Google ya saki Chrome 107, mai binciken gidan yanar gizo. Hakanan ana samun tabbataccen sakin aikin tushen tushen Chromium, tushen Chrome. Chrome ya bambanta da Chromium a cikin amfani da tambarin Google, tsarin sanarwar faɗuwa, kayayyaki don kunna abun ciki na bidiyo mai kariya (DRM), shigarwa ta atomatik, keɓewar akwatin sandbox koyaushe, samar da maɓallan API na Google, da wucewar sigogin RLZ yayin bincike. Ga waɗanda ke buƙatar ƙarin lokaci don sabuntawa, ana kiyaye reshen Extended Stable daban na makonni takwas. An shirya sakin na gaba, Chrome 108, don 29 ga Nuwamba.
Canje-canje masu mahimmanci a cikin Chrome 107:
- An ƙara goyan baya don tsarin ECH (Encrypted Client Hello), wanda shine juyin halitta na ESNI (Rufaffen Sunan uwar garken) kuma ana amfani dashi don ɓoye bayanai game da sigogin zaman TLS, kamar sunan yankin da aka nema. Babban bambanci tsakanin ECH da ESNI shine cewa ECH tana rufaffen saƙon ClientHello TLS gaba ɗaya maimakon rufaffen fage guda ɗaya, yana hana leaks ta filayen da ESNI ba ta rufe ba, kamar filin PSK (Maɓallin Shared Pre-Shared). ECH kuma yana amfani da rikodin HTTPSSVC DNS maimakon rikodin TXT don watsa bayanan maɓalli na jama'a kuma yana amfani da ingantacciyar ɓoyayyen ƙarshen-zuwa-ƙarshen bisa HPKE (Hybrid Public Key Encryption) don samu da ɓoye maɓalli. Saitin "chrome://flags#encrypted-client-hello" yana samuwa don kunna ECH.
- An kunna goyan baya don haɓakar kayan aikin gyara bidiyo a cikin tsarin H.265 (HEVC).
- Mataki na biyar na yankewa a cikin adireshin mai amfani-Agent HTTP da navigator.userAgent, navigator.appVersion, da navigator.platform sigogin JavaScript an kunna. Ana aiwatar da wannan yanke don rage bayanan da za a iya amfani da su don tantance mai amfani. A cikin Chrome 107, dandali da bayanan sarrafawa a cikin kirtani mai amfani-Agent an yanke don masu amfani da tebur, kuma an daskare abubuwan da ke cikin navigator.platform JavaScript sigar. Wannan canjin ana iya gani kawai akan dandamali na Windows, inda aka maye gurbin takamaiman sigar dandamali da "Windows NT 10.0." A kan Linux, abun cikin dandamali a cikin kirtani-Agent User ya kasance baya canzawa.
An maye gurbin lambobin MINOR.BUILD.PATCH waɗanda a baya suka ƙunshi sigar burauzar da 0.0.0. Ci gaba, taken kawai zai ƙunshi bayani game da sunan mai binciken, babban nau'in burauzar, dandamali, da nau'in na'ura (wayar hannu, PC, kwamfutar hannu). Don samun ƙarin bayanai, kamar ainihin sigar da ƙarin bayanan dandamali, yi amfani da API ɗin Abokin Ciniki na Wakilin Mai amfani. Shafukan da ba su da isassun bayanai kuma ba su shirya don canzawa zuwa Alamomin Abokin Ciniki na Wakilin Mai Amfani suna da har zuwa Mayu 2023 don komawa zuwa cikakken Wakilin Mai amfani.
- Sigar Android baya goyon bayan dandamalin Android 6.0; browser yanzu yana buƙatar aƙalla Android 7.0 don aiki.
- An sake fasalin yanayin yanayin zazzagewa. Maimakon mashaya na ƙasa yana nuna ci gaban zazzagewa, an ƙara sabon mai nuna alama zuwa mashigin adireshin. Danna wannan alamar yana nuna ci gaban saukewa da jerin tarihin fayilolin da aka sauke a baya. Ba kamar mashaya na ƙasa ba, maɓallin yana nunawa har abada a cikin mashaya, yana ba da damar shiga cikin sauri zuwa tarihin saukewa. Sabuwar hanyar sadarwa a halin yanzu tana samuwa ta tsohuwa ga wasu masu amfani kuma za a fitar da ita ga duk masu amfani idan babu wata matsala.

- Masu amfani da tebur yanzu suna iya shigo da kalmomin shiga da aka adana a cikin fayil ɗin CSV. A baya, ana iya canza kalmar sirri daga fayil zuwa mashigar burauza ta passwords.google.com, amma yanzu ana iya yin hakan ta hanyar ginanniyar manajan kalmar sirri na mai binciken (Google Password Manager).
- Bayan mai amfani ya ƙirƙiri sabon bayanin martaba, ana nuna gayyata yana neman kunna aiki tare kuma je zuwa saitunan, ta inda za'a iya canza sunan bayanin martaba kuma za'a iya zaɓar jigon launi.
- Sigar dandali na Android yana ba da sabon hanyar sadarwa don zaɓar fayilolin mai jarida don loda hotuna da bidiyo (maimakon aiwatar da kansa, ana amfani da daidaitaccen ƙirar Android Media Picker).

- Soke izinin sanarwa ta atomatik don shafukan da aka samu suna aika sanarwa da saƙonni masu ban haushi. Bugu da ƙari, an dakatar da buƙatun izini don sanarwa don irin waɗannan rukunin yanar gizon.
- API ɗin Ɗaukar allo an sabunta shi tare da sabbin kaddarorin da ke da alaƙa da raba allo: selfBrowserSurface (yana ba ku damar keɓance shafin na yanzu lokacin kiran getDisplayMedia()), surfaceSwitching (yana ba ku damar ɓoye maɓallin don canza shafuka), da nuniSurface (ba ku damar iyakance rabawa zuwa shafi, taga, ko allo).
- An ƙara kayan renderBlockingStatus zuwa API ɗin Performance don gano albarkatun da ke haifar da dakatar da yin shafi har sai sun gama zazzagewa.
- An ƙara sabbin APIs da yawa zuwa Yanayin Gwaji na Asalin (fasali na gwaji waɗanda ke buƙatar kunnawa daban). Gwajin Asalin yana nuna ikon yin aiki tare da ƙayyadaddun API daga aikace-aikacen da aka zazzage daga localhost ko 127.0.0.1, ko bayan yin rijista da karɓar wata alama ta musamman wacce ke aiki na ƙayyadadden lokaci don takamaiman rukunin yanar gizo.
- PendingBeacon declarative API yana ba ku damar sarrafa aika bayanai zuwa uwar garken da baya buƙatar amsa (wanda ake kira fitila). Sabuwar API ɗin tana ba ku damar ƙaddamar da aika irin waɗannan bayanai zuwa mai bincike, ba tare da kiran ayyukan aika aiki a wani takamaiman lokaci ba, misali, don tsara watsa na'urorin sadarwa bayan mai amfani ya rufe shafin.
- Manufofin Izini (Manufar Feature) HTTP header, da aka yi amfani da ita don ba da izini da ba da damar ci-gaba fasali, an sabunta su don tallafawa ƙimar "saukarwa", wanda za'a iya amfani da shi don musaki masu gudanar da taron "cire" akan shafi.
- A cikin tag Ƙara goyon baya ga sifa ta "rel", wanda ke ba ku damar amfani da ma'aunin "rel=noreferrer" don kewayawa ta hanyar shafukan yanar gizo don musaki watsa mai taken Referer, ko "rel=noopener" don musaki saitin kayan Window.opener kuma ya hana samun dama ga mahallin daga inda aka canza canjin.
- CSS Grid yanzu yana goyan bayan haɗakarwa na ginshiƙan-samfurin-ginshiƙi da kaddarorin grid-samfurin-layukan don samar da musanyawa tsakanin jahohin grid daban-daban.
- An inganta kayan aikin haɓaka gidan yanar gizo. An ƙara ikon keɓance maɓallan zafi. An inganta binciken ƙwaƙwalwar ajiya na abubuwan aikace-aikacen C/C++ da aka canza zuwa WebAssembly.
Baya ga sabbin fasaloli da gyare-gyaren kwaro, sabon sigar tana magance lahani 14. An gano da yawa daga cikin raunin ta hanyar gwaji ta atomatik ta amfani da AddressSanitizer, MemorySanitizer, Control Flow Integrity, LibFuzzer, da AFL. Ba a gano mahimman batutuwan da za su iya ba da izinin ƙetare duk matakan kariya na bincike da aiwatar da lambar a wajen yanayin sandbox ba. A matsayin wani ɓangare na shirin ba da lamuni don sakin na yanzu, Google ya ba da kyaututtuka 10 jimlar $57 (lafiya ɗaya kowanne na $20000, $17000, da $7000; kyautar $3000 biyu; ladan $2000 uku; da kuma $1000). Har yanzu ba a tantance adadin kowace kyauta ba.
source: budenet.ru


