diff --git a/OPENCLAW.md b/OPENCLAW.md index 8f5f703efa346..6772055d935a6 100644 --- a/OPENCLAW.md +++ b/OPENCLAW.md @@ -145,6 +145,8 @@ baseline. Engine and Bun headers and libraries must be rebuilt together. ## Unreleased +- Release class-field identifier references when parser arenas are destroyed, preventing native string leaks during class initialization and Worker churn. + - Deliver pending worker heap-limit termination promptly after GC by invalidating optimized code on the mutator, preserving full-GC live accounting and external-buffer exclusions. - Preserve mimalloc pthread TLS-key ownership during shell exit by draining active setters before deletion; cover both late and in-flight allocations with native regressions. Builds on oven-sh/WebKit#698, thanks @dylan-conway. diff --git a/Source/JavaScriptCore/parser/Nodes.h b/Source/JavaScriptCore/parser/Nodes.h index 1470f2309a2a6..7971b1eb52d15 100644 --- a/Source/JavaScriptCore/parser/Nodes.h +++ b/Source/JavaScriptCore/parser/Nodes.h @@ -2401,7 +2401,8 @@ namespace JSC { ExpressionNode* m_argument; }; - class DefineFieldNode final : public StatementNode { + class DefineFieldNode final : public StatementNode, public ParserArenaDeletable { + JSC_MAKE_PARSER_ARENA_DELETABLE_ALLOCATED(DefineFieldNode); public: enum class Type { Name, PrivateName, ComputedName }; DefineFieldNode(const JSTokenLocation&, const Identifier&, ExpressionNode*, Type); diff --git a/Tools/TestWebKitAPI/CMakeLists.txt b/Tools/TestWebKitAPI/CMakeLists.txt index fb877881a9b0a..55b9b1a447c5c 100644 --- a/Tools/TestWebKitAPI/CMakeLists.txt +++ b/Tools/TestWebKitAPI/CMakeLists.txt @@ -221,6 +221,7 @@ if (ENABLE_JAVASCRIPTCORE) Tests/JavaScriptCore/DisallowVMEntry.cpp Tests/JavaScriptCore/InspectorConsoleMessage.cpp Tests/JavaScriptCore/MarkedVector.cpp + Tests/JavaScriptCore/ParserArena.cpp Tests/JavaScriptCore/PropertySlot.cpp Tests/JavaScriptCore/RegularExpression.cpp Tests/JavaScriptCore/StrongBlock.cpp diff --git a/Tools/TestWebKitAPI/Tests/JavaScriptCore/ParserArena.cpp b/Tools/TestWebKitAPI/Tests/JavaScriptCore/ParserArena.cpp new file mode 100644 index 0000000000000..177f0d4b5a1f8 --- /dev/null +++ b/Tools/TestWebKitAPI/Tests/JavaScriptCore/ParserArena.cpp @@ -0,0 +1,58 @@ +/* + * Copyright (C) 2026 Peter Steinberger All rights reserved. + * + * Redistribution and use in source and binary forms, with or without + * modification, are permitted provided that the following conditions + * are met: + * 1. Redistributions of source code must retain the above copyright + * notice, this list of conditions and the following disclaimer. + * 2. Redistributions in binary form must reproduce the above copyright + * notice, this list of conditions and the following disclaimer in the + * documentation and/or other materials provided with the distribution. + * + * THIS SOFTWARE IS PROVIDED BY APPLE INC. AND ITS CONTRIBUTORS ``AS IS'' + * AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, + * THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR + * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL APPLE INC. OR ITS CONTRIBUTORS + * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR + * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF + * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS + * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN + * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) + * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF + * THE POSSIBILITY OF SUCH DAMAGE. + */ + +#include "config.h" + +#include +#include +#include +#include +#include +#include + +namespace TestWebKitAPI { + +TEST(JavaScriptCore_ParserArena, DefineFieldReleasesIdentifier) +{ + WTF::initializeMainThread(); + JSC::initialize(); + RefPtr vm = JSC::VM::create(JSC::HeapType::Small); + JSC::JSLockHolder locker(vm.get()); + auto identifier = JSC::Identifier::fromString(*vm, "parserArenaFieldIdentifier"_s); + auto initialRefCount = identifier.impl()->refCount(); + + for (auto type : { JSC::DefineFieldNode::Type::Name, JSC::DefineFieldNode::Type::PrivateName, JSC::DefineFieldNode::Type::ComputedName }) { + { + JSC::ParserArena arena; + new (arena) JSC::DefineFieldNode(JSC::JSTokenLocation { }, identifier, nullptr, type); + EXPECT_EQ(initialRefCount + 1, identifier.impl()->refCount()); + } + EXPECT_EQ(initialRefCount, identifier.impl()->refCount()); + } + identifier = { }; + vm = nullptr; +} + +} // namespace TestWebKitAPI