AUR AI Reviewer

Review Results

Version #2458 of ungoogled-chromium · commit d4e882059dff · status Reviewed

Risk 0/5 · Safe .SRCINFO
Result #3439

Comment

The only change in this .SRCINFO hunk is a version bump from 152.0.7977.82 to 153.0.8010.47. No source URLs, checksums, build commands, install scripts, permissions, or package metadata affecting trust were changed in the provided diff. On its face this is a routine upstream version update with no direct security red flags in the reviewed hunk.

@@ -1,6 +1,6 @@
 pkgbase = ungoogled-chromium
 	pkgdesc = A lightweight approach to removing Google web service dependency
-	pkgver = 152.0.7977.82
+	pkgver = 153.0.8010.47
 	pkgrel = 1
 	url = https://github.com/ungoogled-software/ungoogled-chromium
 	arch = x86_64
Risk 0/5 · Safe .SRCINFO
Result #3440

Comment

The change only updates .SRCINFO metadata for a version bump and adds new build-time dependencies/patch references that are consistent with the accompanying PKGBUILD and patches already present in the tree. The added makedepends (opus, typescript) and depends (highway) align with the new Chromium release and the included patches to unbundle Opus and point DevTools TypeScript tooling at the system tsc. I did not see any suspicious source URLs, build-time network fetches, privilege escalation, or install-script changes in this diff. Risk is low because this is metadata-only and the new entries are explainable by the version update.

@@ -15,11 +15,13 @@ pkgbase = ungoogled-chromium
 	makedepends = lld
 	makedepends = ninja
 	makedepends = nodejs
+	makedepends = opus
 	makedepends = pipewire
 	makedepends = python
 	makedepends = qt6-base
 	makedepends = rust-bindgen
 	makedepends = rust
+	makedepends = typescript
 	makedepends = python-httplib2
 	makedepends = python-pyparsing
 	makedepends = python-six
Risk 0/5 · Safe .SRCINFO
Result #3441

Comment

The change only adds a runtime dependency on `highway` in .SRCINFO. This is a metadata-only update and does not introduce any build commands, network fetches, privilege changes, install-script behavior, or packaging path changes. `highway` is a plausible multimedia/CPU-optimization dependency for Chromium and does not appear suspicious in this context. No security issue is evident from the diff hunk provided.

@@ -65,6 +67,7 @@ pkgbase = ungoogled-chromium
 	depends = brotli
 	depends = libjpeg-turbo
 	depends = openh264
+	depends = highway
 	depends = dav1d
 	depends = flac
 	depends = libdrm
Risk 0/5 · Safe .SRCINFO
Result #3442

Comment

The change is a routine version bump in .SRCINFO for ungoogled-chromium, updating pkgver/provides/source checksums and adding new upstream patch entries/dependencies. I do not see any security red flags in this metadata-only diff: sources remain HTTPS on the official GitHub project, there is no new build-time network fetch outside source=(), no suspicious scripts or privilege-related changes, and no install/systemd artifacts are involved. Risk is low because the review scope is limited to .SRCINFO and the diff only reflects packaging metadata for a new release.

@@ -82,13 +85,13 @@ pkgbase = ungoogled-chromium
 	optdepends = qt6-base: Qt support
 	optdepends = org.freedesktop.secrets: password storage backend on GNOME, KDE and Xfce
 	optdepends = upower: Battery Status API support
-	provides = chromium=152.0.7977.82
-	provides = chromedriver=152.0.7977.82
+	provides = chromium=153.0.8010.47
+	provides = chromedriver=153.0.8010.47
 	conflicts = chromium
 	conflicts = chromedriver
 	options = !lto
 	source = fetch-chromium-release
-	source = ungoogled-chromium-152.0.7977.82-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/152.0.7977.82-1.tar.gz
+	source = ungoogled-chromium-153.0.8010.47-1.tar.gz::https://github.com/ungoogled-software/ungoogled-chromium/archive/153.0.8010.47-1.tar.gz
 	source = https://github.com/foutrelis/chromium-launcher/archive/v8/chromium-launcher-8.tar.gz
 	source = chromium-138-nodejs-version-check.patch
 	source = chromium-145-fix-SYS_SECCOMP.patch
Risk 0/5 · Safe .SRCINFO
Result #3443

Comment

The .SRCINFO update is a routine version bump from 152.0.7977.82 to 153.0.8010.47 with corresponding source and checksum refreshes. The added/removed patch entries and new makedepends/depend entries are consistent with upstream build changes for the new Chromium release. I do not see any signs of malicious sourcing, floating VCS references, build-time network fetches beyond declared sources, or privilege/persistence mechanisms in this metadata-only change.

@@ -97,31 +100,35 @@ pkgbase = ungoogled-chromium
 	source = chromium-149-drop-unknown-clang-flag.patch
 	source = chromium-149-use-of-undeclared-identifier-ERROR.patch
 	source = chromium-150-revert-avx-flag-change.patch
-	source = chromium-152-crubit.patch
-	source = chromium-152-dawn-llvm-22.patch
 	source = chromium-152-fix-gn-no-public_inputs.patch
 	source = chromium-152-unbundle-minizip-undo-unicode.patch
 	source = chromium-152-unbundle-opus-devtools.patch
+	source = chromium-153-hermetic-python.patch
+	source = chromium-153-iamf-tools-unbundled-opus.patch
+	source = chromium-153-typescript.patch
+	source = chromium-153-crubit.patch
 	source = compiler-rt-adjust-paths.patch
 	source = increase-fortify-level.patch
 	source = enable-widevine-arm64.patch
 	source = use-oauth2-client-switches-as-default.patch
 	source = glibc-2.42-baud-rate-fix.patch
 	sha256sums = 2e2f36e3cd1ebc4ad57fd310774a5e5e9db77883d5f9374fedeaabd3c103b819
-	sha256sums = 0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb
+	sha256sums = 922a6c884a0842c3c0e7fcd30a873acae00f439843c63ea7332d2fe04eef8aec
 	sha256sums = 213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a
 	sha256sums = 11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e
 	sha256sums = 4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e
 	sha256sums = c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a
 	sha256sums = b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05
-	sha256sums = e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9
+	sha256sums = 1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327
 	sha256sums = 951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4
 	sha256sums = 5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60
-	sha256sums = 6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea
-	sha256sums = 5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140
-	sha256sums = 5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07
+	sha256sums = 50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b
 	sha256sums = 890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9
 	sha256sums = 3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3
+	sha256sums = ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49
+	sha256sums = 2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee
+	sha256sums = 44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16
+	sha256sums = a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4
 	sha256sums = ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863
 	sha256sums = d634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342
 	sha256sums = 5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928
Risk 0/5 · Safe PKGBUILD
Result #3444

Comment

The change is a routine version bump plus updated patch set and dependency list. The new patches are narrowly scoped to keep the Chromium build working with system Python, system TypeScript, unbundled Opus, and Crubit-related Rust/C++ integration. I did not see any suspicious build-time network access, shell execution, privilege escalation, or installation-time persistence mechanisms introduced by this diff. The only notable risk is that the patch set is fairly large and touches build internals, but the reviewed hunk itself is just metadata/version updates and the accompanying patches appear build-fix oriented rather than malicious.

@@ -11,14 +11,14 @@
 # Contributor: Daniel J Griffiths <ghost1227@archlinux.us>
 
 pkgname=ungoogled-chromium
-pkgver=152.0.7977.82
+pkgver=153.0.8010.47
 pkgrel=1
 _launcher_ver=8
 _manual_clone=1
 _system_clang=1
 # ungoogled chromium variables
 _uc_usr=ungoogled-software
-_uc_ver=152.0.7977.82-1
+_uc_ver=153.0.8010.47-1
 pkgdesc="A lightweight approach to removing Google web service dependency"
 arch=('x86_64')
 url="https://github.com/ungoogled-software/ungoogled-chromium"
Risk 0/5 · Safe PKGBUILD
Result #3445

Comment

The change only adds two build dependencies, `opus` and `typescript`, to makedepends. This does not introduce any new runtime behavior, install scripts, network fetches, privilege escalation, or packaging changes. Both packages are standard Arch dependencies and the diff is limited to build-time tooling. No security red flags are evident from this hunk alone.

@@ -72,11 +72,13 @@ makedepends=(
   'lld'
   'ninja'
   'nodejs'
+  'opus'
   'pipewire'
   'python'
   'qt6-base'
   'rust-bindgen'
   'rust'
+  'typescript'
 )
 optdepends=('pipewire: WebRTC desktop sharing under Wayland'
             'kdialog: support for native dialogs in Plasma'
Risk 0/5 · Safe PKGBUILD
Result #3446

Comment

The PKGBUILD update is a routine upstream version bump with new/updated patches and dependency adjustments. I did not find signs of supply-chain compromise in the change itself: all sources remain HTTPS from the official Chromium tarball, the added patches are local files in the package tree, and the build still operates within the normal patch/build flow. The new patches are consistent with the added TypeScript, hermetic Python, Opus, and Crubit-related build changes for Chromium 153, and the dependency additions (opus, typescript) match those changes. No curl|bash, external build-time downloads, privilege escalation, or install-script persistence mechanisms are introduced in this diff.

@@ -97,31 +99,35 @@ source=(https://commondatastorage.googleapis.com/chromium-browser-official/chrom
         chromium-149-drop-unknown-clang-flag.patch
         chromium-149-use-of-undeclared-identifier-ERROR.patch
         chromium-150-revert-avx-flag-change.patch
-        chromium-152-crubit.patch
-        chromium-152-dawn-llvm-22.patch
         chromium-152-fix-gn-no-public_inputs.patch
         chromium-152-unbundle-minizip-undo-unicode.patch
         chromium-152-unbundle-opus-devtools.patch
+        chromium-153-hermetic-python.patch
+        chromium-153-iamf-tools-unbundled-opus.patch
+        chromium-153-typescript.patch
+        chromium-153-crubit.patch
         compiler-rt-adjust-paths.patch
         increase-fortify-level.patch
         enable-widevine-arm64.patch
         use-oauth2-client-switches-as-default.patch
         glibc-2.42-baud-rate-fix.patch)
-sha256sums=('a672d1a84b0a7744e2bb6c9d038a2aace269db51bcf99e76895fb169a7e0c218'
-            '0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb'
+sha256sums=('645f64566cfbb780747430d53ff3656f03639f89fed9544c1eadd4c17e7b1c82'
+            '922a6c884a0842c3c0e7fcd30a873acae00f439843c63ea7332d2fe04eef8aec'
             '213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
             '11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
             '4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
             'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
             'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
-            'e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9'
+            '1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327'
             '951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
             '5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
-            '6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea'
-            '5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140'
-            '5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07'
+            '50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b'
             '890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9'
             '3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'
+            'ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49'
+            '2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee'
+            '44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16'
+            'a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4'
             'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
             'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
             '5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'
Risk 0/5 · Safe PKGBUILD
Result #3447

Comment

The change only adds `highway` to the internal `_system_libs` mapping in PKGBUILD, which affects how the package links against system libraries. This is a small metadata/build-configuration change with no evidence of network access, script execution, privilege escalation, or packaging of unexpected artifacts. I did not find any security-relevant red flags in this hunk.

@@ -144,6 +150,7 @@ declare -gA _system_libs=(
   [fontconfig]=fontconfig
   [freetype]=freetype2
   [harfbuzz]=harfbuzz
+  [highway]=highway
   #[icu]=icu
   #[jsoncpp]=jsoncpp  # needs libstdc++
   #[libaom]=aom
Risk 1/5 · Low PKGBUILD
Result #3448

Comment

The change is a packaging-only update for Chromium 153 that removes two older patches and adds three new ones plus dependency adjustments. I do not see any obvious supply-chain red flags in the diff: sources remain upstream Chromium tarball plus local patches, no new network fetches or privilege-escalation behavior, and the new patches are narrowly scoped to build-system compatibility (system Python, TypeScript, unbundled Opus, Crubit). The removed patches appear to be superseded by the new Chromium 153 patch set rather than hiding functionality. Overall this looks low risk, with the main caveat being that the new local patches were not fully audited beyond the provided hunks, but nothing in the reviewed PKGBUILD change suggests malicious behavior.

@@ -231,10 +238,6 @@ prepare() {
   # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
   patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
 
-  patch -Np1 -i ../chromium-152-crubit.patch
-
-  patch -Np1 -i ../chromium-152-dawn-llvm-22.patch
-
   # Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3
   patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src
 
Risk 0/5 · Safe PKGBUILD
Result #3449

Comment

The change is a packaging/build-system update that adds three new local patches and new build dependencies, but the reviewed hunk itself only inserts patch application lines. I checked the referenced patch files: they are straightforward build fixes (switch to system python, adjust Opus include paths, disable tsgo/use system tsc, and Crubit-related GN changes) and do not introduce network access, privilege escalation, persistence, or embedded binaries. The new dependencies are standard Arch packages (`opus`, `typescript`) and the source URLs remain official HTTPS Chromium tarballs. No security red flags are evident in this hunk beyond the normal risk of build patches, so this looks low risk.

@@ -242,6 +245,22 @@ prepare() {
 
   patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch
 
+  # Use system python3 instead of the hermetic cpython3 interpreter
+  # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+  patch -Np1 -i ../chromium-153-hermetic-python.patch
+
+  # third_party/iamf_tools includes vendored Opus via relative "include/opus.h"
+  # paths that only resolve against a real bundled Opus checkout; fix them up
+  # for the unbundled system Opus build
+  patch -Np1 -i ../chromium-153-iamf-tools-unbundled-opus.patch
+
+  # Work around TypeScript becoming a build dependency: disable tsgo for the
+  # WebUI and point devtools at the system tsc binary
+  # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+  patch -Np1 -i ../chromium-153-typescript.patch
+
+  patch -Np1 -i ../chromium-153-crubit.patch
+
   if (( !_system_clang )); then
     # Use prebuilt rust as system rust cannot be used due to the error:
     #   error: the option `Z` is only accepted on the nightly compiler
Risk 0/5 · Safe REUSE.toml
Result #3450

Comment

The REUSE.toml update is metadata-only and reflects the addition/removal of patch files in the package. It does not change build logic, fetch sources, permissions, or install-time behavior. I also checked the referenced patch content: it only adjusts include paths in iamf_tools to work with unbundled system Opus, with no evidence of network access, privilege escalation, or persistence mechanisms. Overall this change is low risk.

@@ -27,6 +27,7 @@ path = [
     "chromium-148-revert-clang-fsanitize-return-flag-1.patch",
     "chromium-148-revert-clang-fsanitize-return-flag-2.patch",
     "glibc-2.42-baud-rate-fix.patch",
+    "chromium-153-iamf-tools-unbundled-opus.patch"
 ]
 SPDX-FileCopyrightText = "Arch Linux contributors"
 SPDX-License-Identifier = "0BSD"
Risk 0/5 · Safe REUSE.toml
Result #3451

Comment

The change only updates REUSE metadata to add copyright/license annotations for three existing patch files. It does not alter build logic, sources, install scripts, permissions, or introduce any execution path. I see no security impact from this diff alone.

@@ -57,11 +58,14 @@ path = [
 SPDX-FileCopyrightText = "chromium contributors"
 SPDX-License-Identifier = "BSD-3-Clause"
 
-# [[annotations]]
-# path = [
-# ]
-# SPDX-FileCopyrightText = "2015-2026 The ungoogled-chromium Authors"
-# SPDX-License-Identifier = "BSD-3-Clause"
+[[annotations]]
+path = [
+    "chromium-153-hermetic-python.patch",
+    "chromium-153-typescript.patch",
+    "chromium-153-crubit.patch",
+]
+SPDX-FileCopyrightText = "2015-2026 The ungoogled-chromium Authors"
+SPDX-License-Identifier = "BSD-3-Clause"
 
 [[annotations]]
 path = [
Risk 0/5 · Safe REUSE.toml
Result #3452

Comment

The change only updates REUSE metadata to include a newly added patch and to classify three Chromium 153 patches under the ungoogled-chromium authorship block. This is documentation/attribution metadata only; it does not alter build logic, sources, install scripts, permissions, or runtime behavior. I do not see any security-relevant impact from this diff alone.

@@ -82,7 +86,6 @@ path = [
     "chromium-149-drop-unknown-clang-flag.patch",
     "chromium-149-use-of-undeclared-identifier-ERROR.patch",
     "chromium-152-crubit.patch",
-    "chromium-152-dawn-llvm-22.patch",
 ]
 SPDX-FileCopyrightText = "2003-2026 Nixpkgs/NixOS contributors"
 SPDX-License-Identifier = "MIT"
Risk 1/5 · Low chromium-149-drop-unknown-clang-flag.patch
Result #3453

Comment

The patch only disables two Chromium GN sanitizer-hardening configs (`c_array_bounds` and `return`) by forcing their conditions to `false`. This is a build-time behavior change, not a runtime persistence/backdoor mechanism. It reduces sanitizer coverage and may hide bugs during compilation/testing, but it does not introduce network access, privilege escalation, or code execution beyond the normal package build. No suspicious sources or install-script behavior are involved in this diff.

@@ -11,21 +11,20 @@ index 7df3e18c4c..1d253318a6 100644
        } else {
          # Combine after https://github.com/llvm/llvm-project/pull/192241
          cflags += [ "/clang:-fdiagnostics-show-inlining-chain" ]
-@@ -1578,7 +1578,7 @@ config("clang_warning_suppression") {
+@@ -1590,7 +1590,7 @@ config("clang_warning_suppression") {
  # See also: https://crbug.com/40891132#comment10
  ubsan_hardening("c_array_bounds") {
    sanitizer = "array-bounds"
--  condition = !(is_asan && target_cpu == "x86") && !is_wasm
+-  condition = !(is_asan && target_cpu == "x86")
 +  condition = false
- 
+
    # Because we've enabled array-bounds sanitizing we also want to suppress
    # the related warning about "unsafe-buffer-usage-in-static-sized-array",
-@@ -1592,7 +1592,7 @@ ubsan_hardening("c_array_bounds") {
+@@ -1604,6 +1604,7 @@ ubsan_hardening("c_array_bounds") {
  # `NOTREACHED()` at the end of such functions.
  ubsan_hardening("return") {
    sanitizer = "return"
--  condition = !is_wasm
 +  condition = false
  }
- 
+
  config("rustc_revision") {
Risk 0/5 · Safe chromium-152-fix-gn-no-public_inputs.patch
Result #3454

Comment

This patch only adjusts a GN helper in Chromium’s TypeScript build logic, removing `public_inputs` exposure and two legacy JS filenames from the generated source list. The change is confined to build metadata, does not add execution paths, network access, privilege changes, or packaging/install behavior, and the removed entries look like ordinary build inputs rather than security-sensitive artifacts. No obvious supply-chain or persistence risk is introduced by this diff.

@@ -128,9 +128,9 @@ diff --git a/scripts/build/typescript/typescript.gni b/scripts/build/typescript/
 index b0d1367..a6f4c04 100644
 --- a/scripts/build/typescript/typescript.gni
 +++ b/scripts/build/typescript/typescript.gni
-@@ -212,19 +212,6 @@
+@@ -207,17 +207,6 @@
      output_files = [ "$target_gen_dir/$target_name-tsconfig.json" ]
- 
+
      if (defined(sources)) {
 -      # Expose ts files to dependent targets.
 -      public_inputs =
Risk 0/5 · Safe chromium-152-fix-gn-no-public_inputs.patch
Result #3455

Comment

The patch only removes GN `public_inputs` exposure for TypeScript-related build templates, reverting a prior change. This affects build graph metadata and may break dependent targets or remote execution visibility, but it does not introduce new code execution, network access, privilege escalation, or packaging persistence mechanisms. The change is limited to build configuration cleanup and appears to reduce exposed inputs rather than add anything suspicious.

@@ -141,8 +141,6 @@ index b0d1367..a6f4c04 100644
 -                           # TODO: Migrate the files below to TypeScript
 -                           # and remove them from this list.
 -                           "*ahem.js",
--                           "*ARIAProperties.js",
--                           "*SupportedCSSProperties.js",
 -                         ])
 -
        args += [ "--sources" ] + rebase_path(sources, root_build_dir)
Risk 1/5 · Low chromium-153-crubit.patch
Result #3456

Comment

The patch is a build-system refactor that moves the Rust/C++ bridge for font format detection from a generated Crubit binding to a direct cxx bridge, and updates the C++ caller to hold a rust::Box instead of a plain value. I do not see any supply-chain or persistence red flags: no new network fetches, no install-script changes, no privilege escalation, and the new Rust bridge only exposes the same font-inspection predicates as before. The deleted BUILD.gn file and the new rust_static_library target are consistent with the code changes, and the modified C++ calls remain local, read-only font parsing logic. Risk is low because this is a fairly mechanical internal API migration with no obvious malicious behavior.

@@ -0,0 +1,278 @@
+--- a/components/cbor/BUILD.gn
++++ b/components/cbor/BUILD.gn
+@@ -12,7 +12,7 @@
+   # TODO(crbug.com/535682335): Remove `USE_CBOR_RUST` buildflag entirely,
+   # unconditionally enable Rust CBOR parser, and drop `is_cronet_build` check
+   # once Cronet supports Crubit dependencies.
+-  flags = [ "USE_CBOR_RUST=!$is_cronet_build" ]
++  flags = [ "USE_CBOR_RUST=$enable_cpp_api_from_rust" ]
+ }
+ 
+ component("cbor") {
+@@ -37,7 +37,7 @@
+     "//base",
+   ]
+ 
+-  if (!is_cronet_build) {
++  if (enable_cpp_api_from_rust) {
+     public_deps = [
+       "//build/rust/crubit",
+       "//components/cbor/rust:cbor_rust_bindings",
+@@ -63,7 +63,7 @@
+     "//testing/gtest",
+     "//third_party/fuzztest",
+   ]
+-  if (!is_cronet_build) {
++  if (enable_cpp_api_from_rust) {
+     deps += [ "//components/cbor/rust:cbor_rust_unittests" ]
+   }
+ 
+
+--- b/third_party/blink/renderer/platform/BUILD.gn
++++ a/third_party/blink/renderer/platform/BUILD.gn
+@@ -186,6 +186,18 @@
+   ]
+ }
+ 
++rust_static_library("font_format_check") {
++  allow_unsafe = true  # Needed for FFI that underpins the `cxx` crate.
++  crate_root = "fonts/opentype/format_check.rs"
++  sources = [ crate_root ]
++  cxx_bindings = [ crate_root ]
++  deps = [
++    "//third_party/rust/font_types/v0_12:lib",
++    "//third_party/rust/read_fonts/v0_41:lib",
++    "//third_party/rust/skrifa/v0_44:lib",
++  ]
++}
++
+ rust_static_library("rustfft_ffi") {
+   allow_unsafe = true  # Needed for FFI that underpins the `cxx` crate.
+   crate_root = "audio/rustfft_ffi.rs"
+@@ -1794,7 +1806,6 @@
+     ":allow_discouraged_type",
+     ":blink_platform_public_deps",
+     ":platform_export",
+-    "//build/rust/crubit",
+     "//gpu/command_buffer/client:raster_interface",
+     "//media/capture:capture_lib",
+     "//mojo/public/cpp/base",
+@@ -1821,8 +1832,8 @@
+     "//ui/native_theme/features",
+   ]
+   deps = [
++    ":font_format_check",
+     ":rustfft_ffi",
+-    "fonts:font_format_bindings",
+     "//base:base_static",
+     "//base/allocator:buildflags",
+     "//build:chromecast_buildflags",
+--- b/third_party/blink/renderer/platform/fonts/BUILD.gn
++++ /dev/null
+@@ -1,19 +0,0 @@
+-# Copyright 2026 The Chromium Authors
+-# Use of this source code is governed by a BSD-style license that can be
+-# found in the LICENSE file.
+-
+-import("//build/rust/rust_static_library.gni")
+-
+-rust_static_library("font_format") {
+-  crate_root = "opentype/format_check.rs"
+-  sources = [ crate_root ]
+-  cpp_api_from_rust = {
+-    target_name = "font_format_bindings"
+-    cpp_namespace = "font_format"
+-  }
+-  deps = [
+-    "//third_party/rust/font_types/v0_12:lib",
+-    "//third_party/rust/read_fonts/v0_41:lib",
+-    "//third_party/rust/skrifa/v0_44:lib",
+-  ]
+-}
+--- b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc
++++ a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.cc
+@@ -7,6 +7,7 @@
+ #include "base/containers/span.h"
+ #include "base/containers/span_rust.h"
+ #include "base/numerics/byte_conversions.h"
++#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h"
+ #include "third_party/blink/renderer/platform/runtime_enabled_features.h"
+ #include "third_party/blink/renderer/platform/wtf/vector.h"
+ #include "third_party/skia/include/core/SkTypeface.h"
+@@ -14,37 +15,35 @@
+ namespace blink {
+ 
+ FontFormatCheck::FontFormatCheck(sk_sp<SkData> sk_data)
++    : format_info_(font_format_check::get_font_format_info(
+-    : format_info_(font_format::get_font_format_info(
+           base::SpanToRustSlice(sk_data->byteSpan()))) {}
+ 
+-FontFormatCheck::~FontFormatCheck() = default;
+-
+ bool FontFormatCheck::IsVariableFont() const {
++  return font_format_check::is_variable(*format_info_);
+-  return font_format::is_variable(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsCbdtCblcColorFont() const {
++  return font_format_check::is_cbdt_cblc(*format_info_);
+-  return font_format::is_cbdt_cblc(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsEbdtEblcMonochromeFont() const {
++  return font_format_check::is_ebdt_eblc(*format_info_);
+-  return font_format::is_ebdt_eblc(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsColrCpalColorFontV0() const {
++  return font_format_check::is_colrv0(*format_info_);
+-  return font_format::is_colrv0(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsColrCpalColorFontV1() const {
++  return font_format_check::is_colrv1(*format_info_);
+-  return font_format::is_colrv1(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsSbixColorFont() const {
++  return font_format_check::is_sbix(*format_info_);
+-  return font_format::is_sbix(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsCff2OutlineFont() const {
++  return font_format_check::is_cff2(*format_info_);
+-  return font_format::is_cff2(format_info_);
+ }
+ 
+ bool FontFormatCheck::IsVariableColrV0Font() const {
+@@ -58,7 +57,7 @@
+ 
+ bool FontFormatCheck::IsAvar2Font() const {
+   return RuntimeEnabledFeatures::FontFormatAvar2Enabled() &&
++         font_format_check::is_avar2(*format_info_);
+-         font_format::is_avar2(format_info_);
+ }
+ 
+ FontFormatCheck::VariableFontSubType FontFormatCheck::ProbeVariableFont(
+--- b/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h
++++ a/third_party/blink/renderer/platform/fonts/opentype/font_format_check.h
+@@ -5,7 +5,7 @@
+ #ifndef THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_
+ #define THIRD_PARTY_BLINK_RENDERER_PLATFORM_FONTS_OPENTYPE_FONT_FORMAT_CHECK_H_
+ 
++#include "third_party/blink/renderer/platform/fonts/opentype/format_check.rs.h"
+-#include "third_party/blink/renderer/platform/fonts/font_format.h"
+ #include "third_party/blink/renderer/platform/platform_export.h"
+ #include "third_party/blink/renderer/platform/wtf/allocator/allocator.h"
+ #include "third_party/skia/include/core/SkData.h"
+@@ -19,7 +19,7 @@
+ 
+  public:
+   explicit FontFormatCheck(sk_sp<SkData>);
++  virtual ~FontFormatCheck() = default;
+-  virtual ~FontFormatCheck();
+   virtual bool IsVariableFont() const;
+   virtual bool IsCbdtCblcColorFont() const;
+   virtual bool IsEbdtEblcMonochromeFont() const;
+@@ -46,7 +46,7 @@
+   enum class COLRVersion { kCOLRV0, kCOLRV1, kNoCOLR };
+ 
+  private:
++  rust::Box<font_format_check::FontFormatInfo> format_info_;
+-  font_format::FontFormatInfo format_info_;
+ };
+ 
+ }  // namespace blink
+--- b/third_party/blink/renderer/platform/fonts/opentype/format_check.rs
++++ a/third_party/blink/renderer/platform/fonts/opentype/format_check.rs
+@@ -23,7 +23,7 @@
+     format_flags: Option<FontFormatFlags>,
+ }
+ 
++pub fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo> {
+-pub fn get_font_format_info(font_bytes: &[u8]) -> FontFormatInfo {
+     let file_ref = make_font_ref_internal(font_bytes, 0);
+ 
+     match file_ref {
+@@ -32,11 +32,11 @@
+                 font.table_directory().table_records().iter().map(|e| e.tag()).collect();
+             let color_version = get_colr_version(&font);
+             let avar_version = get_avar_version(&font);
++            Box::new(FontFormatInfo {
+-            FontFormatInfo {
+                 format_flags: Some(FontFormatFlags { table_tags, color_version, avar_version }),
++            })
+-            }
+         }
++        _ => Box::new(FontFormatInfo::default()),
+-        _ => FontFormatInfo::default(),
+     }
+ }
+ 
+@@ -44,10 +44,10 @@
+     Some(font_ref.colr().ok()?.version())
+ }
+ 
++fn is_colrv1(format_info: &FontFormatInfo) -> bool {
+-pub fn is_colrv1(format_info: &FontFormatInfo) -> bool {
+     matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: Some(1), .. }),)
+ }
++fn is_colrv0(format_info: &FontFormatInfo) -> bool {
+-pub fn is_colrv0(format_info: &FontFormatInfo) -> bool {
+     matches!(&format_info.format_flags, Some(FontFormatFlags { color_version: Some(0), .. }),)
+ }
+ 
+@@ -56,7 +56,7 @@
+     Some((version.major, version.minor))
+ }
+ 
++fn is_avar2(format_info: &FontFormatInfo) -> bool {
+-pub fn is_avar2(format_info: &FontFormatInfo) -> bool {
+     matches!(&format_info.format_flags, Some(FontFormatFlags { avar_version: Some((2, _)), .. }),)
+ }
+ 
+@@ -69,22 +69,39 @@
+     }
+ }
+ 
++fn is_variable(format_info: &FontFormatInfo) -> bool {
+-pub fn is_variable(format_info: &FontFormatInfo) -> bool {
+     has_tags(format_info, &[Tag::new(b"fvar")])
+ }
+ 
++fn is_sbix(format_info: &FontFormatInfo) -> bool {
+-pub fn is_sbix(format_info: &FontFormatInfo) -> bool {
+     has_tags(format_info, &[Tag::new(b"sbix")])
+ }
+ 
++fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool {
+-pub fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool {
+     has_tags(format_info, &[Tag::new(b"CBDT"), Tag::new(b"CBLC")])
+ }
+ 
++fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool {
+-pub fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool {
+     has_tags(format_info, &[Tag::new(b"EBDT"), Tag::new(b"EBLC")])
+ }
+ 
++fn is_cff2(format_info: &FontFormatInfo) -> bool {
+-pub fn is_cff2(format_info: &FontFormatInfo) -> bool {
+     has_tags(format_info, &[Tag::new(b"CFF2")])
+ }
++
++#[cxx::bridge(namespace = "font_format_check")]
++pub mod ffi {
++    extern "Rust" {
++        type FontFormatInfo;
++
++        fn get_font_format_info(font_bytes: &[u8]) -> Box<FontFormatInfo>;
++        fn is_colrv1(format_info: &FontFormatInfo) -> bool;
++        fn is_colrv0(format_info: &FontFormatInfo) -> bool;
++        fn is_cbdt_cblc(format_info: &FontFormatInfo) -> bool;
++        fn is_ebdt_eblc(format_info: &FontFormatInfo) -> bool;
++        fn is_variable(format_info: &FontFormatInfo) -> bool;
++        fn is_sbix(format_info: &FontFormatInfo) -> bool;
++        fn is_cff2(format_info: &FontFormatInfo) -> bool;
++        fn is_avar2(format_info: &FontFormatInfo) -> bool;
++    }
++}
Risk 1/5 · Low chromium-153-hermetic-python.patch
Result #3457

Comment

Risk is low. The patch only changes Chromium's GN configuration to use the system python3 instead of a bundled hermetic interpreter. There is no added code execution, network access, privilege escalation, or packaging-side persistence mechanism in this diff. The main security consideration is reduced build hermeticity/reproducibility and reliance on the host Python, but that is a build-environment trust tradeoff rather than a direct vulnerability in the package change itself.

@@ -0,0 +1,17 @@
+Use the system python3 instead of the hermetic cpython3 interpreter, which
+is not shipped in the tarball and is not needed when building against system
+tools.
+
+Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+
+--- a/.gn
++++ b/.gn
+@@ -9,7 +9,7 @@
+ buildconfig = "//build/config/BUILDCONFIG.gn"
+
+ # The hermetic Python interpreter to use by default.
+-script_executable = "//third_party/cpython3/host/bin/python3"
++script_executable = "python3"
+
+ # These arguments override the default values for items in a declare_args
+ # block. "gn args" in turn can override these.
Risk 0/5 · Safe chromium-153-iamf-tools-unbundled-opus.patch
Result #3458

Comment

The patch only corrects include paths in iamf_tools from a relative bundled-Opus layout to Chromium's unbundled/system-Opus layout. It does not add new code execution, network access, privilege changes, or packaging behavior, and the change is limited to compile-time header resolution. I don't see a security regression in this diff.

