Skip to content

QX-33029 merge mozilla v6.3.289 into mc master - #82

Draft
sben502 wants to merge 1987 commits into
mc-masterfrom
QX-33029-merge-mozilla-v6.3.289-into-mc-master
Draft

sben502 wants to merge 1987 commits into
mc-masterfrom
QX-33029-merge-mozilla-v6.3.289-into-mc-master

Conversation

@sben502

@sben502 sben502 commented Sep 28, 2026 •

Copy link
Copy Markdown

Summary

Quarterly PDF.js maintenance (QX-33029). Merges the latest upstream Mozilla release v6.3.289 into mc-master, preserving all MasterControl customizations. This is a major-version jump (v5.4 → v6.3), so it involved substantial conflict resolution plus follow-up fixes for viewer styling, find-in-document behavior, and CI that v6 restructured.

Merged as a merge commit (not squash) to preserve Mozilla's history for future quarterly merges.

Merge conflict resolutions

Notable calls made while resolving conflicts (base for MC's custom layer was Mozilla v5.4.624):

  • app_options.js — v6 refactored the options object literal into a Map. Re-applied MC's value flips inside the new structure: supportsPrinting:false, supportsDownloading:false, annotationMode:1, printResolution:300, viewerCssTheme (non-Chrome) 1.
  • app.js — adopted v6's new supportsDownloading gating for download()/save()/downloadOrSave() (replaces MC's older comment-out approach; also covers v6's new onSavePages() download path). Took v6's URL-handling fix for issue 20137 (replaces the MC new URL(file, location) workaround).
  • pdf_find_utils.js — took upstream. v6 now runtime-generates the NFKC normalization table for Chrome/Edge, which covers the Kangxi radical range natively — so MC's forced-table customization (QX-28091) is no longer needed.
  • viewer.html / viewer.css — took v6's restructured markup, re-applied MC's hides (attachments/layers views, editor toolbar), mcViewer/mcToolbar/mcSidebar classes, and download/print button hiding.
  • Preserved MC customizations: canPrint print gate, hasOwnCanvas=false (Chromium hardware-accel fix), DOMPurify URL sanitize, mc-build/mc-deploy gulp tasks, findbar/toolbar styling, presentation-mode button, log-injection sanitization.
  • package-lock.json — aligned to upstream v6.3.289's exact lockfile (see follow-up fixes below for why regenerating from scratch was reverted).

Post-merge follow-up fixes

Viewer styling regressions. v6 restructured the views-manager/menu styling; these restore the intended MC appearance (all scoped to viewer-only selectors, no effect elsewhere in MasterControl):

  • Views-manager selector popup text made readable (v6 now derives --menu-text-color from --text-color).
  • Views-manager header "Pages" label: dark background re-asserted so the white label is readable.
  • Views-manager panel open-state inset restored 8px → 1px (v6 widened it, opening an off-color gap).
  • #toolbarViewerLeft inline-start margin 8px → 0 (aligns the sidebar toggle with the container).
  • Findbar previous/next chevrons: cleared the inherited white icon background (no more white squares on the light find bar).

Find-in-document scrolling the embedded viewer's outer container. v6 changed PDFFindController.scrollMatchIntoView() from pdf.js's internal scrollIntoView helper to the native Element.scrollIntoView(), which scrolls every scrollable ancestor — in MC's embedded (iframe) viewer that also scrolled the outer app-view-pdf-document container ~19px, shifting the toolbar up into the divider. Restored the pre-v6 behavior (internal helper + MATCH_SCROLL_OFFSET_TOP). This resolves the toolbar/layout shift previously listed as under investigation.

mc_options.js lint exemption. The gulp lint-licenses task was updated to exempt mc_options.js from the missing-license-header check, and the exemption is documented in the README.

CI fixes for the v6 toolchain:

  • Resolved the 8 ESLint errors CI flagged on the merge (import ordering in gulpfile.mjs and web/pdf_find_controller.js; removed orphaned BASELINE_DIR/MOZCENTRAL_BASELINE_DIR constants left by v6's removal of the baseline gulp tasks).
  • Aligned package-lock.json to Mozilla's exact v6.3.289 lockfile. Regenerating it from scratch during conflict resolution had drifted ~420 transitive deps to newer patches than upstream tested against, cascading into CI failures on unchanged upstream code (tsc-alias 1.9.1→1.9.5 emitting .d.ts imports TypeScript rejects (TS2846); eslint 10.8.1→10.11.0 tripping stricter new-cap).
  • Codecov coverage upload is new in v6; the fork has no CODECOV_TOKEN, so the upload returned HTTP 400 and (with fail_ci_if_error: true) failed every Test/coverage job. Set fail_ci_if_error: false in all five uploading workflows so the step warns instead of failing — the tests themselves still run and gate CI. Documented in the README.

Testing

  • gulp generic and gulp mc-build build cleanly.
  • Deployed to a local MasterControl site and verified the viewer styling fixes and find-in-document scrolling render/behave correctly.
  • Still pending (tracked in QX-33029): full Test Plan (TC-01…TC-13), WebDriver regressions, and runtime verification of Kangxi Japanese search (QX-28091) and relative file= loading.

See the Test Plan: PDF Viewer Component (https://mastercontrol.atlassian.net/wiki/spaces/PDFBombs/pages/969671714/Test+Plan+PDF+Viewer+Component).


Note for viewer testers: the console error quickjs-eval.js wasm streaming compile failed: ... Incorrect response MIME type. Expected 'application/wasm' (+ falling back to ArrayBuffer instantiation) is not a bug in this PR. v6 loads the QuickJS sandbox as WASM via compileStreaming(), which needs Content-Type: application/wasm; MasterControl's StaticContent (served by Lucee) wasn't setting it. Viewer still works via the fallback. Fix is in mastercontrol, not here — a Tuckey urlrewrite.xml rule setting .wasm → application/wasm (mastercontrol PR mozilla#5762).

NG0904, the jQuery unload violation, and "Interactive form support is not enabled" are pre-existing/benign (present on v5 too).

🤖 Generated with Claude Code](#82)

dependabot Bot and others added 30 commits August 4, 2026 12:16
Bumps [github/codeql-action/analyze](https://github.com/github/codeql-action) from 4.37.2 to 4.37.3.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@e064762...e4fba86)

---
updated-dependencies:
- dependency-name: github/codeql-action/analyze
  dependency-version: 4.37.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Follow-up to PR mozilla#21690: these tests check that pressing Home/End
correctly updates the last focused menu-item index, so that a following
ArrowUp/ArrowDown press doesn't move focus to an unexpected menu-item.
Add integration tests for the Home/End keys in the `Menu` class
When a viewer page was copied, each copy got its own annotationStorage
entry, but newAnnotationsByPage was keyed only by source page. As a
result, every output copy received all entries and reused their memoized
references.

Tag each entry with its rank among output copies of the same source page.
The display and worker compute this rank independently; inserted documents
preserve the order of copies. Keep unextracted entries at rank -1 so shared
stamp bitmaps remain available without being written. Without ranks, new
annotations are applied only to the first copy.
It flags the regexes whose search is quadratic in the input length, like
the autolinker and XFA-path ones fixed recently.

The three existing offenders: `\s*` matched the CSS indentation but also
the line terminators that make `^` match with the `m` flag (the
preprocessed CSS is unchanged), `(\d+)` made every digit of a number a
candidate start position, and `/T.*$/` could fail on the `$` and
backtrack since `.` doesn't match a line terminator.
`\d+\.?\d*` can split a run of digits in as many ways as it is long, so
it would backtrack polynomially if anything following it could reject.
The optional exponent can't, hence no bug today, but `\d+(?:\.\d*)?`
accepts the same numbers unambiguously.
…/undici-7.29.0

Bump undici from 7.28.0 to 7.29.0
…ns/github/codeql-action/analyze-4.37.3

Bump github/codeql-action/analyze from 4.37.2 to 4.37.3
…ns/github/codeql-action/init-4.37.3

Bump github/codeql-action/init from 4.37.2 to 4.37.3
Bumps [fast-uri](https://github.com/fastify/fast-uri) from 3.1.4 to 3.1.5.
- [Release notes](https://github.com/fastify/fast-uri/releases)
- [Commits](fastify/fast-uri@v3.1.4...v3.1.5)

---
updated-dependencies:
- dependency-name: fast-uri
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
…ns/github/codeql-action/autobuild-4.37.3

Bump github/codeql-action/autobuild from 4.37.2 to 4.37.3
…shorten

Shorten the `Menu` constructor a tiny bit
…ar-move

Enable the `regexp/no-super-linear-move` ESLint rule
…/fast-uri-3.1.5

Bump fast-uri from 3.1.4 to 3.1.5
Remove the ambiguity from the PostScript number regex
The remaining rules from the plugin's "Best Practices" category that the
recommended config leaves off, plus the two it only warns about, all of
which the code already complies with.

`regexp/prefer-regexp-test` is left off, since `unicorn/prefer-regexp-test`
already covers it.
…-parent-cycle

Avoid an infinite loop on cyclic field Parent chains
Enable a few more `eslint-plugin-regexp` rules
Preserve `RowSpan`, `ColSpan`, `Headers`, `Scope`, `Short` and `Summary`
when serializing the structure tree, and map them to the corresponding
ARIA attributes in the viewer.

The attributes are now collected from both the `A` and the `C` entries,
which may be arrays interleaving dictionaries and revision numbers: this
also fixes the bounding box and the MS Office MathML lookups, which only
handled a single direct dictionary.

Fixes mozilla#18090.
…new-annotations

Give copied annotations distinct references
`/ParentTreeNextKey` was set to `parentTree.size`, but the map is sparse:
`extractPages` deletes the entries of the struct elements that were never
cloned, so `size` is no longer a free key. PDF 32000-1 Table 322 requires
"an integer greater than any key in the parent tree", hence `max(key) + 1`.
…the `src/scripting_api/util.js` file

Rather than inlining all of that code, by moving it into separate helper methods we can utilize `Map.prototype.getOrInsertComputed()` instead.

Also, make a couple of the existing class fields actually private.
….js`

Rather than only caching a string and then re-creating the regular expression on every `Util.prototype._scand` invocation, the entire regular expression can be cached directly instead.
…tions` returning a Map (PR 21664 follow-up)

This was overlooked in PR 21664, since the code-path in question isn't invoked when scripting is enabled (which is the default value).
`parseQueryString`, i.e. `URLSearchParams`, has already percent-decoded the
parameter, hence re-encoding it with `encodeURIComponent` and only restoring
the slashes leaves e.g. "?", "&" and "%" escaped. This breaks relative URLs
with a query string, e.g. `?file=%2Fget.jsp%3Fid%3D1%26x%3D2`, and relative
URLs with a percent-encoded path.

The value is now used as-is, except for a "#" in a relative URL which is
still escaped: since the viewer takes its own hash parameters from the
*viewer* URL, a "#" in the `file` parameter is assumed to be part of the
filename (see mozilla#19990).

It fixes mozilla#20137.
…ethod

The Type3 glyphs are parsed in series, which was implemented by chaining the `getOperatorList` promises together one after another.
Thanks to modern JavaScript this can be simplified a little bit, since we can just `await` within the loop instead.
…on-MathClamp

Use the `MathClamp` helper in the `src/core/annotation.js` file
…int-jsActions-Map

Update `PDFViewerApplication._initializeAutoPrint` to handle `getJSActions` returning a Map (PR 21664 follow-up)
Codecov coverage upload was introduced upstream in v6 (absent in v5). The fork
has no CODECOV_TOKEN, so the upload returns HTTP 400 "not valid tokenless
upload" and, with fail_ci_if_error: true, fails every Test/coverage job.

Set fail_ci_if_error: false in all five workflows that upload to Codecov so the
step warns instead of failing the job; the unit/integration/font/browser tests
themselves still run and gate CI. Documented under "Changes We Have Made From
Mainline > Build & Development" in the README.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@sben502
sben502 deployed to code-coverage September 29, 2026 19:50 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 29, 2026 19:50 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 29, 2026 19:50 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 29, 2026 19:51 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 29, 2026 19:51 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 29, 2026 19:51 — with GitHub Actions Active
…-33029)

When resolving the package-lock.json merge conflict, I had regenerated the
lockfile from scratch, which re-resolved ~420 transitive dependencies to newer
patch versions than Mozilla's v6.3.289 tested against. Those drifts caused a
cascade of CI failures where upstream's own code tripped newer, stricter tool
behavior:
- tsc-alias 1.9.1 -> 1.9.5 emitted `.d.ts` extension imports that TypeScript
  rejects (TS2846), failing the types test (gulp typestest) on two unchanged
  upstream files (annotation_layer_builder, pdf_page_view).
- (earlier) eslint 10.8.1 -> 10.11.0 flagged new-cap on upstream src/ files.

Fix: restore upstream v6.3.289's exact package-lock.json, then re-add only MC's
two dependencies (gulp-artifactory-upload, dompurify) via package-lock-only.
Now the lockfile matches upstream for every shared package (0 version drift);
the only additions are MC's two deps and their subtrees. Verified: gulp
typestest passes and eslint is clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage September 30, 2026 15:33 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 1, 2026 23:13 — with GitHub Actions Active
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active
@sben502
sben502 deployed to code-coverage October 2, 2026 17:23 — with GitHub Actions Active

This branch was successfully deployed

1 active deployment
code-coverage — 7b005688 Deployed Oct 2, 2026 by sben502 via Test (24) #409
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants