From c82e88dd00d1b0b7fcfb4e5628d99611388cef6f Mon Sep 17 00:00:00 2001 From: rawnix ports Date: Sat, 26 Sep 2026 18:19:05 +0000 Subject: sync 2026-09-26 18:19 UTC 1672 files changed, 151396 insertions(+) --- opt/thunderbird/.footprint | 60 +++++++++++++ opt/thunderbird/.signature | 9 ++ opt/thunderbird/MAKEPKG | 169 ++++++++++++++++++++++++++++++++++++ opt/thunderbird/rawnix.js | 90 +++++++++++++++++++ opt/thunderbird/thunderbird.desktop | 12 +++ 5 files changed, 340 insertions(+) create mode 100644 opt/thunderbird/.footprint create mode 100644 opt/thunderbird/.signature create mode 100644 opt/thunderbird/MAKEPKG create mode 100644 opt/thunderbird/rawnix.js create mode 100644 opt/thunderbird/thunderbird.desktop (limited to 'opt/thunderbird') diff --git a/opt/thunderbird/.footprint b/opt/thunderbird/.footprint new file mode 100644 index 0000000..e26c069 --- /dev/null +++ b/opt/thunderbird/.footprint @@ -0,0 +1,60 @@ +drwxr-xr-x root/root usr/ +drwxr-xr-x root/root usr/bin/ +lrwxrwxrwx root/root usr/bin/thunderbird -> /usr/lib/thunderbird/thunderbird +drwxr-xr-x root/root usr/lib/ +drwxr-xr-x root/root usr/lib/thunderbird/ +-rw-r--r-- root/root usr/lib/thunderbird/application.ini +-rw-r--r-- root/root usr/lib/thunderbird/dependentlibs.list +-rwxr-xr-x root/root usr/lib/thunderbird/glxtest +-rw-r--r-- root/root usr/lib/thunderbird/interesting_serverknobs.json +-rwxr-xr-x root/root usr/lib/thunderbird/libgkcodecs.so +-rwxr-xr-x root/root usr/lib/thunderbird/liblgpllibs.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozavcodec.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozavutil.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozgtk.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozsandbox.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozsqlite3.so +-rwxr-xr-x root/root usr/lib/thunderbird/libmozwayland.so +-rwxr-xr-x root/root usr/lib/thunderbird/libxul.so +-rw-r--r-- root/root usr/lib/thunderbird/omni.ja +-rwxr-xr-x root/root usr/lib/thunderbird/pingsender +-rw-r--r-- root/root usr/lib/thunderbird/platform.ini +-rwxr-xr-x root/root usr/lib/thunderbird/thunderbird +-rwxr-xr-x root/root usr/lib/thunderbird/vaapitest +drwxr-xr-x root/root usr/lib/thunderbird/chrome/ +drwxr-xr-x root/root usr/lib/thunderbird/chrome/icons/ +drwxr-xr-x root/root usr/lib/thunderbird/chrome/icons/default/ +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/TB-symbolic.svg +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/calendar-alarm-dialog.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/calendar-general-dialog.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default128.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default16.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default22.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default24.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default256.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default32.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default48.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/default64.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/msgcomposeWindow16.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/msgcomposeWindow24.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/msgcomposeWindow32.png +-rw-r--r-- root/root usr/lib/thunderbird/chrome/icons/default/msgcomposeWindow48.png +drwxr-xr-x root/root usr/lib/thunderbird/defaults/ +drwxr-xr-x root/root usr/lib/thunderbird/defaults/messenger/ +-rw-r--r-- root/root usr/lib/thunderbird/defaults/messenger/mailViews.dat +drwxr-xr-x root/root usr/lib/thunderbird/defaults/pref/ +-rw-r--r-- root/root usr/lib/thunderbird/defaults/pref/channel-prefs.js +-rw-r--r-- root/root usr/lib/thunderbird/defaults/pref/rawnix.js +drwxr-xr-x root/root usr/lib/thunderbird/fonts/ +-rw-r--r-- root/root usr/lib/thunderbird/fonts/TwemojiMozilla.ttf +drwxr-xr-x root/root usr/lib/thunderbird/isp/ +-rw-r--r-- root/root