other popups still use it |
sidebar_highlight |
No visible effect; the default highlight color is used |
sidebar_highlight_text |
No visible effect |
toolbar_bottom_separator |
Acts as a separator next to or below the toolbar and around the page |
The theme manifest reference on MDN is being updated with these changes.
Themes with background images
Themes using images are where you are most likely to see a difference. Your image can now show behind the sidebar and vertical tabs, and an image designed for a wide, short toolbar rarely looks good stretched or tiled down a vertical panel. In our testing of popular themes, the image themes that look off in the sidebar mostly did before Nova too. We did test a number of themes but we invite you to do your own testing. Nova makes the sidebar more visible, so the issues are easier to notice.
You can now choose where your images go with the backgrounds_area property, available from Firefox 156:
- “auto” (the default): Firefox decides from
additional_backgrounds_alignment. If any image is aligned to the vertical center or bottom, images stay in the top toolbars; otherwise they cover the whole window. - “window”: images cover the whole window, including behind the sidebar and vertical tabs.
- “top_toolbars”: images stay in the toolbars at the top of the window, and the sidebar uses your frame color.
If your image was made for the toolbar only, “top_toolbars” with a frame color that suits the image is usually the quickest fix.
Also set a toolbar color, even a semi-transparent one. Without it, notification bars that appear above the page sit directly on your image and can be hard to read.
New Gradient Support
Nova’s color themes use gradients, and you can too. The Nova theme manifests are the best working example; look at how they set colors for each surface, including the sidebar. backgrounds_area applies to gradients the same way it applies to images. Older versions of Firefox ignore color properties they don’t recognize, so your theme still loads there; if you use a feature older versions reject, set strict_min_version in your manifest.
Checklist: what to check in your theme
Install your theme in Firefox 157 and look at it in each of these states:
- Horizontal tabs and vertical tabs.
- Sidebar closed, open, and expanded on hover. Also toggle “Customize sidebar” while the sidebar is open or expanded.
- Compact density, if your users are likely to use it (under settings -> appearance density(.
- A private window.
- Light and dark system settings, since the accent follows the operating system.
- Hover over the buttons on the tab strip.
Then, if something looks off:
- Set
tab_selectedandtab_lineso the selected tab stands out without Firefox’s old shadow. - Set
sidebarandsidebar_textto colors that match your theme. - Use semi-transparent
button_background_hoverandbutton_background_activecolors. - Check that your tab bar and toolbar colors work together with vertical tabs enabled.
- For image themes, choose a
backgrounds_areaand set a toolbar color. - Remove or ignore properties that no longer have an effect.
- Publish an update on AMO so your users get the changes.
What we are still working on
Nova will evolve after launch. Firefox 158 ships on October 13 with the expand-on-hover sidebar fix. We are also working on these, with no release date yet:
- Focus and link colors that fit your theme instead of the fixed blue and cyan.
- A
popup_iconscolor for icons in menus and panels, separate from toolbar icons. - Theme colors for hover and selected states inside sidebar panels.
- Better hover states for tab strip buttons.
We will post again when these land.
For users who prefer the old look
Some of your users may miss Proton. From September 29, Mozilla is featuring a Firefox Proton theme in the Add-ons Manager for anyone who wants the previous look. It is a normal theme, so users can switch between it and yours at any time.
Resources
- Theme manifest reference on MDN: every color, image, and property, including
backgrounds_area. - Static themes on Extension Workshop : updated for Nova.
- Nova theme manifests: worked examples for gradients and sidebar colors; the themes themselves are on AMO, for example Nova Sun.
Questions?
We want your theme to look its best in Nova. If something looks wrong and the checklist does not fix it, tell us on Discourse and include a link to your theme and a screenshot. Those reports help us find the cases that need a Firefox fix rather than a theme change.
Thank you for making Firefox look like you and like your users.
The post Nova is here: what changes for your Firefox theme appeared first on Mozilla Add-ons Community Blog.
The Mozilla Blog
More modern. More flexible. Still Firefox.
What comes to mind when you think of Firefox? Is it our best-in-class privacy features and ad blocking capabilities? Our partnerships with Wrexham, NVIDIA or Mistral? Or maybe our adorable mascot Kit?
If you’ve been following Firefox this year, you’ve seen us add new ways to get things done while giving you more choice over how you browse. That includes browsing two pages side by side, adding an extra layer of privacy with built-in VPN, blocking trackers for smoother scrolling and faster load times, and deciding how AI shows up in Firefox.
For the past few months, many of you have also been trying out our new Firefox design in Nightly and sharing your thoughts with us as we continued to refine the experience.
Today, we’re rolling out that design with FX 157 to everyone using Firefox across desktop and mobile devices. Firefox has done a lot of growing over the last year; now it looks the part.
A more modern Firefox
When we first shared our plans to design Firefox for the future, we said we wanted Firefox to feel “current, but not generic. Warm, but still precise.”
That design ethos now carries across all of Firefox. We’ve refreshed the colors, icons and themes throughout the browser, from the tabs and toolbars you use every day to your New Tab page, Private Browsing experience and more, with no cost to your browser performance.
This shared design language across desktop and mobile gives Firefox a consistent foundation for new features and experiences, while keeping the personality that makes Firefox unique.
Make Firefox yours
We’ve added more choices for how Firefox looks and works, including the return of a feature many of you asked for:
Compact Mode is back. As people started trying the new design, we heard from many of you who wanted to fit more into your browser window. Compact Mode reduces the size of your tabs and toolbar to give more of your screen to the web, with an auto-compact option for smaller screens.
Find your look. A new theme picker makes it easier to explore different looks for Firefox, with new themes and wallpapers to choose from.
Set up New Tab your way. Choose what you want to see on your homepage. Now, you have a dedicated space to pin and organize shortcuts so sites you use all the time stay put.
Refined, not reinvented
Themes and wallpapers may change over time, but the things that made people choose Firefox in the first place are still the same. We’re still independent and open source, with privacy protections built into the browser and controls that put you in charge of how Firefox works for you.
This carries through everything we build, from the height of your toolbars and what belongs on your New Tab page to which AI features show up in your browser, which model you choose and what context you want it to have.
Today’s Firefox is a renewal, grounded in the same principles that have shaped it from the beginning, with a new design built to carry Firefox forward.
For those who have come with us on this journey, thank you for helping us shape the future of Firefox.
If you’ve been away on hiatus, welcome back. Try the latest Firefox and let us know what you think.
The post More modern. More flexible. Still Firefox. appeared first on The Mozilla Blog.
Mozilla Data YouTube Channel
GLAM Datasets
Mozilla Data YouTube Channel
Data Club Lightning Talk: Jan-Erik Rediger - Your personal Glean data pipeline
Mozilla Data YouTube Channel
Responsible Data Collection is Good, Actually (Ubisoft Data Summit 2021)
Firefox Nightly
Shoutout to More Layouts – These Weeks in Firefox: Issue 210
Highlights
- Rév O’Conner added a settings popup to control the layout of the Inspector. “Auto” automatically switches the layout at a given toolbox width.
- The new sidebar (sidebar.revamp) and switcher setting will be enabled by default for users along with Nova in DevEdition, Beta and Release channels. To ease the transition for old sidebar users, the “Open tools from sidebar” option will be unchecked for those users to more closely resemble the old sidebar experience. The migration won’t apply to users who had already tried the new sidebar and reverted back.
- The custom wallpaper library for the New Tab page is coming along! This allows you to save multiple images to your wallpaper folder, rather than replacing one image at a time. While it’s still in development, you can test it by setting
browser.newtabpage.activity-stream.newtabWallpapers.customWallpaper.library.enabledto true, starting in Firefox 157. - Mark added an MDN search engine for Nightly and Developer Edition. Select it from the menus, or type @mdn <search term>.
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- :Benjamin Peterson
- Amadi
- any1here
- Caleb Pickard
- Chris Vander Linden
- Gopalarathnam Venkatesan
- Igor [:ExplodingJoysticks]
- Khalid AlHaddad
- Lukáš Lipinský
- Mayank Bansal
- Nazeer Ahmed Shaikh
- Noah Varghese
- Sameem [:sameembaba]
- Sebastian Zartner [:sebo]
- sfshah
- Xiaosen Zhuang
New contributors (🌟 = first patch)
- Amadi:
- Caleb Pickard
- dchen705: Remove unnecessary module import in browser/components/urlbar/tests/browser/head.js
- Ekerin Agboola: Remove old documentation related to the removed SEARCH_SUGGESTIONS_LATENCY_MS histogram
- Igor [:ExplodingJoysticks]:
- Gopalarathnam Venkatesan:
- 🌟 Jieke Jiang: Remove unused AboutReaderParent._getArticle
- 🌟 Andrew: White flash on startup caused by abouthome_cache storing incompatible startup frame
- 🌟 Rév O’Conner: Inspector does not respect panel layout
- 🌟 Kana: browser_privatebrowsing_resetPBM.js awaits an array instead of Promise.all, so the tab-close wait does nothing
- Raúl: L10nCache.add() throws on an unknown Fluent ID instead of reporting it
- 🌟 Samuel Mbabhazi: Use new color syntax throughout the DevTools
- K: “Go to line” sets a cursor line which does not exist in footer location indicator
- sfshah:
- Nazeer Ahmed Shaikh
- Noah Varghese:
- Valerie Racine (:v-racine): Fix incorrect assertion message in browser_adoptTab_failure.js
- 🌟 Xiaosen Zhuang:
Project Updates
Add-ons / Web Extensions
Addon Manager & about:addons
- As part of Project Nova related work:
- Fixed responsive layout issues that caused horizontal scrolling in about:addons at high zoom levels – Bug 2059864
- Fixed the “Discover extensions” button appearing multiple times in about:addons – Bug 2070281
- Added telemetry for theme-picker shown events and for appearance/native-theme changes in about:addons – Bug 2069417 / Bug 2070341
- Added an accessible name to the themes mode control in about:addons, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2064563
- Thanks to Mark Kennedy for the help on fixing this accessibility gap
- Updated the built-in dark and light theme previews to use the nova style – Bug 2070274
- Thanks to Emilio Cobos Álvarez for the fix to the default light and dark theme previews.
- Fixed the Nova default and AMO curated theme previews to follow the OS light/dark mode while ignoring the Website appearance setting, fixed in Firefox 158 and uplifted to the Firefox 157 beta channel – Bug 2070562
- Stopped setting unused taarId session cookies for AMO on startup – Bug 1871561
- Thanks to Manuel Bucher for helping us to clean up these unused internals.
WebExtension APIs
- Fixed webRequest requestBody parsing so POST form fields named __proto__ are no longer dropped – Bug 2061470
- Changed alarms.clearAll() to resolve with undefined instead of a boolean, starting in Firefox 157 – Bug 2067229
- Thanks to Ollie Hensman-Crook for the fix to the alarms API.
- Implemented native messaging support via xdg-native-messaging-proxy for Flatpak and Snap builds – Bug 1955255
- Thanks to Jan Horak for the native messaging work on Linux packaging.
- As part of Florian Quèze effort to investigate and fix intermittent failures:
- Made windows.update() wait for the window to actually resize or move before resolving, fixing an intermittent Linux test failure – Bug 1307759
- Fixed a pageAction popup incorrectly opening via a commands API shortcut while the extension was already shutting down – Bug 2039637
- Fixed action.openPopup() rejecting when a tab hover preview was showing, a regression from Bug 2022281 in Firefox 150, with the fix shipping in Firefox 157 and no uplift planned – Bug 2062229
DevTools
- The team has a few sizable ongoing projects.
- Bomsy is working on moving Stylesheets to the Debugger so we can retire the (XUL-based) Style Editor, and turn the Debugger into a “Sources” panel (keeping all the existing functionality of course). (pref: devtools.debugger.features.stylesheets-in-debugger)
- Alex is investigating ways to better handle CSS authored text and CSSOM changes in the Inspector, building information directly from the Rust CSS engine, with the hope it will bring performance improvement editing styles in the Rules view.
- Nicolas is implementing a way to show to the user how the engine goes from a CSS declaration value to the computed value so it’s easier to follow what’s the result of the different call sites, or how the different units (em, %, vmin, …) are computed to their final (e.g. px) values. (pref: devtools.inspector.css-explainers)
External contributions
- Chris Vander Linden finalized a multi-months project to add a search toolbar in the Netmonitor Raw Response panel, adapting and reusing the component we are using in the Debugger (#1941575)
- Amadi made the “Open in new tab” context menu entry to open tab next to the selected tab, not at the very end of the tab list (#2059979)
- Mayank Bansal optimized the performance of console.clear() (#2068156, #2068157, #2067000)
- Benoit added JSON Lines (JSONL/NDJSON) support in the Netmonitor Response panel (#2059673)
- Gopalarathnam Venkatesan made the “Add class” button (.cls) to be disabled when a class can’t be added to the selected node (e.g. it’s a text node, or a comment, or the doctype node) (#2000150)
- K fixed an issue with the “Go to line” action in the Debugger (#2064575)
- Samuel Mbabhazi refactored our CSS codebase to use new color syntax (e.g. rgb(255 0 0) instead of rgb(255, 0, 0)) (#2054228)
- sfshah turned devtools/client/jsonview/converter-child.js into an ES class (#2004273)
Team/Project Update
- Florian Quèze [:florian] is working on fixing test flakiness in devtools/client/debugger and already landed an impressive stack of patches (#2001947, #2070917, #2070920, #2070932, #2070970, #2027953, #1932082, #2070923, #2070933, #1814093, #1868969, #2071238)
- that also includes fixing various accessibility issues that were spotted by a11y_checks #2070911, #2070955, #2071227, #2071231)
- Note that Julian Descottes [:jdescottes] also has an ongoing quest to reduce intermittent failures in our codebase and fixed a few those last 2 weeks (#1767707, 2069100, #2009386)
- [florian] 24 patches landed on Friday, you can see the impact on https://tests.firefox.dev/tests.html?path=devtools%2Fclient%2Fdebugger
- Nicolas Chevobbe [:nchevobbe] fixed a few issues spotted by Jake in the Inspector for the new-ish attr()CSS function (#2068479, #2068480, #2068483)
- Alexandre Poirot [:ochameau] fixed an OOM crash when viewing source mapped file for a large wasm module with many workers (#2058286)
- Julian Descottes [:jdescottes] improved performance of the Inspector when Devtools was opened on a page with many grid elements (#1988868)
- Hubert Boma Manilla (:bomsy) fixed an infinite loop in the Debugger search if you were searching for $ on a big JS file (#2068517)
WebDriver
- Sameem merged two internal helpers (remote/shared/Sync.sys.mjs and remote/marionette/sync.sys.mjs) which removed some code duplication.
- Khalid AlHaddad unified the navigation commands in Marionette and WebDriver BiDi to always initiate navigations via browsingContext.loadURI().
- Khalid AlHaddad updated the WebDriver BiDi client used by WebDriver tests so that browsing_context.locate_nodes returns the nodes array directly instead of the enclosing result object, matching the updated command response.
- Julian Descottes made the destinationFolder mandatory when calling the browser.setDownloadBehavior command with type=”allowed” – which aligns us with the specification. In order to restore the default behavior without having to specify a folder, clients should call setDownloadBehavior with null instead.
- Henrik Skupin fixed a bug in geckodriver where specifying androidIntentArguments in the capabilities caused the default intent arguments to be omitted.
Fluent
- According to arewefluentyet.com, ~74.77% of our strings are now using Fluent!
Lint, Docs and Workflow
- According to arewemozsrcyet.com, ~59% of our modules are now using moz-src.
- eslint-plugin-mozilla has switched from using Mocha to Jest for tests.
- Planning on future updates to investigate getting devtools & newtab to use the jest installed at the top-level, rather than separately installed copies.
Information Management/Sidebar
- We’re working away on bug fixes for sidebar, vertical tabs, split-view, and Nova
- Thanks Florian (:fqueze) for landing a set of patches that have markedly reduced test flakiness in the Sidebar component
New Tab Page
- Custom wallpaper library
- Dre added a “Your images” folder to the wallpaper picker on the New Tab Page, letting users save and switch between multiple custom wallpapers directly from the picker UI (desktop channels), which reduces friction for users who frequently change backgrounds.
- Dre implemented storage and migration for multiple custom wallpapers so users keep their existing wallpaper during upgrade while gaining the ability to save and switch multiple wallpapers — migration moves old single-wallpaper prefs into the new multi-wallpaper storage and the NTP now reads the wallpaper array at load/sync points.
- Dre updated New Tab Page strings to support multiple custom wallpapers so users now see accurate, localized labels and accessibility text when managing or switching between multiple custom backgrounds, reducing confusion in the UI during wallpaper selection.
- Dre added a delete affordance for saved custom wallpapers inside the New Tab Page picker so users can remove unwanted images from their saved set without going to profile files or prefs, improving manageability of user-provided wallpapers.
- We’ve completed a mass migration of our unit tests from Mocha (not mochi) / Karma to Jest/RTL, which is more modern and actively maintained.
- Sections is now enabled globally for all regions that show the content feed!
- Reem Hamoui fixed Lists widget so that keyboard users can now tab to completed items on the New Tab Page and see a visible selection/focus state
- Reem Hamoui fixed the Timer widget so that keyboard users can toggle focus vs break modes with standard keys (Enter/Space/arrow keys) thanks to restored keyboard handlers and tabindex semantics.
- Reem Hamoui made it so that screenreaders now announce wallpaper names via added aria-labels/alt text and role improvements in the Customize UI.
- Maxx Crawford made it so that the Customize UI now filters wallpapers by their metadata and no longer surfaces images marked hidden or in specific visibility groups.
- Irene Ni added Section Layout Name (String) telemetry to newtab content impression & click events so impressions/clicks now carry layout identifiers for more granular UX and A/B analysis
- Reem Hamoui added accessible names (aria-label/aria-labelledby) to the HNT Customize panel back buttons to fix screen-reader discoverability and keyboard/AT announcement when navigating the New Tab Customize flow.
- Nina Pypchenko [:nina-py] preserved iframe rendering for New Tab Page widgets during drag operations to prevent iframe-backed widgets from going blank while being moved.
- Nina Pypchenko [:nina-py] restored the Stocks widget dropdown and menu visibility under High Contrast Mode by adjusting contrast-aware CSS and ARIA roles so users relying on HCM can access stock controls again.
- Nina Pypchenko [:nina-py] fixed a results text overflow for long search queries in the Stocks widget by adding word-wrap/clamping to result lines, preventing layout breakage and truncated controls when users enter long symbols or queries.
- Nina Pypchenko [:nina-py] added telemetry for theme selection in the New Tab customization panel by emitting a selection ping on change, enabling measurement of user theme choices without changing UX.
- Irene Ni restored the Lists widget switcher checkmark for the selected list by fixing menu item selection-state rendering so users can again see which list is active in the switcher.
- Reem Hamoui updated the Privacy widget CTA and spacing on the New Tab Page, adjusting CSS/layout and CTA copy so the action is more discoverable and has a clearer tap/click target across responsive breakpoints.
- Reem Hamoui updated the zero-state copy for the New Tab Privacy widget to clarify what the widget does and the next steps for users when no privacy events or trackers are present, reducing confusion for first-time or cleared-state users.
- Maxx Crawford landed Fluent strings for the Nova launch New Tab customization callout, enabling localized text in the New Tab customization callout so users in supported locales see translated UI instead of missing-string fallbacks.
- Nina Pypchenko made the customization panel reset when closed, ensuring about:newtab customization state (temporary tile/layout previews) is cleared on close so users no longer see stale previews when reopening the panel.
- Dão Gottwald fixed New Tab to pick up system High Contrast Mode on Linux and macOS, restoring correct high-contrast colors/contrast on those platforms for users who rely on OS-level accessibility settings.
- Irene Ni restored theme matching for New Tab context menus by reapplying theme-aware CSS variables in the New Tab Page contextmenu styles, fixing mismatched colors for users with custom/light/dark themes.
- Dustin Whisman fixed New Tab section context menu button color regression by adjusting the section-contextmenu button style rules (button color variables and state selectors) so section actions now respect theme contrast.
- Irene Ni restored transparency to New Tab card backgrounds by removing opaque background rules so cards correctly display background images/themes and improve visual consistency across DPI/compositing setups.
Picture-in-Picture
- Thanks to Sebastian Zartner [:sebo] for fixing broken Dailymotion captions on the PiP player.
- kpatenio fixed YouTube’s displayed playback speed settings being out of sync with PiP.
- Reminder that the playback speed settings can be enabled with media.videocontrols.picture-in-picture.playback-speed.enabled.
- Thanks to Sylvestre Ledru [:Sylvestre] for helping fix a broken link in our PiP docs as a part of Bug 2071683.
Search and Urlbar
Address Bar
- Dao and Moritz are working on bringing the full urlbar experience into the newtab page, now enabled on nightly and going through polish and improvements.. (Bug 2068104, Bug 2068633, Bug 2069260, Bug 2064747)
- Drew enabled AMP and Wikipedia by default in AT, BE, CH, ES, IE, LU, NL, PL, PT and SE. (Bug 2066294)
- James gated adaptive autofill page results behind a minimum score threshold. (Bug 2066171)
- any1here stopped disabled Manage AI and Labs quick actions being displayed when disabled. (Bug 2070378)
Search
- Dale landed the Recent Searches widget which will be be used launched as an experiment (Bug 2063718)
- Caleb fixed the search box eating the first character typed into it. (Bug 1953361)
- Mark configured Wikipedia search for Sardinian (sc) to use the Sardinian Wikipedia rather than the Italian one. (Bug 2057690)
Places
- Marco fixed bookmarked Google Maps using Google’s default favicon. (Bug 1575809)
- Marco fixed the Downloads and History windows going full-screen instead of floating on macOS. (Bug 2058062)
Tests
- Dashboards:
- Most frequent oranges: https://tests.firefox.dev/intermittent.html#date=21days
- Folders with the most flaky tests: https://tests.firefox.dev/flaky.html?kind=mochitest#date=21days&view=list
- Issues of tests in a given folder: https://tests.firefox.dev/tests.html
- Eg devtools debugger tests shows progress of the recent effort to fix these tests recently
- Flakiness burn down
- Multi-agent Claude sessions running for hours investigating and fixing tests of a given set provided in the prompt. Still iterating on the process. Did this 3 times so far:
- Bug 2062142 – [meta] Fix the flakiness in browser/components/extensions/test/browser
- Top 20 intermittent mochitest bugs annotated by sheriffs.
- Probably what made the mochitest line go down for the first time on https://tests.firefox.dev/
- And what helped with the sidebar component, even though sidebar wasn’t my target.
- Bug 2070797 – [meta] Fix the flakiness in devtools/client/debugger/test/mochitest
- Multi-agent Claude sessions running for hours investigating and fixing tests of a given set provided in the prompt. Still iterating on the process. Did this 3 times so far:
- Profile your claude session for cost and context size: https://github.com/fqueze/claude-profiler
- To monitor cost during your sessions, try https://github.com/padenot/foxtail
Firefox Tooling Announcements
MozPhab 2.21.0 Released
Bugs resolved in Moz-Phab 2.21.0:
- bug 2068637 code review bot fails to apply patches when the parent is not known
- bug 2073291
moz-phab submitcould load reviewers and review groups in parallel with revisions and diffs - bug 2075401 “Phabricator Error: Validation errors” from
moz-phab submitshould display the revision
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
Mozilla Data YouTube Channel
Introducing Glean Annotations
The Mozilla Blog
Classic, Private, or Smart? Choose the right Firefox window for every task
We spend a lot of time browsing online. Whether you are researching for work, planning a trip, paying your bills, or scrolling through social media, your browser is there for it all.
While all these tasks are very different in nature, a lot of people still tend to stick to the same window type for all their use cases. But what if there was a different way to browse?
You may have noticed Firefox now has three window options for desktop. On top of the Classic and Private windows you’ve known for years, a third choice has been rolling out in beta: Smart Window. This optional AI-powered browsing experience is built to move your work forward and help finish what you started online.
Following the recent addition of several new Smart Window capabilities, we thought now would be the perfect time for a breakdown of what each of our three window options actually does, and when to use them.
Classic: Timeless and tailored to you
Classic Window is still the most customizable option of the three. While Private and Smart windows share many of the same features and capabilities as Classic, a Classic Window offers the widest range of Firefox’s standard personalization options. It gives you the broadest canvas for tailoring Firefox to the way you browse.
What makes it Classic:
- Full oversight over controls, buttons, and toolbars.
- Access to the entire Firefox add-ons library.
- Advanced customization and configuration options.
- The ability to sync your history, bookmarks, and open tabs across your signed-in devices.
When to use it:
Classic is your home base. It’s the best place to start customizing around your browsing needs, whether that means an extension setup specifically tailored to your workflow, a special theme that matches your style, or just the familiar Firefox experience you created over years of tweaking to your personal taste. While many customizations are also available on Private and Smart window, Classic offers the most extensive line-up of optional browser features, extensions, and aesthetics to personalize your setup.
Classic is the right move for general browsing like scrolling through social media, conducting a quick Google search, or reading online articles. It’s also the best place to start if you are looking to build your browser around you.
Private Window: Browse with greater peace of mind
Private Window stays true to its name and number one priority: it’s designed to limit the information associated with your browser session. When a Private Window is closed, Firefox doesn’t retain session information, such as what you searched for, the sites you visited, or the cookies they set.
What makes it Private:
- Pages visited from a Private Window will not be added to the list of sites in Firefox’s History menu, the Library window’s history list, nor the address bar drop-down list.
- Nothing entered into text boxes on web pages and Search bar will be saved for Form autocomplete.
- Cookies set in a Private Window are kept only temporarily in memory, separate from your regular cookies, and are discarded after your last Private Window is closed.
- Extensions are off by default in a Private Window, unless you explicitly grant them permission.
When to use it:
A Private Window is recommended when you don’t want activity from a browsing session sitting in your history, such as shopping for a gift. It’s also helpful when browsing on a shared device, ensuring your history, logins, and cookies will not be saved for the next person.
You may not need a Private Window every time you open your browser, but it’s always there for you when you do.
Smart Window: Firefox’s privacy-first, AI-powered browsing experience to help get stuff done
Smart Windowis Firefox’s newest window type, currently rolling out in Beta to users in the U.S., Canada, and France. Think of it as a Classic Firefox window with a built-in AI assistant layered on top – one that you can choose to have utilize your open tabs, recent browsing, and the page in front of you, so it can help you do more without switching contexts – all with the privacy and security you expect from Firefox.
What makes it Smart:
- A built-in assistant that can summarize pages, generate recommendations, compare information, and plan tasks using your open tabs.
- The ability to retrieve current web information and display the sources behind its response without taking you to a separate search results page, supported by Firefox’s new partnership with Exa.
- Suggested groups for related tabs.
- Visual previews of pages from your browsing history, so you can surface the page you’re looking for more easily among similar results without opening each one.
- The choice of three AI models to power the assistant, as well as the option to bring your own model.
- Optional “memories,” built from either your Smart Window chats or your browsing activity in both Smart and Classic windows, or both. Memories help the assistant give you more helpful, personalized answers over time. They are stored locally on your device and can be deleted at any time.
When to use it:
Smart Window shines when you need a little extra help finishing what you started. Its ability to work with the context you choose to share can help you make progress on ongoing tasks that may require more than one session, like trip or event planning, comparison price shopping, or conducting research for work or personal reasons.
And with Smart Window’s optional memories, which learn your patterns and preferences over time (with your permission), Smart Window gets more useful the more you use it, keeping you from having to spell everything out from scratch each time.
Selecting the right window for the job
None of these windows is “better” than the others, they’re built for different moments.
The good news is you are never locked into one. Firefox lets you move between all three depending on what you’re doing, so you can choose the window that fits each task.
You can access Classic and Private windows at any time from the Firefox menu. As for Smart Window, it remains in beta, with current availability to people in the U.S., Canada, and France.
To try Smart Window, visit https://www.firefox.com/smart-window. Or, if it’s not available in your region yet, you can sign up to be notified when it is.
The post Classic, Private, or Smart? Choose the right Firefox window for every task appeared first on The Mozilla Blog.
Mozilla Data YouTube Channel
Towards a Telemetry Taxonomy
Mozilla Data YouTube Channel
Data Club: Jeff Silverman - Data Science & Astronomy: AAS 243 & ATDS 6
Mozilla Data YouTube Channel
Outreachy Mentorship: A Retrospective
Thunderbird Blog
Thunderbird Monthly Development Digest: September 2026
Greetings once more from the Thunderbird development team!
As the Northern hemisphere summer comes to an end and a slew of PTO, company holidays and projects have wrapped up, what better time to share progress and next steps on the work the Thunderbird Desktop Engineering team has on their plates!?
Exchange support moving well
The powerhouse Exchange engineering team had some great momentum over the summer and completed their work on implementation of the Graph protocol to support email accounts – well in advance of their deadline. They have since moved on to start work to support Exchange calendars using the Graph protocol which is a significant milestone given that our calendar code hasn’t had significant changes for some time.
While some team members are now juggling multiple projects, good progress has been made to wrestle the foundations into place, with calendar discovery and persistence in place, along with display of calendar items. Following a brief hiatus to focus on other priorities, the team is once again back into gear.
Keep track of our Graph API Calendar implementation here.
Account Setup & Authentication
Since I last wrote, many of the account setup and account authentication improvements have landed (mostly in versions 156 & 157), unlocking some important security use cases which are becoming more frequently requested and mandated by organizations and legislation around the world.
While diving into the code is an enjoyable adventure, the newly-minted articles devoted to the topic of Oauth customization might be a better starting point for most:
Knowledge Base – Custom OAuth for Thunderbird
UI overhauls – why just one?!
The front end engineering team has completed the rebuild of our account setup manual configuration flows to include new protocol options and security customizations, so it is time to pick up where we left off on our Calendar UI rebuild.
The majority of the front end team is now either focused on Calendar Event data write operations stemming from the Event Read dialog (delete event, RSVPs, Reminders) – or beginning the largest part of the journey, which is the implementation of a new Calendar Create/Edit dialog, along with REDUX-based state management, a new WYSIWYG editor and more reusable components such as date pickers.
Follow the Calendar Event Create/Edit work here
While that work is underway, why not weave in some more improvements?!
After some extensive user research and testing, our design team has begun work to improve the Settings UI, starting with some updates to humanize and homogenize the various options, headings and guidance provided in that area of the application.
Read more about that journey here
Contributions are on the rise! Some AI guidance…
In the past few months, we’ve seen a wonderful increase in contributions from community members – partially thanks to our move away from Mercurial to a more familiar Git-based workflow – and partially thanks to many LLMs doing a great job of interpreting our public codebase and making it far more accessible. Or it could be that our team is just such a friendly bunch that we’ve attracted a great group of people willing to support.
Whatever the reason, we’re happy to see new names. faces and ideas in our chats and review queue!!
Having said that…We’ve reached the point where the velocity of work is beginning to pile up and clog our review queue – so I felt it might be time to share some guidance to make the process easier for both external contributors and the internal review team. Bear in mind that while we use AI workflows in several areas, our goal is to preserve a codebase which can be maintained by humans. We’re working on a policy that may word some of these points better, but from the past few months of my experience here’s what I see as being helpful:
- Keep patches to a digestible size and understandable complexity – Contributions should save more development time than it takes to review. If the patch contribution creates heavy work for maintainers, it will be deprioritized – so the best approach is to break the work up into pieces that can be understood more easily and discussed together. Bear in mind that many cloud-based models aren’t primarily designed to be frugal with token usage so it’s easy for patches to grow (much) larger than they actually need to be to solve the problem. Be specific with prompts to minimize the surface area of changes so they are reviewable.
- Humanize or write comments (within code and throughout the code review process) by hand – While we’ve become accustomed to interacting with a variety of automated systems in our daily lives, a good chunk of the joy involved in our work is to share knowledge with each other and refine the code so that it can be reused and understood by humans.
- Be wary of license infringement – much of our work is under the MPL license and we must all take care not to introduce refactored code that originally came from licensed software which can be rewritten and translated using LLM, then relabelled under our licence.
- Be transparent – it will often help to share prompts and your model when submitting code for review. Refining all aspects of our workflow is important, and we can all benefit from a collective evolution of skills and prompts that improve over time with input from the team and community.
- We encourage contact with a member of the team to discuss approach and architecture in advance of spending time and tokens on a patch. Some areas of the codebase are already slated for redevelopment and it’s not always obvious what is underway and planned. Having a quick conversation to say “Hey, I’m thinking about working on this” is a great start to landing something that spends less time in review and uses less tokens, energy & the world’s natural resources.
- Of course if none of these guidelines are followed, we’ll still be very happy to receive help from the wider community – the process may just take longer and be a bit less pleasant.
Enterprise
As parts of the world turn their infrastructure priorities toward digital sovereignty, we’ve seen an increase in interest from governments, institutions and organizations around the world who are looking to either improve their existing FOSS-based infrastructure or deploy for the first time. That has resulted in some focused efforts throughout Q3 to improve our Enterprise security and policy framework to bring it in line with the strides that the Firefox engineering team has made, and also roll out more Thunderbird-specific administrative mechanisms that allow granular control over end user configurations. Read more about your options and follow the work below:
Thunderbird Enterprise Policies and Relevant Preferences
Thunderbird Enterprise PoC Work Items
Maintenance, Upstream adaptations, Recent Features and Fixes
Waves of changes from upstream Firefox have continually kept the team on their toes throughout July & August, but the small but mighty gang have kept Daily builds largely intact each day. In addition, the team and contributor community have continued landing a series of reliability, stability, and usability improvements across the application. Recent highlights include:
- Nico has a series of calendar improvements in the works with several now cleared for landing: D319397, D320418, D320419
- Hurtmut has again come to the rescue with a number of patches but most recently solved a widespread filtering problem introduced upstream which will need to be uplifted as a matter of urgency.
- Richard pushed many patches since my last update, many related to upstream changes required after the Firefox project “Nova” was unleashed. He’s also been on the lookout for other breaking changes such as XUL attribute modifications.
- Max was on fire and in constant comms with the team to deliver a large number of important changes but also helped to refine some of our processes relating to AI-driven workflows. Recently, he led an investigation into growing concerns over instability with connections with Gmail accounts in Bug 2028760.
- and many more which are listed in release notes for beta.
If you would like to see new features as they land, and help us find some early bugs, you can try running daily and check the pushlog to see what has recently landed. This assistance is immensely helpful for catching problems early.
—
Toby Pilling
Senior Manager, Desktop Engineering
The post Thunderbird Monthly Development Digest: September 2026 appeared first on The Thunderbird Blog.
Firefox Tooling Announcements
MozPhab 2.20.0 Released
Bugs resolved in Moz-Phab 2.20.0:
- bug 2066178 Drop support for Python 3.9
- bug 2068605 preserve file logging from moz-phab list --format json and moz-phab patch --raw
- bug 2071586 Review queue reminders should ignore group reviews (at least optionally)
- bug 2073088
moz-phab submitis getting the file size from hg/git even if it could infer it from the blob itself - bug 2074036 List index out of range
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
This Week In Rust
This Week in Rust 670
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Official
- Be alert: targeted attacks on prominent Rustaceans
- GitHub Actions leaking secrets when Miri output is cached
- Maintainer spotlight: Alejandra González (@blyxyas)
- Announcing a Maintainer in Residence: Scott Schafer for the Cargo team
Foundation
Project/Tooling Updates
- Fearless SIMD v1.0 is here
- Syncing Rust GCC backend or how to test Murphy's law
- Benchmarking Wild vs Mold
Observations/Thoughts
Rust Walkthroughs
- [video] Understanding Rust Ownership by Building a Zero-Copy Log Line Parser
- Finding Bugs
- Why datadiff matches arrays by key instead of computing tree edit distance
- [video] RustCurious lesson 10: Three Ways to Fix Any Borrowing Error
- Solving for faster SHA-1 collision detection
- Small and secure Docker images for Rust: Alpine vs Debian vs Scratch
Crate of the Week
This week's crate is fastlogging-rs, a fast logger which supports 8 different programming languages.
Thanks to brmmm3 for the self-suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a
call-for-testing label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Cargo, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
RFCs
Rust
Rustup
If you are a feature implementer and would like your RFC to appear on the above list, add the new call-for-testing
label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature
need testing.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- sysknife - A successful automatic rollback renders to the operator as unknown
- sysknife - sysknife-setup --uninstall deletes .mcp.json whole, taking every other MCP server with it
- sysknife - audit export publishes request_hash, an unsalted hash over unredacted params, with no statement of its sensitivity
- Apache Iggy - Python SDK: expose consumer shutdown and offset drain timeout
- Apache Iggy - Python SDK: expose client disconnect and shutdown lifecycle methods
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
618 pull requests were merged in the last week
Compiler
- A couple polonius constraints perf improvements
- AST lowering cleanups
- an assortment of polonius tweaks
- check
tainted_by_errorin LateLint - even more cleanups for
rustc_builtin_macros - perf: keep the first macro syntax-context mapping inline
- suggest fully qualified path on method name collision
Library
- add
Dir::try_clone - add case mapping fast paths for Latin-1
- complex conjugate, negation and default
- constify comparison traits on sliced types
- implement const Iterator for Range
- stabilize
CommandExt::show_window - stabilize
feature(trim_prefix_suffix)({str,[T],Path}::trim_prefixand {str,[T]}::trim_suffix) - stabilize
windows_process_extensions_main_thread_handle
Cargo
build-rs: makeunstablecompile- account for (uplift) hardlinks when calculating clean file size
- fix: return correct package specs when resolving workspace deps
- remove -Zasymmetric-token / cargo:paseto
- report the number of errors with
build.warnings='deny'
Rustdoc
- Correctly handle
dyntrait methods linking for jump to def feature - Correctly handle intra-doc links on inlined same item with different names
Clippy
- add
must_use_without_reasonlint - fix
const_trait_implrelated infinite loop inneedless_borrows_for_generic_args - generalize
extend_with_draintoVecDequeandBinaryHeap - lint
suboptimal_flopsformul_add,custom_absandradiansin const context - lint nested
format_args!for uninlined args
Rust-Analyzer
- prioritise required items in trait autocomplete
- support completions inside
cfg!() - support hover on cfg predicate
- complete cfg value in string
- correct order deprecated const in builtin ty
- not complete attr args when before exists args
- watch include roots recursively once, not every directory
Rust Compiler Performance Triage
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
- No RFCs were approved this week.
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- Types FCP v2: Supertrait item shadowing stabilization
- declare C and C-unwind as mutually ABI-compatible
- Distinguish
repr(C)ZSTs from others in ABI compatibility rules - Implement Default for NumBuffer
- rustc: Stabilize the WebAssembly
wide-arithmeticfeature - Allow elided ('static) lifetimes in
thread_local! - Stabilize
mem::conjure_zst - Prevent mutating the global environment pointer in
CommandExt::execand opt to use execve and resolve path manually - Stabilize
debug_closure_helpers - Additional NonZero conversions
- Stabilize
funnel_shifts(includingconst) - Stabilize
Result::into_{ok,err} - windows: stabilise inherit_handles
- OUT_DIR is also set when running the program
- feat(config): Add build.profile, install.profile
- fix(git)!: Default to net.git-fetch-with-cli if git is present
- Formulate a
trusted-contributorsmarker team - Participation in Outreachy Dec 2026 (dedication of funds)
No Items entered Final Comment Period this week for Rust RFCs, Language Team, Language Reference or Unsafe Code Guidelines. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
- No New or Updated RFCs were created this week.
Upcoming Events
Rusty Events between 2026-09-23 - 2026-10-21 🦀
Virtual
- 2026-09-24 | Virtual (Berlin, DE) | Rust Berlin
- 2026-09-24 | Virtual (Charlottesville, VA, US) | Charlottesville Rust Meetup
- 2026-09-29 | Virtual (London, UK) | Women in Rust
- 2026-09-30 | Virtual (Cardiff, UK) | Rust and C++ Cardiff
- 2026-10-02 | Virtual | Rust Girona
- 2026-10-04 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-06 | Virtual (London, UK) | Women in Rust
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
- 2026-10-08 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-08 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-10-10 | Virtual (Gdansk, PL) | Stacja IT Trójmiasto
- 2026-10-13 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-18 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-20 | Virtual (Washington, DC, US) | Rust DC
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
Asia
- 2026-09-23 | Maharashtra, IN | Rust Pune
Europe
- 2026-09-24 | Aarhus, DK | Rust Aarhus
- 2026-09-24 | Amsterdam, NL | Rust Developers Amsterdam Group
- 2026-09-24 | Frankfurt, DE | Rust Rhein-Main
- 2026-09-24 | London, UK | Rust London User Group
- 2026-09-25 | Edinburgh, UK | Rust and Friends
- 2026-09-26 | Stockholm, SE | Stockholm Rust
- 2026-09-28 | Augsburg, DE | Rust Meetup Augsburg
- 2026-09-29 | Manchester, UK | Rust Manchester
- 2026-09-29 | Milano, IT | Rust Language Milan
- 2026-09-30 | Basel, CH | Rust Basel
- 2026-09-30 | Berlin, DE | Rust Berlin
- 2026-10-05 | München, DE | Rust Munich
- 2026-10-08 | Oslo, NO | Rust Oslo
- 2026-10-10 | Geneva, CH | Rust Geneva
- 2026-10-14 | Barcelona, ES | BcnRust
- 2026-10-14 - 2026-10-17 | Hybrid (Barcelona, ES) | EuroRust
- 2026-10-20 | Leipzig, DE | Rust - Modern Systems Programming in Leipzig
North America
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-24 | Atlanta, GA, US | Rust Atlanta
- 2026-09-26 | Boston, MA, US | Boston Rust Meetup
- 2026-10-01 | Saint Louis, MO, US | STL Rust
- 2026-10-03 | Boston, MA, US | Boston Rust Meetup
- 2026-10-08 | San Diego, CA, US | San Diego Rust
- 2026-10-10 | Boston, MA, US | Boston Rust Meetup
- 2026-10-14 | Los Angeles, CA, US | Rust Los Angeles
- 2026-10-20 | San Francisco, CA, US | San Francisco Rust Study Group
- 2026-10-21 | Hybrid (Vancouver, CA) | Vancouver Rust
Oceania
- 2026-09-29 | Barton, AU | Canberra Rust User Group
South America
- 2026-10-08 | Buenos Aires, AR | Rust en Español
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
operational pedantics
Thanks to Jules Bertholet for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
Firefox Tooling Announcements
Happy BMO Push Day! (20260922.1)
The following changes have been pushed to bugzilla.mozilla.org:
Thanks to Kohei for his work on the newly revised Guided Bug Entry form! If you want to check it out yourself, then click on the Switch to Bugzilla Helper link at the bottom of the enter bug product selection page. Normally users without canconfirm permissions will see the Guided Bug page by default which a large percentage of our Bugzilla users.
- Bug 1995464 - Overhaul guided bug entry form
- Bug 2002553 - BMO rest api search: Failed to fetch key from network storage when an attachment has been deleted
Discuss these changes in the BMO Matrix Room
1 post - 1 participant
Firefox Tooling Announcements
Firefox Profiler Deployment (September 22, 2026)
The latest version of the Firefox Profiler is now live! Check out the full changelog below to see what’s changed:
Highlights:
- [fatadel] Show a category breakdown in profiler-cli (#6256)
- [fatadel] Show allocation data in the cli (#6246)
- [Florian Quèze] profiler-cli: add a thread list command (#6273)
- [Florian Quèze] profiler-cli: add a thread list command (#6273)
- [Nazım Can Altınova] Add a permalink command to profiler-cli for already published profiles (#6331)
- [Florian Quèze] profiler-cli: add profile markers for cross-thread marker search (#6276)
- [Nazım Can Altınova] Add
--with-samplyto “profiler-cli load” (#6339)
Other Changes:
- [Florian Quèze] profiler-cli: name the process in the thread banner, and follow the queried thread (#6269)
- [fatadel] Drive PII sanitization from marker schemas (#6291)
- [fatadel] Move FileIO table labels into marker schemas (#6296)
- [Markus Stange] Add missing finishRawMarkerTableBuilder. (#6318)
- [fatadel] Fix the upload error button contrast (#6315)
- [Markus Stange] Allow typed arrays in the nativeSymbols table (#6300)
- [Markus Stange] Remove brittle test. (#6322)
- [Markus Stange] Fix file extension typo. (#6325)
- [Markus Stange] Typed arrays + flags for the FuncTable (#6323)
- [fatadel] Convert extension text markers to structured payloads (#6314)
- [Florian Quèze] profiler-cli: include per-marker fields and data in --list --json (#6275)
- [Markus Stange] Speed up call tree sidebar by sharing work with the activity graph (#6329)
- [Nazım Can Altınova]
Sync: l10n → main (Sept 22, 2026) (#6341) - [Nazım Can Altınova] Bump profiler-cli version to 0.10.0 (#6342)
Big thanks to our amazing localizers for making this release possible:
- el: Jim Spentzos
- ro: robbp
Find out more about the Firefox Profiler on profiler.firefox.com! If you have any questions, join the discussion on our Matrix channel!
1 post - 1 participant
Firefox Tooling Announcements
Firefox DevTools MCP 0.10.4 released
Firefox DevTools MCP (firefox-devtools-mcp) 0.10.4 is out on npm.
Changes
This release only contains additional hooks and configuration files to register Firefox DevTools MCP on various third-party aggregators, as well as a new task to automatically register the mcp on https://registry.modelcontextprotocol.io/ on release.
Full changelog: Release v0.10.4 · mozilla/firefox-devtools-mcp · GitHub
Repository and issues: GitHub - mozilla/firefox-devtools-mcp: Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi · GitHub
Public chatroom: https://chat.mozilla.org/#/room/#firefox-devtools-mcp:mozilla.org
1 post - 1 participant
Mozilla Data YouTube Channel
Data Club: Jan-Erik Rediger - Little Bobby Tables - from metrics.yaml to data-filled columns
Mozilla Data YouTube Channel
Data Club Talk: Jan-Erik Rediger - The Glean UniFFI migration and how no one noticed
The Rust Programming Language Blog
Announcing a Maintainer in Residence: Scott Schafer for the Cargo team
At the end of August, we announced our first Maintainers in Residence, Rust Project contributors who are funded for their upstream contributions and maintenance work from the Rust Foundation Maintainers Fund (RFMF). Since then, the Rust Leadership Council has dedicated more funds from its Project Priorities budget to RFMF, and together with AWS also providing additional funds, this allowed us to open a new full-time Maintainer in Residence (MiR) position to support the Cargo team. We would like to thank the Rust Leadership Council, AWS, and also the Rust Foundation for providing us with this opportunity! If you would like to help us hire more maintainers to improve Rust, consider donating to RFMF.
This post explains why we chose to support the Cargo team specifically, and introduces Scott Schafer, the new Cargo Maintainer in Residence.
Why Cargo?
The new MiR full-time position is dedicated to helping with the maintenance of Cargo, our build system and package manager. The Cargo project is deeply involved in many new Rust features, improvements, and Project Goals. Combined with its cross-cutting nature, where it has to support many different use-cases and integrate with several other tools, it takes a lot of work just to keep up with its maintenance needs, let alone support so many feature requests and proposed changes.
Because of that, the Cargo team has sometimes struggled with meeting its maintenance demands. You might remember that for several years, it actually held a feature freeze, to reduce Cargo's internal tech debt, perform necessary refactorings, go through the issue and pull request backlog, and come up with scalable internal development and design processes, so that they could eventually go back to even thinking about adding new features.
Recently, some changes occurred within the team, which made it more difficult for them to meet their maintenance baseline. Some members of the team left, while others lost their dedicated funding for working on Cargo maintenance and had to scale down their involvement. The Funding team thus considered it very important to support this team, given that we had an opportunity to do so. And thus we decided to hire a full-time maintainer to work on Cargo for (at least) the next 12 months.
Even though we know that a single full-time maintainer will not completely solve the maintenance struggles of the Cargo team, we hope that it will improve the situation, and provide a bit of a relief for the team.
Introducing Scott Schafer
We are very happy to welcome Scott Schafer (@muscraft) into the Maintainer in Residence role! Scott has joined the Cargo team three years ago, and apart from working on Cargo, he is also the lead of the Rust Docker team, which prepares official Docker images for every Rust version.
Apart from working on general maintenance of Cargo, Scott has implemented Cargo's Workspace inheritance feature, and has also spearheaded a complex multi-year effort to switch the rendering of diagnostics in the Rust compiler to use the annotate-snippets crate. This effort has been completed in the Rust 1.93.0 release. Thanks to it, the same diagnostics interface can now be shared between the compiler and Cargo (and also other tools), which amongst other things unblocked further development of the Cargo linting system, which has now been stabilized and will ship in the Rust 1.100.0 release.
Everyone we talked about was very excited about Scott becoming a Cargo Maintainer in Residence, and we share that feeling. We wish Scott all the best in his new role, and we are very happy that we can support his maintenance work.
Here is what Scott thinks about it:
I am incredibly excited to work on Cargo full-time! There have been so many things that I wish I could've worked on over the years, that I will now be able to get to. I hope that my efforts will bring Cargo into a more maintainable state.
Conclusion
We are incredibly happy that we keep getting more funds for the Rust Foundation Maintainers Fund, which allows us to support Rust Project contributors. The funding team will be working with the supported maintainers, and also the funders, to ensure that they are all happy with the arrangement, so that we can secure stable funding for Rust maintenance for years to come.
If you would like to help us support more Rust maintainers, consider donating to RFMF!
The Mozilla Blog
Stay focused wherever you work with Firefox mobile browsers
When it’s Monday morning and you’re on the subway, in a coffee shop, or squeezing in a few email replies after your morning workout, your phone becomes your digital office. But every time you open your browser, you risk getting struck with any combination of distracting ads, auto-playing videos, and open tabs from the previous week competing for your attention.
For many remote and on-the-go workers, your mobile browser can become a minefield of interruptions and distractions, slowing you down when you need to focus most.
Luckily, there are multiple Firefox features that can help ensure your mobile browser is a focused, productive workspace.
Reduce distractions and clutter with Ad Blocker for Firefox on iOS
Opening a link shared via text or email can save time and keep things moving when a client or coworker needs a fast response. However, once it’s actually opened, there is a lot of opportunity for various pop-ups, overlays, and ads to get in between you and what you came in to do.
Ad Blocker for Firefox on iOS was built to reduce distractions and screen clutter while you browse, so you can stay focused on the task at hand. It’s a built-in, optional feature that blocks many intrusive ad formats, third-party ad networks, and ad-related trackers. That means no separate extension required, and you decide if and when to use it.
Because Firefox’s strong line-up of ad-blocking and privacy extensions on desktop and Android are not available in the same way on iOS, we built Ad Blocker for Firefox directly into the browser. To decide what gets blocked, Ad Blocker uses the EasyList filter and Apple’s WebKit Content Blocker technology. It won’t impact every ad or sponsored content on a new tab, as those presented directly by host sites and displayed in search results will still be visible.
To try Ad Blocker on iOS, go to Settings > Browsing > Ad Blocker and turn it on to enjoy a cleaner browsing experience.
Get the gist faster with Shake to Summarize
When you’re on a deadline, scanning through heavy text, ads, and filler content can turn a quick scan into an infinite scroll session.
Firefox’s Shake to Summarize feature helps people get the gist in seconds on both iOS and Android. To use it, simply shake your phone on any web page under 5,000 words, and a clean summary of the page’s content will instantly appear. It can also be activated by tapping the “Summarize Page” option under “More” in the three-dot menu.
Like all Firefox features, we built Shake to Summarize with your privacy and protection in mind. This means using device-specific technology to keep your data secure. You can learn more about the AI powering this feature here.
The feature launched on iOS last September, received a strong response from users, and earned a special mention in TIME’s Best Inventions of 2025. It is now available on iOS and Android in English, German, French, Spanish, Portuguese, Italian, and Japanese.
Keep your tabs tidy with Tab Groups on Android
Just like us, our smartphones tend to live multiple lives: work, personal, and everything in between. While it can be incredibly convenient to have everything you need for all parts of your life on one device, things can get cluttered fast.
One minute you are knee-deep in a client proposal and the next you’re flicking through the countless Google searches from over the weekend. “How old is Harry Styles?” and “Movie times near me” – while pertinent when you were off the clock 24 hours ago – have absolutely nothing to do with the work you are trying to get done now.
To help make sure your prep for Thursday’s client meeting doesn’t get lost in your pop music deep dive from the weekend, you can group related tabs in Firefox for Android. Each group can be labeled and assigned a color, appearing as a single, searchable card in the tab tray rather than separate tabs, so it’s easy to locate when needed. You can open, rename, recolor, and delete these cards whenever you want.
To use Tab Groups on Android, simply drag one tab onto another, or select a few and tap “Add to group.” Label the group, choose a color, and you’re all set. To try it out, download the latest version of Firefox for Android. iOS support for this feature is on the way.
Pick up where you left off across devices with Firefox Sync
Sometimes we start a task on one device and finish it on another. Maybe you found an article on your computer that you want to read on the subway on your phone. Or, perhaps you want to pull out your laptop and finish filling out that lease application you started on your tablet.
Enable Firefox Sync and you can resume tasks you paused in your browser when switching across your mobile phone, tablet, and laptop. The feature lets you access your open tabs, bookmarks, and passwords across all the devices you access Firefox on.
The best part? We put your data privacy first. Firefox Sync uses end-to-end encryption so your synced data is encrypted before it reaches Mozilla’s servers.
To take your browsing experience with you wherever you go, connect your iOS or Android phone to your Mozilla account and start syncing with your other devices.
Take back control of your focus with Firefox
For remote and on-the-go workers, focus is everything.
With Firefox features like built-in ad blocking on iOS, Shake to Summarize for instant insights, and Tab Groups on Android to keep your work and personal digital spaces organized, you can transform your phone from a distraction hub into a productive workspace.
Download the latest version of Firefox for Android or Firefox for iOS today to test out any of the above features available on your device – and take back control of your attention.
The post Stay focused wherever you work with Firefox mobile browsers appeared first on The Mozilla Blog.
The Rust Programming Language Blog
GitHub Actions leaking secrets when Miri output is cached
The Rust Security Response Team was notified that Miri stores all environment variables to target/, allowing secrets to persist in caches.
While not necessary a vulnerability in and of itself, when paired with GitHub Actions caching behavior, it is possible for this to expose secrets to PRs.
Overview
GitHub Actions makes it possible to cache directories between runs. Typical setups allow CI runs on main (and other branches) to write to cache, and PRs can only read from cache (preventing cache poisoning). Rust projects tend to speed up CI by caching binaries built by cargo install and sometimes the contents of target/.
PR CI can be triggered by anyone who can open PRs on your repository. GitHub requires maintainer approval for the first PR, but future PRs will rerun CI on every push. Anyone who has previously landed a change can trigger a CI run extracting information from cached target/ and then cover their tracks by pushing a second commit to the PR.
GitHub sometimes hides overwritten commits in its UI, making this kind of attack harder to detect. CI run logs and overwritten commits are also deleted after a few months.
When cargo miri is invoked, Miri needs to retain build-relevant environment variables between runs1. The current code to do so achieves this by storing all environment variables to target/. This, of course, persists when target/ is cached.
If your environment contained secrets, these can now be accessed by PRs via the cache.
Our fix
Our short term fix for this is to make Miri only preserve CARGO_* environment variables (excepting CARGO_*_TOKEN) and OUT_DIR. In the longer term, Miri and cargo may figure out better ways to inform Miri of the relevant list of environment variables. Note that this patch may not be available on nightly yet.
We also performed an ecosystem scan of GitHub repositories and identified 1 repository with this issue and 7 repositories that do not appear to be vulnerable but should be cautious anyway. We have reached out to those maintainers.
Am I affected?
It is likely that our scan was imperfect, so we recommend you check your own GitHub Actions setups if you run Miri.
You are vulnerable if:
- You run
cargo miriin CI - The step that runs
cargo mirihas access to secrets as an environment variable:- By being passed in to the step itself as an environment variable
- By being set in
envfor the workflow - By being passed in to a previous step that persists it in the environment somehow
- The workflow being used caches the
targetdirectory, usually done viaactions/cacheorswatinem/rust-cache - The cache is accessible to PRs (common and often the intended use case)
Possible quick fixes include:
- Disabling cache for that job.
- Scoping secrets to steps in that job that do not call Miri.
- Temporarily disabling Miri.
Once done, please clear the cache. Consider rotating any secrets that might have leaked.
The Miri release in the upcoming nightly (2026-09-22) will no longer have this problem.
Even if you do not run Miri, ensure jobs that can write to public caches do not have access to secrets. Many tools do not have special handling for secrets, and assume the entire environment can be written to the filesystem.
Threat model
We consider it bad practice to have a cache that can easily be tainted by secrets.
If caching target/, it is worth making sure that the inputs to processes that create target/ (anything invoking cargo) do not have secrets available. It is generally rare for standard cargo build/test subcommands to need any secrets or tokens2, so this is mostly a matter of being careful about having secrets exposed as environment variables to the entire job.
Cargo/Miri/Rust does not guarantee that environment variables will be safe from being copied into target/. While we are treating this as a security issue and patching it out of an abundance of caution, this is not something you should rely on in general. Beyond official Rust tooling, it is possible for build scripts to be doing things that lead to the environment being stored in compilation artifacts.
Acknowledgements
Thanks to Predrag Gruevski of OpenAI for reporting this issue to us. Furthermore, the ecosystem scan was performed using Codex access and credits donated by OpenAI, which we also thank them for.
Issue triage and remediation was performed by Manish Goregaokar, Ralf Jung, Ben Kimock, Weihang Lo, Jacob Finkelman, Walter Pearce, Josh Stone, and Mark Rousskov.
Firefox Tooling Announcements
Firefox DevTools MCP 0.10.3 released
Firefox DevTools MCP (firefox-devtools-mcp) 0.10.3 is out on npm.
New features:
- New tool:
close_firefox_session— ends the browser session: it releases the connection when the server is attached to an existing Firefox, and closes the browser when the server started it. - New parameter:
fullPageforscreenshot_page— captures the whole scrollable document instead of the viewport. - New parameter:
downloadFolderforset_download_behavior— only used when setting the “allowed” behavior, it sets the folder where downloads should be stored and defaults to~/.firefox-devtools-mcp/output/downloads.
Bug fixes:
- No longer fails to find the Firefox binary on Linux with Flatpak.
restart_firefoxnow rejects when used against a server started with--connectExisting, whereas it used to restart the WebDriver session without restarting the browser and silently ignored all its configuration parameters.
Other changes:
- Servers started with
--connectExistingnow disconnect after 30 minutes without any tool call. restart_firefoxis now part of the mozilla-internal package, and should only be used in controlled environments, as it allows the agent to restart the browser with a custom configuration. Instead, the new toolclose_firefox_sessioncan be used whenever clients do not need to update the browser configuration, and will have a more consistent behavior.- Path checks for the
saveToparameters have been improved to avoid overlapping with existing profile folders
Install:
claude mcp add firefox-devtools npx @mozillamozilla/firefox-devtools-mcp@latest
codex mcp add firefox-devtools – npx @mozilla/firefox-devtools-mcp@latest
For internal Firefox development, swap firefox-devtools-mcp with firefox-devtools-mcp-moz in order to benefit from additional tools, such as chrome-privileged script execution.
Special thanks to all the contributors who filed issues and submitted patches for this release: f3tch (github), shoemoney and mightykatun.
Full changelog: Release v0.10.3 · mozilla/firefox-devtools-mcp · GitHub
Repository and issues: GitHub - mozilla/firefox-devtools-mcp: Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi · GitHub
Public chatroom: https://chat.mozilla.org/#/room/#firefox-devtools-mcp:mozilla.org
1 post - 1 participant
The Mozilla Blog
Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support
Today at ALL IN, Canada’s largest AI and technology event, Mozilla and Mila announced a new initiative and fresh investment to build an open source AI foundation layer that enables organizations and institutions to own and operate advanced AI systems locally, ensuring full control over their technology and data.
Doubling down on its commitment to open source AI, the Government of Canada announced its support for the initiative. Mila will lead the technical delivery and coordination of the project, while Mozilla contributes technical expertise. It also provided the initial $5 million investment to kick off the project. Hypertec is committing an additional $1 million in first-year funding to accelerate initial Canadian deployments of the open source AI foundation layer on Hypertec hardware.
“Canada has a choice: depend on technologies developed elsewhere, or build more of what we need here at home,” said The Honourable Evan Solomon, Minister of Artificial Intelligence and Digital Innovation and Minister responsible for the Federal Economic Development Agency for Southern Ontario. “Open source AI gives Canadian businesses and institutions greater control over their technology and data, while making powerful tools more affordable, accessible, and easier to adapt. By supporting this work, we are strengthening Canada’s capacity to build and adopt AI on our own terms.”
Mila and Mozilla will lead the work together: Mila drawing on a world-class community of close to 2,000 researchers and professionals, Mozilla as technical partner from industry, bringing 25 years of experience stewarding open infrastructure others build on. Mila and Mozilla are actively engaging new partners, inviting companies, research institutions, funders, governments, and developers to join and support this work.
What’s being built
The goal is simple: make owning your AI as easy as renting it. Using open source models was never the hard part. Turning a raw open source model into something a small business, a hospital, a local charity, or a government can run in production — secure, reliable, plugged into everything else — takes an engineering team most organizations and institutions do not have and months they can’t spare.
The goal is to offer businesses and organizations a ready-to-use AI package that they can run privately and keep under their own control, rather than having to build a complex system themselves or rely entirely on expensive, pay-per-use proprietary AI services.
For example, a small manufacturer could use the system as a private AI assistant for its employees. It could search the company’s manuals, procedures, and past project files; help staff draft reports or answer technical questions; and help its software team write and improve code. Because the system is designed to be able to run locally, the company could do this while keeping its proprietary information and data within its own environment.
That also means lower costs. For the vast majority of everyday business tasks, companies will be able to use open source AI running on open source tools instead of paying a commercial provider every time an employee makes a request. But this requires reducing the technical work and expense involved in putting open source AI into practice.
This initiative was founded to solve that problem, building the free layer that makes owning open source AI easy — the same kind of layer the web was built on. It has two halves: An open standard, published as interface contracts, so any part of the stack can be swapped for a better one. And a working “reference implementation” any organization can install on its own machines or the ones it chooses, running the models and controls it chooses against its own data, with governance and access control built in from the start. The ambition is that with the standards and foundation in place, open source AI can be built anywhere, by anyone.
“Six months ago, we announced our partnership with Mozilla to advance open source and sovereign AI. Today, we are bringing that work to a whole new level,” said Valérie Pisano, President and CEO of Mila. “By delivering an open, secure AI foundation layer, we empower organizations, from small businesses to non-profits to governments, to own their technological future so they can run, control, and maintain AI models themselves. At Mila, our research community has always believed that for AI to be trustworthy and accessible, it must be built on open standards that keep control in local hands.”
The work already underway
Over the last six months, Mila and Mozilla have been designing the architecture, deciding which open source components belong at each layer, and testing that the whole system works end to end. This investment builds on that progress.
Working alongside Mila and Mozilla, Hypertec will help move the initiative from research and reference implementation to real-world adoption by Canadian businesses and institutions, providing a practical, private, and cost-effective path to deploy AI while maintaining greater control over their data and technology.
“AI is advancing at an extraordinary pace and has the potential to transform our economy and society for the better. Canada has an important role to play in ensuring that AI is developed and adopted responsibly, said Simon Ahdoot, CEO of Hypertec Group. “Hypertec is proud to help turn open source innovation into AI that Canadian organizations can deploy securely and under their own control. This is exactly the kind of partnership between government, research, and Canadian industry needed to realize the full potential of AI.”
Why now
Mozilla’s State of Open Source AI report found that while 79% of developers adding AI functionality use open models, only 53% of teams ever reach production, stopped by cost, security, integration, and maintenance. This work aims to change that.
“AI today is at a crossroads, where it could be closed and owned by a few, or open and available to every coder, developer, enterprise, and nation,” said Mark Surman, President of Mozilla. That’s what we’re building — an open source AI ecosystem that fits together as seamlessly as the web, and that anyone, anywhere can build on. We’re so grateful to Canada for scaling this work, and call on partners across sectors — from enterprises and governments to coders and startups — to join us in building this future.”
Within six months, Mozilla and Mila expect to publish working reference implementations for enterprise, government and public-interest use cases. The two-year ambition is bigger: to have solved this problem outright, so that open source AI can be adopted fully and easily, anywhere, by anyone.
The post Mila and Mozilla announce new initiative to build trustworthy open source AI for everyone, with Canadian government support appeared first on The Mozilla Blog.
Firefox Nightly
High-speed Release Trains – These Weeks in Firefox: Issue 209
Highlights
- Firefox 155 just released! That’s the first release that went through the full 2-week release cycle process.
- The WebExtensions team added a new backgrounds_area theme property so themes can explicitly control whether background images apply to the whole window or only the top toolbars
- Thanks to Emilio for the new theme property to control background image placement!
- This is targeting Firefox 156, and developer documentation will be added to MDN soon.
- The multi-context address bar for New Tab has been enabled in Nightly!
-
- There are a number of known bugs to address before this can ride. We’re tentatively aiming to have this release sometime in Q4.
- Notice an issue with it? File a bug here!
- Volunteer contributor Andrew fixed a white flash for the New Tab page on startup for users that have dark mode enabled by default.
- The DevTools team has made it possible to inspect and edit stylesheets from within the JavaScript Debugger pane.
-
- The feature can also be enabled from the experimental section in the devtools settings panel, or by setting devtools.debugger.features.stylesheets-in-debugger to true in about:config.
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- :Benjamin Peterson
- ExplodingJoysticks
- Gopalarathnam Venkatesan
- Khalid AlHaddad
- Lukáš Lipinský
- Chris Van Linden
New contributors (🌟 = first patch)
- 🌟 Amadi: Update comments that point at the removed openUILinkIn function
- 🌟 dchen705: Remove unnecessary module import in browser/components/urlbar/tests/browser/head.js
- Ekerin Agboola: Remove old documentation related to the removed SEARCH_SUGGESTIONS_LATENCY_MS histogram
- ExplodingJoysticks:
- Gopalarathnam Venkatesan:
- 🌟 Andrew: White flash on startup caused by abouthome_cache storing incompatible startup frame
- 🌟 Kana: browser_privatebrowsing_resetPBM.js awaits an array instead of Promise.all, so the tab-close wait does nothing
Project Updates
Add-ons / Web Extensions
- As part of Nova about:addons work:
- Restyled the Extensions panel empty states to match the Figma specs, including a new illustration for the disabled add-ons and private browsing states – Bug 2058450
- Fixed a jiggle effect when scrolling through theme previews in about:addons – Bug 2059917
- Added spacing between message bars and their sibling elements in the about:addons page (empty state promo, theme appearance mode control) – Bug 2066436
- Set focus on the extension permissions prompt dialog so keyboard users can reach it – Bug 2059855
- Removed activeAddons/activeTheme/activeGMPlugins from the legacy telemetry environment, now collected only through Glean – Bug 2055613
DevTools
- Nicolas Chevobbe [:nchevobbe] fixed an issue in the inspector to stop showing the HTML editor for nodes (e.g text or whitespace nodes) which should not be editable when F2 is pressed. (#2064213)
- Sebastian Zartner [:sebo] updated the documentation for the Rules view to include details around the @media emulation panel added some weeks back. (#2063851)
- Chris Van Linden fixed an styling issue in debugger editor file search bar where the button hover background overlapped the focus outline (#2063466)
- Nicolas Chevobbe [:nchevobbe] fixed an a11y issue where the keyboard focused sliders in the fonts panel did not have the correct contrast against the background. This allows keyboard users to easily see which control currently has focus. (#2062576)
- Hubert Boma Manilla (:bomsy) added telemetry to track the usage of styles sheets shown in the debugger (#2060500)
WebDriver
- Khalid AlHaddad improved Marionette and Remote Agent to quit Firefox with a custom error code when they failed to start their server.
- Khalid AlHaddad updated the moz:debugging module to properly handle nested pauses.
- Sameem updated the handling of user contexts to clean up the settings set per a user context (e.g., proxy settings or accepting of insecure certificates) also when a user context is removed outside of WebDriver BiDi.
- Henrik Skupin updated the WebDriver:GetElementTagName command to return the element’s qualified name.
- Henrik Skupin improved the Perform Actions command in both Marionette and WebDriver Bidi to dispatch intermediate events at more precise intervals when duration is greater than 0.
- Alexandra Borovova updated the “browsingContext.startScreencast” command to handle a screencast file creation on operating systems that don’t have a dedicated download folder.
Lint, Docs and Workflow
- The TypeScript linter has been promoted to tier-2.
- There is no automation for the core type updates yet.
- However, several areas have been working on support, hence the promotion to tier 2.
- Until we get the automation in place, we will not be ready for wider roll-out, as it will be more likely that core patches will break the TypeScript reporting.
New Tab Page
- Developer experience improvement: it’s no longer necessary to create the WebPack bundles when updating New Tab JSX / SCSS files. This occurs automatically during the ./mach build [faster] step. Thanks to Nathan Barrett for his work there!
- Mike Kaply made it so that New Tab Settings honor Locked Preferences in policy by making the New Tab settings UI read and respect policy-locked preferences and disabling corresponding controls so managed/enterprise users cannot override locked prefs from the settings surface.
- Mike Conley landed a patch to address potential shutdown hangs / crashes when newtab trainhop XPIs are in the midst of being downloaded during a shutdown.
- Irene Ni made it so that we always show an add shortcut button for New Tab shortcuts when hovering the outside edge of the shortcuts area
- Irene Ni fixed some <hr> seperators that were leaking out of some containers by scoping the HR rules to the briefing-card container.
- Reem Hamoui added missing alt text/ARIA labels to the New Tab Page weather widget, restoring screen‑reader semantics for weather images in the NTP widgets.
- Jack Brown added scroll100 and scroll250 boolean metrics to the newtab ping to capture 100px/250px scroll‑depth thresholds for analytics—this is a telemetry/schema change with no UI impact.
- Scott Downe created the ‘spaces’ content layout variant for the New Tab Page, introducing an alternate DOM/CSS layout for Spaces that changes tile/content rendering and is gated by the Spaces rollout flag/pref.
- A Stocks widget is in-flight, starting with the US market
-
- Nina Pypchenko [:nina-py] added a Markets/Watchlist dropdown to the Stocks widget on New Tab so users can switch views in-place; the dropdown selection is persisted in the widget state.
- Nina Pypchenko [:nina-py] let users add default tickers to their Stocks Watchlist so new or reset users see a curated set of tickers and the add-flow now persists defaults to the watchlist storage.
- Nina Pypchenko [:nina-py] added a small size to the Stocks New Tab widget, introducing a compact 1×1 Stocks tile in the Firefox New Tab Page layout so users on narrow windows or dense NTP configurations can keep Stocks visible without consuming medium/large slots.
- Nina Pypchenko [:nina-py] updated the Stocks widget feed to fetch data for individual stock tickers, changing the widget network layer to per-ticker requests so added symbols get independent, timely updates and per-symbol errors are surfaced instead of breaking the entire feed.
- Nina Pypchenko [:nina-py] added ticker search to find and add individual stocks, adding a search/lookup UI and add flow that calls the ticker lookup API and updates widget state/local storage so users can search, add, and immediately see new symbols on their New Tab Page.
- Bryan Olsson added a plural selector to the Fluent string newtab-stocks-watchlist-full in the New Tab Page localization so the Stocks widget shows correct singular/plural wording for watchlist sizes across locales, fixing grammar that could confuse users when their watchlist count changes and touching the NTP stocks string bundle used by all localized builds.
- We’ve also started rolling out an experimental Privacy widget
-
- Reem Hamoui changed the Privacy widget copy color to grey in the New Tab Page so the “Nightly blocks trackers as you browse. You will see them here.” text displays with correct muted contrast (2063205).
- Reem Hamoui restored the ETP OFF state rendering in the New Tab Page privacy widget so the widget shows the actual ETP OFF status instead of misleading ‘blocks trackers’ copy for users who disable ETP (2063525).
- Reem Hamoui applied UX fixes to the New Tab Page privacy widget to correct alignment, labels, and click-targets so users see and interact with the widget reliably and accessibility attributes behave as expected.
- Reem Hamoui fixed the blocked-tracker count not updating after opening a new tab by ensuring the tally is recomputed on tab open (cache invalidation + UI binding refresh), restoring accurate tracker numbers in the widget.
- We’ve also started tinkering with some new layout variants
- Here’s one such layout (widget column on left):
-
- Irene Ni updated SectionsLayoutFeed’s 7-double-row-2-ad fallback to match Remote Settings so feed layout and ad fallback counts align with remote config, reducing layout mismatches and incorrect ad placements in feeds using the fallback (2063684).
- Irene Ni implemented a carousel card type for the New Tab feed, adding slide-based card rendering and navigation hooks so users get swipeable/rotating cards in the carousel component.
- Irene Ni deduped impressions for a carousel slide that cycles back into view, preventing duplicate impression pings when a slide reappears and improving the accuracy of telemetry/ad metrics.
- Dre cleaned up orphaned wallpapers in the wallpaper service to remove broken entries and reduce wasted storage so users no longer see missing background tiles.
- Dre uploaded new wallpaper assets to match updated margins so backgrounds render without cropping or misalignment under the new NTP layout.
- Nina Pypchenko [:nina-py] fixed wallpaper attribution rendering in the Nova New Tab flow by adjusting the Nova-specific NTP component’s conditional rendering (CSS/JS) so the attribution node is not skipped when the nova feature is enabled, restoring photographer/credit metadata on New Tab pages for users on Nova-enabled desktop builds and preventing missing attribution UX.
- We’re in early days in building out the infrastructure for a Recent Searches widget
- Nina Pypchenko [:nina-py] added a blank widget scaffold to the New Tab Page widget registry for the Search team (bug 2065011), creating a no-op/placeholder widget registration hook so the Search team can iterate on experiments without changing current NTP visuals — no immediate visible impact for end-users until the widget is populated.
- Dão Gottwald fixed an unscoped panel-item::part(button) rule that stripped the icon slot from panel-items it didn’t own, restoring missing icons in New Tab panels and preventing blank/empty buttons in the UI.
- Maxx Crawford added support for auto-minimized the New Tab widgets section after a short delay, closing expanded widgets automatically to reduce visual clutter and accidental persistent open state.
- Irene Ni implemented the Topic Navigation Strip V1 in the New Tab Page, adding a horizontal topic-nav UI in the New Tab (top-sites/topics area) that improves discoverability and lets users switch topic feeds faster.
Picture-in-Picture
- Pier Angelo Vendrame made the document PiP video size spoofable under resist fingerprinting.
- Lukáš Lipinský fixed WebVTT tracks failing to display after opening a PiP window.
Search and Urlbar
Nova UI refresh
- Drew and Daisuke continued polishing the urlbar experience in Nova.
- Bug 2067360, Bug 2063170, Bug 2063167, Bug 2063127
Suggest
- Drew fixed alignment of the explanation text on various result types. Bug 2063460
- Drew enabled more providers (like Wikipedia) for DE, FR, IT regions. Bug 2064557
- Drew updated important dates suggestions for 2027 in DE, FR, GB, IT and US regions. Bug 2064437
- Dao fixed a regression with the result menu being empty on certain results. Bug 2066758
Adaptive autofill
- James is analyzing results of experiments and working with Product to let the feature ride to Release in the near future.
Quick actions
- Dale improved the Open Firefox Labs action. Bug 2063849
- Dale improved styling of disabled actions. Bug 2056488
Multi Context Address Bar
- Dao and Moritz made great progress with having the urlbar code work in different contexts, including across processes.
- Dao migrated some text input context menus (address bar, search bar, Thunderbird compose subject) onto a single shared menu with a new custom-item API, allowing removal of the legacy moz-input-box component.See EditContextMenu for documentation and usage. Bug 2064369.
- Dharma started refactoring the urlbar code to use extended classes. Bug 2064728
- New tab search bar has been enabled in Nightly! Bug 2062212
- The uipc variant of urlbar tests is now tier1, failures will be backed out.
Other notable Address Bar fixes
- Dao made tabbing from the urlbar field focus the search field, if present on the toolbar, instead of the search button inside it. Bug 2009628
- Daisuke addressed an issue where an autofilled URL was ignored just after launching Firefox. Bug 2057763
- Moritz fixed a regression causing undo to no longer work in the urlbar. Bug 2061633
- Moritz fixed a regression with the placeholder text in the urlbar showing garbled characters. Bug 2063779
Search
- Mark added support for POST search engines to the contextual actions in the urlbar. Bug 2064047
- Caleb fixed an accessibility issue in the add search engine dialog. Bug 2041438
Places
- Caleb fixed a bug where moving a group of folders could move some bookmarks out of their parent folder. Bug 2044707
Mozilla Privacy Blog
Pragmatic principles for more rights-respecting age assurance architectures
This is the second part of a two-part series in which we explore approaches to protecting children online while safeguarding privacy, security and the open web. Part one covers our concerns regarding age gates, and suggests alternative policy proposals that address the root causes of online harms. Part two explores better ways to build age assurance architectures that respect users’ rights and autonomy.
Across the world, legislation to introduce age gates and social media bans is proliferating. Many governments are still considering age restrictions a straight-forward and cost-effective tool to achieve their child safety goals. However, evidence is mounting that age assurance mandates pose risks to users’ privacy, security, free expression and access to information, threaten the open web and competition, and undermine policymakers’ goals: enabling young people to have safe and trustworthy experiences online, while enabling the digital economy to grow.
As we have said before, we believe that blunt tools like social media bans are overly broad, undermine users’ rights and do not address the root causes of online harm. Reducing risks to young people online requires a holistic, privacy-first approach to online harms emphasizing enforcement of existing rules, addressing harmful design, and equipping all users with better defaults, more choice and granular controls over their experiences online.
Age gates alone are insufficient to address online harms, but age signals can contribute to more holistic approaches by helping achieve age-appropriate experiences online. Where age assurance obligations are considered as one tool out of many to foster age-appropriate experiences, their potential benefits must be balanced against their negative implications for users’ privacy and security, access to services, and the openness of the web.
From the service to the device – taking stock of regulatory models
Implementing age assurance is not a single intervention, but a series of steps. A user’s age is first assessed, which can happen through a variety of sources of age information and with varying degrees of accuracy. That signal is secondly shared with the actor responsible for age-appropriate experiences, and thirdly acted upon or enforced by that actor.
Dominant approaches to age assurance obligations focus on online platforms – given that this is where many risks encountered by young people unfold. In practice, this has led to online services – websites or apps – turning to third-party age assurance providers to perform age assurance, whether through biometric age estimation, age inference based on users’ behavioral data, ID-based checks, or other methods.
In this model, third-party age assurance companies both assess users’ ages and share that signal with the platforms responsible for implementing it. To retain access to social media platforms, messaging services and many other online offerings, users are thus forced to surrender their sensitive personal data to these age brokers, often a different one for each service.
Once in the hands of these providers, peoples’ data is at risk of being sold, repurposed or accessed by law enforcement. The recent data breach of a ID and age verification provider that exposed more than 153 million IDs underscores that this is not a theoretical concern, but a significant risk for anyone asked to prove their age online. Rather than being asked to trust companies, some of which have already been exposed for their harmful data practices, people deserve verifiable guarantees that their data is safe and secure.
Emerging regulatory models are considering the role that device intermediaries, like operating systems, device manufacturers, and app stores, can play in age assurance. In such models, these actors are either required to communicate an age signal to the actor responsible for acting on it, or to restrict access to services themselves, based on an age signal created at the device level.
Device intermediary focused approaches, too, come with significant challenges: Given the significant concentration of power among (mobile) operating systems and app stores, such a legislative design can easily further entrench the dominance of Apple and Google, disadvantage open source competitors, and undermine users’ privacy and control, including over their devices. These implications must be carefully mitigated.
Principles for better age assurance architectures
Every approach to age assurance comes with important trade-offs, and we maintain that there is no age assurance system that mitigates all risks to users’ fundamental rights, access to services, competition and the open web, while being effective in avoiding every instance of under-age access. However, we do believe that better age assurance architectures are possible. In many situations, unverified age signals may be sufficient to provide age -appropriate experiences without undermining fundamental rights. Where stronger assurances are considered necessary, zero knowledge architectures can help protect users’ privacy.
Better age assurance architectures must be private, secure, accessible to all users, and, crucially, must provide them with autonomy, choice and control. Designing age assurance obligations that live up to these values is a question of governance, not technology. Hence, policymakers have a crucial role to play in defining requirements for rights-respecting age assurance systems.
1. Assign responsibilities deliberately.
From people’s devices, to operating systems, app stores and websites or apps, many actors can be involved in age assurance processes. Some of these actors will be better suited to be responsible for certain steps of age assurance processes than others to avoid negative outcomes for fundamental rights and the open web.
Given that websites and apps know most about their services, their features and content hosted, we argue that they are in the best place to act on age signals to provide age-appropriate experiences. Implementing age signals at this level allows for more granular choices for creating age appropriate experiences. Other actors, like network operators or device vendors, simply do not have the necessary information.
While websites or apps are best placed to create age appropriate experiences, device intermediaries like operating systems are well-placed to facilitate the privacy-preserving sharing of age signals created locally. Moving age assessments to the device-level allows users to interact with an age provider once, rather than having their age assessed by a different age provider for every service they use. If such approaches are pursued, strong protections need to be in place for open source operating system providers, as well as mandates for the development of open and free standards to avoid fragmentation and competition harms, and to strengthen transparency and user consent
2. Ensure choice, equity and accessibility.
Age can be attested to, approximated or verified in many ways. Every age assessment method comes with important trade-offs, but people should not be forced to take risks on their personal data and safety to retain access to services and information. Users should thus always have a choice between multiple age providers that are privacy-preserving, non-discriminatory and accessible. This is especially important for young people who often don’t have access to more privacy-preserving age assurance methods, and are expected to hand over their biometric data to stay online.
The question of which providers are deemed trustworthy enough to participate in such a system is a crucial one. Policymakers must ensure that the options available to people protect their privacy and security, and that a diverse list of providers prevents people from being locked out. Only if everyone has the ability to access age assurance systems through privacy-preserving and rights-respecting providers, will the web remain accessible and open. People should be able to rely on a plurality of institutions, government or private, that can either attest to their age, including face-to-face, or have existing knowledge of their ages that they can share through the use of anonymous credential technology. Examples might be banks, public health and educational institutions, libraries, or services like phone providers, ISPs, subscription services or other services that are able to attest to a user’s age.
3. Put people in control.
We should always be in control over what information is shared about us, and to whom. Once an age signal is created, age assurance architectures should empower users to hold that signal – in the form of a credential – on their device. Whether an age signal is shared with an app or website by the operating system or the browser, users must be in control of the decision whether and to whom that information is shared with.
Users must also retain control over – and trust in – their devices. Digital devices are the interface through which we all navigate increasingly large parts of our lives; they are our trust anchors. Enforcing restrictions at the device level on what people can or cannot do online would undermine the already fragile trust relationship between the two — pushing people toward less secure workarounds, rather than addressing the underlying policy concern.
This means that it is best when responsibility for sharing the results of age assessments is performed by users and their devices.
4. Assess risks end-to-end.
Many jurisdictions require age assurance systems to be “highly effective”. We believe that the effectiveness of an age assurance system should be considered end-to-end, and not be limited to the assessment step: After all, where an older relative or friend is willing to help a child circumvent a block, no technical mechanism can be effective.
Given these considerations, we think there is value in considering age assurance approaches that empower parents to attest to their child’s age when setting up their device. Coupled with barriers to resetting the age once set, such an age signal would provide a high degree of confidence without requiring invasive proofs of age through biometric analysis or ID document checks. As noted above, such approaches need to ensure that age attestation is not another factor cementing the dominance for a few actors, and that open source projects are meaningfully protected from being locked out of participating in a market.
Despite those challenges, we believe that it is crucial to not only consider the potential risks young people could encounter online, but also the risks flowing from age assurance systems themselves. Given those risks, parental age attestation can be a lower-risk approach suitable in many contexts.
5. Leverage zero-knowledge architectures.
Where high-assurance age credentials are used, zero-knowledge architectures are the right step towards sharing age signals in a privacy preserving way. Such approaches allow users to verify the truth of a statement about them, like their age or age range, without having to reveal the information on which the statement is based.
While zero-knowledge architectures are promising, they do not solve every issue. Beyond limiting disclosure of information about people (such as attributes other than their age), hiding the issuer of age credentials (like a bank, public service or educational institution) is key to preserving users’ privacy and choice of assessment methods. This prevents discrimination against users of smaller or less common age providers.
Likewise, the issuer of an age credential should not know which service or feature someone is accessing with an age proof. The example of Spain’s Catera Digital, or “porn passport”, shows why: The Spanish age verification system created tokens that the verifying authority could use to infer a user’s browsing history, undermining users’ privacy, trust, and ultimately the adoption of the system.
Zero-knowledge proofs themselves also do not prevent abuse of age information, such as by using age data in ad targeting. Beyond strict prohibitions on repurposing age data, we believe that any age assurance system should be open source to facilitate trust, accountability and transparency.
To prevent the sharing of age tokens, we believe rate limits, which restrict how often an age token can be used, are the best and most effective solution. We strongly caution against linking tokens to attested hardware, such as trusted platform modules (TPMs). Hardware-bound tokens force users to use specific, approved hardware. Hardware attestations can leak details about the device’s configuration and location, thus enabling tracking or unjustified discrimination at the moment of certification issuance. Attestations undermine users’ freedom over their own devices, including what software they can install and run. People who run older or unsupported devices might be excluded as old, weak hardware is routinely found to be compromised, such that it needs to be revoked. Rate limits offer a far simpler and more robust answer to these challenges.
6. Don’t break the internet.
The open internet – and the web built on top of it – is a global public resource that millions depend on every day, and that has become a cornerstone of our societies. This openness thrives on open standards, shared protocols, and interoperability. Age checks risk fragmenting the web in more ways than one: Incompatible requirements will create a patchwork of age-gated communities, and age gates in the hands of a few will push people further into closed ecosystems, undermining the wider digital competition and the decentralization that gives the internet its strength.
To avoid the hollowing out of fundamental rights online, and the undermining of the open internet, international collaboration and free and open standards are urgently needed to govern age assurance across borders.
***
We believe the principles set out above can help mitigate the large-scale erosion of privacy, security, and agency that the first wave of age assurance laws and social media bans has introduced.
But improved legislative mandates and technical fixes alone are not enough to improve young people’s online experiences in a rights-respecting way. Enabling young people to develop positive relationships with digital technologies is foremost a societal issue, not a technical one. Changing norms around how we engage with technology, what we ask of companies seeking our attention, and how we have conversations about what safety means beyond abstinence and control will require a whole-of-society approach to digital well-being.
The post Pragmatic principles for more rights-respecting age assurance architectures appeared first on Open Policy & Advocacy.
The Rust Programming Language Blog
Be alert: targeted attacks on prominent Rustaceans
We believe that there is an ongoing campaign targeting rust-lang members and owners of popular crates that is attempting to compromise devices and accounts in order to use them to publish malware.
What we've seen
A video call is set up for something positive — maybe for a job, maybe for a project, maybe for a contract opportunity — and then that's used as a vector to either get the target to install something on their computer (such as a purportedly missing audio codec) or execute another command (for example, via putting a command on the clipboard).
These attackers are setting up new but legitimate seeming company profiles, including plausible LinkedIn presences, in order to pass cursory inspection.
A previous attack of this form targeted many prominent Rust developers in
June, and, last month, the arrayref crate was briefly compromised through similar
attacks. At this moment we do not know if these are all a part of the same
campaign.
This attack style is known to be used by the DPRK, and has been seen outside of the Rust community as well.
What you can do
Please take extra care in the near term. Be appropriately suspicious of cold outreaches, and ensure that any calls you have with new people are on platforms you trust — ideally, try to be the one who sets up the call on a platform you already use.
Please also re-check that your accounts look normal: MFA enabled, no unexpected logins on platforms that can track that, and so on.
If you have any concerns about your accounts, please reach out to help@crates.io (for crates.io account concerns) and/or security@rust-lang.org (for any other concerns). We're very happy to help.
Firefox Tooling Announcements
Happy BMO Push Day! (20260916.1)
The following changes have been pushed to bugzilla.mozilla.org:
- Bug 2069143 - When retrieving comments for a bug(s) via REST API, remove comments that would be collapsed in the web UI unless explicitly asking for them
- Bug 2070247 - Support limiting who can needinfo the Hackbot account
- Bug 2061445 - Migrate Bugzilla (system info) REST resource to native Mojo API
- Bug 1877201 - Post to
bug/{bugid}/commentreturns wrongcomment_id - Bug 2072224 - Update REST API authentication documentation to reflect per-resource migration to native Mojo auth
- Bug 2060932 - Support GitHub-style <details>/<summary> collapsible sections in comments
- Bug 2072689 - Buglist link on My Dashboard is broken
Discuss these changes in the BMO Matrix Room
1 post - 1 participant
Firefox Tooling Announcements
MozPhab 2.19.1 Released
Bugs resolved in Moz-Phab 2.19.1:
- bug 2071003 moz-phab patch --apply-to head moves to a detached HEAD
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
The Mozilla Blog
Mozilla and Mistral: Partnering to expand AI competition and preserve user choice
The AI race is shifting. Again. Practically overnight, competition has expanded from “which AI model is best?” to a new high-stakes battle over which models people can access, through which products, and whether people have meaningful choice about AI at all.
In response, Mozilla and Mistral today announced a partnership built on a shared idea: a new, open-source AI model alternative to Big Tech-default browser ecosystems. The intent: a model deliberately designed to keep the web open to technological diversity, competition, and choice.
And we’re putting this idea into practice in Firefox.
Mistral Small 4 is coming to Firefox Smart Window beta (learn more about Firefox Smart Window here), becoming a new AI model for Smart Window users in the US and Canada, while expanding Smart Window beta access and French-language support to Firefox users in France. Across all markets where Smart Window beta is available, Firefox users can still choose from a multitude of other AI models.
“AI is becoming part of how people experience the web every day. We want to make sure that doesn’t mean people are chained to one company’s self-serving pipeline. With the browser sitting at the heart of the web and online experience, it should be a place where different AI providers can compete and open source has a seat at the table.
This isn’t just a product partnership. A browser shouldn’t be a one-way funnel. It should preserve what made the internet powerful to begin with: the freedom to explore, discover different ideas and tech, and decide for ourselves where to go next,” said Anthony Enzor-DeMeo, CEO of Mozilla Corporation.
Choice and competition are worth protecting
As AI integration becomes increasingly concentrated, we are in jeopardy of a handful of closed-model companies controlling the browser, the search engine, the AI model, and the surrounding services that connect them. Mozilla and Mistral are betting that independent and interoperable models can offer an alternative to global tech monopolies controlling the next digital era.
“This partnership represents two open source advocates working together to bring Mistral’s scientific innovations to Mozilla’s consumers around the world. Together, we are bringing privacy, control, and choice to AI-powered web browsing,” said Arthur Mensch, Co-founder and CEO of Mistral.
Meaningful choice isn’t confined to personal preference for one AI model over another. Web products need to be able to work with different AI providers, and people deserve the option of switching without being locked into a single company’s ecosystem. When a tech layer as far-reaching and influential as AI is controlled by a small handful of players, it risks creating closed systems and closed doors, making it harder for new ideas and better technologies to grow, reach users, and compete on merits.
Mozilla and Mistral aim to keep that door open. The combination of an independent browser with a frontier European AI company gives people and institutions greater access to useful, responsible AI, the opposite of locking them into one company’s singular technology ecosystem.
