Remove dead code from the build scripts, the vscode and debug-adapter packages, the bake overlay, and two WebCore files - #40122
Conversation
|
Warning Review limit reached
On-demand reviews are free for the next 27 days. After that, they cost $0.25 per reviewed file. Or wait 23 minutes for your next included review. View limit detailsLimit details: You’ve used all 5 included reviews currently available. Review configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (23)
Comment |
|
Updated 9:31 PM PT - Aug 24th, 2026
❌ @robobun, your commit 9ee1796 has 1 failures in
🧪 To try this PR locally: bunx bun-pr 40122That installs a local version of the PR into your bun-40122 --bun |
|
Ready for review. The diff only removes code that has no callers, so there is no behavior that a test can observe before and after the change, and no failing-before test to add. |
There was a problem hiding this comment.
I reviewed this and didn't find any bugs beyond the doc nit already posted inline. Given the breadth — 27 files across the build system (removing an entire BuildSpec variant), the published vscode extension, WebCore C++ TUs, and Rust FFI ownership code in bun_string_jsc.rs — a human look is still worthwhile.
What was reviewed
- Confirmed no dep uses
kind: "cargo";dirnameimport correctly dropped,quoteArgsstill used. runUnsavedCodeindebug.tswas a duplicate — the live copy inextension.tsstill registersextension.bun.runUnsavedCode;web-extension.tshas nopackage.jsonbrowserentry.whenPromiseIsSettled,Bun__startLoop,Adapter.reverseRequest,terminalProfile,global-state.tshave zero remaining references.SliceWithUnderlyingStringJsc::to_js— onlytransfer_to_jsis called (types.rs:385); the inlinedtransfer=truepath is byte-equivalent to the old code.
Extended reasoning...
Overview
Scheduled dead-code sweep removing ~837 lines across 27 files: the cargo BuildSpec variant and its ninja rules from scripts/build/source.ts (plus doc updates), unused helpers in the vscode/debug-adapter/release/inspector packages (including the duplicate runUnsavedCode, the empty web-extension.ts entry point, the semver dependency, and global-state.ts), the unused highlight() render path in the bake overlay's syntax highlighter, two definition-free WebCore TUs (JSDOMPromise.cpp, ServerTiming.cpp), an unused extern in ScriptExecutionContext.cpp, and the non-transfer SliceWithUnderlyingStringJsc::to_js path in Rust. One new test pins the syntaxHighlight() output.
Security risks
None identified. Pure deletions of unreferenced code plus one behavior-preserving inline of a boolean-parameterized helper. No auth, crypto, or input-validation paths touched.
Level of scrutiny
Moderate-to-high. Individually each deletion is mechanical, but the aggregate touches infrastructure everyone depends on: removing a BuildSpec variant affects how build.ninja is generated for every profile, dropping a vscode entry point affects a published artifact, and the bun_string_jsc.rs change — while a straight inline of the transfer=true branch — sits in FFI ownership-transfer code where the repo's review rules demand extra care. I spot-checked each category (grep for remaining references, verified the vscode command is still registered elsewhere, confirmed no dep declares kind: "cargo", traced the one SliceWithUnderlyingString trait consumer to transfer_to_js only) and found nothing wrong, but 27 files across five subsystems exceeds what I'd approve without a maintainer glance.
Other factors
The prior run's inline nit (stale ``/cargo``` fragment at deps/README.md:72`) is still unaddressed — doc-only, doesn't block. The PR description records thorough verification (`bun bd`, `rust:check-all` on 12 targets, tsc on both TS packages, targeted test runs). No human reviewer has weighed in yet.
|
The README nit from the inline review is fixed in f4dbdd9 (the review ran against the earlier head). No other review findings are open. |
There was a problem hiding this comment.
LGTM — the README nit from the earlier pass is fixed in f4dbdd9, and re-checking the current head found nothing new.
What was reviewed:
- Confirmed no
kind: "cargo"deps remain, so theCargoBuild/emitCargo/dep_cargo*removal insource.tsis unreachable code. runUnsavedCodeindebug.tswas a duplicate — the live one inextension.tsis whatextension.bun.runUnsavedCodeis registered to;package.jsonhas nobrowserfield, so droppingweb-extension.tsfrom the esbuild entry points is safe.whenPromiseIsSettled,Bun__startLoop,downloadAsset,terminalProfile,Adapter.reverseRequest,global-state.ts, and the removed overlay methods/options have zero remaining references.- The
bun_string_jsc.rschange just inlinestransfer = trueinto the sole remaining caller;SliceWithUnderlyingStringJscis still used (fortransfer_to_js) insrc/runtime/node/types.rs.
Extended reasoning...
Overview
Scheduled dead-code sweep, net −837 lines across 27 files: the unused cargo BuildSpec variant and its ninja rules in scripts/build/, unused helpers/files/deps in bun-vscode, bun-debug-adapter-protocol, bun-release, and bun-inspector-protocol, an alternate render path in the bake error-overlay highlighter, two definition-free WebCore TUs (JSDOMPromise.cpp, ServerTiming.cpp), an orphan extern "C" decl in ScriptExecutionContext.cpp, and the never-taken transfer=false branch of SliceWithUnderlyingStringJsc. A new test/bake/syntax-highlighter.test.ts pins the live syntaxHighlight() output.
Since the previous review
I reviewed the earlier head and left one doc nit (a stale ``/cargo``` fragment in deps/README.md`). Commit f4dbdd9 fixed exactly that; nothing else changed. This pass re-verified the deletions against the current tree via targeted greps: no dep declares `kind: "cargo"`; `extension.bun.runUnsavedCode` resolves to the surviving implementation in `extension.ts`; `package.json` has only `"main"` (no `"browser"` entry) so `web-extension.ts` was never packaged; and none of `whenPromiseIsSettled`, `Bun__startLoop`, `downloadAsset`, `terminalProfile`, `Adapter.reverseRequest`, `global-state`, `consumeTemplateString`, `shouldRedactSensitive`, or the removed `HighlighterOptions` fields have any remaining reference.
Security risks
None. Pure deletions of unreferenced code plus doc/comment updates; no new inputs, parsing, auth, or trust boundaries.
Level of scrutiny
Broad (build system, native bindings, VS Code extension) but every hunk is a mechanical removal of code with zero call sites, and the one non-deletion edit (bun_string_jsc.rs) is a straight inlining of transfer = true. The PR body documents bun bd, rust:check-all across 12 targets, --configure-only, and tsc on both affected TS projects, which covers the compile-time reachability that dead-code deletion needs.
Other factors
The prior inline finding is resolved; the bug-hunting system found nothing this run. The added snapshot test guards the overlay's remaining render path against regressions from the highlighter refactor.
f4dbdd9 to
af75834
Compare
There was a problem hiding this comment.
I re-reviewed after the README nit was addressed and found no issues. Given the breadth (27 files, −837 lines across the build system, VS Code extension entry points, WebCore C++, and Rust FFI), a human sanity-check would still be worthwhile.
What was reviewed
- Spot-checked ~a dozen deletions for zero callers:
runUnsavedCode(duplicate — live copy is inextension.ts),web-extension.ts(nobrowserentry in package.json),Adapter.reverseRequest,terminalProfile,global-state.ts,downloadAsset,whenPromiseIsSettled,Bun__startLoopextern, thesemverdep, andkind: "cargo"inscripts/build/deps/— all confirmed unreferenced. JSDOMPromise.cpp/ServerTiming.cppare not listed in any explicit source manifest (globbed), so deletion leaves no dangling reference.- The Rust
slice_with_underlying_string_into_jsinlining is a straight constant-fold oftransfer = true; the consuming-selfsignature already implied transfer semantics. - The prior doc nit (line 72 of
deps/README.md) is fixed in the current head.
Extended reasoning...
Overview
Scheduled dead-code sweep removing ~837 lines across 27 files in five areas: (1) the cargo BuildSpec variant and its ninja rules from scripts/build/source.ts plus doc mentions; (2) unused helpers, a duplicate runUnsavedCode, the empty web-extension.ts entry, global-state.ts, and the semver dep from the VS Code / debug-adapter / release / inspector packages; (3) an unused second render path in the bake error-overlay highlighter; (4) JSDOMPromise.cpp (only defined whenPromiseIsSettled, no callers), the empty ServerTiming.cpp TU, and an unused Bun__startLoop extern; (5) the unused SliceWithUnderlyingStringJsc::to_js trait method, with the shared body inlined into into_js at transfer = true. One new test pins syntaxHighlight() output.
Security risks
None identified. Pure removals of unreferenced code; no auth, crypto, permission, or input-validation paths touched. The removed shouldRedactSensitive was itself never called.
Level of scrutiny
Medium-high. Each deletion is mechanical and I verified a representative dozen via grep, but the aggregate is large and spans critical infrastructure: the build-system's dependency dispatch (resolveDep/computeDepLibs), a shipped VS Code extension's build entry points, and native WebCore/Rust FFI. The build system in particular is load-bearing for every CI lane, and the VS Code extension has external consumers whose package.json contribution points I only partially cross-checked.
