ungoogled-chromium-xdg

LOW
maintainer ZhangHua 13 votes scanned 2026-09-17 00:27:14.276658
View on AUR
Why flagged

The package builds Chromium from official source code hosted on Google's own storage domain, which is a standard and trusted source for Chromium; the non-whitelisted host is a known official infrastructure, not a risk for supply-chain tampering.

Triggered rules

Low AI review downgraded a static finding llm_review

The static rules flagged this MEDIUM, but an AI model (qwen/qwen3-235b-a22b-2507) reviewed the full PKGBUILD and judged it LOW (confidence 95%): The package builds Chromium from official source code hosted on Google's own storage domain, which is a standard and trusted source for Chromium; the non-whitelisted host is a known official infrastructure, not a risk for supply-chain tampering.

1 higher static finding superseded - not the current verdict (shown for transparency)
Medium source=() URL on a non-standard host source_untrusted_domain

One or more source=() URLs point to a host outside the trusted allowlist (github.com, gitlab.com, codeberg.org, pypi.org, …).

  • PKGBUILD:91 source=(https://commondatastorage.googleapis.com/chromium-browser-official/chromium-$pkgver-lite.tar.xz

PKGBUILD

1 offending line(s) highlighted
1# Maintainer: Noah Vogt (noahvogt) <noah@noahvogt.com>
2# Maintainer: Seppia <seppia@seppio.fish>
3# Maintainer: JustKidding <jk@vin.ovh>
4
5# Based on extra/chromium, with ungoogled-chromium patches
6
7# Maintainer: Evangelos Foutras <evangelos@foutrelis.com>
8# Contributor: Pierre Schmitz <pierre@archlinux.de>
9# Contributor: Jan "heftig" Steffens <jan.steffens@gmail.com>
10# Contributor: Daniel J Griffiths <ghost1227@archlinux.us>
11
12# binary version of this package (-bin): github.com/noahvogt/ungoogled-chromium-xdg-bin-aur
13
14pkgname=ungoogled-chromium-xdg
15pkgver=153.0.8010.36
16pkgrel=1
17_launcher_ver=8
18_manual_clone=0
19_system_clang=1
20_uc_usr=ungoogled-software
21_uc_ver=$pkgver-1
22pkgdesc="A lightweight approach to removing Google web service dependency - allow disabling omnibox auto completion"
23arch=('x86_64')
24url="https://github.com/ungoogled-software/ungoogled-chromium"
25license=('BSD-3-Clause')
26depends=(
27 'alsa-lib'
28 'at-spi2-core'
29 'cairo'
30 'dbus'
31 'desktop-file-utils'
32 'expat'
33 'glib2'
34 'glibc'
35 'gtk3'
36 'hicolor-icon-theme'
37 'libcups'
38 'libffi'
39 'libgcc'
40 'libgcrypt'
41 'libpulse'
42 'libstdc++'
43 'libva'
44 'libx11'
45 'libxcb'
46 'libxcomposite'
47 'libxdamage'
48 'libxext'
49 'libxfixes'
50 'libxkbcommon'
51 'libxrandr'
52 'libxss'
53 'mesa'
54 'nspr'
55 'nss'
56 'pango'
57 'pciutils'
58 'systemd'
59 'systemd-libs'
60 'ttf-liberation'
61 'xdg-utils'
62 'zlib'
63)
64makedepends=(
65 'clang'
66 'compiler-rt'
67 'git'
68 'gn'
69 'go'
70 'gperf'
71 'java-runtime-headless'
72 'lld'
73 'ninja'
74 'nodejs'
75 'opus'
76 'pipewire'
77 'python'
78 'qt6-base'
79 'rust'
80 'rust-bindgen'
81 'typescript'
82)
83optdepends=('pipewire: WebRTC desktop sharing under Wayland'
84 'kdialog: support for native dialogs in Plasma'
85 'gtk4: for --gtk-version=4 (GTK4 IME might work better on Wayland)'
86 'qt6-base: Qt support'
87 'org.freedesktop.secrets: password storage backend on GNOME, KDE and Xfce'
88 'upower: Battery Status API support'
89 'chromium-extension-web-store: Web Store Functionality')
90options=('!lto') # Chromium adds its own flags for ThinLTO
91source=(https://commondatastorage.googleapis.com/chromium-browser-official/chromium-$pkgver-lite.tar.xz
92 "ungoogled-chromium-$_uc_ver.tar.gz::https://github.com/$_uc_usr/ungoogled-chromium/archive/$_uc_ver.tar.gz"
93 https://github.com/foutrelis/chromium-launcher/archive/v$_launcher_ver/chromium-launcher-$_launcher_ver.tar.gz
94 chromium-138-nodejs-version-check.patch
95 chromium-145-fix-SYS_SECCOMP.patch
96 chromium-147-revert-clang-no-lifetime-dse-flag.patch
97 chromium-147-rust-1.95-bytemuck.patch
98 chromium-149-drop-unknown-clang-flag.patch
99 chromium-149-use-of-undeclared-identifier-ERROR.patch
100 chromium-150-revert-avx-flag-change.patch
101 chromium-152-fix-gn-no-public_inputs.patch
102 chromium-152-unbundle-minizip-undo-unicode.patch
103 chromium-152-unbundle-opus-devtools.patch
104 chromium-153-hermetic-python.patch
105 chromium-153-iamf-tools-unbundled-opus.patch
106 chromium-153-typescript.patch
107 chromium-153-crubit.patch
108 compiler-rt-adjust-paths.patch
109 increase-fortify-level.patch
110 enable-widevine-arm64.patch
111 use-oauth2-client-switches-as-default.patch
112 glibc-2.42-baud-rate-fix.patch
113 # ungoogled-chromium-xdg patches
114 no-omnibox-suggestion-autocomplete.patch)
115sha256sums=('645f64566cfbb780747430d53ff3656f03639f89fed9544c1eadd4c17e7b1c82'
116 '8df8570d440a9117c187f1c466386543381c52bb9044817670df8a741423ca12'
117 '213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
118 '11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
119 '4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
120 'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
121 'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
122 '1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327'
123 '951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
124 '5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
125 '50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b'
126 '890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9'
127 '3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'
128 'ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49'
129 '2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee'
130 '44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16'
131 'a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4'
132 'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
133 'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
134 '5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'
135 '9343afa1a4308a7cfb3317229f5aff7778688debcc03c4a74a85908aa1d0cc3a'
136 '1c1898f263eaacbc069a8e1a3e732852350350d1dad4cb1a6bba430e3b796cd0'
137 'ed335a6b4b9c05fff5fbfb530e83bdd165c002f2219d0adbf9773bc3239620e6')
138
139if (( _manual_clone )); then
140 source[0]=fetch-chromium-release
141 sha256sums[0]='2e2f36e3cd1ebc4ad57fd310774a5e5e9db77883d5f9374fedeaabd3c103b819'
142 makedepends+=('python-httplib2' 'python-pyparsing' 'python-six' 'npm' 'rsync')
143fi
144
145provides=("chromium=${pkgver}" "chromedriver=${pkgver}")
146conflicts=('chromium' 'chromedriver')
147
148# Possible replacements are listed in build/linux/unbundle/replace_gn_files.py
149# Keys are the names in the above script; values are the dependencies in Arch
150declare -gA _system_libs=(
151 [brotli]=brotli
152 [dav1d]=dav1d
153 #[ffmpeg]=ffmpeg # YouTube playback stopped working in Chromium 120
154 [flac]=flac
155 [fontconfig]=fontconfig
156 [freetype]=freetype2
157 [harfbuzz]=harfbuzz
158 [highway]=highway
159 #[icu]=icu
