AUR AI Reviewer

Review Results

Version #2312 of ungoogled-chromium · commit 6f522d5e672d · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #2981

Comment

The change only bumps pkgver in .SRCINFO from 151.0.7922.173 to 152.0.7977.75. No source URLs, checksums, build logic, install scripts, or packaging permissions are altered in the reviewed hunk. On its face this is a routine version update with no security-relevant red flags in the provided diff.

@@ -1,6 +1,6 @@
 pkgbase = ungoogled-chromium
 	pkgdesc = A lightweight approach to removing Google web service dependency
-	pkgver = 151.0.7922.173
+	pkgver = 152.0.7977.75
 	pkgrel = 1
 	url = https://github.com/ungoogled-software/ungoogled-chromium
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #2982

Comment

The change is a routine .SRCINFO refresh for a Chromium version bump. It updates source URLs and checksums, and removes several makedepends that are no longer needed. I do not see any new suspicious sources, network-fetch-at-build behavior, privilege escalation, or packaging red flags in the diff itself. The only notable risk is that .SRCINFO is metadata-only and must match the PKGBUILD, but nothing here suggests malicious intent.

@@ -20,11 +20,6 @@ pkgbase = ungoogled-chromium
 	makedepends = qt6-base
 	makedepends = rust-bindgen
 	makedepends = rust
-	makedepends = python-httplib2
-	makedepends = python-pyparsing
-	makedepends = python-six
-	makedepends = npm
-	makedepends = rsync
 	depends = alsa-lib
 	depends = at-spi2-core
 	depends = cairo
Risk 0/5 · Safe .SRCINFO
Result #2983

Comment

The .SRCINFO update is a routine version bump for ungoogled-chromium from 151.x to 152.x. The new source URLs are HTTPS and point to the official Chromium release archive and the upstream GitHub release tarball; there are no new suspicious hosts, no VCS floating refs, and no build-time network fetches introduced by this metadata-only change. The added/removed patch and checksum entries are consistent with a release refresh. I do note that .SRCINFO no longer lists several makedepends (python-httplib2, python-pyparsing, python-six, npm, rsync), but since this review is limited to the .SRCINFO diff and not the PKGBUILD, I cannot confirm whether that reflects a real packaging change or just metadata drift. Nothing in the provided change suggests a direct security issue.

@@ -82,43 +77,49 @@ pkgbase = ungoogled-chromium
 	optdepends = qt6-base: Qt support
 	optdepends = org.freedesktop.secrets: password storage backend on GNOME, KDE and Xfce
 	optdepends = upower: Battery Status API support
-	provides = chromium=151.0.7922.173
-	provides = chromedriver=151.0.7922.173
+	provides = chromium=152.0.7977.75
+	provides = chromedriver=152.0.7977.75
 	conflicts = chromium
 	conflicts = chromedriver
 	options = !lto
-	source = fetch-chromium-release
-	source = ungoogled-chromium-151.0.7922.173-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/151.0.7922.173-1.tar.gz
+	source = https://commondatastorage.googleapis.com/chromium-browser-official/chromium-152.0.7977.75-lite.tar.xz
+	source = ungoogled-chromium-152.0.7977.75-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/152.0.7977.75-1.tar.gz
 	source = https://github.com/foutrelis/chromium-launcher/archive/v8/chromium-launcher-8.tar.gz
 	source = chromium-138-nodejs-version-check.patch
 	source = chromium-145-fix-SYS_SECCOMP.patch
 	source = chromium-147-revert-clang-no-lifetime-dse-flag.patch
 	source = chromium-147-rust-1.95-bytemuck.patch
 	source = chromium-149-drop-unknown-clang-flag.patch
-	source = chromium-149-unbundle-minizip-undo-unicode.patch
 	source = chromium-149-use-of-undeclared-identifier-ERROR.patch
 	source = chromium-150-revert-avx-flag-change.patch
-	source = chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
+	source = chromium-152-crubit.patch
+	source = chromium-152-dawn-llvm-22.patch
+	source = chromium-152-fix-gn-no-public_inputs.patch
+	source = chromium-152-unbundle-minizip-undo-unicode.patch
+	source = chromium-152-unbundle-opus-devtools.patch
 	source = compiler-rt-adjust-paths.patch
 	source = increase-fortify-level.patch
 	source = enable-widevine-arm64.patch
 	source = use-oauth2-client-switches-as-default.patch
 	source = glibc-2.42-baud-rate-fix.patch
-	sha256sums = 2e2f36e3cd1ebc4ad57fd310774a5e5e9db77883d5f9374fedeaabd3c103b819
-	sha256sums = 82478f1fabf0d56a5fe9784fe342a7a62ea2cbe3226b32fc23fba4ba89160af1
+	sha256sums = 12379ddd4cdce9c318787c32f438dcf386df59b72ba508eb9f9ece54be44eb66
+	sha256sums = 0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb
 	sha256sums = 213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a
 	sha256sums = 11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e
 	sha256sums = 4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e
 	sha256sums = c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a
 	sha256sums = b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05
 	sha256sums = e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9
-	sha256sums = c22338d13f12772cdbcb5cfc1ace94438b9f9c72353cdb165a3ff3ef3d677c78
 	sha256sums = 951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4
 	sha256sums = 5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60
-	sha256sums = 552ddcef0cf139927f54c9c728c68b0e385600107e5166449b29de75e5dfcd7f
+	sha256sums = 6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea
+	sha256sums = 5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140
+	sha256sums = 5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07
+	sha256sums = 890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9
+	sha256sums = 3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3
 	sha256sums = ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863
 	sha256sums = d634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342
-	sha256sums = 33d1650e183a86cc2d0e9b0fcc08a5da76c7354d25a419921e9d2dc02b8b3854
+	sha256sums = 5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928
 	sha256sums = 9343afa1a4308a7cfb3317229f5aff7778688debcc03c4a74a85908aa1d0cc3a
 	sha256sums = 1c1898f263eaacbc069a8e1a3e732852350350d1dad4cb1a6bba430e3b796cd0
 
Risk 0/5 · Safe PKGBUILD
Result #2984

Comment

The change is a straightforward version bump of the package and matching ungoogled-chromium upstream version variable, plus toggling _manual_clone from 1 to 0. In the provided diff there are no new sources, scripts, install hooks, privilege changes, or build-time network/download logic visible. The _manual_clone flag change may affect how sources are obtained, but without any accompanying PKGBUILD logic changes in this hunk it does not by itself indicate a security issue. Based on the reviewed diff alone, this appears low risk.

@@ -11,14 +11,14 @@
 # Contributor: Daniel J Griffiths <ghost1227@archlinux.us>
 
 pkgname=ungoogled-chromium
-pkgver=151.0.7922.173
+pkgver=152.0.7977.75
 pkgrel=1
 _launcher_ver=8
-_manual_clone=1
+_manual_clone=0
 _system_clang=1
 # ungoogled chromium variables
 _uc_usr=ungoogled-software
-_uc_ver=151.0.7922.173-1
+_uc_ver=152.0.7977.75-1
 pkgdesc="A lightweight approach to removing Google web service dependency"
 arch=('x86_64')
 url="https://github.com/ungoogled-software/ungoogled-chromium"
Risk 0/5 · Safe PKGBUILD
Result #2985

Comment

The change is a routine version bump for ungoogled-chromium from 151 to 152 with corresponding checksum updates and a set of upstream patch refreshes. The added/removed patches are all source patches against Chromium/DevTools/Dawn build files or a zlib/minizip behavior change; I did not see any suspicious network fetches, embedded binaries, privilege escalation, install-script persistence, or writes outside the package build directory. The only notable risk is that several new patches are introduced, so correctness depends on their contents, but the reviewed patch hunks themselves are standard build fixes and dependency adjustments rather than security red flags.

@@ -95,30 +95,36 @@ source=(https://commondatastorage.googleapis.com/chromium-browser-official/chrom
         chromium-147-revert-clang-no-lifetime-dse-flag.patch
         chromium-147-rust-1.95-bytemuck.patch
         chromium-149-drop-unknown-clang-flag.patch
-        chromium-149-unbundle-minizip-undo-unicode.patch
         chromium-149-use-of-undeclared-identifier-ERROR.patch
         chromium-150-revert-avx-flag-change.patch
-        chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
+        chromium-152-crubit.patch
+        chromium-152-dawn-llvm-22.patch
+        chromium-152-fix-gn-no-public_inputs.patch
+        chromium-152-unbundle-minizip-undo-unicode.patch
+        chromium-152-unbundle-opus-devtools.patch
         compiler-rt-adjust-paths.patch
         increase-fortify-level.patch
         enable-widevine-arm64.patch
         use-oauth2-client-switches-as-default.patch
         glibc-2.42-baud-rate-fix.patch)
-sha256sums=('3fa13440c0c99145f6628b2cd62438da05c989469c7113b19d11425f9853f645'
-            '82478f1fabf0d56a5fe9784fe342a7a62ea2cbe3226b32fc23fba4ba89160af1'
+sha256sums=('12379ddd4cdce9c318787c32f438dcf386df59b72ba508eb9f9ece54be44eb66'
+            '0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb'
             '213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
             '11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
             '4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
             'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
             'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
             'e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9'
-            'c22338d13f12772cdbcb5cfc1ace94438b9f9c72353cdb165a3ff3ef3d677c78'
             '951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
             '5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
-            '552ddcef0cf139927f54c9c728c68b0e385600107e5166449b29de75e5dfcd7f'
+            '6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea'
+            '5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140'
+            '5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07'
+            '890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9'
+            '3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'
             'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
             'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
-            '33d1650e183a86cc2d0e9b0fcc08a5da76c7354d25a419921e9d2dc02b8b3854'
+            '5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'
             '9343afa1a4308a7cfb3317229f5aff7778688debcc03c4a74a85908aa1d0cc3a'
             '1c1898f263eaacbc069a8e1a3e732852350350d1dad4cb1a6bba430e3b796cd0')
 
Risk 0/5 · Safe PKGBUILD
Result #2986

Comment

The change is a routine version bump from Chromium 151 to 152 with corresponding patch refreshes. The new/updated patches are all local source patches from the package tree, and the diff does not introduce any obvious supply-chain red flags such as new remote downloads, VCS floating refs, curl|bash, privilege escalation, or install-script persistence. The only notable packaging change is switching _manual_clone from 1 to 0, which makes the package use the official Chromium release tarball instead of the helper fetch script; that is not inherently suspicious and still keeps sources pinned and checksummed. Based on the provided diff, I do not see a high-confidence security issue.

@@ -219,18 +225,22 @@ prepare() {
   # https://crbug.com/456677057
   patch -Np1 -i ../glibc-2.42-baud-rate-fix.patch
 
-  # Chromium bundles a patched minizip with extra features.
-  patch -Np1 -i ../chromium-149-unbundle-minizip-undo-unicode.patch
-
   patch -Np1 -i ../chromium-149-use-of-undeclared-identifier-ERROR.patch
 
   # Fix issue about missing AVX functions
   # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
   patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
 
-  # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3883
-  patch -Np1 -i ../chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch
+  patch -Np1 -i ../chromium-152-crubit.patch
+
+  patch -Np1 -i ../chromium-152-dawn-llvm-22.patch
+
+  # Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3
+  patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src
+
+  patch -Np1 -i ../chromium-152-unbundle-minizip-undo-unicode.patch
 
+  patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch
 
   if (( !_system_clang )); then
     # Use prebuilt rust as system rust cannot be used due to the error:
Risk 0/5 · Safe REUSE.toml
Result #2987

Comment

The change only updates REUSE.toml metadata to point at a different patch filename and adds/removes copyright attribution entries. I reviewed the referenced patch for context: it is a Chromium revert of a GN build-system change, with no evidence of shell execution, network access, privilege escalation, or packaging-time side effects. The REUSE.toml edit itself does not affect the build or runtime behavior of the package; it only tracks licensing metadata for shipped patch files. No security issue is apparent from this diff.

@@ -52,7 +52,7 @@ path = [
     "use-oauth2-client-switches-as-default.patch",
     "chromium-150-revert-avx-flag-change.patch",
     "chromium-150-fix-ar-unbundle.patch",
-    "chromium-151-dont-depends-on-histograms.xml-if-it-is-not-git-checkout.patch",
+    "chromium-152-fix-gn-no-public_inputs.patch",
 ]
 SPDX-FileCopyrightText = "chromium contributors"
 SPDX-License-Identifier = "BSD-3-Clause"
Risk 0/5 · Safe REUSE.toml
Result #2988

Comment

The change only updates REUSE.toml license annotations to match renamed/added patch files. This is metadata-only and does not affect build logic, sources, install scripts, or runtime behavior. No security-relevant issues are evident from the diff provided.

@@ -81,13 +81,16 @@ SPDX-License-Identifier = "BSD-2-Clause"
 path = [
     "chromium-149-drop-unknown-clang-flag.patch",
     "chromium-149-use-of-undeclared-identifier-ERROR.patch",
+    "chromium-152-crubit.patch",
+    "chromium-152-dawn-llvm-22.patch",
 ]
 SPDX-FileCopyrightText = "2003-2026 Nixpkgs/NixOS contributors"
 SPDX-License-Identifier = "MIT"
 
 [[annotations]]
 path = [
-    "chromium-149-unbundle-minizip-undo-unicode.patch"
+    "chromium-152-unbundle-minizip-undo-unicode.patch",
+    "chromium-152-unbundle-opus-devtools.patch",
 ]
 SPDX-FileCopyrightText = "LN Liberda <lauren@selfisekai.rocks>"
 
Risk 0/5 · Safe chromium-152-crubit.patch
Result #2989

Comment

The patch only changes a GN build flag gating Rust/Crubit CBOR support from `!is_cronet_build` to `enable_cpp_api_from_rust`, and correspondingly adjusts dependency inclusion. This is a build-configuration change with no evidence of network access, privilege escalation, persistence, or bundled binaries. The new condition appears to be an upstream refactor/feature gate alignment rather than a security-sensitive behavior change. No malicious code paths are introduced in the diff shown.

@@ -0,0 +1,29 @@
+--- a/components/cbor/BUILD.gn
++++ b/components/cbor/BUILD.gn
+@@ -12,7 +12,7 @@
+   # TODO(crbug.com/535682335): Remove `USE_CBOR_RUST` buildflag entirely,
+   # unconditionally enable Rust CBOR parser, and drop `is_cronet_build` check
+   # once Cronet supports Crubit dependencies.
+-  flags = [ "USE_CBOR_RUST=!$is_cronet_build" ]
++  flags = [ "USE_CBOR_RUST=$enable_cpp_api_from_rust" ]
+ }
+ 
+ component("cbor") {
+@@ -37,7 +37,7 @@
+     "//base",
+   ]
+ 
+-  if (!is_cronet_build) {
++  if (enable_cpp_api_from_rust) {
+     public_deps = [
+       "//build/rust/crubit",
+       "//components/cbor/rust:cbor_rust_bindings",
+@@ -63,7 +63,7 @@
+     "//testing/gtest",
+     "//third_party/fuzztest",
+   ]
+-  if (!is_cronet_build) {
++  if (enable_cpp_api_from_rust) {
+     deps += [ "//components/cbor/rust:cbor_rust_unittests" ]
+   }
+ 
Risk 0/5 · Safe chromium-152-dawn-llvm-22.patch
Result #2990

Comment

The patch only removes two Clang lifetime-safety suppression flags from Dawn's BUILD.gn. This is a build-configuration change with no added code execution, no network access, no privilege changes, and no packaging/install-script impact. The change appears to reduce compiler flag suppression rather than introduce risk. I found no security red flags in the provided hunk.

@@ -0,0 +1,13 @@
+diff --git b/third_party/dawn/src/utils/BUILD.gn a/third_party/dawn/src/utils/BUILD.gn
+index b9f0be693eea5aacdac6f7940642a29e0205c7a9..ed7ad3b6d3de1336c7c89cb18d4b6e4359205417 100644
+--- b/third_party/dawn/src/utils/BUILD.gn
++++ a/third_party/dawn/src/utils/BUILD.gn
+@@ -218,8 +218,6 @@ config("dawn_warnings") {
+       # the analysis pass.
+       "-Wno-lifetime-safety",
+       "-Wno-lifetime-safety-all",
+-      "-Xclang=-fno-lifetime-safety-inference",
+-      "-Xclang=-fno-experimental-lifetime-safety-tu-analysis",
+     ]
+ 
+     # P3. Checks that could be nice but probably don't help with hardening.
Risk 0/5 · Safe chromium-152-fix-gn-no-public_inputs.patch
Result #2991

Comment

This patch only reverts GN `public_inputs` propagation for TypeScript-related build templates and a couple of formatting-only `forward_variables_from` line wraps. I do not see any added code execution, network access, privilege changes, or packaging/install-script impact. The revert may affect build correctness or remote-execution dependency tracking, but from a security perspective it does not introduce a credible supply-chain or persistence risk in the reviewed hunk.