Selecting Mistral, and expanding to France
Mozilla selected Mistral Small 4 after evaluating its performance for Smart Window Beta, including multilingual performance, an important part of the fit. The companies approached multilingual and multicultural tuning as a core model feature, rather than simply adapting an English-first experience for a new market.
For Firefox users, Mistral access starts with Smart Window Beta, a browsing experience designed to turn AI into a useful assistant for the things we do online: making sense of complex search trails, finding something valuable you clicked away from, presenting data sources, and generally picking up where day-to-day internet use got left off.
France is the first new market for Smart Window with official French-language support. Mozilla is planning additional European expansion later this year.
A different kind of AI competition
Our Mistral partnership puts an ambitious new AI model approach into practice: a multilingual, globally competitive European AI company reaching people through an independent browser, leveraging openness to create more room for new technologies to compete and succeed. Mistral can reach Firefox users without owning the browser, and Mozilla can integrate and recommend Mistral without removing user choice.
It is a natural extension of the principles that have shaped Firefox and the open web, and the kind of AI ecosystem we intend to continue building.
The post Mozilla and Mistral: Partnering to expand AI competition and preserve user choice appeared first on The Mozilla Blog.
Jonathan Almeida
Checkout a Github pull request from one-off contributions
EDIT: Updated to reference gh correctly. Thanks flod!
Sometimes on Github, I need to fetch a patch from a fork I don't typically see everyday so I can try it out locally. I use the line at the top of the patch which has a copy button next to it because it's convenient.
The common steps for this are:
- Click the contributor's branch and go to their github fork repository.
- Copy the repository link.
- Add a new git remote with an alias (typically their username).
git fetch <alias>git checkout <alias>/<branch>
Here is a one-liner for it that you can add to your gitconfig:
[alias]
co = "!f() { PNAME=$(basename `git rev-parse --show-toplevel`); OWNER=$(echo $1 | cut -d':' -f1); BRANCH=$(echo $1 | cut -d':' -f2); git fetch git@github.com:$OWNER/$PNAME.git $BRANCH; git checkout FETCH_HEAD; }; f"
You might ask, why do all of this when the github gh CLI does this for you?
While it does simplify some tasks, I wanted a solution that was independant to a specific git host. The git@github.com remote that is used in the alias can be changed or made configurable if desired. This is something that I wouldn't be able to do with platform-dependant gh.
The fetch also works well with jj too because the fetch and checkout remain headless.
Formatted and commented, it looks less intimidating:
f() {
# Get the repository name from your checkout (assuming it is the
# original directory name as the remote).
PNAME=$(basename `git rev-parse --show-toplevel`);
# Parse out the fork's owner.
# Example: `<owner>:<branch>`
OWNER=$(echo $1 | cut -d':' -f1);
# Parse out the branch name.
# Example: `<owner>:<branch>`
BRANCH=$(echo $1 | cut -d':' -f2);
# Do a fetch of that particular branch using the extracted
# information from above.
# This assumes the remote is hosted on github.
git fetch git@github.com:$OWNER/$PNAME.git $BRANCH;
# Checkout using the alias `FETCH_HEAD` which git provides.
git checkout FETCH_HEAD;
};
# Execute the function!
# It's easier to build a function that holds variables and execute
# rather than in-line it.
fComments
With an account on the Fediverse or Mastodon, you can respond to this post. Since Mastodon is decentralized, you can use your existing account hosted by another Mastodon server or compatible platform if you don't have an account on this one. Known non-private replies are displayed below.
Learn how this was implemented from the original source here.
This Week In Rust
This Week in Rust 669
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Newsletters
- Rust Trends Issue 82 - Even the Linker Is Getting Rewritten in Rust
- The Embedded Rustacean Issue #80
Project/Tooling Updates
Observations/Thoughts
- Where Does Rust Belong on Arduino? If it belongs.
- CO3: Toward the Optimal FFI
- Why building a Rust LSP is hard · Rust Glancer
- Developing provably correct Rust code with Verus
- Principles for fast Tokio applications
Rust Walkthroughs
- Trying to Make a Loop Auto-Vectorize
- Does Rust Support Inheritance? Yes, No, and Maybe, All in the Same File
- Shipping Rust static libraries without symbol collisions
Rust Walkthroughs
- A visual guide to Rust async
- Rust Projects - Write a Redis Clone - Version 3.0.0
- Can You Use ESP32 as SWD Programmer for STM32 with Rust?
- Time and Panic Traps in WebAssembly: It Compiles, but It Crashes in the Browser
- One Lock to Rule Them All
- Operators of death: checked arithmetic in Rust
- Rust generics: from Static to Dynamic dispatch
- [video] Your First GPUI App - Building a Desktop UI in Rust
Research
Crate of the Week
This week's crate is zenjpeg, a pure Rust JPEG encoder and decoder.
Thanks to Kornel for the suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a
call-for-testing label to your RFC along with a comment providing testing instructions and/or
guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- No Calls for participation were submitted this week.
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
- No Calls for papers or presentations were submitted this week.
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
523 pull requests were merged in the last week
Compiler
- garbage-collect old incremental compilation sessions
- less clones and more cleanup for
rustc_builtin_macros - perf: read hygiene data once when hashing syntax contexts
- use
DenseBitfordrop_live_atin liveness tracing - use
Box<[Word]>for word storage inDenseBitSet
Library
- generalise (most) impls on
Box - implement
Thread::os_id - reserve items in
Extendimplementations - stabilize
Vec::from_fn - stabilize
core::mem::DropGuard - stabilize
unsafe_cell_access
Cargo
fix(git): For git cli, tell users what config we aren't forwarding on errorfix(install): use packaged lockfile by default- fix(trim-paths)!: unremap file in one JSON doc
- lower the lint level of
manual_readmeandnon_kebab_case_binstoallow - specify
--editioninmessagestests - test: add more comprehensive workspace feature unification tests
Rustfmt
- don't treat a raw identifier as a raw string prefix
- fix adjustment of
max_widthwithin macros - reserve width for
constwhen formatting inline const blocks
Clippy
map_clone: avoid suggestions after type-changing coercions- fix
collapsible_matchsuggesting wrongly for conditional compiled code - enable
manual_swapin const contexts
Rust-Analyzer
- cache macro-expanded roots when climbing ancestors
- do not fill unstable methods in "Implement default members"
- do not panic on json with invalid field name
- don't panic on doc comments attached to literal expressions
- fix
hir::Typeowner mismatches between anon consts - fix panic when trait solver re-enters itself
- fix panic when we call
impls_traitfor self type of builtin derive impls for generic types - stop at eager macro recursion overflow
- ide: fix doc comment offset calculation
Rust Compiler Performance Triage
There were almost no regressions this week, and several performance improvements! Though some of them were reverts of regressions from a previous week. #162422 improved the performance of Polonius, whose performance is getting closer to the previous NLL borrow checker.
Triage done by @Kobzol. Revision range: 656a9da1..20d35a3a
Summary:
| (instructions:u) | mean | range | count |
|---|---|---|---|
| Regressions ❌ (primary) |
- | - | 0 |
| Regressions ❌ (secondary) |
0.4% | [0.1%, 0.9%] | 3 |
| Improvements ✅ (primary) |
-0.7% | [-4.4%, -0.1%] | 199 |
| Improvements ✅ (secondary) |
-0.9% | [-2.7%, -0.1%] | 222 |
| All ❌✅ (primary) | -0.7% | [-4.4%, -0.1%] | 199 |
0 Regressions, 5 Improvements, 5 Mixed; 2 of them in rollups 40 artifact comparisons made in total
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
- No RFCs were approved this week.
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- Stabilize
debug_closure_helpers - Additional NonZero conversions
- Implement Default for NumBuffer
- Allow elided ('static) lifetimes in
thread_local! - Stabilize
funnel_shifts(includingconst) - Stabilize
mem::conjure_zst - Stabilize
Result::into_{ok,err} - windows: stabilise inherit_handles
- rustc: Stabilize the WebAssembly
wide-arithmeticfeature - Prevent mutating the global environment pointer in
CommandExt::execand opt to use execve and resolve path manually - alloc: stabilise
Allocator - Disallow accesses through an Index projection when a sibling ConstantIndex projection has been moved out of
- Allow unary operand types to be inferred later
No Items entered Final Comment Period this week for Rust RFCs, Compiler Team, Language Team, Language Reference or Unsafe Code Guidelines. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
Upcoming Events
Rusty Events between 2026-09-16 - 2026-10-14 🦀
Virtual
- 2026-09-16 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-09-17 | Hybrid (Seattle, WA, US) | Seattle Rust User Group
- 2026-09-18 | Virtual | Rust Girona
- 2026-09-20 | Virtual (Bengaluru, IN) | Embedded Rust Discord
- 2026-09-20 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-09-22 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-09-24 | Virtual (Berlin, DE) | Rust Berlin
- 2026-09-24 | Virtual (Charlottesville, VA, US) | Charlottesville Rust Meetup
- 2026-09-29 | Virtual (London, UK) | Women in Rust
- 2026-09-30 | Virtual (Cardiff, UK) | Rust and C++ Cardiff
- 2026-10-02 | Virtual | Rust Girona
- 2026-10-04 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-06 | Virtual (London, UK) | Women in Rust
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
- 2026-10-08 | Virtual (Berlin, DE) | Rust Berlin
- 2026-10-08 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-10-10 | Virtual (Gdansk, PL) | Stacja IT Trójmiasto
- 2026-10-13 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
Europe
- 2026-09-14 - 2026-09-16 | Berlin, DE | Oxidize 2026
- 2026-09-17 | Dortmund, DE | Rust Dortmund
- 2026-09-22 | Prague, CZ | Rust Prague
- 2026-09-24 | Aarhus, DK | Rust Aarhus
- 2026-09-24 | Amsterdam, NL | Rust Developers Amsterdam Group
- 2026-09-24 | Frankfurt, DE | Rust Rhein-Main
- 2026-09-26 | Stockholm, SE | Stockholm Rust
- 2026-09-28 | Augsburg, DE | Rust Meetup Augsburg
- 2026-09-29 | Manchester, UK | Rust Manchester
- 2026-09-30 | Basel, CH | Rust Basel
- 2026-10-05 | München, DE | Rust Munich
- 2026-10-08 | Oslo, NO | Rust Oslo
- 2026-10-10 | Geneva, CH | Rust Geneva
- 2026-10-14 | Barcelona, ES | BcnRust
North America
- 2026-09-16 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-09-16 | San Francisco, CA, US | Bay Area Rust
- 2026-09-17 | Hybrid (Seattle, WA, US) | Seattle Rust User Group
- 2026-09-17 | Mountain View, CA, US | Hacker Dojo
- 2026-09-19 | Boston, MA, US | Boston Rust Meetup
- 2026-09-22 | Chicago, IL, US | Chicago Rust Meetup
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-24 | Atlanta, GA, US | Rust Atlanta
- 2026-09-26 | Boston, MA, US | Boston Rust Meetup
- 2026-10-01 | Saint Louis, MO, US | STL Rust
- 2026-10-03 | Boston, MA, US | Boston Rust Meetup
- 2026-10-08 | San Diego, CA, US | San Diego Rust
- 2026-10-10 | Boston, MA, US | Boston Rust Meetup
- 2026-10-14 | Los Angeles, CA, US | Rust Los Angeles
Oceania
- 2026-09-29 | Barton, AU | Canberra Rust User Group
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
Every so often I am told about some maths fact that I can only assume someone went to prison for discovering
Thanks to Chayim Refael Friedman for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
The Servo Blog
Your Donations at Work: One Year of Sponsored Servo Development
Last September, the Servo project announced that long-time maintainer Josh Bowman-Matthews (@jdm) would work part-time on improving the Servo contributor experience, entirely funded by the monthly donations on OpenCollective and GitHub. In his own words, here is a look back over the past year!
First of all, I am enormously grateful to everyone who financially supports Servo, as those donations have enabled me to devote significant time to a project that I care a lot about. Some highlights from that funded work that I’m proud of:
- I nominated 8 new maintainers
- I reviewed 1150 pull requests
- I filed 114 issues targeted at newer contributors (92% of them have been fixed)
- I wrote new documentation about borrow hazards, experimental features, the AI policy, finding things to do, and fixing stable and intermittent test failures
On top of that, I spent time diagnosing unexpected failures in others’ PRs and fixed numerous intermittent test failures that made merging PRs more difficult for everyone.
A few pieces of work from this period that stand out to me:
- supporting a large scale rewrite of Servo’s JS engine integration to address intermittent panics related to garbage collection—I reviewed lots of pull requests, but also filed many issues that enabled the work addressing the panics to be spread across many other contributors
- getting tagged in to help understand test failures, uncovering our broken window.open behaviour, and eventually making a lot of flaky tests more stable
- supporting another contributor’s grant proposal to work on Servo that was approved!
This role I’ve carved out means a lot to me—I’ve found a healthy balance that allows me to spend time with my family as well as make meaningful contributions to Servo, and I get to spend a lot of time looking for ways to make the project more accessible for others. A big thank you to everybody supporting the project and my work; each individual monthly donation makes a big difference! I’m excited to see what’s possible in the coming year.
Firefox Nightly
The Need for Speed Controls – These Weeks in Firefox: Issue 208
Highlights
- Firefox 154 went out today! Lots of goodies in there for our users, including support for NVIDIA GeForce NOW
- The new 2 week release cycle is now in effect. This means that Firefox 155 is slated to hit release on September 1st!
- You can follow along at https://whattrainisitnow.com/
- As part of the Nova redesign, a “Use Linux system theme” checkbox is being shown on Linux builds for the about:addons theme picker, which will make Firefox’s Nova UI use the colours of the system theme.
- Thanks to Simon Rosen for adding a new playback speed control to the PiP player. The feature can be enabled by flipping the pref media.videocontrols.picture-in-picture.playback-speed.enabled.
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- Benoit
- Chris Vander Linden
- Fede
- japandi
- Lukáš Lipinský
- Nirmal Advani
- Ruhollah Majdoddin
- Sameem [:sameembaba]
- Sebastian Zartner [:sebo]
- Zyphrenn
New contributors (🌟 = first patch)
- Aditi: Increase the maximum number of PDF.js preferences
- Fede:
- Giulio B: frameId is wrong in webRequest events triggered via importScripts
- 🌟 Gopalarathnam Venkatesan: Fix incorrect ‘this’ in the Sync add-on install error handler
- 🌟 Kevin Gosse: nsDataObj::QueryGetData in Firefox returns E_FAIL for formats it doesn’t carry, instead of DV_E_FORMATETC per the COM contract
- 🌟 mikey gough: Remove three unused devtools.debugger.file-search-* preferences
- 🌟 Nathan Leuz: Remove unused legacy preference browser.translation.neverForLanguages
- 🌟 Priyanshu[:0xanshu]: “Forget About This Site” dialog is cut off
- 🌟 K: Disable breakpoints shortcut
- 🌟 Shawn Zivontsis: Reorder moz_origins composite unique index to UNIQUE(host, prefix)
- 🌟 Simon Rosen: Suggestion: Add speed button for Youtube in picture-in-picture(PiP) modals
- tanvi.manku: unnecessary scrollbars in edit dialogs for payments and addresses
- Zyphrenn:
Project Updates
Add-ons / Web Extensions
Addon Manager & about:addons
- As part of Nova about:addons work:
- Replaced the “more themes” button in the themes list view footer with a promo element when Nova is enabled – Bug 2057200
- Removed the testing XPI base url pref from ThemesList.sys.mjs – Bug 2053220
- Fixed a mismatch between the popup panel border radius applied by Nova and the border radius applied to the document.body of the WebExtensions popup page loaded into it – Bug 2057844
- Moved new strings added as part of the about:addons Nova restyling out of the locales preview – Bug 2052034
- As part of legacy telemetry cleanups for the Add-ons related telemetry, migrated addons-search-detection telemetry off the legacy telemetry mirroring path, now collected only through Glean – Bug 2055606
WebExtensions Framework
- Fixed a series of intermittent and CI-reliability test failures across the WebExtensions browser-chrome test suite – Bug 1575369 / Bug 1697626 / Bug 1699341 / Bug 1974953 / Bug 2015004 / Bug 2030542 / Bug 2062186 / Bug 2062187 / Bug 2062189 / Bug 2062191 / Bug 2062193
- Thanks to Florian Quèze for applying his work on an LLM-based system for investigating intermittent tests to investigating and fixing intermittents and perma failures across the WebExtensions test suite.
DevTools
- Ruhollah Majdoddin fixed issues in the Storage panel to make sure we’re only showing relevant cookies (and their values) for the debugged tab (#1856645, #2060029, #2061166) and also did some cleanup in this area (#2061348)
- sevenwithawp added a keyboard shortcut (Ctrl+Alt+B, Cmd+Alt+B on Mac) to disable/enable breakpoints (#1642578)
- Hubert Boma Manilla (:bomsy) continues his work to display stylesheets in the Debugger (#2051029, #2051264)
- Preference: devtools.debugger.features.stylesheets-in-debugger
- Nicolas Chevobbe [:nchevobbe] added support for ::picker() rules in pseudo element section (#2042839)
- Used by customizable select (MDN)
- Preference: dom.select.customizable_select.enabled
- Nicolas Chevobbe [:nchevobbe] made CSS explainers work for substitution functions (var(), attr() and env()) (#2041622)
- Preference: devtools.inspector.css-explainers
- Julian Descottes [:jdescottes] fixed an accessibility bug in about:debugging where error message where not announced (#2056332)
WebDriver
- Sameem added the cleanup logic for subscriptions when a browsing context is destroyed.
- Nirmal Advani updated the Actions API to fire the dblclick event when performing a double-click while holding down the Ctrl key on non-macOS platforms.
- Khalid AlHaddad updated the webdriver bidi moz:debugging module to stop using enterNestedEventLoop which can avoid conflicts with the regular DevTools’ debugger.
- Alexandra Borovova fixed the “browsingContext.reload” command to not fail for frames.
New Tab Page
- Big ticket items:
- Did a trainhop last week to help with the remote layouts effort
- Doing another trainhop this week to make some spacing optimizations, deploying tomorrow if all goes well
- We will be experimenting with some more layout variations over the next few months
- Example:
- We’ve migrated a bunch of our unit tests to Jest/RTL from the deprecated Mocha / Karma framework we’ve historically used.
- Joel added a WebNotifications badge to Top Sites on the New Tab Page which surfaces per-origin unread web-notification state directly on TopSites tiles by rendering a compact badge in the activity-stream/TopSites component—users can now glance at NTP tiles to see which sites have pending web notifications without changing navigation or site state (affects desktop and mobile NTP Top Sites UI). This is something we plan on experimenting with later this year.
- Similarly, Joel added a TopSites hover card with notifications which expands the to show per-site notification items and actions on hover or long-press, enabling users to read and dismiss notifications from the NTP itself rather than opening each site.
- Hanna Alemu fixed the focus outline for the “Learn how we protect your data” link in NEWTAB_PERSONALIZATION_MESSAGE, replacing the blue non-rounded ring with the standard rounded focus style via CSS so keyboard and assistive users get a consistent, discoverable focus indicator.
- Maxx Crawford added logic to show different tip messages throughout the day/week on the New Tab Page in the upcoming privacy widget, implementing time-of-day/day-of-week selection in the tip renderer so users receive context-varying tips rather than a static message, which affects the tip surface and supports time-targeted experiments.
- Irene Ni removed the New Tab daily briefing slice from the New Tab Page, so users will no longer see the daily-briefing card on new tabs and related New Tab slice prefs/registrations were cleaned up.
- Jack Brown migrated the New Tab ContextMenu/LinkMenu implementation to the panel-list component, so right-click menus and link context behavior on the New Tab now use panel-list rendering (affects keyboard navigation, theming, and menu perf).
- Irene Ni removed a root-level <hr> selector from the Weather forecast widget SCSS that leaked global divider styles into the New Tab Page layout, restoring correct dividers and preventing spacing/layout regressions on about:newtab.
- Irene Ni enabled the remote-settings-driven sections layout in Nightly, flipping the remote-settings/sections layout so Nightly users receive Discovery Stream section composition from Remote Settings.
- Irene Ni automated the New Tab Page locales update for train-hop to ensure locale bundles are refreshed on train deploys so users see corrected translations and no longer encounter stale labels after a hop.
- Reem Hamoui fixed the Crossword widget double-counting and removed broad “interaction” user_actions so telemetry and UX-triggered actions reflect a single user event and analytics driven by user_action are no longer inflated.
- Dre fixed the “Show more widgets” visibility by adjusting the widget container overflow/visibility logic so the Show more control is reliably revealed on constrained viewports, restoring widget discoverability.
- Joel fixed newtab.closed and newtab.sections_impression firing unexpectedly on the New Tab Page by gating event emission on section visibility and tab lifecycle, which stops spurious impression and close telemetry pings and improves the accuracy of NTP impression/close counts for affected users.
- Joel added a topsite display customization event to newtab ping, updating the New Tab ping schema so user topsite layout and appearance changes are emitted as topsite.display_customization events, enabling reliable capture of pin/remove/resize/customization actions in Telemetry.
- Nina Pypchenko [:nina-py] added widgets.stocks.interaction and flip it on user actions so explicit click/tap interactions with the Stocks widget now generate widgets.stocks.interaction events, improving engagement capture for the Stocks surface.
- Nina Pypchenko [:nina-py] migrated the Stocks widget telemetry to the shared useWidgetTelemetry hook, standardizing how the Stocks widget emits metrics and ping fields to match other widgets, which reduces missing/duplicate events and makes per-widget telemetry consistent across platforms.
- Irene Ni created an initial JSON dump of Remote Settings sections layouts for cold startup to prepopulate New Tab Page sections on first launch and reduce layout flash or missing tiles.
- Nina Pypchenko [:nina-py] added a persistent “New” badge to the Stocks widget until first user interaction, which improves discoverability of the Stocks card and is cleared on the user’s first click/tap.
- Maxx Crawford implemented a side-by-side content layout variant for the New Tab Page feed, which introduces a new responsive layout option that changes feed column behavior and visual density on wider viewports.
- Scott Downe added support for five-column content feed layouts, which enables denser content grids for large displays by updating grid logic and responsive breakpoints and affects NTP rendering on wide screens.
- Dre added a “Celebrations” UI state to the Privacy Widget, which surfaces milestone/celebratory visuals and transient animations in the Privacy Widget when triggers are satisfied.
- Irene Ni updated the New Tab topsite context menu button to respect prefers-reduced-motion via CSS/media-query changes, so users with reduce-motion enabled no longer see the button’s motion/animation.
- Scott Downe expanded New Tab’s list of region and locales for content support, updating the New Tab content selection config and region→locale mappings so more users in newly-added locales receive localized tiles and recommendations on the New Tab Page.
- Irene Ni fixed the New Shortcut / Edit Shortcut prompt background being transparent with the Newtab addon installed, restoring CSS/background opacity for the edit UI so shortcut editing is readable across themes and addon combinations.
- Maxx Crawford added a dedicated trainhopConfig.widgetPrivacy payload for the Privacy widget feature, introducing a per-trainhop config payload in Discovery Stream so Privacy widget rollouts and toggles can be controlled without code deploys.
- Maxx Crawford added a layout management panel in Discovery Stream Admin, giving editors an admin UI to modify New Tab/stream layouts (reduces manual config edits and speeds layout experiments).
- Dre reduced the Privacy Widget celebration sparkles on the New Tab Page in Privacy Widget Celebration: Reduce the Sparkles by lowering particle counts and throttling animation cadence in the widget’s CSS/JS animation code, reducing visual noise and a small amount of GPU/animation work for users during the celebration without changing privacy settings.
- Maxx Crawford restored the “Change size” context menu item for the side-by-side experimental New Tab layout so users with the side-by-side exp layout enabled regain the resize control in widget context menus.
- Maxx Crawford stopped the sports widget from rendering regardless of the pref so unwanted sports content no longer appears on New Tab when the pref should prevent it.
Picture-in-Picture
- Thanks to Lukáš Lipinský for adding live event caption support for ceskatelevize.cz!
- Thanks to Mike Conley for fixing play / pause issues with the PiP player on Udemy.
Search and Urlbar
- Nova: continued work on the Nova redesign, focusing on CSS fixes, tab group and container styling, and tab/address bar polish. Efforts are underway to ensure the UI integrates correctly with platform themes and high-contrast modes.
- IPC Urlbar / Multi-Context Address Bar (MCAB) on New Tab: Significant progress has been made on the IPC Urlbar implementation. The CI variant is now live and upgraded to Tier 2, allowing for better bug detection. Currently focused on making content modules content-process-safe and preparing for new tab search bar integration. Here’s moz-urlbar rendering something on about:newtab for the first time:
- Post-MVP work continues on refining the new search bar that can be added to the toolbar.
- Google address bar messaging experiment relaunched.
- Search & Suggest Telemetry: Development is ongoing for search term telemetry, specifically regarding fetching results from Merino for online suggestions. Also preparing to retire legacy telemetry for certain search service metrics.
- Favicon & Places:
- Also trim www from URLs, behind pref
Jonathan Almeida
Perf wins from relocating MOZ_OBJDIR have a dev experience cost
This is the opposite of what I wanted to write about: relocating your MOZ_OBJDIR outside of your source directory will make your IDE faster.
In mozilla-central (the firefox monorepo), a default object files directory is created within the same source directory. This is equivalent to the build/ directory you would typically see in other projects.
While this is typically fine, I've found that Android Studio indexes many of these files and that can be slow when you're not working across all the layers in Gecko and Firefox. I ended up with these build directories that grew over time:
| Directory | Last touched | Size | Files |
|---|---|---|---|
| obj-aarch64-unknown-linux-android | 2025-11-04 | 29 G | 113,116 |
| objdir-desktop | 2025-11-04 | 19 G | 41,010 |
| objdir-frontend | 2026-09-09 | 6.3 G | 66,930 |
| obj-aarch64-apple-darwin24.5.0 | 2025-06-16 | 4 K | 1 |
That's a lot to index! I figured a way around this problem is to move the OBJDIRs out of the source directory and into something like ~/.mozbuild:
mk_add_options MOZ_OBJDIR="$HOME/.mozbuild/objdir-frontend"
While this does speed up IDE indexing, it's at the cost of developer experience, because now our generated code (e.g. FxNimbus) shows up as red symbols everywhere.
[insert sad trombone sound clip]
I'm uncertain if trimming what we index in these OBJDIRs is worth a large enough performance win, so for now I'll ensure I clean-up my stale copies which I'm not actively using.
About:Community
Game on: Play, share, and help shape Mozilla
P.S. Apologies for the delay in publishing this edition on the community blog. The original newsletter was sent to subscribers on August 27.
Firefox was leveling up in August! GeForce NOW arrived on Firefox for Windows, JPEG XL support was on the way, and the Firefox + NVIDIA teams joined forces for a Reddit AMA. We also invited SUMO and Mozilla Connect contributors to share their experiences through the Mozilla Contributor Survey, which has since closed (thank you to everyone who took the time to participate!).
Read on to catch up on what you may have missed and see what the community was up to!
GeForce NOW is now available on Firefox for Windows
Firefox has joined NVIDIA GeForce NOW’s supported browser lineup, making it possible to stream more than 2,000 PC games directly from Firefox on Windows. There are no downloads, installs, or hardware upgrades required! Just a Windows PC, a GeForce NOW account, and your existing game library.
Share your voice in the Mozilla Contributor Survey 2026
We’re gathering feedback from SUMO and Mozilla Connect contributors to help shape the future of Mozilla’s contributor community. The 2026 Contributor Survey explores what motivates you to contribute, what matters most throughout your contributor journey, and how we can improve areas such as onboarding, recognition, and the upcoming Mozilla Connect migration to SUMO. The survey takes about 10 minutes to complete and is now open until September 1, 2026, end of day UTC.
JPEG XL is coming to Firefox
Firefox plans to ship support for JPEG XL, a modern image format designed to deliver high-quality images more efficiently. With progressive rendering, images can start appearing before they have fully downloaded so it helps make pages feel faster, especially on slower connections.
From the Reddit Community
The Firefox and NVIDIA GeForce NOW teams are hosting a Reddit AMA on September 2 to celebrate GeForce NOW support on Firefox for Windows. Bring your questions about the integration, share your cloud-gaming setup, and let the teams know what else you’d love Firefox to support for online play.
P.S.
Enjoyed these updates? Subscribe to the Mozilla Community Newsletter and get the latest updates delivered straight to your inbox.
Firefox Tooling Announcements
Happy BMO Push Day! (20260908.1)
The following changes have been pushed to bugzilla.mozilla.org:
- Bug 1205300 - Missing: related documentation “Reporting”
- Bug 2068120 - Thunderbird access to “Iteration” and “Due Date” fields
- Bug 2066252 - Prevent save if keyword checkin-needed-tb exists without target milestone
- Bug 2070017 - Reinstate web bounty form
- Bug 2059948 - Do not offer printable recovery codes to Duo users
Discuss these changes in the BMO Matrix Room
1 post - 1 participant
Firefox Tooling Announcements
MozPhab 2.19.0 Released
Bugs resolved in Moz-Phab 2.19.0:
- bug 1987220
moz-phab patch --apply-to hereshould apply to the original base revision and rebase, rather than applying the raw diff on HEAD - bug 2016442 add
moz-phab listsubcommand
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
Thunderbird Blog
Desktop Settings: Removing technical jargon
Our goal for this phase of work is to remove the technical jargon, use plain language, and make it effortless for everyone to make informed decisions about their settings. With over 250 blocks of settings content to untangle, we aimed for incremental improvements rather than striving for perfection.
While our previous research leaned heavily on our technical power users, this round intentionally focused on new users to make sure Thunderbird is intuitive from day one.
Summary of research
- The new copy tested well: We achieved >80% comprehension across our tested copy for Notifications, Appearance, and Composition settings.
- High confidence levels: Users felt confident to change settings without external help (asking someone, referencing docs, or using AI for support).
- Interactions need refinement: We found spots where the interface didn’t always match expectations, like using a checkbox instead of an on/off toggle.
Using our content guidelines, we audited all 250+ content blocks to check accuracy, what was overly technical, and if anything was outdated. Our strategy was built up into steps to make it more achievable.
Step 1: Research & prioritization
Last month, we conducted research where we used a card sorting method to understand what users actually care about most and where they expect settings to live. Catch up on the Research Summary.
Step 2: Inventory audit
We mapped every piece of text in the app to build a full content inventory, assessing each piece of text for accuracy, freshness, and 8th-grade readability.
Step 3: Content redesign
We removed any developer or system updates from the interface and replaced it with language that speaks to what the setting actually does for the user.
Our findings
We tested prototypes for Notifications, Appearance, and Composition and asked 4 questions to test the purpose of each setting category, scenario comprehension, and user confidence. Our target threshold was 80% comprehension.
Here is how the new copy tested with room for improvement around the interactions, visuals, and how the language can be even more clear and user friendly.
| Settings Category | Purpose Comprehension | Scenario Accuracy | Confidence Score (out of 5) |
| Notifications | 86% | 71% | 4.00 |
| Appearance | 86% | 86% | 4.14 |
| Composition | 100% | 100% | 4.43 |
What’s next
- Improve the interactions: Aligning component types with immediate vs. batch actions so the UI behaves the way people expect.
- Sharper indicators: Testers liked the visual diagrams for Threaded, Unthreaded, and Grouped messages, but they need a bit more detail to make the visual distinction instant.
- Continue iterating on copy: Cleaning up remaining awkward phrasing (like Autosave 5 seconds) that still makes the experience feel slightly dated.
Next, we are taking everything we learned from this copy testing and applying it to the overall settings navigation and layout structure.
Redesigning settings isn’t always glamorous, which is why our team internally nicknamed this effort “Project Toto” inspired by high-tech Japanese toilets. Settings are something most people prefer not to think about, but when they are designed thoughtfully, the experience becomes seamless, intuitive, and surprisingly delightful.
As our new designs take shape, we’ll be reaching back out to both new and long-time users for feedback. Stay tuned for our next update, and let us know your thoughts in the comments!
The post Desktop Settings: Removing technical jargon appeared first on The Thunderbird Blog.
This Week In Rust
This Week in Rust 668
Hello and welcome to another issue of This Week in Rust! Rust is a programming language empowering everyone to build reliable and efficient software. This is a weekly summary of its progress and community. Want something mentioned? Tag us at @thisweekinrust.bsky.social on Bluesky or @ThisWeekinRust on mastodon.social, or send us a pull request. Want to get involved? We love contributions.
This Week in Rust is openly developed on GitHub and archives can be viewed at this-week-in-rust.org. If you find any errors in this week's issue, please submit a PR.
Want TWIR in your inbox? Subscribe here.
Updates from Rust Community
Official
Foundation
Newsletters
Project/Tooling Updates
Observations/Thoughts
- Microcontrollers with good support for Rust
- What Does a Governed Data Runtime Cost? TeaQL vs Diesel and SeaORM on MusicBrainz
- Stabilizing Rust's never type
- Searching through 150 GiB of Text per Second with SIMD
- Nine Rules for Compile-Time Work with Rust
const fn: Parse files, build tables, and catch mistakes … without a build script (Part 2) - A Design Space Exploration of Async/Await
- Rust: When Empty Isn't Bottom
Rust Walkthroughs
- What Rust's +simd128 Actually Changed in My WebAssembly
- Rust Control Flow in Practice - Build a Number Guessing Game
- Unsizing unsized values
- Game architecture
- Introducing CUDA Rust: Two Tracks for Writing GPU Kernels
- The State of Allocators in 2026 - 6 Months Later
- Visualizing Rust's Vtables: How dyn Trait Works In Memory
- Safely generating legal chess moves at 475,000,000 nodes/s
- Speeding up gearhash on ARM64 (2× faster)
- Let's build a compressor from scratch
- Reverse engineering my e-scooter and rewriting the firmware in rust
- Gloo + Yew for persistent webapp state
Miscellaneous
Crate of the Week
This week's crate is tokio-rcu, a user-space RCU implementation specifically built around the semantics of async rust and tokio.
Thanks to Roee Shoshani for the self-suggestion!
Please submit your suggestions and votes for next week!
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a
call-for-testing label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
RFCs
Rust
Rustup
If you are a feature implementer and would like your RFC to appear on the above list, add the new call-for-testing
label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature
need testing.
Call for Participation; projects and speakers
CFP - Projects
Always wanted to contribute to open-source projects but did not know where to start? Every week we highlight some tasks from the Rust community for you to pick and get started!
Some of these tasks may also have mentors available, visit the task page for more information.
- sysknife - action_reference_doc_is_current prints two 44 KB documents instead of the line that differs
- sysknife - packages/setup claims Node 18 support, and Node 18 has been end-of-life since 2025-04-30
- sysknife - cargo test fails intermittently on main: a test sets a process-global env var
If you are a Rust project owner and are looking for contributors, please submit tasks here or through a PR to TWiR or by reaching out on Bluesky or Mastodon!
CFP - Events
Are you a new or experienced speaker looking for a place to share something cool? This section highlights events that are being planned and are accepting submissions to join their event as a speaker.
- No Calls for papers or presentations were submitted this week.
If you are an event organizer hoping to expand the reach of your event, please submit a link to the website through a PR to TWiR or by reaching out on Bluesky or Mastodon!
Updates from the Rust Project
613 pull requests were merged in the last week
Compiler
- always rerun if we normalize local opaques
- optimize empty token streams
- store LiveLoans more densely packed
- use IndexVec instead of BTreeMap for polonius variances
Library
- add custom allocator support to
(try_)maponUniqueArcandUniqueRc - box: fixup
map/try_mapdeallocate calls - stabilize smart pointer map functions
Cargo
docs(lints): how to configure Cargo lintsdocs(trim-paths): add limitations and polishdocs(trim-paths): workspace remap begins with.fix(git): Apply pr hint to git-fetch-with-clifix(git): Make PR dep note cloer to our style guidefix(git): Simplify error messagefix(git): Use git's 429 retry, when availablefix(parser): Resolve theoretical use-after-free- avoid passing search path (-L) args when they are passed as --extern
- docs: switch from "target triple" to "target tuple"
- fix relative symlink handling in
write_atomic - fix(trim-paths)!: limit options to
none|object|all - fix(trim-paths)!: remove default scope from release profile
- fixed stale comment about fingerprint checking method
Rustdoc
Rustfmt
- fix non-idempotent block doc comment closer rewrite
- prevent infinite loops when parsing items from
cfg_select!arms
Clippy
unnecessary_self_imports: lint nested importslegacy_numeric_constants: make fixes machine-applicablestd_instead_of_core: don't suggest a path that does not resolveuseless_conversion: ignoreFrom::fromin generated codeuseless_format: improve suggestionregex_creation_in_loops: check MIR loop structure- check that intra-doc links are not broken
- detect integration tests in
is_in_test - do not trigger
integer_division_remainder_usedin macros - improve
map_unwrap_orlint to supportmap(f).unwrap_or_default() - move the
clippy_ci_panic_testintegration into a regular test - respect inline allows in
needless_pass_by_value - soft rename
clippy::alltoclippy::default
Rust-Analyzer
- add diagnostics for missing bodies for free and associated items
- fix
NamedTempFileconstructors - accept Self as non-leading path segment in attribute paths
- allow inner attributes on blocks in tuple expressions
- avoid type unification errors in term search
- fix handling of
#[unsafe()]attrs without inner meta - fix parsing of
self:: in fn param list - hover
1f64use float instead of integer - follow symlinks when scanning the sysroot for proc-macro dylibs
- install cargo tools with locked dependencies
- merge
hir_def::hir::Expr::UnsafeintoExpr::Block - render const value in completions label details
Rust Compiler Performance Triage
This week we've hit quite a few regressions, both expected and unexpected.
One of them has already been fixed, with fixes for a few others being discussed.
One big improvement comes from caching the sanitizer set in Session, which fixes a large regression from last week.
A few minor improvements landed, including a 75% reduction in memory usage while compiling bevy_render with the next trait solver.
Triage done by @JonathanBrouwer. Revision range: 5321a4f4..656a9da1
Summary:
| (instructions:u) | mean | range | count |
|---|---|---|---|
| Regressions ❌ (primary) |
0.5% | [0.1%, 1.3%] | 121 |
| Regressions ❌ (secondary) |
0.6% | [0.1%, 10.3%] | 106 |
| Improvements ✅ (primary) |
-0.6% | [-1.9%, -0.1%] | 63 |
| Improvements ✅ (secondary) |
-0.6% | [-2.4%, -0.1%] | 65 |
| All ❌✅ (primary) | 0.1% | [-1.9%, 1.3%] | 184 |
3 Regressions, 2 Improvements, 8 Mixed; 6 of them in rollups 33 artifact comparisons made in total
Calls for Testing
An important step for RFC implementation is for people to experiment with the implementation and give feedback, especially before stabilization.
If you are a feature implementer and would like your RFC to appear in this list, add a
call-for-testing label to your RFC along with a comment providing testing instructions and/or guidance on which aspect(s) of the feature need testing.
No calls for testing were issued this week by Rust, Rustup or Rust language RFCs.
Let us know if you would like your feature to be tracked as a part of this list.
Approved RFCs
Changes to Rust follow the Rust RFC (request for comments) process. These are the RFCs that were approved for implementation this week:
- Rustdoc LaTeX math
- RFC: Cargo feature descriptions
- Change
i686-pc-windows-msvcfrom Tier 1 with host tools => Tier 1 without host tools
Final Comment Period
Every week, the team announces the 'final comment period' for RFCs and key PRs which are reaching a decision. Express your opinions now.
Tracking Issues & PRs
- riscv: stabilize 'd' and 'f' target features
- x86: on targets that requires SSE, use those registers for ABI
- Re-export
core::fmt::NumBufferinalloc(andstd) - fix: unfulfilled nested dead code lint
- turn aligned-in-packed error into lint
- Guarantee 8 bytes of alignment of RawWakerVTable
- libtest: Allow passing --test-threads and --color multiple times, with later arguments overriding earlier
- Stabilize
core::mem::DropGuard
No Items entered Final Comment Period this week for Rust RFCs, Compiler Team, Language Team or Leadership Council. Let us know if you would like your PRs, Tracking Issues or RFCs to be tracked as a part of this list.
New and Updated RFCs
- No New or Updated RFCs were created this week.
Upcoming Events
Rusty Events between 2026-09-09 - 2026-10-07 🦀
Virtual
- 2026-09-09 | Virtual (Cardiff, UK) | Rust and C++ Cardiff
- 2026-09-10 | Virtual | Rust 🦀 Maven
- 2026-09-10 | Virtual (Berlin, DE) | Rust Berlin
- 2026-09-10 | Virtual (Nürnberg, DE) | Rust Nuremberg
- 2026-09-15 | Virtual (Washington, DC, US) | Rust DC
- 2026-09-16 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-09-17 | Hybrid (Seattle, WA, US) | Seattle Rust User Group
- 2026-09-18 | Virtual | Rust Girona
- 2026-09-20 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-09-22 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-09-24 | Virtual (Berlin, DE) | Rust Berlin
- 2026-09-24 | Virtual (Charlottesville, VA, US) | Charlottesville Rust Meetup
- 2026-09-29 | Virtual (London, UK) | Women in Rust
- 2026-10-02 | Virtual | Rust Girona
- 2026-10-04 | Virtual (Dallas, TX, US) | Dallas Rust User Meetup
- 2026-10-06 | Virtual (London, UK) | Women in Rust
- 2026-10-07 | Virtual (Indianapolis, IN, US) | Indy Rust
Europe
- 2026-09-10 | Geneva, CH | Rust Geneva
- 2026-09-14 - 2026-09-16 | Berlin, DE | Oxidize 2026
- 2026-09-15 | Leipzig, DE | Rust - Modern Systems Programming in Leipzig
- 2026-09-15 | Madrid, ES | MadRust
- 2026-09-17 | Dortmund, DE | Rust Dortmund
- 2026-09-22 | Prague, CZ | Rust Prague
- 2026-09-24 | Aarhus, DK | Rust Aarhus
- 2026-09-24 | Amsterdam, NL | Rust Developers Amsterdam Group
- 2026-09-24 | Frankfurt, DE | Rust Rhein-Main
- 2026-09-28 | Augsburg, DE | Rust Meetup Augsburg
- 2026-09-29 | Manchester, UK | Rust Manchester
- 2026-09-30 | Basel, CH | Rust Basel
- 2026-10-05 | München, DE | Rust Munich
North America
- 2026-09-08 - 2026-09-11 | Hybrid (Montreal, CA) | RustConf 2026
- 2026-09-09 | Montreal, CA | Women in Rust
- 2026-09-10 | Lehi, UT, US | Utah Rust
- 2026-09-10 | San Diego, CA, US | San Diego Rust
- 2026-09-12 | Boston, MA, US | Boston Rust Meetup
- 2026-09-15 | San Francisco, CA, US | San Francisco Rust Study Group
- 2026-09-16 | San Francisco, CA, US | Bay Area Rust
- 2026-09-16 | Hybrid (Vancouver, CA) | Vancouver Rust
- 2026-09-17 | Hybrid (Seattle, WA, US) | Seattle Rust User Group
- 2026-09-17 | Mountain View, CA, US | Hacker Dojo
- 2026-09-19 | Boston, MA, US | Boston Rust Meetup
- 2026-09-23 | Austin, TX, US | Rust ATX
- 2026-09-24 | Atlanta, GA, US | Rust Atlanta
- 2026-09-26 | Boston, MA, US | Boston Rust Meetup
- 2026-10-01 | Saint Louis, MO, US | STL Rust
- 2026-10-03 | Boston, MA, US | Boston Rust Meetup
Oceania
- 2026-09-29 | Barton, AU | Canberra Rust User Group
If you are running a Rust event please add it to the calendar to get it mentioned here. Please remember to add a link to the event too. Email the Rust Community Team for access.
Jobs
Please see the latest Who's Hiring thread on r/rust
Quote of the Week
The Demon has access to a Super Turing Machine.
Thanks to Theemathas for the suggestion!
Please submit quotes and vote for next week!
This Week in Rust is edited by:
- nellshamrell
- llogiq
- ericseppanen
- extrawurst
- U007D
- mariannegoldin
- bdillo
- opeolluwa
- bnchi
- KannanPalani57
- tzilist
Email list hosting is sponsored by The Rust Foundation
Firefox Nightly
Motion, Colour, Captions, Kit – These Weeks in Firefox: Issue 207
Highlights
- Want some Kit? Check out the store!
- Sebastian Zartner [:sebo] added a panel to expose @media emulation (#1692434) and provided a way to emulate @media (prefers-reduced-motion: reduce) (#1477920)
- More theme controls have been added to the New Tab customization panel:
- Improved Picture-in-Picture caption support from some volunteer contributors
- Thanks to Lukáš Lipinský for adding caption support to Česká televize!
- Thanks to kernp25 for adding caption support to ardmediathek.de!
Friends of the Firefox team
Resolved bugs (excluding employees)
Script to find new contributors from bug list
Volunteers that fixed more than one bug
- :Vincent
- japandi
- Nirmal Advani
- Sebastian Zartner [:sebo]
- tanvi.manku
New contributors (🌟 = first patch)
- Aditi: Increase the maximum number of PDF.js preferences
- 🌟 Anil Verman: [Docs] Trigger listeners doc is seriously out of date
- Fede: more than six thumbnails needed when Ctrl+Tab is used
- Giulio B: frameId is wrong in webRequest events triggered via importScripts
- 🌟 Luiz Henrique Vieira: Remove dead CSS rule .alltabs-item[selected=”true”]
- 🌟 Devin Rousso: `emulation.setLocaleOverride` does not override `Accept-Language` header for in `Worker` for `fetch` and `WebSocket`
- 🌟 muhammad shaikh: Profile delete page heading should enclose profile name in quotes
- 🌟 Kevin Gosse: nsDataObj::QueryGetData in Firefox returns E_FAIL for formats it doesn’t carry, instead of DV_E_FORMATETC per the COM contract
- Lukáš Lipinský: Česká televize captions do not display in the Picture-in-Picture window
- 🌟 mikey gough: Remove three unused devtools.debugger.file-search-* preferences
- 🌟 Nathan Leuz: Remove unused legacy preference browser.translation.neverForLanguages
- 🌟 Shawn Zivontsis: Reorder moz_origins composite unique index to UNIQUE(host, prefix)
- tanvi.manku:
- 🌟 Tim McNulty: Remove always-true clause from NS_ASSERTION in nsNavBookmarks::AdjustIndices (Coverity CID 1274453)
Project Updates
Add-ons / Web Extensions
Addon Manager & about:addons
- As part of Nova about:addons work:
- Introduced a shared localization module for built-in and curated AMO-hosted theme names, and updated the corresponding about:addons theme test to expect the new “Default” theme name shown when Nova is enabled – Bug 2055936 / Bug 2058235
- Added a message bar to the about:addons themes picker to surface AMO-hosted Nova theme download and install failures instead of failing silently – Bug 2054548
WebExtensions Framework
- Fixed a startup race where an extension’s restored dynamic content scripts could be missing from the parent WebExtensionPolicy due to stale shared data – Bug 2058719
WebExtension APIs
- Fixed publicSuffix.isKnownSuffix() to reject invalid domain-name characters, including wildcard suffixes, that could previously be matched as a known public suffix – Bug 2059819
- Fixed the frameId reported by webRequest events for requests made from workers, including importScripts()-loaded scripts, which were previously attributed to the wrong frame – Bug 2048884
- Thanks to Giulio B for the fix to webRequest frameId attribution for worker requests.
DevTools
- Benoit made it possible to display JSON Lines (JSONL/NDJSON) documents in the JSON Viewer (#2055774)
- Leo McArdle [:leo] continues his quest to add MDN icons next links to MDN (#2049610, #2050159)
- Julian Descottes [:jdescottes] vastly improved DevTools screenshot performance (by up to 35%) (#2056716)
- Hubert Boma Manilla (:bomsy) fixed keyboard navigation for about:debugging (#2050797)
- Julian Descottes [:jdescottes] fixed a bug that was preventing to show error messages in about:debugging (#2058021)
- Nicolas Chevobbe [:nchevobbe] made ::checkmark pseudo element visible in the Inspector (#2009909)
- Used by customizable select (MDN)
- Preference: dom.select.customizable_select.enabled
WebDriver
- Nirmal Advani cleaned up our codebase by removing the executeSoon helper, which was just a thin wrapper on top of Services.tm.dispatchToMainThread().
- Sameem removed support for the “contexts” argument in the “session.unsubscribe” command. From now on, clients can unsubscribe only by event names or subscription ids.
- John Schanck added support for validating if an authentication id is stored in the Virtual Authenticator Database.
- Alexandra Borovova disabled the download panel to prevent the loss of the focus of the current document when a download begins.
Fluent
Lint, Docs and Workflow
- Sylvestre has converted all our in-tree documents to be Markdown instead of reStructuredText.
- Standard8 adjusted the source doc upload task, that runs on code review, to report failures into phabricator, rather than having a generic error message.
- Standard8 made it so that test-manifest-toml issues for out-of-order entries should show up in phabricator more often.
- https://arewemozsrcyet.com/ continues to head (mostly) in the right direction.
New Tab Page
- HNT Eng had a work week last week. Did a lot of prep for big cleanups (Nova, Widget cleanup post WCW)
- Also worked on ways to automate trainhops / make them easier to deploy
- Jack Brown updated newtabTrainhopAddon to allow co-enrollment and prioritize the highest version number, which ensures the New Tab Page picks the newest addon build when multiple enrollments overlap and prevents older experiment variants from replacing newer installs.
- Fred Chasen fixed AccuWeather sponsored text overlapping the “Tell us what you think” link by adjusting medium weather card CSS (z-index and pointer-events), restoring hover and click behavior for the feedback link on affected New Tab Page cards.
- Mike Kaply fixed wallpaper uploads failing when the wallpaper list can’t be queried from remote settings by adding a remote‑settings query fallback/local cache and defensive error handling so users can upload custom wallpapers during remote‑settings outages or timeouts.
- japandi added the widgets.clocks.interaction pref and wired interaction tracking so World Clocks now emits telemetry/events for taps and opens (pref registration + tracker hooks), enabling accurate UX metrics without changing visible UI behavior.
- Maxx Crawford prevented the weather widget from activating without user opt‑in by gating activation on the opt‑in pref and updating the onboarding flow, so weather and related location/telemetry remain disabled by default until explicit user consent.
- Irene Ni made the New Tab client request layouts from remote-settings so NTP layouts and remote-config-driven content now update on load instead of remaining stale; this fixes cases where layout changes pushed via the remote-settings service (layouts collection) weren’t applied, improving consistency on desktop and Android clients that rely on remote layouts.
- Nirmal Advani removed three unused activity-stream preferences (discoverystream.thumbsUpDown.*) from prefs and related code paths, reducing prefs surface area and avoiding confusion in about:config/telemetry without changing user-visible behavior.
- Mike Conley fixed ExternalComponentWrapper to forward “live” properties like isIntersecting from MessageWrapper, restoring correct IntersectionObserver-driven behavior (visibility-based lazy-load and impression tracking) for remote components in the New Tab Page and discovery streams that relied on isIntersecting for render/telemetry triggers.
- Irene Ni standardized New Tab widgets and sections header spacing (standardize spacing) to remove misaligned tiles and reduce visual jitter when resizing or toggling sections in the New Tab Page.
- Mike Conley removed version-153 train-hop compatibility shims for the World Cup newtab logo variations (remove compatibility shims), an internal cleanup that prevents legacy logo-selection fallbacks from influencing current logo variations.
- Maxx Crawford exposed available browser themes to New Tab and added apply/install actions (expose and apply themes), allowing users to install or immediately apply themes from the New Tab surface via ThemeManager/Theme API hooks.
- Maxx Crawford added New Tab Customize Panel browser theme selection strings (add theme selection strings) so the new theme-selection UI is localized and displays correct labels across locales.
- Maxx Crawford added a full browser theme selection sub-panel to the New Tab Customize Panel (theme selection sub-panel) to let users browse, preview, and pick themes directly inside the New Tab customization flow.
- Scott Downe fixed Custom newtab wallpapers flash / blink some seconds after loading newtab by ensuring the custom wallpaper is painted only after image data is ready, which removes the multi-second visual flash on about:newtab for users with custom backgrounds and improves perceived stability during initial new-tab load.
- Maxx Crawford exposed trainhopConfig values in Discovery Stream Admin tooling, giving operators direct access to trainhop routing/weight values from the admin UI/API so content trains and experiment routing can be adjusted without code deploys—this has no immediate end-user UI change but reduces time-to-rollout for Discovery Stream content changes.
- Dre fixed Newtab custom wallpapers flash when selecting from picture of the day widget by deferring the wallpaper swap until the selected Picture of the Day is decoded and ready, which prevents the transient blank/flash users saw when changing wallpapers via the widget and makes wallpaper selection feel instantaneous and stable.
- Maxx Crawford used the POTD thumbnailUrl image for the widget background (instead of the high-res image), which reduces bandwidth, memory footprint, and New Tab Page widget load latency for users who see the Picture‑of‑the‑Day widget.
- Kyle Jones added MAC support to TopSitesFeed when fetching tiles from MARS, which enforces authenticated tile retrieval and reduces missing/401 tile failures for users relying on MARS‑served Top Sites tiles.
Performance Tools (aka Firefox Profiler)
- Bug 2050028 – Enable the Gecko profiler by default with low-overhead features when running mochitests landed, which means mochitest failures now upload profiles by default:
- https://tests.firefox.dev/try.html can give you a prompt to ask an AI agent to look at the profile for you using profiler-cli:
- https://tests.firefox.dev/try.html can give you a prompt to ask an AI agent to look at the profile for you using profiler-cli:
Search and Urlbar
- Dao and Moritz continue work on MCAB working on making the address bar’s contents to be content-process-safe and preparing to allow cross-process IPC for the address bar.
- Mike Kaply fixed hidden actions still visible in Quick Actions mode.
- Daisuke and Drew continued work on supporting Nova on the address bar and search bar components.
- Caleb continued work to use array–binding for places sql queries, to improve performance.
The Rust Programming Language Blog
Rust debugging survey 2026 results
One of the biggest challenges Rust developers report in our annual surveys is a subpar debugging experience. So, back in February, we ran our first Rust Debugging Survey, in the hopes of identifying how Rust developers are using debuggers and what problems they are facing when doing so. We received over 2,300 responses, and we'd like to thank everyone who took the time to participate in the survey!
In this report, we'll go over some of the results of the survey. If you'd like, you can also check out the complete results of the survey.
If you'd like to skip ahead to any particular section, you can do so with this index:
Who Uses Debuggers?
The first step to making sense of the survey results is understanding who took the survey. We asked respondents to rate their Rust expertise, from "Never used it" to "Advanced". Over 80% reported themselves as "Advanced" or "Intermediate", split roughly evenly between the two:
We also asked respondents if they currently use or have used debuggers in Rust. Over 46% said they currently do, with the remaining responses split between "have in the past" and "never have". That means that over half of respondents do not currently use a debugger for Rust!
Categorized by expertise, the responses reveal that roughly half of "beginners" have never used debuggers in Rust! On the other hand, nearly half of "advanced users" currently do use debuggers in Rust:
For respondents who indicated they had previously used Rust but no longer did, we asked if challenges with debugging support were why they stopped. For nearly 3%, the answer was "yes", with an additional 24% reporting debugging issues as being partially responsible (though mind the small response count; most respondents were active users of Rust):
How Are Debuggers Used?
Knowing what debuggers developers are using and how is another important part of
understanding the challenges they face. To this end, we asked respondents how
they were debugging their programs. Unsurprisingly, most developers make use of
print debugging and the dbg! macro. Excluding those, using lldb inside an
IDE was the most popular choice, followed by gdb on the command line:
We can get a more detailed breakdown of these results if we include the
operating system on which the respondents use a given debugging approach. We
examine this from two different angles. The first angle being, "On operating
system X, what percent of responses are using debugger Y?". Print debugging and
the dbg! macro are consistently the top two yet again, but looking beyond
that, things get more interesting. On Linux, using gdb on the command line was
the most popular choice by a thin margin, beating lldb in an IDE by only 0.4%.
On Windows, Windows Subsystem for Linux (WSL), and macOS, lldb in an IDE was
the top pick by at least 6%, making it a very popular choice in general. On
Windows, the three least popular choices were the command line debuggers (gdb
CLI, lldb CLI, and BugStalker), and on both Windows and macOS the third most
popular pick was, "I don't know". Those who were debugging on operating systems
not listed (Other) most frequently used some kind of special embedded debugger
or gdb:
The other angle we can look at these responses from is, "For users of debugger
X, what percent of responses are using it on operating system Y?". For most
debuggers, Linux makes up the largest portion of uses, ranging from about 45% to
about 77%, followed by Windows, then macOS. The most notable exceptions are
WinDbg and the Visual Studio debugger, which are primarily used on Windows, and
lldb, which is used more on macOS than Windows in an IDE and on the command
line:
To the 6 respondents who use WinDbg on Linux: we wish you luck!
As for how people actually use their debugger of choice, the aggregate results are not particularly surprising. Roughly 87% of users are using debuggers for stepping line-by-line through programs and a little over half of users are using debuggers to obtain stack traces from hung/crashed processes. Only a quarter of the respondents use a debugger to debug async code. That might be partially caused by the async Rust debugging experience being clumsy and incomplete, or it could just be that users aren't writing much async code:
If we break these results down by expertise, we can learn a bit more about usage patterns. As users become more experienced with Rust, their use of debuggers for learning purposes decreases, and they get more stack traces from crashed processes:
The final bit of insight into how Rustaceans use debuggers is if they are debugging programs that use Rust alongside other programming languages. For 44% of respondents, the answer is "yes", which is a pretty high number!
As for which languages those are, C dominates the scene at a little over 70%, followed by C++ at about 43% and Python at about 20%:
Challenges
Instead of diving right into asking, "what problems do you face when using debuggers?", or something to that effect, we first asked respondents why they decide against using debuggers whenever they do, including for reasons that aren't necessarily "problems with debuggers".
The most commonly reported reason was that it was easier or faster to use logs or print debugging to solve problems, reported by a little over 81% of respondents. This could partially be explained by the open responses, which featured complaints that debuggers were too difficult to set up and/or use (especially on Windows, when dealing with Web Assembly, or in embedded contexts) and sentiment suggesting that small and/or simple problems just don't really need a debugger. It does leave one wondering if the user experience could be made convenient enough to dethrone print debugging, but it seems hard to beat something so intuitive. This is followed by roughly 37% of respondents who write code that Just Works. Fair enough. After that, about 26% of respondents indicated that they've decided not to use debuggers in situations where the language features they were working with had poor support. This is slightly more than issues with standard library types, at about 22%, which is slightly more than issues with external library types, at about 20%:
As stepping through code was anticipated to be one of the most common uses for debuggers, we directly asked respondents if they faced any issues when doing so. A little over 51% of respondents said they did! Of those who reported that they experienced issues stepping through code, we asked when they were experiencing issues. Async code was the most common case reported at slightly over 28%, followed by code involving macros at about 23%. The least common case reported was code involving function pointers, at almost 6%:
We also directly asked respondents which types in the standard library were hard
to work with, if any. This was an open-response question, and reading through
the responses, some particularly common complaints were with enums and
collections, particularly std::collections::HashMap and std::vec::Vec. This
is also visible in the word cloud in the full report.
We asked respondents to indicate which pain points, if any, they have encountered when using debuggers with Rust. At slightly over 74%, poor representation of values was the most common pain point by a decent margin, followed by being unable to print variables at just over 55%:
Debugger Visualizers
We asked respondents to indicate if they were library authors, and if so, if
they were aware of and using the debugger_visualizer attribute. Nearly 62% of
respondents indicated that they were library authors who were not aware of this
attribute:
For those who indicated that they were library authors who knew about the attribute but did not use it, we also asked why. This represented a much smaller fraction of respondents, so keep that in mind! That said, half of these library authors indicated that they didn't have the time to maintain visualizer attributes, and just under half indicated they didn't know how to write visualizer scripts:
For those of you who have been reading this section asking yourself what the
debugger_visualizer attribute is, you can read up on it in
The Rust Reference: Debugger Attributes. The quick
explanation is that the debugger_visualizer attribute can be applied to
modules or the crate root to embed files in the debug information which improve
the display of values with certain debuggers. The two currently supported file
types are Natvis files, used by Microsoft debuggers such as WinDbg, and GDB
"pretty printers", which are structured Python scripts used by GDB.
Closing Remarks
Thanks to your participation in this survey, we've gained some great insights
about how Rustaceans are using debuggers and what issues they are facing. For
example, knowing that such a high number of users are dealing with poor
representation of values pairs well with knowing which standard library types
are causing issues, knowing that many library authors haven't heard of the
debugger_visualizer attribute, and knowing that many of those who have but
don't use it either don't know how or don't have time to maintain visualizer
scripts.
