Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package chromium for openSUSE:Factory checked in at 2026-09-10 11:47:55 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/chromium (Old) and /work/SRC/openSUSE:Factory/.chromium.new.1265 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "chromium" Thu Sep 10 11:47:55 2026 rev:545 rq:1376518 version:153.0.8010.36 Changes: -------- --- /work/SRC/openSUSE:Factory/chromium/chromium.changes 2026-09-07 11:31:01.121549014 +0200 +++ /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium.changes 2026-09-10 11:50:39.624751433 +0200 @@ -1,0 +2,283 @@ +Wed Sep 9 04:29:11 UTC 2026 - Andreas Stieger <[email protected]> + +- Chromium 153 promoted to stable channel +- Chromium 153.0.8010.36 (boo#1279840): + * CVE-2026-87464: Use after free in WebGL + * CVE-2026-87488: Use after free in WebGL + * CVE-2026-87438: Out of bounds write in WebGL + * CVE-2026-87527: Buffer overflow in WebGL + * CVE-2026-87628: Use after free in Cast + * CVE-2026-87512: Use after free in ANGLE + * CVE-2026-87585: Double free in PDFium + * CVE-2026-87444: Memory corruption in Codecs + * CVE-2026-87447: Incorrect authorization in Network + * CVE-2026-87440: Out of bounds read in Media + * CVE-2026-87633: Use after free in Views + * CVE-2026-87525: Out of bounds read in Chromoting + * CVE-2026-87578: Use after free in Receiver + * CVE-2026-87517: Race condition in Mobile + * CVE-2026-87524: Use after free in Core + * CVE-2026-87569: Missing authorization in Views + * CVE-2026-87554: Race condition in Chromoting + * CVE-2026-87467: Race condition in Updater + * CVE-2026-87492: Incorrect authorization in DevTools + * CVE-2026-87520: Use after free in Dawn + * CVE-2026-87514: Use after free in Views + * CVE-2026-87650: Out of bounds read in WebGL + * CVE-2026-87596: Out of bounds read in ANGLE + * CVE-2026-87654: Buffer overflow in ANGLE + * CVE-2026-87604: Out of bounds read in ANGLE + * CVE-2026-87621: Out of bounds write in ANGLE + * CVE-2026-87647: Uninitialized resource in GPU + * CVE-2026-87646: Use after free in Web Authentication + * CVE-2026-87500: Improper validation of array index in ANGLE + * CVE-2026-87572: Injection in DevTools + * CVE-2026-87460: Use after free in Platform + * CVE-2026-87542: Use after free in Input + * CVE-2026-87639: Use after free in WebPackaging + * CVE-2026-87552: Missing authorization in TrustedWebActivities + * CVE-2026-87651: Incorrect authorization in Paint + * CVE-2026-87587: Use after free in V8 + * CVE-2026-87564: Type confusion in V8 + * CVE-2026-87498: Missing authorization in WebUI + * CVE-2026-87499: Incorrect authorization in Network + * CVE-2026-87607: Use after free in Device + * CVE-2026-87558: Use after free in Payments + * CVE-2026-87581: Use after free in Payments + * CVE-2026-87480: Use after free in Printing + * CVE-2026-87612: Type confusion in V8 + * CVE-2026-87536: Use after free in V8 + * CVE-2026-87474: Use after free in Payments + * CVE-2026-87504: Use after free in Core + * CVE-2026-87640: Out of bounds read in WebView + * CVE-2026-87491: Out of bounds write in V8 + * CVE-2026-87478: Observable discrepancy in Autofill + * CVE-2026-87446: Incomplete cleanup in Extensions + * CVE-2026-87657: Use after free in V8 + * CVE-2026-87434: Missing authorization in CORS + * CVE-2026-87487: Missing authorization in FileSystem + * CVE-2026-87453: Confused deputy in BackgroundFetch + * CVE-2026-87588: Use after free in Chromecast + * CVE-2026-87636: Type confusion in XML + * CVE-2026-87611: Missing authorization in FileSystem + * CVE-2026-87606: Missing authorization in SiteIsolation + * CVE-2026-87456: Uninitialized resource in Media + * CVE-2026-87553: Improper input validation in SiteIsolation + * CVE-2026-87658: Information leak in Extensions + * CVE-2026-87465: Incorrect authorization in Downloads + * CVE-2026-87515: Incorrect authorization in FileAPI + * CVE-2026-87547: Incorrect reference resolution in FileSystem + * CVE-2026-87442: Confused deputy in Prerender + * CVE-2026-87506: Privilege elevation in WebUI + * CVE-2026-87433: Race condition in FileAPI + * CVE-2026-87557: Missing authorization in LocalNetworkAccess + * CVE-2026-87457: Race condition in Updater + * CVE-2026-87503: Inappropriate implementation in Downloads + * CVE-2026-87481: Incorrect authorization in WebView + * CVE-2026-87537: Missing authorization in Extensions + * CVE-2026-87471: Incorrect authorization in ServiceWorker + * CVE-2026-87485: Incorrect authorization in CORS + * CVE-2026-87652: Incorrect authorization in PushAPI + * CVE-2026-87582: Confused deputy in DataTransfer + * CVE-2026-87466: Incorrect authorization in Workers + * CVE-2026-87603: Missing authorization in FileSystem + * CVE-2026-87615: Race condition in Payments + * CVE-2026-87642: Uninitialized resource in WebGL + * CVE-2026-87577: Incorrect authorization in Isolated + * CVE-2026-87449: Cross-site request forgery in DeviceBoundSessionCredentials + * CVE-2026-87613: Incorrect reference resolution in Extensions + * CVE-2026-87645: Improper state validation in Safebrowsing + * CVE-2026-87443: Missing authorization in Actor + * CVE-2026-87630: Integer overflow in WebRTC + * CVE-2026-87590: Improper input validation in Passwords + * CVE-2026-87580: Incorrect authorization in WebAppInstalls + * CVE-2026-87482: Cleartext transmission of sensitive data in HttpsUpgrades + * CVE-2026-87497: Uninitialized resource in Codecs + * CVE-2026-87579: Buffer overflow in WebRTC + * CVE-2026-87576: Uninitialized resource in GPU + * CVE-2026-87476: Incorrect authorization in Loader + * CVE-2026-87475: Missing authorization in Omnibox + * CVE-2026-87436: Incomplete cleanup in Browser + * CVE-2026-87479: Insufficient policy enforcement in Extensions + * CVE-2026-87513: Missing authorization in ControlledFrame + * CVE-2026-87432: Incorrect authorization in Navigation + * CVE-2026-87560: Missing authorization in Browser + * CVE-2026-87521: Information leak in WebMCP + * CVE-2026-87539: Observable discrepancy in Network + * CVE-2026-87648: Use after free in ANGLE + * CVE-2026-87534: Missing authorization in WebView + * CVE-2026-87562: Incorrect reference resolution in Accessibility + * CVE-2026-87556: Missing authorization in Browser + * CVE-2026-87508: Incorrect authorization in Loader + * CVE-2026-87643: Integer overflow in GPU + * CVE-2026-87573: Improper input validation in Network + * CVE-2026-87548: Improper state validation in Installer + * CVE-2026-87501: UI misrepresentation in Passwords + * CVE-2026-87452: Incorrect authorization in GPU + * CVE-2026-87516: Observable discrepancy in Navigation + * CVE-2026-87599: Improper input validation in Interstitials + * CVE-2026-87507: UI misrepresentation in Downloads + * CVE-2026-87559: UI misrepresentation in UI + * CVE-2026-87472: Improper input validation in FedCM + * CVE-2026-87486: Clickjacking in TrustedWebActivities + * CVE-2026-87655: Clickjacking in Downloads + * CVE-2026-87462: UI misrepresentation in FedCM + * CVE-2026-87649: UI misrepresentation in Downloads + * CVE-2026-87445: UI misrepresentation in Session + * CVE-2026-87567: UI misrepresentation in UrlFormatting + * CVE-2026-87496: UI misrepresentation in Browser + * CVE-2026-87441: Missing authorization in Downloads + * CVE-2026-87549: Incomplete cleanup in Downloads + * CVE-2026-87458: UI misrepresentation in Geometry + * CVE-2026-87574: Information leak in ServiceWorker + * CVE-2026-87495: Information leak in Scroll + * CVE-2026-87541: Information leak in Navigation + * CVE-2026-87451: Information leak in Downloads + * CVE-2026-87570: Incorrect authorization in SiteIsolation + * CVE-2026-87555: Uninitialized resource in GPU + * CVE-2026-87600: Improper input validation in Safebrowsing + * CVE-2026-87532: Improper state validation in Safebrowsing + * CVE-2026-87439: Information leak in ServiceWorker + * CVE-2026-87450: Incorrect authorization in Permissions + * CVE-2026-87505: Incorrect authorization in FileSystem + * CVE-2026-87622: Missing authorization in FedCM + * CVE-2026-87540: Incorrect authorization in Isolated + * CVE-2026-87594: Incorrect authorization in DataTransfer + * CVE-2026-87518: Observable discrepancy in Safebrowsing + * CVE-2026-87589: Incorrect authorization in SiteIsolation + * CVE-2026-87484: UI misrepresentation in Geometry + * CVE-2026-87530: Uncontrolled search path element in CredentialProvider + * CVE-2026-87550: Improper encoding or escaping of output in CSS + * CVE-2026-87494: Use after free in Browser + * CVE-2026-87483: Incorrect authorization in Browser + * CVE-2026-87454: Information leak in Enterprise + * CVE-2026-87616: Improper initialization in Views + * CVE-2026-87535: Information loss or omission in Safebrowsing + * CVE-2026-87644: Incorrect authorization in Views + * CVE-2026-87533: Use after free in DevTools + * CVE-2026-87635: UI misrepresentation in Payments + * CVE-2026-87641: Race condition in Browser + * CVE-2026-87431: Missing authorization in Extensions + * CVE-2026-87493: Missing authorization in FileSystem + * CVE-2026-87625: Use after free in V8 + * CVE-2026-87468: Incorrect authorization in Isolated + * CVE-2026-87563: Origin validation error in Paint + * CVE-2026-87510: Improper input validation in FileAPI + * CVE-2026-87435: Information leak in ControlledFrame + * CVE-2026-87531: Information leak in CORS + * CVE-2026-87637: Use after free in Extensions + * CVE-2026-87529: Numeric truncation error in Media + * CVE-2026-87470: Improper quantity validation in Tint + * CVE-2026-87586: Out of bounds read in ANGLE + * CVE-2026-87584: Incorrect authorization in WebUI + * CVE-2026-87632: Cross-site scripting in SanitizerAPI + * CVE-2026-87528: Type confusion in Rust + * CVE-2026-87623: Observable discrepancy in DOM + * CVE-2026-87566: Observable discrepancy in Layout + * CVE-2026-87638: Out of bounds write in Media + * CVE-2026-87455: Use after free in Aura + * CVE-2026-87591: Incorrect authorization in Extensions + * CVE-2026-87526: Use after free in Passwords + * CVE-2026-87609: Use after free in Sharing + * CVE-2026-87610: Incorrect authorization in Omnibox + * CVE-2026-87626: Incorrect authorization in DeviceBoundSessionCredentials + * CVE-2026-87629: Incorrect authorization in Sources + * CVE-2026-87653: UI misrepresentation in FullScreen + * CVE-2026-87634: Use after free in WebPackaging + * CVE-2026-87429: Missing authorization in ServiceWorker + * CVE-2026-87618: Incorrect reference resolution in Storage + * CVE-2026-87614: Incorrect authorization in ServiceWorker + * CVE-2026-87619: Observable discrepancy in Prefetch + * CVE-2026-87561: Incorrect authorization in Web Authentication + * CVE-2026-87598: Incorrect authorization in ServiceWorker + * CVE-2026-87519: Incorrect authorization in Safebrowsing + * CVE-2026-87543: Missing authorization in Core + * CVE-2026-87522: Missing authorization in WebView + * CVE-2026-87568: Improper input validation in Chromium + * CVE-2026-87656: Improper state validation in Safebrowsing + * CVE-2026-87511: Missing authorization in DevTools + * CVE-2026-87627: Interpretation conflict in Safebrowsing + * CVE-2026-87595: Server-side request forgery in Mobile + * CVE-2026-87592: Out of bounds read in Tint + * CVE-2026-87620: Observable discrepancy in SVG + * CVE-2026-87502: Confused deputy in Fullscreen + * CVE-2026-87448: Use after free in DevTools + * CVE-2026-87459: Observable discrepancy in Select + * CVE-2026-87463: Incorrect authorization in Certificate + * CVE-2026-87546: Incorrect type conversion or cast in Safebrowsing + * CVE-2026-87538: Clickjacking in Input + * CVE-2026-87545: Information leak in Mobile + * CVE-2026-87617: Use after free in DevTools + * CVE-2026-87523: Race condition in DataTransfer + * CVE-2026-87565: Information leak in Passwords + * CVE-2026-87597: UI misrepresentation in CustomTabs + * CVE-2026-87624: UI misrepresentation in Passwords + * CVE-2026-87605: Missing authorization in Contacts + * CVE-2026-87490: Information leak in Transactions Platform + * CVE-2026-87583: UI misrepresentation in Passwords + * CVE-2026-87509: Incorrect authorization in Updater + * CVE-2026-87473: Incorrect authorization in FileHandling + * CVE-2026-87461: Information leak in Core + * CVE-2026-87631: Missing authorization in DOM + * CVE-2026-87469: Improper input validation in Extensions + * CVE-2026-87489: Memory corruption in V8 + * CVE-2026-87575: Incorrect authorization in Loader + * CVE-2026-87571: Improper certificate validation in Loader + * CVE-2026-87477: Information leak in Core + * CVE-2026-87551: Improper certificate validation in CORS + * CVE-2026-87608: Improper certificate validation in FedCM + * CVE-2026-87437: Information leak in Frames + * CVE-2026-87602: Out of bounds read in ANGLE + * CVE-2026-87601: Race condition in V8 + * CVE-2026-87544: Incorrect authorization in Extensions + * CVE-2026-87430: Buffer overflow in WebRTC + * CVE-2026-87593: Information leak in Editing + +------------------------------------------------------------------- +Sat Sep 5 13:26:10 UTC 2026 - Andreas Stieger <[email protected]> + +- Build with rust 1.94 on openSUSE Tumbleweed + +------------------------------------------------------------------- +Fri Sep 4 15:23:58 UTC 2026 - Andreas Stieger <[email protected]> + +- Build with llvm23 on openSUSE Tumbleweed + +------------------------------------------------------------------- +Fri Sep 4 05:06:58 UTC 2026 - Andreas Stieger <[email protected]> + +- Chromium 153.0.8010.12 (beta released 2026-08-26) +- dropped patches: + * chromium-24264eefbfd3464161764f31a2752c5327719452.patch + (patched file is not being compiled) +- modified patches: + * ppc-fedora-HACK-debian-clang-disable-pa-musttail.patch + * ppc-fedora-0002-regenerate-xnn-buildgn.patch + * chromium-102-regex_pattern-array.patch + * chromium-133-bring_back_and_disable_allowlist.patch + * chromium-146-ignore-for-ubsan.patch + * chromium-152-revert-crubit.patch + * chromium-152-no-lifetime-checks.patch +- added patches: + * chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch + (another crubit revert) + * chromium-153-opus_includes.patch + (adapt include path to system lib) + * chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch + (revert in third-party pipewire for pipewire < 1.6) +- keeplibs: + added: third_party/typescript + (needed by .../extensions_zero_state_promo/build_ts_manifest.json) + added: third_party/iamf_tools + (needed by 'obj/third_party/iamf_tools/iamf_tools_lib/channel_reorderer.o) +- remove typescript binaries from tree +- add typescript-go sources + * TypeScript-7.0.2.tar.gz + * TypeScript-7.0.2-vendor.tar.gz + build the tsc (actually tsgo) binary from source since chromium + build is forcing the go binary (x86 intree binary) to save + three minutes in a fifteen hour build +- added patches: + * chromium-153-ignore-typescript-deps.patch + +------------------------------------------------------------------- Old: ---- chromium-152.0.7977.82-linux.tar.xz chromium-24264eefbfd3464161764f31a2752c5327719452.patch New: ---- TypeScript-7.0.2-vendor.tar.gz TypeScript-7.0.2.tar.gz chromium-153-ignore-typescript-deps.patch chromium-153-opus_includes.patch chromium-153.0.8010.36-linux.tar.xz chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch ----------(Old B)---------- Old:- dropped patches: * chromium-24264eefbfd3464161764f31a2752c5327719452.patch (patched file is not being compiled) ----------(Old E)---------- ----------(New B)---------- New:- added patches: * chromium-153-ignore-typescript-deps.patch New: (another crubit revert) * chromium-153-opus_includes.patch (adapt include path to system lib) New:- added patches: * chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch (another crubit revert) New: (adapt include path to system lib) * chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch (revert in third-party pipewire for pipewire < 1.6) ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ chromium.spec ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:55.922434943 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:55.924435027 +0200 @@ -63,10 +63,10 @@ # LLVM version %if 0%{?suse_version} > 1600 # LLVM version -%define llvm_version 22 -%define llvm_version_long 22.1.8 +%define llvm_version 23 +%define llvm_version_long 23.1.0 # RUST version -%define rust_version 1.93 +%define rust_version 1.94 %else # LLVM version %define llvm_version 19 @@ -120,6 +120,11 @@ %else %bcond_with flac_1_5 %endif +%if %{pkg_vcmp pipewire-devel >= 1.6.0} +%bcond_without pipewire16 +%else +%bcond_with pipewire16 +%endif # Package names %if %{with is_beta} %define chromedriver_name %{name}-chromedriver @@ -132,7 +137,7 @@ %global official_build 1 Name: chromium%{n_suffix} -Version: 152.0.7977.82 +Version: 153.0.8010.36 Release: 0 Summary: Google's open source browser project License: BSD-3-Clause AND LGPL-2.1-or-later @@ -146,6 +151,9 @@ # upstream only contains x86 binary of 4.x, other archs do not work reliably # try to use an old version like in debian package Source4: https://registry.npmjs.org/rollup/-/rollup-%{rollup_version}.tgz +# properly build a typescript-go instead of using an arbitrary intree binary +Source5: TypeScript-7.0.2.tar.gz +Source6: TypeScript-7.0.2-vendor.tar.gz # Toolchain definitions Source30: master_preferences Source104: chromium-symbolic.svg @@ -206,6 +214,8 @@ Patch403: chromium-152-revert-crubit.patch Patch404: chromium-152-value_or.patch Patch405: chromium-152-no-eula.patch +Patch406: chromium-153-opus_includes.patch +Patch407: chromium-153-ignore-typescript-deps.patch # conditionally applied patches ppc64le only # where applicable patch numbers from fedora specfile + 100 Patch452: ppc-fedora-memory-allocator-dcheck-assert-fix.patch @@ -285,9 +295,6 @@ Patch1050: chromium-140-old-flac.patch # only in ffmpeg avutil >= 60.31 Patch1051: chromium-150-ffmpeg_no_agtm.patch -# revert upstream patch ending in compile error -# error: static assertion expression is not an integral constant expression -Patch1060: chromium-24264eefbfd3464161764f31a2752c5327719452.patch Patch1061: chromium-146-static-assert.patch # llvm19 segfaults in # ../services/network/public/cpp/permissions_policy/origin_with_possible_wildcards.cc:99:1: current parser token 'std' @@ -308,6 +315,10 @@ Patch1074: chromium-152-no-lifetime-checks.patch Patch1075: chromium-152-no-warning-suppression-map.patch Patch1080: rollup.patch +# another crubit revert +Patch1081: chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch +# revert patch needing more recent pipewire +Patch1082: chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch # end conditionally applied patches BuildRequires: SDL-devel @@ -322,6 +333,7 @@ BuildRequires: gperf BuildRequires: hicolor-icon-theme BuildRequires: golang(API) +BuildRequires: golang-packaging # Java used during build BuildRequires: java-openjdk-headless BuildRequires: libdc1394 @@ -510,6 +522,7 @@ %if %{with system_zstd} BuildRequires: pkgconfig(libzstd) >= 1.5.5 %endif +BuildRequires: zstd # compiler selection %if %{with clang} # clang/llvm case @@ -537,7 +550,6 @@ %if 0%{?suse_version} >= 1699 #!BuildIgnore: rpmlint rpmlint-Factory rpmlint-mini %endif -BuildRequires: unzip %description Chromium is the open-source project behind Google Chrome. We invite you to join us in our effort to help build a safer, faster, and more stable way for all Internet users to experience the web, and to create a powerful platform for developing a new generation of web applications. @@ -587,7 +599,6 @@ clang_version="$(clang-%{llvm_version} --version | sed -n 's/clang version //p')" if [[ $(echo ${clang_version} | cut -d. -f1) -lt 21 ]]; then -%patch -p1 -R -P 1060 %patch -p1 -P 1061 %patch -p1 -P 1062 %patch -p1 -P 1065 @@ -606,6 +617,16 @@ %patch -p1 -P 1074 fi +# revert another crubit patch until we get a proper building crubit +%patch -p1 -R -P 1081 + +%if %{without pipewire16} +pushd third_party/webrtc +%patch -p1 -R -P 1082 +popd +%endif + + ## ROLLUP_HACK rm -rf third_party/devtools-frontend/src/node_modules/rollup rm -rf third_party/devtools-frontend/src/node_modules/@rollup/rollup-linux-* @@ -667,6 +688,20 @@ cp -a esbuild ../third_party/devtools-frontend/src/third_party/esbuild/esbuild popd +# drop in tree binaries +rm -f third_party/typescript/linux-amd64/src/lib/tsc{,.sig} +tar -xf %{SOURCE5} +pushd TypeScript-*/tsc +tar -xf %{SOURCE6} +# apply the local patch .. sigh +pushd internal/bundled/libs +patch -p2 < ../../../../../third_party/typescript/linux-amd64/3pp/patches/typescript_native_preview.patch +popd +%{goprep} github.com/microsoft/typescript-go +%{gobuild} -mod=vendor ./cmd/tsgo +popd +cp -a $RPM_BUILD_DIR/go/bin/tsgo third_party/typescript/linux-amd64/src/lib/tsc + # Fix the path to nodejs binary mkdir -p third_party/node/linux/node-linux-x64/bin rm -f third_party/node/linux/node-linux-x64/bin/node @@ -834,6 +869,7 @@ third_party/gperf third_party/highway third_party/hunspell + third_party/iamf_tools third_party/ink third_party/inspector_protocol third_party/ipcz @@ -940,6 +976,7 @@ third_party/tflite/src/third_party/fft2d third_party/tflite/src/third_party/xla/third_party/tsl third_party/tflite/src/third_party/xla/xla/tsl + third_party/typescript third_party/ukey2 third_party/utf third_party/vulkan @@ -1022,6 +1059,10 @@ %endif build/linux/unbundle/remove_bundled_libraries.py "${keeplibs[@]}" --do-remove +# re-add a proper python3 link +mkdir -p third_party/cpython3/host/bin +ln -sfn %{_bindir}/$PYTHON third_party/cpython3/host/bin/python3 + # GN sets lto on its own and we need just ldflag options, not cflags %define _lto_cflags %{nil} %if %{with clang} ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.180445764 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.185445973 +0200 @@ -1,6 +1,7 @@ -mtime: 1788465131 -commit: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b +mtime: 1788928336 +commit: 31e0554bd37ac3680ea48233389b8a5f2e7ce0ceaf48bc2235829119feaa99b0 url: https://src.opensuse.org/chromium/chromium -revision: bf745b3d0e23f1cb5558583914be827a578aff693820b31ddfd7e5840415083b +revision: 31e0554bd37ac3680ea48233389b8a5f2e7ce0ceaf48bc2235829119feaa99b0 +trackingbranch: main projectscmsync: https://src.opensuse.org/chromium/_ObsPrj.git ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-09 06:32:16.000000000 +0200 @@ -0,0 +1,4 @@ +.osc +*.patch~ +*-build/ +.*.swp ++++++ chromium-102-regex_pattern-array.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.396454823 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.404455158 +0200 @@ -2,7 +2,7 @@ =================================================================== --- chromium-151.0.7922.10.orig/components/autofill/core/browser/BUILD.gn +++ chromium-151.0.7922.10/components/autofill/core/browser/BUILD.gn -@@ -131,6 +131,11 @@ static_library("browser") { +@@ -131,6 +131,11 @@ _configs = configs configs = [] configs = [ "//third_party/tflite:tflite_shim_config" ] + _configs @@ -12,6 +12,6 @@ + ] + } sources = [ - "at_memory/at_memory_data_type.cc", - "at_memory/at_memory_data_type.h", + "at_memory/at_memory_enablement_utils.cc", + "at_memory/at_memory_enablement_utils.h", ++++++ chromium-133-bring_back_and_disable_allowlist.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.506459436 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.514459772 +0200 @@ -2,20 +2,19 @@ =================================================================== --- chromium-147.0.7727.3.orig/media/base/media_switches.h +++ chromium-147.0.7727.3/media/base/media_switches.h -@@ -472,6 +472,8 @@ MEDIA_EXPORT BASE_DECLARE_FEATURE( - +@@ -290,6 +290,7 @@ + MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseSequencedTaskRunnerForMediaService); + MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseTaskRunnerForMojoAudioDecoderService); MEDIA_EXPORT BASE_DECLARE_FEATURE(kUseWindowBoundsForPip); - +MEDIA_EXPORT BASE_DECLARE_FEATURE(kFFmpegAllowLists); -+ - MEDIA_EXPORT BASE_DECLARE_FEATURE(kMediaLogToConsole); - - MEDIA_EXPORT BASE_DECLARE_FEATURE(kAomVpxUsePresentationThreadType); + MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiEarlyPPSParsingForCENCv1); + MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiLowPowerEncoderGen9x); + MEDIA_EXPORT BASE_DECLARE_FEATURE(kVaapiOnNvidiaGPUs); Index: chromium-147.0.7727.3/media/base/media_switches.cc =================================================================== --- chromium-147.0.7727.3.orig/media/base/media_switches.cc +++ chromium-147.0.7727.3/media/base/media_switches.cc -@@ -1801,6 +1801,11 @@ bool IsRestrictOwnAudioSupported() { +@@ -1891,6 +1891,11 @@ #endif } @@ -24,9 +23,9 @@ + "FFmpegAllowLists", + base::FEATURE_DISABLED_BY_DEFAULT); + - #if BUILDFLAG(IS_WIN) - bool IsMediaFoundationD3D11VideoCaptureEnabled() { - return base::FeatureList::IsEnabled(kMediaFoundationD3D11VideoCapture); + bool IsSystemEchoCancellationEnforced() { + #if (BUILDFLAG(IS_MAC) || BUILDFLAG(IS_WIN)) + return base::FeatureList::IsEnabled(kEnforceSystemEchoCancellation); Index: chromium-147.0.7727.3/media/ffmpeg/ffmpeg_common.cc =================================================================== --- chromium-147.0.7727.3.orig/media/ffmpeg/ffmpeg_common.cc ++++++ chromium-146-ignore-for-ubsan.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.662465979 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.667466189 +0200 @@ -15,10 +15,10 @@ if (diagnostics_print_source_range_info && !is_win) { cflags += [ "-fdiagnostics-print-source-range-info" ] } -@@ -1579,12 +1571,6 @@ +@@ -1394,12 +1394,6 @@ ubsan_hardening("c_array_bounds") { sanitizer = "array-bounds" - condition = !(is_asan && target_cpu == "x86") && !is_wasm + condition = !(is_asan && target_cpu == "x86") - - # Because we've enabled array-bounds sanitizing we also want to suppress - # the related warning about "unsafe-buffer-usage-in-static-sized-array", ++++++ chromium-152-no-lifetime-checks.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.802471851 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.812472270 +0200 @@ -1,7 +1,7 @@ --- chromium-152.0.7977.54/third_party/dawn/src/utils/BUILD.gn 2026/08/21 07:40:42 1.1 +++ chromium-152.0.7977.54/third_party/dawn/src/utils/BUILD.gn 2026/08/21 07:41:10 -@@ -210,16 +210,6 @@ - "-Wno-non-virtual-dtor", +@@ -208,13 +208,6 @@ + "-Wno-float-equal", "-Wno-undefined-func-template", "-Wno-unused-parameter", - @@ -10,10 +10,7 @@ - # -Wlifetime-safety-lifetimebound-violation) are not yet mapped to - # toggleable warning flags, so we suppress the entire group and disable - # the analysis pass. -- "-Wno-lifetime-safety", - "-Wno-lifetime-safety-all", -- "-Xclang=-fno-lifetime-safety-inference", -- "-Xclang=-fno-experimental-lifetime-safety-tu-analysis", ] # P3. Checks that could be nice but probably don't help with hardening. ++++++ chromium-152-revert-crubit.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:56.842473528 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:56.848473780 +0200 @@ -1,6 +1,8 @@ ---- chromium-152.0.7977.54/DEPS 2026/08/20 14:49:31 1.1 -+++ chromium-152.0.7977.54/DEPS 2026/08/20 14:50:05 -@@ -4257,16 +4257,9 @@ +Index: chromium-153.0.8010.5/DEPS +=================================================================== +--- chromium-153.0.8010.5.orig/DEPS ++++ chromium-153.0.8010.5/DEPS +@@ -4322,16 +4322,9 @@ include_rules = [ '+third_party/google_benchmark/src/include/benchmark/benchmark.h', '+third_party/icu/source/common/unicode', '+third_party/icu/source/i18n/unicode', @@ -18,24 +20,28 @@ # Abseil is allowed by default, but some features are banned. See # //styleguide/c++/c++-features.md. '+third_party/abseil-cpp', ---- chromium-152.0.7977.54/tools/rust/build_crubit.py 2026/08/20 14:54:51 1.1 -+++ chromium-152.0.7977.54/tools/rust/build_crubit.py 2026/08/20 14:55:20 -@@ -134,12 +134,8 @@ - shutil.copy(os.path.join(release_dir, bin), - os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'bin', bin)) +Index: chromium-153.0.8010.5/tools/rust/build_crubit.py +=================================================================== +--- chromium-153.0.8010.5.orig/tools/rust/build_crubit.py ++++ chromium-153.0.8010.5/tools/rust/build_crubit.py +@@ -148,12 +148,9 @@ def BuildCrubit(rust_sysroot, out_dir, s + os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'bin', bin), + ) - # `crubit_target_dir` below helps ensure that Chromium can use the same - # `#include` paths as other Crubit clients like google3 - e.g. - # `#include "third_party/crubit/support/rs_std/slice_ref.h"`. print(f'Installing `crubit/support` to {RUST_TOOLCHAIN_OUT_DIR} ...') -- crubit_target_dir = os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'lib', -- 'third_party', 'crubit') -+ crubit_target_dir = os.path.join(RUST_TOOLCHAIN_OUT_DIR, 'lib', 'crubit') + crubit_target_dir = os.path.join( +- RUST_TOOLCHAIN_OUT_DIR, 'lib', 'third_party', 'crubit' ++ RUST_TOOLCHAIN_OUT_DIR, 'lib', 'crubit' + ) for item in ["BUILD.gn", "LICENSE", "crubit.gni", "support"]: source_path = os.path.join(CRUBIT_SRC_DIR, item) - target_path = os.path.join(crubit_target_dir, item) ---- chromium-152.0.7977.54/build_overrides/crubit.gni 2026/08/20 14:54:24 1.1 -+++ chromium-152.0.7977.54/build_overrides/crubit.gni 2026/08/20 14:54:41 +Index: chromium-153.0.8010.5/build_overrides/crubit.gni +=================================================================== +--- chromium-153.0.8010.5.orig/build_overrides/crubit.gni ++++ chromium-153.0.8010.5/build_overrides/crubit.gni @@ -2,7 +2,7 @@ # Use of this source code is governed by a BSD-style license that can be # found in the LICENSE file. @@ -45,10 +51,12 @@ crubit_absl_dep_target = "//third_party/abseil-cpp:absl" crubit_gn_configs_to_remove = [ "//build/config/compiler:chromium_code", ---- chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/unittests.cc 2026/08/20 14:53:31 1.1 -+++ chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/unittests.cc 2026/08/20 14:54:11 -@@ -4,8 +4,8 @@ - +Index: chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/unittests.cc +=================================================================== +--- chromium-153.0.8010.5.orig/build/rust/tests/test_cpp_api_from_rust/unittests.cc ++++ chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/unittests.cc +@@ -5,8 +5,8 @@ + #include "build/build_config.h" #include "build/rust/tests/test_cpp_api_from_rust/rust_lib.h" #include "testing/gtest/include/gtest/gtest.h" -#include "third_party/crubit/support/rs_std/char.h" @@ -58,11 +66,13 @@ TEST(RustCcBindingsFromRs, TestI32) { EXPECT_EQ(12, rust_lib::mul_two_ints_via_rust(3, 4)); ---- chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/BUILD.gn 2026/08/20 14:52:56 1.1 -+++ chromium-152.0.7977.54/build/rust/tests/test_cpp_api_from_rust/BUILD.gn 2026/08/20 14:53:16 -@@ -31,7 +31,8 @@ - deps = [ +Index: chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/BUILD.gn +=================================================================== +--- chromium-153.0.8010.5.orig/build/rust/tests/test_cpp_api_from_rust/BUILD.gn ++++ chromium-153.0.8010.5/build/rust/tests/test_cpp_api_from_rust/BUILD.gn +@@ -32,7 +32,8 @@ source_set("test_cpp_api_from_rust") { ":rust_lib_bindings", + ":target_depending_only_on_bindings", "//base", - "//build/rust/crubit", + "//build/rust/crubit:rs_std", @@ -70,9 +80,11 @@ "//testing/gmock", "//testing/gtest", ] ---- chromium-152.0.7977.54/build/rust/gni_impl/cpp_api_from_rust.gni 2026/08/20 14:51:22 1.1 -+++ chromium-152.0.7977.54/build/rust/gni_impl/cpp_api_from_rust.gni 2026/08/20 14:52:36 -@@ -91,7 +91,8 @@ +Index: chromium-153.0.8010.5/build/rust/gni_impl/cpp_api_from_rust.gni +=================================================================== +--- chromium-153.0.8010.5.orig/build/rust/gni_impl/cpp_api_from_rust.gni ++++ chromium-153.0.8010.5/build/rust/gni_impl/cpp_api_from_rust.gni +@@ -91,7 +91,8 @@ template("cpp_api_from_rust") { _original_attributes.deps += [ "//build/rust/std:std_bindings" ] } @@ -82,8 +94,10 @@ _cpp_api_from_rust_exe_path = "//third_party/rust-toolchain/bin/cc_bindings_from_rs" _rustfmt_exe_path = "//third_party/rust-toolchain/bin/rustfmt" ---- chromium-152.0.7977.54/build/rust/crubit/BUILD.gn 2026/08/20 14:50:21 1.1 -+++ chromium-152.0.7977.54/build/rust/crubit/BUILD.gn 2026/08/20 14:51:00 +Index: chromium-153.0.8010.5/build/rust/crubit/BUILD.gn +=================================================================== +--- chromium-153.0.8010.5.orig/build/rust/crubit/BUILD.gn ++++ chromium-153.0.8010.5/build/rust/crubit/BUILD.gn @@ -4,36 +4,20 @@ import("//build_overrides/crubit.gni") @@ -127,9 +141,11 @@ } # This config is injected via `//build_overrides/crubit.gni`. ---- chromium-152.0.7977.54/components/cbor/BUILD.gn 2026/08/20 16:06:43 1.1 -+++ chromium-152.0.7977.54/components/cbor/BUILD.gn 2026/08/20 16:07:38 -@@ -12,7 +12,7 @@ +Index: chromium-153.0.8010.5/components/cbor/BUILD.gn +=================================================================== +--- chromium-153.0.8010.5.orig/components/cbor/BUILD.gn ++++ chromium-153.0.8010.5/components/cbor/BUILD.gn +@@ -12,7 +12,7 @@ buildflag_header("buildflags") { # TODO(crbug.com/535682335): Remove `USE_CBOR_RUST` buildflag entirely, # unconditionally enable Rust CBOR parser, and drop `is_cronet_build` check # once Cronet supports Crubit dependencies. @@ -138,7 +154,7 @@ } component("cbor") { -@@ -37,12 +37,12 @@ +@@ -35,12 +35,12 @@ component("cbor") { "//base", ] ++++++ chromium-153-ignore-typescript-deps.patch ++++++ --- chromium-153.0.8010.5/tools/typescript/validate_tsconfig.py 2026/08/29 09:27:43 1.1 +++ chromium-153.0.8010.5/tools/typescript/validate_tsconfig.py 2026/08/29 09:29:12 @@ -337,4 +337,5 @@ for missing_input in missing_inputs: errorMessage += f'//{missing_input}\n' - return False, errorMessage + #return False, errorMessage + return True, None ++++++ chromium-153-opus_includes.patch ++++++ --- chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc 2026/08/26 09:00:55 1.1 +++ chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc 2026/08/26 09:01:07 @@ -30,8 +30,8 @@ #include "iamf/obu/decoder_config/opus_decoder_config.h" #include "iamf/obu/substream_channel_count.h" #include "iamf/obu/types.h" -#include "include/opus.h" -#include "include/opus_types.h" +#include "opus.h" +#include "opus_types.h" namespace iamf_tools { --- chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h 2026/08/26 09:01:09 1.1 +++ chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h 2026/08/26 09:01:12 @@ -23,7 +23,7 @@ #include "iamf/cli/codec/decoder_base.h" #include "iamf/obu/decoder_config/opus_decoder_config.h" #include "iamf/obu/substream_channel_count.h" -#include "include/opus.h" +#include "opus.h" namespace iamf_tools { --- chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc 2026/08/26 09:01:12 1.1 +++ chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc 2026/08/26 09:01:21 @@ -32,9 +32,9 @@ #include "iamf/common/utils/validation_utils.h" #include "iamf/obu/decoder_config/opus_decoder_config.h" #include "iamf/obu/substream_channel_count.h" -#include "include/opus.h" -#include "include/opus_defines.h" -#include "include/opus_types.h" +#include "opus.h" +#include "opus_defines.h" +#include "opus_types.h" namespace iamf_tools { --- chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h 2026/08/26 09:01:21 1.1 +++ chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h 2026/08/26 09:01:27 @@ -22,8 +22,8 @@ #include "iamf/obu/codec_config.h" #include "iamf/obu/decoder_config/opus_decoder_config.h" #include "iamf/obu/substream_channel_count.h" -#include "include/opus.h" -#include "include/opus_defines.h" +#include "opus.h" +#include "opus_defines.h" namespace iamf_tools { --- chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc 2026/08/26 09:01:27 1.1 +++ chromium-153.0.8010.5/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc 2026/08/26 09:01:31 @@ -3,7 +3,7 @@ #include "absl/status/status.h" #include "absl/strings/str_cat.h" #include "absl/strings/string_view.h" -#include "include/opus_defines.h" +#include "opus_defines.h" namespace iamf_tools { ++++++ chromium-152.0.7977.82-linux.tar.xz -> chromium-153.0.8010.36-linux.tar.xz ++++++ /work/SRC/openSUSE:Factory/chromium/chromium-152.0.7977.82-linux.tar.xz /work/SRC/openSUSE:Factory/.chromium.new.1265/chromium-153.0.8010.36-linux.tar.xz differ: char 15, line 1 ++++++ chromium-493e6c3911e33cc356856bafbffc6cf95521266b.patch ++++++ commit 493e6c3911e33cc356856bafbffc6cf95521266b Author: Dominik Röttsches <[email protected]> Date: Thu Aug 13 08:42:15 2026 -0700 Migrate OpenType format check bindings to Crubit We can remove the Box<> wrapped typing of FontFormatInfo along the way. DEPS checks for the generated output header files requires us to move the format_check target into the fonts subdirectory. This is a good opportunity to move more font specific build rules to the font subdir in the future and reduce the weight of the platform/BUILD.gn build dir. Exercise in using the Crubit bindings mechanism. No functional change. Change-Id: I9440c7285bb707b325b80ee074de51e714ee4884 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8244248 Reviewed-by: Łukasz Anforowicz <[email protected]> Commit-Queue: Dominik Röttsches <[email protected]> Cr-Commit-Position: refs/heads/main@{#1678858} diff --git a/third_party/blink/renderer/platform/BUILD.gn b/third_party/blink/renderer/platform/BUILD.gn index d5e81a3f07a3c..6a5d275460122 100644 --- a/third_party/blink/renderer/platform/BUILD.gn +++ b/third_party/blink/renderer/platform/BUILD.gn @@ -186,18 +186,6 @@ group("make_platform_generated") { ] } -rust_static_library("font_format_check") { - allow_unsafe = true # Needed for FFI that underpins the `cxx` crate. - crate_root = "fonts/opentype/format_check.rs" - sources = [ crate_root ] - cxx_bindings = [ crate_root ] - deps = [ - "//third_party/rust/font_types/v0_12:lib", - "//third_party/rust/read_fonts/v0_41:lib", - "//third_party/rust/skrifa/v0_44:lib", - ] -} - rust_static_library("rustfft_ffi") { allow_unsafe = true # Needed for FFI that underpins the `cxx` crate. crate_root = "audio/rustfft_ffi.rs" @@ -1806,6 +1794,7 @@ component("platform") { ":allow_discouraged_type", ":blink_platform_public_deps", ":platform_export", + "//build/rust/crubit", "//gpu/command_buffer/client:raster_interface", "//media/capture:capture_lib", "//mojo/public/cpp/base", @@ -1832,8 +1821,8 @@ component("platform") { "//ui/native_theme/features", ] deps = [ - ":font_format_check", ":rustfft_ffi", + "fonts:font_format_bindings", "//base:base_static", "//base/allocator:buildflags", "//build:chromecast_buildflags", diff --git a/third_party/blink/renderer/platform/fonts/BUILD.gn b/third_party/blink/renderer/platform/fonts/BUILD.gn new file mode 100644 index 0000000000000..51b9b03ba7c85 --- /dev/null +++ b/third_party/blink/renderer/platform/fonts/BUILD.gn @@ -0,0 +1,19 @@ +# Copyright 2026 The Chromium Authors +# Use of this source code is governed by a BSD-style license that can be +# found in the LICENSE file. + +import("//build/rust/rust_static_library.gni") + +rust_static_library("font_format") { + crate_root = "opentype/format_check.rs" + sources = [ crate_root ] + cpp_api_from_rust = { + target_name = "font_format_bindings" + cpp_namespace = "font_format" + } + deps = [ + "//third_party/rust/font_types/v0_12:lib", + "//third_party/rust/read_fonts/v0_41:lib", + "//third_party/rust/skrifa/v0_44:lib", + ] +} diff --git a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc index b9d2639822bc0..f58e9433d39f4 100644 --- a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc +++ b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc @@ -7,7 +7,6 @@ #include "base/containers/span.h" #include "base/containers/span_rust.h" #include "base/numerics/byte_conversions.h" -#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h" #include "third_party/blink/renderer/platform/runtime_enabled_features.h" #include "third_party/blink/renderer/platform/wtf/vector.h" #include "third_party/skia/include/core/SkTypeface.h" @@ -15,35 +14,37 @@ namespace blink { FontFormatCheck::FontFormatCheck(sk_sp<SkData> sk_data) - : format_info_(font_format_check::get_font_format_info( + : format_info_(font_format::get_font_format_info( base::SpanToRustSlice(sk_data->byteSpan()))) {} +FontFormatCheck::~FontFormatCheck() = default; + bool FontFormatCheck::IsVariableFont() const { - return font_format_check::is_variable(*format_info_); + return font_format::is_variable(format_info_); } bool FontFormatCheck::IsCbdtCblcColorFont() const { - return font_format_check::is_cbdt_cblc(*format_info_); + return font_format::is_cbdt_cblc(format_info_); } bool FontFormatCheck::IsEbdtEblcMonochromeFont() const { - return font_format_check::is_ebdt_eblc(*format_info_); + return font_format::is_ebdt_eblc(format_info_); } bool FontFormatCheck::IsColrCpalColorFontV0() const { - return font_format_check::is_colrv0(*format_info_); + return font_format::is_colrv0(format_info_); } bool FontFormatCheck::IsColrCpalColorFontV1() const { - return font_format_check::is_colrv1(*format_info_); + return font_format::is_colrv1(format_info_); } bool FontFormatCheck::IsSbixColorFont() const { - return font_format_check::is_sbix(*format_info_); + return font_format::is_sbix(format_info_); } bool FontFormatCheck::IsCff2OutlineFont() const { - return font_format_check::is_cff2(*format_info_); + return font_format::is_cff2(format_info_); } bool FontFormatCheck::IsVariableColrV0Font() const { @@ -57,7 +58,7 @@ bool FontFormatCheck::IsColorFont() const { bool FontFormatCheck::IsAvar2Font() const { return RuntimeEnabledFeatures::FontFormatAvar2Enabled() && - font_format_check::is_avar2(*format_info_); + font_format::is_avar2(format_info_); } FontFormatCheck::VariableFontSubType FontFormatCheck::ProbeVariableFont( diff --git a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h index 19d2639233b07..af50dbdf74d00 100644 --- a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h +++ b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h @@ -5,7 +5,7 @@ #ifndef THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_ #define THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_ -#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h" +#include "third_party/blink/renderer/platform/fonts/font_format.h" #include "third_party/blink/renderer/platform/platform_export.h" #include "third_party/blink/renderer/platform/wtf/allocator/allocator.h" #include "third_party/skia/include/core/SkData.h" @@ -19,7 +19,7 @@ class PLATFORM_EXPORT FontFormatCheck { public: explicit FontFormatCheck(sk_sp<SkData>); - virtual ~FontFormatCheck() = default; + virtual ~FontFormatCheck(); virtual bool IsVariableFont() const; virtual bool IsCbdtCblcColorFont() const; virtual bool IsEbdtEblcMonochromeFont() const; @@ -46,7 +46,7 @@ class PLATFORM_EXPORT FontFormatCheck { enum class COLRVersion { kCOLRV0, kCOLRV1, kNoCOLR }; private: - rust::Box<font_format_check::FontFormatInfo> format_info_; + font_format::FontFormatInfo format_info_; }; } // namespace blink diff --git a/third_party/blink/renderer/platform/fonts/opentype/format_check.rs b/third_party/blink/renderer/platform/fonts/opentype/format_check.rs index eda8e6b2b8188..b99f0ec8655e6 100644 --- a/third_party/blink/renderer/platform/fonts/opentype/format_check.rs +++ b/third_party/blink/renderer/platform/fonts/opentype/format_check.rs @@ -23,7 +23,7 @@ pub struct FontFormatInfo { format_flags: Option<FontFormatFlags>, } -pub fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo> { +pub fn get_font_format_info(font_bytes: &[u8]) -> FontFormatInfo { let file_ref = make_font_ref_internal(font_bytes, 0); match file_ref { @@ -32,11 +32,11 @@ pub fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo> { font.table_directory().table_records().iter().map(|e| e.tag()).collect(); let color_version = get_colr_version(&font); let avar_version = get_avar_version(&font); - Box::new(FontFormatInfo { + FontFormatInfo { format_flags: Some(FontFormatFlags { table_tags, color_version, avar_version }), - }) + } } - _ => Box::new(FontFormatInfo::default()), + _ => FontFormatInfo::default(), } } @@ -44,10 +44,10 @@ fn get_colr_version(font_ref: &FontRef) -> Option<u16> { Some(font_ref.colr().ok()?.version()) } -fn is_colrv1(format_info: &FontFormatInfo) -> bool { +pub fn is_colrv1(format_info: &FontFormatInfo) -> bool { matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: Some(1), .. }),) } -fn is_colrv0(format_info: &FontFormatInfo) -> bool { +pub fn is_colrv0(format_info: &FontFormatInfo) -> bool { matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: Some(0), .. }),) } @@ -56,7 +56,7 @@ fn get_avar_version(font_ref: &FontRef) -> Option<(u16, u16)> { Some((version.major, version.minor)) } -fn is_avar2(format_info: &FontFormatInfo) -> bool { +pub fn is_avar2(format_info: &FontFormatInfo) -> bool { matches!(&format_info.format_flags, Some(FontFormatFlags { avar_version: Some((2, _)), .. }),) } @@ -69,39 +69,22 @@ fn has_tags(format_info: &FontFormatInfo, query: &[Tag]) -> bool { } } -fn is_variable(format_info: &FontFormatInfo) -> bool { +pub fn is_variable(format_info: &FontFormatInfo) -> bool { has_tags(format_info, &[Tag::new(b"fvar")]) } -fn is_sbix(format_info: &FontFormatInfo) -> bool { +pub fn is_sbix(format_info: &FontFormatInfo) -> bool { has_tags(format_info, &[Tag::new(b"sbix")]) } -fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool { +pub fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool { has_tags(format_info, &[Tag::new(b"CBDT"), Tag::new(b"CBLC")]) } -fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool { +pub fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool { has_tags(format_info, &[Tag::new(b"EBDT"), Tag::new(b"EBLC")]) } -fn is_cff2(format_info: &FontFormatInfo) -> bool { +pub fn is_cff2(format_info: &FontFormatInfo) -> bool { has_tags(format_info, &[Tag::new(b"CFF2")]) } - -#[cxx::bridge(namespace = "font_format_check")] -pub mod ffi { - extern "Rust" { - type FontFormatInfo; - - fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo>; - fn is_colrv1(format_info: &FontFormatInfo) -> bool; - fn is_colrv0(format_info: &FontFormatInfo) -> bool; - fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool; - fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool; - fn is_variable(format_info: &FontFormatInfo) -> bool; - fn is_sbix(format_info: &FontFormatInfo) -> bool; - fn is_cff2(format_info: &FontFormatInfo) -> bool; - fn is_avar2(format_info: &FontFormatInfo) -> bool; - } -} ++++++ chromium-a0253ec15b3d3072fb35d6be29ba9224c36f9dd7.patch ++++++ commit a0253ec15b3d3072fb35d6be29ba9224c36f9dd7 Author: Jan Grulich <[email protected]> Date: Thu Aug 13 08:37:32 2026 +0200 Video capture: validate SPA pod values to prevent OOB reads Add bounds checks when reading SPA pod choice values in OnNodeParam and ParseFormat. Validate that the pod value size matches the expected type using spa_pod_type_size() and that the number of choice items is sufficient before accessing the underlying arrays. Bug: chromium:545349644 Change-Id: I865e4736f52be1a0dfce47827181dc072630bb57 Reviewed-on: https://webrtc-review.googlesource.com/c/src/+/495620 Commit-Queue: Jan Grulich <[email protected]> Reviewed-by: Ilya Nikolaevskiy <[email protected]> Reviewed-by: Andreas Pehrson <[email protected]> Reviewed-by: Per Kjellander <[email protected]> Cr-Commit-Position: refs/heads/main@{#48344} diff --git a/modules/video_capture/linux/pipewire_session.cc b/modules/video_capture/linux/pipewire_session.cc index ba841a7f19..e17bab807c 100644 --- a/modules/video_capture/linux/pipewire_session.cc +++ b/modules/video_capture/linux/pipewire_session.cc @@ -46,6 +46,11 @@ namespace webrtc { namespace videocapturemodule { +// Checks that the pod matches the expected type and is large enough to hold it. +static bool SpaValueIsType(const spa_pod* val, uint32_t type) { + return val->type == type && val->size >= spa_pod_type_size(type); +} + VideoType PipeWireRawFormatToVideoType(uint32_t id) { switch (id) { case SPA_VIDEO_FORMAT_I420: @@ -187,20 +192,21 @@ void PipeWireNode::OnNodeParam(void* data, prop = spa_pod_object_find_prop(obj, prop, SPA_FORMAT_VIDEO_framerate); if (prop) { val = spa_pod_get_values(&prop->value, &n_items, &choice); - if (val->type == SPA_TYPE_Fraction) { + if (SpaValueIsType(val, SPA_TYPE_Fraction)) { spa_fraction* fract; fract = static_cast<spa_fraction*>(SPA_POD_BODY(val)); - if (choice == SPA_CHOICE_None) { + if (choice == SPA_CHOICE_None && n_items >= 1) { cap.maxFPS = 1.0 * fract[0].num / fract[0].denom; - } else if (choice == SPA_CHOICE_Enum) { + } else if (choice == SPA_CHOICE_Enum && n_items >= 2) { for (uint32_t i = 1; i < n_items; i++) { cap.maxFPS = std::max( static_cast<int32_t>(1.0 * fract[i].num / fract[i].denom), cap.maxFPS); } - } else if (choice == SPA_CHOICE_Range && fract[1].num > 0) { + } else if (choice == SPA_CHOICE_Range && n_items >= 2 && + fract[1].num > 0) { cap.maxFPS = 1.0 * fract[1].num / fract[1].denom; } } @@ -211,10 +217,10 @@ void PipeWireNode::OnNodeParam(void* data, return; val = spa_pod_get_values(&prop->value, &n_items, &choice); - if (val->type != SPA_TYPE_Rectangle) + if (!SpaValueIsType(val, SPA_TYPE_Rectangle)) return; - if (choice != SPA_CHOICE_None) + if (choice != SPA_CHOICE_None || n_items < 1) return; if (!ParseFormat(param, &cap)) @@ -269,10 +275,10 @@ bool PipeWireNode::ParseFormat(const spa_pod* param, return false; val = spa_pod_get_values(&prop->value, &n_items, &choice); - if (val->type != SPA_TYPE_Id) + if (!SpaValueIsType(val, SPA_TYPE_Id)) return false; - if (choice != SPA_CHOICE_None) + if (choice != SPA_CHOICE_None || n_items < 1) return false; id = static_cast<uint32_t*>(SPA_POD_BODY(val)); ++++++ ppc-fedora-0002-regenerate-xnn-buildgn.patch ++++++ ++++ 62843 lines (skipped) ++++ between /work/SRC/openSUSE:Factory/chromium/ppc-fedora-0002-regenerate-xnn-buildgn.patch ++++ and /work/SRC/openSUSE:Factory/.chromium.new.1265/ppc-fedora-0002-regenerate-xnn-buildgn.patch ++++++ ppc-fedora-HACK-debian-clang-disable-pa-musttail.patch ++++++ --- /var/tmp/diff_new_pack.Wy6hlw/_old 2026-09-10 11:50:58.100526290 +0200 +++ /var/tmp/diff_new_pack.Wy6hlw/_new 2026-09-10 11:50:58.105526500 +0200 @@ -6,8 +6,8 @@ // PA_MUSTTAIL return Func1(d + 1); // `Func1()` will be tail-called. // } // ``` --#if PA_HAS_CPP_ATTRIBUTE(clang::musttail) -+#if PA_HAS_CPP_ATTRIBUTE(clang::musttail) && !defined(__powerpc64__) +-#if __has_cpp_attribute(clang::musttail) ++#if __has_cpp_attribute(clang::musttail) && !defined(__powerpc64__) #define PA_MUSTTAIL [[clang::musttail]] #else #define PA_MUSTTAIL
