Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 955114 - www-client/chromium-136.0.7103.59 stablereq
Summary: www-client/chromium-136.0.7103.59 stablereq
Status: IN_PROGRESS
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Stabilization (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Chromium Project
URL:
Whiteboard:
Keywords: CC-ARCHES, SECURITY
Depends on:
Blocks: CVE-2025-4050, CVE-2025-4051, CVE-2025-4052, CVE-2025-4096
  Show dependency tree
 
Reported: 2025-04-30 09:51 UTC by Matt Jolly
Modified: 2025-05-01 16:13 UTC (History)
4 users (show)

See Also:
Package list:
www-client/chromium-136.0.7103.59 arm64 amd64 media-video/ffmpeg-chromium-136 arm64 amd64
Runtime testing required: No
nattka: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Matt Jolly gentoo-dev 2025-04-30 09:51:44 UTC
Please stabilise
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-05-01 16:01:21 UTC
amd64 done
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-05-01 16:03:46 UTC
The gperf part here isn't right. It stabilises it for only a subset of arches that gperf is available for and has stable keywords on, but also it's not been in-tree that long (and various fixes got committed in fixup releases).

I don't think Chromium actually needs newer gperf, the thing we dropped in the fix for bug 953436 was just a warning fix anyway (just it became fatal as their sed went wrong w/ newer gperf).
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-05-01 16:04:08 UTC
(In reply to Sam James from comment #2)
> The gperf part here isn't right. It stabilises it for only a subset of
> arches that gperf is available for and has stable keywords on, but also it's
> not been in-tree that long (and various fixes got committed in fixup
> releases).
> 
> I don't think Chromium actually needs newer gperf, the thing we dropped in
> the fix for bug 953436 was just a warning fix anyway (just it became fatal
> as their sed went wrong w/ newer gperf).

Stabling 3.3 is OK for now so I won't revert it, but please keep this in mind for future, and it's worth considering dropping any >=3.3 dep in chromium.
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2025-05-01 16:08:02 UTC
(One final note: the convention is different for stabling some package which already has stable keywords but not on some arch (usually no need to wait for an ACK) vs some brand new version that isn't stable at all, especially if it's maintained by base-system (please do get an ACK)).