Branch: refs/heads/webkitglib/2.54
  Home:   https://github.com/WebKit/WebKit
  Commit: bcb07b92c8640e216af36e1b3b646cea47b80e53
      
https://github.com/WebKit/WebKit/commit/bcb07b92c8640e216af36e1b3b646cea47b80e53
  Author: Fujii Hironori <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    M LayoutTests/fast/events/touch/basic-multi-touch-events-limited.html
    M LayoutTests/fast/events/touch/basic-multi-touch-events.html
    M LayoutTests/fast/events/touch/basic-single-touch-events.html
    M LayoutTests/fast/events/touch/frame-hover-update.html
    M LayoutTests/fast/events/touch/gesture/gesture-tap-active-state.html
    M LayoutTests/fast/events/touch/input-touch-target.html
    M LayoutTests/fast/events/touch/multi-touch-grouped-targets.html
    M LayoutTests/fast/events/touch/multi-touch-inside-nested-iframes.html
    M LayoutTests/fast/events/touch/multi-touch-some-without-handlers.html
    M LayoutTests/fast/events/touch/ontouchstart-active-selector.html
    M LayoutTests/fast/events/touch/resources/misc-touch-helpers.js
    M LayoutTests/fast/events/touch/resources/send-touch-up.html
    M LayoutTests/fast/events/touch/resources/touch-stale-node-crash.js
    M LayoutTests/fast/events/touch/send-oncancel-event.html
    M LayoutTests/fast/events/touch/tap-highlight-color.html
    M LayoutTests/fast/events/touch/touch-active-state.html
    M LayoutTests/fast/events/touch/touch-before-pressing-spin-button.html
    M LayoutTests/fast/events/touch/touch-event-frames.html
    M LayoutTests/fast/events/touch/touch-event-pageXY.html
    M LayoutTests/fast/events/touch/touch-inside-iframe-scrolled.html
    M LayoutTests/fast/events/touch/touch-inside-iframe.html
    M LayoutTests/fast/events/touch/touch-scaled-scrolled.html
    M LayoutTests/fast/events/touch/touch-target-limited.html
    M LayoutTests/fast/events/touch/touch-target.html
    M LayoutTests/fast/events/touch/zoomed-touch-event-pageXY.html
    M LayoutTests/platform/glib/TestExpectations
    M LayoutTests/platform/wpe/TestExpectations

  Log Message:
  -----------
  Cherry-pick 318371@main (5ca0a73ea682). 
https://bugs.webkit.org/show_bug.cgi?id=319874

    Rewrite touch event layout tests with EventSender asyncTouch* methods
    https://bugs.webkit.org/show_bug.cgi?id=319874

    Reviewed by Carlos Alberto Lopez Perez.

    317140@main added EventSender.asyncTouch* methods. Rewrote all remaining 
touch
    event layout tests with them.

    * LayoutTests/fast/events/touch/basic-multi-touch-events-limited.html:
    * LayoutTests/fast/events/touch/basic-multi-touch-events.html:
    * LayoutTests/fast/events/touch/basic-single-touch-events.html:
    * LayoutTests/fast/events/touch/frame-hover-update.html:
    * LayoutTests/fast/events/touch/gesture/gesture-tap-active-state.html:
    * LayoutTests/fast/events/touch/input-touch-target.html:
    * LayoutTests/fast/events/touch/multi-touch-grouped-targets.html:
    * LayoutTests/fast/events/touch/multi-touch-inside-nested-iframes.html:
    * LayoutTests/fast/events/touch/multi-touch-some-without-handlers.html:
    * LayoutTests/fast/events/touch/ontouchstart-active-selector.html:
    * LayoutTests/fast/events/touch/resources/misc-touch-helpers.js:
    * LayoutTests/fast/events/touch/send-oncancel-event.html:
    * LayoutTests/fast/events/touch/tap-highlight-color.html:
    * LayoutTests/fast/events/touch/touch-active-state.html:
    * LayoutTests/fast/events/touch/touch-before-pressing-spin-button.html:
    * LayoutTests/fast/events/touch/touch-event-frames.html:
    * LayoutTests/fast/events/touch/touch-event-pageXY.html:
    * LayoutTests/fast/events/touch/touch-inside-iframe-scrolled.html:
    * LayoutTests/fast/events/touch/touch-inside-iframe.html:
    * LayoutTests/fast/events/touch/touch-scaled-scrolled.html:
    * LayoutTests/fast/events/touch/touch-target-limited.html:
    * LayoutTests/fast/events/touch/touch-target.html:
    * LayoutTests/fast/events/touch/zoomed-touch-event-pageXY.html:
    * LayoutTests/fast/events/touch/resources/send-touch-up.html:
    * LayoutTests/fast/events/touch/resources/touch-stale-node-crash.js:
    * LayoutTests/platform/glib/TestExpectations:
    * LayoutTests/platform/wpe/TestExpectations:

