Repository navigation
Redoubt Android 158.0-1 — Beta 1
Pre-releaseImportant
This is a prerelease, built from Firefox 158.0b4, which is Mozilla's beta source. Firefox 158.0 is scheduled for 2026-10-09. Redoubt 158.0-1, built from the final 158.0 source, will follow it and installs over this beta as an update. Redoubt 157.0-3 is still the current stable release. Install this beta only if you want to try Firefox 158 early and can live with beta bugs.
First beta of Redoubt for Android on Firefox 158. It installs over 157.0-3 as an update and keeps your settings. Requires Android 8.0 or later.
Redoubt is an independent project. It is not affiliated with or endorsed by LibreWolf or Mozilla. Website: https://redoubtbrowser.org
How you get it, and how you leave it
- The in-app update check will not offer this beta. It only announces stable releases, so 157.0-3 installs keep saying they are up to date. To try the beta, download it from this page.
- Obtainium: prereleases are offered only if Include prereleases is on for this app.
- Back to stable: 158.0-1 installs over this beta as a normal update. Going back to 157.0-3 is not possible without uninstalling first, which deletes your data, because Android does not install a lower version over a higher one.
- Version shown in About: 158.0b4-1. The final release will show 158.0-1.
What's new since 157.0-3
Firefox 158. The engine moves from Firefox 157 to the 158 beta (158.0b4), with its fixes and changes. Redoubt's patches and privacy configuration carry over; the packaged librewolf.cfg is byte-identical to 157.0-3's.
Password managers can fill Reddit-style login forms. Some sites, reddit.com/login among them, put their username and password fields inside page components (open shadow roots). Android autofill services got no fill request when you tapped such a field. They now get one (tested with a test autofill service; no individual password manager has been tested yet). Only login fields count: a form needs a password field. A newsletter or checkout email field inside a component still does not trigger a request, as in Firefox. Fields inside closed components are still not reachable.
"Delete browsing data on quit" now also works when the app is swiped away, killed or crashes. Before, it ran only when you chose Quit in the menu. Now:
- if the last session did not end with Quit, the next start deletes the data types you selected before any tab, link, custom tab or shortcut loads a page;
- swiping the app away from recent apps also starts the deletion right away, when no other Redoubt window (a custom tab or an installed web app) is still open.
What this means for you: with Cookies selected, any exit other than Quit now logs you out of every site: a swipe-away, Android stopping the app in the background, a crash, or a phone restart. That is what the setting promises, but before this release it often did not happen.
The guarantee is bounded. If the engine has not confirmed the deletion 20 seconds after it started, the start continues anyway (so the browser cannot hang) and the deletion is tried again after the next exit that is not Quit. If the app dies during the deletion itself three starts in a row, the next start skips it, so a deletion that keeps failing cannot lock you out of the browser. Not held back by the deletion: uBlock Origin's filter-list updates, and a pre-connect (no request, no cookie) that an app opening a custom tab may ask for. With Browsing history selected, restored tabs also lose their back/forward list.
Switching uBlock Origin off right after start no longer pauses browsing. If you disabled uBO in Settings → Add-ons while the browser was still starting, pages could stay paused until the start-up wait gave up, with a "startup failed" message. Redoubt now sees that you switched uBO off and lets pages load (unfiltered, as you asked) right away.
Everything else carries over from 157.0-3: uBlock Origin 1.75.0 with the cookie-notice lists on by default, H.264/AAC video playback, the opt-in update check without Accept-Language and hidden on store installs, and the same signing key.
Verify what you downloaded
sha256sum -c SHA256SUMS.signed
apksigner verify --print-certs fenix-<abi>-release.apk | grep -i SHA-256
The certificate digest must be:
64:14:EB:33:46:81:CF:6E:92:90:34:B5:6A:06:2D:2B:8D:A0:90:82:21:72:F7:A3:95:2C:85:FD:D1:28:3B:D0
Signed with APK signature schemes v2 and v3, no v1, using the same key as 157.0-3 and every earlier release.
Which file
fenix-arm64-v8a-release.apk: almost any phone from the last several years.armeabi-v7a: older 32-bit devices.x86_64: emulators.- The universal APK carries all three and is much larger.
Known limitations
These are stated plainly; see docs/android/PARITY.md.
- Beta source: Firefox 158.0b4 is not the final 158.0. Mozilla may still change things before 2026-10-09, and 158.0-1 will be rebuilt from the final source.
- Device testing: automated device testing ran on an x86_64 emulator (Android 14). The ARM builds were checked but not run on a physical phone. Reports from real devices are welcome.
- Autofill: tested only with a test autofill service, test pages and reddit.com/login; no individual password manager (Proton Pass, Bitwarden, KeePassDX…) has been tested yet. On a fresh profile, opening reddit.com/login directly can stay blank (as in 157); open reddit.com first.
- No content-process sandbox on Android: Gecko's content sandbox does not exist on Android, and Android's isolated processes are not used (they break H.264/AAC video; see the 157.0-3 notes). Redoubt ships the same privacy configuration and Gecko security patches as LibreWolf desktop, on a platform with weaker process containment.
- DNS over HTTPS: DoH configuration from preferences doesn't apply. Use the DoH screen in Settings.
- Signing key: one person holds the signing key.
Provenance
- Source: built from
6d146b418962b95631bd4f6da3d9cdbac65b081e(branchandroid/158-beta1) against Firefox 158.0b4 (firefox-158.0b4.source.tar.xz, sha2566e8c17884180287eb31269bd7ada0b6c92440434caa285986101835373e2111a, signature checked against Mozilla's release key). - Build: CI run 37576802707, with MOZ_BUILD_DATE 20261007050000; versionCodes 2016188904-2016188911.
- Signing: signed by the maintainer; CI never sees the key.
- Evidence:
docs/android/evidence/lw-m7-01/release-158.0-1-beta.1/,docs/android/evidence/lw-m7-42/,lw-m7-44/andlw-m7-45/.