Timeline
Apr 9, 2016:
- 8:38 PM Changeset in webkit [199279] by
-
- 21 edits in trunk/Source/JavaScriptCore
tryGetById should be supported by the DFG/FTL
https://bugs.webkit.org/show_bug.cgi?id=156378
Reviewed by Filip Pizlo.
This patch adds support for tryGetById in the DFG/FTL. It adds a new DFG node
TryGetById, which acts similarly to the normal GetById DFG node. One key
difference between GetById and TryGetById is that in the LLInt and Baseline
we do not profile the result type. This profiling is unnessary for the current
use case of tryGetById, which is expected to be a strict equality comparision
against a specific object or undefined. In either case other DFG optimizations
will make this equally fast with or without the profiling information.
Additionally, this patch adds new reuse modes for JSValueRegsTemporary that take
an operand and attempt to reuse the registers for that operand if they are free
after the current DFG node.
- bytecode/GetByIdStatus.cpp:
(JSC::GetByIdStatus::computeFromLLInt):
(JSC::GetByIdStatus::computeForStubInfoWithoutExitSiteFeedback):
- dfg/DFGAbstractInterpreterInlines.h:
(JSC::DFG::AbstractInterpreter<AbstractStateType>::executeEffects):
- dfg/DFGByteCodeParser.cpp:
(JSC::DFG::ByteCodeParser::handleGetById):
(JSC::DFG::ByteCodeParser::parseBlock):
- dfg/DFGCapabilities.cpp:
(JSC::DFG::capabilityLevel):
- dfg/DFGClobberize.h:
(JSC::DFG::clobberize):
- dfg/DFGDoesGC.cpp:
(JSC::DFG::doesGC):
- dfg/DFGFixupPhase.cpp:
(JSC::DFG::FixupPhase::fixupNode):
- dfg/DFGNode.h:
(JSC::DFG::Node::hasIdentifier):
- dfg/DFGNodeType.h:
- dfg/DFGPredictionPropagationPhase.cpp:
(JSC::DFG::PredictionPropagationPhase::propagate):
- dfg/DFGSafeToExecute.h:
(JSC::DFG::safeToExecute):
- dfg/DFGSpeculativeJIT.cpp:
(JSC::DFG::SpeculativeJIT::compileTryGetById):
(JSC::DFG::JSValueRegsTemporary::JSValueRegsTemporary):
- dfg/DFGSpeculativeJIT.h:
(JSC::DFG::GPRTemporary::operator=):
- dfg/DFGSpeculativeJIT32_64.cpp:
(JSC::DFG::SpeculativeJIT::cachedGetById):
(JSC::DFG::SpeculativeJIT::compile):
- dfg/DFGSpeculativeJIT64.cpp:
(JSC::DFG::SpeculativeJIT::cachedGetById):
(JSC::DFG::SpeculativeJIT::compile):
- ftl/FTLCapabilities.cpp:
(JSC::FTL::canCompile):
- ftl/FTLLowerDFGToB3.cpp:
(JSC::FTL::DFG::LowerDFGToB3::compileNode):
(JSC::FTL::DFG::LowerDFGToB3::compileGetById):
(JSC::FTL::DFG::LowerDFGToB3::getById):
- jit/JITOperations.cpp:
- jit/JITOperations.h:
- tests/stress/try-get-by-id.js:
(tryGetByIdTextStrict):
(get let):
(let.get createBuiltin):
(get throw):
(getCaller.obj.1.throw.new.Error): Deleted.
- 6:46 PM Changeset in webkit [199278] by
-
- 2 edits in trunk/Source/WebCore
Fixed compilation of JPEGImageDecoder with libjpeg v9.
https://bugs.webkit.org/show_bug.cgi?id=156445
Patch by Konstantin Tokarev <Konstantin Tokarev> on 2016-04-09
Reviewed by Michael Catanzaro.
ICU defines TRUE and FALSE macros, breaking libjpeg v9 headers.
No new tests needed.
- platform/image-decoders/jpeg/JPEGImageDecoder.h:
- 5:26 PM Changeset in webkit [199277] by
-
- 2 edits1 add in trunk/Source/JavaScriptCore
Allocation sinking SSA Defs are allowed to have replacements
https://bugs.webkit.org/show_bug.cgi?id=156444
Reviewed by Filip Pizlo.
Consider the following program and the annotations that explain why
the SSA defs we create in allocation sinking can have replacements.
function foo(a1) {
let o1 = {x: 20, y: 50};
let o2 = {y: 40, o1: o1};
let o3 = {};
We're Defing a new variable here, call it o3_field.
o3_field is defing the value that is the result of
a GetByOffset that gets eliminated through allocation sinking.
o3.field = o1.y;
dontCSE();
This control flow is here to not allow the phase to consult
its local SSA mapping (which properly handles replacements)
for the value of o3_field.
if (a1) {
a1 = true;
} else {
a1 = false;
}
Here, we ask for the reaching def of o3_field, and assert
it doesn't have a replacement. It does have a replacement
though. The original Def was the GetByOffset. We replaced
that GetByOffset with the value of the o1_y variable.
let value = o3.field;
assert(value === 50);
}
- dfg/DFGObjectAllocationSinkingPhase.cpp:
- tests/stress/allocation-sinking-defs-may-have-replacements.js: Added.
(dontCSE):
(assert):
(foo):
- 1:54 PM Changeset in webkit [199276] by
-
- 9 edits in trunk/Source
Unreviewed, rolling out r199242.
https://bugs.webkit.org/show_bug.cgi?id=156442
Caused many many leaks (Requested by ap on #webkit).
Reverted changeset:
"Web Inspector: get rid of InspectorBasicValue and
InspectorString subclasses"
https://bugs.webkit.org/show_bug.cgi?id=156407
http://trac.webkit.org/changeset/199242
- 1:41 PM Changeset in webkit [199275] by
-
- 5 edits in trunk/Source/JavaScriptCore
Debug JSC test failure: stress/multi-put-by-offset-reallocation-butterfly-cse.js.ftl-no-cjit-small-pool
https://bugs.webkit.org/show_bug.cgi?id=156406
Reviewed by Saam Barati.
The failure was because the GC ran from within the butterfly allocation call in a put_by_id
transition AccessCase that had to deal with indexing storage. When the GC runs in a call from a stub,
then we need to be extra careful:
1) The GC may reset the IC and delete the stub. So, the stub needs to tell the GC that it might be on
the stack during GC, so that the GC keeps it alive if it's currently running.
2) If the stub uses (dereferences or stores) some object after the call, then we need to ensure that
the stub routine knows about that object independently of the IC.
In the case of put_by_id transitions that use a helper to allocate the butterfly, we have both
issues. A long time ago, we had to deal with (2), and we still had code to handle that case, although
it appears to be dead. This change revives that code and glues it together with PolymorphicAccess.
- bytecode/PolymorphicAccess.cpp:
(JSC::AccessCase::alternateBase):
(JSC::AccessCase::doesCalls):
(JSC::AccessCase::couldStillSucceed):
(JSC::AccessCase::generate):
(JSC::PolymorphicAccess::regenerate):
- bytecode/PolymorphicAccess.h:
(JSC::AccessCase::customSlotBase):
(JSC::AccessCase::isGetter):
(JSC::AccessCase::doesCalls): Deleted.
- jit/GCAwareJITStubRoutine.cpp:
(JSC::GCAwareJITStubRoutine::markRequiredObjectsInternal):
(JSC::MarkingGCAwareJITStubRoutine::MarkingGCAwareJITStubRoutine):
(JSC::MarkingGCAwareJITStubRoutine::~MarkingGCAwareJITStubRoutine):
(JSC::MarkingGCAwareJITStubRoutine::markRequiredObjectsInternal):
(JSC::GCAwareJITStubRoutineWithExceptionHandler::GCAwareJITStubRoutineWithExceptionHandler):
(JSC::createJITStubRoutine):
(JSC::MarkingGCAwareJITStubRoutineWithOneObject::MarkingGCAwareJITStubRoutineWithOneObject): Deleted.
(JSC::MarkingGCAwareJITStubRoutineWithOneObject::~MarkingGCAwareJITStubRoutineWithOneObject): Deleted.
(JSC::MarkingGCAwareJITStubRoutineWithOneObject::markRequiredObjectsInternal): Deleted.
- jit/GCAwareJITStubRoutine.h:
(JSC::createJITStubRoutine):
- 1:13 PM Changeset in webkit [199274] by
-
- 13 edits in trunk
Unreviewed, rolling out r199268.
https://bugs.webkit.org/show_bug.cgi?id=156440
Broke Windows build (Requested by ap on #webkit).
Reverted changeset:
"Implement functional :host() pseudo class"
https://bugs.webkit.org/show_bug.cgi?id=156397
http://trac.webkit.org/changeset/199268
- 11:16 AM WebKitGTK/Gardening/Calendar edited by
- (diff)
- 11:16 AM Changeset in webkit [199273] by
-
- 2 edits in trunk/LayoutTests
[GTK] Update another GStreamer test expectation
Unreviewed.
- platform/gtk/TestExpectations:
- 11:11 AM Changeset in webkit [199272] by
-
- 2 edits in trunk/LayoutTests
[GTK] Update some more IndexedDB test expectations.
Unreviewed.
- platform/gtk/TestExpectations:
- 10:59 AM WebKitGTK/Gardening/Calendar edited by
- (diff)
- 10:58 AM Changeset in webkit [199271] by
-
- 2 edits in trunk/LayoutTests
[GTK] Remove failure expectation from storage/indexeddb/connection-leak.html
It's skipped in the global TestExpectations, see bug #152643.
- platform/gtk/TestExpectations:
- 10:45 AM WebKitGTK/Gardening/Calendar edited by
- (diff)
- 10:38 AM WebKitGTK/Gardening/Calendar edited by
- (diff)
- 10:37 AM WebKitGTK/Gardening/Calendar edited by
- (diff)
- 10:29 AM Changeset in webkit [199270] by
-
- 2 edits in trunk/LayoutTests
[GTK] Gardening unexpected passes and IndexedDB tests.
Unreviewed gardening.
- platform/gtk/TestExpectations:
- 12:40 AM Changeset in webkit [199269] by
-
- 2 edits in trunk/Websites/perf.webkit.org
Build fix. Don't treat a build number 0 as a pending build.
- tools/js/buildbot-syncer.js:
(BuildbotBuildEntry.prototype.isPending):
- 12:38 AM Changeset in webkit [199268] by
-
- 13 edits in trunk
Implement functional :host() pseudo class
https://bugs.webkit.org/show_bug.cgi?id=156397
<rdar://problem/25621445>
Reviewed by Darin Adler.
Source/WebCore:
We already support :host. Add functional syntax too.
- css/CSSGrammar.y.in:
Parse functional :host().
- css/CSSParser.cpp:
(WebCore::CSSParser::detectFunctionTypeToken):
- css/CSSParserValues.cpp:
(WebCore::CSSParserSelector::parsePseudoClassHostFunctionSelector):
- css/CSSParserValues.h:
- css/ElementRuleCollector.cpp:
(WebCore::ElementRuleCollector::matchedRuleList):
(WebCore::ElementRuleCollector::addMatchedRule):
Factor some shared code here.
(WebCore::ElementRuleCollector::matchHostPseudoClassRules):
Instead of using the generic paths use a :host specific code path for matching.
This makes it easier to avoid :host matching when it shouldn't.
(WebCore::ElementRuleCollector::collectMatchingRulesForList):
- css/ElementRuleCollector.h:
- css/RuleSet.cpp:
(WebCore::computeMatchBasedOnRuleHash):
:host is always handled by the special matching path.
- css/SelectorChecker.cpp:
(WebCore::SelectorChecker::match):
(WebCore::SelectorChecker::matchHostPseudoClass):
Add a function specifically for checking :host. In always fails on the normal code paths.
Check the argument selector if provided.
(WebCore::hasScrollbarPseudoElement):
- css/SelectorChecker.h:
LayoutTests:
Enable, fix and expand the test.
- fast/shadow-dom/css-scoping-shadow-host-functional-rule.html:
- platform/mac/TestExpectations:
Apr 8, 2016:
- 10:16 PM Changeset in webkit [199267] by
-
- 2 edits in trunk/PerformanceTests
Have Animometer benchmark always start with complexity of 1
https://bugs.webkit.org/show_bug.cgi?id=156432
Reviewed by Ryosuke Niwa.
- Animometer/tests/resources/main.js: Update the default Controller and RampController to
set its minimum complexities to 1 instead of 0.
- 9:56 PM Changeset in webkit [199266] by
-
- 7 edits in trunk/Websites/perf.webkit.org
Escape builder names in url* and pathFor* methods of BuildbotSyncer
https://bugs.webkit.org/show_bug.cgi?id=156427
Reviewed by Darin Adler.
The build fix in r199251 breaks other usage of RemoteAPI. Fix it properly by escaping builder names in
various methods of BuildbotSyncer.
Also fixed a typo in the logging and a bug that the new syncing script never updated "scheduled" to "running".
- server-tests/resources/mock-data.js:
(MockData.mockTestSyncConfigWithTwoBuilders): Renamed "some-builder-2" to "some builder 2" to test the
new escaping behavior in tools-buildbot-triggerable-tests.js and buildbot-syncer-tests.js.
- server-tests/tools-buildbot-triggerable-tests.js: Added tests for status url, and added a new test case
for updating "scheduled" to "running".
- tools/js/buildbot-syncer.js:
(BuildbotBuildEntry.buildRequestStatusIfUpdateIsNeeded): Update the status to "running" when the request's
status is "scheduled" and the buildbot's build is currently in progress.
(BuildbotSyncer.prototype.pathForPendingBuildsJSON): Escape the builder name.
(BuildbotSyncer.prototype.pathForBuildJSON): Ditto.
(BuildbotSyncer.prototype.pathForForceBuild): Ditto.
(BuildbotSyncer.prototype.url): Ditto.
(BuildbotSyncer.prototype.urlForBuildNumber): Ditto.
- tools/js/buildbot-triggerable.js:
(BuildbotTriggerable.prototype._pullBuildbotOnAllSyncers):
(BuildbotTriggerable.prototype._scheduleNextRequestInGroupIfSlaveIsAvailable): Fixed a typo. We are
scheduling new build requests, not syncing them.
- tools/js/remote.js:
(RemoteAPI.sendHttpRequest): Reverted r199251.
- unit-tests/buildbot-syncer-tests.js:
- 8:46 PM Changeset in webkit [199265] by
-
- 28 edits in trunk
Improve IDL support for object arguments that are neither optional nor nullable
https://bugs.webkit.org/show_bug.cgi?id=156149
Reviewed by Chris Dumez.
Source/WebCore:
After this patch, we are almost ready to change some more DOM functions to
use references instead of pointers. Remaining blocking issue is lack of support
for ShouldPassWrapperByReference in the gobject bindings.
- bindings/objc/ExceptionHandlers.h: Add NO_RETURN to raiseDOMException.
Added a new raiseTypeErrorException. Re-indented header and removed unneeded
include and forward declarations.
- bindings/objc/ExceptionHandlers.mm:
(WebCore::raiseDOMException): Added RELEASE_ASSERT_NOT_REACHED so the compiler
will understand this is NO_RETURN. Also updated FIXME comment.
(WebCore::raiseTypeErrorException): Added.
- bindings/scripts/CodeGenerator.pm: Removed unneeded code that allows the type
"AtomicString" in IDL files.
(ShouldPassWrapperByReference): Added. Contains the logic from the function in
the JavaScript code generator that was named IsPointerParameterPassedByReference,
minus a couple checks that are unneeded. For use in other code generators so they
are all consistent about how they call the DOM implementation.
- bindings/scripts/CodeGeneratorGObject.pm:
(SkipFunction): Removed support for unused CustomBinding extended attribute.
- bindings/scripts/CodeGeneratorJS.pm:
(GenerateHeader): Removed support for unused CustomBinding extended attribute.
(GenerateImplementation): Ditto. Also changed type checking code to throw a
type error in a more efficient way, using throwVMTypeError directly.
(GenerateParametersCheck): Rearranged code a bit so that arguments that need to
be passed in unusual ways are handled all in one place. Use WTFMove for newly
created NodeFilter objects. Simplified the reference logic so it doesn't need
to do an additional check to see if a type is a callback. Also changed type
checking code to throw a type error in a more efficient way, using throwVMTypeError
directly. Also corrected mistake where null checking code was throwing
TYPE_MISMATCH_ERR instead of a type error.
(GetNativeType): Coding style tweak.
(ShouldPassWrapperByReference): Renamed from IsPointerParameterPassedByReference.
Changed to call underlying ShouldPassWrapperByReference function in the language-
independent code generator.
(GenerateConstructorDefinition): Updated for name change.
- bindings/scripts/CodeGeneratorObjC.pm:
(SkipFunction): Removed support for unused CustomBinding extended attribute.
(GenerateImplementation): Added code to null check and pass a reference when
ShouldPassWrapperByReference returns true.
- bindings/scripts/IDLAttributes.txt: Sorted in the AppleCopyright and
UsePointersEvenForNonNullableObjectArguments arguments. Removed the unused
CPPPureInterface and CustomBinding attributes.
- bindings/scripts/test/JS/JSTestActiveDOMObject.cpp: Regenerated test results.
- bindings/scripts/test/JS/JSTestInterface.cpp: Ditto.
- bindings/scripts/test/JS/JSTestMediaQueryListListener.cpp: Ditto.
- bindings/scripts/test/JS/JSTestObj.cpp: Ditto.
- bindings/scripts/test/JS/JSTestObj.h: Ditto.
- bindings/scripts/test/JS/JSTestOverloadedConstructors.cpp: Ditto.
- bindings/scripts/test/JS/JSTestTypedefs.cpp: Ditto.
- bindings/scripts/test/ObjC/DOMTestActiveDOMObject.mm: Ditto.
- bindings/scripts/test/ObjC/DOMTestCallback.mm: Ditto.
- bindings/scripts/test/ObjC/DOMTestCallbackFunction.mm: Ditto.
- bindings/scripts/test/ObjC/DOMTestInterface.mm: Ditto.
- bindings/scripts/test/ObjC/DOMTestMediaQueryListListener.mm: Ditto.
- bindings/scripts/test/ObjC/DOMTestObj.mm: Ditto.
- bindings/scripts/test/TestObj.idl: Removed test for CustomBinding.
- dom/DOMImplementation.idl: Fixed #if so that only the return type is different
between JavaScript and the other bindings. Without this change, the different
bindings got different results for ShouldPassWrapperByReference. Also formatted
functions all on a single line.
- dom/EventListener.idl: Removed CPPPureInterface, since it had no effect.
- dom/EventTarget.idl: Ditto.
LayoutTests:
- fast/canvas/canvas-path-addPath-expected.txt: Updated expected result to expect
TypeError rather than TYPE_MISMATCH_ERR. A progression.
- fast/text/font-face-set-javascript-expected.txt: Ditto.
- 8:07 PM Changeset in webkit [199264] by
-
- 32 edits in trunk/Source/WebCore
[WebIDL] Add support for [ExportMacro=XXX] IDL extended attribute
https://bugs.webkit.org/show_bug.cgi?id=156428
Reviewed by Ryosuke Niwa.
Add support for [ExportMacro=XXX] IDL extended attribute (e.g. [ExportMacro=WEBCORE_EXPORT])
so developers can indicate in the IDL which macro to use to export the generated JS bindings
class.
We previously supported this by hard-coding JS class names in the bindings generator which
was ugly.
- Modules/mediasession/MediaSession.idl:
- Modules/mediasource/SourceBuffer.idl:
- Modules/notifications/Notification.idl:
- Modules/webaudio/AudioContext.idl:
- bindings/scripts/CodeGeneratorJS.pm:
(GetExportMacroForJSClass):
(GenerateHeader):
(AddIncludesForType): Deleted.
(AddToImplIncludes): Deleted.
- bindings/scripts/IDLAttributes.txt:
- bindings/scripts/test/TestInterface.idl:
- bindings/scripts/test/TestNode.idl:
- css/CSSStyleDeclaration.idl:
- dom/ClientRect.idl:
- dom/ClientRectList.idl:
- dom/Document.idl:
- dom/Element.idl:
- dom/Node.idl:
- dom/Range.idl:
- fileapi/File.idl:
- html/DOMURL.idl:
- html/HTMLElement.idl:
- html/HTMLMediaElement.idl:
- html/TimeRanges.idl:
- html/canvas/DOMPath.idl:
- inspector/ScriptProfile.idl:
- inspector/ScriptProfileNode.idl:
- page/DOMWindow.idl:
- page/make_settings.pl:
(generateInternalSettingsIdlFile):
- testing/InternalSettings.idl:
- testing/Internals.idl:
- testing/MallocStatistics.idl:
- testing/MemoryInfo.idl:
- testing/TypeConversions.idl:
- xml/XMLHttpRequest.idl:
- 7:37 PM Changeset in webkit [199263] by
-
- 12 edits6 adds in trunk
Web Inspector: XHRs and Web Worker scripts are not searchable
https://bugs.webkit.org/show_bug.cgi?id=154214
<rdar://problem/24643587>
Patch by Joseph Pecoraro <Joseph Pecoraro> on 2016-04-08
Reviewed by Timothy Hatcher.
Source/JavaScriptCore:
- inspector/protocol/Page.json:
Add optional requestId to search results properties and search
parameters for when the frameId and url are not enough. XHR
resources, and "Other" resources will use this.
Source/WebCore:
Test: inspector/page/searchInResources.html
- inspector/InspectorPageAgent.h:
- inspector/InspectorPageAgent.cpp:
(WebCore::InspectorPageAgent::searchInResource):
(WebCore::InspectorPageAgent::searchInResources):
Let the NetworkAgent handle individual search requests
with a requestId. And provide global search results for
"other" resources and will include requestId properties.
- inspector/InspectorNetworkAgent.h:
- inspector/InspectorNetworkAgent.cpp:
(WebCore::InspectorNetworkAgent::didFinishXHRLoading):
(WebCore::buildObjectForSearchResult):
(WebCore::InspectorNetworkAgent::searchOtherRequests):
(WebCore::InspectorNetworkAgent::searchInRequest):
Search saved "other" resource data content.
- inspector/NetworkResourcesData.h:
- inspector/NetworkResourcesData.cpp:
(WebCore::NetworkResourcesData::resources):
Expose the resources for iteration by the NetworkAgent.
Source/WebInspectorUI:
- UserInterface/Views/SearchSidebarPanel.js:
(WebInspector.SearchSidebarPanel.prototype.performSearch.resourceCallback):
(WebInspector.SearchSidebarPanel.prototype.performSearch.resourcesCallback):
Carry forward the requestId property if it is available.
LayoutTests:
- inspector/page/resources/search-script.js: Added.
- inspector/page/resources/search-stylesheet.css: Added.
- inspector/page/resources/search-worker.js: Added.
- inspector/page/resources/search-xhr.txt: Added.
- inspector/page/searchInResources-expected.txt: Added.
- inspector/page/searchInResources.html: Added.
Test for the Page domain's search commands.
- 7:32 PM Changeset in webkit [199262] by
-
- 5 edits in trunk/Source/WebInspectorUI
Web Inspector: Allocation snapshot hover persists after switching tabs
https://bugs.webkit.org/show_bug.cgi?id=156430
<rdar://problem/25633800>
Patch by Joseph Pecoraro <Joseph Pecoraro> on 2016-04-08
Reviewed by Timothy Hatcher.
- UserInterface/Views/HeapSnapshotInstanceDataGridNode.js:
(WebInspector.HeapSnapshotInstanceDataGridNode.prototype._mouseoverHandler):
Don't show the popover if the tree is no longer visible.
- UserInterface/Views/HeapSnapshotInstancesContentView.js:
(WebInspector.HeapSnapshotInstancesContentView.prototype.shown):
- UserInterface/Views/HeapSnapshotInstancesDataGridTree.js:
(WebInspector.HeapSnapshotInstancesDataGridTree):
(WebInspector.HeapSnapshotInstancesDataGridTree.prototype.get visible):
(WebInspector.HeapSnapshotInstancesDataGridTree.prototype.shown):
(WebInspector.HeapSnapshotInstancesDataGridTree.prototype.hidden):
Give the tree a visible state and have its containing ContentView
update it with normal ContentView shown/hidden.
- UserInterface/Views/Popover.js:
We are presenting while we were dismissing, so completely clear the
dismissing state.
- 6:20 PM Changeset in webkit [199261] by
-
- 2 edits in trunk/Source/JavaScriptCore
MIPS: support Signed cond in branchTest32()
https://bugs.webkit.org/show_bug.cgi?id=156260
This is needed since r197688 makes use of it.
Patch by Guillaume Emont <guijemont@igalia.com> on 2016-04-08
Reviewed by Mark Lam.
- assembler/MacroAssemblerMIPS.h:
(JSC::MacroAssemblerMIPS::branchTest32):
- 6:19 PM Changeset in webkit [199260] by
-
- 15 edits in trunk
AX: "AXLandmarkApplication" is an inappropriate subrole for ARIA "application" since it's no longer a landmark
https://bugs.webkit.org/show_bug.cgi?id=155403
Reviewed by Chris Fleizach.
The new subrole is AXWebApplication and the new role description is "web application".
As part of the fix, the WebCore AccessibilityRole for ARIA's "application" role was
renamed from LandmarkApplicationRole to WebApplicationRole.
The roles-exposed.html and aria-grouping-roles.html test expectations were also updated.
Source/WebCore:
- English.lproj/Localizable.strings:
- accessibility/AccessibilityObject.cpp:
(WebCore::AccessibilityObject::accessibleNameDerivesFromContent):
(WebCore::AccessibilityObject::isLandmark):
(WebCore::initializeRoleMap):
- accessibility/AccessibilityObject.h:
- accessibility/atk/WebKitAccessibleWrapperAtk.cpp:
(atkRole):
- accessibility/ios/WebAccessibilityObjectWrapperIOS.mm:
(-[WebAccessibilityObjectWrapper determineIsAccessibilityElement]):
(-[WebAccessibilityObjectWrapper _accessibilityIsLandmarkRole:]):
- accessibility/mac/WebAccessibilityObjectWrapperBase.mm:
(-[WebAccessibilityObjectWrapperBase ariaLandmarkRoleDescription]):
- accessibility/mac/WebAccessibilityObjectWrapperMac.mm:
(createAccessibilityRoleMap):
(-[WebAccessibilityObjectWrapper subrole]):
- platform/LocalizedStrings.cpp:
(WebCore::AXARIAContentGroupText):
Source/WebKit/win:
- AccessibleBase.cpp: Update the rolename
(MSAARole):
LayoutTests:
- accessibility/mac/aria-grouping-roles-expected.txt:
- accessibility/mac/aria-grouping-roles.html:
- platform/mac/accessibility/roles-exposed-expected.txt:
- 6:18 PM Changeset in webkit [199259] by
-
- 16 edits in trunk/Source
[iOS WK2] WKWebViews should consult ancestor UIScrollViews to determine tiling area
https://bugs.webkit.org/show_bug.cgi?id=156429
rdar://problem/25455111
Reviewed by Tim Horton.
When a WKWebView is expanded to full size, then embedded in UIScrollView, it would
create huge tiles that cover the entire view area (since it considered itself non-scrollable).
Fix to always use 512x512 tiles in this configuration, and to adjust the tile coverage
for the area exposed through the enclosing UIScrollView.
Source/WebCore:
- loader/HistoryController.cpp:
(WebCore::HistoryController::saveScrollPositionAndViewStateToItem): setObscuredInset()
moved from FrameView to Page.
- page/FrameView.cpp:
(WebCore::FrameView::adjustTiledBackingScrollability): If we're clipped by an ancestor scrollView,
just assume we're scrollable on both axes.
- page/Page.h:
(WebCore::Page::obscuredInset):
(WebCore::Page::setObscuredInset):
(WebCore::Page::enclosedInScrollView):
(WebCore::Page::setEnclosedInScrollView):
- platform/ScrollView.h:
(WebCore::ScrollView::platformObscuredInset): Deleted.
(WebCore::ScrollView::platformSetObscuredInset): Deleted.
Source/WebKit2:
- Shared/VisibleContentRectUpdateInfo.cpp: Add enclosedInScrollView(), which is used to
trigger normal-sized tiles.
(WebKit::VisibleContentRectUpdateInfo::encode):
(WebKit::VisibleContentRectUpdateInfo::decode):
- Shared/VisibleContentRectUpdateInfo.h:
(WebKit::VisibleContentRectUpdateInfo::VisibleContentRectUpdateInfo):
(WebKit::VisibleContentRectUpdateInfo::enclosedInScrollView):
(WebKit::operator==):
- UIProcess/API/Cocoa/WKWebView.mm:
(-[WKWebView _didInvokeUIScrollViewDelegateCallback]): Pass our scrollView.
(-[WKWebView _didFinishScrolling]):
(-[WKWebView scrollViewDidScroll:]):
(-[WKWebView scrollViewDidZoom:]):
(-[WKWebView scrollViewDidEndZooming:withView:atScale:]):
(-[WKWebView _scrollViewDidInterruptDecelerating:]):
(-[WKWebView _visibleRectInEnclosingScrollView:]):
(-[WKWebView _visibleContentRect]): Compute the exposed part of the content relative
to the WKWebView, then intersect with the exposed part via any ancestor UIScrollView.
(-[WKWebView _didScroll]): This is called by UIKit when some ancestor UIScrollView scrolls.
However, we don't get all the UIScrollView delegate callbacks, so have to use a timer to
trigger a call to -_updateVisibleContentRects when we're in a stable state.
(-[WKWebView _enclosingScrollerScrollingEnded:]):
(-[WKWebView _frameOrBoundsChanged]):
(-[WKWebView _updateVisibleContentRects]):
(-[WKWebView _updateVisibleContentRectAfterScrollInView:]): Get the stable state from the
scroll view that the user is interacting with.
(-[WKWebView _updateContentRectsWithState:]):
- UIProcess/API/Cocoa/WKWebViewInternal.h:
- UIProcess/WebPageProxy.h: Rather than pass a bazillion arguments through updateVisibleContentRects(), just
pass the VisibleContentRectUpdateInfo struct.
- UIProcess/ios/WKContentView.h:
- UIProcess/ios/WKContentView.mm:
(-[WKContentView didUpdateVisibleRect:unobscuredRect:unobscuredRectInScrollViewCoordinates:obscuredInset:scale:minimumScale:inStableState:isChangingObscuredInsetsInteractively:enclosedInScrollView:]):
(-[WKContentView didUpdateVisibleRect:unobscuredRect:unobscuredRectInScrollViewCoordinates:obscuredInset:scale:minimumScale:inStableState:isChangingObscuredInsetsInteractively:]): Deleted.
- UIProcess/ios/WebPageProxyIOS.mm:
(WebKit::WebPageProxy::updateVisibleContentRects):
- UIProcess/mac/RemoteLayerTreeDrawingAreaProxy.mm:
(WebKit::RemoteLayerTreeDrawingAreaProxy::RemoteLayerTreeDrawingAreaProxy):
(WebKit::RemoteLayerTreeDrawingAreaProxy::indicatorLocation):
- WebProcess/WebPage/WebPage.cpp:
(WebKit::WebPage::updatePreferences):
- WebProcess/WebPage/ios/WebPageIOS.mm:
(WebKit::WebPage::updateVisibleContentRects):
- 5:42 PM Changeset in webkit [199258] by
-
- 4 edits in trunk/Source
[iOS Simulator] Build failure (property 'contentsFormat' not found on object of type 'LegacyTileLayer *')
https://bugs.webkit.org/show_bug.cgi?id=156415
Patch by Joseph Pecoraro <Joseph Pecoraro> on 2016-04-08
Reviewed by Simon Fraser.
Source/WebCore:
- platform/spi/cocoa/QuartzCoreSPI.h:
Provide SPI forward declaration of the CALayer contentsFormat property.
Source/WebKit2:
- UIProcess/API/Cocoa/_WKElementAction.mm:
(-[_WKElementAction runActionWithElementInfo:]):
Use WeakObjCPtr instead of weak to avoid build errors when not under ARC.
- 5:36 PM Changeset in webkit [199257] by
-
- 19 edits in trunk
Progress towards running CMake WebKit2 on Mac
https://bugs.webkit.org/show_bug.cgi?id=156426
Reviewed by Tim Horton.
.:
- Source/cmake/OptionsMac.cmake:
FTL works on Mac, so let's use it.
- Source/cmake/WebKitMacros.cmake:
Source/JavaScriptCore:
- PlatformMac.cmake:
Source/WebCore:
- CMakeLists.txt:
- PlatformGTK.cmake:
- PlatformMac.cmake:
- PlatformWin.cmake:
On Mac, WTF is a static library that is linked only with JavaScriptCore.
Source/WebKit:
- CMakeLists.txt:
- PlatformMac.cmake:
- PlatformWin.cmake:
Source/WebKit2:
- CMakeLists.txt:
- PlatformMac.cmake:
Put the xpc service binaries in the right place.
Source/WTF:
- wtf/PlatformMac.cmake:
- 5:33 PM Changeset in webkit [199256] by
-
- 3 edits in trunk/Source/WebKit2
Build fix with IndexedDB disabled but DatabaseProcess enabled after r199230
https://bugs.webkit.org/show_bug.cgi?id=156321
Rubber-stamped by Brady Eidson.
- DatabaseProcess/DatabaseProcess.cpp:
(WebKit::DatabaseProcess::deleteWebsiteDataForOrigins):
(WebKit::DatabaseProcess::grantSandboxExtensionsForBlobs):
(WebKit::DatabaseProcess::accessToTemporaryFileComplete):
(WebKit::DatabaseProcess::indexedDatabaseOrigins):
- DatabaseProcess/DatabaseProcess.h:
Add some more guards.
- 4:01 PM Changeset in webkit [199255] by
-
- 2 edits in branches/safari-601.1.46-branch/Source/WebCore
Merged r199253. rdar://problem/25533763
- 3:59 PM Changeset in webkit [199254] by
-
- 2 edits in branches/safari-601.1.46-branch/Source/WebCore
Merged r199252. rdar://problem/25533763
- 3:54 PM Changeset in webkit [199253] by
-
- 2 edits in trunk/Source/WebCore
Unreviewed 32-bit build fix; make type of std::min<> explicit.
- platform/audio/ios/AudioDestinationIOS.cpp:
(WebCore::AudioDestinationIOS::render):
- 3:41 PM Changeset in webkit [199252] by
-
- 2 edits in trunk/Source/WebCore
CRASH in AudioDestinationNode::render()
https://bugs.webkit.org/show_bug.cgi?id=156308
Reviewed by Eric Carlson.
Yet another math error in AudioDestinationIOS::render(). It is possible for the difference between
m_startSpareFrame and m_endSpareFrame to be greater than the numberOfFrames to be rendered. Protect
against this case by taking the min() of those two values and only advancing m_startSpareFrame by
that amount. This guarantees that framesThisTime will never underflow, and that data will not be
written past the end of the ioData parameter.
- platform/audio/ios/AudioDestinationIOS.cpp:
(WebCore::AudioDestinationIOS::render):
- 3:37 PM Changeset in webkit [199251] by
-
- 2 edits in trunk/Websites/perf.webkit.org
Build fix. We need to escape the path or http.request would fail.
- tools/js/remote.js:
- 3:01 PM Changeset in webkit [199250] by
-
- 12 edits in trunk/Source/WebCore
Modern IDB: Use more IDBValue and IDBGetResult in IDBBackingStore.
https://bugs.webkit.org/show_bug.cgi?id=156418
Reviewed by Alex Christensen.
No new tests (Refactor, no change in behavior).
- Modules/indexeddb/IDBValue.cpp:
(WebCore::IDBValue::IDBValue):
- Modules/indexeddb/IDBValue.h:
- Modules/indexeddb/server/IDBBackingStore.h:
- Modules/indexeddb/server/MemoryBackingStoreTransaction.cpp:
(WebCore::IDBServer::MemoryBackingStoreTransaction::abort):
- Modules/indexeddb/server/MemoryIDBBackingStore.cpp:
(WebCore::IDBServer::MemoryIDBBackingStore::addRecord):
(WebCore::IDBServer::MemoryIDBBackingStore::getRecord):
- Modules/indexeddb/server/MemoryIDBBackingStore.h:
- Modules/indexeddb/server/MemoryObjectStore.cpp:
(WebCore::IDBServer::MemoryObjectStore::addRecord):
- Modules/indexeddb/server/MemoryObjectStore.h:
- Modules/indexeddb/server/SQLiteIDBBackingStore.cpp:
(WebCore::IDBServer::SQLiteIDBBackingStore::addRecord):
(WebCore::IDBServer::SQLiteIDBBackingStore::getRecord):
- Modules/indexeddb/server/SQLiteIDBBackingStore.h:
- Modules/indexeddb/server/UniqueIDBDatabase.cpp:
(WebCore::IDBServer::UniqueIDBDatabase::performPutOrAdd):
(WebCore::IDBServer::UniqueIDBDatabase::performGetRecord):
- 2:21 PM Changeset in webkit [199249] by
-
- 2 edits in trunk/Source/JavaScriptCore
Debugger may dereference m_currentCallFrame even after the VM has gone idle
https://bugs.webkit.org/show_bug.cgi?id=156413
Reviewed by Mark Lam.
There is a bug where the debugger may dereference its m_currentCallFrame
pointer after that pointer becomes invalid to read from. This happens like so:
We may step over an instruction which causes the end of execution for the
current program. This causes the VM to exit. Then, we perform a GC which
causes us to collect the global object. The global object being collected
causes us to detach the debugger. In detaching, we think we still have a
valid m_currentCallFrame, we dereference it, and crash. The solution is to
make sure we're paused when dereferencing this pointer inside ::detach().
- debugger/Debugger.cpp:
(JSC::Debugger::detach):
- 2:11 PM Changeset in webkit [199248] by
-
- 8 edits in trunk/Source/WebCore
Modern IDB: Make IDBGetResult contain an IDBValue instead of a buffer, and remove unused methods.
https://bugs.webkit.org/show_bug.cgi?id=156416
Reviewed by Alex Christensen.
No new tests (Refactor, no change in behavior).
- Modules/indexeddb/IDBCursor.cpp:
(WebCore::IDBCursor::setGetResult):
- Modules/indexeddb/IDBGetResult.cpp:
(WebCore::IDBGetResult::dataFromBuffer):
(WebCore::IDBGetResult::isolatedCopy):
- Modules/indexeddb/IDBGetResult.h:
(WebCore::IDBGetResult::IDBGetResult):
(WebCore::IDBGetResult::value):
(WebCore::IDBGetResult::encode):
(WebCore::IDBGetResult::decode):
(WebCore::IDBGetResult::valueBuffer): Deleted.
(WebCore::IDBGetResult::setValueBuffer): Deleted.
(WebCore::IDBGetResult::setKeyData): Deleted.
(WebCore::IDBGetResult::setPrimaryKeyData): Deleted.
(WebCore::IDBGetResult::setKeyPath): Deleted.
- Modules/indexeddb/IDBTransaction.cpp:
(WebCore::IDBTransaction::didGetRecordOnServer):
- Modules/indexeddb/IDBValue.cpp:
(WebCore::IDBValue::IDBValue):
- Modules/indexeddb/IDBValue.h:
- Modules/indexeddb/server/SQLiteIDBBackingStore.cpp:
(WebCore::IDBServer::SQLiteIDBBackingStore::getIndexRecord):
- 2:01 PM Changeset in webkit [199247] by
-
- 10 edits6 adds in trunk
Focus ring drawn at incorrect location on image map with CSS transform.
https://bugs.webkit.org/show_bug.cgi?id=143527
<rdar://problem/21908735>
Reviewed by Simon Fraser.
Source/WebCore:
Implement pathForFocusRing for HTMLAreaElement. It follows the logic of RenderObject::addFocusRingRects().
Tests: fast/images/image-map-outline-in-positioned-container.html
fast/images/image-map-outline-with-paint-root-offset.html
fast/images/image-map-outline-with-scale-transform.html
fast/images/image-map-outline.html
- html/HTMLAreaElement.cpp:
(WebCore::HTMLAreaElement::pathForFocusRing):
- html/HTMLAreaElement.h:
- rendering/RenderElement.cpp:
(WebCore::RenderElement::paintFocusRing): Move addFocusRingRects() out of focus ring painting.
(WebCore::RenderElement::paintOutline):
- rendering/RenderElement.h:
- rendering/RenderImage.cpp:
(WebCore::RenderImage::paint):
(WebCore::RenderImage::paintAreaElementFocusRing):
- rendering/RenderImage.h:
- rendering/RenderInline.cpp:
(WebCore::RenderInline::paintOutline):
LayoutTests:
Implement pathForFocusRing for HTMLAreaElement.
- fast/images/image-map-outline-in-positioned-container-expected.html: Added.
- fast/images/image-map-outline-in-positioned-container.html: Added.
- fast/images/image-map-outline-with-paint-root-offset-expected.html: Added.
- fast/images/image-map-outline-with-paint-root-offset.html: Added.
- fast/images/image-map-outline-with-scale-transform-expected.html: Added.
- fast/images/image-map-outline-with-scale-transform.html: Added.
- 1:59 PM Changeset in webkit [199246] by
-
- 3 edits in trunk/Source/bmalloc
bmalloc: stress_aligned test fails if you increase smallMax
https://bugs.webkit.org/show_bug.cgi?id=156414
Reviewed by Oliver Hunt.
When size exceeds alignment and is a multiple of alignment and is not
a power of two, such as 24kB with 8kB alignment, the small allocator
did not always guarantee alignment. Let's fix that.
- bmalloc/Algorithm.h:
(bmalloc::divideRoundingUp): Math is hard.
- bmalloc/Allocator.cpp:
(bmalloc::Allocator::allocate): Align to the page size unconditionally.
Even if the page size is not a power of two, it might be a multiple of
a power of two, and we want alignment to that smaller power of two to
be guaranteed.
- 1:46 PM Changeset in webkit [199245] by
-
- 2 edits in trunk/Source/WebCore
[WK1] Wheel event callback removing the window causes crash in WebCore
https://bugs.webkit.org/show_bug.cgi?id=156409
<rdar://problem/25631267>
Reviewed by Simon Fraser.
Null check the Widget before using it, since the iframe may have been removed
from its parent document inside the event handler.
This is the WK1 fix for https://bugs.webkit.org/show_bug.cgi?id=150871.
Tested by fast/events/wheel-event-destroys-frame.html
- page/EventHandler.cpp:
(WebCore::widgetForElement): Added.
(WebCore::EventHandler::handleWheelEvent): Use new helper function to
clean up the code, and allow us to check that the Widget has not been
destroyed during the event handler.
- 1:19 PM Changeset in webkit [199244] by
-
- 5 edits in trunk/PerformanceTests
Fix SVG benchmark test
https://bugs.webkit.org/show_bug.cgi?id=156410
Reviewed by Dean Jackson.
- Animometer/resources/extensions.js: Update Point.zero to be a static Point.
- Animometer/tests/simple/resources/tiled-canvas-image.js:
(Stage.call._setupTiles): Refactor.
- Animometer/tests/master/resources/particles.js:
(Particle.prototype.reset): Use Point.center.
(complexity): We are not using a gradient background anymore, so remove the +1.
- Animometer/tests/master/resources/svg-particles.js: Update to use SVG transform
instead of CSS transform.
- 1:07 PM Changeset in webkit [199243] by
-
- 2 edits in trunk/Source/WebCore
Timing attack on SVG feComposite filter circumvents same-origin policy
https://bugs.webkit.org/show_bug.cgi?id=154338
Patch by Said Abou-Hallawa <sabouhallawa@apple,com> on 2016-04-08
Reviewed by Oliver Hunt.
Ensure the FEComposite arithmetic filter is clamping the resulted color
components in a constant time.
- platform/graphics/filters/FEComposite.cpp:
(WebCore::clampByte):
(WebCore::computeArithmeticPixels):
- 12:59 PM Changeset in webkit [199242] by
-
- 9 edits in trunk/Source
Web Inspector: get rid of InspectorBasicValue and InspectorString subclasses
https://bugs.webkit.org/show_bug.cgi?id=156407
<rdar://problem/25627659>
Reviewed by Timothy Hatcher.
Source/JavaScriptCore:
There's no point having these subclasses as they don't save any space.
Add m_stringValue to the union and merge some implementations of writeJSON.
Move uses of the subclass to InspectorValue and delete redundant methods.
Now, most InspectorValue methods are non-virtual so they can be templated.
- bindings/ScriptValue.cpp:
(Deprecated::jsToInspectorValue):
- inspector/InjectedScriptBase.cpp:
(Inspector::InjectedScriptBase::makeCall):
Don't used deleted subclasses.
- inspector/InspectorValues.cpp:
(Inspector::InspectorValue::null):
(Inspector::InspectorValue::create):
(Inspector::InspectorValue::asValue):
(Inspector::InspectorValue::asBoolean):
(Inspector::InspectorValue::asDouble):
(Inspector::InspectorValue::asInteger):
(Inspector::InspectorValue::asString):
These only need one implementation now.
(Inspector::InspectorValue::writeJSON):
Still a virtual method since Object and Array need their members.
(Inspector::InspectorObjectBase::InspectorObjectBase):
(Inspector::InspectorBasicValue::asBoolean): Deleted.
(Inspector::InspectorBasicValue::asDouble): Deleted.
(Inspector::InspectorBasicValue::asInteger): Deleted.
(Inspector::InspectorBasicValue::writeJSON): Deleted.
(Inspector::InspectorString::asString): Deleted.
(Inspector::InspectorString::writeJSON): Deleted.
(Inspector::InspectorString::create): Deleted.
(Inspector::InspectorBasicValue::create): Deleted.
- inspector/InspectorValues.h:
(Inspector::InspectorObjectBase::setBoolean):
(Inspector::InspectorObjectBase::setInteger):
(Inspector::InspectorObjectBase::setDouble):
(Inspector::InspectorObjectBase::setString):
(Inspector::InspectorArrayBase::pushBoolean):
(Inspector::InspectorArrayBase::pushInteger):
(Inspector::InspectorArrayBase::pushDouble):
(Inspector::InspectorArrayBase::pushString):
Use new factory methods.
- replay/EncodedValue.cpp:
(JSC::ScalarEncodingTraits<bool>::encodeValue):
(JSC::ScalarEncodingTraits<double>::encodeValue):
(JSC::ScalarEncodingTraits<float>::encodeValue):
(JSC::ScalarEncodingTraits<int32_t>::encodeValue):
(JSC::ScalarEncodingTraits<int64_t>::encodeValue):
(JSC::ScalarEncodingTraits<uint32_t>::encodeValue):
(JSC::ScalarEncodingTraits<uint64_t>::encodeValue):
- replay/EncodedValue.h:
Use new factory methods.
Source/WebCore:
- inspector/InspectorDatabaseAgent.cpp: Don't use deleted subclasses.
- 12:40 PM Changeset in webkit [199241] by
-
- 3 edits in trunk/Source/WebInspectorUI
JSContext Inspector: Fix asserts and uncaught exception showing Timeline Tab
https://bugs.webkit.org/show_bug.cgi?id=156411
Patch by Joseph Pecoraro <Joseph Pecoraro> on 2016-04-08
Reviewed by Timothy Hatcher.
- UserInterface/Views/OverviewTimelineView.js:
(WebInspector.OverviewTimelineView):
(WebInspector.OverviewTimelineView.prototype.closed):
Gracefully handle if we do not have a Network Timeline.
- UserInterface/Views/TimelineTabContentView.js:
(WebInspector.TimelineTabContentView.prototype._changeViewMode):
This function is always called by the constructor, so the assert
is not useful since it can be called when FPS is not supported.
- 12:37 PM Changeset in webkit [199240] by
-
- 8 edits19 adds in trunk
Add IC support for arguments.length
https://bugs.webkit.org/show_bug.cgi?id=156389
Reviewed by Geoffrey Garen.
Source/JavaScriptCore:
This adds support for caching accesses to arguments.length for both DirectArguments and
ScopedArguments. In strict mode, we already cached these accesses since they were just
normal properties.
Amazingly, we also already supported caching of overridden arguments.length in both
DirectArguments and ScopedArguments. This is because when you override, the property gets
materialized as a normal JS property and the structure is changed.
This patch painstakingly preserves our previous caching of overridden length while
introducing caching of non-overridden length (i.e. the common case). In fact, we even cache
the case where it could either be overridden or not, since we just end up with an AccessCase
for each and they cascade to each other.
This is a >3x speed-up on microbenchmarks that do arguments.length in a polymorphic context.
Entirely monomorphic accesses were already handled by the DFG.
- bytecode/PolymorphicAccess.cpp:
(JSC::AccessGenerationState::calculateLiveRegistersForCallAndExceptionHandling):
(JSC::AccessCase::guardedByStructureCheck):
(JSC::AccessCase::generateWithGuard):
(JSC::AccessCase::generate):
(WTF::printInternal):
- bytecode/PolymorphicAccess.h:
- jit/ICStats.h:
- jit/JITOperations.cpp:
- jit/Repatch.cpp:
(JSC::tryCacheGetByID):
(JSC::tryCachePutByID):
(JSC::tryRepatchIn):
- tests/stress/direct-arguments-override-length-then-access-normal-length.js: Added.