Looking to the future, the survey results have suggested that there are a few notable ways we could most significantly improve the debugging experience in Rust, such as:
- Fixing the way
enums are represented by debuggers so they show actual variants - Fixing the way collections (such as
HashMap) are represented by debuggers so they show their contents, rather than their implementation details - Fixing the way string types (such as
StringandCString) are represented by debuggers so they render as text, rather than their implementation details - Improving the
asyncdebugging experience, particularly with stack traces - Improving stepping through certain state machines (such as iterators and
Futures) - Providing documentation on basic set up and use of some common debuggers
A common suggestion that could resolve those first three points is to use the
Debug implementation of types to display them in debuggers. There are
challenges to that approach, such as the fact that the Debug implementation is
not present in the final binary unless it is actually used somewhere in the
program, but it isn't impossible. Notably, this is already supported by the
BugStalker debugger (given the same condition that the Debug
implementation must actually be used), which some of you first heard about from
the survey! It also appears to have some support for async, with plans to
expand.
One notable way the debugger experience is currently being improved is through the ongoing Google Summer of Code project improving how we test debug info and visualizer scripts, making it easier to maintain and improve our own visualizer scripts and general compatibility with visualizer scripts without silent breakage or regressions.
Once again, we'd like to thank everyone who took the time to participate in the survey!
Firefox Tooling Announcements
Firefox DevTools MCP 0.10.2 released
Firefox DevTools MCP (firefox-devtools-mcp) 0.10.2 is out on npm.
New tools:
press_key— sends a single key, optionally with modifiers, to a snapshot element or the focused element (Return, Escape, Tab, arrows, ctrl+shift+t, …).type_text— types text key by key into the focused element, with an optional key to press afterwards.set_network_cache— bypass or restore the HTTP cache, for the selected tab or browser-wide. Useful before a performance measurement or when verifying a change a cached asset would otherwise hide.
Other changes:
navigate_pageandnew_pagetake an optionalwaitargument (none, interactive, complete), so an agent can wait for the load event before deciding a page is done.- Windows: per-user Firefox installs are now detected, instead of failing with “unable to find binary in default location”.
- aarch64 Linux: geckodriver is now resolved on all platforms, fixing “Unable to obtain browser driver” when a native geckodriver is on PATH.
- Several Windows path fixes for --output-file, --log-file and saveTo.
- New generated reference page documenting every tool and its parameters: docs/tools.md (firefox-devtools-mcp/docs/tools.md at main · mozilla/firefox-devtools-mcp · GitHub)
Install:
claude mcp add firefox-devtools npx @mozilla/firefox-devtools-mcp@latest
codex mcp add firefox-devtools – npx @mozilla/firefox-devtools-mcp@latest
For internal Firefox development, swap firefox-devtools-mcp with firefox-devtools-mcp-moz in order to benefit from additional tools, such as chrome-privileged script execution.
Special thanks to all the contributors who filed issues and submitted patches for this release: freema, f3tch (github), jasonanovak and shoemoney.
Full changelog: https://github.com/mozilla/firefox-devtools-mcp/releases/tag/v0.10.2
Repository and issues: GitHub - mozilla/firefox-devtools-mcp: Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi · GitHub
Public chatroom: https://chat.mozilla.org/#/room/#firefox-devtools-mcp:mozilla.org
1 post - 1 participant
Firefox Tooling Announcements
PerfCompare just deployed (Sept 3, 2026)
The latest version of PerfCompare is now live! This includes the launch of PerfCompare’s Simple View. Read the following blog post, Introducing PerfCompare’s Simple View, to learn more.
Check out the change-log below to see the updates:
Highlights:
[kala-moz]
-
Bug 2059826 - Simplified View: Create checkbox selection for advanced columns and display how to read the results #1069
-
Bug 2059830 Simplified View: Create checkbox selection for expanded row components (#1089)
-
Bug 2068296 Simplified View Follow up for expanded view (#1094)
-
Bug 2058240: Filters from cookies don’t make it into the URL (#1076)
-
Simplified View Follow-up: reduce size of cols and link subtest pills to subtests page (#1083)
Other changes:
[kala-moz]
-
Removed silverman and kde warnings (#1082)
-
Bug 2059493: Clean up components in perfcompare frontend using the unecessary silverman_kde data (#1079)
-
Fix for Bug 2060613: PerfCompare statistical analysis has some NaN values in explanations (#1077)
[gopar]
[bug-2021092] Update light/dark toggle wording to be less ambiguous (#1073)
Thank you for the contributions!
Bugs or feature requests can be filed on Bugzilla. The team can also be found on the #perfcompare channel on Matrix. Come and chat!
1 post - 1 participant
Mozilla Performance Blog
Introducing PerfCompare’s Simple View
We heard you. You don’t want to open your PerfCompare performance comparison and feel like you need a background in statistics to interpret the Mann-Whitney-U results. Cliff’s Delta, CLES, and normality tests, oh my! It should not feel like you’ve blindly walked into a college stats exam, unless of course, you love statistics. For the rest, all you want is an easy answer to the question: Did my changes make things faster or slower?
So we fixed that. PerfCompare now shows the bare essentials by default and tucks the heavy statistics one click away.
An approachable default for beginners and occasional users
The results table now leads with the platform, the Base and New values, how far the median moved and its direction, the status (which includes the option to filter out noise) and the size of the change. To create a more advanced view, a single “Advanced options” dropdown allows you to add the expert columns (Cliff’s Delta, CLES, Significance) and the info-rich expanded row details below the full-width graph. A small help section at the top of the results provides a quick explanation of the columns. The purpose is to serve a diverse audience while preserving your selections in the URL so a shared link reproduces your view.
The “Advanced options” dropdown lets you add the precise statistics columns:
- Cliff’s Delta: An effect-size measure of how far the Base and New distributions have pulled apart
- CLES (Common Language Effect Size): The chance a random New run beats a random Base run, e.g. “New wins 78% of the time”
- Significance: Whether the difference is a real signal or just noise
Each one toggles on independently, so you can surface only Significance or the whole trio.
Expand a result and you get a clean panel: a full-width graph of how your Base and New runs are spread out, a quick summary (platform, app, which direction is “better”), and a little “how to read this graph” tool-tip for anyone who hasn’t stared at a distribution curve before. You can still poke at the graph’s mode controls if you want to dig in.
You can access the extra expanded row details such as effect size and confidence intervals or the full stats table in the “Advanced options” dropdown. Turn on what you need, and the expanded extras lay out in neat two-column rows. If you turn on mode analysis and there aren’t multiple modes to show, we now say “No mode analysis available” instead of a blank space.
Lastly, the advanced columns and expanded-row details you’ve switched on, along with your filters and sorting, are all encoded in the URL. Paste it to a coworker and they’ll land on the same result you were looking at; for filters and sorting, the shared link takes precedence over whatever they had saved locally. (One exception: the “How to read the results” panel is a personal per-browser preference, so it stays with you rather than tagging along on the link.)
What’s next
Several follow-ups on the way:
- Remembering your advanced choices. Right now the advanced columns and expanded-row toggles start from the clean defaults each visit (they only persist in a link). Soon PerfCompare will remember them in your browser the same way we do for filters. However, if you open a shared link from a colleague, their specific view takes priority, overriding your own local settings so you both see the exact same data.
- Carrying your selections into subtests. Today, the Advanced options you pick on the main results page don’t follow you when you open a test’s subtests. We’re wiring it up so whatever you’ve enabled up top is automatically enabled in the subtests dropdown too, for one consistent view.
- Expanding the “How to read the results” cheat sheet to include Cliff’s Delta, CLES, and Significance definitions.
Share your feedback
We want PerfCompare to work for all users, whether you’re chasing your first regression, or you’re an expert who doesn’t want to lose their favorite metrics to a cleaner view. Our answer is separating the simple view from the power user view, and making the toggle obvious and shareable.
The great news is it’s live now! Go expand a Mann-Whitney-U result, click around the Advanced options, and tell us what you think. Please share your feedback, suggestions, or comments on the #perfcompare channel on Matrix. If you’ve encountered a bug or have a feature request, please file them in Bugzilla. We’re listening.
Firefox Tooling Announcements
Firefox Profiler Deployment (September 3, 2026)
The latest version of the Firefox Profiler is now live! Check out the full changelog below to see what’s changed:
Highlights:
- [Andrew Creskey] Show which network requests were prefetched (#6259)
- [Florian Quèze] profiler-cli: accept --limit 0 as unlimited, and make truncation loud (#6267)
Other Changes:
- [Nazım Can Altınova] Update oxfmt 0.59.0 → 0.63.0 (major) (#6262)
- [Florian Quèze] profiler-cli: document the marker field:value search syntax (#6265)
- [Florian Quèze] profiler-cli: report one time base for text and JSON output (#6266)
- [Florian Quèze] profiler-cli: avoid a stack overflow on large marker threads (#6264)
- [Markus Stange] Give the frameTable a lib column (#6258)
- [Florian Quèze] profiler-cli: report the network request count the filters ran against (#6274)
- [Nazım Can Altınova] Fix dark mode contrast of the warning icons in the publish panel (#6280)
- [Nazım Can Altınova] Extract the publish panel warning indicator into a small component (#6282)
- [Markus Stange] More typed arrays in the FrameTable (and a flags column) (#6173)
- [Nazım Can Altınova] Improve the profiler-cli publish script and document the whole deployment in a better way (#6260)
- [fatadel]
Sync: l10n → main (September 3, 2026) (#6301) - [fatadel] Bump profiler-cli version to 0.9.0 (#6302)
Big thanks to our amazing localizers for making this release possible:
- es-CL: ravmn
- nl: Mark Heijl
- sv-SE: Andreas Pettersson
- sv-SE: Luna Jernberg
- sv-SE: Peter Kihlstedt
- tr: Selim Şumlu
- tr: giray
- zh-CN: 高乐喆
Find out more about the Firefox Profiler on profiler.firefox.com! If you have any questions, join the discussion on our Matrix channel!
1 post - 1 participant
The Rust Programming Language Blog
Announcing Rust 1.98.1
The Rust team has published a new point release of Rust, 1.98.1. Rust is a programming language that is empowering everyone to build reliable and efficient software.
If you have a previous version of Rust installed via rustup, getting Rust 1.98.1 is as easy as:
rustup update stable
If you don't have it already, you can get rustup from the appropriate page on our website.
What's in 1.98.1
Rust 1.98.1 fixes a miscompilation in vtable generation.
In Rust 1.98.0, in some circumstances, rustc would incorrectly generate a trait object vtable with a null pointer where a function pointer should be. This leads to undefined behavior in the emitted code. In some cases this may 'just' cause segfaults due to the null pointer being loaded, but it is possible for it to be justification for arbitrary effects (as is typical for UB).
If you'd like to help us out by testing future releases, you might consider
using the beta (rustup default beta) and nightly (rustup default nightly) channels locally and in your CI. Please
report any bugs you
might come across!
Contributors to 1.98.1
Many people came together to create Rust 1.98.1. We couldn't have done it without all of you. Thanks!
Thunderbird Blog
Thunderbird Desktop New Protocol Support: Microsoft Graph API
As many of you know, Microsoft will be disabling Exchange Web Services (EWS) support on its Microsoft 365 platform later this year. The Thunderbird Desktop team has been hard at work to ensure continuity of functionality through this transition, and today we are pleased to announce the release of native Thunderbird support for the Microsoft Graph API! Curious what this means for you? Then keep reading to find out!
IMAP and EWS and Graph, Oh My!
When connecting to either on-premises or hosted Microsoft accounts, Thunderbird users now have an array of options. Users might not know which option is best for their case, so we’ll start with a little bit of guidance to help users decide what will be best for them. First off, if you are currently using IMAP with an on-premises Exchange account or a Microsoft 365 hosted account, and it’s currently working for you, then there’s nothing you need to do! EWS and Graph support are for users whose organizations do not allow IMAP access.
Now for the more complicated part. Last year, we released EWS email support for both on-premises Exchange accounts and Microsoft 365 hosted accounts. If you are using the EWS protocol with an on-premises Exchange account, then you don’t need to do anything.
However, if your organization uses Microsoft 365 for email, and you’re currently using EWS to connect to that account, then you need to take action before October of this year. Earlier this year, Microsoft announced that they would begin a phased shutdown of EWS on Microsoft 365/Exchange Online starting in October of 2026 with the goal of a complete shutdown in 2027. If you are currently using Thunderbird’s EWS support to connect to a Microsoft 365/Exchange Online email account, then you will need to switch to the Microsoft Graph API support to keep using Thunderbird beyond these dates. See below for details.
So the TL;DR is:
- IMAP for on-premises or Microsoft 365 hosted email => No action required.
- EWS for on-premises Exchange => No action required.
- EWS for Microsoft 365/Exchange Online => Set up a new Microsoft Graph account in Thunderbird.
Microsoft only supports the Graph protocol on Microsoft 365, so that is the only provider that offers it. On-premises Exchange servers do not implement the Graph API, so Thunderbird’s EWS support will continue to be the primary mechanism for users on these servers to connect to their email accounts.
Microsoft Graph Account Set Up
Thunderbird does not support migrating accounts to different protocols. Instead, you will need to set up a new account. If you have an existing EWS-connected Microsoft 365 account, first you’ll need to delete that account in Thunderbird. You can do this from the account settings. Deleting the account locally in Thunderbird will not affect any data stored on Microsoft 365, so your data is safe.
Once your previous EWS account has been deleted, you can use Account Hub to set up a new account. In the new account set up dialog, enter your Microsoft 365 hosted email account. Thunderbird should automatically detect that your email is hosted on Microsoft 365 and will give you a few options for getting connected. Choose the Microsoft Graph option, and you should be good to go! If for some reason automatic configuration doesn’t work, you can still configure your account manually using these instructions.
What is currently supported?
As with EWS, Thunderbird’s current Graph support extends only to email. Thunderbird does not yet support Calendar and Address Book functionality with either EWS or Graph.
What’s in ESR?
Thunderbird’s current Extended Support Release, version 153, supports the EWS protocol, but does not support the Microsoft Graph API, which was first enabled in the Thunderbird Release channel in version 154. Users on the ESR channel who are using Microsoft 365 will need to migrate to the Release channel in order to use the Microsoft Graph API support to continue accessing Microsoft 365 hosted mailboxes.
What’s Next?
Calendar and Address Book! The Thunderbird Desktop team has already started working on support for connecting to Microsoft 365-hosted calendars using the Graph protocol. We will be busily working on this throughout the rest of the year. As with our previous work on Thunderbird support for EWS, this is the first new calendar protocol to be added to Thunderbird in many years. We are currently doing some up-front design work to ensure a sustainable product going forward and hopefully make the next calendar protocol easier to add.
How can users give us feedback?
As with all new functionality, there may be features we are missing or unexpected issues. As always, Bugzilla is always open! You can send us feature requests and issue reports using this Bugzilla link. Thunderbird’s greatest strength is its community of users, developers, and supporters who help us deliver the best tools we can to connect people with one another. We welcome community involvement to help us make everything better!
Nitty-Gritty development details
Those of you who have followed along with development throughout EWS and into Graph support might have noticed that, compared to EWS, we were able to implement support for the Microsoft Graph API relatively quickly. This is largely due to the up-front thought and work that went into the design and development of Thunderbird’s EWS support. The Graph implementation was the team’s first test of the extensibility of the new architecture, and we were very pleased with the results. It took 11 months to enable basic synchronization with EWS. With the new architecture, we were able to cut that time down to 4 months with Graph.
Graph’s operations are similar to the operations that EWS provides, but different enough that it served as a great first test case for how the new email client architecture can support future protocols, such as JMAP. Given the results of the Graph implementation, we are optimistic that the same architecture will extend to JMAP once the team decides to move forward to that new protocol. We are hopeful that what we have built here can provide a sustainable base on which to build future protocol support in Thunderbird.
This would not have been possible without many contributions from Thunderbird developers, past and present, and the community of users who have helped us improve Thunderbird by submitting issue reports and feature requests. We are grateful to everyone for their support!
The post Thunderbird Desktop New Protocol Support: Microsoft Graph API appeared first on The Thunderbird Blog.
The Mozilla Blog
AI on your terms: Firefox meets you where you are
People feel differently about AI, and here at Firefox, we think that is completely reasonable. Something else that is completely reasonable: deciding for yourself how and when you engage with AI features.
For some of you, AI is part of your everyday life, whether you are using it to summarize a large amount of information, brainstorm ideas for work, or research trips and personal purchases. Some of you interact with AI as little as possible, and prefer to keep it that way. And a lot of you are somewhere in between: curious, but exploring on your own terms and at your own pace.
Your personal use of AI is just that, personal. Firefox offers various levels of AI integration into your browser, and the choice between them is entirely yours.
Block new and current AI features in a single switch
Opting out of upcoming and current AI features on your browser should not require endless navigation through multiple Settings pages. That’s why Firefox offers an AI controls section within its General Settings panel. A single, easily located place where you can block current and future AI features and related pop-ups with the swipe of a toggle.
Not only do we want people to have the choice to remove certain AI features from their Firefox browsing experience, we make sure doing so is as easy and accessible as possible.
Choose the features that work for you
For the many people who sit in the middle of the AI usage spectrum, we made sure you can opt in and out of specific features in line with your preferences. Capabilities like AI translations, image alt text in Firefox PDF viewer, tab group suggestions, and key points in link previews can all be individually switched on and off, ensuring you can enjoy such offerings on a case by case basis as it suits your needs.
In addition, if there is an AI chatbot provider you already trust or pay for, you can use it directly inside Firefox’s built-in desktop sidebar. This means you can use your chatbot of choice and browse side by side without ping-ponging between tabs.
While some browsers integrate a singular AI model or chatbot into their system, this can restrict flexibility and concentrate data sharing. Firefox prioritizes transparency and user control by letting you select from multiple providers, allowing you to review each option’s policies before you engage with them.
You can turn on AI chatbot providers in the AI controls section of browser settings and select one of the following: Anthropic Claude, ChatGPT, Google Gemini, and Le Chat Mistral. Once this feature is turned on, you can switch between chatbots within the sidebar itself based on your preferences and task at hand.
Smart Window, for when you want help finishing what you started
Smart Window is Firefox’s most integrated AI experience, but that doesn’t mean it compromises our commitment to choice, privacy, and transparency. Our newest window type, which we’ve been polishing and testing in beta, uses only the context you share with it to help you move work forward and across the finish line.
When permitted by you, its built-in, AI-powered assistant can work directly with your open tabs and browsing history to connect the dots. This means comparing information, generating recommendations, summarizing pages, and planning projects without having to feed every crumb of context from your previous and current browsing activity each time you enter a new prompt.
As we’ve built out Smart Window, we’ve added a few additional features to align its design with how people actually browse. These include the ability to group related tabs together – so you can make sense of what’s open without spending time organizing everything yourself – and visual history previews that help you spot a page you visited earlier when you can’t remember the exact URL or phrase searched. In addition, a new partnership with Exa enables Smart Window to not only locate current web information to include in responses, but also display the sources behind these responses so you can verify what you’re seeing, without breaking your flow.
We understand people use different Firefox windows for different reasons, and often switch between options based on the task at hand. Smart Window is the window you reach for when your browsing turns into a project. When your quick search becomes inspo for the girls’ trip you’ve been meaning to plan, or finding the perfect gift for your partner becomes a dozen tabs comparing prices and reviews, turn the window you’re already using into a Smart Window. Your tabs and progress stay in place while Smart Window helps organize the task and move it forward. Use it for one complex project, use it all the time, or switch it back when you’re done.
Smart Window remains in beta as we continue to learn and improve from our community’s feedback. At present, it’s available in English to people in the U.S. and Canada.
To try Smart Window, visit: https://www.firefox.com/smart-window
Always your call
Your opinions and preferences on AI usage are individual to you.
We don’t think there is one right answer for how and when to engage with AI, and we’re not going to pretend there is one. What we can do is make sure that whatever level of engagement is right for you, Firefox supports it well. Because the only person telling you how much AI you need should be you.
The post AI on your terms: Firefox meets you where you are appeared first on The Mozilla Blog.
Firefox Developer Experience
Firefox WebDriver Newsletter 155
WebDriver is a remote control interface that enables introspection and control of user agents. As such, it can help developers to verify that their websites are working and performing well with all major browsers. The protocol is standardized by the W3C and consists of two separate specifications: WebDriver classic (HTTP) and the new WebDriver BiDi (Bi-Directional).This newsletter gives an overview of the work we’ve done as part of the Firefox 155 release cycle.
Contributions
Firefox is an open source project, and we are always happy to receive external code contributions to our WebDriver implementation. We want to give special thanks to everyone who filed issues, bugs, and submitted patches. In Firefox 155, several WebDriver bugs were fixed by contributors:
- Khalid AlHaddad updated the Mozilla-specific
moz:debuggingmodule to no longer rely on the same nested event loop API as DevTools, which prevents conflicts when WebDriver BiDi and DevTools are used in parallel. - Nirmal Advani cleaned up our codebase by removing the executeSoon helper, which was just a thin wrapper on top of Services.tm.dispatchToMainThread().
- Nirmal Advani fixed the Actions API so that the
dblclickevent is fired when performing a double-click while holding down theCtrlkey on non-macOS platforms. - Sameem added the cleanup logic for subscriptions when a browsing context is destroyed.
- Sameem removed support for the
contextsargument in thesession.unsubscribecommand. From now on, clients can unsubscribe only by event names or subscription ids.
WebDriver code is written in JavaScript, Python, and Rust, so any web developer can contribute! Read how to set up the work environment and check the list of mentored issues for Marionette or the list of mentored JavaScript bugs for WebDriver BiDi. Join our chatroom if you need any help to get started!
All Changes
A complete list of developer-facing changes included in this Firefox release is available in the MDN Firefox 155 Release Notes.
Mozilla Privacy Blog
Browsers compete on privacy. When the operating system allows.
For more than two decades, Mozilla has advocated for an internet where people, not powerful platforms, determine how technology works for them. Meaningful consumer choice requires more than the ability to select a browser. People should also be able to choose what their browser can do, from the privacy protections it provides to the ways they can customize their experience.
A recent Firefox product initiative brings that longstanding policy concern into focus.
Firefox is bringing a built-in Ad Blocker to Firefox for iOS, giving people an optional way to reduce intrusive ads and ad-related trackers while browsing. The feature uses an EasyList-based filter list and Apple’s WebKit Content Blocker framework. It is off by default and can be enabled or disabled at any time.
The feature responds to years of requests from Firefox users on iPhone. It also illustrates a wider policy problem: dominant mobile platforms can determine which privacy and customization tools competing browsers are able to offer.
On Firefox for desktop and Android, people can install add-ons that change how they experience the web.
Almost 40% of all Firefox users take advantage of this functionality. They include content blockers, accessibility tools, password managers and other extensions that allow people to shape their browser around their own priorities.
Firefox cannot offer that same add-on ecosystem on iOS. Apple’s App Review Guidelines generally require apps to remain self-contained and restrict them from downloading or executing code that introduces or changes an app’s functionality.
Apple also controls the conditions under which browsers may use alternative browser engines, with entitlement pathways available only in certain jurisdictions and subject to detailed requirements that no browser developer has been able to meet. In practice, the combined effect of Apple’s app distribution and browser policies prevents Mozilla from bringing the full Firefox add-on experience available on other platforms to iPhone users.
This is not simply a technical inconvenience but a competition and consumer-choice problem.
A mobile platform owner controls the operating system, the primary app-distribution channel and its own browser.
When that company can also determine which technologies, add-on models and operating-system capabilities competing browsers may use, it sets the boundaries within which browser competition takes place.
Operating system restrictions can prevent independent browsers from differentiating themselves.
Even when users want browsers to differentiate on privacy, operating system restrictions can prevent independent browsers from doing so. They can also force browser developers to recreate individual tools as platform-specific, built-in features rather than allowing people to choose from a broader add-on ecosystem. That increases development costs, slows or restricts innovation and produces uneven experiences across devices.
The new Firefox Ad Blocker is a practical response to those constraints. It gives iPhone users more control today using the technical options currently available to us. But building one feature directly into a browser is not a replacement for a healthy, independent add-on ecosystem. It addresses a specific capability gap for Firefox users on iOS at this time.
A competitive browser ecosystem should focus on the entire user experience.
The EU’s Digital Markets Act has shown that policy interventions can improve user choice, with Mozilla and other browsers reporting significant growth following the introduction of browser choice screens. However, meaningful browser competition must extend to the full user experience. This includes whether people can easily choose and change their default browser. It also includes whether people can benefit from the full set of innovations developed by rival browsers by ensuring adequate interoperability with the operating system. With this deeper focus on the full user experience, people can benefit from differentiated privacy and security features.
People’s privacy choices should not depend on whether a dominant platform permits their browser to offer them.
The post Browsers compete on privacy. When the operating system allows. appeared first on Open Policy & Advocacy.
The Mozilla Blog
Introducing Ad Blocker for Firefox on iOS: More control, fewer distractions
There’s only so much room on your screen. Pop-ups, overlays, and ads can take over fast, getting between you and what you came to do.
That’s where Ad Blocker for Firefox on iOS comes in: a built-in option that blocks many third-party ads and ad-related trackers before they load, helping reduce clutter and distractions while you browse.
How it works
Ad Blocker uses Apple’s WebKit Content Blocker technology and the EasyList filter list to determine what gets blocked. There’s no separate extension to install, and you can turn it on in Settings > Browsing > Ad Blocker. It’s off by default, so you decide whether to use it.
Ad Blocker won’t block every ad. Ads served directly by the site you’re visiting and ads shown in search results will still appear. Sponsored shortcuts and other sponsored content shown by Firefox when you open a new tab are separate from ads on the web pages you visit, so Ad Blocker doesn’t affect them.
Ad Blocker works alongside the privacy protections already built into Firefox, including Enhanced Tracking Protection, which blocks many trackers and limits tracking across the web.
More control over how you experience the web
On Desktop and Android, Firefox already supports a strong ecosystem of ad-blocking and privacy extensions, giving people the flexibility to choose the tools that work best for them. We value that ecosystem and will keep supporting it.
iOS works differently. Extensions aren’t available in the same way, and we know people want more options. Bringing ad blocking to Firefox on iOS meant building it directly into the browser.
Giving people choice in how they experience the web is important to us. Advertising helps fund much of the open web, supporting the publishers, creators and websites people rely on. We also know that ads can sometimes crowd the screen or interrupt what you’re trying to do.
That’s why Ad Blocker is optional: you decide whether it’s part of how you browse. It’s part of a broader approach across Firefox to give you more control over your experience, from the extensions you use to how AI shows up in your browser.
Try it
To turn on Ad Blocker, go to Settings > Browsing > Ad Blocker.
If you find an ad you expected to be blocked, a site that behaves strangely or something we should improve, let us know on Mozilla Connect.
Visit our Support page for more details on Ad Blocker for Firefox on iOS. For more on Firefox’s built-in privacy protections, check out How Firefox Protects Your Data.
The post Introducing Ad Blocker for Firefox on iOS: More control, fewer distractions appeared first on The Mozilla Blog.
The Rust Programming Language Blog
Announcing rustup 1.29.1
The rustup team is happy to announce the release of rustup version 1.29.1.
Rustup is the recommended tool to install Rust, a programming language that empowers everyone to build reliable and efficient software.
What's new in rustup 1.29.1
The headlines of this release are:
-
Concurrency in certain
rustupoperations has been improved: -
Implicit installation of the active toolchain in
rustup-initandrustupinvocations has been deprecated where deemed unnecessary and will now produce a warning. pr#4840- Please see our blog post for more details regarding this change.
-
rustup docnow supports the--serveflag which allows serving the docs over local HTTP. This should help users with containerized browser and/or rustup setups. pr#4986 -
Installing
i686-pc-windows-*host toolchains on 64-bit Windows now requires--force-non-host. pr#4935 -
rustup-initwill no longer leave unexpected files on disk after cancelled installations. pr#4996 -
A bug has been fixed which might cause Windows installation to fail when using
rustup-init.sh. pr#4756 -
"Target triple" has been renamed to "target tuple" across the project to reflect the new terminology. pr#4743 pr#4827 pr#4834
- Please note that this is not a breaking change in the CLI since the existing
options such as
--targetare not using this terminology.
- Please note that this is not a breaking change in the CLI since the existing
options such as
In addition, rustup now officially supports aarch64-pc-windows-gnullvm as a host platform. pr#4523
Further details are available in the changelog!
How to update
If you have a previous version of rustup installed, getting the new one is as easy as stopping any programs which may be using rustup (e.g. closing your IDE) and running:
$ rustup self update
Rustup will also automatically update itself at the end of a normal toolchain update:
$ rustup update
If you don't have it already, you can get rustup from the appropriate page on our website.
Rustup's documentation is also available in the rustup book.
Caveats
Rustup releases can come with problems not caused by rustup itself but just due to having a new release.
In particular, anti-malware scanners might block rustup or stop it from creating or copying
files, especially when installing rust-docs which contains many small files.
Issues like this should be automatically resolved in a few weeks when the anti-malware scanners are updated to be aware of the new rustup release.
Thanks
Thanks again to all the contributors who made this rustup release possible!
Mozilla Privacy Blog
How Challengers Thrive and Competition Survives In Today’s Ecosystem
The web should be a place where people can choose how they connect, which tools they use, and who they trust. At Mozilla, we live these values, prioritizing products that ensure users can control their experience and that the web remains a global public resource.
Challengers across the tech ecosystem provide these competitive opportunities, but they contend with structural barriers imposed by tech giants leveraging market dominance. A healthy internet depends on ensuring that independent companies have a fair opportunity to innovate and compete on merit. That’s why Mozilla and many others support key legislation like AICOA.
So how do we promote proposals like AICOA and ensure that challengers can thrive in markets controlled by powerful gatekeepers? We explored these questions and more at the recent Mozilla Meetup, “How Challengers Thrive: Why Competition Matters for AI, Security, and the Open Internet.” Across panel events, a lightning discussion, and a networking happy hour, we discussed promoting an innovative, secure internet.
Partnering with Internet Works, Mozilla invited leading minds in tech policy to explore the importance of Middle Tech, AI’s impact on security and competition, and new research on deceptive design practices. Below are some highlights.
On today’s competition landscape, and Middle Tech as a user-first alternative:
Peter Chandler, Executive Director, Internet Works:
“Less competition equals less innovation equals less choices for consumers. It’s that simple.”
Charlotte Slaiman, Principal, Charlotte Slaiman Impact Advising:
“There are all sorts of reasons that competition is not just a click away. There are lock-in effects. There is gatekeeper power. Those things are protecting incumbents and making it much harder for consumers to switch to an alternative.”
On the impact of deceptive design tactics:
Gemma Petrie, Principal Researcher, Competition & Regulation, Mozilla:
“For independent browsers like Firefox, dominant operating systems are both the gateway to consumers and the direct competitor. When these platforms use harmful design to undermine free choice, this is not simply inconvenient. It can create consumer harm by overriding informed choice, social harm by eroding public trust in technology, and market harm by undermining competition and innovation.”
On the role of AI in competition and security:
Helen Toner, Executive Director, Georgetown’s Center for Security and Emerging Technology (CSET):
“It is really notable that in open source software, if you have more eyes on software and you can identify vulnerabilities, that makes it easier and quicker to patch those vulnerabilities to solve the problem. With AI, often we actually don’t have very good solutions when we identify problems, when we identify security risks, and so I think that can change some of the dynamics.”
Chris Lewis, President & CEO, Public Knowledge:
“We have an opportunity. It’s not too late in the AI era to not only design for competition through open technology, open source AI, model weights, some of the things we heard in the introduction, but also to set policies that promote competition.”
Avery Gardiner, Director of Global Competition Policy, Spotify:
“A big part of what I’m thinking about with AI is how quickly it allows us to innovate as an app developer, right, and how quickly we can speed up our coding, bring more features to consumers, bring more things to market, and be better at innovating for the consumer. And all of our competitors can do the same thing. So there’s this remarkable thing where the AI opportunities, the AI services, are getting better every passing day.”
There’s a reason we convene this community. As the web becomes both more complex and even more integral to our lives, competition offers people the ability to make meaningful choices about privacy, security, and control. Competition fosters innovation and spurs better products and services. Now is a particularly important moment to advance these priorities.
The post How Challengers Thrive and Competition Survives In Today’s Ecosystem appeared first on Open Policy & Advocacy.
Mozilla Localization (L10N)
Minding My Language: My Internship Story
Hello everyone! It’s Jamie. My internship at Mozilla is quite unfortunately coming to an end, after which I will be heading back to study at the University of Toronto. In this post, I want to share a rundown of my story working on the Localization (L10N) team, break down the projects I built, and reflect on what made this experience so special.
The First Day
Before joining Mozilla I was quite a bit nervous, as I had never worked at such a large organization before. The first day shattered this perception, as getting an office tour and having a live Q&A with VPs of Engineering really set the expectations of what working at Mozilla would be like.
The Toronto office became the go-to place for connecting with passionate, mission-oriented people across different teams. After getting my computer set up, I immediately got to work on Pontoon, Mozilla’s Translation Management System (TMS). Since Pontoon’s codebase relies on React and Django — frameworks I’ve worked with before — I was able to set up my local environment running smoothly and ship code early on. Over time, I had the opportunity to meet my fellow interns, each on their own teams, and we had chances to bond over our shared experiences and different problems.
Since Mozilla is a remote-first company, the L10N team is distributed across Europe and North America. Working with them was an absolute highlight. To put it simply, they are a brilliant group of people of engineers, project managers and open-source contributors who keep Mozilla, and by extension, the wider web open and accessible.
So, what was working at Mozilla like?
Working at Mozilla, I had the opportunity to contribute to a variety of features involving Pontoon, associated localization workflows and other cool projects. During the duration of my internship, a great deal of localization related work was centralized and continues to be that way, which significantly influenced the projects that I worked on, and more generally, how the L10N team will continue to operate when I am gone.
This work unfolded against the backdrop of an ever changing technological landscape, particularly involving industry adoption of AI tools for code generation. In 2025 and 2026, agentic coding assistants like Claude Code and Cursor began to achieve mass adoption in software development. At Mozilla, I was introduced to Claude Code as a tool later in my internship, which was excellent, as it allowed me to gain a broad understanding of how the codebase worked without the use of AI. After the introduction of Claude Code to my workflow, I was able to push code and conduct code reviews on a much greater scale. I appreciate that Mozilla does not shy away from the practical uses of AI, especially in the realm of improving engineer and localizer workflows, and importantly, making it a choice.
The Work
Here is a shortlist of the varying projects I had the opportunity to work on at my time with the L10N team.
GraphQL Deprecation and REST API Implementation
The first task I was assigned to primarily revolved around the deprecation of Pontoon’s public-facing GraphQL API endpoints in favor of a Django REST Framework implementation. The motivations for this project included a preference for simplicity, desire for faster API response times and consistency with existing vanilla Django REST endpoints. The new public facing API lives here.
Personal Access Tokens
The next project I was given was to devise a new personal access token (PAT) implementation in Pontoon in order to gate permissions to the newly created REST API endpoints. I was inspired by the way that GitHub did their Classic personal access tokens so I tried to model my design around their implementation as much as possible.
Pontoon Translation Search
The next project I took up was to reduce the feature gap between Pontoon and Transvision. For context, Transvision was and is used for searching available translations of strings across certain Mozilla products. It uses GitHub as its primary source, which is why it is limited only to the big projects. Thus the motivation was to create a similar service directly on Pontoon that has the most up to date strings with all Mozilla products, with data manipulation and access being a non-issue due to existing on Pontoon directly. Translation Search lives here.
Taking responsibility for Pontoon Add-on
The Pontoon Add-on was a community maintained browser extension that enabled localizers to keep track of their locale’s progress and receive any notifications from Pontoon directly in the browser. As part of the Pontoon API rework mentioned earlier, we needed to refactor the add-on code in order to maintain functionality. The main contributor had limited availability to continue maintaining the add-on anymore, so Mozilla assumed ownership of the extension, and we managed to clean up some of the backlog and redeploy.
Firefox for Android localization workflow changes
For years, Firefox Desktop and Firefox for Android used to operate under different localization workflows. Firefox for Android’s workflow was written such that Android developers needed to maintain deprecated strings to prevent previous versions of localizations of Firefox for Android breaking. Firefox Desktop does not have this issue due to different logic, so I rewrote the whole Firefox for Android workflow to be closer in substance to Firefox Desktop’s localization process. This subsequently deprecated the need for Android engineers to maintain the string deprecation process needed, which was great.
Insights Project Manager Dashboard and Alert system
The last main feature set I worked on was the Insights dashboard and accompanying alert system. For context, the Project Managers on the L10N team needed to calculate a score assigned to locales each month for community health analysis purposes using a mish mash of spreadsheets and Python scripts. This project automated the capture and calculation of these statistics to the first of each month and displayed them on a dashboard along with other useful information. The alert system was also implemented which notifies admins of significant changes of scores for specific locales, so certain locales can get increased focus.
Final Thoughts
Working at Mozilla has undoubtedly been an enriching experience. I have met a great number of incredible people who have guided me, encouraged me and shaped me into a better engineer and a better person. It has certainly widened my perspective on localization as a global effort, where peoples across different languages, cultures and creeds can work together to build a better web. I leave with sharper technical skills, amazing memories, and zero regrets, only immense gratitude for the opportunity to contribute to software that empowers millions. 🙂
Acknowledgements
To Matjaž (engineer and mentor): Your presence has been invaluable, both as a mentor and a friend. Thank you for your patience with my 10 PM deployment requests, endless questions, and edge-case bugs.
To Flod (manager): You are as always the backbone of the team, and have certainly taught me many lessons regarding leadership, professionalism and dependability. Thank you for reminding me about my deadlines and being the go-to for questions and feedback.
To Eemeli (engineer): Your Zoom call escapades have always been inspiring to me, from burning detritus, cooking random stuff, remote data lag spikes and such much more. I truly wish to become like you with such a vast and bottomless knowledge for so many facets of software engineering, before AI completely rots my brain.
To Ayush (fellow intern): I hope my mentorship was as helpful to you as your camaraderie was to me. You are going to accomplish great things, my friend.
To Eric (engineer): I very much enjoyed your unique German humor, your kindness and passion for building cool technologies.
To Camila (PM): Your personality is incredibly energetic, and I’m sure you will continue to bring so much positive energy to the team. I hope that you continue to be ambitious in everything that you do.
To Eda (PM): I really hope you enjoy working as part of the L10N team. I hope that you continue to make an excellent contribution to Mozilla!
Thank you for reading about my time at Mozilla! If you would like to learn more or wish to connect, feel free to contact me on LinkedIn.
Fin.
The Servo Blog
July in Servo: more platforms, faster canvas, web fonts in SVG, and more!
Servo 0.5.0 contains all of the changes we landed in July, which came out to 488 commits, and we now publish binaries for Linux aarch64 (@mukilan, #46760)!
DOM text selections are now visible (@mrobinson, @SimonSapin, #46698, #46864, #46742, #46889, #46126). Interactive selection is coming soon!
For security fixes, see § Security.
We’ve shipped several new web platform features:
- ‘Cache-Control: stale-while-revalidate’ (@arayaryoma, #46060)
- ‘text-decoration-thickness’ (@nicoburns, #46592)
- ‘box-decoration-break’, for the most part (@Psychpsyo, #45492)
- ‘@font-feature-values’, for the most part (@simonwuelker, #45308)
- ‘font-language-override’, for the most part (@simonwuelker, #46618)
- ‘font-variant-alternates’, for the most part (@simonwuelker, #45308)
Plus a bunch of new DOM APIs:
- Ed448, X448, and KMAC algorithms in SubtleCrypto (@kkoyung, #46402, #46141, #46180, #46583, #46606, #46622, #46334, #46376)
- ‘insertHorizontalRule’, ‘insertImage’, ‘insertText’, and ‘forwardDelete’ commands in document.execCommand() (@Psychpsyo, #46608, #46597, #46538, #46838)
- AnimationEffect (@simonwuelker, #46677)
- new Touch() (@yezhizhen, #46741)
- duplex property on Request (@Taym95, #46858)
- effect property on Animation (@simonwuelker, #46677)
- getKeyframes() and setKeyframes() on KeyframeEffect (@simonwuelker, #46118)
- id property on LargestContentfulPaint (@shubhamg13, #46828)
- read-only CSSFontFeatureValuesRule (@simonwuelker, #46728)
This is another big update, so here’s an outline:
You can help!
If you’re working on a pull request that you think might be interesting for the next monthly update, even if you’re not 100% sure, tell us about it by following the steps below:
-
You add the monthly update label to your pull request, or comment
@servo-highfive monthly update -
Highfive posts a comment asking you some questions
-
You answer those questions in a comment containing
@servo-highfive monthly update answer
Security
Servo was potentially affected by vulnerabilities in quick-xml and crossbeam-epoch that have been fixed in Servo 0.5.0 (@atouchet, @Loirooriol, #46737, #46324). For more details, see RUSTSEC-2026-0194, RUSTSEC-2026-0195, and RUSTSEC-2026-0204.
We’ve updated ANGLE from a version based on Firefox 115.x ESR (02755361e26d8) to a version based on Firefox 140.12.0 ESR (f8025617e815f), which likely includes many security fixes (@jschwe, @sagudev, #46455, mozangle#100).
Real world compat
The duck on the DuckDuckGo (duckduckgo.com) landing page now renders in v0.5.0, after we fixed a preload bug that affected SVG images (@jdm, #46668).
Most of Gumroad (gumroad.com), except for the landing page, did not render at all in v0.4.0, but as of v0.5.0, pages like the Discover page or this product page render almost perfectly.
We’re interested to hear how well your favourite websites run in Servo! Report successes in this Zulip thread, and failures in our GitHub issues.
Work in progress
The upgrade to Stylo 2026-07-01 brings several changes to built-in CSS functions (@Loirooriol, #46129):
-
‘alpha()’ is now supported, under
--pref layout_css_alpha_color_function_enabled -
‘progress()’ is now supported, under
--pref layout_css_progress_function_enabled -
‘ellipse()’ values ‘closest-corner’ and ‘farthest-corner’ are no longer stable due to spec uncertainty, but they are still experimental, under
--pref layout_css_ellipse_corners_enabled -
‘attr()’ is more conformant, under
--pref layout_css_attr_enabled
WebGPU content can now enjoy better conformance and use GPUExternalTexture and importExternalTexture() on GPUDevice, under --pref dom_webgpu_enabled (@sagudev, #45873, #46178, #46286).
IndexedDB content can now use the name property on IDBIndex, under --pref dom_indexeddb_enabled (@skyz1, #45512).
document.fonts now includes a FontFace for each valid ‘@font-face’, under --pref dom_fontface_enabled (@simonwuelker, #46509, #46537).
All of the features above are enabled in servoshell’s experimental mode.
We’ve started implementing WebVTT for native subtitles and captions, enabled by default (no --pref).
While they don’t render just yet, we can now fetch each <track src>, parse the WebVTT, and expose cues via the track property on HTMLTrackElement (@TimvdLippe, #46289, #46383).
July was a big month for accessibility in Servo, under --pref accessibility_enabled.
The focus for this month has been on performance, with the accessibility tree now supporting incremental updates (@alice, @delan, #45578, #45971, #46589, #46691, #46385), requiring fewer HashMap lookups and tree walks (@alice, @delan, #45798, #46740, #46348), and allowing for faster DOM mutations (@alice, #46348, #46530).
We’ve also started working on the File and Directory Entries API, to allow users to select and upload entire directories via <input type=file> and drag-and-drop.
To that end, we now have webkitGetAsEntry() on DataTransferItem, plus minimal support for FileSystemEntry, FileSystemDirectoryEntry, and FileSystemFileEntry, under --pref dom_entries_api_enabled (@yezhizhen, #46456, #46879, #46832).
Embedding API
We’ve improved the docs for the servo crate, and for WebViewDelegate (@mukilan, #46193).
Breaking change: ServoBuilder::webxr_registry() has been removed.
Instead use the new Servo::register_webxr_registry, which is a lazy design that has allowed servoshell to halve its startup time (@Narfinger, #46494).
For users and developers
servoshell for Android now runs on Android 10+ (91% market share), not just Android 13+ (68% market share), improving adaptability and reducing waste (@jschwe, #46142, #46308). We’ve also fixed a problem with building for Android on macOS (@jschwe, #46128).
servoshell for Windows is now better behaved when run in a console window, making the command prompt wait until servoshell exits (@yezhizhen, #43010).
When using the Firefox DevTools, the Console tab now supports some basic autocomplete (@freyacodes, #46382).
We’ve finished modernising servoshell for Android to use Compose UI (@veyndan, #46085, #46164, #46253, #46257, #46317, #46353, #46565, #46612, #46626, #46666, #46663, #46700), and we’re now migrating Servo as a library to use Kotlin (@veyndan, #46817, #46895, #46772).
More on the web platform
Inline SVG can now use web fonts defined in the containing page (@yodalee, #45979). We’re also implementing the SVG DOM, starting with stub interfaces for SVGElement, SVGCircleElement, SVGDefsElement, SVGEllipseElement, SVGLineElement, SVGLinearGradientElement, SVGPathElement, SVGPolygonElement, SVGPolylineElement, SVGRadialGradientElement, SVGStopElement, SVGRectElement, SVGSymbolElement, and SVGUseElement (@mu-mostafa98, #46558).
<button> now vertically centers its contents (@Loirooriol, @mrobinson, #46590), and behaves better with ‘display: block’ and ‘display: inline’ (@Loirooriol, #46536).
We’ve improved the conformance of <form> without <form action> (@kevlu93, #46860), <color> values (@Loirooriol, #46129), GamepadEvent (@log101, #46788), document.execCommand(“delete”) (@Psychpsyo, #46539), the selectorText property on CSSStyleRule (@simonwuelker, #46687), and Set Window Rect in WebDriver (@janeoa, #46475, #46477).
We’ve fixed bugs related to <iframe> (@jschwe, @jdm, #46587), <img> (@yodalee, #46892), <textarea> (@SimonSapin, @mrobinson, #46309), custom properties (@Loirooriol, #46129), ‘::before’ and ‘::after’ (@Loirooriol, #46640), ‘flex-direction: column’ (@simonwuelker, #46697), ‘float’ (@Loirooriol, @mrobinson, #46407, #46500, #46505), ‘@font-face’ (@simonwuelker, #46568, #46271, #46436), ‘position: absolute’ (@simonwuelker, #46358, #46637), Blob (@jdm, #46881), IDBDatabase and IDBObjectStore and IDBIndex (@mrobinson, #46615), the adoptedStyleSheets property on ShadowRoot (@simonwuelker, #46738), delete() on FontFaceSet (@simonwuelker, #46634), moveBefore() on Element (@mrobinson, #46599), resizeTo() on Window (@janeoa, #46477), the selected property on HTMLOptionElement (@rhit-kapilaar, #46386), and the value property on HTMLSelectElement (@simonwuelker, #46230).
Performance and stability
2D canvas rendering is now multithreaded, improving frame rates by up to 55% and power consumption per frame by up to 42% (@yezhizhen, #46410), and should use a lot less memory too (@jschwe, @sagudev, #46786).
Text rendering is up to 10x faster for cases with the same text and different ‘font-size’ (@Loirooriol, #46129).
Flex layout benchmarks are up to 3% faster, and an improvement to getElementsByClassName() has made some websites up to 1% faster (@Narfinger, @jdm, #46563, #46595, #46594).
We’ve also reduced memory usage, allocations, GC rooting steps, and other operations in many parts of Servo (@mrobinson, @jdm, @yezhizhen, @Narfinger, @Gae24, @SimonSapin, @Taym95, @cychronex-labs, @arayaryoma, #46499, #46411, #46659, #45974, #46377, #45758, #46440, #46762, #46301, #46349, #46419, #46418, #46420, #46460, #46633, #46638, #46690, #46745, #46726, #46564, #46144, #46664, #46462, #46139, #46430, #46446, #46498, #46548, #46598, #46632, #46656, #46678, #46718, #46722, #46238, #46072, #46408, #46438, #46437, #46528, #46124, #46330, #46412, #46807).
We’ve fixed a crash regression with memory corruption (@mrobinson, #46316), several dynamic-borrow-related crashes (@Narfinger, @SharanRP, @Taym95, @agrawalx, @amittenak47, @sungmen, #46381, #46384, #46405, #46684, #46452, #46770, #46830, #46763), plus crashes related to:
- <area> without <area href> (@simonwuelker, #46341)
- <progress> or shadow DOM (@mrobinson, @simonwuelker, #46188)
- <table> layout (@mrobinson, #46775)
- <td rowspan> (@mrobinson, #46841)
- <svg> without <svg viewBox> (@Narfinger, @mrobinson, #46199)
- <use> in SVG (@mrobinson, @Loirooriol, #46261)
- ‘animation’ (@mrobinson, @Loirooriol, #46689)
- ‘content’ (@Loirooriol, @mrobinson, #46314)
- ‘mix-blend-mode’ (@mrobinson, #45624)
- ArrayBuffer (@jdm, #46504)
- adoptedStyleSheets on Document (@TimvdLippe, #46373)
- execCommand(
"delete") on Document (@TimvdLippe, #46265) - removing DOM nodes (@SimonSapin, #46866)
We’ve continued our long-running effort to use the Rust type system to make Servo’s integration with SpiderMonkey safer and more reliable (@Gae24, @Narfinger, @TimvdLippe, @jdm, @kunalmohan, @lumiscosity, @simonwuelker, #46191, #46777, #46890, #46243, #46248, #46246, #46310, #46312, #46333, #46147, #46150, #46151, #46229, #46262, #46375, #46374, #46529, #46584, #46585, #46593, #46693, #46166, #46156, #46254, #46267, #46268, #46269, #46270, #46284, #46285, #46318, #46435, #46461).
New contributors
A special thanks to the following people for landing their first patch in Servo:
- Umut Cevdet Koçak (@UMCEKO, #46256)
- Yash Agrawal (@agrawalx, #46770)
- amittenak47 (@amittenak47, #46743)
- Apoorva Pendse (@apoorvapendse, #46739)
- dDostalker (@dDostalker, #46181)
- Oisín Ó Maolchathail (@eachra-bawn, #46478)
- Kevin Lu (@kevlu93, #46860)
- Mohamed Mostafa (@mu-mostafa98, #45405)
- SeongMan Jeon (@sungmen, #46763)
- Yoda Lee (@yodalee, #45979)
Interested in helping build a web browser? Take a look at our curated list of issues that are good for new contributors!
Donations
Thanks again for your generous support! We are now receiving 7824 USD/month (+1.8% from June) in recurring donations. This helps us cover the cost of our speedy CI and benchmarking servers, one of our latest Outreachy interns, and funding maintainer work that helps more people contribute to Servo.
Servo is also on thanks.dev, and already 35 GitHub users (same as June) that depend on Servo are sponsoring us there. If you use Servo libraries like url, html5ever, selectors, or cssparser, signing up for thanks.dev could be a good way for you (or your employer) to give back to the community.
We now have sponsorship tiers that allow you or your organisation to donate to the Servo project with public acknowlegement of your support. If you’re interested in this kind of sponsorship, please contact us at join@servo.org.
Use of donations is decided transparently via the Technical Steering Committee’s public funding request process, and active proposals are tracked in servo/project#187. For more details, head to our Sponsorship page.
Firefox Tooling Announcements
MozPhab 2.18.0 Released
Bugs resolved in Moz-Phab 2.18.0:
- bug 1898339
moz-phabincorrectly uploads symlinks as text files when using Mercurial - bug 2063674 Consider reminding people of their review queue when they push to try or moz-phab
- bug 2064223 Add pyrefly type checking to moz-phab test suite
Discuss these changes in #engineering-workflow on Slack or #Conduit Matrix.
1 post - 1 participant
Serge Guelton
Pros and Cons of Unified Build
Unified builds (also know as Jumbo Builds) is a build techniques that aims at improving build time through the concatenation of several sources as a single unified source before compilation.
The goal is obtained through implicit caching of header instantiation, although it implies a trade-off with parallelism.
Let's illustrate this behavior through a simple example, two codes that implement variation of the same approach:
/* algo0.cpp */
#include<iostream>
#include<string>
#include<vector>
voidtranslate(std::vector<std::string>&w,void(&t)(std::string&));
voidtranslate(std::vector<std::string>&w_out,std::vector<std::string>const&w_in,void(&t)(std::string&)){
std::cout<<"[log] through transform\n";
w_out=w_in;
translate(w_out,t);
}
/* algo1.cpp */
#include<algorithm>
#include<iostream>
#include<string>
#include<vector>
voidtranslate(std::vector<std::string>&w,void(&t)(std::string&)){
std::cout<<"[log] through for_each\n";
std::for_each(w.begin(),w.end(),[&t](std::string&s){t(s);});
}
Compiling individual files take the following times:
%hyperfine--warmup5"/usr/bin/clang++ -O2 algo0.cpp -c"
Benchmark1:/usr/bin/clang++-O2algo0.cpp-c
Time(mean±σ):267.7ms±7.4ms[User:234.6ms,System:30.4ms]
Range(min…max):259.7ms…277.3ms11runs
%hyperfine--warmup5"/usr/bin/clang++ -O2 algo1.cpp -c"
Benchmark1:/usr/bin/clang++-O2algo1.cpp-c
Time(mean±σ):173.6ms±46.3ms[User:149.6ms,System:22.1ms]
Range(min…max):130.4ms…231.6ms13runs
Creation of the unified file is just a matter of invoking cat, let's benchmark the compilation of the unified source:
%catalgo{0,1}.cpp>unified_algo.cpp
%hyperfine--warmup5"/usr/bin/clang++ -O2 unified_algo.cpp -c"
Benchmark1:/usr/bin/clang++-O2unified_algo.cpp-c
Time(mean±σ):223.8ms±64.5ms[User:193.0ms,System:28.4ms]
Range(min…max):160.8ms…301.8ms10runs
In that simple case, the weight of headers with respect to actual user code is such that compilation of the unified file takes almost the same time as the max compilation time among each individual file. That's roughly a 1.97x speedup on compilation time.
That's the promise given by unified builds. And it's a promise held.
Now let's have a look at the consequences of that deal.
Beforehand, we still need to introduce another parameter tied to unified builds: the unification parameter, say P. That parameter bounds the number of files that are unified together. Let's imagine we have a hundred of individual source files compiled with exactly the same compilation flags. Setting P to 5 leads to the generation of 20 unified sources compiled independently.
Remember the parameter P.
Quality of the Generated Code
Let's create a shared object from algo{0,1}.o (this implies a recompilation with -fPIC of the sources):
%/usr/bin/clang++-O2algo0.cpp-c-fPIC
%/usr/bin/clang++-O2algo1.cpp-c-fPIC
%/usr/bin/clang++-sharedalgo{0,1}.o-fPIC-oalgo.so
And do the same from unified_algo.o:
%/usr/bin/clang++-O2unified_algo.cpp-c-fPIC
%/usr/bin/clang++-sharedunified_algo.o-fPIC-ounified_algo.so
After stripping, comparing the size of the binaries yield a difference of a few bytes. After disassembling, it turns out the compiler decides to inline the call to void translate(std::vector<std::string>& w, void (&t)(std::string&)) from algo0.cpp when compiling the unified source, something the compiler cannot do when doing split compilation, as it does not know anything about the implementation of that function.
Interestingly, compiling with -flto=thin still lead the compiler instantiation through different optimization path.
Falling back to -flto=full finally yields to the same shared object, which makes sense because Full LTO is very close to performing source unification at the bytecode level and our sources are very simple. It's not a given though because the actual optimisation pipeline is still different in the two scenario.
Why does it matter? Depending on the value of P, the compiler will see different sets of files per unified file, which will result in different binary code. It's actually even worse: depending on the way we fill those unification sets, event with the same parameter P, we end up with different binaries. Let's call that the reunifying problem.
Even if we have an algorithm that seems to guarantee reproducibility, for instance working on a sorted list of files with a fixed P, variation can arise: the introduction of a new source file can lead to changes in every unified file (e.g. if the split is done by chunks and the new file ends up at the beginning of the file list).
So unified builds tend to improve performance, but they do not interact in a gentle way with performance reproducibility.
Recompilation Times
Let's denote S as the number of sources and C as the number of CPUs.
Intuitively, setting P=1 yields to the faster recompilation time when a single file is touched---a usual scenario when developing a new feature.
On the opposite, setting P=S yields to the slower recompilation time (if S >> C!) under the same scenario as all sources are recompiled under that scenario.
The form of the curve between those two extreme varies depending on the nature of the files, and the amount of header sharing between individual sources.
Caching tools like sccache is impacted by the same mechanism: as P gets greater, more cache misses are hit and more recompilation are done.
Marginally, introducing a new source also pollutes the cache or triggers recompilation for the unified source it gets added to, and eventually for all the unified sources derived from the associated file list. The reunifying problem strikes again.
So unified build make compilation faster, but recompilation slower. Setting P to an acceptable value is important depending on the usage scenario.
Correctness
Unified build changing the compilation unit frontier, which in turns modifies the semantic of the program. This change can be straight-forward or complex to debug, and even remain silent. I've listed a few instances of the two first categories below, and a crafted one for the latter category.
Macro / Symbol Redefinition
This one is trivial to spot (a preprocessor-warning is issued for the macro, and a compiler error is issued for the symbol redefinition):
/* pi0.cpp */
#define PI 3.141593
constexprdoublepi(){return3.141593;}
/* pi1.cpp */
#define PI 3.14159265
constexprdoublepi(){return3.14159265;}
The solution usually lies in moving the definition in a shared header, moving the declaration in a shared header and the definition in a single file, or renaming identifiers to avoid the name conflict. Note that depending on the solution we may change the visibility of the symbols, or impact code readability (assuming the identifier name was perfectly chosen in the first place).
Overload Conflicts
This one is also trivial to spot and may hint toward debatable design. But it exists and may be more complex to understand than the above:
/* overload0.cpp */
staticfloatdoit(floatf){returnf;}
constfloatf=doit(1);
/* overload1.cpp */
staticdoubledoit(doubled){returnd;}
constdoubled=doit(1);
The fix is generally to provide a perfect match for the overload, change the call site to avoid the ambiguity, or rename the functions/change their namespace to make the call site explicit.
Using Namespace Confusion
This one tends to creep a lot in codebase where using namespace is used. It generates ambiguity among potential symbols.
A caricatured situation is exhibited with the following situation:
/* using.h */
#pragma once
namespacea{
namespacea{}
}
/* using0.cpp */
#include"using.h"
usingnamespacea;
/* using1.cpp */
#include"using.h"
usingnamespacea;
Once using{0,1}.cpp unified, the second using namespace a; directive is ambiguous.
A more realistic (but similar in spirit) situation arises when the same symbol is defined in different namespaces:
/* namespace0.cpp */
namespacea0{
intvar;
}
usingnamespacea0;
intfoo=var;
/* namespace1.cpp */
namespacea1{
intvar;
}
usingnamespacea1;
intbar=var;
The problem with that category is that the fix is quite unsatisfying: there is no way to limit the scope of a using directive, removing using directive can lead to very verbose codebase, renaming symbols to avoid conflicts goes against the very purpose of namespaces...
Delicatessen
I spent a lot of time nailing that one down, so I wrote a small reproducer to illustrate the problem.
%tail-n+1*.h*.cpp
==>header0.h<==
#ifndef H0
#define H0
namespacemozilla::dom{
classLockfinal{};
}
#endif
==>header1.h<==
#ifndef H1
#define H1
#include "header0.h"
classLock{};
classAutoUnlock{
Lock*lock_;
};
#endif
==>src0.cpp<==
#include "header1.h"
==>src1.cpp<==
#include "header0.h"
==>src2.cpp<==
namespacemozilla::dom{};
usingnamespacemozilla::dom;
usingnamespacemozilla;
==>src3.cpp<==
#include "header1.h"
Let me comment that layout a bit: We basically have two different classes named Lock: one lives in the mozilla::dom namespace, and one lives at top-level. In header1.h, although we include the definition of mozilla::dom::Lock, we also get the definition of ::Lock, so a straight reference to Lock is not ambiguous.
Concerning source files, src0.cpp, src1.cpp and src3.cpp just include headers while src2.cpp contains the infamous using namespace modilla::dom; statement.
Let's now consider various partition of the file list src0.cpp, src1.cpp, src2.cpp, src3.cpp:
%forpermin0,12,30,1,21,2,30,1,2,3;doprintf"unifying $perm... ";cat`evalechosrc{$perm}.cpp`|clang++-xc++--fsyntax-only2>/dev/null&&echook||echoko;done
unifying0,1...ok
unifying2,3...ko
unifying0,1,2...ok
unifying1,2,3...ko
unifying0,1,2,3...ok
Isn't that amazing? Some intermediate unification, namely 0,1;2,3 and 0;1,2,3 fail, but other unifications, namely 0,1,2,3 and 0;1,2,3 fail. Did you notice that both non-unified and full unified build succeeds, while some intermediate unification fail? What a disaster. This basically mean that given a set of sources, and without putting restriction on the language (like banning using statement), the only way to be sure that a unified build always succeeds whatever the chosen partition is to test every partition. Not very satisfying.
As a side effect, we can also deduce that adding a new source file to a set of files to be unified can break compilation in files that used to compile fine. That's another instance of the reunifying problem.