usr/lib/thunderbird/isp/Bogofilter.sfd +-rw-r--r-- root/root usr/lib/thunderbird/isp/DSPAM.sfd +-rw-r--r-- root/root usr/lib/thunderbird/isp/POPFile.sfd +-rw-r--r-- root/root usr/lib/thunderbird/isp/SpamAssassin.sfd +-rw-r--r-- root/root usr/lib/thunderbird/isp/SpamPal.sfd +drwxr-xr-x root/root usr/share/ +drwxr-xr-x root/root usr/share/applications/ +-rw-r--r-- root/root usr/share/applications/thunderbird.desktop +drwxr-xr-x root/root usr/share/pixmaps/ +lrwxrwxrwx root/root usr/share/pixmaps/thunderbird.png -> /usr/lib/thunderbird/chrome/icons/default/default128.png diff --git a/opt/thunderbird/.signature b/opt/thunderbird/.signature new file mode 100644 index 0000000..5ba48b0 --- /dev/null +++ b/opt/thunderbird/.signature @@ -0,0 +1,9 @@ +RWTZ9IduCSQ/mJaKIXt8Ugy/K3LLFjHmQx3DxmUYqRThC38kjY52yiX9eJpTbruKFwJvm2oI4B/69EQ/AWc2tcFsjdBwKHGlDAc= + +SHA256 (MAKEPKG) = ea77dd273b9ab24378c040ffba0d1bc4f3447687d5234e5cc8ac5c740385dc53 +SHA256 (.footprint) = bdbfa96901bb391d10a5ca298f267c2c1eef5c5af499e60b68fcf330655447d0 +SHA256 (thunderbird-153.3.1esr.source.tar.xz) = f4684de0caebf54352f8247ea3106b3c577509a26556759f6417bdc42f7567aa +SHA256 (firefox-153esr-patches-03.tar.xz) = 39efa65af2e5eecac09745b8d2b469a6137365a786d118100d2eb1dc28288e49 +SHA256 (thunderbird.desktop) = 926ad4122618b29bd5424ff43fdc87e5aa006dfe7f569c8773d33ca7b693ab94 +SHA256 (rawnix.js) = 685fb14c8f35b817cc756605ba025b9a5fff4f5c9a44b42647d5cdc949c8d37a +SHA256 (thunderbird#153.3.1esr-1.pkg.tar.gz) = b7938c18b8c9b967aab52c88310f1104decac1964fa5cefbd7ce271b8af5e403 diff --git a/opt/thunderbird/MAKEPKG b/opt/thunderbird/MAKEPKG new file mode 100644 index 0000000..db90475 --- /dev/null +++ b/opt/thunderbird/MAKEPKG @@ -0,0 +1,169 @@ +#!/bin/mkpkg +# description: Mozilla Thunderbird email client +# url: https://www.thunderbird.net/ + +name=thunderbird +version=153.3.1esr +_version=153.3.1 +_patch=153esr-patches-03 +release=1 +depends=(gtk3 nss nspr libvpx libwebp pixman libffi alsa-lib ffmpeg rnp dbus) +makedeps=(rust cbindgen nodejs python3 nasm) +source=( + https://ftp.mozilla.org/pub/$name/releases/$version/source/$name-$version.source.tar.xz + https://dev.gentoo.org/~juippis/mozilla/patchsets/firefox-$_patch.tar.xz + thunderbird.desktop + rawnix.js +) + +sha256sums=( + "f4684de0caebf54352f8247ea3106b3c577509a26556759f6417bdc42f7567aa" + "39efa65af2e5eecac09745b8d2b469a6137365a786d118100d2eb1dc28288e49" + "926ad4122618b29bd5424ff43fdc87e5aa006dfe7f569c8773d33ca7b693ab94" + "685fb14c8f35b817cc756605ba025b9a5fff4f5c9a44b42647d5cdc949c8d37a" +) + +patch() { + cd $name-$_version + + # https://dev.gentoo.org/~juippis + for p in "$SRC"/firefox-patches/*.patch; do + [ -f "$p" ] && patch -p1 -i "$p" + done + + # musl: allow select() syscall in all sandbox policies + awk '/CASES_FOR_poll:/{print; print "#ifdef __NR_select"; print " case __NR_select:"; print "#endif"; next}1' \ + security/sandbox/linux/SandboxFilter.cpp > SandboxFilter.tmp + mv SandboxFilter.tmp security/sandbox/linux/SandboxFilter.cpp + + # bindgen: don't panic on unresolved field types when computing union layout (libclang 23) + # comm/ carries its own vendored crate set, so patch both copies if present + for d in third_party/rust/bindgen comm/third_party/rust/bindgen; do + [ -d "$d" ] || continue + sed -i 's/ctx\.resolve_type(inner)\.layout(ctx)/ctx.resolve_item_fallible(inner)?.kind().as_type()?.layout(ctx)/' "$d"/ir/ty.rs + sed -i 's/ctx\.resolve_type(data\.ty)\.layout(ctx)/ctx.resolve_item_fallible(data.ty)?.kind().as_type()?.layout(ctx)/' "$d"/ir/comp.rs + sed -i 's/"files":{[^}]*}/"files":{}/' "$d"/.cargo-checksum.json + done + +} + +build() { + cd $name-$_version + + export MACH_BUILD_PYTHON_NATIVE_PACKAGE_SOURCE=none + export MOZBUILD_STATE_PATH="$PWD"/mozbuild + export MOZ_NOSPAM=1 + export SHELL=/bin/bash + + # musl rust target + export RUST_TARGET="x86_64-unknown-linux-musl" + + # Toolchain + export CC=clang CXX=clang++ + export AR=llvm-ar NM=llvm-nm RANLIB=llvm-ranlib + export AS="clang -c" + + # Flags + export CFLAGS="$CFLAGS -w" + export CXXFLAGS="$CXXFLAGS -w" + export LDFLAGS="$LDFLAGS -Wl,-rpath=/usr/lib/thunderbird,--enable-new-dtags" + export MOZ_DEBUG_FLAGS=-g0 + export CXXSTDLIB=c++ + export LIBCLANG_PATH=/usr/lib + export MOZ_MAKE_FLAGS="-j$(nproc)" + + # Rustc wrapper: force -crt-static so build scripts can dlopen libclang + mkdir -p "$PWD"/rustc-wrap + printf '#!/bin/sh\nexec /usr/bin/rustc -Ctarget-feature=-crt-static -Cdebuginfo=0 "$@"\n' \ + > "$PWD"/rustc-wrap/rustc + chmod +x "$PWD"/rustc-wrap/rustc + export PATH="$PWD/rustc-wrap:$PATH" + + cat > .mozconfig << EOF +mk_add_options MOZ_OBJDIR=@TOPSRCDIR@/thunderbird-shared +unset MOZ_TELEMETRY_REPORTING + +ac_add_options --prefix=/usr +ac_add_options --libdir=/usr/lib +ac_add_options --host=x86_64-unknown-linux-musl +ac_add_options --target=x86_64-unknown-linux-musl + +ac_add_options --enable-release +ac_add_options --enable-optimize +ac_add_options --enable-strip +ac_add_options --enable-install-strip +ac_add_options --enable-official-branding +ac_add_options --enable-application=comm/mail +ac_add_options --enable-project=comm/mail +ac_add_options --enable-audio-backends=alsa +ac_add_options --enable-dbus +ac_add_options --enable-rust-simd +ac_add_options --enable-default-toolkit=cairo-gtk3-wayland-only + +# OpenPGP - use system librnp (which links against system botan) +ac_add_options --with-system-librnp + +# System libraries +ac_add_options --with-system-ffi +ac_add_options --with-system-jpeg +ac_add_options --with-system-libvpx +ac_add_options --with-system-nspr +ac_add_options --with-system-nss +ac_add_options --with-system-pixman +ac_add_options --without-system-png +ac_add_options --with-system-webp +ac_add_options --with-system-zlib +ac_add_options --without-wasm-sandboxed-libraries + +# No Mozilla/Google service keys +ac_add_options --without-mozilla-api-keyfile +ac_add_options --without-google-location-service-api-keyfile +ac_add_options --without-google-safebrowsing-api-keyfile + +# Disable unused features +ac_add_options --disable-jemalloc +ac_add_options --disable-elf-hack +ac_add_options --disable-tests +ac_add_options --disable-updater +ac_add_options --disable-crashreporter +ac_add_options --disable-debug +ac_add_options --disable-debug-symbols +ac_add_options --disable-profiling +ac_add_options --disable-necko-wifi +ac_add_options --disable-webspeech +ac_add_options --disable-accessibility +ac_add_options --disable-parental-controls +ac_add_options --disable-system-extension-dirs +ac_add_options --disable-vtune +ac_add_options --disable-callgrind +ac_add_options --disable-eme +ac_add_options --without-onnx-runtime +EOF + + ./mach configure + ./mach build + + DESTDIR="$PKG" ./mach install + + # Desktop integration + install -Dm644 "$SRC"/thunderbird.desktop "$PKG"/usr/share/applications/thunderbird.desktop + mkdir -p "$PKG"/usr/share/pixmaps + ln -sf /usr/lib/thunderbird/chrome/icons/default/default128.png \ + "$PKG"/usr/share/pixmaps/thunderbird.png + + # System-wide privacy prefs (default prefs, user-overridable) + install -Dm644 "$SRC"/rawnix.js \ + "$PKG"/usr/lib/thunderbird/defaults/pref/rawnix.js + + # Cleanup + rm -f "$PKG"/usr/lib/thunderbird/thunderbird-bin + rm -rf "$PKG"/usr/lib/thunderbird/features + rm -f "$PKG"/usr/lib/thunderbird/removed-files +} + +signify() { + untrusted comment: public key + RWTZ9IduCSQ/mL8337TEUinPwT92xFEUpD92hkS7IxcOnzTt9QdpohT3 +} + +# vim: filetype=sh diff --git a/opt/thunderbird/rawnix.js b/opt/thunderbird/rawnix.js new file mode 100644 index 0000000..6285d01 --- /dev/null +++ b/opt/thunderbird/rawnix.js @@ -0,0 +1,90 @@ +// rawnix default prefs for Thunderbird +// Installed to /usr/lib/thunderbird/defaults/pref/rawnix.js +// These are defaults: users can override them in about:config or prefs.js. + +// Telemetry, studies, data reporting +pref("toolkit.telemetry.enabled", false); +pref("toolkit.telemetry.unified", false); +pref("toolkit.telemetry.archive.enabled", false); +pref("toolkit.telemetry.server", "data:,"); +pref("toolkit.telemetry.newProfilePing.enabled", false); +pref("toolkit.telemetry.shutdownPingSender.enabled", false); +pref("toolkit.telemetry.firstShutdownPing.enabled", false); +pref("toolkit.telemetry.updatePing.enabled", false); +pref("toolkit.telemetry.bhrPing.enabled", false); +pref("toolkit.telemetry.coverage.opt-out", true); +pref("toolkit.coverage.opt-out", true); +pref("toolkit.coverage.endpoint.base", ""); +pref("datareporting.healthreport.uploadEnabled", false); +pref("datareporting.policy.dataSubmissionEnabled", false); +pref("app.shield.optoutstudies.enabled", false); +pref("app.normandy.enabled", false); +pref("app.normandy.api_url", ""); +pref("breakpad.reportURL", ""); + +// Start page, in-app notifications, default-client nag +pref("mailnews.start_page.enabled", false); +pref("mailnews.start_page.url", "about:blank"); +pref("mailnews.start_page.override_url", ""); +pref("mail.inappnotifications.enabled", false); +pref("mail.shell.checkDefaultClient", false); + +// Account setup: don't send the full address to the ISP's autoconfig +// server, and only accept TLS configs. Keeps ISPDB lookup working. +pref("mailnews.auto_config.fetchFromISP.sendEmailAddress", false); +pref("mailnews.auto_config.ssl_only", true); + +// Cloud/provider features +pref("mail.cloud_files.enabled", false); +pref("mail.provider.enabled", false); + +// Message display: block remote content, render HTML as sanitized +// "Simple HTML" (View > Message Body As to change per user) +pref("mailnews.message_display.disable_remote_image", true); +pref("mailnews.display.html_as", 3); +pref("mailnews.display.disallow_mime_handlers", 3); +pref("mail.phishing.detection.enabled", true); +pref("network.IDN_show_punycode", true); + +// Feeds: show the feed summary instead of loading the web page +pref("rss.show.content-base", 1); + +// Outgoing headers: no User-Agent, no Content-Language, +// UTC Date rounded to the minute, generic EHLO +pref("mailnews.headers.sendUserAgent", false); +pref("mail.suppress_content_language", true); +pref("mail.sanitize_date_header", true); +pref("mail.smtpserver.default.hello_argument", "[127.0.0.1]"); + +// Never send read receipts +pref("mail.mdn.report.enabled", false); + +// Compose in plain text by default (uncomment if wanted) +// pref("mail.identity.default.compose_html", false); + +// Chat (IRC/Matrix/XMPP) +pref("mail.chat.enabled", false); + +// Network: no prefetching or speculative connections +pref("network.prefetch-next", false); +pref("network.dns.disablePrefetch", true); +pref("network.predictor.enabled", false); +pref("network.http.speculative-parallel-limit", 0); +pref("network.captive-portal-service.enabled", false); +pref("network.connectivity-service.enabled", false); + +// Safe Browsing: built without keys, so disable the lookups +pref("browser.safebrowsing.malware.enabled", false); +pref("browser.safebrowsing.phishing.enabled", false); +pref("browser.safebrowsing.downloads.enabled", false); +pref("browser.safebrowsing.downloads.remote.enabled", false); + +// Add-on recommendations +pref("extensions.getAddons.showPane", false); +pref("extensions.htmlaboutaddons.recommendations.enabled", false); + +// Attack surface a mail client doesn't need +pref("media.peerconnection.enabled", false); +pref("webgl.disabled", true); +pref("geo.enabled", false); +pref("geo.provider.network.url", ""); diff --git a/opt/thunderbird/thunderbird.desktop b/opt/thunderbird/thunderbird.desktop new file mode 100644 index 0000000..5ba0733 --- /dev/null +++ b/opt/thunderbird/thunderbird.desktop @@ -0,0 +1,12 @@ +[Desktop Entry] +Name=Thunderbird +GenericName=Email Client +Comment=Send and receive email +Exec=thunderbird %u +Icon=thunderbird +Terminal=false +Type=Application +MimeType=message/rfc822;x-scheme-handler/mailto;application/x-xpinstall; +Categories=Network;Email; +StartupNotify=true +StartupWMClass=thunderbird -- cgit v1.3.1