Chromium 140.0.7339.80 boo#1249093 #2

Manually merged
AndreasStieger merged 350 commits from :leap-16.0 into leap-16.0 2025-09-04 16:27:17 +02:00
Contributor

Chromium 140 / 140.0.7339.80 boo#1249093

Chromium 140 / 140.0.7339.80 [boo#1249093](https://bugzilla.opensuse.org/show_bug.cgi?id=1249093)
AndreasStieger added 350 commits 2025-09-03 17:13:29 +02:00
next attempt, an actually running chromium-125

OBS-URL: https://build.opensuse.org/request/show/1175065
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=1
Chromium 126 - wip

OBS-URL: https://build.opensuse.org/request/show/1175329
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=4
126.0.6478.26

OBS-URL: https://build.opensuse.org/request/show/1177641
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=10
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=11
- Chromium 126.0.6478.36

OBS-URL: https://build.opensuse.org/request/show/1179067
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=12
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=14
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=15
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=16
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=17
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=20
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=21
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=24
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=25
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=26
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=27
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=28
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=29
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=30
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=31
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=32
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=33
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=34
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=37
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=38
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=39
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=40
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=45
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=46
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=47
- Chromium 127.0.6533.119
  * CVE-2024-7532: Out of bounds memory access in ANGLE
  * CVE-2024-7533: Use after free in Sharing
  * CVE-2024-7550: Type Confusion in V8
  * CVE-2024-7534: Heap buffer overflow in Layout
  * CVE-2024-7535: Inappropriate implementation in V8
  * CVE-2024-7536: Use after free in WebAudio

- Chromium 127.0.6533.88
  * CVE-2024-6988: Use after free in Downloads
  * CVE-2024-6989: Use after free in Loader
  * CVE-2024-6991: Use after free in Dawn
  * CVE-2024-6992: Out of bounds memory access in ANGLE
  * CVE-2024-6993: Inappropriate implementation in Canvas
  * CVE-2024-6994: Heap buffer overflow in Layout
  * CVE-2024-6995: Inappropriate implementation in Fullscreen
  * CVE-2024-6996: Race in Frames
  * CVE-2024-6997: Use after free in Tabs
  * CVE-2024-6998: Use after free in User Education
  * CVE-2024-6999: Inappropriate implementation in FedCM
  * CVE-2024-7000: Use after free in CSS. Reported by Anonymous
  * CVE-2024-7001: Inappropriate implementation in HTML
  * CVE-2024-7003: Inappropriate implementation in FedCM
  * CVE-2024-7004: Insufficient validation of untrusted input
    in Safe Browsing
  * CVE-2024-7005: Insufficient validation of untrusted input
    in Safe Browsing
  * CVE-2024-6990: Uninitialized Use in Dawn
  * CVE-2024-7255: Out of bounds read in WebTransport
  * CVE-2024-7256: Insufficient data validation in Dawn

OBS-URL: https://build.opensuse.org/request/show/1194297
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=48
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=49
- Chromium 128.0.6613.36 (current beta release) 
- modified patches:
  * chromium-norar.patch drop most hunks,
    upstream has a config for this now
  * gcc-enable-lto.patch update context
  * chromium-125-compiler.patch update context
  * chromium-127-constexpr.patch update context
- drop patches: (should be obsolete with llvm>17 and libc++)
  chromium-120-emplace.patch
  chromium-125-emplace-struct.patch
- drop patches: (upstream)
  * chromium-121-nullptr_t-without-namespace-std.patch
  * chromium-123-stats-collector.patch
  * chromium-127-paint-layer-header.patch
  * chromium-127-ninja-1.21.1-deps-part0.patch
  * chromium-127-ninja-1.21.1-deps-part1.patch
  * chromium-127-ninja-1.21.1-deps-part2.patch
  * chromium-127-ninja-1.21.1-deps-part3.patch
- disable rpmlint only for factory/tw where it is broken because
  of the large archive size of the source here
- keeplibs add
  third_party/devtools-frontend/src/front_end/third_party/
  puppeteer/package/lib/esm/third_party/parsel-js
  third_party/tflite/src/third_party/xla/xla/tsl/framework
- buildflags add
  safe_browsing_use_unrar=false

OBS-URL: https://build.opensuse.org/request/show/1195041
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=50
128.0.6613.84

OBS-URL: https://build.opensuse.org/request/show/1195219
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=52
Chromium 129.0.6668.12

OBS-URL: https://build.opensuse.org/request/show/1195829
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=53
- Chromium 129.0.6668.22 (beta released 2024-08-29)

OBS-URL: https://build.opensuse.org/request/show/1198480
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=54
- Chromium 129.0.6668.29 (beta released 2024-09-04)
- add to keeplibs:
  third_party/rapidhash
- Chromium 128.0.6613.119 (released 2024-09-02) (boo#1230108)
  * CVE-2024-8362: Use after free in WebAudio
  * CVE-2024-7970: Out of bounds write in V8

- Chromium 128.0.6613.113 (boo#1229897)
  * CVE-2024-7969: Type Confusion in V8
  * CVE-2024-8193: Heap buffer overflow in Skia
  * CVE-2024-8194: Type Confusion in V8
  * CVE-2024-8198: Heap buffer overflow in Skia

OBS-URL: https://build.opensuse.org/request/show/1199635
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=55
* CVE-2024-8636: Heap buffer overflow in Skia
  * CVE-2024-8637: Use after free in Media Router
  * CVE-2024-8638: Type Confusion in V8
  * CVE-2024-8639: Use after free in Autofill

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=6
OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=7
* CVE-2024-8904: Type Confusion in V8
  * CVE-2024-8905: Inappropriate implementation in V8
  * CVE-2024-8906: Incorrect security UI in Downloads
  * CVE-2024-8907: Insufficient data validation in Omnibox
  * CVE-2024-8908: Inappropriate implementation in Autofill
  * CVE-2024-8909: Inappropriate implementation in UI

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=8
- Chromium 129.0.6668.58 (beta released 2024-09-17)
  * CVE-2024-8904: Type Confusion in V8
  * CVE-2024-8905: Inappropriate implementation in V8
  * CVE-2024-8906: Incorrect security UI in Downloads
  * CVE-2024-8907: Insufficient data validation in Omnibox
  * CVE-2024-8908: Inappropriate implementation in Autofill
  * CVE-2024-8909: Inappropriate implementation in UI
- Chromium 128.0.6613.137 (released 2024-09-10) (boo#1230391)
  * CVE-2024-8636: Heap buffer overflow in Skia
  * CVE-2024-8637: Use after free in Media Router
  * CVE-2024-8638: Type Confusion in V8
  * CVE-2024-8639: Use after free in Autofill

OBS-URL: https://build.opensuse.org/request/show/1201828
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=56
- Chromium 129.0.6668.58 (stable released 2024-09-17)

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=10
* exclude_ymp.patch update context

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=11
- dropped patches:
  * chromium-disable-GlobalMediaControlsCastStartStop.patch
    it was applied at the wrong place and the crash is gone

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=12
proto_fetcher.h

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=13
- drop from keeplibs:
  courgette/third_party dropped upstream
  (boo#1230678)

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=14
- add to keepllibs:
  third_party/fast_float needed by v8/src/numbers/conversion.cc

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=15
OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=16
* chromium-130-missing-include.patch include optional

- bump BR for nodejs to minimal 20.0
- dropped patches:
  * chromium-disable-GlobalMediaControlsCastStartStop.patch
    it was applied at the wrong place and the crash is gone

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=17
workaround for older libcpp

OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=18
OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=19
OBS-URL: https://build.opensuse.org/package/show/home:oertel:branches:network:chromium/chromium-beta?expand=0&rev=20
- Chromium 130.0.6723.6 (beta released 2024-09-18) 
- modified patches:
  * exclude_ymp.patch update context
  * chromium-125-compiler.patch update context
  * chromium-125-lp155-typename.patch drop hunks for rewritten
    proto_fetcher.h
  * chromium-127-bindgen.patch update context
- added patches:
  * chromium-130-missing-includes.patch include optional, stack
  * chromium-130-no-hardware_destructive_interference_size.patch
    workaround for older libcpp
- drop from keeplibs:
  courgette/third_party dropped upstream
- add to keepllibs:
  third_party/fast_float needed by v8/src/numbers/conversion.cc

- bump BR for nodejs to minimal 20.0
- dropped patches:
  * chromium-disable-GlobalMediaControlsCastStartStop.patch
    it was applied at the wrong place and the crash is gone

- Chromium 129.0.6668.58 (stable released 2024-09-17)
  (boo#1230678)

OBS-URL: https://build.opensuse.org/request/show/1202767
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=57
initial

OBS-URL: https://build.opensuse.org/request/show/1202768
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=1
- Chromium 129.0.6668.70 (stable released 2024-09-24)
  (boo#1230964)
  * CVE-2024-9120: Use after free in Dawn
  * CVE-2024-9121: Inappropriate implementation in V8
  * CVE-2024-9122: Type Confusion in V8
  * CVE-2024-9123: Integer overflow in Skia

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=58
- Chromium 130.0.6723.19 (beta released 2024-09-25)

- Chromium 129.0.6668.70 (stable released 2024-09-24)
  (boo#1230964)
  * CVE-2024-9120: Use after free in Dawn
  * CVE-2024-9121: Inappropriate implementation in V8
  * CVE-2024-9122: Type Confusion in V8
  * CVE-2024-9123: Integer overflow in Skia

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=2
* chromium-130-missing-includes.patch (upstream)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=3
- Chromium 129.0.6668.89 (stable released 2024-09-24)
  (boo#1231232)
  * CVE-2024-7025: Integer overflow in Layout
  * CVE-2024-9369: Insufficient data validation in Mojo
  * CVE-2024-9370: Inappropriate implementation in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=59
130.0.6735.44

OBS-URL: https://build.opensuse.org/request/show/1207448
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=60
bump

OBS-URL: https://build.opensuse.org/request/show/1208656
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=61
(beta releaed 2024-10-23)
- dropped patches:
  * chromium-130-missing-includes.patch (upstream)
- added patches:
  * chromium-131-no-crel.patch
    do not use "--crel,----allow-experimental-crel" for "-Wa"

- Chromium 130.0.6723.69 (boo#1232060)
  * CVE-2024-10229: Inappropriate implementation in Extensions
  * CVE-2024-10230: Type Confusion in V8
  * CVE-2024-10231: Type Confusion in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=62
(beta releaed 2024-10-30)

- Chromium 130.0.6723.91 (boo#1232566)
  * CVE-2024-10487: Out of bounds write in Dawn
  * CVE-2024-10488: Use after free in WebRTC

- change BR for rust to require version 1.81
  (1.82 uses a newer llvm)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=63
* chromium-125-lp155-typename.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=65
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=66
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=67
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=68
third_party/devtools-frontend/src/front_end/third_party/lodash-isequal

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=69
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=70
* chromium-131-unbundle-enable-freetype.patch
    from git, missing in 131 release

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=71
third_party/tflite/src/third_party/xla/xla/tsl/protobuf

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=72
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=73
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=74
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=75
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=76
(dev released 2024-10-24) 
- dropped patches:
  * chromium-131-unbundle-enable-freetype.patch (upstream)

- Chromium 131.0.6778.24 
  (beta releaed 2024-10-30)
  * chromium-131-unbundle-enable-freetype.patch
    from git, missing in 131 release
- update context in
  * chromium-125-lp155-typename.patch
  * chromium-127-bindgen.patch
  * chromium-127-constexpr.patch
- drop from keeplibs: (deleted upstream)
  third_party/devtools-frontend/src/front_end/third_party/lodash-isequal
- add to keeplibs:
  third_party/tflite/src/third_party/xla/xla/tsl (drop subdirs)
  third_party/ink

- Chromium 130.0.6723.91 (boo#1232566)
  * CVE-2024-10487: Out of bounds write in Dawn
  * CVE-2024-10488: Use after free in WebRTC

- change BR for rust to require version 1.81
  (1.82 uses a newer llvm) 

- Chromium 130.0.6723.69 (boo#1232060)
  * CVE-2024-10229: Inappropriate implementation in Extensions
  * CVE-2024-10230: Type Confusion in V8
  * CVE-2024-10231: Type Confusion in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=4
(beta releaed 2024-11-06)

- Chromium 130.0.6723.116 (boo#1232843)
  * CVE-2024-10826: Use after free in Family Experiences
  * CVE-2024-10827: Use after free in Serial

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=78
(dev released 2024-11-05) 
- Chromium 131.0.6778.33 
  (beta releaed 2024-11-06)

- Chromium 130.0.6723.116 (boo#1232843)
  * CVE-2024-10826: Use after free in Family Experiences
  * CVE-2024-10827: Use after free in Serial

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=5
* chromium-125-compiler.patch
- update patch
  * chromium-127-bindgen.patch (drop allowlist part, not needed)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=7
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=8
- drop old tarball
  - use upstream release tarball for 0.24.0
  - add vendor tarball for golang.org/x/sys

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=9
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=10
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=11
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=12
* chromium-132-shared_storage-fix_include.patch (from upstream)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=13
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=14
(dev released 2024-11-07)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=15
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=17
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=80
(beta released 2024-11-13) 
- dropped patches:
  * chromium-131-unbundle-enable-freetype.patch (upstream)
- update context in
  * chromium-125-compiler.patch
  * chromium-127-rust-clanglib.patch
  * Cr122-ffmpeg-new-channel-layout.patch
- update esbuild to 0.24.0
  - drop old tarball
  - use upstream release tarball for 0.24.0
  - add vendor tarball for golang.org/x/sys

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=81
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=83
(dev release 2024-11-14) 

- Chromium 132.0.6834.6
  (beta released 2024-11-13) 
  * chromium-127-rust-clanglib.patch
  * Cr122-ffmpeg-new-channel-layout.patch
- Chromium 131.0.6778.69 
  (stable released 2024-11-12) (boo#1233311)
  * CVE-2024-11110: Inappropriate implementation in Blink.
  * CVE-2024-11111: Inappropriate implementation in Autofill.
  * CVE-2024-11112: Use after free in Media.
    (n/a for linux)
  * CVE-2024-11113: Use after free in Accessibility.
  * CVE-2024-11114: Inappropriate implementation in Views.
    (n/a for linux)
  * CVE-2024-11115: Insufficient policy enforcement in Navigation.
    (n/a for linux)
  * CVE-2024-11116: Inappropriate implementation in Paint.
  * CVE-2024-11117: Inappropriate implementation in FileSystem.
  * chromium-125-lp155-typename.patch (not required with llvm)
- modified patches:
  * chromium-127-bindgen.patch (drop all allowlist changes)
  * chromium-127-constexpr.patch (update from debian patch)
  * chromium-131-clang-stack-protector.patch
    (partial revert of upstream commit
     c3dadb02f611a360fb40fd8844ed3c1ef1e7834e)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=18
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=84
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=85
third_party/libtess2

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=86
* chromium-93-ffmpeg-4.4.patch
- add to keeplibs:
  third_party/libtess2

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=20
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=87
from upstream git, node-module fast-glob is incomplete
  in chromium 132 tarball

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=88
(beta released 2024-11-20) 

- Chromium 131.0.6778.85
  (stable released 2024-11-19) (boo#1233534)
  * CVE-2024-11395: Type Confusion in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=89
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=91
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=92
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=93
add hunk in components/compose/core/browser/config.cc

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=94
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=95
* chromium-132-base_span.patch
    (try to fix compile error in ffmpeg_demuxer.cc on llvm17)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=96
(apply git upstream reverse for 15.x with llvm17)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=97
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=98
(split off to only apply after the reverse)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=99
* chromium-132-old_libdrm.patch
    (applied only on 15.5 with libdrm < 2.4.116)
  * chromium-132-pdfium-explicit-template.patch
    (error: alias template requires template arguments)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=100
(beta released 2024-12-04) 

- Chromium 131.0.6778.108
  (stable released 2024-12-04) (boo#1234118)
  * CVE-2024-12053: Type Confusion in V8
- update patches:
  chromium-127-constexpr.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=101
(dev release 2024-11-21) 

- Chromium 132.0.6834.32
  (beta released 2024-12-04) 
- added patches:
  * chromium-8d882c289f17e3a67d6d67d5ff7e9d16ebb4f19a.patch
    (apply git upstream reverse for 15.x with llvm17)
  * chromium-93-ffmpeg-4.4-rest.patch
    (split off to only apply after the reverse) 
  * chromium-132-old_libdrm.patch
    (applied only on 15.5 with libdrm < 2.4.116)
  * chromium-132-pdfium-explicit-template.patch
    (error: alias template requires template arguments)
  * chromium-127-constexpr.patch
  third_party/devtools-frontend/src/node_modules/fast-glob

- Chromium 131.0.6778.108
  (stable released 2024-12-04) (boo#1234118)
  * CVE-2024-12053: Type Confusion in V8
- update patches:
  chromium-127-constexpr.patch

- Chromium 131.0.6778.85
  (stable released 2024-11-19) (boo#1233534)
  * CVE-2024-11395: Type Confusion in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=21
chromium-125-disable-FFmpegAllowLists.patch
  chromium-129-revert-AVFMT_FLAG_NOH264PARSE.patch
  (underlying code is gone upstream, see commit
   574c1e6678da435efb2ea9dba5dd890c2704b8af)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=23
Chromium 132.0.6834.46

OBS-URL: https://build.opensuse.org/request/show/1230981
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=103
Chromium 132.0.6834.57

OBS-URL: https://build.opensuse.org/request/show/1232690
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=104
(dev release 2024-12-12)
- Chromium 132.0.6834.57
  (beta released 2024-12-19) 

- Chromium 131.0.6778.204 (boo#1234704)
  * CVE-2024-12692: Type Confusion in V8
  * CVE-2024-12693: Out of bounds memory access in V8
  * CVE-2024-12694: Use after free in Compositing
  * CVE-2024-12695: Out of bounds write in V8
  * Various fixes from internal audits, fuzzing and other initiatives
 

- Chromium 131.0.6778.139 (boo#1234361)
  * CVE-2024-12381: Type Confusion in V8
  * CVE-2024-12382: Use after free in Translate
  * Various fixes from internal audits, fuzzing and other initiatives

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=24
third_party/simdutf

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=26
(beta released 2024-01-08) 

- more work on 15.7/15-SP7 using recent llvm,rust,gcc
- cleanup use of suse_version macro
- cleanup use of conditionally applied patches, switch from
  autoset to setup/autopatch which allows to specify a range
  and apply remaining patches conditionally

- Chromium 131.0.6778.264 (boo#1235422)
  * CVE-2025-0291: Type Confusion in V8
  * Various fixes from internal audits, fuzzing and other initiatives

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=105
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=107
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=108
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=109
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=110
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=111
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=112
* CVE-2025-0434: Out of bounds memory access in V8
  * CVE-2025-0435: Inappropriate implementation in Navigation
  * CVE-2025-0436: Integer overflow in Skia
  * CVE-2025-0437: Out of bounds read in Metrics
  * CVE-2025-0438: Stack buffer overflow in Tracing
  * CVE-2025-0439: Race in Frames
  * CVE-2025-0440: Inappropriate implementation in Fullscreen
  * CVE-2025-0441: Inappropriate implementation in Fenced Frames
  * CVE-2025-0442: Inappropriate implementation in Payments
  * CVE-2025-0443: Insufficient data validation in Extensions
  * CVE-2025-0446: Inappropriate implementation in Extensions
  * CVE-2025-0447: Inappropriate implementation in Navigation
  * CVE-2025-0448: Inappropriate implementation in Compositing

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=113
(beta released 2025-01-15)
- dropped patches:
  chromium-125-disable-FFmpegAllowLists.patch
  chromium-129-revert-AVFMT_FLAG_NOH264PARSE.patch
  (underlying code is gone upstream, see commit
   574c1e6678da435efb2ea9dba5dd890c2704b8af)
- add to keeplibs:
  third_party/simdutf

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=114
chromium-102-regex_pattern-array.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=116
sync changelog

OBS-URL: https://build.opensuse.org/request/show/1238314
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=117
(code dropped upstream)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=118
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=119
third_party/jstemplate does not exist
  third_party/qcms does not exist
  v8/src/third_party/siphash does not exist
  v8/src/third_party/utf8-decoder does not exist
  v8/src/third_party/valgrind does not exist

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=120
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=121
as the lib was dropped upstream

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=122
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=123
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=124
chromium-129-revert-AVFMT_FLAG_NOH264PARSE.patch
  (rest of code is gone upstream, see commit
   574c1e6678da435efb2ea9dba5dd890c2704b8af)
  third_party/wasm_tts_engine (needed by tools/grit)
  v8/third_party/siphash (moved)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=125
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=126
v8/third_party/utf8-decoder (moved inside of v8)
  v8/third_party/valgrind (moved inside of v8)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=127
chromium-add-atomicops.patch
  (upstream commit d29b01737a841b5627249d50f007dcdc7e26462b)
  chromium-use-atomicops.patch
  (upstream commit 780efe38034cfdc1bdf4c74e82e7ca7c14e8ac5b)
- update INSTALL.sh to generate appdata.xml from template

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=128
does not seem to be in 133 yet)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=129
(stable released 2025-01-22) (bsc#1236306)
  * CVE-2025-0611: Object corruption in V8
  * CVE-2025-0612: Out of bounds memory access in V8
  (stable released 2025-01-14) (bsc#1235892)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=130
(one more place to use string_view, also only llvm17)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=131
(beta released 2025-01-23)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=132
(dev release 2025-01-24)

- Chromium 133.0.6943.27
  (beta released 2025-01-23)
- use llvm19 also on 15.6/SLE-15-SP6
  chromium-119-assert.patch
  (code dropped upstream)
- modified patches
  (rest of code is gone upstream, see commit
- update context in
  chromium-102-regex_pattern-array.patch
  chromium-125-ffmpeg-5.x-reordered_opaque.patch
  third_party/wasm_tts_engine (needed by tools/grit)
  v8/third_party/siphash (moved inside of v8)
  v8/third_party/utf8-decoder (moved inside of v8)
  v8/third_party/valgrind (moved inside of v8)
- drop from keeplibs (gone in source):
  third_party/jstemplate does not exist
  third_party/qcms does not exist
- drop buildreq for libevent and libevent from system libs
  as the lib was dropped upstream
- added patches (as revert for llvm17 in sp6):
  chromium-add-atomicops.patch
  (upstream commit d29b01737a841b5627249d50f007dcdc7e26462b)
  (upstream commit 780efe38034cfdc1bdf4c74e82e7ca7c14e8ac5b
   does not seem to be in 133 yet)
  chromium-133-string_view.patch
  (one more place to use string_view, also only llvm17)
- update INSTALL.sh to generate appdata.xml from template

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=27
fix_building_widevinecdm_with_chromium.patch
  (do not define WIDEVINE_CDM_VERSION_STRING, gone upstream)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=29
chromium-134-revert-allowlist.patch
  (avoid having to update gn on all targets)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=30
third_party/search_engines_data

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=31
(revert rust change from adler to adler2 while we have 1.83)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=32
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=33
* CVE-2025-0762: Use after free in DevTools

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=134
(revert change to pthreadpool requiring std=c++23)

- Chromium 132.0.6834.159 (boo#1236586)
  * CVE-2025-0762: Use after free in DevTools

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=34
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=35
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=36
(beta released 2025-01-29)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=135
obsolete as we are not building for 15.5 anymore

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=137
chromium-130-no-hardware_destructive_interference_size.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=138
(dev release 2025-01-31)
- dropped patches: (obsolete with recent llvm)
  chromium-130-no-hardware_destructive_interference_size.patch

- Chromium 133.0.6943.35
  (beta released 2025-01-29)
- drop chromium-132-old_libdrm.patch
  obsolete as we are not building for 15.5 anymore

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=37
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=39
third_party/libavif (gone) (FIXME cleanup)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=40
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=41
025a94257380eadfad2d705129e5863fca0bf89e.patch (revert)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=42
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-dev?expand=0&rev=43
- Chromium 134.0.6988.2
  (dev release 2025-01-31)
- modified patches:
  fix_building_widevinecdm_with_chromium.patch
  (do not define WIDEVINE_CDM_VERSION_STRING, gone upstream)
  system-libdrm.patch (context update)
- added patches:
  chromium-134-revert-allowlist.patch
  (avoid having to update gn on all targets)
  chromium-134-revert-rust-adler2.patch
  (revert rust change from adler to adler2 while we have 1.83)
  pthreadpool-revert-stdatomic-prep.patch
  pthreadpool-revert-stdatomic.patch
  (revert change to pthreadpool requiring std=c++23)
  3b811ffd3cef9d11cda6812ac4d22dcfdbad7d0f.patch (revert)
  025a94257380eadfad2d705129e5863fca0bf89e.patch (revert)
- add to keeplibs:
  third_party/search_engines_data
  v8/third_party/rapidhash-v8
- drop from keeplibs:
  third_party/libavif (gone) (FIXME cleanup)

OBS-URL: https://build.opensuse.org/request/show/1243622
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=139
(beta release 2025-02-05) 

- Chromium 133.0.6943.53 
  (stable released 2024-02-04) (bsc#1236806)
  * CVE-2025-0444: Use after free in Skia
  * CVE-2025-0445: Use after free in V8
  * CVE-2025-0451: Inappropriate implementation in Extensions API

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=140
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=142
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=143
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=144
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=145
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=146
chromium-127-clang17-traitors.patch
  chromium-add-atomicops.patch
  chromium-133-string_view.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=147
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=148
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=149
(beta release 2025-02-12) 
- comment out chromium-127-constexpr.patch for the moment 

- Chromium 133.0.
  (stable released 2025-02-12) (bsc#1237121)
  * CVE-2025-0995: Use after free in V8
  * CVE-2025-0996: Inappropriate implementation in Browser UI
  * CVE-2025-0997: Use after free in Navigation
  * CVE-2025-0998: Out of bounds memory access in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=150
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=151
- reenable qt6 for TW

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=153
* fix-build-with-pipewire-1.3.82.patch 

- Add patch to fix build with pipewire 1.3.82:
  * fix-build-with-pipewire-1.3.82.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=154
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=155
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=156
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=157
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=159
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=160
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=161
(beta release 2025-02-19) 
- reenable qt6 for TW

- Chromium 133.0.6943.126 (boo#1237343)
  * CVE-2025-0999: Heap buffer overflow in V8
  * CVE-2025-1426: Heap buffer overflow in GPU
  * CVE-2025-1006: Use after free in Network

- add patch chromium-133-bring_back_and_disable_allowlist.patch
  trying to fix issues with YT playback (bsc#1237071)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=163
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=164
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=165
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=166
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=167
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=168
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=169
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=170
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=171
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=172
- added patches:
  chromium-131-fix-qt-ui.pach (from fedora)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=173
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=174
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=175
This update includes 1 security fix.
  * Various fixes from internal audits, fuzzing and other initiatives

- fix build with qt6 and enable qt6 also for 15.x
- added patches:
  chromium-131-fix-qt-ui.pach (from fedora)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=176
(beta release 2025-02-26)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=177
chromium-134-specialize-some-to_value_list.patch
  by patch
  chromium-134-type-mismatch-error.patch (from fedora)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=179
(beta release 2025-03-05) 
- modified patches:
  system-libdrm.patch (context update)
  gcc-enable-lto.patch (context update)
  chromium-127-constexpr.patch (context update)
- add to keeplibs:
  third_party/protobuf/third_party/utf8_range
- config variable changed from use_qt to use_qt5
  (stable release 2025-03-04) (boo#1238575)
  * CVE-2025-1914: Out of bounds read in V8
  * CVE-2025-1915: Improper Limitation of a Pathname to a Restricted Directory in DevTools
  * CVE-2025-1916: Use after free in Profiles
  * CVE-2025-1917: Inappropriate Implementation in Browser UI
  * CVE-2025-1918: Out of bounds read in PDFium
  * CVE-2025-1919: Out of bounds read in Media
  * CVE-2025-1921: Inappropriate Implementation in Media Stream
  * CVE-2025-1922: Inappropriate Implementation in Selection
  * CVE-2025-1923: Inappropriate Implementation in Permission Prompts

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=181
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=182
third_party/iccjpeg (gone upstream)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=183
chromium-134-revert-allowlist.patch
  (need updated gn anyway)
- bump buildrequires for gn to 0.20250306

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=184
gtk-414.patch (reverse apply since our gtk4 is too old)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=185
- Chromium 134.0.6998.88
  (stable released 2025-03-11) (boo#1239216)
  * CVE-2025-1920: Type Confusion in V8
  * CVE-2025-2135: Type Confusion in V8
  * CVE-TBD: Out of bounds write in GPU
  * CVE-2025-2136: Use after free in Inspector
  * CVE-2025-2137: Out of bounds read in V8

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=186
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=187
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=188
(build fail after ffmpeg updated from 4.4 to 4.4.5 in code15)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=190
(stable released 2025-03-20) (boo#1239819)
  * CVE-2025-2476: Use after free in Lens 

- use rust1.85 

- drop chromium-94-ffmpeg-roll.patch
  (build fail after ffmpeg updated from 4.4 to 4.4.5 in code15)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=191
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=192
(beta release 2025-03-20)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=193
(beta release 2025-03-26)

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=195
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=197
(beta release 2025-04-03)
- dropped patches:
  fix-build-with-pipewire-1.3.82.patch (upstream)
- modified patches:
  chromium-125-compiler.patch (context)
  gtk-414.patch (one more place with GSK_SUBSURFACE_NODE)
- bump esbuild from 0.24.0 to 0.25.1
  * Fix incorrect paths in inline source maps (#4070, #4075, #4105)
  * Fix invalid generated source maps (#4080, #4082, #4104, #4107)
  * Fix a regression with non-file source map paths (#4078)
  * Update Go from 1.23.5 to 1.23.7 (#4076, #4077)

- add patch chromium-135-add_map_droppable.patch
  add MAP_DROPPABLE introduced by recent QT
  (boo#1238826, boo#1239780)

- Chromium 135.0.7049.52
  (stable release 2025-04-01) (boo#1240555)
  * CVE-2025-3066: Use after free in Navigations
  * CVE-2025-3067: Inappropriate implementation in Custom Tabs
  * CVE-2025-3068: Inappropriate implementation in Intents
  * CVE-2025-3069: Inappropriate implementation in Extensions
  * CVE-2025-3070: Insufficient validation of untrusted input in Extensions
  * CVE-2025-3071: Inappropriate implementation in Navigations
  * CVE-2025-3072: Inappropriate implementation in Custom Tabs
  * CVE-2025-3073: Inappropriate implementation in Autofill
  * CVE-2025-3074: Inappropriate implementation in Downloads

- drop chromium-134-revert-allowlist.patch

OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=199
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=200
OBS-URL: https://build.opensuse.org/package/show/network:chromium/chromium-beta?expand=0&rev=201
updated ffmpeg-new-channel-layout.patch
add chromium-9fdfe846b61d5163f210d587735c83f1871cf958.patch
just reverting all recent commits in the ffmpeg interface is pointless
(only apply ppc patches on ppc)
(at least until we ever get ffmpeg7 in code15)
to fix build of in-tree ffmpeg copy on ppc64le (used on code15)
Merge 'chromium-beta/main' up to 28ba4454d7
autogits_workflow_pr_bot requested review from bigironman 2025-09-03 17:13:47 +02:00
autogits_workflow_pr_bot requested review from legaldb 2025-09-03 17:13:47 +02:00
autogits_workflow_pr_bot requested review from lkocman-factory 2025-09-03 17:13:48 +02:00
autogits_workflow_pr_bot requested review from maxlin_factory 2025-09-03 17:13:48 +02:00
autogits_workflow_pr_bot requested review from smithfarm 2025-09-03 17:13:49 +02:00
Author
Contributor

Needs pool/gn#1

Needs https://src.opensuse.org/pool/gn/pulls/1
Member

Legal review in progress.

Legal review [in progress](https://legaldb.suse.de/reviews/details/464257).
Member

Legal reviewed by dec16180 as acceptable_by_lawyer:

Reviewed ok
Legal reviewed by *dec16180* as [acceptable_by_lawyer](https://legaldb.suse.de/reviews/details/464257): ``` Reviewed ok ```
legaldb approved these changes 2025-09-04 16:23:12 +02:00
maxlin_factory approved these changes 2025-09-04 16:25:16 +02:00
autogits_workflow_pr_bot removed review request for bigironman 2025-09-04 16:27:08 +02:00
autogits_workflow_pr_bot removed review request for lkocman-factory 2025-09-04 16:27:08 +02:00
autogits_workflow_pr_bot removed review request for smithfarm 2025-09-04 16:27:08 +02:00
AndreasStieger manually merged commit 441316e535 into leap-16.0 2025-09-04 16:27:17 +02:00
Sign in to join this conversation.