Commit graph

78 commits

Author SHA1 Message Date
Than Ngo
2a9bd95cc9 - Enable system libcxx
- Fix link error when building with system libcxx
- Apply memory-allocator-dcheck-assert-fix for aarch64
2025-12-01 21:53:04 +09:00
LuK1337
592b771cbb Backport Wayland DnD bug fix from upstream 2025-12-01 21:53:02 +09:00
Than Ngo
125d451ec5 - Update to 142.0.7444.175
- * High CVE-2025-13223: Type Confusion in V8
- * High CVE-2025-13224: Type Confusion in V8
2025-12-01 21:52:46 +09:00
Asahi Lina
975764e257 Update to cef-142.0.14+gceaf578 (rhbz#2413981) 2025-11-18 17:23:07 +09:00
Than Ngo
0d600b2ab3 Fix FTBFS caused by rust-1.88 on EL9 2025-11-18 17:03:19 +09:00
Than Ngo
7ef7af094e Fix FTBFS - epel9 has new rust-1.88, dropp chromium-134-rust-libadler2.patch 2025-11-18 17:03:16 +09:00
Asahi Lina
674820d49c Disable broken patches
Chromium update broke this patch. It's Mac-only, so disable it.

[skip changelog]
2025-11-15 19:51:45 +09:00
Than Ngo
8707dcd994 - Update to 142.0.7444.162
- * High CVE-2025-13042: Inappropriate implementation in V8
2025-11-15 04:40:46 +09:00
Dominik 'Rathann' Mierzejewski
22c176d500 Rebuilt for FFmpeg 8 2025-11-11 17:21:01 +01:00
Asahi Lina
0159773b24 Update to cef-142.0.10+g29548e2 (rhbz#2413981) 2025-11-11 17:32:15 +09:00
Than Ngo
2c29b05488 Update to 142.0.7444.134 (rhbz#2413621)
- * High CVE-2025-12725: Out of bounds write in WebGPU
- * High CVE-2025-12726: Inappropriate implementation in Views
- * High CVE-2025-12727: Inappropriate implementation in V8
- * Medium CVE-2025-12728: Inappropriate implementation in Omnibox
- * Medium CVE-2025-12729: Inappropriate implementation in Omnibox
2025-11-09 22:05:49 +09:00
Than Ngo
0942b479c2 Add CVEs in changelog
-   * High CVE-2025-12428: Type Confusion in V8
-   * High CVE-2025-12429: Inappropriate implementation in V8
-   * High CVE-2025-12430: Object lifecycle issue in Media
-   * High CVE-2025-12431: Inappropriate implementation in Extensions
-   * High CVE-2025-12432: Race in V8
-   * High CVE-2025-12433: Inappropriate implementation in V8
-   * High CVE-2025-12036: Inappropriate implementation in V8
-   * Medium CVE-2025-12434: Race in Storage
-   * Medium CVE-2025-12435: Incorrect security UI in Omnibox
-   * Medium CVE-2025-12436: Policy bypass in Extensions
-   * Medium CVE-2025-12437: Use after free in PageInfo
-   * Medium CVE-2025-12438: Use after free in Ozone
-   * Medium CVE-2025-12439: Inappropriate implementation in App-Bound Encryption
-   * Low CVE-2025-12440: Inappropriate implementation in Autofill
-   * Medium CVE-2025-12441: Out of bounds read in V8
-   * Medium CVE-2025-12443: Out of bounds read in WebXR
-   * Low CVE-2025-12444: Incorrect security UI in Fullscreen UI
-   * Low CVE-2025-12445: Policy bypass in Extensions
-   * Low CVE-2025-12446: Incorrect security UI in SplitView
-   * Low CVE-2025-12447: Incorrect security UI in Omnibox
2025-11-09 22:05:49 +09:00
Than Ngo
d33f56a8fe Update spec file for the FTBFS on EL9
[skip changelog]
2025-11-09 22:05:49 +09:00
Than Ngo
7fb62cfe8f Fixed FTBFS due to old ffmpeg-5.x on EL9
[skip changelog]
2025-11-09 22:05:49 +09:00
Dominik 'Rathann' Mierzejewski
4abefb93c7 Rebuilt for FFmpeg 8 2025-11-04 23:46:50 +01:00
Than Ngo
dde15b4d42 Update to 142.0.7444.59
- * Update to cef-142.0.6+ga56110d (Asahi Lina) (beta)
- * Refreshed ppc64le patches
- * Refreshed system-brotli patch
- * Refreshed clang++-unknown-argument patch
- * Refreshed split-threshold-for-reg-with-hint patch
- * Fixed some FTBFS caused by missing header files
- * Fixed FTBFS caused by old rust compiler
- * Fixed FTBFS caused by new glibc-2.42 in Rawhide
- * Fixed FTBFS caused by old python-3.9.x in EL8/9
- * Dropped obsoleted chromium-141-el9-ffmpeg-5.x-duration.patch for old ffmpeg on EL9
2025-10-30 21:57:11 +09:00
Than Ngo
0f0c5cf790 Update to 141.0.7390.122
- * High CVE-2025-12036 chromium: Inappropriate implementation in V8
2025-10-30 20:33:53 +09:00
Than Ngo
d12d52e97e Update 141.0.7390.107
- * High CVE-2025-11756: Use after free in Safe Browsing
2025-10-30 20:33:53 +09:00
Than Ngo
a860d6d748 Update to 141.0.7390.76 2025-10-30 20:33:53 +09:00
Than Ngo
f7c2acbf51 Update to 141.0.7390.65
- * High CVE-2025-11458: Heap buffer overflow in Sync
- * High CVE-2025-11460: Use after free in Storage
- * Medium CVE-2025-11211: Out of bounds read in WebCodecs
- remove 0001-Change-use-of-removed-intrinsic.patch as it is included in
  141.0.7390.65
2025-10-30 20:33:53 +09:00
Tom Stellard
5e2ea7843f Fix build with clang-22
[skip changelog]
2025-10-30 20:33:53 +09:00
Than Ngo
bdf0e5a857 Update to 141.0.7390.54
- * Update to cef-141.0.11+g7e73ac4 (rhbz#2402447) (Asahi Lina)
- * High CVE-2025-11205: Heap buffer overflow in WebGPU
- * High CVE-2025-11206: Heap buffer overflow in Video
- * Medium CVE-2025-11207: Side-channel information leakage in Storage
- * Medium CVE-2025-11208: Inappropriate implementation in Media
- * Medium CVE-2025-11209: Inappropriate implementation in Omnibox
- * Medium CVE-2025-11210: Side-channel information leakage in Tab
- * Medium CVE-2025-11211: Out of bounds read in Media
- * Medium CVE-2025-11212: Inappropriate implementation in Media
- * Medium CVE-2025-11213: Inappropriate implementation in Omnibox
- * Medium CVE-2025-11215: Off by one error in V8
- * Low CVE-2025-11216: Inappropriate implementation in Storage
- * Low CVE-2025-11219: Use after free in V8
- Refreshed ppc64le patches
- Fixed issue with incorrect display of the links on startpage in Darkmode
- Fixed FTBFS - error: no member named 'bPsnrY' in 'Source_Picture_s'
- Fixed, DebugInfo packages aren't being produced
- Refreshed rust-clanglib patch
- Fixed FTBFS due to old ffmpeg on Epel9
- Fixed FTBFS - error: invalid application of 'sizeof' to an incomplete type 'blink::CSSStyleSheet'
- Fixed FTBFS due to missing header files
2025-10-30 20:33:53 +09:00
Asahi Lina
91dd791eda cherry-pick.sh: Handle empty better
[skip changelog]
2025-10-29 15:28:29 +09:00
Than Ngo
9397c6d665 Fix chromium FTBFS on EL9 with error: undefined symbol: __rust_no_alloc_shim_is_unstable
[skip changelog]
2025-09-30 22:13:03 +09:00
Asahi Lina
52b242d356 cherry-pick.sh: Prune empty commits
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
4b5a9c1270 Update to 140.0.7339.207
- * CVE-2025-10890: Side-channel information leakage in V8
- * CVE-2025-10891: Integer overflow in V8
- * CVE-2025-10892: Integer overflow in V8
2025-09-30 22:13:00 +09:00
Than Ngo
7245726806 Add __rust_alloc_error_handler_should_panic_v2 to fix the build error:
- undefined symbol: __rust_no_alloc_shim_is_unstab

[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
7c5bc037b0 Fix FTBFS on F44 - undefined symbol: __rust_no_alloc_shim_is_unstable
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
a7f42a823b Update to 140.0.7339.185
- * CVE-2025-10585: Type Confusion in V8
- * CVE-2025-10500: Use after free in Dawn
- * CVE-2025-10501: Use after free in WebRTC
- * CVE-2025-10502: Heap buffer overflow in ANGLE
- * Fix rendering issue on epel9
2025-09-30 22:13:00 +09:00
Than Ngo
933e2cdd13 Update to 140.0.7339.127
- * CVE-2025-10200: Use after free in Serviceworker
- * CVE-2025-10201: Inappropriate implementation in Mojo
2025-09-30 22:13:00 +09:00
Than Ngo
9afce20744 Workaround for build error due to old ffmpeg 5.x on el9
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
01f395e838 Fix FTBFS: undefined symbol: __rust_no_alloc_shim_is_unstable on epel
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
aefe477f6c Drop ffmpeg-5.x-reordered_opaque patch as it's merged in upstream
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
1d67505bcf rebase swiftshader-fix-build to fix build error on ppc64le
- drop Include-cstddef-to-fix-build fix-ppc64-rust_png-build-error

[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
5f9c02e656 Fix file list
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
418ced779a rebase clang++-unknown-argument patch
[skip changelog]
2025-09-30 22:13:00 +09:00
Than Ngo
28dc83db64 Update to 140.0.7339.80 (rhbz#2396308)
- * Update to cef-140.1.15+gfaef09b (rhbz#2380429) (Asahi Lina)
- * CVE-2025-9864: Use after free in V8
- * CVE-2025-9865: Inappropriate implementation in Toolbar
- * CVE-2025-9866: Inappropriate implementation in Extensions
- * CVE-2025-9867: Inappropriate implementation in Downloads
2025-09-30 22:13:00 +09:00
Asahi Lina
c8e295e571 cherry-pick.sh: Fix error path
[skip changelog]
2025-09-30 22:12:57 +09:00
Than Ngo
5f5eceb27f - Update to 139.0.7258.154
- * CVE-2025-9478: Use after free in ANGLE
2025-08-29 19:59:59 +09:00
Asahi Lina
168e14b56b Update to cef 139.0.37+gb457b0b (rhbz#2391243) 2025-08-29 19:59:59 +09:00
Than Ngo
7e2484b8cb - Updated to 139.0.7258.138
- * CVE-2025-9132: Out of bounds write in V8
2025-08-29 19:57:58 +09:00
Asahi Lina
eb81941eaf Update to cef-139.0.26+g9d80e0d 2025-08-21 22:30:33 +09:00
Than Ngo
8ca74c66e4 Fix rhbz#2387446, FTBFS with rust-1.89.0
[skip changelog]
2025-08-14 22:05:09 +09:00
Than Ngo
c8e140d475 - Updated to 139.0.7258.127 (rhbz#2381869)
- * CVE-2025-8879: Heap buffer overflow in libaom
- * CVE-2025-8880: Race in V8
- * CVE-2025-8901: Out of bounds write in ANGLE
- * CVE-2025-8881: Inappropriate implementation in File Picker
- * CVE-2025-8882: Use after free in Aura
2025-08-14 22:05:09 +09:00
Than Ngo
118f391e94 - Updated to 139.0.7258.66
- Asahi Lina: Update to cef-139.0.20+g60bd77d
- * CVE-2025-8576: Use after free in Extensions
- * CVE-2025-8578: Use after free in Cast
- * CVE-2025-8579: Inappropriate implementation in Gemini Live in Chrome
- * CVE-2025-8580: Inappropriate implementation in Filesystems
- * CVE-2025-8581: Inappropriate implementation in Extensions
- * CVE-2025-8582: Insufficient validation of untrusted input in DOM
- * CVE-2025-8583: Inappropriate implementation in Permissions
2025-08-14 22:05:04 +09:00
Than Ngo
8f60fa14a7 - Update to 138.0.7204.183
- * CVE-2025-8292: Use after free in Media Stream
2025-08-14 21:53:41 +09:00
Than Ngo
0902ffe4c0 - Update to 138.0.7204.168
- * CVE-2025-8010: Type Confusion in V8
- * CVE-2025-8011: Type Confusion in V8
2025-08-14 21:53:41 +09:00
Tom Stellard
1f259410de Backport fix for build failure with clang-21 2025-08-14 12:53:20 +00:00
Dominik Mierzejewski
8402dfb7ae drop unused yasm build dependency
part of https://fedoraproject.org/wiki/Changes/DeprecateYASM
2025-07-25 01:49:51 +02:00
Fedora Release Engineering
797ca19a13 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild 2025-07-23 18:11:13 +00:00