Other factors
- My earlier README nit was addressed (commit f4dbdd9); the diff now reads
nested-cmakeonly. - The one non-pure-deletion (Rust inlining) is a trivially correct constant-fold — the removed
transfer=falsebranch was the only difference, andinto_jstakesselfby value so transfer was already the contract. - PR body reports
bun bd,bun run rust:check-all(12 targets),tscon both TS packages, and--configure-onlyall pass, which would catch any stray reference to a deleted symbol. - Deferring rather than approving because the change is large and touches build infrastructure + a shipped extension; the guidelines favor a human look at that scale even when no defects are found.
… packages, bun-inspector-frontend, the bake error overlay, and two WebCore files scripts/build: the `cargo` dependency BuildSpec (CargoBuild, emitCargo, the dep_cargo and dep_cargo_cross ninja rules and the matching branches in resolveDep and computeDepLibs). No dependency has used `kind: "cargo"` since lolhtml became a cargo path dependency of the workspace. Also Ninja.variable() and tty.red, which nothing calls. The docs that described the cargo dep kind are updated. packages/bun-vscode: global-state.ts (no importer), web-extension.ts (built but never loaded: package.json has no `browser` entry), the second runUnsavedCode in features/debug.ts (extension.ts registers its own), TerminalDebugSession.terminalProfile, two unused event interfaces, EditorStateManager.getVisibleEditorsWithErrors, a commented-out block that referenced the deleted global-state API, and three unused mock types. packages/bun-debug-adapter-protocol: the commented-out body of the Console.messageAdded handler (2023) and the helpers only it referenced (consoleMessageGroup, consoleLevelToAnsiColor), sourceToPath, isSameLocation, locationIsSame, the never-called #reverseRequest and its Adapter.reverseRequest event (plus the listener in bun-vscode), and the unused semver dependency. packages/bun-inspector-frontend: the whole package. Its build script reads WebInspectorUI from src/bun.js/WebKit, a path that no longer exists, and nothing references the package. packages/bun-release: downloadAsset. packages/bun-inspector-protocol: test/inspector/worker.js, which no test spawns. src/runtime/bake/client/JavaScriptSyntaxHighlighter.ts: the unused highlight(), buildHtmlElement, consumeTemplateString, shouldRedactSensitive, sensitivePatterns and the options only they read. The overlay only uses syntaxHighlight() -> highlightLine(). src/jsc: JSDOMPromise.cpp (DOMPromise::whenPromiseIsSettled, never called) with its declaration and enum, ServerTiming.cpp (a TU with no definitions), a stale Bun__startLoop prototype, and the unused SliceWithUnderlyingStringJsc::to_js path in bun_jsc.
Its build script produces the debug.bun.sh bundle from a WebKit checkout outside this repo, and #36288 changes it. It is a manual tool, not dead code.
af75834 to
c04a718
Compare
There was a problem hiding this comment.
I reviewed this PR and didn't find any bugs (the earlier README nit is fixed). Because it's a large sweep across five subsystems — the build-system source.ts losing the entire cargo BuildSpec path, two WebCore TUs deleted, and shipped bun-vscode surface removed — a human look would still be worthwhile.
What was reviewed:
- Confirmed no
kind: "cargo"dep remains inscripts/build/deps/, and no caller ofNinja.variable()/tty.red. - Confirmed
extension.bun.runUnsavedCodestill resolves viaextension.ts(the deleteddebug.tscopy was the duplicate);package.jsonhas nobrowser/web-extension entry. - Confirmed
whenPromiseIsSettled,Bun__startLoop,global-state.ts,downloadAsset,worker.js, and the removed bake highlighter methods have zero remaining references. - The overlay only calls
syntaxHighlight()→highlightLine(); the new snapshot test pins that path.
Extended reasoning...
Overview
Scheduled dead-code sweep touching 25 files (-824 / +30). Five clusters: (1) scripts/build/source.ts drops the CargoBuild variant, emitCargo(), the dep_cargo/dep_cargo_cross ninja rules, and the matching branches in resolveDep/computeDepLibs, plus doc/comment updates in CLAUDE.md, deps/README.md, rules.ts, rust.ts, and unused Ninja.variable()/tty.red; (2) bun-vscode and bun-debug-adapter-protocol lose unused helpers, the Adapter.reverseRequest event + listener, a duplicate runUnsavedCode, terminalProfile, global-state.ts, web-extension.ts, mock types, and the semver dep; (3) bun-release loses downloadAsset; (4) two WebCore TUs (JSDOMPromise.cpp, ServerTiming.cpp) and an unused extern in ScriptExecutionContext.cpp; (5) the bake overlay's second render path (highlight(), buildHtmlElement, consumeTemplateString, shouldRedactSensitive, sensitivePatterns, and unused HighlighterOptions fields), with a new snapshot test pinning syntaxHighlight().
Verification performed
I grepped for every deleted symbol/file to confirm zero remaining references: no kind: "cargo" in any dep spec; runUnsavedCode still lives in extension.ts and is command-registered there (the debug.ts export was the dead duplicate); no browser entry in bun-vscode/package.json for web-extension.ts; overlay.ts imports only syntaxHighlight; no callers of whenPromiseIsSettled, Bun__startLoop, downloadAsset, typedGlobalState, terminalProfile, MockTextDocument, or the removed adapter helpers. The dirname import removed from source.ts was only used by emitCargo. The earlier inline nit (stale /cargo fragment at README line 72) is resolved in the current diff.
Security risks
None identified. Pure deletions of unreferenced code plus doc/comment updates; no new inputs, no auth/crypto/permission surface touched.
Level of scrutiny
Medium-high. Individually each deletion is mechanical, but the aggregate spans build infrastructure that every CI lane runs through, a shipped VS Code extension, and JSC WebCore bindings. Removing a BuildSpec variant and two compiled TUs is the kind of change where a maintainer familiar with pending work (e.g., whether anything is about to reintroduce a cargo dep, or whether web-extension.ts was a stub for planned web-mode support) should confirm intent.
Other factors
The prior review round found only a doc nit, now fixed. The PR author verified bun bd, rust:check-all, --configure-only, and tsc on the affected packages. The new test/bake/syntax-highlighter.test.ts is a reasonable pin for the surviving path (though by design it also passes on main). Given the breadth across five subsystems and the repo's guidance that dead-code deletions still warrant sign-off on what's being removed, I'm deferring rather than shadow-approving.
There was a problem hiding this comment.
I re-reviewed after the README fix in f4dbdd9 and found no issues. Given the breadth — build-system infrastructure (source.ts's BuildSpec union), the published VSCode extension, and native WebCore TUs — a human sanity check is still worthwhile.
What was reviewed:
- Confirmed no
scripts/build/deps/*.tsuseskind: "cargo";ninjaEscapeVarValueis still used bybuild()aftervariable()is removed;gamble.ts'sredis local, not fromtty.ts. - Verified
extension.bun.runUnsavedCoderemains registered inextension.ts(the deleted copy indebug.tswas the duplicate); nopackage.jsonbrowserentry points atweb-extension.ts; nothing importsglobal-state.ts. - Confirmed zero references to
whenPromiseIsSettled,Bun__startLoop,Adapter.reverseRequest,downloadAsset,terminalProfile, and the removed bake-highlighter methods;JSDOMPromise.cpp/ServerTiming.cppappear in no source list (globbed).
Extended reasoning...
Overview
Scheduled dead-code sweep removing ~824 lines across 25 files: the cargo BuildSpec variant and its ninja rules from scripts/build/source.ts, unused helpers in ninja.ts/tty.ts, dead helpers and a duplicate runUnsavedCode in the bun-vscode/bun-debug-adapter-protocol/bun-release packages, two entirely-deleted vscode source files, an unreachable render path in the bake error-overlay highlighter, and two WebCore TUs (JSDOMPromise.cpp, ServerTiming.cpp). One new test pins the surviving syntaxHighlight() output.
Security risks
None. Pure deletions of unreferenced code plus doc/comment updates and a lockfile trim; no new inputs, no changed validation, no auth/crypto surface.
Level of scrutiny
Medium-high. Each deletion is individually mechanical and I grep-verified the key ones (no dep uses kind: "cargo"; the runUnsavedCode command is still registered in extension.ts; web-extension.ts isn't referenced from package.json; whenPromiseIsSettled/Bun__startLoop have zero hits; the deleted .cpp files aren't in any explicit source list). But the PR simultaneously touches core build infrastructure, a published VSCode extension, and native bindings — a human glance at that combination is prudent even when each piece checks out.
Other factors
My prior review's only finding (stale /cargo fragment in deps/README.md line 72) is confirmed fixed in the current diff. The PR body documents thorough verification (bun bd, rust:check-all, --configure-only, tsc on both affected TS projects). No outstanding reviewer comments remain.
…sc JSC bindings (#40413) ### Problem - Four Rust host exports have no C++ caller: `Bun__WebSocketClient__writeBlob`, `Bun__WebSocketClientTLS__writeBlob`, `Bun__WebSocketClientTLS__initWithTunnel`, and `Bun__internal_drainTimers`. `WebSocket.cpp` converts a Blob to bytes itself and calls `writeBinaryData`, and the tunnel path only creates the non-TLS client. The `HOST_EXPORT` marker roots each of them, so neither rustc nor hawk can see that they are dead. - A handful of C++ methods are declared and defined but never called: `HTTPParser::lessThan`, one `JSNodePerformanceHooksHistogram::create` overload, `JSAbortAlgorithm::callbackData` and `toJS(AbortAlgorithm&)`, `JSPerformance::toWrapped`, `JSCStackFrame::typeName`, `root(CryptoKey*)`, the `String` overload of `throwNodeRangeError`, and 16 ncrypto helpers. - Two `pub` Rust items have no caller in any crate: `bun_base64::simdutf_encode_url_safe_alloc` and `CowSliceZ::init_unchecked`. ### Fix - Delete the items above. `WebSocketClient::write_blob` goes with its exports. `encode_append_impl` folds into `encode_append`, its only remaining caller. The ncrypto `Ec` class keeps its one live member, `GetCurveIdFromName`. - Every deletion is confirmed two ways: `rg` over `src/`, `build/debug/codegen/`, `src/codegen/`, `packages/`, and `vendor/WebKit` finds no reference, and a `bun-debug` relink with `--gc-sections --print-gc-sections` discards each symbol. `host_fn_this_value` and `root(MessagePort*)` looked the same way and stay: codegen emits the first, and #39841 is editing `MessagePort.cpp`, so the second waits for that fix to land. - New source lint `test/internal/source-lints/host-export-callers.test.ts`: every `c`/`jsc` `HOST_EXPORT` marker must be named by a C or C++ source. It fails on main with exactly the four exports above and passes here. - Verified: `bun bd` builds, `bun run rust:check-all` passes on all 12 targets, `clang-format` and `cargo fmt` are clean. Ran `test/js/web/websocket/` (blob, client, bidir proxy), `test/js/node/crypto/` (crypto, ecdh, hmac, sign, x509), `node-http`, `node-http-parser`, `perf_hooks`, and `abort`. ### Background - `// HOST_EXPORT(Name, c)` marks a Rust fn that `src/codegen/generate-host-exports.ts` wraps in an `extern "C"` thunk for C++. The thunk exists whether or not C++ calls it, so an orphaned export compiles without a warning. - ncrypto (`src/jsc/bindings/ncrypto.{cpp,h}`) is Bun's copy of Node's OpenSSL helper layer. Node still uses the removed helpers; Bun's callers never did. - The linker check: a debug link with `-Wl,--gc-sections -Wl,--print-gc-sections` lists every function section nothing references. A function that is discarded and also absent from the linked binary has no caller on that platform. Platform-gated code then needs a source check, which is why the darwin-only `Bun__noOrphans_*` and the Windows-only `windowsEnv` builtin stay. <details><summary>Notes</summary> Removed, by file: - `src/http_jsc/websocket_client.rs`: `bun__websocketclient__write_blob`, `bun__websocketclienttls__write_blob`, `bun__websocketclienttls__init_with_tunnel`, `WebSocketClient::write_blob`, and the now unused `JSValue` import. - `src/runtime/timer/Timer.rs`: `drain_timers_export` (`Bun__internal_drainTimers`). - `src/base64/lib.rs`: `simdutf_encode_url_safe_alloc`; `encode_append_impl` folded into `encode_append`. - `src/ptr/CowSlice.rs`: `CowSliceZ::init_unchecked`. - `src/jsc/bindings/node/http/NodeHTTPParser.{cpp,h}`: `HTTPParser::lessThan`. - `src/jsc/bindings/JSNodePerformanceHooksHistogram.{cpp,h}`: `create(VM&, Structure*, JSGlobalObject*, HistogramData&&)`. - `src/jsc/bindings/webcore/JSAbortAlgorithm.{cpp,h}`: `callbackData()`, `toJS(AbortAlgorithm&)`, `toJS(AbortAlgorithm*)`. - `src/jsc/bindings/webcore/JSPerformance.{cpp,h}`: `JSPerformance::toWrapped`. - `src/jsc/bindings/ErrorStackTrace.{cpp,h}`: `JSCStackFrame::typeName`, `retrieveTypeName`, `m_typeName`. - `src/jsc/bindings/webcrypto/CryptoKey.{cpp,h}`: `root(CryptoKey*)` and the `WebCoreOpaqueRoot` forward declaration and include it needed. - `src/jsc/bindings/webcore/JSDOMOperation.{cpp,h}`: `throwNodeRangeError(JSGlobalObject*, ThrowScope&, const String&)`; every caller passes an `ASCIILiteral`. - `src/jsc/bindings/ncrypto.{cpp,h}`: `CryptoErrorList::add`, `CryptoErrorList::pop_front`, `BignumPointer::encode`, `BignumPointer::encodeInto`, `X509View::clone`, `BIOPointer::New(const BIO_METHOD*)`, `BIOPointer::Write`, `EVPKeyPointer::bits`, `Cipher::EMPTY`, `ECKeyPointer::New(const EC_GROUP*)`, `EVPKeyCtxPointer::derive`, `HMACCtxPointer::digest`, `Ec::Ec()`, `Ec::Ec(const EC_KEY*)`, `Ec::getGroup`, and the `Ec` conversion operators and field. Scan summary for this run. Areas: Rust in `src/runtime`, `src/http_jsc`, `src/bun_core`, `src/base64`, `src/ptr`, and the JSC bindings outside the files that open dead-code PRs (#39929, #40232, #40367, #40294, #40172, #40122) already touch; the TS builtins in `src/js`. - hawk over `x86_64-unknown-linux-gnu`, `x86_64-pc-windows-msvc`, `aarch64-apple-darwin` (release profile, per `hawk.toml`): 847 `dead_public` findings. 668 are fields of FFI mirror structs (`libuv.rs`, `windows_sys/externs.rs`, `boringssl.rs`). Most of the rest are in files the open PRs own, are debug-only (`has_resolve_breakpoint`, `StoredTrace::capture`, `ArrayHashMap::unlock_pointers`), are codegen targets (`host_fn_this_value`), or are FFI enum mirrors (`tty::Mode::Io`, `ImplementationVisibility`). - oxlint with `no-unused-vars`, `no-unused-private-class-members`, `no-unreachable` over `src/js`: 0 findings. No `src/js` file is unimported. No `.rs` file is outside a `mod` tree except the three `[[bench]]` targets. - `--gc-sections` relink of `bun-debug`: 1005 non-generated discarded symbols, 283 of them in files no open PR touches. After removing sqlite3.c, llhttp, vendored shims, platform-gated code, and generated `ZigGeneratedClasses` helpers, the list above is what remains. Possibly dead, left alone: - `bun_core::strings::split_once` / `rsplit_once`: no caller today, but `clippy.toml` names them as the replacement for the denied `str::split_once` / `bstr::split_once_str` forms. Kept as API surface. - `src/jsc/bindings/webcore/streams/JSCrossRealmTransformState.{cpp,h}` (135 lines): the `CrossRealm` source and sink kinds in `StreamsForward.h` are never constructed. It reads as scaffolding for stream transfer in the native streams work, so it stays. - `ECDSASigPointer`, `ECGroupPointer`, `ECPointPointer`, `HMACCtxPointer`: default constructor, move constructor, and `release()` are unreferenced, but they are the smart-pointer idiom the rest of ncrypto follows. - `src/threading/Futex.rs` `wasm_impl` and `unsupported_impl`: no shipped target compiles them. - `bun_core::Global::StoredTrace::{EMPTY, capture}`, `has_resolve_breakpoint`, `ArrayHashMap::unlock_pointers`, `TaskTag::name`: release-dead, used under `debug_assertions`. </details>
