SVG Chromium bug is more than 10 years old
bugs.chromium.org
bugs.chromium.org
Browser engineers have an extremely difficult job. The codebase is incredibly complex (they aren't just copying data from one system to another - it takes years to get up to speed in just a small area of the codebase) - any change (even improvements/fixes) risks breaking websites.
You might think you are complaining to a faceless organization, but in reality your really just talking to 1-2 people. Be kind. Each time an engineers gets dumped on you risk them throwing in the towel for good (engineer burnout is real), your bug will very much not be fixed then.
Engineers like fs@ are one of a kind and experts in their area. (fs@ implemented SVG favicons to Chromium for example - https://bugs.chromium.org/p/chromium/issues/detail?id=294179 ). As the web platform is so expansive there are really only a few people in the world at one time who understand various problems deeply enough to make progress on a fix.
What does help? In this particular case - if you are affected by this bug starring it helps. If you can kindly describe how this affects you - that also helps. The Chromium project actively tracks highly starred bugs. (Keep in mind the project also takes into account "gaming" the count so getting 100 people to star the bug mindlessly wont help).
That said, it's pretty clear when you're up against an org like that, and communicating that you are angry because you are experiencing hardship from an unresolved issue in software that you license never, ever warrants personal attacks; implications that the developers are lazy, stupid, or disorganized; implications that they're maliciously withholding fixes, etc etc etc.
And beyond that, there's no excuse for being cranky in bug reports for free software or in small fora like issue reports on repos that go directly to developers, or anything like that.
Regardless, the answer to that comment says that the reason why this but wasn't fixed yet is due to "priorities"... which I guess makes sense as Google would rather allocate people to working on Web Environment Integrity than bulking up the "1-2 people" you say are working on this part of the code. Remember: the large tech monopoly isn't our friend, and the people who work choose to work at one deserve our collective scorn.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1790500 [2]: https://bugzilla.mozilla.org/show_bug.cgi?id=1792598
(My experience is almost all more than two years old. Haven’t needed to file much in the last couple of years.)
In general I have the feeling that Firefox and Chromium developers take bug reports very seriously. Safari is a different story, my bug reports there got frequently ignored. But I have the feeling that the entire Safari project is handled by one single developer, so it's not really surprising.
If we include the android edition it's easy to mention the UX customization options as another example. "Scroll to hide toolbar" frequently breaks the viewport size calculation, making it impossible to scroll to the bottom of most pages. "Pull to refresh" keeps triggering when trying to scroll up on pages. "Swipe toolbar to switch tabs" is great, even though it occasionally sends you to the new-tab splashpage which I'm still not quite sure how to effectively return from. And the decision to make most addons unavailable is just confusing through and through.
I get the motivation to add "some value" to set Firefox apart from the competition; I just wish it was a far second to bugfixes.
I guess the target for complaining would be rather Mozilla, who rather drastically cut down their engineers. I think those who remain, do all they can, with their limited manpower.
[0] https://github.com/mozilla-mobile/firefox-ios/issues/12279
I'm not sure how this could be fixed. Knowing that the file isn't used anywhere else after you upload it would require a full gc pass in the general case even if it's obvious in your snippet, right?
I'm on my phone or I'd check if chrome on Linux has the same issue. Do you know?
Never closing the file handle on macOS is much more serious, but you don't mention that in the body of your bug report, just on your linked page with a repro demo.
Firefox /appears/ to immediately be closing files as well, as long as they are only accessed by a FileReader and not by an XmlHttpRequest, however this could just be luck.
And I agree my phrasing was suboptimal on that part. I recall that was the first impression I had when encountering the issue and misremembered the details.
One commenter puts it into perspective:
"How is this still not fixed 10 years later? This bug is now just as old as Voyager 1 leaving the solar system or Lana Del Rey debut album. We went through an entire Spider Man reboot cycle and 3 James Bond movies. A whole generation of consoles came and passed by with PlayStation 4 being both released and superseded by PlayStation 5 while this bug was open. This bug is older than Grand Theft Auto 5. We live in a whole different world now, especially considering the pace web is developing and we STILL cannot store an icon with a gradient in an external SVG sheet."
Maybe the commenter is less than ten years old. Otherwise they have as little excuse as the rest of us.
At times, it appears that web standards have evolved from their open nature to primarily supporting Google's agenda. If Google wants a certain product to run the browser, they will bend the standards to do that.
I bet as soon as a Google product needs this feature, the bug will be fixed.
It's hard to interact with because falsifying it requires invoking it yourself.
ex. here, we'd have to say "I bet you'd be right here complaining if it was fixed that Google was allowing arbitrary remote loads in not provably secure context." It requires a whole lot of supposition and negativity.
But this guy from Russia came in, threw a fit and was never heard again in this bug.
And still, the reply was polite.
I am sure there are tons of more bugs in the chromium project that are 10 years or older. Some things are just more critical than other.
So? Google still has a team assigned to the project, and that team has limited people, and it also has preferences and priorities.
Being open source doesn't mean that you can contribute to it at all. In this particular case, Google does actually take contributions, but only from people who signed their CLA, and many people aren't going to agree to that.
So, if you did that it'd probably be worse than useless because it might hamper the legal adoption of identical or near-identical code if the fix was such that there was essentially only one decent solution.
Google allows WTFPL third party code.
To look at the metric another way: 10 years, 120 months. 95 comments (including all kinds of automated comments). So less than one a month, among a small group of people. Fixing the bug is clearly not just a one-line thing and requires a ton of effort (including the loading of external resources, which always requires security consideration), which doesn't bode well when compared with the size of audience clamouring for it.
The reality is that it just isn’t that important.
Sometimes a bug just doesn't have the same importance to the maintainers as it does to you.
If it's that important, fix it yourself.
You know exactly what would happen. You make PR, and then.... Nothing. Enjoy all that wasted effort.
And second, it's still not wasted effort if you get the fix that you need.
Putting aside the impracticality of building Chrome or Android from source in perpetuity - and the fact that you'd actually end up with Chromium and AOSP - what good does it do if you fix a bug for one user? You still have to deal with it existing for 99.99999% of users in your app/website.
What's your problem?
This also isn't a solvable problem: Google cannot simply hire more people to fix more bugs (mythical man month, remember?).
The reality is that if you have a pet bug, that is specifically important to you, and not important to anyone, is not a security bug, and isn't a feature regular users or web devs are clamoring for, you're probably going to need to fix it yourself (or pay someone else to). Given a choice between paying an engineer to spend time fixing a bug that has no significant impact, and paying that same engineer to work on something that thousands/millions will benefit from, or something google directly benefits from, google (or any employer) is going to choose one of the latter options. That's just sensible management.
Vector GPU Rasterization in Chrome is still broken on Apple Silicon Macs. Has been for more than a year.
(I'm being tongue-in-check, but those who know the story of Microsoft beating up their APIs to keep Adobe happy know that's actually how this goes sometimes. "Who's gonna pay the cost for this being broken?" is a business concern as much as a technical one).
What is the difference between these begging, cajoling bug reports and similar bug reports for proprietary closed source software?
Seems the software is just as centralized and the commercial company is just as much in charge versus the user.
A developer running in to problems trying to use this