@@ -0,0 +1,150 @@
+From 8dab8b761385b7946588232e4e2a8c116f9293c3 Mon Sep 17 00:00:00 2001
+From: Philip Pfaffe <pfaffe@chromium.org>
+Date: Thu, 09 Jul 2026 05:06:16 -0700
+Subject: [PATCH] Revert "Expose TypeScript files to dependent targets"
+
+This reverts commit 9482fa06243e2941e1b7797ac9f9773f86500453.
+
+Reason for revert: Getting `copy.gni:29:21: Assignment had no effect` in local builds on tip of tree.
+
+Failure Link: N/A
+
+Original change's description:
+> Expose TypeScript files to dependent targets
+>
+> Use `public_inputs` in GN build templates to propagate `.ts` files to
+> dependent targets. This ensures that remote execution environments for
+> TypeScript compilations have access to all necessary directly or
+> indirectly imported source files.
+>
+> Specific changes include:
+> * Filtering and exposing `*.ts` files in `copy.gni` and
+>   `devtools_pre_built.gni`.
+> * Exposing the entrypoint file in `devtools_entrypoint.gni`.
+> * Filtering and exposing `*.ts` and specific legacy `.js` files
+>   (`ahem.js`, `ARIAProperties.js`, `SupportedCSSProperties.js`) in
+>   `typescript.gni`.
+> * Applying minor formatting fixes to `forward_variables_from` calls.
+>
+> Ref: https://gn.googlesource.com/gn/+/refs/heads/main/docs/reference.md#var_public_inputs
+> Bug: 513105742
+> Change-Id: Ibe4e0be27ea0d9d7c3e8309219f0f822a55b9bb5
+> Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/8064364
+> Reviewed-by: Simon Zünd <szuend@chromium.org>
+> Commit-Queue: Takuto Ikuta <tikuta@chromium.org>
+> Reviewed-by: Michael Achenbach <machenbach@chromium.org>
+
+Bug: 513105742
+No-Presubmit: true
+No-Tree-Checks: true
+No-Try: true
+Change-Id: Ia4882d1ae1bb5e45aaef4bb831cd2a10eda1ac69
+Reviewed-on: https://chromium-review.googlesource.com/c/devtools/devtools-frontend/+/8069251
+Auto-Submit: Philip Pfaffe <pfaffe@chromium.org>
+Commit-Queue: Michael Achenbach <machenbach@chromium.org>
+Reviewed-by: Michael Achenbach <machenbach@chromium.org>
+---
+
+diff --git a/scripts/build/ninja/copy.gni b/scripts/build/ninja/copy.gni
+index d6d71a6..a03d647 100644
+--- a/scripts/build/ninja/copy.gni
++++ b/scripts/build/ninja/copy.gni
+@@ -25,9 +25,6 @@
+       string_join(",", sources),
+     ]
+ 
+-    # Expose ts files to dependent targets.
+-    public_inputs = filter_include(sources, [ "*.ts" ])
+-
+     outputs = []
+     foreach(_input, sources) {
+       outputs += [ "$target_gen_dir/$_input" ]
+diff --git a/scripts/build/ninja/devtools_entrypoint.gni b/scripts/build/ninja/devtools_entrypoint.gni
+index 6bee3ef..cedcbb4 100644
+--- a/scripts/build/ninja/devtools_entrypoint.gni
++++ b/scripts/build/ninja/devtools_entrypoint.gni
+@@ -35,13 +35,7 @@
+     _ts_library_target_name = _entrypoint_target_name + "-typescript"
+ 
+     ts_library(_ts_library_target_name) {
+-      forward_variables_from(invoker,
+-                             [
+-                               "deps",
+-                               "es_target",
+-                               "es_libs",
+-                               "inputs",
+-                             ])
++      forward_variables_from(invoker, ["deps", "es_target", "es_libs", "inputs"])
+ 
+       sources = [ invoker.entrypoint ]
+     }
+@@ -110,19 +104,14 @@
+     }
+ 
+     ts_library(_prebundle_target_name) {
+-      forward_variables_from(invoker,
+-                             [
+-                               "deps",
+-                               "es_target",
+-                               "es_libs",
+-                               "inputs",
+-                             ])
++      forward_variables_from(invoker, ["deps", "es_target", "es_libs", "inputs"])
+ 
+       sources = [ _copy_output_file_name ]
+ 
+       rootdir = target_gen_dir
+ 
+       public_deps = [ ":$_copy_target_name" ]
++
+     }
+ 
+     bundle(_bundle_target_name) {
+@@ -197,9 +186,6 @@
+   node_action(target_name) {
+     script = "scripts/build/ninja/generate-tsconfig.js"
+ 
+-    # Expose ts files to dependent targets.
+-    public_inputs = [ invoker.entrypoint ]
+-
+     args = [
+              rebase_path(_generated_tsconfig_location, root_build_dir),
+              rebase_path(invoker.entrypoint, root_build_dir),
+diff --git a/scripts/build/ninja/devtools_pre_built.gni b/scripts/build/ninja/devtools_pre_built.gni
+index 1f38b18..3d76a75 100644
+--- a/scripts/build/ninja/devtools_pre_built.gni
++++ b/scripts/build/ninja/devtools_pre_built.gni
+@@ -17,9 +17,6 @@
+ 
+     public_deps = invoker.deps
+ 
+-    # Expose ts files to dependent targets.
+-    public_inputs = filter_include(sources, [ "*.ts" ])
+-
+     _copy_src = rebase_path(get_path_info(target_name, "dir"), root_build_dir)
+     _copy_dest = rebase_path(target_gen_dir, root_build_dir)
+ 
+diff --git a/scripts/build/typescript/typescript.gni b/scripts/build/typescript/typescript.gni
+index b0d1367..a6f4c04 100644
+--- a/scripts/build/typescript/typescript.gni
++++ b/scripts/build/typescript/typescript.gni
+@@ -212,19 +212,6 @@
+     output_files = [ "$target_gen_dir/$target_name-tsconfig.json" ]
+ 
+     if (defined(sources)) {
+-      # Expose ts files to dependent targets.
+-      public_inputs =
+-          filter_include(sources,
+-                         [
+-                           "*.ts",
+-
+-                           # TODO: Migrate the files below to TypeScript
+-                           # and remove them from this list.
+-                           "*ahem.js",
+-                           "*ARIAProperties.js",
+-                           "*SupportedCSSProperties.js",
+-                         ])
+-
+       args += [ "--sources" ] + rebase_path(sources, root_build_dir)
+ 
+       foreach(src, sources) {
Risk 1/5 · Low chromium-152-unbundle-minizip-undo-unicode.patch
Result #2992

Comment

The patch removes Chromium-specific handling of the Info-ZIP Unicode Path Extra Field from zip_reader.cc, causing the physical path to always follow the effective path and eliminating the prior safety merge logic for directory/unsafe flags. This is a functional regression in archive path interpretation, but I do not see a direct security escalation in the patch itself: it does not add code execution, network access, privilege changes, or persistence. The main risk is reduced correctness/safety when processing ZIPs with Unicode path extra fields, which could affect extraction or scanning behavior, but the change is narrowly scoped and appears intentional as part of unbundling minizip behavior.

@@ -0,0 +1,62 @@
+From 5ebe0b53a5f4a33faf138191b254a7d4a5285a5f Mon Sep 17 00:00:00 2001
+From: LN Liberda <lauren@selfisekai.rocks>
+Date: Thu, 27 Aug 2026 08:13:35 +0200
+Subject: [PATCH] unbundle/minizip: Ignore Unicode Path Extra Field
+
+The fields come from chromium's patches on minizip
+---
+ third_party/zlib/google/zip_reader.cc | 34 +--------------------------
+ 1 file changed, 1 insertion(+), 33 deletions(-)
+
+diff --git a/third_party/zlib/google/zip_reader.cc b/third_party/zlib/google/zip_reader.cc
+index 7b5b28967cfbb..2054e3c09e419 100644
+--- a/third_party/zlib/google/zip_reader.cc
++++ b/third_party/zlib/google/zip_reader.cc
+@@ -314,32 +314,6 @@ bool ZipReader::OpenEntry() {
+   bool physical_path_is_directory = false;
+   bool physical_path_is_unsafe = false;
+ 
+-  // If an Info-ZIP Unicode Path Extra Field is present, the physical Central
+-  // Directory path is about to be overridden. Decode and normalize it now into
+-  // `entry_.physical_path` so consumers (e.g. Safe Browsing) can still see the
+-  // name that other tools (e.g. Windows Explorer) would use for extraction.
+-  if (info.size_utf8_filename > 0) {
+-    std::u16string physical_path_in_utf16;
+-    if (!base::CodepageToUTF16(entry_.path_in_original_encoding,
+-                               configured_encoding,
+-                               base::OnStringConversionError::SUBSTITUTE,
+-                               &physical_path_in_utf16)) {
+-      LOG(ERROR) << "Cannot convert path from encoding " << configured_encoding;
+-      return false;
+-    }
+-    // Normalize() stores the normalized result in entry_.path; copy it before
+-    // applying the Unicode Path Extra Field below.
+-    Normalize(physical_path_in_utf16);
+-    entry_.physical_path = entry_.path;
+-    physical_path_is_directory = entry_.is_directory;
+-    physical_path_is_unsafe = entry_.is_unsafe;
+-
+-    // Use the Info-ZIP Unicode Path Extra Field if present.
+-    DCHECK(info.utf8_filename[info.size_utf8_filename] == '\0');
+-    entry_.path_in_original_encoding = info.utf8_filename;
+-    entry_path_encoding = base::kCodepageUTF8;
+-  }
+-
+   // Convert path from original encoding to Unicode.
+   std::u16string path_in_utf16;
+   if (!base::CodepageToUTF16(entry_.path_in_original_encoding,
+@@ -353,13 +327,7 @@ bool ZipReader::OpenEntry() {
+   // Normalize path.
+   Normalize(path_in_utf16);
+ 
+-  if (info.size_utf8_filename > 0) {
+-    // Treat an entry as a directory only if both names are directories;
+-    // otherwise callers that analyze file entries should inspect it as a file.
+-    entry_.is_directory = entry_.is_directory && physical_path_is_directory;
+-    // Treat an entry as unsafe if either name is unsafe.
+-    entry_.is_unsafe = entry_.is_unsafe || physical_path_is_unsafe;
+-  } else {
++ {
+     // In the common case (no Unicode Path Extra Field) the physical path
+     // matches the effective path.
+     entry_.physical_path = entry_.path;
Risk 0/5 · Safe chromium-152-unbundle-opus-devtools.patch
Result #2993

Comment

The patch is a minimal build-system change that adds a missing dependency on the already-shipped upstream Opus source tree for Chromium’s devtools media encoding service. It does not introduce new code, network access, privilege changes, install-time behavior, or embedded binaries. The change appears consistent with unbundling hygiene and only affects GN dependency wiring. No security red flags are evident in the provided diff.

@@ -0,0 +1,22 @@
+From 47459e81cbfc542aca5a4493dba8457fe11f7108 Mon Sep 17 00:00:00 2001
+From: LN Liberda <lauren@selfisekai.rocks>
+Date: Thu, 27 Aug 2026 20:27:03 +0200
+Subject: [PATCH] unbundle/opus: add missing dep on opus in
+ devtools_media_encoding_service
+
+---
+ content/services/devtools_media_encoding_service/BUILD.gn | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/content/services/devtools_media_encoding_service/BUILD.gn b/content/services/devtools_media_encoding_service/BUILD.gn
+index ce2b615256d36..ef222ca3597c2 100644
+--- a/content/services/devtools_media_encoding_service/BUILD.gn
++++ b/content/services/devtools_media_encoding_service/BUILD.gn
+@@ -18,6 +18,7 @@ source_set("devtools_media_encoding_service") {
+     "//media/mojo/common",
+     "//media/mojo/mojom",
+     "//mojo/public/cpp/bindings",
++    "//third_party/opus",
+     "//ui/gfx/geometry",
+   ]
+ 
Risk 0/5 · Safe enable-widevine-arm64.patch
Result #2994

Comment

The patch only changes a build-time architecture gate for Widevine on Linux, re-enabling arm support in `widevine.gni`. This does not introduce new code execution, network access, privilege escalation, or packaging/install-script behavior; it merely broadens which target CPUs can build the existing Widevine component. No suspicious sources or embedded artifacts are involved in this hunk. Security risk appears low.

@@ -1,9 +1,9 @@
 --- a/third_party/widevine/cdm/widevine.gni	2026-02-15 16:29:15.620518832 +0800
 +++ b/third_party/widevine/cdm/widevine.gni	2026-02-15 16:29:43.721371706 +0800
-@@ -4,7 +4,7 @@
+@@ -27,7 +27,7 @@
+ # supported via Android MediaDrm API.
  library_widevine_cdm_available =
-     (is_chromeos &&
-      (target_cpu == "x64" || target_cpu == "arm" || target_cpu == "arm64")) ||
+     (is_chromeos && (target_cpu == "x64" || target_cpu == "arm64")) ||
 -    (target_os == "linux" && (target_cpu == "x64" || target_cpu == "arm64")) ||
 +    (target_os == "linux" && (target_cpu == "x64" || target_cpu == "arm" || target_cpu == "arm64")) ||
      (target_os == "mac" && (target_cpu == "x64" || target_cpu == "arm64")) ||