Skip to content

fix(minifier): make __proto__ write tracking execution-order independent#24280

Merged
graphite-app[bot] merged 1 commit into
mainfrom
minifier-proto-written-fact
Jul 8, 2026
Merged

fix(minifier): make __proto__ write tracking execution-order independent#24280
graphite-app[bot] merged 1 commit into
mainfrom
minifier-proto-written-fact

Conversation

@Dunqing

@Dunqing Dunqing commented Jul 8, 2026

Copy link
Copy Markdown
Member

Fixes #21248

What

In propertyWriteSideEffects: false mode, the minifier must keep a property write when the object's __proto__ was written somewhere, because that write may have installed a setter. This tracking ran inside the same pass that removes writes, so a __proto__ write the traversal reaches later — for example inside a hoisted function — was not recorded yet, and the property write was wrongly dropped.

How

The per-pass proto_write_symbols set is replaced by a PROTO_WRITTEN bit on PersistentSymbolFacts (introduced in the parent PR). The Normalize pass seeds it for the whole program before the fixed-point loop starts, so the order the loop visits expressions no longer matters. track_proto_write and the old set are deleted. The scan also catches shapes the old tracking never saw, such as destructuring targets ([o.__proto__] = arr).

Default mode is unaffected: a symbol with a __proto__ write already carries MEMBER_WRITE_HAZARD, which the default path checks separately. tasks/minsize output is byte-identical; the previously commented-out ordering test in remove_unused_expression.rs now runs.

Example

With propertyWriteSideEffects: false:

const obj = {};
f();
obj.a = 1;
function f() {
  g();
  obj.__proto__ = { set a(v) { console.log(v); } };
}

Before: obj.a = 1 was dropped. The setter installed when f() runs never fires, so console.log(1) is lost.

After: obj.a = 1 is kept.

@github-actions github-actions Bot added the A-minifier Area - Minifier label Jul 8, 2026

Dunqing commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

How to use the Graphite Merge Queue

Add either label to this PR to merge it via the merge queue:

  • 0-merge - adds this PR to the back of the merge queue
  • hotfix - for urgent changes, fast-track this PR to the front of the merge queue

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has enabled the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@codspeed-hq

codspeed-hq Bot commented Jul 8, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 52 untouched benchmarks
⏩ 19 skipped benchmarks1


Comparing minifier-proto-written-fact (9c1b03b) with minifier-write-only-prop-dce (144288b)

Open in CodSpeed

Footnotes

  1. 19 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports.

@Dunqing Dunqing changed the title fix(minifier): make __proto__ write tracking execution-order independent fix(minifier): make __proto__ write tracking execution-order independent Jul 8, 2026
@Dunqing Dunqing added the run-monitor-oxc Add to a PR to dispatch oxc-project/monitor-oxc CI against it label Jul 8, 2026
@oxc-guard

oxc-guard Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

@oxc-guard oxc-guard Bot removed the run-monitor-oxc Add to a PR to dispatch oxc-project/monitor-oxc CI against it label Jul 8, 2026
@Dunqing
Dunqing marked this pull request as ready for review July 8, 2026 02:25
@Dunqing Dunqing added the 0-merge Merge with Graphite Merge Queue label Jul 8, 2026

Dunqing commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

Merge activity

…ndent (#24280)

Fixes #21248

### What

In `propertyWriteSideEffects: false` mode, the minifier must keep a property write when the object's `__proto__` was written somewhere, because that write may have installed a setter. This tracking ran inside the same pass that removes writes, so a `__proto__` write the traversal reaches later — for example inside a hoisted function — was not recorded yet, and the property write was wrongly dropped.

### How

The per-pass `proto_write_symbols` set is replaced by a `PROTO_WRITTEN` bit on `PersistentSymbolFacts` (introduced in the parent PR). The `Normalize` pass seeds it for the whole program before the fixed-point loop starts, so the order the loop visits expressions no longer matters. `track_proto_write` and the old set are deleted. The scan also catches shapes the old tracking never saw, such as destructuring targets (`[o.__proto__] = arr`).

Default mode is unaffected: a symbol with a `__proto__` write already carries `MEMBER_WRITE_HAZARD`, which the default path checks separately. `tasks/minsize` output is byte-identical; the previously commented-out ordering test in `remove_unused_expression.rs` now runs.

### Example

With `propertyWriteSideEffects: false`:

```js
const obj = {};
f();
obj.a = 1;
function f() {
  g();
  obj.__proto__ = { set a(v) { console.log(v); } };
}
```

Before: `obj.a = 1` was dropped. The setter installed when `f()` runs never fires, so `console.log(1)` is lost.

After: `obj.a = 1` is kept.
@graphite-app
graphite-app Bot force-pushed the minifier-write-only-prop-dce branch from 144288b to 34ff7b4 Compare July 8, 2026 02:28
@graphite-app
graphite-app Bot requested a review from overlookmotel as a code owner July 8, 2026 02:28
@graphite-app
graphite-app Bot force-pushed the minifier-proto-written-fact branch from 9c1b03b to 40f769d Compare July 8, 2026 02:29
Base automatically changed from minifier-write-only-prop-dce to main July 8, 2026 02:32
@graphite-app graphite-app Bot removed the 0-merge Merge with Graphite Merge Queue label Jul 8, 2026
@graphite-app
graphite-app Bot merged commit 40f769d into main Jul 8, 2026
31 checks passed
@graphite-app
graphite-app Bot deleted the minifier-proto-written-fact branch July 8, 2026 02:33
Boshen added a commit that referenced this pull request Jul 14, 2026
### 🚀 Features

- 616bfa2 minifier: Remove unreachable code after terminating statements
(#24441) (Dunqing)
- ddab89a data_structures: Add `likely` and `unlikely` functions
(#24368) (overlookmotel)
- a3a39f9 react_compiler: Implement enableEmitHookGuards codegen
(#24329) (Boshen)
- b79eef7 minifier: Apply De Morgan's law to negated comparison chains
in jump guards and loop tests (#24279) (Dunqing)
- 34ff7b4 minifier: Drop write-only property assignments to unused local
bindings by default (#24112) (Dunqing)
- 1b829d8 semantic: Record const enums in EnumData (#24268) (Dunqing)
- ba0944c semantic: Add `Scoping::set_symbol_span` (#24221) (camc314)

### 🐛 Bug Fixes

- 7d33363 minifier: Preserve guaranteed throws from class heritage
evaluation (#24349) (Dunqing)
- 058a62f semantic: Track ambient contexts in `SemanticBuilder` (#24327)
(camc314)
- 721eb0b transformer/decorator: Scope accessor class binding (#24330)
(camc314)
- 1ebdce3 semantic: Allow reserved keywords in ambient declaration types
(#24325) (camc314)
- 460176a track-memory-allocations: Exclude arena chunks from Sys allocs
(#24292) (Dunqing)
- af4922b transformer: Clear lowered namespace redeclarations (#24300)
(camc314)
- ffd2765 semantic: Mark declared computed `MethodDefinition`s as type
references (#24296) (camc314)
- f17514b isolated-declarations: Emit const readonly fields as types
(#24288) (camc314)
- 40f769d minifier: Make `__proto__` write tracking execution-order
independent (#24280) (Dunqing)
- 6371fed transformer: Remove stale enum member bindings (#24272)
(camc314)
- f05dfab transformer: Correct symbol flags for lowered namespaces
(#24271) (Dunqing)
- 84eeb55 transformer: Correct symbol flags for lowered enums (#24269)
(Dunqing)
- c3057da transformer: Preserve generated class binding spans (#24220)
(camc314)
- 8260096 transformer: Correct span for lowered namespace symbol
(#24222) (camc314)
- 42d00d3 semantic: Mark declared class heritage as type references
(#24237) (camc314)
- 588d997 semantic: Mark TS `PropertyDefinition`s computed fields as
type references (#24233) (camc314)
- 9b95632 semantic: Mark computed method keys in `TSMethodSignature`s as
type references (#24232) (camc314)

### ⚡ Performance

- 5b26643 transformer_plugins: Dispatch global defines by trailing name
(#23666) (Boshen)
- dce0f29 react_compiler: Replace all compiled functions in a single AST
walk (#24403) (Boshen)
- f85f0d8 ast: Delegate inherited enum variants in clone_in and estree
derives (#23555) (Boshen)
- 3ff0234 allocator: Remove `unwrap` from `ReplaceWith` (#24365)
(overlookmotel)
- ab22e80 transformer: Fix Rust 1.97 performance regression (#24354)
(camc314)
- b47585c parser: Use `ReplaceWith` instead of `TakeIn` (#24018)
(overlookmotel)
- b227a06 minifier: Use `ReplaceWith` instead of `TakeIn` (#24017)
(overlookmotel)

Co-authored-by: Boshen <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

A-minifier Area - Minifier

Projects

None yet

Development

Successfully merging this pull request may close these issues.

minifier: property write removal misses __proto__ setter installed after the write site

1 participant