⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Timeline



Apr 14, 2022:

11:08 PM Changeset in webkit [292901] by Martin Robinson
  • 3 edits in trunk/Source/WebCore

[GTK] AddressSanitizer: heap-buffer-overflow in WebCore::Length::ref()
https://bugs.webkit.org/show_bug.cgi?id=237389

Reviewed by Žan Doberšek.

  • platform/graphics/nicosia/NicosiaAnimation.cpp:

(Nicosia::createThreadsafeKeyFrames): Convert Length members of transform functions to
the fixed variety before they are moved to separate threads.
(Nicosia::Animation::Animation): Use the new helper.

  • platform/graphics/transforms/TranslateTransformOperation.h: Added setters.
10:54 PM Changeset in webkit [292900] by zan@falconsigh.net
  • 2 edits in trunk/Source/WebCore

Unreviewed build fix for GTK and WPE.

  • platform/graphics/gbm/DMABufFormat.h: Add a missing <array> header include.
10:44 PM Changeset in webkit [292899] by Chris Dumez
  • 25 edits in trunk/Source/WebCore

Use WebCoreBuiltinNames when possible
https://bugs.webkit.org/show_bug.cgi?id=239361

Reviewed by Yusuke Suzuki.

Use WebCoreBuiltinNames when possible to avoid unnecessary calls to Identifier::fromString().
This is more efficient.

  • Modules/encryptedmedia/legacy/LegacyCDMSessionClearKey.cpp:

(WebCore::CDMSessionClearKey::update):

  • bindings/js/JSDOMGlobalObject.cpp:

(WebCore::JSDOMGlobalObject::addBuiltinGlobals):

  • bindings/js/JSDOMMapLike.cpp:

(WebCore::getBackingMap):

  • bindings/js/JSDOMSetLike.cpp:

(WebCore::getBackingSet):

  • bindings/js/JSDOMWindowBase.cpp:

(WebCore::JSDOMWindowBase::initStaticGlobals):
(WebCore::JSDOMWindowBase::finishCreation):
(WebCore::JSDOMWindowBase::updateDocument):

  • bindings/js/JSDOMWindowCustom.cpp:

(WebCore::jsDOMWindowGetOwnPropertySlotRestrictedAccess):
(WebCore::JSDOMWindow::getOwnPropertySlot):
(WebCore::JSDOMWindow::put):
(WebCore::addCrossOriginPropertyNames):
(WebCore::JSDOMWindow::defineOwnProperty):
(WebCore::JSDOMWindow::setOpener):
(WebCore::JSDOMWindow::openDatabase const):
(WebCore::JSDOMWindow::setOpenDatabase):

  • bindings/js/JSEventListener.cpp:

(WebCore::JSEventListener::handleEvent):

  • bindings/js/JSLocationCustom.cpp:

(WebCore::getOwnPropertySlotCommon):
(WebCore::JSLocation::put):

  • bindings/js/JSRemoteDOMWindowCustom.cpp:

(WebCore::JSRemoteDOMWindow::put):

  • bindings/js/ReadableStream.cpp:

(WebCore::ReadableStream::create):
(WebCore::ReadableStream::lock):

  • bindings/js/ScriptController.cpp:

(WebCore::ScriptController::setupModuleScriptHandlers):

  • bindings/js/ScriptModuleLoader.cpp:

(WebCore::rejectToPropagateNetworkError):
(WebCore::rejectWithFetchError):

  • bindings/js/WebCoreBuiltinNames.h:
  • bindings/js/WebCoreJSClientData.h:

(WebCore::webCoreBuiltinNames):

  • bindings/scripts/CodeGeneratorJS.pm:

(GenerateImplementation):

  • bindings/scripts/test/JS/JSDOMWindow.cpp:

(WebCore::JSDOMWindow::finishCreation):

  • bindings/scripts/test/JS/JSTestConditionallyReadWrite.cpp:

(WebCore::JSTestConditionallyReadWritePrototype::finishCreation):
(WebCore::JSTestConditionallyReadWrite::finishCreation):

  • bindings/scripts/test/JS/JSTestEnabledBySetting.cpp:

(WebCore::JSTestEnabledBySetting::finishCreation):

  • bindings/scripts/test/JS/JSTestEnabledForContext.cpp:

(WebCore::JSTestEnabledForContext::finishCreation):

  • bindings/scripts/test/JS/JSTestGlobalObject.cpp:

(WebCore::JSTestGlobalObject::finishCreation):

  • bindings/scripts/test/JS/JSTestObj.cpp:

(WebCore::JSTestObjPrototype::finishCreation):

  • html/HTMLMediaElement.cpp:

(WebCore::controllerJSValue):
(WebCore::HTMLMediaElement::didAddUserAgentShadowRoot):

  • testing/Internals.cpp:

(WebCore::Internals::cloneArrayBuffer):

  • workers/WorkerOrWorkletScriptController.cpp:

(WebCore::WorkerOrWorkletScriptController::loadModuleSynchronously):
(WebCore::WorkerOrWorkletScriptController::loadAndEvaluateModule):

6:45 PM Changeset in webkit [292898] by Wenson Hsieh
  • 20 edits in trunk

Undo option after invoking "Markup Image" says "Undo Paste"
https://bugs.webkit.org/show_bug.cgi?id=239351
rdar://91647863

Reviewed by Darin Adler.

Source/WebCore:

Add plumbing to allow a caller of Editor::replaceNodeFromPasteboard to specify an EditAction for the editing
command that is not just EditAction::Paste, and use it to supply a more specific edit action type of
MarkupImage in the case where "Markup Image" is used to replace an image element with other image data. This
allows the undo/redo title to be more accurate than simply "Undo/Redo Paste".

Test: ImageAnalysisTests.PerformImageAnalysisMarkup

  • dom/TextEvent.cpp:

(WebCore::TextEvent::createForPlainTextPaste):
(WebCore::TextEvent::createForFragmentPaste):
(WebCore::TextEvent::TextEvent):

  • dom/TextEvent.h:
  • dom/TextEventInputType.h:

Introduce TextEventInputMarkup. This is used to preserve the fact that a TextEvent was triggered via
"Markup Image" as opposed to a regular "Paste" command, when plumbing this event object through DOM event
propagation code. Once it reenters editing code, we consult this type to re-map this event to
EditAction::MarkupImage if appropriate.

I opted for this (slightly more roundabout) approach to prevent a potential layering violation, due to TextEvent
otherwise knowing about EditAction.

  • editing/EditAction.cpp:

(WebCore::undoRedoLabel):

  • editing/EditAction.h:

Introduce EditAction::MarkupImage. Additionally, alphabetically sort these enum types.

  • editing/Editor.cpp:

(WebCore::Editor::handleTextEvent):
(WebCore::Editor::pasteAsFragment):
(WebCore::Editor::replaceSelectionWithFragment):

  • editing/Editor.h:
  • editing/cocoa/EditorCocoa.mm:

(WebCore::Editor::replaceNodeFromPasteboard):

Add an EditAction argument; by default, this is EditAction::Paste.

  • en.lproj/Localizable.strings:

Add a new localized string to represent the name of the "Markup Image" item, for the purposes of setting the
Redo/Undo action title.

Source/WebKit:

Rename replaceWithPasteboardData to the more specific replaceImageWithMarkupResults. This method was
introduced (and is currently only used) to drive image replacement using "Markup Image"; giving this method a
more specific name allows us to hard-code EditAction::MarkupImage when calling into Editor to carry out the
replacement editing action in WebPage::replaceImageWithMarkupResults.

See WebCore/ChangeLog for additional details.

  • UIProcess/Cocoa/WebPageProxyCocoa.mm:

(WebKit::WebPageProxy::replaceImageWithMarkupResults):
(WebKit::WebPageProxy::replaceWithPasteboardData): Deleted.

  • UIProcess/WebPageProxy.h:
  • UIProcess/ios/WKContentViewInteraction.mm:

(-[WKContentView imageAnalysisMarkupMenu]):

  • UIProcess/mac/WebContextMenuProxyMac.mm:

(WebKit::WebContextMenuProxyMac::applyMarkupToControlledImage):

  • WebProcess/WebPage/Cocoa/WebPageCocoa.mm:

(WebKit::WebPage::replaceImageWithMarkupResults):
(WebKit::WebPage::replaceWithPasteboardData): Deleted.

  • WebProcess/WebPage/WebPage.h:
  • WebProcess/WebPage/WebPage.messages.in:

Tools:

Augment an existing API test to verify that the resulting undo action title after invoking "Markup Image" is not
"Undo Paste".

  • TestWebKitAPI/Tests/WebKitCocoa/ImageAnalysisTests.mm:

(TestWebKitAPI::TEST):

5:27 PM Changeset in webkit [292897] by Matteo Flores
  • 4 edits in trunk/LayoutTests

EXPECTATIONS: [ Monterey wk2 ] 7 /paymentrequest/* tests are constant text failures https://bugs.webkit.org/show_bug.cgi?id=238908 Unreviewed test gardening. * TestExpectations: * platform/ios-wk2/TestExpectations: * platform/mac-wk2/TestExpectations:

5:21 PM Changeset in webkit [292896] by Wenson Hsieh
  • 2 edits in trunk/Source/WebKit

Unreviewed, fix the Catalyst build after r292888

MCProfileConnection is not available on Mac Catalyst.

  • UIProcess/ios/WKContentViewInteraction.mm:

(-[WKContentView _dataOwnerForPasteboard:]):

4:39 PM Changeset in webkit [292895] by caitp@igalia.com
  • 8 edits
    3 adds in trunk

[JSC] ShadowRealm global object has a mutable prototype
https://bugs.webkit.org/show_bug.cgi?id=239332

Reviewed by Yusuke Suzuki.

JSTests:

  • stress/shadow-realm-globalThis-mutable-prototype.js: Added.

Source/JavaScriptCore:

This patch circumvents the ASSERT(toThis() == this) in JSObject::setPrototypeWithCycleCheck()
when this is a GlobalObject. Ordinarily, GlobalObjects have the IsImmutablePrototypeExoticObject
bit set and miss this pathway, however this is not the case for ShadowRealm Global Objects.

In addition, the JSC internal version is also modified to have a mutable prototype in the same way
as in WebCore.

  • runtime/JSGlobalObject.h:

(JSC::JSGlobalObject::deriveShadowRealmGlobalObject):
(JSC::JSGlobalObject::createStructureForShadowRealm):

  • runtime/JSObject.cpp:

(JSC::JSObject::setPrototypeWithCycleCheck):

Source/WebCore:

Hack: The IDL code generator now special cases ShadowRealmGlobalObject to remove the
ImmutablePrototypeExoticObject bit from the inherited JSGlobalObject structure flags.

As a result, this enables the assignment of a ShadowRealm's globalThis.proto, or
overwriting the prototype with [Object / Reflect].setPrototypeOf().

Test: js/ShadowRealm-globalThis.html

  • bindings/scripts/CodeGeneratorJS.pm:

(GenerateHeader):

  • bindings/scripts/test/JS/JSShadowRealmGlobalScope.h:

LayoutTests:

Add a new layout test to verify changes to verify that ShadowRealmGlobalObject has a properly
mutable prototype.

  • js/ShadowRealm-globalThis-expected.txt: Added.
  • js/ShadowRealm-globalThis.html: Added.
4:36 PM Changeset in webkit [292894] by Jenner@apple.com
  • 2 edits in trunk/Tools

Add an additional system to unsafe-merge queue
https://bugs.webkit.org/show_bug.cgi?id=239354

Reviewed by Ryan Haddad.

  • CISupport/ews-build/config.json:
4:32 PM Changeset in webkit [292893] by Nikos Mouchtaris
  • 15 edits in trunk

calc(): Serialize top level min/max/hypot as calc()
https://bugs.webkit.org/show_bug.cgi?id=239019

Reviewed by Darin Adler.

LayoutTests/imported/w3c:

  • web-platform-tests/css/css-values/hypot-pow-sqrt-invalid-expected.txt:
  • web-platform-tests/css/css-values/hypot-pow-sqrt-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-angle-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-length-percent-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-length-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-number-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-percentage-serialize-expected.txt:
  • web-platform-tests/css/css-values/minmax-time-serialize-expected.txt:

Source/WebCore:

For functions that would have no effect on the top level value, serialize as calc() rather
than the function.

  • css/calc/CSSCalcOperationNode.cpp:

(WebCore::CSSCalcOperationNode::simplifyNode):

  • css/calc/CSSCalcOperationNode.h:

LayoutTests:

  • fast/css/calc-parsing-expected.txt:
  • fast/css/calc-parsing.html:
4:26 PM Changeset in webkit [292892] by gnavamarino@apple.com
  • 2 edits in trunk/Source/WebCore

WebCore::WorkerStorageConnection::fileSystemGetDirectory could have invalid storageConnection()
https://bugs.webkit.org/show_bug.cgi?id=239355

Reviewed by Sihui Liu.

Add a check since storageConnection() can be invalid at this point.

  • Modules/storage/WorkerStorageConnection.cpp:

(WebCore::WorkerStorageConnection::fileSystemGetDirectory):

2:56 PM Changeset in webkit [292891] by ysuzuki@apple.com
  • 10 edits in trunk/Source

[JSC] Reduce use of CallFrame::deprecatedVM
https://bugs.webkit.org/show_bug.cgi?id=239326

Reviewed by Devin Rousso.

Reduce use of CallFrame::deprecatedVM, mainly in inspector related code to eventually remove CallFrame::deprecatedVM.

  • Source/JavaScriptCore/debugger/Debugger.cpp:

(JSC::Debugger::evaluateBreakpointCondition):
(JSC::Debugger::evaluateBreakpointActions):
(JSC::Debugger::exceptionOrCaughtValue):

  • Source/JavaScriptCore/debugger/DebuggerCallFrame.cpp:

(JSC::DebuggerCallFrame::globalObject):
(JSC::DebuggerCallFrame::functionName const):
(JSC::DebuggerCallFrame::scope):
(JSC::DebuggerCallFrame::type const):
(JSC::DebuggerCallFrame::evaluateWithScopeExtension):
(JSC::DebuggerCallFrame::deprecatedVMEntryGlobalObject const): Deleted.

  • Source/JavaScriptCore/debugger/DebuggerCallFrame.h:
  • Source/JavaScriptCore/inspector/JSJavaScriptCallFrame.cpp:

(Inspector::JSJavaScriptCallFrame::evaluateWithScopeExtension):
(Inspector::JSJavaScriptCallFrame::scopeDescriptions):
(Inspector::JSJavaScriptCallFrame::functionName const):
(Inspector::JSJavaScriptCallFrame::scopeChain const):
(Inspector::JSJavaScriptCallFrame::type const):

  • Source/JavaScriptCore/inspector/JavaScriptCallFrame.h:

(Inspector::JavaScriptCallFrame::functionName const):
(Inspector::JavaScriptCallFrame::type const):
(Inspector::JavaScriptCallFrame::scopeChain const):
(Inspector::JavaScriptCallFrame::evaluateWithScopeExtension const):
(Inspector::JavaScriptCallFrame::deprecatedVMEntryGlobalObject const): Deleted.

  • Source/JavaScriptCore/inspector/agents/InspectorDebuggerAgent.cpp:

(Inspector::InspectorDebuggerAgent::debuggerScopeExtensionObject):
(Inspector::InspectorDebuggerAgent::didPause):

  • Source/JavaScriptCore/interpreter/Interpreter.cpp:

(JSC::Interpreter::debug):

Canonical link: https://commits.webkit.org/249661@main

2:15 PM Changeset in webkit [292890] by Jonathan Bedard
  • 6 edits in trunk/Tools

[git-webkit] Personal branch is "not a PR branch"
https://bugs.webkit.org/show_bug.cgi?id=239329
<rdar://problem/91756286>

Reviewed by Yusuke Suzuki.

  • Tools/Scripts/libraries/webkitscmpy/setup.py: Bump version.
  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/init.py: Ditto.
  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/local/git.py:

(Git.branches_for): Provide optional caching.

  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/program/branch.py:

(Branch.editable): If a branch does not exist on production remotes, that branch
should also be considered a PR branch.

  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/program/pull_request.py:

(PullRequest.main): Only create a new PR branch if the current branch is a
production branch.

Canonical link: https://commits.webkit.org/249660@main

2:00 PM Changeset in webkit [292889] by Jonathan Bedard
  • 2 edits in trunk/Websites/webkit.org

[webkit.org] Remove leading r from archive revisions
https://bugs.webkit.org/show_bug.cgi?id=239322
<rdar://problem/91735590>

Reviewed by Ryan Haddad.

  • Websites/webkit.org/wp-content/themes/webkit/build-archives.php: Remove leading 'r' from revisions,

since "revisions" will now be identifiers.

Canonical link: https://commits.webkit.org/249659@main

1:58 PM Changeset in webkit [292888] by Wenson Hsieh
  • 7 edits in trunk

[iOS] [WK2] Managed pasteboard should function for all managed domains
https://bugs.webkit.org/show_bug.cgi?id=239319
rdar://80059355

Reviewed by Kate Cheney.

Source/WebCore/PAL:

Add an SPI method on MCProfileConnection.

  • pal/spi/ios/ManagedConfigurationSPI.h:

Source/WebKit:

Unless a WebKit client has specified a data owner for the web view that is not _UIDataOwnerUndefined, fall back
to _UIDataOwnerEnterprise when the current domain of the WKWebView is managed (that is, `-[MCProfileConnection
isURLManaged:]` returns YES for the web view's current URL). This allows managed pasteboard to work for all
WebKit clients, if the current URL is managed.

Test: UIPasteboardTests.PerformAsDataOwnerWithManagedURL

  • Platform/spi/ios/UIKitSPI.h:

Drive-by fix: move the staged declarations of -_dataOwnerForCopy and -_dataOwnerForPaste out of the IPI
section, and into the non-internal SDK section.

  • UIProcess/ios/WKContentViewInteraction.mm:

(-[WKContentView _dataOwnerForPasteboard:]):

Tools:

Add a new API test to verify that we fall back to consulting -[MCProfileConnection isURLManaged:] when
determining the data owner for copy and paste, unless a data owner is already explicitly set on a view in the
responder chain (specifically, the WKWebView).

  • TestWebKitAPI/Tests/ios/UIPasteboardTests.mm:

(+[TestUIPasteboard _performAsDataOwner:block:]):
(-[TestMCProfileConnection isURLManaged:]):
(TestWebKitAPI::TEST):

1:35 PM Changeset in webkit [292887] by Chris Dumez
  • 3 edits in trunk/Source/WebCore

Require an existing AtomString for HTMLFormElement's named getter parameter
https://bugs.webkit.org/show_bug.cgi?id=239335

Reviewed by Darin Adler.

Require an existing AtomString for HTMLFormElement's named getter parameter. There is no point
in allocating a new AtomString as the AtomString should already exist if there is any element
with this name / id.

  • html/HTMLFormElement.cpp:

(WebCore::HTMLFormElement::namedElements):

  • html/HTMLFormElement.idl:
1:19 PM Changeset in webkit [292886] by Alexey Shvayka
  • 2 edits in trunk/Source/JavaScriptCore

InternalFunction::createSubclassStructure() should use base object's global object
https://bugs.webkit.org/show_bug.cgi?id=239346

Unreviewed, account for offline feedback by Yusuke Suzuki.

  • runtime/InternalFunction.cpp:

(JSC::InternalFunction::createSubclassStructure):

12:52 PM Changeset in webkit [292885] by Chris Dumez
  • 2 edits in trunk/Source/WebCore

Require an existing AtomString for HTMLDocument's named getter parameter
https://bugs.webkit.org/show_bug.cgi?id=239334

Reviewed by Alexey Shvayka.

Require an existing AtomString for HTMLDocument's named getter parameter. There is no point
in allocating a new AtomString as the AtomString should already exist if there is any element
with this name.

  • html/HTMLDocument.idl:
12:45 PM Changeset in webkit [292884] by Jonathan Bedard
  • 1 edit
    2 adds in trunk

Add .github/pull_request_template.md
https://bugs.webkit.org/show_bug.cgi?id=239347
<rdar://problem/91763594>

Reviewed by Michael Catanzaro.

  • .github/pull_request_template.md: Added.

Canonical link: https://commits.webkit.org/249654@main

12:30 PM Changeset in webkit [292883] by Alexey Shvayka
  • 4 edits in trunk

InternalFunction::createSubclassStructure() should use base object's global object
https://bugs.webkit.org/show_bug.cgi?id=239346

Reviewed by Darin Adler.

JSTests:

  • stress/internal-function-subclass-structure-realm.js:

Source/JavaScriptCore:

Chrome and Firefox don't agree on interoperable behavior in case of cross-realm
NewTarget's "prototype", so this patch aligns WebKit with Chrome to fix a web-compat issue.

  • runtime/InternalFunction.cpp:

(JSC::InternalFunction::createSubclassStructure):

12:13 PM Changeset in webkit [292882] by J Pascoe
  • 41 edits
    9 deletes in trunk

[WebAuthn] Clean up WebAuthenticationModern and WebAuthnProcess
https://bugs.webkit.org/show_bug.cgi?id=239073
rdar://problem/91571030

Source/WebCore:

The WebAuthenticationModern flag and WebAuthnProcess are no longer used
and can be removed. This patch removes all references to both the flag
and the process.

Reviewed by Brent Fulgham.

  • page/RuntimeEnabledFeatures.h:

(WebCore::RuntimeEnabledFeatures::setWebAuthenticationModernEnabled): Deleted.
(WebCore::RuntimeEnabledFeatures::webAuthenticationModernEnabled const): Deleted.

  • platform/RuntimeApplicationChecks.cpp:

(WebCore::processTypeDescription):

  • platform/RuntimeApplicationChecks.h:

Source/WebKit:

The WebAuthenticationModern flag and WebAuthnProcess are no longer used
and can be removed. This patch removes all references to both the flag
and the process.

Reviewed by Brent Fulgham.

Covered by existing tests and manual testing on macOS / iOS.

  • Configurations/WebAuthnService.xcconfig: Removed.
  • Configurations/WebKit.xcconfig:
  • DerivedSources.make:
  • Resources/SandboxProfiles/ios/com.apple.WebKit.WebAuthn.sb.in: Removed.
  • Scripts/process-entitlements.sh:
  • Shared/Cocoa/DefaultWebBrowserChecks.mm:

(WebKit::isInWebKitChildProcess):

  • Shared/EntryPointUtilities/Cocoa/XPCService/XPCServiceEntryPoint.h:
  • Shared/EntryPointUtilities/Cocoa/XPCService/XPCServiceMain.mm:

(WebKit::XPCServiceEventHandler):

  • Shared/mac/AuxiliaryProcessMac.mm:

(WebKit::processStorageClass):
(WebKit::sandboxDirectory):

  • Sources.txt:
  • SourcesCocoa.txt:
  • UIProcess/API/C/WKPreferences.cpp:

(WKPreferencesSetWebAuthenticationModernEnabled): Deleted.
(WKPreferencesGetWebAuthenticationModernEnabled): Deleted.

  • UIProcess/API/C/WKPreferencesRefPrivate.h:
  • UIProcess/API/Cocoa/WKProcessPool.mm:

(+[WKProcessPool _webAuthnProcessIdentifier]): Deleted.

  • UIProcess/API/Cocoa/WKProcessPoolPrivate.h:
  • UIProcess/API/Cocoa/_WKWebAuthenticationPanel.mm:

(+[_WKWebAuthenticationPanel importLocalAuthenticatorWithAccessGroup:credential:error:]):

  • UIProcess/AuxiliaryProcessProxy.cpp:

(WebKit::AuxiliaryProcessProxy::getLaunchOptions):

  • UIProcess/Cocoa/WebProcessPoolCocoa.mm:

(WebKit::WebProcessPool::notifyPreferencesChanged):

  • UIProcess/Launcher/ProcessLauncher.h:
  • UIProcess/Launcher/cocoa/ProcessLauncherCocoa.mm:

(WebKit::serviceName):
(WebKit::shouldLeakBoost):

  • UIProcess/WebAuthentication/Authenticator.h:

(WebKit::Authenticator::requestData const):
(WebKit::Authenticator::setWebAuthenticationModernEnabled): Deleted.
(WebKit::Authenticator::webAuthenticationModernEnabled const): Deleted.
(): Deleted.

  • UIProcess/WebAuthentication/AuthenticatorManager.cpp:

(WebKit::AuthenticatorManager::authenticatorAdded):
(WebKit::AuthenticatorManager::enableModernWebAuthentication): Deleted.

  • UIProcess/WebAuthentication/AuthenticatorManager.h:
  • UIProcess/WebAuthentication/Cocoa/LocalAuthenticator.mm:

(WebKit::LocalAuthenticator::makeCredential):
(WebKit::LocalAuthenticator::getAssertion):
(WebKit::LocalAuthenticator::continueGetAssertionAfterResponseSelected):

  • UIProcess/WebAuthentication/WebAuthnProcessProxy.cpp: Removed.
  • UIProcess/WebAuthentication/WebAuthnProcessProxy.h: Removed.
  • UIProcess/WebAuthentication/fido/CtapAuthenticator.cpp:

(WebKit::CtapAuthenticator::continueGetNextAssertionAfterResponseReceived):
(WebKit::CtapAuthenticator::continueRequestPinAfterGetKeyAgreement):

  • UIProcess/WebProcessPool.cpp:

(WebKit::WebProcessPool::getWebAuthnProcessConnection): Deleted.

  • UIProcess/WebProcessPool.h:
  • UIProcess/WebProcessProxy.cpp:

(WebKit::WebProcessProxy::getWebAuthnProcessConnection): Deleted.

  • UIProcess/WebProcessProxy.h:
  • UIProcess/WebProcessProxy.messages.in:
  • WebAuthnProcess/EntryPoint/Cocoa/XPCService/WebAuthnService/Info-OSX.plist: Removed.
  • WebAuthnProcess/EntryPoint/Cocoa/XPCService/WebAuthnService/Info-iOS.plist: Removed.
  • WebAuthnProcess/EntryPoint/Cocoa/XPCService/WebAuthnServiceEntryPoint.mm: Removed.
  • WebAuthnProcess/WebAuthnConnectionToWebProcess.cpp: Removed.
  • WebAuthnProcess/WebAuthnConnectionToWebProcess.h: Removed.
  • WebAuthnProcess/WebAuthnConnectionToWebProcess.messages.in: Removed.
  • WebAuthnProcess/WebAuthnProcess.cpp: Removed.
  • WebAuthnProcess/WebAuthnProcess.h: Removed.
  • WebAuthnProcess/WebAuthnProcess.messages.in: Removed.
  • WebAuthnProcess/WebAuthnProcessCreationParameters.cpp: Removed.
  • WebAuthnProcess/WebAuthnProcessCreationParameters.h: Removed.
  • WebAuthnProcess/ios/WebAuthnProcessIOS.mm: Removed.
  • WebAuthnProcess/mac/WebAuthnProcessMac.mm: Removed.
  • WebAuthnProcess/mac/com.apple.WebKit.WebAuthnProcess.sb.in: Removed.
  • WebKit.xcodeproj/project.pbxproj:
  • WebProcess/WebAuthentication/WebAuthenticatorCoordinator.cpp:

(WebKit::WebAuthenticatorCoordinator::makeCredential):
(WebKit::WebAuthenticatorCoordinator::getAssertion):
(WebKit::WebAuthenticatorCoordinator::isUserVerifyingPlatformAuthenticatorAvailable):

  • WebProcess/WebAuthentication/WebAuthnProcessConnection.cpp: Removed.
  • WebProcess/WebAuthentication/WebAuthnProcessConnection.h: Removed.
  • WebProcess/WebAuthentication/WebAuthnProcessConnection.messages.in: Removed.
  • WebProcess/WebAuthentication/WebAuthnProcessConnectionInfo.h: Removed.
  • WebProcess/WebCoreSupport/WebChromeClient.cpp:

(WebKit::WebChromeClient::setMockWebAuthenticationConfiguration):

  • WebProcess/WebProcess.cpp:

(WebKit::getWebAuthnProcessConnection): Deleted.
(WebKit::WebProcess::ensureWebAuthnProcessConnection): Deleted.
(WebKit::WebProcess::webAuthnProcessConnectionClosed): Deleted.

  • WebProcess/WebProcess.h:

(WebKit::WebProcess::existingWebAuthnProcessConnection): Deleted.

Source/WTF:

Reviewed by Brent Fulgham.

  • Scripts/Preferences/WebPreferencesExperimental.yaml:

Tools:

Reviewed by Brent Fulgham.

  • TestWebKitAPI/Tests/WebKitCocoa/_WKWebAuthenticationPanel.mm:

(TestWebKitAPI::TEST):
(TestWebKitAPI::WebCore::webAuthenticationModernExperimentalFeature): Deleted.

12:04 PM Changeset in webkit [292881] by Jonathan Bedard
  • 2 edits in trunk/Tools

[build.webkit.org] Use identifier as version when uploading artifacts
https://bugs.webkit.org/show_bug.cgi?id=239321
<rdar://problem/91734798>

Reviewed by Ryan Haddad.

  • Tools/CISupport/build-webkit-org/steps.py:

(GenerateJSCBundle): Use archive_revision to name generated content.
(GenerateMiniBrowserBundle): Ditto
(UploadBuiltProduct): Ditto
(UploadMinifiedBuiltProduct): Ditto
(DownloadBuiltProduct): Ditto
(DownloadBuiltProductFromMaster): Ditto
(RunBenchmarkTests): Ditto
(UploadTestResults): Ditto
(TransferToS3): Ditto
(ExtractTestResults.init): Ditto
(ShowIdentifier.evaluateCommand): Set archive_revision as identifier,
fall back to got_revision.

Canonical link: https://commits.webkit.org/249651@main

11:00 AM Changeset in webkit [292880] by Aditya Keerthi
  • 4 edits in trunk/Source/WebKit

[iOS] Add support for find-and-replace keyboard shortcut
https://bugs.webkit.org/show_bug.cgi?id=239320
rdar://91537724

Reviewed by Wenson Hsieh.

  • UIProcess/API/ios/WKWebViewIOS.h:
  • UIProcess/ios/WKContentViewInteraction.h:
  • UIProcess/ios/WKContentViewInteraction.mm:

(-[WKContentView canPerformActionForWebView:withSender:]):
(-[WKContentView findAndReplaceForWebView:]):

10:55 AM Changeset in webkit [292879] by Chris Dumez
  • 44 edits in trunk

Drop inefficient String::append() overloads
https://bugs.webkit.org/show_bug.cgi?id=239289

Reviewed by Sam Weinig.

Source/JavaScriptCore:

  • heap/HeapSnapshotBuilder.cpp:

(JSC::HeapSnapshotBuilder::json):

  • runtime/IntlObject.cpp:

(JSC::resolveLocale):

  • runtime/TemporalObject.cpp:

(JSC::ellipsizeAt):

  • tools/FunctionOverrides.cpp:

(JSC::initializeOverrideInfo):
(JSC::parseClause):

Source/WebCore:

  • Modules/indexeddb/IDBKeyData.cpp:

(WebCore::IDBKeyData::loggingString const):

  • Modules/indexeddb/IDBKeyRangeData.cpp:

(WebCore::IDBKeyRangeData::loggingString const):

  • Modules/indexeddb/shared/IDBIndexInfo.cpp:

(WebCore::IDBIndexInfo::loggingString const):

  • Modules/websockets/WebSocketHandshake.cpp:

(WebCore::trimInputSample):

  • accessibility/isolatedtree/AXIsolatedObject.cpp:

(WebCore::AXIsolatedObject::initializeAttributeData):

  • dom/CharacterData.cpp:

(WebCore::CharacterData::parserAppendData):

  • dom/Text.cpp:

(WebCore::appendTextRepresentation):

  • dom/ViewportArguments.cpp:

(WebCore::viewportErrorMessage):

  • editing/markup.cpp:

(WebCore::fillContainerFromString):

  • html/FTPDirectoryDocument.cpp:

(WebCore::FTPDirectoryDocumentParser::parseAndAppendOneLine):
(WebCore::FTPDirectoryDocumentParser::append):
(WebCore::FTPDirectoryDocumentParser::finish):

  • html/canvas/WebGLRenderingContextBase.cpp:

(WebCore::WebGLRenderingContextBase::getActiveUniform):

  • html/track/WebVTTParser.cpp:

(WebCore::WebVTTParser::checkAndStoreStyleSheet):

  • html/track/WebVTTParser.h:
  • inspector/InspectorOverlay.cpp:

(WebCore::truncateWithEllipsis):

  • inspector/InspectorOverlayLabel.cpp:

(WebCore::InspectorOverlayLabel::draw):

  • inspector/agents/InspectorDOMAgent.cpp:

(WebCore::InspectorDOMAgent::buildObjectForNode):

  • page/scrolling/ScrollingStateTree.cpp:

(WebCore::ScrollingStateTree::scrollingStateTreeAsText const):

  • platform/graphics/HEVCUtilities.cpp:

(WebCore::createHEVCCodecParametersString):

  • platform/network/HTTPParsers.cpp:

(WebCore::trimInputSample):

  • platform/network/curl/CurlCacheEntry.cpp:

(WebCore::CurlCacheEntry::CurlCacheEntry):
(WebCore::CurlCacheEntry::saveResponseHeaders):

  • platform/network/curl/CurlCacheManager.cpp:

(WebCore::CurlCacheManager::setCacheDirectory):

  • platform/network/curl/CurlContext.cpp:

(WebCore::CurlHandle::addExtraNetworkLoadMetrics):

  • rendering/RenderLayerBacking.cpp:

(WebCore::RenderLayerBacking::createPrimaryGraphicsLayer):

Source/WebKit:

  • Shared/mac/AuxiliaryProcessMac.mm:

(WebKit::populateSandboxInitializationParameters):

  • WebProcess/Plugins/PDF/PDFPlugin.mm:

(WebKit::PDFPlugin::setSuggestedFilename):

Source/WebKitLegacy/win:

  • WebDownload.cpp:

(WebDownload::bundlePathForTargetPath):

Source/WTF:

  • wtf/Assertions.cpp:
  • wtf/text/StringBuilder.h:

(WTF::StringBuilder::append):

  • wtf/text/WTFString.cpp:

(WTF::String::insert):
(WTF::String::append):

  • wtf/text/WTFString.h:

Tools:

  • TestWebKitAPI/Tests/WTF/FileSystem.cpp:

(TestWebKitAPI::TEST_F):

  • TestWebKitAPI/Tests/WTF/StringBuilder.cpp:

(TestWebKitAPI::TEST):

  • TestWebKitAPI/Tests/WebCore/ContentExtensions.cpp:

(TestWebKitAPI::TEST_F):

  • WebKitTestRunner/TestController.cpp:

(WTR::TestController::didReceiveAuthenticationChallenge):

10:46 AM Changeset in webkit [292878] by gnavamarino@apple.com
  • 2 edits in trunk/Source/WebCore

ScriptDisallowedScope::isEventAllowedInMainThread assert failure when activating AudioSession
https://bugs.webkit.org/show_bug.cgi?id=239343

Reviewed by Eric Carlson.

As part of HTMLMediaElement::clearMediaPlayer we call PlatformMediaSession::canProduceAudioChanged
which can result in activating the AudioSession when the page is capturing audio.

This sends a synchronous IPC message to the GPU process. As part of IPC::Connection::waitForSyncReply,
we also end up dispatching enqueued messages, including a WebPage_EndPrinting message that
fires an event listener on the main thread.

This patch will instead queue the PlatformMediaSession::canProduceAudioChanged as a task to avoid
firing the event listener on the main thread, which results in assertion failure.

  • html/HTMLMediaElement.cpp:

(WebCore::HTMLMediaElement::clearMediaPlayer):

10:26 AM Changeset in webkit [292877] by Russell Epstein
  • 9 edits in branches/safari-614.1.10-branch/Source

Versioning.

WebKit-7614.1.10.1

10:23 AM Changeset in webkit [292876] by commit-queue@webkit.org
  • 2 edits in trunk/Tools

Replace PaintCompositedResultsToMediaSample with PaintCompositedResultsToVideoFrame in generate-gpup-webgl
https://bugs.webkit.org/show_bug.cgi?id=239317

Patch by John Cunningham <johncunningham@apple.com> on 2022-04-14
Reviewed by Alexey Proskuryakov.

  • Scripts/generate-gpup-webgl:
10:15 AM Changeset in webkit [292875] by Karl Rackler
  • 2 edits in trunk/LayoutTests

[ Mac ] editing/execCommand/insert-ordered-list-and-delete.html is a flaky failure
https://bugs.webkit.org/show_bug.cgi?id=239345

Unreviewed test gardening.

  • platform/mac/TestExpectations:
10:07 AM Changeset in webkit [292874] by Chris Dumez
  • 3 edits in trunk/Source/WebCore

Update ContainerNode::getElementsByName() to take in an AtomString
https://bugs.webkit.org/show_bug.cgi?id=239333

Reviewed by Alexey Shvayka.

Update ContainerNode::getElementsByName() to take in an AtomString instead of a String.
Its implementation ends up atomizing the name anyway.

  • dom/ContainerNode.cpp:

(WebCore::ContainerNode::getElementsByName):

  • dom/ContainerNode.h:
9:39 AM Changeset in webkit [292873] by Robert Jenner
  • 2 edits in trunk/Tools

Remove bot241 to be re-purposed
<rdar://problem/91729033>

Unreviewed configuration change.

  • Tools/CISupport/build-webkit-org/config.json:
9:23 AM Changeset in webkit [292872] by youenn@apple.com
  • 2 edits in trunk/Source/WebCore

Add logging for persistent notification event handler failure
https://bugs.webkit.org/show_bug.cgi?id=239131

Reviewed by Chris Dumez.

  • workers/service/server/SWServer.cpp:

(WebCore::SWServer::processNotificationEvent):

9:05 AM Changeset in webkit [292871] by Karl Rackler
  • 2 edits in trunk/LayoutTests

[ Mac wk2 arm64 ] scrollingcoordinator/mac/fixed-backgrounds/fixed-background-in-overflow-in-iframe.html is a flaky failure
https://bugs.webkit.org/show_bug.cgi?id=225529

Unreviewed test gardening.

  • platform/mac-wk2/TestExpectations:
8:56 AM Changeset in webkit [292870] by Justin Michaud
  • 32 edits
    1 add in trunk

[PGO] We should be able to build WebKit to collect PGO profiles easily
https://bugs.webkit.org/show_bug.cgi?id=238776

Reviewed by Wenson Hsieh.

.:

  • Makefile.shared:
  • Source/cmake/WebKitFeatures.cmake:

Source/JavaScriptCore:

  • Configurations/JavaScriptCore.xcconfig:
  • runtime/VM.cpp:

(JSC::VM::VM):

Source/WebCore:

  • Configurations/WebCore.xcconfig:
  • Configurations/WebCoreTestSupport.xcconfig:
  • page/Frame.cpp:

(WebCore::Frame::Frame):

Source/WebKit:

  • Configurations/BaseTarget.xcconfig:
  • Configurations/WebKit.xcconfig:
  • GPUProcess/mac/GPUProcessMac.mm:

(WebKit::GPUProcess::initializeProcess):

  • NetworkProcess/mac/NetworkProcessMac.mm:

(WebKit::NetworkProcess::initializeProcess):

  • WebProcess/WebPage/WebPage.cpp:

(WebKit::m_appHighlightsVisible):

Source/WTF:

Build WebKit as follows: make release WK_LTO_MODE=thin ENABLE_LLVM_PROFILE_GENERATION=ON
Then, follow the directions in the log output at runtime to collect your raw PGO profiles!

We add a new compile flag plus WTF::registerProfileGenerationCallback, allowing llvm profiles
to be collected by sending a notifyutil signal. The files are written to the temp directory,
and it seems like the sandbox permits this by default. You may need to disable the sandbox if
you encounter issues, either by editing the *.sb files or by using an inserted dylib to interpose
the sandbox initialization calls.

  • WTF.xcodeproj/project.pbxproj:
  • wtf/CMakeLists.txt:
  • wtf/GenerateProfiles.h: Added.

(WTF::registerProfileGenerationCallback):

  • wtf/PlatformEnable.h:

Tools:

  • Scripts/check-for-weak-vtables-and-externals:
  • Scripts/webkitdirs.pm:

(XcodeOptions):

  • Scripts/webkitperl/FeatureList.pm:
8:48 AM Changeset in webkit [292869] by youenn@apple.com
  • 3 edits in trunk/Source/WebKit

REGRESSION (249029@main): http/wpt/cache-storage/cache-storage-networkprocess-crash.html is a flaky CRASH with ASSERTION FAILED: m_pageMap.isEmpty()
https://bugs.webkit.org/show_bug.cgi?id=239095
<rdar://problem/91595784>

Reviewed by Chris Dumez.

We send the same IPC message to close WebSWContextManagerConnection from either network process or UIProcess.
To prevent closing twice the same connection, we exit early if the connection is closed.

Covered by existing tests.

  • WebProcess/Storage/WebSWContextManagerConnection.cpp:
  • WebProcess/Storage/WebSharedWorkerContextManagerConnection.cpp:
8:44 AM Changeset in webkit [292868] by youenn@apple.com
  • 2 edits in trunk/Tools

Enable ExitsUnderMemoryPressureWebRTCCase and disable ExitsUnderMemoryPressureGetUserMediaAudioCase on iOS simulator
https://bugs.webkit.org/show_bug.cgi?id=239115

Reviewed by Eric Carlson.

  • TestWebKitAPI/Tests/WebKitCocoa/GPUProcess.mm:

(TEST):

7:52 AM Changeset in webkit [292867] by Kate Cheney
  • 16 edits in trunk

WKWebView: navigator.serviceWorker.register method fails for a new version of an already registered service worker.
https://bugs.webkit.org/show_bug.cgi?id=229554
<rdar://problem/82388593>

Reviewed by Brent Fulgham.

Source/WebCore:

Check to see if a domain has already been registered when validating
a service worker registration domain. In this case, we allow an
updated registration.

There are a couple of other changes that are key for testing this.
First, this adds a way to override the max registration count for
tests. This is because we can only use 127.0.0.1 and localhost in
tests, but would need 3 domains in order to test the max count.
overrideServiceWorkerRegistrationCountTestingValue lets us lower that
number.

Second, we also want a way to override the loopback IP address check
to make sure we don't get a false positive test result for localhost
and 127.0.0.1 in API tests.

  • workers/service/server/SWServer.cpp:

(WebCore::SWServer::addRegistrationFromStore):
(WebCore::SWServer::addRegistration):
(WebCore::SWServer::SWServer):
(WebCore::SWServer::maxRegistrationCount):
(WebCore::SWServer::allowLoopbackIPAddress):
(WebCore::SWServer::validateRegistrationDomain):
(WebCore::SWServer::scheduleJob):
(WebCore::SWServer::removeFromScopeToRegistrationMap):

  • workers/service/server/SWServer.h:

Source/WebKit:

Plumbing to override the max service worker registration count for
test purposes. See WebCore changelog for details.

  • NetworkProcess/NetworkSession.cpp:

(WebKit::NetworkSession::NetworkSession):
(WebKit::NetworkSession::ensureSWServer):

  • NetworkProcess/NetworkSession.h:

(WebKit::NetworkSession::overrideServiceWorkerRegistrationCountTestingValue const):

  • NetworkProcess/NetworkSessionCreationParameters.cpp:

(WebKit::NetworkSessionCreationParameters::encode const):
(WebKit::NetworkSessionCreationParameters::decode):

  • NetworkProcess/NetworkSessionCreationParameters.h:
  • UIProcess/API/Cocoa/_WKWebsiteDataStoreConfiguration.h:
  • UIProcess/API/Cocoa/_WKWebsiteDataStoreConfiguration.mm:

(-[_WKWebsiteDataStoreConfiguration overrideServiceWorkerRegistrationCountTestingValue]):
(-[_WKWebsiteDataStoreConfiguration setOverrideServiceWorkerRegistrationCountTestingValue:]):

  • UIProcess/WebsiteData/WebsiteDataStore.cpp:

(WebKit::WebsiteDataStore::parameters):

  • UIProcess/WebsiteData/WebsiteDataStoreConfiguration.cpp:

(WebKit::WebsiteDataStoreConfiguration::copy const):

  • UIProcess/WebsiteData/WebsiteDataStoreConfiguration.h:

(WebKit::WebsiteDataStoreConfiguration::overrideServiceWorkerRegistrationCountTestingValue const):
(WebKit::WebsiteDataStoreConfiguration::setOverrideServiceWorkerRegistrationCountTestingValue):

Tools:

Adds a new test for re-registering and an overdue test for
unregistering now that we have the infrastructure. This also does some
refactoring to reduce duplicate code.

  • TestWebKitAPI/Info.plist:

Update the Info.plist to consider localhost an app-bound domain so we
can test the max count when overriding the loopback IP. This requires
replacing an existing domain to stay under the count limit.

  • TestWebKitAPI/Tests/WebKitCocoa/InAppBrowserPrivacy.mm:

(TEST):

7:36 AM Changeset in webkit [292866] by Kate Cheney
  • 2 edits in trunk/LayoutTests

[ iOS ] imported/w3c/web-platform-tests/content-security-policy/worker-src/service-* tests are consistently failing (229875)
https://bugs.webkit.org/show_bug.cgi?id=229875
<rdar://problem/82727204>

Unreviewed. Updating test expectations to enable CSP worker-src tests.

  • platform/ios-wk2/TestExpectations:
7:35 AM Changeset in webkit [292865] by zan@falconsigh.net
  • 3 edits in trunk

[GTK][WPE] Make the ENABLE_GPU_PROCESS CMake option depend on USE_ANGLE_WEBGL
https://bugs.webkit.org/show_bug.cgi?id=239330

Reviewed by Adrian Perez de Castro.

For the GTK and WPE ports, the ENABLE_GPU_PROCESS CMake option should
depend on the USE_ANGLE_WEBGL option being enabled. There's no plans
to support 'direct' GL execution in that process, and the ANGLE usage
also implies (for these two ports) usage of generic buffer solutions
that are shareable across process boundaries, as is necessary for a
functioning GPUProcess implementation.

  • Source/cmake/OptionsGTK.cmake:
  • Source/cmake/OptionsWPE.cmake:
7:13 AM Changeset in webkit [292864] by zan@falconsigh.net
  • 2 edits in trunk/Source/WebCore

[GTK][WPE] Provide WK2 IPC encoding, decoding methods for the DMABufObject type
https://bugs.webkit.org/show_bug.cgi?id=239038

Reviewed by Adrian Perez de Castro.

Provide encoding and decoding methods on the DMABufObject class,
enabling transport over IPC channels.

There are two separate ref-qualified encoding methods. When encoding
an object that's managed through an lvalue reference, we duplicate the
file descriptor objects since the DMABufObject will live on. When
managed through an rvalue object, we know the object's lifetime is
intended to be limited to this encoding process, so we can avoid the
file descriptor duplication and move the fd values into the encoder.

  • platform/graphics/gbm/DMABufObject.h:

(WebCore::DMABufObject::encode const):
(WebCore::DMABufObject::encode):
(WebCore::DMABufObject::decode):

7:12 AM Changeset in webkit [292863] by zan@falconsigh.net
  • 24 edits in trunk/Source

[WK2] Enable more efficient encoding of synchronous-message reply arguments
https://bugs.webkit.org/show_bug.cgi?id=238740
<rdar://problem/91567779>

Reviewed by Kimmo Kinnunen.

Source/WebKit:

Handling of synchronous messages requires construction of a
CompletionHandler object that wraps a lambda function which handles
logging of the passed-in reply arguments as well as subsequent encoding
and dispatching of the reply into the IPC channel.

Right now, for any given message the CompletionHandler type is generated
from the IPC message specification, and it's essentially a function type
with a void return value and const lvalue references for every
non-builtin parameter type. This type is imposed onto the lambda handler
and when invoked, all the reply arguments are passed on to the IPC
encoding as lvalue references.

This inhibits opportunities where the reply argument could instead be
moved into the completion handler invocation, enabling a more efficient
encoding of the passed-in value. For instance, if a Unix file descriptor
was moved into the completion handler invocation, it could be trickled
down into an IPC::Attachment object and dispatched over IPC without any
problems. Instead, because the lvalue reference is imposed as the type,
it will have to be duplicated even if the object itself is expiring or
would be movable down the invocation.

To cover these cases, the actual completion handler type is now deduced
from the synchronous-message-handling method itself. This means that
the completion handler parameter for the given handler method can now
specify whether it wants to receive reply arguments by value or by
either lvalue or rvalue reference. The completion handler lambda can
combine these parameter types with std::forward() to pass down the
actual arguments in the most optimal fashion.

To avoid problems, each CompletionHandler specialization retrieved from
the method siganture is validated against the CompletionHandler type
generated from the IPC specification, requiring that the decayed
parameter types match between the two. It's still possible to directly
use the CompletionHandler type from the IPC specification as the
completion handler type in the message-handling method.

An rvalue reference variant of ArgumentCoder<T>::encode() is added.
Generic implementation again casts the passed-in reference into an
rvalue and calls the encode() on that object. If that type provides
ref-qualified encode() methods, implementations of those methods can
adjust and more aggressively move things into the encoder when the
method is called on an rvalue. It would also be possible to delete the
ref-qualified method covering lvalues, meaning encoding would be allowed
only for objects that are moved into the completion handler.

For types with custom specializations of ArgumentCoder<T>, those
specializations would again have to provide rvalue variants of the
encode() method and handle the passed-in values appropriately.

The send() methods that were previously generated for every IPC message
are removed in favor of encoding and calling Connection::sendSyncReply()
in the completion-handler lambda. Missing std::forward() calls are added
in parameter pack expansions as required.

  • GPUProcess/media/RemoteCDMProxy.cpp:

(WebKit::RemoteCDMProxy::getSupportedConfiguration):

  • GPUProcess/media/RemoteCDMProxy.h:
  • GPUProcess/media/RemoteImageDecoderAVFProxy.cpp:

(WebKit::RemoteImageDecoderAVFProxy::createFrameImageAtIndex):

  • GPUProcess/media/RemoteImageDecoderAVFProxy.h:
  • Platform/IPC/ArgumentCoder.h:

(IPC::ArgumentCoder::encode):

  • Platform/IPC/HandleMessage.h:

(IPC::C::):
(IPC::CompletionHandlerValidation::matchingParameters):
(IPC::CompletionHandlerValidation::matchingTypes):
(IPC::handleMessageSynchronous):
(IPC::handleMessageSynchronousWantsConnection):
(IPC::handleMessageAsync):
(IPC::handleMessageAsyncWantsConnection):

  • Platform/IPC/StreamServerConnection.h:

(IPC::StreamServerConnection::sendSyncReply):

  • Scripts/webkit/messages.py:

(message_to_struct_declaration):
(generate_message_handler):

  • Scripts/webkit/tests/TestWithCVPixelBufferMessageReceiver.cpp:

(Messages::TestWithCVPixelBuffer::ReceiveCVPixelBuffer::send): Deleted.

  • Scripts/webkit/tests/TestWithCVPixelBufferMessages.h:
  • Scripts/webkit/tests/TestWithImageDataMessageReceiver.cpp:

(Messages::TestWithImageData::ReceiveImageData::send): Deleted.

  • Scripts/webkit/tests/TestWithImageDataMessages.h:
  • Scripts/webkit/tests/TestWithLegacyReceiverMessageReceiver.cpp:

(Messages::TestWithLegacyReceiver::CreatePlugin::send): Deleted.
(Messages::TestWithLegacyReceiver::RunJavaScriptAlert::send): Deleted.
(Messages::TestWithLegacyReceiver::GetPlugins::send): Deleted.
(Messages::TestWithLegacyReceiver::GetPluginProcessConnection::send): Deleted.
(Messages::TestWithLegacyReceiver::TestMultipleAttributes::send): Deleted.
(Messages::TestWithLegacyReceiver::InterpretKeyEvent::send): Deleted.

  • Scripts/webkit/tests/TestWithLegacyReceiverMessages.h:
  • Scripts/webkit/tests/TestWithSemaphoreMessageReceiver.cpp:

(Messages::TestWithSemaphore::ReceiveSemaphore::send): Deleted.

  • Scripts/webkit/tests/TestWithSemaphoreMessages.h:
  • Scripts/webkit/tests/TestWithSuperclassMessageReceiver.cpp:

(Messages::TestWithSuperclass::TestAsyncMessage::send): Deleted.
(Messages::TestWithSuperclass::TestAsyncMessageWithNoArguments::send): Deleted.
(Messages::TestWithSuperclass::TestAsyncMessageWithMultipleArguments::send): Deleted.
(Messages::TestWithSuperclass::TestAsyncMessageWithConnection::send): Deleted.
(Messages::TestWithSuperclass::TestSyncMessage::send): Deleted.
(Messages::TestWithSuperclass::TestSynchronousMessage::send): Deleted.

  • Scripts/webkit/tests/TestWithSuperclassMessages.h:
  • Scripts/webkit/tests/TestWithoutAttributesMessageReceiver.cpp:

(Messages::TestWithoutAttributes::CreatePlugin::send): Deleted.
(Messages::TestWithoutAttributes::RunJavaScriptAlert::send): Deleted.
(Messages::TestWithoutAttributes::GetPlugins::send): Deleted.
(Messages::TestWithoutAttributes::GetPluginProcessConnection::send): Deleted.
(Messages::TestWithoutAttributes::TestMultipleAttributes::send): Deleted.
(Messages::TestWithoutAttributes::InterpretKeyEvent::send): Deleted.

  • Scripts/webkit/tests/TestWithoutAttributesMessages.h:
  • UIProcess/ProvisionalPageProxy.cpp:

Add a missing include that brings in the definition of the
WebBackForwardListCounts type along with its encode() method.

Source/WTF:

Add two helper types, OutType and InTypes, on both CompletionHandler
classes. OutType is an alias against the return type of the invokable
handler, InTypes is a tuple with types corresponding to the parameter
types of the invokable handler.

These are especially helpful in various templates dealing with the
CompletionHandler types.

  • wtf/CompletionHandler.h:

(WTF::CompletionHandler):
(WTF::CompletionHandlerWithFinalizer):

6:23 AM Changeset in webkit [292862] by commit-queue@webkit.org
  • 3 edits in trunk/Source/WebKit

Some IPC related message forwarding functions use const lvalue references
https://bugs.webkit.org/show_bug.cgi?id=238937

Patch by Kimmo Kinnunen <kkinnunen@apple.com> on 2022-04-14
Reviewed by Antti Koivisto.

Passing the message as const lvalue reference prevents IPC messages to be
changed to support move semantics for some message arguments.

Fix by using universal references in the shell function signatures.
Forward the messages from one shell function to other as rvalue references
via WTFMove, since the messages are always such that they are forwarded so.
This also catches most such errors in the future.

No new tests, refactor.

  • Platform/IPC/MessageSender.h:

(IPC::MessageSender::send):
(IPC::MessageSender::sendSync):
(IPC::MessageSender::sendWithAsyncReply):

  • WebProcess/WebPage/DrawingArea.h:

(WebKit::DrawingArea::send):

1:48 AM Changeset in webkit [292861] by youenn@apple.com
  • 46 edits
    4 adds in trunk

Expose workers as service worker clients and implement registration matching for dedicated workers
https://bugs.webkit.org/show_bug.cgi?id=239066

Reviewed by Chris Dumez.

LayoutTests/imported/w3c:

  • web-platform-tests/service-workers/service-worker/local-url-inherit-controller.https-expected.txt:
  • web-platform-tests/service-workers/service-worker/worker-client-id.https-expected.txt:
  • web-platform-tests/service-workers/service-worker/worker-interception-redirect.https-expected.txt:
  • web-platform-tests/service-workers/service-worker/worker-interception.https-expected.txt:

Source/WebCore:

Add support for exposing workers (dedicated and shared) as service worker clients.
Add support for setting the controlling registration for dedicated workers
(a follow-up patch should handle shared workers).
To properly handle loads coming from a worker, we properly set clientIdentifier and registration identifier
from the worker context, instead of from the worker's document.

Small refactoring to pass additional data to worker through WorkerInitializationData.
This is used to set the context ID and context controlling service worker.

Adding a specific check in CachedResourceLoader to not reuse the cache in case the service worker modes are different.
A potential issue is that the service workers are the same (0) as one request is the main request
and the second request is the request triggered by service worker to answer the first request.

Properly support blob URL matching directly in WorkerScriptLoader for workers.

