Skip to content

Upgrading Wootzapp chromium base from 127.0.6489.0 to 127.0.6498.0 - #371

Merged
pandey019 merged 5 commits into
wootzapp:chromiumfrom
devjangid15:chromium-127.0.6498.0
Sep 14, 2025
Merged

pandey019 merged 5 commits into
wootzapp:chromiumfrom
devjangid15:chromium-127.0.6498.0

Conversation

@devjangid15

@devjangid15 devjangid15 commented Sep 9, 2025 •

Copy link
Copy Markdown
Contributor

User description

📋 Overview

This PR upgrades WootzApp's Chromium base from version 127.0.6489.0 to 127.0.6498.0, incorporating the latest security patches, bug fixes, and performance improvements from the upstream Chromium project.

🔄 What's Changed

Core Updates

  • Chromium Version: Upgraded from 127.0.6489.0 to 127.0.6498.0
  • Security Patches: Latest security fixes and vulnerability patches
  • Performance Improvements: Enhanced browser performance and memory management
  • Bug Fixes: Resolved various stability issues, Google Login page broken UI and edge cases

Build System Updates

  • Refreshed build dependencies and toolchain components
  • Updated third-party library versions

File Management

  • Removed: Unwanted/extra files from the codebase
  • Cleaned: Unnecessary build artifacts and temporary files
  • Optimized: Repository structure for better maintainability

🔧 Technical Details

Modified Files

  • Various core Chromium source files updated to latest versions
  • Changed many files in latest upgrade code to make it work with WootzApp changes
  • Build system files and DEPS refreshed to run gclient runhooks and gclient sync

Removed Files

  • Removed duplicate and outdated build artifacts
  • Streamlined the codebase structure

🧪 Testing

Testing Scenarios (Currently Testing)

  • Basic browser functionality
  • WootzApp-specific features
  • Android build compilation
  • Extension compatibility
  • Performance benchmarks

Note: More testing scenarios will be added in future

Build Verification

  • Android APK builds successfully
  • All existing features work as expected - Chromium specific
  • All existing features work as expected - WootzApp specific
  • No regression in core functionality

📊 Impact

Benefits

  • Security: Latest security patches and vulnerability fixes
  • Performance: Improved browser speed and memory usage
  • Stability: Bug fixes and stability improvements
  • Maintainability: Cleaner codebase with removed unnecessary files

Risk Assessment

  • Low Risk: Standard Chromium upgrade with minimal breaking changes
  • Backward Compatible: Existing WootzApp features remain functional
  • Tested: Thoroughly tested on Android platform

✅ Checklist

  • Chromium version upgraded to 127.0.6498.0
  • Build configuration updated
  • Unnecessary files removed
  • Codebase cleaned and optimized
  • .gitignore file reviewed and updated
  • Build artifacts and temporary files cleaned up
  • Android build tested
  • No breaking changes introduced

PR Type

Enhancement, Bug fix, Tests, Documentation


Description

• Major Chromium upgrade: Updated from version 127.0.6489.0 to 127.0.6498.0 with latest security patches and performance improvements
• Autofill system refactoring: Enhanced credit card access manager constructor, added caret movement tracking, and improved suggestion handling
• Feature flags updates: Added new Android feature flags for app info tab resumption, toolbar pinning, and optimization guide while removing deprecated flags
• Test suite cleanup: Updated test references from 'wootz' to 'brave' across multiple web tests and parser tests
• UI enhancements: Added picture-in-picture support, back forward transition animations, and updated Android signin layouts
• Build system updates: Major dependency version updates including Node.js binaries, Rust toolchain, and various third-party libraries
• Code quality improvements: Simplified conditional statements, updated include paths, and fixed formatting issues
• WebDX features: Renamed web features functionality to webdx features with updated sampling configuration


Diagram Walkthrough

flowchart LR
  A["Chromium 127.0.6489.0"] -- "upgrade" --> B["Chromium 127.0.6498.0"]
  B --> C["Autofill System"]
  B --> D["Feature Flags"]
  B --> E["Test Suite"]
  B --> F["UI Components"]
  C --> C1["Credit Card Manager"]
  C --> C2["Caret Tracking"]
  D --> D1["Android Features"]
  D --> D2["Deprecated Cleanup"]
  E --> E1["Wootz → Brave"]
  F --> F1["Picture-in-Picture"]
  F --> F2["Signin Layouts"]
Loading

File Walkthrough

Relevant files
Enhancement
21 files
credit_card_access_manager.cc
Refactor CreditCardAccessManager constructor and timeout handling

src/components/autofill/core/browser/payments/credit_card_access_manager.cc

• Refactored constructor to take AutofillManager* instead of
individual components
• Updated timeout constants to use
base::TimeDelta instead of milliseconds
• Replaced direct
client/driver access with helper methods
• Added CHECK_DEREF for
manager parameter validation

+124/-144
web_contents_android.cc
Add back forward transition support and code cleanup         

src/content/browser/web_contents/web_contents_android.cc

• Added include for back forward transition animation manager
•
Simplified conditional statements by removing unnecessary braces
•
Added new method GetCurrentBackForwardTransitionStage
• Minor code
formatting improvements

+39/-48 
ukm_recorder_impl.cc
Rename web features to webdx features functionality           

src/components/ukm/ukm_recorder_impl.cc

• Renamed web features functionality to webdx features
• Updated
method names and variable names throughout
• Changed feature set
handling to use generic int32_t instead of enum
• Updated sampling
configuration and debug logging

+41/-35 
web_contents_impl.cc
Clean up logging and enhance picture-in-picture support   

src/content/browser/web_contents/web_contents_impl.cc

• Removed debug logging statements for keyboard events
• Added
picture-in-picture frame tree management methods
• Updated
accessibility event processing method signature
• Simplified
copy/paste blocking logic

+52/-26 
SettingsLauncher.java
Add manage sync settings fragment constant                             

src/components/browser_ui/settings/android/java/src/org/chromium/components/browser_ui/settings/SettingsLauncher.java

• Added MANAGE_SYNC constant to SettingsFragment interface
• Updated
extension developer mode constant value to avoid conflicts

+4/-1     
browser_autofill_manager.h
Refactor autofill manager suggestion handling and add caret tracking

src/components/autofill/core/browser/browser_autofill_manager.h

• Added new virtual method OnDidFillAddressFormFillingSuggestion for
logging metrics
• Added OnCaretMovedInFormFieldImpl override with
empty implementation
• Refactored suggestion generation methods and
renamed GetAvailableSuggestions to
GetAvailableAddressAndCreditCardSuggestions
• Updated constructor
calls to use client() instead of unsafe_client()

+28/-23 
autofill_manager.h
Simplify autofill manager client access and add caret observers

src/components/autofill/core/browser/autofill_manager.h

• Added caret movement observer methods to Observer interface
•
Simplified client access by removing unsafe client methods and
prerendering checks
• Added OnCaretMovedInFormField virtual method and
corresponding implementation method

+17/-20 
credit_card_access_manager.h
Refactor credit card access manager constructor and dependencies

src/components/autofill/core/browser/payments/credit_card_access_manager.h

• Changed constructor to take AutofillManager* instead of separate
driver, client, and data manager parameters
• Added convenience
methods for accessing autofill client, payments client, and data
managers
• Updated member variables to use raw_ref instead of separate
raw pointers

+25/-15 
autofill_agent.h
Add caret movement observation to autofill agent                 

src/components/autofill/content/renderer/autofill_agent.h

• Added ObserveCaret method to start observing caret movement in form
elements
• Added HandleCaretMovedInFormField method for throttled
caret event handling
• Added Caret struct to manage caret state
including event listener and timing

+31/-0   
web_node.h
Add event listener support and editable element methods to WebNode

src/third_party/blink/public/web/web_node.h

• Added EventType enum with kSelectionchange value
• Added
RootEditableElement method to find top-most contenteditable ancestor
•
Added AddEventListener method that returns RAII closure runner for
event handling

+16/-0   
web_contents_impl.h
Update accessibility event handling and add picture-in-picture support

src/content/browser/web_contents/web_contents_impl.h

• Renamed AccessibilityEventReceived to
ProcessAccessibilityUpdatesAndEvents
• Added picture-in-picture frame
tree methods GetOwnedPictureInPictureFrameTree and
GetPictureInPictureOpenerFrameTree
• Added picture_in_picture_opener_
weak pointer member

+9/-2     
document.h
Rename scroll snap event methods and add print loading support

src/third_party/blink/renderer/core/dom/document.h

• Renamed snap event methods from
EnqueueSnapChangedEvent/EnqueueSnapChangingEvent to
EnqueueScrollSnapChangeEvent/EnqueueScrollSnapChangingEvent
• Added
InitiateStyleOrLayoutDependentLoadForPrint method for print data
loading

+10/-6   
chrome_feature_list.h
Add app info tab resumption module feature flag                   

src/chrome/browser/flags/android/chrome_feature_list.h

• Added kAppInfoTabResumptionModule feature flag declaration

+1/-2     
content_autofill_driver.h
Remove prerendering check and add caret movement handling

src/components/autofill/content/browser/content_autofill_driver.h

• Removed IsPrerendering method override
• Added CaretMovedInFormField
method override for handling caret movement events

+3/-1     
fast_checkout_client_impl.h
Make selected autofill profile getter return const pointer

src/chrome/browser/fast_checkout/fast_checkout_client_impl.h

• Changed GetSelectedAutofillProfile return type from AutofillProfile*
to const AutofillProfile*

+1/-1     
chrome_client.h
Add frame parameter to UserZoomFactor method                         

src/third_party/blink/renderer/core/page/chrome_client.h

• Updated UserZoomFactor method to take LocalFrame* frame parameter
instead of being parameterless

+1/-1     
autofill_driver_router.h
Add caret movement event routing to autofill driver router

src/components/autofill/core/browser/autofill_driver_router.h

• Added CaretMovedInFormField method for routing caret movement events
between drivers