    Canonical link: https://commits.webkit.org/318371@main

Canonical link: https://commits.webkit.org/317695.383@webkitglib/2.54


  Commit: f8e45f93e4a9064fab813d4e7c521a2e4791d405
      
https://github.com/WebKit/WebKit/commit/f8e45f93e4a9064fab813d4e7c521a2e4791d405
  Author: Fujii Hironori <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    M LayoutTests/fast/events/touch/basic-multi-touch-events-limited.html
    M LayoutTests/fast/events/touch/basic-multi-touch-events.html
    M LayoutTests/fast/events/touch/basic-single-touch-events.html
    M LayoutTests/fast/events/touch/input-touch-target.html
    M LayoutTests/fast/events/touch/moved-touch-target.html
    M LayoutTests/fast/events/touch/multi-touch-grouped-targets.html
    M LayoutTests/fast/events/touch/multi-touch-inside-iframes.html
    M LayoutTests/fast/events/touch/multi-touch-inside-nested-iframes.html
    M LayoutTests/fast/events/touch/multi-touch-some-without-handlers.html
    M LayoutTests/fast/events/touch/removed-fragment-touch-target.html
    M LayoutTests/fast/events/touch/removed-touch-target.html
    M LayoutTests/fast/events/touch/resources/touch-stale-node-crash.js
    M LayoutTests/fast/events/touch/send-oncancel-event.html
    M LayoutTests/fast/events/touch/tap-highlight-color.html
    M LayoutTests/fast/events/touch/text-node-touch-target.html
    M LayoutTests/fast/events/touch/textarea-touch-target.html
    M LayoutTests/fast/events/touch/touch-active-state.html
    M LayoutTests/fast/events/touch/touch-coords-in-zoom-and-scroll.html
    M LayoutTests/fast/events/touch/touch-event-frames.html
    M LayoutTests/fast/events/touch/touch-event-pageXY.html
    M LayoutTests/fast/events/touch/touch-inside-iframe.html
    M LayoutTests/fast/events/touch/touch-scaled-scrolled.html
    M LayoutTests/fast/events/touch/touch-slider-no-js-touch-listener.html
    M LayoutTests/fast/events/touch/touch-slider.html
    M LayoutTests/fast/events/touch/touch-stale-node-crash.html
    M LayoutTests/fast/events/touch/touch-target.html
    M LayoutTests/resources/ui-helper.js
    M Source/WTF/Scripts/Preferences/UnifiedWebPreferences.yaml
    M Source/WTF/wtf/PlatformEnableGlib.h
    M Source/WebCore/dom/Document.cpp
    M Source/WebCore/html/HTMLInputElementInlines.h
    M Source/WebCore/page/scrolling/ScrollingTree.cpp
    M Source/WebCore/page/scrolling/ScrollingTree.h
    M Source/WebCore/page/scrolling/ThreadedScrollingTree.h
    M Source/WebCore/page/scrolling/coordinated/ScrollingTreeCoordinated.cpp
    M Source/WebCore/page/scrolling/coordinated/ScrollingTreeCoordinated.h
    M Source/WebCore/platform/ScrollingEffectsController.cpp
    M Source/WebKit/UIProcess/WebPageProxy.cpp
    M Source/WebKit/UIProcess/WebPageProxy.h
    M Source/WebKit/WebProcess/WebPage/EventDispatcher.cpp
    M Source/WebKit/WebProcess/WebPage/EventDispatcher.h
    M Source/WebKit/WebProcess/WebPage/EventDispatcher.messages.in
    M Source/WebKit/WebProcess/WebPage/WebPage.cpp
    M Source/WebKit/WebProcess/WebPage/WebPage.h

  Log Message:
  -----------
  Cherry-pick 319347@main (2dce2395a46b). 
https://bugs.webkit.org/show_bug.cgi?id=318938

    [GTK][WPE] Support touch event asynchronous scrolling
    https://bugs.webkit.org/show_bug.cgi?id=318938

    Reviewed by Carlos Garcia Campos.

    GTK and WPE ports support touch events, but previously supported the
    asynchronous scrolling only for wheel events. While the iOS port supports
    asynchronous scrolling for touch events too, its platform layer tree and
    scrolling tree reside in the UIProcess. In contrast, GTK and WPE maintain 
both
    trees in the WebProcess using Coordinated Graphics, so the iOS 
implementation
    cannot be directly reused.

    This patch adds support for touch event asynchronous scrolling in GTK and 
WPE
    by following an approach similar to asynchronous wheel event scrolling:

    1. Enable ENABLE_TOUCH_EVENT_REGIONS to register touch related event 
regions to
       the platform layer tree.
    2. Send touch events to EventDispatcher in the EventDispatcher thread of 
web process.
    3. Handle touch events asynchronously or synchronously depending on whether 
the
       touch target falls within a non-passive touch event region.

    Additionally, updated touch event layout tests. Because touch event regions
    must be calculated and propagated to the scrolling tree before dispatching
    touch events, tests registering new event listeners now wait for two 
animation
    frames before dispatching touch events. Added a new helper function
    UIHelper.renderingComplete().

    * Source/WTF/Scripts/Preferences/UnifiedWebPreferences.yaml:
    * Source/WTF/wtf/PlatformEnableGlib.h:
    * Source/WebCore/dom/Document.cpp:
    (WebCore::Document::hasTouchEventHandlers const):
    * Source/WebCore/page/scrolling/ScrollingTree.cpp:
    (WebCore::ScrollingTree::determineTouchEventTrackingTypeForPoint):
    (WebCore::ScrollingTree::mainFrameScrollOffset const):
    * Source/WebCore/page/scrolling/ScrollingTree.h:
    * Source/WebCore/page/scrolling/coordinated/ScrollingTreeCoordinated.cpp:
    (WebCore::ScrollingTreeCoordinated::findTouchEventTrackingTypeForPoint 
const):
    (WebCore::findLayerForPoint):
    (WebCore::mergeTrackingTypes):
    (WebCore::ScrollingTreeCoordinated::eventTrackingTypeForTouchEvent):
    (WebCore::findLayerOfEventRegionAtPoint):
    * Source/WebCore/page/scrolling/coordinated/ScrollingTreeCoordinated.h:
    * Source/WebKit/UIProcess/WebPageProxy.cpp:
    (WebKit::WebPageProxy::processNextQueuedTouchEvent):
    (WebKit::WebPageProxy::touchEventHandlingCompleted):
    (WebKit::WebPageProxy::handleTouchEvent):
    * Source/WebKit/UIProcess/WebPageProxy.h:
    * Source/WebKit/WebProcess/WebPage/EventDispatcher.cpp:
    (WebKit::mergeTrackingTypes):
    (WebKit::EventDispatcher::updateTouchEventTracking):
    (WebKit::EventDispatcher::touchEventTrackingType const):
    (WebKit::EventDispatcher::dispatchTouchEventViaMainThread):
    (WebKit::EventDispatcher::touchEvent):
    (WebKit::EventDispatcher::EventDispatcher):
    * Source/WebKit/WebProcess/WebPage/EventDispatcher.h:
    * Source/WebKit/WebProcess/WebPage/EventDispatcher.messages.in:
    * Source/WebKit/WebProcess/WebPage/WebPage.cpp:
    (WebKit::WebPage::dispatchTouchEvent):
    * Source/WebKit/WebProcess/WebPage/WebPage.h:
    * LayoutTests/fast/events/touch/basic-multi-touch-events-limited.html:
    * LayoutTests/fast/events/touch/basic-multi-touch-events.html:
    * LayoutTests/fast/events/touch/basic-single-touch-events.html:
    * LayoutTests/fast/events/touch/input-touch-target.html:
    * LayoutTests/fast/events/touch/moved-touch-target.html:
    * LayoutTests/fast/events/touch/multi-touch-grouped-targets.html:
    * LayoutTests/fast/events/touch/multi-touch-inside-iframes.html:
    * LayoutTests/fast/events/touch/multi-touch-inside-nested-iframes.html:
    * LayoutTests/fast/events/touch/multi-touch-some-without-handlers.html:
    * LayoutTests/fast/events/touch/removed-fragment-touch-target.html:
