Fix Safari's implementation broken link - #257
Merged
Merged
Conversation
Safari's implementation boken linkSafari's implementation broken link
Collaborator
|
Thanks |
Jarred-Sumner
pushed a commit
that referenced
this pull request
Jul 1, 2026
Bumps `vendor/WebKit` to upstream `WebKit/WebKit@d81bcc3d833c` (2026-06-30). 887 upstream commits since the last Bun sync point (`b5ba38a21e17`, 2026-06-16); 117 touch `Source/JavaScriptCore`, 54 touch `Source/WTF`, 10 touch `Source/bmalloc`. The fork-side work is split across two merge PRs: - oven-sh/WebKit#261: `b5ba38a21e17` to `ce481c4cfedb`, merged as `0d9ee56ba4f6`. - oven-sh/WebKit#263: `ce481c4cfedb` to `d81bcc3d833c`, based on the fork's current `main`, so it also carries oven-sh/WebKit#257 and oven-sh/WebKit#262, which landed on the fork between the two merges and which fix real Bun bugs (see below). > [!NOTE] > oven-sh/WebKit#263 has landed on `main` as `c9ad5813fd23`, and `WEBKIT_VERSION` now points at that commit's release, `autobuild-c9ad5813fd23bd8b98b0738abc3d037ec716aa92`. Nothing else is pending on the WebKit side. It was landed as a squash rather than a merge commit, but `c9ad5813fd23`'s git tree is byte-identical to the preview head `f652829d78`'s tree (verified: both are `470eee60f5`), so the final artifacts are built from exactly the source all of the verification below ran against. The squash does drop the upstream parent link, so whoever does the next fork upgrade will need a merge-base fixup like the one that followed oven-sh/WebKit#251. Fixes #32793 ## Bun changes required by this upgrade ### From `b5ba38a2 -> ce481c4c`: three builtin rewrites Upstream removed three bytecode intrinsics that Bun's built-in JS modules use (https://bugs.webkit.org/show_bug.cgi?id=318076 and https://bugs.webkit.org/show_bug.cgi?id=318028). Bumping the version without these rewrites aborts on every `Buffer.from()` call: ``` ASSERTION FAILED: Private symbol not found: tryGetByIdWithWellKnownSymbol(value, "toPrimitive"); ``` and on `new console.Console(stream).table(...)` (the global `console.table` is native and was unaffected). - `src/js/builtins/JSBufferConstructor.ts`: `$tryGetByIdWithWellKnownSymbol(value, "toPrimitive")` becomes an ordinary `value[Symbol.toPrimitive]` read, which is exactly what Node's `lib/buffer.js` does. The removed intrinsic never invoked accessors, so this is also a Node-compat improvement: a getter-defined `Symbol.toPrimitive` is now honored. `test/js/node/buffer-from-symbol-to-primitive.test.ts` covers it and fails on the released Bun. - `src/js/builtins/ConsoleObject.ts`: `$isMapIterator` / `$isSetIterator` become `require("node:util/types").isMapIterator / isSetIterator`, which is exactly what Node's `internal/console/constructor.js` does. `test/js/node/console/console-table-iterators.test.ts` is a snapshot test that passes on both the released Bun and this branch, proving the rewrite is behavior-preserving (there was no prior coverage for `Console#table` on a Map/Set iterator). - `src/js/builtins.d.ts`: the declarations for all ten removed intrinsics are deleted so nothing reaches for them again. ### From oven-sh/WebKit#257: `jest` fake-time code must use the new `NaN` sentinel oven-sh/WebKit#257 changed the "no override is active" sentinel on `JSGlobalObject::overridenDateNow` from `-1` to `NaN` (see `JSGlobalObject::jsDateNow()`). Bun's reset paths still wrote `-1`, which the new semantics read as a *live* override frozen at `-1` ms, so `jest.useRealTimers()` and `setSystemTime()` with no argument left `Date.now()` stuck at `1969-12-31T23:59:59.999Z`. `test/js/bun/test/test-timers.test.ts` ("we can go back in time") caught this against a Bun built from the #263 artifact. - `src/runtime/test_runner/timers/FakeTimers.rs`: `CurrentTime::clear` (the `jest.useRealTimers()` path) writes `f64::NAN` instead of `-1.0`. - `src/jsc/bindings/JSMockFunction.cpp`, `JSMock__jsSetSystemTime`: the reset value becomes `PNaN`. The old `>= 0` / `std::isnormal()` gating existed only to serve the `-1` sentinel and silently dropped every pre-epoch and zero override (a bug the #257 review called out); with the `NaN` sentinel every real timestamp is a valid override, so `setSystemTime(-1)` and `setSystemTime(new Date("1960-01-01"))` now work. A new test in `test/js/bun/test/test-timers.test.ts` covers the pre-epoch, zero, `-1`, and no-argument-reset cases and fails on Bun 1.4.0. - Deleted `JSMock__jsUseRealTimers` from `JSMockFunction.cpp`: nothing registers it (`jest.useRealTimers` is the Rust `use_real_timers` in `FakeTimers.rs`), and it was the third place that would have needed the sentinel change. `ce481c4c -> d81bcc3d` itself (the 84 upstream commits) requires nothing: no bytecode intrinsics changed, `JSType.h` did not change, and the only WebCore code-generator change is to a helper Bun does not use. ## Bun bugs fixed by the fork-side commits this carries - oven-sh/WebKit#257: `Date.now()` is tagged `DateNowIntrinsic`, so a hot call site is inlined by the DFG/FTL as a `DateNow` node, and `operationDateNow` returned the wall clock instead of reading `JSGlobalObject::overridenDateNow`. A `setSystemTime()` override therefore silently wore off as soon as a `Date.now()` call site tiered up (#32793). `test/regression/issue/32793.test.ts` spawns the loop from that issue and asserts the override never diverges; on the released Bun it diverges at iteration 99, and it also fails against a build of this branch's previous pin (`0d9ee56ba4f6`, which predates #257), so the test isolates exactly this commit. - oven-sh/WebKit#262: a top-level `import()` whose embedder fetch rejects with a value that is not an `ErrorInstance` (a single-message transpile failure rejects with a `BuildMessage`) poisoned its module registry entry, and every later importer of the same file hung forever. The Bun-side regression test lives in #33149, which also pins a WebKit preview; once this lands, #33149 reduces to its test plus its `scripts/sync-webkit-source.ts` improvement. ## Why the regression tests are spawned fixtures Without the three builtin rewrites, a Bun built against this WebKit aborts on the first `Buffer.from()` call: ``` ASSERTION FAILED: Private symbol not found: tryGetByIdWithWellKnownSymbol(value, "toPrimitive"); ``` `Buffer.from` is fundamental enough that this takes down the `bun test` runner itself, before any test file finishes loading and before the JUnit reporter can write anything. So `buffer-from-symbol-to-primitive.test.ts` and `console-table-iterators.test.ts` live in two small files of their own and spawn a child Bun instead of calling the affected APIs in process: a child abort becomes an ordinary `exitCode`/`stdout` assertion failure, whereas an in-process call takes the parent test runner down with it and reports nothing. Their fail-before is "this branch minus the `src/js/` rewrites", which is a deterministic SIGABRT: ```sh git checkout $(git merge-base HEAD origin/main) -- src/js/ # keep scripts/ (the WEBKIT_VERSION bump) bun bd test test/js/node/buffer-from-symbol-to-primitive.test.ts # => ASSERTION FAILED: Private symbol not found: tryGetByIdWithWellKnownSymbol(...) (SIGABRT) git checkout HEAD -- src/js/ ``` `test/js/bun/test/test-timers.test.ts` is the equivalent fail-before for the sentinel change: with the `src/` diff reverted but the new WebKit kept, both "we can go back in time" and the new `setSystemTime` test fail. `test/regression/issue/32793.test.ts` is different from all of the above: its fix lives entirely in the vendored engine, selected by `scripts/build/deps/webkit.ts` rather than by anything under `src/`. So its before/after is a function of which WebKit artifact is linked, not of the `src/` diff: it fails on the released Bun (1.4.0), fails against this branch built with the previous pin `0d9ee56ba4f6`, and passes against this branch built with the #263 artifact. ## Verification All of the following were run against a debug Bun built from this branch and the `autobuild-preview-pr-263-f652829d` artifact. - The four test files this PR adds or modifies (`test/js/bun/test/test-timers.test.ts`, `test/regression/issue/32793.test.ts`, `test/js/node/buffer-from-symbol-to-primitive.test.ts`, `test/js/node/console/console-table-iterators.test.ts`): 5 tests, all pass. Every one fails in the right "before" state as described above. - Every test file in the repo that exercises `setSystemTime` / `useFakeTimers` / `useRealTimers` / `advanceTimers*` (the blast radius of the sentinel change): `test/js/bun/test/fake-timers/fake-timers.test.ts`, `test/js/bun/test/fake-timers/sinonjs/fake-timers.test.ts`, `test/js/bun/cron/in-process-cron.test.ts`, `test/regression/issue/25869.test.ts`, `test/regression/issue/26284.test.ts`, and the five `test/js/third_party/jsonwebtoken/*.test.js` suites. 249 pass, 1 todo, 0 fail. - One more file turned out to be in that blast radius: `test/js/bun/test/fake-timers/sinonjs/issue-207.test.ts`. The sentinel change makes pre-epoch and negative clock values work, so its three long-`.failing` tests ("should floor negative now values", "should floor negative start times", "should handle ticks on the negative side of the Epoch") started passing, which Bun's runner reports as a failure until the stale marker is removed. `d2309c92c2` removes them; all ten tests in the file pass against this branch. - `test/js/node/buffer.test.js`: 539 pass, 1 pre-existing skip, 0 fail. `test/js/node/console/console.test.ts`: 7 pass. Neither file is modified by this PR. - oven-sh/WebKit#263's preview build produced all 43 platform artifacts with no job failures. ## Upstream changelog <details> <summary><code>ce481c4c</code> -> <code>d81bcc3d</code> (the new hop in this revision)</summary> Memory safety and security: - `TypedArray.from()` out-of-bounds read via resizable `ArrayBuffer` resize/transfer inside the `mapFn` callback - Stale structure bit in `SlowPutArrayStorage` - Do not cache property absence on dictionary structures - Missing `codeBlock->m_lock` in `repatchGetBySlowPathCall` - Insert a write barrier for `MultiPutByOffset` when it can reallocate storage - Unconditionally keep `OMGOSREntryCallee` alive while updating its callsites - Disallow defining private names on WasmGC objects - Size limit on Yarr-generated code Correctness: - DFG spread did not account for `cellButterflyOnlyAtomStringsStructure` - YarrJIT `negativeOffsetIndexedAddress` discarded the adjusted base register - `DFGArgumentsEliminationPhase::removeViaKill` did not reset the node scan index between `InlineCallFrame`s Other: - An `ArrayStorage`-specific `GetByVal` DFG operation - ES2022 private method support in the Web Inspector - WTF: `TinyLRUCache::findIfCached` / `insert` </details> <details> <summary>Security / correctness fixes (<code>b5ba38a2</code> -> <code>ce481c4c</code>)</summary> - Use-after-free after Wasm memory grow via a stale pointer folded by DFGConstantFoldingPhase - Keep `JSWebAssemblyMemory` alive from wasm-originated `JSArrayBuffer`s (UAF) - Use-after-free of `StreamingCompiler::m_ticket` - `BBQCallee` kept alive between callsite collection and repatch (upstreams and extends oven-sh/WebKit#210) - `Array.from(arguments)` fast path bails out past `MAX_STORAGE_VECTOR_LENGTH` - `JSArray::fastFlat` bounds-checked against the maximum legal length - `Array#flat` fast path was dropping prototype-backed holes in nested arrays - `Array.from(map.keys())` fast path was ignoring `Symbol.iterator` overrides - `RegExp#@@split` crash on a huge flags string - `LiteralParser` takes the slow path if the original structure changes - Missing exit-profile bails on some DFG nodes - `IteratorClose` in `forEachInIterable` uses the Map/Set's own realm's iterator structure - YARR: JIT backreference with a non-BMP character was skipping the next match start position - Wasm Memory64: fix parsing of data segment init expressions - Track `customSlotBase` for `CustomAccessorGetter` / `CustomAccessorSetter` - Set `MayStoreHole` appropriately; `"entries"` ArrayIterator emits `ExitOK` before `NewArray` - `poisonedDeadOSRExitValue` made crashier and on by default in debug builds </details> <details> <summary>Language features and spec alignment (<code>b5ba38a2</code> -> <code>ce481c4c</code>)</summary> - BigInt Math proposal implemented - Temporal: spec-alignment passes across `PlainDate`, `PlainTime`, `Duration`, `Instant`, plus a unified `ParseISODateTime` - `Intl.PluralRules` reflects `compactDisplay` in its skeleton and `resolvedOptions()` </details> <details> <summary>Performance (<code>b5ba38a2</code> -> <code>ce481c4c</code>)</summary> JavaScript-visible fast paths: - `JSON.stringify` space/indentation argument handled by `FastStringifier` - Fast path for the `RegExp#flags` getter; cached named-capture `groups` Structure on `RegExp` - Map/Set iterator `next` and `%RegExpStringIteratorPrototype%.next` moved to C++ - int32 fast path in `parseInt` for short decimal strings - `NumericStrings` int cache lookup inlined into DFG/FTL `ToString(Int32)` - `Object#isPrototypeOf` uses the `InstanceOf` DFG node - `Object.freeze` / `seal` / `preventExtensions` no longer allocate `ArrayStorage` for `NonArray` objects - Map/Set `set` + `delete` churn no longer expands then immediately shrinks - Avoided an intermediate `StringImpl` allocation feeding `StringBuilder` into `makeString` - Wasm `intoCharCodeArray` bulk-copies 8-bit strings; unnecessary watchpoints avoided - `DFG::GetByVal` widens to `SpecBytecodeTop` instead of forcing an OSR exit on an empty value profile YARR (the RegExp engine): - `latin1Table` for efficient Char8 filtering, reused for Char16 and the interpreter - `StringList` optimization when captures are unused; atom fast path enabled for unicode patterns JIT compile time (a large batch aimed at DFG/FTL/B3/Air throughput): - Semi-NCA algorithm for `WTF::Dominators`; reverse post-order in `WTF::Liveness` and B3 `ReduceStrength`; `SparseBitVector` in `DFGLivenessAnalysis` - Unified `SSACalculator`; dominance frontiers computed once per graph - `AirFixObviousSpills`, `AirEliminateDeadCode`, `Air::RegLiveness`, and the greedy register allocator all got cheaper - B3 CSE reimplemented without `B3::Variable`; `B3::Value::effects` uses a constant table - `ReduceStrength` avoids fixed-point iteration; `InferSwitch` disabled in B3 for Wasm - Fixup-inserted `RegExp` primordial `TryGetById` chains replaced with a single `CheckStructure` - Parser: create save points only when actually needed - Baseline/LLInt profile `op_unsigned` overflow and report int32 overflow to the DFG </details> <details> <summary>WTF, bmalloc, and the build system (<code>b5ba38a2</code> -> <code>ce481c4c</code>)</summary> - `SaturatedArithmetic.h` and its APIs renamed to `Saturating` (Bun does not use these directly) - Checked arithmetic helpers now require two or more arguments - `OrderedHashTable` load-factor policy aligned with `HashTable` - `JSON::Value::dump` no longer corrupts large string values via `PrintStream` truncation - Structured clone: the remaining terminal JS value tags moved from WebCore into JSC (`CloneSerializerBase.h` / `StructuredCloneTags.h`). Bun keeps its own fork of `SerializedScriptValue.cpp`, so this is additive. - Workaround for a GCC 14+ false `-Wuninitialized` in `Variant`; `[[msvc::no_unique_address]]` used on MSVC - WTF / libpas exception codes changed to `0xbb08` - libpas: per-heap tagging policy rework; `pas_deallocate` split into inline-only and casual variants; PGO applied to WTF/bmalloc - CMake: prefix headers expanded, headermap generation reworked, stale staged headers pruned, and the Darwin platform block in `BPlatform.h` / `pas_platform.h` no longer excludes CMake builds (restored in the fork, see oven-sh/WebKit#261; without it the Linux-to-macOS cross lane fails to link `gigacageEnabledForProcess`) </details>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.