Skip to content

[js-api] Fix misapplied ECMA-262 ReturnIfAbrupt shorthand (?, !) - #2256

Merged
Ms2ger merged 1 commit into
WebAssembly:mainfrom
kaist-plrg:fix/js-api-completion-record-shorthand
Sep 30, 2026
Merged

Ms2ger merged 1 commit into
WebAssembly:mainfrom
kaist-plrg:fix/js-api-completion-record-shorthand

Conversation

@f52985

@f52985 f52985 commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Two directions of the same underlying mistake - misreading what the ?/! shorthand actually requires:

  • [=!=] wrongly applied to ToJSValue (7 sites), OrdinaryObjectCreate (3 sites), CreateBuiltinFunction (1 site), and IsStrictlyEqual (2 sites): none of these ever return a Completion Record, so there is nothing for ! to unwrap. ToJSValue's own body is bare Let/Return statements with no Throw / NormalCompletion / ThrowCompletion anywhere; OrdinaryObjectCreate and CreateBuiltinFunction are declared with non-completion return types in ECMA-262; IsStrictlyEqual is declared with return type ': a Boolean'.
  • read the imports is missing [=?=] before HasProperty: unlike every other HasProperty/Get call in this exact algorithm, which are all correctly marked [=?=].

Two directions of the same underlying mistake - misreading what the
?/! shorthand actually requires:

- [=!=] applied to ToJSValue (7 sites), OrdinaryObjectCreate (3
  sites), CreateBuiltinFunction (1 site), and IsStrictlyEqual (2
  sites): none of these ever return a Completion Record, so there is
  nothing for ! to unwrap. ToJSValue's own body is bare Let/Return
  statements with no Throw/NormalCompletion/ThrowCompletion anywhere;
  OrdinaryObjectCreate and CreateBuiltinFunction are declared with
  non-completion return types in ECMA-262; IsStrictlyEqual is
  declared ': a Boolean'. Every other call site of these same
  operations elsewhere in this corpus (~40 occurrences of
  CreateBuiltinFunction alone, in webidl/index.bs) correctly omits
  the shorthand - these are the sole exceptions.
- read the imports is missing [=?=] before [$HasProperty$]: unlike
  every other [$HasProperty$]/[$Get$] call in this exact algorithm,
  which are all correctly marked [=?=], this one omission means the
  fallback branch it's meant to guard (falling back to reading from
  the plain importObject when a builtin-provided export doesn't have
  the requested property) can never fire, since the raw Completion
  Record it produces is compared against the literal false value as
  a Record, never true.
@Ms2ger
Ms2ger merged commit 31ef4f7 into WebAssembly:main Sep 30, 2026
11 checks passed
@f52985
f52985 deleted the fix/js-api-completion-record-shorthand branch October 1, 2026 11:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants