Repository navigation
Bun/upgrade to dbdca7545d - #773
Conversation
https://bugs.webkit.org/show_bug.cgi?id=325849 Reviewed by Rob Buis. A non-scaling stroke depends on every transform between the shape and the outermost <svg> element. When one of them changed, the cached stroke bounding box of the shape was not invalidated, so hit testing and repainting kept using the old stroke width until the shape was laid out again. Invalidate the cached stroke bounding boxes wherever a transform is written, both for the shape itself and for all non-scaling strokes below it. To keep this cheap, a new RenderElement bit marks the subtrees that contain a non-scaling stroke. Tests: imported/w3c/web-platform-tests/svg/interact/scripted/non-scaling-stroke-transform-change-hittest.html svg/repaint/non-scaling-stroke-ancestor-transform-repaint-rects.html * LayoutTests/imported/w3c/web-platform-tests/svg/interact/scripted/non-scaling-stroke-transform-change-hittest-expected.txt: Added. * LayoutTests/imported/w3c/web-platform-tests/svg/interact/scripted/non-scaling-stroke-transform-change-hittest.html: Added. * LayoutTests/platform/mac-tahoe-wk2-lbse-text/imported/w3c/web-platform-tests/svg/interact/scripted/non-scaling-stroke-transform-change-hittest-expected.txt: Added. * LayoutTests/svg/repaint/non-scaling-stroke-ancestor-transform-repaint-rects-expected.txt: Added. * LayoutTests/svg/repaint/non-scaling-stroke-ancestor-transform-repaint-rects.html: Added. * Source/WebCore/rendering/RenderElement.cpp: (WebCore::RenderElement::setMayHaveNonScalingStrokeInSubtreeIncludingAncestors): (WebCore::RenderElement::insertedIntoTree): * Source/WebCore/rendering/RenderElement.h: (WebCore::RenderElement::mayHaveNonScalingStrokeInSubtree const): * Source/WebCore/rendering/RenderLayer.cpp: (WebCore::RenderLayer::updateTransform): * Source/WebCore/rendering/RenderLayerModelObject.cpp: (WebCore::RenderLayerModelObject::updateTransformAndRepaintForSVGAfterAttributeChange): (WebCore::RenderLayerModelObject::invalidateCachedSVGBoundingBoxesOfAncestors const): (WebCore::invalidateNonScalingStrokeCachesInSubtree): (WebCore::RenderLayerModelObject::invalidateNonScalingStrokeCachesInSubtreeForSVG): * Source/WebCore/rendering/RenderLayerModelObject.h: * Source/WebCore/rendering/svg/RenderSVGModelObject.cpp: (WebCore::RenderSVGModelObject::updateFromStyle): (WebCore::RenderSVGModelObject::updateLocalTransform): (WebCore::RenderSVGModelObject::updateLayerTransform): * Source/WebCore/rendering/svg/RenderSVGShape.cpp: (WebCore::RenderSVGShape::updateFromStyle): (WebCore::RenderSVGShape::invalidateNonScalingStrokeCaches): * Source/WebCore/rendering/svg/RenderSVGShape.h: Canonical link: https://commits.webkit.org/322540@main
https://bugs.webkit.org/show_bug.cgi?id=325730 Reviewed by Zak Ridouh. Standalone executables need an an embedded __info_plist section. Needed for WTF::applicationBundleIdentifier() and isRunningTest(), and to avoid crashes in privateClickMeasurement tests. * Tools/WebKitTestRunner/PlatformCocoa.cmake: Canonical link: https://commits.webkit.org/322541@main
https://bugs.webkit.org/show_bug.cgi?id=325718 Reviewed by Richard Robinson. Fix discrepancies found by comparing each project's predefined macros with Xcode's: - ENABLE_CONJECTURE_ASSERT, which Xcode defines in Debug and sanitizer builds. - HAVE_CORE_PREDICTION, which WebKit defined only for the iOS family, so the macOS resource load statistics classifier never used CorePrediction. Define it for all Cocoa platforms, and on macOS also weak-link CorePrediction and install its model, as Xcode does. - ENABLE_WEBKIT_UNSET_DYLD_FRAMEWORK_PATH, which WebKitLegacy defines in every configuration except Production. * Source/WebKit/PlatformCocoa.cmake: * Source/WebKitLegacy/PlatformCocoa.cmake: * Source/cmake/OptionsCocoa.cmake: Canonical link: https://commits.webkit.org/322542@main
https://bugs.webkit.org/show_bug.cgi?id=325723 Reviewed by Richard Robinson. WebAuthenticationPanel and WebJavaScriptTextInputPanel load their nibs from WebKitLegacy.framework, which CMake did not compile. The default UI delegate's prompt() panel asserted and the default authentication panel failed to load. Compile both xibs with ibtool, as Xcode does. * Source/WebKitLegacy/PlatformCocoa.cmake: Canonical link: https://commits.webkit.org/322543@main
https://bugs.webkit.org/show_bug.cgi?id=324616 <rdar://182292558> Reviewed by Etienne Segonzac. Content in a connected volumetric scene kept its inline fit, which comes from the layer's bounds in points, so it sat in the volume at the wrong size and off-center, and a resize did not re-fit it. Fit it to a sphere inscribed in the volume's smaller in-plane extent instead, resting on the floor of the volume. The fit also canceled the bounding box center without rotating it, so rotated content whose bounding box is not centered on its origin ended up off-center. The orbit path masked this by re-centering afterward in WKRKEntity's recenter(at:), but other re-fits did not, such as a resize after leaving orbit. Cancel the rotated center in the fit and remove recenter(at:). setContainerTransformInPortal() now keeps the content in place when it moves the orbit pivot, as operationDidUpdate() already did, because the pivot is now re-centered after each re-fit. Tests: model-element/model-element-fit-centers-content.html model-element/volumetric/volumetric-scene-fit.html * LayoutTests/model-element/model-element-fit-centers-content-expected.txt: Added. * LayoutTests/model-element/model-element-fit-centers-content.html: Added. * LayoutTests/model-element/volumetric/volumetric-scene-fit-expected.txt: Added. * LayoutTests/model-element/volumetric/volumetric-scene-fit.html: Added. * Source/WebKit/ModelProcess/cocoa/ModelProcessModelPlayerProxy.h: * Source/WebKit/ModelProcess/cocoa/ModelProcessModelPlayerProxy.mm: (WebKit::computeSRT): (WebKit::ModelProcessModelPlayerProxy::computeMergedBounds const): (WebKit::ModelProcessModelPlayerProxy::computeTransform): (WebKit::ModelProcessModelPlayerProxy::didFinishLoading): (WebKit::ModelProcessModelPlayerProxy::updateForCurrentStageMode): (WebKit::ModelProcessModelPlayerProxy::setPresentationMode): (WebKit::ModelProcessModelPlayerProxy::applyPresentationTransform): (WebKit::isFinite): (WebKit::ModelProcessModelPlayerProxy::computeVolumetricFitSRT): (WebKit::ModelProcessModelPlayerProxy::applyVolumetricPresentationTransform): * Source/WebKit/UIProcess/Model/PortalPresentationManagerProxy.mm: (WebKit::PortalPresentationManagerProxy::showVolumetricScene): (WebKit::PortalPresentationManagerProxy::reconnectVolumetricSceneToContentContext): Report the mock size to a rebound player too, as a real scene does. * Source/WebKit/WebKitSwift/RealityKit/WKRKEntity.h: * Source/WebKit/WebKitSwift/RealityKit/WKRKEntity.swift: (WKRKEntity.transformMatrix(relativeTo:)): (WKRKEntity.setTransformMatrix(_:relativeTo:)): (WKRKEntity.removeFromParentEntity): (WKRKEntity.interactionContainerDidRecenter(fromTransform:)): Deleted. (WKRKEntity.recenter(at:)): Deleted. * Source/WebKit/WebKitSwift/StageMode/WKStageMode.swift: (WKStageModeInteractionDriver.recenterInteractionPivotOnContent): (WKStageModeInteractionDriver.setContainerTransformInPortal): (WKStageModeInteractionDriver.operationDidUpdate(_:)): Canonical link: https://commits.webkit.org/322544@main
https://bugs.webkit.org/show_bug.cgi?id=325725 Reviewed by Zak Ridouh. The Adwaita controls' scripts and style sheets were concatenated into every port's ModernMediaControls.js and .css, including Cocoa's, where nothing uses them. Add them only with USE_THEME_ADWAITA, and list the remaining scripts in DerivedSources.make's order so that the Mac build produces the same files as Xcode. * Source/WebCore/CMakeLists.txt: Canonical link: https://commits.webkit.org/322545@main
https://bugs.webkit.org/show_bug.cgi?id=325728 Reviewed by Zak Ridouh. On macOS, the bundle needs a Contents/ and Contents/Resources directory to work with the standard CFBundle loader. It also needs an Info.plist. On Xcode, this is generated automatically via build settings; generate one at configure time. Fixes a testing bug where TextManipulation.StartTextManipulationExtractsUserInfo saw the wrong document URL. * Tools/TestWebKitAPI/PlatformCocoa.cmake: Canonical link: https://commits.webkit.org/322546@main
https://bugs.webkit.org/show_bug.cgi?id=325729 Reviewed by Zak Ridouh. Xcode builds bmalloc at -O3 in every configuration (bmalloc's Base.xcconfig has no Debug override), and WTF.xcodeproj compiles FastMalloc.cpp, which inlines the libpas allocation fast paths, at -O3. The CMake Debug build compiled both at -O0, making allocation-heavy work about 2.5x slower and the WebContent process roughly 1.5x slower overall than in the Xcode build. That was enough to make timing-sensitive layout tests such as media/modern-media-controls/macos-fullscreen-media-controls/macos-fullscreen-media-controls-mute-button-rtl-positioning.html time out. * Source/WTF/wtf/PlatformCocoa.cmake: * Source/bmalloc/PlatformCocoa.cmake: Canonical link: https://commits.webkit.org/322547@main
https://bugs.webkit.org/show_bug.cgi?id=325994 rdar://188941869 Reviewed by Brady Eidson. Its one use should be represented by a Variant of the two instead. * Source/WebKit/Shared/WebHitTestResultData.cpp: (WebKit::WebHitTestResultData::WebHitTestResultData): * Source/WebKit/Shared/WebHitTestResultData.h: * Source/WebKit/Shared/WebHitTestResultData.serialization.in: * Source/WebKit/UIProcess/Cocoa/WebPageProxyCocoa.mm: * Source/WebKit/UIProcess/WebPageProxy.cpp: (WebKit::WebPageProxy::didPerformImmediateActionHitTest): * Source/WebKit/UIProcess/WebPageProxy.h: * Source/WebKit/UIProcess/WebPageProxy.messages.in: * Source/WebKit/WebProcess/WebPage/mac/WebPageMac.mm: (WebKit::WebPage::performImmediateActionHitTestAtLocation): Canonical link: https://commits.webkit.org/322548@main
…rrayStride triggers a validation error https://bugs.webkit.org/show_bug.cgi?id=326020 rdar://188846674 Reviewed by Mike Wyrzykowski. computeMininumVertexInstanceCount() already computes this condition correctly for both vertex- and instance-stepped buffers, and drawIndexed(), drawIndirect() and drawIndexedIndirect() all use it. Call it from draw() as well instead of guessing from vertexCount, so the lastStride-as-stride pipeline gets substituted whenever Metal would demand a full stride the bound buffer cannot provide. Test: fast/webgpu/regression/instance-step-buffer-smaller-than-stride.html * LayoutTests/fast/webgpu/regression/instance-step-buffer-smaller-than-stride-expected.txt: Added. * LayoutTests/fast/webgpu/regression/instance-step-buffer-smaller-than-stride.html: Added. * Source/WebGPU/WebGPU/RenderBundleEncoder.mm: (WebGPU::Metal::RenderBundleEncoder::draw): * Source/WebGPU/WebGPU/RenderPassEncoder.h: * Source/WebGPU/WebGPU/RenderPassEncoder.mm: (WebGPU::Metal::RenderPassEncoder::draw): Canonical link: https://commits.webkit.org/322549@main
…s a flaky with timeouts https://bugs.webkit.org/show_bug.cgi?id=326119 rdar://189033093 Unreviewed test gardening * TestExpectations/apitests: Canonical link: https://commits.webkit.org/322550@main
… ignored https://bugs.webkit.org/show_bug.cgi?id=325454 <rdar://problem/188552622> Reviewed by Antti Koivisto. <div style="position: absolute; width: 100px; line-clamp: 1">first line second line</div> The box should show one line with an ellipsis. LineClampUpdater keeps the clamp of the containing block out of floats and out-of-flow boxes, but it also returned before looking at the box's own max-lines, so the box never clamped. Now it clamps its own content, and its lines still do not count towards an outer clamp since it establishes an independent formatting context. * LayoutTests/TestExpectations: block-ellipsis-018, -019, -021 and -039 pass now. * LayoutTests/imported/w3c/web-platform-tests/css/css-overflow/line-clamp/block-ellipsis-018.html: Tolerate the gradient's off-by-one green pixels. * Source/WebCore/rendering/LineClampUpdater.h: (WebCore::LineClampUpdater::LineClampUpdater): (WebCore::LineClampUpdater::~LineClampUpdater): Canonical link: https://commits.webkit.org/322551@main
… uses a content basis https://bugs.webkit.org/show_bug.cgi?id=324668 <rdar://problem/187928912> Reviewed by Antti Koivisto. <div style="display: flex; width: 600px"> <div style="flex-basis: calc-size(content, size / 2)">…</div> </div> `content` sizes the item as max-content, 600px, so `size` is 600px and the item is 300px wide rather than 600px. FlexBasis::tryPreferredSize() has nothing to hand over for a content basis, since `content` is not a value a box can be laid out with, so the item is measured as max-content and never sees the calculation. Applying it to that measurement is what the spec asks for either way: `content` means the item's content based size, which is what `size` stands for. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::Layout::FlexFormattingContext::flexBaseSizeForFlexItem): (WebCore::FlexFormattingContext::flexBaseSizeForFlexItem): Applies the calculation to the max-content measurement a content basis gets, which is what `size` stands for there. * LayoutTests/imported/w3c/web-platform-tests/css/css-values/calc-size/calc-size-flex-basis-on-column-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/css/css-values/calc-size/calc-size-flex-basis-on-row-expected.txt: 4 subtests progress and none regress: calc-size-flex-basis-on-column PASS 31 -> 33 calc-size-flex-basis-on-row PASS 30 -> 32 Canonical link: https://commits.webkit.org/322552@main
… elements in cross-site iframes https://bugs.webkit.org/show_bug.cgi?id=326026 rdar://188962256 Reviewed by Ryosuke Niwa. WebPageProxy::focusTextInputContextAndPlaceCaret sends WebPage::FocusTextInputContextAndPlaceCaret to the main frame process only so elements in a cross-site iframe / process weren't resolved and thus focusing failed. The fix is to send the message to the appropriate iframe process which is identified by the context's document identifier. To accommodate this, we also converted the provided caret point from main frame coordinates to coordinates relative to the iframe. Test: Tools/TestWebKitAPI/Tests/WebKit/WKWebView/SiteIsolation-1.mm * Source/WebCore/page/FrameView.cpp: (WebCore::FrameView::rootViewToContentsAcrossIsolatedFrames const): * Source/WebCore/page/FrameView.h: * Source/WebKit/UIProcess/ios/WebPageProxyIOS.mm: (WebKit::WebPageProxy::focusTextInputContextAndPlaceCaret): * Source/WebKit/WebProcess/WebPage/ios/WebPageIOS.mm: * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/SiteIsolation-1.mm: (TestWebKitAPI::synchronouslyRequestTextInputContextsInRect): (TestWebKitAPI::synchronouslyFocusTextInputContext): (TestWebKitAPI::TEST(SiteIsolation, FocusTextInputContextInOffsetCrossOriginIframeMovesCaret)): (TestWebKitAPI::TEST(SiteIsolation, FocusTextInputContextInCrossOriginIframeMovesCaret)): Canonical link: https://commits.webkit.org/322553@main
…ited punctuation when the text item doesn't start at offset 0 https://bugs.webkit.org/show_bug.cgi?id=325910 rdar://188884467 Reviewed by Alan Baradlay. firstCharacterBreakRespectingLineStartProhibitions() advanced the break position with U16_FWD_1 using an item-relative index into the text box content. When the text item does not start at offset 0, U16_FWD_1 read the wrong code unit. A surrogate pair at that wrong spot made the break position advance by 2 instead of 1, so the line kept characters that should have wrapped (e.g. "a,b" instead of "a,"). It could also break the line in the middle of a surrogate pair. Fix this by advancing with an absolute position into the content and converting it back to an item-relative break position. Test: fast/text/overflow-wrap-anywhere-punctuation-non-zero-item-start.html * LayoutTests/fast/text/overflow-wrap-anywhere-punctuation-non-zero-item-start-expected.txt: Added. * LayoutTests/fast/text/overflow-wrap-anywhere-punctuation-non-zero-item-start.html: Added. * Source/WebCore/layout/formattingContexts/inline/InlineContentBreaker.cpp: (WebCore::Layout::firstCharacterBreakRespectingLineStartProhibitions): Canonical link: https://commits.webkit.org/322554@main
https://bugs.webkit.org/show_bug.cgi?id=325732 Reviewed by Zak Ridouh. Xcode hides symbols by default in every language (GCC_SYMBOLS_PRIVATE_EXTERN), but CMake did so only for C and C++, and hid inline functions only in C++. So every inline function and template instantiation an Objective-C++ file emitted was an exported weak definition. Align to Xcode's configuration. One caveat: WebKit keeps default visibility because TestIPC imports WebKit's IPC serialization code. In Xcode, we build a separate WebKitPlatform static library to work around this; we'll have to take a similar approach for CMake. Also enable dead-stripping in WebKit's Debug builds, matching the definition of DEAD_CODE_STRIPPING in Xcode. This drops the precompiled headers' copies of inline functions which call the now-hidden WTF and WebCore functions. * Source/JavaScriptCore/PlatformCocoa.cmake: * Source/ThirdParty/libwebrtc/CMakeLists.txt: * Source/WebKit/PlatformCocoa.cmake: * Source/WebKitLegacy/PlatformCocoa.cmake: * Source/cmake/OptionsCocoa.cmake: Canonical link: https://commits.webkit.org/322555@main
https://bugs.webkit.org/show_bug.cgi?id=325560 rdar://problem/188642043 Reviewed by Zak Ridouh. Several test sources that Xcode compiles (through membershipExceptions) were missing from the CMake lists, so their tests never ran. Add them, along with resources they need. * Source/WebKit/PlatformCocoa.cmake: One source (FullscreenTouchSecheuristicParameters.cpp) was marked iOS only, but its test is run cross-platform. Move it to the right list. * Tools/TestWebKitAPI/PlatformCocoa.cmake: Canonical link: https://commits.webkit.org/322556@main
… its main size is fit-content https://bugs.webkit.org/show_bug.cgi?id=324669 <rdar://problem/187932371> Reviewed by Antti Koivisto. <!-- the item's max-content width is 600px, min-content 400px --> <div style="display: flex; width: 500px"> <div style="width: calc-size(fit-content, size + 12px); flex-basis: calc-size(auto, size + 4px)">…</div> </div> fit-content is 500px here, the space the flex container has for the item, so the width property is 512px and the flex base size 516px. It was 616px, because the base size came from the item's max-content contribution, where fit-content can only answer max-content. Flexbox 9.2 step E asks for the item to be sized into the available space with its used flex basis in place of its main size, which is what the block axis does by laying the item out. The inline axis reads the item's max-content contribution instead, so a main size whose used value depends on that space - fit-content, stretch, or a percentage - came out too large. A plain auto main size makes the used flex basis `content`, which the contribution answers correctly, so that keeps its path. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::Layout::FlexFormattingContext::flexBaseSizeForFlexItem): (WebCore::FlexFormattingContext::flexBaseSizeForFlexItem): Sizes the item into the available space when its main size needs that space to resolve, and lets the flex basis's calculation run over that. The block axis already lays the item out, so this is the inline axis only. * LayoutTests/imported/w3c/web-platform-tests/css/css-values/calc-size/calc-size-flex-basis-on-row-expected.txt: Canonical link: https://commits.webkit.org/322557@main
…s a flaky with timeouts https://bugs.webkit.org/show_bug.cgi?id=326119 rdar://189033093 Unreviewed test Gardening Fixing the typo * TestExpectations/apitests: Canonical link: https://commits.webkit.org/322558@main
https://bugs.webkit.org/show_bug.cgi?id=326138 rdar://188935150 Reviewed by Dan Hecht. Splitting JSTests/wasm/v8/memory64.js will hopefully stop it from running out of memory when bots are running the test suite. * JSTests/wasm/v8/memory64-16gb.js: Added. (TestMaxMem64Size): * JSTests/wasm/v8/memory64-3gb.js: Added. (Test3GBMemory): * JSTests/wasm/v8/memory64-5gb.js: Added. (Test5GBMemory): * JSTests/wasm/v8/memory64-common.js: Added. (BasicMemory64Tests): (allowOOM): * JSTests/wasm/v8/memory64.js: (BasicMemory64Tests): Deleted. (allowOOM): Deleted. (Test3GBMemory): Deleted. Canonical link: https://commits.webkit.org/322559@main
https://bugs.webkit.org/show_bug.cgi?id=326101 Reviewed by Simon Fraser. The renderer passed to NinePieceImagePainter can never be null, so we should pass it as a reference. * Source/WebCore/rendering/BorderPainter.cpp: * Source/WebCore/rendering/NinePieceImagePainter.cpp: * Source/WebCore/rendering/NinePieceImagePainter.h: Canonical link: https://commits.webkit.org/322560@main
…_page->settings().siteIsolationEnabled() in TestWebKitAPI.SiteIsolation.RemoteProcessTerminationAfterDisablingSiteIsolation https://bugs.webkit.org/show_bug.cgi?id=326137 rdar://189038671 Unreviewed test gardening * TestExpectations/apitests: Canonical link: https://commits.webkit.org/322561@main
https://bugs.webkit.org/show_bug.cgi?id=326120 Reviewed by Alejandro G. Castro. The DRM vblank monitor was added for WPE in 268722@main. It stopped working for the legacy API due to two regressions: 1. 274136@main made DisplayVBlankMonitor::create() fall back to the timer for display ID 0. The legacy view never sets a display ID, so it always got the timer since then. Assign a fixed non-zero display ID when creating the page, so that we get a chance to create the DRM vlank monitor. 2. 303781@main changed the connector loop in the WPE findCrtc() to declare a new local variable instead of assigning the outer one - shadowing the outer one -> findCrtc() always failed and a matching connector was leaked. This went unnoticed because the code was no longer reachable... With both fixed, the legacy API is driven by the DRM vblank monitor again instead of a 60 fps timer - and we should be able to handle non-60 Hz display refresh rates again, even with the legacy API. * Source/WebKit/UIProcess/API/wpe/WPEWebViewLegacy.cpp: (WKWPE::ViewLegacy::ViewLegacy): * Source/WebKit/UIProcess/glib/DisplayVBlankMonitorDRM.cpp: (WebKit::findCrtc): Canonical link: https://commits.webkit.org/322562@main
…but exempted for other system colors https://bugs.webkit.org/show_bug.cgi?id=326114 rdar://189026759 Reviewed by Tim Nguyen and Simon Fraser. RenderTheme's default link, visited link and active link colors change with StyleColorOptions::UseDarkAppearance but are not marked semantic, so -apple-color-filter recolors them while every other appearance-dependent system color is exempt. Mark all three semantic. * LayoutTests/css3/color-filters/color-filter-ignore-semantic-active-link-expected.html: Added. * LayoutTests/css3/color-filters/color-filter-ignore-semantic-active-link.html: Added. * LayoutTests/css3/color-filters/color-filter-ignore-semantic-expected.html: * LayoutTests/css3/color-filters/color-filter-ignore-semantic.html: * Source/WebCore/rendering/RenderTheme.cpp: (WebCore::defaultLinkColor): (WebCore::defaultVisitedLinkColor): (WebCore::RenderTheme::systemColor): Canonical link: https://commits.webkit.org/322563@main
https://bugs.webkit.org/show_bug.cgi?id=324621 <rdar://182292385> Reviewed by Mike Wyrzykowski. Content presented in a connected volumetric scene could not be orbited. The page's pan recognizer hit-tests the flat content view, where a presented element no longer draws anything, so no drag reached stage mode. Capture drags on an input surface inside the volume instead, and route them into the existing stage mode session. Whether orbit is available in the volume follows the element's stage mode, exactly as it does inline. No new tests needed. * Source/WebCore/Modules/model-element/HTMLModelElement.cpp: (WebCore::HTMLModelElement::supportsStageModeInteraction const): * Source/WebCore/Modules/model-element/HTMLModelElement.h: * Source/WebCore/Modules/model-element/SpatialPortalController.cpp: (WebCore::SpatialPortalController::interactiveControllerForHitTestedElement): * Source/WebKit/WebProcess/WebPage/Cocoa/PositionInformationForWebPage.mm: (WebKit::positionInformationForWebPage): The element stays interactive while it is in a volume, but its box on the page is blank, so a hit test over that box must not reach it. * Source/WebCore/page/EventHandler.h: * Source/WebCore/page/ios/EventHandlerIOS.mm: (WebCore::EventHandler::requestInteractiveModelElementAtPoint): (WebCore::EventHandler::stageModeSessionDidBegin): * Source/WebKit/UIProcess/WebPageProxy.cpp: (WebKit::WebPageProxy::requestInteractiveModelElementAtPoint): (WebKit::WebPageProxy::stageModeSessionDidBegin): * Source/WebKit/UIProcess/WebPageProxy.h: * Source/WebKit/WebProcess/WebPage/WebPage.cpp: (WebKit::WebPage::requestInteractiveModelElementAtPoint): (WebKit::WebPage::stageModeSessionDidBegin): * Source/WebKit/WebProcess/WebPage/WebPage.h: * Source/WebKit/WebProcess/WebPage/WebPage.messages.in: Inline, the hit test that finds the element also begins the session. Away from the page the node is already known and there is nothing to hit-test, so begin takes the node directly. * Source/WebKit/Modules/Internal/module.modulemap: * Source/WebKit/UIProcess/Cocoa/WKPortalVolumetricGestureController.h: Copied from Source/WebKit/UIProcess/ios/WKPortalVolumetricSceneController.h. * Source/WebKit/UIProcess/Cocoa/WKPortalVolumetricGestureController.swift: Added. (WKPortalVolumetricGestureOverlay.body): (WKPortalVolumetricGestureController.onDragBegan): (WKPortalVolumetricGestureController.onDragChanged): (WKPortalVolumetricGestureController.onDragEnded): (WKPortalVolumetricGestureController.makeHostingController): (WKPortalVolumetricGestureController.updateProxyExtents(withWidth:height:depth:)): * Source/WebKit/WebKit.xcodeproj/project.pbxproj: A volume has no window glass for a pan recognizer to sit on. Capture drags with an invisible RealityKit entity filling the volume, targeted by a SwiftUI drag gesture. * Source/WebKit/UIProcess/Model/PortalPresentationManagerProxy.mm: (WebKit::stageModeTransformForLocation): (WebKit::PortalPresentationManagerProxy::showVolumetricScene): * Source/WebKit/UIProcess/ios/WKPortalVolumetricSceneController.h: * Source/WebKit/UIProcess/ios/WKPortalVolumetricSceneController.mm: (-[WKPortalVolumetricSceneController _applyInputSurfaceExtents]): (-[WKPortalVolumetricSceneController updateLayoutForVolumeSize]): (-[WKPortalVolumetricSceneController hostContentWithContext:pid:]): (-[WKPortalVolumetricSceneController installInputSurfaceWithBegan:changed:ended:]): (-[WKPortalVolumetricSceneController _removeInputSurface]): (-[WKPortalVolumetricSceneController dismissWithCompletion:]): Host that surface in the volumetric window, keep its extent in step with the volume, and report drag locations in points, the packing stage mode already uses inline. * Source/WebKit/ModelProcess/cocoa/ModelProcessModelPlayerProxy.mm: (WebKit::ModelProcessModelPlayerProxy::setPresentationMode): Tearing the volume down destroys the input surface without an end event, so end the session there instead. Canonical link: https://commits.webkit.org/322564@main
…e anchor-visible rdar://188939499 https://bugs.webkit.org/show_bug.cgi?id=325988 Reviewed by Elika Etemad. History lesson: position-visibility used to accept plural keywords (anchors-visible, anchors-valid), because it looked at all anchors being used. Then CSSWG changed it [1] to only look at the default anchor, and renamed the keywords to singular (anchor-visible, anchor-valid). WebKit renamed them and aliased the plural to singular form in 312080@main, but the initial value is still the plural form, so this patch fixes it to be the singular form. [1]: w3c/csswg-drafts#10201 Test: imported/w3c/web-platform-tests/css/css-anchor-position/parsing/position-visibility-computed.html * LayoutTests/imported/w3c/web-platform-tests/css/css-anchor-position/parsing/position-visibility-computed-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/css/css-anchor-position/parsing/position-visibility-computed.html: - Import from WPT. Ideally we should've imported the whole directory, but there are some complications to sort out. * Source/WebCore/css/CSSProperties.json: * Source/WebCore/style/computed/StyleComputedStyleProperties+InitialCustomInlines.h: (WebCore::Style::ComputedStyleProperties::initialPositionVisibility): * Source/WebCore/style/values/anchor-position/StylePositionVisibility.h: Canonical link: https://commits.webkit.org/322565@main
…ore the full URL they were authored with https://bugs.webkit.org/show_bug.cgi?id=326091 Reviewed by Simon Fraser. Simplify how we get the full URL (including the fragment that would otherwise be stripped) to Style::CachedImage by passing it in at creation time rather than requiring it to be bundled later with a draw call. To keep behavior the same, we also add a new parameter on creation of Style::CachedImage that specifies the SVG referencing mode (https://svgwg.org/specs/integration/#referencing-modes). For <img> (and similar), we use an "animated image document" reference mode which disables the SVG resource paths in Style::CachedImage (matching existing behavior and what we want). CSS images use "animated image document" or "resource document", allowing the SVG resource paths. In the future, we will likely want to limit "resource document" to just mask related CSS properties, but for now we are maintaining parity. * Source/WebCore/rendering/RenderImage.cpp: * Source/WebCore/rendering/RenderImage.h: * Source/WebCore/rendering/RenderImageResource.cpp: * Source/WebCore/rendering/RenderImageResource.h: * Source/WebCore/rendering/svg/RenderSVGImage.cpp: * Source/WebCore/rendering/svg/RenderSVGImage.h: * Source/WebCore/rendering/svg/legacy/LegacyRenderSVGImage.cpp: * Source/WebCore/rendering/svg/legacy/LegacyRenderSVGImage.h: * Source/WebCore/style/values/images/kinds/StyleCachedImage.cpp: * Source/WebCore/style/values/images/kinds/StyleCachedImage.h: * Source/WebCore/style/values/images/kinds/StyleCursorImage.cpp: * Source/WebCore/style/values/images/kinds/StyleCursorImage.h: * Source/WebCore/style/values/images/kinds/StyleImage.h: * Source/WebCore/style/values/images/kinds/StyleMultiImage.cpp: * Source/WebCore/style/values/images/kinds/StyleMultiImage.h: Canonical link: https://commits.webkit.org/322566@main
rdar://188881915 https://bugs.webkit.org/show_bug.cgi?id=325901 Reviewed by Vassili Bykov. We deployed transition cache and single-transition cache for JSON object baking. But still loading a StringImpl from a Structure and comparing it with lexed buffer is costly, largely due to dependent load. This patch introduces layered cache mechanism on the top of that. Now we have new Name cache and PrefixedName cache. Name cache covers quick fast path for single-transition cache, and PrefixedName cache covers transition cache pattern. By recording the actual JSON text content directly into the entry, like `"type":`, lookup directly compares the source's string sequence with this content. Also we cache this into the cache's Entry directly (up to 32 characters) and we do comparison with hard-coded optimized SIMD operation. And still transition cache and single-transition cache covers failed cases, and they populate the result to the front cache to accelerate the next lookup. This removes any constly load from Structure*, and keep lookup sufficiently efficient and improves cache locality significantly. Test: JSTests/stress/json-parse-cached-property-name.js * JSTests/stress/json-parse-cached-property-name.js: Added. (shouldBe): (shouldThrow): (roundTrip): (iteration.const.name.of.names.shouldThrow.JSON.parse.shouldBe.roundTrip.i.shouldBe.roundTrip.JSON.stringify): * Source/JavaScriptCore/JavaScriptCore.xcodeproj/project.pbxproj: * Source/JavaScriptCore/Sources.txt: * Source/JavaScriptCore/runtime/JSONCache.cpp: Added. (JSC::JSONCache::recordableName): (JSC::JSONCache::NameTable<size>::insert): (JSC::JSONCache::makeText): (JSC::JSONCache::textPrefix): (JSC::JSONCache::addPrefixedName): (JSC::JSONCache::addName): * Source/JavaScriptCore/runtime/JSONCache.h: (JSC::JSONCache::clearStrings): (JSC::JSONCache::reconcileTransitionsAtGCEnd): (JSC::JSONCache::atomStringIndex): (JSC::JSONCache::atomStringSlot): (JSC::JSONCache::stringIndex): Deleted. (JSC::JSONCache::stringSlot): Deleted. * Source/JavaScriptCore/runtime/JSONCacheInlines.h: (JSC::JSONCache::makeIdentifier): (JSC::JSONCache::existingIdentifier): (JSC::JSONCache::makeJSString): (JSC::JSONCache::nameIndex): (JSC::JSONCache::prefixedNameIndex): (JSC::JSONCache::textMatches): (JSC::JSONCache::NameTable<size>::match const): (JSC::JSONCache::findName const): (JSC::JSONCache::visitAggregate): * Source/JavaScriptCore/runtime/LiteralParser.cpp: (JSC::reviverMode>::existingIdentifier): (JSC::reviverMode>::makeJSString): (JSC::reviverMode>::Lexer::skipWhitespaceBeforeKey): (JSC::reviverMode>::parsePrimitiveValue): (JSC::requires): * Source/JavaScriptCore/runtime/LiteralParser.h: (JSC::LiteralParser::Lexer::remaining const): (JSC::LiteralParser::Lexer::advance): Canonical link: https://commits.webkit.org/322567@main
…ng (part 4) https://bugs.webkit.org/show_bug.cgi?id=326052 rdar://188988905 Reviewed by Timothy Hatcher. * TestExpectations/apitests: * Tools/Scripts/webkitpy/api_tests/allowlist.txt: * Tools/TestWebKitAPI/Helpers/cocoa/HTTPServer/HTTPServer.swift: (responseBehavior(_:)): (Connection.receiveRequestPath): (Connection.send(_:)): (Connection.terminate): * Tools/TestWebKitAPI/Helpers/cocoa/HTTPServer/HTTPServerConnection.swift: (NWConnection.terminate): * Tools/TestWebKitAPI/Helpers/cocoa/HTTPServer/HTTPServerCore.swift: (didReceive(_:)): * Tools/TestWebKitAPI/Helpers/cocoa/WebExtensionUtilities.h: * Tools/TestWebKitAPI/Helpers/cocoa/WebExtensionUtilities.mm: (testExceptionRaisedBySettingValue): (-[TestWebExtensionManager waitForTestMessage:completionHandler:]): (-[TestWebExtensionManager waitForContextErrorWithCompletionHandler:]): (-[TestWebExtensionManager done]): (-[TestWebExtensionManager _webExtensionController:receivedTestMessage:withArgument:andSourceURL:lineNumber:]): * Tools/TestWebKitAPI/PlatformCocoa.cmake: * Tools/TestWebKitAPI/SourcesCocoa.txt: * Tools/TestWebKitAPI/TestWebKitAPI.xcodeproj/project.pbxproj: * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPITest.mm: Removed. * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPITest.swift: Added. (WKWebExtensionAPITestTests.testStartedEvent): (WKWebExtensionAPITestTests.testFinishedEvent): (WKWebExtensionAPITestTests.messageEvent): (WKWebExtensionAPITestTests.messageEventInWebPage): (WKWebExtensionAPITestTests.messageEventInContentScript): (WKWebExtensionAPITestTests.messageEventWithSendMessageReply): (WKWebExtensionAPITestTests.sendMessage): (WKWebExtensionAPITestTests.sendMessageMultipleTimes): (WKWebExtensionAPITestTests.sendMessageOutOfOrder): (WKWebExtensionAPITestTests.sendMessageBeforeListenerAdded): (WKWebExtensionAPITestTests.addAnonymousAsyncTest): (WKWebExtensionAPITestTests.addAsyncTestThatPasses): (WKWebExtensionAPITestTests.addAsyncTestThatFails): (WKWebExtensionAPITestTests.addAsyncTestThatThrows): (WKWebExtensionAPITestTests.addMultipleAsyncTestsThatPass): (WKWebExtensionAPITestTests.addMultipleAsyncTestsWithFailure): (WKWebExtensionAPITestTests.addAnonymousTest): (WKWebExtensionAPITestTests.addTestThatPasses): (WKWebExtensionAPITestTests.addTestThatFails): (WKWebExtensionAPITestTests.addTestThatThrows): (WKWebExtensionAPITestTests.addMultipleTestsThatPass): (WKWebExtensionAPITestTests.addMultipleTestsWithFailure): (WKWebExtensionAPITestTests.runAnonymousTests): (WKWebExtensionAPITestTests.runTestsThatPass): (WKWebExtensionAPITestTests.runTestsWithTestThatFails): (WKWebExtensionAPITestTests.runTestsWithAsyncTestThatFails): (WKWebExtensionAPITestTests.runTestsVerifyFailedTestAborts): * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPIWebNavigation.mm: Removed. * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPIWebNavigation.swift: Added. (WKWebExtensionAPIWebNavigationTests.eventListenerRegistration): (WKWebExtensionAPIWebNavigationTests.beforeNavigateEvent): (WKWebExtensionAPIWebNavigationTests.committedEvent): (WKWebExtensionAPIWebNavigationTests.domContentLoadedEvent): (WKWebExtensionAPIWebNavigationTests.completedEvent): (WKWebExtensionAPIWebNavigationTests.allowedFilter): (WKWebExtensionAPIWebNavigationTests.deniedFilter): (WKWebExtensionAPIWebNavigationTests.allEventsFired): (WKWebExtensionAPIWebNavigationTests.documentIdAcrossEvents): (WKWebExtensionAPIWebNavigationTests.removeListenerDuringEvent): (WKWebExtensionAPIWebNavigationTests.errorOccurredEventDuringProvisionalLoad): (WKWebExtensionAPIWebNavigationTests.errorOccurredEventDuringLoad): (WKWebExtensionAPIWebNavigationTests.getFrameWithMainFrame): (getFrameWithSubframe): (getAllFrames): (errorOccurred): (errors): (urlFilterTestMatchAllPredicates): (urlFilterMatchesOnePredicate): (emptyFilterMatchesEverything): (urlKeyTypeChecking): * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPIWebRequest.mm: Removed. * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionAPIWebRequest.swift: Added. (WKWebExtensionAPIWebRequestTests.configurationEnablingFeature(_:)): (WKWebExtensionAPIWebRequestTests.error): (WKWebExtensionAPIWebRequestTests.manifestV2Persistent): (WKWebExtensionAPIWebRequestTests.manifestV2NonPersistent): (WKWebExtensionAPIWebRequestTests.eventListenerRegistration): (WKWebExtensionAPIWebRequestTests.beforeRequestEvent): (WKWebExtensionAPIWebRequestTests.beforeRequestEventForSubresource): (WKWebExtensionAPIWebRequestTests.beforeRequestEventForSubframe): * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionContext.mm: Removed. * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionContext.swift: Added. (WKWebExtensionContextTests.defaultPermissionChecks): (WKWebExtensionContextTests.permissionGranting): (WKWebExtensionContextTests.contentScriptsParsing): (WKWebExtensionContextTests.optionsPageURLParsing): (WKWebExtensionContextTests.urlOverridesParsing): (WKWebExtensionContextTests.commandsParsing): (WKWebExtensionContextTests.loadNonExistentImage): (WKWebExtensionContextTests.topLevelThrowInModuleBackground): (WKWebExtensionContextTests.referenceErrorInBackground): (WKWebExtensionContextTests.callingMissingBrowserAPIInBackground): (WKWebExtensionContextTests.uncaughtScriptErrorInBackground): (WKWebExtensionContextTests.unhandledPromiseRejectionInBackground): (WKWebExtensionContextTests.uncaughtScriptErrorInServiceWorkerBackground): (WKWebExtensionContextTests.unhandledPromiseRejectionInServiceWorkerBackground): (WKWebExtensionContextTests.syntaxErrorInBackground): (WKWebExtensionContextTests.noErrorForCaughtExceptionsInBackground): (WKWebExtensionContextTests.uncaughtScriptErrorInContentScript): (WKWebExtensionContextTests.uncaughtScriptErrorInMainWorldContentScript): (WKWebExtensionContextTests.pageScriptErrorNotReportedToExtension): (WKWebExtensionContextTests.consoleErrorDoesNotEvaluateArgumentsTwice): (WKWebExtensionContextTests.uncaughtScriptErrorInEventListener): (WKWebExtensionContextTests.topLevelThrowInPopup): (WKWebExtensionContextTests.consoleErrorReportedNotLogOrWarn): (WKWebExtensionContextTests.consoleAssertWithMessage): (WKWebExtensionContextTests.consoleAssertWithoutMessage): (WKWebExtensionContextTests.cleanUpOldOriginDataAfterMigration): * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionController.mm: Removed. * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/WKWebExtensionController.swift: Added. (WKWebExtensionControllerTests.configuration): (WKWebExtensionControllerTests.loadingAndUnloadingContexts): (WKWebExtensionControllerTests.backgroundPageLoading): (WKWebExtensionControllerTests.backgroundPageWithModulesLoading): (WKWebExtensionControllerTests.backgroundWithServiceWorkerPreferredEnvironment): (WKWebExtensionControllerTests.backgroundWithPageDocumentPreferredEnvironment): (WKWebExtensionControllerTests.backgroundWithScriptsDocumentPreferredEnvironment): (WKWebExtensionControllerTests.backgroundWithMultipleDocumentModuleScripts): (WKWebExtensionControllerTests.backgroundWithMultipleServiceWorkerScripts): (WKWebExtensionControllerTests.backgroundWithMultipleServiceWorkerModuleScripts): (WKWebExtensionControllerTests.contentScriptLoading): (WKWebExtensionControllerTests.cssUserOrigin): (WKWebExtensionControllerTests.cssAuthorOrigin): (WKWebExtensionControllerTests.contentSecurityPolicyV2BlockingImageLoad): (WKWebExtensionControllerTests.contentSecurityPolicyV3BlockingImageLoad): (WKWebExtensionControllerTests.webAccessibleResources): (WKWebExtensionControllerTests.webAccessibleResourcesWithLeadingSlash): (WKWebExtensionControllerTests.webAccessibleResourceInSubframeFromAboutBlank): (WKWebExtensionControllerTests.webAccessibleResourcesV2): Canonical link: https://commits.webkit.org/322568@main
https://bugs.webkit.org/show_bug.cgi?id=325717 Reviewed by Zak Ridouh. Some macOS tests are broken because ENABLE_DEVICE_ORIENTATION, ENABLE_NAVIGATOR_STANDALONE and ENABLE_WEBDRIVER_BIDI follow the CMake default (OFF) instead of the value Xcode-based builds use from Platform.h. These options don't need to have a hard-coded definition at configuration time; remove them from cmakeconfig.h and make them Platform.h derived. To support some code generators' usage of these flags, plumb the FEATURE_AND_PLATFORM_DEFINES file into a few more places. * Source/CMakeLists.txt: * Source/JavaScriptCore/CMakeLists.txt: * Source/JavaScriptCore/Scripts/generate-combined-inspector-json.py: * Source/WebCore/CMakeLists.txt: * Source/WebKit/CMakeLists.txt: * Source/cmake/OptionsCocoa.cmake: * Source/cmake/WebKitFeatures.cmake: * Source/cmake/WebKitMacros.cmake: (webkit_generate_platform_feature_defines_file): Canonical link: https://commits.webkit.org/322569@main
… formatting context https://bugs.webkit.org/show_bug.cgi?id=326200 <rdar://problem/189090409> Reviewed by Antti Koivisto. <div style="line-clamp: auto; max-height: 160px; line-height: 32px"><div style="margin: 16px">Line 1<br>Line 2<br>Line 3<br>Line 4<br>Line 5</div></div> The inner div's margins should stay inside the line-clamp container, so only 4 lines fit. The container does not establish an independent formatting context, so the margins collapse through it and 5 lines fit instead. Per spec, a box with continue: discard (which is what line-clamp sets in WebKit) "must establish an independent formatting context". (https://drafts.csswg.org/css-overflow-4/#valdef-continue-discard) * LayoutTests/TestExpectations: line-clamp-auto-028, -029, -030 and line-clamp-bfc pass now. * Source/WebCore/rendering/RenderBlock.cpp: (WebCore::RenderBlock::establishesIndependentFormattingContextIgnoringDisplayType const): Canonical link: https://commits.webkit.org/322767@main
…mputeIsIgnored() https://bugs.webkit.org/show_bug.cgi?id=326354 Reviewed by Darin Adler. Use natural dimensions rather than RenderImage::imageSizeAsRendered() in AccessibilityRenderObject::computeIsIgnored() to more accurately do what the comment states the intent is: "check whether rendered image was stretched from one-dimensional file image" Also adds an explicit check for whether there is an image at all to maintain the behavior expected by layout tests. * Source/WebCore/accessibility/AccessibilityRenderObject.cpp: Canonical link: https://commits.webkit.org/322768@main
https://bugs.webkit.org/show_bug.cgi?id=326369 Reviewed by Darin Adler and Tim Nguyen. Style::Image's drawResolving family of functions were only needed for staging. They can now be removed. * Source/WebCore/style/values/images/kinds/StyleImage.cpp: * Source/WebCore/style/values/images/kinds/StyleImage.h: Canonical link: https://commits.webkit.org/322769@main
https://bugs.webkit.org/show_bug.cgi?id=326362 Reviewed by Aditya Keerthi. Fixes typo "Contibute" -> "Contribute" * Source/WebCore/rendering/RenderBox.cpp: * Source/WebCore/rendering/RenderElement.h: Canonical link: https://commits.webkit.org/322770@main
https://bugs.webkit.org/show_bug.cgi?id=326365 Reviewed by Tim Nguyen. Removes unused class WebCore::GeneratedImage. * Source/WebCore/Headers.cmake: * Source/WebCore/Sources.txt: * Source/WebCore/WebCore.xcodeproj/project.pbxproj: * Source/WebCore/platform/graphics/GeneratedImage.cpp: Removed. * Source/WebCore/platform/graphics/GeneratedImage.h: Removed. * Source/WebCore/platform/graphics/Image.h: Canonical link: https://commits.webkit.org/322771@main
https://bugs.webkit.org/show_bug.cgi?id=326227 <rdar://problem/189105782> Reviewed by Antti Koivisto. <div style="line-clamp: 1 ')'; hanging-punctuation: last; width: 5ch; font-family: monospace">12345 678</div> The first line should show "12345)" with the closing parenthesis hanging past the end of the line, as "the ellipsis is subject to the effects of the 'hanging punctuation' property". Instead the ellipsis took its full width from the line and displaced "12345". Now the hangable trailing punctuation of the ellipsis does not take space from the line, and it is painted past the end of the line. * LayoutTests/TestExpectations: block-ellipsis-035 passes now. * Source/WebCore/layout/formattingContexts/inline/InlineFormattingUtils.cpp: (WebCore::Layout::InlineFormattingUtils::blockEllipsisForLine const): * Source/WebCore/layout/formattingContexts/inline/InlineLineTypes.h: * Source/WebCore/layout/formattingContexts/inline/display/InlineDisplayLineBuilder.cpp: (WebCore::Layout::trailingBlockEllipsis): * Source/WebCore/layout/formattingContexts/inline/text/TextUtil.cpp: (WebCore::Layout::TextUtil::hangablePunctuationEndWidth): * Source/WebCore/layout/formattingContexts/inline/text/TextUtil.h: Canonical link: https://commits.webkit.org/322772@main
https://bugs.webkit.org/show_bug.cgi?id=326113 rdar://problem/189026641 Reviewed by Tim Nguyen and Brady Eidson. Move the remaining GameController code into open source. Also add the Singleton suffix that the soft-linked constant getters now require. * Source/WebCore/platform/gamepad/cocoa/GameControllerGamepadProvider.mm: (WebCore::shouldExcludeGameController): * Source/WebCore/platform/gamepad/cocoa/GameControllerSoftLink.h: * Source/WebCore/platform/gamepad/cocoa/GameControllerSoftLink.mm: Canonical link: https://commits.webkit.org/322773@main
…IntrinsicContributionLayoutScope https://bugs.webkit.org/show_bug.cgi?id=326042 <rdar://problem/188970306> Reviewed by Antti Koivisto. IntrinsicLogicalHeightComputationScope marks an orthogonal box laid out only to give its container an intrinsic inline-size contribution, so its own percentage min/max-height follows the cyclic percentage rules. Its name suggested a general intrinsic block-size measurement, the counterpart of an intrinsic width computation, which it is not. * Source/WebCore/page/LocalFrameViewLayoutContext.cpp: (WebCore::LocalFrameViewLayoutContext::addOrthogonalIntrinsicContributionLayout): (WebCore::LocalFrameViewLayoutContext::removeOrthogonalIntrinsicContributionLayout): (WebCore::LocalFrameViewLayoutContext::isInOrthogonalIntrinsicContributionLayout const): (WebCore::LocalFrameViewLayoutContext::addIntrinsicLogicalHeightComputationFor): Deleted. (WebCore::LocalFrameViewLayoutContext::removeIntrinsicLogicalHeightComputationFor): Deleted. (WebCore::LocalFrameViewLayoutContext::isComputingIntrinsicLogicalHeightFor const): Deleted. * Source/WebCore/page/LocalFrameViewLayoutContext.h: * Source/WebCore/rendering/RenderBox.cpp: (WebCore::RenderBox::computeLogicalHeight const): (WebCore::RenderBox::computeIntrinsicLogicalHeight): * Source/WebCore/rendering/RenderLayoutState.cpp: (WebCore::OrthogonalIntrinsicContributionLayoutScope::OrthogonalIntrinsicContributionLayoutScope): (WebCore::OrthogonalIntrinsicContributionLayoutScope::~OrthogonalIntrinsicContributionLayoutScope): (WebCore::IntrinsicLogicalHeightComputationScope::IntrinsicLogicalHeightComputationScope): Deleted. (WebCore::IntrinsicLogicalHeightComputationScope::~IntrinsicLogicalHeightComputationScope): Deleted. * Source/WebCore/rendering/RenderLayoutState.h: Canonical link: https://commits.webkit.org/322774@main
https://bugs.webkit.org/show_bug.cgi?id=326412 rdar://188897444 This didn't quite work and could lead to a transient activation from evaluateJavaScript being leaked. For instance: 1. The client calls [webView evaluateJavaScript:@"setTimeout(f, 10)" ...]. The forced user gesture gives the window activation at time T1. The pending timer keeps the gesture's token alive. 2. Before f runs, the client calls [webView evaluateJavaScript:@"setTimeout(g, 1000)" ...]. The second forced user gesture records T1 as the window's previous activation timestamp, and gives the window activation at time T2. 3. f runs and the first token is destroyed. The window's activation is T2, not T1, so nothing is revoked. 4. g runs and the second token is destroyed. The window's activation is T2, so it is restored to the previous activation that the second gesture recorded (T1). This also caused a PLT regression. Reverted change: Regression(316338@main) “Copy to clipboard” button on some sites sometimes does not copy the first time https://bugs.webkit.org/show_bug.cgi?id=324512 rdar://186521201 321448@main (c963a9e) Canonical link: https://commits.webkit.org/322775@main
…al object wraps a LocalDOMWindow https://bugs.webkit.org/show_bug.cgi?id=325814 rdar://188827090 Reviewed by Qianlang Chen. JSObject::calculatedClassName uses the object's own realm as the lexical global object. For a RemoteDOMWindow, the resulting access check reaches remoteFrameAccessError(), and activeDOMWindow()'s downcast<LocalDOMWindow> fails. Use dynamicDowncast and return an empty message when the lexical global object isn't a local window. * LayoutTests/http/tests/site-isolation/inspector/runtime/evaluate-remote-dom-window-expected.txt: Added. * LayoutTests/http/tests/site-isolation/inspector/runtime/evaluate-remote-dom-window.html: Added. * Source/WebCore/bindings/js/JSDOMBindingSecurity.cpp: (WebCore::remoteFrameAccessError): Canonical link: https://commits.webkit.org/322776@main
…at the same time and nest run loops https://bugs.webkit.org/show_bug.cgi?id=325815 rdar://188827623 Reviewed by Qianlang Chen. Under site isolation, same-site frames share a process and each has its own FrameDebugger over the one VM and main thread. While one debugger is paused, JS in another frame can run inside its nested run loop and pause that frame's debugger too, nesting a second loop. Add Debugger::isPauseBlockedByAnotherDebugger() so a subclass can hold off pausing without dropping pending pause state. breakProgram() and didReachDebuggerStatement() also check it before setting any pause state. FrameDebugger uses it to allow one paused debugger per process, and now suspends all local frames of the page while paused, matching PageDebugger. * Source/JavaScriptCore/debugger/Debugger.cpp: (JSC::Debugger::breakProgram): (JSC::Debugger::pauseIfNeeded): (JSC::Debugger::didReachDebuggerStatement): * Source/JavaScriptCore/debugger/Debugger.h: (JSC::Debugger::isPauseBlockedByAnotherDebugger const): * Source/WebCore/inspector/FrameDebugger.cpp: (WebCore::FrameDebugger::~FrameDebugger): (WebCore::FrameDebugger::recompileAllJSFunctions): (WebCore::FrameDebugger::didPause): (WebCore::FrameDebugger::didContinue): (WebCore::FrameDebugger::isPauseBlockedByAnotherDebugger const): (WebCore::FrameDebugger::setJavaScriptPausedInAllPages): * Source/WebCore/inspector/FrameDebugger.h: Canonical link: https://commits.webkit.org/322777@main
https://bugs.webkit.org/show_bug.cgi?id=326264 <rdar://problem/189127202> Reviewed by Antti Koivisto. No change in functionality. * Source/WebCore/Sources.txt: * Source/WebCore/rendering/LineClampUpdater.cpp: Added. (WebCore::LineClampUpdater::LineClampUpdater): (WebCore::LineClampUpdater::~LineClampUpdater): (WebCore::LineClampUpdater::setMaximumLines): (WebCore::LineClampUpdater::resetLineClamp): (WebCore::LineClampUpdater::maximumLinesForAutoClampPoint const): * Source/WebCore/rendering/LineClampUpdater.h: * Source/WebCore/rendering/RenderBlockFlow.cpp: (WebCore::RenderBlockFlow::layoutInFlowChildren): (WebCore::maximumLinesForAutoClampPoint): Deleted. Canonical link: https://commits.webkit.org/322778@main
…itAPI.TextExtractionTests tests are timing out https://bugs.webkit.org/show_bug.cgi?id=326416 rdar://189227379 Unreviewed test gardening * TestExpectations/apitests: Canonical link: https://commits.webkit.org/322779@main
…e present and the thumb is hidden https://bugs.webkit.org/show_bug.cgi?id=326240 rdar://189116567 Reviewed by Aditya Keerthi. When a range slider has datalist ticks and its thumb is not visible, RenderThemeCocoa::paintSliderTrackForVectorBasedControls() extends the fill by additionalLength (1.5 times the tick length) so that the fill fully covers the tick for the current value. The horizontal branch does this correctly. The vertical branch multiplied by tickLength a second time. As a result, the overshoot was 1.5 * tickLength^2 instead of 1.5 * tickLength, and it grew with the square of the zoom. At zoom: 3 on macOS, the fill ran 54px past the value instead of 9px. Use additionalLength in the vertical branch too, matching the horizontal branch. Test: fast/forms/form-control-refresh/range-vertical-hidden-thumb-ticks-fill-length.html * LayoutTests/fast/forms/form-control-refresh/range-vertical-hidden-thumb-ticks-fill-length-expected.html: Added. * LayoutTests/fast/forms/form-control-refresh/range-vertical-hidden-thumb-ticks-fill-length.html: Added. * Source/WebCore/rendering/cocoa/RenderThemeCocoa.mm: (WebCore::RenderThemeCocoa::paintSliderTrackForVectorBasedControls): Canonical link: https://commits.webkit.org/322780@main
https://bugs.webkit.org/show_bug.cgi?id=325328 rdar://problem/188436006 Reviewed by Alan Baradlay. This is the first step towards supporting grid items with a preferred aspect ratio in GFC. It implements the logic needed to compute the automatic size of these types of grid items as the final step of grid layout. Most of the logic related to aspect-ratio comes from the following portion of the spec which is what this code implements: https://www.w3.org/TR/css-sizing-4/#ratios Specifically what we implement is: - Determining which axis is the ratio-determining axis - Computing the automatic size for the item from the ratio-determining axis. For example, for an item with an aspect-ratio, fixed width, and auto height we detect that we need to compute the height from the width and aspect-ratio. - For any min/max sizes that are not definite we will also consider any of the min/max sizes from the opposite axis (min/max size transfers) One thing to note about this implementation is that since this occurs after track sizing has completed this means that the grid area is known and percentages/calc are considered definite. However, aspect-ratio will also have an effect during track sizing (e.g. applying the automatic minimum size) in which case the grid area is not known and percentages/calc will be indefinite. We will implement this in a separate patch as a follow up from this. * Source/WebCore/layout/formattingContexts/grid/GridLayout.cpp: (WebCore::Layout::GridLayout::layoutGridItems const): When not considering the aspect ratio computing the used inline and block sizes are fairly straightforward and we can do them independently. aspect-ratio complicates this slightly, however, since computing a size in one dimension is now dependent on the other. Instead of complicating the existing code and trying to shoehorn the logic into the two codepaths we will check to see if we are going to use the aspect-ratio to compute the size of the grid item in which we then go through a new dedicated path. * Source/WebCore/layout/formattingContexts/grid/GridLayoutUtils.cpp: (WebCore::Layout::GridLayoutUtils::blockSizeFromAspectRatio): (WebCore::Layout::GridLayoutUtils::inlineSizeFromAspectRatio): The very basic helper functions to compute the size from the aspect ratio. (WebCore::Layout::GridLayoutUtils::hasAutomaticSizeDuringItemSizing): (WebCore::Layout::GridLayoutUtils::sizeDependsOnAspectRatio): Figure out if we are going to need to use the aspect ratio to size an item. (WebCore::Layout::GridLayoutUtils::isDefiniteMinimumSizeDuringItemSizing): (WebCore::Layout::GridLayoutUtils::isDefiniteMaximumSizeDuringItemSizing): Used when applying the transfers. These are only for the final item sizing, where the grid area is known so percentages and calc are resolvable. When we extend this for track sizing we will add separate functions that take in the grid area size in the relevant axis, since it is only known for the axis that has already been sized. (WebCore::Layout::GridLayoutUtils::needsTransferredBlockMinimumSize): (WebCore::Layout::GridLayoutUtils::needsTransferredBlockMaximumSize): (WebCore::Layout::GridLayoutUtils::needsTransferredInlineMinimumSize): (WebCore::Layout::GridLayoutUtils::needsTransferredInlineMaximumSize): (WebCore::Layout::GridLayoutUtils::transferredBlockMinimumSize): (WebCore::Layout::GridLayoutUtils::transferredBlockMaximumSize): (WebCore::Layout::GridLayoutUtils::transferredInlineMinimumSize): (WebCore::Layout::GridLayoutUtils::transferredInlineMaximumSize): (WebCore::Layout::GridLayoutUtils::blockMinimumSizeForAspectRatio): (WebCore::Layout::GridLayoutUtils::blockMaximumSizeForAspectRatio): (WebCore::Layout::GridLayoutUtils::inlineMinimumSizeForAspectRatio): (WebCore::Layout::GridLayoutUtils::inlineMaximumSizeForAspectRatio): (WebCore::Layout::GridLayoutUtils::ratioDeterminingAxis): (WebCore::Layout::GridLayoutUtils::preferredSizesForAspectRatio): All of the basic building block helper functions to implement each part of the process described in the spec in some hopefully well contained functions. (WebCore::Layout::GridLayoutUtils::usedSizesForAspectRatioItem): Aforementioned dedicated path that will be used to compute the used inline and block sizes with the help of the aspect ratio. Canonical link: https://commits.webkit.org/322781@main
…t one rdar://189219104 https://bugs.webkit.org/show_bug.cgi?id=326397 Reviewed by Abrar Rahman Protyasha. These are the checks added in 320667@main * Source/WebKit/UIProcess/WebBackForwardList.cpp: (frameStateChildCount): (frameStateChildAtIndex): (maxFrameStateDepthForMessageCheck): * Source/WebKit/UIProcess/WebBackForwardList.swift: (Direction.messageCheckItemURLs(_:process:)): Deleted. * Source/WebKit/UIProcess/WebBackForwardListSwiftUtilities.h: Canonical link: https://commits.webkit.org/322782@main
https://bugs.webkit.org/show_bug.cgi?id=326313 Reviewed by Anne van Kesteren. Protect the remaining unprotected links in call chains under html/canvas and html/parser. Move the call that passes the fullscreen layer to the media player into a new ObjC++ file, where PlatformLayer is not a forward-declared C++ class. * Source/WebCore/SourcesCocoa.txt: * Source/WebCore/WebCore.xcodeproj/project.pbxproj: * Source/WebCore/html/HTMLMediaElement.cpp: (WebCore::HTMLMediaElement::mediaEngineWasUpdated): * Source/WebCore/html/HTMLMediaElement.h: * Source/WebCore/html/HTMLMediaElementCocoa.mm: Added. (WebCore::HTMLMediaElement::updatePlayerVideoFullscreenLayer): * Source/WebCore/html/canvas/CanvasFilterContextSwitcher.cpp: (WebCore::CanvasFilterContextSwitcher::expandedBounds const): * Source/WebCore/html/canvas/CanvasRenderingContext.cpp: (WebCore::CanvasRenderingContext::taintsOrigin): * Source/WebCore/html/canvas/CanvasRenderingContext2D.cpp: (WebCore::CanvasRenderingContext2D::drawFocusIfNeededInternal): (WebCore::CanvasRenderingContext2D::setFontWithoutUpdatingStyle): * Source/WebCore/html/canvas/CanvasRenderingContext2DBase.cpp: (WebCore::CanvasRenderingContext2DBase::FontProxy::operator=): (WebCore::CanvasRenderingContext2DBase::realizeSaves): (WebCore::CanvasRenderingContext2DBase::createPattern): (WebCore::CanvasRenderingContext2DBase::baseTransform const): (WebCore::CanvasRenderingContext2DBase::setLetterSpacing): (WebCore::CanvasRenderingContext2DBase::setWordSpacing): * Source/WebCore/html/canvas/CanvasStyle.cpp: (WebCore::CanvasStyleColorResolutionDelegate::currentColor const): * Source/WebCore/html/canvas/OffscreenCanvasRenderingContext2D.cpp: (WebCore::OffscreenCanvasRenderingContext2D::setFont): * Source/WebCore/html/parser/HTMLDocumentParser.cpp: (WebCore::HTMLDocumentParser::runScriptsForPausedTreeBuilder): (WebCore::HTMLDocumentParser::notifyFinished): * Source/WebCore/html/parser/HTMLParserScheduler.cpp: (WebCore::HTMLParserScheduler::shouldYieldBeforeExecutingScript): * Source/WebCore/html/parser/HTMLScriptRunner.cpp: (WebCore::HTMLScriptRunner::executePendingScriptAndDispatchEvent): (WebCore::HTMLScriptRunner::runScript): Canonical link: https://commits.webkit.org/322783@main
…e repainting https://bugs.webkit.org/show_bug.cgi?id=326356 Reviewed by Darin Adler. Get rid of the last use of RenderImageResource::imageSize() by using svgImageRenderingSize() in RenderSVGImage::repaintOrMarkForLayout(). * Source/WebCore/rendering/RenderImageResource.cpp: * Source/WebCore/rendering/RenderImageResource.h: * Source/WebCore/rendering/svg/RenderSVGImage.cpp: Canonical link: https://commits.webkit.org/322784@main
…merging upstream's This reverts the source changes of the first and third commits of #630 (600e439 "for-of and array destructuring over an Array do not allocate an Array Iterator object" and 902d3c5 "op_iterator_close_check jumps over the IteratorClose sequence itself"). The RegExp literal part of #630 (op_new_reg_exp_shared) stays. Upstream landed the same change as 321765@main (35637c6, "Iterate Arrays without allocating a JSArrayIterator") and has built on it since: the Baseline and LLInt inline paths (bb73af4, 39f7f21), Strings without a JSStringIterator (5330149), and a DFG fix (45d9af5). The two versions add the same opcode and touch the same lines of the LLInt, the Baseline JIT, the DFG bytecode parser and the generator, so merging upstream on top of the fork's version would define most of it twice. With the fork's version gone the merge that follows takes upstream's as it is. Removed with it, because they were written against the fork's opcode and sentinel: Options::useUnboxedFastArrayIteration, VM::fastArrayUnboxedSentinel, the bytecode optimizer's case for op_iterator_close_check, its exclusion from CodeBlock::bytecodeCost(), the CompareEqPtr folding in the DFG abstract interpreter, and the RELEASE_ASSERTs for a sentinel cell in JSValue::synthesizePrototype() and JSCell::toStringSlowCase(). The ones that still apply to upstream's version come back after the merge. The JSTests of #630 (for-of-array-index-in-frame-*.js) stay: they describe behaviour of the language. cachedTypesFormatRevision is not lowered. This commit is a step of the upgrade and is not meant to be used on its own.
1020 upstream commits since 7b485a7 (the previous upgrade, #725), 188 of them in Source/JavaScriptCore, Source/WTF or Source/bmalloc. #725 landed as a squash, so git's merge base with upstream was still ccdcb8a. This merge was computed against 7b485a7 (a temporary `git replace --graft` gave 7465044 its upstream parent). It records upstream/main as a parent, so the next upgrade finds its base by itself as long as this lands as a merge commit and not as a squash. Conflicts, and what was done about them: Heap / Collector (c2fa192 and the eight commits after it move the collection cycle out of Heap into a new Collector class): - Heap.cpp, Heap.h: upstream's layout, with the fork's changes carried over. The auxiliary block evacuation, setInitialAllocationBudget(), releaseUnusedSharedBaselineCode() (now called from pruneDeadReferences()), the decoder string table hooks, the allocation counters and the aging stamps stay in Heap. The stamps that runBeginPhase() takes moved with it to Collector::runBeginPhase(). Heap::isIdleCollection() is out of line, since the current request is the Collector's. - GC rate limiting stays reverted (642e225): it is taken out of upstream's new Heap::recordCollectionTime() too. - GCRequest::didFinishEndPhase stays. Upstream removed it as unused (a516249); Bun sets it (JSC__VM__collectAsyncIdle). Collector::runEndPhase() runs it where Heap::runEndPhase() did. Source positions (93ebfac, c59d70e): - SourceProvider keeps the fork's encoded line start tables and its virtual lineColumnInTextForOffset(). That function now goes through upstream's LineStartTable::zeroBasedLineColumnForOffset(), which builds the table with withSourceConcurrently() and is safe off the main thread. - ExpressionInfo has both caches: upstream's decoded entries (under the unlinked code block's lock) and the fork's line/column map. decodeEntryForInstPC() is public, for the caller of expressionInfoIfDecoded() that can neither lock nor allocate. - BuiltinsSourceProvider keeps lineStartAfterTerminator(), which upstream dropped from SourceCharacters.h. ErrorInstance (696c406, lazy Error.captureStackTrace): upstream's captured stack trace next to the fork's onComputeErrorInfo hooks. m_hasErrorInfo replaces the empty-string placeholder, and setStackFrames() clears it with the string. m_stackString is written under the cell lock in the new paths as well, because the fork reads it from estimatedSize() during marking. Microtasks (53d4af9): runInternalMicrotask() takes its arguments by value. With USE(BUN_JSC_ADDITIONS) there are four of them (maxMicrotaskArguments is 4), and the four-argument JSGlobalObject::queueMicrotask() gets the same fast path. JSON (f62059d and the JSONCache commits): JSONAtomStringCache is gone. The fork's out-of-memory handling for long strings is now JSONCache::tryMakeJSString() / tryMakeLongJSString(), and the new inline string path of the parser checks for null. JSONCacheInlines.h is a private header (Bun includes it). JSBigInt (b071cfa, 13a1f29): the fork's division (Burnikel-Ziegler with interrupt checks, Barrett) is kept as it is. Upstream's Burnikel-Ziegler, which has lower thresholds and does not allocate at the leaves, is not taken; its three helpers that nothing else used are left out. WTF / libpas: - AvailableMemory: upstream's structure (7cc8fd9), with the cgroup limit (uv_get_constrained_memory) and the FreeBSD branch. The statm parsing fix is carried to MemoryFootprintGeneric.cpp, where LinuxMemory moved. - pas_compact_heap_reservation.c (5b0cfbc, two allocation fronts): Windows commits on demand for the top front too, and initializes both committed marks. - URLParser: the fork's scheme scan, with upstream's shrink(0). - AssemblerBuffer: both caps apply (upstream's option is off by default). Fork code adjusted to upstream API changes: typed C strings in ffi/ (UTF8CString), ASCIILiteral messages for DFG_CRASH, Collector::suspendCompilerThreads(), JSModuleLoader::drainSynchronousModuleQueue().
…on of it What the fork had built around its own for-of / array destructuring change (#630) and that still applies now that the opcode is upstream's (321765@main): - CodeBlock::bytecodeCost() does not count op_iterator_close_check. Tier-up thresholds and inlining budgets scale with that number, and the opcode stands in front of every IteratorClose sequence. - The bytecode optimizer does not substitute the opcode's operands: it reads and writes its iterator operand, and names the registers that op_iterator_open / op_iterator_next keep their state in. - JSValue::synthesizePrototype() and JSCell::toStringSlowCase() RELEASE_ASSERT a Symbol where they assumed one, so that a sentinel cell that got out of a frame register fails loudly. The throw of synthesizePrototype() is out of line again. - cachedTypesFormatRevision 13: the opcode has metadata now and sits among the opcodes with metadata, and op_iterator_open / op_iterator_next keep a String's iteration state in their registers too (322172@main). - The for-of-array-index-in-frame-*.js tests lose the run lines for --useUnboxedFastArrayIteration, an option of the fork's version. Not brought back: Options::useUnboxedFastArrayIteration, VM::fastArrayUnboxedSentinel (upstream has VM::fastArraySentinel) and the CompareEqPtr folding in the DFG abstract interpreter, which upstream's op_iterator_close_check does not need (it records the modes it has seen in its metadata).
There was a problem hiding this comment.
Findings marked 🟡 are optional suggestions and need no follow-up push.
Additional findings (outside the current diff — GitHub can't attach inline comments there):
-
🔴
Source/JavaScriptCore/runtime/JSArray.cpp:1109— Anyone who calls Array.prototype.splice on an array made immutable by JSObject::makePropertiesImmutable now mutates it in place or crashes, instead of getting the base branch's TypeError. fastSplice (JSArray.cpp:1063) never checks tryMakeWritable or hasImmutableProperties: at JSArray.cpp:1101-1107 it ignores the false that shiftCountWithAnyIndexingType / unshiftCountWithAnyIndexingType return for such an array and then memcpy's the items into the copy-on-write butterfly, and at JSArray.cpp:1109 ensureWritable trips the RELEASE_ASSERT in convertFromCopyOnWrite. Fix: fastSplice must return false whenever the array's elements cannot be made writable, e.g.if (!tryMakeWritable(vm)) return false;before any mutation.Why this was flagged
The fork makes an Int32/Double/Contiguous JSArray immutable by keeping its elements in copy-on-write storage (JSObject.cpp:3108-3135, Options::useCopyOnWriteArraysForImmutableProperties); its indexingType() still reads ArrayWithInt32 etc. because the CopyOnWrite bit is masked (JSCell.h:157), and tryMakeWritable returns false for it (JSObjectInlines.h:1651-1659). Upstream's new JSArray::fastSplice, reached from arrayProtoFuncSplice (ArrayPrototype.cpp:1250-1256) and from arraySpliceImpl (DFGOperations.cpp:1597), was merged without that check. For
a.splice(1, 0, 9)unshiftCountWithAnyIndexingType returns false at JSArray.cpp:1941-1942; ASSERT_UNUSED at JSArray.cpp:1106 is a no-op in release, so the memcpy at JSArray.cpp:1122 writes 9 over element 1 of the immutable butterfly and splice returns normally. On the base branch splice went through shift/unshift and putByIndexInline, where JSArray::put (JSArray.cpp:317) and the refused deletes threw TypeError, which JSTests/stress/immutable-properties-array-storage.js:99-102 asserts fora => a.splice(10, 5).Verification: New JSArray::fastSplice (Source/JavaScriptCore/runtime/JSArray.cpp:1063-1128) gates only on indexingType() (JSCell.h:157 masks the CopyOnWrite bit, so an immutable CoW array still reads ArrayWithInt32/Double/Contiguous), length, holes and item kinds; it never calls tryMakeWritable or checks hasImmutableProperties.
-
🟡
Source/JavaScriptCore/runtime/ArrayPrototypeInlines.h:155— Callers of push(), splice() with no arguments, or pop()/shift() on an empty array no longer get a TypeError when the array was made immutable with copy-on-write storage; they silently succeed. The new early return at ArrayPrototypeInlines.h:154-155 assumes only ArrayStorage can hold a read-only length, but the fork's JSArray::setLength also refuses an unchanged length for CopyOnWrite arrays whose structure hasImmutableProperties (JSArray.cpp:1352-1356). Fix: keep routing to JSArray::setLength whenever the length is read-only, e.g. only take the early return when!array->structure()->hasImmutableProperties()as well, so every setLength caller in ArrayPrototype.cpp (lines 558, 743, 1192, 1271, 609, 1301) still throws for immutable arrays.Why this was flagged
An array made immutable via JSObject::makePropertiesImmutable keeps Int32/Double/Contiguous copy-on-write storage (JSObject.cpp:3108-3121), so hasAnyArrayStorage(array->indexingType()) is false. arrayProtoFuncPush with zero arguments reaches setLength(globalObject, vm, thisObj, length) at ArrayPrototype.cpp:609 with newLength == length; arrayProtoFuncSplice with no arguments does so at ArrayPrototype.cpp:1192; pop and shift on a length-0 array at ArrayPrototype.cpp:558 and 743. On the base branch this always called JSArray::setLength, whose CopyOnWriteArrayWith* case throws ReadonlyPropertyWriteError when structure()->hasImmutableProperties() (JSArray.cpp:1355-1356). After the merge the comparison at ArrayPrototypeInlines.h:154 returns before that check, so the call completes without an exception. Frozen arrays via Object.freeze are unaffected because preventExtensions gives them ArrayStorage; only the fork's immutable arrays lose the error.
Verification: The new early return in ArrayPrototypeInlines.h:152-155 returns when !hasAnyArrayStorage(array->indexingType()) && array->length() == value. The base called setLength unconditionally. JSArray::setLength (JSArray.cpp:1352-1356) throws ReadonlyPropertyWriteError for CopyOnWriteArrayWith* when structure()->hasImmutableProperties() before the newLength == publicLength() check. Existing tests only cover push(9)/splice(0,1), which change length.
-
🟡
Source/WebCore/Modules/cookie-store/CookieStore.cpp:396— Sites on Cocoa that call cookieStore.set() with a non-ASCII name or value now send mojibake to their server in the Cookie request header. CookieStore.cpp:395-396 rewrites cookie.name and cookie.value through cookieStringForStorage, which on Cocoa (CookieCocoa.mm:226-236) turns the UTF-8 bytes into a Latin-1 String before createNSHTTPCookie; CFNetwork then UTF-8-encodes that string on the wire, so the bytes are double-encoded. The diff's own rebaseline records this: the subtest "HTTP headers agreed with CookieStore on encoding non-ASCII cookies" flips PASS to FAIL with the server receiving "ðª=ðµ" for '🍪=🔵'. Fix: cookies written by cookieStore.set must reach the server as the UTF-8 bytes of the script string (as on the base branch) while still matching names written through document.cookie.Why this was flagged
A page on macOS/iOS runs cookieStore.set('🍪', '🔵') and then fetches a same-origin resource with credentials. CookieStore::set at Source/WebCore/Modules/cookie-store/CookieStore.cpp:395-396 passes cookie.name and cookie.value through CookieUtil::cookieStringForStorage before the Cookie reaches CookieStorageSession::setCookieFromDOM (CookieStorageSessionCocoa.mm:408) and Cookie::createNSHTTPCookie (CookieCocoa.mm:150,159). On Cocoa cookieStringForStorage (CookieCocoa.mm:226-236) returns String(byteCast(scriptValue.utf8().span())). CFNetwork serializes the Cookie request header by UTF-8-encoding those NSStrings, so the server receives C3 B0 C2 9F C2 8D C2 AA instead of F0 9F 8D AA. The diff records exactly this in LayoutTests/imported/w3c/web-platform-tests/cookiestore/change_eventhandler_for_http_cookie_and_set_cookie_headers.https.window-expected.txt:7, where the subtest 'HTTP headers agreed with CookieStore on encoding non-ASCII cookies' goes from PASS to FAIL with 'HTTP cookie jar contains only cookie we set expected "🍪=🔵" but got "ðª=ðµ"'. On the base branch this subtest passed, so the server received the correct UTF-8 bytes.
Verification: Source/WebCore/Modules/cookie-store/CookieStore.cpp:395-396 (new) rewrites cookie.name and cookie.value through cookieStringForStorage before the Cookie reaches storage. On Cocoa, CookieCocoa.mm:226-236 returns String(byteCast(scriptValue.utf8().span())), and CookieCocoa.mm:150/159 put that string into NSHTTPCookieName/NSHTTPCookieValue. The rebaseline flips the non-ASCII subtest from PASS to FAIL with "ðª=ðµ".
Bionic has no POSIX shared memory: <sys/mman.h> of the NDK declares neither shm_open() nor shm_unlink(), so posixShmOpen() / posixShmUnlink() (new in a506af4) do not compile there, and the header is included by FileSystemPOSIX.cpp, ExecutableAllocator.cpp and the jsc shell. Nothing that the Android build compiles calls them.
… alone Upstream's new fast path for Array.prototype.splice (d29218b) goes by indexingType(), which does not say copy-on-write, so it spliced an array whose properties were made immutable (#759) in place. It now returns false for such an array, and the generic path refuses the puts and deletes as before. stress/immutable-properties-array-storage.js failed in every mode without this. With it, run-javascriptcore-tests (the options of the CI test job, release build, Linux x64) passes.
|
Preview build of 5dbf444: |
There was a problem hiding this comment.
Findings marked 🟡 are optional suggestions and need no follow-up push.
Additional findings (outside the current diff — GitHub can't attach inline comments there):
-
🔴
Source/JavaScriptCore/runtime/ErrorInstance.cpp:596— Reading err.stack on an error whose properties were made immutable after Error.captureStackTrace(err) now hands JS the internal CustomGetterSetter cell and loses the captured frames, where the base returned the stack string. materializeCapturedStackPropertyIfSaved moves the frames out and then calls putDirect at ErrorInstance.cpp:596 without the AllowLazyMaterializationOfImmutableProperties scope, so JSObjectInlines.h:510-512 refuses the store and the placeholder accessor stays. Fix: perform that putDirect under AllowLazyMaterializationOfImmutableProperties like ErrorInstance.cpp:517 and :538, and make errorInstanceMaterializingStackGetter never return the accessor cell (format and return the string when the store is refused).Why this was flagged
Trigger: Error.captureStackTrace(err) on an extensible ErrorInstance installs a CustomValue placeholder for "stack" and saves the frames in m_capturedStackTrace (ErrorInstance.cpp:562-577); the object is then made immutable with JSObject::makePropertiesImmutable, and err.stack is read. materializeCapturedStackPropertyIfSaved moves m_capturedStackTrace and m_stackString out (ErrorInstance.cpp:587-590), formats the string, then calls putDirect at ErrorInstance.cpp:596 with no AllowLazyMaterializationOfImmutableProperties scope. putDirectInternal returns ReadonlyPropertyChangeError at JSObjectInlines.h:510-512 because structure->hasImmutableProperties(), so nothing is stored and the return value is ignored. The frames are now gone and the CustomValue placeholder remains, so errorInstanceMaterializingStackGetter (ErrorInstance.cpp:42-48) finds m_capturedStackTrace null and returns getDirect(vm, stack), i.e. the CustomGetterSetter cell itself, to JavaScript. On the base branch captureStackTrace stored the formatted string directly, so err.stack was a string regardless of later immutability.
Verification: materializeCapturedStackPropertyIfSaved (ErrorInstance.cpp:579-598) moves m_capturedStackTrace and m_stackString out into locals and then calls plain putDirect at line 596 with no AllowLazyMaterializationOfImmutableProperties scope, unlike the sibling puts at lines 497, 517 and 538; JSObjectInlines.h:510-512 returns ReadonlyPropertyChangeError, the return value is ignored, and the captured trace is gone for good.
-
🟡
Source/JavaScriptCore/runtime/LiteralParser.cpp:931— nit (Bun-only): callers of streamingJSONParse now get a stale charactersConsumed on the error path, pointing inside a value that was already appended to results. The new fast-path lexer helpers (nextAfterValue at LiteralParser.cpp:907, also nextString, nextNumber, consumeColon) advance m_ptr without updating m_positionAfterLastToken, which only lex() sets at LiteralParser.cpp:764. tryStreamingParse reads it at LiteralParser.cpp:2348 right after a value whose next character is ',', '}' or ']'. Fix: record m_positionAfterLastToken in every helper that consumes a token under USE(BUN_JSC_ADDITIONS), or fall back to next() there, so the position always follows the last consumed token.Why this was flagged
Input to Bun's streamingJSONParse such as
{"a":1},\n{"b":2}(a top-level value directly followed by ',', '}' or ']'). parseRecursively ends the object with m_lexer.nextAfterValue() at LiteralParser.cpp:1916; nextAfterValue sees ',' and takes the fast path at LiteralParser.cpp:917-931, which only bumps m_ptr and sets m_currentToken.type. m_positionAfterLastToken is only assigned inside lex() at LiteralParser.cpp:764, so it still holds the position from the last full lex() call, which for this object is just after '{'. tryStreamingParse at LiteralParser.cpp:2348-2363 then sets lastGoodPosition to that stale offset and returns Status::Error with charactersConsumed inside the value even though the value was appended to results at LiteralParser.cpp:2347. On the base branch every token went through lex(), so lastGoodPosition was the offset right after '}'. jsc.cpp:2389 exposes this as charactersConsumed. Only the position differs; the status is Error on both branches.Verification: Triggered only in a USE(BUN_JSC_ADDITIONS) build when a streamingJSONParse top-level value is directly followed by ',', '}' or ']'.
m_positionAfterLastToken = m_ptr;is assigned only inLexer::lex()(LiteralParser.cpp:764);nextAfterValue()(907-933) does++m_ptrwithout touching it.tryStreamingParse(2347-2348) then returns Error with a stalecharactersConsumedpointing inside a value already appended toresults.
oven-sh/WebKit#773 has landed as 0c06faadf65b, and its autobuild release is published for every platform. This replaces the preview tag, whose release goes away with the pull request. The merge commit also contains oven-sh/WebKit#772 (a catch OSR entrypoint needs a sample of every operand), which landed on the fork's main in between.
Upgrades the WebKit fork to upstream WebKit `dbdca7545d` (2026-10-05): 1020 upstream commits since `7b485a76e9` (#43882), 188 of them in JavaScriptCore, WTF or bmalloc. Fork PR: oven-sh/WebKit#773. ### Pin - `WEBKIT_VERSION` points at the preview build of the fork PR (`autobuild-preview-pr-773-5dbf444e`). **Before this merges, bump it to the `autobuild-<sha>` of the fork's merge commit**, once oven-sh/WebKit#773 has landed. ### What changed in Bun - `WTF::CString` is a class template upstream now, and `data()` of a UTF-8 one is a `const char8_t*`. Declarations name `UTF8CString` (or `Latin1CString`), and calls into C APIs (`execve`, `posix_spawn`, `dlopen`, `dlsym`, `GetProcAddress`, libsecret, CoreFoundation, the Windows credential API, sqlite, ncrypto) take `legacyCStringPointer()`. Files: the Secrets backends, `BunProcess.cpp`, `BunString.h`, `NodeTLS.cpp`, the sqlite bindings, `JSBundlerPlugin.cpp`, `JSX509CertificatePrototype.cpp`, `CryptoGenEcKeyPair.cpp`, the V8 CPU profiler shim, `JSCompressionStreamShared.cpp`, `ChromeBackend.cpp`, `ObjCRuntime.h`. - `JSONRowsToJS.cpp` uses `VM::jsonCache()` (`JSONAtomStringCache` is gone). The fork keeps `tryMakeJSString()` there. - `Zig::GlobalObject::visitChildrenImpl` takes the VM from the cell: a slot visitor has no `vm()` any more. - `makeDOMAttributeGetterTypeErrorMessage` takes a `StringView`; `Yarr::FlagsString` has `span()` only (`SerializedScriptValue.cpp`); `RemoteInspectorServer::start` takes a `UTF8CStringView`; `StringView::fromLatin1(span)` is gone (`ChromeBackend.cpp`). - Nothing changes for `JSC__VM__collectAsyncIdle` and the four-argument microtasks: the fork keeps `GCRequest::didFinishEndPhase` and `maxMicrotaskArguments = 4`, which upstream removed or does not have. - `src/jsc/JSType.rs` needs no change: `JSType.h` is the same. - `bundler_bytecode_portable.test.ts` has a new snapshot, because the bytecode cache format changed. Caches written by an older Bun are rejected and rebuilt, and `--compile --bytecode` executables must be rebuilt. - The macOS and Windows parts of these edits (`SecretsDarwin.cpp`, `SecretsWindows.cpp`, `ObjCRuntime.h`, the `posix_spawn` and `GetProcAddress` calls) were made by reading the code. They have not been compiled: only Linux x64 was built locally. ### How was it verified Debug + ASAN build against the local WebKit tree, Linux x64. - `test/js/bun/jsc/webkit-upgrade-dbdca7545d.test.ts` (new, 9 cases): passes. On Bun 1.3.13, 8 of the 9 fail; the ninth checks that for-of and destructuring still close an Array or String iteration, which did not change. - These pass: `webkit-upgrade-7b485a76e9`, `webkit-upgrade-ccdcb8a026`, `bun-jsc`, `capture-stack-trace`, `AsyncLocalStorage`, `async-local-storage-thenable`, `jsonl-parse`, `json5`, `xml-test-suite`, `ffi`, `cc`, `sqlite`, `node-sqlite`, `process-execve`, `compression`, `x509`, `gc-controller-cadence`, `error-stack-finalizer-exception`, `bundler_compile_prelinked`, `vm`, `workers/structured-clone`, `process-nexttick`, `microtask`, `inspect-error`, `test/stack`. Five of them (`AsyncLocalStorage`, `json5`, `ffi`, `gc-controller-cadence`, the encoder cases of `bundler_bytecode_portable`) need more than the default 5 s per test on this debug build and were run with a longer timeout. - `bundler_bytecode_portable.test.ts`: the two encoder cases pass with the new snapshot. Its `--compile` cases were not completed locally (the machine ran out of temporary disk space for the debug executables), so CI is the first full run of that file. - `capture-stack-trace.test.js` caught a mistake in the merge (a stale flag after `Error.captureStackTrace` replaced a stack that a collection had formatted). It is fixed in the fork PR. - With the pin in place, a debug build against the prebuilt `autobuild-preview-pr-773-5dbf444e` (`bun bd`) builds, and the new test and `capture-stack-trace.test.js` pass on it. - The fork's CI for oven-sh/WebKit#773 is green on every lane, including its JavaScriptCore test run on Linux x64 and arm64. - The full Bun test suite has not been run locally. Upstream WebKit `7b485a76e9c..dbdca7545da` — 188 non-merge commits touching `Source/JavaScriptCore`, `Source/WTF` or `Source/bmalloc`, committed 2026-09-23 through 2026-10-05 (36 of them are WebCore/WebKit changes that only touch `UnifiedWebPreferences.yaml`, `Platform*.h` or similar in WTF). ### Notes for Bun Bun usage below was found by grepping `src/jsc/bindings` and `src/jsc/JSType.rs`. "What changed in Bun" above says what was done about each item. **`JSType.h`** - `Source/JavaScriptCore/runtime/JSType.h` is unchanged in this range (empty diff). No enum values added, removed or reordered, so `src/jsc/JSType.rs` needs no change. **API changes that Bun's bindings use** - `WTF::CString` is now a class template. The untyped class was renamed `CStringBase` with protected constructors, assignment, destructor and `data()`; `CStringWithEncoding<T>` was renamed `CString<T>` (`UTF8CString`, `Latin1CString`, `ASCIICString` aliases are unchanged). `data()` on the typed strings returns `const char8_t*` / `const Latin1Character*` / `const char*`; `legacyCStringPointer()` remains on `UTF8CString` only. `CStringHash` / `DefaultHash` / `HashTraits` are now templates over the typed string. Bun uses bare `CString` / `WTF::CString` as a concrete type (locals without initializer, parameters, members, `Vector<CString>`, `std::variant<WTF::CString, …>`) and calls `.data()` on the sliced value in 19 files: `Secrets.h`, `SecretsDarwin.cpp`, `SecretsLinux.cpp`, `SecretsWindows.cpp`, `JSSecrets.cpp`, `BunProcess.cpp`, `BunString.h`, `bindings.cpp`, `ZigGlobalObject.cpp`, `NodeTLS.cpp`, `JSX509CertificatePrototype.cpp`, `JSBundlerPlugin.cpp`, `webcrypto/SubtleCrypto.cpp`, `node/crypto/CryptoGenEcKeyPair.cpp`, `v8/shim/CpuProfiler.h`, `sqlite/JSSQLStatement.cpp`, `sqlite/NodeSqlite.cpp`, `webcore/streams/BunStreamConsumers.cpp`, `webcore/streams/JSCompressionStreamShared.cpp`. `22e1cc5592e` `f2ca04538ea` `4cd0b19673f` `2c5cd6d774d` `8a38069dceb` `165f9ed4d01` - `AbstractSlotVisitor::vm()` and `heap()` were removed; visitors now hold a `Collector&` (`visitor.collector().heap()`), plus `collectionScope()` and `heapAnalyzer()`. Used at `ZigGlobalObject.cpp:3301` (`WebCore::clientData(visitor.vm())`). `101392f63ca` - `GCRequest::didFinishEndPhase` was removed (upstream had no user), and `GCRequest::subsumedBy()` no longer treats a request with a callback as never subsumed. `JSC__VM__collectAsyncIdle` in `bindings.cpp:3184-3198` sets `request.didFinishEndPhase` and relies on that non-coalescing rule (see also `BunClientData.h:262`). `a5162492689` - `JSONAtomStringCache.h` / `JSONAtomStringCacheInlines.h` were deleted and `VM::jsonAtomStringCache` removed; the replacement is `VM::jsonCache()` (`JSONCache.h`, `JSONCacheInlines.h`), whose `makeIdentifier` / `makeJSString` take `VM&` as first argument. `JSONRowsToJS.cpp` includes the deleted header and calls `vm.jsonAtomStringCache.makeIdentifier(...)` and `tryMakeJSString(...)` (the latter exists only in Bun's fork). `f62059d5478` - `JSC::Yarr::FlagsString` changed from `std::array<char, N>` to a class exposing only `span()` (`std::span<const Latin1Character>`). `webcore/SerializedScriptValue.cpp:1188` calls `flagsString(...).data()`. `4356bc5514b` - `makeDOMAttributeGetterTypeErrorMessage` / `makeDOMAttributeSetterTypeErrorMessage` take `StringView interfaceName` instead of `const char*`; `StringView(const char*)` is private. `ZigGlobalObject.cpp:1872` passes `utf8().legacyCStringPointer()`. `JSDOMExceptionHandling.cpp:267` passes an `ASCIILiteral`, which converts. `0f3178a96a1` - `runInternalMicrotask` now takes `uint8_t payload, JSValue argument0, argument1, argument2` by value instead of a `std::span<const JSValue, maxMicrotaskArguments>`, and `JSGlobalObject::queueMicrotask` writes the `QueuedTask` straight into the deque on the fast path. Bun's bindings do not call `runInternalMicrotask`, but they build 4-argument `QueuedTask`s (`bindings.cpp:4020`, `bindings.cpp:5871`, `webcore/streams/JSStreamPipeToOperation.cpp:120`, `webcore/streams/WritableStreamOperations.cpp:76`) and the fork sets `maxMicrotaskArguments = 4`; upstream's new signature carries three. `53d4af93f61` **API changes checked and not used by Bun's bindings** - `Heap::lastChanceToFinalize()` is private; `VM::~VM` calls the new `Heap::shutDown()`. Bun only mentions it in comments. `1d03118dfe7` - Moved from `Heap` to the new `Collector` class (`heap/Collector.h`, reachable via `Heap::collector()`): `runTaskInParallel`, `runFunctionInParallel`, `forEachSlotVisitor`, the request queue, phase machine, marking constraint set, collector thread. `Heap::phaseVersion()`, `increaseLastFullGCLength()` removed; `didDiscoverPendingWasmCallee` renamed `markWasmCalleeIfPending`; `collectorSlotVisitor()` and `isInPhase()` are now defined in `HeapInlines.h`. `Heap::collectAsync/collectSync/collectNow(GCRequest)` and `Heap::addMarkingConstraint(std::unique_ptr<MarkingConstraint>)` keep their signatures. `SlotVisitor` is now `alignas(128)` and constructed from a `Collector&`. `c2fa1927604` `5e53548c666` `5297538c7da` - `SourceProvider::codeBlockHashConcurrently` is no longer virtual (and is `const`); the new virtual is `withSourceConcurrently(const ScopedLambda<void(StringView)>&) const`, whose default calls `source()`. `documentLineColumnForOffset()` (used by `ErrorStackFrame.cpp:69`) keeps its signature and 1-based result but now goes through `withSourceConcurrently`. `positionInfoForOffset()` / `offsetForPosition()` assert they are not on a GC thread. No override of `codeBlockHashConcurrently` found in Bun's bindings. `93ebfacfd7a` - `ErrorInstance`: `setStackPropertyAlreadyMaterialized()` renamed `setStackPropertyProvidedByCapturedStackTrace()`; new `m_capturedStackTrace`, `m_hasErrorInfo`, `trySaveCapturedStackTraceForLazyMaterialization()`. The methods Bun calls that exist upstream (`stackTrace()`, `materializeErrorInfoIfNeeded()`, `setNativeGetterTypeError()`, `isStackOverflowError()`) are unchanged. `696c406fe52` - `JSObject::setStructure(VM&, Structure*)` is now defined in `StructureCreateInlines.h` (included by `JSObjectInlines.h`) instead of `JSObject.h`. `JSDOMWrapperCache.cpp:49` calls it and already reaches `JSObjectInlines.h` through `root.h` → `JSCInlines.h`. `720bc3a7c71` - `PropertySlot::setCustom(…, DOMAttributeAnnotation)` overload removed; `JSObject::fillCustomGetterPropertySlot` lost its `Structure*` parameter. `96fed6d5b49` - `RegExpObject::isSymbol{Match,Search,MatchAll,Replace,Split}FastAndNonObservable()` now take a `JSGlobalObject*`; `constructArrayBufferWithSize()` lost its `JSGlobalObject*` parameter. `bffe36ec16e` `94de22268a7` - `VM::fastStringValuesSentinel()` renamed `fastStringSentinel()`; new `VM::fastArraySentinel()`. `5330149c555` `35637c64339` - `Debugger::forEachBreakpointLocation` takes `const Function&` instead of `Function&&`; new virtual `Debugger::isPauseBlockedByAnotherDebugger()` (default false), `Debugger::hasProfilingClient(const ProfilingClient&)`, `InspectorEnvironment::forEachDebugger()` (default visits `debugger()`). `ba688904ad4` `7c0df54a062` - `StructuredCloneTags.h` gains `QuotaExceededErrorTag = 69`. Bun's `SerializedScriptValue.cpp` does not include this header. `21862acf2c3` - C API helpers: `createJSString()` in `JSStringRefCPP.h` returns `RefPtr<OpaqueJSString>` instead of `JSRetainPtr<JSStringRef>`; new `API/JSStringRefPtr.h`. `71d5b30126a` - WTF: `wtf/text/CStringView.h` renamed `wtf/text/UTF8CStringView.h` (`CStringView` → `UTF8CStringView`) `df3a6b749ba`; `StringView::fromLatin1(std::span<const Latin1Character>)` removed (the `const char*` overload Bun uses remains) `3fb615cd242`; `ParkingLot::UnparkResult::didUnparkThread` replaced by `unparkedCount`, `unparkOneImpl` replaced by `unparkCountImpl`, and `unparkCount(address, 0)` now release-asserts `5d43ab597d9` `35ba3364d35`; `ReadWriteLock::ReadLock/WriteLock` renamed `ReadLockView/WriteLockView` `5d43ab597d9`; `GuaranteedSerialFunctionDispatcher` gains pure virtual `dispatchAfter(Seconds, Function<void()>&&)`, and `RunLoop::dispatchAfter` returning a `DispatchTimer` was renamed `RunLoop::scheduleTimer` `155da279924`; `WTF::MemoryStatus`, `memoryStatus()`, `isUnderMemoryPressure()` removed and `percentAvailableMemoryInUse()` is now an exported function `7cc8fd9a7f6`; `WTFLogChannelByName`, `WTFInitializeLogChannelStatesFromString`, `FilePrintStream::open`, `stringFromFileSystemRepresentation` take typed strings `0f3178a96a1`; `wtf/SwiftCXXThunk.h` and `HAS_SWIFTCXX_THUNK` removed `edbf6068f30`; `SWIFT_ESCAPABLE*` / `SWIFT_NONESCAPABLE` renamed `SWIFT_SELF_CONTAINED*` / `SWIFT_VIEW` `46495d17ae3`. - Many functor parameters in WTF and JSC were annotated `NOESCAPE` and changed from `F&&` to `const F&` (for example `StringView::find/contains`, `WTF::map`, `handleWithAdapters`, `UUID::handle`, `JSBigInt::absoluteBitwiseOp`, `MarkedVector::fillWith`). A `mutable` lambda passed to one of these no longer binds. A grep for `mutable` lambdas passed directly to these in Bun's bindings found none; this was not checked exhaustively. `b0aeb546671` `01e2533964d` **Overlap with Bun's fork patches** - `git diff --name-only 7b485a76e9c HEAD` and `7b485a76e9c upstream/main` share 241 files under these three directories. Files where upstream's change is structural and the fork also carries patches: `heap/Heap.{h,cpp}`, `heap/GCRequest.{h,cpp}`, `heap/SlotVisitor.h`, `heap/AbstractSlotVisitor{,Inlines}.h`, `runtime/JSMicrotask.{h,cpp}`, `runtime/MicrotaskQueueInlines.h`, `runtime/JSONAtomStringCache{,Inlines}.h` (deleted upstream), `runtime/LiteralParser.{h,cpp}`, `runtime/ErrorInstance.{h,cpp}`, `runtime/ErrorConstructor.cpp`, `parser/SourceProvider.{h,cpp}`, `runtime/VM.{h,cpp}`, `runtime/OptionsList.h`, `bytecode/BytecodeList.rb`, `runtime/JSArrayIterator{,Inlines}.h`, `yarr/YarrFlags.h`, `wtf/RunLoop.h`, `wtf/AvailableMemory.{h,cpp}`, `wtf/text/StringView.h`, `bmalloc/bmalloc.{h,cpp}`. The fork PR lists how each one was resolved. **Build system** - New JSC sources: `heap/Collector.cpp`, `runtime/JSONCache.cpp` (`Sources.txt`). New JSC headers: `heap/Collector.h`, `heap/CollectorInlines.h`, `runtime/JSONCache.h`, `runtime/JSONCacheInlines.h`, `API/JSStringRefPtr.h`, `corpse/CorpseMemory*.h`. Removed: `runtime/JSONAtomStringCache{,Inlines}.h`, `runtime/JSONTransitionCache{,Inlines}.h` (added and removed within the range). - New WTF headers: `LayeredHashMap.h`, `MonotonicObjectIdentifier.h`, `posix/POSIXExtras.h`, `glib/GLibExtras.h` (GLib ports and JSCOnly with GLib). Removed: `SwiftCXXThunk.h`. Renamed: `text/CStringView.{h,cpp}` → `text/UTF8CStringView.{h,cpp}`. - bmalloc `CMakeLists.txt`: `pas_small_medium_bootstrap_free_heap.{c,h}` and `pas_small_medium_bootstrap_heap_page_provider.{c,h}` replaced by `pas_mte_bootstrap_*`; `pas_allocation_mode.h`, `pas_compact_bitfit_global_directory_ptr.h`, `pas_compact_segregated_heap_ptr.h` removed. `c8cb35beaca` `5b0cfbc518e` - Top-level `CMakeLists.txt` sets `CMAKE_PCH_PROLOGUE ""` and a `WEBKIT_ENABLE_LANGUAGE` macro replaces direct `enable_language()`, so generated `cmake_pch.hxx` no longer starts with `#pragma clang system_header` and warnings in prefix headers are reported. The 2003-era `NULL` redefinition was dropped from `JavaScriptCorePrefix.h`. `12dd44cb41c` - `WebKitCompilerFlags.cmake` adds `-Wno-unused-template` globally for GCC/Clang. `75930ee50a6` `fce5f763755` - JSC `CMakeLists.txt` passes `--defines-file ${WEBKIT_PLATFORM_FEATURE_DEFINES_FILE}` to `generate-combined-inspector-json.py` when that variable is set. `71b89186dc0` - New CMake options: `GENERATE_DSYM` (Apple only; `LLIntSettingsExtractor` / `LLIntOffsetsExtractor` marked `SKIP_DSYM`) `5bd718a24ea`, `ENABLE_SWIFT_BASE_CLASS_ANNOTATIONS` (default from detected Swift version, off when not found) `5f4afbfb124`, `ENABLE_CONNECTED_VOLUMETRIC_SCENE` (off) `a216b77387a`, `USE_EXTENSIONKIT` (off). - `OptionsJSCOnly.cmake`, `OptionsCommon.cmake` and `WebKitCommon.cmake` are unchanged. The remaining `Source/cmake` commits are Cocoa/GTK/WPE packaging (Info.plists, entitlements, XPC services, OpenSSL crypto backend option for GLib, Cog removal, symbol visibility for ObjC, `-O3` for bmalloc in Cocoa Debug builds). - `PlatformEnable.h`: adds `ENABLE_CONNECTED_VOLUMETRIC_SCENE` (default 0) and `ENABLE_SWIFT_BASE_CLASS_ANNOTATIONS` (Apple SDK 27+). `PlatformHave.h`: removes `HAVE_WK_SECURE_CODING_NSURLREQUEST`, adds `HAVE_UI_HINGE_INTERACTION`. No `ENABLE_`/`USE_` default relevant to JSCOnly changed. **Runtime options and defaults** - `useWasmWideArithmetic` default changed from false to true (defined via `jscOptionName` in `UnifiedWebPreferences.yaml`). `ba4ffde8464` - `useWasmFastMemory` is no longer forced off on Windows in `Options::notifyOptionsChanged()`. No reference to this option was found in Bun's source. `653b77d5bdd` - New: `useCachedAssemblerDataCapacityLimit` (default false, from `UnifiedWebPreferences.yaml`) and `maximumCachedAssemblerDataCapacity` (4 MB). `6e9eb5b8025` `edb44235bc7` - New: `maxB3WasmGCEpochSnapshotEntries` (1048576). Removed: `useB3ReduceStrengthFixpoint`. `33ca66ce3ff` `1ffb8e9a913` - No reference to any of these option names was found in Bun's `src`, `scripts` or `cmake` directories. **Bytecode and bytecode cache** - New opcode `op_iterator_close_check` (operands `iterator`, `next`, `iterable`, `targetLabel`; metadata `seenModes`), inserted before the metadata-less opcodes, so later opcode IDs shift. `35637c64339` `5330149c555` - `op_iterator_open` / `op_iterator_next` operand meaning changed in `FastArray` and the new `FastString` iteration modes: `iterator` holds a per-VM sentinel and `next` holds the Int32 index. - `Reflect.construct(F, [a, b])` with a hole-free, spread-free array literal now emits `op_construct` instead of `op_construct_varargs`. `8ae122a8481` - Upstream's `runtime/CachedTypes.cpp` is unchanged. Bytecode produced by the previous WebKit is not valid for this one because of the opcode changes: the fork's `cachedTypesFormatRevision` goes from 12 to 13, and Bun keys its cache version on `BUN_WEBKIT_VERSION` (`ZigGlobalObject.cpp:264-271`), which changes with the upgrade. ### New features / spec changes - WebAssembly wide arithmetic enabled by default. `ba4ffde8464` (325219) - `(a?.b)(x)` now parses as a call outside the optional chain: when `a` is nullish the arguments are evaluated and a TypeError is thrown instead of returning undefined. `(a?.b)() = 1` in sloppy mode becomes a runtime ReferenceError instead of a SyntaxError. `63b7d629dd1` (325104) - Tagged templates keep `this` for a parenthesized optional-chain tag (`(o?.b)\`x\``) and use the current `this` for a `super.tag\`x\`` tag. `7fbe85cfbfd` (325401) `24e354459de` (325756) - `await` is accepted as an identifier in the body of a non-async function nested in an async function's parameters. `09c4cfc7d73` (325954) - `catch (await)` is rejected in async functions, modules and static blocks, including the escaped spelling. `edb17fbf37d` (325957) - `new Array(len)` reads `newTarget.prototype` before throwing RangeError for an invalid length; `new ArrayBuffer(len)` applies ToIndex to length and `maxByteLength` before reading `newTarget.prototype`. `e4e335cf8df` (325494) `1b1238d3e39` (325496) - TypedArray construction from a Proxy array-like performs a real `Get` of `length`; a module namespace export named `length` is not used as the length. `71d329770b1` `240fe1fc636` (325491) - `Intl.DurationFormat`: keeps the minus sign for fractions between -1 and 0, and keeps a sub-second fraction folded into a zero-valued unit. `501d1f661f9` (325247) `ee8e5dbbcc2` (325238) - `Intl.Segmenter` `containing()` returns the right segment when the index is a lead surrogate. `3e27303e85c` (324036) - Temporal: invalid calendar identifier errors use one message format and ellipsize very long ids. `3141e1c6626` (325305) - Wasm ESM integration: `wasm:` / `wasm-js:` reserved-name LinkErrors skip string-constant imports and recognized builtins. `caa67084218` (325162) ### Performance **Bytecode, LLInt, Baseline** - `for-of` and array destructuring over an Array no longer allocate a `JSArrayIterator` in LLInt/Baseline/DFG; state is kept in registers. `35637c64339` (324224) - The same for Strings (`JSStringIterator`). `5330149c555` (325452) - `op_iterator_next` FastArray path is inlined in Baseline and LLInt for Int32/Contiguous arrays. `bb73af4a4bc` (325235) `39f7f217cda` (325774) - LLInt gets an integer TypedArray fast path for `put_by_val`. `41302976307` (326248) - `Reflect.construct` with an array literal avoids allocating the array. `8ae122a8481` (325232) **DFG / FTL** - `CheckStructure` with several structures compares recently seen structures first. `ebb9bf5fa08` (326249) - String equality with a rope operand compares lengths inline before calling `operationCompareStringEq`. `bd3aa0eab70` (326312) - `ValueSub` reads its arith profile in `makeSafe`, avoiding repeated OSR exits on double results. `e3ff851cf04` (326000) - `CompareEq(String, StringOrOther)` is converted to `CompareStrictEq`; `MakeRope` accepts `StringOrOther` operands outside `String#concat`. `4f03ef594d4` (325583) `db86e0961a4` (325751) - BigInt comparisons against `0n` become pointer / sign-bit checks. `73af864d11c` (325432) - Int52: architecture-specific `tryConvertToInt52`, more precise Int52 overflow profiling, B3 SShr+Mul range optimization. `be0094718dc` (325457) - FTL OSR exits are stored as a byte stream (reported 56 B → about 12 B per exit on JetStream 3), with their `ValueRep`s inline. `ee4792cb07c` (324517) `fb512fb75f6` (325463) - ICs flatten an uncacheable dictionary when they see a getter on it, as they already did for data properties. `96fed6d5b49` (325245) **B3 / Air / OMG** - Value-numbering based CSE and WasmGC load forwarding in the first `ReduceStrength` run, using a new `WTF::LayeredHashMap`; forward store elimination and Phi synthesis for WasmGC reads were dropped. `33ca66ce3ff` (324906) `8e2d66bfd16` (325885) - Constant-condition branches are pruned when FTL/OMG generate B3; `Switch` on a constant is folded. `c3148b98af6` (325097) - `simplifyCFG` no longer iterates to a fixpoint; the fixpoint debugging mode was removed. `33bc312ad4c` (325484) `1ffb8e9a913` (325459) - `fixSSA` runs at every opt level so `Get`/`Set` never reach Air lowering. `d9fb479bd09` (325079) - OMG: no predecessor wiring in the frontend, no redundant address `Add` for stack arguments/results; `BasicBlock::appendNewControlValue` removed. `a8c7000ca69` `5e551b0a24e` `6edd3cc7294` **Runtime** - `JSON.parse`: single-transition and transition caches for object keys (8-bit and 16-bit sources), an embedded name / prefixed-name cache compared with SIMD, one-character token fast paths, more SIMD scanning in string lexing, a long-string cache, a 64-entry cache for repeated short string values, bulk copy when materializing arrays. The caches live in a new heap-allocated `JSONCache`. `b718c65267c` `12ea13fb7c8` `1e80c1e3efb` `0506f92aff1` `ec88ec5ecbe` `7fb452f1a4b` `e5517023f3e` `f62059d5478` `26fbddd98c8` `07a51e24339` `615e180ef2c` - `JSArray::fastSplice` for Int32/Contiguous/Double arrays. `d29218b6deb` - BigInt division uses Burnikel-Ziegler for divisors of 24+ digits and quotients of 48+; the schoolbook leaf no longer heap-allocates. `b071cfab287` (325444) `13a1f291693` (326174) - `parseInt` avoids resolving rope arguments; `ToNumber` on a string rejects non-numeric input by its first character. `1df0dac22df` (325765) `bef9d7e6329` (325591) - `Error.captureStackTrace()` on an `ErrorInstance` without an own `stack` captures frames only and formats the string on first access. `696c406fe52` (325578) - Decoded `ExpressionInfo` entries are cached per bytecode offset (under a lock); line start tables are built in one SIMD pass. `c59d70e267e` (325559) - Microtask queueing and draining avoid copying `QueuedTask` through the stack; `clearExceptionExceptTermination()` returns early when no exception is pending. `53d4af93f61` (326306) `346b6ce3d9f` (325968) - `setPrototypeDirect` skips `haveABadTime()` when the old prototype chain already intercepted indexed access. `9ef3e2eb29b` (325587) - Per-thread `AssemblerBuffer` storage above `maximumCachedAssemblerDataCapacity` can be freed instead of cached (behind `useCachedAssemblerDataCapacityLimit`, default off; landed, reverted, relanded). `6e9eb5b8025` `06d713139e1` `edb44235bc7` (325503) **GC (refactoring, stated as no behavior change)** - Collection-cycle state and machinery moved from `Heap` into a new `Collector` class, in preparation for one collector marking several heaps: marking machinery, phase machine, collector thread, request queue, constraint set, setup/teardown, and the begin/end-of-collection boundary. `c2fa1927604` `59be6c12449` `36d446cb4f9` `5e53548c666` `1d03118dfe7` `648d26d0bfa` `152ae41b47b` `5297538c7da` `d3c92619498` - `SlotVisitor` no longer holds a `Heap`; `visitChildren` implementations and constraints take the VM/heap from the cell or capture it. `6730df1f851` `101392f63ca` - Renames: conservative scan "current thread" → conductor; Wasm callee cleanup functions named for marking. `dfdac830e36` `868ef794075` ### Bug fixes **JIT correctness** - B3 `specializeSelect` cloned `Phi`s between the `Select` and the `Check`, leaving a Phi slot unwritten and producing a garbage value in exit state. `6dd325c7d06` (325312) - DFG fixup cleared `NodeMustGenerate` on `ArithFloor/Ceil/Round/Trunc` in Int32 rounding modes, so DCE could remove an operation that must exit on overflow or negative zero. `f325c4f3adb` (325499) - DFG constant folding skips CFA-unreachable blocks (debug assertion). `64baa915314` (325835) - DFG assertion on a `for-of` site that sees both an Array and a generic iterator. `45d9af505ef` (325416) **Cross-realm** - Promise `then`/`catch`/`finally` fast paths and DFG inlining of `Promise.prototype.then` / `Promise.resolve` / `Promise.reject` are no longer taken for another realm's promise or function. `1f47117433c` (325110) - The same for String/RegExp fast paths (`match`, `matchAll`, `replace`, `replaceAll`, `search`, `split`, `RegExp.prototype.test`). `bffe36ec16e` (325134) - DFG `ArrayBuffer` construction uses the realm of the baked-in structure. `94de22268a7` (326133) **Memory safety, races, platform** - `ReadWriteLock`: the last reader could write to the lock after the writer it drained for had acquired and freed it. `e71d94bd49e` (325611) - Wasm `RTT` is allocated with the compact allocator, matching its use in `CompactPointerTuple` (affects MTE-enabled configurations). `03befd703d6` (323513) - `fastMallocSize` handles allocations from the tagged bmalloc heap under MTE. `88167d46efc` (325834) - Line/column lookups (`SourceProvider::documentLineColumnForOffset`) are safe off the main thread. `93ebfacfd7a` (324838) - Windows: creating or growing a Wasm memory, resizable `ArrayBuffer` or growable `SharedArrayBuffer` at the commit limit reports out of memory instead of crashing. `987be10500c` (325406) - Windows: the Wasm guard region is reserved rather than committed, and Wasm fast memory is re-enabled. `653b77d5bdd` (304154) - `AvailableMemory` on iOS reads the jetsam limit via `task_info`; the previous sandboxed syscall made it always report 1024 MB. `7cc8fd9a7f6` (325827) **Debugger / inspector** - `Debugger::isPauseBlockedByAnotherDebugger()` lets a subclass hold off pausing; checked by `breakProgram()` and `didReachDebuggerStatement()`. `ba688904ad4` (325815) - Script profiler installs its client on every debugger of the environment. `7c0df54a062` (323477) - GLib and Socket `RemoteInspector::setup` ignore a Setup message for a target that already has a connection. `2dc02450f27` (326023) - Wasm debugger: `qMemoryRegionInfo` always describes a region; no null `CodeBlock` read for host-function frames. `840c8efcbd1` (325534) `3087a955392` (325518) ### WTF - `CString` typing series (see Notes): typed C strings everywhere, `UTF8CStringView`, `UTF8CString::unsafeFromUTF8()` / `fromUTF8()`, `StringView(const ASCIICString&)`, `StringView::codePointCount()`, `SAFE_*` printf macros in more call sites, logging passes `utf8()` instead of lossy `ascii()`. `165f9ed4d01` `8a38069dceb` `0f3178a96a1` `df3a6b749ba` `f2ca04538ea` `22e1cc5592e` `1bb8f8abf2d` `2c5cd6d774d` `4b3653d2ed3` `4cd0b19673f` `4356bc5514b` `3fb615cd242` `ce9608ae41d` - New `wtf/posix/POSIXExtras.h` (`posixOpen`, `posixStat`, `posixFopen`, … taking `UTF8CStringView`) and `wtf/glib/GLibExtras.h` wrappers and `SAFE_G_*` macros. `a506af486d6` `6448e98fedb` `b46c2cfc57b` `bdea79f67f1` - `ReadWriteLock` reimplemented as a 16-byte phase-fair lock with `Locker { lock.read() }` / `Locker { lock.write() }`; `ParkingLot::unparkCount(address, count, callback)` added and `unparkOne` built on it. `5d43ab597d9` (325091) - `find8()` compares the first 16 bytes with SIMD before falling back to `memchr`. `046a5a8d15c` (325953) - `Deque::constructAndAppend()`. `c06ff4e9930` (325441) - `URL::string() &&` overload. `b31697dfe26` (325669) - `CheckedPtr` / `RefPtr` constructible from `std::unique_ptr`, `CheckedRef` / `Ref` from `UniqueRef`; `protect()` on those returns the matching smart pointer. `31571413598` (325911) - `GuaranteedSerialFunctionDispatcher::dispatchAfter()` with implementations in `RunLoop`, `WorkQueue`, `MainThreadDispatcher`. `155da279924` (324711) - `MonotonicObjectIdentifier` moved into WTF. `28001e7f661` - Several reused vectors switch from `clear()` to `shrink(0)`. `9679818e585` (325059) - Swift interop: reference-counting annotations on WTF ref-counted base classes behind `ENABLE(SWIFT_BASE_CLASS_ANNOTATIONS)`; annotation renames; unused `SwiftCXXThunk` macros removed. `5f4afbfb124` `46495d17ae3` `edbf6068f30` ### bmalloc / libpas - MTE allocations are served from a separate `tagged_bmalloc_heap`; the compact / non-compact distinction is removed from libpas internals and dispatch happens in `bmalloc.h`. `c8cb35beaca` (317893) - Compact heap reservation grows to 256 MiB with two allocation fronts and an over-aligned compact pointer type. `5b0cfbc518e` (325689) - bmalloc and libpas check `__SANITIZE_THREAD__`-style macros as well as `__has_feature`. `4558079bcd4` (326161) - `BCRASH()` static-analyzer annotation uses the checker's new name. `f4478d48f89` (325557) ### Other - Corpse tooling: `Corpse::Memory` for mapped views of remote corpse memory; unused export flag removed. `9cf419e5c4b` `ce61c78c8b8` - GLib API: `JSCException` and `JSCClass` use typed strings / `GMallocString`; `jsc_exception_report()` decodes UTF-8 correctly; `JSCCallbackFunction::construct()` sizes its argument span by `argumentCount`. `780fb0070b8` `a5815bc9797` `a7c1eda41a7` - Build fixes and gardening (one line): `720bc3a7c71` `5869341e6cc` `523f2e2ae26` `48ab96aa6b2` `7c9c2207d0c`, Xcode filelist check landed and reverted (`b77e70c813e` `5ce175f5a3c`), Safer C++ expectation updates (`8591160211b` `18e3f9366c7` `ceba48c3cdf` `ce1fa925b83`), CMake packaging for Cocoa (`c456b2841c0` `b98997507b7` `2ea49531186` `d14a3b7571a`). - 36 commits are WebCore/WebKit features whose only change in these directories is a preference entry in `UnifiedWebPreferences.yaml` or a platform macro (for example Document-Isolation-Policy, Device Posture, CSS `calc-size()`, `corner-*` shorthands, threaded animations); they do not change JSC or WTF behavior.
Upgrade to upstream WebKit dbdca75
Merges upstream WebKit
dbdca7545d(2026-10-05): 1020 commits since7b485a76e9(#725), 188 of them in Source/JavaScriptCore, Source/WTF or Source/bmalloc.Please land this as a merge commit, not a squash. #725 was squashed, so git's merge base with upstream stayed at
ccdcb8a026. This merge was computed against7b485a76e9and records upstream as a parent; a squash would lose that again.Three commits:
049e2899097removes the fork's for-of / array destructuring change (the first and third commits of [JSC] for-of / array destructuring without an Array Iterator object, and one RegExpObject per /x/.test(s) literal site #630). Upstream landed the same change as 321765@main and built the Baseline and LLInt inline paths, String iteration and a DFG fix on it. With the fork's copy gone the merge takes upstream's as it is. The RegExp literal part of [JSC] for-of / array destructuring without an Array Iterator object, and one RegExpObject per /x/.test(s) literal site #630 stays. This commit does not build by itself.661e26ef130is the merge. Its message lists every conflict; the same list is below.05fef3340d7brings back what the fork had tied toop_iterator_close_checkand that still applies: it is not counted inCodeBlock::bytecodeCost(), the bytecode optimizer leaves its operands alone, the two RELEASE_ASSERTs for a sentinel cell,cachedTypesFormatRevision13, and the test run lines.The merge
1020 upstream commits since 7b485a7 (the previous upgrade, #725), 188 of them
in Source/JavaScriptCore, Source/WTF or Source/bmalloc.
#725 landed as a squash, so git's merge base with upstream was still
ccdcb8a. This merge was computed against 7b485a7 (a temporary
git replace --graftgave 7465044 its upstream parent). It recordsupstream/main as a parent, so the next upgrade finds its base by itself as long
as this lands as a merge commit and not as a squash.
Conflicts, and what was done about them:
Heap / Collector (c2fa192 and the eight commits after it move the
collection cycle out of Heap into a new Collector class):
The auxiliary block evacuation, setInitialAllocationBudget(),
releaseUnusedSharedBaselineCode() (now called from pruneDeadReferences()),
the decoder string table hooks, the allocation counters and the aging stamps
stay in Heap. The stamps that runBeginPhase() takes moved with it to
Collector::runBeginPhase(). Heap::isIdleCollection() is out of line, since the
current request is the Collector's.
new Heap::recordCollectionTime() too.
(a516249); Bun sets it (JSC__VM__collectAsyncIdle). Collector::runEndPhase()
runs it where Heap::runEndPhase() did.
Source positions (93ebfac, c59d70e):
lineColumnInTextForOffset(). That function now goes through upstream's
LineStartTable::zeroBasedLineColumnForOffset(), which builds the table with
withSourceConcurrently() and is safe off the main thread.
code block's lock) and the fork's line/column map. decodeEntryForInstPC() is
public, for the caller of expressionInfoIfDecoded() that can neither lock nor
allocate.
dropped from SourceCharacters.h.
ErrorInstance (696c406, lazy Error.captureStackTrace): upstream's captured
stack trace next to the fork's onComputeErrorInfo hooks. m_hasErrorInfo replaces
the empty-string placeholder, and setStackFrames() clears it with the string.
m_stackString is written under the cell lock in the new paths as well, because
the fork reads it from estimatedSize() during marking.
Microtasks (53d4af9): runInternalMicrotask() takes its arguments by value.
With USE(BUN_JSC_ADDITIONS) there are four of them (maxMicrotaskArguments is 4),
and the four-argument JSGlobalObject::queueMicrotask() gets the same fast path.
JSON (f62059d and the JSONCache commits): JSONAtomStringCache is gone. The
fork's out-of-memory handling for long strings is now
JSONCache::tryMakeJSString() / tryMakeLongJSString(), and the new inline string
path of the parser checks for null. JSONCacheInlines.h is a private header (Bun
includes it).
JSBigInt (b071cfa, 13a1f29): the fork's division (Burnikel-Ziegler with
interrupt checks, Barrett) is kept as it is. Upstream's Burnikel-Ziegler, which
has lower thresholds and does not allocate at the leaves, is not taken; its three
helpers that nothing else used are left out.
WTF / libpas:
(uv_get_constrained_memory) and the FreeBSD branch. The statm parsing fix is
carried to MemoryFootprintGeneric.cpp, where LinuxMemory moved.
commits on demand for the top front too, and initializes both committed marks.
Fork code adjusted to upstream API changes: typed C strings in ffi/ (UTF8CString),
ASCIILiteral messages for DFG_CRASH, Collector::suspendCompilerThreads(),
JSModuleLoader::drainSynchronousModuleQueue().
Not taken, for a follow-up
b071cfab287,13a1f291693) has lower thresholds than the fork's and does not allocate at the leaves. The fork keeps its own division, which also has the interrupt checks and Barrett.Options::useUnboxedFastArrayIterationis gone with the fork's iterator change. Upstream has no option for it.Verification
jscand Bun build against this tree (debug + ASAN, Linux x64, clang 23.1.2). No other platform was built here.jsc: all pass. 55 are skipped by their own directives. Eight needed their own options, a larger stack or more time than my ad-hoc runner gave them, and pass when run that way. The full JSC test run of CI has not been run.