@@ -0,0 +1,76 @@
+third_party/iamf_tools (new in 153) includes the vendored copy of Opus via
+relative "include/opus.h"-style paths that only resolve when
+//third_party/opus/src is the real bundled Opus checkout. With Opus
+unbundled (system libopus via build/linux/unbundle/opus.gn's shim_headers
+target), that directory doesn't contain a real "include/" subtree, so the
+compile fails with:
+
+  fatal error: 'include/opus.h' file not found
+
+Use the same full "third_party/opus/src/include/..." style path that other
+in-tree consumers (e.g. third_party/opus/tests/opus_benchmark.cc) use, which
+resolves correctly against both the shim headers and a real bundled Opus
+checkout, since root src is always on the include path.
+
+--- a/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc
++++ b/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.cc
+@@ -30,8 +30,8 @@
+ #include "iamf/obu/decoder_config/opus_decoder_config.h"
+ #include "iamf/obu/substream_channel_count.h"
+ #include "iamf/obu/types.h"
+-#include "include/opus.h"
+-#include "include/opus_types.h"
++#include "third_party/opus/src/include/opus.h"
++#include "third_party/opus/src/include/opus_types.h"
+
+ namespace iamf_tools {
+
+--- a/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h
++++ b/third_party/iamf_tools/src/iamf/cli/codec/opus_decoder.h
+@@ -23,7 +23,7 @@
+ #include "iamf/cli/codec/decoder_base.h"
+ #include "iamf/obu/decoder_config/opus_decoder_config.h"
+ #include "iamf/obu/substream_channel_count.h"
+-#include "include/opus.h"
++#include "third_party/opus/src/include/opus.h"
+
+ namespace iamf_tools {
+
+--- a/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc
++++ b/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.cc
+@@ -32,9 +32,9 @@
+ #include "iamf/common/utils/validation_utils.h"
+ #include "iamf/obu/decoder_config/opus_decoder_config.h"
+ #include "iamf/obu/substream_channel_count.h"
+-#include "include/opus.h"
+-#include "include/opus_defines.h"
+-#include "include/opus_types.h"
++#include "third_party/opus/src/include/opus.h"
++#include "third_party/opus/src/include/opus_defines.h"
++#include "third_party/opus/src/include/opus_types.h"
+
+ namespace iamf_tools {
+
+--- a/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h
++++ b/third_party/iamf_tools/src/iamf/cli/codec/opus_encoder.h
+@@ -22,8 +22,8 @@
+ #include "iamf/obu/codec_config.h"
+ #include "iamf/obu/decoder_config/opus_decoder_config.h"
+ #include "iamf/obu/substream_channel_count.h"
+-#include "include/opus.h"
+-#include "include/opus_defines.h"
++#include "third_party/opus/src/include/opus.h"
++#include "third_party/opus/src/include/opus_defines.h"
+
+ namespace iamf_tools {
+
+--- a/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc
++++ b/third_party/iamf_tools/src/iamf/cli/codec/opus_utils.cc
+@@ -3,7 +3,7 @@
+ #include "absl/status/status.h"
+ #include "absl/strings/str_cat.h"
+ #include "absl/strings/string_view.h"
+-#include "include/opus_defines.h"
++#include "third_party/opus/src/include/opus_defines.h"
+
+ namespace iamf_tools {
Risk 0/5 · Safe chromium-153-typescript.patch
Result #3459

Comment

The patch is a narrow build-time workaround that disables Chromium's native TypeScript compiler flag and hardcodes DevTools to use the system `tsc` binary. I don't see evidence of malicious behavior, privilege escalation, persistence, or network access. The main risk is packaging integrity/portability: it introduces a hard dependency on `/usr/bin/tsc`, which can fail if the expected Arch `typescript` package is absent or if the path differs, but that is a build/runtime compatibility issue rather than a security issue. No suspicious downloads, shell execution, or install-script changes are present in the reviewed hunk.

@@ -0,0 +1,31 @@
+TypeScript became a build dependency (added in crrev.com/c/7861311, enabled in
+crrev.com/c/8104602). Work around it for a system build:
+
+  * Disable the native TypeScript compiler (tsgo) for the WebUI; the JS-based
+    compiler bundled with the checkout still works.
+  * DevTools already removed that flag (crrev.com/c/8193297), so point its
+    typescript.py helper at the system tsc binary (from the 'typescript' package).
+
+Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+
+--- a/ui/webui/webui_features.gni
++++ b/ui/webui/webui_features.gni
+@@ -33,7 +33,7 @@
+
+   # Enable the native TypeScript compiler (tsgo) instead of the JS-based one.
+   # TODO(crbug.com/423789047): Remove this flag once fully committed to v7.
+-  use_typescript_go = true
++  use_typescript_go = false
+ }
+
+ if (enable_cast_receiver || is_cast_android || is_castos) {
+--- a/third_party/devtools-frontend/src/third_party/typescript/typescript.py
++++ b/third_party/devtools-frontend/src/third_party/typescript/typescript.py
+@@ -10,6 +10,7 @@
+
+
+ def GetBinaryPath():
++    return "/usr/bin/tsc"
+     if platform.machine() == 'arm64':
+         darwin_path = 'mac-arm64'
+     else: