Upgrade to upstream WebKit 01aaa3e0be0c - #352
Conversation
…essibility relations https://bugs.webkit.org/show_bug.cgi?id=319937 rdar://182309307 Reviewed by Dominic Mazzoni and Chris Fleizach. When accessibility relations are rebuilt, updateRelationsIfNeeded() iterates m_elementsWithRelationAttributes, which can hold detached elements. For an origin that is not in a tree scope, Element::elementsArrayForAttributeInternal() cannot use the TreeScope id map and falls back to getElementByIdIncludingDisconnected(), which linearly scans the entire detached subtree once per referenced id. On pages with large detached subtrees that carry ARIA relation attributes, this can severely harm performance. Fix this by skipping resolution of relations for origins that are not in a tree scope. Such elements have no accessibility object, so their relations have no consumer. Additionally, this commit reduces how often relations are rebuilt. performDeferredCacheUpdate() used to mark all relations dirty on every id-attribute change, forcing a full rebuild, regardless of whether that id was part of a relation. Now we track every id referenced by a relation attribute (resolved or not) in a new m_referencedRelationTargetIds set and only dirty relations when a changed id can actually affect one. * LayoutTests/accessibility/aria-relations-disconnected-subtree-no-timeout-expected.txt: Added. * LayoutTests/accessibility/aria-relations-disconnected-subtree-no-timeout.html: Added. * Source/WebCore/accessibility/AXObjectCache.cpp: (WebCore::AXObjectCache::performDeferredCacheUpdate): (WebCore::AXObjectCache::updateRelationsIfNeeded): (WebCore::AXObjectCache::idChangeCanAffectRelations const): (WebCore::AXObjectCache::addRelation): (WebCore::AXObjectCache::addLabelForRelation): * Source/WebCore/accessibility/AXObjectCache.h: Canonical link: https://commits.webkit.org/317690@main
https://bugs.webkit.org/show_bug.cgi?id=319944 rdar://182860876 Reviewed by Alex Christensen. The imported WPT idlharness harness (webidl2.js@e6d8ab8) requires the single-token "async_iterable" WebIDL syntax and emits a validation error for the older two-token "async iterable" syntax. The imported dependency IDL files streams.idl and fs.idl still used the old syntax, so every idl_test that pulls in streams.idl recorded a spurious "FAIL idl_test validation" line, affecting idlharness expected files across compression, encoding, fs, streams, webrtc-encoded-transform, and webtransport. Update both imported IDL files to the async_iterable syntax and rebaseline the affected idlharness expected files. The new IDL matches upstream web-platform-tests, taken from commit 14c7ae5dd9a2c7f726ed51f968dc2340cb4fbe74 (2025-08-20, "Sync interfaces/ with @webref/idl 3.66.2", WebKit#54029), which updated both interfaces/streams.idl and interfaces/fs.idl to async_iterable. Covered by existing tests (the rebaselined idlharness tests). * LayoutTests/imported/w3c/web-platform-tests/compression/idlharness.https.any-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/compression/idlharness.https.any.worker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.serviceworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.sharedworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/encoding/idlharness.any.worker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/fs/idlharness.https.any-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/fs/idlharness.https.any.worker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/interfaces/fs.idl: * LayoutTests/imported/w3c/web-platform-tests/interfaces/streams.idl: * LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.serviceworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.sharedworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/streams/idlharness.any.worker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/webrtc-encoded-transform/idlharness.https.window-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.serviceworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.sharedworker-expected.txt: * LayoutTests/imported/w3c/web-platform-tests/webtransport/idlharness.https.sub.any.worker-expected.txt: Canonical link: https://commits.webkit.org/317691@main
…-space-trim-inline-block.html is failing since added in 317172@main https://bugs.webkit.org/show_bug.cgi?id=319954 Unreviewed test gardening. * LayoutTests/platform/glib/TestExpectations: Canonical link: https://commits.webkit.org/317692@main
… after showing the keyboard in iPhone Mirroring https://bugs.webkit.org/show_bug.cgi?id=319948 rdar://181639089 Reviewed by Abrar Rahman Protyasha. Revert the changes in 314741@main for now; this caused the keyboard on iOS to dismiss immediately after focusing a text field in iPhone Mirroring mode, from macOS. * LayoutTests/editing/selection/ios/select-text-by-long-press-with-focused-element-expected.txt: Removed. * LayoutTests/editing/selection/ios/select-text-by-long-press-with-focused-element.html: Removed. * LayoutTests/editing/selection/ios/select-text-by-long-press-with-hardware-keyboard-expected.txt: Removed. * LayoutTests/editing/selection/ios/select-text-by-long-press-with-hardware-keyboard.html: Removed. * LayoutTests/editing/selection/ios/tap-focused-input-clears-outside-selection-expected.txt: Removed. * LayoutTests/editing/selection/ios/tap-focused-input-clears-outside-selection.html: Removed. * Source/WebKit/UIProcess/ios/WKContentViewInteraction.h: * Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm: (-[WKContentView cleanUpInteraction]): (-[WKContentView textInteractionGesture:shouldBeginAtPoint:]): (-[WKContentView selectPositionAtPoint:completionHandler:]): (-[WKContentView _selectPositionAtPoint:stayingWithinFocusedElement:completionHandler:]): (-[WKContentView _hideKeyboard:]): (-[WKContentView _elementDidBlur]): (-[WKContentView _updateSelectionAssistantSuppressionState]): Canonical link: https://commits.webkit.org/317693@main
…ail surrogate, not after https://bugs.webkit.org/show_bug.cgi?id=319932 Reviewed by Yusuke Suzuki. reread() returns errorCodePoint for a trail surrogate whose *following* code unit is a lead. The error case is a read landing in the middle of a pair, so it must look at the preceding unit; readCheckedDontAdvance() already does this. tryConsumeBackReference() rereads the captured text, and errorCodePoint there fails the backreference unconditionally. Patterns with a lookbehind always run in the interpreter, so this reproduces with default options: var unit = "\uDC00\uD800a"; /(?<=^)(...)\1/u.test(unit + unit); // false, should be true Also move the from + 1 < length check into the lead branch, so that a trail surrogate at the end of the input is still checked. Introduced in 280563@main. Test: JSTests/stress/regexp-backreference-lone-trail-then-lone-lead.js * JSTests/stress/regexp-backreference-lone-trail-then-lone-lead.js: Added. (shouldBe): * Source/JavaScriptCore/yarr/YarrInterpreter.cpp: (JSC::Yarr::Interpreter::InputStream::reread): Canonical link: https://commits.webkit.org/317694@main
…selection has a decoration. https://bugs.webkit.org/show_bug.cgi?id=319947 rdar://182864748 Reviewed by Wenson Hsieh. hasDecoration in paintForegroundAndDecorations only accounted for the originating element, custom highlights, and spelling/grammar — not ::selection. So when text had no decoration of its own and only ::selection did, the decoration-paint path was skipped and the selection's decoration never painted. Add a hasSelectionDecoration check so the path runs, making selection-text-decoration-currentcolor.html and target-text-005.html pass. imported/w3c/web-platform-tests/css/css-pseudo/selection-text-decoration-currentcolor.html imported/w3c/web-platform-tests/css/css-pseudo/target-text-005.html * LayoutTests/TestExpectations: * LayoutTests/platform/ios/TestExpectations: * Source/WebCore/rendering/TextBoxPainter.cpp: (WebCore::TextBoxPainter::paintForegroundAndDecorations): Canonical link: https://commits.webkit.org/317695@main
rdar://182509958 https://bugs.webkit.org/show_bug.cgi?id=319666 Reviewed by Andy Estes and Jean-Yves Avenard. We update the project to include asm and .S files. We exclude them for non arm64/arm64e builds. We update Source/WebCore/PAL/ThirdParty/dav1d/config.h to enable ASM for arm64. We add Source/WebCore/PAL/ThirdParty/dav1d/config folder from upstream repo as it is useful to update Source/WebCore/PAL/ThirdParty/dav1d/config.h. Covered by existing tests. * Source/WebCore/PAL/ThirdParty/dav1d/Configurations/dav1d.xcconfig: * Source/WebCore/PAL/ThirdParty/dav1d/config.h: * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/arm/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/arm64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x64/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x86/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/apple/x86/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux-noasm/generic/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux-noasm/x64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/arm/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/arm64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/riscv64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/riscv64/cpu-renamed.c: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x64/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x86/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/linux/x86/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/win/arm64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/win/x64/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/win/x64/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/win/x86/config.asm: Added. * Source/WebCore/PAL/ThirdParty/dav1d/config/win/x86/config.h: Added. * Source/WebCore/PAL/ThirdParty/dav1d/dav1d.xcodeproj/project.pbxproj: Canonical link: https://commits.webkit.org/317696@main
…OMAgent https://bugs.webkit.org/show_bug.cgi?id=X rdar://179248483 Reviewed by Qianlang Chen. Under Site Isolation a cross-origin iframe's DOM lives in a separate WebProcess with its own FrameDOMAgent. The DOM.shadowRootPushed and shadowRootPopped events are fired through InstrumentingAgents, which only notified the page-level agent, so attaching a shadow root inside a cross- origin iframe reached no agent for that frame -- and even when it did, the frontend dropped it for a FrameTarget. The shadow root never appeared in the Elements tree. didPushShadowRootImpl and willPopShadowRootImpl now resolve the host's frame and notify that frame's persistentFrameDOMAgent before falling through to the page agent, matching the branch already used by the sibling per-node hooks (didModifyDOMAttr, didInsertDOMNode). The main frame has no persistentFrameDOMAgent and the page agent's boundNodeId() guard suppresses subframe hosts, so there is no double-fire. DOM.json widens both events' targetTypes from ["page"] to ["frame","page"] so the generated dispatcher accepts them from a FrameTarget; FrameDOMAgent already implemented didPushShadowRoot/willPopShadowRoot. On the frontend, DOMObserver replaces the two FrameTarget FIXME early-returns with _frameTargetShadowRootPushed/_frameTargetShadowRootPopped, modeled on _frameTargetChildNodeInserted/Removed. They scope the shadow-root WI.DOMNode to the owning frame target (target.identifier + ":" + nodeId) so colliding raw NodeIds across frames stay distinct. shadowRootPopped is wired but has no end-to-end test: author shadow roots have no scriptable detach, so willPopShadowRoot only fires on host destruction, and removing the host first unbinds the root (FrameDOMAgent::unbind), leaving boundNodeId 0 so the backend suppresses the event. Tests: http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target.html http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target.html * LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-child-frame.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-frame.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/resources/shadow-root-grandchild-frame.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target-expected.txt: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-cross-frame-isolation-frame-target.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target-expected.txt: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/shadow-root-pushed-frame-target.html: Added. * Source/JavaScriptCore/inspector/protocol/DOM.json: * Source/WebCore/inspector/InspectorInstrumentation.cpp: (WebCore::InspectorInstrumentation::didPushShadowRootImpl): (WebCore::InspectorInstrumentation::willPopShadowRootImpl): * Source/WebInspectorUI/UserInterface/Controllers/DOMManager.js: (WI.DOMManager.prototype._frameTargetShadowRootPushed): (WI.DOMManager.prototype._frameTargetShadowRootPopped): * Source/WebInspectorUI/UserInterface/Protocol/DOMObserver.js: (WI.DOMObserver.prototype.shadowRootPushed): (WI.DOMObserver.prototype.shadowRootPopped): Canonical link: https://commits.webkit.org/317697@main
https://bugs.webkit.org/show_bug.cgi?id=315597 rdar://177978474 Reviewed by Qianlang Chen. Replace WI.DOMUndoCoordinator's single _lastEditTarget slot with a pair of LIFO target stacks that record one entry per edit, in order. Each edit's target — the main page or a cross-origin iframe — is pushed when didEdit is called. undo pops the top, dispatches to that target's DOMAgent, and pushes to the redo stack on completion; redo is the symmetric inverse. Empty-stack undo and redo fall back to the main target as a no-op without pushing onto either stack. TargetRemoved filters both stacks so a torn-down frame can't be popped later. End-user effect: edit a node in a cross-origin iframe, edit a node on the main page, press Cmd+Z — the main edit reverses; press Cmd+Z again, the iframe edit reverses. The existing single-target dispatch test is updated to await the now- async undo/redo entry points. Test: http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator.html * LayoutTests/http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator-expected.txt: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/cross-frame-undo-coordinator.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/undo-coordinator-frame-target-expected.txt: * LayoutTests/http/tests/site-isolation/inspector/dom/undo-coordinator-frame-target.html: * Source/WebInspectorUI/UserInterface/Controllers/DOMUndoCoordinator.js: (WI.DOMUndoCoordinator): (WI.DOMUndoCoordinator.prototype.didEdit): (WI.DOMUndoCoordinator.prototype.markUndoableState): (WI.DOMUndoCoordinator.prototype.undo): (WI.DOMUndoCoordinator.prototype.redo): (WI.DOMUndoCoordinator.prototype._performOperationSoon): (WI.DOMUndoCoordinator.prototype.async _undo): (WI.DOMUndoCoordinator.prototype.async _redo): (WI.DOMUndoCoordinator.prototype._handleTargetRemoved): Canonical link: https://commits.webkit.org/317698@main
…o-element events to Frame Targets https://bugs.webkit.org/show_bug.cgi?id=NNNNNN rdar://179176056 Reviewed by Qianlang Chen. Web Inspector's Elements tree for an out-of-process iframe went stale on these lifecycle changes: - DOM.customElementStateChanged - DOM.pseudoElementAdded - DOM.pseudoElementRemoved They were stubbed off at every layer for the frame target: the protocol declared them "page"-only, InspectorInstrumentation routed them only to the page-level persistentDOMAgent(), and the frontend DOMObserver early-returned with a FIXME for FrameTarget. FrameDOMAgent already had complete, correct implementations of all three methods, so this is a pure wiring change, not a new feature. This adds the missing routing following the existing convention used by didInsertDOMNode / didModifyDOMAttr (notify the frame's own FrameDOMAgent, then the page agent), declares the events for the frame target, and adds the scoped-id frontend handlers so the iframe's Elements tree stays live. The added layout test deliberately covers multiple, repeated, and interleaved scenarios rather than a single event per type, since these handlers manage per-node and per-pseudo-type state: two custom elements upgraded back-to-back (no cross-contamination), ::before and ::after coexisting, targeted single-pseudo removal leaving the sibling intact, and an add/remove/re-add cycle guarding against stale-node leaks. It also documents that one upgrade legitimately emits two transitions (FailedOrPrecustomized then Custom), which the frame target relays just like the page target. Test: http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target.html * LayoutTests/http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target-expected.txt: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/custom-elements-and-pseudo-elements-frame-target.html: Added. * LayoutTests/http/tests/site-isolation/inspector/dom/resources/custom-elements-and-pseudo-elements-frame.html: Added. * Source/JavaScriptCore/inspector/protocol/DOM.json: * Source/WebCore/inspector/InspectorInstrumentation.cpp: (WebCore::InspectorInstrumentation::didChangeCustomElementStateImpl): (WebCore::InspectorInstrumentation::pseudoElementCreatedImpl): (WebCore::InspectorInstrumentation::pseudoElementDestroyedImpl): * Source/WebInspectorUI/UserInterface/Controllers/DOMManager.js: (WI.DOMManager.prototype._frameTargetCustomElementStateChanged): (WI.DOMManager.prototype._frameTargetPseudoElementAdded): (WI.DOMManager.prototype._frameTargetPseudoElementRemoved): * Source/WebInspectorUI/UserInterface/Protocol/DOMObserver.js: (WI.DOMObserver.prototype.customElementStateChanged): (WI.DOMObserver.prototype.pseudoElementAdded): (WI.DOMObserver.prototype.pseudoElementRemoved): Canonical link: https://commits.webkit.org/317699@main
…toBuffer()` https://bugs.webkit.org/show_bug.cgi?id=319673 Reviewed by Sosuke Suzuki. This change is related to only the fast path of `Array#flat()`. `resultIndex` is 8-bytes (`uint64_t`). It's enough small size. Interestingly, this change has a side-effect which is a micro benchmark progression on macOS arm64 at least. TipOfTree Patched array-prototype-flat-depth-1-string 124.7313+-15.7674 ? 126.7053+-14.0930 ? might be 1.0158x slower array-prototype-flat-depth-1-double 85.8047+-8.6982 ? 88.9680+-4.1780 ? might be 1.0369x slower array-prototype-flat-large-nested 45.0930+-2.4765 ^ 27.1562+-1.0824 ^ definitely 1.6605x faster array-prototype-flat-huge-arrays 10.5353+-1.8040 10.0453+-1.7224 might be 1.0488x faster array-prototype-flat-small-arrays 3.4522+-0.1238 3.3026+-0.0755 might be 1.0453x faster array-prototype-flat-depth-infinity 117.2919+-1.0095 117.0930+-0.6006 array-prototype-flat-depth-2 94.7117+-1.3260 ? 95.6852+-4.3372 ? might be 1.0103x slower array-prototype-flat-depth-1-int32 85.2135+-4.3134 ? 88.4635+-2.5566 ? might be 1.0381x slower array-prototype-flat-depth-3 105.7020+-7.5027 102.3541+-4.5175 might be 1.0327x faster array-prototype-flat-sparse-array 152.1396+-3.2477 ? 161.3152+-11.0580 ? might be 1.0603x slower array-prototype-flat-depth-1-mixed 93.9877+-4.2939 ? 94.3616+-4.7335 ? <geometric> 57.9736+-0.6088 ^ 55.5547+-0.9141 ^ definitely 1.0435x faster No new tests. It wlll be covered by exist test cases. Canonical link: https://commits.webkit.org/317700@main
… ENABLE_INSPECTOR_NETWORK_THROTTLING is enabled https://bugs.webkit.org/show_bug.cgi?id=319487 Reviewed by Devin Rousso. Move the owned std::optional<int64_t> when forwarding it to WebInspectorUIProxy::setEmulatedConditions(). WebInspectorBackendProxy owns the std::optional by value but forwards it to a function taking std::optional<int64_t>&&, causing compilation to fail when ENABLE_INSPECTOR_NETWORK_THROTTLING is enabled. Forward the optional using WTF::move(). * Source/WebKit/UIProcess/Inspector/WebInspectorBackendProxy.cpp: (WebKit::WebInspectorBackendProxy::setEmulatedConditions): Canonical link: https://commits.webkit.org/317701@main
…omed lengths https://bugs.webkit.org/show_bug.cgi?id=319905 Reviewed by Antoine Quint. Converts the view-timeline-inset CSS property to use unzoomed lengths. New test added showing view-timeline-inset working properly with inherited + zoomed values. Tests: imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset.html * LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/reference/view-timeline-inset-ref.html: Added. * LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset-expected.html: Added. * LayoutTests/imported/w3c/web-platform-tests/css/css-viewport/zoom/view-timeline-inset.html: Added. * Source/WebCore/Headers.cmake: * Source/WebCore/WebCore.xcodeproj/project.pbxproj: * Source/WebCore/animation/CSSAnimation.cpp: * Source/WebCore/animation/ResolvableViewTimelineInsets.h: Added. * Source/WebCore/animation/StyleOriginatedTimelinesController.cpp: * Source/WebCore/animation/StyleOriginatedTimelinesController.h: * Source/WebCore/animation/ViewTimeline.cpp: * Source/WebCore/animation/ViewTimeline.h: * Source/WebCore/style/Styleable.cpp: * Source/WebCore/style/values/scroll-animations/StyleViewTimelineInsetItem.h: Canonical link: https://commits.webkit.org/317702@main
https://bugs.webkit.org/show_bug.cgi?id=319974 Unreviewed test gardening. * LayoutTests/platform/wpe/TestExpectations: Canonical link: https://commits.webkit.org/317703@main
https://bugs.webkit.org/show_bug.cgi?id=319949 Unreviewed test gardening. This test was marked as expected to crash in glib/TestExpectations in 317682@main but there was an override of in wpe/TestExpectations. Temporarily comment out the override. * LayoutTests/platform/wpe/TestExpectations: Canonical link: https://commits.webkit.org/317704@main
…networkConnectionToWebProcess rdar://182761259 https://bugs.webkit.org/show_bug.cgi?id=319968 Reviewed by Chris Dumez. WebSWServerConnection sometimes calls networkProcess() asynchronously following an IPC message, for instance in WebSWServerConnection::postMessageToServiceWorkerClient. In that case, there is no guarantee that m_networkConnectionToWebProcess is not nullptr and calling WebSWServerConnection::networkProcess should return nullptr. We change WebSWServerConnection::networkProcess to account for this and return a NetworkProcess pointer instead of a ref. At call sites, we check for networkProcess being nullptr for async cases. Covered by existing tests. * Source/WebKit/NetworkProcess/ServiceWorker/WebSWServerConnection.cpp: (WebKit::WebSWServerConnection::networkProcess): (WebKit::WebSWServerConnection::sharedPreferencesForWebProcess const): (WebKit::WebSWServerConnection::resolveUnregistrationJobInClient): * Source/WebKit/NetworkProcess/ServiceWorker/WebSWServerConnection.h: Canonical link: https://commits.webkit.org/317705@main
https://bugs.webkit.org/show_bug.cgi?id=312461 Reviewed by Carlos Garcia Campos. This change unifies the default font rendering settings between GTK and WPE. To be more precise, it changes the WPE's default value for subpixel layout from RGB to NONE so that it matches the default from FontRenderOptions that is used by GTK normally. Canonical link: https://commits.webkit.org/317706@main
rdar://182400674 https://bugs.webkit.org/show_bug.cgi?id=319570 Reviewed by Chris Dumez. WebTransport is subclassing WritableStreamDefaultWriter in WebTransportWriter. To prepare for implementing WebTransportWriter, we make WritableStreamDefaultWriter a standard C++ class instead of a JS built-in. We beef up InternalWritableStreamWriter to support more bindings API and we forward WritableStreamDefaultWriter calls to InternalWritableStreamWriter. Covered by existing tests. * Source/WebCore/CMakeLists.txt: * Source/WebCore/DerivedSources-input.xcfilelist: * Source/WebCore/DerivedSources-output.xcfilelist: * Source/WebCore/DerivedSources.make: * Source/WebCore/Modules/streams/WritableStream.cpp: (WebCore::WritableStream::getWriter): (WebCore::JSWritableStream::getWriter): Deleted. * Source/WebCore/Modules/streams/WritableStream.h: * Source/WebCore/Modules/streams/WritableStream.idl: * Source/WebCore/Modules/streams/WritableStreamDefaultWriter.cpp: Added. (WebCore::WritableStreamDefaultWriter::create): (WebCore::WritableStreamDefaultWriter::WritableStreamDefaultWriter): (WebCore::WritableStreamDefaultWriter::desiredSize): (WebCore::WritableStreamDefaultWriter::releaseLock): (WebCore::JSWritableStreamDefaultWriter::closed const): (WebCore::JSWritableStreamDefaultWriter::ready const): (WebCore::JSWritableStreamDefaultWriter::abort): (WebCore::JSWritableStreamDefaultWriter::close): (WebCore::JSWritableStreamDefaultWriter::write): * Source/WebCore/Modules/streams/WritableStreamDefaultWriter.h: Added. (WebCore::WritableStreamDefaultWriter::internalWriter): * Source/WebCore/Modules/streams/WritableStreamDefaultWriter.idl: * Source/WebCore/Modules/streams/WritableStreamDefaultWriter.js: Removed. * Source/WebCore/Modules/streams/WritableStreamInternals.js: (acquireWritableStreamDefaultWriter): (writableStreamDefaultWriterClosedForBindings): (writableStreamDefaultWriterReadyForBindings): (writableStreamDefaultWriterDesiredSizeForBindings): (writableStreamDefaultWriterAbortForBindings): (writableStreamDefaultWriterCloseForBindings): (writableStreamDefaultWriterReleaseLockForBindings): (writableStreamDefaultWriterWriteForBindings): * Source/WebCore/Sources.txt: * Source/WebCore/WebCore.xcodeproj/project.pbxproj: * Source/WebCore/bindings/js/InternalWritableStreamWriter.cpp: (WebCore::InternalWritableStreamWriter::closedForBindings): (WebCore::InternalWritableStreamWriter::desiredSizeForBindings): (WebCore::InternalWritableStreamWriter::readyForBindings): (WebCore::InternalWritableStreamWriter::abortForBindings): (WebCore::InternalWritableStreamWriter::closeForBindings): (WebCore::InternalWritableStreamWriter::releaseLockForBindings): (WebCore::InternalWritableStreamWriter::writeForBindings): * Source/WebCore/bindings/js/InternalWritableStreamWriter.h: Canonical link: https://commits.webkit.org/317707@main
https://bugs.webkit.org/show_bug.cgi?id=319959 Reviewed by Alan Baradlay. The failures seem related to 317593@main. * Source/WebCore/SaferCPPExpectations/NoUncheckedPtrMemberCheckerExpectations: * Source/WebCore/SaferCPPExpectations/UncheckedCallArgsCheckerExpectations: * Source/WebCore/SaferCPPExpectations/UncheckedLocalVarsCheckerExpectations: * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::FlexFormattingContext::layout): (WebCore::FlexFormattingContext::layoutFlexItems): (WebCore::FlexFormattingContext::handleCrossAxisAlignmentForFlexLines): (WebCore::FlexFormattingContext::performBaselineAlignment): (WebCore::FlexFormattingContext::computeFlexItemRects): (WebCore::FlexFormattingContext::placeFlexItems): (WebCore::FlexFormattingContext::reverseColumnLinesFromContainerMainEndIfNeeded): (WebCore::FlexFormattingContext::layoutColumnReverse): (WebCore::ScopedFlexBasisAsFlexItemMainSize::ScopedFlexBasisAsFlexItemMainSize): (WebCore::ScopedFlexBasisAsFlexItemMainSize::~ScopedFlexBasisAsFlexItemMainSize): (WebCore::FlexFormattingContext::flexBaseSizeForFlexItem): (WebCore::FlexFormattingContext::flexBaseSizeNeedsBlockAxisContentSize): (WebCore::FlexFormattingContext::ensureBlockAxisContentSizeForFlexItemIfNeeded): (WebCore::FlexFormattingContext::computeContentBasedMinMainSize): (WebCore::FlexFormattingContext::computeMainAxisExtentForFlexItem): (WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing const): (WebCore::FlexFormattingContext::flexItemIntrinsicLogicalHeight const): (WebCore::FlexFormattingContext::flexItemCrossSizeIsDefinite): (WebCore::FlexFormattingContext::trimMainAxisMarginStart): (WebCore::FlexFormattingContext::trimMainAxisMarginEnd): (WebCore::FlexFormattingContext::trimCrossAxisMarginStart): (WebCore::FlexFormattingContext::trimCrossAxisMarginEnd): (WebCore::FlexFormattingContext::canFitItemWithTrimmedMarginEnd const): (WebCore::FlexFormattingContext::removeMarginEndFromFlexSizes const): (WebCore::FlexFormattingContext::applyStretchAlignmentToFlexItem): (WebCore::FlexFormattingContext::applyStretchMinMaxCrossSize): * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h: * Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.cpp: (WebCore::LayoutIntegration::FlexLayout::collectFlexItems): (WebCore::LayoutIntegration::FlexLayout::flexItemForFirstBaseline const): (WebCore::LayoutIntegration::FlexLayout::flexItemForLastBaseline const): (WebCore::LayoutIntegration::FlexLayout::baselineFlexItemInLine const): * Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.h: * Source/WebCore/rendering/RenderFlexibleBox.cpp: * Source/WebCore/rendering/RenderFlexibleBox.h: Canonical link: https://commits.webkit.org/317708@main
…after the WebContent process exits https://bugs.webkit.org/show_bug.cgi?id=319952 Reviewed by Per Arne Vollan. When log forwarding is enabled, each WebContent process gets a LogStream in the UI process (WebProcessProxy::createLogStream), backed by a StreamServerConnection over its own IPC::Connection. LogStream::stopListeningForIPC() only called StreamServerConnection::stopReceivingMessages(), which unregisters the message receiver but never invalidates the underlying IPC::Connection. An open connection keeps itself alive through its Mach-receive dispatch source (which holds a Ref back to the connection) and holds its Mach port / kqueue workloop until it is explicitly invalidated. So tearing down the WebProcessProxy released its reference to the LogStream but did not release the connection: StreamServerConnection::m_receivers and the connection's own receive source kept the LogStream / StreamServerConnection / IPC::Connection alive as a self-sustaining island with a dead peer. One such connection leaked per WebContent process. Over a long session these accumulate in the UI process until it is killed for Mach port exhaustion (32768) or kqueue workloop exhaustion (2048), whichever limit is reached first. Fix LogStream::stopListeningForIPC() to also invalidate() the connection: stopReceivingMessages() clears the receiver map (breaking the m_receivers <-> m_connection retain cycle so the objects can be freed) and invalidate() cancels the receive source and releases the Mach port / kqueue workloop. Also tear the log stream down from WebProcessProxy::shutDown() (via a new stopLogStream() helper, shared with platformDestroy()) so the connection is released as soon as the process shuts down, rather than waiting for the proxy object to be destroyed. * Source/WebKit/Shared/LogStream.mm: (WebKit::LogStream::stopListeningForIPC): * Source/WebKit/UIProcess/Cocoa/WebProcessProxyCocoa.mm: (WebKit::WebProcessProxy::platformDestroy): (WebKit::WebProcessProxy::stopLogStream): * Source/WebKit/UIProcess/WebProcessProxy.cpp: (WebKit::WebProcessProxy::shutDown): * Source/WebKit/UIProcess/WebProcessProxy.h: Canonical link: https://commits.webkit.org/317709@main
https://bugs.webkit.org/show_bug.cgi?id=319933 rdar://182856553 Reviewed by Chris Dumez. This improves readability and enforces more idiomatic C++ by resorting to equivalent binary boolean operations. * Source/WebCore/css/parser/CSSPropertyParserConsumer+Transform.cpp: (WebCore::CSSPropertyParserHelpers::consumeRotate): * Source/WebCore/css/typedom/CSSNumericValue.cpp: (WebCore::operationOnValuesOfSameUnit): * Source/WebCore/dom/Document.cpp: (WebCore::Document::hasTouchEventHandlers const): * Source/WebCore/dom/Node.cpp: (WebCore::Node::canStartSelection const): * Source/WebCore/dom/ScriptExecutionContext.cpp: (WebCore::ScriptExecutionContext::allowsMediaDevices const): * Source/WebCore/rendering/LogicalSelectionOffsetCachesInlines.h: (WebCore::LogicalSelectionOffsetCaches::ContainingBlockInfo::setBlock): * Source/WebCore/rendering/RenderBlockFlow.cpp: (WebCore::RenderBlockFlow::MarginInfo::MarginInfo): (WebCore::RenderBlockFlow::styleWillChange): (WebCore::RenderBlockFlow::hasContentfulInlineOrBlockLine const): (WebCore::RenderBlockFlow::hasContentfulInlineLine const): * Source/WebCore/rendering/RenderBoxModelObject.cpp: (WebCore::RenderBoxModelObject::adjustedPositionRelativeToOffsetParent const): * Source/WebCore/rendering/RenderLayer.cpp: (WebCore::RenderLayer::referenceBoxRectForClipPath const): (WebCore::RenderLayer::calculateClipRects const): * Source/WebCore/rendering/RenderLayerCompositor.cpp: (WebCore::RenderLayerCompositor::updateCompositingLayers): * Source/WebCore/rendering/RenderLayoutState.cpp: (WebCore::RenderLayoutState::computeOffsets): * Source/WebCore/rendering/RenderObject.cpp: (WebCore::RenderObject::canUpdateSelectionOnRootLineBoxes): * Source/WebCore/rendering/RenderTreeAsText.cpp: (WebCore::writeLayers): * Source/WebCore/rendering/shapes/ShapeInterval.h: (WebCore::ShapeInterval::isEmpty const): * Source/WebCore/rendering/svg/RenderSVGInlineText.cpp: (WebCore::RenderSVGInlineText::styleDidChange): Canonical link: https://commits.webkit.org/317710@main
https://bugs.webkit.org/show_bug.cgi?id=319983 rdar://179862957 Reviewed by Etienne Segonzac. Align the immersive documentation syntax with the other API documentations. * Source/WebKit/UIProcess/API/Cocoa/WKImmersiveEnvironment.h: * Source/WebKit/UIProcess/API/Cocoa/WKImmersiveEnvironmentDelegate.h: * Source/WebKit/UIProcess/API/Swift/WebPage+Configuration.swift: * Source/WebKit/UIProcess/API/Swift/WebPage+ImmersiveEnvironment.swift: * Source/WebKit/_WebKit_SwiftUI/API/View+WebViewModifiers.swift: * Source/WebKit/_WebKit_SwiftUI/API/WebViewImmersiveEnvironmentView.swift: Canonical link: https://commits.webkit.org/317711@main
https://bugs.webkit.org/show_bug.cgi?id=319942 rdar://problem/182860702 Reviewed by Cole Carley. After track sizing is finished, we attempt to resolve the margins for grid items in two different places: once during the final sizing of the item and then when we want to align them. The logic to do this is exactly the same and we do it in two different ways in both scenarios when we do not need to. Instead, let's just use the static helper function that we already have during item sizing and remove the lambdas that were basically just duplicate code. This change requires us to compute a list of the margins for each grid item rather than resolve the margins one at a time, but this is basically just a matter of plumbing the values to the right place. * Source/WebCore/layout/formattingContexts/grid/GridLayout.cpp: Remove the local UsedMargins definition now that it lives in GridLayoutUtils.h. (WebCore::Layout::GridLayout::layoutGridItems const): Resolve each grid item's used margins with computeMarginsForAxis and pass them into the sizing functions. * Source/WebCore/layout/formattingContexts/grid/GridLayoutUtils.cpp: (WebCore::Layout::GridLayoutUtils::stretchFitSize): (WebCore::Layout::GridLayoutUtils::inlinePreferredSize): (WebCore::Layout::GridLayoutUtils::blockPreferredSize): (WebCore::Layout::GridLayoutUtils::inlineUsedSize): (WebCore::Layout::GridLayoutUtils::blockUsedSize): Aforementioned plumbing from GridLayout::layoutGridItems to the spots where we were manually resolving them in the lambdas. Canonical link: https://commits.webkit.org/317712@main
rdar://182758228 https://bugs.webkit.org/show_bug.cgi?id=319969 Reviewed by Jean-Yves Avenard. In M150 libwebrtc resync, explicit hopping from network thread to worker thread was removed from WebRtcVideoReceiveChannel::OnPacketReceived. This is ok in Chrome since network thread and worker thread are the same. We apply the same setup in WebKit in LibWebRTCProvider::createPeerConnectionFactory. The issue is that while Call::DeliverRtpPacket use a safety task to make sure the Call pointer is valid after hopping to worker thread, the OnUndemuxablePacketHandler is keeping a pointer to WebRtcVideoReceiveChannel/WebRtcVoiceReceiveChannel, which are not guaranteed to stay valid in our previous config where worker thread and signalling thread were the same. For good measure, we make sure that the OnUndemuxablePacketHandler given to Call::DeliverRtpPacket from WebRtcVideoReceiveChannel and WebRtcVoiceReceiveChannel use safety flags so that we protect from any misuse pointers. * Source/ThirdParty/libwebrtc/Source/webrtc/media/engine/webrtc_video_engine.cc: * Source/ThirdParty/libwebrtc/Source/webrtc/media/engine/webrtc_voice_engine.cc: * Source/WebCore/platform/mediastream/libwebrtc/LibWebRTCProvider.cpp: (WebCore::LibWebRTCProvider::createPeerConnectionFactory): Canonical link: https://commits.webkit.org/317713@main
rdar://182612413 https://bugs.webkit.org/show_bug.cgi?id=319922 Reviewed by Alex Christensen. There's already many `.frame` properties on various classes on Cocoa platforms, most of which are NS/CGRect. This new property is a bit confusing for devs cognitively, and also trips up tooling. Let's rename to something that already has WebKit precedent. * Source/WebKit/UIProcess/API/Cocoa/WKJSHandle.h: * Source/WebKit/UIProcess/API/Cocoa/WKJSHandle.mm: (-[WKJSHandle sourceFrame]): (-[_WKJSHandle frame]): (-[WKJSHandle frame]): Deleted. * Source/WebKit/UIProcess/API/Cocoa/_WKJSHandle.h: Canonical link: https://commits.webkit.org/317714@main
https://bugs.webkit.org/show_bug.cgi?id=247996 rdar://102634281 Reviewed by BJ Burg. Implement the "consume user activation of Window" WebDriver extension command (POST /session/{id}/window/consume-user-activation) defined in HTML, which consumes the current browsing context active window's transient user activation and returns whether activation was present. The command mirrors the existing getComputedRole automation command, routing from the UI process to the web process to call LocalDOMWindow::consumeTransientActivation(). * Source/WebDriver/Session.cpp: (WebDriver::Session::consumeUserActivation): * Source/WebDriver/Session.h: * Source/WebDriver/WebDriverService.cpp: (WebDriver::WebDriverService::consumeUserActivation): * Source/WebDriver/WebDriverService.h: * Source/WebKit/UIProcess/Automation/Automation.json: * Source/WebKit/UIProcess/Automation/WebAutomationSession.cpp: (WebKit::WebAutomationSession::consumeUserActivation): * Source/WebKit/UIProcess/Automation/WebAutomationSession.h: * Source/WebKit/UIProcess/WebPageProxy.cpp: * Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.cpp: (WebKit::WebAutomationSessionProxy::consumeUserActivation): * Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.h: * Source/WebKit/WebProcess/Automation/WebAutomationSessionProxy.messages.in: Canonical link: https://commits.webkit.org/317715@main
…d isAnyOf https://bugs.webkit.org/show_bug.cgi?id=319815 rdar://182714057 Reviewed by Sam Weinig. The const variadic overloads in WeakPtr.h and UniqueRef.h were mistakenly named is() instead of isAnyOf(), colliding with the const single-argument is() overload and leaving isAnyOf() without a const overload for these two types. Ref.h, RefPtr.h, CheckedPtr.h, and CheckedRef.h all name this overload isAnyOf() correctly. * Source/WTF/wtf/UniqueRef.h: (WTF::isAnyOf): * Source/WTF/wtf/WeakPtr.h: (WTF::isAnyOf): Canonical link: https://commits.webkit.org/317716@main
…code https://bugs.webkit.org/show_bug.cgi?id=319964 rdar://182889728 Reviewed by Yijia Huang. Since japanese calendar is using proleptic Gregorian calendar, for year, day, month, monthcode, we do not need to query to the calendar, we can just use ISO 8601 values. For era related ones need to query to the actual calendar. Test: JSTests/stress/temporal-japanese-calendar-proleptic-gregorian.js * JSTests/stress/temporal-japanese-calendar-proleptic-gregorian.js: Added. (shouldBe): (checkDateFields): (checkEra): * Source/JavaScriptCore/runtime/temporal/core/CalendarICUBridge.cpp: (JSC::TemporalCore::isoToCalendarFields): (JSC::TemporalCore::calendarMonth): (JSC::TemporalCore::calendarMonthCode): (JSC::TemporalCore::calendarDay): Canonical link: https://commits.webkit.org/317717@main
https://bugs.webkit.org/show_bug.cgi?id=319400 rdar://157892382 Reviewed by Aakash Jain. EWSContext defines the EWS results schema (bug 319113); this adds the read and write path on top of it. register() classifies a run's unexpected failures and stores them, routing to the flaky table when given a flaky_type and the failed table otherwise, and find_for_test() queries either table via a flaky flag. EWSContext is wired into Model, with a mock helper (add_mock_ews_results) and unit tests. This also refines the landed skeleton: the result column becomes result_id, a build_number column is added, and a Source value type bundles the provenance columns (remote, pr_number, commit_hash, build_number). * Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/ews_context.py: (Source): (Source.unpack): (EWSContext): (EWSContext.EWSResultsBase): (EWSContext.EWSResultsBase.unpack): (EWSContext.EWSFailedTestsByCommit): (EWSContext.EWSFlakyTestsByCommit): (EWSContext.__init__): (EWSContext.register): (EWSContext._classify_unexpected): (EWSContext.find_for_test): * Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/ews_context_unittest.py: Added. (EWSContextTest): (EWSContextTest.init_database): (EWSContextTest._find): (EWSContextTest.test_unexpected_failures_stored): (EWSContextTest.test_metadata_stored): (EWSContextTest.test_flaky_results_stored): (EWSContextTest.test_retries_preserved_for_same_commit): (EWSContextTest.test_no_unexpected_failures): (EWSContextTest.test_no_results): * Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/mock_model_factory.py: (MockModelFactory): (MockModelFactory.add_mock_ews_results): * Tools/Scripts/libraries/resultsdbpy/resultsdbpy/model/model.py: (Model.__init__): Canonical link: https://commits.webkit.org/317718@main
https://bugs.webkit.org/show_bug.cgi?id=319982 Reviewed by Patrick Griffis. Problems fixed: 1) const usage in Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp https://docs.openssl.org/3.0/man7/migration_guide/#functions-that-return-an-internal-key-should-be-treated-as-read-only "the value returned from EVP_PKEY_get0_RSA(3), ... have been made const" 2) Feature test ifdefs in Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp no longer work https://github.com/WebKit/WebKit/blob/6d8ca7e79a097c2013cf960c16489930cad90f11/Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp#L39 These were macros in OpenSSL 1.x, but are now real functions in OpenSSL 3.x: https://docs.openssl.org/3.0/man3/EVP_PKEY_CTX_ctrl/#history "In OpenSSL 1.1.1 and below the functions were mostly macros. From OpenSSL 3.0 they are all functions." So the ifdefs do not see the macros defined (because they are now functions), so the code incorrectly returns ExceptionCode::NotSupportedError. The solution is to remove these feature checks, surely no one is still using OpenSSL 0.x from before these were added as macros. 3) Runtime GCM failures. In Source/WebCore/crypto/openssl/CryptoAlgorithmAESGCMOpenSSL.cpp EVP_CIPHER_CTX_set_padding() is called *before* EVP_EncryptInit_ex() and EVP_DecryptInit_ex(). The OpenSSL documentation says: "This function should be called after the context is set up for encryption or decryption" https://docs.openssl.org/3.0/man3/EVP_EncryptInit/#description . In OpenSSL 1.x this did not matter because EVP_EncryptInit_ex() always returned 1: https://github.com/openssl/openssl/blob/OpenSSL_1_1_1-stable/crypto/evp/evp_enc.c#L650 , but in OpenSSL 3.x it can return 0 if it is called incorrectly, as here with a null ctx->cipher. The solution is to move the function calls after the init functions. No new tests: fixes behaviour in non default configuration * Source/WebCore/crypto/openssl/CryptoAlgorithmAESGCMOpenSSL.cpp: move EVP_CIPHER_CTX_set_padding() calls (WebCore::cryptEncrypt): move EVP_CIPHER_CTX_set_padding() call after EVP_EncryptInit_ex() (WebCore::cryptDecrypt): move EVP_CIPHER_CTX_set_padding() call after EVP_DecryptInit_ex() * Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_OAEPOpenSSL.cpp: delete broken feature check #ifs (WebCore::CryptoAlgorithmRSA_OAEP::platformEncrypt): delete broken feature check #if (WebCore::CryptoAlgorithmRSA_OAEP::platformDecrypt): delete broken feature check #if * Source/WebCore/crypto/openssl/CryptoAlgorithmRSA_PSSOpenSSL.cpp: delete broken feature check #ifs (WebCore::CryptoAlgorithmRSA_PSS::platformSign): delete broken feature check #if (WebCore::CryptoAlgorithmRSA_PSS::platformVerify): delete broken feature check #if * Source/WebCore/crypto/openssl/CryptoKeyRSAOpenSSL.cpp: Add const to match OpenSSL 3.x API changes (WebCore::getRSAModulusLength): add const (WebCore::CryptoKeyRSA::keySizeInBits const): add const (WebCore::CryptoKeyRSA::algorithm const): add const (WebCore::CryptoKeyRSA::exportData const): add const Canonical link: https://commits.webkit.org/317719@main
…e measurement https://bugs.webkit.org/show_bug.cgi?id=320236 Reviewed by Antti Koivisto. A couple of flex-item measurements still read the render tree straight from FlexFormattingContext. Move them behind FlexIntegrationUtils so the formatting context keeps the flex algorithm and the integration owns the RenderBox access. flexItemIntrinsicLogicalHeight and flexItemIntrinsicLogicalWidth move to FlexIntegrationUtils. Each takes the one flex-algorithm decision it needs -- whether the item's logical height must be stretched, and whether its cross size is definite -- as a bool computed by the formatting context (via FlexFormattingUtils / FlexLayoutState) and passed in. That keeps FlexLayoutState and the FlexFormattingUtils queries on the formatting-context side and leaves the integration methods as pure render-tree measurement: scrollbar + border/padding + constrainLogicalHeightByMinMax, or computeLogicalWidth with the item's overriding width cleared. While here, fold the flex-base-size max-content branch's border/padding subtraction into the integration. maxContentMainAxisExtentForFlexItem now returns the content-box extent (the contribution minus the item's main-axis border/padding) instead of the raw contribution, so flexBaseSizeForFlexItem no longer reads the item's border/padding directly. It is renamed from maxContentMainAxisContributionForFlexItem to reflect the value it returns. No change in behavior. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::FlexFormattingContext::hypotheticalCrossSizeForFlexItems): (WebCore::FlexFormattingContext::flexBaseSizeForFlexItem): (WebCore::FlexFormattingContext::flexItemIntrinsicLogicalHeight): Deleted. (WebCore::FlexFormattingContext::flexItemIntrinsicLogicalWidth): Deleted. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h: * Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp: (WebCore::LayoutIntegration::FlexIntegrationUtils::maxContentMainAxisExtentForFlexItem): (WebCore::LayoutIntegration::FlexIntegrationUtils::flexItemIntrinsicLogicalHeight): (WebCore::LayoutIntegration::FlexIntegrationUtils::flexItemIntrinsicLogicalWidth): (WebCore::LayoutIntegration::FlexIntegrationUtils::maxContentMainAxisContributionForFlexItem): Deleted. * Source/WebCore/layout/integration/flex/FlexIntegrationUtils.h: Canonical link: https://commits.webkit.org/317923@main
…es.html` test expectation https://bugs.webkit.org/show_bug.cgi?id=320280 rdar://183197290 Reviewed by Abrar Rahman Protyasha. Re-baseline this test since the font/metrics have slightly become mismatched. * LayoutTests/http/tests/quicklook/resources/secure-document-with-subresources-expected/index.css: (.p1): (.p2): (.it2): (.it3): * LayoutTests/platform/ios/TestExpectations: Canonical link: https://commits.webkit.org/317924@main
…verride for GTK/WPE ports https://bugs.webkit.org/show_bug.cgi?id=320272 rdar://183191094 Reviewed by Patrick Griffis. lint_test_expectations.py compared the Port object itself against the strings 'gtk' and 'wpe' instead of comparing port_to_lint.port_name. Port has no __eq__, so the comparison was always False and the glib-specific TestExpectations override (LayoutTests/platform/glib/ TestExpectations) was silently never added for either port. * Tools/Scripts/webkitpy/layout_tests/lint_test_expectations.py: (lint): Compare port_to_lint.port_name instead of port_to_lint. * Tools/Scripts/webkitpy/layout_tests/lint_test_expectations_unittest.py: (FakePort.__init__): Add port_name and _options so tests can exercise the glib-expectations branch. (LintTest.test_glib_additional_expectations): Added. Verifies gtk and wpe ports get the glib TestExpectations override and other ports don't. Canonical link: https://commits.webkit.org/317925@main
…rations into FlexIntegrationUtils https://bugs.webkit.org/show_bug.cgi?id=320252 Reviewed by Antti Koivisto. FlexFormattingContext still made a number of non-trivial calls directly on the flex item's renderer -- margin trimming, auto-margin resolution, min/max constraining, and percentage-height / logical-size computation. Move them behind FlexIntegrationUtils so the formatting context reaches the flex item's renderer only through cheap getters. Moved to FlexIntegrationUtils (each takes a FlexLayoutItem and derives the container's flow / writing mode from flexBox() rather than from the formatting context's constraints): - updateAutoMarginsInMainAxis / updateAutoMarginsInCrossAxis (renderer margin mutations). - trimMainAxisMarginStart / trimMainAxisMarginEnd / trimCrossAxisMarginStart / trimCrossAxisMarginEnd. - constrainFlexItemLogicalHeightByMinMax / constrainFlexItemLogicalWidthByMinMax (the width helper supplies flexBox() as the containing block). - computePercentageLogicalHeightForFlexItem, computeLogicalHeightUsingForFlexItem and computeLogicalWidthUsingForFlexItem (templated, with explicit instantiations for the size types the formatting context resolves). The formatting context keeps the flex-algorithm decisions: it still gates margin trimming on FlexFormattingUtils::shouldTrim*, and computes the stretch / cross-size-definiteness booleans it passes into the intrinsic-size helpers. Drive-by cleanup in the same functions: dropped the redundant out-of-flow-positioned ASSERTs and the CheckedRef renderer locals that existed only to feed the moved calls, and converted the isRenderTable() / isRenderReplaced() virtual checks to is<RenderTable> / is<RenderReplaced> (adding the corresponding includes). No change in behavior. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::FlexFormattingContext::computeFlexLines): (WebCore::FlexFormattingContext::trimCrossAxisMarginsForFlexItems): (WebCore::FlexFormattingContext::handleCrossAxisAlignmentForFlexItems): (WebCore::FlexFormattingContext::performBaselineAlignment): (WebCore::FlexFormattingContext::placeFlexItems): (WebCore::FlexFormattingContext::computeContentBasedMinMainSize): (WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing): (WebCore::FlexFormattingContext::computeUsedNonAutoMinMainSize): (WebCore::FlexFormattingContext::flexItemCrossSizeIsDefinite): (WebCore::FlexFormattingContext::applyStretchAlignmentToFlexItem): (WebCore::FlexFormattingContext::applyStretchMinMaxCrossSize): (WebCore::FlexFormattingContext::updateAutoMarginsInMainAxis): Deleted. (WebCore::FlexFormattingContext::updateAutoMarginsInCrossAxis): Deleted. (WebCore::FlexFormattingContext::trimMainAxisMarginStart): Deleted. (WebCore::FlexFormattingContext::trimMainAxisMarginEnd): Deleted. (WebCore::FlexFormattingContext::trimCrossAxisMarginStart): Deleted. (WebCore::FlexFormattingContext::trimCrossAxisMarginEnd): Deleted. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.h: * Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp: (WebCore::LayoutIntegration::FlexIntegrationUtils::updateAutoMarginsInMainAxis): (WebCore::LayoutIntegration::FlexIntegrationUtils::updateAutoMarginsInCrossAxis): (WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginStart): (WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginEnd): (WebCore::LayoutIntegration::FlexIntegrationUtils::trimCrossAxisMarginStart): (WebCore::LayoutIntegration::FlexIntegrationUtils::trimCrossAxisMarginEnd): (WebCore::LayoutIntegration::FlexIntegrationUtils::constrainFlexItemLogicalHeightByMinMax): (WebCore::LayoutIntegration::FlexIntegrationUtils::constrainFlexItemLogicalWidthByMinMax): (WebCore::LayoutIntegration::FlexIntegrationUtils::computePercentageLogicalHeightForFlexItem): (WebCore::LayoutIntegration::FlexIntegrationUtils::computeLogicalHeightUsingForFlexItem): (WebCore::LayoutIntegration::FlexIntegrationUtils::computeLogicalWidthUsingForFlexItem): * Source/WebCore/layout/integration/flex/FlexIntegrationUtils.h: Canonical link: https://commits.webkit.org/317926@main
…FlexibleBox's flex-item query wrappers https://bugs.webkit.org/show_bug.cgi?id=320254 Reviewed by Antti Koivisto. RenderFlexibleBox carried thin flex-item query wrappers -- mainAxisIsFlexItemInlineAxis, flexBasisForFlexItem, alignmentForFlexItem, hasDefiniteCrossSizeForFlexItem -- that only forwarded to the corresponding FlexFormattingUtils statics, plus useContentBasedMinimumBlockSize which composed two of them. Their only callers are render-side (RenderBox / RenderBlock), which already pull in FlexFormattingUtils.h transitively through RenderFlexibleBox.h, so the wrappers were redundant indirection. Drop the four proxies from RenderFlexibleBox and move the useContentBasedMinimumBlockSize composition to a FlexFormattingUtils static. The statics take the flex item and derive the flex container from its parent, so the call sites pass the item directly; isFlexItem() already implies a RenderFlexibleBox parent, so RenderBox loses two now-redundant downcast guards. RenderBox.cpp and RenderBlock.cpp gain a direct FlexFormattingUtils.h include. No change in behavior. * Source/WebCore/rendering/RenderFlexibleBox.h: * Source/WebCore/rendering/RenderFlexibleBox.cpp: (WebCore::RenderFlexibleBox::mainAxisIsFlexItemInlineAxis): Deleted. (WebCore::RenderFlexibleBox::flexBasisForFlexItem): Deleted. (WebCore::RenderFlexibleBox::alignmentForFlexItem): Deleted. (WebCore::RenderFlexibleBox::hasDefiniteCrossSizeForFlexItem): Deleted. (WebCore::RenderFlexibleBox::useContentBasedMinimumBlockSize): Deleted. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.h: * Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.cpp: (WebCore::FlexFormattingUtils::useContentBasedMinimumBlockSize): * Source/WebCore/rendering/RenderBox.cpp: (WebCore::RenderBox::isBlockSizeResolvableForStretch): (WebCore::RenderBox::computeContentAndScrollbarLogicalHeightUsing): * Source/WebCore/rendering/RenderBlock.cpp: (WebCore::RenderBlock::hasDefiniteLogicalHeightForPercentageResolutionFromStyle): Canonical link: https://commits.webkit.org/317927@main
https://bugs.webkit.org/show_bug.cgi?id=319814 Reviewed by Yijia Huang. Resolve ordinary supported Chinese and Dangi related-year and ordinal numeric-month field resolution without relying on ICU extended-year identity. Keep year/era/eraYear and monthCode/ordinal-month consistency, with({year}), Duration relativeTo, Hebrew month behavior, and PlainMonthDay required-field ordering consistent. Tests: JSTests/stress/temporal-lunisolar-ordinal-month.js Tests: jsc --useTemporal=1 JSTests/stress/temporal-lunisolar-ordinal-month.js Tests: readable focused Temporal field-resolution, Duration, Hebrew, PlainMonthDay ordering, and arithmetic tests Canonical link: https://commits.webkit.org/317928@main
…nd border/padding off the renderer https://bugs.webkit.org/show_bug.cgi?id=320283 Reviewed by Antti Koivisto. A few flex-item reads were left in FlexFormattingContext, all going straight to the renderer for values the formatting context either already has or can get through the utils. computeFlexBaseAndHypotheticalMainSizes re-reads an orthogonal item's main-axis margin after flexBaseSizeForFlexItem has laid the item out (the item's block-direction margins are only resolved at that point), duplicating the horizontal/verticalMarginExtent selection that FlexFormattingUtils already does. That helper had two behaviours behind one name though: for a clean item it returned the resolved physical extent, but for a dirty one it recomputed the margins in the container's inline/block directions, which only line up with the main/cross axes in a horizontal writing mode. Split it in two -- usedMainAxisMarginExtentForFlexItem returns what layout resolved, and resolveMainAxisMarginExtentForFlexItem resolves first for the one caller that needs that, staticMainAxisPositionForPositionedFlexItem, which computes an out-of-flow item's static position outside of flex layout. computeFlexBaseAndHypotheticalMainSizes wants the former. removeMarginEndFromFlexSizes computes the item's main-axis end margin to subtract it from the running flex base and hypothetical main sizes -- the same value that FlexIntegrationUtils::trimMainAxisMarginEnd subtracts from the item's cached mainAxisMargin, and the two are always called together. Add FlexFormattingUtils::mainAxisMarginEndForFlexItem (a static form taking the container, plus the usual instance overload, matching crossAxisMarginExtentForFlexItem) and have both call sites use it. computeMainSizeFromAspectRatioUsing recomputes the item's main-axis border/padding from the renderer even though FlexLayoutItem already caches it (with the same expression), and the same function already uses the cached cross-axis value a few lines up. Unlike margins, border/padding is not resolved during layout, so this is simply a duplicate read: use the cached FlexLayoutItem::mainAxisBorderAndPadding instead. With this the formatting context reaches a flex item's renderer only through the FlexLayoutItem constructor's one-time snapshot, cheap getters and asserts. No change in behavior. * Source/WebCore/layout/formattingContexts/flex/FlexFormattingContext.cpp: (WebCore::FlexFormattingContext::computeFlexBaseAndHypotheticalMainSizes): (WebCore::FlexFormattingContext::computeMainSizeFromAspectRatioUsing): (WebCore::FlexFormattingContext::removeMarginEndFromFlexSizes): * Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.h: * Source/WebCore/layout/formattingContexts/flex/FlexFormattingUtils.cpp: (WebCore::FlexFormattingUtils::resolveMainAxisMarginExtentForFlexItem): (WebCore::FlexFormattingUtils::usedMainAxisMarginExtentForFlexItem): (WebCore::FlexFormattingUtils::mainAxisMarginEndForFlexItem): (WebCore::FlexFormattingUtils::mainAxisMarginExtentForFlexItem): Deleted. * Source/WebCore/layout/integration/flex/FlexIntegrationUtils.cpp: (WebCore::LayoutIntegration::FlexIntegrationUtils::trimMainAxisMarginEnd): * Source/WebCore/layout/integration/flex/LayoutIntegrationFlexLayout.cpp: (WebCore::LayoutIntegration::FlexLayout::staticMainAxisPositionForPositionedFlexItem): Canonical link: https://commits.webkit.org/317929@main
…sting whether a second one is needed https://bugs.webkit.org/show_bug.cgi?id=320088 Reviewed by Yusuke Suzuki. tryReadUnicodeCharImpl loads 32 bits up front so that it can detect a surrogate pair, and therefore checks that both code units are in bounds before loading anything. Surrogate pairs are rare compared to BMP code points, though, and deciding whether a code unit is a BMP code point on its own does not need 32 bits. Load the first code unit alone and test its top five bits: U+D800-U+DFFF are exactly the code units whose top five bits are 0b11011. If it is not a surrogate, it is the code point, so jump to done right there. Only if it is a surrogate do we check the bounds, load 32 bits, and either decode a proper surrogate pair or fall into the slow cases. Keeping the bit 15 test from 317749@main as the fast-path branch would take fewer instructions, but that branch depends on the character being read and mispredicts badly once the subject mixes code units below and above U+8000. The surrogate test costs one more instruction but only changes direction when a surrogate actually appears. Baseline Patched regexp-unicode-bmp-hangul-and-fullwidth 43.9718+-0.9491 34.3181+-2.8952 definitely 1.2813x faster regexp-unicode-bmp-above-latin 45.6190+-0.7442 35.8214+-2.6717 definitely 1.2735x faster regexp-u-global-es6 31.8327+-0.2765 30.5326+-0.3346 definitely 1.0426x faster regexp-unicode-latin-before-surrogate 55.0738+-1.6395 52.8071+-3.0785 might be 1.0429x faster regexp-unicode-surrogate-pairs 45.9197+-1.5007 46.1131+-1.7645 neutral * Source/JavaScriptCore/yarr/YarrJIT.cpp: (JSC::Yarr::tryReadUnicodeCharImpl): Canonical link: https://commits.webkit.org/317930@main
…nments` https://bugs.webkit.org/show_bug.cgi?id=320151 Reviewed by Yusuke Suzuki. JSModuleRecord kept copies of the module's declared and lexical VariableEnvironments alive for the lifetime of the record, but the lexical one is only read by ModuleAnalyzer (which already receives the ModuleProgramNode) and the declared one only by InitializeEnvironment's var initialization loop. Read the former from the node and store the latter in UnlinkedModuleProgramCodeBlock, as UnlinkedProgramCodeBlock already does for scripts, so it lives and dies with the unlinked code. This shrinks JSModuleRecord from 512 to 320 bytes. * Source/JavaScriptCore/bytecode/UnlinkedModuleProgramCodeBlock.h: * Source/JavaScriptCore/bytecompiler/BytecodeGenerator.cpp: (JSC::BytecodeGenerator::BytecodeGenerator): * Source/JavaScriptCore/parser/ModuleAnalyzer.cpp: (JSC::ModuleAnalyzer::ModuleAnalyzer): (JSC::ModuleAnalyzer::analyze): * Source/JavaScriptCore/parser/ModuleAnalyzer.h: * Source/JavaScriptCore/runtime/CachedTypes.cpp: (JSC::CachedModuleCodeBlock::encode): (JSC::CachedModuleCodeBlock::decode const): * Source/JavaScriptCore/runtime/Completion.cpp: (JSC::checkModuleSyntax): * Source/JavaScriptCore/runtime/CyclicModuleRecord.cpp: (JSC::CyclicModuleRecord::initializeEnvironment): * Source/JavaScriptCore/runtime/JSModuleLoader.cpp: (JSC::JSModuleLoader::makeModule): * Source/JavaScriptCore/runtime/JSModuleRecord.cpp: (JSC::JSModuleRecord::create): (JSC::JSModuleRecord::JSModuleRecord): * Source/JavaScriptCore/runtime/JSModuleRecord.h: Canonical link: https://commits.webkit.org/317931@main
…tributed string https://bugs.webkit.org/show_bug.cgi?id=320263 rdar://183187277 Reviewed by Wenson Hsieh. collectDictationTextAlternatives() and shouldRegisterInsertionUndoGroup() both unconditionally read attributes at index 0 of the NSAttributedString passed to WebViewImpl::insertText(id, NSRange), without checking the string's length first. An empty NSMutableAttributedString raises NSRangeException for such an access, so passing a zero-length attributed string (e.g. from an input method committing a composition down to nothing, or from the Character Viewer) crashed. Guard both functions with a length check. Note that an empty immutable NSAttributedString happens not to raise, so the new tests use NSMutableAttributedString to exercise the crashing path. The equivalent WebHTMLView insertText: path in WebKitLegacy has a third unguarded index-0 read of NSTextInputReplacementRangeAttributeName that this change does not address. * Source/WebCore/editing/mac/TextAlternativeWithRange.mm: (WebCore::collectDictationTextAlternatives): * Source/WebCore/editing/mac/TextUndoInsertionMarkupMac.mm: (WebCore::shouldRegisterInsertionUndoGroup): * Tools/TestWebKitAPI/Tests/WebKit/WKWebView/mac/WKWebViewMacEditingTests.mm: (TestWebKitAPI::TEST(WKWebViewMacEditingTests, InsertEmptyAttributedStringDoesNotCrash)): (TestWebKitAPI::TEST(WKWebViewMacEditingTests, InsertEmptyAttributedStringWithAttributesDoesNotCrash)): Canonical link: https://commits.webkit.org/317932@main
…the line box top instead of the element's bounding rect https://bugs.webkit.org/show_bug.cgi?id=316063 rdar://178491868 Reviewed by Alan Baradlay. This patch aligns WebKit with Blink / Chromium. RenderElement::getLeadingCorner() computed the leading corner of an inline element's anchor rect by taking the x from the text's linesBoundingBox() but the y from the line box's contentLogicalTop(). When the inline shares a line with a much taller sibling (e.g. a 100vh image), the line box is inflated and its top sits far above the baseline-aligned text, so the leading corner pointed at the top of the line box rather than at the text itself. This made scrollIntoView() scroll to the wrong position, since getTrailingCorner() already uses the text's linesBoundingBox(). Take both x and y from the text's linesBoundingBox(), mirroring getTrailingCorner(), so the anchor rect is the element's own bounding rect. For normal lines linesBoundingBox().y() equals contentLogicalTop(), so only the tall-line case changes behavior. * LayoutTests/TestExpectations: Remove [ Failure ] expectations * Source/WebCore/rendering/RenderElement.cpp: (WebCore::RenderElement::getLeadingCorner const): > Platform Specific Updates: * LayoutTests/platform/glib/fast/scrolling/scroll-to-anchor-zoomed-header-expected.txt: Removed. (Now matches pass expectation) * LayoutTests/platform/ios/fast/dynamic/anchor-lock-expected.txt: Rebaselined * LayoutTests/platform/glib/fast/dynamic/anchor-lock-expected.txt: Ditto Canonical link: https://commits.webkit.org/317933@main
- AbstractModuleRecord::setImportedModule: drop m_dependencies write (member removed upstream in bug 320144; m_loadedModules is the sole lookup path now). - NodesCodegen: keep emit_intrinsic_getInternalField (Bun's @getInternalField bytecode intrinsic) after the conflict-region resolution dropped it alongside the stale asyncFromSyncIteratorInternalFieldIndex helper.
| // %AsyncFromSyncIteratorPrototype%.throw with an undefined `throw` method must close the sync iterator via | ||
| // IteratorClose and settle the returned promise via IfAbruptRejectPromise -- i.e. REJECT the promise rather than | ||
| // escape synchronously -- for every IteratorClose outcome. The async-from-sync wrapper is not user-observable, so | ||
| // it is reached through `yield*` over a sync iterable inside an async generator. Behavior and error identity are | ||
| // verified against the ECMA-262 %AsyncFromSyncIteratorPrototype%.throw / IteratorClose / GetMethod steps and match |
There was a problem hiding this comment.
🔴 The AsyncContextSwapScope adaptation missed two new AsyncGeneratorDriverResume scheduling sites introduced by upstream's AsyncFromSyncIterator rewrite (bug 319435): JSMicrotask.cpp:376 (asyncFromSyncIteratorContinueOrDone Rejected branch) and AsyncFromSyncIteratorPrototype.cpp:291 (driveAsyncFromSyncIteratorWithDriver sync-throws branch) both pass the raw driver instead of AsyncContextSwapScope::wrapWithCurrent(...). As a result, Bun's AsyncLocalStorage snapshot is dropped when a for await over a sync iterable rejects (rejected-promise element or sync next() throws). Both sites should wrap the driver under #if USE(BUN_JSC_ADDITIONS), mirroring JSMicrotask.cpp:552-558. (Anchored to a test file because JSMicrotask.cpp is beyond the 300-file diff window.)
Extended reasoning...
What the bug is
The fork's convention (established in this PR's own adaptation) is that every context value passed to InternalMicrotask::AsyncGeneratorDriverResume is wrapped with AsyncContextSwapScope::wrapWithCurrent(vm, globalObject, driver) so that the receive-side handler can restore Bun's async context before resuming the driver. The receive side at JSMicrotask.cpp:2086-2092 does:
case InternalMicrotask::AsyncGeneratorDriverResume: {
JSValue contextArg = arguments[2];
#if USE(BUN_JSC_ADDITIONS)
AsyncContextSwapScope asyncContextScope(vm, globalObject, AsyncContextSwapScope::unwrapContextTuple(contextArg));
#endif
...
}The PR correctly applied this to settleDriverWithIteratorResult (line 309-316) and to asyncGeneratorCompleteStep's isThrow path (line 552-558). But upstream's bug 319435 rewrite introduced two additional AsyncGeneratorDriverResume scheduling sites that were left unwrapped.
The two affected sites
Site 1 — JSMicrotask.cpp:376, in asyncFromSyncIteratorContinueOrDone's Rejected / non-JSPromise-target branch:
JSPromise::rejectWithInternalMicrotask(vm, globalObject, result, InternalMicrotask::AsyncGeneratorDriverResume, target);Here target is the raw driver from iterator->extractTarget(). This runs inside the AsyncFromSyncIteratorContinue/Done microtask handler, which has restored the async context (line 2036), so wrapWithCurrent at this point would capture a live snapshot — but it is never called.
Site 2 — AsyncFromSyncIteratorPrototype.cpp:291, in driveAsyncFromSyncIteratorWithDriver's exception branch:
JSPromise::rejectWithInternalMicrotask(vm, globalObject, error, InternalMicrotask::AsyncGeneratorDriverResume, driver);This is called synchronously from op_async_iterator_next inside the driver body, where the async context is active.
rejectWithInternalMicrotask (JSPromise.cpp:1048-1051) does not wrap its context — only resolveWithInternalMicrotaskForAsyncAwait does (line 967-971). So both sites queue the raw driver directly.
Why existing code doesn't prevent it
When the AsyncGeneratorDriverResume microtask fires, unwrapContextTuple(contextArg) (AsyncContextSwapScope.h:82-91) sees a non-InternalFieldTuple, leaves contextArg untouched (so the driver still resumes correctly), and returns jsUndefined(). The AsyncContextSwapScope constructor then early-returns on undefined (line 52-53) and installs no context. There is no crash — unwrapContextTuple is graceful — but the driver's rejection continuation runs with whatever async context happens to be ambient at microtask time, not the snapshot from the await point.
Step-by-step proof
Under USE(BUN_JSC_ADDITIONS):
await asyncLocalStorage.run(store, async () => {
try {
for await (const x of [Promise.reject(err)]) {}
} catch (e) {
asyncLocalStorage.getStore(); // -> undefined, expected: store
}
});for awaitopens an async-from-sync wrapper over the array; the driver is the enclosing async function.- The wrapper's
next()yieldsPromise.reject(err);awaitAndContinueschedulesAsyncFromSyncIteratorContinue(context wrapped byresolveWithInternalMicrotaskForAsyncAwait). - That microtask runs with the async context restored, calls
asyncFromSyncIteratorContinueOrDonewithStatus::Rejected, and reaches line 376. - Line 376 queues
AsyncGeneratorDriverResumewith the rawtarget. - The driver-resume microtask runs:
unwrapContextTuplereturnsjsUndefined(), no context is installed, and the driver'scatchblock executes with noAsyncLocalStoragestore.
Site 2 triggers the same way when the sync iterator's next() itself throws, e.g. { [Symbol.iterator]() { return { next() { throw err } } } } — driveSyncIterator throws, catchScope catches it, and line 291 queues the raw driver.
Impact and fix
This is a Bun-specific behavioural regression vs. the pre-merge fork, where the equivalent reject path (asyncGeneratorCompleteStep isThrow) wrapped the target. It affects Bun's core Node.js-compat AsyncLocalStorage feature on the (common) error paths of for await over sync iterables.
Fix: at both sites, wrap the driver under #if USE(BUN_JSC_ADDITIONS), mirroring lines 552-558:
#if USE(BUN_JSC_ADDITIONS)
JSValue wrappedTarget = AsyncContextSwapScope::wrapWithCurrent(vm, globalObject, target);
#else
JSValue wrappedTarget = target;
#endif
JSPromise::rejectWithInternalMicrotask(vm, globalObject, result, InternalMicrotask::AsyncGeneratorDriverResume, wrappedTarget);- SegmentedVector: gate the new Segment no-header static_assert (bug 320260) to non-Windows. On the MSVC ABI a class whose only member is a zero-length array has non-zero size (padded to alignof(T)), so the !sizeof(Segment) check only holds on the Itanium ABI. The non-Windows builds still enforce the invariant. - WebKitMacros: skip _WEBKIT_ADD_CODE_SIGN when CMAKE_CROSSCOMPILING. Bun's macOS JSC is cross-built from a Linux Docker image where /usr/bin/codesign is unavailable and /bin/sh is dash (no 'set -o pipefail').
5efd3c6 to
3974430
Compare
Preview Builds
|
Upstream's m_dependencies removal (bug 320144) rewrote this lookup as a
hardcoded loop over {JavaScript, JSON, WebAssembly, None}. Bun's fork adds a
fifth ScriptFetchParameters::Type, HostDefined, for 'with { type: "text" }'
and friends; requests keyed with it were no longer found here, so the caller
dereferenced null during link/resolveExport and segfaulted.
Include HostDefined in the probe list under USE(BUN_JSC_ADDITIONS).
…JSC_ADDITIONS) Upstream bug 319887 reserves uid 1 for the Linux process main thread (getpid()==gettid()). Bun's 'bun build' evaluates macros on a bundler worker thread, which is the first thread to call WTF::initializeMainThread() and so becomes the 'WebKit main thread' per initializeMainThreadPlatform(). With the OS-main-thread pinning that worker is constructed IsMain::No (uid >= 2) but isMainThread() is true for it, so the RELEASE_ASSERT in initializeMainThread() trips and aborts. Fall through to the first-thread-gets-uid-1 behaviour under USE(BUN_JSC_ADDITIONS), matching the pre-319887 Linux path.
IntlCache.h transitively includes ICU headers (<unicode/udat.h>, <unicode/udatpg.h>) that Bun's own C++ cannot see on macOS (the prebuilt tarball drops include/unicode/ there and relies on system ICU, which is not in Bun's include path). Expose a small out-of-line VM method that clears both dateCache and intlCache so Bun's process.env.TZ / setTimeZone() setters can invalidate the new Intl.DateTimeFormat instance cache (bug 314337) without including IntlCache.h.
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800 (2026-08-02) via oven-sh/WebKit#383. oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`. ## Bun-side changes Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier, ScriptFetchParameters::Type)` and threads the type through `ImportEntry`, `ExportEntry`, `StarExportEntry`, and `ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the `BunTranspiledModule` path), Bun'''s synthesized record must agree with what JSC'''s own `ModuleAnalyzer` would produce from the printed source; a mismatch fails the BUN_DEBUG record diff in debug and null-derefs `hostResolveImportedModule` in release. - `analyze_transpiled_module` / `js_printer`: every `RecordKind` now carries one trailing `FetchParameters` slot. `add_import_info_*` and `add_export_info_*` accept it; `finalize()` propagates the source import'''s slot through the Local->Indirect conversion. `RequestedModules` dedupes on `(specifier, Type, phase)`. - `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and passes it to every `addImportEntry*` / `addIndirectExport` / `addNamespaceExport` / `addStarExport`; buffer validation is per-slot so only the trailing slot accepts the wider `FetchParameters` sentinel range. - `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` / `add*Export` functions take `uint8_t moduleRequestType` and set `.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for import/export/star entries; `static_assert` pins the ordinal values `to_script_fetch_parameters_type()` hardcodes. - `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout change). ## WebKit-side changes (oven-sh/WebKit#383) - 17 merge conflicts resolved in JSC/WTF; fork's `USE(BUN_JSC_ADDITIONS)` hunks preserved. - Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64` macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`). - `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic` in new `scriptTypeForScript` switch. - Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352 was a squash merge). ## How did you verify your code works? - `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e 'print(42)'` -> `42`). - `bun run build:local -p '42'` links and runs against the local merged WebKit. - oven-sh/WebKit#383 preview build green on all 38 platform variants. - `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`. - New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC lacks `Iterator.prototype.includes`, returns `""` for cyclic join, `WebAssembly.Exception.length === 1`). ## JavaScriptCore/WTF/bmalloc changes since 01aaa3e0be0c (Jul 25) Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026). ### Highlights - `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and `CPU(NEEDS_ALIGNED_ACCESS)` deleted). - `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now; drops remaining 32-bit/x86 JIT refs). - `232cebabc1f3` Remove big-endian support and platforms without unaligned loads/stores (WTF + JSC). - `6eaa5ac1f65d` Remove 32-bit libpas support. - `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator (greedy is the only allocator now). - `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD follow-ups). - `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic `toString`/`join` now throws RangeError via stack check (spec-correct). - `319f94b3db4a` Enable `Iterator.prototype.includes()` by default. - `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute `type` (module loader behavior change). - `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc APIs on ARM64 (perf + ABI of WTF alloc entry points). ### JavaScriptCore **Runtime / builtins** - `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow checks. - `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in runtime. - `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in `JSObject::toString`. - `960adeccefcd` Fast operation for `Array#shift`. - `92c6650c7947` Add `JSArrayIterator::next` C++ helper. - `cb1c48b3e95f` Extend `Array.from()` Set fast path to `set.keys()/.values()`. - `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path ignored `Symbol.iterator` overrides. - `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators. - `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in `JSON.stringify` string copy (same-type & upconvert). - `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check. - `2eb77e9c9473` BigInt: implement Crandall reduction. - `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly. - `319f94b3db4a` Enable `Iterator.prototype.includes()`. - `0731b27c1b60` `Iterator.zip`: use null-prototype objects for options/underlying iterator. - `90b2ecf79ae3` `hostResolveImportedModule` respects module request import-attribute `type`. - `4f54300b848a` Collect diagnostics when `getDirect` returns zero JSValue in `llint_slow_path_get_by_id`. **Parser / bytecompiler** - `c2beca7a439f` Lexer: scan integer tokens in a single pass. - `72ea806faa21` Use overflow-safe range when choosing a switch jump table. **LLInt / DFG / FTL / B3** - `29ceb3c03de3` Remove 32-bit JSValues. - `857bd4334690` Remove ARMv7 JIT support. - `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator. - `68cde6ba2ad3` Make IRO (Air register allocation) faster. - `83540481435f` DFG: allocate `BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets. - `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must require original array structure for `InBoundsSaneChain`. - `e759fa9dd063` LLInt: inline hot path of `op_enter`. - `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for BaseIndex operands. - `4ebed2479144` Speed up `addSortedRange` via binary search. - `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit. **WebAssembly** - `0d0080ea539d` Enable Memory64 feature flag. - `15aa6fad53e3` Memory64: SIMD support. - `bf0425598904` Memory64: expand declared memory limits. - `862994e2cc37` Memory64: validate table import address-type match. - `184ee4c654bd` Memory64: Table64 in OMG tier. - `d202bedc5ff6` Memory64: Table64 in BBQ tier. - `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+ `stack` getter, ctor length = 2). - `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting, icache barrier rework). - `1803d6109d98` Speed up `WebAssembly.Table` construction. - `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target runs. - `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`. - `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales. **Yarr / RegExp** - `581f1d958329` Start end-anchored fixed-size regexps at the only possible position. - `a458a6c1f0a7` v-mode class-set op loop: stop early when no more output possible. - `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`. - `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for `ParenContext`. - `1e43057f135a` Extend first-character filter further. - `54916608d7d6` Fix non-BMP advance latch; simplify `tryReadUnicodeCharImpl`. - `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative lookaheads. - `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns. - `98d0367d2247` Fix: `^` inside a paren that can match empty does not anchor the pattern. **Intl / Temporal** - `09917ef55b0f` Add missing `U_FAILURE(status)` check in `actualLunisolarMonthLength`. **Inspector** - `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d` Canvas: instrument & record WebGPU devices/pipelines. - `301d6b2b21f7` Associate WebAssembly module scripts with the fetching resource. - `28b979b1659b` / `479edb2e4395` Site Isolation: implement `Network.loadResource` / `Network.getSerializedCertificate`. ### WTF - `232cebabc1f3` Remove big-endian support and `CPU(NEEDS_ALIGNED_ACCESS)`. - `e5fa5c604438` Upgrade fast_float to 8.2.10. - `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII case-conversion prefix copy. - `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated `find()`. - `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table off-by-one. - `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64. - `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`. - `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`. - `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete. - `bf15f00ebe95` Remove 12 unused internal-linkage templates (TypeTraits/HashTable/Vector/etc.). - `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang static analyzer. - `158f737725b7` Add helpers for Darwin temp/cache directories. - `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity). - `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE and fix findings. - `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa". - `cfb222f3c4d1` CMake: run `cleandead` at end of configuration. ### bmalloc - `6eaa5ac1f65d` Remove 32-bit libpas support. - `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64). - `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in `VMAllocate.cpp`. - `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its should-go-again result. - `90cbe5e85528` libpas: fix benign read from a deallocated TLC. - `e388877954d1` PGM allocator: fix uninitialized `free_status` misclassifying OOB as UAF. - `05c83a6550b7` libpas: fix `MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling MTE. - `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage (scavenging / zeroing / paged-out pages). ### Breaking/notable for Bun - **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed), `857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)` removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun patches are now dead. - **`VM` layout**: `f2f2c2ddf637` deletes `StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws `RangeError` instead of returning `""`. - **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule` to propagate the import-attribute `type` — check Bun's module loader hook signatures. - **Register allocator**: `bfb1b1183bc2` removes the B3/Air graph-coloring allocator and its `Options::` toggle. - **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds `__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. — affects anything calling these across the WTF boundary on arm64. - **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as private-only; `WebAssembly.Exception` constructor `length` becomes 2 and gains a `stack` prototype getter. - **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default; `319f94b3db4a` `Iterator.prototype.includes` on by default. - **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee publication and adds `Thread::barrierInstructionCache()` in WTF. <!-- robobun:evidence:begin --> --- **[decide:webkit]** gate passed · iteration 2 · 8 files touched <details><summary>fails on main (without fix)</summary> ```console ASAN without fix: BUILD FAILED (no junit output) $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" ninja: Entering directory `/workspace/bun/build/debug' [1/182] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/182] gen cpp.rs (cppbind) [3/182] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt [4/182] gen JS modules (bundle-modules) Preprocess modules (8715ms) Bundle modules (63ms) Postprocesss modules (24ms) Bundle Functions (746ms) Generate Code (12ms) [9.57s] Bundled "src/js" for development 2749 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) [177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o FAILED: obj/unified/UnifiedSou ... (truncated) release without fix: all passed bun test v1.4.0-canary.1 (385f528) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [152.00ms] __F:0:S:0 ``` </details> <details><summary>passes on PR (with fix)</summary> ```console ASAN with fix: all passed $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" bun test v1.4.0 (59b0de0) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [3.17s] __F:0:S:0 release with fix: all passed $ bun scripts/build.ts --profile=release [configured] bun-profile → bun (stripped) in 676ms (unchanged) ninja: Entering directory `/workspace/bun/build/release' [1/140] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/140] gen cpp.rs (cppbind) [3/140] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt [4/140] gen JS modules (bundle-modules) Preprocess modules (8727ms) Bundle modules (51ms) Postprocesss modules (106ms) Bundle Functions (687ms) Generate Code (20ms) [9.61s] Bundled "src/js" for production 2559 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) ^[[1m^[[92m Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core) ^[[1m^[[92m Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime) ^[[1m^[[92m Compilin ... (truncated) ``` </details> <details><summary>diff hotspot</summary> ``` scripts/build/deps/webkit.ts | 2 +- src/bundler/analyze_transpiled_module.rs | 38 +++-- src/bundler/linker_context/postProcessJSChunk.rs | 8 +- src/bundler_jsc/analyze_jsc.rs | 135 ++++++++++++---- src/js_printer/lib.rs | 191 +++++++++++++++++------ src/jsc/RuntimeTranspilerCache.rs | 5 +- src/jsc/bindings/BunAnalyzeTranspiledModule.cpp | 39 +++-- test/js/bun/jsc/webkit-upgrade-3722912f.test.ts | 106 +++++++++++++ 8 files changed, 416 insertions(+), 108 deletions(-) ``` </details> **gate history** · 5 passed · 1 rejected · iteration 2 <details><summary>evidence per changed file</summary> ``` file reads edits tests scripts/build/deps/webkit.ts 1 1 0 src/bundler/analyze_transpiled_module.rs 3 3 0 src/bundler/linker_context/postProcessJSChunk.rs 1 1 0 src/bundler_jsc/analyze_jsc.rs 13 15 0 src/js_printer/lib.rs 9 16 0 src/jsc/RuntimeTranspilerCache.rs 2 3 0 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp 8 12 0 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts 2 5 0 ``` </details> <!-- robobun:evidence:end --> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800 (2026-08-02) via oven-sh/WebKit#383. oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`. Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier, ScriptFetchParameters::Type)` and threads the type through `ImportEntry`, `ExportEntry`, `StarExportEntry`, and `ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the `BunTranspiledModule` path), Bun'''s synthesized record must agree with what JSC'''s own `ModuleAnalyzer` would produce from the printed source; a mismatch fails the BUN_DEBUG record diff in debug and null-derefs `hostResolveImportedModule` in release. - `analyze_transpiled_module` / `js_printer`: every `RecordKind` now carries one trailing `FetchParameters` slot. `add_import_info_*` and `add_export_info_*` accept it; `finalize()` propagates the source import'''s slot through the Local->Indirect conversion. `RequestedModules` dedupes on `(specifier, Type, phase)`. - `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and passes it to every `addImportEntry*` / `addIndirectExport` / `addNamespaceExport` / `addStarExport`; buffer validation is per-slot so only the trailing slot accepts the wider `FetchParameters` sentinel range. - `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` / `add*Export` functions take `uint8_t moduleRequestType` and set `.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for import/export/star entries; `static_assert` pins the ordinal values `to_script_fetch_parameters_type()` hardcodes. - `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout change). - 17 merge conflicts resolved in JSC/WTF; fork's `USE(BUN_JSC_ADDITIONS)` hunks preserved. - Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64` macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`). - `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic` in new `scriptTypeForScript` switch. - Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352 was a squash merge). - `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e 'print(42)'` -> `42`). - `bun run build:local -p '42'` links and runs against the local merged WebKit. - oven-sh/WebKit#383 preview build green on all 38 platform variants. - `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`. - New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC lacks `Iterator.prototype.includes`, returns `""` for cyclic join, `WebAssembly.Exception.length === 1`). Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026). - `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and `CPU(NEEDS_ALIGNED_ACCESS)` deleted). - `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now; drops remaining 32-bit/x86 JIT refs). - `232cebabc1f3` Remove big-endian support and platforms without unaligned loads/stores (WTF + JSC). - `6eaa5ac1f65d` Remove 32-bit libpas support. - `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator (greedy is the only allocator now). - `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD follow-ups). - `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic `toString`/`join` now throws RangeError via stack check (spec-correct). - `319f94b3db4a` Enable `Iterator.prototype.includes()` by default. - `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute `type` (module loader behavior change). - `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc APIs on ARM64 (perf + ABI of WTF alloc entry points). **Runtime / builtins** - `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow checks. - `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in runtime. - `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in `JSObject::toString`. - `960adeccefcd` Fast operation for `Array#shift`. - `92c6650c7947` Add `JSArrayIterator::next` C++ helper. - `cb1c48b3e95f` Extend `Array.from()` Set fast path to `set.keys()/.values()`. - `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path ignored `Symbol.iterator` overrides. - `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators. - `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in `JSON.stringify` string copy (same-type & upconvert). - `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check. - `2eb77e9c9473` BigInt: implement Crandall reduction. - `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly. - `319f94b3db4a` Enable `Iterator.prototype.includes()`. - `0731b27c1b60` `Iterator.zip`: use null-prototype objects for options/underlying iterator. - `90b2ecf79ae3` `hostResolveImportedModule` respects module request import-attribute `type`. - `4f54300b848a` Collect diagnostics when `getDirect` returns zero JSValue in `llint_slow_path_get_by_id`. **Parser / bytecompiler** - `c2beca7a439f` Lexer: scan integer tokens in a single pass. - `72ea806faa21` Use overflow-safe range when choosing a switch jump table. **LLInt / DFG / FTL / B3** - `29ceb3c03de3` Remove 32-bit JSValues. - `857bd4334690` Remove ARMv7 JIT support. - `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator. - `68cde6ba2ad3` Make IRO (Air register allocation) faster. - `83540481435f` DFG: allocate `BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets. - `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must require original array structure for `InBoundsSaneChain`. - `e759fa9dd063` LLInt: inline hot path of `op_enter`. - `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for BaseIndex operands. - `4ebed2479144` Speed up `addSortedRange` via binary search. - `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit. **WebAssembly** - `0d0080ea539d` Enable Memory64 feature flag. - `15aa6fad53e3` Memory64: SIMD support. - `bf0425598904` Memory64: expand declared memory limits. - `862994e2cc37` Memory64: validate table import address-type match. - `184ee4c654bd` Memory64: Table64 in OMG tier. - `d202bedc5ff6` Memory64: Table64 in BBQ tier. - `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+ `stack` getter, ctor length = 2). - `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting, icache barrier rework). - `1803d6109d98` Speed up `WebAssembly.Table` construction. - `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target runs. - `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`. - `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales. **Yarr / RegExp** - `581f1d958329` Start end-anchored fixed-size regexps at the only possible position. - `a458a6c1f0a7` v-mode class-set op loop: stop early when no more output possible. - `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`. - `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for `ParenContext`. - `1e43057f135a` Extend first-character filter further. - `54916608d7d6` Fix non-BMP advance latch; simplify `tryReadUnicodeCharImpl`. - `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative lookaheads. - `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns. - `98d0367d2247` Fix: `^` inside a paren that can match empty does not anchor the pattern. **Intl / Temporal** - `09917ef55b0f` Add missing `U_FAILURE(status)` check in `actualLunisolarMonthLength`. **Inspector** - `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d` Canvas: instrument & record WebGPU devices/pipelines. - `301d6b2b21f7` Associate WebAssembly module scripts with the fetching resource. - `28b979b1659b` / `479edb2e4395` Site Isolation: implement `Network.loadResource` / `Network.getSerializedCertificate`. - `232cebabc1f3` Remove big-endian support and `CPU(NEEDS_ALIGNED_ACCESS)`. - `e5fa5c604438` Upgrade fast_float to 8.2.10. - `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII case-conversion prefix copy. - `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated `find()`. - `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table off-by-one. - `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64. - `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`. - `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`. - `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete. - `bf15f00ebe95` Remove 12 unused internal-linkage templates (TypeTraits/HashTable/Vector/etc.). - `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang static analyzer. - `158f737725b7` Add helpers for Darwin temp/cache directories. - `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity). - `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE and fix findings. - `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa". - `cfb222f3c4d1` CMake: run `cleandead` at end of configuration. - `6eaa5ac1f65d` Remove 32-bit libpas support. - `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64). - `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in `VMAllocate.cpp`. - `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its should-go-again result. - `90cbe5e85528` libpas: fix benign read from a deallocated TLC. - `e388877954d1` PGM allocator: fix uninitialized `free_status` misclassifying OOB as UAF. - `05c83a6550b7` libpas: fix `MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling MTE. - `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage (scavenging / zeroing / paged-out pages). - **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed), `857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)` removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun patches are now dead. - **`VM` layout**: `f2f2c2ddf637` deletes `StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws `RangeError` instead of returning `""`. - **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule` to propagate the import-attribute `type` — check Bun's module loader hook signatures. - **Register allocator**: `bfb1b1183bc2` removes the B3/Air graph-coloring allocator and its `Options::` toggle. - **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds `__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. — affects anything calling these across the WTF boundary on arm64. - **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as private-only; `WebAssembly.Exception` constructor `length` becomes 2 and gains a `stack` prototype getter. - **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default; `319f94b3db4a` `Iterator.prototype.includes` on by default. - **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee publication and adds `Thread::barrierInstructionCache()` in WTF. <!-- robobun:evidence:begin --> --- **[decide:webkit]** gate passed · iteration 2 · 8 files touched <details><summary>fails on main (without fix)</summary> ```console ASAN without fix: BUILD FAILED (no junit output) $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" ninja: Entering directory `/workspace/bun/build/debug' [1/182] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/182] gen cpp.rs (cppbind) [3/182] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt [4/182] gen JS modules (bundle-modules) Preprocess modules (8715ms) Bundle modules (63ms) Postprocesss modules (24ms) Bundle Functions (746ms) Generate Code (12ms) [9.57s] Bundled "src/js" for development 2749 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) [177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o FAILED: obj/unified/UnifiedSou ... (truncated) release without fix: all passed bun test v1.4.0-canary.1 (385f528) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [152.00ms] __F:0:S:0 ``` </details> <details><summary>passes on PR (with fix)</summary> ```console ASAN with fix: all passed $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" bun test v1.4.0 (59b0de0) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [3.17s] __F:0:S:0 release with fix: all passed $ bun scripts/build.ts --profile=release [configured] bun-profile → bun (stripped) in 676ms (unchanged) ninja: Entering directory `/workspace/bun/build/release' [1/140] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/140] gen cpp.rs (cppbind) [3/140] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt [4/140] gen JS modules (bundle-modules) Preprocess modules (8727ms) Bundle modules (51ms) Postprocesss modules (106ms) Bundle Functions (687ms) Generate Code (20ms) [9.61s] Bundled "src/js" for production 2559 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) ^[[1m^[[92m Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core) ^[[1m^[[92m Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime) ^[[1m^[[92m Compilin ... (truncated) ``` </details> <details><summary>diff hotspot</summary> ``` scripts/build/deps/webkit.ts | 2 +- src/bundler/analyze_transpiled_module.rs | 38 +++-- src/bundler/linker_context/postProcessJSChunk.rs | 8 +- src/bundler_jsc/analyze_jsc.rs | 135 ++++++++++++---- src/js_printer/lib.rs | 191 +++++++++++++++++------ src/jsc/RuntimeTranspilerCache.rs | 5 +- src/jsc/bindings/BunAnalyzeTranspiledModule.cpp | 39 +++-- test/js/bun/jsc/webkit-upgrade-3722912f.test.ts | 106 +++++++++++++ 8 files changed, 416 insertions(+), 108 deletions(-) ``` </details> **gate history** · 5 passed · 1 rejected · iteration 2 <details><summary>evidence per changed file</summary> ``` file reads edits tests scripts/build/deps/webkit.ts 1 1 0 src/bundler/analyze_transpiled_module.rs 3 3 0 src/bundler/linker_context/postProcessJSChunk.rs 1 1 0 src/bundler_jsc/analyze_jsc.rs 13 15 0 src/js_printer/lib.rs 9 16 0 src/jsc/RuntimeTranspilerCache.rs 2 3 0 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp 8 12 0 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts 2 5 0 ``` </details> <!-- robobun:evidence:end --> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Upgrades the WebKit fork to upstream WebKit/WebKit@3722912ff800 (2026-08-02) via oven-sh/WebKit#383. oven-sh/WebKit#383 is merged; `WEBKIT_VERSION` points at the merge commit `e6e37cda216c0292ae68c30c84a9dc8601d0fba5`. ## Bun-side changes Upstream `90b2ecf79ae3` keys `m_loadedModules` on `(specifier, ScriptFetchParameters::Type)` and threads the type through `ImportEntry`, `ExportEntry`, `StarExportEntry`, and `ModuleAnalyzer::appendRequestedModule`. Under `bun test --isolate` (the `BunTranspiledModule` path), Bun'''s synthesized record must agree with what JSC'''s own `ModuleAnalyzer` would produce from the printed source; a mismatch fails the BUN_DEBUG record diff in debug and null-derefs `hostResolveImportedModule` in release. - `analyze_transpiled_module` / `js_printer`: every `RecordKind` now carries one trailing `FetchParameters` slot. `add_import_info_*` and `add_export_info_*` accept it; `finalize()` propagates the source import'''s slot through the Local->Indirect conversion. `RequestedModules` dedupes on `(specifier, Type, phase)`. - `analyze_jsc.rs`: decodes the trailing slot to the JSC `Type` enum and passes it to every `addImportEntry*` / `addIndirectExport` / `addNamespaceExport` / `addStarExport`; buffer validation is per-slot so only the trailing slot accepts the wider `FetchParameters` sentinel range. - `BunAnalyzeTranspiledModule.cpp`: all seven `addImportEntry*` / `add*Export` functions take `uint8_t moduleRequestType` and set `.moduleRequestType` explicitly; `dumpRecordInfo()` prints `type(N)` for import/export/star entries; `static_assert` pins the ordinal values `to_script_fetch_parameters_type()` hardcodes. - `RuntimeTranspilerCache` `EXPECTED_VERSION` -> 25 (esm_record layout change). ## WebKit-side changes (oven-sh/WebKit#383) - 17 merge conflicts resolved in JSC/WTF; fork's `USE(BUN_JSC_ADDITIONS)` hunks preserved. - Fork `ffi/` code adapted to upstream's 32-bit removal (`USE_JSVALUE64` macro deleted, `is64Bit()` removed, `payloadFor` -> `lowWordFor`). - `InspectorDebuggerAgent.cpp`: handle `BunTranspiledModule`/`Synthetic` in new `scriptTypeForScript` switch. - Recorded `01aaa3e0be0c` as ancestor via `-s ours` (oven-sh/WebKit#352 was a squash merge). ## How did you verify your code works? - `bun run jsc:build:debug` builds and the `jsc` shell runs (`-e 'print(42)'` -> `42`). - `bun run build:local -p '42'` links and runs against the local merged WebKit. - oven-sh/WebKit#383 preview build green on all 38 platform variants. - `bun bd -p 'process.versions.webkit'` -> `preview-pr-383-b9ea4dc5`. - New test `test/js/bun/jsc/webkit-upgrade-3722912f.test.ts`: 4/4 pass with `bun bd test`, 3/4 fail with `USE_SYSTEM_BUN=1 bun test` (old JSC lacks `Iterator.prototype.includes`, returns `""` for cyclic join, `WebAssembly.Exception.length === 1`). ## JavaScriptCore/WTF/bmalloc changes since 01aaa3e0be0c (Jul 25) Upstream range: WebKit/WebKit@01aaa3e0be0c...3722912ff800 (474 commits total, 110 touching JSC/WTF/bmalloc, Jul 25 → Aug 2 2026). ### Highlights - `29ceb3c03de3` Remove 32-bit JSValues (JSVALUE32_64 and `CPU(NEEDS_ALIGNED_ACCESS)` deleted). - `857bd4334690` Remove ARMv7 JIT support (ARMv7 is CLoop-only now; drops remaining 32-bit/x86 JIT refs). - `232cebabc1f3` Remove big-endian support and platforms without unaligned loads/stores (WTF + JSC). - `6eaa5ac1f65d` Remove 32-bit libpas support. - `bfb1b1183bc2` Remove the B3/Air graph-coloring register allocator (greedy is the only allocator now). - `0d0080ea539d` Enable WebAssembly Memory64 by default (+ Table64/SIMD follow-ups). - `f2f2c2ddf637` Remove `StringRecursionChecker`; cyclic `toString`/`join` now throws RangeError via stack check (spec-correct). - `319f94b3db4a` Enable `Iterator.prototype.includes()` by default. - `90b2ecf79ae3` `hostResolveImportedModule` now honors import-attribute `type` (module loader behavior change). - `f5716f6401ed` Add `preserve_most` calling convention to fastMalloc APIs on ARM64 (perf + ABI of WTF alloc entry points). ### JavaScriptCore **Runtime / builtins** - `f2f2c2ddf637` Remove StringRecursionChecker; rely on stack-overflow checks. - `cd91e7f128dd` Add fast flag for `ToPrimitive(Object)` calls in runtime. - `173a0bd6d937` Use `defaultToPrimitiveFastAndNonObservable` in `JSObject::toString`. - `960adeccefcd` Fast operation for `Array#shift`. - `92c6650c7947` Add `JSArrayIterator::next` C++ helper. - `cb1c48b3e95f` Extend `Array.from()` Set fast path to `set.keys()/.values()`. - `4a2e724d6789` Fix: `Array.from(set.keys()/.values())` fast path ignored `Symbol.iterator` overrides. - `73e4c589c1e6` Extend `StringSplitCache` to RegExp separators. - `656d3c36830f` / `1d355c27ea88` 8-byte SWAR fast paths in `JSON.stringify` string copy (same-type & upconvert). - `9f9370cc729f` Fix JSON.stringify regression around `toJSON` check. - `2eb77e9c9473` BigInt: implement Crandall reduction. - `39b1bb9cfc85` BigInt: deploy Comba multiplication more broadly. - `319f94b3db4a` Enable `Iterator.prototype.includes()`. - `0731b27c1b60` `Iterator.zip`: use null-prototype objects for options/underlying iterator. - `90b2ecf79ae3` `hostResolveImportedModule` respects module request import-attribute `type`. - `4f54300b848a` Collect diagnostics when `getDirect` returns zero JSValue in `llint_slow_path_get_by_id`. **Parser / bytecompiler** - `c2beca7a439f` Lexer: scan integer tokens in a single pass. - `72ea806faa21` Use overflow-safe range when choosing a switch jump table. **LLInt / DFG / FTL / B3** - `29ceb3c03de3` Remove 32-bit JSValues. - `857bd4334690` Remove ARMv7 JIT support. - `bfb1b1183bc2` Remove B3/Air graph-coloring register allocator. - `68cde6ba2ad3` Make IRO (Air register allocation) faster. - `83540481435f` DFG: allocate `BasicBlock::intersectionOfPastValuesAtHead` only for OSR-entry targets. - `1566615170ec` DFG fix: `EnumeratorNextUpdateIndexAndMode` must require original array structure for `InBoundsSaneChain`. - `e759fa9dd063` LLInt: inline hot path of `op_enter`. - `9610c2113b45` offlineasm: emit ARM64 register-offset addressing for BaseIndex operands. - `4ebed2479144` Speed up `addSortedRange` via binary search. - `1c006b0b0f62` Fix regex `setLastIndex` on 32-bit. **WebAssembly** - `0d0080ea539d` Enable Memory64 feature flag. - `15aa6fad53e3` Memory64: SIMD support. - `bf0425598904` Memory64: expand declared memory limits. - `862994e2cc37` Memory64: validate table import address-type match. - `184ee4c654bd` Memory64: Table64 in OMG tier. - `d202bedc5ff6` Memory64: Table64 in BBQ tier. - `bf6512f84f7d` Support `WebAssembly.Exception` `options.traceStack` (+ `stack` getter, ctor length = 2). - `24527bbb9ac8` Optimize Wasm JITCallee publication (lock splitting, icache barrier rework). - `1803d6109d98` Speed up `WebAssembly.Table` construction. - `d434a41411a3` BBQ: optimize `br_table` for consecutive same-target runs. - `51d3dbaa278e` IPInt: add `DEFINE_IPINT_THUNK_FOR_ENTRY`. - `244cd98f7986` Fix `generateWasmOpsHeader.py` under non-UTF-8 locales. **Yarr / RegExp** - `581f1d958329` Start end-anchored fixed-size regexps at the only possible position. - `a458a6c1f0a7` v-mode class-set op loop: stop early when no more output possible. - `7c5dbbcba110` Extend `ParenthesesSubpatternTerminal`. - `e1def8f4e5fd` Don't save sibling/ancestor-sibling frame slots for `ParenContext`. - `1e43057f135a` Extend first-character filter further. - `54916608d7d6` Fix non-BMP advance latch; simplify `tryReadUnicodeCharImpl`. - `46a4b17efbe9` `optimizeBOL`: don't filter contents of negative lookaheads. - `b128ddd863ab` Fix dot-star-wrapped optimization for sticky patterns. - `98d0367d2247` Fix: `^` inside a paren that can match empty does not anchor the pattern. **Intl / Temporal** - `09917ef55b0f` Add missing `U_FAILURE(status)` check in `actualLunisolarMonthLength`. **Inspector** - `3722912ff800` / `7be5445e4a22` / `e8c97076834e` / `f3e34dde7c9d` Canvas: instrument & record WebGPU devices/pipelines. - `301d6b2b21f7` Associate WebAssembly module scripts with the fetching resource. - `28b979b1659b` / `479edb2e4395` Site Isolation: implement `Network.loadResource` / `Network.getSerializedCertificate`. ### WTF - `232cebabc1f3` Remove big-endian support and `CPU(NEEDS_ALIGNED_ACCESS)`. - `e5fa5c604438` Upgrade fast_float to 8.2.10. - `a288a8ec809b` Widen `find16`/`find32` SIMD threshold; faster ASCII case-conversion prefix copy. - `6cb1077d85c8` `makeStringByReplacingAll()` now uses SIMD-accelerated `find()`. - `5590f2e70615` Fix `AdaptiveStringSearcher` good-suffix shift table off-by-one. - `f5716f6401ed` Add `preserve_most` to most fastMalloc APIs on ARM64. - `f7a9d16e1531` Add `removeIf()` to `WeakHashSet` / `WeakListHashSet`. - `e1fc460b8f1d` Add `removeIf()` to `RobinHoodHashTable`. - `ff1f31c83dc7` Treat creating/destroying a `CheckedPtr` as no-delete. - `bf15f00ebe95` Remove 12 unused internal-linkage templates (TypeTraits/HashTable/Vector/etc.). - `5b84cf3719fa` Use `__builtin_trap` instead of inline asm under clang static analyzer. - `158f737725b7` Add helpers for Darwin temp/cache directories. - `04e3d47960f3` Limit URL size at IPC boundary (Chrome/Blink parity). - `5daad377031c` / `a7ea27dd3bb6` Enable `-Wthread-safety` on GTK/WPE and fix findings. - `7eb640d408f8` CMake: merge Mac and iOS ports into "Cocoa". - `cfb222f3c4d1` CMake: run `cleandead` at end of configuration. ### bmalloc - `6eaa5ac1f65d` Remove 32-bit libpas support. - `f5716f6401ed` `preserve_most` on fastMalloc APIs (ARM64). - `8b8b3e5ee16c` Fix inverted `MADV_ZERO` support latch in `VMAllocate.cpp`. - `ead6285911f6` libpas: `pas_thread_local_cache_for_all` clobbered its should-go-again result. - `90cbe5e85528` libpas: fix benign read from a deallocated TLC. - `e388877954d1` PGM allocator: fix uninitialized `free_status` misclassifying OOB as UAF. - `05c83a6550b7` libpas: fix `MTE_overrideEnablementForJavaScriptCore=true` incorrectly disabling MTE. - `f01297663d40` / `86fb5e3a4eef` / `d18773ec666e` libpas test coverage (scavenging / zeroing / paged-out pages). ### Breaking/notable for Bun - **32-bit purge**: `29ceb3c03de3` (JSVALUE32_64 removed), `857bd4334690` (ARMv7 JIT removed), `6eaa5ac1f65d` (32-bit libpas removed), `232cebabc1f3` (big-endian + `CPU(NEEDS_ALIGNED_ACCESS)` removed). Any `#if USE(JSVALUE64)` / `CPU(ADDRESS32)` guards in Bun patches are now dead. - **`VM` layout**: `f2f2c2ddf637` deletes `StringRecursionChecker.{h,cpp}` and the `stringRecursionCheck*` fields from `VM.h`. Cyclic `Array.prototype.join`/`toString` now throws `RangeError` instead of returning `""`. - **Module loader**: `90b2ecf79ae3` changes `hostResolveImportedModule` to propagate the import-attribute `type` — check Bun's module loader hook signatures. - **Register allocator**: `bfb1b1183bc2` removes the B3/Air graph-coloring allocator and its `Options::` toggle. - **fastMalloc ABI (ARM64)**: `f5716f6401ed` adds `__attribute__((preserve_most))` to `fastMalloc`/`fastFree` etc. — affects anything calling these across the WTF boundary on arm64. - **BuiltinNames**: `bf6512f84f7d` registers `stackPrivateName` as private-only; `WebAssembly.Exception` constructor `length` becomes 2 and gains a `stack` prototype getter. - **Feature defaults**: `0d0080ea539d` Wasm Memory64 on by default; `319f94b3db4a` `Iterator.prototype.includes` on by default. - **Wasm threading**: `24527bbb9ac8` reworks icache barrier / callee publication and adds `Thread::barrierInstructionCache()` in WTF. <!-- robobun:evidence:begin --> --- **[decide:webkit]** gate passed · iteration 2 · 8 files touched <details><summary>fails on main (without fix)</summary> ```console ASAN without fix: BUILD FAILED (no junit output) $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" ninja: Entering directory `/workspace/bun/build/debug' [1/182] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/182] gen cpp.rs (cppbind) [3/182] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/debug/codegen/JSSink.lut.h from /workspace/bun/build/debug/codegen/JSSink.lut.txt [4/182] gen JS modules (bundle-modules) Preprocess modules (8715ms) Bundle modules (63ms) Postprocesss modules (24ms) Bundle Functions (746ms) Generate Code (12ms) [9.57s] Bundled "src/js" for development 2749 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/181] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) [177/181] cxx obj/unified/UnifiedSource-src_jsc_bindings-0.cpp.o FAILED: obj/unified/UnifiedSou ... (truncated) release without fix: all passed bun test v1.4.0-canary.1 (385f52890) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [0.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [2.51ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [0.48ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [8.49ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [22.09ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [152.00ms] __F:0:S:0 ``` </details> <details><summary>passes on PR (with fix)</summary> ```console ASAN with fix: all passed $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" "test/js/bun/jsc/webkit-upgrade-3722912f.test.ts" bun test v1.4.0 (59b0de097) test/js/bun/jsc/webkit-upgrade-3722912f.test.ts: (pass) WebKit 3722912ff800 upgrade > Iterator.prototype.includes is enabled by default (319f94b3db4a) [13.19ms] (pass) WebKit 3722912ff800 upgrade > cyclic Array.prototype.join throws RangeError (f2f2c2ddf637) [10.75ms] (pass) WebKit 3722912ff800 upgrade > WebAssembly.Exception gains options.traceStack and stack getter (bf6512f84f7d) [3.66ms] (pass) WebKit 3722912ff800 upgrade > typed import attributes resolve through BunTranspiledModule (--isolate) (90b2ecf79ae3) [317.28ms] (pass) WebKit 3722912ff800 upgrade > indirect, namespace and star re-exports link on the JSC ModuleAnalyzer path (90b2ecf79ae3) [1138.48ms] 5 pass 0 fail 12 expect() calls Ran 5 tests across 1 file. [3.17s] __F:0:S:0 release with fix: all passed $ bun scripts/build.ts --profile=release [configured] bun-profile → bun (stripped) in 676ms (unchanged) ninja: Entering directory `/workspace/bun/build/release' [1/140] gen generated_host_exports.rs generated_host_exports.rs: 94 exports (host=3, lazy=10, generic=81, rust=0); 238 extern-C blocks audited [2/140] gen cpp.rs (cppbind) [3/140] gen JSSink.{cpp,h,lut.h,rs} generated_jssink.rs: 7 sinks, 84 exported symbols Generating /workspace/bun/build/release/codegen/JSSink.lut.h from /workspace/bun/build/release/codegen/JSSink.lut.txt [4/140] gen JS modules (bundle-modules) Preprocess modules (8727ms) Bundle modules (51ms) Postprocesss modules (106ms) Bundle Functions (687ms) Generate Code (20ms) [9.61s] Bundled "src/js" for production 2559 kb 193 internal modules 13 native modules 90 internal functions across 19 files [4/139] cargo bun_bin → libbun_rust.a (--target x86_64-unknown-linux-gnu) nightly-2026-07-20-x86_64-unknown-linux-gnu unchanged - rustc 1.99.0-nightly (9f36de775 2026-07-19) ^[[1m^[[92m Compiling^[[0m bun_core v0.0.0 (/workspace/bun/src/bun_core) ^[[1m^[[92m Compiling^[[0m bun_runtime v0.0.0 (/workspace/bun/src/runtime) ^[[1m^[[92m Compilin ... (truncated) ``` </details> <details><summary>diff hotspot</summary> ``` scripts/build/deps/webkit.ts | 2 +- src/bundler/analyze_transpiled_module.rs | 38 +++-- src/bundler/linker_context/postProcessJSChunk.rs | 8 +- src/bundler_jsc/analyze_jsc.rs | 135 ++++++++++++---- src/js_printer/lib.rs | 191 +++++++++++++++++------ src/jsc/RuntimeTranspilerCache.rs | 5 +- src/jsc/bindings/BunAnalyzeTranspiledModule.cpp | 39 +++-- test/js/bun/jsc/webkit-upgrade-3722912f.test.ts | 106 +++++++++++++ 8 files changed, 416 insertions(+), 108 deletions(-) ``` </details> **gate history** · 5 passed · 1 rejected · iteration 2 <details><summary>evidence per changed file</summary> ``` file reads edits tests scripts/build/deps/webkit.ts 1 1 0 src/bundler/analyze_transpiled_module.rs 3 3 0 src/bundler/linker_context/postProcessJSChunk.rs 1 1 0 src/bundler_jsc/analyze_jsc.rs 13 15 0 src/js_printer/lib.rs 9 16 0 src/jsc/RuntimeTranspilerCache.rs 2 3 0 src/jsc/bindings/BunAnalyzeTranspiledModule.cpp 8 12 0 test/js/bun/jsc/webkit-upgrade-3722912f.test.ts 2 5 0 ``` </details> <!-- robobun:evidence:end --> --------- Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Merges
WebKit/WebKit@01aaa3e0be0c(2026-07-25) into the fork. 538 upstream commits since the previous sync point (2603e9eb41f0); 117 touchSource/JavaScriptCore,Source/WTForSource/bmalloc.Conflict resolution
Nine files conflicted. Seven were include-block noise from the squash-sync ancestor (the conflict region carried the pre-
<JavaScriptCore/...>include style and stale upstream content):SpeculatedType.h,IncrementalSweeper.h,VM.h,JSModuleRecord.h,WasmIPIntSlowPaths.cpp,UnifiedWebPreferences.yaml,NodesCodegen.cpp. Resolved by taking upstream for the conflict region only, preserving all auto-mergedUSE(BUN_JSC_ADDITIONS)blocks elsewhere in the file.emit_intrinsic_getInternalFieldinNodesCodegen.cppis a real fork addition (Bun's@getInternalFieldbytecode intrinsic) and was kept; the adjacentasyncFromSyncIteratorInternalFieldIndexhelper was stale upstream code and dropped.JSONAtomStringCacheInlines.hkeeps the fork's fallibletryCreateUninitializedpath (#317) rather than upstream'screate8BitIfPossible, soJSON.parseof an unallocatable string still throws instead of crashing.JSMicrotask.cpp: upstream introducedsettleDriverWithIteratorResult(cached iterator-result object for cooperative drivers, bug 319817) and rewrote theAsyncFromSyncIteratorcontinuation path (bug 319435). Adapted the fork'sAsyncContextSwapScopewrapping:settleDriverWithIteratorResultnow takesJSGlobalObject*and wrapstargetwith the current async context internally; the unwrappedtargetis still used for the cached-result identity check so the reuse optimisation is kept.asyncGeneratorCompleteStep/enqueueAsyncGeneratorDrivercall the helper instead of inlining the resolve path.InternalMicrotask::AsyncFromSyncIterator{Continue,Done}unwrap the tuple (resolveWithInternalMicrotaskForAsyncAwaitwraps the iterator on the scheduling side) before the newJSAsyncFromSyncIterator*cast.InternalMicrotask::AsyncModuleExecutionResumeported to the new no-scopeasyncModuleExecutionResumesignature.Follow-up fixes for upstream API changes
AbstractModuleRecord::setImportedModuledrops them_dependencieswrite;m_loadedModulesis the only lookup map now (bug 320144).NodesCodegen.cpprestoresemit_intrinsic_getInternalFieldafter the conflict-region resolution.Bun-side changes required by this merge live in the companion oven-sh/bun PR.