404PrivacyDocs

JavaScript runtime

The browser-side runtime is a JavaScript bundle built from assets/js/src/runtime.js and embedded in the Rust binary. It reads the profile configuration injected with the page’s script element, initializes shared state, and installs selected wrappers for browser APIs. It is page code, so it cannot change native browser behavior before it loads or outside contexts it reaches.

Bootstrap sequence

The bundle sets up a shared runtime registry, captures native references, installs Function.prototype.toString masking for wrapped functions, reads the nonce and config, initializes deterministic entropy and policy, then installs modules. Policy flags can disable some modules. A compatibility policy suppresses audio and event-timing modules on a small set of named services.

Module familyExamples of surfaces
Identitynavigator, User-Agent Client Hints on Chromium-family profiles, screen, timezone, plugins, fonts, performance.
CapabilitiesPermissions, notifications, battery, storage, network, media capabilities.
Rendering and mediaCanvas, WebGL, audio, media devices, speech, gamepads, WebRTC, event timing.
Evasion and privacySelected automation signals, geolocation denial, beacon handling.
Context propagationSame-origin iframe descriptors and supported classic worker bootstrap.

These are wrappers around supported APIs, not a replacement for the rendering engine. A Firefox engine running a Chrome profile can expose contradictory behavior even if a navigator string matches Chrome. See Profile anatomy for family selection.

Iframes and workers

The iframe module propagates selected registry state and descriptors into reachable same-origin frames. Cross-origin frames are not freely accessible to parent-page JavaScript. The automation module wraps Worker and SharedWorker constructors to create a blob bootstrap for classic workers created after installation. In the current implementation, module workers pass through untouched because blob rewriting would break relative module imports. Service workers and pre-existing workers also remain outside this bootstrap path.

Stability is conditional

The runtime derives entropy from shared profile and startup state to keep selected values internally consistent. Individual API modules may have compatibility limits; page timing, CSP, browser internals, and native engine details still matter. The separate behavioral_noise_v1.js and Rust behavioral stage include placeholder logic; do not read them as a complete synthetic-behavior system.

Source: runtime entrypoint, policy, worker wrappers, and iframe propagation.