…her crates (#40610) ### Problem - The workspace denies `dead_code` and `unreachable_pub`, and earlier sweeps removed the `pub` items a cross-crate analysis can see. What is left is code no lint reports: branches behind constant conditions, `pub` enum variants that nothing constructs, `pub` struct fields that nothing reads, and commented-out code. - The largest case is the js lexer: `LexerType` carried seven const generic parameters for a JSON mode (`IS_JSON`, `ALLOW_COMMENTS`, ...) that no caller ever set. The only instantiation is the default one, so every `if IS_JSON` body in `src/js_parser/lexer.rs` was unreachable. JSON is parsed by `src/parsers/json.rs`. ### Fix - Delete the items. 83 source files, +221 / -1653. Every candidate was checked with `rg` over `src/`, `build/debug/codegen/` and `src/codegen/`, including `#[cfg(windows)]` and macOS paths. The Notes list each one. - The lexer becomes a plain `struct Lexer<'a>`: the `JsonOptionsT` trait, the `NewLexer` alias, the `lexer_impl_header!` macro and the `generic_const_exprs` feature gate go with the JSON branches. The only JS-visible change is none: the default instantiation was the only one. - `bun_runtime::Error` loses 85 unit variants that are never built (the X509 codes live in `bun_http::CertError`; `InstallFailed` and friends are only ever nested as `Error::Install(..)`). The `AllocatorVTable` keeps only `free`, the one slot `StdAllocator` dispatches. - New source lint `test/internal/source-lints/literal-bool-condition.test.ts`: a statement-level `if true {` / `if false {` outside `#[cfg(test)]` code fails the lint. rustc and clippy accept both, so the dead `if false { break 'outer; }` in `doStep5.rs` and the always-taken `if true {` block in `Watcher.rs` (unwrapped here) had no other guard. The lint fails on `main` with those two lines and passes with this PR. - Verified: `bun bd`, `bun run rust:check-all` (12 targets), `cargo clippy --workspace`, `cargo check --workspace --tests`, `cargo fmt --check`. `bun bd test` on transpiler, bundler edge cases, shell, yaml, zstd, transpiler cache, `Bun.write`, `Bun.file`, sourcemap, resolver cache, WebSocket client, `bun add`/`bun remove`, lockfile sync, archive, `bun:test`, `--watch`, and the source lints (about 2,700 tests, 0 failures attributable to this change; see Notes). ### Background - `dead_code` does not report a `pub` item, a trait impl, an enum variant that a `match` arm names, or a field that a compound assignment (`+=`) touches. Each of those counts as a use to rustc even when nothing reads the result. - A `const bool` that is the same in every build (`const ALLOW_TMPFILE: bool = false`, a trait const no impl overrides, a const generic no caller sets) makes one side of its `if` unreachable, but rustc still type-checks and keeps that side. The removed branches are all of this kind. Flags that vary per build (`IS_WINDOWS`, `IS_DEBUG`, `ENABLE_ASAN`) and the debug toggles (`TRACING`, `VERBOSE_FS`-style logging switches that still have a body) were left alone. - `BunBuiltinNames.h` entries and JS private names can be referenced by string (`$getByIdDirectPrivate(this, "writer")`), so a name with no `$name` hit is not dead. Two such candidates were checked and kept. <details><summary>Notes</summary> Removed, constant conditions: - `src/js_parser/lexer.rs`: the 7 const generic parameters of `LexerType`, the `JsonOptionsT` trait, `DefaultJsonOptions`, the `NewLexer` alias and the `lexer_impl_header!` macro. 30 `if IS_JSON` bodies, `assert_not_json` and its 13 calls, the `is_ascii_only` field (only written in JSON mode), `Error::JSONStringsMustUseDoubleQuotes`, and the `if !FeatureFlags::ALLOW_JSON_SINGLE_QUOTES` block. `src/js_parser/lib.rs` drops `#![feature(adt_const_params, generic_const_exprs)]`, which nothing else in the crate used. - `src/bun_core/feature_flags.rs`: `ENABLE_ENTRY_CACHE` (always true: the "cache disabled" tails of `read_directory_error` and `read_directory_with_iterator` in `src/resolver/lib.rs`), `VERBOSE_FS` (always false: two `prettyln!` blocks in `src/resolver/fs.rs` and the `bstr::BStr` import), `HARDCODE_LOCALHOST_TO_127_0_0_1` (always false: the rewrite in `HTTPContext::connect` and `WebSocketUpgradeClient`), `ALLOW_JSON_SINGLE_QUOTES` (only read by the lexer JSON mode). - `src/sys/tmp.rs`: `ALLOW_TMPFILE = false` with the `O_TMPFILE` open and `linkat` paths and the `using_tmpfile` field. `RuntimeTranspilerCache.rs` always unlinks the tmp name on failure now, which is what the `!using_tmpfile` guard already did. The non-Linux `O::TMPFILE` consts and `linkat_tmpfile` stubs in `src/sys/lib.rs` had no other caller (`src/install/npm.rs` uses them under `cfg(linux)`). - `src/libarchive/lib.rs`: `ArchiveAppender::HAS_APPEND_MUTABLE`, no impl overrides the `false` default. With it: `append_mutable`, the `if A::HAS_APPEND_MUTABLE` block, `Context::all_files`, `EntryMap`, `U64Context` and its two impls, and the `all_files` initializer in `create_command.rs`. - `src/bundler/linker_context/doStep5.rs`: `if false { break 'outer; }` and the label. `src/watcher/Watcher.rs`: an `if true {` block around the "Added to watch list" log, unwrapped. - `src/io/PipeWriter.rs`: `PosixStreamingWriterParent::HAS_ON_READY`, set by both impls (the macro and `Terminal.rs`), read by nothing. Removed, enum variants nothing constructs (each with its `name()` arm and match arms): - `bun_runtime::Error` (`src/runtime/error.rs`): `Panic`, `RequestBodyNotReusable`, `DNSResolveFailed`, `TooManyRedirects`, `ConnectionRefused`, `RedirectURLInvalid`, the 66 X509 verification codes from `UNABLE_TO_GET_ISSUER_CERT` to `UNKNOWN_CERTIFICATE_VERIFICATION_ERROR`, `InstallFailed`, `InvalidPackageJSON`, `PathAlreadyExists`, `InvalidTarget`, `OpenFailed`, `UnableToDecode`, `SocketClosed`, `StackOverflow`, `Test`, `MissingTranspileExtra`, `PluginError`, `Name`, `EscapeCalledTwice`. The or-patterns in `install_command.rs`, `pm_update_package_json.rs` and `jsc_hooks.rs` keep their live alternatives. - `bun_core::strings::BOM::{Utf16Be, Utf32Le, Utf32Be}`: `detect()` only returns `Utf8` and `Utf16Le`. With them: the three byte-pattern consts, the `_ =>` arms in the two `remove_and_convert_*` functions, and the commented-out detection lines. - `bun_shell_parser`: `Token::{Dollar, Eq}` and `TokenTag::{Dollar, Eq}` (the lexer never pushes them), with the `TestToken` mirrors and JSON arms in `src/runtime/shell/shell_body.rs`. - `ShellErr::Todo` (`shell_body.rs`, `Builtin.rs`), `bun_crash_handler::Error::InvalidDebugInfo` (patterns in `crash_handler/lib.rs` and `jsc/btjs.rs`) and the `bun_jsc::Error::InvalidDebugInfo` mirror, `FetchFlags::PrintSourceAndClone` (`ModuleLoader.rs`, arm in `jsc_hooks.rs`), yaml `ParseError::InvalidIndentation` and the `ParseResultError::InvalidIndentation` it alone produced, `bun_sourcemap::Error::Unknown`. Removed, fields nothing reads: - `AllocatorVTable::{alloc, resize, remap}` (`src/bun_alloc/lib.rs`): only `free` is ever dispatched. With them: `NO_ALLOC`/`NO_RESIZE`/`NO_REMAP`, `MimallocAllocator` and its four functions in `basic.rs`, `default_alloc::{malloc_aligned, realloc_aligned}` and `Alignment::to_byte_units`. - `ArgumentsSlice::all` (`src/jsc/CallFrame.rs`), `ParseTask::tree_shaking` (`src/bundler/ParseTask.rs`, 11 writers in `bundle_v2.rs`; the parser reads `topts.tree_shaking`), `JSMeta::entry_point_part_index` (`LinkerGraph.rs`, written in `scanImportsAndExports.rs`), `NetworkSink::high_water_mark` (`streams.rs`, `s3/client.rs`, with the `part_size` locals that fed it), `CopyFile::read_off`, the POSIX `ReadFile::byte_store`, `file_sink::Options::close`, `ZstdReaderArrayList::total_out`, `Cloner::trees_count`. Removed, commented-out code older than six months (blame on the line, or on the Zig line the port copied): - C++: `ImportMetaObject.cpp`, `InspectorHTTPServerAgent.cpp`, `JSDOMExceptionHandling.cpp`, `ncrypto.cpp`, `KeyObject.cpp`, `EventTarget.cpp`, `JSPerformanceEntryCustom.cpp`, `MessageEvent.h` (plus a duplicate `#include "MessagePort.h"`), `Performance.cpp`, `Performance.h`, `PerformanceEntry.cpp`, `PerformanceObserver.cpp`, `PerformanceResourceTiming.cpp`, `WebSocket.cpp`. - Rust: `AstBuilder.rs`, `postProcessCSSChunk.rs`, `postProcessJSChunk.rs`, `crash_handler/lib.rs`, `css/declaration.rs`, `css/selectors/selector.rs`, `css/values/percentage.rs`, `WebSocketUpgradeClient.rs`, `lexer.rs`, `parse_fn.rs`, `visit_expr.rs`, `paths/resolve_path.rs`, `exec_command.rs`, `braces.rs`, `sha_hmac/sha.rs`, `StaticHashMap.rs`, `ffi_body.rs`. - `.classes.ts`: disabled entries in `sql.classes.ts`, `sockets.classes.ts`, `server.classes.ts`, `jest.classes.ts`; a leftover loop in `generate_uv_posix_stubs.ts`. Declaration-only C++: `CryptoKeyOKP::platformExportSpki/platformExportPkcs8`, `JSX509Certificate::getPublicKey`, `KeyPairJobCtx::deinit`, `BunShell`/`ShellError` in `BunObject.h`. Checked and kept: `Terminal::get_slave_fd` (used by `js_bun_spawn_bindings.rs`), `macro(writer)` and `macro(mockedFunction)` in `BunBuiltinNames.h` (`$getByIdDirectPrivate(this, "writer")` in `ConsoleObject.ts`, `BunCommonStrings.h`), css `Segment::Name` and `CssModuleExport::is_referenced` (lightningcss data model), the react_compiler variants and fields that mirror the upstream schema, `Mode::ProductionDynamic` (bake scaffolding), the MySQL protocol fields that mirror the wire format, the debug toggles `LOG_ALLOCATIONS`, `DISABLE_COMPRESSION_IN_HTTP_CLIENT`, crash handler `ENABLE`, `ENABLE_AUTO_CORK`/`ENABLE_ALLOCATOR_POOL`, and the wasm scaffolding behind `IS_WASM`/`IS_BROWSER`. Test runs: `test/js/web/fetch/fetch.test.ts` fails the same 26 tests with the released `bun` in this container (root user, no network). `Bun.write > copyFileRange is not available > on large files` hits its 5 s timeout under the ASAN debug build while filling a 256 MB buffer in JS; the copy itself takes 0.6 s and the hash matches. This PR repeats no deletion of the open dead-code PRs (#39929, #40122, #40172, #40232, #40294, #40367, #40492, #40525, #40557), checked by diffing the removed lines. Three files are shared with them in other regions (`src/install/lockfile/Package.rs`, `src/runtime/cli/create_command.rs`, `src/runtime/jsc_hooks.rs`). </details> <!