160 #[jsoncpp]=jsoncpp # needs libstdc++
161 #[libaom]=aom
162 #[libavif]=libavif # needs -DAVIF_ENABLE_EXPERIMENTAL_GAIN_MAP=ON
163 [libdrm]=libdrm
164 [libjpeg]=libjpeg-turbo
165 #[libpng]=libpng # libpng has been replaced by the png rust crate
166 #[libvpx]=libvpx
167 [libwebp]=libwebp
168 [libxml]=libxml2
169 [libxslt]=libxslt
170 [openh264]=openh264
171 [opus]=opus
172 #[re2]=re2 # needs libstdc++
173 #[snappy]=snappy # needs libstdc++
174 #[woff2]=woff2 # needs libstdc++
175 [zlib]=minizip
176 [zstd]=zstd
177)
178_unwanted_bundled_libs=(
179 $(printf "%s\n" ${!_system_libs[@]} | sed 's/^libjpeg$/&_turbo/')
180)
181depends+=(${_system_libs[@]})
182
183# Google API keys (see https://www.chromium.org/developers/how-tos/api-keys)
184# Note: These are for Arch Linux use ONLY. For your own distribution, please
185# get your own set of keys.
186#
187# Starting with Chromium 89 (2021-03-02) the OAuth2 credentials have been left
188# out: https://archlinux.org/news/chromium-losing-sync-support-in-early-march/
189
190prepare() {
191 if (( _manual_clone )); then
192 ./fetch-chromium-release $pkgver
193 fi
194 cd chromium-$pkgver
195
196 # Allow building against system libraries in official builds
197 sed -i 's/OFFICIAL_BUILD/GOOGLE_CHROME_BUILD/' \
198 tools/generate_shim_headers/generate_shim_headers.py
199
200 # https://crbug.com/893950
201 sed -i -e 's/\<xmlMalloc\>/malloc/' -e 's/\<xmlFree\>/free/' \
202 -e '1i #include <cstdlib>' \
203 third_party/blink/renderer/core/xml/*.cc \
204 third_party/blink/renderer/core/xml/parser/xml_document_parser.cc \
205 third_party/libxml/chromium/*.cc
206
207 # Use the --oauth2-client-id= and --oauth2-client-secret= switches for
208 # setting GOOGLE_DEFAULT_CLIENT_ID and GOOGLE_DEFAULT_CLIENT_SECRET at
209 # runtime -- this allows signing into Chromium without baked-in values
210 patch -Np1 -i ../use-oauth2-client-switches-as-default.patch
211
212 # Upstream fixes
213
214 # Fixes from Gentoo
215 patch -Np1 -i ../chromium-138-nodejs-version-check.patch
216
217 # Allow libclang_rt.builtins from compiler-rt >= 16 to be used
218 patch -Np1 -i ../compiler-rt-adjust-paths.patch
219
220 # Increase _FORTIFY_SOURCE level to match Arch's default flags
221 patch -Np1 -i ../increase-fortify-level.patch
222
223 # clang 22 lacks -fsanitize-ignore-for-ubsan-feature, which is needed to use
224 # -fsanitize=array-bounds without triggering UBSan feature detection. Without
225 # feature detection suppression, V8 compiles in __sanitizer_set_death_callback
226 # calls that require the UBSan runtime, which is not linked in a trap-mode
227 # build. Drop the entire sanitize_c_array_bounds cflags block.
228 # Can be dropped when arch has LLVM 23.
229 patch -Np1 -i ../chromium-149-drop-unknown-clang-flag.patch
230
231 # Causes a build failure with our clang version
232 patch -Np1 -i ../chromium-147-revert-clang-no-lifetime-dse-flag.patch
233
234 # https://crbug.com/456218403
235 patch -Np1 -i ../chromium-145-fix-SYS_SECCOMP.patch
236
237 patch -Np1 -i ../chromium-147-rust-1.95-bytemuck.patch
238
239 # enable widevine for arm64
240 patch -Np1 -i ../enable-widevine-arm64.patch
241
242 # https://crbug.com/456677057
243 patch -Np1 -i ../glibc-2.42-baud-rate-fix.patch
244
245 patch -Np1 -i ../chromium-149-use-of-undeclared-identifier-ERROR.patch
246
247 # Fix issue about missing AVX functions
248 # Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
249 patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
250
251 # Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3
252 patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src
253
254 patch -Np1 -i ../chromium-152-unbundle-minizip-undo-unicode.patch
255
256 patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch
257
258 # Use system python3 instead of the hermetic cpython3 interpreter
259 # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
260 patch -Np1 -i ../chromium-153-hermetic-python.patch
261
262 # third_party/iamf_tools includes vendored Opus via relative "include/opus.h"
263 # paths that only resolve against a real bundled Opus checkout; fix them up
264 # for the unbundled system Opus build
265 patch -Np1 -i ../chromium-153-iamf-tools-unbundled-opus.patch
266
267 # Work around TypeScript becoming a build dependency: disable tsgo for the
268 # WebUI and point devtools at the system tsc binary
269 # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
270 patch -Np1 -i ../chromium-153-typescript.patch
271
272 patch -Np1 -i ../chromium-153-crubit.patch
273
274 # Custom Patches
275
276 # You can now set '1' in the flag #omnibox-ui-max-autocomplete-matches to
277 # effectively disable autocompletion in the url bar (and therefore the so-
278 # called 'shoulder surfing').
279 patch -p1 -i ../no-omnibox-suggestion-autocomplete.patch
280
281 if (( !_system_clang )); then
282 # Use prebuilt rust as system rust cannot be used due to the error:
283 # error: the option `Z` is only accepted on the nightly compiler
284 ./tools/rust/update_rust.py
285
286 # To link to rust libraries we need to compile with prebuilt clang
287 ./tools/clang/scripts/update.py
288 else
289 # To fix missing libadler.rlib
290 sed -i 's/rustc_nightly_capability = use_chromium_rust_toolchain/rustc_nightly_capability = true/' \
291 build/config/rust.gni
292 fi
293
294
295 # Ungoogled Chromium changes
296 _ungoogled_repo="$srcdir/${pkgname%xdg*}$_uc_ver"
297
298 _utils="${_ungoogled_repo}/utils"
299 msg2 'Pruning binaries'
300 python "$_utils/prune_binaries.py" ./ "$_ungoogled_repo/pruning.list"
301 msg2 'Applying patches'
302 python "$_utils/patches.py" apply ./ "$_ungoogled_repo/patches"
303 msg2 'Applying domain substitution'
304 python "$_utils/domain_substitution.py" apply -r "$_ungoogled_repo/domain_regex.list" \
305 -f "$_ungoogled_repo/domain_substitution.list" -c domainsubcache.tar.gz ./
306
307 # Link to system tools required by the build
308 mkdir -p third_party/node/linux/node-linux-x64/bin \
309 third_party/rust-toolchain/bin \
310 third_party/jdk/current/bin \
311 third_party/gperf/cipd/bin \
312 third_party/dawn/tools/golang/linux-amd64/bin
313 ln -s /usr/bin/node third_party/node/linux/node-linux-x64/bin/
314 if (( ! _manual_colne )); then
315 ln -s /usr/bin/rustc third_party/rust-toolchain/bin/
316 fi
317 ln -s /usr/bin/java third_party/jdk/current/bin/
318 ln -s /usr/bin/gperf third_party/gperf/cipd/bin/
319 ln -s /usr/bin/go third_party/dawn/tools/golang/linux-amd64/bin/
320
321 # Remove bundled libraries for which we will use the system copies; this
322 # *should* do what the remove_bundled_libraries.py script does, with the
323 # added benefit of not having to list all the remaining libraries
324 local _lib
325 for _lib in ${_unwanted_bundled_libs[@]}; do
326 find "third_party/$_lib" -type f \
327 \! -path "third_party/$_lib/chromium/*" \
328 \! -path "third_party/$_lib/google/*" \
329 \! -path "third_party/harfbuzz-ng/utils/hb_scoped.h" \
330 \! -regex '.*\.\(gn\|gni\|isolate\)' \
331 -delete
332 done
333
334 ./build/linux/unbundle/replace_gn_files.py \
335 --system-libraries "${!_system_libs[@]}"
336
337 # Generate missing header
338 if (( _manual_clone )); then
339 python3 build/util/lastchange.py -m DAWN_COMMIT_HASH \
340 -s third_party/dawn --revision gpu/webgpu/DAWN_VERSION \
341 --header gpu/webgpu/dawn_commit_hash.h
342 fi
343}
344
345build() {
346 make -C chromium-launcher-$_launcher_ver
347
348 cd chromium-$pkgver
349
350 if (( _system_clang )); then
351 export CC=clang
352 export CXX=clang++
353 export AR=ar
354 export NM=nm
355 else
356 local _clang_path="$PWD/third_party/llvm-build/Release+Asserts/bin"
357 export CC=$_clang_path/clang
358 export CXX=$_clang_path/clang++
359 export AR=$_clang_path/llvm-ar
360 export NM=$_clang_path/llvm-nm
361 fi
362
363
364 local _flags=(
365 'custom_toolchain="//build/toolchain/linux/unbundle:default"'
366 'host_toolchain="//build/toolchain/linux/unbundle:default"'
367 'is_official_build=true' # implies is_cfi=true on x86_64
368 'symbol_level=0' # sufficient for backtraces on x86(_64)
369 'treat_warnings_as_errors=false'
370 'fatal_linker_warnings=false'
371 'disable_fieldtrial_testing_config=true'
372 'blink_enable_generated_code_formatting=false'
373 'ffmpeg_branding="Chrome"'
374 'proprietary_codecs=true'
375 'rtc_use_pipewire=true'
376 'link_pulseaudio=true'
377 'use_custom_libcxx=true' # https://github.com/llvm/llvm-project/issues/61705
378 'use_sysroot=false'
379 'use_system_libffi=true'
380 'enable_widevine=true'
381 'use_qt5=false'
382 'use_qt6=true'
383 'moc_qt6_path="/usr/lib/qt6"'
384 'enable_platform_hevc=true'
385 'enable_hevc_parser_and_hw_decoder=true'
386 'use_clang_modules=false'
387 )
388
389 if [[ -n ${_system_libs[icu]+set} ]]; then
390 _flags+=('icu_use_data_file=false')
391 fi
392
393 # Append ungoogled chromium flags to _flags array
394 _ungoogled_repo="$srcdir/${pkgname%xdg*}$_uc_ver"
395 readarray -t -O ${#_flags[@]} _flags < "${_ungoogled_repo}/flags.gn"
396
397
398 if (( _system_clang )); then
399 local _clang_version=$(
400 clang --version | grep -m1 version | sed 's/.* \([0-9]\+\).*/\1/')
401
402 _flags+=(
403 'clang_base_path="/usr"'
404 'clang_use_chrome_plugins=false'
405 "clang_version=\"$_clang_version\""
406 'chrome_pgo_phase=0' # needs newer clang to read the bundled PGO profile
407 )
408
409 # Allow the use of nightly features with stable Rust compiler
410 # https://github.com/ungoogled-software/ungoogled-chromium/pull/2696#issuecomment-1918173198
411 export RUSTC_BOOTSTRAP=1
412
413 _flags+=(
414 'rust_sysroot_absolute="/usr"'
415 'rust_bindgen_root="/usr"'
416 "rustc_version=\"$(rustc --version | awk '{ print $2 ;}')\""
417 )
418 fi
419
420 # Facilitate deterministic builds (taken from build/config/compiler/BUILD.gn)
421 CFLAGS+=' -Wno-builtin-macro-redefined'
422 CXXFLAGS+=' -Wno-builtin-macro-redefined'
423 CPPFLAGS+=' -D__DATE__= -D__TIME__= -D__TIMESTAMP__='
424
425 # Do not warn about unknown warning options
426 CFLAGS+=' -Wno-unknown-warning-option'
427 CXXFLAGS+=' -Wno-unknown-warning-option'
428
429 # Let Chromium set its own symbol level
430 CFLAGS=${CFLAGS/-g }
431 CXXFLAGS=${CXXFLAGS/-g }
432
433 # https://github.com/ungoogled-software/ungoogled-chromium-archlinux/issues/123
434 CFLAGS=${CFLAGS/-fexceptions}
435 CFLAGS=${CFLAGS/-fcf-protection}
436 CXXFLAGS=${CXXFLAGS/-fexceptions}
437 CXXFLAGS=${CXXFLAGS/-fcf-protection}
438
439 # This appears to cause random segfaults when combined with ThinLTO
440 # https://bugs.archlinux.org/task/73518
441 CFLAGS=${CFLAGS/-fstack-clash-protection}
442 CXXFLAGS=${CXXFLAGS/-fstack-clash-protection}
443
444 # https://crbug.com/957519#c122
445 CXXFLAGS=${CXXFLAGS/-Wp,-D_GLIBCXX_ASSERTIONS}
446
447 if [[ $CARCH == aarch64 ]] || [[ $CARCH == riscv64 ]]; then
448 # On aarch64 and riscv64, certain files (e.g. in libvpx and libyuv) needs to
449 # be compiled with additional arch features (e.g. dotprod, sve, sme, rvv)
450 # Having an arch setting in the C(XX)FLAGS overrides those
451 # and causes compilation failure
452 CFLAGS="${CFLAGS/-march=*([^ ]) }"
453 CXXFLAGS="${CXXFLAGS/-march=*([^ ]) }"
454 fi
455
456 gn gen out/Release --args="${_flags[*]}"
457 ninja -C out/Release chrome chrome_sandbox chromedriver
458}
459
460package() {
461 cd chromium-launcher-$_launcher_ver
462 make PREFIX=/usr DESTDIR="$pkgdir" install
463 install -Dvm644 LICENSE \
464 "$pkgdir/usr/share/licenses/chromium/LICENSE.launcher"
465
466 cd ../chromium-$pkgver
467
468 install -Dv out/Release/chrome "$pkgdir/usr/lib/chromium/chromium"
469 install -Dv out/Release/chromedriver "$pkgdir/usr/bin/chromedriver"
470 install -Dvm4755 out/Release/chrome_sandbox "$pkgdir/usr/lib/chromium/chrome-sandbox"
471
472 install -Dvm644 chrome/installer/linux/common/desktop.template \
473 "$pkgdir/usr/share/applications/chromium.desktop"
474 install -Dvm644 chrome/app/resources/manpage.1.in \
475 "$pkgdir/usr/share/man/man1/chromium.1"
476 sed -i \
477 -e 's/@@MENUNAME/Chromium/g' \
478 -e 's/@@PACKAGE/chromium/g' \
479 -e 's/@@usr_bin_symlink_name/chromium/g' \
480 -e 's|@@uri_scheme|x-scheme-handler/chromium;|g' \
481 -e 's/@@extra_desktop_entries//g' \
482 "$pkgdir/usr/share/applications/chromium.desktop" \
483 "$pkgdir/usr/share/man/man1/chromium.1"
484
485 # Fill in common Chrome/Chromium AppData template with Chromium info
486 (
487 tmpl_file=chrome/installer/linux/common/appdata.xml.template
488 info_file=chrome/installer/linux/common/chromium-browser.info
489 . $info_file; PACKAGE=chromium
490 export $(grep -o '^[A-Z_]*' $info_file)
491 sed -E -e 's/@@([A-Z_]*)/\${\1}/g' -e '/<update_contact>/d' $tmpl_file | envsubst
492 ) \
493 | install -Dvm644 /dev/stdin "$pkgdir/usr/share/metainfo/chromium.appdata.xml"
494
495 local toplevel_files=(
496 chrome_100_percent.pak
497 chrome_200_percent.pak
498 chrome_crashpad_handler
499 libqt6_shim.so
500 resources.pak
501 v8_context_snapshot.bin
502
503 # ANGLE
504 libEGL.so
505 libGLESv2.so
506
507 # SwiftShader ICD
508 libvk_swiftshader.so
509 libvulkan.so.1
510 vk_swiftshader_icd.json
511 )
512
513 if [[ -z ${_system_libs[icu]+set} ]]; then
514 toplevel_files+=(icudtl.dat)
515 fi
516
517 cp "${toplevel_files[@]/#/out/Release/}" "$pkgdir/usr/lib/chromium/"
518 install -Dvm644 -t "$pkgdir/usr/lib/chromium/locales" out/Release/locales/*.pak
519
520 for size in 24 48 64 128 256; do
521 install -Dvm644 "chrome/app/theme/chromium/product_logo_$size.png" \
522 "$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/chromium.png"
523 done
524
525 for size in 16 32; do
526 install -Dvm644 "chrome/app/theme/default_100_percent/chromium/product_logo_$size.png" \
527 "$pkgdir/usr/share/icons/hicolor/${size}x${size}/apps/chromium.png"
528 done
529
530 install -Dvm644 LICENSE "$pkgdir/usr/share/licenses/chromium/LICENSE"
531}
532
533# vim:set ts=2 sw=2 et:
534

Changes since previous scan

--- PKGBUILD @ 2026-09-15 00:25
+++ PKGBUILD @ 2026-09-17 00:27
@@ -12,7 +12,7 @@
# binary version of this package (-bin): github.com/noahvogt/ungoogled-chromium-xdg-bin-aur
pkgname=ungoogled-chromium-xdg
-pkgver=152.0.7977.75
+pkgver=153.0.8010.36
pkgrel=1
_launcher_ver=8
_manual_clone=0
@@ -72,11 +72,13 @@
'lld'
'ninja'
'nodejs'
+ 'opus'
'pipewire'
'python'
'qt6-base'
+ 'rust'
'rust-bindgen'
- 'rust'
+ 'typescript'
)
optdepends=('pipewire: WebRTC desktop sharing under Wayland'
'kdialog: support for native dialogs in Plasma'
@@ -96,11 +98,13 @@
chromium-149-drop-unknown-clang-flag.patch
chromium-149-use-of-undeclared-identifier-ERROR.patch
chromium-150-revert-avx-flag-change.patch
- chromium-152-crubit.patch
- chromium-152-dawn-llvm-22.patch
chromium-152-fix-gn-no-public_inputs.patch
chromium-152-unbundle-minizip-undo-unicode.patch
chromium-152-unbundle-opus-devtools.patch
+ chromium-153-hermetic-python.patch
+ chromium-153-iamf-tools-unbundled-opus.patch
+ chromium-153-typescript.patch
+ chromium-153-crubit.patch
compiler-rt-adjust-paths.patch
increase-fortify-level.patch
enable-widevine-arm64.patch
@@ -108,21 +112,23 @@
glibc-2.42-baud-rate-fix.patch
# ungoogled-chromium-xdg patches
no-omnibox-suggestion-autocomplete.patch)
-sha256sums=('12379ddd4cdce9c318787c32f438dcf386df59b72ba508eb9f9ece54be44eb66'
- '0754581d607ab3806cb5dbb319f28d0bb0cddfe6c64015b59dff7d40c859cddb'
+sha256sums=('645f64566cfbb780747430d53ff3656f03639f89fed9544c1eadd4c17e7b1c82'
+ '8df8570d440a9117c187f1c466386543381c52bb9044817670df8a741423ca12'
'213e50f48b67feb4441078d50b0fd431df34323be15be97c55302d3fdac4483a'
'11a96ffa21448ec4c63dd5c8d6795a1998d8e5cd5a689d91aea4d2bdd13fb06e'
'4fc040a0656a0a524dd8ad090cd129fc5b6cb21adcc66be82080165789e8c13e'
'c382830318c5b37826ecf44f3ba9def6be8affdad1bce819ecb83f3222ff4b3a'
'b9e6339221efe03540ffb360c161d93604a1fc93a5a1c53e5e9849066f987d05'
- 'e25cf8fb60f5958127053c515b8decc2b45acceebf9a57654066d093df11f8e9'
+ '1b5190fa030850cf30a97dc90e35b31f3097243c88743fbfaedbd64ea80f1327'
'951514535be65f0e2f84e82305d96292be1da353c1427ba1048ea24be70003c4'
'5f6ccb7b945c8a13c690493723bad816b36f2f25792d47e677b56f8200907e60'
- '6cf0b76bc5d9c9bb82ecde1fa87ed1f4380b4bbd29ea485261e5f2aada5d71ea'
- '5e465d199c1a28d58078af08bcab151561d6423f43c6dba57d4db3f5de534140'
- '5c4640a211d02ba8249299842ea2999ccc239d85bfd59a0f7c302483683adc07'
+ '50115642099ac131f40c419cbd12ed72e352538002d4bdc11ab657335891d03b'
'890e5d98088ef1c7c075a551442f03385d1db266cad8a65576704a22720683f9'
'3276453f2ce655b6286476f48d4df837be952d9447afa46583f79ec71f2288c3'
+ 'ebf74154266d0b6d6cc957c413f845052c5fcfce7745befb8821595cdf3f7d49'
+ '2ab9fbe653829ce692f83ee780aad07e8c83a6686e51ab9459ad736cfa2850ee'
+ '44c86a7c26d726559d5bd06a64f81e6bcced7ab4dc949c899e4fd2c64ff37a16'
+ 'a20e615fa03713e464fc3f2966c84e2130b6d942a4c8b5919ba0bf8320d39ed4'
'ec8e49b7114e2fa2d359155c9ef722ff1ba5fe2c518fa48e30863d71d3b82863'
'd634d2ce1fc63da7ac41f432b1e84c59b7cceabf19d510848a7cff40c8025342'
'5ee4bb69379ac0cea7946c9f8f4ca9e20e0a9e4ee2ee9121eb0ebbb94dd7e928'
@@ -149,6 +155,7 @@
[fontconfig]=fontconfig
[freetype]=freetype2
[harfbuzz]=harfbuzz
+ [highway]=highway
#[icu]=icu
#[jsoncpp]=jsoncpp # needs libstdc++
#[libaom]=aom
@@ -241,16 +248,28 @@
# Credit: https://github.com/ungoogled-software/ungoogled-chromium/pull/3837
patch -Np1 -i ../chromium-150-revert-avx-flag-change.patch
- patch -Np1 -i ../chromium-152-crubit.patch
-
- patch -Np1 -i ../chromium-152-dawn-llvm-22.patch
-
# Just the reverted commit 8dab8b761385b7946588232e4e2a8c116f9293c3
patch -Np1 -i "$srcdir/chromium-152-fix-gn-no-public_inputs.patch" -d third_party/devtools-frontend/src
patch -Np1 -i ../chromium-152-unbundle-minizip-undo-unicode.patch
patch -Np1 -i ../chromium-152-unbundle-opus-devtools.patch
+
+ # Use system python3 instead of the hermetic cpython3 interpreter
+ # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+ patch -Np1 -i ../chromium-153-hermetic-python.patch
+
+ # third_party/iamf_tools includes vendored Opus via relative "include/opus.h"
+ # paths that only resolve against a real bundled Opus checkout; fix them up
+ # for the unbundled system Opus build
+ patch -Np1 -i ../chromium-153-iamf-tools-unbundled-opus.patch
+
+ # Work around TypeScript becoming a build dependency: disable tsgo for the
+ # WebUI and point devtools at the system tsc binary
+ # https://github.com/ungoogled-software/ungoogled-chromium/pull/3946
+ patch -Np1 -i ../chromium-153-typescript.patch
+
+ patch -Np1 -i ../chromium-153-crubit.patch
# Custom Patches

Scan history

Scanned at (UTC)SeverityRules
2026-09-17 00:27:14 Low 2
2026-09-16 00:03:17 Low 2
2026-09-15 05:18:46 Medium 1
2026-09-15 00:25:31 Low 2
2026-09-14 00:27:57 Low 2
2026-09-13 00:19:54 Low 2
2026-09-12 00:25:17 Low 2
2026-09-11 00:19:22 Low 2
2026-09-10 00:22:44 Low 2
2026-09-09 00:04:09 Low 2
2026-09-08 00:18:08 Low 2
2026-09-07 00:30:15 Low 2
2026-09-06 00:17:06 Low 2
2026-09-05 03:59:20 Medium 1
2026-09-05 00:16:27 Low 2
2026-09-04 07:57:01 Medium 1
2026-09-04 00:03:13 Low 2
2026-09-03 00:15:47 Low 2
2026-09-02 00:02:31 Low 2
2026-09-01 00:11:19 Low 2

Report a package

Reports go to the AURWatch maintainer (one person) and are read by hand. No login required.

0 / 4000
Your suggestion