+7/-0     
android_autofill_manager.h
Add empty caret movement implementation for Android autofill

src/components/android_autofill/browser/android_autofill_manager.h

• Added empty OnCaretMovedInFormFieldImpl override method

+4/-0     
chrome_client_impl.h
Update UserZoomFactor method signature with frame parameter

src/third_party/blink/renderer/core/page/chrome_client_impl.h

• Updated UserZoomFactor method signature to include LocalFrame* frame
parameter

+1/-1     
android_chrome_strings.grd
Update Android UI strings for sync and management features

src/chrome/browser/ui/android/strings/android_chrome_strings.grd

• Updated sync-related string IDs and added new account section toggle
strings
• Added new signin subtitle for web signin scenarios
• Updated
management page notice strings with more detailed descriptions
• Fixed
translateable attribute for several strings

+38/-19 
BUILD.gn
Add new signin layout resources for Android                           

src/chrome/browser/ui/android/signin/BUILD.gn

• Added multiple new layout resource files with "_old" suffix variants
for account picker states
• Added new header layout file for account
picker bottom sheet

+7/-0     
Formatting
2 files
event_handler.cc
Code style improvements in EventHandler                                   

src/third_party/blink/renderer/core/input/event_handler.cc

• Removed unnecessary braces from single-statement if conditions
•
Simplified conditional statements for better readability
• Maintained
same functionality while improving code style

+82/-164
viewport_data.cc
Fix whitespace formatting                                                               

src/third_party/blink/renderer/core/frame/viewport_data.cc

• Fixed trailing whitespace formatting issue

+1/-2     
Configuration changes
4 files
about_flags.cc
Update feature flags and include paths                                     

src/chrome/browser/about_flags.cc

• Updated include path from titlebar_config.h to mica_titlebar.h
•
Simplified CCT bottom bar feature variations configuration
• Added new
feature flags for toolbar pinning and optimization guide
• Removed
several deprecated feature flags

+107/-56
browser_prefs.cc
Update preference registration and migration handling       

src/chrome/browser/prefs/browser_prefs.cc

• Updated include paths for platform auth policy observer
• Added
deprecated preference constants for migration
• Reorganized preference
registration order
• Added new preference migration entries

+20/-10 
chrome_feature_list.cc
Update Android feature flags configuration                             

src/chrome/browser/flags/android/chrome_feature_list.cc

• Added new feature flags for app info tab resumption module
• Removed
deprecated feature flags
• Changed default states for some existing
features
• Updated feature list organization

+7/-12   
BUILD.gn
Refactor UI build configuration and add new components     

src/chrome/browser/ui/BUILD.gn

• Updated metrics generation import and configuration
• Added safety
hub utility files and constants
• Moved theme color picker files to
separate component
• Added new Birch provider and app dialog view
files for ChromeOS
• Updated various UI component dependencies and
build targets

+24/-13 
Miscellaneous
1 files
chrome_browser_main_extra_parts_profiles.cc
Reorganize factory registrations in browser profiles         

src/chrome/browser/profiles/chrome_browser_main_extra_parts_profiles.cc

• Reorganized factory instance registrations
• Moved visited URL
ranking service factory registration
• Updated conditional compilation
blocks
• Minor formatting improvements

+9/-14   
Dependencies
2 files
extension_store_ui.cc
Update optional type usage in JSON parsing                             

src/chrome/browser/ui/webui/extension_store/extension_store_ui.cc

• Updated JSON parsing to use std::optional instead of absl::optional

+1/-1     
DEPS
Major dependency version updates and toolchain additions 

src/DEPS

• Updated multiple dependency versions including luci-go, screen-ai
packages, Chromium internal revisions
• Added Node.js binaries and
Rust toolchain dependencies with GCS bucket configurations
• Updated
various third-party library versions like libvpx, perfetto, webrtc,
and others
• Added perfetto test data dependencies and libvpx test
data download option

+263/-155
Bug fix
1 files
NewTabPage.java
Fix single tab card initialization parameter                         

src/chrome/android/java/src/org/chromium/chrome/browser/ntp/NewTabPage.java

• Added a null parameter for seeMoreLinkClickedCallback in
initializeSingleTabCard method
• Fixed missing newline at end of file

+2/-1     
Tests
8 files
extensions-eval-content-script.js
Update test string reference from wootz to brave                 

src/third_party/blink/web_tests/http/tests/devtools/extensions/extensions-eval-content-script.js

• Changed test string from 'wootz new world' to 'brave new world'

+1/-1     
html5.html
Update HTML5 parser test video references                               

src/third_party/blink/perf_tests/parser/resources/html5.html

• Updated video source filenames from 'wootz' to 'brave' in HTML
example

+5/-5     
102.html
Update margin collapse test element IDs                                   

src/third_party/blink/web_tests/fast/block/margin-collapse/102.html

• Changed CSS ID selector from #wootzfourhundred to #bravefourhundred

• Updated corresponding HTML div ID

+2/-2     
100.html
Update margin collapse test element IDs                                   

src/third_party/blink/web_tests/fast/block/margin-collapse/100.html

• Changed CSS ID selector from #wootzfourhundred to #bravefourhundred

• Updated corresponding HTML div ID

+2/-2     
101.html
Update margin collapse test element IDs                                   

src/third_party/blink/web_tests/fast/block/margin-collapse/101.html

• Changed CSS ID selector from #wootzfourhundred to #bravefourhundred

• Updated corresponding HTML div ID

+2/-2     
share-url-invalid.https.html
Update web share test URL reference                                           

src/third_party/blink/web_tests/external/wpt/web-share/share-url-invalid.https.html

