Clear LCPP hint during redirects to prevent cross-origin info leak [chromium/src : main]

0 views
Skip to first unread message

Minoru Chikamune (Gerrit)

unread,
Apr 2, 2026, 11:33:14 AM (yesterday) Apr 2
to Minoru Chikamune, Yoshisato Yanagisawa, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org
Attention needed from Yoshisato Yanagisawa

Minoru Chikamune voted Commit-Queue+1

Commit-Queue+1
Open in Gerrit

Related details

Attention is currently required from:
  • Yoshisato Yanagisawa
Submit Requirements:
  • requirement satisfiedCode-Coverage
  • requirement is not satisfiedCode-Owners
  • requirement is not satisfiedCode-Review
  • requirement is not satisfiedReview-Enforcement
Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
Gerrit-MessageType: comment
Gerrit-Project: chromium/src
Gerrit-Branch: main
Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
Gerrit-Change-Number: 7725921
Gerrit-PatchSet: 4
Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
Gerrit-Attention: Yoshisato Yanagisawa <yyana...@chromium.org>
Gerrit-Comment-Date: Thu, 02 Apr 2026 15:32:49 +0000
Gerrit-HasComments: No
Gerrit-Has-Labels: Yes
satisfied_requirement
unsatisfied_requirement
open
diffy

Yoshisato Yanagisawa (Gerrit)

unread,
Apr 2, 2026, 8:23:30 PM (yesterday) Apr 2
to Minoru Chikamune, Lingqi Chi, Takashi Toyoshima, Rakina Zata Amni, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org
Attention needed from Lingqi Chi, Minoru Chikamune, Rakina Zata Amni and Takashi Toyoshima

Yoshisato Yanagisawa voted Code-Review+1

Code-Review+1
Open in Gerrit

Related details

Attention is currently required from:
  • Lingqi Chi
  • Minoru Chikamune
  • Rakina Zata Amni
  • Takashi Toyoshima
Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement is not satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Gerrit-Change-Number: 7725921
    Gerrit-PatchSet: 5
    Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Lingqi Chi <lin...@chromium.org>
    Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Reviewer: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
    Gerrit-Attention: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Attention: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Attention: Lingqi Chi <lin...@chromium.org>
    Gerrit-Attention: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Comment-Date: Fri, 03 Apr 2026 00:23:03 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Rakina Zata Amni (Gerrit)

    unread,
    Apr 2, 2026, 9:46:18 PM (23 hours ago) Apr 2
    to Minoru Chikamune, Yoshisato Yanagisawa, Lingqi Chi, Takashi Toyoshima, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org
    Attention needed from Lingqi Chi, Minoru Chikamune and Takashi Toyoshima

    Rakina Zata Amni voted Code-Review+1

    Code-Review+1
    Open in Gerrit

    Related details

    Attention is currently required from:
    • Lingqi Chi
    • Minoru Chikamune
    • Takashi Toyoshima
    Gerrit-Comment-Date: Fri, 03 Apr 2026 01:45:42 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    unsatisfied_requirement
    open
    diffy

    Lingqi Chi (Gerrit)

    unread,
    Apr 2, 2026, 11:28:20 PM (22 hours ago) Apr 2
    to Minoru Chikamune, Rakina Zata Amni, Yoshisato Yanagisawa, Takashi Toyoshima, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org
    Attention needed from Minoru Chikamune and Takashi Toyoshima

    Lingqi Chi voted Code-Review+1

    Code-Review+1
    Open in Gerrit

    Related details

    Attention is currently required from:
    • Minoru Chikamune
    • Takashi Toyoshima
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Gerrit-Change-Number: 7725921
    Gerrit-PatchSet: 5
    Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Lingqi Chi <lin...@chromium.org>
    Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Reviewer: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
    Gerrit-Attention: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Attention: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Comment-Date: Fri, 03 Apr 2026 03:27:43 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    open
    diffy

    Takashi Toyoshima (Gerrit)

    unread,
    12:59 AM (20 hours ago) 12:59 AM
    to Minoru Chikamune, Lingqi Chi, Rakina Zata Amni, Yoshisato Yanagisawa, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org
    Attention needed from Minoru Chikamune

    Takashi Toyoshima voted Code-Review+1

    Code-Review+1
    Open in Gerrit

    Related details

    Attention is currently required from:
    • Minoru Chikamune
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Gerrit-Change-Number: 7725921
    Gerrit-PatchSet: 5
    Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Lingqi Chi <lin...@chromium.org>
    Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Reviewer: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
    Gerrit-Attention: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Comment-Date: Fri, 03 Apr 2026 04:59:07 +0000
    Gerrit-HasComments: No
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    open
    diffy

    Minoru Chikamune (Gerrit)

    unread,
    1:39 AM (19 hours ago) 1:39 AM
    to Minoru Chikamune, Takashi Toyoshima, Lingqi Chi, Rakina Zata Amni, Yoshisato Yanagisawa, Chromium LUCI CQ, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org

    Minoru Chikamune voted and added 1 comment

    Votes added by Minoru Chikamune

    Commit-Queue+2

    1 comment

    Patchset-level comments
    File-level comment, Patchset 5 (Latest):
    Minoru Chikamune . resolved

    Thanks!

    Open in Gerrit

    Related details

    Attention set is empty
    Submit Requirements:
    • requirement satisfiedCode-Coverage
    • requirement satisfiedCode-Owners
    • requirement satisfiedCode-Review
    • requirement satisfiedReview-Enforcement
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: comment
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Gerrit-Change-Number: 7725921
    Gerrit-PatchSet: 5
    Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Lingqi Chi <lin...@chromium.org>
    Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Reviewer: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
    Gerrit-Comment-Date: Fri, 03 Apr 2026 05:38:32 +0000
    Gerrit-HasComments: Yes
    Gerrit-Has-Labels: Yes
    satisfied_requirement
    open
    diffy

    Chromium LUCI CQ (Gerrit)

    unread,
    1:42 AM (19 hours ago) 1:42 AM
    to Minoru Chikamune, Takashi Toyoshima, Lingqi Chi, Rakina Zata Amni, Yoshisato Yanagisawa, chromium...@chromium.org, alexmo...@chromium.org, bmcquad...@chromium.org, creis...@chromium.org, csharris...@chromium.org, loading-rev...@chromium.org, navigation...@chromium.org, speed-metrics...@chromium.org, speed-metr...@chromium.org

    Chromium LUCI CQ submitted the change

    Change information

    Commit message:
    Clear LCPP hint during redirects to prevent cross-origin info leak

    During redirects, stale LCPP (LCP Critical Path Predictor) hints from
    the initial origin could leak to the redirect target's renderer process.
    This could potentially be used for XS-Search attacks.

    This CL ensures that the LCPP hint is properly cleared during redirects.
    Bug: 497490364
    Bug: 40063266
    Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Reviewed-by: Lingqi Chi <lin...@chromium.org>
    Reviewed-by: Takashi Toyoshima <toyo...@chromium.org>
    Reviewed-by: Yoshisato Yanagisawa <yyana...@chromium.org>
    Reviewed-by: Rakina Zata Amni <rak...@chromium.org>
    Commit-Queue: Minoru Chikamune <chik...@chromium.org>
    Cr-Commit-Position: refs/heads/main@{#1609673}
    Files:
    • M chrome/browser/page_load_metrics/observers/lcp_critical_path_predictor_page_load_metrics_observer_unittest.cc
    • M chrome/browser/predictors/loading_predictor_tab_helper.cc
    • M content/browser/renderer_host/navigation_request.cc
    • M content/browser/renderer_host/navigation_request.h
    • M content/public/browser/navigation_handle.h
    • M content/public/test/mock_navigation_handle.h
    • M content/web_test/browser/web_test_control_host.cc
    Change size: S
    Delta: 7 files changed, 14 insertions(+), 8 deletions(-)
    Branch: refs/heads/main
    Submit Requirements:
    • requirement satisfiedCode-Review: +1 by Takashi Toyoshima, +1 by Yoshisato Yanagisawa, +1 by Rakina Zata Amni, +1 by Lingqi Chi
    Open in Gerrit
    Inspect html for hidden footers to help with email filtering. To unsubscribe visit settings. DiffyGerrit
    Gerrit-MessageType: merged
    Gerrit-Project: chromium/src
    Gerrit-Branch: main
    Gerrit-Change-Id: I196a8e26f6403f6eb9571aa1d19411f182600af4
    Gerrit-Change-Number: 7725921
    Gerrit-PatchSet: 6
    Gerrit-Owner: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Chromium LUCI CQ <chromiu...@luci-project-accounts.iam.gserviceaccount.com>
    Gerrit-Reviewer: Lingqi Chi <lin...@chromium.org>
    Gerrit-Reviewer: Minoru Chikamune <chik...@chromium.org>
    Gerrit-Reviewer: Rakina Zata Amni <rak...@chromium.org>
    Gerrit-Reviewer: Takashi Toyoshima <toyo...@chromium.org>
    Gerrit-Reviewer: Yoshisato Yanagisawa <yyana...@chromium.org>
    open
    diffy
    satisfied_requirement
    Reply all
    Reply to author
    Forward
    0 new messages