Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
104 commits
Select commit Hold shift + click to select a range
c18f11b
[WebRTC] Out-of-bounds write in copyVideoFrameBuffer for odd-width I4…
youennf Aug 28, 2026
92e0ba8
[webkitbugspy] Cannot remove a relation between two issues
TheBoyRoy05 Aug 28, 2026
585cb45
AX: AXTextMarkerRangeForUIElement covers a native text control as a r…
minorninth Aug 28, 2026
0fb9b2c
[JSC] Update profile concurrently from GC marker threads
Constellation Aug 28, 2026
b2177e4
AX: AXReplaceRangeWithText inserts text at the wrong index
minorninth Aug 28, 2026
0d9f8fa
Drop RefCounted's adoption requirement assertion
cdumez Aug 28, 2026
4ae5342
Fix compilation issue with WK_WEB_EXTENSIONS_OFFSCREEN on iOS
b-weinstein Aug 28, 2026
d01d085
[CFNetwork] Honor Expires cookie dates that use JS Date.toString() da…
brentfulgham Aug 28, 2026
2715812
REGRESSION(319888@main): [AppKit Gestures] Cannot back/forward naviga…
aprotyas Aug 28, 2026
36058b8
[Wasm] Unreachable end ops don't widen result types
kmiller68 Aug 28, 2026
befc998
AX: In isolated tree mode, AXStringForTextMarkerRange unexpectedly in…
twilco Aug 28, 2026
31dc597
[TextureMapper] Remove unused BitmapTexture::Flags::DepthBuffer
carlosgcampos Aug 28, 2026
cec9d20
:target should keep matching a target element that is removed and rei…
annevk Aug 28, 2026
3b492a1
[css-mixins-1] Registered function arguments should evaluate in calli…
anttijk Aug 28, 2026
2257a2c
[css-overflow-4] Support `text-overflow: <string>`
nt1m Aug 28, 2026
881e23e
Unreviewed, reverting 319908@main (80fc868e7373)
revert-bot Aug 28, 2026
96b6729
[Re-landing] Introducing Mya, a MemorY Analyzer, and libJavaScriptCor…
Aug 28, 2026
f54d057
[scroll-animations] keep track of style scope for `animation-timeline…
graouts Aug 28, 2026
5f47279
[JSC][Wasm] Inline BBQ array.new_default for v128
chicoxyzzy Aug 28, 2026
ff8fd01
[GLIB] imported/w3c/web-platform-tests/css/css-values/ch-unit-017.htm…
dpino Aug 28, 2026
5c1c95d
[webkit-sysprof] Add a frame cycle breakdown to analyze
nikolaszimmermann Aug 28, 2026
70826d7
WebEvent and its subclasses should always be heap-allocated
cdumez Aug 28, 2026
ffbf2c9
[GLIB] Unskip ipc/serialized-type-info.html
csaavedra Aug 28, 2026
00c991b
[Swift in WebKit] Introduce a bridging mechanism to create `std::expe…
rr-codes Aug 28, 2026
969d785
[GTK][WPE] Gardening of tests - 2026-08-28
kate-k-lee Aug 28, 2026
029da7d
Page freezes with CSS transition duration calc(infinity * 1s)
graouts Aug 28, 2026
129c7bc
[GLib] Add monado packages to system dependencies list
dpino Aug 28, 2026
0c7b760
Pass correct linker prefix on PlayStation platform
adetaylor Aug 28, 2026
c67740b
Fix typo in `WGSL::Types::Primitive` and `WGSL::nameForPrimitiveKind`
iidmsa Aug 28, 2026
2668e2d
[non-cocoa][fuzz] OOB write in APNG ICC conversion
justinmichaud Aug 28, 2026
18e0887
Creating or destroying a ThreadSafeWeakPtr should be considered no-de…
rniwa Aug 28, 2026
d729ce6
[scroll-animations] make timeline names loosely-matched
graouts Aug 28, 2026
27441f0
[Gardening]: (REGRESSION(318498@main): [Tahoe] 11 imported/w3c/web-pl…
karlrackler Aug 28, 2026
05b6f71
Create dispatch queues with autorelease pools
bnham Aug 28, 2026
119fd82
[Site Isolation] Coalesce per-rendering-update frame geometry IPCs
bnham Aug 28, 2026
8458822
[css-text-decor] Negative text-decoration-inset is clipped when the d…
alanbaradlay Aug 28, 2026
1aa99d7
[LBSE] Fix viewport clipping issues
nikolaszimmermann Aug 28, 2026
9ec86f1
[Gardening]: (New Test(319793@main): [macOS Debug] imported/w3c/web-p…
karlrackler Aug 28, 2026
cbd4392
[Gardening]: (New Test(319793@main): [macOS Debug] imported/w3c/web-p…
karlrackler Aug 28, 2026
261bcb4
[Wasm] Delegate should widen types like End
kmiller68 Aug 28, 2026
31b4991
Unreviewed, fix safer cpp regression from 320030@main
cdumez Aug 28, 2026
2b43852
media/media-source/media-source-video-renders.html is constant ImageO…
jyavenard Aug 28, 2026
e803244
ESPN.com on iPhone: After exiting full screen, video pauses and tappi…
danae404 Aug 28, 2026
64e677b
[css-text-decor-4] Support percentages in text-decoration-inset
alanbaradlay Aug 28, 2026
ad023b3
[JSC][Wasm] Compare custom section names without allocating a String
chicoxyzzy Aug 28, 2026
98007ce
[JSC][Wasm] Inline ref.func
chicoxyzzy Aug 28, 2026
d3e6e0f
[JSC][Wasm] Fast-path i31ref in the JS-to-Wasm entry stub
chicoxyzzy Aug 28, 2026
565aa48
[JSC][Wasm] Fill wasm ref arrays without per-element set()
chicoxyzzy Aug 28, 2026
bb8cb62
[JSC][Wasm] Expect CompileError for an empty WebAssembly.Module
chicoxyzzy Aug 28, 2026
81b5126
[JSC][Wasm] ESM mutable globals should be live unwrapped bindings
chicoxyzzy Aug 28, 2026
6f7bb45
[JSC][Wasm] Reserved wasm: and wasm-js: names should LinkError in ESM
chicoxyzzy Aug 28, 2026
209e271
Move some part of collectScreenProperties to a background thread
bnham Aug 28, 2026
929f6e8
[Wasm] Exclude wasmBoundsCheckingSizeRegister from the callee saves r…
kmiller68 Aug 28, 2026
d95a22a
[JSC][Wasm] Cover elem kind 6 initialized from global.get
chicoxyzzy Aug 28, 2026
4b267e8
corner-shape: backdrop-filter is clipped to the rounded rect, ignorin…
cupidsity Aug 28, 2026
8093ad2
Refactor `RunJavaScriptResult` into a standalone typed using declaration
rr-codes Aug 28, 2026
868c075
[Interop 2026] Sync with upstream WPT for popover related tests
brentfulgham Aug 28, 2026
ef84d01
GitHub.com: v2: emoji reaction overlaps code box in comment
sammygill Aug 28, 2026
bc80ea5
[perf.webkit.org] Update sync-commits.py to support Canonical-link
gsnedders Aug 28, 2026
7418d7f
Change movingSteps isSubtreeRoot parameter to an enum
lukewarlow Aug 28, 2026
0ac697f
Add new ChildChange types for moveBefore
lukewarlow Aug 28, 2026
feb2b77
[Quirks] Remove unused function declarations
colelao Aug 28, 2026
9dcbd25
[Wasm] Argument and Result block types should always widen
kmiller68 Aug 28, 2026
26aa84f
OSR Availability Fails to Invalidate Local Recoveries Across LoadVarargs
kmiller68 Aug 28, 2026
f0d5be8
CanvasRenderingContext2DBase::drawTextUnchecked: don't re-use pointer…
tuankiet65 Aug 28, 2026
dd8d648
Remove MAYBE_EVALUATE_URL_WITH_TRANSITIVE_TRUST and MAYBE_REQUEST_PER…
jelee53 Aug 28, 2026
1a0fe8e
Resync `css/css-inline/parsing` from WPT Upstream
swpatters Aug 28, 2026
33a2d05
Fold EarlyHintsResourceLoader into NetworkResourceLoader.
yoavweiss Aug 28, 2026
bc7a9e0
Persist the resolved IP address space with a cached response
igower Aug 28, 2026
084154b
Unify naming of zoom applying/unapplying functions
weinig Aug 28, 2026
937b1dd
[Quirks] Make QuirkMatch a generic URL matcher
colelao Aug 28, 2026
37966e5
[Interop 2026] Correct two Dialogs and Popover failures after WPT sync
brentfulgham Aug 28, 2026
1458014
HTMLVideoElement::player() is called and protected redundantly in sev…
Aug 28, 2026
77a6c78
HTMLMediaElement::isSafeToLoadURL() computes isIPAddressDisallowed() …
Aug 28, 2026
1e5465e
[JSC] ArrayProfile read / update does not need a lock
Constellation Aug 28, 2026
a346ccb
All subsequent videos played after the first one auto exit fullscreen…
Aug 28, 2026
3708229
Enable the offscreen web extension API
b-weinstein Aug 28, 2026
1c9b16d
[YARR] Fix lastIndex and ^ handling in dotAll mode
syg Aug 29, 2026
651c2a2
[EWS] Activate flaky test verdicts
TheBoyRoy05 Aug 29, 2026
24a47dd
[css-overflow-4] `text-overflow: <string>` should work on `<input>`
nt1m Aug 29, 2026
f54ee01
Unreviewed, fix JSCOnly build
Constellation Aug 29, 2026
31fe328
Re-import css/css-overflow & css/css-ui WPT
nt1m Aug 29, 2026
120664e
Unreviewed, Fix JSCOnly port part 2
Constellation Aug 29, 2026
d0e525d
Unreviewed, marking test as slow
Constellation Aug 29, 2026
fcd8c65
[SaferCPP] Address more warnings in Source/WebKit found by the latest…
cdumez Aug 29, 2026
66e2e26
Make CSSTokenizer work efficiently with StringViews
weinig Aug 29, 2026
87a413d
Update safer C++ expectations (2026-08-28)
rniwa Aug 29, 2026
e25bd0f
RemoteLayerTreeEventDispatcher: add lock to guard access to m_momentu…
robert-jenner Aug 29, 2026
b0d927d
REGRESSION(316606.145@safari-7625-branch): UI process crash under Dis…
aprotyas Aug 29, 2026
f014a04
[GLib] layout test gardening 2026-08-29
fujii Aug 29, 2026
d545f58
[JSC] DFG `StringReplace` constant folding steps into a surrogate pai…
sosukesuzuki Aug 29, 2026
038b868
REGRESSION(320028@main): [GLIB] Apply advance height only if font has…
dpino Aug 29, 2026
e846671
[GLIB] Unskip the IPC colorspace tests on the GLib ports
csaavedra Aug 29, 2026
24545f4
[non-cocoa][fuzz] Frame cache evicted or unparsed frames dereferenced
justinmichaud Aug 29, 2026
be31a7f
Simplify SVGLengthValue::setValueAsString() whitespace handling
Ahmad-S792 Aug 29, 2026
26f0db0
[JSC] incorrect ValueProfile is used in BaselineJIT iterator_next
Constellation Aug 29, 2026
ff78e4f
Cache invalidation bypass via monotonic max-index tracking leads to G…
mwyrzykowski Aug 29, 2026
4307d59
[WebDriver][Tools] Some WPT tests depend on a deprecated event_loop f…
lauromoura Aug 29, 2026
bfd4410
[GStreamer] Auto-plug parsers before decoders in the Thunder parser
TingPing Aug 30, 2026
382a689
Skip PGO profiling for JavaScriptCoreTools.
dewei-zhu Aug 30, 2026
faa08bc
[GLib] layout test gardening 2026-08-30
fujii Aug 30, 2026
61474c0
Remove unused tryResolved() from CSS::CustomIdent
weinig Aug 30, 2026
df289ce
[JSC] Reuse `FunctionExecutables` instantiated for module function de…
sosukesuzuki Aug 30, 2026
509bfed
Merge upstream WebKit df289ce551 into main
robobun Aug 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
//@ requireOptions("--forceCodeBlockToJettisonDueToOldAge=1", "--useEagerCodeBlockJettisonTiming=1")
import { shouldBe } from "./resources/assert.js";
import * as A from "./module-function-declaration-executable-reuse-jettison/a.js";

shouldBe(A.before, "f g h s");
shouldBe(A.after, "f 42 h2 s");
shouldBe(A.blockResult, "block");
shouldBe(A.fAfterBlock, "f");
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
export function f() { return "f"; }
export function g() { return "g"; }
export function h() { return "h"; }
function s() { return "s"; }
export const before = [f(), g(), h(), s()].join(" ");
g = 42;
h = function () { return "h2"; };
Promise.resolve().then(() => { fullGC(); });
await 0;
export const after = [f(), g, h(), s()].join(" ");
export let blockResult;
{
function f() { return "block"; }
blockResult = f();
}
export const fAfterBlock = f();
23 changes: 23 additions & 0 deletions JSTests/modules/module-function-declaration-executable-reuse.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
import { shouldBe } from "./resources/assert.js";
import * as A from "./module-function-declaration-executable-reuse/a.js";
import * as Same1 from "./module-function-declaration-executable-reuse/same-1.js";
import * as Same2 from "./module-function-declaration-executable-reuse/same-2.js";

shouldBe(A.f(), "f");
shouldBe(A.blockResult, "block");
shouldBe(A.gSeenInB, "g");
shouldBe(A.hSeenInB, "h");
shouldBe(A.kSeenInB, "k");
shouldBe(A.gInBody(), "replaced");
shouldBe(A.hInBody, 42);
shouldBe(A.kInBody, Math.max);
shouldBe(A.callCaptured(), "captured");
shouldBe(A.localResult, "local");
shouldBe(A.gen().next().value, "gen");
shouldBe(typeof A.asyncFn, "function");
shouldBe(typeof A.asyncGen, "function");

shouldBe(Same1.fInBody, Same2.f);
shouldBe(Same2.fInBody, Same1.f);
shouldBe(Same1.f(), "f");
shouldBe(Same2.f(), "f");
29 changes: 29 additions & 0 deletions JSTests/modules/module-function-declaration-executable-reuse/a.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
import { gSeenInB, hSeenInB, kSeenInB } from "./b.js";

export function f() { return "f"; }
export function g() { return "g"; }
export function h() { return "h"; }
export function k() { return "k"; }
export function setG(value) { g = value; }
export function setH(value) { h = value; }
export function setK(value) { k = value; }
export function* gen() { yield "gen"; }
export async function asyncFn() { return "async"; }
export async function* asyncGen() { yield "asyncGen"; }

function captured() { return "captured"; }
export function callCaptured() { return captured(); }

function local() { return "local"; }
export const localResult = local();

export let blockResult;
{
function f() { return "block"; }
blockResult = f();
}

export const gInBody = g;
export const hInBody = h;
export const kInBody = k;
export { gSeenInB, hSeenInB, kSeenInB };
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
import { g, h, k, setG, setH, setK } from "./a.js";

export const gSeenInB = g();
export const hSeenInB = h();
export const kSeenInB = k();
setG(function () { return "replaced"; });
setH(42);
setK(Math.max);
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
import "./same-setter.js";
export function f() { return "f"; }
export function setF(value) { f = value; }
export const fInBody = f;
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
import "./same-setter.js";
export function f() { return "f"; }
export function setF(value) { f = value; }
export const fInBody = f;
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
import { f, setF } from "./same-1.js";
import { f as f2, setF as setF2 } from "./same-2.js";

setF(f2);
setF2(f);
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
//@ runDefault("--thresholdForJITAfterWarmUp=10", "--thresholdForFTLOptimizeAfterWarmUp=1000", "--useConcurrentJIT=false", "--validateFTLOSRExitLiveness=true")

