Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package chromium for openSUSE:Factory 
checked in at 2026-09-10 11:47:55
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/chromium (Old)
 and      /work/SRC/openSUSE:Factory/.chromium.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "chromium"

Thu Sep 10 11:47:55 2026 rev:545 rq:1376518 version:153.0.8010.36

Changes:
--------
--- /work/SRC/openSUSE:Factory/chromium/chromium.changes        2026-09-07 
11:31:01.121549014 +0200
+++ /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium.changes      
2026-09-10 11:50:39.624751433 +0200
@@ -1,0 +2,283 @@
+Wed Sep  9 04:29:11 UTC 2026 - Andreas Stieger <[email protected]>
+
+- Chromium 153 promoted to stable channel
+- Chromium 153.0.8010.36 (boo#1279840):
+  * CVE-2026-87464: Use after free in WebGL
+  * CVE-2026-87488: Use after free in WebGL
+  * CVE-2026-87438: Out of bounds write in WebGL
+  * CVE-2026-87527: Buffer overflow in WebGL
+  * CVE-2026-87628: Use after free in Cast
+  * CVE-2026-87512: Use after free in ANGLE
+  * CVE-2026-87585: Double free in PDFium
+  * CVE-2026-87444: Memory corruption in Codecs
+  * CVE-2026-87447: Incorrect authorization in Network
+  * CVE-2026-87440: Out of bounds read in Media
+  * CVE-2026-87633: Use after free in Views
+  * CVE-2026-87525: Out of bounds read in Chromoting
+  * CVE-2026-87578: Use after free in Receiver
+  * CVE-2026-87517: Race condition in Mobile
+  * CVE-2026-87524: Use after free in Core
+  * CVE-2026-87569: Missing authorization in Views
+  * CVE-2026-87554: Race condition in Chromoting
+  * CVE-2026-87467: Race condition in Updater
+  * CVE-2026-87492: Incorrect authorization in DevTools
+  * CVE-2026-87520: Use after free in Dawn
+  * CVE-2026-87514: Use after free in Views
+  * CVE-2026-87650: Out of bounds read in WebGL
+  * CVE-2026-87596: Out of bounds read in ANGLE
+  * CVE-2026-87654: Buffer overflow in ANGLE
+  * CVE-2026-87604: Out of bounds read in ANGLE
+  * CVE-2026-87621: Out of bounds write in ANGLE
+  * CVE-2026-87647: Uninitialized resource in GPU
+  * CVE-2026-87646: Use after free in Web Authentication
+  * CVE-2026-87500: Improper validation of array index in ANGLE
+  * CVE-2026-87572: Injection in DevTools
+  * CVE-2026-87460: Use after free in Platform
+  * CVE-2026-87542: Use after free in Input
+  * CVE-2026-87639: Use after free in WebPackaging
+  * CVE-2026-87552: Missing authorization in TrustedWebActivities
+  * CVE-2026-87651: Incorrect authorization in Paint
+  * CVE-2026-87587: Use after free in V8
+  * CVE-2026-87564: Type confusion in V8
+  * CVE-2026-87498: Missing authorization in WebUI
+  * CVE-2026-87499: Incorrect authorization in Network
+  * CVE-2026-87607: Use after free in Device
+  * CVE-2026-87558: Use after free in Payments
+  * CVE-2026-87581: Use after free in Payments
+  * CVE-2026-87480: Use after free in Printing
+  * CVE-2026-87612: Type confusion in V8
+  * CVE-2026-87536: Use after free in V8
+  * CVE-2026-87474: Use after free in Payments
+  * CVE-2026-87504: Use after free in Core
+  * CVE-2026-87640: Out of bounds read in WebView
+  * CVE-2026-87491: Out of bounds write in V8
+  * CVE-2026-87478: Observable discrepancy in Autofill
+  * CVE-2026-87446: Incomplete cleanup in Extensions
+  * CVE-2026-87657: Use after free in V8
+  * CVE-2026-87434: Missing authorization in CORS
+  * CVE-2026-87487: Missing authorization in FileSystem
+  * CVE-2026-87453: Confused deputy in BackgroundFetch
+  * CVE-2026-87588: Use after free in Chromecast
+  * CVE-2026-87636: Type confusion in XML
+  * CVE-2026-87611: Missing authorization in FileSystem
+  * CVE-2026-87606: Missing authorization in SiteIsolation
+  * CVE-2026-87456: Uninitialized resource in Media
+  * CVE-2026-87553: Improper input validation in SiteIsolation
+  * CVE-2026-87658: Information leak in Extensions
+  * CVE-2026-87465: Incorrect authorization in Downloads
+  * CVE-2026-87515: Incorrect authorization in FileAPI
+  * CVE-2026-87547: Incorrect reference resolution in FileSystem
+  * CVE-2026-87442: Confused deputy in Prerender
+  * CVE-2026-87506: Privilege elevation in WebUI
+  * CVE-2026-87433: Race condition in FileAPI
+  * CVE-2026-87557: Missing authorization in LocalNetworkAccess
+  * CVE-2026-87457: Race condition in Updater
+  * CVE-2026-87503: Inappropriate implementation in Downloads
+  * CVE-2026-87481: Incorrect authorization in WebView
+  * CVE-2026-87537: Missing authorization in Extensions
+  * CVE-2026-87471: Incorrect authorization in ServiceWorker
+  * CVE-2026-87485: Incorrect authorization in CORS
+  * CVE-2026-87652: Incorrect authorization in PushAPI
+  * CVE-2026-87582: Confused deputy in DataTransfer
+  * CVE-2026-87466: Incorrect authorization in Workers
+  * CVE-2026-87603: Missing authorization in FileSystem
+  * CVE-2026-87615: Race condition in Payments
+  * CVE-2026-87642: Uninitialized resource in WebGL
+  * CVE-2026-87577: Incorrect authorization in Isolated
+  * CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials
+  * CVE-2026-87613: Incorrect reference resolution in Extensions
+  * CVE-2026-87645: Improper state validation in Safebrowsing
+  * CVE-2026-87443: Missing authorization in Actor
+  * CVE-2026-87630: Integer overflow in WebRTC
+  * CVE-2026-87590: Improper input validation in Passwords
+  * CVE-2026-87580: Incorrect authorization in WebAppInstalls
+  * CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades
+  * CVE-2026-87497: Uninitialized resource in Codecs
+  * CVE-2026-87579: Buffer overflow in WebRTC
+  * CVE-2026-87576: Uninitialized resource in GPU
+  * CVE-2026-87476: Incorrect authorization in Loader
+  * CVE-2026-87475: Missing authorization in Omnibox
+  * CVE-2026-87436: Incomplete cleanup in Browser
+  * CVE-2026-87479: Insufficient policy enforcement in Extensions
+  * CVE-2026-87513: Missing authorization in ControlledFrame
+  * CVE-2026-87432: Incorrect authorization in Navigation
+  * CVE-2026-87560: Missing authorization in Browser
+  * CVE-2026-87521: Information leak in WebMCP
+  * CVE-2026-87539: Observable discrepancy in Network
+  * CVE-2026-87648: Use after free in ANGLE
+  * CVE-2026-87534: Missing authorization in WebView
+  * CVE-2026-87562: Incorrect reference resolution in Accessibility
+  * CVE-2026-87556: Missing authorization in Browser
+  * CVE-2026-87508: Incorrect authorization in Loader
+  * CVE-2026-87643: Integer overflow in GPU
+  * CVE-2026-87573: Improper input validation in Network
+  * CVE-2026-87548: Improper state validation in Installer
+  * CVE-2026-87501: UI misrepresentation in Passwords
+  * CVE-2026-87452: Incorrect authorization in GPU
+  * CVE-2026-87516: Observable discrepancy in Navigation
+  * CVE-2026-87599: Improper input validation in Interstitials
+  * CVE-2026-87507: UI misrepresentation in Downloads
+  * CVE-2026-87559: UI misrepresentation in UI
+  * CVE-2026-87472: Improper input validation in FedCM
+  * CVE-2026-87486: Clickjacking in TrustedWebActivities
+  * CVE-2026-87655: Clickjacking in Downloads
+  * CVE-2026-87462: UI misrepresentation in FedCM
+  * CVE-2026-87649: UI misrepresentation in Downloads
+  * CVE-2026-87445: UI misrepresentation in Session
+  * CVE-2026-87567: UI misrepresentation in UrlFormatting
+  * CVE-2026-87496: UI misrepresentation in Browser
+  * CVE-2026-87441: Missing authorization in Downloads
+  * CVE-2026-87549: Incomplete cleanup in Downloads
+  * CVE-2026-87458: UI misrepresentation in Geometry
+  * CVE-2026-87574: Information leak in ServiceWorker
+  * CVE-2026-87495: Information leak in Scroll
+  * CVE-2026-87541: Information leak in Navigation
+  * CVE-2026-87451: Information leak in Downloads
+  * CVE-2026-87570: Incorrect authorization in SiteIsolation
+  * CVE-2026-87555: Uninitialized resource in GPU
+  * CVE-2026-87600: Improper input validation in Safebrowsing
+  * CVE-2026-87532: Improper state validation in Safebrowsing
+  * CVE-2026-87439: Information leak in ServiceWorker
+  * CVE-2026-87450: Incorrect authorization in Permissions
+  * CVE-2026-87505: Incorrect authorization in FileSystem
+  * CVE-2026-87622: Missing authorization in FedCM
+  * CVE-2026-87540: Incorrect authorization in Isolated
+  * CVE-2026-87594: Incorrect authorization in DataTransfer
+  * CVE-2026-87518: Observable discrepancy in Safebrowsing
+  * CVE-2026-87589: Incorrect authorization in SiteIsolation
+  * CVE-2026-87484: UI misrepresentation in Geometry
+  * CVE-2026-87530: Uncontrolled search path element in CredentialProvider
+  * CVE-2026-87550: Improper encoding or escaping of output in CSS
+  * CVE-2026-87494: Use after free in Browser
+  * CVE-2026-87483: Incorrect authorization in Browser
+  * CVE-2026-87454: Information leak in Enterprise
+  * CVE-2026-87616: Improper initialization in Views
+  * CVE-2026-87535: Information loss or omission in Safebrowsing
+  * CVE-2026-87644: Incorrect authorization in Views
+  * CVE-2026-87533: Use after free in DevTools
+  * CVE-2026-87635: UI misrepresentation in Payments
+  * CVE-2026-87641: Race condition in Browser
+  * CVE-2026-87431: Missing authorization in Extensions
+  * CVE-2026-87493: Missing authorization in FileSystem
+  * CVE-2026-87625: Use after free in V8
+  * CVE-2026-87468: Incorrect authorization in Isolated
+  * CVE-2026-87563: Origin validation error in Paint
+  * CVE-2026-87510: Improper input validation in FileAPI
+  * CVE-2026-87435: Information leak in ControlledFrame
+  * CVE-2026-87531: Information leak in CORS
+  * CVE-2026-87637: Use after free in Extensions
+  * CVE-2026-87529: Numeric truncation error in Media
+  * CVE-2026-87470: Improper quantity validation in Tint
+  * CVE-2026-87586: Out of bounds read in ANGLE
+  * CVE-2026-87584: Incorrect authorization in WebUI
+  * CVE-2026-87632: Cross-site scripting in SanitizerAPI
+  * CVE-2026-87528: Type confusion in Rust
+  * CVE-2026-87623: Observable discrepancy in DOM
+  * CVE-2026-87566: Observable discrepancy in Layout
+  * CVE-2026-87638: Out of bounds write in Media
+  * CVE-2026-87455: Use after free in Aura
+  * CVE-2026-87591: Incorrect authorization in Extensions
+  * CVE-2026-87526: Use after free in Passwords
+  * CVE-2026-87609: Use after free in Sharing
+  * CVE-2026-87610: Incorrect authorization in Omnibox
+  * CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials
+  * CVE-2026-87629: Incorrect authorization in Sources
+  * CVE-2026-87653: UI misrepresentation in FullScreen
+  * CVE-2026-87634: Use after free in WebPackaging
+  * CVE-2026-87429: Missing authorization in ServiceWorker
+  * CVE-2026-87618: Incorrect reference resolution in Storage
+  * CVE-2026-87614: Incorrect authorization in ServiceWorker
+  * CVE-2026-87619: Observable discrepancy in Prefetch
+  * CVE-2026-87561: Incorrect authorization in Web Authentication
+  * CVE-2026-87598: Incorrect authorization in ServiceWorker
+  * CVE-2026-87519: Incorrect authorization in Safebrowsing
+  * CVE-2026-87543: Missing authorization in Core
+  * CVE-2026-87522: Missing authorization in WebView
+  * CVE-2026-87568: Improper input validation in Chromium
+  * CVE-2026-87656: Improper state validation in Safebrowsing
+  * CVE-2026-87511: Missing authorization in DevTools
+  * CVE-2026-87627: Interpretation conflict in Safebrowsing
+  * CVE-2026-87595: Server-side request forgery in Mobile
+  * CVE-2026-87592: Out of bounds read in Tint
+  * CVE-2026-87620: Observable discrepancy in SVG
+  * CVE-2026-87502: Confused deputy in Fullscreen
+  * CVE-2026-87448: Use after free in DevTools
+  * CVE-2026-87459: Observable discrepancy in Select
+  * CVE-2026-87463: Incorrect authorization in Certificate
+  * CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing
+  * CVE-2026-87538: Clickjacking in Input
+  * CVE-2026-87545: Information leak in Mobile
+  * CVE-2026-87617: Use after free in DevTools
+  * CVE-2026-87523: Race condition in DataTransfer
+  * CVE-2026-87565: Information leak in Passwords
+  * CVE-2026-87597: UI misrepresentation in CustomTabs
+  * CVE-2026-87624: UI misrepresentation in Passwords
+  * CVE-2026-87605: Missing authorization in Contacts
+  * CVE-2026-87490: Information leak in Transactions Platform
+  * CVE-2026-87583: UI misrepresentation in Passwords
+  * CVE-2026-87509: Incorrect authorization in Updater
+  * CVE-2026-87473: Incorrect authorization in FileHandling
+  * CVE-2026-87461: Information leak in Core
+  * CVE-2026-87631: Missing authorization in DOM
+  * CVE-2026-87469: Improper input validation in Extensions
+  * CVE-2026-87489: Memory corruption in V8
+  * CVE-2026-87575: Incorrect authorization in Loader
+  * CVE-2026-87571: Improper certificate validation in Loader
+  * CVE-2026-87477: Information leak in Core
+  * CVE-2026-87551: Improper certificate validation in CORS
+  * CVE-2026-87608: Improper certificate validation in FedCM
+  * CVE-2026-87437: Information leak in Frames
+  * CVE-2026-87602: Out of bounds read in ANGLE
+  * CVE-2026-87601: Race condition in V8
+  * CVE-2026-87544: Incorrect authorization in Extensions
+  * CVE-2026-87430: Buffer overflow in WebRTC
+  * CVE-2026-87593: Information leak in Editing
+
+-------------------------------------------------------------------
+Sat Sep  5 13:26:10 UTC 2026 - Andreas Stieger <[email protected]>
+
+- Build with rust 1.94 on openSUSE Tumbleweed
+
+-------------------------------------------------------------------
+Fri Sep  4 15:23:58 UTC 2026 - Andreas Stieger <[email protected]>
+
+- Build with llvm23 on openSUSE Tumbleweed
+
+-------------------------------------------------------------------
+Fri Sep  4 05:06:58 UTC 2026 - Andreas Stieger <[email protected]>
+
+- Chromium 153.0.8010.12 (beta released 2026-08-26)
+- dropped patches:
+  * chromium-24264eefbfd3464161764f31a2752c5327719452.patch
+    (patched file is not being compiled)
+- modified patches:
+  * ppc-fedora-HACK-debian-clang-disable-pa-musttail.patch
+  * ppc-fedora-0002-regenerate-xnn-buildgn.patch
+  * chromium-102-regex_pattern-array.patch
+  * chromium-133-bring_back_and_disable_allowlist.patch
+  * chromium-146-ignore-for-ubsan.patch
+  * chromium-152-revert-crubit.patch
+  * chromium-152-no-lifetime-checks.patch
+- added patches:
+  * chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch
+    (another crubit revert)
+  * chromium-153-opus_includes.patch
+    (adapt include path to system lib)
+  * chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch
+    (revert in third-party pipewire for pipewire < 1.6)
+- keeplibs:
+  added: third_party/typescript
+  (needed by .../extensions_zero_state_promo/build_ts_manifest.json)
+  added: third_party/iamf_tools
+  (needed by 'obj/third_party/iamf_tools/iamf_tools_lib/channel_reorderer.o)
+- remove typescript binaries from tree
+- add typescript-go sources
+  * TypeScript-7.0.2.tar.gz
+  * TypeScript-7.0.2-vendor.tar.gz
+  build the tsc (actually tsgo) binary from source since chromium
+  build is forcing the go binary (x86 intree binary) to save
+  three minutes in a fifteen hour build
+- added patches:
+  * chromium-153-ignore-typescript-deps.patch
+
+-------------------------------------------------------------------

Old:
----
  chromium-152.0.7977.82-linux.tar.xz
  chromium-24264eefbfd3464161764f31a2752c5327719452.patch

New:
----
  TypeScript-7.0.2-vendor.tar.gz
  TypeScript-7.0.2.tar.gz
  chromium-153-ignore-typescript-deps.patch
  chromium-153-opus_includes.patch
  chromium-153.0.8010.36-linux.tar.xz
  chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch
  chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch

----------(Old B)----------
  Old:- dropped patches:
  * chromium-24264eefbfd3464161764f31a2752c5327719452.patch
    (patched file is not being compiled)
----------(Old E)----------

----------(New B)----------
  New:- added patches:
  * chromium-153-ignore-typescript-deps.patch
  New:    (another crubit revert)
  * chromium-153-opus_includes.patch
    (adapt include path to system lib)
  New:- added patches:
  * chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch
    (another crubit revert)
  New:    (adapt include path to system lib)
  * chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch
    (revert in third-party pipewire for pipewire < 1.6)
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ chromium.spec ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:55.922434943 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:55.924435027 +0200
@@ -63,10 +63,10 @@
 # LLVM version
 %if 0%{?suse_version} > 1600
 # LLVM version
-%define llvm_version 22
-%define llvm_version_long 22.1.8
+%define llvm_version 23
+%define llvm_version_long 23.1.0
 # RUST version
-%define rust_version 1.93
+%define rust_version 1.94
 %else
 # LLVM version
 %define llvm_version 19
@@ -120,6 +120,11 @@
 %else
 %bcond_with flac_1_5
 %endif
+%if %{pkg_vcmp pipewire-devel >= 1.6.0}
+%bcond_without pipewire16
+%else
+%bcond_with pipewire16
+%endif
 # Package names
 %if %{with is_beta}
 %define chromedriver_name %{name}-chromedriver
@@ -132,7 +137,7 @@
 %global official_build 1
 
 Name:           chromium%{n_suffix}
-Version:        152.0.7977.82
+Version:        153.0.8010.36
 Release:        0
 Summary:        Google's open source browser project
 License:        BSD-3-Clause AND LGPL-2.1-or-later
@@ -146,6 +151,9 @@
 # upstream only contains x86 binary of 4.x, other archs do not work reliably
 # try to use an old version like in debian package
 Source4:        
https://registry.npmjs.org/rollup/-/rollup-%{rollup_version}.tgz
+# properly build a typescript-go instead of using an arbitrary intree binary
+Source5:        TypeScript-7.0.2.tar.gz
+Source6:        TypeScript-7.0.2-vendor.tar.gz
 # Toolchain definitions
 Source30:       master_preferences
 Source104:      chromium-symbolic.svg
@@ -206,6 +214,8 @@
 Patch403:       chromium-152-revert-crubit.patch
 Patch404:       chromium-152-value_or.patch
 Patch405:       chromium-152-no-eula.patch
+Patch406:       chromium-153-opus_includes.patch
+Patch407:       chromium-153-ignore-typescript-deps.patch
 # conditionally applied patches ppc64le only
 # where applicable patch numbers from fedora specfile + 100
 Patch452:       ppc-fedora-memory-allocator-dcheck-assert-fix.patch
@@ -285,9 +295,6 @@
 Patch1050:      chromium-140-old-flac.patch
 # only in ffmpeg avutil >= 60.31
 Patch1051:      chromium-150-ffmpeg_no_agtm.patch
-# revert upstream patch ending in compile error
-# error: static assertion expression is not an integral constant expression
-Patch1060:       chromium-24264eefbfd3464161764f31a2752c5327719452.patch
 Patch1061:       chromium-146-static-assert.patch
 # llvm19 segfaults in
 # 
../services/network/public/cpp/permissions_policy/origin_with_possible_wildcards.cc:99:1:
 current parser token 'std'
@@ -308,6 +315,10 @@
 Patch1074:       chromium-152-no-lifetime-checks.patch 
 Patch1075:       chromium-152-no-warning-suppression-map.patch
 Patch1080:       rollup.patch
+# another crubit revert
+Patch1081:       chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch
+# revert patch needing more recent pipewire
+Patch1082:       chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch
 
 # end conditionally applied patches
 BuildRequires:  SDL-devel
@@ -322,6 +333,7 @@
 BuildRequires:  gperf
 BuildRequires:  hicolor-icon-theme
 BuildRequires:  golang(API)
+BuildRequires:  golang-packaging
 # Java used during build
 BuildRequires:  java-openjdk-headless
 BuildRequires:  libdc1394
@@ -510,6 +522,7 @@
 %if %{with system_zstd}
 BuildRequires:  pkgconfig(libzstd) >= 1.5.5
 %endif
+BuildRequires:  zstd
 # compiler selection
 %if %{with clang}
 # clang/llvm case
@@ -537,7 +550,6 @@
 %if 0%{?suse_version} >= 1699
 #!BuildIgnore:  rpmlint rpmlint-Factory rpmlint-mini
 %endif
-BuildRequires:  unzip
 
 %description
 Chromium is the open-source project behind Google Chrome. We invite you to 
join us in our effort to help build a safer, faster, and more stable way for 
all Internet users to experience the web, and to create a powerful platform for 
developing a new generation of web applications.
@@ -587,7 +599,6 @@
 
 clang_version="$(clang-%{llvm_version} --version | sed -n 's/clang version 
//p')"
 if [[ $(echo ${clang_version} | cut -d. -f1) -lt 21 ]]; then
-%patch -p1 -R -P 1060
 %patch -p1 -P 1061
 %patch -p1 -P 1062
 %patch -p1 -P 1065
@@ -606,6 +617,16 @@
 %patch -p1 -P 1074
 fi
 
+# revert another crubit patch until we get a proper building crubit
+%patch -p1 -R -P 1081
+
+%if %{without pipewire16}
+pushd third_party/webrtc
+%patch -p1 -R -P 1082
+popd
+%endif
+
+
 ## ROLLUP_HACK
 rm -rf third_party/devtools-frontend/src/node_modules/rollup
 rm -rf third_party/devtools-frontend/src/node_modules/@rollup/rollup-linux-*
@@ -667,6 +688,20 @@
 cp -a esbuild ../third_party/devtools-frontend/src/third_party/esbuild/esbuild
 popd
 
+# drop in tree binaries
+rm -f third_party/typescript/linux-amd64/src/lib/tsc{,.sig}
+tar -xf %{SOURCE5}
+pushd TypeScript-*/tsc
+tar -xf %{SOURCE6}
+# apply the local patch .. sigh
+pushd internal/bundled/libs
+patch -p2 < 
../../../../../third_party/typescript/linux-amd64/3pp/patches/typescript_native_preview.patch
+popd
+%{goprep} github.com/microsoft/typescript-go
+%{gobuild} -mod=vendor ./cmd/tsgo
+popd
+cp -a $RPM_BUILD_DIR/go/bin/tsgo third_party/typescript/linux-amd64/src/lib/tsc
+
 # Fix the path to nodejs binary
 mkdir -p third_party/node/linux/node-linux-x64/bin
 rm -f third_party/node/linux/node-linux-x64/bin/node
@@ -834,6 +869,7 @@
     third_party/gperf
     third_party/highway
     third_party/hunspell
+    third_party/iamf_tools
     third_party/ink
     third_party/inspector_protocol
     third_party/ipcz
@@ -940,6 +976,7 @@
     third_party/tflite/src/third_party/fft2d
     third_party/tflite/src/third_party/xla/third_party/tsl
     third_party/tflite/src/third_party/xla/xla/tsl
+    third_party/typescript
     third_party/ukey2
     third_party/utf
     third_party/vulkan
@@ -1022,6 +1059,10 @@
 %endif
 build/linux/unbundle/remove_bundled_libraries.py "${keeplibs[@]}" --do-remove
 
+# re-add a proper python3 link
+mkdir -p third_party/cpython3/host/bin
+ln -sfn %{_bindir}/$PYTHON third_party/cpython3/host/bin/python3
+
 # GN sets lto on its own and we need just ldflag options, not cflags
 %define _lto_cflags %{nil}
 %if %{with clang}

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.180445764 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.185445973 +0200
@@ -1,6 +1,7 @@
-mtime: 1788465131
-commit: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b
+mtime: 1788928336
+commit: 31e0554bd37ac3680ea48233389b8a5f2e7ce0ceaf48bc2235829119feaa99b0
 url: https://src.opensuse.org/chromium/chromium
-revision: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b
+revision: 31e0554bd37ac3680ea48233389b8a5f2e7ce0ceaf48bc2235829119feaa99b0
+trackingbranch: main
 projectscmsync: https://src.opensuse.org/chromium/_ObsPrj.git
 

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-09 06:32:16.000000000 +0200
@@ -0,0 +1,4 @@
+.osc
+*.patch~
+*-build/
+.*.swp

++++++ chromium-102-regex_pattern-array.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.396454823 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.404455158 +0200
@@ -2,7 +2,7 @@
 ===================================================================
 --- chromium-151.0.7922.10.orig/components/autofill/core/browser/BUILD.gn
 +++ chromium-151.0.7922.10/components/autofill/core/browser/BUILD.gn
-@@ -131,6 +131,11 @@ static_library("browser") {
+@@ -131,6 +131,11 @@
    _configs = configs
    configs = []
    configs = [ "//third_party/tflite:tflite_shim_config" ] + _configs
@@ -12,6 +12,6 @@
 +    ]
 +  }
    sources = [
-     "at_memory/at_memory_data_type.cc",
-     "at_memory/at_memory_data_type.h",
+     "at_memory/at_memory_enablement_utils.cc",
+     "at_memory/at_memory_enablement_utils.h",
 

++++++ chromium-133-bring_back_and_disable_allowlist.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.506459436 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.514459772 +0200
@@ -2,20 +2,19 @@
 ===================================================================
 --- chromium-147.0.7727.3.orig/media/base/media_switches.h
 +++ chromium-147.0.7727.3/media/base/media_switches.h
-@@ -472,6 +472,8 @@ MEDIA_EXPORT BASE_DECLARE_FEATURE(
- 
+@@ -290,6 +290,7 @@
+ MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseSequencedTaskRunnerForMediaService);
+ MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseTaskRunnerForMojoAudioDecoderService);
  MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseWindowBoundsForPip);
- 
 +MEDIA_EXPORT BASE_DECLARE_FEATURE(kFFmpegAllowLists);
-+
- MEDIA_EXPORT BASE_DECLARE_FEATURE(kMediaLogToConsole);
- 
- MEDIA_EXPORT BASE_DECLARE_FEATURE(kAomVpxUsePresentationThreadType);
+ MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiEarlyPPSParsingForCENCv1);
+ MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiLowPowerEncoderGen9x);
+ MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiOnNvidiaGPUs);
 Index: chromium-147.0.7727.3/media/base/media_switches.cc
 ===================================================================
 --- chromium-147.0.7727.3.orig/media/base/media_switches.cc
 +++ chromium-147.0.7727.3/media/base/media_switches.cc
-@@ -1801,6 +1801,11 @@ bool IsRestrictOwnAudioSupported() {
+@@ -1891,6 +1891,11 @@
  #endif
  }
  
@@ -24,9 +23,9 @@
 +             "FFmpegAllowLists",
 +             base::FEATURE_DISABLED_BY_DEFAULT);
 +
- #if BUILDFLAG(IS_WIN)
- bool IsMediaFoundationD3D11VideoCaptureEnabled() {
-   return base::FeatureList::IsEnabled(kMediaFoundationD3D11VideoCapture);
+ bool IsSystemEchoCancellationEnforced() {
+ #if (BUILDFLAG(IS_MAC) || BUILDFLAG(IS_WIN))
+   return base::FeatureList::IsEnabled(kEnforceSystemEchoCancellation);
 Index: chromium-147.0.7727.3/media/ffmpeg/ffmpeg_common.cc
 ===================================================================
 --- chromium-147.0.7727.3.orig/media/ffmpeg/ffmpeg_common.cc

++++++ chromium-146-ignore-for-ubsan.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.662465979 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.667466189 +0200
@@ -15,10 +15,10 @@
      if (diagnostics_print_source_range_info && !is_win) {
        cflags += [ "-fdiagnostics-print-source-range-info" ]
      }
-@@ -1579,12 +1571,6 @@
+@@ -1394,12 +1394,6 @@
  ubsan_hardening("c_array_bounds") {
    sanitizer = "array-bounds"
-   condition = !(is_asan && target_cpu == "x86") && !is_wasm
+   condition = !(is_asan && target_cpu == "x86")
 -
 -  # Because we've enabled array-bounds sanitizing we also want to suppress
 -  # the related warning about "unsafe-buffer-usage-in-static-sized-array",

++++++ chromium-152-no-lifetime-checks.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.802471851 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.812472270 +0200
@@ -1,7 +1,7 @@
 --- chromium-152.0.7977.54/third_party/dawn/src/utils/BUILD.gn 2026/08/21 
07:40:42     1.1
 +++ chromium-152.0.7977.54/third_party/dawn/src/utils/BUILD.gn 2026/08/21 
07:41:10
-@@ -210,16 +210,6 @@
-       "-Wno-non-virtual-dtor",
+@@ -208,13 +208,6 @@
+       "-Wno-float-equal",
        "-Wno-undefined-func-template",
        "-Wno-unused-parameter",
 -
@@ -10,10 +10,7 @@
 -      # -Wlifetime-safety-lifetimebound-violation) are not yet mapped to
 -      # toggleable warning flags, so we suppress the entire group and disable
 -      # the analysis pass.
--      "-Wno-lifetime-safety",
 -      "-Wno-lifetime-safety-all",
--      "-Xclang=-fno-lifetime-safety-inference",
--      "-Xclang=-fno-experimental-lifetime-safety-tu-analysis",
      ]
  
      # P3. Checks that could be nice but probably don't help with hardening.

++++++ chromium-152-revert-crubit.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:56.842473528 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:56.848473780 +0200
@@ -1,6 +1,8 @@
---- chromium-152.0.7977.54/DEPS        2026/08/20 14:49:31     1.1
-+++ chromium-152.0.7977.54/DEPS        2026/08/20 14:50:05
-@@ -4257,16 +4257,9 @@
+Index: chromium-153.0.8010.5/DEPS
+===================================================================
+--- chromium-153.0.8010.5.orig/DEPS
++++ chromium-153.0.8010.5/DEPS
+@@ -4322,16 +4322,9 @@ include_rules = [
    '+third_party/google_benchmark/src/include/benchmark/benchmark.h',
    '+third_party/icu/source/common/unicode',
    '+third_party/icu/source/i18n/unicode',
@@ -18,24 +20,28 @@
    # Abseil is allowed by default, but some features are banned. See
    # //styleguide/c++/c++-features.md.
    '+third_party/abseil-cpp',
---- chromium-152.0.7977.54/tools/rust/build_crubit.py  2026/08/20 14:54:51     
1.1
-+++ chromium-152.0.7977.54/tools/rust/build_crubit.py  2026/08/20 14:55:20
-@@ -134,12 +134,8 @@
-         shutil.copy(os.path.join(release_dir, bin),
-                     os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'bin', bin))
+Index: chromium-153.0.8010.5/tools/rust/build_crubit.py
+===================================================================
+--- chromium-153.0.8010.5.orig/tools/rust/build_crubit.py
++++ chromium-153.0.8010.5/tools/rust/build_crubit.py
+@@ -148,12 +148,9 @@ def BuildCrubit(rust_sysroot, out_dir, s
+             os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'bin', bin),
+         )
  
 -    # `crubit_target_dir` below helps ensure that Chromium can use the same
 -    # `#include` paths as other Crubit clients like google3 - e.g.
 -    # `#include "third_party/crubit/support/rs_std/slice_ref.h"`.
      print(f'Installing `crubit/support` to {RUST_TOOLCHAIN_OUT_DIR} ...')
--    crubit_target_dir = os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'lib',
--                                     'third_party', 'crubit')
-+    crubit_target_dir = os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'lib', 'crubit')
+     crubit_target_dir = os.path.join(
+-        RUST_TOOLCHAIN_OUT_DIR, 'lib', 'third_party', 'crubit'
++        RUST_TOOLCHAIN_OUT_DIR, 'lib', 'crubit'
+     )
      for item in ["BUILD.gn", "LICENSE", "crubit.gni", "support"]:
          source_path = os.path.join(CRUBIT_SRC_DIR, item)
-         target_path = os.path.join(crubit_target_dir, item)
---- chromium-152.0.7977.54/build_overrides/crubit.gni  2026/08/20 14:54:24     
1.1
-+++ chromium-152.0.7977.54/build_overrides/crubit.gni  2026/08/20 14:54:41
+Index: chromium-153.0.8010.5/build_overrides/crubit.gni
+===================================================================
+--- chromium-153.0.8010.5.orig/build_overrides/crubit.gni
++++ chromium-153.0.8010.5/build_overrides/crubit.gni
 @@ -2,7 +2,7 @@
  # Use of this source code is governed by a BSD-style license that can be
  # found in the LICENSE file.
@@ -45,10 +51,12 @@
  crubit_absl_dep_target = "//third_party/abseil-cpp:absl"
  crubit_gn_configs_to_remove = [
    "//build/config/compiler:chromium_code",
---- 
chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/unittests.cc     
   2026/08/20 14:53:31     1.1
-+++ 
chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/unittests.cc     
   2026/08/20 14:54:11
-@@ -4,8 +4,8 @@
- 
+Index: 
chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/unittests.cc
+===================================================================
+--- 
chromium-153.0.8010.5.orig/build/rust/tests/test_cpp_api_from_rust/unittests.cc
++++ chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/unittests.cc
+@@ -5,8 +5,8 @@
+ #include "build/build_config.h"
  #include "build/rust/tests/test_cpp_api_from_rust/rust_lib.h"
  #include "testing/gtest/include/gtest/gtest.h"
 -#include "third_party/crubit/support/rs_std/char.h"
@@ -58,11 +66,13 @@
  
  TEST(RustCcBindingsFromRs, TestI32) {
    EXPECT_EQ(12, rust_lib::mul_two_ints_via_rust(3, 4));
---- chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/BUILD.gn    
2026/08/20 14:52:56     1.1
-+++ chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/BUILD.gn    
2026/08/20 14:53:16
-@@ -31,7 +31,8 @@
-   deps = [
+Index: chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/BUILD.gn
+===================================================================
+--- chromium-153.0.8010.5.orig/build/rust/tests/test_cpp_api_from_rust/BUILD.gn
++++ chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/BUILD.gn
+@@ -32,7 +32,8 @@ source_set("test_cpp_api_from_rust") {
      ":rust_lib_bindings",
+     ":target_depending_only_on_bindings",
      "//base",
 -    "//build/rust/crubit",
 +    "//build/rust/crubit:rs_std",
@@ -70,9 +80,11 @@
      "//testing/gmock",
      "//testing/gtest",
    ]
---- chromium-152.0.7977.54/build/rust/gni_impl/cpp_api_from_rust.gni   
2026/08/20 14:51:22     1.1
-+++ chromium-152.0.7977.54/build/rust/gni_impl/cpp_api_from_rust.gni   
2026/08/20 14:52:36
-@@ -91,7 +91,8 @@
+Index: chromium-153.0.8010.5/build/rust/gni_impl/cpp_api_from_rust.gni
+===================================================================
+--- chromium-153.0.8010.5.orig/build/rust/gni_impl/cpp_api_from_rust.gni
++++ chromium-153.0.8010.5/build/rust/gni_impl/cpp_api_from_rust.gni
+@@ -91,7 +91,8 @@ template("cpp_api_from_rust") {
      _original_attributes.deps += [ "//build/rust/std:std_bindings" ]
    }
  
@@ -82,8 +94,10 @@
    _cpp_api_from_rust_exe_path =
        "//third_party/rust-toolchain/bin/cc_bindings_from_rs"
    _rustfmt_exe_path = "//third_party/rust-toolchain/bin/rustfmt"
---- chromium-152.0.7977.54/build/rust/crubit/BUILD.gn  2026/08/20 14:50:21     
1.1
-+++ chromium-152.0.7977.54/build/rust/crubit/BUILD.gn  2026/08/20 14:51:00
+Index: chromium-153.0.8010.5/build/rust/crubit/BUILD.gn
+===================================================================
+--- chromium-153.0.8010.5.orig/build/rust/crubit/BUILD.gn
++++ chromium-153.0.8010.5/build/rust/crubit/BUILD.gn
 @@ -4,36 +4,20 @@
  
  import("//build_overrides/crubit.gni")
@@ -127,9 +141,11 @@
  }
  
  # This config is injected via `//build_overrides/crubit.gni`.
---- chromium-152.0.7977.54/components/cbor/BUILD.gn     2026/08/20 16:06:43    
 1.1
-+++ chromium-152.0.7977.54/components/cbor/BUILD.gn     2026/08/20 16:07:38
-@@ -12,7 +12,7 @@
+Index: chromium-153.0.8010.5/components/cbor/BUILD.gn
+===================================================================
+--- chromium-153.0.8010.5.orig/components/cbor/BUILD.gn
++++ chromium-153.0.8010.5/components/cbor/BUILD.gn
+@@ -12,7 +12,7 @@ buildflag_header("buildflags") {
    # TODO(crbug.com/535682335): Remove `USE_CBOR_RUST` buildflag entirely,
    # unconditionally enable Rust CBOR parser, and drop `is_cronet_build` check
    # once Cronet supports Crubit dependencies.
@@ -138,7 +154,7 @@
  }
  
  component("cbor") {
-@@ -37,12 +37,12 @@
+@@ -35,12 +35,12 @@ component("cbor") {
      "//base",
    ]
  

++++++ chromium-153-ignore-typescript-deps.patch ++++++
--- chromium-153.0.8010.5/tools/typescript/validate_tsconfig.py 2026/08/29 
09:27:43     1.1
+++ chromium-153.0.8010.5/tools/typescript/validate_tsconfig.py 2026/08/29 
09:29:12
@@ -337,4 +337,5 @@
   for missing_input in missing_inputs:
     errorMessage += f'//{missing_input}\n'
 
-  return False, errorMessage
+  #return False, errorMessage
+  return True, None

++++++ chromium-153-opus_includes.patch ++++++
--- 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc 
    2026/08/26 09:00:55     1.1
+++ 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc 
    2026/08/26 09:01:07
@@ -30,8 +30,8 @@
 #include "iamf/obu/decoder_config/opus_decoder_config.h"
 #include "iamf/obu/substream_channel_count.h"
 #include "iamf/obu/types.h"
-#include "include/opus.h"
-#include "include/opus_types.h"
+#include "opus.h"
+#include "opus_types.h"
 
 namespace iamf_tools {
 
--- 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h  
    2026/08/26 09:01:09     1.1
+++ 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h  
    2026/08/26 09:01:12
@@ -23,7 +23,7 @@
 #include "iamf/cli/codec/decoder_base.h"
 #include "iamf/obu/decoder_config/opus_decoder_config.h"
 #include "iamf/obu/substream_channel_count.h"
-#include "include/opus.h"
+#include "opus.h"
 
 namespace iamf_tools {
 
--- 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc 
    2026/08/26 09:01:12     1.1
+++ 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc 
    2026/08/26 09:01:21
@@ -32,9 +32,9 @@
 #include "iamf/common/utils/validation_utils.h"
 #include "iamf/obu/decoder_config/opus_decoder_config.h"
 #include "iamf/obu/substream_channel_count.h"
-#include "include/opus.h"
-#include "include/opus_defines.h"
-#include "include/opus_types.h"
+#include "opus.h"
+#include "opus_defines.h"
+#include "opus_types.h"
 
 namespace iamf_tools {
 
--- 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h  
    2026/08/26 09:01:21     1.1
+++ 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h  
    2026/08/26 09:01:27
@@ -22,8 +22,8 @@
 #include "iamf/obu/codec_config.h"
 #include "iamf/obu/decoder_config/opus_decoder_config.h"
 #include "iamf/obu/substream_channel_count.h"
-#include "include/opus.h"
-#include "include/opus_defines.h"
+#include "opus.h"
+#include "opus_defines.h"
 
 namespace iamf_tools {
 
--- 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc   
    2026/08/26 09:01:27     1.1
+++ 
chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc   
    2026/08/26 09:01:31
@@ -3,7 +3,7 @@
 #include "absl/status/status.h"
 #include "absl/strings/str_cat.h"
 #include "absl/strings/string_view.h"
-#include "include/opus_defines.h"
+#include "opus_defines.h"
 
 namespace iamf_tools {
 

++++++ chromium-152.0.7977.82-linux.tar.xz -> 
chromium-153.0.8010.36-linux.tar.xz ++++++
/work/SRC/openSUSE:Factory/chromium/chromium-152.0.7977.82-linux.tar.xz 
/work/SRC/openSUSE:Factory/.chromium.new.1265/chromium-153.0.8010.36-linux.tar.xz
 differ: char 15, line 1

++++++ chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch ++++++
commit 493e6c3911e33cc356856bafbffc6cf95521266b
Author: Dominik Röttsches <[email protected]>
Date:   Thu Aug 13 08:42:15 2026 -0700

    Migrate OpenType format check bindings to Crubit
    
    We can remove the Box<> wrapped typing of FontFormatInfo along the way.
    
    DEPS checks for the generated output header files requires us to move
    the format_check target into the fonts subdirectory. This is a good
    opportunity to move more font specific build rules to the font subdir in
    the future and reduce the weight of the platform/BUILD.gn build dir.
    
    Exercise in using the Crubit bindings mechanism.
    
    No functional change.
    
    Change-Id: I9440c7285bb707b325b80ee074de51e714ee4884
    Reviewed-on: 
https://chromium-review.googlesource.com/c/chromium/src/+/8244248
    Reviewed-by: Łukasz Anforowicz <[email protected]>
    Commit-Queue: Dominik Röttsches <[email protected]>
    Cr-Commit-Position: refs/heads/main@{#1678858}

diff --git a/third_party/blink/renderer/platform/BUILD.gn 
b/third_party/blink/renderer/platform/BUILD.gn
index d5e81a3f07a3c..6a5d275460122 100644
--- a/third_party/blink/renderer/platform/BUILD.gn
+++ b/third_party/blink/renderer/platform/BUILD.gn
@@ -186,18 +186,6 @@ group("make_platform_generated") {
   ]
 }
 
-rust_static_library("font_format_check") {
-  allow_unsafe = true  # Needed for FFI that underpins the `cxx` crate.
-  crate_root = "fonts/opentype/format_check.rs"
-  sources = [ crate_root ]
-  cxx_bindings = [ crate_root ]
-  deps = [
-    "//third_party/rust/font_types/v0_12:lib",
-    "//third_party/rust/read_fonts/v0_41:lib",
-    "//third_party/rust/skrifa/v0_44:lib",
-  ]
-}
-
 rust_static_library("rustfft_ffi") {
   allow_unsafe = true  # Needed for FFI that underpins the `cxx` crate.
   crate_root = "audio/rustfft_ffi.rs"
@@ -1806,6 +1794,7 @@ component("platform") {
     ":allow_discouraged_type",
     ":blink_platform_public_deps",
     ":platform_export",
+    "//build/rust/crubit",
     "//gpu/command_buffer/client:raster_interface",
     "//media/capture:capture_lib",
     "//mojo/public/cpp/base",
@@ -1832,8 +1821,8 @@ component("platform") {
     "//ui/native_theme/features",
   ]
   deps = [
-    ":font_format_check",
     ":rustfft_ffi",
+    "fonts:font_format_bindings",
     "//base:base_static",
     "//base/allocator:buildflags",
     "//build:chromecast_buildflags",
diff --git a/third_party/blink/renderer/platform/fonts/BUILD.gn 
b/third_party/blink/renderer/platform/fonts/BUILD.gn
new file mode 100644
index 0000000000000..51b9b03ba7c85
--- /dev/null
+++ b/third_party/blink/renderer/platform/fonts/BUILD.gn
@@ -0,0 +1,19 @@
+# Copyright 2026 The Chromium Authors
+# Use of this source code is governed by a BSD-style license that can be
+# found in the LICENSE file.
+
+import("//build/rust/rust_static_library.gni")
+
+rust_static_library("font_format") {
+  crate_root = "opentype/format_check.rs"
+  sources = [ crate_root ]
+  cpp_api_from_rust = {
+    target_name = "font_format_bindings"
+    cpp_namespace = "font_format"
+  }
+  deps = [
+    "//third_party/rust/font_types/v0_12:lib",
+    "//third_party/rust/read_fonts/v0_41:lib",
+    "//third_party/rust/skrifa/v0_44:lib",
+  ]
+}
diff --git 
a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc 
b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc
index b9d2639822bc0..f58e9433d39f4 100644
--- a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc
+++ b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc
@@ -7,7 +7,6 @@
 #include "base/containers/span.h"
 #include "base/containers/span_rust.h"
 #include "base/numerics/byte_conversions.h"
-#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h"
 #include "third_party/blink/renderer/platform/runtime_enabled_features.h"
 #include "third_party/blink/renderer/platform/wtf/vector.h"
 #include "third_party/skia/include/core/SkTypeface.h"
@@ -15,35 +14,37 @@
 namespace blink {
 
 FontFormatCheck::FontFormatCheck(sk_sp<SkData> sk_data)
-    : format_info_(font_format_check::get_font_format_info(
+    : format_info_(font_format::get_font_format_info(
           base::SpanToRustSlice(sk_data->byteSpan()))) {}
 
+FontFormatCheck::~FontFormatCheck() = default;
+
 bool FontFormatCheck::IsVariableFont() const {
-  return font_format_check::is_variable(*format_info_);
+  return font_format::is_variable(format_info_);
 }
 
 bool FontFormatCheck::IsCbdtCblcColorFont() const {
-  return font_format_check::is_cbdt_cblc(*format_info_);
+  return font_format::is_cbdt_cblc(format_info_);
 }
 
 bool FontFormatCheck::IsEbdtEblcMonochromeFont() const {
-  return font_format_check::is_ebdt_eblc(*format_info_);
+  return font_format::is_ebdt_eblc(format_info_);
 }
 
 bool FontFormatCheck::IsColrCpalColorFontV0() const {
-  return font_format_check::is_colrv0(*format_info_);
+  return font_format::is_colrv0(format_info_);
 }
 
 bool FontFormatCheck::IsColrCpalColorFontV1() const {
-  return font_format_check::is_colrv1(*format_info_);
+  return font_format::is_colrv1(format_info_);
 }
 
 bool FontFormatCheck::IsSbixColorFont() const {
-  return font_format_check::is_sbix(*format_info_);
+  return font_format::is_sbix(format_info_);
 }
 
 bool FontFormatCheck::IsCff2OutlineFont() const {
-  return font_format_check::is_cff2(*format_info_);
+  return font_format::is_cff2(format_info_);
 }
 
 bool FontFormatCheck::IsVariableColrV0Font() const {
@@ -57,7 +58,7 @@ bool FontFormatCheck::IsColorFont() const {
 
 bool FontFormatCheck::IsAvar2Font() const {
   return RuntimeEnabledFeatures::FontFormatAvar2Enabled() &&
-         font_format_check::is_avar2(*format_info_);
+         font_format::is_avar2(format_info_);
 }
 
 FontFormatCheck::VariableFontSubType FontFormatCheck::ProbeVariableFont(
diff --git 
a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h 
b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h
index 19d2639233b07..af50dbdf74d00 100644
--- a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h
+++ b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h
@@ -5,7 +5,7 @@
 #ifndef THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_
 #define THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_
 
-#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h"
+#include "third_party/blink/renderer/platform/fonts/font_format.h"
 #include "third_party/blink/renderer/platform/platform_export.h"
 #include "third_party/blink/renderer/platform/wtf/allocator/allocator.h"
 #include "third_party/skia/include/core/SkData.h"
@@ -19,7 +19,7 @@ class PLATFORM_EXPORT FontFormatCheck {
 
  public:
   explicit FontFormatCheck(sk_sp<SkData>);
-  virtual ~FontFormatCheck() = default;
+  virtual ~FontFormatCheck();
   virtual bool IsVariableFont() const;
   virtual bool IsCbdtCblcColorFont() const;
   virtual bool IsEbdtEblcMonochromeFont() const;
@@ -46,7 +46,7 @@ class PLATFORM_EXPORT FontFormatCheck {
   enum class COLRVersion { kCOLRV0, kCOLRV1, kNoCOLR };
 
  private:
-  rust::Box<font_format_check::FontFormatInfo> format_info_;
+  font_format::FontFormatInfo format_info_;
 };
 
 }  // namespace blink
diff --git a/third_party/blink/renderer/platform/fonts/opentype/format_check.rs 
b/third_party/blink/renderer/platform/fonts/opentype/format_check.rs
index eda8e6b2b8188..b99f0ec8655e6 100644
--- a/third_party/blink/renderer/platform/fonts/opentype/format_check.rs
+++ b/third_party/blink/renderer/platform/fonts/opentype/format_check.rs
@@ -23,7 +23,7 @@ pub struct FontFormatInfo {
     format_flags: Option<FontFormatFlags>,
 }
 
-pub fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo> {
+pub fn get_font_format_info(font_bytes: &[u8]) -> FontFormatInfo {
     let file_ref = make_font_ref_internal(font_bytes, 0);
 
     match file_ref {
@@ -32,11 +32,11 @@ pub fn get_font_format_info(font_bytes: &[u8]) -> 
Box<FontFormatInfo> {
                 font.table_directory().table_records().iter().map(|e| 
e.tag()).collect();
             let color_version = get_colr_version(&font);
             let avar_version = get_avar_version(&font);
-            Box::new(FontFormatInfo {
+            FontFormatInfo {
                 format_flags: Some(FontFormatFlags { table_tags, 
color_version, avar_version }),
-            })
+            }
         }
-        _ => Box::new(FontFormatInfo::default()),
+        _ => FontFormatInfo::default(),
     }
 }
 
@@ -44,10 +44,10 @@ fn get_colr_version(font_ref: &FontRef) -> Option<u16> {
     Some(font_ref.colr().ok()?.version())
 }
 
-fn is_colrv1(format_info: &FontFormatInfo) -> bool {
+pub fn is_colrv1(format_info: &FontFormatInfo) -> bool {
     matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: 
Some(1), .. }),)
 }
-fn is_colrv0(format_info: &FontFormatInfo) -> bool {
+pub fn is_colrv0(format_info: &FontFormatInfo) -> bool {
     matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: 
Some(0), .. }),)
 }
 
@@ -56,7 +56,7 @@ fn get_avar_version(font_ref: &FontRef) -> Option<(u16, u16)> 
{
     Some((version.major, version.minor))
 }
 
-fn is_avar2(format_info: &FontFormatInfo) -> bool {
+pub fn is_avar2(format_info: &FontFormatInfo) -> bool {
     matches!(&format_info.format_flags, Some(FontFormatFlags { avar_version: 
Some((2, _)), .. }),)
 }
 
@@ -69,39 +69,22 @@ fn has_tags(format_info: &FontFormatInfo, query: &[Tag]) -> 
bool {
     }
 }
 
-fn is_variable(format_info: &FontFormatInfo) -> bool {
+pub fn is_variable(format_info: &FontFormatInfo) -> bool {
     has_tags(format_info, &[Tag::new(b"fvar")])
 }
 
-fn is_sbix(format_info: &FontFormatInfo) -> bool {
+pub fn is_sbix(format_info: &FontFormatInfo) -> bool {
     has_tags(format_info, &[Tag::new(b"sbix")])
 }
 
-fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool {
+pub fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool {
     has_tags(format_info, &[Tag::new(b"CBDT"), Tag::new(b"CBLC")])
 }
 
-fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool {
+pub fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool {
     has_tags(format_info, &[Tag::new(b"EBDT"), Tag::new(b"EBLC")])
 }
 
-fn is_cff2(format_info: &FontFormatInfo) -> bool {
+pub fn is_cff2(format_info: &FontFormatInfo) -> bool {
     has_tags(format_info, &[Tag::new(b"CFF2")])
 }
-
-#[cxx::bridge(namespace = "font_format_check")]
-pub mod ffi {
-    extern "Rust" {
-        type FontFormatInfo;
-
-        fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo>;
-        fn is_colrv1(format_info: &FontFormatInfo) -> bool;
-        fn is_colrv0(format_info: &FontFormatInfo) -> bool;
-        fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool;
-        fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool;
-        fn is_variable(format_info: &FontFormatInfo) -> bool;
-        fn is_sbix(format_info: &FontFormatInfo) -> bool;
-        fn is_cff2(format_info: &FontFormatInfo) -> bool;
-        fn is_avar2(format_info: &FontFormatInfo) -> bool;
-    }
-}

++++++ chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch ++++++
commit a0253ec15b3d3072fb35d6be29ba9224c36f9dd7
Author: Jan Grulich <[email protected]>
Date:   Thu Aug 13 08:37:32 2026 +0200

    Video capture: validate SPA pod values to prevent OOB reads
    
    Add bounds checks when reading SPA pod choice values in OnNodeParam
    and ParseFormat. Validate that the pod value size matches the expected
    type using spa_pod_type_size() and that the number of choice items
    is sufficient before accessing the underlying arrays.
    
    Bug: chromium:545349644
    Change-Id: I865e4736f52be1a0dfce47827181dc072630bb57
    Reviewed-on: https://webrtc-review.googlesource.com/c/src/+/495620
    Commit-Queue: Jan Grulich <[email protected]>
    Reviewed-by: Ilya Nikolaevskiy <[email protected]>
    Reviewed-by: Andreas Pehrson <[email protected]>
    Reviewed-by: Per Kjellander <[email protected]>
    Cr-Commit-Position: refs/heads/main@{#48344}

diff --git a/modules/video_capture/linux/pipewire_session.cc 
b/modules/video_capture/linux/pipewire_session.cc
index ba841a7f19..e17bab807c 100644
--- a/modules/video_capture/linux/pipewire_session.cc
+++ b/modules/video_capture/linux/pipewire_session.cc
@@ -46,6 +46,11 @@
 namespace webrtc {
 namespace videocapturemodule {
 
+// Checks that the pod matches the expected type and is large enough to hold 
it.
+static bool SpaValueIsType(const spa_pod* val, uint32_t type) {
+  return val->type == type && val->size >= spa_pod_type_size(type);
+}
+
 VideoType PipeWireRawFormatToVideoType(uint32_t id) {
   switch (id) {
     case SPA_VIDEO_FORMAT_I420:
@@ -187,20 +192,21 @@ void PipeWireNode::OnNodeParam(void* data,
   prop = spa_pod_object_find_prop(obj, prop, SPA_FORMAT_VIDEO_framerate);
   if (prop) {
     val = spa_pod_get_values(&prop->value, &n_items, &choice);
-    if (val->type == SPA_TYPE_Fraction) {
+    if (SpaValueIsType(val, SPA_TYPE_Fraction)) {
       spa_fraction* fract;
 
       fract = static_cast<spa_fraction*>(SPA_POD_BODY(val));
 
-      if (choice == SPA_CHOICE_None) {
+      if (choice == SPA_CHOICE_None && n_items >= 1) {
         cap.maxFPS = 1.0 * fract[0].num / fract[0].denom;
-      } else if (choice == SPA_CHOICE_Enum) {
+      } else if (choice == SPA_CHOICE_Enum && n_items >= 2) {
         for (uint32_t i = 1; i < n_items; i++) {
           cap.maxFPS = std::max(
               static_cast<int32_t>(1.0 * fract[i].num / fract[i].denom),
               cap.maxFPS);
         }
-      } else if (choice == SPA_CHOICE_Range && fract[1].num > 0) {
+      } else if (choice == SPA_CHOICE_Range && n_items >= 2 &&
+                 fract[1].num > 0) {
         cap.maxFPS = 1.0 * fract[1].num / fract[1].denom;
       }
     }
@@ -211,10 +217,10 @@ void PipeWireNode::OnNodeParam(void* data,
     return;
 
   val = spa_pod_get_values(&prop->value, &n_items, &choice);
-  if (val->type != SPA_TYPE_Rectangle)
+  if (!SpaValueIsType(val, SPA_TYPE_Rectangle))
     return;
 
-  if (choice != SPA_CHOICE_None)
+  if (choice != SPA_CHOICE_None || n_items < 1)
     return;
 
   if (!ParseFormat(param, &cap))
@@ -269,10 +275,10 @@ bool PipeWireNode::ParseFormat(const spa_pod* param,
       return false;
 
     val = spa_pod_get_values(&prop->value, &n_items, &choice);
-    if (val->type != SPA_TYPE_Id)
+    if (!SpaValueIsType(val, SPA_TYPE_Id))
       return false;
 
-    if (choice != SPA_CHOICE_None)
+    if (choice != SPA_CHOICE_None || n_items < 1)
       return false;
 
     id = static_cast<uint32_t*>(SPA_POD_BODY(val));

++++++ ppc-fedora-0002-regenerate-xnn-buildgn.patch ++++++
++++ 62843 lines (skipped)
++++ between 
/work/SRC/openSUSE:Factory/chromium/ppc-fedora-0002-regenerate-xnn-buildgn.patch
++++ and 
/work/SRC/openSUSE:Factory/.chromium.new.1265/ppc-fedora-0002-regenerate-xnn-buildgn.patch

++++++ ppc-fedora-HACK-debian-clang-disable-pa-musttail.patch ++++++
--- /var/tmp/diff_new_pack.Wy6hlw/_old  2026-09-10 11:50:58.100526290 +0200
+++ /var/tmp/diff_new_pack.Wy6hlw/_new  2026-09-10 11:50:58.105526500 +0200
@@ -6,8 +6,8 @@
  //     PA_MUSTTAIL return Func1(d + 1);  // `Func1()` will be tail-called.
  //   }
  // ```
--#if PA_HAS_CPP_ATTRIBUTE(clang::musttail)
-+#if PA_HAS_CPP_ATTRIBUTE(clang::musttail) && !defined(__powerpc64__)
+-#if __has_cpp_attribute(clang::musttail)
++#if __has_cpp_attribute(clang::musttail) && !defined(__powerpc64__)
  #define PA_MUSTTAIL [[clang::musttail]]
  #else
  #define PA_MUSTTAIL

Reply via email to