-- robobun:evidence:begin --> --- **[review]** gate passed · iteration 2 · 84 files touched <details><summary>fails on main (without fix)</summary> ```console ASAN without fix: BUILD FAILED (no junit output) $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/literal-bool-condition.test.ts ninja: Entering directory `/workspace/bun/build/debug' [1/166] gen generated_host_exports.rs generated_host_exports.rs: 122 exports (host=5, lazy=10, generic=107, rust=0); 243 extern-C blocks audited [2/166] gen ZigGeneratedClasses.{cpp,h,rs} Found 2 classes from /workspace/bun/src/jsc/resolve_message.classes.ts - ResolveMessage (15 fields) - BuildMessage (10 fields) Found 1 classes from /workspace/bun/src/runtime/api/Archive.classes.ts - Archive (4 fields, 1 class fields) Found 2 classes from /workspace/bun/src/runtime/api/BunObject.classes.ts - ResourceUsage (8 fields) - Subprocess (20 fields) Found 1 classes from /workspace/bun/src/runtime/api/cron.classes.ts - CronJob (5 fields) Found 3 classes from /workspace/bun/src/runtime/api/filesystem_router.classes.ts - FileSystemRouter (5 fields) - FrameworkFileSystemRouter (2 fields) - MatchedRoute (8 fields) Found 1 classes from /workspace/bun/src/runtime/api/Glob.classes.ts - Glob (5 fields) Found 1 classes fro ... (truncated) release without fix: 1 FAILED bun test v1.4.1-canary.1 (9e0b058) test/internal/source-lints/literal-bool-condition.test.ts: (pass) scans a non-empty set of tracked Rust sources [0.09ms] (pass) withoutTestItems keeps production code and blanks #[cfg(test)] items [0.09ms] 234 | "fn after_strings() {}", 235 | ]); 236 | }); 237 | 238 | test("if true { .. } / if false { .. } outside #[cfg(test)] code", () => { 239 | expect(offenders).toEqual([]); ^ error: expect(received).toEqual(expected) - [] + [ + "src/bundler/linker_context/doStep5.rs:308: if false {", + "src/watcher/Watcher.rs:752: if true {", + ] - Expected - 1 + Received + 4 at <anonymous> (/workspace/bun/test/internal/source-lints/literal-bool-condition.test.ts:239:21) (fail) if true { .. } / if false { .. } outside #[cfg(test)] code [0.19ms] 2 pass 1 fail 3 expect() calls Ran 3 tests across 1 file. [798.00ms] __F:1:S:0 ``` </details> <details><summary>passes on PR (with fix)</summary> ```console ASAN with fix: all passed $ BUN_DEBUG_QUIET_LOGS=1 bun scripts/build.ts --profile=debug --quiet test "--reporter=junit" "--reporter-outfile=/tmp/mechgate.xml" test/internal/source-lints/literal-bool-condition.test.ts bun test v1.4.1 (731aa92) test/internal/source-lints/literal-bool-condition.test.ts: (pass) scans a non-empty set of tracked Rust sources [2.29ms] (pass) withoutTestItems keeps production code and blanks #[cfg(test)] items [4.24ms] (pass) if true { .. } / if false { .. } outside #[cfg(test)] code [1.22ms] 3 pass 0 fail 3 expect() calls Ran 3 tests across 1 file. [62.41s] __F:0:S:0 release with fix: all passed $ bun scripts/build.ts --profile=release [configured] bun-profile → bun (stripped) in 631ms (unchanged) ninja: Entering directory `/workspace/bun/build/release' [1/126] gen generated_host_exports.rs generated_host_exports.rs: 122 exports (host=5, lazy=10, generic=107, rust=0); 243 extern-C blocks audited [2/126] gen ZigGeneratedClasses.{cpp,h,rs} Found 2 classes from /workspace/bun/src/jsc/resolve_message.classes.ts - ResolveMessage (15 fields) - BuildMessage (10 fields) Found 1 classes from /workspace/bun/src/runtime/api/Archive.classes.ts - Archive (4 fields, 1 class fields) Found 2 classes from /workspace/bun/src/runtime/api/BunObject.classes.ts - ResourceUsage (8 fields) - Subprocess (20 fields) Found 1 classes from /workspace/bun/src/runtime/api/cron.classes.ts - CronJob (5 fields) Found 3 classes from /workspace/bun/src/runtime/api/filesystem_router.classes.ts - FileSystemRouter (5 fields) - FrameworkFileSystemRouter (2 fields) - MatchedRoute (8 fields) Found 1 classes from /workspace/bun/src/runtime/api/Glob.classes.ts - Glob (5 fields) Found 1 classes from /workspace/bun/src/runtime/api/h2.classes.ts - H2FrameParser (32 fields) Found ... (truncated) ``` </details> <details><summary>diff hotspot</summary> ``` src/bun_alloc/basic.rs | 73 +-- src/bun_alloc/lib.rs | 105 +--- src/bun_core/feature_flags.rs | 14 - src/bun_core/string/immutable/unicode.rs | 28 - src/bundler/AstBuilder.rs | 4 - src/bundler/LinkerGraph.rs | 3 - src/bundler/ParseTask.rs | 4 - src/bundler/bundle_v2.rs | 9 - src/bundler/linker_context/doStep5.rs | 5 +- src/bundler/linker_context/postProcessCSSChunk.rs | 9 - src/bundler/linker_context/postProcessJSChunk.rs | 5 - .../linker_context/scanImportsAndExports.rs | 2 - src/collections/StaticHashMap.rs | 7 - src/crash_handler/error.rs | 3 - src/crash_handler/lib.rs | 7 +- src/css/declaration.rs | 4 - src/css/selectors/selector.rs | 23 - src/css/values/percentage.rs | 11 - src/http/HTTPContext.rs | 16 +- .../websocket_client/WebSocketUpgradeClient.rs | 19 +- src/install/lockfile.rs | 2 - src/install/lockfile/Package.rs | 4 +- src/io/PipeWriter.rs | 2 - src/js_parser/lexer.rs | 631 ++++----------------- src/js_parser/lib.rs | 6 - src/js_parser/parse/parse_fn.rs | 3 - src/js_parser/visit/visit_expr.rs | 6 - src/jsc/CallFrame.rs | 9 +- src/jsc/ModuleLoader.rs | 1 - src/jsc/RuntimeTranspilerCache.rs | 6 +- src/jsc/bindings/BunObject.h | 3 - src/jsc/bindings/ImportMetaObject.cpp | 4 - src/jsc/bindings/InspectorHTTPSe ... (truncated) ``` </details> **gate history** · 2 passed · 1 rejected · iteration 2 <details><summary>evidence per changed file</summary> ``` file reads edits tests src/bun_alloc/basic.rs 0 0 0 src/bun_alloc/lib.rs 0 0 0 src/bun_core/feature_flags.rs 1 0 0 src/bun_core/string/immutable/unicode.rs 0 0 0 src/bundler/AstBuilder.rs 0 0 0 src/bundler/LinkerGraph.rs 0 0 0 src/bundler/ParseTask.rs 0 0 0 src/bundler/bundle_v2.rs 0 0 0 src/bundler/linker_context/doStep5.rs 0 0 0 src/bundler/linker_context/postProcessCSSChunk.rs 0 0 0 src/bundler/linker_context/postProcessJSChunk.rs 0 0 0 src/bundler/linker_context/scanImportsAndExports.rs 0 0 0 src/collections/StaticHashMap.rs 0 0 0 src/crash_handler/error.rs 0 0 0 src/crash_handler/lib.rs 0 0 0 src/css/declaration.rs 0 0 0 (+ 68 more files) ``` </details> <!-- robobun:evidence:end --> --------- Co-authored-by: Jarred Sumner <jarred@jarredsumner.com>
… the build scripts (#43778) ### Problem - A few C++ and TypeScript items have no caller, no producer, or no effect. - `BUN_MESSAGEPORT_USES_PIPE` (`src/jsc/bindings/webcore/MessagePort.h`) is always `1`. The `#if` around all of `MessagePortPipe.cpp` never excludes anything. ### Fix - WebView: remove `WebViewProto::Reader::u16()` and `f32()` (`ipc_protocol.h`), which have no caller. Remove the CDP `Method` values `RuntimeEnable`, `TargetCloseTarget` and `InputDispatchScrollEvent` with their `case` labels (`ChromeBackend.{h,cpp}`). No pending entry carries them. - WebCore bindings: remove the `BUN_MESSAGEPORT_USES_PIPE` define and guard, the self-alias of `ExtendedDOMClientIsoSubspaces`, the forward declaration of `URLPatternUtilities::URLPatternInit` (no such type), the enumerators `PerformanceEntry::Type::Paint` and `CastedThisErrorBehavior::ReturnEarly`, and 13 lines of commented-out WebKit code. - Build scripts: remove `getBuildNumber()` (`.buildkite/ci.ts`) and `BunOutput.rustObjects` (`scripts/build/bun.ts`). Nothing reads either. - Verified: `rg -w` for each symbol over `src`, `packages`, `scripts`, `test` and `build/debug/codegen` finds no other use. `bun bd` passes. The Notes list the tests. ### Background - `ipc_protocol.h` is the wire format between bun and the WebView host process. `Reader` decodes frames. Every caller uses `u8`, `u32`, `bytes` and `str` only. - `ChromeBackend` tags each pending Chrome DevTools Protocol command with a `Method`, so that the response handler knows which promise to settle. A value that no pending entry carries cannot reach the `switch`. - #29937 added the guard so that `MessagePortPipe.cpp` compiled to nothing while a verification step reverted `MessagePort.h`. Both files are on main now. ### Downsides - None found. Checked each removed symbol for users in C++, Rust, generated code and `src/symbols.*`. The removed enum values are in-memory tags or template arguments. Rust mirrors neither enum. <details><summary>Notes</summary> Smoke tests with the debug build, all pass: `test/js/web/workers/message-port-pipe.test.ts`, `message-channel.test.ts`, `performance-observer-leak.test.ts`, `test/js/node/perf_hooks/perf_hooks.test.ts`, `test/js/web/urlpattern/`, `test/js/bun/webview/webview-chrome-pipe.test.ts`. `clang-format` and `prettier` report no change on the touched files. `.buildkite/ci.ts` still transpiles. Each removal was checked against the diffs of the 34 open dead-code PRs. None of them removes the same lines. `MessagePort.h` is also touched by #40525, in a different hunk. How the Rust side was scanned, and why this PR has no Rust in it: - `cargo mordant` at the revision pinned in `.github/workflows/rust-lints.yml`, over the Linux, Windows and macOS targets, with the `unused_pub` entries taken out of the baseline. It reports 188 `pub` items that nothing in the workspace uses. Every function, method and struct in that list is in one of four groups: an open PR already removes it, a `cfg` that the run does not build uses it (`bun_zstd::inflate_embedded*` under `bun_codegen_embed`, `StoredTrace::from` in `PackageInstall.rs`), only a unit test uses it (`CowSliceZ::init_dupe`), or #42119 left it on purpose (`host_fn_this_value`, `host_fn_setter`, `JsClass::estimated_size`). The constants are flag, errno and syscall-tag tables. - A rust-analyzer SCIP index for five targets (Linux, Windows, macOS, FreeBSD, Android) plus a reachability closure over it. Two blind spots make it unreliable alone: rust-analyzer sets `cfg(test)` by default, which hides `src/runtime/bin_entry`, and references that come from a `macro_rules!` body are not indexed (`comptime_string_map!`, the CSS `to_css` bridges). With those corrected, it agrees with mordant and adds nothing. - Cargo's own `unused_dependencies` warnings: 9 edges. Each is used on another target, or #40294 already removes it. - Rust files outside every module tree: none. Headers that nothing includes: none (the remaining ones come in through `GeneratedJS2Native.h`, `NativeModuleImpl.h` or `include_bytes!`). Also scanned and clean: `src/js/{node,internal,bun,thirdparty}` and `src/js/builtins` (all 50 builtins and all 177 private names have a user), `scripts/`, `misctools/`, `.buildkite/ci.ts`, and the C++ under `webcore/`, `webcrypto/`, `node/` and `src/runtime/` that no open PR touches. Probably dead, left alone on purpose: - `bun_core::strings::split_once` (`src/bun_core/string/immutable.rs`): no caller on any target. It sits next to the hunk in which #40824 removes `rsplit_once`, so a removal here would conflict with that PR. - The raw-list `myersDiff` export of `src/js/internal/assert/myers_diff.ts` and the `Output::List` path behind it in `src/runtime/node/node_assert.rs` (about 115 lines): nothing consumes it. #39924 kept the export on purpose, and Node's own `test-assert-myers-diff.js` needs it if that test is vendored. - `BuiltinName::{redirect, asyncIterator, name, default, fatal, ignoreBOM}` (`src/jsc/lib.rs`, mirrored by position in `bindings.cpp`): never constructed. A removal conflicts with #40232. - `FetchHeaders` guard handling (`removePrivilegedNoCORSRequestHeaders` and the `Guard::Immutable` checks): every construction site passes `Guard::None`, and #43644 removes `setGuard`. This is unreachable code, not unreferenced code. - `ServerTiming`'s constructor and its `durationSet` / `descriptionSet` fields: nothing constructs a `ServerTiming`. #40122 and #41385 touch the same cluster. - The `$isPromiseFulfilled`, `$isPromiseRejected` and `$alwaysInline` codegen macros: no user since 92459cd. - `scripts/build/config.ts` flags `logs` and `baseline`: parsed and printed, never read since the Rust rewrite. `NestedCmakeBuild.{extraCFlags, extraCxxFlags, libSubdir, sourceSubdir, pic}`: no dependency sets them, but `scripts/build/deps/README.md` documents them as the API for future dependencies. - `misctools/gen-unicode-table.ts` and `unicode-generator.ts` emit Zig. Nothing references them, but `src/bun_core/string/identifier.rs` still names the generator as the way to rebuild its tables. - `completions/bun-cli.json` and `misctools/generate-cli-completions.ts`: nothing in the repository reads the JSON. It is still updated by hand, so something outside the repository may use it. </details>
### Problem - `hasExportStar` in `src/runtime/bake/hmr-module.ts` has no caller. Its only call site is a block that #18109 commented out on 2025-03-14. The `availableExportKeys` local above that block is read only by the commented-out code. - `firstConnection` in `src/runtime/bake/client/websocket.ts` is assigned once and never read. - No lint reports them. Earlier sweeps ran `tsc --noUnusedLocals` over `src/js` and `scripts` only, not over `src/runtime/bake`. ### Fix - Delete `hasExportStar`, the commented-out check, `availableExportKeys`, and `firstConnection`. 2 files, 40 lines removed. - Correct because the bundler already drops `hasExportStar`. The generated `bake.client.js`, `bake.server.js` and `bake.error.js` differ from `main` only by the two removed local declarations. - Verified: `tsc -p src/runtime/bake/tsconfig.json --noUnusedLocals` no longer reports either file. `test/bake/dev/esm.test.ts` (17 pass), `hot.test.ts` (11 pass) and `bundle.test.ts` (23 pass) with the debug build. Behaviour change: none ### Background - `hmr-module.ts` is the module loader that the dev server sends to the browser and to the SSR realm. `parseEsmDependencies` walks the dependency list of an ES module. Each entry carries the export names that the importer uses. - The removed check compared those names with the exports of the dependency and threw a `SyntaxError` for a missing one. It has been off for 18 months. A missing export fails at the use site. - A deletion has one possible place, so no other design was weighed. ### Downsides - The commented-out check was the only sketch of export verification in the HMR runtime. A person who wants to build it starts from the history of #18109. <details><summary>Notes</summary> #### Why this run is small Every other hit of this run is live, is platform code with a user on another target, or is a line that one of the 34 open dead-code pull requests already deletes. Each removed line here was checked against those diffs. #40492 and #43378 touch `websocket.ts` in other hunks. #### Scans of this run, all clean or already claimed - Debug objects linked again with `--gc-sections --print-gc-sections`, then `llvm-symbolizer` for `file:line`. 20,668 discarded functions in bun's objects. The Rust ones outside macros and trait impls are Windows or macOS helpers, or claimed (#40824, #40557, #40232). The C++ ones are claimed, are template instantiations, or have a Rust caller on another target (`bsd_socket_export`, `posix_spawnattr_reset_signals`). - Rust functions that never get a symbol (generic or `#[inline]`, never instantiated), found by comparing every `fn` line with the DWARF declaration lines of all emitted functions. 86 hits outside `cfg`, trait impls and `#[inline(always)]`. All are Windows-only, test-only (the outbound half of `api/bun/h2/connection.rs`), or claimed. - `clang -fsyntax-only -Wunused-function -Wunused-macros -Wunused-template -Wunused-member-function` over 588 translation units and the 69 unified ones (the build passes `-Wno-unused-function`). 3 functions and 6 macros. `formatStackTraceToJSValueWithoutPrepareStackTrace`, `hostName`, `G_TRUE`, `G_FALSE`, `MAX_LABELS` and `us_ioctl` are claimed (#40367, #43378, #40492, #40294). `us_quic_send_one` is used under the non-Linux `#if` branch. - A whole-program C++ reference index (`c-index-test -index-file`, 657 translation units, 32,018 symbols declared in bun's tree). 8,711 have no recorded reference. After filters for template-dependent uses, `extern "C"`, virtual methods and names that WebKit headers use, 78 remain. All are index artifacts (typedef struct tags, primary templates with used specializations, `requires` clauses) or one-line getters in files that open pull requests rewrite. - `tsc --noUnusedLocals` over `src/js`, `scripts`, `src/codegen`, `src/runtime/bake`, `src/node-fallbacks` and the sources of each package. The hits outside this change are claimed (#40122, #41169, #41385, #40492, #43778) or are loop variables. - Regex scans for struct fields with no read and for `bool` or `Option` fields that only ever get one constant. Nothing new after #43745. - Exports of `src/js` modules and builtin functions with no mention in another file: none. - Files that nothing includes, imports or names: none outside `.idl` copies (#41064). `src/symbols.txt`, `symbols.def` and the `package.json` scripts name nothing that is gone. No `#if 0`. </details> <!-- robobun:evidence:begin --> --- **no test proof** · iteration 1 · the description declares no behaviour change, so there is no failing test to prove; the existing suite in CI is the check <!-- robobun:evidence:end -->
… and the CI pipeline script (#43976) Behaviour change: none ### Problem - Eleven files hold items that nothing reads or calls: write-only fields, an uncalled method, four unused types, and CI options that are parsed and dropped. - No tool reports them. C and C++ have no dead-code lint. TypeScript counts `x += n` as a read. The Rust types come from a macro. ### Fix - TypeScript: remove `DataViewReader.u16()`, `DataViewWriter.capacity`, the `totalCount` local in `updateBuildErrorOverlay`, and a commented-out block from 2024 in `src/js/node/dgram.ts`. - C and C++: remove `us_udp_socket_t.connected`, `us_quic_stream_s.headers_delivered` and `Http2ResponseData::totalSize` (each is only written), and `#undef FD_BITS` (nothing defines it). - Rust and CI: remove the opaque types `us_loop_t`, `us_socket_context_t`, `us_udp_socket_t`, `us_udp_packet_buffer_t` from `src/uws_sys/lib.rs`. In `.buildkite/ci.ts`, remove `dryRun`, `Platform.features`, four emoji entries, and the union members `"amazonlinux"` and `"eol"`. - Verified: `rg -w` for each symbol over `src`, `packages`, `scripts`, `test` and `build/debug/codegen` finds no other use. `bun bd`, `bun run rust:check-all` (12 targets) and `tsc` pass. Self-reviewed: 1 concern raised, 1 addressed. ### Background - `DataViewReader` and `DataViewWriter` decode and encode the binary messages between the dev server and its browser client. - `us_udp_socket_t` and `us_quic_stream_s` are private C structs of uSockets. Rust holds them as opaque pointers, so no Rust struct mirrors their layout. - `bun_core::opaque_extern!` declares a zero-sized Rust type for a C struct. Rust code names `Loop`, `udp::Socket` and `udp::PacketBuffer`, not the four removed types. ### Downsides - None found. Checked each removed symbol for users in Rust, C, C++, TypeScript, generated code, tests, and open pull requests. <details><summary>Notes</summary> **Evidence per removal** | Item | Evidence | | --- | --- | | `DataViewReader.u16()` | `rg '\.u16\('` over `src/runtime/bake`, `test/bake`, `test/cli/inspect`: no hit. | | `DataViewWriter.capacity` | The only hit of `.capacity` in the bake TypeScript is the assignment in the constructor. `initCapacity` is the only caller of the constructor. | | `totalCount` | Two hits: the declaration and one `+=`. | | `dgram.ts` block | `git blame`: 589f941, 2024-04-26. `replaceHandle` and `startListening` are not defined in the file. | | `us_udp_socket_t.connected` | Two hits, both `udp->connected = 0;`. | | `us_quic_stream_s.headers_delivered` | Two hits in `quic.c`: the field and one `= 1`. The struct is private to `quic.c`. | | `Http2ResponseData::totalSize` | One member access: `data.totalSize = totalSize;`. The other hits of `totalSize` are the function parameter. | | `#undef FD_BITS` | The only hit of `FD_BITS` in `src` and `packages`. | | Four opaque types | Each name has one non-comment hit in all Rust sources and generated Rust: the macro call. | | `dryRun` | Four hits in `ci.ts`: the field, two assignments, one destructure. Nothing reads the binding. | | `Platform.features` | One hit. | | Emoji, `Distro`, `Tier` entries | No platform in `ci.ts` or image in `scripts/build/ci-images/spec.ts` carries them. `Emoji` is `keyof typeof emojiMap`, so a remaining caller would fail `tsc -p scripts/tsconfig.json`. It passes. | **Taken out because an open pull request uses or removes the item** - `DataViewWriter.u8()`: dead on main, but #42075 adds its first caller (`check.u8(IncomingMessageId.check_errors)` in `hmr-runtime-error.ts`). Git merges the two without a conflict, so the method stays. The tree that results from a merge of this branch with #42075 has no type error for `u8`. - `declare module "bun:wrap"` in `bake.private.d.ts`: no importer, but #39488 already has the same hunk. **Tests run with the debug build, all pass** `test/js/bun/udp/udp_socket.test.ts` (218), `test/js/bun/udp/dgram.test.ts` (62), `test/js/bun/http/serve-http2.test.ts` (93), `test/js/bun/http/serve-http3.test.ts` (73), `test/bake/dev/bundle.test.ts` (23), `test/bake/dev/esm.test.ts` (17), `test/bake/hmr-socket-protocol.test.ts` (4), `test/cli/inspect/BunFrontendDevServer.test.ts` (7). `test/js/node/dgram/node-dgram.test.js` passes 3 of 4: the IPv6 multicast test fails with `ENODEV` in the test container, with and without this change. `prettier` and `cargo fmt --check` report no change. **Overlap with open pull requests** Each removed line was compared with the diffs of the 35 open dead-code pull requests. None removes the same lines. Five files are also touched by an open pull request, in hunks more than 6 lines away: `internal.h` and `quic.c` (#40294, #42431), `dgram.ts` (#42431), `overlay.ts` (#43378, #42075, #39488), `src/uws_sys/lib.rs` (#43010). The added lines of the 122 open pull requests that were updated since 2026-09-18 and touch the bake, uSockets, uWS, uws_sys, server, socket or CI sources name none of the removed symbols. **What was scanned** - C and C++: the debug binary was linked a second time with `--gc-sections`, and the two symbol tables were compared. 