Crypto Histograms must be executed after the deriveBits operation

In r1227708 we have added use counters to measure the usage of the
deriveBits's 'length' parameter with 2 specific values. The counter to
detect non-zero truncation should be executed after the deriveBits
operation is completed, since only then we can know the size of the
derived key and whether the length's parameter value implies that the
key is being truncated.

In r1227708 we executed the counters just after calling Blink's platform
WebCryptoImpl::DeriveBits method, which is asynchronous. Hence, we were
checking for the warning before we actually set it in the WebCrypto
component's code.

This CL moves the call to the WebCryptoImpl::DoDeriveBitsReply func,
invoked as an async post-task. This changes requires to declare the
HistogramDeriveBitsTruncation function in the Blink public platform
as an exported symbol, so that it could be invoked from the webcrypto

Bug: 1439774
Change-Id: I510e4bb9d35ed38da573bedb2e62ad35eebc6a89
Reviewed-by: Dmitry Gozman <>
Commit-Queue: Javier Fernandez <>
Reviewed-by: David Benjamin <>
Cr-Commit-Position: refs/heads/main@{#1283786}
11 files changed
tree: 096903bf0332c1c14307c9cc41ac98d72350e7f4
  1. android_webview/
  2. apps/
  3. ash/
  4. base/
  5. build/
  6. build_overrides/
  7. buildtools/
  8. cc/
  9. chrome/
  10. chromecast/
  11. chromeos/
  12. codelabs/
  13. components/
  14. content/
  15. courgette/
  16. crypto/
  17. dbus/
  18. device/
  19. docs/
  20. extensions/
  21. fuchsia_web/
  22. gin/
  23. google_apis/
  24. google_update/
  25. gpu/
  26. headless/
  27. infra/
  28. ios/
  29. ipc/
  30. media/
  31. mojo/
  32. native_client_sdk/
  33. net/
  34. pdf/
  35. ppapi/
  36. printing/
  37. remoting/
  38. rlz/
  39. sandbox/
  40. services/
  41. skia/
  42. sql/
  43. storage/
  44. styleguide/
  45. testing/
  46. third_party/
  47. tools/
  48. ui/
  49. url/
  50. webkit/
  51. .clang-format
  52. .clang-tidy
  53. .clangd
  54. .eslintrc.js
  55. .git-blame-ignore-revs
  56. .gitallowed
  57. .gitattributes
  58. .gitignore
  59. .gitmodules
  60. .gn
  61. .mailmap
  62. .rustfmt.toml
  63. .vpython3
  64. .yapfignore
  69. codereview.settings
  70. DEPS
  73. LICENSE.chromium_os
  74. OWNERS

Logo Chromium

Chromium is an open-source browser project that aims to build a safer, faster, and more stable way for all users to experience the web.

The project's web site is

To check out the source code locally, don't use git clone! Instead, follow the instructions on how to get the code.

Documentation in the source is rooted in docs/

Learn how to Get Around the Chromium Source Code Directory Structure.

For historical reasons, there are some small top level directories. Now the guidance is that new top level directories are for product (e.g. Chrome, Android WebView, Ash). Even if these products have multiple executables, the code should be in subdirectories of the product.

If you found a bug, please file it at