Read this before touching anything that names the project, and before assuming what we can publish or where.
Most of this board was planned on an unstated assumption: that this work was being
done by the LibreWolf project. It is not. This repository is a fork of
librewolf.dev/librewolf/source, worked on by someone who is not a LibreWolf
developer.
That assumption reached eleven tasks — "Set up the LibreWolf F-Droid repository", "Publish the Android pages on librewolf.net", "Update the FAQ and close out issue 2169", the signing key, the Codeberg tracker. All of those have been re-scoped or placeholdered. If you find another, it is a bug: fix it rather than working around it.
The source is MPL-2.0. Section 3.4 is explicit: the licence grants no rights in any contributor's trademarks, service marks or logos.
So:
| fork the code, modify it, ship it | yes — that is what the MPL is for |
| ship it called "LibreWolf" | no |
| ship LibreWolf's privacy configuration | yes, with attribution |
| imply LibreWolf built, endorses or supports it | no |
There is an obvious precedent: LibreWolf exists in significant part because Mozilla's trademark policy forbids shipping modified builds as "Firefox". Doing to LibreWolf what Mozilla forbids being done to it would be a poor way to treat the project whose work this depends on.
The practical objection matters more than the legal one. A user installing "LibreWolf" from F-Droid would reasonably believe the LibreWolf team built it and would judge its security posture on that basis. They would be wrong, and the mistake would be ours.
The project is called Redoubt. Chosen 2026-08-20, after checking seven candidates against the browser, security-software and general software namespaces; six collided and this one did not. A redoubt is a small isolated fortification, which is close enough to what the process model is trying to be.
It is deliberately not a near-miss of LibreWolf, and not of IronFox or Mull either — see "the space is occupied" below.
The forge is https://github.com/CPlusPlus17/Redoubt.
Both decided 2026-08-23. No placeholders remain.
domain redoubtbrowser.org
applicationId org.redoubtbrowser
Two segments, not three. org.redoubtbrowser.android was the alternative; the
shorter form leaves the channel suffixes clean — org.redoubtbrowser.beta,
org.redoubtbrowser.debug — rather than stacking to
org.redoubtbrowser.android.beta.
libreRedoubt was proposed and rejected, and the reasoning belongs in the
record. Putting "Libre" in front reverses the whole point of choosing Redoubt:
it reads as a LibreWolf sub-brand, so a user installing it from F-Droid would
credit the LibreWolf team for its security posture and be wrong. That is the
harm this file exists to prevent, and it is what LibreWolf itself exists because
Mozilla forbids. libreredoubt.org was available; it was not taken.
redoubt.org, .net, .io, .dev, .app, .page, .software, .systems
and .build are all registered to other parties. redoubt.foundation was free
and was rejected too: there is no foundation, and claiming one would be the same
species of overclaim as "provably zero-GMS".
The domain is live (since 2026-10-04). Registered 2026-08-23 at Namecheap; it
serves the project site (GitHub Pages, built from site/, HTTPS enforced, apex
redoubtbrowser.org with www redirecting to it) and, from Beta 6, the update-check
document at /update/android/latest.json. The domain is verified for the owner's
GitHub account, so no one else can claim it on GitHub Pages.
IronFox (https://github.com/ironfox-oss/IronFox) is the active community
successor to Divested's Mull: a privacy-hardened Firefox for Android, shipped on
F-Droid, maintained. Iceraven and Fennec are also live.
This is not a reason to stop, but it does mean Redoubt has to be able to say what it does that they do not. The honest answer is the build model: Redoubt compiles Gecko from source with LibreWolf's patch set and pref configuration shared with the desktop build, rather than patching a prebuilt Fennec. That is a real difference and it is also the expensive one. LW-M7-03 owns saying it accurately and without overclaiming.
org.redoubtbrowser is one-way. A changed applicationId is a different app
to Android: no upgrade path, no data migration, every user reinstalls by hand. It
is the same severity as losing the signing key, and F-Droid and Accrescent both
key on it. It is decided; do not revisit it after the first public build.
Note the current build still ships as org.mozilla + .fenix.debug. That must
change before anything is published: it is Mozilla's namespace and it collides
with a real Firefox install.
The fork inherits upstream identifiers, and they are code, not branding. Leave them:
settings/librewolf.cfg the config file autoconfig reads
scripts/librewolf-patches.py the patcher
librewolf.* prefs 12 of them, compiled into StaticPrefList
lw/ , librewolf-<version>-<release> build paths and the source dir name
Renaming these buys nothing, breaks every patch that references them, and would
make rebasing against upstream needlessly painful. --with-app-name and the
user-visible strings are the branding surface; those belong to LW-M4-07 and
LW-M4-12.
All of the engineering. The three-way patch split, the Android build, the autoconfig channel, the telemetry removal, the measurements. None of it depends on what the result is called.
The privacy configuration is the product. Roughly 267 pref decisions in
settings/librewolf.cfg, and the patch set that makes them enforceable, are
LibreWolf's work. LW-M7-03 owns saying so prominently rather than in a licence
footer. See also docs/android/UPSTREAM-REPORTS.md — three defects found in their
build that are worth reporting back whether or not anything else here goes anywhere.