Changing Semantic
It is quite easy to derive from the above an example whose semantic change once unified. Let's slightly change the overload conflict example from above:
/* silent0.cpp */
#include<cstdio>
staticintdoit(intf){putchar('0');returnf;}
constintf=doit(1);
/* silent1.cpp */
#include<cstdio>
staticdoubledoit(doubled){putchar('1');returnd;}
constdoubled=doit(1);
When compiled independently, this results in a binary that prints a 0 and a 1 on the screen. But when compiled as a unified source, we only get a pair of 0.
Concluding Words
Remember that discussion between Luke and Yoda?
LUKE Vader. Is the dark side stronger?
YODA No… no… no. Quicker, easier, more seductive.
That's exactly my thoughts on unified builds: they give you quick wins in term of cold build speed and give faster builds. That's very good properties, and you rip the benefit of them very quickly. Then you realize that you're tied to a monster in terms of maintainability and developer experience, but you're already addict to the speed it gave you.
Mozilla Performance Blog
The Road to Better Performance Profiles – Part 2
Following the symbolication work from Part 1, I undertook two more efforts to improve performance profiles for the Performance team.
Native Profiling (Bugs 2030161, 2030166, 2047451, and 2030423)
The first effort was to use platform-specific profilers to generate profiles in CI of browsers running the Speedometer 3 benchmark, the industry-leading benchmark for browser performance. These ‘native’ profiles provide rich, system-wide insight into how browsers handle Speedometer 3, helping developers analyze and diagnose behaviour. They also provide us with profiles we can use to generate comparison reports for patches. We needed Raptor to generate native profiles for all of our platforms, namely Windows, macOS, Linux, and Android.
At a high level, the pipeline to generate native profiles is as follows:
- Start the system profiler.
- Run Speedometer 3 on Firefox or Chromium as Release using Raptor and Browsertime.
- Stop the system profiler.
- Symbolicate the profiles using
samplyand the corresponding build symbols. - Post-process the symbolicated profiles using
profiler-edit(formerlysymbolicator-cli) and create compact and labelled variants of the profiles. - Upload the processed profiles as artifacts.
To run tests with native profiling, you can use ./mach try fuzzy --full or ./mach try perf --full and run any test that has the -native-profiling suffix.
On Windows, we produced profiles using xperf, a tracer that uses the Event Tracing for Windows framework (ETW) to capture system-level data on applications running on Windows. To use xperf with our CI machines, scheduled tasks to run the tracer were configured in Puppet (see our ronin_puppet repository).
After adding support to Raptor to trigger these xperf tasks, we can start a trace and run the Speedometer 3 benchmark on Firefox or Chromium as Release (our custom Chromium build configured with release flags) using Browsertime. The Speedometer 3 benchmark runs 20 times, with each run in a separate browser cycle, to ensure we collect enough samples before stopping the trace.
Once completed, xperf provides a user trace and a kernel trace, which are combined into a full trace. We can then use samply to convert and symbolicate these traces into Firefox Profiler profiles, complete with markers and JIT information (Figure 1 and Figure 2).

Figure 1: Native profile of Speedometer 3 running on Firefox on Windows

Figure 2: Native profile of Speedometer 3 running on Chromium as Release on Windows
On macOS, we took a similar approach. We used samply to collect and symbolicate profiles. After implementing a workaround to allow samply to profile across multiple browser cycles and sorting out permission issues in CI, samply could profile Speedometer 3 on Firefox with minimal CI configuration and symbolicate the profiles afterwards.
On Linux, we ran perf with elevated privileges to collect profiling data system-wide before using samply to symbolicate and convert the data into a Firefox Profiler profile. Other than enabling our CI machines to run sudo perf, no additional machine configuration or workarounds were needed.
For Android, we took a slightly different approach. We used simpleperf to collect profiles on our mobile devices in CI (Samsung A55, Google Pixel 6, and Samsung S24) and samply to symbolicate them.
Initially, we wanted to profile 20 Speedometer 3 runs in a single simpleperf session, matching our desktop profiling workflow, but this proved unreliable during testing, as the on-device profiling appeared to be resource-intensive and would intermittently fail or crash.
We decided to use our simpleperf support introduced in Browsertime in Part 1 to profile the 20 individual test suites that make up a single Speedometer 3 run separately, which proved to be more stable (Figure 3). In the long term, we plan to support profiling complete Speedometer 3 runs with simpleperf on Android, bringing the workflow closer to what we currently use for desktop profiling (Bug 2032007). We will introduce native profiles for Chromium as Release (mobile) on Android in Bug 2067157.

Figure 3: Native profile of the TodoMVC-Vue Speedometer 3 test running on Fenix (Firefox for Android)
To make our Speedometer 3 profiles clearer and more helpful, we post-process them with profiler-edit, which adds labels (groupings of JS frames) to the profile (Figure 5) and also provides a more compact version (Figure 4) where all runs are placed on the same process track.

Figure 4: Compact Speedometer 3 native profile

Figure 5: Labelled Speedometer 3 native profile
In CI, we routinely generate Firefox profiles on autoland (Figure 6) and Chromium as Release profiles on mozilla-central. These native profiles have already been used to produce Speedometer 3 comparison reports (Figure 7) and investigate incidents in CI. Currently, profiles for Chromium as Release on macOS and Linux are works in progress (see Bug 2050869 and Bug 2065970, respectively).

Figure 6: Native profiles running routinely on autoland

Figure 7: Comparison reports using native profiles (preview courtesy of Markus Stange)
Modernizing mozgeckoprofiler (Bug 1992000)
The second effort was to fully modernize symbolication in mozgeckoprofiler, the module responsible for symbolication across four performance testing frameworks: Raptor, Talos, XPCShell, and Mochitest. This mainly involved phasing out Eliot, an older symbolication API service scheduled to sunset in the near future, and fully transitioning the module’s symbolication workflow to use samply and profiler-edit.
In Part 1, we added support that allowed Raptor and Talos to symbolicate their profiles using our new approach. This left two main cases that were still handled by Eliot: XPCShell and Mochitest symbolication, and local profile symbolication.
Implementing XPCShell and Mochitest profile symbolication (Bug 1998767) was relatively straightforward. We followed the same approach used for Talos and Raptor by adding our new symbolication dependencies to XPCShell and Mochitest taskgraph configurations. Since these tests and their profiles (Figure 8) can be generated in parallel, we made sure to perform symbolication only after all profiles had been generated. You can try these jobs by running ./mach try fuzzy --profiler and selecting any XPCShell and/or Mochitest job (Figure 9).

Figure 8: Symbolicated Mochitest profile

Figure 9: Mochitest tests running in CI produce symbolicated profiles
Originally, when generating profiles locally from one of our performance frameworks, Eliot was used to symbolicate those profiles. To replace it with our new approach, we needed to bootstrap samply and profiler-edit onto local developer machines. Now, when you run ./mach bootstrap, the latest builds of samply and profiler-edit available in CI for your platform are automatically installed under the local .mozbuild/ directory. With this change, the use of Eliot in PerfTest has been completely replaced by our new symbolication approach, and Eliot can safely be retired from mozgeckoprofiler!
What’s Next
These patches are part of an ongoing effort to make performance profiling easier, more standardized, and more useful for Firefox developers. Here are a few related bugs to keep an eye on:
- In Bug 2050869, Bug 2065970, and Bug 2067157, we’ll add Chromium-as-Release profiling support for macOS, Linux, and Android, respectively.
- In Bug 2066906, we’ll officially remove Eliot as
mozgeckoprofiler’s fallback symbolication service. - In Bug 2032007, we’ll add support for profiling full Speedometer 3 runs with
simpleperf, rather than producing a profile for each test suite. - In Bug 2036104, we’ll continue developing reports that compare native profiles across patches, making it easier for developers to investigate performance differences and regressions.
The Rust Programming Language Blog
Announcing our first Maintainers in Residence
We are very happy to announce the Rust Project's first round of Maintainers in Residence:
Gen Li (@rami3l), Chris Denton (@ChrisDenton), Alejandra González (@blyxyas), León Liehr (@fmease), and Maintainer Grant recipients: Jason Newcomb (@Jarcho) and Jonas Böttiger (@joboet). These contributors will be funded for their rust-lang maintenance activities for (at least) the following 12 months!
The funding of the Maintainer in Residence (MiR) and Maintainer Grantee roles is possible thanks to generous donations to the Rust Foundation Maintainers Fund (RFMF) from Google, AWS, OpenAI, the Rust Project Leadership Council and also individual sponsors. We also want to thank the people who advocated for maintainer funding within their companies; Tyler Mandry from Google, Niko Matsakis and Jess Izen from AWS and Predrag Gruevski from OpenAI, and also the whole Rust Leadership Council and our funding advisors. If you would like to help us support even more Rust contributors, consider donating to RFMF.
The Rust Foundation has published a press release and a blog post, where you can learn more about the sponsors and the supported contributors.
Read more below to learn about the MiR program, how we chose the funded contributors, and of course who they are!
Background
The Maintainer in Residence program, established in RFC 3931, is designed to provide stable financial support for Rust contributors, so that they can truly focus on crucial maintenance activities. Currently, there are three categories of support that we offer:
- Full-time MiR: funded for 5 days/week of Rust Project work
- Half-time MiR: funded for ~2.5 days/week of Rust Project work
- Maintainer Grant: funded for ~1 day/week of Rust Project work
Funding for this program comes from the Rust Foundation Maintainers Fund, which was launched recently, and the whole program is managed by the Rust Funding team.
When deciding who to fund, we took a systematic approach. First, we looked at Rust teams to understand their maintenance baseline (the smallest number of maintainers they need to ensure a healthy long-term status of the given project or repository), and how far they currently are from that baseline. From there, we identified and prioritized Rust teams who were both critically underfunded, and have a high impact on the language and its users. These teams (in no particular order) were rustdoc, rustup, cargo, compiler, libs, clippy, rustfmt, rust analyzer and mods.
The next step was pairing these teams with maintainers looking for funding. And it turns out that finding such maintainers for some teams turned out to be much more difficult than we originally assumed! For example, some maintainers are already employed, some do not want to be funded, and while we did our best to promote our funding efforts, not everyone looking for funding actually asked us for it. We also realized that some teams on our list have essentially no active members, which makes it tricky to onboard new contributors, even if they would like to help out.
In the end, we decided to start by supporting six contributors, who will help maintain several critical Rust projects and teams and who could start immediately. However, we are not stopping there. Our funding efforts are ongoing, so stay tuned for more MiR announcements in the near future! If you would like to learn more about our process, check out our recent post.
And now, without further ado, let's meet our newly funded maintainers!
Gen Li (@rami3l)
Turning volunteering into an actual job has really been an empowering experience so far! I finally have the bandwidth to take a careful look at my inbox and can actually read each message without the fear of missing crucial details while rushing prompt replies, which has really helped me retain the essential compassion as a maintainer. I also get to interact with regular contributors a lot more often. Finally, I can't wait to see what I can come up with in terms of Project Goals :)
Chris Denton (@ChrisDenton)
Even though it is still early days, I'm feeling pretty optimistic about the health of the Rust Project going forward, thanks to the recent funding efforts.
Alejandra González (@blyxyas)
Funding is the system that helps me pour my heart into a project without worrying about making ends meet. Having those needs met is a game-changer and boosts my productivity. One of the areas where I want to focus my efforts is mentoring new contributors. If new people coming is the lifeblood of a project, I want to be the cardiologist!
León Liehr (@fmease)
Being funded to work on Rust means I can sustainably focus my time and energy on a project I call a passion of mine.
Jonas Böttiger (@joboet)
Getting funding for my work is a dream come true. It will allow me to continue doing the thing I love instead of worrying about whether I should rather invest all that time in a money-earning job with much less positive impact on the world around me.
Jason Newcomb (@Jarcho)
Being funded allows me to work on something I care about and want to work on instead of what will get me paid. I'm looking forward to seeing how this will impact Clippy and the Rust project in general.
Conclusion
The contributors presented above will be funded for the next 12 months, though of course we hope that we will be able to extend their support going further, as this program is designed to be for long-term stable maintenance funding. We are very excited about them; each one of them has been with the Project for years, and we are very glad that we can support their maintenance work! All of them have already signed their contracts, so they are already being funded as we speak.
While there are many other Rust contributors who are doing awesome work, and who would also deserve to get proper funding for it, we think that this is a great start. We hope that the awesome work done by the funded maintainers will allow us to promote this program, so that we can fund even more Rust contributors!
We would like to once again sincerely thank everyone who made this possible, especially our sponsors. If you would like to help us fund more maintainers, consider donating to RFMF. You can also sponsor individual Rust contributors directly.
Firefox Nightly
Icons! Lots of them! – These Weeks in Firefox: Issue 206
Highlights
- Starting in Firefox 154, we’ve added a new capability for changing the default browser icon for Windows (Windows-only, for now, and not MSIX / Store installs) in about:settings#appearance!
-
- Notice any bugs? File them here!
- Hubert Boma Manilla continued his work to handle CSS files in the Debugger (#2036376, #2037041). The feature can now be enabled from the Settings panel (#2051876)
- The Picture-in-Picture WebAPI is now available, starting with release version Firefox 153!
- This does not replace the built-in Picture-in-Picture mechanism, and is in fact powered by it.
Friends of the Firefox team
Resolved bugs (excluding employees)
Volunteers that fixed more than one bug
- japandi
New contributors (🌟 = first patch)
- 🌟 Luiz Henrique Vieira helped remove some dead CSS from our tabbrowser code!
Project Updates
Add-ons / Web Extensions
Addon Manager & about:addons
- As part of Project Nova work:
- Added moz-promo cards to the about:addons extensions list recommendations footer and empty state, and updated the openAmoInTab helper to support a custom UTM content value – Bug 2043615 / Bug 2050880
- Introduced the building blocks for the Nova Themes Picker in about:addons: a shared Firefox Themes list source of truth, a light/dark/device theme-mode switcher, a reusable theme-preview webcomponent, and Nova-styled theme previews – Bug 2051554 / Bug 2051559 / Bug 2051564 / Bug 2051573
- Updated the Extensions panel empty state illustration and toolbar item icon for Project Nova – Bug 2030715
- Thanks to Michael Hynson for driving this.
- Removed the legacy AddonManager Glean metrics used for mirroring legacy telemetry events, along with the corresponding legacy telemetry test checks – Bug 1923949 / Bug 1981822
- Thanks to Chris H-C for collaborating with us on this.
- Fixed themes installed through the distribution mechanism not fetching their AMO metadata, which was resulting in distribution installed themes left without a preview image in about:addons – Bug 1917279
- Thanks to Mike Kaply for the fix to the distribution themes metadata handling.
- Fixed amContentHandler to verify that a system triggeringPrincipal genuinely originated from the parent process, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2048964
WebExtensions Framework
- Fixed a startup performance regression by avoiding an NSS-initializing crypto.getRandomValues() call during extension startup, a regression introduced in Firefox 153 and fixed in Firefox 154 (with a beta 153 uplift requested) – Bug 2050882
- Enabled tier 3 TypeScript typecheck linting for the extensions framework code – Bug 2050124
- Implemented the WebExtensions manifest sandbox key, letting extensions keep using string-based code execution in unprivileged sandboxed extension documents – Bug 1685123
- Thanks to Robin for the implementation of the manifest sandbox support.
WebExtension APIs
- Enabled storage.local database auto-reset on detected corrupted IndexedDB storage on all channels, starting in Firefox 154 – Bug 1992973
- Simplified registerTraceableChannel to make it synchronous again, removing the delay before blocking webRequest listeners can register a traceable channel – Bug 2044518
- Restored the contextualIdentities iconUrl container icons to their intrinsic 32×32 size, fixing a regression introduced earlier in the Firefox 154 cycle – Bug 2048599
- Thanks to Andrea Marchesini for the fix to the contextualIdentities container icons.
- Fixed the MV2 userScripts API failing with an Xrays TypedArray access error due to a missing isWebExtensionContentScript flag – Bug 2054083
- Thanks to erosman for the fix to the MV2 userScripts API.
DevTools
- Emilio Cobos Álvarez fixed the Inspector highlighters for SVG documents (#1850539)
- Andreas Farre made the Session History table header clickable to navigate the content page to given entry (#2018878)
- Sylvestre Ledru added Browser and Content filter to the Browser Toolbox Console and the Browser Console (#2048893)
- Adel Fatkhutdinov adapted the about:debugging Performance dialog for Nova (#2049348, #2053817)
- Nicolas Chevobbe about:debugging is now using moz-page-nav for its left sidebar (#2048544), thanks to Mark making it possible to disable collapsing that occurs on narrow screen (#2050907)
- (not all items were migrated to moz-page-nav-button though, see #2050746 for remaining work)
- Alexandre Poirot made it possible to control the request and response body size limit from the Settings panel (#2040892)
- Alexandre Poirot added a notification when DevTools are open and the user navigate to a file:// document to promote Local Mode (#2044464), and added documentation for the feature (#2045987)
- Nicolas Chevobbe improved Inspector performance for elements with lots of Rules (reported bug was causing a crash on Penpot) (#2034445)
- Alexandre Poirot made the Ruler to remain visible after reloading the page (#1247553)
- Nicolas Chevobbe made the DevTools splitter keyboard accessible (#2015949)
- Nicolas Chevobbe fixed pretty printing in Debugger for sources using Regex with the v flag (#2053574)
WebDriver
- Devin Rousso enhanced the emulation.setLocaleOverride command to allow overriding the Accept-Language header for fetch and WebSocket requests in Workers.
- Nazım Can Altınova created the moz:profiler module (mozilla-only!), allowing clients to control the Firefox Profiler from WebDriver BiDi.
- Julian Descottes fixed a bug in geckodriver which prevented connecting to a non-rooted device.
- Alexandra Borovova implemented the “browsingContext.startScreencast” and “browsingContext.stopScreencast” commands, which will record a browsing context and save the result as a video file.
- Alexandra Borovova added download id to “browsingContext.downloadWillBegin” and “browsingContext.downloadEnd” events” to make it easier to identify which events belong to the same download.
- Henrik Skupin fixed a bug in WebDriver BiDi where same-document navigations or loading error pages in frames caused the browsingContext.navigate command to return prematurely.
- Henrik Skupin released geckodriver 0.37.1, including a fix for Android. See the release page for details.
Credential Management
- The new Rust-based storage mechanism for logins has been enabled by default, starting in Firefox 154. This component is an application-services component that can be shared with iOS and Android.
Migration Improvements
- We recently updated the Passwords import instructions for Safari to be up-to-date with macOS Sequoia and up.
New Tab Page
- That’s a wrap for the World Cup! We’re powering down the Sports widget today.
- Some folks might see a survey about the Sports widget, to get feedback from the wild on whether or not it provided any user value (Telemetry points to “yes”, but it’s good to get qual data too)
- We’re replacing it with some new widgets. If you’re in an English-speaking region, you will probably see it replaced with a Daily Crossword widget. Otherwise, it’ll be replaced with a Picture of the Day widget.
- Sections have rolled out to 100% in France! We’re now doing 10% Sections experiments in Spain, Italy, Austria, Switzerland and Belgium.
- Shout out to volunteer Sameeksha who added an accessible name to the Task list widget ••• button, adding an aria-label/accessible-name so NVDA/VoiceOver announce the control and keyboard navigation/activation works correctly on New Tab.
- Joel added WebNotifications to the newtab state, allowing New Tab widgets to observe and reflect WebNotification events (affects the notification-driven widget lifecycle and UI state updates).
- Reem Hamoui adjusted the New-Tab Widgets 3-dot menu layout to vertically center menu entries inside the hover-granted colorful stripe, removing visual misalignment and small hit-area offsets on touch and pointer inputs.
- Dre implemented the show less/show more transition animation for New Tab expand/collapse, smoothing layout shifts with a CSS transition to reduce perceived jank during widget list changes.
- Scott Downe fixed New Tab Page drag-and-drop so widgets no longer jump or keep moving during drags (2049472).
- Reem Hamoui rendered the Daily Crossword in a sandboxed iframe to isolate its scripts/CSP on the New Tab Page (2049489).
- Reem Hamoui added the Crossword option to about:preferences and wired the New Tab Page crossword widget into prefs (2050340), so users can enable or disable the crossword via the standard Preferences UI rather than about:config.
- Dre set up the Picture of the Day boilerplate, including prefs and basic New Tab UI components (2050969), which exposes a configurable PoD surface for users to opt into and customize.
- Dre added a dismiss control and persisted dismissal state to the daily photo UI (2050972), allowing users to remove the current picture from their New Tab and avoid immediate reappearance.
- Dre added a “set as wallpaper” action and hooked it into New Tab wallpaper storage/prefs (2050973), enabling users to promote a PoD image to their custom New Tab wallpaper persistently.
- Dre connected the Picture of the day widget to the Merino endpoint to set the background of the widget to the current picture (2050976). He also added telemetry for the Picture of the day widget on the New Tab Page to capture impressions and clicks for usage analysis (2050977).
- Nina Pypchenko [:nina-py] added a small size variant for the Focus Timer widget in Nova so the timer can render compactly in narrow/new tab layouts and reduce vertical space usage (2051179).
- Maxx Crawford created a DevTools ‘controls’ area on the New Tab Page to enable and configure the widget, exposing toggles and settings that let developers and experimenters flip the widget without changing prefs, which reduces friction when reproducing NTP widget behaviors during debugging and testing.
- Irene Ni switched the New Tab ‘inferred personalization’ checkbox to the platform moz-checkbox control, restoring native checkbox semantics (role/keyboard focus/visual state) so users toggling inferred personalization see consistent a11y behavior and platform rendering across Windows/macOS/Linux.
- Scott Downe fixed an intermittent visual reload/flicker of sponsored tiles and the Add Shortcut button when pinning/unpinning shortcuts, preventing momentary tile DOM reflows and layout thrash that caused perceived data loss or longer perceived latency during shortcut edits.
- Scott Downe ensured custom image URLs persist on manually added Top Site tiles after edit, so users’ uploaded or external thumbnails no longer revert to the site’s homepage preview when saving edits and their custom thumbnails are correctly cached and displayed.
- Dre introduced two variants of the World Cup widget survey message, changing the copy delivered in the widget to support an A/B/message-variant experiment and altering what users see when the World Cup widget surfaces survey prompts on their New Tab Page.
- Nina Pypchenko [:nina-py] introduced a default state for Medium and Large Stocks widget sizes on the New Tab Page to surface placeholder content and avoid blank tiles when the Stocks feed is empty or slow to load.
- Nina Pypchenko [:nina-py] added an error state to the Stocks widget on the New Tab Page to show an explicit failure UI when quote fetches or network requests fail, reducing user confusion.
- Alexandre Hanot migrated AdsFeed to fetch New Tab ads through the MozAdsClient, changing the ad retrieval path (AdsFeed -> MozAdsClient) which affects ads loading behavior and telemetry for users who see New Tab Page ads.
- Irene Ni fixed the New Tab add-pin flow that was creating extra rows when grouped pins was off by changing the insertion logic to append into the existing grid, which eliminates unexpected row creation and layout shifts for users managing many pins (2053251).
- Scott Downe updated New Tab section rendering to hide cards that don’t fill their row by adjusting layout logic/CSS, removing orphaned placeholders and reducing blank space on narrow viewports or low-item sections for a cleaner grid appearance (2053264).
- Reem Hamoui added a context menu to the Crossword widget using a postMessage integration between the iframe and parent page, enabling right-click actions (copy/hint/theme) and making the embedded crossword more interactive and accessible to users who rely on context menus (2053311).
- Reem Hamoui added a visible “New” badge plus interaction handlers and state tracking to the Crossword widget on the New Tab Page to improve discoverability and make tapping/clicking behave reliably when launching puzzles (2053667).
- Irene Ni removed unused Add Shortcut OMC artifacts from the New Tab Page (2053843); this is a cleanup of obsolete assets/templates and has no direct runtime user impact.
- Maxx Crawford added author and license attribution to the Picture of the Day widget (2053933); this surfaces photographer credit and license metadata on the New Tab Page for users who want provenance information.
- Maxx Crawford applied UX refinements to the Picture of the Day widget (2054109); users will see improved layout, spacing, and touch targets in the POTD area for clearer interactions.
- Maxx Crawford added a pref and trainhopConfig gate to toggle the POTD “Set as wallpaper” feature (2054111); rollout and availability of the wallpaper action are now controllable via pref and remote trainhopConfig.
- Maxx Crawford added a dedicated trainhopConfig.widgetPictureOfTheDay payload for POTD feature config (bug 2054112) so the New Tab Page train-hop widget can be controlled server-side — this delivers image URLs, attribution and display params remotely which lets us enable/disable POTD per cohort without ship-side changes and reduces rollout latency for users who see the Picture‑of‑the‑Day widget.
- Irene Ni updated the Shortcuts Add/Edit dialog for Nova (bug 2054175) to improve the add/edit UX on the New Tab Shortcuts surface — the patch adjusts dialog layout and controls, tightens validation and accessibility labels, and reduces accidental duplicate/invalid shortcut creation so users editing shortcuts have a more reliable, faster flow.
- Maxx Crawford fixed the Daily crossword widget content overflowing and clipping past the bottom container boundary by adjusting the crossword widget’s layout/CSS (container height calculations and overflow/overflow-anchor rules) on the New Tab Page, restoring full visibility of clues and controls across responsive breakpoints.
- Maxx Crawford fixed Related articles not opening on click by repairing the related-articles component’s click handling and event delegation (anchor href/target behavior and JS listener) on the New Tab Page so article tiles now reliably open on click for users.
- Maxx Crawford added a “New” badge and interactions to the Picture of the Day widget, implementing an isNew flag, local state/localStorage handling, ARIA label updates and click behavior so users can immediately see and act on newly added images.
- Maxx Crawford updated the initial order of the Picture of the day widget by changing the PoD component’s initial ordering/priority algorithm so first-run and default NTP surfaces surface curated/high-priority images first.
- Maxx Crawford migrated Crossword widget strings from Fluent back to inline markup to fix localization/formatting regressions in the crossword UI and ensure consistent rendering of labels and controls across locales.
- Irene Ni migrated the New Tab Widgets expand button to moz-button which standardizes the expand/collapse control on the New Tab Page widgets area, fixing inconsistent styling and keyboard/click handling so users now get consistent visuals and improved accessibility across platforms.
- Reem Hamoui added a dedicated trainhopConfig.widgetCrossword payload for Crossword feature config which isolates crossword rollout flags and content settings from other trainhop payloads, allowing targeted remote-config changes and safer A/B testing of the crossword widget without impacting unrelated New Tab features.
- Maxx Crawford fixed the Daily crossword widget being blank after closing and reopening the browser by ensuring widget state is correctly initialized/persisted on startup (New Tab Page widget lifecycle), so users now reliably see the daily puzzle after a restart instead of an empty frame.
- Reem Hamoui fixed Daily crossword completed puzzle and show clues are displayed in medium sized widget, restoring completed-puzzle rendering and clue visibility in the New Tab Page medium widget (widget template/CSS).
- Maxx Crawford updated Discovery Stream Admin buttons to use moz-button components, replacing custom controls with moz-button to standardize admin UI styling and focus behavior.
- Maxx Crawford added per-widget feature toggles and pref reset buttons to Discovery Stream Admin, enabling admins to toggle individual widgets and reset prefs without code deploys — changes here can alter what users see when toggled.
- Maxx Crawford migrated Discovery Stream Admin unit tests to jest, moving tests to Jest for faster developer feedback and more consistent test tooling.
- Maxx Crawford enforced Fail jest tests that emit console.error messages, making tests fail on console.error to catch regressions earlier and improve content quality before release.
- Kyle Jones populated MozAdsRequestOptions flags from adsBackendConfig in AdsFeed on the New Tab Page, changing ad request parameters that may alter which ads or personalization users see.
- Mike Conley removed the version 145 train-hop shim for the PrivacyFeed getTodayStats guard, simplifying guard logic in the New Tab Page with no direct user-visible change.
Search and Urlbar
Search
- Mandy fixed the “New” label incorrectly appearing for user-installed third party search engines that override application-provided engines (2053710).
- Standard8 fixed search engine telemetry notifications and private browsing search engine defaults (2053129, 1792669).
Suggest
- Adw added header_text support for AMP (AdMarketPlace) suggestions (2053626).
Nova
- Adw continued working on Nova with visual improvements across the address bar, search UI, icons, spacing, hover states, and accessibility (2019160, 2050821, 2053381, 2055109, 2053652, 2054784, 2055353, 2053927, 2053332, 2050366, 2053038).
- Daisuke improved the legacy search bar for Nova and fixed several Nova UI issues (2053934, 2050759, 2054304, 2046300, 2045993).
Address Bar
- Dharma improved Unified Search Button with search engine icons and a modernized result menu (2052741, 2039292).
- James continued work on adaptive autofill improvements (2013362, 2053891, 2050379).
- Dao and Mortiz continue multi-context address bar work (MCAB) (2054328, 2054207, 2054168, 2054110, 2054070, 2054066, 2051435, 2055474, 2054801, 2052555).
Places & Bookmarks
- Mak fixed several favicon and Places issues, including bookmark/history fixes (418144, 2055488, 2053482, 2052799, 2050378).
- Caleb improved Places performance by batching bookmark lookups and modernizing bookmark APIs (2042098, 2042099, 2042087, 2042097)
Storybook/Reusable Components/Acorn Design System
- Nova stuff
- Theme Picker for HNT, OMC and Profiles
- [mconley] There’s a new vertical variant for visual picker. Thanks for the reviews, hjones!
Firefox Tooling Announcements
Happy BMO Push Day! (20260824.1)
The following changes have been pushed to bugzilla.mozilla.org:
- Bug 1224099 - create 2fa user documentation
- Bug 1832783 - Wrong error message for exceeding file size
- Bug 2064475 - phab-bot leaves #release-managers review as non-blocking when a user manually adds it first
- Bug 2043229 - Display a “Show External” button beneath attachments list to display all attachments that would redirect such as Github and Phabricator
- Bug 2057679 - Update docker build process to pull in latest builds of vendered javascript libraries needed by the client
- Bug 2061264 - Remove CSP header from REST API responses
- Bug 2061831 - Add additional information to bugzilla comments in REST API if comment edited before
- Bug 2061441 - Migrate Classification REST resource to native Mojo API
- Bug 2064523 - [meta] tracking bug for BMO dependency upgrades
- Bug 2053504 - Need to add index to tracking_flags_values table for better performance from /bzapi/bug and REST search
- Bug 2055001 - Github Pull Requests: Look for etag value before fetching pull request data to cut down on rate limiting
Discuss these changes in the BMO Matrix Room
1 post - 1 participant