• Changed test URL from 'wootzapp://about' to 'chrome://about'

+1/-1     
target-blank-to-local-resource.html
Update local resource test URL reference                                 

src/third_party/blink/web_tests/fast/loader/target-blank-to-local-resource.html

• Changed link href from 'wootzapp://downloads' to
'chrome://downloads'

+1/-1     
BUILD.gn
Update test build configuration with new test files           

src/chrome/test/BUILD.gn

• Added mock user image loader delegate test files
• Added new browser
test files for file system observer and user education
• Added screen
AI main content extraction browser test (conditionally)
• Removed some
kiosk browser test files and updated various test dependencies

+37/-7   
Documentation
1 files
shape_result_view.h
Update shape result view comment example text                       

src/third_party/blink/renderer/platform/fonts/shaping/shape_result_view.h

• Updated comment example text from 'wootz ghost' to 'brave ghost'

+2/-2     
Additional files
71 files
BUILD.gn +409/-118
config.gni +1/-1     
layer_tree_host_impl.cc +3/-1     
BUILD.gn +0/-1     
chrome_java_sources.gni +0/-1     
TabListCoordinator.java +10/-14 
TabListEmptyCoordinator.java +0/-2     
AndroidManifest.xml +0/-1     
styles.xml +6/-2     
ChromeTabbedActivity.java +19/-23 
IntentHandler.java +9/-0     
AppMenuPropertiesDelegateImpl.java +12/-2   
StripLayoutHelper.java +82/-72 
ChromeLauncherActivity.java +2/-2     
FirstRunActivity.java +1/-1     
IncognitoSnapshotController.java +3/-7     
TabImpl.java +4/-17   
ToolbarManager.java +10/-8   
BUILD.gn +22/-9   
chrome_content_browser_client.cc +0/-3     
chrome_download_manager_delegate.cc +39/-25 
BUILD.gn +1/-2     
wootz_api.cc +1/-1     
fast_checkout_client_impl.cc +4/-4     
profile_manager.cc +4/-6     
AppMenuHandlerImpl.java +11/-12 
dimens.xml +2/-2     
LocationBarCoordinator.java +2/-1     
AutocompleteCoordinator.java +14/-12 
AutocompleteMediator.java +114/-145
OmniboxSuggestionsDropdown.java +67/-67 
SuggestionLayout.java +2/-4     
account_picker_bottom_sheet_header.xml +4/-3     
account_picker_state_confirm_management.xml +4/-3     
account_picker_state_signin_in_progress.xml +4/-3     
BUILD.gn +17/-1   
content_autofill_driver.cc +20/-8   
autofill_driver.mojom +12/-0   
autofill_agent.cc +97/-8   
autofill_driver_router.cc +15/-0   
autofill_manager.cc +19/-3   
BUILD.gn +1/-0     
host_content_settings_map.cc +15/-72 
content_subresource_filter_throttle_manager.cc +2/-2     
BUILD.gn +19/-17 
clipboard_host_impl.cc +6/-12   
render_widget_host_view_android.cc +1/-1     
BUILD.gn +9/-4     
navigation_throttle.cc +4/-4     
extension_features.cc +4/-0     
features.cc +13/-14 
browser_protocol.pdl +30/-0   
document.cc +34/-17 
element.cc +10/-3   
web_document.cc +1/-1     
web_node.cc +55/-0   
web_node_test.cc +54/-0   
content_security_policy.cc +0/-1     
csp_directive_list.cc +0/-1     
history_util_test.cc +15/-15 
web_local_frame_impl.cc +17/-5   
web_local_frame_impl.h +0/-3     
chrome_client_impl.cc +5/-2     
dom_feature_policy.cc +0/-9     
permissions_policy_features.json5 +0/-1     
clipboard_promise.cc +1/-2     
BUILD.gn +1/-0     
org-list.txt +1/-1     
README +1/-1     
extensions-eval-content-script-expected.txt +1/-1     
enums.xml +121/-6 

@qodo-code-review

Copy link
Copy Markdown

PR Reviewer Guide 🔍

Here are some key observations to aid the review process:

⏱️ Estimated effort to review: 4 🔵🔵🔵🔵⚪
🧪 No relevant tests
🔒 No security concerns identified
⚡ Recommended focus areas for review

Behavior Change

Multiple API and ownership shifts from client_/driver_/personal_data_manager_ to manager()/autofill_client()/payments_autofill_client() alter lifecycle, nullability, and threading assumptions. Validate that all new accessors (e.g., payments_data_manager(), autofill_client(), payments_autofill_client()) are valid at these call sites across platforms and incognito, and that GetWeakPtr() semantics match previous weak_ptr_factory_ usages.

    AutofillManager* manager,
    autofill_metrics::CreditCardFormEventLogger* form_event_logger)
    : manager_(CHECK_DEREF(manager)), form_event_logger_(form_event_logger) {}

CreditCardAccessManager::~CreditCardAccessManager() {
  // This clears the record type of the most recently autofilled card with no
  // interactive authentication flow upon page navigation, as page navigation
  // results in us destroying the current CreditCardAccessManager and creating a
  // new one.
  if (auto* form_data_importer = autofill_client().GetFormDataImporter()) {
    form_data_importer
        ->SetPaymentMethodTypeIfNonInteractiveAuthenticationFlowCompleted(
            std::nullopt);
  }
}

void CreditCardAccessManager::UpdateCreditCardFormEventLogger() {
  std::vector<CreditCard*> credit_cards =
      payments_data_manager().GetCreditCards();
  size_t server_record_type_count = 0;
  size_t local_record_type_count = 0;
  for (CreditCard* credit_card : credit_cards) {
Timeout Units

kUnmaskDetailsResponseTimeout and kDelayForGetUnmaskDetails converted from raw ms ints to base::TimeDelta and used directly. Ensure all PostDelayedTask and delay computations now pass TimeDelta consistently and no remaining Milliseconds conversions are missing, especially around Android/iOS conditionals.

// Timeout to wait for unmask details from Google Payments.
constexpr auto kUnmaskDetailsResponseTimeout = base::Seconds(3);
// Time to wait between multiple calls to GetUnmaskDetails().
constexpr auto kDelayForGetUnmaskDetails = base::Minutes(3);

// Suffix for server IDs in the cache indicating that a card is a virtual card.
constexpr char kVirtualCardIdentifier[] = "_vcn";

}  // namespace

CreditCardAccessManager::CreditCardAccessManager(
    AutofillManager* manager,
    autofill_metrics::CreditCardFormEventLogger* form_event_logger)
    : manager_(CHECK_DEREF(manager)), form_event_logger_(form_event_logger) {}

CreditCardAccessManager::~CreditCardAccessManager() {
  // This clears the record type of the most recently autofilled card with no
  // interactive authentication flow upon page navigation, as page navigation
  // results in us destroying the current CreditCardAccessManager and creating a
  // new one.
  if (auto* form_data_importer = autofill_client().GetFormDataImporter()) {
    form_data_importer
        ->SetPaymentMethodTypeIfNonInteractiveAuthenticationFlowCompleted(
            std::nullopt);
  }
}

void CreditCardAccessManager::UpdateCreditCardFormEventLogger() {
  std::vector<CreditCard*> credit_cards =
      payments_data_manager().GetCreditCards();
  size_t server_record_type_count = 0;
  size_t local_record_type_count = 0;
  for (CreditCard* credit_card : credit_cards) {
Logic Simplification Risk

Many early-return brace removals and condition compressions change readability and could subtly affect side-effects order. Verify no behavior changes slipped in for selection/cursor/drag paths (e.g., StartMiddleClickAutoscroll, PerformHitTest, HandleMousePress/Move/Release) and that null checks still guard all dereferences on all platforms.

// node.
bool ShouldRefetchEventTarget(const MouseEventWithHitTestResults& mev) {
  Node* target_node = mev.InnerNode();
  if (!target_node || !target_node->parentNode())
    return true;
  if (auto* shadow_root = DynamicTo<ShadowRoot>(target_node))
    return IsA<HTMLInputElement>(shadow_root->host());
  return false;
}

gfx::Point GetMiddleSelectionCaretOfPosition(
    const PositionWithAffinity& position) {
  const LocalCaretRect& local_caret_rect = LocalCaretRectOfPosition(position);
  if (local_caret_rect.IsEmpty())
    return gfx::Point();
  const gfx::Rect rect = AbsoluteCaretBoundsOf(position);
  // In a multiline edit, rect.bottom() would end up on the next line, so
  // take the midpoint in order to use this corner point directly.
  if (local_caret_rect.layout_object->IsHorizontalWritingMode())
    return {rect.x(), (rect.y() + rect.bottom()) / 2};

  // When text is vertical, rect.right() would end up on the next line, so
  // take the midpoint in order to use this corner point directly.

@qodo-code-review

qodo-code-review Bot commented Sep 9, 2025 •

Copy link
Copy Markdown

PR Code Suggestions ✨

Explore these optional code suggestions:

CategorySuggestion                                                                                                                                    Impact
Possible issue
Fix enum value collision

MANAGE_SYNC and EXTENSION_DEVELOPER_MODE share the same value, causing routing
collisions. Assign a unique, unused value to avoid launching the wrong settings
screen.

src/components/browser_ui/settings/android/java/src/org/chromium/components/browser_ui/settings/SettingsLauncher.java [53-55]

 /// Manage sync.
 int MANAGE_SYNC = 9;
 /// Extension developer settings.
-int EXTENSION_DEVELOPER_MODE = 9;
+int EXTENSION_DEVELOPER_MODE = 10;

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 10

__

Why: The suggestion correctly identifies a critical bug where two different settings constants, MANAGE_SYNC and EXTENSION_DEVELOPER_MODE, are assigned the same value, which would lead to incorrect navigation.

High
Initialize event type in listener

Initialize event_type_ in the listener to avoid reading an uninitialized enum,
which breaks the switch and can crash. Also capture and use the event_type
parameter when computing the event name.

src/third_party/blink/renderer/core/exported/web_node.cc [280-327]

 base::ScopedClosureRunner WebNode::AddEventListener(
     EventType event_type,
     base::RepeatingCallback<void(WebDOMEvent)> handler) {
   class EventListener : public NativeEventListener {
    public:
     EventListener(Node* node,
+                  EventType event_type,
                   base::RepeatingCallback<void(WebDOMEvent)> handler)
-        : node_(node), handler_(std::move(handler)) {}
+        : node_(node), event_type_(event_type), handler_(std::move(handler)) {}
 
     void Invoke(ExecutionContext*, Event* event) override {
       handler_.Run(WebDOMEvent(event));
     }
 
     void AddListener() {
-      node_->addEventListener(event_type_name(), this,
-                              /*use_capture=*/false);
+      node_->addEventListener(event_type_name(), this, /*use_capture=*/false);
     }
 
     void RemoveListener() {
-      node_->removeEventListener(event_type_name(), this,
-                                 /*use_capture=*/false);
+      node_->removeEventListener(event_type_name(), this, /*use_capture=*/false);
     }
 
     void Trace(Visitor* visitor) const override {
       NativeEventListener::Trace(visitor);
       visitor->Trace(node_);
     }
 
    private:
-    const AtomicString& event_type_name() {
+    const AtomicString& event_type_name() const {
       switch (event_type_) {
         case EventType::kSelectionchange:
           return event_type_names::kSelectionchange;
       }
       NOTREACHED_NORETURN();
     }
 
     Member<Node> node_;
     EventType event_type_;
     base::RepeatingCallback<void(WebDOMEvent)> handler_;
   };
 
   WebPrivatePtrForGC<EventListener> listener =
-      MakeGarbageCollected<EventListener>(Unwrap<Node>(), std::move(handler));
+      MakeGarbageCollected<EventListener>(Unwrap<Node>(), event_type, std::move(handler));
   listener->AddListener();
   return base::ScopedClosureRunner(WTF::BindOnce(
       &EventListener::RemoveListener, WrapWeakPersistent(listener.Get())));
 }

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 9

__

Why: The suggestion correctly identifies that the event_type_ member was not initialized, leading to undefined behavior and a likely crash when used in the switch statement.

High
Use WeakPtr in delayed task

*Capturing this by reference in a delayed task risks use-after-free if the agent
is destroyed before timer fires. Bind a WeakPtr to AutofillAgent and
early-return if it has expired.

src/components/autofill/content/renderer/autofill_agent.cc [588-634]

 void AutofillAgent::HandleCaretMovedInFormField(WebElement element,
                                                 blink::WebDOMEvent) {
-  auto handle_throttled_caret_change = [](AutofillAgent& self,
-                                          WebElement element) {
-    if (!self.unsafe_render_frame() || !element.Focused() ||
-        !element.ContainsFrameSelection()) {
-      return;
-    }
-    gfx::Rect caret_bounds = GetCaretBounds(*self.unsafe_render_frame());
-    ...
-  };
+  auto handle_throttled_caret_change =
+      [](base::WeakPtr<AutofillAgent> weak_self, WebElement element) {
+        if (!weak_self)
+          return;
+        AutofillAgent& self = *weak_self;
+        if (!self.unsafe_render_frame() || !element.Focused() ||
+            !element.ContainsFrameSelection()) {
+          return;
+        }
+        gfx::Rect caret_bounds = GetCaretBounds(*self.unsafe_render_frame());
+        ...
+      };
   const base::Time now = base::Time::Now();
   const base::TimeDelta time_since_last = now - caret_state_.time_of_last_event;
   caret_state_.time_of_last_event = now;
+  auto weak_this = weak_ptr_factory_.GetWeakPtr();
   if (time_since_last < base::Milliseconds(100)) {
     caret_state_.timer.Start(FROM_HERE, base::Milliseconds(100),
                              base::BindOnce(handle_throttled_caret_change,
-                                            std::ref(*this), element));
+                                            weak_this, element));
   } else {
     caret_state_.timer.Stop();
-    handle_throttled_caret_change(*this, element);
+    handle_throttled_caret_change(weak_this, element);
   }
 }

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 9

__

Why: The suggestion correctly identifies a potential use-after-free bug where *this is captured by reference in a delayed task. Using a WeakPtr is the standard and correct way to fix this lifetime issue.

High
Cancel listener on early return

Ensure the listener is notified on early return to avoid leaving pending chooser
callbacks dangling. Currently, when blocking, FileSelectionCanceled() is never
invoked, which can deadlock callers waiting for a response.

src/content/browser/web_contents/web_contents_impl.cc [8316-8335]

 void WebContentsImpl::RunFileChooser(
     RenderFrameHost* render_frame_host,
     scoped_refptr<RenderFrameHostImpl::FileChooser::Listener> listener,
     const blink::mojom::FileChooserParams& params) {
   auto cancel = base::BindOnce(
       [](scoped_refptr<RenderFrameHostImpl::FileChooser::Listener> listener) {
         listener->FileSelectionCanceled();
       },
       listener);
 
   std::string domain = GetLastCommittedURL().host();
   bool should_block = false;
 
   if (ShouldBlockUpload(domain, params.accept_types)) {
     should_block = true;
   }
 
   if (should_block) {
     ShowUploadBlockedSnackbar("upload");
+    std::move(cancel).Run();
     return;
   }
 
   // ... continue to show chooser
 }

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 8

__

Why: The suggestion correctly points out that the listener is not notified when the file chooser is blocked, which could lead to a deadlock for the caller waiting for a response.

Medium
Bounds-check feature IDs

Validate that all feature IDs are within [0, max_feature_value] before adding
them to the bitset. Without bounds checks, out-of-range values can trigger
DCHECKs in debug or corrupt data in release builds. Reject or clamp invalid IDs
and log for diagnostics.

src/components/ukm/ukm_recorder_impl.cc [1057-1112]

 void UkmRecorderImpl::RecordWebDXFeatures(SourceId source_id,
                                           const std::set<int32_t>& features,
                                           size_t max_feature_value) {
   DCHECK_CALLED_ON_VALID_SEQUENCE(sequence_checker_);
-  // Sanity check that we don't have an unreasonably large max feature
-  // value. This isn't expected to grow much past 2000 for a long time.
   DCHECK_LT(max_feature_value, 3000u);
 
   if (!recording_enabled()) {
     RecordDroppedWebDXFeaturesSet(DroppedDataReason::RECORDING_DISABLED);
     return;
   }
 
   const auto required_consent = GetConsentType(GetSourceIdType(source_id));
   if (!recording_enabled(required_consent)) {
     if (required_consent == UkmConsentType::MSBB) {
       RecordDroppedWebDXFeaturesSet(DroppedDataReason::MSBB_CONSENT_DISABLED);
     } else if (required_consent == UkmConsentType::APPS) {
       RecordDroppedWebDXFeaturesSet(DroppedDataReason::APPS_CONSENT_DISABLED);
     }
     return;
   }
 
   if (!IsSamplingConfigured()) {
     RecordDroppedWebDXFeaturesSet(DroppedDataReason::SAMPLING_UNCONFIGURED);
     return;
   }
 
-  // Apply sampling on a per-source-id basis for web features.
-  // Note: the `event_id` passed is 0. The actual number doesn't really matter,
-  // what matters is that we either record all features or no features at all
-  // for a given source.
   if (!IsSampledIn(source_id, /*event_id=*/0, webdx_features_sampling_)) {
     RecordDroppedWebDXFeaturesSet(DroppedDataReason::SAMPLED_OUT);
     return;
   }
 
-  // Create a bitset for `source_id` if there is not already one. The size of
-  // the bitset is max_feature_value + 1 since 0 is included.
   auto result = recordings_.webdx_features.try_emplace(
       source_id,
       /*set_size=*/max_feature_value + 1);
   BitSet& features_set = result.first->second;
   CHECK_EQ(features_set.set_size(), max_feature_value + 1);
 
   for (const auto& feature : features) {
-    features_set.Add(feature);
+    if (feature < 0 || static_cast<size_t>(feature) > max_feature_value) {
+      DVLOG(1) << "Ignoring out-of-range WebDX feature id: " << feature
+               << " (max=" << max_feature_value << ")";
+      continue;
+    }
+    features_set.Add(static_cast<size_t>(feature));
   }
 
   DVLOG(DebuggingLogLevel::Medium)
       << "RecordWebDXFeatures: [source_id=" << source_id << " features={"
       << WebDXFeaturesToStringForDebug(features) << "}]";
 }

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 7

__

Why: The suggestion correctly identifies a missing bounds check for feature IDs, which could lead to a DCHECK failure in debug builds or memory corruption in release builds.

Medium
Restore correct omnibox paddings

Replacing the modern padding dimen and forcing bottom padding to 0 may break
touch targets and visual density. Restore using the modern-specific dimen and
preserve bottom padding from resources instead of hardcoding 0.

src/chrome/browser/ui/android/omnibox/java/src/org/chromium/chrome/browser/omnibox/suggestions/base/SuggestionLayout.java [153-154]

-int endSpace = res.getDimensionPixelSize(R.dimen.omnibox_suggestion_end_padding);
-setPaddingRelative(0, 0, endSpace, 0);
+int endSpace = res.getDimensionPixelSize(R.dimen.omnibox_suggestion_end_padding_modern);
+int bottomPadding = res.getDimensionPixelSize(R.dimen.omnibox_suggestion_bottom_padding_modern);
+setPaddingRelative(0, 0, endSpace, bottomPadding);
  • Apply / Chat
Suggestion importance[1-10]: 6

__

Why: The suggestion correctly identifies a potentially unintentional UI change that could impact layout and touch targets, and proposes reverting to the previous padding logic which is a valid concern to raise.

Low
High-level
Risky behavioral changes without guards

This upgrade includes numerous non-trivial behavior changes (e.g., new
caret-tracking Autofill pipeline, WebContents accessibility API change,
picture-in-picture frame tree plumbing, Android omnibox/session logic refactors,
content settings provider path, and node/rust toolchain delivery via GCS)
without feature flags, migration fallbacks, or clear compatibility gates. Given
the breadth and cross-component impact, gate these changes behind runtime
feature flags or staged rollouts and add opt-out paths to minimize regressions
across platforms and products.

Examples:

src/components/content_settings/core/browser/host_content_settings_map.cc [1076-1108]
src/content/browser/web_contents/web_contents_impl.cc [5254-5272]

Solution Walkthrough:

Before:

// In content_settings/core/browser/host_content_settings_map.cc
// Logic was conditional on a feature flag
if (base::FeatureList::IsEnabled(kIndexedHostContentSettingsMap)) {
  auto rule = provider->GetRule(...);
  // ... use rule
} else {
  std::unique_ptr<content_settings::RuleIterator> iterator =
      provider->GetRuleIterator(...);
  // ... use iterator
}

// In content/browser/web_contents/web_contents_impl.cc
void WebContentsImpl::AccessibilityEventReceived(
    const ui::AXUpdatesAndEvents& details) {
  observers_.NotifyObservers(&WebContentsObserver::AccessibilityEventReceived,
                             details);
}

After:

// In content_settings/core/browser/host_content_settings_map.cc
// The old path and feature flag are removed, making the new path default.
auto rule = provider->GetRule(...);
if (rule) {
  // ... use rule
}

// In content/browser/web_contents/web_contents_impl.cc
// Method renamed and logic changed, now calling a delegate.
void WebContentsImpl::ProcessAccessibilityUpdatesAndEvents(
    ui::AXUpdatesAndEvents& details) {
  observers_.NotifyObservers(&WebContentsObserver::AccessibilityEventReceived,
                             details);
  if (delegate_) {
    delegate_->ProcessAccessibilityUpdatesAndEvents(details);
  }
}
Suggestion importance[1-10]: 9

__

Why: The suggestion correctly identifies several significant, unguarded behavioral changes and refactors across multiple critical components like Autofill, accessibility, and content settings, which could introduce regressions. While it misses that the new Autofill caret tracking is feature-flagged, the other points about major unguarded changes are valid and highlight a substantial risk in this large-scale upgrade.

High
Security
Sanitize and guard intent logging

Remove the error-level log with non-actionable text and guard against
non-http/https schemes to avoid leaking data and noisy logs. Use debug logging
and sanitize the message.

src/chrome/android/java/src/org/chromium/chrome/browser/IntentHandler.java [118-126]

 public static boolean checkAndShowCustomSplash(Activity activity, Intent intent) {
-    if (intent != null && intent.getData() != null) {
-        Uri uri = intent.getData();
-        String utmSource = extractUtmParameter(uri, "utm_source");
-        Log.e("IntentHandler", "UTM source: of the god itself " + (utmSource != null ? utmSource : "null"));
-        // onIntentReceived(intent);
+    if (intent == null) return false;
+    final Uri uri = intent.getData();
+    if (uri == null) return false;
+    final String scheme = uri.getScheme();
+    if (scheme == null || (!"http".equalsIgnoreCase(scheme) && !"https".equalsIgnoreCase(scheme))) {
+        return false;
+    }
+    final String utmSource = extractUtmParameter(uri, "utm_source");
+    if (BuildConfig.DEBUG) {
+        Log.d("IntentHandler", "UTM source present: " + (utmSource != null));
     }
     return false;
 }
  • Apply / Chat
Suggestion importance[1-10]: 7

__

Why: The suggestion correctly points out that the new logging is unprofessional, uses the wrong log level, and could log data from unintended URI schemes, proposing a much cleaner and safer implementation.

Medium
General
Map enum to stable ints

Guard against mismatched enum values between C++ and Java by validating the cast
or mapping explicitly. Directly casting C++ enum to jint may yield undefined
values on Java side if the enum changes, causing crashes or logic errors.

src/content/browser/web_contents/web_contents_android.cc [915-922]

 jint WebContentsAndroid::GetCurrentBackForwardTransitionStage(JNIEnv* env) {
   auto stage = BackForwardTransitionAnimationManager::AnimationStage::kNone;
   if (auto* animation =
           web_contents_->GetBackForwardTransitionAnimationManager()) {
     stage = animation->GetCurrentAnimationStage();
   }
-  return static_cast<jint>(stage);
+  // Map to stable int values expected by Java instead of raw cast.
+  switch (stage) {
+    case BackForwardTransitionAnimationManager::AnimationStage::kNone:
+      return 0;
+    case BackForwardTransitionAnimationManager::AnimationStage::kPending:
+      return 1;
+    case BackForwardTransitionAnimationManager::AnimationStage::kRunning:
+      return 2;
+    case BackForwardTransitionAnimationManager::AnimationStage::kCompleted:
+      return 3;
+  }
+  // Fallback for unknown/added enum values.
+  return 0;
 }

[To ensure code accuracy, apply this suggestion manually]

Suggestion importance[1-10]: 5

__

Why: The suggestion proposes a more robust way to pass enum values to Java by mapping them to stable integers, preventing potential issues if the C++ enum changes.

Low
  • Update

@pandey019
pandey019 merged commit 536038b into wootzapp:chromium Sep 14, 2025
1 check passed
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 14, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants