Update on what happened in WebKit in the week from September 21 to September 28.
Following the stable releases last week, we have the first security advisory covering fixes included in them; the flurry of fixes and polish for the Skia compositor continues; SharedArrayBuffer gets re-enabled, and more.
Cross-Port 🐱
Fixed a crash on exit in WebKitGTK
and WPE WebKit, caused by the EGL display being torn down in an atexit()
handler while other threads were still using it, by now destroying it on the
main thread once the GPU process has stopped its WebGL thread and the web
process has closed its pages.
Fixed moving steps for source
element to account for the <media> and <model> elements.
JavaScriptCore 🐟
The built-in JavaScript/ECMAScript engine for WebKit, also known as JSC or SquirrelFish.
SharedArrayBuffer is now enabled for the WPE and GTK
ports.
SharedArrayBuffer is exposed when the origin is cross-origin isolated. We have
enabled 35 associated cross-origin isolation tests. Initialization was
designed to work with Android service-launched processes, too.
Graphics 🖼️
Fixed a bug with 3D-transformed elements that are tilted so far away from the viewer that part of them ends up behind the camera, where WebKit got the visible area of the element wrong and computed the hidden part instead. As a result, the visible part of such elements is no longer left blank in WebKitGTK and WPE—painting and hit-testing works properly now.
Fixed oversized damage regions for 3D-transformed layers that cross the camera plane, by clipping their projected polygon against the clip bounds so the damage now matches what the layer actually paints.
GPU renderer small paths now use Skia distance fields. Bitmap atlas entries depended on the transform and subpixel position, causing animated paths to be re-rasterized and uploaded every frame. With distance field indexed entries we can reuse them across transforms. We are improving MotionMark Suits results on Raspberry Pi 4 and desktop.
Fixed the paint order of preserve-3d
layers that cross the camera plane in
the Skia-based compositor. Layer corners behind the camera used to be flipped
to the far side of the screen when projected—layers were sorted against the
wrong geometry and far layers painted over near ones. Now the part of a layer
that lies behind the camera is clipped away before sorting, which makes
complex 3D scenes like the CSS FPS
demo render correctly.
Aligned the filter surface with the device pixel grid in the Skia-based compositor, so layers with CSS filters that end up at fractional device positions are no longer resampled when the filtered result is drawn. This fixes wrong colors in the outermost rows and columns of pixels of such layers, which now render the same as they would without a filter.
Fixed SMIL-animated viewBox
changes being ignored on the
outermost <svg> element in the Layer-Based SVG Engine (LBSE), bringing it in
line with the legacy SVG engine.
Fixed edge artifacts on scaled or transformed non-repeating background images in the Skia-based compositor, which painted all composited background images as if they repeat, so a thin line of the opposite edge showed up along the border. Only tiles that actually repeat are painted that way now, which removes the yellow line that showed up above the gun in the CSS FPS demo. This fixes the last known artifact in that demo.
Fixed rendering artifacts in
WebKitGTK and WPE WebKit for 3D-transformed layers that extend behind the
camera under a perspective (for example a large element under
rotateX(90deg)), whose re-composited area came out too small because corners
behind the camera were projected onto the wrong side of the frame, and are now
clipped away before mapping.
WebKitGTK 🖥️
Fixed touch positions in the GTK
port, which were offset by the
surface transform, the room left for the client-side decoration shadows,
because it was not subtracted from the raw GdkEvent position, so every touch
landed away from the finger unless the window was maximized. The same change
cancels the touch sequences that were stranded when the web view is unmapped
or a dialog was shown, which left the page with a finger that was never
released.
WPE WebKit 📟
WPE Platform API 🧩
New, modern platform API that supersedes usage of libwpe and WPE backends.
The ENABLE_WPE_PLATFORM build option has been
removed.
The new WPE Platform API, which was enabled by default since 2.54, is now
always enabled.
Releases 📦️
A new security advisory, WSA-2026-0006, has been published for
WebKitGTK and for
WPE. This covers issues
fixed in the recent 2.54.0 releases, and for the first time includes security
issues fixed in the bundled ANGLE and
Skia libraries. Updating to the latest stable release is
highly recommended.
That’s all for this week!