Skip to content

Upgrade WebKit to 0d58b764 - #41332

Merged
dylan-conway merged 2 commits into
mainfrom
claude/webkit-upgrade-0d58b764
Sep 4, 2026
Merged

dylan-conway merged 2 commits into
mainfrom
claude/webkit-upgrade-0d58b764

Conversation

@Jarred-Sumner

Copy link
Copy Markdown
Collaborator

WebKit upgrade: upstream changes

Range: c119008088192c83b7861bcbaf24a675f9d7e837..0d58b764f34b86ecf520ac7954b7aa1ded15cc5e (354 upstream commits, 67 touch JavaScriptCore, WTF, or bmalloc).

Notes for Bun

  • Upstream removed wtf/Expected.h. WTF now uses std::expected. Bun's ExceptionOr.h, CallbackResult.h, and JSDOMConvertResult.h are updated to match.
  • Upstream replaced the per-field DFG Date getter operations with operationDateGetStorage and operationDateGetStorageUTC. It also removed DateInstanceCache. The fork's JSGlobalObject::jsDateNow() hook (used for fake timers) is kept in operationDateNow and callDate.
  • DateInstance no longer holds a RefPtr<DateInstanceData>. It stores a packed PlainGregorianDateTime inline and is no longer destructible.
  • JSEnvironmentVariableMap.cpp used DateInstanceCache.h and DateInstance::offsetOfData(). Both are gone. The heap walk now calls DateInstance::invalidateCachedLocalGregorianDateTime().
  • Keep Bun's own heap walk. Upstream now walks dateInstanceSpace on VM entry, but only when DateCache::hasTimeZoneChange() is true. Bun calls clearForTimeZoneChange() directly, so that upstream path does not run for process.env.TZ writes.
  • JSType.h did not change.
  • The WebCore bindings generator output changed only cosmetically (SUPPRESS_UNCOUNTED_LOCAL removed).
  • JSValueRegs and SnippetReg are removed from the JIT. The fork's DFG buffer ops and FFI stubs now use GPRReg.
  • useGlobalInliningPlanner now defaults to true. This changes DFG/FTL inlining choices. It has no observable JS behavior change.
  • No public C API changes. JSValue.mm had a small Objective-C cleanup.

Runtime and builtins

Date

  • DateInstance stores its broken-down time inline. A new BrokenDownDateCache replaces DateInstanceCache. https://bugs.webkit.org/show_bug.cgi?id=323204
  • On a time zone change, JSC now invalidates every live DateInstance, not only the ones still in the cache.
  • DFG and FTL use a new DateGetStorage node. Getters such as getFullYear read fields from it.

Intl and Temporal

RegExp (Yarr)

JIT (Baseline, DFG, FTL, B3)

WebAssembly

WTF

Build and refactors

  • JSValueRegs and SnippetReg are removed from the JIT. The fork's DFG buffer ops and FFI stubs now use GPRReg.
  • The jsc shell sets its main thread QoS to user-interactive on Darwin. https://bugs.webkit.org/show_bug.cgi?id=323207
  • 21 other commits are Cocoa/Xcode/CMake build changes, Safer CPP macro cleanups, test-tool fixes, or WebCore-only work that touched shared files.
  • The remaining 287 commits do not touch JavaScriptCore, WTF, or bmalloc.

@robobun

robobun commented Sep 4, 2026 •

Copy link
Copy Markdown
Collaborator
Updated 11:45 PM PT - Sep 3rd, 2026

❌ @Jarred-Sumner, your commit 0b43085 has 1 failures in Build #110061 (All Failures):


🧪   To try this PR locally:

bunx bun-pr 41332

That installs a local version of the PR into your bun-41332 executable, so you can run:

bun-41332 --bun

@coderabbitai

coderabbitai Bot commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Essentials

Run ID: 877ff041-82ab-4dbc-af28-d8f16c77328b

📥 Commits

Reviewing files that changed from the base of the PR and between f7301f3 and ada6dfc.

📒 Files selected for processing (2)
  • test/js/bun/jsc/webkit-upgrade-3722912f.test.ts
  • test/regression/issue/41198.test.ts

Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review.


Walkthrough

The change updates the WebKit dependency revision and JavaScriptCore bindings. Bindings now use std::expected, public date-cache invalidation, and value-returning Gregorian date-time APIs. Tests add coverage for cyclic-array conversions and joining.

Changes

WebKit dependency revision

Layer / File(s) Summary
WebKit revision update
scripts/build/deps/webkit.ts
The default WEBKIT_VERSION hash changes to d4e7e206dc9b1c58eb8aca8f06eed7a6f4abb98a.

JavaScriptCore binding updates

Layer / File(s) Summary
Standard expected storage
src/jsc/bindings/ExceptionOr.h, src/jsc/bindings/webcore/CallbackResult.h, src/jsc/bindings/webcore/JSDOMConvertResult.h
ExceptionOr, CallbackResult, and conversion result storage now use std::expected.
Date cache invalidation
src/jsc/bindings/JSEnvironmentVariableMap.cpp, src/jsc/bindings/JSEnvironmentVariableMap.h
Live DateInstance objects invalidate cached local Gregorian date-time values through the public invalidation method.
Gregorian date-time API migration
src/jsc/bindings/bindings.cpp, src/jsc/bindings/Cookie.cpp, src/jsc/bindings/wtf-bindings.cpp
Cookie and ISO string formatting use value-returning Gregorian date-time conversions. Existing formatting behavior remains unchanged.
Cyclic-array regression coverage
test/js/bun/jsc/webkit-upgrade-3722912f.test.ts, test/regression/issue/41198.test.ts
Tests expect cyclic arrays to convert and join without throwing. Tests continue to expect JSON.stringify to reject cyclic arrays.

Merge Risk: ⚪ Minimal · up to 0b430

This update preserves cyclic-array string conversion behavior and adds regression coverage without any identified current-head merge risk.

🚥 Pre-merge checks | ✅ 3 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description provides extensive context about the WebKit upgrade and Bun-specific changes, but it does not include the required "How did you verify your code works?" section or any verification det… Add the required "### How did you verify your code works?" section and document the tests, builds, or other validation performed. Use the template heading "### What does this PR do?" or otherwise clearly identify that section as well.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly identifies the primary change as a WebKit upgrade and is concise. The referenced commit hash differs from the updated hash in the file summary, but the title remains directly related…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description provides extensive context about the WebKit upgrade and Bun-specific changes, but it does not include the required "How did you verify your code works?" section or any verification details.


Comment @coderabbitai help to get the list of available commands.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed the Bun-side binding adaptations and didn't find any bugs. Given the underlying WebKit range pulls in 67 JSC/WTF/bmalloc commits (DateInstance layout rework, useGlobalInliningPlanner default flip, megamorphic-cache invalidation changes), a human look and full CI signal are still worthwhile before landing.

What was reviewed:

  • msToGregorianDateTime out-param → return-by-value at all three call sites (Cookie.cpp, bindings.cpp, wtf-bindings.cpp) — field reads unchanged.
  • Bun__gregorianDateTimeToMS unpacked-arg call preserves the month - 1 adjustment and TimeType selection.
  • JSC__JSValue__DateNowISOString keeps the if (!gregorianDateTime) invalid-date guard and only swaps -> for . on the accessors.
  • JSEnvironmentVariableMap.cpp drops the offsetOfData()/RefPtr reinterpret hack for the new invalidateCachedLocalGregorianDateTime() — the heap walk is retained (matches the note that upstream's own walk only fires on hasTimeZoneChange()).
  • wtf/Expected.h → <expected> / std::expected in ExceptionOr.h, CallbackResult.h, JSDOMConvertResult.h; makeUnexpected still resolved via wtf/StdLibExtras.h.
Extended reasoning...

Overview

This PR bumps the pinned WEBKIT_VERSION in scripts/build/deps/webkit.ts and adapts eight C++ binding files to upstream JavaScriptCore/WTF API changes in the new range. The Bun-side edits are mechanical: DateCache::msToGregorianDateTime now returns by value, gregorianDateTimeToMS takes unpacked scalar arguments, DateInstance::gregorianDateTimeUTC returns a falsy-checkable value type, DateInstance exposes a public invalidateCachedLocalGregorianDateTime() (replacing the offset-based RefPtr<DateInstanceData> poke), and WTF's Expected<T,E> alias is gone in favor of std::expected.

Security risks

None introduced by the Bun-side diff itself — no parsing of untrusted input, no auth/crypto surface, no new allocations or ownership changes. The std::expected swap is type-for-type. The removed reinterpret_cast hack in JSEnvironmentVariableMap.cpp is a net safety improvement. Any security-relevant changes live in the 354 upstream WebKit commits, which are outside what this diff review can verify directly.

Level of scrutiny

High. The Bun-side hunk is small and mechanical, but the real payload is the dependency bump: 67 upstream commits touch JSC/WTF/bmalloc, including a DateInstance storage-layout rewrite (no longer destructible, inline PlainGregorianDateTime), the global inlining planner flipping on by default, megamorphic store-cache invalidation fixes, YarrJIT backtrack fixes, and FTL codegen corrections. Per the repo's own guidance, dependency/vendoring bumps route through .claude/docs/landing-prs.md § Dependencies & vendoring, and REVIEW.md's "refactors are guilty until proven behavior-preserving" applies to the pointer→value transition in JSC__JSValue__DateNowISOString. Approving would signal no human needs to look, which is not appropriate for a JS-engine bump of this scope.

Other factors

The bug hunt exited on dry_streak with no findings and no ruled-out candidates. No CODEOWNERS entries cover the changed paths. The month - 1 offset and WTF::TimeType branch in Bun__gregorianDateTimeToMS are preserved verbatim, and all three msToGregorianDateTime call sites were updated consistently (fix-the-whole-class satisfied). The retained heap walk in invalidateLiveDateInstanceCaches is justified by the PR note that upstream's new VM-entry walk is gated on DateCache::hasTimeZoneChange(), which Bun's direct clearForTimeZoneChange() path bypasses. The one thing I could not verify against source (vendored WebKit not present on disk) is that the new gregorianDateTimeUTC return type exposes both operator! and direct .year()-style accessors — the code assumes both, and if it compiles that assumption holds.

Upstream removed wtf/Expected.h and changed the Date cache APIs. Update
the bindings to use std::expected, PlainGregorianDateTime, and
DateInstance::invalidateCachedLocalGregorianDateTime().
@Jarred-Sumner
Jarred-Sumner force-pushed the claude/webkit-upgrade-0d58b764 branch from ada6dfc to 409d9a6 Compare September 4, 2026 05:16

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review found no issues

No high-confidence issues detected in this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants