Skip to content

Upgrade to upstream WebKit 01aaa3e0be0c - #352

Merged
Jarred-Sumner merged 544 commits into
mainfrom
bun/upgrade-to-01aaa3e0be0c
Jul 28, 2026
Merged

Jarred-Sumner merged 544 commits into
mainfrom
bun/upgrade-to-01aaa3e0be0c

Conversation

@robobun

@robobun robobun commented Jul 26, 2026

Copy link
Copy Markdown
Collaborator

Merges WebKit/WebKit@01aaa3e0be0c (2026-07-25) into the fork. 538 upstream commits since the previous sync point (2603e9eb41f0); 117 touch Source/JavaScriptCore, Source/WTF or Source/bmalloc.

Conflict resolution

Nine files conflicted. Seven were include-block noise from the squash-sync ancestor (the conflict region carried the pre-<JavaScriptCore/...> include style and stale upstream content): SpeculatedType.h, IncrementalSweeper.h, VM.h, JSModuleRecord.h, WasmIPIntSlowPaths.cpp, UnifiedWebPreferences.yaml, NodesCodegen.cpp. Resolved by taking upstream for the conflict region only, preserving all auto-merged USE(BUN_JSC_ADDITIONS) blocks elsewhere in the file. emit_intrinsic_getInternalField in NodesCodegen.cpp is a real fork addition (Bun's @getInternalField bytecode intrinsic) and was kept; the adjacent asyncFromSyncIteratorInternalFieldIndex helper was stale upstream code and dropped.

JSONAtomStringCacheInlines.h keeps the fork's fallible tryCreateUninitialized path (#317) rather than upstream's create8BitIfPossible, so JSON.parse of an unallocatable string still throws instead of crashing.

JSMicrotask.cpp: upstream introduced settleDriverWithIteratorResult (cached iterator-result object for cooperative drivers, bug 319817) and rewrote the AsyncFromSyncIterator continuation path (bug 319435). Adapted the fork's AsyncContextSwapScope wrapping:

  • settleDriverWithIteratorResult now takes JSGlobalObject* and wraps target with the current async context internally; the unwrapped target is still used for the cached-result identity check so the reuse optimisation is kept.
  • asyncGeneratorCompleteStep / enqueueAsyncGeneratorDriver call the helper instead of inlining the resolve path.
  • InternalMicrotask::AsyncFromSyncIterator{Continue,Done} unwrap the tuple (resolveWithInternalMicrotaskForAsyncAwait wraps the iterator on the scheduling side) before the new JSAsyncFromSyncIterator* cast.
  • InternalMicrotask::AsyncModuleExecutionResume ported to the new no-scope asyncModuleExecutionResume signature.

Follow-up fixes for upstream API changes

  • AbstractModuleRecord::setImportedModule drops the m_dependencies write; m_loadedModules is the only lookup map now (bug 320144).
  • NodesCodegen.cpp restores emit_intrinsic_getInternalField after the conflict-region resolution.

Bun-side changes required by this merge live in the companion oven-sh/bun PR.

twilco and others added 30 commits July 21, 2026 22:18
…essibility relations

https://bugs.webkit.org/show_bug.cgi?id=319937
rdar://182309307

Reviewed by Dominic Mazzoni and Chris Fleizach.

When accessibility relations are rebuilt, updateRelationsIfNeeded() iterates
m_elementsWithRelationAttributes, which can hold detached elements. For an origin
that is not in a tree scope, Element::elementsArrayForAttributeInternal() cannot
use the TreeScope id map and falls back to getElementByIdIncludingDisconnected(),
which linearly scans the entire detached subtree once per referenced id. On pages
with large detached subtrees that carry ARIA relation attributes, this can severely
harm performance.

Fix this by skipping resolution of  relations for origins that are not in a tree scope.
Such elements have no accessibility object, so their relations have no consumer.

Additionally, this commit reduces how often relations are rebuilt. performDeferredCacheUpdate()
used to mark all relations dirty on every id-attribute change, forcing a full rebuild, regardless
of whether that id was part of a relation. Now we track every id referenced by a relation attribute
(resolved or not) in a new m_referencedRelationTargetIds set and only dirty relations when a changed
id can actually affect one.

* LayoutTests/accessibility/aria-relations-disconnected-subtree-no-timeout-expected.txt: Added.
* LayoutTests/accessibility/aria-relations-disconnected-subtree-no-timeout.html: Added.
* Source/WebCore/accessibility/AXObjectCache.cpp:
(WebCore::AXObjectCache::performDeferredCacheUpdate):
(WebCore::AXObjectCache::updateRelationsIfNeeded):
(WebCore::AXObjectCache::idChangeCanAffectRelations const):
(WebCore::AXObjectCache::addRelation):
(WebCore::AXObjectCache::addLabelForRelation):
* Source/WebCore/accessibility/AXObjectCache.h:

Canonical link: https://commits.webkit.org/317690@main
https://bugs.webkit.org/show_bug.cgi?id=319944
rdar://182860876

Reviewed by Alex Christensen.

The imported WPT idlharness harness (webidl2.js@e6d8ab8) requires the
single-token "async_iterable" WebIDL syntax and emits a validation error
for the older two-token "async iterable" syntax. The imported dependency
IDL files streams.idl and fs.idl still used the old syntax, so every
idl_test that pulls in streams.idl recorded a spurious
"FAIL idl_test validation" line, affecting idlharness expected files
across compression, encoding, fs, streams, webrtc-encoded-transform, and
webtransport.

Update both imported IDL files to the async_iterable syntax and rebaseline
the affected idlharness expected files. The new IDL matches upstream
web-platform-tests, taken from commit
14c7ae5dd9a2c7f726ed51f968dc2340cb4fbe74 (2025-08-20, "Sync interfaces/
with @webref/idl 3.66.2", WebKit#54029), which updated both interfaces/streams.idl
and interfaces/fs.idl to async_iterable.

Covered by existing tests (the rebaselined idlharness tests).

* LayoutTests/imported/w3c/web-platform-tests/compression/idlharness.https.any-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/compression/idlharness.https.any.worker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.serviceworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.sharedworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.worker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/fs/idlharness.https.any-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/fs/idlharness.https.any.worker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/interfaces/fs.idl:
* LayoutTests/imported/w3c/web-platform-tests/interfaces/streams.idl:
* LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.serviceworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.sharedworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.worker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/webrtc-encoded-transform/idlharness.https.window-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.serviceworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.sharedworker-expected.txt:
* LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.worker-expected.txt:

Canonical link: https://commits.webkit.org/317691@main
…-space-trim-inline-block.html is failing since added in 317172@main

https://bugs.webkit.org/show_bug.cgi?id=319954

Unreviewed test gardening.

* LayoutTests/platform/glib/TestExpectations:

Canonical link: https://commits.webkit.org/317692@main
… after showing the keyboard in iPhone Mirroring

https://bugs.webkit.org/show_bug.cgi?id=319948
rdar://181639089

Reviewed by Abrar Rahman Protyasha.

Revert the changes in 314741@main for now; this caused the keyboard on iOS to dismiss immediately
after focusing a text field in iPhone Mirroring mode, from macOS.

* LayoutTests/editing/selection/ios/select-text-by-long-press-with-focused-element-expected.txt: Removed.
* LayoutTests/editing/selection/ios/select-text-by-long-press-with-focused-element.html: Removed.
* LayoutTests/editing/selection/ios/select-text-by-long-press-with-hardware-keyboard-expected.txt: Removed.
* LayoutTests/editing/selection/ios/select-text-by-long-press-with-hardware-keyboard.html: Removed.
* LayoutTests/editing/selection/ios/tap-focused-input-clears-outside-selection-expected.txt: Removed.
* LayoutTests/editing/selection/ios/tap-focused-input-clears-outside-selection.html: Removed.
* Source/WebKit/UIProcess/ios/WKContentViewInteraction.h:
* Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm:
(-[WKContentView cleanUpInteraction]):
(-[WKContentView textInteractionGesture:shouldBeginAtPoint:]):
(-[WKContentView selectPositionAtPoint:completionHandler:]):
(-[WKContentView _selectPositionAtPoint:stayingWithinFocusedElement:completionHandler:]):
(-[WKContentView _hideKeyboard:]):
(-[WKContentView _elementDidBlur]):
(-[WKContentView _updateSelectionAssistantSuppressionState]):

Canonical link: https://commits.webkit.org/317693@main
…ail surrogate, not after

https://bugs.webkit.org/show_bug.cgi?id=319932

Reviewed by Yusuke Suzuki.

reread() returns errorCodePoint for a trail surrogate whose *following* code
unit is a lead. The error case is a read landing in the middle of a pair, so it
must look at the preceding unit; readCheckedDontAdvance() already does this.

tryConsumeBackReference() rereads the captured text, and errorCodePoint there
fails the backreference unconditionally. Patterns with a lookbehind always run
in the interpreter, so this reproduces with default options:

    var unit = "\uDC00\uD800a";
    /(?<=^)(...)\1/u.test(unit + unit);  // false, should be true

Also move the from + 1 < length check into the lead branch, so that a trail
surrogate at the end of the input is still checked.

Introduced in 280563@main.

Test: JSTests/stress/regexp-backreference-lone-trail-then-lone-lead.js

* JSTests/stress/regexp-backreference-lone-trail-then-lone-lead.js: Added.
(shouldBe):
* Source/JavaScriptCore/yarr/YarrInterpreter.cpp:
(JSC::Yarr::Interpreter::InputStream::reread):

Canonical link: https://commits.webkit.org/317694@main
…selection has a decoration.

https://bugs.webkit.org/show_bug.cgi?id=319947
rdar://182864748

Reviewed by Wenson Hsieh.

hasDecoration in paintForegroundAndDecorations only accounted for the originating element, custom highlights,
and spelling/grammar — not ::selection. So when text had no decoration of its own and only ::selection did,
the decoration-paint path was skipped and the selection's decoration never painted. Add a hasSelectionDecoration
check so the path runs, making selection-text-decoration-currentcolor.html and target-text-005.html pass.

imported/w3c/web-platform-tests/css/css-pseudo/selection-text-decoration-currentcolor.html
imported/w3c/web-platform-tests/css/css-pseudo/target-text-005.html

* LayoutTests/TestExpectations:
* LayoutTests/platform/ios/TestExpectations:
* Source/WebCore/rendering/TextBoxPainter.cpp:
(WebCore::TextBoxPainter::paintForegroundAndDecorations):

Canonical link: https://commits.webkit.org/317695@main
rdar://182509958
https://bugs.webkit.org/show_bug.cgi?id=319666

Reviewed by Andy Estes and Jean-Yves Avenard.

We update the project to include asm and .S files.
We exclude them for non arm64/arm64e builds.
We update Source/WebCore/PAL/ThirdParty/dav1d/config.h to enable ASM for arm64.
We add Source/WebCore/PAL/ThirdParty/dav1d/config folder from upstream repo as it is useful to update Source/WebCore/PAL/ThirdParty/dav1d/config.h.

Covered by existing tests.

* Source/WebCore/PAL/ThirdParty/dav1d/Configurations/dav1d.xcconfig:
* Source/WebCore/PAL/ThirdParty/dav1d/config.h:
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/arm/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/arm64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x64/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x86/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x86/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux-noasm/generic/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux-noasm/x64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/arm/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/arm64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/riscv64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/riscv64/cpu-renamed.c: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x64/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x86/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x86/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/win/arm64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/win/x64/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/win/x64/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/win/x86/config.asm: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/config/win/x86/config.h: Added.
* Source/WebCore/PAL/ThirdParty/dav1d/dav1d.xcodeproj/project.pbxproj:

Canonical link: https://commits.webkit.org/317696@main
…OMAgent

https://bugs.webkit.org/show_bug.cgi?id=X
rdar://179248483

Reviewed by Qianlang Chen.

Under Site Isolation a cross-origin iframe's DOM lives in a separate
WebProcess with its own FrameDOMAgent. The DOM.shadowRootPushed and
shadowRootPopped events are fired through InstrumentingAgents, which only
notified the page-level agent, so attaching a shadow root inside a cross-
origin iframe reached no agent for that frame -- and even when it did, the
frontend dropped it for a FrameTarget. The shadow root never appeared in the
Elements tree.

didPushShadowRootImpl and willPopShadowRootImpl now resolve the host's frame
and notify that frame's persistentFrameDOMAgent before falling through to the
page agent, matching the branch already used by the sibling per-node hooks
(didModifyDOMAttr, didInsertDOMNode). The main frame has no
persistentFrameDOMAgent and the page agent's boundNodeId() guard suppresses
subframe hosts, so there is no double-fire. DOM.json widens both events'
targetTypes from ["page"] to ["frame","page"] so the generated dispatcher
accepts them from a FrameTarget; FrameDOMAgent already implemented
didPushShadowRoot/willPopShadowRoot.

On the frontend, DOMObserver replaces the two FrameTarget FIXME early-returns
with _frameTargetShadowRootPushed/_frameTargetShadowRootPopped, modeled on
_frameTargetChildNodeInserted/Removed. They scope the shadow-root WI.DOMNode
to the owning frame target (target.identifier + ":" + nodeId) so colliding
raw NodeIds across frames stay distinct.

shadowRootPopped is wired but has no end-to-end test: author shadow roots have
no scriptable detach, so willPopShadowRoot only fires on host destruction, and
removing the host first unbinds the root (FrameDOMAgent::unbind), leaving
boundNodeId 0 so the backend suppresses the event.

Tests: http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target.html
       http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target.html

* LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-child-frame.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-frame.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-grandchild-frame.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target-expected.txt: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target-expected.txt: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target.html: Added.
* Source/JavaScriptCore/inspector/protocol/DOM.json:
* Source/WebCore/inspector/InspectorInstrumentation.cpp:
(WebCore::InspectorInstrumentation::didPushShadowRootImpl):
(WebCore::InspectorInstrumentation::willPopShadowRootImpl):
* Source/WebInspectorUI/UserInterface/Controllers/DOMManager.js:
(WI.DOMManager.prototype._frameTargetShadowRootPushed):
(WI.DOMManager.prototype._frameTargetShadowRootPopped):
* Source/WebInspectorUI/UserInterface/Protocol/DOMObserver.js:
(WI.DOMObserver.prototype.shadowRootPushed):
(WI.DOMObserver.prototype.shadowRootPopped):

Canonical link: https://commits.webkit.org/317697@main
https://bugs.webkit.org/show_bug.cgi?id=315597
rdar://177978474

Reviewed by Qianlang Chen.

Replace WI.DOMUndoCoordinator's single _lastEditTarget slot with a pair
of LIFO target stacks that record one entry per edit, in order. Each
edit's target — the main page or a cross-origin iframe — is pushed when
didEdit is called. undo pops the top, dispatches to that target's
DOMAgent, and pushes to the redo stack on completion; redo is the
symmetric inverse. Empty-stack undo and redo fall back to the main
target as a no-op without pushing onto either stack. TargetRemoved
filters both stacks so a torn-down frame can't be popped later.

End-user effect: edit a node in a cross-origin iframe, edit a node on
the main page, press Cmd+Z — the main edit reverses; press Cmd+Z again,
the iframe edit reverses.

The existing single-target dispatch test is updated to await the now-
async undo/redo entry points.

Test: http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator.html

* LayoutTests/http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator-expected.txt: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/undo-coordinator-frame-target-expected.txt:
* LayoutTests/http/tests/site-isolation/inspector/dom/undo-coordinator-frame-target.html:
* Source/WebInspectorUI/UserInterface/Controllers/DOMUndoCoordinator.js:
(WI.DOMUndoCoordinator):
(WI.DOMUndoCoordinator.prototype.didEdit):
(WI.DOMUndoCoordinator.prototype.markUndoableState):
(WI.DOMUndoCoordinator.prototype.undo):
(WI.DOMUndoCoordinator.prototype.redo):
(WI.DOMUndoCoordinator.prototype._performOperationSoon):
(WI.DOMUndoCoordinator.prototype.async _undo):
(WI.DOMUndoCoordinator.prototype.async _redo):
(WI.DOMUndoCoordinator.prototype._handleTargetRemoved):

Canonical link: https://commits.webkit.org/317698@main
…o-element events to Frame Targets

https://bugs.webkit.org/show_bug.cgi?id=NNNNNN
rdar://179176056

Reviewed by Qianlang Chen.

Web Inspector's Elements tree for an out-of-process iframe went
stale on these lifecycle changes:

- DOM.customElementStateChanged
- DOM.pseudoElementAdded
- DOM.pseudoElementRemoved

They were stubbed off at every layer for the frame target: the protocol declared
them "page"-only, InspectorInstrumentation routed them only to the page-level
persistentDOMAgent(), and the frontend DOMObserver early-returned with a FIXME
for FrameTarget. FrameDOMAgent already had complete, correct implementations of
all three methods, so this is a pure wiring change, not a new feature.

This adds the missing routing following the existing convention used by
didInsertDOMNode / didModifyDOMAttr (notify the frame's own FrameDOMAgent, then
the page agent), declares the events for the frame target, and adds the
scoped-id frontend handlers so the iframe's Elements tree stays live.

The added layout test deliberately covers multiple, repeated, and interleaved
scenarios rather than a single event per type, since these handlers manage
per-node and per-pseudo-type state: two custom elements upgraded back-to-back
(no cross-contamination), ::before and ::after coexisting, targeted single-pseudo
removal leaving the sibling intact, and an add/remove/re-add cycle guarding
against stale-node leaks. It also documents that one upgrade legitimately emits
two transitions (FailedOrPrecustomized then Custom), which the frame target
relays just like the page target.

Test: http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target.html

* LayoutTests/http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target-expected.txt: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target.html: Added.
* LayoutTests/http/tests/site-isolation/inspector/dom/resources/custom-elements-and-pseudo-elements-frame.html: Added.
* Source/JavaScriptCore/inspector/protocol/DOM.json:
* Source/WebCore/inspector/InspectorInstrumentation.cpp:
(WebCore::InspectorInstrumentation::didChangeCustomElementStateImpl):
(WebCore::InspectorInstrumentation::pseudoElementCreatedImpl):
(WebCore::InspectorInstrumentation::pseudoElementDestroyedImpl):
* Source/WebInspectorUI/UserInterface/Controllers/DOMManager.js:
(WI.DOMManager.prototype._frameTargetCustomElementStateChanged):
(WI.DOMManager.prototype._frameTargetPseudoElementAdded):
(WI.DOMManager.prototype._frameTargetPseudoElementRemoved):
* Source/WebInspectorUI/UserInterface/Protocol/DOMObserver.js:
(WI.DOMObserver.prototype.customElementStateChanged):
(WI.DOMObserver.prototype.pseudoElementAdded):
(WI.DOMObserver.prototype.pseudoElementRemoved):

Canonical link: https://commits.webkit.org/317699@main
…toBuffer()`

https://bugs.webkit.org/show_bug.cgi?id=319673

Reviewed by Sosuke Suzuki.

This change is related to only the fast path of `Array#flat()`.
`resultIndex` is 8-bytes (`uint64_t`). It's enough small size.

Interestingly, this change has a side-effect which is a micro benchmark
progression on macOS arm64 at least.

                                             TipOfTree                  Patched

array-prototype-flat-depth-1-string      124.7313+-15.7674    ?    126.7053+-14.0930       ? might be 1.0158x slower
array-prototype-flat-depth-1-double       85.8047+-8.6982     ?     88.9680+-4.1780        ? might be 1.0369x slower
array-prototype-flat-large-nested         45.0930+-2.4765     ^     27.1562+-1.0824        ^ definitely 1.6605x faster
array-prototype-flat-huge-arrays          10.5353+-1.8040           10.0453+-1.7224          might be 1.0488x faster
array-prototype-flat-small-arrays          3.4522+-0.1238            3.3026+-0.0755          might be 1.0453x faster
array-prototype-flat-depth-infinity      117.2919+-1.0095          117.0930+-0.6006
array-prototype-flat-depth-2              94.7117+-1.3260     ?     95.6852+-4.3372        ? might be 1.0103x slower
array-prototype-flat-depth-1-int32        85.2135+-4.3134     ?     88.4635+-2.5566        ? might be 1.0381x slower
array-prototype-flat-depth-3             105.7020+-7.5027          102.3541+-4.5175          might be 1.0327x faster
array-prototype-flat-sparse-array        152.1396+-3.2477     ?    161.3152+-11.0580       ? might be 1.0603x slower
array-prototype-flat-depth-1-mixed        93.9877+-4.2939     ?     94.3616+-4.7335        ?

<geometric>                               57.9736+-0.6088     ^     55.5547+-0.9141        ^ definitely 1.0435x faster

No new tests.
It wlll be covered by exist test cases.

Canonical link: https://commits.webkit.org/317700@main
… ENABLE_INSPECTOR_NETWORK_THROTTLING is enabled

https://bugs.webkit.org/show_bug.cgi?id=319487

Reviewed by Devin Rousso.

Move the owned std::optional<int64_t> when forwarding it to
WebInspectorUIProxy::setEmulatedConditions().

WebInspectorBackendProxy owns the std::optional by value but forwards it
to a function taking std::optional<int64_t>&&, causing compilation to
fail when ENABLE_INSPECTOR_NETWORK_THROTTLING is enabled.

Forward the optional using WTF::move().

* Source/WebKit/UIProcess/Inspector/WebInspectorBackendProxy.cpp:
(WebKit::WebInspectorBackendProxy::setEmulatedConditions):

Canonical link: https://commits.webkit.org/317701@main
…omed lengths

https://bugs.webkit.org/show_bug.cgi?id=319905

Reviewed by Antoine Quint.

Converts the view-timeline-inset CSS property to use unzoomed lengths.

New test added showing view-timeline-inset working properly with inherited + zoomed values.

Tests: imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset.html
* LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/reference/view-timeline-inset-ref.html: Added.
* LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset-expected.html: Added.
* LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset.html: Added.
* Source/WebCore/Headers.cmake:
* Source/WebCore/WebCore.xcodeproj/project.pbxproj:
* Source/WebCore/animation/CSSAnimation.cpp:
* Source/WebCore/animation/ResolvableViewTimelineInsets.h: Added.
* Source/WebCore/animation/StyleOriginatedTimelinesController.cpp:
* Source/WebCore/animation/StyleOriginatedTimelinesController.h:
* Source/WebCore/animation/ViewTimeline.cpp:
* Source/WebCore/animation/ViewTimeline.h:
* Source/WebCore/style/Styleable.cpp:
* Source/WebCore/style/values/scroll-animations/StyleViewTimelineInsetItem.h:

Canonical link: https://commits.webkit.org/317702@main
https://bugs.webkit.org/show_bug.cgi?id=319949

Unreviewed test gardening.

This test was marked as expected to crash in glib/TestExpectations in
317682@main but there was an override of in wpe/TestExpectations.

Temporarily comment out the override.

* LayoutTests/platform/wpe/TestExpectations:

Canonical link: https://commits.webkit.org/317704@main
…networkConnectionToWebProcess

rdar://182761259
https://bugs.webkit.org/show_bug.cgi?id=319968

Reviewed by Chris Dumez.

WebSWServerConnection sometimes calls networkProcess() asynchronously following an IPC message, for instance in WebSWServerConnection::postMessageToServiceWorkerClient.
In that case, there is no guarantee that m_networkConnectionToWebProcess is not nullptr and calling WebSWServerConnection::networkProcess should return nullptr.

We change WebSWServerConnection::networkProcess to account for this and return a NetworkProcess pointer instead of a ref.
At call sites, we check for networkProcess being nullptr for async cases.

Covered by existing tests.

* Source/WebKit/NetworkProcess/ServiceWorker/WebSWServerConnection.cpp:
(WebKit::WebSWServerConnection::networkProcess):
(WebKit::WebSWServerConnection::sharedPreferencesForWebProcess const):
(WebKit::WebSWServerConnection::resolveUnregistrationJobInClient):
* Source/WebKit/NetworkProcess/ServiceWorker/WebSWServerConnection.h:

Canonical link: https://commits.webkit.org/317705@main
https://bugs.webkit.org/show_bug.cgi?id=312461

Reviewed by Carlos Garcia Campos.

This change unifies the default font rendering settings between GTK
and WPE.

To be more precise, it changes the WPE's default value for
subpixel layout from RGB to NONE so that it matches the default from
FontRenderOptions that is used by GTK normally.

Canonical link: https://commits.webkit.org/317706@main
rdar://182400674
https://bugs.webkit.org/show_bug.cgi?id=319570

Reviewed by Chris Dumez.

WebTransport is subclassing WritableStreamDefaultWriter in WebTransportWriter.
To prepare for implementing WebTransportWriter, we make WritableStreamDefaultWriter a standard C++ class instead of a JS built-in.
We beef up InternalWritableStreamWriter to support more bindings API and we forward WritableStreamDefaultWriter calls to InternalWritableStreamWriter.

Covered by existing tests.

* Source/WebCore/CMakeLists.txt:
* Source/WebCore/DerivedSources-input.xcfilelist:
* Source/WebCore/DerivedSources-output.xcfilelist:
* Source/WebCore/DerivedSources.make:
* Source/WebCore/Modules/streams/WritableStream.cpp:
(WebCore::WritableStream::getWriter):
(WebCore::JSWritableStream::getWriter): Deleted.
* Source/WebCore/Modules/streams/WritableStream.h:
* Source/WebCore/Modules/streams/WritableStream.idl:
* Source/WebCore/Modules/streams/WritableStreamDefaultWriter.cpp: Added.
(WebCore::WritableStreamDefaultWriter::create):
(WebCore::WritableStreamDefaultWriter::WritableStreamDefaultWriter):
(WebCore::WritableStreamDefaultWriter::desiredSize):
(WebCore::WritableStreamDefaultWriter::releaseLock):
(WebCore::JSWritableStreamDefaultWriter::closed const):
(WebCore::JSWritableStreamDefaultWriter::ready const):
(WebCore::JSWritableStreamDefaultWriter::abort):
(WebCore::JSWritableStreamDefaultWriter::close):
(WebCore::JSWritableStreamDefaultWriter::write):
* Source/WebCore/Modules/streams/WritableStreamDefaultWriter.h: Added.
(WebCore::WritableStreamDefaultWriter::internalWriter):
* Source/WebCore/Modules/streams/WritableStreamDefaultWriter.idl:
* Source/WebCore/Modules/streams/WritableStreamDefaultWriter.js: Removed.
* Source/WebCore/Modules/streams/WritableStreamInternals.js:
(acquireWritableStreamDefaultWriter):
(writableStreamDefaultWriterClosedForBindings):
(writableStreamDefaultWriterReadyForBindings):
(writableStreamDefaultWriterDesiredSizeForBindings):
(writableStreamDefaultWriterAbortForBindings):
(writableStreamDefaultWriterCloseForBindings):
(writableStreamDefaultWriterReleaseLockForBindings):
(writableStreamDefaultWriterWriteForBindings):
* Source/WebCore/Sources.txt:
* Source/WebCore/WebCore.xcodeproj/project.pbxproj:
* Source/WebCore/bindings/js/InternalWritableStreamWriter.cpp:
(WebCore::InternalWritableStreamWriter::closedForBindings):
(WebCore::InternalWritableStreamWriter::desiredSizeForBindings):
(WebCore::InternalWritableStreamWriter::readyForBindings):
(WebCore::InternalWritableStreamWriter::abortForBindings):
(WebCore::InternalWritableStreamWriter::closeForBindings):
(WebCore::InternalWritableStreamWriter::releaseLockForBindings):
(WebCore::InternalWritableStreamWriter::writeForBindings):
* Source/WebCore/bindings/js/InternalWritableStreamWriter.h:

Canonical link: https://commits.webkit.org/317707@main
https://bugs.webkit.org/show_bug.cgi?id=319959

Reviewed by Alan Baradlay.

The failures seem related to 317593@main.

* Source/WebCore/SaferCPPExpectations/NoUncheckedPtrMemberCheckerExpectations:
* Source/WebCore/SaferCPPExpectations/UncheckedCallArgsCheckerExpectations:
* Source/WebCore/SaferCPPExpectations/UncheckedLocalVarsCheckerExpectations:
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp:
(WebCore::FlexFormattingContext::layout):
(WebCore::FlexFormattingContext::layoutFlexItems):
(WebCore::FlexFormattingContext::handleCrossAxisAlignmentForFlexLines):
(WebCore::FlexFormattingContext::performBaselineAlignment):
(WebCore::FlexFormattingContext::computeFlexItemRects):
(WebCore::FlexFormattingContext::placeFlexItems):
(WebCore::FlexFormattingContext::reverseColumnLinesFromContainerMainEndIfNeeded):
(WebCore::FlexFormattingContext::layoutColumnReverse):
(WebCore::ScopedFlexBasisAsFlexItemMainSize::ScopedFlexBasisAsFlexItemMainSize):
(WebCore::ScopedFlexBasisAsFlexItemMainSize::~ScopedFlexBasisAsFlexItemMainSize):
(WebCore::FlexFormattingContext::flexBaseSizeForFlexItem):
(WebCore::FlexFormattingContext::flexBaseSizeNeedsBlockAxisContentSize):
(WebCore::FlexFormattingContext::ensureBlockAxisContentSizeForFlexItemIfNeeded):
(WebCore::FlexFormattingContext::computeContentBasedMinMainSize):
(WebCore::FlexFormattingContext::computeMainAxisExtentForFlexItem):
(WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing const):
(WebCore::FlexFormattingContext::flexItemIntrinsicLogicalHeight const):
(WebCore::FlexFormattingContext::flexItemCrossSizeIsDefinite):
(WebCore::FlexFormattingContext::trimMainAxisMarginStart):
(WebCore::FlexFormattingContext::trimMainAxisMarginEnd):
(WebCore::FlexFormattingContext::trimCrossAxisMarginStart):
(WebCore::FlexFormattingContext::trimCrossAxisMarginEnd):
(WebCore::FlexFormattingContext::canFitItemWithTrimmedMarginEnd const):
(WebCore::FlexFormattingContext::removeMarginEndFromFlexSizes const):
(WebCore::FlexFormattingContext::applyStretchAlignmentToFlexItem):
(WebCore::FlexFormattingContext::applyStretchMinMaxCrossSize):
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h:
* Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.cpp:
(WebCore::LayoutIntegration::FlexLayout::collectFlexItems):
(WebCore::LayoutIntegration::FlexLayout::flexItemForFirstBaseline const):
(WebCore::LayoutIntegration::FlexLayout::flexItemForLastBaseline const):
(WebCore::LayoutIntegration::FlexLayout::baselineFlexItemInLine const):
* Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.h:
* Source/WebCore/rendering/RenderFlexibleBox.cpp:
* Source/WebCore/rendering/RenderFlexibleBox.h:

Canonical link: https://commits.webkit.org/317708@main
…after the WebContent process exits

https://bugs.webkit.org/show_bug.cgi?id=319952

Reviewed by Per Arne Vollan.

When log forwarding is enabled, each WebContent process gets a LogStream in the UI process
(WebProcessProxy::createLogStream), backed by a StreamServerConnection over its own IPC::Connection.

LogStream::stopListeningForIPC() only called StreamServerConnection::stopReceivingMessages(),
which unregisters the message receiver but never invalidates the underlying IPC::Connection. An
open connection keeps itself alive through its Mach-receive dispatch source (which holds a Ref
back to the connection) and holds its Mach port / kqueue workloop until it is explicitly
invalidated. So tearing down the WebProcessProxy released its reference to the LogStream but did
not release the connection: StreamServerConnection::m_receivers and the connection's own receive
source kept the LogStream / StreamServerConnection / IPC::Connection alive as a self-sustaining
island with a dead peer.

One such connection leaked per WebContent process. Over a long session these accumulate in the UI
process until it is killed for Mach port exhaustion (32768) or kqueue workloop exhaustion (2048),
whichever limit is reached first.

Fix LogStream::stopListeningForIPC() to also invalidate() the connection: stopReceivingMessages()
clears the receiver map (breaking the m_receivers <-> m_connection retain cycle so the objects can
be freed) and invalidate() cancels the receive source and releases the Mach port / kqueue workloop.

Also tear the log stream down from WebProcessProxy::shutDown() (via a new stopLogStream() helper,
shared with platformDestroy()) so the connection is released as soon as the process shuts down,
rather than waiting for the proxy object to be destroyed.

* Source/WebKit/Shared/LogStream.mm:
(WebKit::LogStream::stopListeningForIPC):
* Source/WebKit/UIProcess/Cocoa/WebProcessProxyCocoa.mm:
(WebKit::WebProcessProxy::platformDestroy):
(WebKit::WebProcessProxy::stopLogStream):
* Source/WebKit/UIProcess/WebProcessProxy.cpp:
(WebKit::WebProcessProxy::shutDown):
* Source/WebKit/UIProcess/WebProcessProxy.h:

Canonical link: https://commits.webkit.org/317709@main
https://bugs.webkit.org/show_bug.cgi?id=319933
rdar://182856553

Reviewed by Chris Dumez.

This improves readability and enforces more idiomatic C++ by resorting to
equivalent binary boolean operations.

* Source/WebCore/css/parser/CSSPropertyParserConsumer+Transform.cpp:
(WebCore::CSSPropertyParserHelpers::consumeRotate):
* Source/WebCore/css/typedom/CSSNumericValue.cpp:
(WebCore::operationOnValuesOfSameUnit):
* Source/WebCore/dom/Document.cpp:
(WebCore::Document::hasTouchEventHandlers const):
* Source/WebCore/dom/Node.cpp:
(WebCore::Node::canStartSelection const):
* Source/WebCore/dom/ScriptExecutionContext.cpp:
(WebCore::ScriptExecutionContext::allowsMediaDevices const):
* Source/WebCore/rendering/LogicalSelectionOffsetCachesInlines.h:
(WebCore::LogicalSelectionOffsetCaches::ContainingBlockInfo::setBlock):
* Source/WebCore/rendering/RenderBlockFlow.cpp:
(WebCore::RenderBlockFlow::MarginInfo::MarginInfo):
(WebCore::RenderBlockFlow::styleWillChange):
(WebCore::RenderBlockFlow::hasContentfulInlineOrBlockLine const):
(WebCore::RenderBlockFlow::hasContentfulInlineLine const):
* Source/WebCore/rendering/RenderBoxModelObject.cpp:
(WebCore::RenderBoxModelObject::adjustedPositionRelativeToOffsetParent const):
* Source/WebCore/rendering/RenderLayer.cpp:
(WebCore::RenderLayer::referenceBoxRectForClipPath const):
(WebCore::RenderLayer::calculateClipRects const):
* Source/WebCore/rendering/RenderLayerCompositor.cpp:
(WebCore::RenderLayerCompositor::updateCompositingLayers):
* Source/WebCore/rendering/RenderLayoutState.cpp:
(WebCore::RenderLayoutState::computeOffsets):
* Source/WebCore/rendering/RenderObject.cpp:
(WebCore::RenderObject::canUpdateSelectionOnRootLineBoxes):
* Source/WebCore/rendering/RenderTreeAsText.cpp:
(WebCore::writeLayers):
* Source/WebCore/rendering/shapes/ShapeInterval.h:
(WebCore::ShapeInterval::isEmpty const):
* Source/WebCore/rendering/svg/RenderSVGInlineText.cpp:
(WebCore::RenderSVGInlineText::styleDidChange):

Canonical link: https://commits.webkit.org/317710@main
https://bugs.webkit.org/show_bug.cgi?id=319983
rdar://179862957

Reviewed by Etienne Segonzac.

Align the immersive documentation syntax with the other API documentations.

* Source/WebKit/UIProcess/API/Cocoa/WKImmersiveEnvironment.h:
* Source/WebKit/UIProcess/API/Cocoa/WKImmersiveEnvironmentDelegate.h:
* Source/WebKit/UIProcess/API/Swift/WebPage+Configuration.swift:
* Source/WebKit/UIProcess/API/Swift/WebPage+ImmersiveEnvironment.swift:
* Source/WebKit/_WebKit_SwiftUI/API/View+WebViewModifiers.swift:
* Source/WebKit/_WebKit_SwiftUI/API/WebViewImmersiveEnvironmentView.swift:

Canonical link: https://commits.webkit.org/317711@main
https://bugs.webkit.org/show_bug.cgi?id=319942
rdar://problem/182860702

Reviewed by Cole Carley.

After track sizing is finished, we attempt to resolve the margins for
grid items in two different places: once during the final sizing of the
item and then when we want to align them. The logic to do this is
exactly the same and we do it in two different ways in both scenarios
when we do not need to. Instead, let's just use the static helper
function that we already have during item sizing and remove the lambdas
that were basically just duplicate code.

This change requires us to compute a list of the margins for each grid
item rather than resolve the margins one at a time, but this is
basically just a matter of plumbing the values to the right place.

* Source/WebCore/layout/formattingContexts/grid/GridLayout.cpp:
Remove the local UsedMargins definition now that it lives in
GridLayoutUtils.h.

(WebCore::Layout::GridLayout::layoutGridItems const):
Resolve each grid item's used margins with computeMarginsForAxis and pass
them into the sizing functions.

* Source/WebCore/layout/formattingContexts/grid/GridLayoutUtils.cpp:
(WebCore::Layout::GridLayoutUtils::stretchFitSize):
(WebCore::Layout::GridLayoutUtils::inlinePreferredSize):
(WebCore::Layout::GridLayoutUtils::blockPreferredSize):
(WebCore::Layout::GridLayoutUtils::inlineUsedSize):
(WebCore::Layout::GridLayoutUtils::blockUsedSize):
Aforementioned plumbing from GridLayout::layoutGridItems to the spots
where we were manually resolving them in the lambdas.

Canonical link: https://commits.webkit.org/317712@main
rdar://182758228
https://bugs.webkit.org/show_bug.cgi?id=319969

Reviewed by Jean-Yves Avenard.

In M150 libwebrtc resync, explicit hopping from network thread to worker thread was removed from WebRtcVideoReceiveChannel::OnPacketReceived.
This is ok in Chrome since network thread and worker thread are the same.
We apply the same setup in WebKit in LibWebRTCProvider::createPeerConnectionFactory.

The issue is that while Call::DeliverRtpPacket use a safety task to make sure the Call pointer is valid after hopping to worker thread,
the OnUndemuxablePacketHandler is keeping a pointer to WebRtcVideoReceiveChannel/WebRtcVoiceReceiveChannel, which are not guaranteed to stay valid in our previous config where worker thread and signalling thread were the same.
For good measure, we make sure that the OnUndemuxablePacketHandler given to Call::DeliverRtpPacket from WebRtcVideoReceiveChannel and WebRtcVoiceReceiveChannel use safety flags so that we protect from any misuse pointers.

* Source/ThirdParty/libwebrtc/Source/webrtc/media/engine/webrtc_video_engine.cc:
* Source/ThirdParty/libwebrtc/Source/webrtc/media/engine/webrtc_voice_engine.cc:
* Source/WebCore/platform/mediastream/libwebrtc/LibWebRTCProvider.cpp:
(WebCore::LibWebRTCProvider::createPeerConnectionFactory):

Canonical link: https://commits.webkit.org/317713@main
rdar://182612413
https://bugs.webkit.org/show_bug.cgi?id=319922

Reviewed by Alex Christensen.

There's already many `.frame` properties on various classes on Cocoa platforms, most of which are NS/CGRect.
This new property is a bit confusing for devs cognitively, and also trips up tooling.

Let's rename to something that already has WebKit precedent.

* Source/WebKit/UIProcess/API/Cocoa/WKJSHandle.h:
* Source/WebKit/UIProcess/API/Cocoa/WKJSHandle.mm:
(-[WKJSHandle sourceFrame]):
(-[_WKJSHandle frame]):
(-[WKJSHandle frame]): Deleted.
* Source/WebKit/UIProcess/API/Cocoa/_WKJSHandle.h:

Canonical link: https://commits.webkit.org/317714@main
https://bugs.webkit.org/show_bug.cgi?id=247996
rdar://102634281

Reviewed by BJ Burg.

Implement the "consume user activation of Window" WebDriver extension command
(POST /session/{id}/window/consume-user-activation) defined in HTML, which
consumes the current browsing context active window's transient user activation
and returns whether activation was present. The command mirrors the existing
getComputedRole automation command, routing from the UI process to the web
process to call LocalDOMWindow::consumeTransientActivation().

* Source/WebDriver/Session.cpp:
(WebDriver::Session::consumeUserActivation):
* Source/WebDriver/Session.h:
* Source/WebDriver/WebDriverService.cpp:
(WebDriver::WebDriverService::consumeUserActivation):
* Source/WebDriver/WebDriverService.h:
* Source/WebKit/UIProcess/Automation/Automation.json:
* Source/WebKit/UIProcess/Automation/WebAutomationSession.cpp:
(WebKit::WebAutomationSession::consumeUserActivation):
* Source/WebKit/UIProcess/Automation/WebAutomationSession.h:
* Source/WebKit/UIProcess/WebPageProxy.cpp:
* Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.cpp:
(WebKit::WebAutomationSessionProxy::consumeUserActivation):
* Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.h:
* Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.messages.in:

Canonical link: https://commits.webkit.org/317715@main
…d isAnyOf

https://bugs.webkit.org/show_bug.cgi?id=319815
rdar://182714057

Reviewed by Sam Weinig.

The const variadic overloads in WeakPtr.h and UniqueRef.h were
mistakenly named is() instead of isAnyOf(), colliding with the
const single-argument is() overload and leaving isAnyOf() without
a const overload for these two types. Ref.h, RefPtr.h, CheckedPtr.h,
and CheckedRef.h all name this overload isAnyOf() correctly.

* Source/WTF/wtf/UniqueRef.h:
(WTF::isAnyOf):
* Source/WTF/wtf/WeakPtr.h:
(WTF::isAnyOf):

Canonical link: https://commits.webkit.org/317716@main
…code

https://bugs.webkit.org/show_bug.cgi?id=319964
rdar://182889728

Reviewed by Yijia Huang.

Since japanese calendar is using proleptic Gregorian calendar, for year,
day, month, monthcode, we do not need to query to the calendar, we can
just use ISO 8601 values. For era related ones need to query to the
actual calendar.

Test: JSTests/stress/temporal-japanese-calendar-proleptic-gregorian.js

* JSTests/stress/temporal-japanese-calendar-proleptic-gregorian.js: Added.
(shouldBe):
(checkDateFields):
(checkEra):
* Source/JavaScriptCore/runtime/temporal/core/CalendarICUBridge.cpp:
(JSC::TemporalCore::isoToCalendarFields):
(JSC::TemporalCore::calendarMonth):
(JSC::TemporalCore::calendarMonthCode):
(JSC::TemporalCore::calendarDay):

Canonical link: https://commits.webkit.org/317717@main
https://bugs.webkit.org/show_bug.cgi?id=319400
rdar://157892382

Reviewed by Aakash Jain.

EWSContext defines the EWS results schema (bug 319113); this adds the read
and write path on top of it. register() classifies a run's unexpected
failures and stores them, routing to the flaky table when given a
flaky_type and the failed table otherwise, and find_for_test() queries
either table via a flaky flag. EWSContext is wired into Model, with a mock
helper (add_mock_ews_results) and unit tests.

This also refines the landed skeleton: the result column becomes result_id,
a build_number column is added, and a Source value type bundles the
provenance columns (remote, pr_number, commit_hash, build_number).

* Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/ews_context.py:
(Source):
(Source.unpack):
(EWSContext):
(EWSContext.EWSResultsBase):
(EWSContext.EWSResultsBase.unpack):
(EWSContext.EWSFailedTestsByCommit):
(EWSContext.EWSFlakyTestsByCommit):
(EWSContext.__init__):
(EWSContext.register):
(EWSContext._classify_unexpected):
(EWSContext.find_for_test):
* Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/ews_context_unittest.py: Added.
(EWSContextTest):
(EWSContextTest.init_database):
(EWSContextTest._find):
(EWSContextTest.test_unexpected_failures_stored):
(EWSContextTest.test_metadata_stored):
(EWSContextTest.test_flaky_results_stored):
(EWSContextTest.test_retries_preserved_for_same_commit):
(EWSContextTest.test_no_unexpected_failures):
(EWSContextTest.test_no_results):
* Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/mock_model_factory.py:
(MockModelFactory):
(MockModelFactory.add_mock_ews_results):
* Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/model.py:
(Model.__init__):

Canonical link: https://commits.webkit.org/317718@main
https://bugs.webkit.org/show_bug.cgi?id=319982

Reviewed by Patrick Griffis.

Problems fixed:

1)
const usage in Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp
https://docs.openssl.org/3.0/man7/migration_guide/#functions-that-return-an-internal-key-should-be-treated-as-read-only
"the value returned from EVP_PKEY_get0_RSA(3), ... have been made const"

2)
Feature test ifdefs in Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp no longer work
https://github.com/WebKit/WebKit/blob/6d8ca7e79a097c2013cf960c16489930cad90f11/Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp#L39
These were macros in OpenSSL 1.x, but are now real functions in OpenSSL 3.x:
https://docs.openssl.org/3.0/man3/EVP_PKEY_CTX_ctrl/#history "In OpenSSL 1.1.1 and below the functions were mostly macros. From OpenSSL 3.0 they are all functions."
So the ifdefs do not see the macros defined (because they are now functions), so the code incorrectly returns ExceptionCode::NotSupportedError.
The solution is to remove these feature checks, surely no one is still using OpenSSL 0.x from before these were added as macros.

3)
Runtime GCM failures. In Source/WebCore/crypto/openssl/CryptoAlgorithmAESGCMOpenSSL.cpp EVP_CIPHER_CTX_set_padding() is called *before*
EVP_EncryptInit_ex() and EVP_DecryptInit_ex().
The OpenSSL documentation says:
"This function should be called after the context is set up for encryption or decryption"
https://docs.openssl.org/3.0/man3/EVP_EncryptInit/#description .
In OpenSSL 1.x this did not matter because EVP_EncryptInit_ex() always returned 1:
https://github.com/openssl/openssl/blob/OpenSSL_1_1_1-stable/crypto/evp/evp_enc.c#L650 ,
but in OpenSSL 3.x it can return 0 if it is called incorrectly, as here with a null ctx->cipher.
The solution is to move the function calls after the init functions.

No new tests: fixes behaviour in non default configuration

* Source/WebCore/crypto/openssl/CryptoAlgorithmAESGCMOpenSSL.cpp: move EVP_CIPHER_CTX_set_padding() calls
(WebCore::cryptEncrypt): move EVP_CIPHER_CTX_set_padding() call after EVP_EncryptInit_ex()
(WebCore::cryptDecrypt): move EVP_CIPHER_CTX_set_padding() call after EVP_DecryptInit_ex()
* Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp: delete broken feature check #ifs
(WebCore::CryptoAlgorithmRSA_OAEP::platformEncrypt): delete broken feature check #if
(WebCore::CryptoAlgorithmRSA_OAEP::platformDecrypt): delete broken feature check #if
* Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_PSSOpenSSL.cpp: delete broken feature check #ifs
(WebCore::CryptoAlgorithmRSA_PSS::platformSign): delete broken feature check #if
(WebCore::CryptoAlgorithmRSA_PSS::platformVerify): delete broken feature check #if
* Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp: Add const to match OpenSSL 3.x API changes
(WebCore::getRSAModulusLength): add const
(WebCore::CryptoKeyRSA::keySizeInBits const): add const
(WebCore::CryptoKeyRSA::algorithm const): add const
(WebCore::CryptoKeyRSA::exportData const): add const

Canonical link: https://commits.webkit.org/317719@main
alanbaradlay and others added 13 commits July 25, 2026 14:40
…e measurement

https://bugs.webkit.org/show_bug.cgi?id=320236

Reviewed by Antti Koivisto.

A couple of flex-item measurements still read the render tree straight from
FlexFormattingContext. Move them behind FlexIntegrationUtils so the formatting context keeps
the flex algorithm and the integration owns the RenderBox access.

flexItemIntrinsicLogicalHeight and flexItemIntrinsicLogicalWidth move to FlexIntegrationUtils.
Each takes the one flex-algorithm decision it needs -- whether the item's logical height must be
stretched, and whether its cross size is definite -- as a bool computed by the formatting context
(via FlexFormattingUtils / FlexLayoutState) and passed in. That keeps FlexLayoutState and the
FlexFormattingUtils queries on the formatting-context side and leaves the integration methods as
pure render-tree measurement: scrollbar + border/padding + constrainLogicalHeightByMinMax, or
computeLogicalWidth with the item's overriding width cleared.

While here, fold the flex-base-size max-content branch's border/padding subtraction into the
integration. maxContentMainAxisExtentForFlexItem now returns the content-box extent (the
contribution minus the item's main-axis border/padding) instead of the raw contribution, so
flexBaseSizeForFlexItem no longer reads the item's border/padding directly. It is renamed from
maxContentMainAxisContributionForFlexItem to reflect the value it returns.

No change in behavior.

* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp:
(WebCore::FlexFormattingContext::hypotheticalCrossSizeForFlexItems):
(WebCore::FlexFormattingContext::flexBaseSizeForFlexItem):
(WebCore::FlexFormattingContext::flexItemIntrinsicLogicalHeight): Deleted.
(WebCore::FlexFormattingContext::flexItemIntrinsicLogicalWidth): Deleted.
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h:
* Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp:
(WebCore::LayoutIntegration::FlexIntegrationUtils::maxContentMainAxisExtentForFlexItem):
(WebCore::LayoutIntegration::FlexIntegrationUtils::flexItemIntrinsicLogicalHeight):
(WebCore::LayoutIntegration::FlexIntegrationUtils::flexItemIntrinsicLogicalWidth):
(WebCore::LayoutIntegration::FlexIntegrationUtils::maxContentMainAxisContributionForFlexItem): Deleted.
* Source/WebCore/layout/integration/flex/FlexIntegrationUtils.h:

Canonical link: https://commits.webkit.org/317923@main
…es.html` test expectation

https://bugs.webkit.org/show_bug.cgi?id=320280
rdar://183197290

Reviewed by Abrar Rahman Protyasha.

Re-baseline this test since the font/metrics have slightly become mismatched.

* LayoutTests/http/tests/quicklook/resources/secure-document-with-subresources-expected/index.css:
(.p1):
(.p2):
(.it2):
(.it3):
* LayoutTests/platform/ios/TestExpectations:

Canonical link: https://commits.webkit.org/317924@main
…verride for GTK/WPE ports

https://bugs.webkit.org/show_bug.cgi?id=320272
rdar://183191094

Reviewed by Patrick Griffis.

lint_test_expectations.py compared the Port object itself against the
strings 'gtk' and 'wpe' instead of comparing port_to_lint.port_name.
Port has no __eq__, so the comparison was always False and the
glib-specific TestExpectations override (LayoutTests/platform/glib/
TestExpectations) was silently never added for either port.

* Tools/Scripts/webkitpy/layout_tests/lint_test_expectations.py:
(lint): Compare port_to_lint.port_name instead of port_to_lint.
* Tools/Scripts/webkitpy/layout_tests/lint_test_expectations_unittest.py:
(FakePort.__init__): Add port_name and _options so tests can exercise
the glib-expectations branch.
(LintTest.test_glib_additional_expectations): Added. Verifies gtk and
wpe ports get the glib TestExpectations override and other ports don't.

Canonical link: https://commits.webkit.org/317925@main
…rations into FlexIntegrationUtils

https://bugs.webkit.org/show_bug.cgi?id=320252

Reviewed by Antti Koivisto.

FlexFormattingContext still made a number of non-trivial calls directly on the flex item's renderer
-- margin trimming, auto-margin resolution, min/max constraining, and percentage-height /
logical-size computation. Move them behind FlexIntegrationUtils so the formatting context reaches
the flex item's renderer only through cheap getters.

Moved to FlexIntegrationUtils (each takes a FlexLayoutItem and derives the container's flow /
writing mode from flexBox() rather than from the formatting context's constraints):

- updateAutoMarginsInMainAxis / updateAutoMarginsInCrossAxis (renderer margin mutations).
- trimMainAxisMarginStart / trimMainAxisMarginEnd / trimCrossAxisMarginStart / trimCrossAxisMarginEnd.
- constrainFlexItemLogicalHeightByMinMax / constrainFlexItemLogicalWidthByMinMax (the width helper
  supplies flexBox() as the containing block).
- computePercentageLogicalHeightForFlexItem, computeLogicalHeightUsingForFlexItem and
  computeLogicalWidthUsingForFlexItem (templated, with explicit instantiations for the size types
  the formatting context resolves).

The formatting context keeps the flex-algorithm decisions: it still gates margin trimming on
FlexFormattingUtils::shouldTrim*, and computes the stretch / cross-size-definiteness booleans it
passes into the intrinsic-size helpers.

Drive-by cleanup in the same functions: dropped the redundant out-of-flow-positioned ASSERTs and
the CheckedRef renderer locals that existed only to feed the moved calls, and converted the
isRenderTable() / isRenderReplaced() virtual checks to is<RenderTable> / is<RenderReplaced> (adding
the corresponding includes).

No change in behavior.

* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp:
(WebCore::FlexFormattingContext::computeFlexLines):
(WebCore::FlexFormattingContext::trimCrossAxisMarginsForFlexItems):
(WebCore::FlexFormattingContext::handleCrossAxisAlignmentForFlexItems):
(WebCore::FlexFormattingContext::performBaselineAlignment):
(WebCore::FlexFormattingContext::placeFlexItems):
(WebCore::FlexFormattingContext::computeContentBasedMinMainSize):
(WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing):
(WebCore::FlexFormattingContext::computeUsedNonAutoMinMainSize):
(WebCore::FlexFormattingContext::flexItemCrossSizeIsDefinite):
(WebCore::FlexFormattingContext::applyStretchAlignmentToFlexItem):
(WebCore::FlexFormattingContext::applyStretchMinMaxCrossSize):
(WebCore::FlexFormattingContext::updateAutoMarginsInMainAxis): Deleted.
(WebCore::FlexFormattingContext::updateAutoMarginsInCrossAxis): Deleted.
(WebCore::FlexFormattingContext::trimMainAxisMarginStart): Deleted.
(WebCore::FlexFormattingContext::trimMainAxisMarginEnd): Deleted.
(WebCore::FlexFormattingContext::trimCrossAxisMarginStart): Deleted.
(WebCore::FlexFormattingContext::trimCrossAxisMarginEnd): Deleted.
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h:
* Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp:
(WebCore::LayoutIntegration::FlexIntegrationUtils::updateAutoMarginsInMainAxis):
(WebCore::LayoutIntegration::FlexIntegrationUtils::updateAutoMarginsInCrossAxis):
(WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginStart):
(WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginEnd):
(WebCore::LayoutIntegration::FlexIntegrationUtils::trimCrossAxisMarginStart):
(WebCore::LayoutIntegration::FlexIntegrationUtils::trimCrossAxisMarginEnd):
(WebCore::LayoutIntegration::FlexIntegrationUtils::constrainFlexItemLogicalHeightByMinMax):
(WebCore::LayoutIntegration::FlexIntegrationUtils::constrainFlexItemLogicalWidthByMinMax):
(WebCore::LayoutIntegration::FlexIntegrationUtils::computePercentageLogicalHeightForFlexItem):
(WebCore::LayoutIntegration::FlexIntegrationUtils::computeLogicalHeightUsingForFlexItem):
(WebCore::LayoutIntegration::FlexIntegrationUtils::computeLogicalWidthUsingForFlexItem):
* Source/WebCore/layout/integration/flex/FlexIntegrationUtils.h:

Canonical link: https://commits.webkit.org/317926@main
…FlexibleBox's flex-item query wrappers

https://bugs.webkit.org/show_bug.cgi?id=320254

Reviewed by Antti Koivisto.

RenderFlexibleBox carried thin flex-item query wrappers -- mainAxisIsFlexItemInlineAxis,
flexBasisForFlexItem, alignmentForFlexItem, hasDefiniteCrossSizeForFlexItem -- that only forwarded
to the corresponding FlexFormattingUtils statics, plus useContentBasedMinimumBlockSize which
composed two of them. Their only callers are render-side (RenderBox / RenderBlock), which already
pull in FlexFormattingUtils.h transitively through RenderFlexibleBox.h, so the wrappers were
redundant indirection.

Drop the four proxies from RenderFlexibleBox and move the useContentBasedMinimumBlockSize
composition to a FlexFormattingUtils static. The statics take the flex item and derive the flex
container from its parent, so the call sites pass the item directly; isFlexItem() already implies a
RenderFlexibleBox parent, so RenderBox loses two now-redundant downcast guards. RenderBox.cpp and
RenderBlock.cpp gain a direct FlexFormattingUtils.h include.

No change in behavior.

* Source/WebCore/rendering/RenderFlexibleBox.h:
* Source/WebCore/rendering/RenderFlexibleBox.cpp:
(WebCore::RenderFlexibleBox::mainAxisIsFlexItemInlineAxis): Deleted.
(WebCore::RenderFlexibleBox::flexBasisForFlexItem): Deleted.
(WebCore::RenderFlexibleBox::alignmentForFlexItem): Deleted.
(WebCore::RenderFlexibleBox::hasDefiniteCrossSizeForFlexItem): Deleted.
(WebCore::RenderFlexibleBox::useContentBasedMinimumBlockSize): Deleted.
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.h:
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.cpp:
(WebCore::FlexFormattingUtils::useContentBasedMinimumBlockSize):
* Source/WebCore/rendering/RenderBox.cpp:
(WebCore::RenderBox::isBlockSizeResolvableForStretch):
(WebCore::RenderBox::computeContentAndScrollbarLogicalHeightUsing):
* Source/WebCore/rendering/RenderBlock.cpp:
(WebCore::RenderBlock::hasDefiniteLogicalHeightForPercentageResolutionFromStyle):

Canonical link: https://commits.webkit.org/317927@main
https://bugs.webkit.org/show_bug.cgi?id=319814

Reviewed by Yijia Huang.

Resolve ordinary supported Chinese and Dangi related-year and ordinal numeric-month field resolution without relying on ICU extended-year identity. Keep year/era/eraYear and monthCode/ordinal-month consistency, with({year}), Duration relativeTo, Hebrew month behavior, and PlainMonthDay required-field ordering consistent.

Tests: JSTests/stress/temporal-lunisolar-ordinal-month.js

Tests: jsc --useTemporal=1 JSTests/stress/temporal-lunisolar-ordinal-month.js

Tests: readable focused Temporal field-resolution, Duration, Hebrew, PlainMonthDay ordering, and arithmetic tests
Canonical link: https://commits.webkit.org/317928@main
…nd border/padding off the renderer

https://bugs.webkit.org/show_bug.cgi?id=320283

Reviewed by Antti Koivisto.

A few flex-item reads were left in FlexFormattingContext, all going straight to the renderer for
values the formatting context either already has or can get through the utils.

computeFlexBaseAndHypotheticalMainSizes re-reads an orthogonal item's main-axis margin after
flexBaseSizeForFlexItem has laid the item out (the item's block-direction margins are only resolved
at that point), duplicating the horizontal/verticalMarginExtent selection that FlexFormattingUtils
already does. That helper had two behaviours behind one name though: for a clean item it returned
the resolved physical extent, but for a dirty one it recomputed the margins in the container's
inline/block directions, which only line up with the main/cross axes in a horizontal writing mode.
Split it in two -- usedMainAxisMarginExtentForFlexItem returns what layout resolved, and
resolveMainAxisMarginExtentForFlexItem resolves first for the one caller that needs that,
staticMainAxisPositionForPositionedFlexItem, which computes an out-of-flow item's static position
outside of flex layout. computeFlexBaseAndHypotheticalMainSizes wants the former.

removeMarginEndFromFlexSizes computes the item's main-axis end margin to subtract it from the
running flex base and hypothetical main sizes -- the same value that
FlexIntegrationUtils::trimMainAxisMarginEnd subtracts from the item's cached mainAxisMargin, and the
two are always called together. Add FlexFormattingUtils::mainAxisMarginEndForFlexItem (a static form
taking the container, plus the usual instance overload, matching crossAxisMarginExtentForFlexItem)
and have both call sites use it.

computeMainSizeFromAspectRatioUsing recomputes the item's main-axis border/padding from the renderer
even though FlexLayoutItem already caches it (with the same expression), and the same function
already uses the cached cross-axis value a few lines up. Unlike margins, border/padding is not
resolved during layout, so this is simply a duplicate read: use the cached
FlexLayoutItem::mainAxisBorderAndPadding instead.

With this the formatting context reaches a flex item's renderer only through the FlexLayoutItem
constructor's one-time snapshot, cheap getters and asserts.

No change in behavior.

* Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp:
(WebCore::FlexFormattingContext::computeFlexBaseAndHypotheticalMainSizes):
(WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing):
(WebCore::FlexFormattingContext::removeMarginEndFromFlexSizes):
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.h:
* Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.cpp:
(WebCore::FlexFormattingUtils::resolveMainAxisMarginExtentForFlexItem):
(WebCore::FlexFormattingUtils::usedMainAxisMarginExtentForFlexItem):
(WebCore::FlexFormattingUtils::mainAxisMarginEndForFlexItem):
(WebCore::FlexFormattingUtils::mainAxisMarginExtentForFlexItem): Deleted.
* Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp:
(WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginEnd):
* Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.cpp:
(WebCore::LayoutIntegration::FlexLayout::staticMainAxisPositionForPositionedFlexItem):

Canonical link: https://commits.webkit.org/317929@main
…sting whether a second one is needed

https://bugs.webkit.org/show_bug.cgi?id=320088

Reviewed by Yusuke Suzuki.

tryReadUnicodeCharImpl loads 32 bits up front so that it can detect a
surrogate pair, and therefore checks that both code units are in bounds before
loading anything.

Surrogate pairs are rare compared to BMP code points, though, and deciding
whether a code unit is a BMP code point on its own does not need 32 bits. Load
the first code unit alone and test its top five bits: U+D800-U+DFFF are exactly
the code units whose top five bits are 0b11011. If it is not a surrogate, it is
the code point, so jump to done right there. Only if it is a surrogate do we
check the bounds, load 32 bits, and either decode a proper surrogate pair or
fall into the slow cases.

Keeping the bit 15 test from 317749@main as the fast-path branch would take
fewer instructions, but that branch depends on the character being read and
mispredicts badly once the subject mixes code units below and above U+8000.
The surrogate test costs one more instruction but only changes direction when
a surrogate actually appears.

                                            Baseline           Patched

regexp-unicode-bmp-hangul-and-fullwidth 43.9718+-0.9491    34.3181+-2.8952   definitely 1.2813x faster
regexp-unicode-bmp-above-latin          45.6190+-0.7442    35.8214+-2.6717   definitely 1.2735x faster
regexp-u-global-es6                     31.8327+-0.2765    30.5326+-0.3346   definitely 1.0426x faster
regexp-unicode-latin-before-surrogate   55.0738+-1.6395    52.8071+-3.0785   might be 1.0429x faster
regexp-unicode-surrogate-pairs          45.9197+-1.5007    46.1131+-1.7645   neutral

* Source/JavaScriptCore/yarr/YarrJIT.cpp:
(JSC::Yarr::tryReadUnicodeCharImpl):

Canonical link: https://commits.webkit.org/317930@main
…nments`

https://bugs.webkit.org/show_bug.cgi?id=320151

Reviewed by Yusuke Suzuki.

JSModuleRecord kept copies of the module's declared and lexical VariableEnvironments alive for
the lifetime of the record, but the lexical one is only read by ModuleAnalyzer (which already receives
the ModuleProgramNode) and the declared one only by InitializeEnvironment's var initialization loop.
Read the former from the node and store the latter in UnlinkedModuleProgramCodeBlock, as
UnlinkedProgramCodeBlock already does for scripts, so it lives and dies with the unlinked code.

This shrinks JSModuleRecord from 512 to 320 bytes.

* Source/JavaScriptCore/bytecode/UnlinkedModuleProgramCodeBlock.h:
* Source/JavaScriptCore/bytecompiler/BytecodeGenerator.cpp:
(JSC::BytecodeGenerator::BytecodeGenerator):
* Source/JavaScriptCore/parser/ModuleAnalyzer.cpp:
(JSC::ModuleAnalyzer::ModuleAnalyzer):
(JSC::ModuleAnalyzer::analyze):
* Source/JavaScriptCore/parser/ModuleAnalyzer.h:
* Source/JavaScriptCore/runtime/CachedTypes.cpp:
(JSC::CachedModuleCodeBlock::encode):
(JSC::CachedModuleCodeBlock::decode const):
* Source/JavaScriptCore/runtime/Completion.cpp:
(JSC::checkModuleSyntax):
* Source/JavaScriptCore/runtime/CyclicModuleRecord.cpp:
(JSC::CyclicModuleRecord::initializeEnvironment):
* Source/JavaScriptCore/runtime/JSModuleLoader.cpp:
(JSC::JSModuleLoader::makeModule):
* Source/JavaScriptCore/runtime/JSModuleRecord.cpp:
(JSC::JSModuleRecord::create):
(JSC::JSModuleRecord::JSModuleRecord):
* Source/JavaScriptCore/runtime/JSModuleRecord.h:

Canonical link: https://commits.webkit.org/317931@main
…tributed string

https://bugs.webkit.org/show_bug.cgi?id=320263
rdar://183187277

Reviewed by Wenson Hsieh.

collectDictationTextAlternatives() and shouldRegisterInsertionUndoGroup()
both unconditionally read attributes at index 0 of the NSAttributedString
passed to WebViewImpl::insertText(id, NSRange), without checking the
string's length first. An empty NSMutableAttributedString raises
NSRangeException for such an access, so passing a zero-length attributed
string (e.g. from an input method committing a composition down to nothing,
or from the Character Viewer) crashed. Guard both functions with a length
check.

Note that an empty immutable NSAttributedString happens not to raise, so
the new tests use NSMutableAttributedString to exercise the crashing path.

The equivalent WebHTMLView insertText: path in WebKitLegacy has a third
unguarded index-0 read of NSTextInputReplacementRangeAttributeName that
this change does not address.

* Source/WebCore/editing/mac/TextAlternativeWithRange.mm:
(WebCore::collectDictationTextAlternatives):
* Source/WebCore/editing/mac/TextUndoInsertionMarkupMac.mm:
(WebCore::shouldRegisterInsertionUndoGroup):
* Tools/TestWebKitAPI/Tests/WebKit/WKWebView/mac/WKWebViewMacEditingTests.mm:
(TestWebKitAPI::TEST(WKWebViewMacEditingTests, InsertEmptyAttributedStringDoesNotCrash)):
(TestWebKitAPI::TEST(WKWebViewMacEditingTests, InsertEmptyAttributedStringWithAttributesDoesNotCrash)):

Canonical link: https://commits.webkit.org/317932@main
…the line box top instead of the element's bounding rect

https://bugs.webkit.org/show_bug.cgi?id=316063
rdar://178491868

Reviewed by Alan Baradlay.

This patch aligns WebKit with Blink / Chromium.

RenderElement::getLeadingCorner() computed the leading corner of an
inline element's anchor rect by taking the x from the text's
linesBoundingBox() but the y from the line box's contentLogicalTop().
When the inline shares a line with a much taller sibling (e.g. a
100vh image), the line box is inflated and its top sits far above the
baseline-aligned text, so the leading corner pointed at the top of the
line box rather than at the text itself. This made scrollIntoView()
scroll to the wrong position, since getTrailingCorner() already uses
the text's linesBoundingBox().

Take both x and y from the text's linesBoundingBox(), mirroring
getTrailingCorner(), so the anchor rect is the element's own bounding
rect. For normal lines linesBoundingBox().y() equals
contentLogicalTop(), so only the tall-line case changes behavior.

* LayoutTests/TestExpectations: Remove [ Failure ] expectations
* Source/WebCore/rendering/RenderElement.cpp:
(WebCore::RenderElement::getLeadingCorner const):

> Platform Specific Updates:
* LayoutTests/platform/glib/fast/scrolling/scroll-to-anchor-zoomed-header-expected.txt: Removed. (Now matches pass expectation)
* LayoutTests/platform/ios/fast/dynamic/anchor-lock-expected.txt: Rebaselined
* LayoutTests/platform/glib/fast/dynamic/anchor-lock-expected.txt: Ditto

Canonical link: https://commits.webkit.org/317933@main
- AbstractModuleRecord::setImportedModule: drop m_dependencies write (member removed
  upstream in bug 320144; m_loadedModules is the sole lookup path now).
- NodesCodegen: keep emit_intrinsic_getInternalField (Bun's @getInternalField bytecode
  intrinsic) after the conflict-region resolution dropped it alongside the stale
  asyncFromSyncIteratorInternalFieldIndex helper.
Comment thread JSTests/stress/resources/async-iterator-tla-basic.js
Comment on lines +1 to +5
// %AsyncFromSyncIteratorPrototype%.throw with an undefined `throw` method must close the sync iterator via
// IteratorClose and settle the returned promise via IfAbruptRejectPromise -- i.e. REJECT the promise rather than
// escape synchronously -- for every IteratorClose outcome. The async-from-sync wrapper is not user-observable, so
// it is reached through `yield*` over a sync iterable inside an async generator. Behavior and error identity are
// verified against the ECMA-262 %AsyncFromSyncIteratorPrototype%.throw / IteratorClose / GetMethod steps and match

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 The AsyncContextSwapScope adaptation missed two new AsyncGeneratorDriverResume scheduling sites introduced by upstream's AsyncFromSyncIterator rewrite (bug 319435): JSMicrotask.cpp:376 (asyncFromSyncIteratorContinueOrDone Rejected branch) and AsyncFromSyncIteratorPrototype.cpp:291 (driveAsyncFromSyncIteratorWithDriver sync-throws branch) both pass the raw driver instead of AsyncContextSwapScope::wrapWithCurrent(...). As a result, Bun's AsyncLocalStorage snapshot is dropped when a for await over a sync iterable rejects (rejected-promise element or sync next() throws). Both sites should wrap the driver under #if USE(BUN_JSC_ADDITIONS), mirroring JSMicrotask.cpp:552-558. (Anchored to a test file because JSMicrotask.cpp is beyond the 300-file diff window.)

Extended reasoning...

What the bug is

The fork's convention (established in this PR's own adaptation) is that every context value passed to InternalMicrotask::AsyncGeneratorDriverResume is wrapped with AsyncContextSwapScope::wrapWithCurrent(vm, globalObject, driver) so that the receive-side handler can restore Bun's async context before resuming the driver. The receive side at JSMicrotask.cpp:2086-2092 does:

case InternalMicrotask::AsyncGeneratorDriverResume: {
    JSValue contextArg = arguments[2];
#if USE(BUN_JSC_ADDITIONS)
    AsyncContextSwapScope asyncContextScope(vm, globalObject, AsyncContextSwapScope::unwrapContextTuple(contextArg));
#endif
    ...
}

The PR correctly applied this to settleDriverWithIteratorResult (line 309-316) and to asyncGeneratorCompleteStep's isThrow path (line 552-558). But upstream's bug 319435 rewrite introduced two additional AsyncGeneratorDriverResume scheduling sites that were left unwrapped.

The two affected sites

Site 1 — JSMicrotask.cpp:376, in asyncFromSyncIteratorContinueOrDone's Rejected / non-JSPromise-target branch:

JSPromise::rejectWithInternalMicrotask(vm, globalObject, result, InternalMicrotask::AsyncGeneratorDriverResume, target);

Here target is the raw driver from iterator->extractTarget(). This runs inside the AsyncFromSyncIteratorContinue/Done microtask handler, which has restored the async context (line 2036), so wrapWithCurrent at this point would capture a live snapshot — but it is never called.

Site 2 — AsyncFromSyncIteratorPrototype.cpp:291, in driveAsyncFromSyncIteratorWithDriver's exception branch:

JSPromise::rejectWithInternalMicrotask(vm, globalObject, error, InternalMicrotask::AsyncGeneratorDriverResume, driver);

This is called synchronously from op_async_iterator_next inside the driver body, where the async context is active.

rejectWithInternalMicrotask (JSPromise.cpp:1048-1051) does not wrap its context — only resolveWithInternalMicrotaskForAsyncAwait does (line 967-971). So both sites queue the raw driver directly.

Why existing code doesn't prevent it

When the AsyncGeneratorDriverResume microtask fires, unwrapContextTuple(contextArg) (AsyncContextSwapScope.h:82-91) sees a non-InternalFieldTuple, leaves contextArg untouched (so the driver still resumes correctly), and returns jsUndefined(). The AsyncContextSwapScope constructor then early-returns on undefined (line 52-53) and installs no context. There is no crash — unwrapContextTuple is graceful — but the driver's rejection continuation runs with whatever async context happens to be ambient at microtask time, not the snapshot from the await point.

Step-by-step proof

Under USE(BUN_JSC_ADDITIONS):

await asyncLocalStorage.run(store, async () => {
  try {
    for await (const x of [Promise.reject(err)]) {}
  } catch (e) {
    asyncLocalStorage.getStore();  // -> undefined, expected: store
  }
});
  1. for await opens an async-from-sync wrapper over the array; the driver is the enclosing async function.
  2. The wrapper's next() yields Promise.reject(err); awaitAndContinue schedules AsyncFromSyncIteratorContinue (context wrapped by resolveWithInternalMicrotaskForAsyncAwait).
  3. That microtask runs with the async context restored, calls asyncFromSyncIteratorContinueOrDone with Status::Rejected, and reaches line 376.
  4. Line 376 queues AsyncGeneratorDriverResume with the raw target.
  5. The driver-resume microtask runs: unwrapContextTuple returns jsUndefined(), no context is installed, and the driver's catch block executes with no AsyncLocalStorage store.

Site 2 triggers the same way when the sync iterator's next() itself throws, e.g. { [Symbol.iterator]() { return { next() { throw err } } } } — driveSyncIterator throws, catchScope catches it, and line 291 queues the raw driver.

Impact and fix

This is a Bun-specific behavioural regression vs. the pre-merge fork, where the equivalent reject path (asyncGeneratorCompleteStep isThrow) wrapped the target. It affects Bun's core Node.js-compat AsyncLocalStorage feature on the (common) error paths of for await over sync iterables.

Fix: at both sites, wrap the driver under #if USE(BUN_JSC_ADDITIONS), mirroring lines 552-558:

#if USE(BUN_JSC_ADDITIONS)
    JSValue wrappedTarget = AsyncContextSwapScope::wrapWithCurrent(vm, globalObject, target);
#else
    JSValue wrappedTarget = target;
#endif
    JSPromise::rejectWithInternalMicrotask(vm, globalObject, result, InternalMicrotask::AsyncGeneratorDriverResume, wrappedTarget);

- SegmentedVector: gate the new Segment no-header static_assert (bug 320260) to
  non-Windows. On the MSVC ABI a class whose only member is a zero-length array
  has non-zero size (padded to alignof(T)), so the !sizeof(Segment) check only
  holds on the Itanium ABI. The non-Windows builds still enforce the invariant.
- WebKitMacros: skip _WEBKIT_ADD_CODE_SIGN when CMAKE_CROSSCOMPILING. Bun's
  macOS JSC is cross-built from a Linux Docker image where /usr/bin/codesign is
  unavailable and /bin/sh is dash (no 'set -o pipefail').
@robobun
robobun force-pushed the bun/upgrade-to-01aaa3e0be0c branch from 5efd3c6 to 3974430 Compare July 26, 2026 08:52
@github-actions

github-actions Bot commented Jul 26, 2026 •

Copy link
Copy Markdown

Preview Builds

Commit Release Date
f8c38e23 autobuild-preview-pr-352-f8c38e23 2026-07-26 13:06:16 UTC
642e4852 autobuild-preview-pr-352-642e4852 2026-07-26 11:15:49 UTC
39744305 autobuild-preview-pr-352-39744305 2026-07-26 09:40:19 UTC

robobun added 3 commits July 26, 2026 10:28
Upstream's m_dependencies removal (bug 320144) rewrote this lookup as a
hardcoded loop over {JavaScript, JSON, WebAssembly, None}. Bun's fork adds a
fifth ScriptFetchParameters::Type, HostDefined, for 'with { type: "text" }'
and friends; requests keyed with it were no longer found here, so the caller
dereferenced null during link/resolveExport and segfaulted.

Include HostDefined in the probe list under USE(BUN_JSC_ADDITIONS).
…JSC_ADDITIONS)

Upstream bug 319887 reserves uid 1 for the Linux process main thread
(getpid()==gettid()). Bun's 'bun build' evaluates macros on a bundler worker
thread, which is the first thread to call WTF::initializeMainThread() and so
becomes the 'WebKit main thread' per initializeMainThreadPlatform(). With the
OS-main-thread pinning that worker is constructed IsMain::No (uid >= 2) but
isMainThread() is true for it, so the RELEASE_ASSERT in initializeMainThread()
trips and aborts.

Fall through to the first-thread-gets-uid-1 behaviour under
USE(BUN_JSC_ADDITIONS), matching the pre-319887 Linux path.
IntlCache.h transitively includes ICU headers (<unicode/udat.h>,
<unicode/udatpg.h>) that Bun's own C++ cannot see on macOS (the prebuilt
tarball drops include/unicode/ there and relies on system ICU, which is not in
Bun's include path). Expose a small out-of-line VM method that clears both
dateCache and intlCache so Bun's process.env.TZ / setTimeZone() setters can
invalidate the new Intl.DateTimeFormat instance cache (bug 314337) without
including IntlCache.h.
@Jarred-Sumner
Jarred-Sumner merged commit 6886cd2 into main Jul 28, 2026
43 checks passed
dylan-conway pushed a commit to oven-sh/bun that referenced this pull request Aug 3, 2026
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800
(2026-08-02) via oven-sh/WebKit#383.

oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge
commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`.

## Bun-side changes

Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier,
ScriptFetchParameters::Type)` and threads the type through
`ImportEntry`, `ExportEntry`, `StarExportEntry`, and
`ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the
`BunTranspiledModule` path), Bun'''s synthesized record must agree with
what JSC'''s own `ModuleAnalyzer` would produce from the printed source;
a mismatch fails the BUN_DEBUG record diff in debug and null-derefs
`hostResolveImportedModule` in release.

- `analyze_transpiled_module` / `js_printer`: every `RecordKind` now
carries one trailing `FetchParameters` slot. `add_import_info_*` and
`add_export_info_*` accept it; `finalize()` propagates the source
import'''s slot through the Local->Indirect conversion.
`RequestedModules` dedupes on `(specifier, Type, phase)`.
- `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and
passes it to every `addImportEntry*` / `addIndirectExport` /
`addNamespaceExport` / `addStarExport`; buffer validation is per-slot so
only the trailing slot accepts the wider `FetchParameters` sentinel
range.
- `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` /
`add*Export` functions take `uint8_t moduleRequestType` and set
`.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for
import/export/star entries; `static_assert` pins the ordinal values
`to_script_fetch_parameters_type()` hardcodes.
- `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout
change).

## WebKit-side changes (oven-sh/WebKit#383)

- 17 merge conflicts resolved in JSC/WTF; fork's
`USE(BUN_JSC_ADDITIONS)` hunks preserved.
- Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64`
macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`).
- `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic`
in new `scriptTypeForScript` switch.
- Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352
was a squash merge).

## How did you verify your code works?

- `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e
'print(42)'` -> `42`).
- `bun run build:local -p '42'` links and runs against the local merged
WebKit.
- oven-sh/WebKit#383 preview build green on all 38 platform variants.
- `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`.
- New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass
with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC
lacks `Iterator.prototype.includes`, returns `""` for cyclic join,
`WebAssembly.Exception.length === 1`).

## JavaScriptCore/WTF/bmalloc changes since 01aaa3e0be0c (Jul 25)

Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits
total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026).

### Highlights

- `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and
`CPU(NEEDS_ALIGNED_ACCESS)` deleted).
- `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now;
drops remaining 32-bit/x86 JIT refs).
- `232cebabc1f3` Remove big-endian support and platforms without
unaligned loads/stores (WTF + JSC).
- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator
(greedy is the only allocator now).
- `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD
follow-ups).
- `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic
`toString`/`join` now throws RangeError via stack check (spec-correct).
- `319f94b3db4a` Enable `Iterator.prototype.includes()` by default.
- `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute
`type` (module loader behavior change).
- `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc
APIs on ARM64 (perf + ABI of WTF alloc entry points).

### JavaScriptCore

**Runtime / builtins**
- `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow
checks.
- `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in
runtime.
- `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in
`JSObject::toString`.
- `960adeccefcd` Fast operation for `Array#shift`.
- `92c6650c7947` Add `JSArrayIterator::next` C++ helper.
- `cb1c48b3e95f` Extend `Array.from()` Set fast path to
`set.keys()/.values()`.
- `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path
ignored `Symbol.iterator` overrides.
- `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators.
- `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in
`JSON.stringify` string copy (same-type & upconvert).
- `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check.
- `2eb77e9c9473` BigInt: implement Crandall reduction.
- `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly.
- `319f94b3db4a` Enable `Iterator.prototype.includes()`.
- `0731b27c1b60` `Iterator.zip`: use null-prototype objects for
options/underlying iterator.
- `90b2ecf79ae3` `hostResolveImportedModule` respects module request
import-attribute `type`.
- `4f54300b848a` Collect diagnostics when `getDirect` returns zero
JSValue in `llint_slow_path_get_by_id`.

**Parser / bytecompiler**
- `c2beca7a439f` Lexer: scan integer tokens in a single pass.
- `72ea806faa21` Use overflow-safe range when choosing a switch jump
table.

**LLInt / DFG / FTL / B3**
- `29ceb3c03de3` Remove 32-bit JSValues.
- `857bd4334690` Remove ARMv7 JIT support.
- `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator.
- `68cde6ba2ad3` Make IRO (Air register allocation) faster.
- `83540481435f` DFG: allocate
`BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets.
- `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must
require original array structure for `InBoundsSaneChain`.
- `e759fa9dd063` LLInt: inline hot path of `op_enter`.
- `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for
BaseIndex operands.
- `4ebed2479144` Speed up `addSortedRange` via binary search.
- `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit.

**WebAssembly**
- `0d0080ea539d` Enable Memory64 feature flag.
- `15aa6fad53e3` Memory64: SIMD support.
- `bf0425598904` Memory64: expand declared memory limits.
- `862994e2cc37` Memory64: validate table import address-type match.
- `184ee4c654bd` Memory64: Table64 in OMG tier.
- `d202bedc5ff6` Memory64: Table64 in BBQ tier.
- `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+
`stack` getter, ctor length = 2).
- `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting,
icache barrier rework).
- `1803d6109d98` Speed up `WebAssembly.Table` construction.
- `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target
runs.
- `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`.
- `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales.

**Yarr / RegExp**
- `581f1d958329` Start end-anchored fixed-size regexps at the only
possible position.
- `a458a6c1f0a7` v-mode class-set op loop: stop early when no more
output possible.
- `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`.
- `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for
`ParenContext`.
- `1e43057f135a` Extend first-character filter further.
- `54916608d7d6` Fix non-BMP advance latch; simplify
`tryReadUnicodeCharImpl`.
- `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative
lookaheads.
- `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns.
- `98d0367d2247` Fix: `^` inside a paren that can match empty does not
anchor the pattern.

**Intl / Temporal**
- `09917ef55b0f` Add missing `U_FAILURE(status)` check in
`actualLunisolarMonthLength`.

**Inspector**
- `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d`
Canvas: instrument & record WebGPU devices/pipelines.
- `301d6b2b21f7` Associate WebAssembly module scripts with the fetching
resource.
- `28b979b1659b` / `479edb2e4395` Site Isolation: implement
`Network.loadResource` / `Network.getSerializedCertificate`.

### WTF

- `232cebabc1f3` Remove big-endian support and
`CPU(NEEDS_ALIGNED_ACCESS)`.
- `e5fa5c604438` Upgrade fast_float to 8.2.10.
- `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII
case-conversion prefix copy.
- `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated
`find()`.
- `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table
off-by-one.
- `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64.
- `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`.
- `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`.
- `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete.
- `bf15f00ebe95` Remove 12 unused internal-linkage templates
(TypeTraits/HashTable/Vector/etc.).
- `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang
static analyzer.
- `158f737725b7` Add helpers for Darwin temp/cache directories.
- `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity).
- `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE
and fix findings.
- `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa".
- `cfb222f3c4d1` CMake: run `cleandead` at end of configuration.

### bmalloc

- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64).
- `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in
`VMAllocate.cpp`.
- `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its
should-go-again result.
- `90cbe5e85528` libpas: fix benign read from a deallocated TLC.
- `e388877954d1` PGM allocator: fix uninitialized `free_status`
misclassifying OOB as UAF.
- `05c83a6550b7` libpas: fix
`MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling
MTE.
- `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage
(scavenging / zeroing / paged-out pages).

### Breaking/notable for Bun

- **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed),
`857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas
removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)`
removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun
patches are now dead.
- **`VM` layout**: `f2f2c2ddf637` deletes
`StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields
from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws
`RangeError` instead of returning `""`.
- **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule`
to propagate the import-attribute `type` — check Bun's module loader
hook signatures.
- **Register allocator**: `bfb1b1183bc2` removes the B3/Air
graph-coloring allocator and its `Options::` toggle.
- **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds
`__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. —
affects anything calling these across the WTF boundary on arm64.
- **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as
private-only; `WebAssembly.Exception` constructor `length` becomes 2 and
gains a `stack` prototype getter.
- **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default;
`319f94b3db4a` `Iterator.prototype.includes` on by default.
- **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee
publication and adds `Thread::barrierInstructionCache()` in WTF.

<!-- robobun:evidence:begin -->

---

**[decide:webkit]** gate passed · iteration 2 · 8 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: BUILD FAILED (no junit output)
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
ninja: Entering directory `/workspace/bun/build/debug'
[1/182] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/182] gen cpp.rs (cppbind)
[3/182] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt
[4/182] gen JS modules (bundle-modules)
Preprocess modules (8715ms)
Bundle modules (63ms)
Postprocesss modules (24ms)
Bundle Functions (746ms)
Generate Code (12ms)

[9.57s] Bundled "src/js" for development
  2749 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

[177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o
FAILED: obj/unified/UnifiedSou
... (truncated)

release without fix: all passed
bun test v1.4.0-canary.1 (385f528)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [152.00ms]
__F:0:S:0
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
bun test v1.4.0 (59b0de0)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [3.17s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 676ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/140] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/140] gen cpp.rs (cppbind)
[3/140] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[4/140] gen JS modules (bundle-modules)
Preprocess modules (8727ms)
Bundle modules (51ms)
Postprocesss modules (106ms)
Bundle Functions (687ms)
Generate Code (20ms)

[9.61s] Bundled "src/js" for production
  2559 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

^[[1m^[[92m   Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
^[[1m^[[92m   Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime)
^[[1m^[[92m   Compilin
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
scripts/build/deps/webkit.ts                     |   2 +-
 src/bundler/analyze_transpiled_module.rs         |  38 +++--
 src/bundler/linker_context/postProcessJSChunk.rs |   8 +-
 src/bundler_jsc/analyze_jsc.rs                   | 135 ++++++++++++----
 src/js_printer/lib.rs                            | 191 +++++++++++++++++------
 src/jsc/RuntimeTranspilerCache.rs                |   5 +-
 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp  |  39 +++--
 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts  | 106 +++++++++++++
 8 files changed, 416 insertions(+), 108 deletions(-)
```

</details>

**gate history** · 5 passed · 1 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                              reads  edits  tests
scripts/build/deps/webkit.ts                          1      1      0
src/bundler/analyze_transpiled_module.rs              3      3      0
src/bundler/linker_context/postProcessJSChunk.rs      1      1      0
src/bundler_jsc/analyze_jsc.rs                       13     15      0
src/js_printer/lib.rs                                 9     16      0
src/jsc/RuntimeTranspilerCache.rs                     2      3      0
src/jsc/bindings/BunAnalyzeTranspiledModule.cpp       8     12      0
test/js/bun/jsc/webkit-upgrade-3722912f.test.ts       2      5      0
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
springmin pushed a commit to springmin/bun that referenced this pull request Aug 3, 2026
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800
(2026-08-02) via oven-sh/WebKit#383.

oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge
commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`.

Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier,
ScriptFetchParameters::Type)` and threads the type through
`ImportEntry`, `ExportEntry`, `StarExportEntry`, and
`ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the
`BunTranspiledModule` path), Bun'''s synthesized record must agree with
what JSC'''s own `ModuleAnalyzer` would produce from the printed source;
a mismatch fails the BUN_DEBUG record diff in debug and null-derefs
`hostResolveImportedModule` in release.

- `analyze_transpiled_module` / `js_printer`: every `RecordKind` now
carries one trailing `FetchParameters` slot. `add_import_info_*` and
`add_export_info_*` accept it; `finalize()` propagates the source
import'''s slot through the Local->Indirect conversion.
`RequestedModules` dedupes on `(specifier, Type, phase)`.
- `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and
passes it to every `addImportEntry*` / `addIndirectExport` /
`addNamespaceExport` / `addStarExport`; buffer validation is per-slot so
only the trailing slot accepts the wider `FetchParameters` sentinel
range.
- `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` /
`add*Export` functions take `uint8_t moduleRequestType` and set
`.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for
import/export/star entries; `static_assert` pins the ordinal values
`to_script_fetch_parameters_type()` hardcodes.
- `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout
change).

- 17 merge conflicts resolved in JSC/WTF; fork's
`USE(BUN_JSC_ADDITIONS)` hunks preserved.
- Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64`
macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`).
- `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic`
in new `scriptTypeForScript` switch.
- Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352
was a squash merge).

- `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e
'print(42)'` -> `42`).
- `bun run build:local -p '42'` links and runs against the local merged
WebKit.
- oven-sh/WebKit#383 preview build green on all 38 platform variants.
- `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`.
- New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass
with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC
lacks `Iterator.prototype.includes`, returns `""` for cyclic join,
`WebAssembly.Exception.length === 1`).

Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits
total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026).

- `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and
`CPU(NEEDS_ALIGNED_ACCESS)` deleted).
- `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now;
drops remaining 32-bit/x86 JIT refs).
- `232cebabc1f3` Remove big-endian support and platforms without
unaligned loads/stores (WTF + JSC).
- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator
(greedy is the only allocator now).
- `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD
follow-ups).
- `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic
`toString`/`join` now throws RangeError via stack check (spec-correct).
- `319f94b3db4a` Enable `Iterator.prototype.includes()` by default.
- `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute
`type` (module loader behavior change).
- `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc
APIs on ARM64 (perf + ABI of WTF alloc entry points).

**Runtime / builtins**
- `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow
checks.
- `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in
runtime.
- `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in
`JSObject::toString`.
- `960adeccefcd` Fast operation for `Array#shift`.
- `92c6650c7947` Add `JSArrayIterator::next` C++ helper.
- `cb1c48b3e95f` Extend `Array.from()` Set fast path to
`set.keys()/.values()`.
- `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path
ignored `Symbol.iterator` overrides.
- `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators.
- `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in
`JSON.stringify` string copy (same-type & upconvert).
- `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check.
- `2eb77e9c9473` BigInt: implement Crandall reduction.
- `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly.
- `319f94b3db4a` Enable `Iterator.prototype.includes()`.
- `0731b27c1b60` `Iterator.zip`: use null-prototype objects for
options/underlying iterator.
- `90b2ecf79ae3` `hostResolveImportedModule` respects module request
import-attribute `type`.
- `4f54300b848a` Collect diagnostics when `getDirect` returns zero
JSValue in `llint_slow_path_get_by_id`.

**Parser / bytecompiler**
- `c2beca7a439f` Lexer: scan integer tokens in a single pass.
- `72ea806faa21` Use overflow-safe range when choosing a switch jump
table.

**LLInt / DFG / FTL / B3**
- `29ceb3c03de3` Remove 32-bit JSValues.
- `857bd4334690` Remove ARMv7 JIT support.
- `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator.
- `68cde6ba2ad3` Make IRO (Air register allocation) faster.
- `83540481435f` DFG: allocate
`BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets.
- `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must
require original array structure for `InBoundsSaneChain`.
- `e759fa9dd063` LLInt: inline hot path of `op_enter`.
- `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for
BaseIndex operands.
- `4ebed2479144` Speed up `addSortedRange` via binary search.
- `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit.

**WebAssembly**
- `0d0080ea539d` Enable Memory64 feature flag.
- `15aa6fad53e3` Memory64: SIMD support.
- `bf0425598904` Memory64: expand declared memory limits.
- `862994e2cc37` Memory64: validate table import address-type match.
- `184ee4c654bd` Memory64: Table64 in OMG tier.
- `d202bedc5ff6` Memory64: Table64 in BBQ tier.
- `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+
`stack` getter, ctor length = 2).
- `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting,
icache barrier rework).
- `1803d6109d98` Speed up `WebAssembly.Table` construction.
- `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target
runs.
- `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`.
- `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales.

**Yarr / RegExp**
- `581f1d958329` Start end-anchored fixed-size regexps at the only
possible position.
- `a458a6c1f0a7` v-mode class-set op loop: stop early when no more
output possible.
- `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`.
- `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for
`ParenContext`.
- `1e43057f135a` Extend first-character filter further.
- `54916608d7d6` Fix non-BMP advance latch; simplify
`tryReadUnicodeCharImpl`.
- `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative
lookaheads.
- `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns.
- `98d0367d2247` Fix: `^` inside a paren that can match empty does not
anchor the pattern.

**Intl / Temporal**
- `09917ef55b0f` Add missing `U_FAILURE(status)` check in
`actualLunisolarMonthLength`.

**Inspector**
- `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d`
Canvas: instrument & record WebGPU devices/pipelines.
- `301d6b2b21f7` Associate WebAssembly module scripts with the fetching
resource.
- `28b979b1659b` / `479edb2e4395` Site Isolation: implement
`Network.loadResource` / `Network.getSerializedCertificate`.

- `232cebabc1f3` Remove big-endian support and
`CPU(NEEDS_ALIGNED_ACCESS)`.
- `e5fa5c604438` Upgrade fast_float to 8.2.10.
- `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII
case-conversion prefix copy.
- `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated
`find()`.
- `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table
off-by-one.
- `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64.
- `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`.
- `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`.
- `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete.
- `bf15f00ebe95` Remove 12 unused internal-linkage templates
(TypeTraits/HashTable/Vector/etc.).
- `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang
static analyzer.
- `158f737725b7` Add helpers for Darwin temp/cache directories.
- `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity).
- `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE
and fix findings.
- `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa".
- `cfb222f3c4d1` CMake: run `cleandead` at end of configuration.

- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64).
- `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in
`VMAllocate.cpp`.
- `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its
should-go-again result.
- `90cbe5e85528` libpas: fix benign read from a deallocated TLC.
- `e388877954d1` PGM allocator: fix uninitialized `free_status`
misclassifying OOB as UAF.
- `05c83a6550b7` libpas: fix
`MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling
MTE.
- `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage
(scavenging / zeroing / paged-out pages).

- **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed),
`857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas
removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)`
removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun
patches are now dead.
- **`VM` layout**: `f2f2c2ddf637` deletes
`StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields
from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws
`RangeError` instead of returning `""`.
- **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule`
to propagate the import-attribute `type` — check Bun's module loader
hook signatures.
- **Register allocator**: `bfb1b1183bc2` removes the B3/Air
graph-coloring allocator and its `Options::` toggle.
- **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds
`__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. —
affects anything calling these across the WTF boundary on arm64.
- **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as
private-only; `WebAssembly.Exception` constructor `length` becomes 2 and
gains a `stack` prototype getter.
- **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default;
`319f94b3db4a` `Iterator.prototype.includes` on by default.
- **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee
publication and adds `Thread::barrierInstructionCache()` in WTF.

<!-- robobun:evidence:begin -->

---

**[decide:webkit]** gate passed · iteration 2 · 8 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: BUILD FAILED (no junit output)
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
ninja: Entering directory `/workspace/bun/build/debug'
[1/182] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/182] gen cpp.rs (cppbind)
[3/182] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt
[4/182] gen JS modules (bundle-modules)
Preprocess modules (8715ms)
Bundle modules (63ms)
Postprocesss modules (24ms)
Bundle Functions (746ms)
Generate Code (12ms)

[9.57s] Bundled "src/js" for development
  2749 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

[177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o
FAILED: obj/unified/UnifiedSou
... (truncated)

release without fix: all passed
bun test v1.4.0-canary.1 (385f528)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [152.00ms]
__F:0:S:0
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
bun test v1.4.0 (59b0de0)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [3.17s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 676ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/140] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/140] gen cpp.rs (cppbind)
[3/140] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[4/140] gen JS modules (bundle-modules)
Preprocess modules (8727ms)
Bundle modules (51ms)
Postprocesss modules (106ms)
Bundle Functions (687ms)
Generate Code (20ms)

[9.61s] Bundled "src/js" for production
  2559 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

^[[1m^[[92m   Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
^[[1m^[[92m   Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime)
^[[1m^[[92m   Compilin
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
scripts/build/deps/webkit.ts                     |   2 +-
 src/bundler/analyze_transpiled_module.rs         |  38 +++--
 src/bundler/linker_context/postProcessJSChunk.rs |   8 +-
 src/bundler_jsc/analyze_jsc.rs                   | 135 ++++++++++++----
 src/js_printer/lib.rs                            | 191 +++++++++++++++++------
 src/jsc/RuntimeTranspilerCache.rs                |   5 +-
 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp  |  39 +++--
 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts  | 106 +++++++++++++
 8 files changed, 416 insertions(+), 108 deletions(-)
```

</details>

**gate history** · 5 passed · 1 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                              reads  edits  tests
scripts/build/deps/webkit.ts                          1      1      0
src/bundler/analyze_transpiled_module.rs              3      3      0
src/bundler/linker_context/postProcessJSChunk.rs      1      1      0
src/bundler_jsc/analyze_jsc.rs                       13     15      0
src/js_printer/lib.rs                                 9     16      0
src/jsc/RuntimeTranspilerCache.rs                     2      3      0
src/jsc/bindings/BunAnalyzeTranspiledModule.cpp       8     12      0
test/js/bun/jsc/webkit-upgrade-3722912f.test.ts       2      5      0
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
liooil pushed a commit to liooil/poly that referenced this pull request Aug 7, 2026
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800
(2026-08-02) via oven-sh/WebKit#383.

oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge
commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`.

## Bun-side changes

Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier,
ScriptFetchParameters::Type)` and threads the type through
`ImportEntry`, `ExportEntry`, `StarExportEntry`, and
`ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the
`BunTranspiledModule` path), Bun'''s synthesized record must agree with
what JSC'''s own `ModuleAnalyzer` would produce from the printed source;
a mismatch fails the BUN_DEBUG record diff in debug and null-derefs
`hostResolveImportedModule` in release.

- `analyze_transpiled_module` / `js_printer`: every `RecordKind` now
carries one trailing `FetchParameters` slot. `add_import_info_*` and
`add_export_info_*` accept it; `finalize()` propagates the source
import'''s slot through the Local->Indirect conversion.
`RequestedModules` dedupes on `(specifier, Type, phase)`.
- `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and
passes it to every `addImportEntry*` / `addIndirectExport` /
`addNamespaceExport` / `addStarExport`; buffer validation is per-slot so
only the trailing slot accepts the wider `FetchParameters` sentinel
range.
- `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` /
`add*Export` functions take `uint8_t moduleRequestType` and set
`.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for
import/export/star entries; `static_assert` pins the ordinal values
`to_script_fetch_parameters_type()` hardcodes.
- `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout
change).

## WebKit-side changes (oven-sh/WebKit#383)

- 17 merge conflicts resolved in JSC/WTF; fork's
`USE(BUN_JSC_ADDITIONS)` hunks preserved.
- Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64`
macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`).
- `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic`
in new `scriptTypeForScript` switch.
- Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352
was a squash merge).

## How did you verify your code works?

- `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e
'print(42)'` -> `42`).
- `bun run build:local -p '42'` links and runs against the local merged
WebKit.
- oven-sh/WebKit#383 preview build green on all 38 platform variants.
- `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`.
- New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass
with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC
lacks `Iterator.prototype.includes`, returns `""` for cyclic join,
`WebAssembly.Exception.length === 1`).

## JavaScriptCore/WTF/bmalloc changes since 01aaa3e0be0c (Jul 25)

Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits
total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026).

### Highlights

- `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and
`CPU(NEEDS_ALIGNED_ACCESS)` deleted).
- `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now;
drops remaining 32-bit/x86 JIT refs).
- `232cebabc1f3` Remove big-endian support and platforms without
unaligned loads/stores (WTF + JSC).
- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator
(greedy is the only allocator now).
- `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD
follow-ups).
- `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic
`toString`/`join` now throws RangeError via stack check (spec-correct).
- `319f94b3db4a` Enable `Iterator.prototype.includes()` by default.
- `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute
`type` (module loader behavior change).
- `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc
APIs on ARM64 (perf + ABI of WTF alloc entry points).

### JavaScriptCore

**Runtime / builtins**
- `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow
checks.
- `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in
runtime.
- `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in
`JSObject::toString`.
- `960adeccefcd` Fast operation for `Array#shift`.
- `92c6650c7947` Add `JSArrayIterator::next` C++ helper.
- `cb1c48b3e95f` Extend `Array.from()` Set fast path to
`set.keys()/.values()`.
- `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path
ignored `Symbol.iterator` overrides.
- `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators.
- `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in
`JSON.stringify` string copy (same-type & upconvert).
- `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check.
- `2eb77e9c9473` BigInt: implement Crandall reduction.
- `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly.
- `319f94b3db4a` Enable `Iterator.prototype.includes()`.
- `0731b27c1b60` `Iterator.zip`: use null-prototype objects for
options/underlying iterator.
- `90b2ecf79ae3` `hostResolveImportedModule` respects module request
import-attribute `type`.
- `4f54300b848a` Collect diagnostics when `getDirect` returns zero
JSValue in `llint_slow_path_get_by_id`.

**Parser / bytecompiler**
- `c2beca7a439f` Lexer: scan integer tokens in a single pass.
- `72ea806faa21` Use overflow-safe range when choosing a switch jump
table.

**LLInt / DFG / FTL / B3**
- `29ceb3c03de3` Remove 32-bit JSValues.
- `857bd4334690` Remove ARMv7 JIT support.
- `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator.
- `68cde6ba2ad3` Make IRO (Air register allocation) faster.
- `83540481435f` DFG: allocate
`BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets.
- `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must
require original array structure for `InBoundsSaneChain`.
- `e759fa9dd063` LLInt: inline hot path of `op_enter`.
- `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for
BaseIndex operands.
- `4ebed2479144` Speed up `addSortedRange` via binary search.
- `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit.

**WebAssembly**
- `0d0080ea539d` Enable Memory64 feature flag.
- `15aa6fad53e3` Memory64: SIMD support.
- `bf0425598904` Memory64: expand declared memory limits.
- `862994e2cc37` Memory64: validate table import address-type match.
- `184ee4c654bd` Memory64: Table64 in OMG tier.
- `d202bedc5ff6` Memory64: Table64 in BBQ tier.
- `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+
`stack` getter, ctor length = 2).
- `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting,
icache barrier rework).
- `1803d6109d98` Speed up `WebAssembly.Table` construction.
- `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target
runs.
- `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`.
- `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales.

**Yarr / RegExp**
- `581f1d958329` Start end-anchored fixed-size regexps at the only
possible position.
- `a458a6c1f0a7` v-mode class-set op loop: stop early when no more
output possible.
- `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`.
- `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for
`ParenContext`.
- `1e43057f135a` Extend first-character filter further.
- `54916608d7d6` Fix non-BMP advance latch; simplify
`tryReadUnicodeCharImpl`.
- `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative
lookaheads.
- `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns.
- `98d0367d2247` Fix: `^` inside a paren that can match empty does not
anchor the pattern.

**Intl / Temporal**
- `09917ef55b0f` Add missing `U_FAILURE(status)` check in
`actualLunisolarMonthLength`.

**Inspector**
- `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d`
Canvas: instrument & record WebGPU devices/pipelines.
- `301d6b2b21f7` Associate WebAssembly module scripts with the fetching
resource.
- `28b979b1659b` / `479edb2e4395` Site Isolation: implement
`Network.loadResource` / `Network.getSerializedCertificate`.

### WTF

- `232cebabc1f3` Remove big-endian support and
`CPU(NEEDS_ALIGNED_ACCESS)`.
- `e5fa5c604438` Upgrade fast_float to 8.2.10.
- `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII
case-conversion prefix copy.
- `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated
`find()`.
- `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table
off-by-one.
- `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64.
- `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`.
- `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`.
- `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete.
- `bf15f00ebe95` Remove 12 unused internal-linkage templates
(TypeTraits/HashTable/Vector/etc.).
- `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang
static analyzer.
- `158f737725b7` Add helpers for Darwin temp/cache directories.
- `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity).
- `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE
and fix findings.
- `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa".
- `cfb222f3c4d1` CMake: run `cleandead` at end of configuration.

### bmalloc

- `6eaa5ac1f65d` Remove 32-bit libpas support.
- `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64).
- `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in
`VMAllocate.cpp`.
- `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its
should-go-again result.
- `90cbe5e85528` libpas: fix benign read from a deallocated TLC.
- `e388877954d1` PGM allocator: fix uninitialized `free_status`
misclassifying OOB as UAF.
- `05c83a6550b7` libpas: fix
`MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling
MTE.
- `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage
(scavenging / zeroing / paged-out pages).

### Breaking/notable for Bun

- **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed),
`857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas
removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)`
removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun
patches are now dead.
- **`VM` layout**: `f2f2c2ddf637` deletes
`StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields
from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws
`RangeError` instead of returning `""`.
- **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule`
to propagate the import-attribute `type` — check Bun's module loader
hook signatures.
- **Register allocator**: `bfb1b1183bc2` removes the B3/Air
graph-coloring allocator and its `Options::` toggle.
- **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds
`__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. —
affects anything calling these across the WTF boundary on arm64.
- **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as
private-only; `WebAssembly.Exception` constructor `length` becomes 2 and
gains a `stack` prototype getter.
- **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default;
`319f94b3db4a` `Iterator.prototype.includes` on by default.
- **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee
publication and adds `Thread::barrierInstructionCache()` in WTF.

<!-- robobun:evidence:begin -->

---

**[decide:webkit]** gate passed · iteration 2 · 8 files touched

<details><summary>fails on main (without fix)</summary>

```console
ASAN without fix: BUILD FAILED (no junit output)
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
ninja: Entering directory `/workspace/bun/build/debug'
[1/182] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/182] gen cpp.rs (cppbind)
[3/182] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt
[4/182] gen JS modules (bundle-modules)
Preprocess modules (8715ms)
Bundle modules (63ms)
Postprocesss modules (24ms)
Bundle Functions (746ms)
Generate Code (12ms)

[9.57s] Bundled "src/js" for development
  2749 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

[177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o
FAILED: obj/unified/UnifiedSou
... (truncated)

release without fix: all passed
bun test v1.4.0-canary.1 (385f52890)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [152.00ms]
__F:0:S:0
```

</details>

<details><summary>passes on PR (with fix)</summary>

```console
ASAN with fix: all passed
$ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts"
bun test v1.4.0 (59b0de097)

test/js/bun/jsc/webkit-upgrade-3722912f.test.ts:
(pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms]
(pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms]
(pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms]
(pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms]
(pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms]

 5 pass
 0 fail
 12 expect() calls
Ran 5 tests across 1 file. [3.17s]
__F:0:S:0

release with fix: all passed
$ bun scripts/build.ts --profile=release
[configured] bun-profile → bun (stripped) in 676ms (unchanged)
ninja: Entering directory `/workspace/bun/build/release'
[1/140] gen generated_host_exports.rs
generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited
[2/140] gen cpp.rs (cppbind)
[3/140] gen JSSink.{cpp,h,lut.h,rs}
generated_jssink.rs: 7 sinks, 84 exported symbols
Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt
[4/140] gen JS modules (bundle-modules)
Preprocess modules (8727ms)
Bundle modules (51ms)
Postprocesss modules (106ms)
Bundle Functions (687ms)
Generate Code (20ms)

[9.61s] Bundled "src/js" for production
  2559 kb
  193 internal modules
  13 native modules
  90 internal functions across 19 files
[4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu)

  nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19)

^[[1m^[[92m   Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core)
^[[1m^[[92m   Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime)
^[[1m^[[92m   Compilin
... (truncated)
```

</details>

<details><summary>diff hotspot</summary>

```
scripts/build/deps/webkit.ts                     |   2 +-
 src/bundler/analyze_transpiled_module.rs         |  38 +++--
 src/bundler/linker_context/postProcessJSChunk.rs |   8 +-
 src/bundler_jsc/analyze_jsc.rs                   | 135 ++++++++++++----
 src/js_printer/lib.rs                            | 191 +++++++++++++++++------
 src/jsc/RuntimeTranspilerCache.rs                |   5 +-
 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp  |  39 +++--
 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts  | 106 +++++++++++++
 8 files changed, 416 insertions(+), 108 deletions(-)
```

</details>

**gate history** · 5 passed · 1 rejected · iteration 2

<details><summary>evidence per changed file</summary>

```
file                                              reads  edits  tests
scripts/build/deps/webkit.ts                          1      1      0
src/bundler/analyze_transpiled_module.rs              3      3      0
src/bundler/linker_context/postProcessJSChunk.rs      1      1      0
src/bundler_jsc/analyze_jsc.rs                       13     15      0
src/js_printer/lib.rs                                 9     16      0
src/jsc/RuntimeTranspilerCache.rs                     2      3      0
src/jsc/bindings/BunAnalyzeTranspiledModule.cpp       8     12      0
test/js/bun/jsc/webkit-upgrade-3722912f.test.ts       2      5      0
```

</details>

<!-- robobun:evidence:end -->

---------

Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.