This change updades our checker to use the newer version and keeps a
nullified implementation for the new method added to this new class.
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/75b2acce79497326ac3388f8d3e6d03a21b1459e
commit 75b2acce79497326ac3388f8d3e6d03a21b1459e
Author: Haihan Chen <haihan@google.com>
Date: Thu Apr 9 08:57:26 2026 -0700
[GLIC CEP Paste Support] Merge actor enterprise checks into single `EnterprisePolicyChecker` interface
To simplify the API and avoid extra param for actor tasks for content
policy checks specifically, since glic is the only user and implements
both url and content checks in a single class right now
(`glicactorpolicychecker`).
This is a refactor, content validation usage in tools like `PageTool` in
follow-up CL.
Bug: 473047343
Change-Id: I8fb9b45955ccff15c3331af445df05dfcc589ac4
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7735646
Reviewed-by: Kevin McNee <mcnee@chromium.org>
Commit-Queue: Haihan Chen <haihan@google.com>
Cr-Commit-Position: refs/heads/main@{#1612275}
This the componentisation of these files, we do not need anymore to
include these sources ourselves in `brave_browser_tests`.
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/e0cd9afb25e911c62c8c096ef55816bd9e3b665e
commit e0cd9afb25e911c62c8c096ef55816bd9e3b665e
Author: Tiago Vignatti <tvignatti@igalia.com>
Date: Thu Apr 9 07:28:31 2026 -0700
Componentize chrome/browser/ui/test/
This changes create chrome/browser/ui/test/BUILD.gn with dedicated
targets for all test files in this directory, which were previously
scattered across chrome/test/BUILD.gn and chrome/browser/ui/BUILD.gn.
Some of the files were duplicated in multiple targets, and has now
fixed.
New targets:
- :dialog — moved from //chrome/test:test_support and de-duplicated from
browser_tests/interactive_ui_tests
- :closed_waiter — moved from //chrome/test:test_support_ui
- :test_support — de-duplicated and moved from browser_tests,
interactive_ui_tests, and //chrome/browser/ui:test_support
- :confirm_bubble — moved from //chrome/browser/ui:test_support
- :browser_tests — browser test files
- :interactive_ui_tests — interactive UI test files
- :app_window — moved from //chrome/browser/ui:test_support
Bug: 353332589
Change-Id: I602615d0b8a96af88af82cf1caaf75a3a2184d07
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7704138
Reviewed-by: Darryl James <dljames@chromium.org>
Commit-Queue: Tiago Vignatti <tvignatti@igalia.com>
Cr-Commit-Position: refs/heads/main@{#1612208}
This recent change requires us to fix our own overrides and callers for
these functions.
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/1575bebcd1c16fa1508c87eda06c5b3b1c364c3c
commit 1575bebcd1c16fa1508c87eda06c5b3b1c364c3c
Author: Duncan Mercer <mercerd@google.com>
Date: Wed Apr 8 15:31:53 2026 -0700
[Blink/Network] Support origin targeting for secure exemptions
This change updates WebSecurityPolicy to support origin targeting
for secure embedder exceptions by allowing specific origins instead
of applying globally to an entire scheme.
It also migrates secure cookie exemptions—specifically those affecting
third-party cookie blocking and SameSite restrictions—in CookieManager
and CookieSettings from scheme/host-based registration to
url::Origin-based registration. This enables precise, unscoped
exemptions for secure origins (such as chrome-untrusted://lens)
without modifying the properties or behavior of the cookie origin
itself.
Bug: b:483614998
Change-Id: I7fe2a00e631513c6ebcdb5fb996914f5b48a9447
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7689068
Reviewed-by: Daniel Cheng <dcheng@chromium.org>
Reviewed-by: Nidhi Jaju <nidhijaju@chromium.org>
Reviewed-by: Dylan Cutler <dylancutler@google.com>
Commit-Queue: Duncan Mercer <mercerd@google.com>
Reviewed-by: Joshua Hood <jdh@chromium.org>
Reviewed-by: Lily Chen <chlily@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1611822}
This change corrects several places to pass `TranslateUrlFetcher` into
`TranslateLanguageList`.
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/6aef37c345ee6449713a213c04878417dd87d0c4
commit 6aef37c345ee6449713a213c04878417dd87d0c4
Author: Danilo Françoso Tedeschi <danft@google.com>
Date: Wed Apr 8 06:26:11 2026 -0700
Replace static DisableUpdate with dependency injection for TranslateLanguageList.
This change removes the global static flag `update_is_disabled` from TranslateLanguageList and instead allows injecting a TranslateUrlFetcher instance. This improves testability by allowing mock fetchers to be used without relying on global state. TranslateDownloadManager now has a setter for its TranslateLanguageList.
Change-Id: I739659aba52e95e6236e0b5d85fd9672b090c864
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7719220
Reviewed-by: Basia Zimirska <basiaz@google.com>
Commit-Queue: Danilo Françoso Tedeschi <danft@google.com>
Cr-Commit-Position: refs/heads/main@{#1611437}
This used to be an alias to:
```cxx
using BubbleAnchor = std::variant<std::nullptr_t, View*, ui::TrackedElement*>;
```
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/1ba6a69579ba3b5f5925ff77a390be5a99d748e7
commit 1ba6a69579ba3b5f5925ff77a390be5a99d748e7
Author: Maks Orlovich <morlovich@chromium.org>
Date: Tue Apr 7 11:33:31 2026 -0700
Make BubbleAnchor an own class.
The variant implementation has a property that seems very unfortunate:
it has 3 possible places it can store nullptr, which makes it tricky to
reason about and work with, e.g.:
BubbleAnchor Foo() {
if (View* view = Bar()) {
return view;
}
return nullptr;
}
is not equivalent to: BubbleAnchor Foo() {
return Bar();
}
It's also somewhat awkward to use, and can't be forward declared.
The class wrapper normalizes the nulls. It also gives it is own
header (and can be forward declared).
Change-Id: I2aacb894ee995af7fd012f2762826cd30f277179
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7647509
Reviewed-by: Dana Fried <dfried@chromium.org>
Commit-Queue: Maks Orlovich <morlovich@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1610910}
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/ddd5ffe0ad3129bb03508ab864465e77f0e50bedhttps://chromium.googlesource.com/chromium/src/+/2174233eeebf04d1a671c66f2be7b630e6117de0
commit ddd5ffe0ad3129bb03508ab864465e77f0e50bed
Author: Yu He <yhe@microsoft.com>
Date: Wed Apr 8 12:02:16 2026 -0700
[bedrock] Remove unused chrome::FindAnyBrowser()
The FindAnyBrowser() function in browser_finder.h
is unused. Its declaration already carried a warning ("Do not use this
method"), and there are no remaining callers in the codebase.
Remove the declaration and definition to reduce dead code.
Bug: 494010890
Change-Id: Iec391a4c4f9001726daf4b350fc3e3eccafe9017
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7736509
Commit-Queue: Tom Lukaszewicz <tluk@chromium.org>
Auto-Submit: Yu He <yhe@microsoft.com>
Reviewed-by: Tom Lukaszewicz <tluk@chromium.org>
Reviewed-by: Qikai Zhong <qikaizhong@microsoft.com>
Cr-Commit-Position: refs/heads/main@{#1611701}
commit 2174233eeebf04d1a671c66f2be7b630e6117de0
Author: yhe <yhe@microsoft.com>
Date: Sun Mar 29 15:57:42 2026 -0700
[bedrock] Move FindAnyBrowser to ui_test_utils
Migrate chrome::FindAnyBrowser() into ui_test_utils::FindAnyBrowser(),
reimplementing it on top of GlobalBrowserCollection and
BrowserWindowInterface instead of the legacy Browser-based APIs.
The new helper:
- Returns BrowserWindowInterface* (instead of Browser*).
- Iterates browsers via GlobalBrowserCollection::ForEach() in
activation order.
- Skips delete-scheduled browsers.
- On ChromeOS, excludes windows shown on another user's desktop
via ash::MultiUserWindowManager.
- Defaults match_original_profiles to true (most callers used true).
Update all test call-sites to use the new function:
- session_login_browsertest.cc
- profile_window_browsertest.cc
- browser_finder_chromeos_browsertest.cc
- browser_finder_chromeos_unittest.cc
- toolbar_view_interactive_uitest.cc
Add the required BUILD.gn deps (//chrome/browser/ui/browser_window,
//chrome/browser/ui/ash/multi_user, //chrome/test:test_support_ui).
Bug: 494010890
Change-Id: I07701d0c20514e51ead54c3367ddfbb0317735a6
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7686930
Reviewed-by: Qikai Zhong <qikaizhong@microsoft.com>
Reviewed-by: Tom Lukaszewicz <tluk@chromium.org>
Commit-Queue: Tom Lukaszewicz <tluk@chromium.org>
Auto-Submit: Yu He <yhe@microsoft.com>
Cr-Commit-Position: refs/heads/main@{#1606838}
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/57a7dfb4e2645b9c62d3a005436c815f4314b5e6https://chromium.googlesource.com/chromium/src/+/a65d0fd3d0c70c37e7ac03bbc7389961eb69e66d
commit 57a7dfb4e2645b9c62d3a005436c815f4314b5e6
Author: Daniel Cheng <dcheng@chromium.org>
Date: Tue Apr 7 01:29:42 2026 -0700
Remove base/logging.h include from validation_errors.h
This header is included in many C++ source files generated from .mojom
and is fairly heavyweight. While moving the logging out of the headers
is straightforward, array validation failures generate a std::string
with some runtime details. `std::string_view` handles both cases nicely,
but there is value in minimizing the includes in this file as much as
possible. `const char*` and using `.c_str()` was the initial approach
considered, but discarded as a bit too hacky after some prototyping.
Instead, the helpers that create additional context for array validation
failures now return a struct with details about the failure. The various
validation error reporting functions have additional overloads that
internally stringify the details so that validation errors are still
reported in the exact same way.
gemini-cli was used to quickly prototype some ideas as well as implement
the overall CL, with some manual followups to improve naming and reduce
duplication.
One unintended side effect is a minor improvement in binary size, since
the new error detail structs are trivially destructible, unlike
std::string.
Bug: 499476145
Change-Id: If52b10f4928b7920ea7b120754a1798c125fefa7
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7730404
Commit-Queue: Daniel Cheng <dcheng@chromium.org>
Reviewed-by: Lei Zhang <thestig@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1610607}
commit a65d0fd3d0c70c37e7ac03bbc7389961eb69e66d
Author: Daniel Cheng <dcheng@chromium.org>
Date: Tue Apr 7 01:23:35 2026 -0700
Fix several more IWYU errors for base/logging.h
Bug: 499476145
Change-Id: Iba431f2c534365f9ea575c9be86bd70e8fa6a268
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7732103
Owners-Override: Takuto Ikuta <tikuta@chromium.org>
Reviewed-by: Takuto Ikuta <tikuta@chromium.org>
Reviewed-by: Kentaro Hara <haraken@chromium.org>
Reviewed-by: Kouhei Ueno <kouhei@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1610606}
This feature was being disabled in Brave.
Chromium changes:
https://chromium.googlesource.com/chromium/src/+/d57f3260469cb57abc0109976110a760d30dcfbb
commit d57f3260469cb57abc0109976110a760d30dcfbb
Author: Andrew Paseltiner <apaseltiner@chromium.org>
Date: Wed Apr 8 14:15:25 2026 -0700
Remove experimental CSSSelectorFragmentAnchor feature
The CSSSelectorFragmentAnchor feature was an experimental extension to
fragment directives that has not seen active development in years and
has never been officially specified. Furthermore, the implementation
lacked certain security controls (crbug.com/497956094) discussed in the
feature proposal
(https://github.com/WICG/scroll-to-text-fragment/blob/main/EXTENSIONS.md#proposed-solution).
This CL removes the implementation, including:
- The CssSelectorFragmentAnchor and CssSelectorDirective classes.
- The CSSSelectorFragmentAnchor runtime-enabled feature flag.
- The -internal-selector-fragment-anchor pseudo-class.
- Associated UA styles and metrics.
The createSelectorDirective() JS API is preserved as it is used by the
Text Fragments feature to generate TextDirectives. Related WPTs are
updated to remove CssSelector specific tests while maintaining coverage
for general directive parsing.
Bug: 1253707, 40203851, 40203761, 497956094
Change-Id: I2b11bdbde4475e48693f182ecca3c0bf9c79c198
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7735903
Reviewed-by: Sebastien S-G <sebsg@chromium.org>
Commit-Queue: Andrew Paseltiner <apaseltiner@chromium.org>
Reviewed-by: Rick Byers <rbyers@chromium.org>
Cr-Commit-Position: refs/heads/main@{#1611777}
Redesigned Manage Password Detail screen in iOS Settings with a SwiftUI-based UI following Figma spec.
Added a new view for displaying passwords belonging to the same domain (Password Group).
The user is able to delete passwords in the group.
Also updated authentication challenge to be performed before entering Manage Passwords.
New SwiftUI Components
ManagePasswordDetailView – Displays the contents of a CWVPassword object:
- Provides menu to copy content on tap
- Securely copies password into paste board
- Hides passwords by default
- Provides a reveal button
ManagePasswordGroupViewMode - Data model for showing and modifying passwords in a group.
- Edit mode for multi-select and bulk delete
- For future Add password to the group (next PR)
ManagePasswordGroupView – Displays a group of password items belonging to the same domain.
Add an enable_brave_stats_updater buildflag that defaults to
!is_brave_origin_branded, following the pattern used by other features
(enable_brave_ads, enable_brave_rewards, etc.). On Brave Origin builds,
exclude brave_stats_updater.cc/.h and its tests via GN, guard callers
with #if BUILDFLAG, and put a static_assert in the header so any
accidental include fails with a clear error.
Resolves https://github.com/brave/brave-browser/issues/55595
* Remove `brave_compact_horizontal_tabs_layout.h` and colocate
constants with existing metrics in `layout_constants.h`.
* Inline constant values into metric accessor helpers.
* Increase clarity of code comments.
This PR introduces the YAML frontend for plaster that is meant to
eventually become the only frontend, once all `.toml` Plaster files are
migrated.
This change covers all places where the assumption about `.toml` files
was being used, inclusing `brockit`, and `git-cr` tools.
Most of the code that should be deleted in the future is well guarded
with comments leading back to the issue tracking, so the TOML parser can
be dropped eventually.
With this change, a dependency to `pyyaml` has been introduced. This
dependency has wheels provided by `vpython`, which is already the
expected python runtime for Plaster.
- Rationale for this change
We have experimented at length with `.toml` files, in order to
understand some of the shortcomings they have that would be addressed
with `.yaml` files.
* `prettier` offers YAML formatting out-of-the-box. On the other hand,
formatters for TOML files are not easy to find, as both `prettier`
and `vpython` have their own challanges with the current options
* YAML's sytanx works better with codeblocks, as it doesn't require
quoting. This makes the content seen less noisy. Looking on some of
the migrated plasters, the YAML substitutions look more readable.
* YAML has better sytanx highlight support in some editors.
Bug: https://github.com/brave/brave-browser/issues/55738
* [Origin] Honor BraveRewardsDisabled policy when starting Rewards engine
Defer `RewardsServiceImpl::CheckPreferences()` -- the gate that decides
whether to spin up the Rewards engine process -- behind a
`brave_policy::PolicyInitializationWaiter` so that the managed
`brave_rewards::prefs::kDisabledByPolicy` pref is visible by the time the
gate evaluates. Without this, `Init()` runs before the policy bundle has
been merged into the managed pref store and the engine starts -- pinging
`/v1/parameters` and `/v4/wallets/...` -- even when Brave Origin has
disabled Rewards via `BraveRewardsDisabled`.
Resolves: https://github.com/brave/brave-browser/issues/55696
This PR introduces some fallback parsing for `tomllib` use, when running
this script in a machine with a python version older than `3.11`. This
will be necessary for the time being with the Linux node still using
Python 3.10.
On Mac, we use a server-status endpoint for OnDemand VPN functionality.
The change upgrades the old (current) API `/vpnsrv/api/server-status`,
to the new one: `/api/v1.3/server-status`. The API responses are
claimed by Guardian to be identical, zero behavioural change.
On Windows, we have to manually correct the default the `ar`
`config.toml` value to `llvm-ar.exe`, as Windows defaults as a normal
Windows build uses `llvm-lib.exe`.