Truly independent web browser ladybird.org
Go to file
Luke Wilde 5f33383a7b LibJS: Propagate direct eval presence if the current scope is screwed
Previously it only deoptimized the parent scope if the current scope
contains direct eval, which is incorrect because code ran in direct
eval mode has access to the entire scope chain it was executed in.
The fix is to also propagate direct eval's presence if the current
scope is marked as being screwed by direct eval.

This fixes Google's botguard failing to complete on Google sign in, as
it tried to access local variables outside of a direct parent function
with eval, causing it throw "unhandled" exceptions. Unhandled is in
quotes because their bytecode VM _technically_ caught it, but it was
considered an unhandled exception. This was determined by removing get
optimizations and then adding debug output for every get operation.
Using this, I noticed that for these errors, it would access the
'message' and 'stack' properties. This is because their error handler
function noticed this was not a synthesised error, which is never
expected to happen. That was determined by using Chrome Devtools 'pause
on handled exception' feature, and noticing it never threw a '[var] is
not defined' exception, but only synthesized error objects which
contained a sentinel value to let it know it was synthesized.

I added debug output to eval to print out what was being eval'd because
it makes heavy use of eval. This revealed that the exceptions only came
from eval.

I then dumped every generated executable and noticed the variables it
was trying to access were generated as local variables in the top
scope. This led to checking what makes a variable considered local or
not, which then lead to this block of code in ~ScopePusher that
propagates eval presence only to the immediate parent scope. This
variable directly controls whether to create all variables properly
with variable environments and bindings or allow them to be stored as
local registers tied to that function's executable.

Since this now lets botguard run to completion, it no longer considers
us to be an insecure/potential bot browser when signing in, now
allowing us to be able to sign in to Google.
2025-01-17 14:36:03 +01:00
.devcontainer Devcontainer: Add a Fedora 41 devcontainer for use in CI 2024-12-31 13:42:50 -07:00
.github CI: Do not insinuate PRs can be reopened in stalebot's close message 2025-01-16 23:40:19 +01:00
AK AK: Add a const iterator for COWVector 2025-01-17 10:13:51 +01:00
Base/res LibWeb/CSS: Implement the color-scheme CSS property 2025-01-08 11:18:13 +00:00
Documentation LibWeb: Update add_libweb_test.py to support Screenshot, Ref, and Layout 2025-01-13 14:25:26 +00:00
Libraries LibJS: Propagate direct eval presence if the current scope is screwed 2025-01-17 14:36:03 +01:00
Meta LibWeb/CSS: Merge RotationStyleValue into TransformationStyleValue 2025-01-17 10:12:39 +01:00
Services LibWeb: Use finalize for cleaning up all navigables 2025-01-17 10:08:42 +01:00
Tests LibWeb: Always return a KeyAlgorithm from RsaHashedKeyAlgorithm 2025-01-17 12:43:03 +01:00
Toolchain Meta: Update vcpkg to the December 2024 release 2024-12-22 11:33:19 +01:00
UI headless-browser: Add support for crash tests 2025-01-17 09:08:15 +01:00
Utilities LibURL+LibWeb: Make URL::basic_parse return an Optional<URL> 2025-01-11 10:08:29 -05:00
.clang-format Meta: Support using clang-format on Objective-C++ files 2023-08-22 21:36:19 -04:00
.clang-tidy Everywhere: Hoist the Libraries folder to the top-level 2024-11-10 12:50:45 +01:00
.clangd Meta: Change the default build directories to exclude "ladybird" prefix 2024-11-06 10:38:57 -07:00
.editorconfig Meta: Add .editorconfig 2022-09-10 17:32:55 +01:00
.gitattributes LibGfx: Remove support for the various "portable" image formats 2024-06-17 21:57:35 +02:00
.gitignore Everywhere: Hoist the Libraries folder to the top-level 2024-11-10 12:50:45 +01:00
.gn Meta: Automatically generate a compilation database for clangd 2023-11-14 14:29:35 -05:00
.mailmap Meta: Update my e-mail address everywhere 2024-10-04 13:19:50 +02:00
.pre-commit-config.yaml Meta: Replace deprecated pre-commit stage name 2024-10-18 09:40:59 +02:00
.prettierignore Everywhere: Hoist the Libraries folder to the top-level 2024-11-10 12:50:45 +01:00
.prettierrc
.swift-format Meta: Add swift-format configuration 2024-07-30 18:38:02 -06:00
.ycm_extra_conf.py Meta: Make YCM return flags as Python list 2024-07-06 14:50:43 -06:00
CMakeLists.txt CMake: Add workaround for binutils+patchelf incompatability 2024-12-12 17:22:34 -07:00
CMakePresets.json CMake: Rename our triplets to their canonical names 2024-12-22 15:48:30 -07:00
CODE_OF_CONDUCT.md Meta: Add code of conduct (from the Ruby community) 2024-10-02 09:49:52 +02:00
CONTRIBUTING.md Meta: Switch to clang-format-19 as the standard formatter 2024-12-28 05:39:32 -08:00
flake.lock Flake: Add and run formatter + Rename devshell 2024-12-18 15:15:42 +00:00
flake.nix Flake: Add and run formatter + Rename devshell 2024-12-18 15:15:42 +00:00
ISSUES.md Docs: Add info about --enable-idl-tracing flag 2025-01-15 13:25:35 +00:00
LICENSE Meta: Update root LICENSE to say Ladybird instead of SerenityOS 2024-06-04 07:25:44 +02:00
README.md Libraries: Remove LibArchive 2024-11-25 13:37:45 +01:00
SECURITY.md Documentation: Make updates to align better with new issue template 2024-10-31 09:18:08 +01:00
shell.nix Flake/devshell: Add more useful packages 2024-12-27 17:13:26 -07:00
vcpkg-configuration.json Meta: Add overlay port for vulkan-loader 2024-07-07 15:56:59 +02:00
vcpkg.json Meta: Update ffmpeg to 7.1 2025-01-06 12:29:02 +01:00

Ladybird

Ladybird is a truly independent web browser, using a novel engine based on web standards.

Important

Ladybird is in a pre-alpha state, and only suitable for use by developers

Features

We aim to build a complete, usable browser for the modern web.

Ladybird uses a multi-process architecture with a main UI process, several WebContent renderer processes, an ImageDecoder process, and a RequestServer process.

Image decoding and network connections are done out of process to be more robust against malicious content. Each tab has its own renderer process, which is sandboxed from the rest of the system.

At the moment, many core library support components are inherited from SerenityOS:

  • LibWeb: Web rendering engine
  • LibJS: JavaScript engine
  • LibWasm: WebAssembly implementation
  • LibCrypto/LibTLS: Cryptography primitives and Transport Layer Security
  • LibHTTP: HTTP/1.1 client
  • LibGfx: 2D Graphics Library, Image Decoding and Rendering
  • LibUnicode: Unicode and locale support
  • LibMedia: Audio and video playback
  • LibCore: Event loop, OS abstraction layer
  • LibIPC: Inter-process communication

How do I build and run this?

See build instructions for information on how to build Ladybird.

Ladybird runs on Linux, macOS, Windows (with WSL2), and many other *Nixes.

How do I read the documentation?

Code-related documentation can be found in the documentation folder.

Get in touch and participate!

Join our Discord server to participate in development discussion.

Please read Getting started contributing if you plan to contribute to Ladybird for the first time.

Before opening an issue, please see the issue policy and the detailed issue-reporting guidelines.

The full contribution guidelines can be found in CONTRIBUTING.md.

License

Ladybird is licensed under a 2-clause BSD license.