Upgrade WebKit to 0d58b764 - #41332
Conversation
|
Updated 11:45 PM PT - Sep 3rd, 2026
❌ @Jarred-Sumner, your commit 0b43085 has 1 failures in
🧪 To try this PR locally: bunx bun-pr 41332That installs a local version of the PR into your bun-41332 --bun |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Essentials Run ID: 📒 Files selected for processing (2)
Included review availability: Your plan provides up to 10 included reviews per hour; 6 remain after this review. WalkthroughThe change updates the WebKit dependency revision and JavaScriptCore bindings. Bindings now use ChangesWebKit dependency revision
JavaScriptCore binding updates
Merge Risk: ⚪ Minimal · up to This update preserves cyclic-array string conversion behavior and adds regression coverage without any identified current-head merge risk. 🚥 Pre-merge checks | ✅ 3 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (3 passed)
Full details: Description checkExplanation The description provides extensive context about the WebKit upgrade and Bun-specific changes, but it does not include the required "How did you verify your code works?" section or any verification details. Comment |
There was a problem hiding this comment.
I reviewed the Bun-side binding adaptations and didn't find any bugs. Given the underlying WebKit range pulls in 67 JSC/WTF/bmalloc commits (DateInstance layout rework, useGlobalInliningPlanner default flip, megamorphic-cache invalidation changes), a human look and full CI signal are still worthwhile before landing.
What was reviewed:
msToGregorianDateTimeout-param → return-by-value at all three call sites (Cookie.cpp, bindings.cpp, wtf-bindings.cpp) — field reads unchanged.Bun__gregorianDateTimeToMSunpacked-arg call preserves themonth - 1adjustment and TimeType selection.JSC__JSValue__DateNowISOStringkeeps theif (!gregorianDateTime)invalid-date guard and only swaps->for.on the accessors.JSEnvironmentVariableMap.cppdrops theoffsetOfData()/RefPtrreinterpret hack for the newinvalidateCachedLocalGregorianDateTime()— the heap walk is retained (matches the note that upstream's own walk only fires onhasTimeZoneChange()).wtf/Expected.h→<expected>/std::expectedin ExceptionOr.h, CallbackResult.h, JSDOMConvertResult.h;makeUnexpectedstill resolved viawtf/StdLibExtras.h.
Extended reasoning...
Overview
This PR bumps the pinned WEBKIT_VERSION in scripts/build/deps/webkit.ts and adapts eight C++ binding files to upstream JavaScriptCore/WTF API changes in the new range. The Bun-side edits are mechanical: DateCache::msToGregorianDateTime now returns by value, gregorianDateTimeToMS takes unpacked scalar arguments, DateInstance::gregorianDateTimeUTC returns a falsy-checkable value type, DateInstance exposes a public invalidateCachedLocalGregorianDateTime() (replacing the offset-based RefPtr<DateInstanceData> poke), and WTF's Expected<T,E> alias is gone in favor of std::expected.
Security risks
None introduced by the Bun-side diff itself — no parsing of untrusted input, no auth/crypto surface, no new allocations or ownership changes. The std::expected swap is type-for-type. The removed reinterpret_cast hack in JSEnvironmentVariableMap.cpp is a net safety improvement. Any security-relevant changes live in the 354 upstream WebKit commits, which are outside what this diff review can verify directly.
Level of scrutiny
High. The Bun-side hunk is small and mechanical, but the real payload is the dependency bump: 67 upstream commits touch JSC/WTF/bmalloc, including a DateInstance storage-layout rewrite (no longer destructible, inline PlainGregorianDateTime), the global inlining planner flipping on by default, megamorphic store-cache invalidation fixes, YarrJIT backtrack fixes, and FTL codegen corrections. Per the repo's own guidance, dependency/vendoring bumps route through .claude/docs/landing-prs.md § Dependencies & vendoring, and REVIEW.md's "refactors are guilty until proven behavior-preserving" applies to the pointer→value transition in JSC__JSValue__DateNowISOString. Approving would signal no human needs to look, which is not appropriate for a JS-engine bump of this scope.
Other factors
The bug hunt exited on dry_streak with no findings and no ruled-out candidates. No CODEOWNERS entries cover the changed paths. The month - 1 offset and WTF::TimeType branch in Bun__gregorianDateTimeToMS are preserved verbatim, and all three msToGregorianDateTime call sites were updated consistently (fix-the-whole-class satisfied). The retained heap walk in invalidateLiveDateInstanceCaches is justified by the PR note that upstream's new VM-entry walk is gated on DateCache::hasTimeZoneChange(), which Bun's direct clearForTimeZoneChange() path bypasses. The one thing I could not verify against source (vendored WebKit not present on disk) is that the new gregorianDateTimeUTC return type exposes both operator! and direct .year()-style accessors — the code assumes both, and if it compiles that assumption holds.
Upstream removed wtf/Expected.h and changed the Date cache APIs. Update the bindings to use std::expected, PlainGregorianDateTime, and DateInstance::invalidateCachedLocalGregorianDateTime().
ada6dfc to
409d9a6
Compare
WebKit upgrade: upstream changes
Range:
c119008088192c83b7861bcbaf24a675f9d7e837..0d58b764f34b86ecf520ac7954b7aa1ded15cc5e(354 upstream commits, 67 touch JavaScriptCore, WTF, or bmalloc).Notes for Bun
wtf/Expected.h. WTF now usesstd::expected. Bun'sExceptionOr.h,CallbackResult.h, andJSDOMConvertResult.hare updated to match.operationDateGetStorageandoperationDateGetStorageUTC. It also removedDateInstanceCache. The fork'sJSGlobalObject::jsDateNow()hook (used for fake timers) is kept inoperationDateNowandcallDate.DateInstanceno longer holds aRefPtr<DateInstanceData>. It stores a packedPlainGregorianDateTimeinline and is no longer destructible.JSEnvironmentVariableMap.cppusedDateInstanceCache.handDateInstance::offsetOfData(). Both are gone. The heap walk now callsDateInstance::invalidateCachedLocalGregorianDateTime().dateInstanceSpaceon VM entry, but only whenDateCache::hasTimeZoneChange()is true. Bun callsclearForTimeZoneChange()directly, so that upstream path does not run forprocess.env.TZwrites.JSType.hdid not change.SUPPRESS_UNCOUNTED_LOCALremoved).JSValueRegsandSnippetRegare removed from the JIT. The fork's DFG buffer ops and FFI stubs now useGPRReg.useGlobalInliningPlannernow defaults totrue. This changes DFG/FTL inlining choices. It has no observable JS behavior change.JSValue.mmhad a small Objective-C cleanup.Runtime and builtins
Object.freezeon a prototype now invalidates the megamorphic cache. https://bugs.webkit.org/show_bug.cgi?id=323131new TypedArray(array)now copies the array first whenToNumbercan run user code. https://bugs.webkit.org/show_bug.cgi?id=322954TypedArray.prototype.setno longer usesmemmovewhen overlapping regions need spec-order reads. https://bugs.webkit.org/show_bug.cgi?id=322892indexOf,includes,lastIndexOf,startsWith, andendsWithreturn early when the search string is longer than the subject. https://bugs.webkit.org/show_bug.cgi?id=322924Date
DateInstancestores its broken-down time inline. A newBrokenDownDateCachereplacesDateInstanceCache. https://bugs.webkit.org/show_bug.cgi?id=323204DateInstance, not only the ones still in the cache.DateGetStoragenode. Getters such asgetFullYearread fields from it.Intl and Temporal
Intl.PluralRules.prototype.selectandselectRangeacceptBigInt. https://bugs.webkit.org/show_bug.cgi?id=323092Intl.DurationFormatomits the separator when minutes are hidden. https://bugs.webkit.org/show_bug.cgi?id=317486Temporal.ZonedDateTime.prototype.roundresolves the offset exactly, not to the minute. https://bugs.webkit.org/show_bug.cgi?id=322923RegExp (Yarr)
/vclass, a character after a nested class or\q{}no longer addsU+0000to the set. https://bugs.webkit.org/show_bug.cgi?id=322962JIT (Baseline, DFG, FTL, B3)
ObjectCreatefolding now emits its edge checks. https://bugs.webkit.org/show_bug.cgi?id=317570toLowerCaseandtoUpperCasestrings inline. https://bugs.webkit.org/show_bug.cgi?id=323033GCOwnedDataScopeon the compiler thread. https://bugs.webkit.org/show_bug.cgi?id=323102CodeBlock::m_lockis held for less time. https://bugs.webkit.org/show_bug.cgi?id=322895Output::loademitted the wrong instruction; validation patchpoints andcachedPutByIdregister constraints are tighter. https://bugs.webkit.org/show_bug.cgi?id=323238 https://bugs.webkit.org/show_bug.cgi?id=323249 https://bugs.webkit.org/show_bug.cgi?id=323248tbz/tbnzfor single-bit tests on ARM64. https://bugs.webkit.org/show_bug.cgi?id=322779ldpmetadata load in the Baseline JIT and the add/sub-zero-to-mov change in the macro assemblers. https://bugs.webkit.org/show_bug.cgi?id=323058 https://bugs.webkit.org/show_bug.cgi?id=323056WebAssembly
.wasmmodules get the JS string builtins andwasm:js/string-constants. https://bugs.webkit.org/show_bug.cgi?id=322238WebAssembly.Exceptiontreatsnulloptions likeundefinedand throwsTypeErrorfor non-objects. https://bugs.webkit.org/show_bug.cgi?id=322948br_on_castandbr_on_cast_fail. https://bugs.webkit.org/show_bug.cgi?id=317349addReturnpatchpoint clobbers macro registers. https://bugs.webkit.org/show_bug.cgi?id=323245table.getfor funcref andany.convert_extern, no write barrier for constant non-cells, andShlfolded into ARM64 addresses. https://bugs.webkit.org/show_bug.cgi?id=322528 https://bugs.webkit.org/show_bug.cgi?id=322781 https://bugs.webkit.org/show_bug.cgi?id=322500 https://bugs.webkit.org/show_bug.cgi?id=323211WTF
wtf/Expected.his removed. Usestd::expectedandstd::unexpected. https://bugs.webkit.org/show_bug.cgi?id=322947 https://bugs.webkit.org/show_bug.cgi?id=322894Build and refactors
JSValueRegsandSnippetRegare removed from the JIT. The fork's DFG buffer ops and FFI stubs now useGPRReg.jscshell sets its main thread QoS to user-interactive on Darwin. https://bugs.webkit.org/show_bug.cgi?id=323207