Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions Source/JavaScriptCore/runtime/JSGlobalObject.h
Original file line number Diff line number Diff line change
Expand Up @@ -691,6 +691,9 @@ class JSGlobalObject : public JSSegmentedVariableObject {
bool m_webAssemblyEnabled { true };
bool m_needsSiteSpecificQuirks { false };
bool m_canDoASCIIUCADUCETLocaleCompare { false };
#if USE(BUN_JSC_ADDITIONS)
bool m_allowsProxyInPrototypeChain { false };
#endif
unsigned m_globalLexicalBindingEpoch { 1 };
String m_evalDisabledErrorMessage;
String m_webAssemblyDisabledErrorMessage;
Expand Down Expand Up @@ -1348,6 +1351,16 @@ class JSGlobalObject : public JSSegmentedVariableObject {
bool needsSiteSpecificQuirks() const { return m_needsSiteSpecificQuirks; }
JS_EXPORT_PRIVATE void exposeDollarVM(VM&);

#if USE(BUN_JSC_ADDITIONS)
// A global object is normally an immutable prototype exotic object, so a Proxy can never reach its
// prototype chain, and ProgramExecutable::initializeGlobalProperties rejects a chain that holds one.
// An embedder whose global object has a mutable prototype (node:vm contexts, where jsdom installs a
// Proxy in the chain of the window) opts out of that rejection here. Global declaration instantiation
// only reads own properties of the global object, so no Proxy trap runs while a program links.
bool allowsProxyInPrototypeChain() const { return m_allowsProxyInPrototypeChain; }
void setAllowsProxyInPrototypeChain(bool allows) { m_allowsProxyInPrototypeChain = allows; }
#endif

#if JSC_OBJC_API_ENABLED
JSWrapperMap* wrapperMap() const { return m_wrapperMap.get(); }
void setWrapperMap(JSWrapperMap* map) { m_wrapperMap = map; }
Expand Down
17 changes: 12 additions & 5 deletions Source/JavaScriptCore/runtime/ProgramExecutable.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -117,11 +117,18 @@ JSObject* ProgramExecutable::initializeGlobalProperties(VM& vm, JSGlobalObject*
if (error.isValid())
RELEASE_AND_RETURN(throwScope, error.toErrorObject(globalObject, source()));

JSValue nextPrototype = globalObject->getPrototypeDirect();
while (nextPrototype && nextPrototype.isObject()) {
if (asObject(nextPrototype)->type() == ProxyObjectType) [[unlikely]]
return createTypeError(globalObject, "Proxy is not allowed in the global prototype chain."_s);
nextPrototype = asObject(nextPrototype)->getPrototypeDirect();
#if USE(BUN_JSC_ADDITIONS)
bool rejectProxyInPrototypeChain = !globalObject->allowsProxyInPrototypeChain();
#else
bool rejectProxyInPrototypeChain = true;
#endif
if (rejectProxyInPrototypeChain) {
JSValue nextPrototype = globalObject->getPrototypeDirect();
while (nextPrototype && nextPrototype.isObject()) {
if (asObject(nextPrototype)->type() == ProxyObjectType) [[unlikely]]
return createTypeError(globalObject, "Proxy is not allowed in the global prototype chain."_s);
nextPrototype = asObject(nextPrototype)->getPrototypeDirect();
}
}

JSGlobalLexicalEnvironment* globalLexicalEnvironment = globalObject->globalLexicalEnvironment();
Expand Down
Loading