414 functions in bun's own C and C++ are unreachable on Linux. Open pull requests remove 263 of them. The remainder is in the list below, has a caller on Windows or macOS, or comes from a macro. - Rust: 37 `#[no_mangle]` exports are unreachable in the Linux link. Each has a caller on another platform, or #40824, #40232 or #40557 removes it. A count of references for all 58,055 Rust definitions found no other item without a user. Of the 144 `allow` attributes for the unused and unreachable lints, each covers code that depends on `cfg` or is macro output. - Cargo: five dependency edges are unused on all 12 targets. #40294 removes three. `bun_resolver -> bun_zstd` is used under `cfg(bun_codegen_embed)`. `bun_wyhash -> bstr` is used by unit tests. - Preprocessor: `USE(BIGINT32)` and `ENABLE(MALLOC_BREAKDOWN)` are never true. #43644 and #40557 remove those branches. - Also scanned and clean: `src/js`, `src/node-fallbacks`, `src/codegen`, `scripts/`, `misctools/`, `patches/` (every patch file has a user), `packages/` except `bun-types`. **Probably dead, left alone on purpose** - The `PerformanceResourceTiming` cluster under `src/jsc/bindings/webcore` (about 2,000 lines: `PerformanceResourceTiming`, `PerformanceServerTiming`, `ResourceTiming`, `NetworkLoadMetrics`, `ResourceLoadTiming`, `ServerTiming` and the two JS wrappers). The linker drops every constructor, so no instance can exist. The two globals are public and `test/js/web/web-globals.test.js` checks them. This needs a decision: keep it for a future resource-timing implementation, or reduce it to the two constructors. - `WEBCORE_GENERATED_CONSTRUCTOR_GETTER` (`ZigGlobalObject.cpp`) emits an `X_getter` function for 50 classes. 45 have no user. A removal needs a second macro and saves no source lines. - The WebIDL converters for `byte`, `short` and `long long`, and most `Clamp` and `EnforceRange` specializations in `JSDOMConvertNumbers.cpp`. No binding uses them, but `src/codegen/bindgen.ts` maps `t.i8`, `t.i16` and `t.i64` to them. - `src/js/bun/sql.ts`: the export properties `sql`, `Query`, `postgres` and the four error classes. Native code reads only `default` and `SQL`. It is not certain that no loader path exposes the module object. - `us_nq_settings_set_scid_len` and `us_nq_settings_set_delay_onclose` (`node_quic_shim.c`, declared in `src/lsquic_sys/lib.rs`): no caller. `node:quic` is under active work. - `Event::currentTargetIsInShadowTree()` and its bit: no reader. The lines sit next to a hunk of #39929. - Bake client: `WebSocketWrapper.close()` and `[Symbol.dispose]()`, `streamingStarted`, the `line` and `column` bookkeeping and seven enum members in `JavaScriptSyntaxHighlighter.ts`, and `externals` in `src/node-fallbacks/build-fallbacks.ts`. Each sits next to a hunk of #43378, #40492, #40122 or #41385. - The `internal: true` property option of the class generator. A guard throws on it, so the branches behind it cannot run. Five open pull requests touch `generate-classes.ts`. - `H2App::getNativeHandle` (next to a hunk of #41195) and `uws_app_listen_config_t` (its last user goes with #42431). - `UWS_ALLOW_SHARED_AND_DEDICATED_COMPRESSOR_MIX`, `UWS_ALLOW_8_WINDOW_BITS` and `LIBUS_NO_SSL`: never defined, but they are documented opt-in switches of the upstream libraries. - `scripts/debug-coredump.ts`, `scripts/gamble.ts`, `scripts/github-metrics.ts`, `scripts/lldb-inline.sh` with `scripts/lldb-inline-tool.cpp`, and `packages/h3blast`: nothing references them. They read as tools that a person runs by hand. - #40232 removes `napi_internal_get_version`. #42556 renamed that function to `Bun__napi_get_version` on main, and it still has no caller. </details>
Scheduled dead-code sweep. Net -794 lines (25 files, +30 / -824). Every item has zero references in
src/,packages/,scripts/,test/,.github/,.buildkite/and the regeneratedbuild/debug/codegen/. No deletion here is also made by an open dead-code PR (#37181, #39581, #39618, #39929, #40066): the overlap was checked line by line against their diffs.Problem
scripts/build/source.tsstill carries thecargodependency build kind (CargoBuild,emitCargo, thedep_cargo/dep_cargo_crossninja rules and the branches inresolveDepandcomputeDepLibs). No dependency has usedkind: "cargo"since lolhtml became a cargo path dependency of the workspace.Ninja.variable()andtty.redhave no caller.packages/bun-vscode,bun-debug-adapter-protocol,bun-releaseandbun-inspector-protocolkeep helpers, a duplicaterunUnsavedCode, a 2023 commented-outConsole.messageAddedbody, an unusedsemverdependency and two files nothing imports or loads.src/runtime/bake/client/JavaScriptSyntaxHighlighter.tshas a second render path (highlight(),buildHtmlElement,consumeTemplateString,shouldRedactSensitive) that the overlay never calls.JSDOMPromise.cppdefines onlyDOMPromise::whenPromiseIsSettled, which has no caller.ServerTiming.cppis a TU with no definitions.Fix
semver.test/bake/syntax-highlighter.test.ts(new, pins thesyntaxHighlight()output the overlay depends on),bun bd,bun run rust:check-all(12 targets),bun scripts/build.ts --configure-only,tsconscripts/buildandpackages/bun-vscode(same pre-existing error counts as main),bun bd teston the deep-equals, fetch headers, crypto, MIME, inspect, expect, assert and bake dev-server files, and the bun-vscode unit tests (the twosocket-integrationfailures also fail on main).Background
scripts/build/source.tsdescribes how each vendored dependency is fetched and built; aBuildSpecpicks the strategy (direct,nested-cmake,none). The removedcargovariant rancargo buildin a vendored crate.packages/bun-debug-adapter-protocoltranslates the Debug Adapter Protocol that VS Code speaks into JSC inspector messages.#reverseRequestwas the adapter-to-client request path; nothing ever emitted it, so theAdapter.reverseRequestevent and its listener inbun-vscodego too.syntaxHighlight()->highlightLine().Notes
How the candidates were found: the debug binary was relinked with
--gc-sections --print-gc-sections(no-rdynamic, every Rust#[no_mangle]export pinned with-uso debugger hooks such asdumpBtjsTracestay live), and the removed sections were diffed against the live symbol table. That list was then checked withrgand against the five open dead-code PRs.Found dead but already removed by the open #39618, so not repeated here: 78
extern "C"shims inbindings.cppthat Rust no longer calls (JSC__JSValue__putRecord,JSC__JSModuleLoader__evaluate, theJSC__JSInternalPromise__*set,JSC__JSValue__DateNowISOString,Bun__REPL__formatValue, ...), theirheaders.hdeclarations,keyFromString/keyFromPublicString/passphraseFromBufferSource/ByteSource::fromBIOinnode/crypto, the unusedstatichelpers inJSMIMEType.cpp,JSDOMBindingInternalsBuiltins.cpp, theIDLCallbackInterfaceconverters,napi_set_ref,napi_internal_get_version,highway_json_index,bun_ignore_sigpipe,Bun__disableSOLinger, andStringJsc::to_range_error_instance. Two more shims inbindings.cppare dead and not in any open PR (JSC__JSInternalPromise__status,JSC__JSMap__has); they are left for a sweep after #39618 lands to avoid a conflicting edit to the same file.Left alone on purpose:
packages/bun-inspector-frontend(nothing in the repo references it and its build script reads a WebKit checkout atsrc/bun.js/WebKit, but it is the manual tool that produces the debug.bun.sh bundle and #36288 edits it),scripts/trace.sh(a manual macOS Instruments helper),rustLinkFlags()inscripts/build/rust.ts(a comment inbun.tsnames it as the helper to use), thelogged_severitymethods insrc/react_compiler/diagnostics(TS-parity port),JSCrossRealmTransformState(streams transfer scaffolding wired into the type tables), the Rust#[no_mangle]exports with no C++ caller (Zig__GlobalObject__reportUncaughtException,Bun__ConsoleObject__profile*,ZigString__free),Worker::isOnline, and thesrc/jsbuilt-ins (checked, nothing dead after the four sweeps that already landed there).Rebased twice: onto #40238 and then onto #40374. #40374 removed
SliceWithUnderlyingStringand its JSC trait entirely, which made theto_jscleanup this PR carried inbun_jscmoot, so that part is gone and the PR no longer touches Rust.On tests: every deleted item has no caller, so there is no behavior that differs before and after this PR, and no test can fail on main because of it.
test/bake/syntax-highlighter.test.tspins the output of the one live path whose module changed shape (syntaxHighlight()); it passes on main too, by design.The bun-vscode
socket-integration.test.tsfailures are pre-existing and vary per run on main (they spawn the installed bun for test discovery).CI: the only test that stays red is
test/cli/run/require-cache.test.tson the debian 13 x64-asan lane (twovia import()leak probes hit their 30 s / 60 s timeouts). The same test is red on the same lane in unrelated PR builds (105252, 105259, 105268), and this PR changes nothing on the module loading path. Everything else that failed passed on retry.