Test: http/wpt/service-workers/controlled-dedicatedworker.https.html

  • WebCore.xcodeproj/project.pbxproj:
  • dom/Document.h:
  • dom/ScriptExecutionContext.h:
  • loader/DocumentLoader.cpp:
  • loader/FetchOptions.h:
  • loader/ThreadableLoader.cpp:
  • loader/WorkerThreadableLoader.cpp:
  • loader/cache/CachedResourceLoader.cpp:
  • workers/DedicatedWorkerThread.cpp:
  • workers/Worker.cpp:
  • workers/Worker.h:
  • workers/WorkerGlobalScope.cpp:
  • workers/WorkerGlobalScope.h:
  • workers/WorkerGlobalScopeProxy.h:
  • workers/WorkerInitializationData.h: Added.
  • workers/WorkerMessagingProxy.cpp:
  • workers/WorkerMessagingProxy.h:
  • workers/WorkerOrWorkletGlobalScope.cpp:
  • workers/WorkerOrWorkletGlobalScope.h:
  • workers/WorkerScriptLoader.cpp:
  • workers/WorkerScriptLoader.h:
  • workers/WorkerThread.cpp:
  • workers/WorkerThread.h:
  • workers/service/SWClientConnection.cpp:
  • workers/service/ServiceWorker.h:
  • workers/service/ServiceWorkerClientData.cpp:
  • workers/service/ServiceWorkerClientType.h:
  • workers/service/ServiceWorkerContainer.cpp:
  • workers/service/context/ServiceWorkerThread.cpp:
  • workers/shared/SharedWorkerScriptLoader.h:
  • workers/shared/context/SharedWorkerThreadProxy.cpp:

Source/WebKit:

Reuse the same strategy for DedicatedWorkers as for Documents to match registrations and control then:

  • Do matching in network process
  • If matching, send a message to WebProcess to set the matching registration data.

Add specific handling for worker registration rematching in case of redirections:

  • If redirection comes from service worker (via respondWith), do rematching.
  • If redirection comes from network, do not do rematching.
  • NetworkProcess/NetworkResourceLoader.cpp:
  • NetworkProcess/ServiceWorker/ServiceWorkerFetchTask.cpp:
  • NetworkProcess/ServiceWorker/WebSWServerConnection.cpp:
  • WebProcess/Network/WebLoaderStrategy.cpp:
  • WebProcess/Storage/WebSWClientConnection.cpp:
  • WebProcess/Storage/WebSWClientConnection.h:
  • WebProcess/Storage/WebSWClientConnection.messages.in:

LayoutTests:

  • TestExpectations:
  • http/wpt/service-workers/controlled-dedicatedworker.https-expected.txt: Added.
  • http/wpt/service-workers/controlled-dedicatedworker.https.html: Added.
  • http/wpt/service-workers/resources/controlled-worker.js: Added.
12:16 AM Changeset in webkit [292860] by youenn@apple.com
  • 22 edits
    4 adds in trunk

A shared worker in a cached page should not allow the remote shared worker to continue executing
https://bugs.webkit.org/show_bug.cgi?id=239286

Reviewed by Chris Dumez.

Source/WebCore:

SharedWorker need to react to resume/suspend in case of page cache so that the corresponding
remote shared worker might get suspended if all its shared worker objects are suspended.

Test: http/tests/navigation/page-cache-shared-worker.html

  • workers/shared/SharedWorker.cpp:
  • workers/shared/SharedWorker.h:
  • workers/shared/SharedWorkerObjectConnection.h:
  • workers/shared/context/SharedWorkerContextManager.cpp:
  • workers/shared/context/SharedWorkerContextManager.h:

Source/WebKit:

Store whether shared worker objects are suspended or resumed.
If all objects are suspended, suspend the remote shared worker.
Otherwise, keep the remote shared worker live.
Add plumbing code to make this happen.

  • NetworkProcess/ServiceWorker/WebSWServerConnection.cpp:
  • NetworkProcess/SharedWorker/WebSharedWorker.cpp:
  • NetworkProcess/SharedWorker/WebSharedWorker.h:
  • NetworkProcess/SharedWorker/WebSharedWorkerServer.cpp:
  • NetworkProcess/SharedWorker/WebSharedWorkerServer.h:
  • NetworkProcess/SharedWorker/WebSharedWorkerServerConnection.cpp:
  • NetworkProcess/SharedWorker/WebSharedWorkerServerConnection.h:
  • NetworkProcess/SharedWorker/WebSharedWorkerServerConnection.messages.in:
  • NetworkProcess/SharedWorker/WebSharedWorkerServerToContextConnection.cpp:
  • NetworkProcess/SharedWorker/WebSharedWorkerServerToContextConnection.h:
  • WebProcess/Storage/WebSharedWorkerContextManagerConnection.messages.in:
  • WebProcess/Storage/WebSharedWorkerObjectConnection.cpp:
  • WebProcess/Storage/WebSharedWorkerObjectConnection.h:

LayoutTests:

  • http/tests/navigation/page-cache-shared-worker-expected.txt: Added.
  • http/tests/navigation/page-cache-shared-worker.html: Added.
  • http/tests/navigation/resources/page-cache-helper-for-sharedworker.html: Added.
  • http/tests/navigation/resources/shared-worker-script.js: Added.
  • platform/mac-wk1/TestExpectations:
  • platform/win/TestExpectations:

Apr 13, 2022:

11:19 PM Changeset in webkit [292859] by mmaxfield@apple.com
  • 15 edits
    2 deletes in trunk

Revert r291846 because it caused a 3% performance regression
https://bugs.webkit.org/show_bug.cgi?id=239323
<rdar://problem/91046238>

Rubber-stamped by Stephanie Lewis.

Source/WebCore:

I'm having trouble figuring out why this caused a regression, so I'm reverting the patch
wholesale while I can do more investigation.

  • platform/graphics/cocoa/FontCacheCoreText.cpp:

(WebCore::normalizeWeight):
(WebCore::denormalizeWeight):
(WebCore::preparePlatformFont):
(WebCore::fontCacheRegisteredFontsChangedNotificationCallback):
(WebCore::FontCache::platformInit):
(WebCore::variationCapabilitiesForFontDescriptor):
(WebCore::normalizeGXWeight): Deleted.
(WebCore::normalizeCTWeight): Deleted.
(WebCore::denormalizeGXWeight): Deleted.
(WebCore::denormalizeCTWeight): Deleted.
(WebCore::overrideEnhanceTextLegibility): Deleted.
(WebCore::setOverrideEnhanceTextLegibility): Deleted.
(WebCore::shouldEnhanceTextLegibility): Deleted.

  • platform/graphics/cocoa/FontCacheCoreText.h:
  • testing/Internals.cpp:

(WebCore::Internals::setOverrideEnhanceTextLegibility): Deleted.

  • testing/Internals.h:
  • testing/Internals.idl:

Source/WebCore/PAL:

  • pal/spi/cf/CoreTextSPI.h:
  • pal/spi/cocoa/AccessibilitySupportSPI.h:

LayoutTests:

  • TestExpectations:
  • fast/text/accessibility-bold-expected-mismatch.html: Removed.
  • fast/text/accessibility-bold.html: Removed.
  • platform/ios-wk2/TestExpectations:
  • platform/ios/TestExpectations:
  • platform/mac-wk2/TestExpectations:
  • platform/mac/TestExpectations:
11:11 PM Changeset in webkit [292858] by graouts@webkit.org
  • 3 edits
    2 adds in trunk

[web-animations] REGRESSION(r291527): assertion hit during teardown of document with CSS Animations
https://bugs.webkit.org/show_bug.cgi?id=239291
rdar://90699078

Reviewed by Dean Jackson.

Source/WebCore:

When a CSS Animation is not considered to be relevant anymore, it is removed from both AnimationTimeline::m_animations
and Styleable::animations(). However, if that animation becomes relevant again, it will be added back to the associated
effect stack as well as AnimationTimeline::m_animations but not to Styleable::animations().

This causes a problem because when eventually that CSS Animation's target is removed from the tree, such as during
document teardown, Styleable::cancelDeclarativeAnimations() will be called an iterate over Styleable::animations()
to find declarative animations to cancel. Since the CSS animation was not added to Styleable::animations(), it will
not be canceled and the associated effect will not be removed from the effect stack.

Later in Styleable::cancelDeclarativeAnimations(), the list of associated CSS Animation names is cleared.

If during that teardown an animation resolution is performed, such as within a "beforeunload" event listener as
shown in the new test, we will get into a state where there are effects left in the effect stack of the element
being torn down but no associated CSS Animation names and we will hit the RELEASE_ASSERT_NOT_REACHED() at the
end of compareCSSAnimations().

To fix this, we simply ensure that we add animations back to Styleable::animations() within
AnimationTimeline::animationTimingDidChange() the same way we add the animations back to
AnimationTimeline::m_animations.

Test: webanimations/css-animation-resolution-during-teardown.html

  • animation/AnimationTimeline.cpp:

(WebCore::AnimationTimeline::animationTimingDidChange):

LayoutTests:

Add a new test that would have asserted prior to the source change.

  • webanimations/css-animation-resolution-during-teardown-expected.txt: Added.
  • webanimations/css-animation-resolution-during-teardown.html: Added.
9:50 PM Changeset in webkit [292857] by Chris Dumez
  • 87 edits in trunk

Replace calls to substring(0, x) with the more concise left(x)
https://bugs.webkit.org/show_bug.cgi?id=239306

Reviewed by Darin Adler.

Source/JavaScriptCore:

  • inspector/ScriptArguments.h:
  • runtime/ExceptionHelpers.cpp:

(JSC::clampErrorMessage):

  • runtime/IntlNumberFormat.cpp:

(JSC::wellFormedUnitIdentifier):

  • runtime/IntlObject.cpp:

(JSC::resolveLocale):

  • runtime/IntlObjectInlines.h:

(JSC::bestAvailableLocale):

Source/WebCore:

Replace calls to substring(0, x) with the more concise left(x). Also use StringView in more cases
for performance.

  • Modules/fetch/FetchBodyConsumer.cpp:

(WebCore::parseMIMEType):

  • Modules/indexeddb/IDBCursor.cpp:

(WebCore::IDBCursor::setGetResult):

  • Modules/indexeddb/IDBKeyPath.cpp:

(WebCore::IDBKeyPathLexer::lexIdentifier):

  • Modules/mediastream/PeerConnectionBackend.cpp:

(WebCore::shouldIgnoreIceCandidate):

  • Modules/mediastream/RTCDTMFSender.cpp:

(WebCore::RTCDTMFSender::playNextTone):

  • Modules/mediastream/gstreamer/GStreamerMediaEndpoint.cpp:

(WebCore::GStreamerMediaEndpoint::addRemoteStream):

  • Modules/mediastream/libwebrtc/LibWebRTCRtpTransceiverBackend.cpp:

(WebCore::toRtpCodecCapability):

  • Modules/plugins/YouTubePluginReplacement.cpp:

(WebCore::processAndCreateYouTubeURL):
(WebCore::YouTubePluginReplacement::youTubeURLFromAbsoluteURL):

  • display/css/DisplayTextBox.cpp:

(WebCore::Display::TextBox::debugDescription const):

  • dom/Document.cpp:

(WebCore::Document::parseQualifiedName):

  • dom/Text.cpp:

(WebCore::Text::splitText):

  • editing/TextCheckingHelper.cpp:

(WebCore::checkTextOfParagraph):

  • editing/TextIterator.cpp:

(WebCore::SearchBuffer::prependContext):

  • editing/VisibleUnits.cpp:

(WebCore::suffixLengthForRange):
(WebCore::startWordBoundary):
(WebCore::previousWordPositionBoundary):

  • editing/cocoa/DataDetection.mm:

(WebCore::DataDetection::detectContentInRange):

  • editing/markup.cpp:

(WebCore::shouldPreserveMSOLists):

  • html/FeaturePolicy.cpp:

(WebCore::updateList):

  • html/HTMLMediaElement.cpp:

(WTF::LogArgument<URL>::toString):

  • html/HTMLTrackElement.cpp:

(WebCore::urlForLoggingTrack):

  • html/URLDecomposition.cpp:

(WebCore::URLDecomposition::setHost):

  • html/parser/HTMLParserIdioms.cpp:

(WebCore::parseHTTPRefreshInternal):

  • html/parser/HTMLSrcsetParser.cpp:

(WebCore::parseDescriptors):

  • html/parser/HTMLTreeBuilder.cpp:

(WebCore::HTMLTreeBuilder::ExternalCharacterTokenBuffer::characterPredicate):

  • inspector/InspectorStyleSheet.cpp:

(WebCore::StyleSheetHandler::observeComment):

  • layout/layouttree/LayoutTreeBuilder.cpp:

(WebCore::Layout::outputLayoutBox):

  • loader/appcache/ApplicationCacheManifestParser.cpp:

(WebCore::manifestPath):

  • mathml/MathMLPresentationElement.cpp:

(WebCore::MathMLPresentationElement::parseNumberAndUnit):

  • page/Frame.cpp:

(WebCore::createRegExpForLabels):

  • page/SecurityOriginData.cpp:

(WebCore::SecurityOriginData::fromDatabaseIdentifier):

  • platform/SharedStringHash.cpp:

(WebCore::computeSharedStringHashInline):

  • platform/graphics/StringTruncator.cpp:

(WebCore::centerTruncateToBuffer):
(WebCore::rightTruncateToBuffer):
(WebCore::rightClipToCharacterBuffer):
(WebCore::rightClipToWordBuffer):

  • platform/graphics/gstreamer/MediaPlayerPrivateGStreamer.cpp:

(WebCore::MediaPlayerPrivateGStreamer::setPlaybinURL):

  • platform/graphics/gstreamer/mse/SourceBufferPrivateGStreamer.cpp:

(WebCore::SourceBufferPrivateGStreamer::platformMaximumBufferSize const):

  • platform/graphics/win/FontCacheWin.cpp:

(WebCore::createGDIFont):
(WebCore::FontCache::getFontSelectionCapabilitiesInFamily):

  • platform/ios/UserAgentIOS.mm:

(WebCore::deviceNameForUserAgent):

  • platform/network/CacheValidation.cpp:

(WebCore::trimToNextSeparator):
(WebCore::parseCacheHeader):

  • platform/network/CredentialStorage.cpp:

(WebCore::protectionSpaceMapKeyFromURL):
(WebCore::CredentialStorage::findDefaultProtectionSpaceForURL):

  • platform/network/DataURLDecoder.cpp:

(WebCore::DataURLDecoder::DecodeTask::process):

  • platform/network/HTTPParsers.cpp:

(WebCore::parseStructuredFieldValue):

  • platform/network/MIMEHeader.cpp:

(WebCore::retrieveKeyValuePairs):

  • platform/network/curl/CookieUtil.cpp:

(WebCore::CookieUtil::parseCookieAttributes):
(WebCore::CookieUtil::parseCookieHeader):
(WebCore::CookieUtil::defaultPathForURL):

  • platform/text/LocaleToScriptMapping.cpp:

(WebCore::localeToScriptCodeForFontSelection):

  • platform/win/PasteboardWin.cpp:

(WebCore::fileSystemPathFromURLOrTitle):
(WebCore::Pasteboard::writeURLToDataObject):
(WebCore::createGlobalImageFileDescriptor):

  • platform/win/WebCoreTextRenderer.cpp:

(WebCore::doDrawTextAtPoint):

  • rendering/RenderObject.cpp:

(WebCore::RenderObject::outputRenderObject const):

  • rendering/style/GridPositionsResolver.cpp:

(WebCore::NamedLineCollectionBase::NamedLineCollectionBase):

  • svg/SVGTests.cpp:

(WebCore::SVGTests::isValid const):

  • svg/SVGURIReference.cpp:

(WebCore::SVGURIReference::fragmentIdentifierFromIRIString):

  • svg/animation/SVGSMILElement.cpp:

(WebCore::SVGSMILElement::parseClockValue):

  • workers/service/ServiceWorkerJob.cpp:

(WebCore::ServiceWorkerJob::validateServiceWorkerResponse):

  • workers/service/ServiceWorkerRegistrationKey.cpp:

(WebCore::ServiceWorkerRegistrationKey::fromDatabaseKey):

  • workers/service/server/SWServer.cpp:

(WebCore::SWServer::canHandleScheme const):

Source/WebDriver:

  • CommandResult.cpp:

(WebDriver::CommandResult::CommandResult):

Source/WebKit:

  • NetworkProcess/WebStorage/LocalStorageDatabaseTracker.cpp:

(WebKit::LocalStorageDatabaseTracker::origins const):

  • NetworkProcess/cache/NetworkCacheStorage.cpp:

(WebKit::NetworkCache::traverseRecordsFiles):

  • NetworkProcess/storage/LocalStorageManager.cpp:

(WebKit::fileNameToOrigin):

  • Shared/API/c/WKString.cpp:

(WKStringGetCharacters):

  • UIProcess/API/glib/InputMethodFilter.cpp:

(WebKit::InputMethodFilter::notifySurrounding):

  • UIProcess/gtk/GtkSettingsManager.cpp:

(WebKit::GtkSettingsManager::themeName const):

  • UIProcess/gtk/TextCheckerGtk.cpp:

(WebKit::TextChecker::checkTextOfParagraph):

  • UIProcess/win/WebProcessPoolWin.cpp:

(WebKit::initializeRemoteInspectorServer):

Source/WebKitLegacy:

  • Storage/StorageTracker.cpp:

(WebKit::StorageTracker::syncFileSystemAndTrackerDatabase):

Source/WebKitLegacy/mac:

  • WebView/WebHTMLRepresentation.mm:

(regExpForLabels):

Source/WTF:

  • wtf/URL.cpp:

(WTF::URL::protocol const):
(WTF::URL::protocolHostAndPort const):
(WTF::URL::setProtocol):
(WTF::URL::setHost):
(WTF::URL::setHostAndPort):
(WTF::URL::strippedForUseAsReferrer const):

  • wtf/URLParser.cpp:

(WTF::URLParser::addNonSpecialDotSlash):
(WTF::URLParser::parseURLEncodedForm):

  • wtf/UUID.cpp:

(WTF::UUID::parse):

  • wtf/text/WTFString.cpp:

(WTF::String::insert):

  • wtf/text/WTFString.h:

Tools:

  • DumpRenderTree/win/DumpRenderTree.cpp:

(findFontFallback):

  • TestWebKitAPI/Tests/WTF/URLParser.cpp:

(TestWebKitAPI::insertTabAtLocation):

  • TestWebKitAPI/Tests/WebCore/FileMonitor.cpp:

(TestWebKitAPI::readContentsOfFile):

  • TestWebKitAPI/Tests/WebCore/HTTPHeaderField.cpp:

(canonicalizeHTTPHeader):

  • TestWebKitAPI/Tests/WebCore/URLParserTextEncoding.cpp:

(TestWebKitAPI::insertTabAtLocation):

  • WebKitTestRunner/InjectedBundle/InjectedBundlePage.cpp:

(WTR::pathSuitableForTestResult):
(WTR::dumpFrameText):
(WTR::stripTrailingSpacesAddNewline):
(WTR::InjectedBundlePage::willAddMessageToConsole):

9:38 PM Changeset in webkit [292856] by commit-queue@webkit.org
  • 4 edits in trunk

Punycode encode U+15AF when not in context of other Canadian aboriginal code points
https://bugs.webkit.org/show_bug.cgi?id=239316
<rdar://91248059>

Patch by Alex Christensen <achristensen@webkit.org> on 2022-04-13
Reviewed by Darin Adler.

Source/WTF:

  • wtf/URLHelpers.cpp:

(WTF::URLHelpers::isLookalikeCharacterOfScriptType<USCRIPT_CANADIAN_ABORIGINAL>):
(WTF::URLHelpers::isLookalikeCharacter):

Tools:

  • TestWebKitAPI/Tests/WTF/cocoa/URLExtras.mm:

(TestWebKitAPI::TEST):

8:56 PM Changeset in webkit [292855] by Alan Bujtas
  • 5 edits
    2 adds in trunk

REGRESSION (r292043): [ Mac ] fast/block/positioning/fixed-container-with-relative-parent.html is a flaky image failure
https://bugs.webkit.org/show_bug.cgi?id=239101
<rdar://problem/91603539>

Reviewed by Antti Koivisto.

Source/WebCore:

  1. Out of flow boxes are laid out independently from each other as the last step of their containing block layout.
  2. However their static positions are computed during regular in-flow layout (as if their positions were static).

In order to do #1, we maintain a ListHashSet for the out-of-flow boxes and insert them at #2 (and we also have
a corresponding HashMap<ContainingBlock, ListHasSet>).

Normally this is a very simple list of descendant positioned boxes and since out-of-flow boxes don't interact with each
other, their position in the list is not important.

e.g.

<div id=A style="position: relative">

<div>

<div id=B style="position: absolute"></div>
<div id=C style="position: absolute"></div>

</div>

</div>

At in-flow layout (#2), we insert B and C to "ListHashSet of A" as we come across them in DOM order and compute their static positions.
Later in the layout flow when we get to the "let's layout the out-of-flow boxes" phase (#1) we simply walk
the ListHashSet and lay out B and C (but "C and B" order would also work just fine).

However the ICB (RenderView) is a special containing block as it can hold different types of out-of-flow boxes (absolute and fixed)
and those out-of-flow boxes may have layout dependencies.
e.g.

<body><div id=A class=absolute><div id=B class=fixed></div></div></body>

ICB's ListHasSet has both A and B, but in this case there's (static)layout dependency between these boxes.
In order to figure out the static position of B, we have to have A laid out first. In order to lay out A before B,
B has to be preceded by A in ICB's ListHasSet.

Now full layout always guarantees the correct order.
However in case of partial layout since we don't run a full #2, the ListHasSet may end up having an unexpected order.

e.g.

<body><div id=A class=absolute><div id=B><div id=C class=fixed></div></div></div></body>

  1. The initial (full) layout produces the following (correct) order for the ICB's ListHasSet -> AC.
  2. A subsequent partial layout (e.g. triggered by A's position change) runs an in-flow layout on the <body> which (re-)appends A to the ListHasSet (CA <- incorrect order). Now at this point we assume that the in-flow layout picks up B which eventually (re-)appends C to the ListHashSet (AC <- correct order). However since B does not need layout, we just stop at <body> which leaves us with an unexpected ListHashSet.
  3. As part of the ICB's out-of-flow layout, we pick C as the first box to lay out followed by A. However since C's static position depends on A's position, we end up using stale geometry when computing C's static position.

This patch fixes this issue by ensuring the absolute positioned boxes always come first in the ICB's ListHasSet (note
that their order is not really important -see above. What's important is that a potential (as-if-static) containing block always
comes before the fixed boxes).

Test: fast/block/fixed-inside-absolute-positioned.html

  • rendering/RenderBlock.cpp:

(WebCore::PositionedDescendantsMap::addDescendant):
(WebCore::RenderBlock::insertPositionedObject):

LayoutTests:

  • fast/block/fixed-inside-absolute-positioned-expected.html: Added.
  • fast/block/fixed-inside-absolute-positioned.html: Added.
  • platform/mac-wk1/TestExpectations:
8:55 PM Changeset in webkit [292854] by Chris Dumez
  • 59 edits in trunk/Source/WebCore

Use [AtomString] where appropriate in IDL files for performance
https://bugs.webkit.org/show_bug.cgi?id=239314

Reviewed by Alexey Shvayka.

Use [AtomString] where appropriate in IDL files for performance. I added [AtomString] on the
IDL side whenever our C++ implementation uses AtomString.

Without this, the generated bindings code will generate a String, which will then get atomized
once passed to our implementation. This means we're doing unnecessary String allocations in
cases where the AtomString is already in the AtomStringTable.

  • dom/Attr.idl:
  • dom/Document+HTML.idl:
  • dom/Document.cpp:

(WebCore::Document::createAttribute):

  • dom/Document.h:
  • dom/Document.idl:
  • dom/Element.cpp:

(WebCore::Element::getAttribute const):

  • dom/Element.idl:
  • dom/ElementContentEditable.idl:
  • dom/Event.idl:
  • dom/FocusEvent.idl:
  • dom/FormDataEvent.idl:
  • dom/HashChangeEvent.idl:
  • dom/InputEvent.idl:
  • dom/KeyboardEvent.idl:
  • dom/MessageEvent.idl:
  • dom/MouseEvent.idl:
  • dom/MutationEvent.idl:
  • dom/NamedNodeMap.idl:
  • dom/Node.idl:
  • dom/OverflowEvent.idl:
  • dom/PageTransitionEvent.idl:
  • dom/PointerEvent.idl:
  • dom/ProgressEvent.idl:
  • dom/PromiseRejectionEvent.idl:
  • dom/SecurityPolicyViolationEvent.idl:
  • dom/TextEvent.idl:
  • dom/TouchEvent.idl:
  • dom/TransitionEvent.idl:
  • dom/UIEvent.idl:
  • dom/WheelEvent.idl:
  • html/HTMLButtonElement.idl:
  • html/HTMLDocument.idl:
  • html/HTMLElement.idl:
  • html/HTMLFormElement.idl:
  • html/HTMLImageElement.idl:
  • html/HTMLInputElement.idl:
  • html/HTMLLinkElement.idl:
  • html/HTMLMediaElement.idl:
  • html/HTMLScriptElement.idl:
  • html/HTMLTableCellElement.idl:
  • html/HTMLTrackElement.idl:
  • html/MediaEncryptedEvent.idl:
  • html/SubmitEvent.idl:
  • html/track/AudioTrack.idl:
  • html/track/AudioTrackList.idl:
  • html/track/TextTrack.idl:
  • html/track/TextTrackList.idl:
  • html/track/VTTRegion.idl:
  • html/track/VideoTrack.idl:
  • html/track/VideoTrackList.idl:
  • page/DOMWindow.idl:
  • page/UserMessageHandlersNamespace.idl:
  • storage/StorageEvent.idl:
  • svg/SVGAltGlyphElement.idl:
  • svg/SVGStyleElement.idl:
  • workers/service/ExtendableEvent.idl:
  • workers/service/ExtendableMessageEvent.idl:
  • workers/service/FetchEvent.idl:
7:34 PM Changeset in webkit [292853] by Matteo Flores
  • 2 edits in trunk/Tools

[ iOS ] TestWebKitAPI.WebKit2.CrashGPUProcessWhileCapturing is a flaky timeout https://bugs.webkit.org/show_bug.cgi?id=239315 Unreviewed test gardening. * TestWebKitAPI/Tests/WebKit/GetUserMedia.mm:

7:24 PM Changeset in webkit [292852] by Matteo Flores
  • 2 edits in trunk/Tools

[ iOS ] TestWebKitAPI.WebKit2.CrashGPUProcessWhileCapturingAndCalling is a flaky timeout https://bugs.webkit.org/show_bug.cgi?id=239309 Unreviewed test gardening. * TestWebKitAPI/Tests/WebKit/GetUserMedia.mm: Disabling test to help EWS

7:02 PM Changeset in webkit [292851] by Matteo Flores
  • 2 edits in trunk/Tools

[ iOS ] TestWebKitAPI.SOAuthorizationSubFrame.InterceptionErrorWithReferrer is a flaky timeout https://bugs.webkit.org/show_bug.cgi?id=239311 Unreviewed test gardening * TestWebKitAPI/Tests/WebKitCocoa/TestSOAuthorization.mm: Disabling the test to help EWS (TestWebKitAPI::TEST):

6:50 PM Changeset in webkit [292850] by Matteo Flores
  • 2 edits in trunk/Tools

REGRESSION(r292401-r292310): [ iOS ] TestWebKitAPI.GPUProcess.CanvasBasicCrashHandling is a constant failure on iOS https://bugs.webkit.org/show_bug.cgi?id=239303 Unreviewed test gardening. * TestWebKitAPI/Tests/WebKitCocoa/GPUProcess.mm: Disabling the test to help EWS (TEST):

6:30 PM Changeset in webkit [292849] by Matteo Flores
  • 2 edits in trunk/Tools

[ iOS ] TestWebKitAPI.IndexedDB.IndexedDBSuspendImminently is a constant timeout https://bugs.webkit.org/show_bug.cgi?id=239310 Unreviewed test gardening. * TestWebKitAPI/Tests/WebKitCocoa/IndexedDBSuspendImminently.mm: Disabling the test (TEST):

6:18 PM Changeset in webkit [292848] by Kocsen Chung
  • 1 copy in tags/WebKit-7613.2.6.0.1

Tag WebKit-7613.2.6.0.1.

6:05 PM Changeset in webkit [292847] by Kocsen Chung
  • 1 copy in tags/WebKit-7613.2.6.1.1

Tag WebKit-7613.2.6.1.1.

5:52 PM Changeset in webkit [292846] by achristensen@apple.com
  • 3 edits in trunk/Source/WebKit

Adjust when _setPrivacyProxyFailClosedForUnreachableNonMainHosts is called
https://bugs.webkit.org/show_bug.cgi?id=237735

Reviewed by Geoff Garen.

This is recommitting http://trac.webkit.org/r291598 but leaving the definition of PrivateRelayed::Yes and ::No
based on whether metrics._privacyStance == nw_connection_privacy_stance_direct instead of nw_connection_privacy_stance_failed.
It has flip flopped several times in the various related commits, but it needs to be nw_connection_privacy_stance_direct.
I manually verified that this fixes <rdar://88965550> without reintroducing <rdar://90677955>.

  • NetworkProcess/cocoa/NetworkDataTaskCocoa.mm:

(WebKit::NetworkDataTaskCocoa::NetworkDataTaskCocoa):

  • NetworkProcess/cocoa/NetworkSessionCocoa.mm:

(-[WKNetworkSessionDelegate URLSession:dataTask:didReceiveResponse:completionHandler:]):
(WebKit::NetworkSessionCocoa::createWebSocketTask):

5:15 PM Changeset in webkit [292845] by Elliott Williams
  • 16 edits in trunk

[Xcode] Fix public watchOS workspace build by updating scheme and build settings
https://bugs.webkit.org/show_bug.cgi?id=239301

Reviewed by Alexey Proskuryakov.

.:

Add AD_HOC_CODE_SIGNING_ALLOWED=YES (similar to
https://commits.webkit.org/249449@main) and
DISABLE_SDK_METADATA_PARSING=YES in various places to work around
open-source workspace build failures when building for watchOS.

  • WebKit.xcworkspace/xcshareddata/xcschemes/All Source.xcscheme:
  • Remove libwebrtc from the "All Source" scheme. On watchOS, it doesn't

build, and on other platforms, it is an implicit dependency, so
removing it lets the build system determine whether or not it should
build.

  • Remove MiniBrowser from the "All Source" scheme, as it's part of "All

Tools". "All Tools" probably shouldn't be built for embedded
platforms, as it contains some Mac-only tools, but we do not enforce
this.

Source/WebCore:

  • Configurations/Base.xcconfig:
  • Configurations/WebCore.xcconfig:
  • Configurations/WebCoreTestSupport.xcconfig:

Source/WebGPU:

  • Configurations/Base.xcconfig:
  • Configurations/WebGPU.xcconfig:

Source/WebInspectorUI:

  • Configurations/Base.xcconfig:

Source/WebKit:

  • Configurations/WebKit.xcconfig:

Source/WebKitLegacy/mac:

  • Configurations/Base.xcconfig:
  • Configurations/WebKitLegacy.xcconfig:
4:43 PM Changeset in webkit [292844] by Jonathan Bedard
  • 6 edits in trunk/Tools

[git-webkit] Found branch name instead of hash
https://bugs.webkit.org/show_bug.cgi?id=239296
<rdar://problem/91720224>

Reviewed by Michael Catanzaro.

  • Tools/Scripts/libraries/webkitscmpy/setup.py: Bump version.
  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/init.py: Ditto.
  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/local/git.py:

(Git.Cache.populate): Add --no-decorate to git log command.
(Git.commit): Ditto.
(Git.commits): Ditto.

  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/mocks/local/git.py:
  • Tools/Scripts/libraries/webkitscmpy/webkitscmpy/test/git_unittest.py:

(TestGit.test_log): Ditto.

Canonical link: https://commits.webkit.org/249617@main

4:24 PM Changeset in webkit [292843] by Ross Kirsling
  • 4 edits
    1 add in trunk/Tools

Add PlayStation builds to bot watcher's dashboard.
https://bugs.webkit.org/show_bug.cgi?id=239090

Reviewed by Jonathan Bedard.

  • Tools/CISupport/build-webkit-org/public_html/dashboard/Images/PlayStation.png: Added.
  • Tools/CISupport/build-webkit-org/public_html/dashboard/Scripts/Dashboard.js:
  • Tools/CISupport/build-webkit-org/public_html/dashboard/Scripts/WebKitBuildbot.js:

(WebKitBuildbot):

  • Tools/CISupport/build-webkit-org/public_html/dashboard/Styles/Main.css:

(table.queue-grid tr.platform.playstation img.logo):

Canonical link: https://commits.webkit.org/249616@main

4:17 PM Changeset in webkit [292842] by Chris Dumez
  • 2 edits in trunk/Source/WebKit

WebContent crashes with SIGTERM_TIMEOUT on macOS
https://bugs.webkit.org/show_bug.cgi?id=239298
<rdar://90665705>

Reviewed by Darin Adler.

To make sure that WebProcesses cannot use any CPU time while in the WebProcess cache on macOS, I recently tried to
suspend these cached processes. However, since we haven't adopted RunningBoard on macOS yet, I was doing suspension
and resuming manually via the SIGSTOP & SIGCONT signals. While this properly suspended our cached processes, this
introduced SIGTERM_TIMEOUT crashes and potential delays when exiting Safari or logging out of macOS while Safari is
running. This is because our cached & suspended processes are unable to process the SIGTERM signal they receive and
thus don't cleanly exit. After a timeout, the system forcefully kills them and generates a crash log with
SIGTERM_TIMEOUT to let us know.

To address the issue, I am disabling the WebProcess suspension logic that I recently added. We can reconsider doing
something like this once we adopt RunningBoard on macOS, assuming the same issue doesn't affect suspension via
RunningBoard.

  • UIProcess/mac/WebProcessProxyMac.mm:

(WebKit::WebProcessProxy::platformSuspendProcess):
(WebKit::WebProcessProxy::platformResumeProcess):

4:14 PM Changeset in webkit [292841] by commit-queue@webkit.org
  • 2 edits in trunk/Source/JavaScriptCore

GCC 12 -Wdangling-pointer warning spam from AbstractSlotVisitorInlines.h
https://bugs.webkit.org/show_bug.cgi?id=239299

Patch by Michael Catanzaro <mcatanzaro@redhat.com> on 2022-04-13
Reviewed by Mark Lam.

Suppress this warning, so we can see other warnings.

  • heap/AbstractSlotVisitorInlines.h:

(JSC::AbstractSlotVisitor::ReferrerContext::ReferrerContext):

3:55 PM Changeset in webkit [292840] by commit-queue@webkit.org
  • 14 edits in trunk/Source

Misc compiler warnings, April 2022 edition
https://bugs.webkit.org/show_bug.cgi?id=239290

Patch by Michael Catanzaro <Michael Catanzaro> on 2022-04-13
Reviewed by Adrian Perez de Castro.

Fix the usual spam of -Wreturn-type warnings.

Bonus warnings: unused variable, unknown pragmas, and redundant move.

  • Source/JavaScriptCore/bytecode/PropertyCondition.cpp:

(JSC::PropertyCondition::isStillValidAssumingImpurePropertyWatchpoint const):
(JSC::watchabilityToConcurrency):
(JSC::PropertyCondition::validityRequiresImpurePropertyWatchpoint const):

  • Source/JavaScriptCore/runtime/JSObject.h:

(JSC::JSObject::getDirect const):

  • Source/JavaScriptCore/runtime/Structure.h:

(JSC::Structure::get):

  • Source/WebKit/NetworkProcess/storage/OriginStorageManager.cpp:

(WebKit::OriginStorageManager::StorageBucket::resolvedPath):

  • Source/WebCore/dom/ScriptExecutionContext.cpp:

(WebCore::ScriptExecutionContext::canAccessResource const):

  • Source/WebCore/page/DebugPageOverlays.cpp:
  • Source/WebCore/page/InteractionRegion.cpp:

(WebCore::regionForElement):

  • Source/WebCore/platform/graphics/GraphicsContextState.cpp:

(WebCore::stateChangeName):

  • Source/WebCore/rendering/style/RenderStyle.cpp:

(WebCore::getPathFromPathOperation):

  • Source/WebCore/style/ContainerQueryEvaluator.cpp:

(WebCore::Style::ContainerQueryEvaluator::evaluateSizeFeature const):

  • Source/WebCore/testing/Internals.cpp:

(WebCore::Internals::categoryAtMostRecentPlayback const):

Canonical link: https://commits.webkit.org/249613@main

3:50 PM Changeset in webkit [292839] by Truitt Savell
  • 2 edits in trunk/LayoutTests

[ Monterey WK2 ] media/media-source/media-source-webm-vorbis-partial.html is a constant failure
https://bugs.webkit.org/show_bug.cgi?id=239308

Unreviewed test gardening

  • platform/mac-wk2/TestExpectations:
3:50 PM Changeset in webkit [292838] by Diego Pino Garcia
  • 2 edits in trunk/Source/WebCore

Unreviewed, fix non-unified build after r292810

  • editing/HTMLInterchange.h:
3:47 PM Changeset in webkit [292837] by Andres Gonzalez
  • 1 edit
    2 adds
    2 deletes in trunk/LayoutTests

Rewrite accessibility/mac/stale-table-rows.html to properly check that the number of rows and columns are correct after grid changes.
https://bugs.webkit.org/show_bug.cgi?id=239292
<rdar://problem/91705969>

Reviewed by Chris Fleizach.

This test had a weak success criterion that was passing when two
expressions were equal without checking the actual value of the
expressions, which was incorrect in isolated tree mode. This is a
rewrite of the test that makes the success criteria more strict and
modernize the test to be async so that it can pass in isolated tree
mode. In addition, renamed the test to better reflect what it is
actually doing.

  • accessibility/mac/grid-add-remove-rows-expected.txt: Added.
  • accessibility/mac/grid-add-remove-rows.html: Added.
  • accessibility/mac/stale-table-rows-expected.txt: Renamed to above.
  • accessibility/mac/stale-table-rows.html: Renamed to above.
3:44 PM Changeset in webkit [292836] by sihui_liu@apple.com
  • 2 edits in trunk/Source/WebCore

StorageMap::importItems may update currentSize wrongly in release build
https://bugs.webkit.org/show_bug.cgi?id=239255

Reviewed by Chris Dumez.

StorageMap::importItems() has a debug assertion that keys of imported items do not exist in map, but that does
not prevent this from happening in release build. With our current implementation, if this happens in release
build, we increase currentSize without updating the map, which may lead to overflow.

To make StorageMap more safe to use, we can calculate the correct currentSize based on size of exsiting item, as
in StorageMap::setItem(), or we just don't update currentSize or map if key already exists. Since current users
of StorageMap should only call importItems() when the map is empty, we can add an early return if map is not
empty.

  • storage/StorageMap.cpp:

(WebCore::StorageMap::importItems):

3:43 PM Changeset in webkit [292835] by Karl Rackler
  • 2 edits in trunk/LayoutTests

[ Monterey wk2 release ] imported/w3c/web-platform-tests/content-security-policy/inheritance/blob-url-inherits-from-initiator.sub.html is a flaky crash
https://bugs.webkit.org/show_bug.cgi?id=239307

Unreviewed test gardening.

  • platform/mac-wk2/TestExpectations:
3:22 PM Changeset in webkit [292834] by commit-queue@webkit.org
  • 5 edits
    2 deletes in trunk

Unreviewed, reverting r292817.
https://bugs.webkit.org/show_bug.cgi?id=239305

some dialog tests are asserting

Reverted changeset:

"REGRESSION (r292043): [ Mac ] fast/block/positioning/fixed-
container-with-relative-parent.html is a flaky image failure"
https://bugs.webkit.org/show_bug.cgi?id=239101
https://commits.webkit.org/r292817

3:04 PM Changeset in webkit [292833] by Karl Rackler
  • 2 edits in trunk/LayoutTests

[ Mac wk2 ] http/tests/cache-storage/cache-origins.https.html is a flaky failure
https://bugs.webkit.org/show_bug.cgi?id=239304

Unreviewed test gardening.

2:41 PM Changeset in webkit [292832] by Chris Dumez
  • 3 edits in trunk/LayoutTests/imported/w3c

imported/w3c/web-platform-tests/webaudio/the-audio-api/the-biquadfilternode-interface/no-dezippering.html
https://bugs.webkit.org/show_bug.cgi?id=238790
<rdar://problem/91607355>

Reviewed by Eric Carlson.

The audio values may differ slightly from hardware to hardware due to floating point precision and vectorization.
On one of our ARM platforms, we were getting values slightly outside the allowed range but still close enough
that we consider the behavior to be correct. As a result, I am increasing the tolerance a bit in the test.

If this resolves the issue on our bot (I cannot reproduce locally), I'll submit a PR upstream.

  • web-platform-tests/webaudio/the-audio-api/the-biquadfilternode-interface/no-dezippering-expected.txt:
  • web-platform-tests/webaudio/the-audio-api/the-biquadfilternode-interface/no-dezippering.html:
2:27 PM Changeset in webkit [292831] by Matteo Flores
  • 2 edits in trunk/LayoutTests

REBASLINE: [ Monterey wk2 ] 7 /paymentrequest/* tests are constant text failures

https://bugs.webkit.org/show_bug.cgi?id=238908

Unreviewed test gardening.

2:01 PM Changeset in webkit [292830] by ysuzuki@apple.com
  • 9 edits in trunk/Source/JavaScriptCore

[JSC] Remove DeprecatedCallFrameForDebugger
https://bugs.webkit.org/show_bug.cgi?id=239045

Reviewed by Devin Rousso.

We should not enlarge sizeof(JSGlobalObject) by having DeprecatedCallFrameForDebugger which is only used for Debugger, and it is used
only when we have an error when evaluating top-level SyntaxError. This patch removes it: we introduce EmptyTopLevelCallFrameForDebugger
which can be constructed on stack and we use it instead of DeprecatedCallFrameForDebugger.

  • Source/JavaScriptCore/debugger/Debugger.cpp:

(JSC::Debugger::updateCallFrame):
(JSC::EmptyTopLevelCallFrameForDebugger::EmptyTopLevelCallFrameForDebugger):
(JSC::EmptyTopLevelCallFrameForDebugger::asCallFrame):
(JSC::Debugger::exception):

  • Source/JavaScriptCore/debugger/DebuggerCallFrame.cpp:

(JSC::DebuggerCallFrame::create):
(JSC::DebuggerCallFrame::positionForCallFrame):

  • Source/JavaScriptCore/interpreter/CallFrame.cpp:

(JSC::CallFrame::convertToStackOverflowFrame):
(JSC::CallFrame::initDeprecatedCallFrameForDebugger): Deleted.

  • Source/JavaScriptCore/interpreter/CallFrame.h:

(JSC::CallFrame::isEmptyTopLevelCallFrameForDebugger const):
(JSC::CallFrame::isDeprecatedCallFrameForDebugger const): Deleted.

  • Source/JavaScriptCore/interpreter/Interpreter.cpp:

(JSC::Interpreter::notifyDebuggerOfExceptionToBeThrown):

  • Source/JavaScriptCore/runtime/JSGlobalObject.cpp:

(JSC::JSGlobalObject::init):
(JSC::JSGlobalObject::deprecatedCallFrameForDebugger): Deleted.

  • Source/JavaScriptCore/runtime/JSGlobalObject.h:
  • Source/JavaScriptCore/runtime/VM.cpp:

(JSC::VM::throwException):

Canonical link: https://commits.webkit.org/249603@main

1:50 PM Changeset in webkit [292829] by Kocsen Chung
  • 14 edits in branches/safari-613-branch/Source/WebCore

Cherry-pick r292801. rdar://problem/91346216

Crash under CachedResourceClientWalker<WebCore::CachedImageClient>::next()
https://bugs.webkit.org/show_bug.cgi?id=239253
<rdar://91346216>

Reviewed by Simon Fraser and Brent Fulgham.

I haven't been able to reproduce the issue or figure out why this is happening so I am doing
some hardening and adding assertions to help catch the underlying bug.

  • loader/ImageLoader.cpp: (WebCore::ImageLoader::didUpdateCachedImage): There is some speculation that r291141 could have caused this because of the timing of when this patch landed and the fact that this patch modifies ImageLoader, which is a CachedImageClient. I couldn't see anything wrong with the change. However, I did notice that we were calling didUpdateCachedImage() twice with the same CachedImage now for lazy loading (once initially and then another time when the image actually starts lazily). This was intentional. However, the registering again as a client of the CachedImage (and then unregistering right away) was not. Technically, this should be fine since CachedResource is using a HashCountedSet for m_clients locally. However, for the sake of safety, I am now not doing this redundant registering/unregistering as a client of the CachedImage when this image has not changed.
  • loader/cache/CachedCSSStyleSheet.cpp: (WebCore::CachedCSSStyleSheet::checkNotify):
  • loader/cache/CachedFont.cpp: (WebCore::CachedFont::checkNotify):
  • loader/cache/CachedImage.cpp: (WebCore::CachedImage::load): (WebCore::CachedImage::addClientWaitingForAsyncDecoding): (WebCore::CachedImage::notifyObservers): (WebCore::CachedImage::canDestroyDecodedData): (WebCore::CachedImage::imageFrameAvailable): (WebCore::CachedImage::scheduleRenderingUpdate): (WebCore::CachedImage::isVisibleInViewport): (WebCore::CachedImage::isVisibleInViewport const): Deleted.
  • loader/cache/CachedImage.h:
  • loader/cache/CachedRawResource.cpp: (WebCore::CachedRawResource::notifyClientsDataWasReceived): (WebCore::iterateRedirects):

(WebCore::CachedRawResource::redirectReceived):
The new assertions found a bug here where we were capturing the CachedRawResourceClient by value in the lambda and thus
making a copy of it (even though this is a polymorphic class). I fixed the bug and marked CachedResourceClient as non
copyable to avoid issues like these.

(WebCore::CachedRawResource::responseReceived):
(WebCore::CachedRawResource::shouldCacheResponse):
(WebCore::CachedRawResource::didSendData):
(WebCore::CachedRawResource::finishedTimingForWorkerLoad):
(WebCore::CachedRawResource::previewResponseReceived):

  • loader/cache/CachedResource.cpp: (WebCore::CachedResource::checkNotify): (WebCore::CachedResource::didAddClient): (WebCore::CachedResource::addClientToSet): (WebCore::CachedResource::removeClient):
  • loader/cache/CachedResource.h:
  • loader/cache/CachedResourceClient.h: (WebCore::CachedResourceClient::~CachedResourceClient): (WebCore::CachedResourceClient::addAssociatedResource): (WebCore::CachedResourceClient::removeAssociatedResource): Add new assertions to make sure that a CachedResourceClient is no longer associated (i.e. marked as a client of) with any CachedResource at the time it is destroyed. Hopefully, this will catch the issue right away and give us a useful stack trace, instead of crashing later on when iterating over the clients of a CachedResource.
  • loader/cache/CachedResourceClientWalker.h: (WebCore::CachedResourceClientWalker::CachedResourceClientWalker): (WebCore::CachedResourceClientWalker::next): CachedResourceClientWalker is meant to be a safe way of iterating over the clients of a CachedResource, allowing clients to unregister themselves as we iterate. However, when clients unregister themselves, it could in theory cause the CachedResource itself to get destroyed. In such cases, the CachedResourceClientWalker would not be safe since its m_clientSet data member would come from a dead CachedResource. To address the issue, the walker now keeps a handle to the cached resource, instead of the reference to the CachedResource's clients set. The handle will ensure the cached resource stays alive.
  • loader/cache/CachedScript.cpp:
  • loader/cache/CachedTextTrack.cpp: (WebCore::CachedTextTrack::doUpdateBuffer):
  • loader/cache/CachedXSLStyleSheet.cpp: (WebCore::CachedXSLStyleSheet::checkNotify):
  • rendering/RenderObject.cpp:

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@292801 268f45cc-cd09-0410-ab3c-d52691b4dbfc

1:50 PM Changeset in webkit [292828] by Kocsen Chung
  • 4 edits in branches/safari-613-branch

Cherry-pick r292721. rdar://problem/88249235

Fix size computation in WebCore::StorageMap
https://bugs.webkit.org/show_bug.cgi?id=239024
rdar://88249235

Reviewed by Chris Dumez.

Source/WebCore:

We use currentSize to track size for StorageMap. There are a few issues in current implementation that can make
currentSize incorrect and may lead to overflow:

  1. When computing size of key, StorageMap uses parameter key instead of stored key. The problem is that two Strings can be evaluated to equal while their sizeInBytes() value is different, when one String is 8-bit and the other is 16-bit. That means removeItem() may decrease currentSize by wrong number (e.g setItem() with an 8-bit key, converting the key to 16-bit, removeItem() with the key). To fix this, StorageMap now always uses stored key for computation.
  2. When map.take(key) or map.get(key) returns null string, StorageMap takes it as the key does not exist and will not correctly update currentSize, but user of WebCore::StorageMap may store null string as value. To fix this, StorageMap now check if key exists with find() function.
  3. StorageMap only uses CheckedUint32 in setItem(), but removeItem() and importItem() may cause overflow in currentSize as mentioned above, and the error will not be caught until setItem() is called. To fix this, StorageMap now uses CheckedUint32 in all places that update currentSize.

New test: WKWebView.LocalStorageNoSizeOverflow

  • storage/StorageMap.cpp: (WebCore::StorageMap::setItem): (WebCore::StorageMap::removeItem): (WebCore::StorageMap::importItems):

Tools:

  • TestWebKitAPI/Tests/WebKitCocoa/LocalStoragePersistence.mm: (TEST):

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@292721 268f45cc-cd09-0410-ab3c-d52691b4dbfc

1:49 PM Changeset in webkit [292827] by Truitt Savell
  • 2 edits in trunk/LayoutTests

[ Monterey ] 4 http/tests/paymentrequest tests failing
https://bugs.webkit.org/show_bug.cgi?id=239300

Unreviewed test gardening.

  • platform/mac-wk2/TestExpectations:
1:32 PM Changeset in webkit [292826] by Kocsen Chung
  • 14 edits in branches/safari-613.2.6.1-branch/Source/WebCore

Cherry-pick r292801. rdar://problem/91346216

Crash under CachedResourceClientWalker<WebCore::CachedImageClient>::next()
https://bugs.webkit.org/show_bug.cgi?id=239253
<rdar://91346216>

Reviewed by Simon Fraser and Brent Fulgham.

I haven't been able to reproduce the issue or figure out why this is happening so I am doing
some hardening and adding assertions to help catch the underlying bug.

  • loader/ImageLoader.cpp: (WebCore::ImageLoader::didUpdateCachedImage): There is some speculation that r291141 could have caused this because of the timing of when this patch landed and the fact that this patch modifies ImageLoader, which is a CachedImageClient. I couldn't see anything wrong with the change. However, I did notice that we were calling didUpdateCachedImage() twice with the same CachedImage now for lazy loading (once initially and then another time when the image actually starts lazily). This was intentional. However, the registering again as a client of the CachedImage (and then unregistering right away) was not. Technically, this should be fine since CachedResource is using a HashCountedSet for m_clients locally. However, for the sake of safety, I am now not doing this redundant registering/unregistering as a client of the CachedImage when this image has not changed.
  • loader/cache/CachedCSSStyleSheet.cpp: (WebCore::CachedCSSStyleSheet::checkNotify):
  • loader/cache/CachedFont.cpp: (WebCore::CachedFont::checkNotify):
  • loader/cache/CachedImage.cpp: (WebCore::CachedImage::load): (WebCore::CachedImage::addClientWaitingForAsyncDecoding): (WebCore::CachedImage::notifyObservers): (WebCore::CachedImage::canDestroyDecodedData): (WebCore::CachedImage::imageFrameAvailable): (WebCore::CachedImage::scheduleRenderingUpdate): (WebCore::CachedImage::isVisibleInViewport): (WebCore::CachedImage::isVisibleInViewport const): Deleted.
  • loader/cache/CachedImage.h:
  • loader/cache/CachedRawResource.cpp: (WebCore::CachedRawResource::notifyClientsDataWasReceived): (WebCore::iterateRedirects):

(WebCore::CachedRawResource::redirectReceived):
The new assertions found a bug here where we were capturing the CachedRawResourceClient by value in the lambda and thus
making a copy of it (even though this is a polymorphic class). I fixed the bug and marked CachedResourceClient as non
copyable to avoid issues like these.

(WebCore::CachedRawResource::responseReceived):
(WebCore::CachedRawResource::shouldCacheResponse):
(WebCore::CachedRawResource::didSendData):
(WebCore::CachedRawResource::finishedTimingForWorkerLoad):
(WebCore::CachedRawResource::previewResponseReceived):

  • loader/cache/CachedResource.cpp: (WebCore::CachedResource::checkNotify): (WebCore::CachedResource::didAddClient): (WebCore::CachedResource::addClientToSet): (WebCore::CachedResource::removeClient):
  • loader/cache/CachedResource.h:
  • loader/cache/CachedResourceClient.h: (WebCore::CachedResourceClient::~CachedResourceClient): (WebCore::CachedResourceClient::addAssociatedResource): (WebCore::CachedResourceClient::removeAssociatedResource): Add new assertions to make sure that a CachedResourceClient is no longer associated (i.e. marked as a client of) with any CachedResource at the time it is destroyed. Hopefully, this will catch the issue right away and give us a useful stack trace, instead of crashing later on when iterating over the clients of a CachedResource.
  • loader/cache/CachedResourceClientWalker.h: (WebCore::CachedResourceClientWalker::CachedResourceClientWalker): (WebCore::CachedResourceClientWalker::next): CachedResourceClientWalker is meant to be a safe way of iterating over the clients of a CachedResource, allowing clients to unregister themselves as we iterate. However, when clients unregister themselves, it could in theory cause the CachedResource itself to get destroyed. In such cases, the CachedResourceClientWalker would not be safe since its m_clientSet data member would come from a dead CachedResource. To address the issue, the walker now keeps a handle to the cached resource, instead of the reference to the CachedResource's clients set. The handle will ensure the cached resource stays alive.
  • loader/cache/CachedScript.cpp:
  • loader/cache/CachedTextTrack.cpp: (WebCore::CachedTextTrack::doUpdateBuffer):
  • loader/cache/CachedXSLStyleSheet.cpp: (WebCore::CachedXSLStyleSheet::checkNotify):
  • rendering/RenderObject.cpp:

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@292801 268f45cc-cd09-0410-ab3c-d52691b4dbfc

1:11 PM Changeset in webkit [292825] by Andres Gonzalez
  • 5 edits in trunk/Source/WebCore

Fix for accessibility/table-add-remove-rows.html in isolated tree mode.
https://bugs.webkit.org/show_bug.cgi?id=239271
<rdar://problem/91663287>

Reviewed by Chris Fleizach.

Test: accessibility/table-add-remove-rows.html

Added AXIsolatedTree::updateTableProperties() to recalculate all cached
table properties when the children of a table object change.
AXIsolatedTree::updateChildren now calls updateRelatedProperties to
update properties that can change as the result of children changes for
specific types of objects like tables, trees and treeitems.
Moved and renamed idsForObjects as axIDs() so that it can be used across
the board.

  • accessibility/AccessibilityObjectInterface.h:

(WebCore::axIDs):
(WebCore::AXCoreObject::childrenIDs):

  • accessibility/isolatedtree/AXIsolatedObject.cpp:

(WebCore::AXIsolatedObject::setObjectVectorProperty):
(WebCore::AXIsolatedObject::setSelectedChildren):

  • accessibility/isolatedtree/AXIsolatedTree.cpp:

(WebCore::AXIsolatedTree::updateNodeProperty):
(WebCore::AXIsolatedTree::updateTableProperties):
(WebCore::AXIsolatedTree::updateTreeItemProperties):
(WebCore::AXIsolatedTree::updateRelatedProperties):
(WebCore::AXIsolatedTree::updateChildren):
(WebCore::AXIsolatedTree::idsForObjects const): Moved to AccessibilityObjectInterface.h as axIDs().

  • accessibility/isolatedtree/AXIsolatedTree.h:
1:05 PM Changeset in webkit [292824] by hironori.fujii@sony.com
  • 5 edits in trunk

[WinCairo] WEBKIT_LIBRARIES env var should be customizable
https://bugs.webkit.org/show_bug.cgi?id=239268

Reviewed by Yusuke Suzuki.

  • Tools/Scripts/update-webkit-wincairo-libs.py:
  • Source/WebKitLegacy/CMakeLists.txt:
  • Source/WebKitLegacy/PlatformWin.cmake:

Canonical link: https://commits.webkit.org/249600@main

12:53 PM Changeset in webkit [292823] by Kocsen Chung
  • 14 edits in branches/safari-613.2.6.0-branch/Source/WebCore

Cherry-pick r292801. rdar://problem/91346216

Crash under CachedResourceClientWalker<WebCore::CachedImageClient>::next()
https://bugs.webkit.org/show_bug.cgi?id=239253
<rdar://91346216>

Reviewed by Simon Fraser and Brent Fulgham.

I haven't been able to reproduce the issue or figure out why this is happening so I am doing
some hardening and adding assertions to help catch the underlying bug.

  • loader/ImageLoader.cpp: (WebCore::ImageLoader::didUpdateCachedImage): There is some speculation that r291141 could have caused this because of the timing of when this patch landed and the fact that this patch modifies ImageLoader, which is a CachedImageClient. I couldn't see anything wrong with the change. However, I did notice that we were calling didUpdateCachedImage() twice with the same CachedImage now for lazy loading (once initially and then another time when the image actually starts lazily). This was intentional. However, the registering again as a client of the CachedImage (and then unregistering right away) was not. Technically, this should be fine since CachedResource is using a HashCountedSet for m_clients locally. However, for the sake of safety, I am now not doing this redundant registering/unregistering as a client of the CachedImage when this image has not changed.
  • loader/cache/CachedCSSStyleSheet.cpp: (WebCore::CachedCSSStyleSheet::checkNotify):
  • loader/cache/CachedFont.cpp: (WebCore::CachedFont::checkNotify):
  • loader/cache/CachedImage.cpp: (WebCore::CachedImage::load): (WebCore::CachedImage::addClientWaitingForAsyncDecoding): (WebCore::CachedImage::notifyObservers): (WebCore::CachedImage::canDestroyDecodedData): (WebCore::CachedImage::imageFrameAvailable): (WebCore::CachedImage::scheduleRenderingUpdate): (WebCore::CachedImage::isVisibleInViewport): (WebCore::CachedImage::isVisibleInViewport const): Deleted.
  • loader/cache/CachedImage.h:
  • loader/cache/CachedRawResource.cpp: (WebCore::CachedRawResource::notifyClientsDataWasReceived): (WebCore::iterateRedirects):

(WebCore::CachedRawResource::redirectReceived):
The new assertions found a bug here where we were capturing the CachedRawResourceClient by value in the lambda and thus
making a copy of it (even though this is a polymorphic class). I fixed the bug and marked CachedResourceClient as non
copyable to avoid issues like these.

(WebCore::CachedRawResource::responseReceived):
(WebCore::CachedRawResource::shouldCacheResponse):
(WebCore::CachedRawResource::didSendData):
(WebCore::CachedRawResource::finishedTimingForWorkerLoad):
(WebCore::CachedRawResource::previewResponseReceived):

  • loader/cache/CachedResource.cpp: (WebCore::CachedResource::checkNotify): (WebCore::CachedResource::didAddClient): (WebCore::CachedResource::addClientToSet): (WebCore::CachedResource::removeClient):
  • loader/cache/CachedResource.h:
  • loader/cache/CachedResourceClient.h: (WebCore::CachedResourceClient::~CachedResourceClient): (WebCore::CachedResourceClient::addAssociatedResource): (WebCore::CachedResourceClient::removeAssociatedResource): Add new assertions to make sure that a CachedResourceClient is no longer associated (i.e. marked as a client of) with any CachedResource at the time it is destroyed. Hopefully, this will catch the issue right away and give us a useful stack trace, instead of crashing later on when iterating over the clients of a CachedResource.
  • loader/cache/CachedResourceClientWalker.h: (WebCore::CachedResourceClientWalker::CachedResourceClientWalker): (WebCore::CachedResourceClientWalker::next): CachedResourceClientWalker is meant to be a safe way of iterating over the clients of a CachedResource, allowing clients to unregister themselves as we iterate. However, when clients unregister themselves, it could in theory cause the CachedResource itself to get destroyed. In such cases, the CachedResourceClientWalker would not be safe since its m_clientSet data member would come from a dead CachedResource. To address the issue, the walker now keeps a handle to the cached resource, instead of the reference to the CachedResource's clients set. The handle will ensure the cached resource stays alive.
  • loader/cache/CachedScript.cpp:
  • loader/cache/CachedTextTrack.cpp: (WebCore::CachedTextTrack::doUpdateBuffer):
  • loader/cache/CachedXSLStyleSheet.cpp: (WebCore::CachedXSLStyleSheet::checkNotify):
  • rendering/RenderObject.cpp:

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@292801 268f45cc-cd09-0410-ab3c-d52691b4dbfc

12:53 PM Changeset in webkit [292822] by Kocsen Chung
  • 4 edits in branches/safari-613.2.6.0-branch

Cherry-pick r292721. rdar://problem/88249235

Fix size computation in WebCore::StorageMap
https://bugs.webkit.org/show_bug.cgi?id=239024
rdar://88249235

Reviewed by Chris Dumez.

Source/WebCore:

We use currentSize to track size for StorageMap. There are a few issues in current implementation that can make
currentSize incorrect and may lead to overflow:

  1. When computing size of key, StorageMap uses parameter key instead of stored key. The problem is that two Strings can be evaluated to equal while their sizeInBytes() value is different, when one String is 8-bit and the other is 16-bit. That means removeItem() may decrease currentSize by wrong number (e.g setItem() with an 8-bit key, converting the key to 16-bit, removeItem() with the key). To fix this, StorageMap now always uses stored key for computation.
  2. When map.take(key) or map.get(key) returns null string, StorageMap takes it as the key does not exist and will not correctly update currentSize, but user of WebCore::StorageMap may store null string as value. To fix this, StorageMap now check if key exists with find() function.
  3. StorageMap only uses CheckedUint32 in setItem(), but removeItem() and importItem() may cause overflow in currentSize as mentioned above, and the error will not be caught until setItem() is called. To fix this, StorageMap now uses CheckedUint32 in all places that update currentSize.

New test: WKWebView.LocalStorageNoSizeOverflow

  • storage/StorageMap.cpp: (WebCore::StorageMap::setItem): (WebCore::StorageMap::removeItem): (WebCore::StorageMap::importItems):

Tools:

  • TestWebKitAPI/Tests/WebKitCocoa/LocalStoragePersistence.mm: (TEST):

git-svn-id: https://svn.webkit.org/repository/webkit/trunk@292721 268f45cc-cd09-0410-ab3c-d52691b4dbfc

12:43 PM Changeset in webkit [292821] by Russell Epstein
  • 1 copy in tags/WebKit-7614.1.10

Tag WebKit-7614.1.10.

12:27 PM Changeset in webkit [292820] by Kocsen Chung
  • 9 edits in branches/safari-613.2.6.0-branch/Source

Versioning.

WebKit-7613.2.6.0.1

12:12 PM Changeset in webkit [292819] by Antti Koivisto
  • 7 edits in trunk

[CSS Container Queries] Correct container selection for pseudo-elements
https://bugs.webkit.org/show_bug.cgi?id=239279

Reviewed by Simon Fraser.

Source/WebCore:

The element itself may be the container for its pseudo-elements.

  • css/CSSPrimitiveValue.cpp:

(WebCore::CSSPrimitiveValue::computeNonCalcLengthDouble):

  • style/ContainerQueryEvaluator.cpp:

(WebCore::Style::ContainerQueryEvaluator::ContainerQueryEvaluator):
(WebCore::Style::ContainerQueryEvaluator::selectContainer const):
(WebCore::Style::ContainerQueryEvaluator::selectContainer):

  • style/ContainerQueryEvaluator.h:

Instead of passing the pseudo-element being matched, pass a container selection mode flag. The exact pseudo-element type
doesn't matter.

  • style/ElementRuleCollector.cpp:

(WebCore::Style::ElementRuleCollector::containerQueriesMatch):

We need to use the pseudo-element mode when matching a rule that matches a pseudo-element, even when we are not actually resolving
the pseudo element. This is because regular element rule matching sets the style bits that indicate what pseudo-elements the
element has.

LayoutTests:

11:53 AM Changeset in webkit [292818] by Patrick Angle
  • 3 edits in trunk/Source/WebInspectorUI

Web Inspector: Clean up WI.DOMNode to no longer require the shared WI.DOMManager be passed during construction
https://bugs.webkit.org/show_bug.cgi?id=239129

Reviewed by Devin Rousso.

  • UserInterface/Controllers/DOMManager.js:

(WI.DOMManager.prototype._setDocument):
(WI.DOMManager.prototype._childNodeInserted):
(WI.DOMManager.prototype._pseudoElementAdded):

  • Update to use new syntax for WI.DOMNode constructor/newOrExistingFromPayload. Additionally, there is no

need to explicitly map node ids to nodes here since WI.DOMNode's constructor does this.

(WI.DOMManager.prototype._setChildNodes):
(WI.DOMManager.prototype._setDetachedRoot): Deleted.

  • Inline _setDetachedRoot with a comment instead and update to use WI.DOMNode.newOrExistingFromPayload instead

of always creating a new node.

  • UserInterface/Models/DOMNode.js:

(WI.DOMNode):

  • Remove the _domManager property since it will always be WI.domManager, the shared singleton and update the

required arguments to use an options object for non-required parameters.

(WI.DOMNode.prototype.newOrExistingFromPayload):
(WI.DOMNode.prototype._insertChild):
(WI.DOMNode.prototype._setChildrenPayload):

  • Update to use new constructor syntax.
11:50 AM Changeset in webkit [292817] by Alan Bujtas
  • 5 edits
    2 adds in trunk

REGRESSION (r292043): [ Mac ] fast/block/positioning/fixed-container-with-relative-parent.html is a flaky image failure
https://bugs.webkit.org/show_bug.cgi?id=239101
<rdar://problem/91603539>

Reviewed by Antti Koivisto.

Source/WebCore:

  1. Out of flow boxes are laid out independently from each other as the last step of their containing block layout.
  2. However their static positions are computed during regular in-flow layout (as if their positions were static).

In order to do #1, we maintain a ListHashSet for the out-of-flow boxes and insert them at #2 (and we also have
a corresponding HashMap<ContainingBlock, ListHasSet>).

Normally this is a very simple list of descendant positioned boxes and since out-of-flow boxes don't interact with each
other, their position in the list is not important.

e.g.

<div id=A style="position: relative">

<div>

<div id=B style="position: absolute"></div>
<div id=C style="position: absolute"></div>

</div>

</div>

At in-flow layout (#2), we insert B and C to "ListHashSet of A" as we come across them in DOM order and compute their static positions.
Later in the layout flow when we get to the "let's layout the out-of-flow boxes" phase (#1) we simply walk
the ListHashSet and lay out B and C (but "C and B" order would also work just fine).

However the ICB (RenderView) is a special containing block as it can hold different types of out-of-flow boxes (absolute and fixed)
and those out-of-flow boxes may have layout dependencies.
e.g.

<body><div id=A class=absolute><div id=B class=fixed></div></div></body>

ICB's ListHasSet has both A and B, but in this case there's (static)layout dependency between these boxes.
In order to figure out the static position of B, we have to have A laid out first. In order to lay out A before B,
B has to be preceded by A in ICB's ListHasSet.

Now full layout always guarantees the correct order.
However in case of partial layout since we don't run a full #2, the ListHasSet may end up having an unexpected order.

e.g.

<body><div id=A class=absolute><div id=B><div id=C class=fixed></div></div></div></body>

  1. The initial (full) layout produces the following (correct) order for the ICB's ListHasSet -> AC.
  2. A subsequent partial layout (e.g. triggered by A's position change) runs an in-flow layout on the <body> which (re-)appends A to the ListHasSet (CA <- incorrect order). Now at this point we assume that the in-flow layout picks up B which eventually (re-)appends C to the ListHashSet (AC <- correct order). However since B does not need layout, we just stop at <body> which leaves us with an unexpected ListHashSet.
  3. As part of the ICB's out-of-flow layout, we pick C as the first box to lay out followed by A. However since C's static position depends on A's position, we end up using stale geometry when computing C's static position.

This patch fixes this issue by ensuring the absolute positioned boxes always come first in the ICB's ListHasSet (note
that their order is not really important -see above. What's important is that a potential (as-if-static) containing block always
comes before the fixed boxes).

Test: fast/block/fixed-inside-absolute-positioned.html

  • rendering/RenderBlock.cpp:

(WebCore::PositionedDescendantsMap::addDescendant):
(WebCore::RenderBlock::insertPositionedObject):

LayoutTests:

  • fast/block/fixed-inside-absolute-positioned-expected.html: Added.
  • fast/block/fixed-inside-absolute-positioned.html: Added.
  • platform/mac-wk1/TestExpectations:
11:48 AM Changeset in webkit [292816] by Antti Koivisto
  • 4 edits in trunk

[CSS Container Queries] Limit query range syntax
https://bugs.webkit.org/show_bug.cgi?id=239118

Reviewed by Simon Fraser.

LayoutTests/imported/w3c:

  • web-platform-tests/css/css-contain/container-queries/at-container-parsing-expected.txt:

Source/WebCore:

The spec disallows things like (100px = width < 200px) and (100px < width > 200px).

https://www.w3.org/TR/mediaqueries-4/#mq-range-context

  • css/ContainerQueryParser.cpp:

(WebCore::ContainerQueryParser::consumeContainerQuery):

Try as a condition first.
Return UnknownQuery on parse failure.

(WebCore::ContainerQueryParser::consumeRangeSizeFeature):

Validate the ranges so what ends up being allowed matches the spec productions.

11:17 AM Changeset in webkit [292815] by Russell Epstein
  • 1 copy in tags/WebKit-7614.1.9.4

Tag WebKit-7614.1.9.4.

10:52 AM Changeset in webkit [292814] by Chris Dumez
  • 2 edits in trunk/Source/WTF

Drop unused AtomString(const LChar*) constructor
https://bugs.webkit.org/show_bug.cgi?id=239274

Reviewed by Darin Adler.

  • wtf/text/AtomString.h:
9:52 AM Changeset in webkit [292813] by Russell Epstein
  • 9 edits in branches/safari-614.1.9-branch/Source

Versioning.

WebKit-7614.1.9.4

9:41 AM Changeset in webkit [292812] by Simon Fraser
  • 23 edits
    2 adds in trunk

[css-scroll-snap] scrollIntoView fails with scroll-snap-type on :root
https://bugs.webkit.org/show_bug.cgi?id=239063
<rdar://problem/91603363>

Reviewed by Dean Jackson.

Source/WebCore:

Programmatic smooth scrolls on iframe documents were broken because
ScrollingTreeFrameScrollingNodeRemoteIOS was overlooked when adding support (easily done
since the main frame's scrolling is controlled via the WKWebView; some unification here
would be beneficial). Implementing startAnimatedScrollToPosition() and stopAnimatedScroll()
on ScrollingTreeFrameScrollingNodeRemoteIOS fixes this.

However, this revealed an additional bug; RenderLayer::scrollRectToVisible() failed to clamp
the target scroll position correctly, and nothing in the iOS-smooth scrolling code path
clamped, so the scroll would go too far.

Testing required getting UIHelper.waitForScrollCompletion() to work. This is based on the
uiController.didEndScrollingCallback, but that was only hooked up for the main scroller. So
make it work for all scrollers by plumbing ScrollingNodeIDs through
scrollingNodeScrollViewDidScroll() and friends so that everything ends up in -[WKWebViewIOS
_didFinishScrolling:] with a UIScrollView argument; to avoid any behavior change, this bails
for non-main scroll views, but TestRunnerWKWebView overrides it to make testing work.

Test: fast/scrolling/ios/constrain-scrollintoview-position.html

  • rendering/RenderLayer.cpp:

(WebCore::RenderLayer::scrollRectToVisible):

Source/WebKit:

Programmatic smooth scrolls on iframe documents were broken because
ScrollingTreeFrameScrollingNodeRemoteIOS was overlooked when adding support (easily done
since the main frame's scrolling is controlled via the WKWebView; some unification here
would be beneficial). Implementing startAnimatedScrollToPosition() and stopAnimatedScroll()
on ScrollingTreeFrameScrollingNodeRemoteIOS fixes this.

However, this revealed an additional bug; RenderLayer::scrollRectToVisible() failed to clamp
the target scroll position correctly, and nothing in the iOS-smooth scrolling code path
clamped, so the scroll would go too far.

Testing required getting UIHelper.waitForScrollCompletion() to work. This is based on the
uiController.didEndScrollingCallback, but that was only hooked up for the main scroller. So
make it work for all scrollers by plumbing ScrollingNodeIDs through
scrollingNodeScrollViewDidScroll() and friends so that everything ends up in -[WKWebViewIOS
_didFinishScrolling:] with a UIScrollView argument; to avoid any behavior change, this bails
for non-main scroll views, but TestRunnerWKWebView overrides it to make testing work.

Test: fast/scrolling/ios/constrain-scrollintoview-position.html

  • UIProcess/API/ios/WKWebViewIOS.h:
  • UIProcess/API/ios/WKWebViewIOS.mm:

(-[WKWebView _didFinishScrolling:]):
(-[WKWebView scrollViewDidEndDragging:willDecelerate:]):
(-[WKWebView scrollViewDidEndDecelerating:]):
(-[WKWebView scrollViewDidScrollToTop:]):
(-[WKWebView scrollViewDidEndScrollingAnimation:]):
(-[WKWebView _didFinishScrolling]): Deleted.

  • UIProcess/PageClient.h:
  • UIProcess/RemoteLayerTree/RemoteScrollingCoordinatorProxy.cpp:

(WebKit::RemoteScrollingCoordinatorProxy::scrollingTreeNodeDidScroll):

  • UIProcess/RemoteLayerTree/ios/RemoteScrollingCoordinatorProxyIOS.mm:

(WebKit::RemoteScrollingCoordinatorProxy::scrollingTreeNodeWillStartPanGesture):
(WebKit::RemoteScrollingCoordinatorProxy::scrollingTreeNodeWillStartScroll):
(WebKit::RemoteScrollingCoordinatorProxy::scrollingTreeNodeDidEndScroll):

  • UIProcess/RemoteLayerTree/ios/ScrollingTreeFrameScrollingNodeRemoteIOS.h:
  • UIProcess/RemoteLayerTree/ios/ScrollingTreeFrameScrollingNodeRemoteIOS.mm:

(WebKit::ScrollingTreeFrameScrollingNodeRemoteIOS::startAnimatedScrollToPosition):
(WebKit::ScrollingTreeFrameScrollingNodeRemoteIOS::stopAnimatedScroll):

  • UIProcess/RemoteLayerTree/ios/ScrollingTreeScrollingNodeDelegateIOS.mm:

(-[WKScrollingNodeScrollViewDelegate scrollViewDidEndScrollingAnimation:]):
(WebKit::ScrollingTreeScrollingNodeDelegateIOS::repositionScrollingLayers):

  • UIProcess/WebPageProxy.h:
  • UIProcess/WebPageProxy.messages.in:
  • UIProcess/ios/PageClientImplIOS.h:
  • UIProcess/ios/PageClientImplIOS.mm:

(WebKit::PageClientImpl::scrollingNodeScrollViewWillStartPanGesture):
(WebKit::PageClientImpl::scrollingNodeScrollViewDidScroll):
(WebKit::PageClientImpl::scrollingNodeScrollWillStartScroll):
(WebKit::PageClientImpl::scrollingNodeScrollDidEndScroll):

  • UIProcess/ios/WKContentViewInteraction.h:
  • UIProcess/ios/WKContentViewInteraction.mm:

(-[WKContentView _scrollingNodeScrollingWillBegin:]):
(-[WKContentView _scrollingNodeScrollingDidEnd:]):
(-[WKContentView keyboardScrollViewAnimatorDidFinishScrolling:]):
(-[WKContentView _scrollingNodeScrollingWillBegin]): Deleted.
(-[WKContentView _scrollingNodeScrollingDidEnd]): Deleted.

  • UIProcess/ios/WebPageProxyIOS.mm:

(WebKit::WebPageProxy::scrollingNodeScrollViewWillStartPanGesture):
(WebKit::WebPageProxy::scrollingNodeScrollViewDidScroll):
(WebKit::WebPageProxy::scrollingNodeScrollWillStartScroll):
(WebKit::WebPageProxy::scrollingNodeScrollDidEndScroll):

  • WebProcess/WebCoreSupport/ios/WebChromeClientIOS.mm:

(WebKit::WebChromeClient::didStartOverflowScroll):
(WebKit::WebChromeClient::didEndOverflowScroll):

Tools:

_didFinishScrolling: now works for subscrollers too.

  • WebKitTestRunner/cocoa/TestRunnerWKWebView.mm:

(-[TestRunnerWKWebView _didFinishScrolling:]):
(-[TestRunnerWKWebView _didFinishScrolling]): Deleted.

LayoutTests:

Make UIHelper.waitForScrollCompletion() work on iOS.

  • fast/scrolling/ios/constrain-scrollintoview-position-expected.txt: Added.
  • fast/scrolling/ios/constrain-scrollintoview-position.html: Added.
  • resources/ui-helper.js:

(window.UIHelper.async waitForScrollCompletion.await.new.Promise.):
(window.UIHelper.async waitForScrollCompletion.await.new.Promise):
(window.UIHelper.async waitForScrollCompletion):

9:12 AM Changeset in webkit [292811] by Wenson Hsieh
  • 2 edits in trunk/Source/WTF

MSE video is not drawn onto canvas
https://bugs.webkit.org/show_bug.cgi?id=206812
rdar://31763425

Reviewed by Eric Carlson.

Enable MediaSource inline painting by default on all platforms where AVSampleBufferVideoOutput has been tuned
with a more aggressive pruning interval; this avoids significant increases in memory and power use when
utilizing the sample buffer to snapshot videos with MSE.

  • Scripts/Preferences/WebPreferencesExperimental.yaml:
7:47 AM Changeset in webkit [292810] by Chris Dumez
  • 78 edits in trunk

Replace AtomString(const char*) with AtomString::fromLatin1(const char*)
https://bugs.webkit.org/show_bug.cgi?id=239127

Reviewed by Darin Adler.

Source/JavaScriptCore:

  • API/JSBase.cpp:

(JSGetMemoryUsageStatistics):

  • runtime/Identifier.h:
  • runtime/IdentifierInlines.h:

(JSC::Identifier::fromLatin1):
(JSC::Identifier::fromCString): Deleted.

  • runtime/JSObject.cpp:

(JSC::JSObject::reifyAllStaticProperties):

  • runtime/JSObjectInlines.h:

(JSC::JSObject::getNonReifiedStaticPropertyNames):

Source/WebCore:

  • Modules/encryptedmedia/InitDataRegistry.cpp:

(WebCore::InitDataRegistry::InitDataRegistry):

  • accessibility/AccessibilityRenderObject.cpp:

(WebCore::AccessibilityRenderObject::setElementAttributeValue):

  • animation/WebAnimation.cpp:

(WebCore::WebAnimation::commitStyles):

  • dom/DocumentInlines.h:

(WebCore::Document::encoding const):

  • dom/Element.cpp:

(WebCore::Element::dispatchWebKitImageReadyEventForTesting):

  • dom/PseudoElement.cpp:

(WebCore::pseudoElementTagName):

  • editing/Editing.cpp:

(WebCore::createTabSpanElement):

  • editing/Editor.cpp:

(WebCore::Editor::willUnapplyEditing const):
(WebCore::Editor::unappliedEditing):
(WebCore::Editor::willReapplyEditing const):
(WebCore::Editor::reappliedEditing):
(WebCore::Editor::quoteFragmentForPasting):

  • editing/HTMLInterchange.h:
  • editing/IndentOutdentCommand.cpp:

(WebCore::IndentOutdentCommand::IndentOutdentCommand):

  • editing/markup.cpp:

(WebCore::createFragmentFromText):

  • html/HTMLAudioElement.cpp:

(WebCore::HTMLAudioElement::createForLegacyFactoryFunction):

  • html/HTMLDetailsElement.cpp:

(WebCore::summarySlotName):

  • html/HTMLElement.cpp:

(WebCore::HTMLElement::setTranslate):

  • html/HTMLMediaElement.cpp:

(WebCore::HTMLMediaElement::updateShouldContinueAfterNeedKey):
(WebCore::HTMLMediaElement::mediaPlayerKeyNeeded):
(WebCore::HTMLMediaElement::layoutSizeChanged):

  • html/HTMLMeterElement.cpp:

(WebCore::setValueClass):
(WebCore::HTMLMeterElement::didAddUserAgentShadowRoot):

  • html/ImageDocument.cpp:

(WebCore::ImageDocument::createDocumentStructure):

  • html/PDFDocument.cpp:

(WebCore::PDFDocument::createDocumentStructure):
(WebCore::PDFDocument::injectStyleAndContentScript):

  • html/canvas/CanvasRenderingContext2DBase.cpp:
  • html/canvas/CanvasRenderingContext2DBase.h:
  • html/parser/HTMLTreeBuilder.cpp:

(WebCore::createForeignAttributesMap):

  • html/parser/TextDocumentParser.cpp:

(WebCore::TextDocumentParser::insertFakePreElement):

  • html/track/TextTrack.cpp:

(WebCore::TextTrack::captionMenuOffItem):
(WebCore::TextTrack::captionMenuAutomaticItem):

  • html/track/TextTrackCue.cpp:

(WebCore::cueAttributName):
(WebCore::cueBackgroundAttributName):

  • html/track/WebVTTElement.cpp:

(WebCore::nodeTypeToTagName):

  • html/track/WebVTTElement.h:
  • inspector/InspectorAuditAccessibilityObject.cpp:

(WebCore::InspectorAuditAccessibilityObject::getComputedProperties):

  • inspector/InspectorOverlayLabel.cpp:

(WebCore::systemFont):

  • inspector/InspectorStyleSheet.cpp:

(WebCore::InspectorStyleSheetForInlineStyle::InspectorStyleSheetForInlineStyle):
(WebCore::InspectorStyleSheetForInlineStyle::elementStyleText const):

  • inspector/agents/InspectorDOMAgent.cpp:

(WebCore::InspectorDOMAgent::buildObjectForAccessibilityProperties):

  • loader/LinkLoader.cpp:

(WebCore::LinkLoader::preloadIfNeeded):

  • mathml/MathMLPresentationElement.cpp:

(WebCore::MathMLPresentationElement::isFlowContent):

  • page/DebugPageOverlays.cpp:

(WebCore::NonFastScrollableRegionOverlay::drawRect):
(WebCore::InteractionRegionOverlay::drawSettings):

  • page/Quirks.cpp:

(WebCore::Quirks::shouldTooltipPreventFromProceedingWithClick const):
(WebCore::Quirks::simulatedMouseEventTypeForTarget const):
(WebCore::isKinjaLoginAvatarElement):
(WebCore::isStorageAccessQuirkDomainAndElement):
(WebCore::isBBCPopUpPlayerElement):
(WebCore::Quirks::triggerOptionalStorageAccessQuirk const):

  • platform/cocoa/VideoFullscreenModelVideoElement.mm:

(WebCore::VideoFullscreenModelVideoElement::eventNameAll):

  • platform/graphics/avfoundation/objc/MediaPlayerPrivateAVFoundationObjC.mm:

(WebCore::MediaPlayerPrivateAVFoundationObjC::processMetadataTrack):
(WebCore::MediaPlayerPrivateAVFoundationObjC::setCurrentTextTrack):

  • platform/graphics/avfoundation/objc/SourceBufferParserAVFObjC.mm:
  • platform/graphics/ca/PlatformCALayer.cpp:

(WebCore::PlatformCALayer::drawRepaintIndicator):

  • platform/mock/MockRealtimeVideoSource.cpp:

(WebCore::MockRealtimeVideoSource::drawText):

  • platform/network/BlobRegistryImpl.cpp:

(WebCore::registerBlobResourceHandleConstructor):

  • rendering/RenderCounter.cpp:

(showCounterRendererTree):

  • rendering/RenderLayerBacking.cpp:

(WebCore::patternForDescription):

  • rendering/mathml/RenderMathMLFenced.cpp:
  • style/StyleResolveForDocument.cpp:

(WebCore::Style::resolveForDocument):

  • svg/SVGFontFaceUriElement.cpp:

(WebCore::SVGFontFaceUriElement::srcValue const):

  • svg/SVGUseElement.cpp:

(WebCore::SVGUseElement::transferSizeAttributesToTargetClone const):

  • workers/service/FetchEvent.cpp:

(WebCore::FetchEvent::createForTesting):

  • xml/XMLErrors.cpp:

(WebCore::createXHTMLParserErrorHeader):
(WebCore::XMLErrors::insertErrorMessageBlock):

  • xml/XMLTreeViewer.cpp:

(WebCore::XMLTreeViewer::transformDocumentToTreeView):

Source/WebKit:

  • WebProcess/Plugins/PDF/PDFPluginPasswordField.mm:

(WebKit::PDFPluginPasswordField::createAnnotationElement):

  • WebProcess/WebPage/IPCTestingAPI.cpp:

(WebKit::IPCTestingAPI::JSIPC::messages):

  • WebProcess/WebPage/ios/WebPageIOS.mm:

(WebKit::WebPage::focusedElementInformation):

Source/WTF:

  • wtf/text/AtomString.cpp:

(WTF::AtomString::init):

  • wtf/text/AtomString.h:

(WTF::operator==):
(WTF::operator!=):

Tools:

  • TestWebKitAPI/Tests/WTF/AtomString.cpp:

(TestWebKitAPI::TEST):

  • TestWebKitAPI/Tests/WTF/StringOperators.cpp:

(TestWebKitAPI::TEST):

  • TestWebKitAPI/Tests/WebCore/ComplexTextController.cpp:

(TestWebKitAPI::TEST_F):

  • TestWebKitAPI/Tests/WebCore/cg/BifurcatedGraphicsContextTestsCG.cpp:

(TestWebKitAPI::TEST):

6:52 AM Changeset in webkit [292809] by Angelos Oikonomopoulos
  • 2 edits in trunk/Tools

[run-jsc-stress-tests] Minor robustness fix
https://bugs.webkit.org/show_bug.cgi?id=239280

Reviewed by Adrian Perez de Castro.

Occasionally (e.g. https://build.webkit.org/#/builders/31/builds/3282),
run-jsc-stress-tests will receive a partial line when recovering the
results because the remote has died. The original code was being too
defensive; we should simply ignore those lines and allow for a retry.

  • Scripts/run-jsc-stress-tests:
6:39 AM Changeset in webkit [292808] by Angelos Oikonomopoulos
  • 2 edits in trunk/Tools

[run-jsc-stress-tests] Use ServerAliveInterval in GNU parallel
https://bugs.webkit.org/show_bug.cgi?id=239283

Reviewed by Adrian Perez de Castro.

run-jsc-stress-tests occasionally dies e.g. in
https://build.webkit.org/#/builders/31/builds/3262/steps/8/logs/stdio
because the remote commands don't produce any output for a full hour.

This seems like an issue with hung ssh connections (possibly because of
all the remotes rebooting at the same time), so use ServerAliveInterval
to detect that.

Reuse SSH_OPTIONS_DEFAULT to pick up the ServerAliveInterval. While
here, move the extra ssh options outside the command string and
document them properly.

  • Scripts/run-jsc-stress-tests:
5:53 AM Changeset in webkit [292807] by Jonathan Bedard
  • 3 edits in trunk/Tools

[Merge-Queue] Do not duplicate reviewer names
https://bugs.webkit.org/show_bug.cgi?id=239270
<rdar://problem/91662347>

Reviewed by Yusuke Suzuki.

  • Tools/CISupport/ews-build/steps.py:

(ValidateCommitterAndReviewer.start):

  • Tools/CISupport/ews-build/steps_unittest.py:

Canonical link: https://commits.webkit.org/249589@main

5:20 AM Changeset in webkit [292806] by Diego Pino Garcia
  • 2 edits in trunk/Tools

[JHBuild] Unreviewed, replace 'false' for 'disabled' in glib mesonargs

  • gtk/jhbuild.modules:
5:16 AM Changeset in webkit [292805] by Diego Pino Garcia
  • 3 edits in trunk/Tools

[JHBuild] Unreviewed, fix 'glib-networking' module path in WPE and GTK general modules

  • gtk/jhbuild.modules:
  • wpe/jhbuild.modules:
3:39 AM Changeset in webkit [292804] by youenn@apple.com
  • 4 edits in trunk

Complement implementation of step 5.5 of https://fetch.spec.whatwg.org/#http-fetch
https://bugs.webkit.org/show_bug.cgi?id=239123

Reviewed by Darin Adler.

LayoutTests/imported/w3c:

  • web-platform-tests/service-workers/service-worker/fetch-response-taint.https-expected.txt:

Source/WebCore:

Covered by rebased test.

  • workers/service/context/ServiceWorkerFetch.cpp:

(WebCore::ServiceWorkerFetch::validateResponse):

12:29 AM Changeset in webkit [292803] by commit-queue@webkit.org
  • 22 edits in trunk/Source/WebKit

RemoteRenderingBackend should have dedicated IPC::Connection for out-of-stream messages
https://bugs.webkit.org/show_bug.cgi?id=238516

Patch by Kimmo Kinnunen <kkinnunen@apple.com> on 2022-04-13
Reviewed by Simon Fraser.

Use dedicated IPC::Connection for RemoteRenderingBackend IPC stream connection instead
of using the WP-GPUP main connection. RemoteDisplayListRecorder starts listening to
its messages in the worker thread. At that point, some out-of-stream message for that
id might already have been dispatched to main thread, causing missing message and assert.

Instead, use dedicated connection and route all the messages to the StreamServerConnection
in a "message queue". This way when each out-of-stream message marker is processed, the
message will be, directly or eventually, found from the message queue.

Remove workarounds:

  • Adding a listener to the main WP-GPUP connection for all RemoteDisplayListRecorder messages and routing them to particular StreamServerConnection. This was problematic since there are many RRB StreamServerConnection instances, one per Page, but only one WP-GPUP connection.
  • RELEASE_LOG in MessageReceiveQueueMap about warning for the above. Turn this back into an ASSERT.

Since IPC::StreamClientConnection and IPC::StreamServerConnection are like IPC::Connection,
add open() and invalidate() calls. These have same contract as with IPC::Connection:
open() should be called if connection is to be used, invalidate() must be called if open() was called.
These calls have an effect currently only with dedicated connections, but these are added to all
IPC::Stream*Connection clients for consistency and future uses.

Changes semantics of IPC::Connection slightly:
Before, there was no untrusted holders of "server" IPC::Connection, e.g. the IPC::Connection instances
were never instantiated by WP.
After, untrusted WP instantiates these IPC stream dedicated connections.
This is accounted in the case where IPC::Connection ensures that IPC::MessageNames::InitializeConnection
message is not acted on twice.

Tested by imported/w3c/web-platform-tests/html/semantics/links/links-created-by-a-and-area-elements/target_blank_implicit_noopener.html

--child-processes=1 --experimental-feature=UseGPUProcessForDOMRenderingEnabled=true --iterations=100 --force --simulator

  • GPUProcess/GPUConnectionToWebProcess.cpp:

(WebKit::GPUConnectionToWebProcess::createRenderingBackend):

  • GPUProcess/GPUConnectionToWebProcess.h:
  • GPUProcess/GPUConnectionToWebProcess.messages.in:
  • GPUProcess/graphics/RemoteGraphicsContextGL.cpp:

(WebKit::RemoteGraphicsContextGL::initialize):
(WebKit::RemoteGraphicsContextGL::stopListeningForIPC):

  • GPUProcess/graphics/RemoteRenderingBackend.cpp:

(WebKit::RemoteRenderingBackend::create):
(WebKit::RemoteRenderingBackend::RemoteRenderingBackend):
(WebKit::RemoteRenderingBackend::startListeningForIPC):
(WebKit::RemoteRenderingBackend::stopListeningForIPC):
(WebKit::RemoteRenderingBackend::messageSenderConnection const):

  • GPUProcess/graphics/RemoteRenderingBackend.h:
  • GPUProcess/graphics/WebGPU/RemoteGPU.cpp:

(WebKit::RemoteGPU::initialize):
(WebKit::RemoteGPU::stopListeningForIPC):

  • Platform/IPC/MessageReceiveQueueMap.cpp:

(IPC::MessageReceiveQueueMap::addImpl):
(IPC::MessageReceiveQueueMap::remove):

  • Platform/IPC/StreamClientConnection.cpp:

(IPC::StreamClientConnection::createWithDedicatedConnection):
(IPC::StreamClientConnection::StreamClientConnection):
(IPC::StreamClientConnection::~StreamClientConnection):
(IPC::StreamClientConnection::open):
(IPC::StreamClientConnection::invalidate):
(IPC::StreamClientConnection::connectionForTesting):

  • Platform/IPC/StreamClientConnection.h:

(IPC::StreamClientConnection::send):
(IPC::StreamClientConnection::sendSync):
(IPC::StreamClientConnection::waitForAndDispatchImmediately):
(IPC::StreamClientConnection::trySendSyncStream):

  • Platform/IPC/StreamServerConnection.cpp:

(IPC::StreamServerConnection::create):
(IPC::StreamServerConnection::createWithDedicatedConnection):
(IPC::StreamServerConnectionBase::StreamServerConnectionBase):
(IPC::StreamServerConnectionBase::~StreamServerConnectionBase):
(IPC::StreamServerConnectionBase::open):
(IPC::StreamServerConnectionBase::invalidate):
(IPC::StreamServerConnectionBase::startReceivingMessagesImpl):
(IPC::StreamServerConnectionBase::stopReceivingMessagesImpl):

  • Platform/IPC/StreamServerConnection.h:
  • Shared/IPCStreamTester.cpp:

(WebKit::IPCStreamTester::initialize):
(WebKit::IPCStreamTester::stopListeningForIPC):

  • WebProcess/GPU/graphics/RemoteGraphicsContextGLProxy.cpp:

(WebKit::RemoteGraphicsContextGLProxy::RemoteGraphicsContextGLProxy):
(WebKit::RemoteGraphicsContextGLProxy::disconnectGpuProcessIfNeeded):

  • WebProcess/GPU/graphics/RemoteRenderingBackendProxy.cpp:

(WebKit::RemoteRenderingBackendProxy::ensureGPUProcessConnection):
(WebKit::RemoteRenderingBackendProxy::disconnectGPUProcess):

  • WebProcess/GPU/graphics/RemoteRenderingBackendProxy.h:
  • WebProcess/GPU/graphics/WebGPU/RemoteGPUProxy.cpp:

(WebKit::RemoteGPUProxy::RemoteGPUProxy):
(WebKit::RemoteGPUProxy::abandonGPUProcess):

  • WebProcess/WebPage/IPCTestingAPI.cpp:

(WebKit::IPCTestingAPI::JSIPCStreamClientConnection::sendMessage):
(WebKit::IPCTestingAPI::JSIPCStreamClientConnection::sendSyncMessage):

12:20 AM Changeset in webkit [292802] by Diego Pino Garcia
  • 2 edits in trunk/Tools

[JHBuild] Unreviewed, fix 'glib-networking' module path

  • jhbuild/jhbuild-minimal.modules:
Note: See TracTimeline for information about the timeline view.