Don't allow image-orientation to leak EXIF information via cross-fade() [chromium/src : main]

0 views
Skip to first unread message

Rune Lillesveen (Gerrit)

unread,
Apr 14, 2026, 7:37:38 AM (5 days ago) Apr 14
to Rune Lillesveen, Stephen Chenney, chromiu...@luci-project-accounts.iam.gserviceaccount.com, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org
Attention needed from Stephen Chenney

New activity on the change

Open in Gerrit

Related details

Attention is currently required from:
  • Stephen Chenney
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
Gerrit-Change-Number: 7761585
Gerrit-PatchSet: 1
Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
Gerrit-CC: Dirk Schulze <dsch...@chromium.org>
Gerrit-Attention: Stephen Chenney <sche...@chromium.org>
Gerrit-Comment-Date: Tue, 14 Apr 2026 11:37:22 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: No
satisfied_requirement
unsatisfied_requirement
open
diffy

Stephen Chenney (Gerrit)

unread,
Apr 14, 2026, 11:09:01 AM (4 days ago) Apr 14
to Rune Lillesveen, chromiu...@luci-project-accounts.iam.gserviceaccount.com, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org
Attention needed from Rune Lillesveen

Stephen Chenney voted and added 1 comment

Votes added by Stephen Chenney

Code-Review+1

1 comment

Patchset-level comments
File-level comment, Patchset 1 (Latest):
Stephen Chenney . resolved

LGTM. Funnily enough I was about to write a test for cross origin images in cross-fade leaking with HTML-in-Canvas because I think right now they will.

Open in Gerrit

Related details

Attention is currently required from:
  • Rune Lillesveen
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Gerrit-Change-Number: 7761585
    Gerrit-PatchSet: 1
    Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
    Gerrit-CC: Dirk Schulze <dsch...@chromium.org>
    Gerrit-Attention: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Comment-Date: Tue, 14 Apr 2026 15:08:52 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    open
    diffy

    Blink W3C Test Autoroller (Gerrit)

    unread,
    Apr 14, 2026, 11:13:50 AM (4 days ago) Apr 14
    to Rune Lillesveen, Stephen Chenney, chromiu...@luci-project-accounts.iam.gserviceaccount.com, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org
    Attention needed from Rune Lillesveen

    Message from Blink W3C Test Autoroller

    Exportable changes to web-platform-tests were detected in this CL and a pull request in the upstream repo has been made: https://github.com/web-platform-tests/wpt/pull/59211.

    When this CL lands, the bot will automatically merge the PR on GitHub if the required GitHub checks pass; otherwise, ecosystem-infra@ team will triage the failures and may contact you.

    WPT Export docs:
    https://chromium.googlesource.com/chromium/src/+/main/docs/testing/web_platform_tests.md#Automatic-export-process

    Open in Gerrit

    Related details

    Attention is currently required from:
    • Rune Lillesveen
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Gerrit-Change-Number: 7761585
    Gerrit-PatchSet: 1
    Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
    Gerrit-CC: Blink W3C Test Autoroller <blink-w3c-te...@chromium.org>
    Gerrit-Comment-Date: Tue, 14 Apr 2026 15:13:41 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: No
    satisfied_requirement
    open
    diffy

    Rune Lillesveen (Gerrit)

    unread,
    Apr 14, 2026, 11:46:00 AM (4 days ago) Apr 14
    to Rune Lillesveen, Blink W3C Test Autoroller, Stephen Chenney, chromiu...@luci-project-accounts.iam.gserviceaccount.com, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org

    Rune Lillesveen voted Commit-Queue+2

    Commit-Queue+2
    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Gerrit-Change-Number: 7761585
    Gerrit-PatchSet: 1
    Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
    Gerrit-CC: Blink W3C Test Autoroller <blink-w3c-te...@chromium.org>
    Gerrit-CC: Dirk Schulze <dsch...@chromium.org>
    Gerrit-Comment-Date: Tue, 14 Apr 2026 15:45:41 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    open
    diffy

    chromium-scoped@luci-project-accounts.iam.gserviceaccount.com (Gerrit)

    unread,
    Apr 14, 2026, 11:51:45 AM (4 days ago) Apr 14
    to Rune Lillesveen, Blink W3C Test Autoroller, Stephen Chenney, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org

    chromiu...@luci-project-accounts.iam.gserviceaccount.com submitted the change

    Change information

    Commit message:
    Don't allow image-orientation to leak EXIF information via cross-fade()
    Bug: 502231588
    Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Reviewed-by: Stephen Chenney <sche...@chromium.org>
    Commit-Queue: Rune Lillesveen <fut...@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#1614508}
    Files:
    • M third_party/blink/renderer/core/style/style_crossfade_image.cc
    • M third_party/blink/renderer/core/style/style_crossfade_image.h
    • M third_party/blink/renderer/platform/graphics/crossfade_generated_image.cc
    • A third_party/blink/web_tests/external/wpt/css/css-images/cross-fade-cross-origin-orientation-ref.html
    • A third_party/blink/web_tests/external/wpt/css/css-images/cross-fade-cross-origin-orientation.sub.html
    Change size: M
    Delta: 5 files changed, 48 insertions(+), 5 deletions(-)
    Branch: refs/heads/main
    Submit Requirements:
    • requirement satisfiedCode-Review: +1 by Stephen Chenney
    Open in Gerrit
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: merged
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Gerrit-Change-Number: 7761585
    Gerrit-PatchSet: 2
    Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
    open
    diffy
    satisfied_requirement

    Blink W3C Test Autoroller (Gerrit)

    unread,
    Apr 14, 2026, 10:16:00 PM (4 days ago) Apr 14
    to chromiu...@luci-project-accounts.iam.gserviceaccount.com, Rune Lillesveen, Stephen Chenney, chromium...@chromium.org, Dirk Schulze, android-bu...@system.gserviceaccount.com, blink-reviews-p...@chromium.org, fmalit...@chromium.org, fserb...@chromium.org, blink-rev...@chromium.org, blink-...@chromium.org, kinuko...@chromium.org, blink-revie...@chromium.org, drott+bl...@chromium.org

    Message from Blink W3C Test Autoroller

    The WPT PR for this CL has been merged upstream! https://github.com/web-platform-tests/wpt/pull/59211

    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I2149c06cb1fc732e4cf45a2c492fe968edce9aa4
    Gerrit-Change-Number: 7761585
    Gerrit-PatchSet: 2
    Gerrit-Owner: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Rune Lillesveen <fut...@chromium.org>
    Gerrit-Reviewer: Stephen Chenney <sche...@chromium.org>
    Gerrit-CC: Blink W3C Test Autoroller <blink-w3c-te...@chromium.org>
    Gerrit-CC: Dirk Schulze <dsch...@chromium.org>
    Gerrit-Comment-Date: Wed, 15 Apr 2026 02:15:50 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: No
    satisfied_requirement
    open
    diffy
    Reply all
    Reply to author
    Forward
    0 new messages