    * LayoutTests/fast/events/touch/removed-touch-target.html:
    * LayoutTests/fast/events/touch/send-oncancel-event.html:
    * LayoutTests/fast/events/touch/tap-highlight-color.html:
    * LayoutTests/fast/events/touch/text-node-touch-target.html:
    * LayoutTests/fast/events/touch/textarea-touch-target.html:
    * LayoutTests/fast/events/touch/touch-active-state.html:
    * LayoutTests/fast/events/touch/touch-coords-in-zoom-and-scroll.html:
    * LayoutTests/fast/events/touch/touch-event-frames.html:
    * LayoutTests/fast/events/touch/touch-event-pageXY.html:
    * LayoutTests/fast/events/touch/touch-inside-iframe.html:
    * LayoutTests/fast/events/touch/touch-scaled-scrolled.html:
    * LayoutTests/fast/events/touch/touch-slider-no-js-touch-listener.html:
    * LayoutTests/fast/events/touch/touch-slider.html:
    * LayoutTests/fast/events/touch/touch-target.html:
    * LayoutTests/fast/events/touch/resources/touch-stale-node-crash.js:
    (onload.async await):
    (onload):
    (onload.async if): Deleted.
    * LayoutTests/fast/events/touch/touch-stale-node-crash.html:
    * LayoutTests/resources/ui-helper.js:
    (window.UIHelper.async renderingUpdate):
    (window.UIHelper.async renderingComplete):
    * Source/WebCore/html/HTMLInputElementInlines.h:
    (WebCore::HTMLInputElement::updateTouchEventHandler):
    * Source/WebCore/platform/ScrollingEffectsController.cpp:
    (WebCore::ScrollingEffectsController::handleWheelEvent):
    * Source/WebCore/page/scrolling/ThreadedScrollingTree.h:
    (WebCore::ThreadedScrollingTree::eventTrackingTypeForTouchEvent):

    Canonical link: https://commits.webkit.org/319347@main

Canonical link: https://commits.webkit.org/317695.384@webkitglib/2.54


  Commit: 757cfcd2740a1cafeedddfcebd1fcae1c342792d
      
https://github.com/WebKit/WebKit/commit/757cfcd2740a1cafeedddfcebd1fcae1c342792d
  Author: Pablo Saavedra <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    A 
LayoutTests/fast/events/touch/touch-move-during-pending-touch-start-expected.txt
    A LayoutTests/fast/events/touch/touch-move-during-pending-touch-start.html
    M Source/WebKit/UIProcess/WebPageProxy.cpp

  Log Message:
  -----------
  Cherry-pick 319960@main (f0c538173039). 
https://bugs.webkit.org/show_bug.cgi?id=322698

    REGRESSION(319347@main): Touchmove is dropped when it arrives while 
touchstart is still in flight
    https://bugs.webkit.org/show_bug.cgi?id=322698

    Reviewed by Fujii Hironori.

    319347@main ([GTK][WPE] Support touch event asynchronous scrolling) 
introduced a
    serialized touch event queue in the UI process for the 
COORDINATED_TOUCH_EVENTS
    path, which coalesces consecutive touch moves onto the queued one. The 
coalescing
    condition, however, has no fallback:

        if (event.type() == WebEventType::TouchMove && 
!touchEventQueue.isEmpty()) {
            QueuedTouchEvents& lastEvent = touchEventQueue.last();
            if (lastEvent.forwardedEvent.type() == WebEventType::TouchMove)
                lastEvent.deferredTouchEvents.append(event);
        } else {
            touchEventQueue.append(event);
            ...
        }

    When a TouchMove arrives while the queue is non-empty but the last queued 
event is
    not itself a TouchMove -- that is, while the TouchStart is still awaiting 
its
    asynchronous reply from the web process -- neither branch runs and the 
event is
    silently discarded. It is not forwarded to the web process and it is not 
appended
    to deferredTouchEvents, so it never reaches the DOM and, because
    PageClientImpl::doneWithTouchEvent() is only called for events that made it 
into
    the queue, it never reaches the WPE gesture controller either.

    The practical effect is that a touch drag delivered as a back-to-back
    down/move/up burst degenerates into a second tap: the page observes 
touchstart
    and touchend with no touchmove, the gesture controller sees no motion and
    synthesizes mousemove/mousedown/mouseup/click, and nothing scrolls. This is 
how
    touch events arrive both from a real touchscreen and from WebDriver, which 
emits
    a single WPE_EVENT_TOUCH_MOVE per move action with no interpolation and no 
wait
    between events (see the TODO in 
WebAutomationSession::platformSimulateTouchInteraction,
    https://bugs.webkit.org/show_bug.cgi?id=275031).

    Before 319347@main, the generic ENABLE(TOUCH_EVENTS) path sent every touch 
event
    straight through with sendWithAsyncReply and no queue at all, and on 
non-Cocoa
    platforms updateTouchEventTracking() unconditionally marked every tracking 
type
    Synchronous, so every touchmove reached the DOM.

    Restructure the condition so that coalescing is an early return and every 
other
    event, including a TouchMove that cannot be coalesced, falls through to the
    enqueue path. The intended coalescing behaviour is unchanged.

    This went unnoticed because every test in fast/events/touch/ drives the 
engine
    through eventSender.asyncTouchStart()/asyncTouchMove()/asyncTouchEnd(), 
each of
    which awaits its round trip via 
doAfterProcessingAllPendingTouchAndWheelEvents().
    The queue is therefore always empty by the time the next event is 
dispatched, and
    the dropped-event path is never exercised.

    The new test uses the synchronous eventSender touch API instead, which 
dispatches
    the event and returns without waiting, so the whole sequence is pushed back 
to
    back the way a touchscreen or WebDriver delivers it. Its listeners are 
registered
    non-passive so that the touch start is tracked synchronously: its reply then
    requires the web process main thread, which is blocked in the synchronous
    eventSender message for the touch move, making the reproduction 
deterministic
    rather than a race.

    Test: fast/events/touch/touch-move-during-pending-touch-start.html
    * 
LayoutTests/fast/events/touch/touch-move-during-pending-touch-start-expected.txt:
 Added.
    * LayoutTests/fast/events/touch/touch-move-during-pending-touch-start.html: 
Added.
    * Source/WebKit/UIProcess/WebPageProxy.cpp:
    (WebKit::WebPageProxy::handleTouchEvent):

    Co-Authored-By: Claude Sonnet 5 <[email protected]>
    Canonical link: https://commits.webkit.org/319960@main

Canonical link: https://commits.webkit.org/317695.385@webkitglib/2.54


  Commit: 7ea14cf7c3f99344cc6182f69a0b1515cbf28159
      
https://github.com/WebKit/WebKit/commit/7ea14cf7c3f99344cc6182f69a0b1515cbf28159
  Author: Claudio Saavedra <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    M LayoutTests/platform/glib/TestExpectations
    M LayoutTests/platform/gtk/TestExpectations
    A 
LayoutTests/platform/gtk/fast/events/touch/basic-single-touch-events-expected.txt
    M LayoutTests/platform/wpe/TestExpectations
    M Source/WebKit/Shared/NativeWebTouchEvent.h
    M Source/WebKit/Shared/gtk/NativeWebTouchEventGtk.cpp
    M Source/WebKit/UIProcess/API/gtk/WebKitWebViewBase.cpp
    M Source/WebKit/UIProcess/API/gtk/WebKitWebViewBaseInternal.h
    M Tools/WebKitTestRunner/EventSenderProxy.h
    M Tools/WebKitTestRunner/gtk/EventSenderProxyGtk.cpp

  Log Message:
  -----------
  Cherry-pick 319450@main (c4264e1b1836). 
https://bugs.webkit.org/show_bug.cgi?id=319580

    [GTK] Implement touch event synthesis in WebKitTestRunner
    https://bugs.webkit.org/show_bug.cgi?id=319580

    Reviewed by Nikolas Zimmermann and Carlos Garcia Campos.

    The GTK EventSenderProxy touch methods were empty stubs, so
    eventSender.addTouchPoint(), touchStart() and friends dispatched nothing
    and the fast/events/touch tests timed out. Unlike mouse, key and wheel
    events, WebKitWebViewBase had no touch synthesis entry point, and the
    existing touch path is built around GdkEvent, which cannot be constructed
    by application code under GTK4. Add webkitWebViewBaseSynthesizeTouchEvent(),
    which builds the WebPlatformTouchPoint list and dispatches a
    NativeWebTouchEvent directly, the same way the mouse path already bypasses
    GdkEvent; the GTK EventSenderProxy keeps the touch point state and maps it
    onto that entry point.

    Update the touch event test expectations for the tests that now pass, were
    unskipped, or changed to a deterministic failure, and add a GTK baseline
    for basic-single-touch-events.html (touch point radius is unsupported, as
    on WPE, but the touch modifiers are applied).

    Covered by fast/events/touch tests.

    * LayoutTests/platform/glib/TestExpectations:
    * LayoutTests/platform/gtk/TestExpectations:
    * 
LayoutTests/platform/gtk/fast/events/touch/basic-single-touch-events-expected.txt:
 Added.
    * LayoutTests/platform/wpe/TestExpectations:
    * Source/WebKit/Shared/NativeWebTouchEvent.h:
    * Source/WebKit/Shared/gtk/NativeWebTouchEventGtk.cpp:
    (WebKit::NativeWebTouchEvent::NativeWebTouchEvent):
    (WebKit::m_nativeEvent):
    * Source/WebKit/UIProcess/API/gtk/WebKitWebViewBase.cpp:
    (toWebPlatformTouchPointState):
    (webkitWebViewBaseSynthesizeTouchEvent):
    * Source/WebKit/UIProcess/API/gtk/WebKitWebViewBaseInternal.h:
    * Tools/WebKitTestRunner/EventSenderProxy.h:
    * Tools/WebKitTestRunner/gtk/EventSenderProxyGtk.cpp:
    (WTR::toSyntheticTouchPointState):
    (WTR::EventSenderProxy::addTouchPoint):
    (WTR::EventSenderProxy::updateTouchPoint):
    (WTR::sendTouchEvent):
    (WTR::markAllTouchPointsStationary):
    (WTR::EventSenderProxy::touchStart):
    (WTR::EventSenderProxy::touchMove):
    (WTR::EventSenderProxy::touchEnd):
    (WTR::EventSenderProxy::touchCancel):
    (WTR::EventSenderProxy::clearTouchPoints):
    (WTR::EventSenderProxy::releaseTouchPoint):
    (WTR::EventSenderProxy::cancelTouchPoint):
    (WTR::EventSenderProxy::setTouchModifier):

    Canonical link: https://commits.webkit.org/319450@main

Canonical link: https://commits.webkit.org/317695.386@webkitglib/2.54


  Commit: 381ce36a6115f78ff8a66c3c5dc8bbef98d18efa
      
https://github.com/WebKit/WebKit/commit/381ce36a6115f78ff8a66c3c5dc8bbef98d18efa
  Author: Fujii Hironori <[email protected]>
  Date:   2026-10-02 (Fri, 02 Oct 2026)

  Changed paths:
    M Source/WebKit/UIProcess/API/gtk/WebKitWebViewBase.cpp

  Log Message:
  -----------
  Cherry-pick 321593@main (705dc8136413). 
https://bugs.webkit.org/show_bug.cgi?id=324698

    [GTK] Fix touch positions and cancel outstanding touch sequences
    https://bugs.webkit.org/show_bug.cgi?id=324698

    Reviewed by Carlos Garcia Campos.

    Four problems in the GTK touch event path. Mouse input is unaffected by any 
of
    them.

    1. The touch positions are offset by the surface transform.

    appendTouchEvent() takes the raw position of the GdkEvent, which in GTK4 is
    relative to the GdkSurface, and converts it with
    gtk_widget_translate_coordinates(). That function is a thin wrapper around
    gtk_widget_compute_point() and only converts between widget coordinate 
spaces.
    The surface transform, the offset of the native widget within the surface 
that
    leaves room for the client-side decoration shadows, lies outside the widget
    hierarchy, so it is not accounted for and every touch point lands that far 
away
    from the finger. Maximizing the window makes the offset disappear, because 
the
    shadows are dropped.

    GTK's own translate_event_coordinates() subtracts the surface transform 
before
    computing the point, which is why only touch is wrong. The mouse event 
handlers
    get their coordinates from the GtkGesture signals, which have already been
    through it; the touch path re-derives them from the raw event and skips it. 
Do
    the same here.

    2. Touch sequences are stranded when the view is unmapped.

    priv->touchEvents was only ever modified by webkitWebViewBaseTouchEvent(), 
which
    is not reached once the widget is unmapped: gtk_widget_event() returns 
early for
    unmapped widgets, and GTK does not cancel the sequences on our behalf. It 
hands
    the implicit grab over to the parent widget and synthesizes crossing 
events, but
    no touch end. Keeping a finger down while switching to another tab therefore
    left the page with a touch that is never released, and the stale touch 
point was
    reported as Stationary in every subsequent touch event for the lifetime of 
the
    view. In debug builds the ASSERT(!priv->touchEvents.contains(sequence)) of 
the
    GDK_TOUCH_BEGIN case could also be hit, if GDK reused the GdkEventSequence
    pointer value of a stranded sequence.

    Cancel the outstanding sequences from the unmap handler, before chaining 
up, so
    that the widget is still mapped and rooted while the touch points are 
converted.
    A GDK_TOUCH_CANCEL that arrives afterwards is ignored, because
    webkitWebViewBaseTouchEvent() returns early for a sequence that is not in 
the
    map.

    3. A cancelled touch point is reported as Released.

    webkitWebViewBaseGetTouchPointsForEvent() appends the sequence that has just
    been taken out of the map with State::Released for GDK_TOUCH_END and
    GDK_TOUCH_CANCEL alike, even though WebEventFactory::createWebTouchEvent() 
types
    the event itself as TouchCancel. Use State::Cancelled there, matching what 
the
    new unmap path sends.

    4. Touch sequences are stranded when a dialog is shown.

    The same defect as 2, through a different door. 
webkitWebViewBaseTouchEvent()
    returns GDK_EVENT_STOP as soon as priv->dialog is set, before the map is
    touched, so a finger that is down when an authentication or script dialog 
comes
    up never has its sequence removed. Cancel the outstanding sequences from
    webkitWebViewBaseAddDialog() as well. Nothing is added to the map for as 
long as
    the dialog is up, so it is still empty once the dialog goes away, and the
    GDK_TOUCH_UPDATE and GDK_TOUCH_END of a sequence that started before it are
    dropped by the same early returns that ignore a late GDK_TOUCH_CANCEL.

    No new tests. The coordinate offset only shows up with client-side 
decoration
    shadows, and the stranded sequences need the view to be unmapped or a 
dialog to
    come up mid-gesture; the touch event synthesis of WebKitTestRunner cannot
    reproduce either.

    * Source/WebKit/UIProcess/API/gtk/WebKitWebViewBase.cpp:
    (webkitWebViewBaseAddDialog):
    (webkitWebViewBaseUnmap):
    (appendTouchEvent):
    (webkitWebViewBaseGetTouchPointsForEvent):
    (webkitWebViewBaseCancelTouchSequences):

    Co-Authored-By: Claude Opus 5
    Canonical link: https://commits.webkit.org/321593@main

Canonical link: https://commits.webkit.org/317695.387@webkitglib/2.54


Compare: https://github.com/WebKit/WebKit/compare/628d6ce1850e...381ce36a6115

To unsubscribe from these emails, change your notification settings at 
https://github.com/WebKit/WebKit/settings/notifications

Reply via email to