From 69273cc9bb8a258377e18216048bd01af1f924d5 Mon Sep 17 00:00:00 2001
From: uazo <29201891+uazo@users.noreply.github.com>
Date: Wed, 29 Oct 2025 17:06:30 +0000
Subject: [PATCH] [AUTO][DOC] Generate patches doc for master branch
---
docs/PATCHES.md | 2 ++
1 file changed, 2 insertions(+)
diff --git a/docs/PATCHES.md b/docs/PATCHES.md
index 687cc95d..e0071765 100644
--- a/docs/PATCHES.md
+++ b/docs/PATCHES.md
@@ -94,6 +94,7 @@
|**Disable Read Aloud by default**
Wed, 24 Jan 2024 12:19:44 +0000
File: [Disable-Read-Aloud-by-default.patch](/build/patches/Disable-Read-Aloud-by-default.patch)
Author: uazo
Context:
License: ||
|**Disable Real Box**
Sun, 5 Nov 2023 17:59:54 +0000
File: [Disable-Real-Box.patch](/build/patches/Disable-Real-Box.patch)
Author: uazo
Context:
License: |Real-box is search box in ntp|
|**Disable Service and Shared workers on 3P iframe**
Sun, 5 Nov 2023 18:05:19 +0000
File: [Disable-Service-and-Shared-workers-on-3P-iframe.patch](/build/patches/Disable-Service-and-Shared-workers-on-3P-iframe.patch)
Author: uazo
Context:
License: GPL-2.0-or-later |Disabled by default due https://bugs.chromium.org/p/chromium/issues/detail?id=1147281
Workers can be reenabled per top-site-url using "Allow 3P Cookies"
("Block 3P Cookies" in ui to off) in site settings|
+|**Disable Sticky User Activation Across Same Origin Navigation**
Wed, 29 Oct 2025 13:01:41 +0000
File: [Disable-Sticky-User-Activation-Across-Same-Origin-Navigation.patch](/build/patches/Disable-Sticky-User-Activation-Across-Same-Origin-Navigation.patch)
Author: uazo
Context:
License: GPL-2.0-or-later |Do not retains the user activation status after navigating
from one page to another page of the same origin.
It is currently not possible to remove activation once it has been granted.|
|**Disable TLS resumption**
Thu, 24 Mar 2022 10:08:00 +0000
File: [Disable-TLS-resumption.patch](/build/patches/Disable-TLS-resumption.patch)
Author: uazo
Context:
License: GPL-3.0-only |Disable resumption feature for all HTTPS and QUIC connections;
the feature could be used to track users even without cookies.
Sessions are not currently saved to disk in Chromium (although
there is support for it) but are long enough to constitute a
privacy risk (2h for TLS 1.2 and 7 days for TLS 1.3) if user
does not frequently close the browser.
Since session information is not kept in the HTTP cache it is
not cleared when deleting navigation data (although it is possible
to clear it by selecting "passwords").
Two new user configurable flags are introduced:
* kDisableTLSResumption, active by default
* kLogTLSResumption, that would allow to find in logcat reused
sessions in lines matching "SSL Log:"
See also:
* https://arxiv.org/abs/1810.07304|
|**Disable UA full version**
Wed, 16 Feb 2022 14:28:58 +0000
File: [Disable-UA-full-version.patch](/build/patches/Disable-UA-full-version.patch)
Author: uazo
Context:
License: GPL-3.0-only |getHighEntropyValues will return only the major version|
|**Disable Viewport Segments**
Sat, 28 Jun 2025 08:17:07 +0000
File: [Disable-Viewport-Segments.patch](/build/patches/Disable-Viewport-Segments.patch)
Author: uazo
Context:
License: GPL-2.0-or-later |Disable Viewport Segments API, specifically for foldable devices,
since it exposes the geometry of the fold.|
@@ -268,6 +269,7 @@
|**Temp disable experimental-web-platform-features**
Mon, 2 Sep 2024 07:05:25 +0000
File: [Temp-disable-experimental-web-platform-features.patch](/build/patches/Temp-disable-experimental-web-platform-features.patch)
Author: uazo
Context:
License: ||
|**Temp disable predictive back gesture**
Sat, 12 Aug 2023 14:48:57 +0000
File: [Temp-disable-predictive-back-gesture.patch](/build/patches/Temp-disable-predictive-back-gesture.patch)
Author: uazo
Context:
License: GPL-2.0-or-later ||
|**Temp guard FileSystemAccessPersistentPermissions**
Sun, 29 Oct 2023 15:18:24 +0000
File: [Temp-guard-FileSystemAccessPersistentPermissions.patch](/build/patches/Temp-guard-FileSystemAccessPersistentPermissions.patch)
Author: uazo
Context:
License: ||
+|**Temp use PREVIEW for IDCompositionDevice5**
Wed, 29 Oct 2025 12:30:49 +0000
File: [Temp-use-PREVIEW-for-IDCompositionDevice5.patch](/build/patches/Temp-use-PREVIEW-for-IDCompositionDevice5.patch)
Author: uazo
Context:
License: GPL-2.0-or-later |Temporarily restore the statement from v141 while waiting to update the Windows SDK.
See Remove preview usage of DynamicTexture DComp APIs.
https://chromium-review.googlesource.com/c/chromium/src/+/6902339|
|**Timezone customization**
Wed, 30 Sep 2020 07:40:01 +0000
File: [Timezone-customization.patch](/build/patches/Timezone-customization.patch)
Author: uazo
Context:
License: GPL-3.0-only |Allow specifying a custom timezone, or using a random one.
See also: https://github.com/bromite/bromite/wiki/TimezoneOverride
Require: Content-settings-infrastructure.patch|
|**Try to fix 2082**
Thu, 15 May 2025 06:55:56 +0000
File: [Try-to-fix-2082.patch](/build/patches/Try-to-fix-2082.patch)
Author: uazo
Context:
License: ||
|**Use 64-bit WebView processes**
Thu, 26 Jan 2017 01:30:12 -0500
File: [Use-64-bit-WebView-processes.patch](/build/patches/Use-64-bit-WebView-processes.patch)
Author: Daniel
Context:
License: GPL-3.0-only |64-bit processes introduce 10% or so higher memory consumption.
The reason for preferring 64-bit processes is providing substantially better
exploit mitigations at the expense of slightly more memory usage.
In addition to the standard mitigations, it also enables usage of
https://github.com/AndroidHardening/hardened_malloc (where available).
It will provide high entropy ASLR (24-bit to 32-bit depending on whether the
kernel uses 3 or 4 level page tables rather than 16-bit for 32-bit processes),
high entropy stack canaries (56/64-bit instead of 24/32-bit depending on
whether a zero byte is used) and also features like pointer authentication and
memory tagging when those are made available in the future.
The reason why upstream started preferring 32-bit processes is to save memory,
particularly since saving memory makes it feasible to use finer-grained
sandboxing.|