(args):
(foo):
(result.foo):
LayoutTests:
- js/regress/direct-arguments-length-expected.txt: Added.
- js/regress/direct-arguments-length.html: Added.
- js/regress/direct-arguments-overridden-length-expected.txt: Added.
- js/regress/direct-arguments-overridden-length.html: Added.
- js/regress/direct-arguments-possibly-overridden-length-expected.txt: Added.
- js/regress/direct-arguments-possibly-overridden-length.html: Added.
- js/regress/scoped-arguments-length-expected.txt: Added.
- js/regress/scoped-arguments-length.html: Added.
- js/regress/scoped-arguments-overridden-length-expected.txt: Added.
- js/regress/scoped-arguments-overridden-length.html: Added.
- js/regress/scoped-arguments-possibly-overridden-length-expected.txt: Added.
- js/regress/scoped-arguments-possibly-overridden-length.html: Added.
- js/regress/script-tests/direct-arguments-length.js: Added.
(args):
- js/regress/script-tests/direct-arguments-overridden-length.js: Added.
(args):
- js/regress/script-tests/direct-arguments-possibly-overridden-length.js: Added.
(args1):
(args2):
- js/regress/script-tests/scoped-arguments-length.js: Added.
(args):
- js/regress/script-tests/scoped-arguments-overridden-length.js: Added.
(args):
- js/regress/script-tests/scoped-arguments-possibly-overridden-length.js: Added.
(args1):
(args2):
- 11:55 AM Changeset in webkit [199239] by
-
- 5 edits in branches/safari-601-branch/Source
Versioning.
- 11:32 AM Changeset in webkit [199238] by
-
- 2 edits in trunk/Source/WebCore
Fix leaks in WebAVMediaSelectionOptionMac and WebPlaybackControlsManager
https://bugs.webkit.org/show_bug.cgi?id=156379
Reviewed by Tim Horton.
These classes should use RetainPtrs.
- platform/mac/WebVideoFullscreenInterfaceMac.mm:
(-[WebAVMediaSelectionOptionMac localizedDisplayName]):
(-[WebAVMediaSelectionOptionMac setLocalizedDisplayName:]):
(-[WebPlaybackControlsManager timing]):
(-[WebPlaybackControlsManager setTiming:]):
(-[WebPlaybackControlsManager seekableTimeRanges]):
(-[WebPlaybackControlsManager setSeekableTimeRanges:]):
(-[WebPlaybackControlsManager audioMediaSelectionOptions]):
(-[WebPlaybackControlsManager setAudioMediaSelectionOptions:]):
(-[WebPlaybackControlsManager currentAudioMediaSelectionOption]):
(-[WebPlaybackControlsManager setCurrentAudioMediaSelectionOption:]):
(-[WebPlaybackControlsManager legibleMediaSelectionOptions]):
(-[WebPlaybackControlsManager setLegibleMediaSelectionOptions:]):
(-[WebPlaybackControlsManager currentLegibleMediaSelectionOption]):
(-[WebPlaybackControlsManager setCurrentLegibleMediaSelectionOption:]):
- 11:28 AM Changeset in webkit [199237] by
-
- 2 edits in trunk/Source/WebCore
Touching any IDL files rebuilds all bindings in CMake Ninja build
https://bugs.webkit.org/show_bug.cgi?id=156400
Patch by Fujii Hironori <Hironori.Fujii@jp.sony.com> on 2016-04-08
Reviewed by Brent Fulgham.
- bindings/scripts/preprocess-idls.pl:
(GenerateConstructorAttribute):
WriteFileIfChanged does not work due to flaky results of 'keys'.
Sort results of 'keys'.
- 11:18 AM Changeset in webkit [199236] by
-
- 3 edits in trunk/LayoutTests
Redefining a method of the same name hits an assertion
https://bugs.webkit.org/show_bug.cgi?id=144258
Reviewed by Ryosuke Niwa.
- TestExpectations:
- js/script-tests/class-syntax-semicolon.js:
This test no longer asserts.
- 11:07 AM Changeset in webkit [199235] by
-
- 6 edits1 add in trunk/Source/JavaScriptCore
UInt32ToNumber should have an Int52 path
https://bugs.webkit.org/show_bug.cgi?id=125704
Patch by Benjamin Poulain <bpoulain@apple.com> on 2016-04-08
Reviewed by Filip Pizlo.
When dealing with big numbers, fall back to Int52 instead
of double when possible.
- dfg/DFGAbstractInterpreterInlines.h:
(JSC::DFG::AbstractInterpreter<AbstractStateType>::executeEffects):
- dfg/DFGFixupPhase.cpp:
(JSC::DFG::FixupPhase::fixupNode):
- dfg/DFGPredictionPropagationPhase.cpp:
(JSC::DFG::PredictionPropagationPhase::propagate):
- dfg/DFGSpeculativeJIT.cpp:
(JSC::DFG::SpeculativeJIT::compileUInt32ToNumber):
- ftl/FTLLowerDFGToB3.cpp:
(JSC::FTL::DFG::LowerDFGToB3::compileUInt32ToNumber):
- 10:50 AM Changeset in webkit [199234] by
-
- 2 edits in trunk/Source/WebKit
[cmake] Use ICU include dirs in WebKit.
https://bugs.webkit.org/show_bug.cgi?id=156402
Patch by Konstantin Tokarev <Konstantin Tokarev> on 2016-04-08
Reviewed by Brent Fulgham.
- CMakeLists.txt:
- 10:22 AM Changeset in webkit [199233] by
-
- 19 edits in trunk/Source
[iOS WK2] Stop using exposedContentRect for history scroll state restoration
https://bugs.webkit.org/show_bug.cgi?id=156392
Reviewed by Tim Horton.
A future commit will alter the meaning of exposedContentRect on iOS to take into
account clipped out parts of the WKWebView. To achieve this, wean history restoration
off of using exposedContentRect for scroll state restoration. It did this to restore
the page to the same position relative to the view's top-left (to avoid jiggles caused
by changing obscured insets).
Do this by pushing the left/top obscured insets down with visible content rects updates,
storing them on ScrollView, and adding them to HistoryItem. Those insets are then used
for scroll state restoration in WKWebView.
Source/WebCore:
- history/HistoryItem.cpp:
(WebCore::HistoryItem::HistoryItem):
- history/HistoryItem.h:
(WebCore::HistoryItem::obscuredInset):
(WebCore::HistoryItem::setObscuredInset):
- loader/HistoryController.cpp:
(WebCore::HistoryController::saveScrollPositionAndViewStateToItem):
- platform/ScrollView.h:
(WebCore::ScrollView::platformObscuredInset):
(WebCore::ScrollView::platformSetObscuredInset):
Source/WebKit2:
- Shared/VisibleContentRectUpdateInfo.cpp: Add FloatSize for obscuredInset.
(WebKit::VisibleContentRectUpdateInfo::encode):
(WebKit::VisibleContentRectUpdateInfo::decode):
- Shared/VisibleContentRectUpdateInfo.h:
(WebKit::VisibleContentRectUpdateInfo::VisibleContentRectUpdateInfo):
(WebKit::VisibleContentRectUpdateInfo::obscuredInset):
(WebKit::operator==):
- UIProcess/API/Cocoa/WKWebView.mm:
(-[WKWebView _processDidExit]): Rename _needsToRestoreExposedRect to _needsToRestoreScrollPosition
(-[WKWebView _didCommitLayerTree:]): Restore the scroll position using the scaled scrollOffset minus
the old obscuredInset.
(-[WKWebView _layerTreeCommitComplete]):
(-[WKWebView _restorePageScrollPosition:scrollOrigin:previousObscuredInset:scale:]):
(-[WKWebView _restorePageStateToUnobscuredCenter:scale:]):
(-[WKWebView _scrollToContentScrollPosition:scrollOrigin:]):
(-[WKWebView _updateVisibleContentRects]):
(-[WKWebView _restorePageStateToExposedRect:scrollOrigin:scale:]): Deleted.
- UIProcess/API/Cocoa/WKWebViewInternal.h:
- UIProcess/PageClient.h:
- UIProcess/WebPageProxy.h:
- UIProcess/WebPageProxy.messages.in:
- UIProcess/ios/PageClientImplIOS.h:
- UIProcess/ios/PageClientImplIOS.mm:
(WebKit::PageClientImpl::restorePageState):
- UIProcess/ios/WKContentView.h:
- UIProcess/ios/WKContentView.mm:
(-[WKContentView didUpdateVisibleRect:unobscuredRect:unobscuredRectInScrollViewCoordinates:obscuredInset:scale:minimumScale:inStableState:isChangingObscuredInsetsInteractively:]):
(-[WKContentView didUpdateVisibleRect:unobscuredRect:unobscuredRectInScrollViewCoordinates:scale:minimumScale:inStableState:isChangingObscuredInsetsInteractively:]): Deleted.
- UIProcess/ios/WebPageProxyIOS.mm:
(WebKit::WebPageProxy::updateVisibleContentRects):
(WebKit::WebPageProxy::restorePageState):
- WebProcess/WebPage/ios/WebPageIOS.mm:
(WebKit::WebPage::restorePageState):
(WebKit::WebPage::updateVisibleContentRects):
- 10:21 AM Changeset in webkit [199232] by
-
- 2 edits in trunk/Source/WebCore
Build fix followup to http://trac.webkit.org/changeset/199230
Unreviewed.
- platform/posix/FileSystemPOSIX.cpp:
(WebCore::hardLinkOrCopyFile): Stricter POSIX systems require a umask for O_CREAT opens,
so let's provide one.
- 9:59 AM Changeset in webkit [199231] by
-
- 16 edits in trunk/Source/WebCore
Remove 14 more unnecessary uses of UsePointersEvenForNonNullableObjectArguments
https://bugs.webkit.org/show_bug.cgi?id=156405
Reviewed by Chris Dumez.
- Modules/encryptedmedia/MediaKeySession.idl:
- Modules/encryptedmedia/MediaKeys.idl:
- dom/Element.idl:
- dom/NamedNodeMap.idl:
- html/HTMLElement.idl:
- html/canvas/OESVertexArrayObject.idl:
- html/canvas/WebGLRenderingContext.idl:
- page/DOMSelection.idl:
- storage/StorageEvent.idl:
- svg/SVGSVGElement.idl:
- xml/XMLSerializer.idl:
- xml/XPathEvaluator.idl:
- xml/XPathExpression.idl:
- xml/XSLTProcessor.idl:
Removed UsePointersEvenForNonNullableObjectArguments, which was having no effect
in any of these classes. Also tweaked formatting of some of the IDL, merging things
onto single lines, changing paragraphing and indenting a bit, and fixing some typos.
- 9:57 AM Changeset in webkit [199230] by
-
- 27 edits in trunk/Source
Modern IDB (Blob support): Write blobs to temporary files and move them to the correct location when storing them.
https://bugs.webkit.org/show_bug.cgi?id=156321
Reviewed by Alex Christensen, Andy Estes, and Darin Adler.
Source/WebCore:
No new tests (No testable change in behavior yet, current tests pass).
When asked to store a Blob (including Files) in IndexedDB, the Blob is written out to a temporary file.
Then when the putOrAdd request is received by IDBServer it includes a list of blobURLs and their mappings
to temporary files.
Finally, as part of storing the Blob value in the database, those temporary files are moved in to place
under the IndexedDB directory for storage and later retrieval.
- Modules/indexeddb/IDBValue.cpp:
(WebCore::IDBValue::IDBValue):
- Modules/indexeddb/server/IDBBackingStore.h:
(WebCore::IDBServer::IDBBackingStoreTemporaryFileHandler::~IDBBackingStoreTemporaryFileHandler):
- Modules/indexeddb/server/IDBServer.cpp:
(WebCore::IDBServer::IDBServer::create):
(WebCore::IDBServer::IDBServer::IDBServer):
(WebCore::IDBServer::IDBServer::createBackingStore):
- Modules/indexeddb/server/IDBServer.h:
- Modules/indexeddb/server/SQLiteIDBBackingStore.cpp:
(WebCore::IDBServer::blobRecordsTableSchema):
(WebCore::IDBServer::blobRecordsTableSchemaAlternate):
(WebCore::IDBServer::blobFilesTableSchema):
(WebCore::IDBServer::blobFilesTableSchemaAlternate):
(WebCore::IDBServer::SQLiteIDBBackingStore::SQLiteIDBBackingStore):
(WebCore::IDBServer::SQLiteIDBBackingStore::ensureValidBlobTables):
(WebCore::IDBServer::SQLiteIDBBackingStore::getOrEstablishDatabaseInfo):
(WebCore::IDBServer::SQLiteIDBBackingStore::addRecord):
- Modules/indexeddb/server/SQLiteIDBBackingStore.h:
(WebCore::IDBServer::SQLiteIDBBackingStore::temporaryFileHandler):
- Modules/indexeddb/server/SQLiteIDBTransaction.cpp:
(WebCore::IDBServer::SQLiteIDBTransaction::commit):
(WebCore::IDBServer::SQLiteIDBTransaction::moveBlobFilesIfNecessary):
(WebCore::IDBServer::SQLiteIDBTransaction::abort):
(WebCore::IDBServer::SQLiteIDBTransaction::reset):
(WebCore::IDBServer::SQLiteIDBTransaction::addBlobFile):
- Modules/indexeddb/server/SQLiteIDBTransaction.h:
- Modules/indexeddb/shared/InProcessIDBServer.cpp:
(WebCore::InProcessIDBServer::InProcessIDBServer):
(WebCore::InProcessIDBServer::accessToTemporaryFileComplete):
- Modules/indexeddb/shared/InProcessIDBServer.h:
- bindings/js/SerializedScriptValue.cpp:
(WebCore::SerializedScriptValue::blobURLsIsolatedCopy):
- bindings/js/SerializedScriptValue.h:
- platform/FileSystem.h:
- platform/gtk/FileSystemGtk.cpp:
(WebCore::hardLinkOrCopyFile):
- platform/posix/FileSystemPOSIX.cpp:
(WebCore::hardLinkOrCopyFile):
Source/WebKit2:
The NetworkProcess writes a blob to a temporary file, then tells the UIProcess to grant the DatabaseProcess
a Sandbox Extension to that path.
It then tells the WebProcess the paths for the temporary files, which then tells the DatabaseProcess to store
the contents of those files as blob references in the database.
Since the UIProcess had already granted it a Sandbox Extension, it is able to do so.
- DatabaseProcess/DatabaseProcess.cpp:
(WebKit::DatabaseProcess::idbServer):
(WebKit::DatabaseProcess::grantSandboxExtensionsForBlobs):
(WebKit::DatabaseProcess::prepareForAccessToTemporaryFile):
(WebKit::DatabaseProcess::accessToTemporaryFileComplete):
- DatabaseProcess/DatabaseProcess.h:
- DatabaseProcess/DatabaseProcess.messages.in:
- NetworkProcess/NetworkConnectionToWebProcess.cpp:
(WebKit::NetworkConnectionToWebProcess::writeBlobsToTemporaryFiles):
- NetworkProcess/NetworkProcess.cpp:
(WebKit::NetworkProcess::grantSandboxExtensionsToDatabaseProcessForBlobs):
(WebKit::NetworkProcess::didGrantSandboxExtensionsToDatabaseProcessForBlobs):
- NetworkProcess/NetworkProcess.h:
- NetworkProcess/NetworkProcess.messages.in:
- UIProcess/Network/NetworkProcessProxy.cpp:
(WebKit::NetworkProcessProxy::grantSandboxExtensionsToDatabaseProcessForBlobs):
- UIProcess/Network/NetworkProcessProxy.h:
- UIProcess/Network/NetworkProcessProxy.messages.in:
- 9:40 AM WebKitGTK/2.12.x edited by
- Replace bug link with changeset link now that patch has landed (diff)
- 9:39 AM WebKitGTK/2.10.x edited by
- Replace bug link with changeset link now that patch has landed (diff)
- 9:36 AM Changeset in webkit [199229] by
-
- 4 edits3 adds in trunk
AX: [ATK] Crash getting text under element in CSS table
https://bugs.webkit.org/show_bug.cgi?id=156328
Reviewed by Chris Fleizach.
Source/WebCore:
AccessibilityRenderObject::textUnderElement() assumes (and asserts) that
the first and last child of an anonymous block will each have nodes with
which to define positions. This is not the case for CSS Tables and their
anonymous descendants. AccessibilityNodeObject:textUnderElement() is our
fallback for the instances where a text range cannot be created based on
positions, so let it handle anonymous RenderTable parts.
Test: accessibility/generated-content-with-display-table-crash.html
- accessibility/AccessibilityRenderObject.cpp:
(WebCore::AccessibilityRenderObject::textUnderElement):
(WebCore::AccessibilityRenderObject::shouldGetTextFromNode):
- accessibility/AccessibilityRenderObject.h:
LayoutTests:
While this crash is currently seen only for ATK, there is nothing to
prevent another port from attempting to get all the text under a CSS
RenderTable. Hence the shared test.
- accessibility/generated-content-with-display-table-crash.html: Added.
- platform/gtk/accessibility/generated-content-with-display-table-crash-expected.txt: Added.
- platform/mac/accessibility/generated-content-with-display-table-crash-expected.txt: Added.
- 9:11 AM Changeset in webkit [199228] by
-
- 2 edits in trunk/LayoutTests
Unreviewed.
Rebasing LayoutTests/imported/w3c/web-platform-tests/dom/nodes/MutationObserver-childList.html expectation after https://trac.webkit.org/changeset/199225.
Removing its Timeout expectation.
- 9:05 AM Changeset in webkit [199227] by
-
- 3 edits in trunk/Source/WebInspectorUI
Web Inspector: Attempting to dismiss a popover that is already being dismissed causes an error
https://bugs.webkit.org/show_bug.cgi?id=156385
<rdar://problem/25617962>
Reviewed by Timothy Hatcher.
The Popover element is removed from the DOM once it's fade-out transition
completes. Since Popover.dismiss proceeds as long as it's element has a
parent, successive calls to dismiss can run before the popover is removed.
Rather than rely on the presence of the popover in the DOM, set a "dismissing"
flag the first time dismiss is called, before the fade-out animation begins.
- UserInterface/Controllers/BreakpointPopoverController.js:
(WebInspector.BreakpointPopoverController.prototype._conditionCodeMirrorEscapeOrEnterKey):
Check for null popover.
- UserInterface/Views/Popover.js:
(WebInspector.Popover):
(WebInspector.Popover.prototype.dismiss):
Do nothing if already dismissing.
(WebInspector.Popover.prototype.handleEvent):
Reset dismissing flag after style transition completes.
- 9:04 AM Changeset in webkit [199226] by
-
- 5 edits in trunk
Web Inspector: Quick Open fails to match pattern "bB" in file "abBc"
https://bugs.webkit.org/show_bug.cgi?id=156398
Reviewed by Timothy Hatcher.
Source/WebInspectorUI:
Correct an off-by-one error in the backtrack routine that set the dead
branch index to the character just before the match that was popped.
The dead branch index should equal the index of the popped match.
- UserInterface/Controllers/ResourceQueryController.js:
(WebInspector.ResourceQueryController.prototype._findQueryMatches.backtrack):
(WebInspector.ResourceQueryController.prototype._findQueryMatches):
LayoutTests:
- inspector/unit-tests/resource-query-controller-expected.txt:
- inspector/unit-tests/resource-query-controller.html:
Test that two repeated characters in the search string are correctly
matched when the first character is lowercase and the second is uppercase.
- 7:45 AM Changeset in webkit [199225] by
-
- 13 edits2 adds in trunk
LayoutTests/imported/w3c:
Testharness-based tests that time out should be able to produce detailed output
https://bugs.webkit.org/show_bug.cgi?id=145313
Reviewed by Xabier Rodriguez-Calvar.
Rebasing tests that produce output after testharness timeout() is called.
- web-platform-tests/fetch/api/request/request-cache-expected.txt:
- web-platform-tests/html/semantics/document-metadata/the-link-element/link-style-error-01-expected.txt:
- web-platform-tests/html/semantics/document-metadata/the-style-element/style-error-01-expected.txt:
- web-platform-tests/html/semantics/embedded-content/the-img-element/environment-changes/viewport-change-expected.txt:
Tools:
Testharness-based tests that time out should be able to produce a detailed output
https://bugs.webkit.org/show_bug.cgi?id=145313
Reviewed by Xabier Rodriguez-Calvar.
Adding timeout readonly accessor to TestRunner for both WK1 and WK2.
- DumpRenderTree/TestRunner.cpp:
(getTimeoutCallback): The js "timeout" property getter.
(TestRunner::staticValues): Adding "timeout" property to DumpRenderTree so that testRunner.timeout called from JS returns the timeout value.
- DumpRenderTree/TestRunner.h:
(TestRunner::timeout): Adding access to DRT m_timeout private value.
- WebKitTestRunner/InjectedBundle/Bindings/TestRunner.idl: Adding timeout readonly attribute so that testRunner.timeout can be called from JS.
- WebKitTestRunner/InjectedBundle/TestRunner.h: Adding DOM timeout getter to implement timeout IDL definition.
(WTR::TestRunner::timeout):
LayoutTests:
Testharness-based tests that time out should be able to produce a detailled output
https://bugs.webkit.org/show_bug.cgi?id=145313
Reviewed by Xabier Rodriguez-Calvar.
- TestExpectations: Removed TIMEOUT for some tests for which testharness.timeout will be called just before WTR times out.
- platform/gtk/imported/w3c/web-platform-tests/fetch/api/request/request-cache-expected.txt: GTK specific baseline.
- resources/testharnessreport.js:
(add_completion_callback): Improving error logging message. Dumping of the tests status in error case.
- 2:04 AM Changeset in webkit [199224] by
-
- 9 edits in trunk/Source/WebCore
Remove unneeded UsePointersEvenForNonNullableObjectArguments from event classes
https://bugs.webkit.org/show_bug.cgi?id=156396
Reviewed by Youenn Fablet.
- dom/CompositionEvent.idl:
- dom/KeyboardEvent.idl:
- dom/MouseEvent.idl:
- dom/MutationEvent.idl:
- dom/TextEvent.idl:
- dom/TouchEvent.idl:
- dom/UIEvent.idl:
- dom/WheelEvent.idl:
Removed UsePointersEvenForNonNullableObjectArguments, which was having no effect.
- 1:52 AM Changeset in webkit [199223] by
-
- 3 edits4 adds in trunk
[css-grid] Fix positioned items with grid gaps
https://bugs.webkit.org/show_bug.cgi?id=156288
Reviewed by Darin Adler.
Source/WebCore:
When we place a positioned items in a grid with gaps,
we were not taking into accounts the gutter size.
We've to use that size to properly place and size the item.
Tests: fast/css-grid-layout/grid-positioned-items-gaps-rtl.html
fast/css-grid-layout/grid-positioned-items-gaps.html
- rendering/RenderGrid.cpp:
(WebCore::RenderGrid::offsetAndBreadthForPositionedChild):
LayoutTests:
Added new tests checking the right behavior.
- fast/css-grid-layout/grid-positioned-items-gaps-expected.txt: Added.
- fast/css-grid-layout/grid-positioned-items-gaps-rtl-expected.txt: Added.
- fast/css-grid-layout/grid-positioned-items-gaps-rtl.html: Added.
- fast/css-grid-layout/grid-positioned-items-gaps.html: Added.
- 1:01 AM Changeset in webkit [199222] by
-
- 2 edits in trunk/Source/WebCore
[css-grid] Remove unnecessary iteration in populateGridPositions loop
https://bugs.webkit.org/show_bug.cgi?id=156376
Reviewed by Darin Adler.
The populateGridPositions loop limit was set to 'lastLine'. However, the
the position of last track's start line is updated after the loop, since
it does not follow the same pattern; it does not have a content
distribution offset.
So, since we are essentially overwriting the value stored in the last
iteration, we can just lower the loop limit.
No new tests added, because there is no change in the functionality.
- rendering/RenderGrid.cpp:
(WebCore::RenderGrid::populateGridPositions):
- 12:17 AM Changeset in webkit [199221] by
-
- 11 edits in trunk
CSP: Block XHR when calling XMLHttpRequest.send() and throw network error.
https://bugs.webkit.org/show_bug.cgi?id=153598
<rdar://problem/24391483>
Patch by John Wilander <wilander@apple.com> on 2016-04-08
Reviewed by Darin Adler.
Source/WebCore:
No new tests. Changes to existing tests are sufficient.
- xml/XMLHttpRequest.cpp:
(WebCore::XMLHttpRequest::open):
(WebCore::XMLHttpRequest::initSend):
Moved the CSP check from XMLHttpRequest::open() to XMLHttpRequest::initSend().
Changed the thrown error type from Security to Network for synchronous requests.
Changed from throwing an error to firing an error event for asynchronous requests.
These changes are in conformance with connect-src of Content Security Policy Level 2.
https://www.w3.org/TR/CSP2/#directive-connect-src (W3C Candidate Recommendation, 21 July 2015)
LayoutTests:
- fast/workers/resources/worker-inherits-csp-blocks-xhr.js:
(catch):
- fast/workers/worker-inherits-csp-blocks-xhr-expected.txt:
Changed expected error from DOMException.SECURITY_ERR to DOMException.NETWORK_ERR.
- http/tests/security/contentSecurityPolicy/connect-src-xmlhttprequest-blocked-expected.txt:
- http/tests/security/contentSecurityPolicy/connect-src-xmlhttprequest-blocked.html:
Now tests that XMLHttpRequest.send() is blocked if the URL voilates the connect-src directive in CSP.
- http/tests/security/contentSecurityPolicy/resources/worker.php:
Added two additional calls to XMLHttpRequest.send() and switched to receiving an error event to make
existing tests work with code changes.
- http/tests/security/contentSecurityPolicy/source-list-parsing-malformed-meta.html:
Added an additional call to XMLHttpRequest.send() and switched to receiving an error event to make
existing test work with code changes.
- http/tests/security/isolatedWorld/bypass-main-world-csp-for-xhr-expected.txt:
- http/tests/security/isolatedWorld/bypass-main-world-csp-for-xhr.html:
Added an additional call to XMLHttpRequest.send() and switched to receiving an error event to make
existing tests work with code changes.
Refactored test mechnism with additional parameters to cover synchronous/asynchronous as well as
same-origin/cross-origin in isolated worlds.
- 12:15 AM Changeset in webkit [199220] by
-
- 5 edits2 adds in trunk/Websites/perf.webkit.org
Fix various bugs in the new syncing script
https://bugs.webkit.org/show_bug.cgi?id=156393
Reviewed by Darin Adler.
- server-tests/resources/common-operations.js: Added. This file was supposed to be added in r199191.
(addBuilderForReport):
(addSlaveForReport):
(connectToDatabaseInEveryTest):
(submitReport):
- tools/js/buildbot-triggerable.js:
(BuildbotTriggerable.prototype._pullBuildbotOnAllSyncers): Don't log every time we pull from buildbot
builder as this dramatically increases the amount of log we generate.
- tools/js/parse-arguments.js:
(parseArguments): Fixed a typo. This should be parseArgument*s*, not parseArgument.
- tools/js/remote.js:
(RemoteAPI.prototype.url): Fixed a bug that portSuffix wasn't being expanded in the template literal.
(RemoteAPI.prototype.configure): Added more validations with nice error messages.
(RemoteAPI.prototype.sendHttpRequest): Falling back to port 80 isn't right when scheme is https. Compute
the right port in configure instead based on the scheme.
- tools/sync-buildbot.js:
(syncLoop): Fixed the bug that syncing multiple times fail because Manifest.fetch() create new Platform
and Test objects. This results in various references in BuildRequest objects to get outdated. Fixing this
properly in Manifest.fetch() because we do need to "forget" about some tests and platforms in some cases.
For now, delete all v3 model objects and start over in each syncing cycle.
- unit-tests/tools-js-remote-tests.js: Added. Unit tests for the aforementioned changes to RemoteAPI.
- 12:13 AM Changeset in webkit [199219] by
-
- 4 edits2 adds in trunk/Source/JavaScriptCore
Web Inspector: protocol generator should emit an error when 'type' is used instead of '$ref'
https://bugs.webkit.org/show_bug.cgi?id=156275
<rdar://problem/25569331>
Reviewed by Darin Adler.
- inspector/protocol/Heap.json: Fix a mistake that's now caught by the protocol generator.
- inspector/scripts/codegen/models.py:
(TypeReference.init): Check here if type_kind is on a whitelist of primitive types.
(TypeReference.referenced_name): Update comment.
Add a new test specifically for the case when the type would otherwise be resolved. Rebaseline.
- inspector/scripts/tests/expected/fail-on-type-reference-as-primitive-type.json-error: Added.
- inspector/scripts/tests/expected/fail-on-unknown-type-reference-in-type-declaration.json-error:
- inspector/scripts/tests/fail-on-type-reference-as-primitive-type.json: Added.
- 12:08 AM Changeset in webkit [199218] by
-
- 2 edits in trunk/Source/WTF
[JSC] Enable Concurrent JIT by default
https://bugs.webkit.org/show_bug.cgi?id=156341
Reviewed by Filip Pizlo.
We enable Concurrent JIT by default when DFG JIT and JSVALUE64 are enabled.
This change offers Concurrent JIT to the JSCOnly port.
- wtf/Platform.h: