head 1.1; access; symbols; locks; strict; comment @ * @; 1.1 date 2026.08.09.06.31.18; author kikadf; state Exp; branches; next ; commitid 8RN084OnLnGuCVQG; desc @@ 1.1 log @ chromium: update to 151.0.7922.108 * 151.0.7922.108 This update includes 41 security fixes. Please see the Chrome Security Page for more information. [TBD][499602793] Critical CVE-2026-19137: Use after free in WebGL. Reported by anonymous on 2026-04-05 [N/A][524824288] Critical CVE-2026-19149: Use after free in Aura. Reported by Google on 2026-06-17 [N/A][532941869] Critical CVE-2026-19154: Use after free in Skia. Reported by Google on 2026-07-09 [N/A][534903095] Critical CVE-2026-19157: Out of bounds write in ANGLE. Reported by Google on 2026-07-14 [TBD][537729021] Critical CVE-2026-19170: Use after free in WebGL. Reported by Muhammad Alifa Ramdhan, Pan ZhenPeng, Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. on 2026-07-22 [N/A][537838324] Critical CVE-2026-19172: Use after free in Views. Reported by Google on 2026-07-22 [$5000][537390933] High CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks. Reported by Sven Dysthe (@@svn-dys) on 2026-07-21 [$500][536945254] High CVE-2026-19168: Inappropriate implementation in V8. Reported by XBOW and triaged by Andrés Luksenberg on 2026-07-20 [N/A][500097298] High CVE-2026-19138: Heap buffer overflow in CrashReporting. Reported by Google on 2026-04-06 [N/A][511731805] High CVE-2026-19139: Race in CredentialProvider. Reported by Google on 2026-05-10 [N/A][513044017] High CVE-2026-19140: Use after free in GPU. Reported by Google on 2026-05-14 [N/A][513602949] High CVE-2026-19141: Use after free in Resources. Reported by Google on 2026-05-15 [N/A][515428251] High CVE-2026-19142: Use after free in Views. Reported by Google on 2026-05-21 [N/A][517772612] High CVE-2026-19143: Insufficient validation of untrusted input in WebAPKs. Reported by Google on 2026-05-29 [N/A][520167277] High CVE-2026-19144: Use after free in HTML. Reported by Google on 2026-06-05 [N/A][521878431] High CVE-2026-19145: Use after free in Translate. Reported by Google on 2026-06-09 [N/A][523713150] High CVE-2026-19146: Uninitialized Use in GPU. Reported by Google on 2026-06-14 [N/A][524439798] High CVE-2026-19147: Use after free in Aura. Reported by Google on 2026-06-16 [N/A][524460000] High CVE-2026-19148: Out of bounds write in GPU. Reported by Google on 2026-06-16 [N/A][526380803] High CVE-2026-19150: Inappropriate implementation in V8. Reported by Google on 2026-06-22 [N/A][530663440] High CVE-2026-19151: Use after free in V8. Reported by Google on 2026-07-02 [N/A][531165110] High CVE-2026-19152: Inappropriate implementation in Navigation. Reported by Google on 2026-07-04 [N/A][532939327] High CVE-2026-19153: Insufficient validation of untrusted input in Workers. Reported by Google on 2026-07-09 [N/A][533053621] High CVE-2026-19155: Use after free in Payments. Reported by Google on 2026-07-09 [TBD][533331920] High CVE-2026-19156: Heap buffer overflow in Base. Reported by Viktoria Zlatinova on 2026-07-10 [N/A][535749174] High CVE-2026-19158: Use after free in Views. Reported by Google on 2026-07-17 [N/A][536067175] High CVE-2026-19159: Use after free in Views. Reported by Google on 2026-07-17 [N/A][536068737] High CVE-2026-19160: Uninitialized Use in Skia. Reported by Google on 2026-07-17 [N/A][536165038] High CVE-2026-19161: Uninitialized Use in Skia. Reported by Google on 2026-07-18 [TBD][536271629] High CVE-2026-19162: Out of bounds write in V8. Reported by OpenAI Codex Security (amyb) on 2026-07-19 [N/A][536449742] High CVE-2026-19163: Use after free in Media. Reported by Google on 2026-07-19 [N/A][536470854] High CVE-2026-19164: Insufficient validation of untrusted input in Codecs. Reported by Google on 2026-07-19 [TBD][536512612] High CVE-2026-19165: Use after free in Extensions. Reported by @@bean5oup on 2026-07-19 [TBD][536584251] High CVE-2026-19166: Use after free in Web Authentication. Reported by heesun on 2026-07-20 [N/A][536666274] High CVE-2026-19167: Integer overflow in GPU. Reported by Google on 2026-07-20 [N/A][537832446] High CVE-2026-19171: Use after free in Media. Reported by Google on 2026-07-22 [TBD][538332338] High CVE-2026-19173: Out of bounds write in Skia. Reported by Vu Van Tien (@@n0_Be3r) on 2026-07-24 [TBD][538378084] High CVE-2026-19174: Integer overflow in V8. Reported by Seunghyun Lee (@@0x10n) of QED Audit (qedaudit.io) on 2026-07-24 [N/A][540138836] High CVE-2026-19175: Use after free in Payments. Reported by Google on 2026-07-29 [TBD][540157141] High CVE-2026-19176: Use after free in Skia. Reported by WinD39 - Huynh Dinh Vu on 2026-07-29 [TBD][540289900] High CVE-2026-19177: Insufficient validation of untrusted input in UI. Reported by Fabian Wahle (Hap Security) on 2026-07-29 * 151.0.7922.71 This update includes 370 security fixes. Please see the Chrome Security Page for more information. See: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html @ text @$NetBSD$ * Part of patchset to build chromium on NetBSD * Based on OpenBSD's chromium patches, and pkgsrc's qt5-qtwebengine patches --- media/base/audio_bus.h.orig 2026-08-05 20:17:42.000000000 +0000 +++ media/base/audio_bus.h @@@@ -110,6 +110,23 @@@@ class MEDIA_EXPORT AudioBus { // Returns the currently used bitstream data. BitstreamData bitstream_data() const { return bitstream_data_; } + // Note: DEPRECATED, prefer spanified version instead. + // Overwrites the sample values stored in this AudioBus instance with values + // from a given interleaved `source_buffer` with expected layout + // [ch0, ch1, ..., chN, ch0, ch1, ...] and sample values in the format + // corresponding to the given SourceSampleTypeTraits. + // The sample values are converted to float values by means of the method + // convert_to_float32() provided by the SourceSampleTypeTraits. For a list of + // ready-to-use SampleTypeTraits, see file audio_sample_types.h. + // If `num_frames_to_write` is less than frames(), the remaining frames are + // zeroed out. If `num_frames_to_write` is more than frames(), this results in + // undefined behavior. + // TODO(crbug.com/373960632): Delete this function. + template + void FromInterleaved( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int num_frames_to_write); + // Overwrites every sample stored in this AudioBus instance with values // from a given interleaved `source` with expected layout // [ch0, ch1, ..., chN, ch0, ch1, ...]. The sample values are converted to @@@@ -122,6 +139,17 @@@@ class MEDIA_EXPORT AudioBus { base::span source, bool zero_remaining_frames = false); + // Note: DEPRECATED, prefer spanified version instead. + // Similar to FromInterleaved...(), but overwrites the frames starting at a + // given offset `write_offset_in_frames` and does not zero out frames that are + // not overwritten. + // TODO(crbug.com/373960632): Delete this function. + template + void FromInterleavedPartial( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int write_offset_in_frames, + int num_frames_to_write); + // Similar to FromInterleaved...(), but overwrites the frames starting at a // given offset `write_offset`, without zero'ing other frames. template @@@@ -129,6 +157,18 @@@@ class MEDIA_EXPORT AudioBus { base::span source, size_t write_offset); + // Note: DEPRECATED, prefer spanified version instead. + // Reads the sample values stored in this AudioBus instance and places them + // into the given `dest_buffer` in interleaved format using the sample format + // specified by TargetSampleTypeTraits. For a list of ready-to-use + // SampleTypeTraits, see file audio_sample_types.h. If `num_frames_to_read` is + // larger than frames(), this results in undefined behavior. + // TODO(crbug.com/373960632): Delete this function. + template + void ToInterleaved( + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest_buffer) const; + // Fills `dest` with the sample values in this AudioBus instance. Converts the // samples to the format specified by `TargetSampleTypeTraits` and places them // in interleaved format. @@@@ -138,6 +178,16 @@@@ class MEDIA_EXPORT AudioBus { void ToInterleaved( base::span dest) const; + // Note: DEPRECATED, prefer spanified version instead. + // Similar to ToInterleaved(), but reads the frames starting at a given + // offset `read_offset_in_frames`. + // TODO(crbug.com/373960632): Delete this function. + template + void ToInterleavedPartial( + int read_offset_in_frames, + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest_buffer) const; + // Similar to ToInterleaved...(), but reads the frames starting at a given // `read_offset`. // Note: `dest` must have a multiple of `channels()` elements, but it does not @@@@ -243,6 +293,12 @@@@ class MEDIA_EXPORT AudioBus { template static void CopyConvertFromInterleavedSourceToAudioBus( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int write_offset_in_frames, + int num_frames_to_write, + AudioBus* dest); + template + static void CopyConvertFromInterleavedSourceToAudioBus( base::span source, size_t write_offset, AudioBus* dest); @@@@ -250,6 +306,12 @@@@ class MEDIA_EXPORT AudioBus { template static void CopyConvertFromAudioBusToInterleavedTarget( const AudioBus* source, + int read_offset_in_frames, + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest_buffer); + template + static void CopyConvertFromAudioBusToInterleavedTarget( + const AudioBus* source, size_t read_offset, base::span dest); @@@@ -298,6 +360,17 @@@@ class MEDIA_EXPORT AudioBus { // Delegates to FromInterleavedPartial() template void AudioBus::FromInterleaved( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int num_frames_to_write) { + FromInterleavedPartial(source_buffer, 0, + num_frames_to_write); + // Zero any remaining frames. + ZeroFramesPartial(num_frames_to_write, frames_ - num_frames_to_write); +} + +// Delegates to FromInterleavedPartial() +template +void AudioBus::FromInterleaved( base::span source, bool zero_remaining_frames) { const size_t source_frame_count = get_frame_count(source, channels()); @@@@ -318,6 +391,16 @@@@ void AudioBus::FromInterleaved( template void AudioBus::FromInterleavedPartial( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int write_offset_in_frames, + int num_frames_to_write) { + CheckOverflow(write_offset_in_frames, num_frames_to_write, frames_); + CopyConvertFromInterleavedSourceToAudioBus( + source_buffer, write_offset_in_frames, num_frames_to_write, this); +} + +template +void AudioBus::FromInterleavedPartial( base::span source, size_t write_offset) { const size_t frame_count = get_frame_count(source, channels()); @@@@ -332,6 +415,15 @@@@ void AudioBus::FromInterleavedPartial( // Delegates to ToInterleavedPartial() template void AudioBus::ToInterleaved( + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest_buffer) const { + ToInterleavedPartial(0, num_frames_to_read, + dest_buffer); +} + +// Delegates to ToInterleavedPartial() +template +void AudioBus::ToInterleaved( base::span dest) const { const size_t frames_count = get_frame_count(dest, channels()); CHECK_EQ(frames_count, frames_); @@@@ -340,6 +432,16 @@@@ void AudioBus::ToInterleaved( template void AudioBus::ToInterleavedPartial( + int read_offset_in_frames, + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest) const { + CheckOverflow(read_offset_in_frames, num_frames_to_read, frames_); + CopyConvertFromAudioBusToInterleavedTarget( + this, read_offset_in_frames, num_frames_to_read, dest); +} + +template +void AudioBus::ToInterleavedPartial( size_t read_offset, base::span dest) const { const size_t frame_count = get_frame_count(dest, channels()); @@@@ -350,6 +452,28 @@@@ void AudioBus::ToInterleavedPartial( this, read_offset, dest); } +// TODO(chfremer): Consider using vector instructions to speed this up, +// https://crbug.com/619628 +template +void AudioBus::CopyConvertFromInterleavedSourceToAudioBus( + const typename SourceSampleTypeTraits::ValueType* source_buffer, + int write_offset_in_frames, + int num_frames_to_write, + AudioBus* dest) { + const int channels = dest->channels(); + for (int ch = 0; ch < channels; ++ch) { + AudioBus::Channel channel_data = dest->channel(ch); + for (int target_frame_index = write_offset_in_frames, + read_pos_in_source = ch; + target_frame_index < write_offset_in_frames + num_frames_to_write; + ++target_frame_index, read_pos_in_source += channels) { + auto source_value = UNSAFE_TODO(source_buffer[read_pos_in_source]); + channel_data[target_frame_index] = + SourceSampleTypeTraits::ToFloat(source_value); + } + } +} + template void AudioBus::CopyConvertFromInterleavedSourceToAudioBus( base::span source, @@@@ -372,6 +496,27 @@@@ void AudioBus::CopyConvertFromInterleave } } +// TODO(chfremer): Consider using vector instructions to speed this up, +// https://crbug.com/619628 +template +void AudioBus::CopyConvertFromAudioBusToInterleavedTarget( + const AudioBus* source, + int read_offset_in_frames, + int num_frames_to_read, + typename TargetSampleTypeTraits::ValueType* dest_buffer) { + const int channels = source->channels(); + for (int ch = 0; ch < channels; ++ch) { + AudioBus::ConstChannel channel_data = source->channel(ch); + for (int source_frame_index = read_offset_in_frames, write_pos_in_dest = ch; + source_frame_index < read_offset_in_frames + num_frames_to_read; + ++source_frame_index, write_pos_in_dest += channels) { + float sourceSampleValue = channel_data[source_frame_index]; + UNSAFE_TODO(dest_buffer[write_pos_in_dest]) = + TargetSampleTypeTraits::FromFloat(sourceSampleValue); + } + } +} + template void AudioBus::CopyConvertFromAudioBusToInterleavedTarget( const AudioBus* source, @