Commit Graph
9889 Commits
Author SHA1 Message Date
Karl Seguin 1cab72edcd Merge pull request #3670 from lightpanda-io/default-sanitizer
mem: remove allocation for default sanitizer
2026-09-28 22:43:15 +08:00
Adrià Arrufat e7cb1779b1 Merge pull request #3637 from mvanhorn/fix/2529-android-termux-binary-limitation
docs: explain Android and Termux binary incompatibility
2026-09-28 15:08:57 +02:00
Pierre Tachoire f6dd43c346 Merge pull request #3654 from lightpanda-io/cors-by-default
Enable CORS by default
2026-09-28 14:32:49 +02:00
Pierre Tachoire be65962d68 testing: remove unused func 2026-09-28 14:04:11 +02:00
Pierre Tachoire 5789e1fc23 README: remove --experimental-features cors 2026-09-28 14:03:39 +02:00
Pierre Tachoire cebd8e3690 cors: fix unit tests when enabling cors by default 2026-09-28 12:23:29 +02:00
Karl Seguin 3ca791be4d fix typo 2026-09-28 18:16:46 +08:00
Karl Seguin 1cf025bcc8 mem: remove allocation for default sanitizer
https://github.com/lightpanda-io/browser/pull/3619 added proper support for
Sanitizer. A consequence of that is that every setHTML/parseHTML without an
explicit creates the default Sanitizer (with its ~300 entries).

This commit creates 1 app-level default sanitizer and uses it, internally, when
none is explicitly given. The sanitizer is immutable so can safely be used
across threads.
2026-09-28 18:12:08 +08:00
Pierre Tachoire 8d6ebf0635 replace --disable-cors by --disable-features cors 2026-09-28 12:03:18 +02:00
Pierre Tachoire 12d3880d20 enable cors by default
keep `--experimental-features cors` available for BC.
add `--disable-cors` option.
2026-09-28 12:03:18 +02:00
Karl Seguin 58357fea3e Merge pull request #3529 from lightpanda-io/nikneym/improve-cdp-error
`cdp`: report back invalid same-site
2026-09-28 16:20:45 +08:00
Karl Seguin 8a3bd6d4b2 Merge pull request #3663 from lightpanda-io/markdown-anchor-no-href
Treat <a> without href as text in markdown and clutter strip
2026-09-28 16:18:12 +08:00
Karl Seguin cfad479548 Merge pull request #3649 from lightpanda-io/cli-suggest-threshold
cli: scale the "did you mean" distance with the input's length
2026-09-28 16:05:53 +08:00
Karl Seguin 3aaed28d20 Merge pull request #3666 from lightpanda-io/domtokenlist-setters
webapi: add a number of DOMTokenList setters
2026-09-28 15:40:48 +08:00
Karl Seguin 915bf31622 Merge pull request #3667 from lightpanda-io/silence-test-logs
chore: silence expected error log in test
2026-09-28 15:39:42 +08:00
Karl Seguin 1bb4aba7fa Merge pull request #3668 from lightpanda-io/flaky-test-fix
ci: fix flaky test
2026-09-28 15:39:29 +08:00
Karl Seguin fd4eaeb01c Merge pull request #3669 from lightpanda-io/M_MMAP_THRESHOLD
mem: Set M_MMAP_THRESHOLD to 128K on linux builds
2026-09-28 15:39:13 +08:00
Karl Seguin cbc9c79afd Merge pull request #3664 from lightpanda-io/always-detach-global
v8: always detach global
2026-09-28 15:38:12 +08:00
nikneym 96d0f07b15 cdp: setCookie sameSite parity with Chrome 2026-09-28 10:27:32 +03:00
Adrià Arrufat b8a6994baf markdown: keep standalone href-less anchors on their own line
Adjacent placeholder anchors, like a JS-driven nav, ran together as
HomeAbout. Keep the standalone line placement linked anchors get and
drop only the link syntax.
2026-09-28 09:27:16 +02:00
Adrià Arrufat 1188554515 cli: read a url-like bare word as the url, not a misspelt command
`lightpanda version.io` was rejected as a misspelt `version`, 3 edits
within the length-scaled limit. Like curl, it fetches now: the command check
shares --dump's isUrlLike.
2026-09-28 09:22:29 +02:00
Karl Seguin 4caaa27411 mem: Set M_MMAP_THRESHOLD to 128K on linux builds
Following some experimentation, this sets M_MMAP_THRESHOLD to 128K on linux
builds IF it isn't explicit set, e.g. via the `MALLOC_MMAP_THRESHOLD_` env. This
allows users explicitly set it if they want.

I've been looking at this for a while, but my understanding is still basic. The
simplistic explanation is that glibc's allocator internally uses arenas.
Allocations above THRESHOLD skip these arenas and are allocated directly from
and freed directly to the OS. Allocations under this threshold are released
to the arena where they can be re-used. Everything works OK, EXCEPT for when it
comes time to release the memory from these arenas back to the OS. If free arena
memory is pinned under live memory, it cannot be released.

Various online posts / comments reference glibc as suffering from significant
fragmentation and "holding" onto memory. That's the behavior that we've seen.
Further, calls to malloc_trim reclaim the lost memory, so what we're seeing
aren't leaks.
2026-09-28 14:02:39 +08:00
Karl Seguin 58622ef7c4 Merge pull request #3571 from lightpanda-io/nikneym/playwright-id-track
`cdp`: answer inspector commands on the session that sent them
2026-09-28 12:36:44 +08:00
Karl Seguin e79c85a587 Merge pull request #3653 from staylor/fix/stylesheet-important-cascade
Honor !important when cascading tracked stylesheet properties
2026-09-28 12:23:02 +08:00
Karl Seguin 9aa748616b Simplify Inspector.Session ownership
Since AttachedSession is already heap-based, it's inspector_session is at a
fixed address and thus can own the session.

Also, hook in some noop callbacks on deinit.
2026-09-28 12:18:33 +08:00
Karl Seguin 46d16e229e Store !important as priority
Encode the !important'ness of a rule into its priority (we have the bit to
spare). This keeps the !important calculation the build-side, not the read side
and is more consistent with how the StyleManager generally works.

CSSStyleDeclaration `getPropertyValue` is now !important aware. Whereas before
an inline value would always win, it now cedes to an !important stylesheet rule
2026-09-28 11:55:34 +08:00
Karl Seguin ce46f90f1c Merge pull request #3657 from onnimonni/fix/input-select-email
webapi: input select() must not throw for email/number
2026-09-28 10:35:38 +08:00
Karl Seguin 72d612472d ci: fix flaky test 2026-09-28 10:34:59 +08:00
Karl Seguin 4ac219c438 zig fmt 2026-09-28 10:25:29 +08:00
Karl Seguin f96c85c2a3 chore: silence expected error log in test 2026-09-28 10:20:13 +08:00
Karl Seguin 550c2b3c61 apply same href-less detection to shell measurement 2026-09-28 10:17:13 +08:00
Karl Seguin 8f568c1382 webapi: add a number of DOMTokenList setters
While the token list itself is readonly, the attribute itself is settable. For
example, HTMLOutputElement's htmlFor says:

"Although the htmlFor property itself is read-only in the sense that you can't
replace the DOMTokenList object, you can still assign to the htmlFor property
directly"
2026-09-28 09:59:04 +08:00
Karl Seguin a9738c7df5 Merge pull request #3660 from lightpanda-io/nikneym/iframe-set-sandbox
`iframe`: add sandbox setter
2026-09-28 09:55:04 +08:00
Karl Seguin a844e38826 preserve correctsendKeys() behavior for webdriver 2026-09-28 09:49:13 +08:00
Karl Seguin 38e8957639 Merge pull request #3665 from lightpanda-io/orderfile-regen
orderfile: regenerate the hot-code profile
2026-09-28 09:18:46 +08:00
github-actions[bot] d0c8a24334 orderfile: regenerate the hot-code profile
hot set 16948KB resident at 4KB fault-around: 21493 text, 22328 rodata symbols
2026-09-28 01:08:30 +00:00
Karl Seguin 389c0826e9 Merge pull request #3642 from lightpanda-io/click-wait-networkidle
tools: wait for networkidle after an action-triggered navigation
2026-09-28 08:00:36 +08:00
Karl Seguin 4d94f7c92e v8: always detach global
Simplifies code and causes v8 to null the microtask queue, removing the
possibility of a UAF
2026-09-28 07:57:37 +08:00
Karl Seguin 111fd35258 have httpclient own idle time 2026-09-28 07:33:06 +08:00
Karl Seguin 895b967259 Merge pull request #3629 from lightpanda-io/nikneym/text-encoder-encode-into
`TextEncoder`: add `encodeInto`
2026-09-28 07:07:17 +08:00
Karl Seguin 8a31f29b8a Merge pull request #3634 from lightpanda-io/v8-wakeup
perf: v8 task wakeup
2026-09-28 07:07:02 +08:00
Karl Seguin 831af0ca37 cleanup code, re-use new helper 2026-09-28 06:46:27 +08:00
Halil Durak d180a3cac2 cdp: report back invalid same-site 2026-09-28 01:40:49 +03:00
Karl Seguin 52cb8cf47b disable poll (0) if there's a foreground task 2026-09-28 06:36:30 +08:00
nikneym 8ede89217a cdp: update tests 2026-09-28 01:29:12 +03:00
nikneym 56cb4205ae cdp: sessions own their inspector session
`Inspector` now supports several sessions; `startSession` allocates one (the V8 channel keeps its address) and `stopSession` frees it. They all connect to the same context group so every session see every context.

`BrowserContext.session_id` stays the primary session's id for the many event call sites.
2026-09-28 01:27:40 +03:00
Adrià Arrufat 2be33e4af8 clutter: don't count <a> without href as link text
Tag chips like <a class="tag">x</a> pushed short quotes on
quotes.toscrape.com/js/ over the 0.2 link-density limit, so
--strip-mode clutter pruned them as navigation.
2026-09-27 23:56:42 +02:00
nikneym 736be5b35b cdp: answer inspector commands on the session that sent them
Playwright's `browserContext.newCDPSession` must get its response on that session, not the primary one. Playwright keys its pending callbacks by session, finds none for that id, and throws
"Assertion error", which takes the whole process down.

Addresses #1838 and #1839.
2026-09-27 23:43:10 +03:00
Adrià Arrufat b6cde68ef6 markdown: render <a> without href as plain text
An anchor with no href is a placeholder, not a hyperlink, so emitting
[text]() produced a broken link. Render its children inline instead.
2026-09-27 21:17:08 +02:00
nikneym 395550488a iframe: add sandbox setter 2026-09-27 14:45:47 +03:00