fix(chromium): disable the WebUI omnibox popup preloaded at browser start

This commit is contained in:
Julien Neuhart
2026-09-09 19:38:40 +02:00
parent b16ce08da7
commit fb7536a526
2 changed files with 43 additions and 0 deletions

View File

@@ -23,6 +23,25 @@ import (
"github.com/gotenberg/gotenberg/v8/pkg/gotenberg"
)
// chromiumDisableFeatures is the value of Chromium's --disable-features
// switch.
//
// It restates the "site-per-process,Translate,BlinkGenPropertyTrees" default
// from chromedp.DefaultExecAllocatorOptions (chromedp v0.14.2) on purpose:
// chromedp.Flag keys its flags by switch name, so a second --disable-features
// replaces chromedp's value instead of merging with it. Revisit this list when
// bumping chromedp.
//
// WebUIOmniboxPopup and WebUIOmniboxAimPopup became enabled by default in
// Chromium 151.0.7922.132. Their presenters build the address-bar popup WebUI
// at browser start, headless included, which leaves a renderer process holding
// ~85 MB of anonymous memory for a UI a PDF service can never show. Chromium
// silently ignores feature names it does not know, so both stay harmless on
// older builds (they exist but default to disabled on the Chromium pinned for
// ppc64el) and once upstream eventually removes them.
// See https://github.com/gotenberg/gotenberg/issues/1656.
const chromiumDisableFeatures = "site-per-process,Translate,BlinkGenPropertyTrees,WebUIOmniboxPopup,WebUIOmniboxAimPopup"
type browser interface {
gotenberg.Process
pdf(ctx context.Context, logger *slog.Logger, url, outputPath string, options PdfOptions, aggregate *networkAggregate) error
@@ -133,6 +152,8 @@ func (b *chromiumBrowser) Start(logger *slog.Logger) error {
chromedp.Flag("disable-dev-shm-usage", true),
// See https://github.com/gotenberg/gotenberg/issues/1293.
chromedp.Flag("disable-component-update", false),
// See https://github.com/gotenberg/gotenberg/issues/1656.
chromedp.Flag("disable-features", chromiumDisableFeatures),
)
if b.arguments.allowInsecureLocalhost {

View File

@@ -3,6 +3,7 @@ package chromium
import (
"context"
"log/slog"
"slices"
"strings"
"testing"
)
@@ -37,3 +38,24 @@ func TestChromiumBrowser_Start_rejectsOverlappingStart(t *testing.T) {
t.Fatal("expected the browser to stay not started")
}
}
// TestChromiumDisableFeatures guards the override described in
// https://github.com/gotenberg/gotenberg/issues/1656. Gotenberg replaces
// chromedp's --disable-features value rather than extending it, as
// chromedp.Flag keys its flags by switch name. Dropping one of chromedp's own
// entries while editing this list would silently re-enable it.
func TestChromiumDisableFeatures(t *testing.T) {
for _, feature := range []string{
// chromedp.DefaultExecAllocatorOptions.
"site-per-process",
"Translate",
"BlinkGenPropertyTrees",
// The address-bar popup WebUI, built even in headless.
"WebUIOmniboxPopup",
"WebUIOmniboxAimPopup",
} {
if !slices.Contains(strings.Split(chromiumDisableFeatures, ","), feature) {
t.Errorf("expected %q to be disabled, got %q", feature, chromiumDisableFeatures)
}
}
}