"use strict";

function shouldBe(actual, expected)
{
if (actual !== expected)
throw new Error("bad value: " + actual + ", expected: " + expected);
}

function five(values1, values2)
{
let result = null;
for (let i = 0; i < 5; ++i) {
function arg() { "use strict"; return arguments; }
const a = arg.apply(undefined, values1);
const b = arg.apply(undefined, values2);
try {
(3881)(b);
} catch (error) {
a.toString();
result = a;
}
}
return result;
}

function eight(values1, values2)
{
let result = null;
for (let i = 0; i < 5; ++i) {
function arg() { "use strict"; return arguments; }
const a = arg.apply(undefined, values1);
const b = arg.apply(undefined, values2);
try {
(3881)(b);
} catch (error) {
a.toString();
result = a;
}
}
return result;
}

function filled(length, value)
{
const result = [];
for (let i = 0; i < length; ++i)
result.push(value);
return result;
}

const fiveMarker = { marker: "five" };
const eightMarker = { marker: "eight" };
const seedArray = [{ marker: "seed" }, 1, 2, 3, 4, 5];

const firstFive = filled(5, fiveMarker);
const overwriteFive = filled(30, fiveMarker);
overwriteFive[22] = 9;

const firstEight = filled(8, eightMarker);
const overwriteEight = filled(30, eightMarker);
overwriteEight[20] = 9;

for (let i = 0; i < testLoopCount; ++i) {
five(firstFive, overwriteFive);
eight(firstEight, overwriteEight);
}

const seedValues = filled(30, seedArray);
seedValues[20] = 9;
for (let i = 0; i < testLoopCount; ++i)
eight(firstEight, seedValues);

const recoveredEight = eight(firstEight, seedValues);
shouldBe(recoveredEight.length, firstEight.length);
for (let i = 0; i < firstEight.length; ++i)
shouldBe(recoveredEight[i], eightMarker);

const recoveredFive = five(firstFive, overwriteFive);
shouldBe(recoveredFive.length, firstFive.length);
for (let i = 0; i < firstFive.length; ++i)
shouldBe(recoveredFive[i], fiveMarker);
shouldBe(recoveredFive[5], undefined);
Original file line number Diff line number Diff line change
@@ -0,0 +1,88 @@
//@ runDefault("--thresholdForJITAfterWarmUp=10", "--thresholdForFTLOptimizeAfterWarmUp=1000", "--useConcurrentJIT=false")

"use strict";

function shouldBe(actual, expected)
{
if (actual !== expected)
throw new Error("bad value: " + actual + ", expected: " + expected);
}
noInline(shouldBe);

function five(values1, values2)
{
let result = null;
for (let i = 0; i < 5; ++i) {
function arg() { "use strict"; return arguments; }
const a = arg.apply(undefined, values1);
const b = arg.apply(undefined, values2);
try {
(3881)(b);
} catch (error) {
a.toString();
result = a;
}
}
return result;
}
noInline(five);

function eight(values1, values2)
{
let result = null;
for (let i = 0; i < 5; ++i) {
function arg() { "use strict"; return arguments; }
const a = arg.apply(undefined, values1);
const b = arg.apply(undefined, values2);
try {
(3881)(b);
} catch (error) {
a.toString();
result = a;
}
}
return result;
}
noInline(eight);

function filled(length, value)
{
const result = [];
for (let i = 0; i < length; ++i)
result.push(value);
return result;
}
noInline(filled);

const fiveMarker = { marker: "five" };
const eightMarker = { marker: "eight" };
const seedArray = [{ marker: "seed" }, 1, 2, 3, 4, 5];

const firstFive = filled(5, fiveMarker);
const overwriteFive = filled(30, fiveMarker);
overwriteFive[22] = 9;

const firstEight = filled(8, eightMarker);
const overwriteEight = filled(30, eightMarker);
overwriteEight[20] = 9;

for (let i = 0; i < testLoopCount; ++i) {
five(firstFive, overwriteFive);
eight(firstEight, overwriteEight);
}

const seedValues = filled(30, seedArray);
seedValues[20] = 9;
for (let i = 0; i < testLoopCount; ++i)
eight(firstEight, seedValues);

const recoveredEight = eight(firstEight, seedValues);
shouldBe(recoveredEight.length, firstEight.length);
for (let i = 0; i < firstEight.length; ++i)
shouldBe(recoveredEight[i], eightMarker);

const recoveredFive = five(firstFive, overwriteFive);
shouldBe(recoveredFive.length, firstFive.length);
for (let i = 0; i < firstFive.length; ++i)
shouldBe(recoveredFive[i], fiveMarker);
shouldBe(recoveredFive[5], undefined);
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
function shouldBe(actual, expected) {
if (actual !== expected)
throw new Error(`bad value: ${JSON.stringify(actual)}, expected ${JSON.stringify(expected)}`);
}

function replaceUnicode() {
return "a\u{1F600}b".replace(/(?:)/gu, "-");
}
noInline(replaceUnicode);

function replaceUnicodeSets() {
return "a\u{1F600}b".replace(/(?:)/gv, "-");
}
noInline(replaceUnicodeSets);

function replaceAllUnicode() {
return "\u{1F600}\u{1F601}".replaceAll(/(?:)/gu, "|");
}
noInline(replaceAllUnicode);

function replaceLoneLead() {
return "a\uD83D".replace(/(?:)/gu, "-");
}
noInline(replaceLoneLead);

function replaceNonUnicode() {
return "a\u{1F600}b".replace(/(?:)/g, "-");
}
noInline(replaceNonUnicode);

for (var i = 0; i < testLoopCount; ++i) {
shouldBe(replaceUnicode(), "-a-\u{1F600}-b-");
shouldBe(replaceUnicodeSets(), "-a-\u{1F600}-b-");
shouldBe(replaceAllUnicode(), "|\u{1F600}|\u{1F601}|");
shouldBe(replaceLoneLead(), "-a-\uD83D-");
shouldBe(replaceNonUnicode(), "-a-\uD83D-\uDE00-b-");
}
40 changes: 40 additions & 0 deletions JSTests/stress/for-of-mixed-element-types-value-profile.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
//@ skip if not $jitTests
//@ $skipModes << :lockdown
//@ requireOptions("--forceUnlinkedDFG=0")

// The baseline JIT's fast-array op_iterator_next path must profile the iterated element into the
// getValue checkpoint's value profile. When it wrote to the computeNext slot instead, the DFG kept
// predicting the loop variable from whatever the LLInt had sampled, so it re-speculated the same
// wrong type on every recompilation until the reoptimization retry counter ran out.

function events(i)
{
// Only the baseline JIT ever sees the number: by iteration 20000 this function is long past the
// LLInt.
return i < 20000 ? ["a", "bb", "ccc"] : ["a", "bb", 0];
}
noInline(events);

function walk(i)
{
let count = 0;
for (let event of events(i)) {
if (typeof event === "number")
count += event;
else
count += event.length;
}
return count;
}
noInline(walk);

let total = 0;
for (let i = 0; i < 300000; ++i)
total += walk(i);

if (total !== 960000)
throw new Error(`bad result: ${total}`);

const compiles = numberOfDFGCompiles(walk);
if (compiles > 4)
throw new Error(`walk was DFG-compiled ${compiles} times; the loop variable's value profile is not being updated`);
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
//@ slow!
//@ runDefault("--forceEagerCompilation=1")

let total = 0;
Expand Down
Loading
Loading