GeckoView for Android
mozilla.github.io
mozilla.github.io
The core of our player application is a Progressive Web Application that runs everywhere and just needs a native container like Electron or a Webview to run. Our customers run on whatever hardware they want(Windows, Mac, ChromeOS, etc)and Android is a really compelling platform since there's a ton of inexpensive AndroidTV devices out there but quality is all over the place.
If you depended on the system provided Webview on AndroidTV you may get anything from version 50 to 80 of Chrome due to fragmentation of the platform and poor update habits of some manufacturers. Our app uses features like CSS grid and doesn't run on a large fraction of Webviews out there in the wild.
The system Webview also doesn't provide much control at all for customizing the browser engine. GeckoView lets you do pretty much anything allow us to support important features we provide with our Electron clients.
You also don't need to worry about a browser update causing trouble as you control when you update the browser engine.
It's a shame that iOS doesn't have something similar because it's a really horrible platform due to Apples Webview for use cases like ours.
would you please write a blog post detailing how did you achieve this?
Or better provide a github repo as an example
thanks
This concerns me. Under the current google model, as long as you have a play store compatible device, you get chrome webview updates through the play store, even if the device fw is eol.
If an app developer doesn't update their app, then you can have potentially vulnerable version of geckoview lying around. I hope a decoupling/webview-style update mechanism is eventually implemented, although I don't know how feasible that is (i'm an amateur android dev)
That said, I really do like the project. And, I use firefox as my personal browser, both on principle and because it's quality software.
Android is the Wild West, with all the good and bad that follows. Manufacturers are often not implementing things properly. Problem is that these devices are all over Amazon and people buy them and expect them to work. We try to steer people to good quality devices such as the Nvidia Shield but you can only do so much.
Keep in mind that GeckoView may not be used to build a browser. Rather it's often an engine used to drive an application built with web technologies. So a developers requirements for updates are different than an interactive browser of arbitrary web content.
The story is the same on the desktop with Electron. When you deploy an electron app the browser underneath it is locked in conjunction with the version of Electron.
It's still up to the app developer to be responsible and follow issues and update as required. But that's a lot less often than when you have a browser of arbitrary web content.
i gathered from your comment about large amts of devices still on 50 D:
I know it won't be used for external web content, but all it takes is an escape or malicious frame/xss, and boom, mass RCE.
I don't like electron for the same reason.
I'm not saying that it's a wasteland out there, it's just one element that concerns me, is all.
It most certainly can :) the new Firefox for Android uses GeckoView.
To clarify: when I said “may not” I meant in the sense “might not” rather than it isn’t permitted.
lol I have a shitty tablet at home with Android 7 to tinker with and when I go on the Play Store is says that Google Chrome is not compatible with the device. It has something like Google Chrome 50 preinstalled and can't be updated.
Good luck getting an updated version of WebView.
This is completely up to them of course, and it probably let them move firefox forward faster, due to not having to care about APIs. However, it also means that chrome completely took over the entire market with electron and similar things.
As you said, this is too little, too late. I'm a Firefox user, but Chrome has pretty much won the browser wars. The only thing preventing it from achieving complete market dominance is the existence of Mobile Safari.
This is for example why Chrome decided to fork WebKit.
(I do believe that people messed around with Electron drop-in replacements, but it's probably hard to sell if it doesn't bring anything new to the table.)
People coding specifically to Chrome when writing Electron apps is way less harmful to the web than people doing the same with web pages. The latter case specifically hurts other browsers, because people who don't use Chrome can't use the site.
Additionally, each Electron app represents a (smallish group of) developers. They're a very small number compared to all the developers writing public-facing websites that (should!) work in all commonly used browsers.
What evidence do you have for this?
AFAIK the main reason why Microsoft picked Chromium is that Web sites are pretty much guaranteed to work well in Chromium without Microsoft having to do any work.
they stated that their experience with CEF (Chromium Embedded Framework) was instrumental in their decision.
VSCode (built on electron) was probably the main PoC for them.
https://docs.microsoft.com/en-us/microsoft-edge/hosting/webv...
Brave is run by ex-Mozilla folks and started with Gecko, but switched to Blink very early on. [1] Their reasons didn't include Electron, so Microsoft's may not have either.
[1] Collection of tweets, and a response from someone at Brave: https://www.reddit.com/r/BATProject/comments/9jpqde/brave_br...
(Disclosure: I work for Google, though not on Chrome. Speaking only for myself.)
What I mean by this - I can recognize a non-Elector vs Electron app by the amount of RAM it consumes. Is your simple color picker/text editor/REST caller/mouse config/ToDo app taking 1GB+ of RAM? It's an Electron app.
For the record, I doubt FF based app would face much better.
At this point, I could almost tolerate the wasted RAM and CPU if interaction latency wasn't that bad.
What made it extra unappealing for Mozilla was that we knew the Firefox/Gecko architecture needed lots of work that would destabilize an embedding API. Not much point in supporting an API that assumes single-process while you're moving to multi-process, or that exposes XUL which you know is a dead end, or that isn't compatible with off-main-thread rendering or GPU rendering, etc. Things are much better now that a lot of that debt has been paid off.
That said, I'm not sure what the point is. I believe (but could be wrong) that Chromium has more features that Gecko doesn't? So if you're choosing one over the other I'm only guessing most people would choose Electron
-- Chromium was faster. (For Electron apps you don't really care about Web compat, where Firefox was ahead of Chromium for a while, but you do care about performance.)
-- Chromium was already multiprocess and had some other architectural advantages where Gecko was still catching up. So, less upcoming architectural churn.
-- Chromium had Google's resources committed to it. (Google's shine has worn off a bit since then but it's still a powerful effect.)
Yeah, sure, imitating your competition is the right way to handle that. /s
References:
1. https://www.dedoimedo.com/computers/firefox-addons-future.ht...
2. https://www.dedoimedo.com/computers/firefox-disable-australi...
3. https://www.dedoimedo.com/computers/firefox-29-sucks.html
4. https://www.dedoimedo.com/computers/firefox-suckfest.html
Probably the same could have been said about IE ~20 years ago.
This is less of a war, more of a never-ending race. Currently (temporarily?) Chrome is ahead.
On desktop Mozilla did that: https://en.wikipedia.org/wiki/XULRunner
It was quite successful und I never understodd what happend for them to abonded it and let mozilla run down so deep into s* as it is now.
https://en.wikipedia.org/wiki/Category:Software_that_uses_XU...
Your comment reminds me of a 15 or 20 year old remark from Feeddemon and Topstyle author (Nick Bradbury) about how he gave up baking firefox preview into his CSS editor.
https://nick.typepad.com/blog/2008/03/can-mozilla-be.html
I loved Topstyle. It was the first editor I invested time into (after Visual Basic for windows 3.11 in the 90's but I was a kid, not a professional or a student).
Unfortunately, there were strategic decisions to basically never maintain it :(
Given more resources, Mozilla absolutely could have done a better job of transitioning faster from XUL to standards-friendly equivalents, and popularizing the latter in an Electron-like framework. But there was never a time when Mozilla had excess resources floating around, and other things took priority. (Also see my comment above about how architectural churn made it unattractive to support a stable embedding API.) As was pointed out in other comments, the benefits of regular Web market share tend to outweigh the benefits of embedding popularity.
Now that I think about it Winamp 3 had its own interesting application framework (https://en.wikipedia.org/wiki/Wasabi_(software)).
..for the 90s. There was very little about XUL that would survive today other than its layout model
Ignoring that XUL has a single implementation and for the most part a single application suite actually using it (not 100% true but very close), I'm not sure what there was to blow.
OTOH I remember some custom XUL apps of yesteryear, and they were always pretty nice to use. Does Firefox have any XUL left? I know there have been ideas to rip it out for a very long time.
What's the issue with that? GTK, WPF Qt, Flutter ... all have a single major implementation.
> for the most part a single application suite actually using it
That is now, but it could've been a lot different.
I'm not that familiar with XUL (I'm just old enough to experience it being phased out) but it appears like a great idea to me: XML is not exactly bad for a UI, but XAML is Microsoft-specific (and not exactly great) and HTML is made for documents (leading to problems with worries about semantic tags, lack of layout features ...).
I also quite like how well Firefox integrates with all kinds of platforms. But who knows, maybe that's not in XUL, but specific to FF.
Yes, recently there's been a big rewrite of lots of things as web components, but some XUL leftovers are still there.
I remember trying it on my Nexus One, back when that phone was hot shit. Constant full-screen checkerboarding.
Mozilla literally had to rewrite Firefox for Android and eliminate XUL from the Android version before it became a usable product.
I think it's at least 45 ESR, as mentioned in release notes ~year ago: https://blog.jolla.com/hossa/
There is an issue tracking the Gecko update on the community discussion/bug reporting tool used for Sailfish OS: https://together.jolla.com/question/133621/update-gecko-in-t...
The source of the Sailfish OS browser lives here: https://github.com/sailfishos/sailfish-browser
(Even though Sailfish OS is sadly not fully open source, the browser is as are other core applications and frameworks.)
> the licence made it very simple for us to decide - WebKit was MIT, Gecko wasn't.
...So what? If it runs on your server, it could be just about anything and it wouldn't matter so long as it's not AGPL. Or was the server meant to belong to the customer?
I am investigating a way to use FF on system as is though by providing a custom profile, a user.css to remove everything but the browser window itself (i.e. no tabs, toolbar, etc), capturing it as a native window (e.g. via QWindow::fromWinId and QWidget::createWindowContainer), and communicating with it via marionette or other remote approach. So far it seems to be ok, but it's a bit of a hack.
There was an equivalent Gecko one for Firefox but I could never get it working correctly so deferred to CEF under Visual Studio (think there's a nuget package for it, conveniently).
Also wxWidgets under C++ offers ability to host a local WebView instance or Trident with wxWebView.
This has been in the works since at least 2016. I believe conversations around improving the embedding story were happening before that, too.
An embeddable Gecko would've created a wonderful ecosystem around it, produced headless browsers, a much wider range of browser alternatives, and had much more leverage when it comes to standard. They had... 8 years? 5 years? on Chomium and now have one hell of a task to correct that error.
Looking at the code of their new layout engine written in Rust, making it embeddable wasn't even remotely on their minds either. A real pity.
Web browsers need patching pretty much every week, and having every app developer needing to re-release their app every time isn't practical. The alternative is a world where my phone can be compromised because an ad rendered in an app using a 3 week old build of gecko had a browser exploit in.
Disadvantage is that as an app developer you're not guaranteed to have any specific version available. Some devices never upgrade the pre-installed version automatically. The user is also able to switch between the Chrome webview and an OS webview on some devices (in developer settings, so it's not common). You can add checks in your app and direct the user to the update links, but requires quite a bit of work to do well.
There is no reason Mozilla could not do that with GeckoView.
Only mostly sarcastic.
That's a lofty, and frankly, unnecessary goal.
Maybe Positron could/should be revived, as a thing of its own, an independent Gecko-based app host, with its own API, distinct and separate from Electron.
(I'm guessing the author of Positron was hoping to attract current Electron users by aiming to make a switch as easy and seamless as possible with a compatible API, and while that's valuable, it would be good to just have an incompatible Electron competitor to begin with.)
[1] https://imgur.com/r8Qti and https://bugzilla.mozilla.org/show_bug.cgi?id=1163827
However, I bet noone would choose gecko because it adds to the APK size.
And finally (and this applies to a standalone GeckoView package without direct API compatibility as well), end users being able to update the Webview independently from the apps using that Webview package means that you're suddenly operating under much more severe backwards compatibility constraints.
(Disclaimer: I work for Mozilla but not on this)
There's a concept of Chrome Custom Tabs - https://developer.chrome.com/multidevice/android/customtabs where the app asks the devices browser to show content hosted inside. Even though the name includes "Chrome", other browsers can provide these as well - I know Firefox for Android and Samsung Browser implement the API and handle the rendering if they're set as default.
I guess it depends on one's definition of "excellent", but I'm still waiting on ES2018's regex lookbehind assertions to be implemented.
And what about Flex-box's safe value for the justify-content property, allowing to justify (center) an element, but still be sure that the left side of the content will not be hidden if the parent container is too small? Right, supported on Firefox since version 63 released on October 23, 2018 and still not supported on Chrome (and to add insult to injury, safe is recognized, it just does nothing, which is worse than really not supporting the feature).
I didn't look for these missing features on purpose, I have been annoyed by them recently or less recently. So as for Chrome's excellent support for modern Web standard, I guess it depends on one's definition of "excellent".
Or more accurately, you can find lacking support for some features of the Web standard in any browser engine. :-)
Food for thought however: what is implemented elsewhere may be an indicator of was level of excellence is achievable.
What others can do is an indication of what is achievable only if what they do is optimal, like let's say for example that a monkey learns 10 words in a planet full of comparable monkeys and things less capable than that, does that environment make the monkey excellent in general as far as learning words goes? I don't think so. I would argue excellence in this sense is to be measured in the scale of what's possible, not as a comparative measure that changes depending on the environment. In this case in particular I wouldn't consider lacking features spec'ed 2 years ago excellence, your mileage may vary.
Yes, they provide mobile browsers, plus a browser with "private mode" (focus) and now this. But on every single one of them, you have the same philosophy of Google Chrome (tm) adopted, of treating the user as a dumb gullible person that should not have access to important settings.
Why would they waste so much effort, and clone all the things people should avoid from Google Chrome?!
For example, any new tech introduced that can be used for browser fingerprinting and user tracking (e.g. canvas, webgl, webrtc, etc) is enabled to every single site by default, just like chrome.
Some you can install extensions (you can't on this and on mozilla focus), some you can fiddle with user-UNfriendly settings in about:config (desktop and full featured android, not focus or this) where you have to guess setting names and cryptic values (what does 2 means in a setting named somethingEnabled?!)
Only on mozilla desktop you can standardize sane settings by importing a user.js file from the dozen of crowdsourced efforts (i recommend the most complete one from https://github.com/pyllyukko/user.js/ ). think about this, there's more then a dozen community led effort to provide sane defaults, not hardcore user optimized settings, sane defaults, for a project that should be open source and the users could have been able to send in patches to have sane defaults in the first place! now, why would those sane defaults everyone want would be denied in the main branch? because mozilla do not represent the users for a long time!
Mozilla is now a corporation that looks for Advertisement companies grants.
GeckoView exposes a wide range of privacy (including anti-tracking and anti-fingerprinting) features in a (hopefully) comprehensive API, see https://mozilla.github.io/geckoview/javadoc/mozilla-central/..., and continues expanding its privacy settings.
> Some you can install extensions (you can't on this and on mozilla focus)...
GeckoView also exposes a WebExtension API, see https://mozilla.github.io/geckoview/javadoc/mozilla-central/..., and continues to expand extension support.
> ...some you can fiddle with user-UNfriendly settings in about:config...
You seem to have answered one of your own questions here.
I also have the impression that you might have not commented on the GeckoView library, but on some range of Mozilla products (you named Focus).
that's is a fallacy and you know it!
There are ZERO settings exposed to the end user.
Those settings are exposed to the App embedding geckoviewer. In other words, the privacy settings are in the hands of the actor who benefit from Advertising by tracking the user!
> GeckoView also exposes a WebExtension API
again to the app.
This thread is discussing GeckoView, which exposes extensive privacy settings.
There is a (hopefully growing) amount of apps based on GeckoView, which will make use and/or expose different variations of GeckoView settings to the user, depending on the purpose and target audience of the app.
You might disagree, but, for example, I consider the level of detail in privacy settings provided by Fenix (Nightly) to be a good balance between user control and comprehensibility.
> > GeckoView also exposes a WebExtension API > again to the app.
Again, taking Fenix (Nightly) as an example, the GeckoView WebExtension API is used to provide a growing selection of add-ons, many of which are aimed at the privacy-conscious user, including uBlock Origin, HTTPS Everywhere, NoScript and Privacy Badger.
Who would use Firefox if all those things who are disabled? Probably about as many people who still use Slackware. At which point, what exactly would be the point? The web is at least safer place to be with Firefox in its current state than with Chrome and Edge having 99% dominance.
If it were truly open source, we would, gasp, have the best of both worlds by making the UI sane and what the end user wants. Not what a few in the inner circle thinks possible in their limited life experience.
Mozilla killed more projects trying to fix firefox than i care to count. icecat i think was the last one. fenned-by-fdroid was killed and resurrected a couple times, last people i know that contributed left when user.js was disabled after a PR from a google engineer was merged "to make fennec better follow android security team recommendations" or something on those lines.
They even implemented bad web standards which its absence would not break websites, such as hyperlink auditing and reporting API.