Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package chromium for openSUSE:Factory checked in at 2026-09-07 11:29:43 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/chromium (Old) and /work/SRC/openSUSE:Factory/.chromium.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "chromium" Mon Sep 7 11:29:43 2026 rev:544 rq:1375678 version:152.0.7977.82 Changes: -------- --- /work/SRC/openSUSE:Factory/chromium/chromium.changes 2026-08-27 18:54:10.610446991 +0200 +++ /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium.changes 2026-09-07 11:31:01.121549014 +0200 @@ -1,0 +2,60 @@ +Thu Sep 3 19:51:30 UTC 2026 - Andreas Stieger <[email protected]> + +- Chromium 152.0.7977.82 (boo#1278683): + * CVE-2026-85046: Type confusion in V8 + * CVE-2026-85052: Out of bounds read in CrashReporting + * CVE-2026-85043: Incomplete cleanup in Network + * CVE-2026-85048: Use after free in Compositing + * CVE-2026-85045: Race condition in V8 + * CVE-2026-85050: Out of bounds write in WebGL + * CVE-2026-85053: Improper resource exposure in CacheStorage + * CVE-2026-85042: Use after free in DevTools + * CVE-2026-85049: Use after free in Skia + * CVE-2026-85051: Type confusion in Compositing + * CVE-2026-85047: Improper input validation in Transactions Platform + * CVE-2026-85044: Use of released resource in Mobile + +------------------------------------------------------------------- +Wed Sep 2 06:53:41 UTC 2026 - Andreas Stieger <[email protected]> + +- Chromium 152.0.7977.75 (boo#1278072): + * CVE-2026-84353: Use after free in Shared Tab Groups + * CVE-2026-84352: Use after free in WebGL + * CVE-2026-84354: Incorrect authorization in FileSystem + * CVE-2026-84359: Information leak in Skia + * CVE-2026-84357: Improper input validation in Omnibox + * CVE-2026-84324: Use after free in Proxy + * CVE-2026-84349: Use after free in Browser + * CVE-2026-84326: Uninitialized resource in V8 + * CVE-2026-84333: Use after free in Dawn + * CVE-2026-84351: Buffer overflow in GPU + * CVE-2026-84325: Improper input validation in DataTransfer + * CVE-2026-84328: Missing authorization in FileSystem + * CVE-2026-84347: Use after free in WebRTC + * CVE-2026-84323: Missing authorization in FileSystem + * CVE-2026-84355: Incorrect authorization in Navigation + * CVE-2026-84358: Improper privilege management in Downloads + * CVE-2026-84332: Incorrect authorization in SiteSettings + * CVE-2026-84330: UI misrepresentation in FullScreen + * CVE-2026-84334: Incorrect authorization in Chromoting + * CVE-2026-84348: Information leak in MediaCapture + * CVE-2026-84335: Incorrect authorization in TabStrip + * CVE-2026-84327: Incorrect authorization in Autofill + * CVE-2026-84329: Confused deputy in CredentialProvider + * CVE-2026-84356: UI misrepresentation in FullScreen + * CVE-2026-84350: Use after free in TabStrip + * CVE-2026-84331: Incorrect authorization in Actor + +------------------------------------------------------------------- +Tue Sep 1 18:20:16 UTC 2026 - Andreas Stieger <[email protected]> + +- build with llvm22 on openSUSE Tumbleweed + +------------------------------------------------------------------- +Thu Aug 27 18:58:50 UTC 2026 - Andreas Stieger <[email protected]> + +- update patch that disables EULA dialog to use preferences instead + of a hardcoded return + chromium-151-no-eula.patch chromium-152-no-eula.patch + +------------------------------------------------------------------- Old: ---- chromium-151-no-eula.patch chromium-152.0.7977.64-linux.tar.xz New: ---- chromium-152-no-eula.patch chromium-152.0.7977.82-linux.tar.xz ----------(Old B)---------- Old: of a hardcoded return chromium-151-no-eula.patch chromium-152-no-eula.patch ----------(Old E)---------- ----------(New B)---------- New: of a hardcoded return chromium-151-no-eula.patch chromium-152-no-eula.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ chromium.spec ++++++ --- /var/tmp/diff_new_pack.nLCSnY/_old 2026-09-07 11:31:14.301010987 +0200 +++ /var/tmp/diff_new_pack.nLCSnY/_new 2026-09-07 11:31:14.303011058 +0200 @@ -63,8 +63,8 @@ # LLVM version %if 0%{?suse_version} > 1600 # LLVM version -%define llvm_version 21 -%define llvm_version_long 21.1.8 +%define llvm_version 22 +%define llvm_version_long 22.1.8 # RUST version %define rust_version 1.93 %else @@ -132,7 +132,7 @@ %global official_build 1 Name: chromium%{n_suffix} -Version: 152.0.7977.64 +Version: 152.0.7977.82 Release: 0 Summary: Google's open source browser project License: BSD-3-Clause AND LGPL-2.1-or-later @@ -205,7 +205,7 @@ Patch402: chromium-150-toolchain.patch Patch403: chromium-152-revert-crubit.patch Patch404: chromium-152-value_or.patch -Patch405: chromium-151-no-eula.patch +Patch405: chromium-152-no-eula.patch # conditionally applied patches ppc64le only # where applicable patch numbers from fedora specfile + 100 Patch452: ppc-fedora-memory-allocator-dcheck-assert-fix.patch ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.nLCSnY/_old 2026-09-07 11:31:14.456016421 +0200 +++ /var/tmp/diff_new_pack.nLCSnY/_new 2026-09-07 11:31:14.460016561 +0200 @@ -1,6 +1,6 @@ -mtime: 1787687527 -commit: 76b02729f0978d32650ef751a84d7c62cff2fdc48baf10b65e8e2c7442a9e376 +mtime: 1788465131 +commit: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b url: https://src.opensuse.org/chromium/chromium -revision: 76b02729f0978d32650ef751a84d7c62cff2fdc48baf10b65e8e2c7442a9e376 +revision: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b projectscmsync: https://src.opensuse.org/chromium/_ObsPrj.git ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-03 21:52:11.000000000 +0200 @@ -0,0 +1,4 @@ +.osc +*.patch~ +*-build/ +.*.swp ++++++ chromium-151-no-eula.patch -> chromium-152-no-eula.patch ++++++ --- /work/SRC/openSUSE:Factory/chromium/chromium-151-no-eula.patch 2026-08-25 13:20:36.305049038 +0200 +++ /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium-152-no-eula.patch 2026-09-07 11:30:44.373961969 +0200 @@ -1,15 +1,13 @@ -Index: chromium-151.0.7922.173/chrome/browser/first_run/first_run_internal_linux.cc +Index: chromium-152.0.7977.64/chrome/browser/first_run/first_run.h =================================================================== ---- chromium-151.0.7922.173.orig/chrome/browser/first_run/first_run_internal_linux.cc -+++ chromium-151.0.7922.173/chrome/browser/first_run/first_run_internal_linux.cc -@@ -50,6 +50,10 @@ bool ShowEulaDialog() { - return true; - } - -+ // Do not show an empty placeholder text in openSUSE's chromium build -+ // boo#1276225 -+ return true; -+ - base::RunLoop run_loop; - bool accepted = false; +--- chromium-152.0.7977.64.orig/chrome/browser/first_run/first_run.h ++++ chromium-152.0.7977.64/chrome/browser/first_run/first_run.h +@@ -74,7 +74,7 @@ struct MasterPrefs { + bool confirm_to_quit; + #endif + #if BUILDFLAG(IS_LINUX) +- bool eula_required = true; ++ bool eula_required = false; + #endif + }; ++++++ chromium-152.0.7977.64-linux.tar.xz -> chromium-152.0.7977.82-linux.tar.xz ++++++ /work/SRC/openSUSE:Factory/chromium/chromium-152.0.7977.64-linux.tar.xz /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium-152.0.7977.82-linux.tar.xz differ: char 15, line 1
