fix(minifier): make __proto__ write tracking execution-order independent#24280
Conversation
How to use the Graphite Merge QueueAdd either label to this PR to merge it via the merge queue:
You must have a Graphite account in order to use the merge queue. Sign up using this link. An organization admin has enabled the Graphite Merge Queue in this repository. Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue. This stack of pull requests is managed by Graphite. Learn more about stacking. |
Merging this PR will not alter performance
Comparing Footnotes
|
__proto__ write tracking execution-order independent
Monitor OxcCommit:
|
Merge activity
|
…ndent (#24280) Fixes #21248 ### What In `propertyWriteSideEffects: false` mode, the minifier must keep a property write when the object's `__proto__` was written somewhere, because that write may have installed a setter. This tracking ran inside the same pass that removes writes, so a `__proto__` write the traversal reaches later — for example inside a hoisted function — was not recorded yet, and the property write was wrongly dropped. ### How The per-pass `proto_write_symbols` set is replaced by a `PROTO_WRITTEN` bit on `PersistentSymbolFacts` (introduced in the parent PR). The `Normalize` pass seeds it for the whole program before the fixed-point loop starts, so the order the loop visits expressions no longer matters. `track_proto_write` and the old set are deleted. The scan also catches shapes the old tracking never saw, such as destructuring targets (`[o.__proto__] = arr`). Default mode is unaffected: a symbol with a `__proto__` write already carries `MEMBER_WRITE_HAZARD`, which the default path checks separately. `tasks/minsize` output is byte-identical; the previously commented-out ordering test in `remove_unused_expression.rs` now runs. ### Example With `propertyWriteSideEffects: false`: ```js const obj = {}; f(); obj.a = 1; function f() { g(); obj.__proto__ = { set a(v) { console.log(v); } }; } ``` Before: `obj.a = 1` was dropped. The setter installed when `f()` runs never fires, so `console.log(1)` is lost. After: `obj.a = 1` is kept.
144288b to
34ff7b4
Compare
9c1b03b to
40f769d
Compare
### 🚀 Features - 616bfa2 minifier: Remove unreachable code after terminating statements (#24441) (Dunqing) - ddab89a data_structures: Add `likely` and `unlikely` functions (#24368) (overlookmotel) - a3a39f9 react_compiler: Implement enableEmitHookGuards codegen (#24329) (Boshen) - b79eef7 minifier: Apply De Morgan's law to negated comparison chains in jump guards and loop tests (#24279) (Dunqing) - 34ff7b4 minifier: Drop write-only property assignments to unused local bindings by default (#24112) (Dunqing) - 1b829d8 semantic: Record const enums in EnumData (#24268) (Dunqing) - ba0944c semantic: Add `Scoping::set_symbol_span` (#24221) (camc314) ### 🐛 Bug Fixes - 7d33363 minifier: Preserve guaranteed throws from class heritage evaluation (#24349) (Dunqing) - 058a62f semantic: Track ambient contexts in `SemanticBuilder` (#24327) (camc314) - 721eb0b transformer/decorator: Scope accessor class binding (#24330) (camc314) - 1ebdce3 semantic: Allow reserved keywords in ambient declaration types (#24325) (camc314) - 460176a track-memory-allocations: Exclude arena chunks from Sys allocs (#24292) (Dunqing) - af4922b transformer: Clear lowered namespace redeclarations (#24300) (camc314) - ffd2765 semantic: Mark declared computed `MethodDefinition`s as type references (#24296) (camc314) - f17514b isolated-declarations: Emit const readonly fields as types (#24288) (camc314) - 40f769d minifier: Make `__proto__` write tracking execution-order independent (#24280) (Dunqing) - 6371fed transformer: Remove stale enum member bindings (#24272) (camc314) - f05dfab transformer: Correct symbol flags for lowered namespaces (#24271) (Dunqing) - 84eeb55 transformer: Correct symbol flags for lowered enums (#24269) (Dunqing) - c3057da transformer: Preserve generated class binding spans (#24220) (camc314) - 8260096 transformer: Correct span for lowered namespace symbol (#24222) (camc314) - 42d00d3 semantic: Mark declared class heritage as type references (#24237) (camc314) - 588d997 semantic: Mark TS `PropertyDefinition`s computed fields as type references (#24233) (camc314) - 9b95632 semantic: Mark computed method keys in `TSMethodSignature`s as type references (#24232) (camc314) ### ⚡ Performance - 5b26643 transformer_plugins: Dispatch global defines by trailing name (#23666) (Boshen) - dce0f29 react_compiler: Replace all compiled functions in a single AST walk (#24403) (Boshen) - f85f0d8 ast: Delegate inherited enum variants in clone_in and estree derives (#23555) (Boshen) - 3ff0234 allocator: Remove `unwrap` from `ReplaceWith` (#24365) (overlookmotel) - ab22e80 transformer: Fix Rust 1.97 performance regression (#24354) (camc314) - b47585c parser: Use `ReplaceWith` instead of `TakeIn` (#24018) (overlookmotel) - b227a06 minifier: Use `ReplaceWith` instead of `TakeIn` (#24017) (overlookmotel) Co-authored-by: Boshen <[email protected]>

Fixes #21248
What
In
propertyWriteSideEffects: falsemode, the minifier must keep a property write when the object's__proto__was written somewhere, because that write may have installed a setter. This tracking ran inside the same pass that removes writes, so a__proto__write the traversal reaches later — for example inside a hoisted function — was not recorded yet, and the property write was wrongly dropped.How
The per-pass
proto_write_symbolsset is replaced by aPROTO_WRITTENbit onPersistentSymbolFacts(introduced in the parent PR). TheNormalizepass seeds it for the whole program before the fixed-point loop starts, so the order the loop visits expressions no longer matters.track_proto_writeand the old set are deleted. The scan also catches shapes the old tracking never saw, such as destructuring targets ([o.__proto__] = arr).Default mode is unaffected: a symbol with a
__proto__write already carriesMEMBER_WRITE_HAZARD, which the default path checks separately.tasks/minsizeoutput is byte-identical; the previously commented-out ordering test inremove_unused_expression.rsnow runs.Example
With
propertyWriteSideEffects: false:Before:
obj.a = 1was dropped. The setter installed whenf()runs never fires, soconsole.log(1)is lost.After:
obj.a = 1is kept.