AUR AI Reviewer

Review Results

Version #2038 of ungoogled-chromium · commit f23a47c85bf0 · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #1705

Comment

The only change in this .SRCINFO hunk is a pkgver bump from 150.0.7871.186 to 151.0.7922.137. No source URLs, checksums, build commands, install scripts, or packaging metadata were altered in the reviewed diff, so there is no direct security signal here. This looks like a routine version update with no evidence of added persistence, privilege escalation, or integrity weakening in the provided change.

@@ -1,6 +1,6 @@
 pkgbase = ungoogled-chromium
 	pkgdesc = A lightweight approach to removing Google web service dependency
-	pkgver = 150.0.7871.186
+	pkgver = 151.0.7922.137
 	pkgrel = 1
 	url = https://github.com/ungoogled-software/ungoogled-chromium
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #1706

Comment

The change only adds `go` to makedepends in .SRCINFO. This is a metadata-only dependency addition and does not introduce any new source, install script, privilege, or network behavior by itself. I did not see any direct security red flags in this diff hunk.

@@ -9,6 +9,7 @@ pkgbase = ungoogled-chromium
 	makedepends = compiler-rt
 	makedepends = git
 	makedepends = gn
+	makedepends = go
 	makedepends = gperf
 	makedepends = java-runtime-headless
 	makedepends = lld
Risk 0/5 · Safe .SRCINFO
Result #1707

Comment

The change is a metadata-only .SRCINFO update for a version bump of ungoogled-chromium. The removed makedepends (python-httplib2, python-pyparsing, python-six, npm, rsync) and added makedepends (go) are plausible build-dependency adjustments for the new upstream release; the source URLs remain HTTPS and point to official upstream locations, and the package still uses pinned release tarballs rather than floating VCS refs. No suspicious install scripts, privilege escalation, or runtime persistence mechanisms are introduced by this diff. Based on the provided hunk, I see no security issue beyond normal package maintenance.

@@ -19,11 +20,6 @@ pkgbase = ungoogled-chromium
 	makedepends = qt6-base
 	makedepends = rust-bindgen
 	makedepends = rust
-	makedepends = python-httplib2
-	makedepends = python-pyparsing
-	makedepends = python-six
-	makedepends = npm
-	makedepends = rsync
 	depends = alsa-lib
 	depends = at-spi2-core
 	depends = cairo
Risk 0/5 · Safe .SRCINFO
Result #1708

Comment

The change is a routine version bump in .SRCINFO for ungoogled-chromium. It updates pkgver/provides and swaps in the new upstream Chromium release tarball plus the corresponding ungoogled-chromium archive and patch/sum entries. I do not see any new red flags such as HTTP sources, VCS floating refs, suspicious external downloads, install-script changes, or privilege/persistence mechanisms. The added/removed makedepends and patch list appear consistent with a package refresh rather than a security-relevant behavior change. Risk is low.

@@ -81,13 +77,13 @@ pkgbase = ungoogled-chromium
 	optdepends = qt6-base: Qt support
 	optdepends = org.freedesktop.secrets: password storage backend on GNOME, KDE and Xfce
 	optdepends = upower: Battery Status API support
-	provides = chromium=150.0.7871.186
-	provides = chromedriver=150.0.7871.186
+	provides = chromium=151.0.7922.137
+	provides = chromedriver=151.0.7922.137
 	conflicts = chromium
 	conflicts = chromedriver
 	options = !lto
-	source = fetch-chromium-release
-	source = ungoogled-chromium-150.0.7871.186-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/150.0.7871.186-1.tar.gz
+	source = https://commondatastorage.googleapis.com/chromium-browser-official/chromium-151.0.7922.137-lite.tar.xz
+	source = ungoogled-chromium-151.0.7922.137-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/151.0.7922.137-1.tar.gz
 	source = https://github.com/foutrelis/chromium-launcher/archive/v8/chromium-launcher-8.tar.gz
 	source = chromium-138-nodejs-version-check.patch
 	source = chromium-145-fix-SYS_SECCOMP.patch
Risk 1/5 · Low .SRCINFO
Result #1709

Comment

Risk is low. This .SRCINFO update mainly bumps ungoogled-chromium from 150 to 151, refreshes source tarball/checksums, and swaps in a Chromium patch that only changes a GN dependency condition for non-git checkouts. The added/removed makedepends and patch list are consistent with the PKGBUILD for this version bump; there are no new suspicious URLs, no build-time network fetches beyond declared sources, no privilege-escalation or persistence mechanisms, and the reviewed patch content is a benign upstream build-system fix. The only notable change is the new go makedepends and removal of some Python/npm/rsync deps, which is not inherently risky.

@@ -96,27 +92,25 @@ pkgbase = ungoogled-chromium
 	source = chromium-149-drop-unknown-clang-flag.patch
 	source = chromium-149-unbundle-minizip-undo-unicode.patch
 	source = chromium-149-use-of-undeclared-identifier-ERROR.patch
-	source = chromium-150-fix-ar-unbundle.patch
-	source = chromium-150-fix-sysroot-path-error.patch
 	source = chromium-150-revert-avx-flag-change.patch
+	source = chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
 	source = compiler-rt-adjust-paths.patch
 	source = increase-fortify-level.patch
 	source = enable-widevine-arm64.patch
 	source = use-oauth2-client-switches-as-default.patch
 	source = glibc-2.42-baud-rate-fix.patch
-	sha256sums = 2e2f36e3cd1ebc4ad57fd310774a5e5e9db77883d5f9374fedeaabd3c103b819
-	sha256sums = f40444c3f7ecf63ed5bfe01944e23ebe9d0d6246ce99f5d2adad0728dc35164f
+	sha256sums = 3fa13440c0c99145f6628b2cd62438da05c989469c7113b19d11425f9853f645
+	sha256sums = f0e6c97580911fd8a0ecd562d743455ee9acb626a54b84682e26549d8ea1fa58
 	sha256sums = 213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a
 	sha256sums = 11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e
 	sha256sums = 4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e
 	sha256sums = c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a
 	sha256sums = b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05
-	sha256sums = 5ade4cdba7afebfcc09fa969f15bf27404579beac5b7bafb59a0214d407e4ad2
+	sha256sums = e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9
 	sha256sums = c22338d13f12772cdbcb5cfc1ace94438b9f9c72353cdb165a3ff3ef3d677c78
 	sha256sums = 951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4
-	sha256sums = f056d12571823d06c2a938158734fb4c7eeccb5c6f68228634d0c73d75feaa78
-	sha256sums = 5c42260b11b87dd01c4ef11598033e9687bdf384af2e45adab2fd00964e977e8
 	sha256sums = 5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60
+	sha256sums = 552ddcef0cf139927f54c9c728c68b0e385600107e5166449b29de75e5dfcd7f
 	sha256sums = ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863
 	sha256sums = d634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342
 	sha256sums = 33d1650e183a86cc2d0e9b0fcc08a5da76c7354d25a419921e9d2dc02b8b3854
Risk 0/5 · Safe PKGBUILD
Result #1710

Comment

The change is low risk. It updates the package to a newer upstream Chromium release, swaps the build mode from manual clone to the release tarball path, adds the Go toolchain needed by upstream build steps, and applies a small upstream GN patch that only changes a build-time dependency condition for non-git checkouts. I checked the new patch and it does not introduce runtime code, persistence, privilege escalation, network access, or suspicious install behavior. The PKGBUILD still sources Chromium and the ungoogled-chromium tarball over HTTPS from official upstream locations, and the added symlink to /usr/bin/go is confined to the build tree. No red flags beyond ordinary version/patch maintenance.

@@ -11,14 +11,14 @@
 # Contributor: Daniel J Griffiths <ghost1227@archlinux.us>
 
 pkgname=ungoogled-chromium
-pkgver=150.0.7871.186
+pkgver=151.0.7922.137
 pkgrel=1
 _launcher_ver=8
-_manual_clone=1
+_manual_clone=0
 _system_clang=1
 # ungoogled chromium variables
 _uc_usr=ungoogled-software
-_uc_ver=150.0.7871.186-1
+_uc_ver=151.0.7922.137-1
 pkgdesc="A lightweight approach to removing Google web service dependency"
 arch=('x86_64')
 url="https://github.com/ungoogled-software/ungoogled-chromium"
Risk 0/5 · Safe PKGBUILD
Result #1711

Comment

The change is narrowly scoped to adding `go` as a makedepend and wiring `/usr/bin/go` into Chromium's expected `third_party/dawn/tools/golang/linux-amd64/bin` path during prepare(). This is consistent with building newer Chromium/Dawn sources and does not introduce new network fetches, privilege escalation, persistence, or installation-time behavior. The rest of the diff is version/patch maintenance and a small appdata sed fix; nothing here suggests a supply-chain or backdoor risk.

@@ -66,6 +66,7 @@ makedepends=(
   'compiler-rt'
   'git'
   'gn'
+  'go'
   'gperf'
   'java-runtime-headless'
   'lld'
Risk 0/5 · Safe PKGBUILD
Result #1712

Comment

The change is low risk. It updates the package to a new Chromium/ungoogled-chromium release, refreshes patch checksums, and swaps out two upstream patches for one new upstream patch. The new patch only changes GN build logic to avoid depending on histograms.xml when the source tree is not a git checkout, which is appropriate for AUR tarball builds and does not add any execution, network, privilege, or persistence behavior. The added Go makedependency and symlink under third_party/dawn/tools/golang are build-time only and point to the system go binary. I did not see any suspicious source URLs, build-time downloads, or install-script/systemd changes in this diff.

@@ -96,27 +97,25 @@ source=(https://commondatastorage.googleapis.com/chromium-browser-official/chrom
         chromium-149-drop-unknown-clang-flag.patch
         chromium-149-unbundle-minizip-undo-unicode.patch
         chromium-149-use-of-undeclared-identifier-ERROR.patch
-        chromium-150-fix-ar-unbundle.patch
-        chromium-150-fix-sysroot-path-error.patch
         chromium-150-revert-avx-flag-change.patch
+        chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
         compiler-rt-adjust-paths.patch
         increase-fortify-level.patch
         enable-widevine-arm64.patch
         use-oauth2-client-switches-as-default.patch
         glibc-2.42-baud-rate-fix.patch)
-sha256sums=('e2654fa7c37ddc20af98f91089ad580e347ca9c526f8de8e625fe1b1cf3d98c6'
-            'f40444c3f7ecf63ed5bfe01944e23ebe9d0d6246ce99f5d2adad0728dc35164f'
+sha256sums=('3fa13440c0c99145f6628b2cd62438da05c989469c7113b19d11425f9853f645'
+            'f0e6c97580911fd8a0ecd562d743455ee9acb626a54b84682e26549d8ea1fa58'
             '213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
             '11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
             '4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
             'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
             'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
-            '5ade4cdba7afebfcc09fa969f15bf27404579beac5b7bafb59a0214d407e4ad2'
+            'e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9'
             'c22338d13f12772cdbcb5cfc1ace94438b9f9c72353cdb165a3ff3ef3d677c78'
             '951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
-            'f056d12571823d06c2a938158734fb4c7eeccb5c6f68228634d0c73d75feaa78'
-            '5c42260b11b87dd01c4ef11598033e9687bdf384af2e45adab2fd00964e977e8'
             '5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
+            '552ddcef0cf139927f54c9c728c68b0e385600107e5166449b29de75e5dfcd7f'
             'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
             'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
             '33d1650e183a86cc2d0e9b0fcc08a5da76c7354d25a419921e9d2dc02b8b3854'
Risk 1/5 · Low PKGBUILD
Result #1713

Comment

The change only removes two existing patch applications and adds one new patch application in prepare(). There are no new network fetches, privilege changes, install-script changes, or suspicious build-time commands in the shown hunk. The added patch is a local file referenced from the package tree, so the main security question is the patch contents themselves; however, based on the diff provided, there is no direct evidence of malicious behavior in PKGBUILD. Risk is low, though not zero because patch content is not shown here.

@@ -225,18 +224,14 @@ prepare() {
 
   patch -Np1 -i ../chromium-149-use-of-undeclared-identifier-ERROR.patch
 
-  # Fix issue about missing AR file
-  # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
-  patch -Np1 -i ../chromium-150-fix-ar-unbundle.patch
-
-  # Fix issue about missing sysroot path
-  # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837#issuecomment-4836756738
-  patch -Np1 -i ../chromium-150-fix-sysroot-path-error.patch
-
   # Fix issue about missing AVX functions
   # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
   patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
 
+  # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3883
+  patch -Np1 -i ../chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
+
+
   if (( !_system_clang )); then
     # Use prebuilt rust as system rust cannot be used due to the error:
     #   error: the option `Z` is only accepted on the nightly compiler
Risk 0/5 · Safe PKGBUILD
Result #1714

Comment

The change only adds a symlink to the system Go toolchain in prepare(), alongside existing symlinks for node/java/rustc/gperf. This does not introduce network access, privilege escalation, persistence, or writes outside the build tree. It simply satisfies Chromium's build-time expectation for a Go binary under third_party/dawn/... and remains confined to the source directory. No suspicious sources or packaging behavior are added in this hunk.

@@ -261,12 +256,14 @@ prepare() {
   mkdir -p third_party/node/linux/node-linux-x64/bin \
            third_party/rust-toolchain/bin \
            third_party/jdk/current/bin \
-           third_party/gperf/cipd/bin
+           third_party/gperf/cipd/bin \
+           third_party/dawn/tools/golang/linux-amd64/bin
 
   ln -s /usr/bin/node third_party/node/linux/node-linux-x64/bin/
   ln -s /usr/bin/java third_party/jdk/current/bin/
   ln -s /usr/bin/rustc third_party/rust-toolchain/bin/
   ln -s /usr/bin/gperf third_party/gperf/cipd/bin/
+  ln -s /usr/bin/go third_party/dawn/tools/golang/linux-amd64/bin/
 
   # Remove bundled libraries for which we will use the system copies; this
   # *should* do what the remove_bundled_libraries.py script does, with the
Risk 0/5 · Safe PKGBUILD
Result #1715

Comment

The change is low risk. It updates the package to a new Chromium release, adds a new upstream patch, and adjusts the appdata template substitution plus a local symlink for Go used by Chromium's build. I reviewed the added patch and it only changes a GN dependency condition from `generate_location_tags` to `path_exists("//.git")`, which is a build-system fix for non-git checkouts and does not introduce new execution paths, network access, privilege changes, or packaging-side persistence. The PKGBUILD diff itself contains no suspicious downloads, sudo usage, or writes outside `$pkgdir`.

@@ -430,7 +427,7 @@ package() {
     info_file=chrome/installer/linux/common/chromium-browser.info
     . $info_file; PACKAGE=chromium
     export $(grep -o '^[A-Z_]*' $info_file)
-    sed -E -e 's/([A-Z_]*)@@/\${\1}/g' -e '/<update_contact>/d' $tmpl_file | envsubst
+    sed -E -e 's/@@([A-Z_]*)/\${\1}/g' -e '/<update_contact>/d' $tmpl_file | envsubst
   ) \
   | install -Dvm644 /dev/stdin "$pkgdir/usr/share/metainfo/chromium.appdata.xml"
 
Risk 0/5 · Safe REUSE.toml
Result #1716

Comment

This change only adds a new patch filename to REUSE.toml’s license metadata list. By itself it does not alter build logic, introduce network access, install scripts, privileges, or shipped binaries. I did not see any security-relevant behavior in this diff hunk; the risk is limited to the possibility that the referenced patch file itself could be malicious, but that content is not part of the reviewed change here.

@@ -52,6 +52,7 @@ path = [
     "use-oauth2-client-switches-as-default.patch",
     "chromium-150-revert-avx-flag-change.patch",
     "chromium-150-fix-ar-unbundle.patch",
+    "chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch",
 ]
 SPDX-FileCopyrightText = "chromium contributors"
 SPDX-License-Identifier = "BSD-3-Clause"
Risk 0/5 · Safe chromium-149-drop-unknown-clang-flag.patch
Result #1717

Comment

The patch only alters Chromium build configuration to disable a few compiler/sanitizer flags by replacing their conditions with `false` or an empty list. This is a build-behavior change, not an execution or packaging change: it does not add network access, scripts, privilege escalation, persistence, or bundled binaries. The main impact is reduced diagnostics/sanitizer coverage on affected targets, which could hide some classes of bugs but is not itself a security backdoor. No high-risk supply-chain or install-time concerns are present in this diff.

@@ -1,29 +1,30 @@
 diff --git a/build/config/compiler/BUILD.gn b/build/config/compiler/BUILD.gn
-index f977c9fed76e6f50c50351ca22128e8c8c8897b1..81460f3591b734f3354a6f9ac7bb0990e5b28889 100644
+index 7df3e18c4c..1d253318a6 100644
 --- a/build/config/compiler/BUILD.gn
 +++ b/build/config/compiler/BUILD.gn
-@@ -589,7 +589,7 @@ config("compiler") {
-     # Flags for diagnostics.
+@@ -578,7 +578,7 @@ config("compiler") {
      cflags += [ "-fcolor-diagnostics" ]
-     if (!is_win) {
--      cflags += [ "-fdiagnostics-show-inlining-chain" ]
-+      cflags += [ ]
-     } else {
-       # Combine after https://github.com/llvm/llvm-project/pull/192241
-       cflags += [ "/clang:-fdiagnostics-show-inlining-chain" ]
-@@ -1911,7 +1911,7 @@ config("clang_warning_suppression") {
+     if (!is_wasm) {
+       if (!is_win) {
+-        cflags += [ "-fdiagnostics-show-inlining-chain" ]
++        cflags += [ ]
+       } else {
+         # Combine after https://github.com/llvm/llvm-project/pull/192241
+         cflags += [ "/clang:-fdiagnostics-show-inlining-chain" ]
+@@ -1578,7 +1578,7 @@ config("clang_warning_suppression") {
  # See also: https://crbug.com/40891132#comment10
  ubsan_hardening("c_array_bounds") {
    sanitizer = "array-bounds"
--  condition = !(is_asan && target_cpu == "x86")
+-  condition = !(is_asan && target_cpu == "x86") && !is_wasm
 +  condition = false
  
    # Because we've enabled array-bounds sanitizing we also want to suppress
    # the related warning about "unsafe-buffer-usage-in-static-sized-array",
-@@ -1925,6 +1925,7 @@ ubsan_hardening("c_array_bounds") {
+@@ -1592,7 +1592,7 @@ ubsan_hardening("c_array_bounds") {
  # `NOTREACHED()` at the end of such functions.
  ubsan_hardening("return") {
    sanitizer = "return"
+-  condition = !is_wasm
 +  condition = false
  }
  
Risk 0/5 · Safe chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
Result #1718

Comment

The patch only changes a GN build condition from `generate_location_tags` to `path_exists("//.git")` so `histograms_xml` is included only in git checkouts. This is a narrow build-system adjustment with no new code execution, no network access, no privilege changes, and no packaging/install-script impact. The change appears consistent with the stated intent and does not introduce obvious supply-chain or persistence risks.

@@ -0,0 +1,37 @@
+From 27f8690db999f6e56f0af7a9ea3d28a019ed72ca Mon Sep 17 00:00:00 2001
+From: Fumitoshi Ukai <ukai@google.com>
+Date: Tue, 30 Jun 2026 18:32:03 -0700
+Subject: [PATCH] don't depends on histograms.xml if it is not git checkout
+
+histograms.xml is only generated on git checkout.
+
+Bug: 329080012
+Change-Id: Iea4484f8af4cf9ef25e25ea1df2c616fbe46ed5c
+Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/8019063
+Reviewed-by: Jesse McKenna <jessemckenna@google.com>
+Commit-Queue: Fumitoshi Ukai <ukai@google.com>
+Auto-Submit: Fumitoshi Ukai <ukai@google.com>
+Cr-Commit-Position: refs/heads/main@{#1655184}
+---
+
+diff --git a/tools/metrics/BUILD.gn b/tools/metrics/BUILD.gn
+index c826e97..23799c7 100644
+--- a/tools/metrics/BUILD.gn
++++ b/tools/metrics/BUILD.gn
+@@ -41,11 +41,11 @@
+   ]
+ 
+   # Only include histograms_xml if we have access to dirmd data, which
+-  # is used to populate ownership information. This is only set to false
+-  # for non-git checkouts.
+-  # TODO(crbug.com/329080012): Remove this once dirmd works in non-git
+-  # checkouts.
+-  if (generate_location_tags) {
++  # is used to populate ownership information. This is disabled
++  # for non-git checkouts, as dirmd doesn't work on non-git checkout.
++  # TODO(crbug.com/329080012): Remove this condition once dirmd works
++  # in non-git checkouts.
++  if (path_exists("//.git")) {
+     deps += [ ":histograms_xml" ]
+   }
+ }